Communication credentials between two operating systems
By generating and transmitting a random salt between two operating systems to generate a second transmission key, the security issue of communication credentials after a device is restored to factory settings is resolved, and secure and reliable communication between operating systems is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BLACKBERRY LTD
- Filing Date
- 2024-08-21
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies present security and reliability issues when communicating credentials between two operating systems, especially after a device is restored to factory settings, requiring the regeneration and repopulation of provisioning credentials to ensure the security of mTLS communication.
The primary operating system generates a first transmission key and a random salt, packages them, and sends them to the secondary operating system. The secondary operating system unpacks the random salt and confirms receipt. Both parties use the random salt to generate a second transmission key for transmitting the supply certificate, and an encoding algorithm is used to protect the data transmission.
It improves the security and reliability of provisioning operations between the two operating systems, ensuring the stability of mTLS communication and the security of data transmission.
Smart Images

Figure CN119885214B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to communication credentials between two operating systems (OS). Background Technology
[0002] In some implementations, credentials can be communicated between two OSes. For example, during a provisioning operation, one OS can send provisioning credentials to another OS. Attached Figure Description
[0003] Figure 1 This is a schematic diagram showing an example system for providing supply operations based on the implementation.
[0004] Figure 2 It is a flowchart showing an example process based on the implemented supply operation.
[0005] Figure 3 It is a diagram showing an example encoding scheme based on the implementation.
[0006] Figure 4 It is a flowchart showing an example method of the supply operation implemented.
[0007] Figure 5 A high-level architecture block diagram based on the implementation of the computer is shown.
[0008] Similar reference numerals and names in the various figures indicate similar elements. Detailed Implementation
[0009] In some cases, two operating systems (OS) can run on the same device. This device can be a standalone device or a module within a system. During provisioning, the primary OS can trigger provisioning on the secondary OS. The primary OS can set a device-specific Certificate Authority (CA) for the device and send the CA credentials and CA key (e.g., CA private key) to the secondary OS. In some implementations, the provisioning process can occur during the manufacturing phase, and both OSes store provisioning credentials when the device is manufactured. However, in some cases, these provisioning credentials can be deleted during initialization (e.g., a factory reset operation). Therefore, runtime provisioning can be used to regenerate and populate provisioning credentials in both OSes to ensure that both OSes can communicate with each other using mutual transport layer security (mTLS).
[0010] In some cases, to securely provide a shared secret (e.g., a supply credential) to a secondary OS, the primary OS can generate a first transmission key and a random salt. The primary OS can send the random salt, wrapped in the first transmission key, to the secondary OS. The secondary OS can obtain the random salt using an unwrapping operation. The secondary OS can send the random salt back to the primary OS to acknowledge receipt. In some cases, the secondary OS sends the size of the random salt back to the primary OS to acknowledge receipt. In some cases, the secondary OS hashes the random salt and sends the hashed random salt back to the primary OS. Both the primary and secondary OSs can use the random salt to generate a second transmission key and communicate the supply credential using the second transmission key. In some cases, encoding algorithms can be used to protect the transmission of the random salt between the primary and secondary OSs. These methods improve the security of the supply operation. Figures 1 to 5 The associated descriptions provide additional details about these implementations.
[0011] Figure 1 This is a schematic diagram showing an example communication system 100 providing supply operations according to an implementation. At a high level, the example communication system 100 includes a vehicle 120 communicatively coupled to a client device 122. The vehicle 120 is also communicatively coupled to a server 130 via a network 140.
[0012] Vehicle 120 may include motor vehicles (e.g., automobiles, cars, trucks, buses, motorcycles, etc.), aircraft (e.g., airplanes, unmanned aerial vehicles, unmanned aerial vehicle systems, drones, helicopters, etc.), spacecraft (e.g., space shuttles, spacecraft, space stations, satellites, etc.), ships (e.g., ships, small boats, hovercraft, submarines, etc.), rail vehicles (e.g., trains, trams, etc.), and other types of vehicles, whether currently existing or emerging, including any combination of the foregoing. In the example shown, vehicle 120 includes one or more sensors 102 connected to bus 110, vehicle component controller 104, vehicle system processor 106, communication subsystem 116, user interface 118, memory 114, and operating devices 150.
[0013] In some cases, a vehicle may include one or more sensors. These sensors may generate inputs, such as video or audio inputs, reflecting the surrounding environment or the environment inside the vehicle. Examples of sensors may include cameras, microphones, lasers, radar, ultrasonic sensors, light detection and ranging (LIDAR), or any other sensors.
[0014] Vehicle 120 includes one or more sensors 102 that detect or measure information about vehicle 120. Examples of sensors 102 may include sensors that capture environmental information outside vehicle 120, such as cameras, microphones, lasers, radar, ultrasonic sensors, light detection and ranging (LIDAR), etc. These sensors can provide environmental input to an automated processing platform operating on vehicle 120 to make automated decisions. Examples of sensors 102 may also include devices that capture information inside vehicle 120, such as monitors for components such as engines, batteries, fuel, electronic systems, cooling systems, etc. These sensors can provide operating status and warnings to an automated processing platform operating on vehicle 120. Examples of sensors 102 may also include acoustic sensors that can detect sound levels inside vehicle 120. The acoustic sensor can determine the noise level inside vehicle 120 or provide input to other signal processors that determine the noise level.
[0015] Vehicle 120 includes vehicle component controller 104. Although in Figure 1 The vehicle component controller 104 is shown as vehicle component controller 104, but vehicle 120 may include two or more vehicle component controllers 104. Vehicle component controller 104 represents a controller that controls the operation of components on vehicle 120. Examples of components may include an engine, accelerator, brakes, radiator, battery, steering wheel, transmission system, cooling system, electrical system, entertainment system, and any other components of vehicle 120. For example, vehicle component controller 104 may control the speaker system of vehicle 120, including controlling volume, balance, attenuation, and any other settings for audio output within vehicle 120. Vehicle component controller 104 may automatically operate the corresponding components based on input from vehicle system processor 106 or a combination thereof. In some implementations, vehicle component controller 104 may include data processing means.
[0016] The vehicle system processor 106 may include one or more processing components (optionally referred to as a "processor" or "central processing unit") configured to execute one or more relevant instructions for a process, step, or action of an automated processing platform operating on the vehicle 120. Typically, the vehicle system processor 106 executes instructions and manipulates data to perform operations of the automated processing platform. The vehicle system processor 106 may receive input from the sensor 102 and generate commands to the vehicle component controller 104. In some cases, the vehicle system processor 106 may perform automated operations. In some cases, the vehicle system processor 106 may include data processing means.
[0017] The communication subsystem 116 can be configured to provide wireless or wired communication for data or control information to the vehicle 120. For example, the communication subsystem 116 can support transmission via wireless local area network (WLAN or WiFi), near field communication (NFC), infrared (IR), radio frequency identification (RFID), Bluetooth (BT), universal serial bus (USB), or any other short-range communication protocol. The communication subsystem 116 can also support Global System for Mobile Communications (GSM), Provisional Standard 95 (IS-95), Universal Mobile Telecommunications System (UMTS), CDMA2000 (Code Division Multiple Access), Evolved Universal Mobile Telecommunications System (E-UMTS), Long Term Evolution (LTE), Advanced LTE, 5G, or any other radio access technology. The communication subsystem 116 may include, for example, one or more antennas, a receiver, a transmitter, a local oscillator, a mixer, and a digital signal processing (DSP) unit. In some implementations, the communication subsystem 116 can support multiple-input multiple-output (MIMO) transmission. In some implementations, the receiver in the communication subsystem 116 can be an advanced receiver or a baseline receiver.
[0018] User interface 118 may include one or more of the following: a display or touchscreen display (e.g., a liquid crystal display (LCD), a light-emitting diode (LED), an organic light-emitting diode (OLED), or a microelectromechanical system (MEMS) display), a keyboard or keypad, a trackball, a speaker, or a microphone. User interface 118 may also include an I / O interface, such as a universal serial bus (USB) interface.
[0019] Memory 114 may be a computer-readable storage medium. Examples of memory 114 include volatile and non-volatile memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), removable media, etc. Memory 114 may store the operating system (OS) of vehicle 120 and various other computer-executable software programs for performing one or more of the above-described processes, steps, or actions.
[0020] Operating device 150 refers to an application, set of applications, software, software module, hardware, or any combination thereof that can be configured to perform one or more specific operations on vehicle 120. In some implementations, operating device 150 may be a module that controls the infotainment operation of vehicle 120. For example, operating device 150 may interact with sensor 102 to obtain data and present it on user interface 118. Operating device 150 may also receive user input from user interface 118 and control speakers or screens to output video or music.
[0021] In some implementations, both the first OS 152 and the second OS 154 can run on the operating device 150. The first OS 152 may also be referred to as the main OS. The first OS 152 can be configured to interact with control components in the vehicle 120 related to the driving operation of the vehicle 120 (e.g., some of the sensors 102 involved in the automatic processing platform, such as LiDAR, vehicle system processor 106, and vehicle component controller 104). The second OS 154 may also be referred to as the secondary OS. The second OS 154 can be configured to interact with the user interface 118, the communication subsystem 116, and external devices such as client device 122 and server 130. In one example, the first OS 152 may be a real-time embedded OS. The second OS 154 may be Android or iOS. In some implementations, the first OS 152 does not have access to components outside the vehicle 120, while the second OS 154 can interact with devices outside the vehicle 120 through the communication subsystem 116.
[0022] In one example operation, the starting of vehicle 120 (e.g., by engine start) can trigger the power-on of operating device 150. When operating device 150 is powered on, first OS 152 starts first to begin runtime operations. Subsequently, first OS 152 starts second OS 154. First OS 152 can check if a provisioning operation is needed. A provisioning operation may be required because no provisioning operation was performed previously or because a re-provisioning operation is needed. First OS 152 establishes a mutual transport layer security (mTLS) relationship with second OS 154 by sharing a secret through communication. In some implementations, first OS 152 can initiate the provisioning process by sending a runtime-generated random salt wrapped with a first transport key to second OS 154. This random salt can be used to generate a second transport key, which is used to transmit the provisioning credentials. Figures 2 to 4 The associated descriptions provide additional details about these implementations. In some implementations, modules or apps within the first OS 152 can be configured to perform some or all of these provisioning operations.
[0023] As shown, bus 110 provides a communication interface for components of an automated processing platform operating on vehicle 120. In some cases, bus 110 may be implemented using a Controller Area Network (CAN) bus.
[0024] Client device 122 represents an application, application set, software, software module, hardware, or any combination thereof that interacts with vehicle 120. For example, client device 122 may interact with operating device 150 for infotainment operation. Client device 122 may be an electronic device, which may include, but is not limited to, any of the following: endpoint, computing device, mobile device, mobile electronic device, user device, mobile station, subscriber station, portable electronic device, mobile communication device, wireless modem, wireless terminal, or other electronic device. Examples of endpoints may include mobile devices, IoT (Internet of Things) devices, EoT (Enterprise of Things) devices, cellular phones, personal data assistants (PDAs), smartphones, laptop computers, tablet computers, personal computers (PCs), pagers, portable computers, portable gaming devices, wearable electronic devices, health / medical / fitness devices, cameras, or other mobile communication devices having components for communicating voice or data via wireless or wired communication networks. Electronic devices may also be peripheral devices, such as headsets, remote controls, or displays. Electronic devices may connect to vehicle 120 using short-range communication technologies. Short-range communication technologies can be wireless, such as BitTorrent, NFC, and WLAN. Short-range communication technologies can also be wired, such as USB.
[0025] Server 130 represents an application, application set, software, software module, hardware, or any combination thereof that can be configured to manage the operation of vehicle 120. In some implementations, server 130 may interact with operating device 150 for security or infotainment operations.
[0026] Example communication system 100 includes network 140. Network 140 represents an application, application set, software, software module, hardware, or combination thereof that can be configured to transmit data between server 130 and vehicle 120 in communication system 100. Network 140 includes wireless network, wired network, or combination thereof. For example, network 140 may include one or more of a radio access network (RAN), a core network (CN), and an external network. The RAN may include one or more radio access technologies. In some implementations, the radio access technology may be Global System for Mobile Communications (GSM), Provisional Standard 95 (IS-95), Universal Mobile Telecommunications System (UMTS), CDMA2000 (Code Division Multiple Access), Evolved Universal Mobile Telecommunications System (E-UMTS), Long Term Evolution (LTE), Advanced LTE, 5G, or any other radio access technology. In some instances, the core network may be an Evolved Packet Core (EPC).
[0027] Although Figure 1The components are shown as various component parts, sections, or modules that implement various features and functions; however, alternatively, these components may appropriately include several sub-modules, third-party services, components, libraries, etc. Furthermore, the features and functions of various components may be appropriately combined into fewer components.
[0028] In addition, although using Figure 1 The vehicle 120 in this disclosure is used as an example to describe the processes and methods of this disclosure; however, these processes and methods can also be used in other non-vehicle devices in which two OSes operate on the same device and communicate to share secrets during supply. Furthermore, these processes and methods can be used between two OSes on different devices to communicate and share secrets during supply.
[0029] Figure 2 This is a flowchart of an example process 200 based on the implementation of a supply operation. Process 200 can be... Figure 1 This can be implemented by one or more entities shown or by any other system or module that provides the supply operation. For example, process 200 can be implemented by... Figure 2 The first OS152 and the second OS154 shown are implemented. Figure 2 The example process 200 shown can be implemented using additional, fewer, or different operations that can be performed in the order shown or in a different order.
[0030] Example process 200 begins at step 202, where the provisioning process is triggered. In some implementations, process 200 may be triggered by the startup of the first OS 152. When the first OS 152 starts, it may check the provisioning storage to determine if some or all of the provisioning credentials are stored. As discussed later in step 232, provisioning credentials may include entity keys, CA keys, entity credentials, or CA credentials, or any combination thereof. In some implementations, these provisioning credentials are stored in a specific storage such that they are accessible to the second OS 154. If the provisioning credentials are stored, the first OS 152 continues to check if they are valid. The first OS 152 may determine the validity of these provisioning credentials by attempting an encryption operation using them. Examples of encryption operations include encryption or decryption operations. This encryption or decryption operation may be based on an Advanced Encryption Standard (AES). If the encryption operation is successfully set to continue to the next step, the provisioning credentials are valid.
[0031] If the supply document is not stored or is invalid, the first OS152 continues to step 210 to begin the supply process.
[0032] In some implementations, the second OS154 can determine whether a provisioning process is required by checking if the provisioning credential is available. In some implementations, the provisioning credential is stored in a keystore accessible to the second OS154. The second OS154 can check this keystore to determine if the provisioning credential is available. If the provisioning credential is available, the second OS154 can continue operating. If the provisioning credential is not available, the second OS154 will wait to receive the provisioning credential.
[0033] In the example shown, the supply process is initiated by the first OS152. Alternatively, or in combination, the second OS154 may also initiate the supply process. For example, if the second OS154 determines that the supply document does not exist, the second OS154 may send a supply request to the first OS152 to trigger step 210.
[0034] At step 210, the first OS152 generates a first transmission key. In some implementations, this first transmission key may be generated based on a passphrase and a first salt. The passphrase is a secret shared between the first OS152 and the second OS154. An example of a passphrase may be a password. The first salt is a fixed value accessible to both the first OS152 and the second OS154. An example of a first salt value may be a random or pseudo-random value. In some cases, the first salt may be generated by the manufacturer of the devices running the first OS152 and the second OS154. The first salt may be stored on a device accessible to both the first OS152 and the second OS154. In some cases, the first salt may be the same for multiple devices manufactured by the same manufacturer.
[0035] A first transport key can be generated using a key derivation function or key generation API with a passphrase and a first salt as input. Examples of key derivation functions or key generation APIs include the OpenSSL API or the EnVeloPe key derivation function (EVP KDF).
[0036] In some cases, the first transmission key can be further processed using a hash function. For example, the Secure Hash Algorithm 256 (SHA 256) can be applied to the first transmission key to extend it to 256 bits. Other hash functions can also be used.
[0037] The first OS152 also generates a random salt at step 210. This random salt can be generated using a pseudo-random number generator. Because the random salt is generated at each runtime during the execution of process 200, unlike the first salt discussed earlier, the random salt is different for each device and is different each time a supply process occurs.
[0038] At position 212, the first OS152 sends a random salt wrapped using the first transmission key to the second OS154. The first OS152 performs the wrapping operation by generating ciphertext from the random salt input using the first transmission key, and the ciphertext is then sent to the second OS154.
[0039] In some cases, data communication between the first OS152 and the second OS154 can be achieved using a memory transfer protocol such as the Hypervisor Abstraction (HAB). Alternatively or in combination, data communication between the first OS152 and the second OS154 can be achieved using other standardized communication protocols, such as the Transmission Control Protocol (TCP) or proprietary communication protocols.
[0040] At 220, the second OS154 receives the packaged random salt and performs an unpacking function to obtain the random salt. As discussed previously, the second OS154 has the same ciphertext and first salt as the first OS152 used to generate the first transmission key. Therefore, the second OS154 can also use the ciphertext and first salt to generate the first transmission key, and can use the first transmission key to unpack the received packaged random salt to obtain the random salt.
[0041] At 222, the second OS154 sends a first response to the first OS152. This first response includes the random salt decoded from step 220. By sending the decoded random salt back to the first OS152, the second OS154 indicates to the first OS152 that the random salt has been successfully received and decoded. Alternatively or additionally, the second OS154 may send the size of the random salt to the first OS152 to confirm receipt of the random salt.
[0042] In some implementations, the second OS154 can process the random salt using a hash function before sending it at position 222. For example, the Secure Hash Algorithm 256 (SHA256) can be applied to the random salt to extend it to 256 bits. Other hash functions can also be used. Sending a hashed random salt can improve the security of the transmitted information.
[0043] In some cases, to further enhance the security of the transmission between the first OS152 and the second OS154, an encoding scheme may be applied to the data transmitted at step 212, step 222, or both. Figure 3 This is a diagram showing the implementation of example encoding scheme 300.
[0044] like Figure 3As shown, input data 310 is encoded to generate encoded data 320. The encoded data is organized into one or more block groups. For example, each block group of block group 330 includes a zeroth block 332. The zeroth block 332 is a bitmask indicating whether each remaining block in the remaining blocks of block group 330 is a data block or a padding block. In the example shown, the bitmask consists of 8 bits, with the first, third, fourth, and sixth bits set to "1", indicating that the corresponding blocks (i.e., blocks 1, 3, 4, and 6) are data blocks. The remaining blocks in the block are padding blocks. Input data 310 can be padded with data blocks sequentially, starting with block 1 and continuing to blocks 3, 4, and 6, skipping padding blocks. Padding blocks can be padded with "1", "0", or randomly generated bits. If there is additional data in input data 310 after the data blocks in padding block group 330, a second block group can be included. The second block group also begins with a bitmask block to indicate whether each remaining block in the remaining blocks of the second block group is a data block or a padding block. This process can be repeated until all input data 310 is included in encoded data 320. In the example shown, each bitmask has 8 bits and each block group has 9 blocks (8 blocks corresponding to each bit in the bitmask, plus the bitmask block), and each block can be a byte. The size of the blocks and the size of the block groups can also be other numbers.
[0045] In some cases, bitmasks can be generated using a random function. The bitmasks in each block group can be the same or different.
[0046] In some implementations, the encoded data 320 may also include an indicator 322. The indicator 322 may indicate a sequential order. For example, bits in the indicator 322 may be set to "0" to indicate normal order and set to "1" to indicate reverse order. Alternatively, the indicator 322 may be a byte set to "0" to indicate normal order and set to "255" to indicate reverse order. In some implementations, normal order may indicate that data is padded from the first data block to the last data block in each block group, while reverse order may indicate that data is padded from the last data block to the first data block in each block group. Alternatively or additionally, normal order may indicate that data is padded from the first block group to the last block group, while reverse order may indicate that data is padded from the last block group to the first block group. Alternatively or additionally, normal order may indicate that the indicator bits in the bitmask are sequential, where the first bit corresponds to the first block after the bitmask, and reverse order may indicate that the indicator bits in the bitmask are reversed, where the first bit corresponds to the last block in the block group. Alternatively or additionally, the normal order can indicate that the indicator bits in the bitmask are set to "1" to represent a data block and set to "0" to represent a padding block, and the reverse order can indicate that the indicator bits in the bitmask are set to "0" to represent a data block and set to "1" to represent a padding block. In some cases, indicator 322 may include multiple bits to indicate the different types of order discussed earlier. For example, one bit may indicate the order within a block group, another may indicate the order between block groups, and yet another one or two bits may indicate the order of the bitmask discussed earlier. In some implementations, indicator 322, or each bit in indicator 322, may be randomly generated.
[0047] Figure 3 The encoding scheme can be used in step 212, where the packaged random salt is encoded using this encoding scheme. A data length indicator can also be transmitted in step 212 to indicate the size of the input data before encoding. The second OS154 will first decode the data according to indicator 322 and the first block 332 in each block group to obtain the packaged random salt. The second OS154 then further decodes the packaged random salt by unpacking it using the first transmission key to obtain the random salt.
[0048] Additional or alternative land can be used in step 222. Figure 3 The encoding scheme in step 222 is used to transmit the first response, which includes a random salt. A data length indicator can also be transmitted in step 222 to indicate the size of the input data prior to encoding.
[0049] return Figure 2 At step 230, the first OS152 receives a first response and determines whether the data in the first response matches a random salt. If the first response uses... Figure 3 Encoded using the encoding scheme in the first response, the first OS152 uses indicator 322 and block 332 in each block group to obtain the data in the first response. In some cases, as discussed previously, the data in the first response may be a hashed random salt. In this case, the first OS152 may also perform a hash on the random salt using the same hash function and compare the hash result with the data in the first response. If the hash result matches the data in the first response, the first OS152 can infer that the second OS154 has successfully obtained the random salt sent at step 212. Alternatively, the data in the first response may include a random salt that has not been hashed. In this case, the first OS152 may simply compare the data with the random salt to determine whether the second OS154 has successfully obtained the random salt.
[0050] If the match fails, the first OS152 can return to step 210 and generate another random salt, and repeat steps 212 to 222.
[0051] If a match is found, both OS152 and OS154 can use the random salt to generate a second transmission key. In some implementations, the second transmission key can be generated using a key derivation function or key generation API, taking the passphrase (used in step 210 to generate the first transmission key) and the random salt as input. Examples of key derivation functions or key generation APIs include the OpenSSL API or EVP KDF. The second transmission key can be used to package supply credentials for transmission by OS152.
[0052] The first OS152 may generate a supply document in response to a successful match found at step 230. Alternatively or in combination, the first OS152 may generate some or all of the supply documents before the successful match at step 230 (e.g., during step 210 or after step 212).
[0053] The supply certificate may include one or more of the following: device CA private key, device CA public key, device CA certificate, entity private key, entity public key, entity certificate, key encryption key used to encapsulate the private key, and other certificates.
[0054] At step 232, the first OS152 sends a supply certificate to the second OS154. This supply certificate is packaged using a second transmission key. The first OS152 performs a packaging operation using the second transmission key to generate ciphertext from the supply certificate, and this ciphertext is then sent to the second OS154. The second OS154 obtains the supply certificate by performing a depackaging operation to depack the received ciphertext using the second transmission key.
[0055] In some cases, the type of provisioning credential generated and transmitted depends on the specific security operations associated with the provisioning process. In one implementation, the device CA is provided by a first OS152. The first OS152 may send the CA private key and CA credentials to a second OS154 in a single transmission or in a separate transmission. The second OS154 may instantiate the CA based on the received CA private key and CA credentials and use it to generate entity credentials for an entity (e.g., operating device 150). In some cases, each endpoint of the connection may be referred to as an entity.
[0056] In another implementation, entity key pairs can be created in the first OS152 and the second OS154. In this case, the first OS152 sends the entity certificate to the second OS154. In yet another implementation, third-party CA credentials are transferred between the first OS152 and the second OS154, and vice versa, depending on which OS has internet access and which OS does not.
[0057] Figure 4 This is a flowchart showing an example method 400 based on the implemented supply operation. Method 400 can be... Figure 1 This can be implemented by one or more entities shown or by any other system or module that provides the supply operation. For example, method 400 can be implemented by... Figure 1 The operation device 150 shown is used to implement this. Figure 4 The example method 400 shown can be implemented using additional, fewer, or different operations that can be performed in the order shown or in a different order.
[0058] At 402, the first OS generates a first transmission key. In some cases, the first OS generates the first transmission key by deriving it from a passphrase and a first salt value. At 404, the first OS sends a random salt to the second OS using the first transmission key. At 406, the first OS generates a second transmission key using the random salt. In some cases, the first OS generates the second transmission key from the passphrase and the random salt. At 408, the first OS sends a supply credential to the second OS using the second transmission key.
[0059] Figure 5 A high-level architecture block diagram of a computer 500 based on an implementation is shown. Computer 500 can be implemented as an operating device 150, a client device 122, a server 130, or any combination thereof. Computer 500 can also be used to implement... Figures 1 to 4The operations discussed herein. The illustrations described are merely one possible implementation of the described subject matter and are not intended to limit this disclosure to a single described implementation. Those skilled in the art will recognize that the described components can be connected, combined, and / or used in alternative ways consistent with this disclosure.
[0060] In some cases, the processing algorithms established by the code grouping can be implemented as executable computational code, such as C / C++ executable code. In some cases, computer 500 may include a standalone Linux system running batch processing applications. In some cases, computer 500 may include a mobile or personal computer.
[0061] Computer 500 may include a computer, which includes input devices such as a keypad, keyboard, touchscreen, microphone, voice recognition device, other devices that can accept user information, and / or output devices that transmit information related to the operation of the computer, including digital data, visual and / or audio information, or a GUI.
[0062] Computer 500 can be used as a client, network component, server, database or other persistence, and / or any other component. In some implementations, one or more components of Computer 500 can be configured to operate within a cloud-based environment.
[0063] At a higher level, computer 500 is an electronic computing device operable to receive, transmit, process, store, or manage data. Depending on some implementations, computer 500 may also include, or be communicatively coupled to, application servers, email servers, web servers, cache servers, streaming data servers, business intelligence (BI) servers, and / or other servers.
[0064] Computer 500 can collect data on network events or mobile application usage events from a web browser or client application (e.g., an installed plugin) via network 110. Furthermore, data can be collected by computer 500 from internal users (e.g., from a command console or through another suitable access method), external or third parties, other automated applications, and any other suitable entity, individual, system, or computer.
[0065] Each component of computer 500 can communicate using system bus 512. In some implementations, any and / or all components (hardware and / or software) of computer 500 can interact with each other and / or with interface 502 via system bus 512 using application programming interface (API) 508 and / or service layer 510. API 508 may include specifications for routines, data structures, and object classes. API 508 may be language-independent or language-dependent and refers to a complete interface, a single function, or even a collection of APIs. Service layer 510 provides software services to computer 500. The functionality of computer 500 is accessible to all service consumers using the service layer. Software services such as those provided by service layer 510 provide reusable, defined business functions through defined interfaces. For example, the interface may be software written in Java, C++, or other suitable languages that provide data in Extensible Markup Language (XML) or other suitable formats. Although shown as an integrated component of computer 500, alternative implementations may show API 508 and / or service layer 510 as independent components relative to other components of computer 500. Furthermore, without departing from the scope of this disclosure, any or all portions of API 508 and / or service layer 510 may be implemented as children or submodules of another software module, enterprise application, or hardware module.
[0066] Computer 500 includes interface 502. Although in Figure 5 The interface 502 is shown as a single interface, but two or more interfaces 502 may be used depending on the specific needs, expectations, or implementation of the computer 500. Interface 502 is used by the computer 500 to communicate with other systems in a distributed environment connected to a network (whether shown or not). Typically, interface 502 includes logic encoded in a suitable combination of software and / or hardware and is operable to communicate with the network. More specifically, interface 502 may include software supporting one or more communication protocols associated with the communication, enabling the network or interface hardware to communicate physical signals both inside and outside the computer 500.
[0067] Computer 500 includes at least one processor 504. Although in Figure 5 The computer is shown as a single processor 504, but two or more processors may be used depending on the specific needs, expectations, or implementation of the computer. Typically, processor 504 executes instructions and manipulates data to perform operations of the computer 500. Specifically, processor 504 executes... Figures 1 to 4 The functions disclosed in the document.
[0068] Computer 500 also includes memory 514 for storing data on computer 500. Although in Figure 5The memory 514 is shown as a single memory, but two or more memories may be used depending on the specific needs, expectations, or implementation of the computer 500. Although the memory 514 is shown as an integrated component of the computer 500, in alternative implementations, the memory 514 may be external to the computer 500.
[0069] Application 506 is an algorithmic software engine that provides functionality (particularly regarding functionality required for anomaly detection) according to the specific needs, expectations, or specific implementation of computer 500. Although shown as a single application 506, application 506 can be implemented as multiple applications 506 on computer 500. Furthermore, although shown as integrated into computer 500, in alternative implementations, application 506 can be external to computer 500.
[0070] There can be any number of computers 500 that are associated with or outside the network and communicate through the network. Furthermore, this disclosure anticipates that many users may use one computer 500, or one user may use multiple computers 500.
[0071] The implementation of the described subject matter may include one or more features, individually or in combination.
[0072] For example, in a first implementation, the method includes: generating a first transmission key by a first operating system (OS); sending a random salt from the first OS to a second OS using the first transmission key; generating a second transmission key by the first OS using the random salt; and sending a supply credential from the first OS to the second OS using the second transmission key.
[0073] Optionally, the foregoing and other described implementations may each include one or more of the following features:
[0074] The first feature is that it can be combined with any of the following features, wherein the supply credential includes at least one of a credential issuing authority (CA)'s private key or a credential of the CA.
[0075] The second feature, which can be combined with any of the previous or following features, also includes receiving a first response from the second OS by the first OS, wherein the first response includes data; and determining by the first OS that the data in the first response matches the random salt.
[0076] The third feature, which can be combined with any of the preceding or following features, includes a bitmask, each bit of which indicates whether the corresponding byte includes data or padding.
[0077] The fourth feature is combinable with any of the preceding or following features, wherein the data includes an indicator indicating one of a sequential or reverse sequential order.
[0078] The fifth feature, which can be combined with any of the preceding or following features, is wherein the data is determined to match the random salt by performing a hash function on the random salt to generate a hash result and determining whether the hash result matches the data.
[0079] The sixth feature, which is composable with any of the preceding features, is that the first OS and the second OS run on the same device and that the first OS and the second OS perform a multi-transport layer security (mTLS) process.
[0080] In a second implementation, a computer-readable medium contains instructions that, when executed, cause an electronic device to perform operations including: generating a first transmission key by a first operating system (OS); sending a random salt from the first OS to a second OS using the first transmission key; generating a second transmission key by the first OS using the random salt; and sending a supply credential from the first OS to the second OS using the second transmission key.
[0081] Optionally, the foregoing and other described implementations may each include one or more of the following features:
[0082] The first feature is that it can be combined with any of the following features, wherein the supply credential includes at least one of a credential issuing authority (CA)'s private key or a credential of the CA.
[0083] The second feature, which can be combined with any of the previous or following features, further includes the operation of the first OS receiving a first response from the second OS, wherein the first response includes data; and the first OS determining that the data in the first response matches the random salt.
[0084] The third feature, which can be combined with any of the preceding or following features, includes a bitmask, each bit of which indicates whether the corresponding byte includes data or padding.
[0085] The fourth feature is combinable with any of the preceding or following features, wherein the data includes an indicator indicating one of a sequential or reverse sequential order.
[0086] The fifth feature, which can be combined with any of the preceding or following features, is wherein the data is determined to match the random salt by performing a hash function on the random salt to generate a hash result and determining whether the hash result matches the data.
[0087] The sixth feature, which is composable with any of the preceding features, is that the first OS and the second OS run on the same device and that the first OS and the second OS perform a multi-transport layer security (mTLS) process.
[0088] In a third implementation, the computer-implemented system includes: one or more computers; and one or more computer memory devices interoperably coupled to the one or more computers and having a tangible, non-transient, machine-readable medium storing one or more instructions, which, when executed by the one or more computers, perform one or more operations, including: generating a first transmission key by a first operating system (OS); sending a random salt from a first OS to a second OS using the first transmission key; generating a second transmission key by the first OS using the random salt; and sending a supply credential from the first OS to the second OS using the second transmission key.
[0089] Optionally, the foregoing and other described implementations may each include one or more of the following features:
[0090] The first feature is that it can be combined with any of the following features, wherein the supply credential includes at least one of a credential issuing authority (CA)'s private key or a credential of the CA.
[0091] The second feature, which can be combined with any of the previous or following features, further includes the operation of the first OS receiving a first response from the second OS, wherein the first response includes data; and the first OS determining that the data in the first response matches the random salt.
[0092] The third feature, which can be combined with any of the preceding or following features, includes a bitmask, each bit of which indicates whether the corresponding byte includes data or padding.
[0093] The fourth feature is combinable with any of the preceding or following features, wherein the data includes an indicator indicating one of a sequential or reverse sequential order.
[0094] The fifth feature, which can be combined with any of the preceding or following features, is wherein the data is determined to match the random salt by performing a hash function on the random salt to generate a hash result and determining whether the hash result matches the data.
[0095] The sixth feature, which is composable with any of the preceding features, is that the first OS and the second OS run on the same device and that the first OS and the second OS perform a multi-transport layer security (mTLS) process.
[0096] The implementation of the subject matter and functional operations described in this specification can be implemented as digital electronic circuit devices, as tangibly embodied computer software or firmware, as computer hardware, including the structures disclosed in this specification and their structural equivalents, or combinations thereof. The software implementation of the described subject matter can be implemented as one or more computer programs, in other words, one or more modules of computer program instructions encoded on a tangible, non-transient, computer-readable medium for execution by or control of the operation of a computer or a computer-implemented system. Alternatively or additionally, program instructions can be encoded in / on artificially generated propagating signals, such as machine-generated electrical, optical, or electromagnetic signals, generated to encode information for transmission to a receiver device for execution by a computer or a computer-implemented system. Computer storage media can be machine-readable storage devices, machine-readable storage substrates, random or serial access memory devices, or combinations of computer storage media. Configuring one or more computers means that the one or more computers have hardware, firmware, or software (or a combination of hardware, firmware, and software) installed such that when the software is executed by the one or more computers, specific computational operations are performed. However, computer storage media are not propagating signals.
[0097] The terms “real-time,” “real time,” “realtime,” “RFT,” “near real-time,” “near real-time,” or similar terms (as understood by one of ordinary skill in the art) mean that actions and responses are close in time, such that an individual perceives the actions and responses as occurring substantially simultaneously. For example, the time difference between an individual's action of accessing data and the display of the data (or the initiation of the display) may be less than 1 millisecond (ms), less than 1 second (s), or less than 5 seconds. Although the requested data does not need to be displayed immediately (or initiated for display), the requested data is displayed (or initiated for display) without any intentional delay, taking into account the processing limitations of the described computing system and the time required for, for example, collecting, accurately measuring, analyzing, processing, storing, or transmitting data.
[0098] The terms “data processing apparatus,” “computer,” “computing device,” or “electronic computer equipment” (or equivalent terms as understood by one of ordinary skill in the art) refer to data processing hardware and include all types of means, devices, and machines for processing data, including, by way of example, a programmable processor, a computer, or multiple processors or computers. A computer may also be or further include special-purpose logic circuitry, such as a central processing unit (CPU), a field-programmable gate array (FPGA), or an application-specific integrated circuit (ASIC). In some implementations, the computer or computer-implemented system or special-purpose logic circuitry (or a combination of a computer or computer-implemented system and special-purpose logic circuitry) may be hardware-based or software-based (or a combination of hardware-based and software-based). The computer may optionally include code that creates an execution environment for computer programs, such as code constituting a combination of processor firmware, protocol stack, database management system, operating system, or execution environment. This disclosure contemplates the use of a computer or computer-implemented system having an operating system or a combination of operating systems, such as LINUX, UNIX, WINDOWS, MAC OS, ANDROID, or IOS.
[0099] A computer program, also referred to or described as a program, software, software application, unit, module, software module, script, code, or other component, can be written in any form of programming language, including compiled or interpreted languages, or declarative or procedural languages, and can be deployed in any form, including, for example, as a standalone program, module, component, or subroutine for use in a computing environment. A computer program may, but does not need to, correspond to a file in a file system. A program can be stored as a portion of a file containing other programs or data, for example, stored in one or more scripts in a markup language document, stored in a single file dedicated to the program in question, or stored in multiple co-files, for example, a file storing one or more modules, subroutines, or code portions. A computer program can be deployed to execute on a single computer or on multiple computers located at a site or distributed across multiple sites and interconnected by a communication network.
[0100] While the program portions shown in the various figures may be depicted as separate components, such as units or modules, implementing the described features and functions using various objects, methods, or other processes, the program may instead suitably include several sub-units, sub-modules, third-party services, components, libraries, and other components. Conversely, the features and functions of various components may be suitably combined into a single component. The thresholds used for calculation determination may be determined statically, dynamically, or both statically and dynamically.
[0101] The described methods, processes, or logical flows represent one or more examples of functionality consistent with this disclosure, and are not intended to limit this disclosure to the described or illustrated implementations, but rather to conform to the broadest scope consistent with the described principles and features. The described methods, processes, or logical flows can be executed by one or more programmable computers executing one or more computer programs to perform functions by manipulating input data and generating output data. The methods, processes, or logical flows can also be executed by special-purpose logic circuitry devices, and the computer can also be implemented as a special-purpose logic circuitry device, such as a CPU, FPGA, or ASIC.
[0102] A computer used to execute computer programs can be based on a general-purpose or special-purpose microprocessor, both of these, or another type of CPU. Typically, the CPU receives instructions and data from memory and writes to memory. The basic components of a computer are the CPU for executing instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more mass storage devices for storing data, such as disks, magneto-optical disks, or optical disks, or be operatively coupled to, receive data from, or transfer data to one or more mass storage devices, or both. However, a computer does not necessarily need to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a Global Positioning System (GPS) receiver, or a portable memory storage device such as a Universal Serial Bus (USB) flash drive, to name just a few.
[0103] Non-transient computer-readable media used for storing computer program instructions and data can include all forms of permanent / non-permanent or volatile / non-volatile memory, media, and memory devices, including, by way of example, semiconductor memory devices such as random access memory (RAM), read-only memory (ROM), phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory devices; magnetic devices such as magnetic tape, cassette tape, internal / removable disk; magneto-optical disk; and optical memory devices such as digital universal / video disc (DVD), compact disc (CD) ROM, DVD+ / -R, DVD-RAM, DVD-ROM, high-definition / density (HD)-DVD, and Blu-ray / Blu-ray disc (BD), and other optical memory technologies. Memory can store various objects or data, including caches, classes, frames, applications, modules, backup data, jobs, web pages, web page templates, data structures, database tables, and repositories of dynamic information or other suitable information including any parameters, variables, algorithms, instructions, rules, constraints, or references. Furthermore, memory can include other suitable data such as logs, policies, security or access data, or report files. Processors and memory can be supplemented or incorporated into dedicated logic circuitry.
[0104] To provide interaction with the user, the implementation of the subject matter described in this specification can be carried out on a computer having a display device for displaying information to the user, such as a cathode ray tube (CRT), liquid crystal display (LCD), light-emitting diode (LED), or plasma monitor, and a keyboard and pointing device through which the user can provide input to the computer, such as a mouse, trackball, or trackpad. Touchscreens can also be used to provide input to the computer, such as a pressure-sensitive tablet computer surface or a multi-touch screen using capacitive or inductive sensing. Other types of devices can be used to interact with the user. For example, feedback provided to the user can be any form of sensory feedback (e.g., visual, auditory, tactile, or a combination of feedback types). Input from the user can be received in any form, including sound, speech, or tactile input. Furthermore, the computer can interact with the user by sending and receiving documents to and from a client computing device used by the user (e.g., by sending a webpage to a web browser in response to a request received from a web browser on the user's mobile computing device).
[0105] The term "graphical user interface (GUI)" can be used in the singular or plural to describe one or more graphical user interfaces and each display on a monitor for a particular graphical user interface. Therefore, a GUI can represent any graphical user interface, including but not limited to a web browser, a touchscreen, or a command-line interface (CLI) that processes information and effectively presents the results to the user. Typically, a GUI may include several user interface (UI) elements, some or all of which are associated with a web browser, such as interactive fields, dropdown lists, and buttons. These and other UI elements may relate to or represent the functionality of the web browser.
[0106] The implementation of the subject matter described in this specification can be implemented in a computing system that includes backend components, such as a data server, or middleware components, such as an application server, or frontend components, such as a client computer with a graphical user interface or a web browser through which a user can interact with the implementation of the subject matter described in this specification, or any combination of one or more such backend, middleware, or frontend components. The components of the system can be interconnected via any form or medium of wired or wireless digital data communication (or a combination of data communications), such as a communication network. Examples of communication networks include local area networks (LANs), radio access networks (RANs), metropolitan area networks (MANs), wide area networks (WANs), global microwave access interoperability (WIMAX), wireless local area networks (WLANs) using protocols such as 802.11x or others, all or part of the Internet, another communication network, or a combination of communication networks. Communication networks can communicate between network nodes using, for example, Internet Protocol (IP) packets, Frame Relay frames, Asynchronous Transfer Mode (ATM) cells, voice, video, data, or other information.
[0107] This computing system may include clients and servers. Clients and servers are typically geographically separated and usually interact via a communication network. The client-server relationship is established by computer programs running on their respective computers and having a client-server relationship with each other.
[0108] In some implementations, any or all components (hardware and / or software) of the computing system can interact with each other and / or interact using APIs and / or service layers. APIs may include specifications for routines, data structures, and object classes. APIs may be language-independent or language-dependent and refer to complete interfaces, single functions, or even sets of APIs. The service layer provides software services to the computing system. The functionality of the various components of the computing system is accessible to all service consumers via this service layer. Software services provide reusable, defined business functions through defined interfaces. For example, an interface may be software written in JAVA, C++, or other suitable languages that provide data in XML or other suitable formats. The API and / or service layer may be integrated and / or independent components related to other components of the computing system. Furthermore, without departing from the scope of this disclosure, any or all portions of the service layer may be implemented as another software module, enterprise application, or child or submodule of a hardware module.
[0109] While this specification contains numerous specific implementation details, these should not be construed as limiting the scope of any inventive concept or the scope of the claims, but rather as descriptions of features characteristic of a particular implementation of a specific inventive concept. Certain features described in this specification in the context of individual implementations may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented individually or in any sub-combination in multiple implementations. Furthermore, although features previously described may be described as functioning in certain combinations and even initially claimed in this way, in some cases, one or more features from the claimed combination may be removed from that combination, and the claimed combination may refer to a sub-combination or a variation of the sub-combination.
[0110] Specific implementations of the subject matter have been described. Other implementations, modifications, and substitutions of the described implementations are within the scope of the appended claims and will be apparent to those skilled in the art. Although operations are depicted in a specific order in the drawings or claims, this should not be construed as requiring the operations to be performed in the specific order shown or in a sequential order to achieve the desired result, or to perform all of the operations shown (some operations may be considered optional). In some cases, multitasking or parallel processing (or a combination of multitasking and parallel processing) may be advantageous and implemented where deemed appropriate.
[0111] The splitting or integration of various system modules and components described in the previous implementation should not be interpreted as requiring device splitting or integration in all implementations. Rather, it should be understood that the described program components and systems can typically be integrated into a single software product or packaged into multiple software products.
[0112] Therefore, the example implementation described above does not define or constrain this disclosure. Other changes, substitutions, and modifications may be made without departing from the scope of this disclosure.
[0113] Furthermore, any claimed implementation is considered applicable to at least one computer-implemented method; a non-transient computer-readable medium storing computer-readable instructions for performing the computer-implemented method; and a computer system including computer memory interoperably coupled to a hardware processor configured to perform the computer-implemented method or instructions stored on the non-transient computer-readable medium.
Claims
1. A method comprising: The first transmission key is generated by the first operating system (OS); A random salt is sent from the first OS to the second OS using the first transmission key; The first OS generates a second transmission key by using the random salt; The first OS receives a first response from the second OS, wherein the first response includes data, wherein the data includes a bitmask, and each bit of the bitmask indicates whether the corresponding byte includes data or padding. The first OS determines that the data in the first response matches the random salt; as well as The supply certificate is sent from the first OS to the second OS using the second transmission key.
2. The method of claim 1, wherein the supply certificate includes at least one of a private key of a credential issuing authority (CA) or a certificate of the CA.
3. The method of claim 1, wherein the data includes an indicator indicating either a sequential order or a reverse sequential order.
4. The method of claim 1, wherein whether the data matches the random salt is determined by performing a hash function on the random salt to generate a hash result and determining whether the hash result matches the data.
5. The method of claim 1, wherein the first OS and the second OS run on the same device, and the first OS and the second OS perform a multi-transport layer security (mTLS) procedure.
6. The method of claim 1, wherein the supply certificate includes at least one of an entity private key or an entity public key.
7. The method of claim 1, wherein the supply certificate includes at least one of a physical certificate or a key encryption key.
8. A non-transitory computer-readable medium containing instructions that, when executed, cause an electronic device to perform operations, the operations including: The first transmission key is generated by the first operating system (OS); A random salt is sent from the first OS to the second OS using the first transmission key; The first OS generates a second transmission key by using the random salt; The first OS receives a first response from the second OS, wherein the first response includes data, wherein the data includes a bitmask, and each bit of the bitmask indicates whether the corresponding byte includes data or padding. The first OS determines that the data in the first response matches the random salt; as well as The supply certificate is sent from the first OS to the second OS using the second transmission key.
9. The computer-readable medium of claim 8, wherein the supply credential comprises at least one of a private key of a credential issuing authority (CA) or a credential of the CA.
10. The computer-readable medium of claim 8, wherein the data includes an indicator indicating an order of either a sequential order or a reverse sequential order.
11. The computer-readable medium of claim 8, wherein whether the data matches the random salt is determined by performing a hash function on the random salt to generate a hash result and determining whether the hash result matches the data.
12. The computer-readable medium of claim 8, wherein the first OS and the second OS run on the same device, and the first OS and the second OS perform a multi-transport layer security (mTLS) procedure.
13. The computer-readable medium of claim 8, wherein the supply certificate comprises at least one of a physical private key or a physical public key.
14. A computer-implemented system, comprising: One or more computers; as well as One or more computer memory devices, interoperably coupled to the one or more computers and having a tangible, non-transient machine-readable medium storing one or more instructions, which, when executed by the one or more computers, perform one or more operations, the one or more operations including: The first transmission key is generated by the first operating system (OS); A random salt is sent from the first OS to the second OS using the first transmission key; The first OS generates a second transmission key by using the random salt; The first OS receives a first response from the second OS, wherein the first response includes data, wherein the data includes an indicator indicating an order of either a sequential order or a reverse sequential order; The first OS determines that the data in the first response matches the random salt; and The supply certificate is sent from the first OS to the second OS using the second transmission key.
15. The computer-implemented system of claim 14, wherein the supply credential includes at least one of a private key of a credential issuing authority (CA) or a credential of the CA.
16. The computer-implemented system of claim 14, wherein the data includes a bitmask, each bit of the bitmask indicating whether the corresponding byte includes data or padding.
17. The computer-implemented system of claim 15, wherein whether the data matches the random salt is determined by performing a hash function on the random salt to generate a hash result and determining whether the hash result matches the data.
18. The computer-implemented system of claim 14, wherein the first OS and the second OS run on the same device, and the first OS and the second OS perform a multi-transport layer security (mTLS) procedure.
19. The computer-implemented system of claim 14, wherein the supply credential includes at least one of a physical private key or a physical public key.
20. The computer-implemented system of claim 14, wherein the supply certificate includes at least one of a physical certificate or a key encryption key.