Key negotiation method, device and system
By indicating and selecting the commonly supported key negotiation algorithm and parameters between the sending device and the receiving device in the IKEv2 key negotiation protocol, the problem of inefficient key negotiation is solved, and a more efficient key negotiation process is achieved.
Patent Information
- Application Number
- CN202411999568.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-29
- Publication Date
- 2025-05-09
AI Technical Summary
In the existing IKEv2 key negotiation protocol, the number of packet interactions increases when the sender device and the receiver device negotiate the key, resulting in inefficient key negotiation.
By sending the first information, the N kinds of key negotiation algorithms supported by the sending device are instructed, and the receiving device selects and sends the second information from it, instructs the target key negotiation algorithm and its parameters, and generates the target key.
Reduces the number of packet interactions during key negotiation and improves the efficiency of key negotiation.
Smart Images

Figure CN119966630A_ABST
Abstract
Description
[0001] This application is a divisional application. The application number of the original application is 202080101497.X, and the original application date is May 29, 2020. The entire contents of the original application are incorporated into this application by reference. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a key negotiation method, device and system, which can be applied to short-distance communication, such as cockpit communication. Background Art
[0003] IKEv2 (Internet Key Exchange Version 2) is a protocol for negotiating keys and can negotiate security protocols, algorithms, keys and other parameters for IPsec (Internet Protocol Security) tunnels.
[0004] An IKEv2 negotiation process may be: the negotiation message sent by the sending device to the receiving device includes at least one key negotiation algorithm supported by the sending device and the key negotiation parameters of one of the key negotiation algorithms corresponding to the sending device. After receiving the negotiation message, the receiving device selects a key negotiation algorithm supported by the receiving device from the key negotiation algorithms included in the negotiation message. If the key negotiation parameters of the sending device included in the negotiation message do not correspond to the key negotiation algorithm selected by the receiving device, the receiving device sends a message including the key negotiation algorithm supported by the receiving device to the sending device, and then the sending device resends the negotiation message according to the key negotiation algorithm supported by the receiving device, which increases the number of message interactions between the sending device and the receiving device, resulting in low efficiency of key negotiation. Summary of the invention
[0005] Embodiments of the present application provide a key negotiation method, device, and system to improve the efficiency of key negotiation.
[0006] In a first aspect, an embodiment of the present application provides a key negotiation method, including:
[0007] Sending first information, where the first information is used to indicate N key agreement algorithms, where N is an integer greater than or equal to 1, and the N key agreement algorithms are algorithms supported by the sending device;
[0008] receiving second information from the receiving device, the second information being used to indicate a target key agreement algorithm and including a first key agreement parameter, the target key agreement algorithm being a key agreement algorithm among the N key agreement algorithms and supported by the receiving device. Specifically, the first key agreement parameter is a key agreement parameter corresponding to the receiving device and obtained based on the target key agreement algorithm, or in other words, the first key agreement parameter is a key agreement parameter generated by the receiving device based on the target key agreement algorithm;
[0009] A target key is generated according to the target key negotiation algorithm and the first key negotiation parameter.
[0010] In one possible design, the method further includes:
[0011] Sending third information to the receiving device, the third information including a second key negotiation parameter, where the second key negotiation parameter is a key negotiation parameter corresponding to the sending device and obtained based on the target key negotiation algorithm.
[0012] In one possible design, sending the third information to the receiving device includes:
[0013] The third information processed by the integrity protection algorithm is sent to the receiving device.
[0014] In one possible design, the first information is also used to indicate priority information of the N key negotiation algorithms; wherein the first information includes identification information of the N key negotiation algorithms, and the identification information is arranged or encapsulated according to the priority information of the N key negotiation algorithms.
[0015] In one possible design, the second information is also used to indicate M key agreement algorithms supported by the receiving device, where M is an integer greater than or equal to 1.
[0016] In one possible design, generating a target key according to the target key agreement algorithm and the first key agreement parameter includes:
[0017] Determining that the target key agreement algorithm is a key agreement algorithm with the highest priority that is supported by the receiving device among the N key agreement algorithms;
[0018] A target key is generated according to the target key negotiation algorithm and the first key negotiation parameter.
[0019] In other words, in this possible design, the target key agreement algorithm is the key agreement algorithm with the highest priority that is supported by the receiving device among the N key agreement algorithms.
[0020] In one possible design, the method further includes:
[0021] Receive priority information of the M key agreement algorithms from the receiving device.
[0022] In a possible design, the second information is further used to indicate priority information of M key agreement algorithms supported by the receiving device;
[0023] The second information includes identification information of the M key agreement algorithms, and the identification information is arranged or encapsulated according to the priority of the M key agreement algorithms.
[0024] In one possible design, the third information also includes first authentication data, and the first authentication data is authentication data obtained by the sending device through authentication processing on the second information. Or in this possible design, the method also includes: sending the first authentication data to the receiving device, and the first authentication data is authentication data obtained by the sending device through authentication processing on the second information. The first authentication data can be indicated by the third information, or can be indicated or carried by other information.
[0025] In one possible design, the method further includes:
[0026] receiving and verifying fourth information sent by the receiving device;
[0027] The fourth information includes second authentication data, which is data from the receiving device obtained by authenticating the third information.
[0028] In one possible design, the method includes:
[0029] receiving and verifying fourth information sent by the receiving device;
[0030] The fourth information includes third authentication data, and the third authentication data is data from the receiving device obtained by authenticating the N key agreement algorithms indicated in the first information and the third information.
[0031] In one possible design, the fourth information is fourth information processed by an integrity protection algorithm.
[0032] In one possible design, the authentication process also includes performing authentication processing according to a preset shared key.
[0033] In one possible design, the third information also indicates N key agreement algorithms supported by the sending device.
[0034] In one possible design, sending the first information to the receiving device includes:
[0035] The first information is broadcasted to the receiving device.
[0036] In a possible design, before sending the first information to the receiving device, the method further includes:
[0037] receiving fifth information from the receiving device, where the fifth information is used to instruct the sending device to send the first information to the receiving device;
[0038] The sending the first information to the receiving device includes:
[0039] The first information is unicast-sent to the receiving device.
[0040] In a second aspect, an embodiment of the present application provides a key negotiation method, the method comprising:
[0041] Receiving first information from a sending device, where the first information indicates N key agreement algorithms supported by the sending device, where N is an integer greater than or equal to 1;
[0042] Determine a target key agreement algorithm, where the target key agreement algorithm is a key agreement algorithm among the N key agreement algorithms and supported by the receiving device;
[0043] Generate a first key negotiation parameter according to the target key negotiation algorithm, wherein the first key negotiation parameter is a key negotiation parameter corresponding to the receiving device and obtained based on the target key negotiation algorithm, or the first key negotiation parameter is a key negotiation parameter generated by the receiving device based on the target key negotiation algorithm;
[0044] Second information is sent to the sending device, where the second information indicates the target key negotiation algorithm and includes the first key negotiation parameter.
[0045] In one possible design, the method further includes: receiving third information from the sender device, the third information indicating a second key negotiation parameter, the second key negotiation parameter corresponding to a key negotiation parameter of the sender device obtained based on the target key negotiation algorithm;
[0046] A target key is generated according to the second key negotiation parameter and the target key negotiation algorithm.
[0047] In one possible design, the third information is third information processed by an integrity protection algorithm.
[0048] In one possible design, the second information further indicates priority information of M key agreement algorithms supported by the receiving device;
[0049] The second information includes identification information of the M key negotiation algorithms, and the identification information is arranged or encapsulated according to priority information of the M key negotiation algorithms.
[0050] In one possible design, the first information is also used to indicate priority information of the N key negotiation algorithms; wherein the first information includes identification information of the N key negotiation algorithms, and the identification information is arranged or encapsulated according to the priority information of the N key negotiation algorithms.
[0051] In one possible design, determining a target key agreement algorithm includes:
[0052] A key agreement algorithm with the highest priority is determined from the N key agreement algorithms as a target key agreement algorithm.
[0053] In other words, in this possible design, the target key agreement algorithm is the key agreement algorithm with the highest priority that is supported by the receiving device among the N key agreement algorithms.
[0054] In one possible design, the method further includes:
[0055] Receive first authentication data from the sender device; the first authentication data is authentication data obtained by the sender device through authentication processing on the second information. Or the third information also includes the first authentication data, and the first authentication data is authentication data obtained by the sender device through authentication processing on the second information. The first authentication data can be indicated by the third information, or can be indicated or carried by other information.
[0056] In one possible design, it also includes:
[0057] Send fourth information to the sending device, the fourth information including second authentication data, where the second authentication data is authentication data obtained by the receiving device through authentication processing on the third information.
[0058] In one possible design, it also includes:
[0059] Sending fourth information to the sending device, the fourth information including third authentication data, the third authentication data being authentication data obtained by the receiving device by performing authentication processing on the N key agreement algorithms indicated in the first information and the third information.
[0060] In one possible design, sending fourth information to the sending device includes:
[0061] The fourth information processed by the integrity protection algorithm is sent to the sending device.
[0062] In one possible design, the authentication process also includes performing authentication processing according to a preset key.
[0063] In one possible design, the third information also indicates N key agreement algorithms supported by the sending device.
[0064] In a possible design, before receiving the first information from the sending device, the method further includes:
[0065] Send fifth information to the sending device, where the fifth information is used to instruct the sending device to send the first information to the receiving device.
[0066] In a third aspect, an embodiment of the present application provides a key negotiation device, including:
[0067] At least one module, component or circuit for implementing the key agreement method of the first aspect; or,
[0068] At least one module, component or circuit used to implement the key negotiation method of the second aspect.
[0069] In a fourth aspect, an embodiment of the present application provides a key negotiation device, comprising: at least one processor and a memory; the at least one processor is used to run a computer program in the memory, so that the key negotiation device executes the key negotiation method described in the first aspect or the second aspect of the embodiment of the present application.
[0070] In a fifth aspect, an embodiment of the present application provides a key negotiation device, the key negotiation device comprising one or more processors and a communication unit. The one or more processors are configured to support the communication device to perform the key negotiation method described in the first aspect or the second aspect of the present application. The communication unit is used to support the key negotiation device to communicate with other devices to implement receiving and / or sending functions.
[0071] Optionally, the device may further include one or more memories, which are coupled to the processor and store program instructions and / or data necessary for the device. The one or more memories may be integrated with the processor or may be separated from the processor. This application is not limited.
[0072] The key negotiation device may also be a chip. The communication unit may be an input / output circuit or an interface of a communication chip.
[0073] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium for storing a computer program, wherein the computer program includes instructions for executing the key negotiation method described in the embodiment of the present application in the first or second aspect above.
[0074] In the seventh aspect, an embodiment of the present application provides a computer program product, which includes: a computer program code, when the computer program code is run on a computer, enables the computer to execute the key negotiation method described in any one of the first or second aspects of the embodiments of the present application.
[0075] In an eighth aspect, an embodiment of the present application provides a key negotiation system, including: a key negotiation device for executing the first aspect of the embodiment of the present application and a key negotiation device for executing the second aspect of the embodiment of the present application.
[0076] In the ninth aspect, an embodiment of the present application provides a terminal, which can be a means of transportation or an intelligent device, including a drone, an unmanned transport vehicle, a car or a robot, etc. The means of transportation or the intelligent device includes the key negotiation device described in the third aspect and / or the fourth aspect and / or the fifth aspect above.
[0077] The embodiments of the present application provide a key negotiation method, apparatus and system, wherein when a sending device and a receiving device conduct a key negotiation, the sending device notifies the receiving device of all key negotiation algorithms it supports through the first information, and the receiving device selects a key negotiation algorithm supported by itself from the key negotiation algorithms supported by the receiving device. In this way, the key negotiation algorithm selected by the receiving device is a key negotiation algorithm supported by both the sending device and the receiving device, thereby avoiding the failure of the key negotiation algorithm negotiation caused by the key negotiation algorithm selected by the receiving device not supported by the sending device, thereby improving the efficiency of the key negotiation. In addition, the key negotiation method provided by the embodiments of the present application supports the national secret algorithm. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application;
[0079] Figure 2 is a schematic diagram of the hardware structure of a communication device applicable to an embodiment of the present application;
[0080] Figure 3 is a flow chart of a key negotiation method;
[0081] Figure 4 A flowchart of a key negotiation method provided in an embodiment of the present application;
[0082] Figure 5 A flowchart of a key negotiation method provided in another embodiment of the present application;
[0083] Figure 6 A flowchart of a key negotiation method provided in another embodiment of the present application;
[0084] Figure 7 A flowchart of a key negotiation method provided in another embodiment of the present application;
[0085] Figure 8 A schematic diagram of the structure of a key agreement device provided in one embodiment of the present application;
[0086] Fig. 9 A schematic diagram of the structure of a key agreement device provided in another embodiment of the present application;
[0087] Fig.10 A schematic diagram of the structure of a key agreement device provided in another embodiment of the present application;
[0088] Fig.11 A schematic diagram of the structure of a key agreement system provided in one embodiment of the present application. DETAILED DESCRIPTION
[0089] The terms used in the implementation section of this application are only used to explain the specific embodiments of this application and are not intended to limit this application.
[0090] The embodiments of the present application can be applied to various types of communication systems. Figure 1 A schematic diagram of an application scenario provided by an embodiment of the present application. Figure 1 The communication system shown mainly includes a sending device 11 and a receiving device 12. The sending device 11 is the initiator of the communication, and the receiving device 12 is the receiver of the communication.
[0091] Figure 1The sending device 11 or the receiving device 12 included in the communication system shown can be any device with a sending and receiving function. Including but not limited to: an evolved base station (NodeB or eNB or e-NodeB, evolutionary Node B) in the long term evolution (LTE) system of general mobile communication technology, a base station (gNodeB or gNB) or a transmission receiving point / transmission reception point (TRP) in the new radio (NR) system, a base station subsequently evolved by the third generation partnership project (3GPP), an access node in a wireless communication system (such as WiFi, Bluetooth, etc.), a wireless relay node, a wireless backhaul node, a data transfer device (such as a router, a repeater, a bridge or a switch), etc. The base station can be: a macro base station, a micro base station, a pico base station, a small station, a relay station, or a balloon station, etc.
[0092] The sending device 11 or the receiving device 12 may also be a wireless controller, a centralized unit (CU), and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario.
[0093] The sender device 11 or the receiver device 12 may also be a server, a wearable device (such as a smart watch, a smart bracelet, a pedometer, etc.), a machine communication device, or a vehicle-mounted device, etc.
[0094] The sending device 11 or the receiving device 12 may also be a mobile phone, a tablet computer, a computer with wireless transceiver function, headphones, speakers, virtual reality (VR) terminal equipment, augmented reality (AR) terminal equipment, terminals in machine type communication (MTC), terminals in industrial control, vehicle-mounted terminal equipment, terminals in self-driving, terminal equipment in assisted driving, terminals in remote medical, terminals in smart grid, terminals in transportation safety, terminals in smart city, terminals in smart home, etc.
[0095] The sender device 11 or the receiver device 12 can also be a car cockpit domain device, or a module in the car cockpit device (cockpit domain controller (CDC), camera, screen, microphone, audio, electronic key, keyless entry and start system controller and other modules).
[0096] The embodiments of the present application do not limit the application scenarios. The terminal may also be sometimes referred to as terminal equipment, user equipment (UE), access terminal equipment, vehicle-mounted terminal, industrial control terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal equipment, mobile equipment, UE terminal equipment, wireless communication equipment, machine terminal, UE agent or UE device, etc. The terminal may be fixed or mobile.
[0097] Figure 1 The communication system 10 shown is only used as an example and is not used to limit the technical solution of the present application. Those skilled in the art should understand that in the specific implementation process, the communication system 10 may also include other devices, and the number of sender devices and receiver devices may also be determined according to specific needs without limitation.
[0098] Optionally, the present application embodiment Figure 1Each device in the example, such as the sender device 11 and the receiver device 12, may be a functional module in a device. It is understood that the functional module may be a component in a hardware device, such as a chip or a communication component in a terminal device or a network device, or a software functional module running on hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform).
[0099] For example, Figure 1 Each device in the Figure 2 The communication device 200 is implemented in the embodiment, wherein the communication device 200 may be the device itself or a chip or integrated circuit inside the device. Figure 2 FIG. 2 is a schematic diagram of the hardware structure of a communication device applicable to an embodiment of the present application. The communication device 200 may include at least one processor 201 and at least one communication interface 204. Optionally, the communication device 200 may also include at least one of a communication line 202 and a memory 203.
[0100] The processor 201 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0101] The communication link 202 may include a path to transmit information between the above-mentioned components, such as a bus.
[0102] The communication interface 204 uses any transceiver-like device for communicating with other devices or communication networks, such as an Ethernet interface, a radio access network interface (RAN), a wireless local area network interface (WLAN), etc.
[0103] The memory 203 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited to this. The memory can be independent and connected to the processor through a communication line 202. The memory can also be integrated with the processor. The memory provided in the embodiment of the present application can generally have non-volatility. Among them, the memory 203 is used to store the computer execution instructions involved in the execution of the present application scheme, and the execution is controlled by the processor 201. The processor 201 is used to execute the computer-executable instructions stored in the memory 203, so as to implement the method provided in the embodiment of the present application.
[0104] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.
[0105] In a specific implementation, as an embodiment, the processor 201 may include one or more CPUs, such as Figure 2 CPU0 and CPU1 in.
[0106] In a specific implementation, as an embodiment, the communication device 200 may include multiple processors, such as Figure 2 201 and processor 207 in the embodiment of the present invention. Each of these processors may be a single-CPU processor or a multi-CPU processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0107] In a specific implementation, as an embodiment, the communication device 200 may further include an output device 205 and an input device 206. The output device 205 communicates with the processor 201 and may display information in a variety of ways. For example, the output device 205 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 206 communicates with the processor 201 and may receive user input in a variety of ways. For example, the input device 206 may be a mouse, a keyboard, a touch screen device, or a sensor device.
[0108] In a specific implementation, the communication device 200 may be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, an embedded device, or a Figure 2 The embodiment of the present application does not limit the type of the communication device 200.
[0109] Combine the following Figure 1 and Figure 2 A possible key negotiation method is described in detail. The sending device and the receiving device in the following embodiments may have Figure 2 Parts shown.
[0110] For key negotiation between the sending device and the receiving device, the key negotiation method is as follows: Figure 3 As shown, the key negotiation method includes:
[0111] S301: A sending device sends a negotiation message to a receiving device. Correspondingly, the receiving device receives the negotiation message.
[0112] The negotiation message is used to indicate N key negotiation algorithms and includes a key negotiation parameter of a sending device, where the key negotiation parameter is a key negotiation parameter obtained based on one of the key negotiation algorithms supported by the sending device.
[0113] In this embodiment, the sending device uses any key negotiation algorithm supported by the sending device as the algorithm for generating the target key, obtains the key negotiation parameters based on the selected key negotiation algorithm, and includes the key negotiation parameters in the negotiation message when the sending device sends the negotiation message to the receiving device. Therefore, the receiving device can not only determine all the key negotiation algorithms supported by the sending device through the negotiation message, but also directly obtain the key negotiation parameters of the sending device used by the receiving device to generate the target key.
[0114] S302: The receiving device determines a target key negotiation algorithm, and generates a key negotiation parameter of the receiving device according to the target negotiation algorithm.
[0115] The key negotiation parameters of the receiving device are key negotiation parameters obtained based on the target key negotiation algorithm.
[0116] In this embodiment, the receiving device also selects any key negotiation algorithm from all key negotiation algorithms supported by the sending device obtained according to the negotiation message as the algorithm for generating the target key, and obtains the key negotiation parameters based on the selected key negotiation algorithm. Among them, when the receiving device selects the target key negotiation algorithm, it does not consider the key negotiation algorithm selected by the sending device, that is, the sending device and the receiving device are independent of each other when selecting their respective key negotiation algorithms for generating the target key. Therefore, it is easy to cause the key negotiation algorithm selected by the receiving device to be inconsistent with the key negotiation algorithm selected by the sending device, and therefore, the key negotiation algorithm selected by the receiving device is inconsistent with the key negotiation parameters of the sending device.
[0117] S303: If the key negotiation parameters of the sending device match the target key negotiation algorithm, the receiving device negotiates a response message to the sending device.
[0118] The negotiation response message is used to indicate the target key negotiation algorithm and includes the key negotiation parameters of the receiving device.
[0119] S304: The receiving device generates a target key according to the key negotiation parameters of the sending device and the target key negotiation algorithm.
[0120] S305: The sending device generates a target key according to the key negotiation parameters of the receiving device and a target key negotiation algorithm.
[0121] In this embodiment, the process of generating the target key by the receiving device and the sending device is as follows:
[0122] Taking the Diffie-Hellman DH algorithm as an example, two nodes use the same relatively large prime number p and the same random number g (that is, the prime number p and the random number g are the public key between the sender and the receiver), and each generates random numbers a and b (that is, the random number a is the private key of the receiver, and the random number b is the private key of the sender). The above prime number p, random number g, random number a and b can all be regarded as parameters of the key agreement algorithm. The receiver generates the value A (that is, A = g) by taking g a modulo P. amod p, A is the first key agreement algorithm parameter) is sent to the sending device, and the sending device then performs a b-th power operation on the received value A to generate a secret value KE; the sending device generates a value B (i.e., B = g mod p, where A is the first key agreement algorithm parameter) by performing ... b mod p, B is the second key agreement algorithm parameter) is sent to the receiving device, and the receiving device performs a power operation on the received value B to generate a secret value KE. Since KE = A b mod p=(g a mod p) b mod p = g ab mod p=(g b mod p) a mod p=B a mod p, so the secret value KE generated by the sending device and the receiving device is the same, that is, the target key is the same.
[0123] It can be seen that in the prior art, since the receiving device and the sending device each select the key negotiation algorithm they support, it is easy to cause the key negotiation algorithm selected by the receiving device to not match the key negotiation parameters of the initiating device, thereby causing the negotiation to fail. When the key negotiation algorithm selected by the receiving device does not match the key negotiation parameters of the initiating device, the receiving device needs to send a message to the initiating device so that the initiating device resends the negotiation message, and repeats the above actions again until the key negotiation algorithm selected by the receiving device matches the key negotiation parameters of the initiating device. In this way, the number of message interactions between the sending device and the receiving device increases, resulting in low efficiency of key negotiation.
[0124] To solve the above problems, an embodiment of the present application proposes: the sending device notifies the receiving device of the key negotiation algorithms it supports, and the receiving device selects a key negotiation algorithm supported by both the receiving device and the sending device, and sends the selected key negotiation algorithm and the key negotiation parameters corresponding to the receiving device generated according to the key negotiation algorithm to the sending device, instead of the sending device and the receiving device each selecting a key negotiation algorithm supported by them. This solves the problem that the key negotiation algorithms selected by the sending device and the receiving device each select a key negotiation algorithm supported by them, thereby improving the efficiency of key negotiation.
[0125] The key negotiation method proposed in this application is described in detail below in conjunction with specific embodiments.
[0126] Figure 4 This is a flow chart of a key negotiation method provided in one embodiment of the present application. Figure 4 As shown, the key negotiation method in the embodiment of the present application includes:
[0127] S401: A sending device sends first information to a receiving device. Correspondingly, the receiving device receives the first information.
[0128] The first information is used to indicate N key negotiation algorithms, where N is an integer greater than or equal to 1, and the N key negotiation algorithms are algorithms supported by the sending device.
[0129] Exemplarily, the first information is carried in a negotiation message. Specifically, before two devices in a communication system transmit data, they need to perform key negotiation to obtain a target key, so as to encrypt and decrypt the transmitted data according to the target key. When a sending device and a receiving device perform key negotiation, the initiator device sends a negotiation message to the receiving device.
[0130] The first information may indicate the N key agreement algorithms in any of the following ways:
[0131] Method 1: The first information includes identifiers of N key agreement algorithms supported by the initiator device, so that the recipient device obtains the N key agreement algorithms supported by the initiator device.
[0132] Exemplarily, taking the algorithm identification shown in Table 1 as an example, when the first information includes ID1, ID3 and ID5, the first information is used to indicate algorithm 1, algorithm 3 and algorithm 5; when the first information includes ID2 and ID4, the first information is used to indicate algorithm 2 and algorithm 4.
[0133] Table 1
[0134] algorithm Algorithm Identification Algorithm 1 ID1 Algorithm 2 ID2 Algorithm 3 ID3 Algorithm 4 ID4 Algorithm 5 ID5
[0135] It can be understood that Table 1 is only an example of the key agreement algorithm identifier indicated by the first information. In a specific application, the key agreement algorithm indicated by the first information may also be in other forms without limitation.
[0136] Mode 2: The first information includes a bit sequence, one bit in the bit sequence corresponds to an algorithm, and each bit in the bit sequence can indicate whether the first information indicates the algorithm corresponding to the bit by 0 or 1. For example, if the bit is 1, it can indicate that the first information indicates the algorithm corresponding to the bit, and if the bit is 0, it can indicate that the first information does not indicate the algorithm corresponding to the bit, and vice versa.
[0137] For example, taking the first information including 5 bits, the first bit of the 5 bits corresponds to algorithm 1, the second bit corresponds to algorithm 2, the third bit corresponds to algorithm 3, the fourth bit corresponds to algorithm 4, and the fifth bit corresponds to algorithm 5, if the 5 bits are 01010, it can indicate that the first information is used to indicate algorithm 2 and algorithm 4; if the 5 bits are 11001, it can indicate that the first information is used to indicate algorithm 1, algorithm 2 and algorithm 5.
[0138] Optionally, the first information is also used to indicate priority information of N key negotiation algorithms; wherein the identification information of the N key negotiation algorithms contained in the first information is arranged or encapsulated according to the priority information of the N key negotiation algorithms.
[0139] Exemplarily, the priorities of the N key agreement algorithms indicated by the first information are arranged from high to low, or the priorities of the N key agreement algorithms indicated by the first information are arranged from low to high. For example, as shown in Table 2, the first information is used to indicate algorithm 1, algorithm 2, algorithm 3, algorithm 4, and algorithm 5, wherein the priority of algorithm 4 is higher than that of algorithm 2, the priority of algorithm 2 is higher than that of algorithm 5, the priority of algorithm 5 is higher than that of algorithm 1, and the priority of algorithm 1 is higher than that of algorithm 3.
[0140] Table 2
[0141] Algorithm Priority algorithm Algorithm Identification Priority 1 Algorithm 4 ID4 Priority 2 Algorithm 2 ID2 Priority 3 Algorithm 5 ID5 Priority 4 Algorithm 1 ID1 Priority 5 Algorithm 3 ID3
[0142] Optionally, the sending device sends the negotiation message to the receiving device by broadcasting, so that no additional message interaction is required, thereby improving the efficiency of key negotiation. In addition, sending the negotiation message to the receiving device by broadcasting can enable multiple receiving devices to receive the negotiation message, further reducing the interaction of messages.
[0143] It should be noted that, since the first information may be intercepted by a third-party device during the sending process, the third-party device tampers with the first information and sends the tampered first information to the receiving device. Therefore, there may be a difference between the key agreement algorithm supported by the sending device indicated by the first information received by the receiving device and the key agreement algorithm supported by the sending device indicated in the first information sent by the sending device. Therefore, the key agreement algorithms supported by the sending device indicated by the first information received by the receiving device are K key agreement algorithms, where K is an integer greater than or equal to 0.
[0144] It can be understood that the relationship between the K key agreement algorithms supported by the sending device indicated by the first information received by the receiving device and the N key agreement algorithms supported by the sending device indicated in the first information sent by the sending device includes at least:
[0145] The first relationship: K is equal to N, and the K key agreement algorithms supported by the sending device indicated by the first information received by the receiving device correspond one-to-one to the N key agreement algorithms supported by the sending device indicated in the first information sent by the sending device;
[0146] The second relationship: K is equal to N, but the K key agreement algorithms supported by the sending device indicated by the first information received by the receiving device are not in one-to-one correspondence with the N key agreement algorithms supported by the sending device indicated in the first information sent by the sending device;
[0147] The third relationship: K is not equal to N.
[0148] Among them, if the relationship between the K key negotiation algorithms and the N key negotiation algorithms is the first relationship, it means that the N key negotiation algorithms indicated in the first information sent by the sending device have not been tampered with; if the relationship between the K key negotiation algorithms and the N key negotiation algorithms is the second relationship or the third relationship, it means that the first information sent by the sending device has been tampered with.
[0149] Optionally, before S401, the key agreement algorithm shown in the present application also includes: receiving fifth information from the receiving device, the fifth information is used to instruct the sending device to send the first information; accordingly, a possible implementation of S401 is: unicasting the first information to the receiving device. Specifically, when the receiving device needs to communicate with the sending device, it can first send information to the sending device, that is, the fifth information, the fifth information is used to instruct the sending device to send the first information to the receiving device, so that after the sending device receives the fifth information, it sends the first information to the receiving device. Among them, the sending device sends the first information by unicast.
[0150] Optionally, the fifth information carries an indication identifier, which may be pre-negotiated by the sending device and the receiving device, for example. When the receiving device needs to instruct the sending device to send the first information to the receiving device, the fifth information includes the pre-negotiated indication identifier. After the sending device receives the fifth information including the indication identifier, it sends the first information to the receiving device.
[0151] Optionally, the fifth information includes an empty target key negotiation algorithm. For example, the bit used to indicate the key negotiation algorithm is identified as "null". When the receiving device needs to instruct the sending device to send the first information to the receiving device, the fifth information includes the empty target key negotiation algorithm. After the sending device receives the fifth information including the empty target key negotiation algorithm, it sends the first information to the receiving device.
[0152] S402: The receiving device determines a target key negotiation algorithm.
[0153] The target key agreement algorithm is a key agreement algorithm among the N key agreement algorithms and supported by the receiving device.
[0154] In this embodiment, the receiving device determines a key negotiation algorithm supported by itself from the N key negotiation algorithms in the first information as the target negotiation algorithm.
[0155] Optionally, the receiving device determines the key agreement algorithm with the highest priority supported by the receiving device from the N key agreement algorithms according to the priority information of the N key agreement algorithms indicated in the received first information, and uses it as the target agreement algorithm. It should be noted that the highest priority here is determined according to the priority order of the key agreement algorithm of the sending device.
[0156] Exemplarily, Table 3 shows all key negotiation algorithms supported by the receiving device. The first information received by the receiving device indicates the five key negotiation algorithms shown in Table 1. In the first information, the identifiers of the five algorithms are arranged in descending order of priority. Among the five key negotiation algorithms, according to Tables 1 to 3, the receiving device supports Algorithm 2, Algorithm 3, and Algorithm 5, and Algorithm 2 has a higher priority than Algorithm 3 and Algorithm 5. Therefore, the receiving device selects Algorithm 2 as the target negotiation algorithm.
[0157] Table 3
[0158] algorithm Algorithm Identification Algorithm 2 ID2 Algorithm 3 ID3 Algorithm 5 ID5 Algorithm 6 ID6
[0159] Optionally, the receiving device determines, according to the N key agreement algorithms indicated in the received first information, a key agreement algorithm that it supports and has a relatively highest priority for itself from the N key agreement algorithms, and uses it as the target agreement algorithm. That is, among the N key agreement algorithms, for the key agreement algorithms supported by both the receiving device and the sending device, the target key agreement algorithm is determined according to the priority order of the key agreement algorithms of the receiving device.
[0160] Exemplarily, Table 4 shows the priority information of the key negotiation algorithms supported by the receiving device. As shown in Table 3, the first information received by the receiving device indicates the five key negotiation algorithms shown in Table 1. Among the five key negotiation algorithms, the receiving device supports Algorithm 2, Algorithm 3 and Algorithm 5. According to Table 4, in the receiving device, Algorithm 3 has a higher priority than Algorithm 2, and Algorithm 2 has a higher priority than Algorithm 5, so the receiving device selects Algorithm 3 as the target negotiation algorithm. It should be noted that, in this embodiment, the N key negotiation algorithms supported by the sending device indicated in the first information may not be arranged in order of priority, that is, the first information does not indicate the priority information of the N key negotiation algorithms supported by the sending device.
[0161] Table 4
[0162] Algorithm Priority algorithm Algorithm Identification Priority 1 Algorithm 3 ID3 Priority 2 Algorithm 6 ID6 Priority 3 Algorithm 2 ID2 Priority 4 Algorithm 5 ID5
[0163] S403: The receiving device generates a first key negotiation parameter according to the target key negotiation algorithm.
[0164] The first key negotiation parameter is a key negotiation parameter corresponding to the receiving device and obtained based on the target key negotiation algorithm.
[0165] Exemplarily, the receiving device uses S304 to generate a private key that is only known to the receiving device, and then generates a public key of the corresponding receiving device through the selected key negotiation algorithm, and uses the public key as the first key negotiation parameter, namely, the key negotiation parameter KE1.
[0166] The present application does not limit the method for obtaining the first key negotiation parameter.
[0167] S404: The receiving device sends the second information to the sending device. Correspondingly, the sending device receives the second information from the receiving device.
[0168] The second information indicates a target key negotiation algorithm and includes a first key negotiation parameter.
[0169] Optionally, the second information also carries a first random number, wherein the first random number NONCE1 is a random number generated by the receiving device.
[0170] S405: The sending device generates a target key according to the target key negotiation algorithm and the first key negotiation parameter.
[0171] In this embodiment, since the identifier of the target key agreement algorithm is carried in the second information, the sending device determines the key agreement algorithm selected by the receiving device through the identifier of the target key agreement algorithm. The sending device, for example, uses the method of S305 to generate a private key, which is known only to the sending device, and then calculates the public key of the corresponding sending device according to the first target key agreement algorithm, and uses the public key as the second key agreement parameter, which is recorded as KE2. Then, according to the target key agreement algorithm and the key agreement parameter KE1, the target key KE is generated.
[0172] Optionally, after the sending device determines the target key agreement algorithm through the second information, it determines whether the target key agreement algorithm is one of the N key agreement algorithms indicated by the first information. If so, it obtains the target key and / or key agreement parameter KE2 according to the target key agreement algorithm; if not, the sending device discards the second information.
[0173] Optionally, the sending device obtains an encryption key and an integrity protection key according to the target key KE. The encryption key is used to encrypt information transmitted between the sending device and the receiving device. The integrity protection key is used to perform integrity protection on information transmitted between the sending device and the receiving device.
[0174] Among them, one way of sending device encryption key and integrity protection key is:
[0175] The sending device randomly generates a second random number NONCE2, and the sending device uses the target key KE, the random number NONCE1 and the random number NONCE2 as inputs of a key derivation function (KDF) KDF1 to obtain a shared key Kgt, ie, Kgt=KDF1(KE, NONCE1, NONCE2).
[0176] The sending device uses the shared key Kgt as the input of KDF2 to obtain the encryption key and the integrity protection key, that is, Kenc=KDF2(Kgt); similarly, Kint=KDF3(Kgt), where Kenc is the encryption key and Kint is the integrity protection key.
[0177] Another way is: after obtaining the target key KE, the sending device uses the target key KE as the input of KDF2 to obtain the encryption key and the integrity protection key, that is, Kenc=KDF2(KE); similarly, Kint=KDF3(KE), where Kenc is the encryption key and Kint is the integrity protection key.
[0178] It should be noted that KDF1, KDF2 and KDF3 may be the same or different. Furthermore, the present application does not restrict the KDF used to obtain the shared key Kgt, the KDF used to obtain the encryption key Kenc and the KDF used to obtain the integrity protection key Kint.
[0179] It can be understood that the method of obtaining the shared key Kgt, the encryption key Kenc, and the integrity protection key Kint shown in the embodiment of the present application is not intended to limit the present application, and other methods may be selected to obtain them. For example, Kenc = KDF2 (Kgt, ID1), Kint = KDF3 (Kgt, ID2), where ID1 is the identifier of the encryption algorithm, and ID2 is the identifier of the integrity protection algorithm.
[0180] Optionally, the method further includes S406: the sending device sends third information to the receiving device. Correspondingly, the receiving device receives the third information from the sending device.
[0181] The third information includes a second key negotiation parameter, where the second key negotiation parameter is a key negotiation parameter corresponding to the sender device and based on a target key negotiation algorithm.
[0182] Specifically, the third information carries the second random number NONCE2.
[0183] Since the second information sent by the receiving device to the sending device is not protected, the second information may be tampered with during the sending process. If the second information is tampered with, the key negotiation between the sending device and the receiving device will fail. Therefore, it is necessary to verify whether the second information has been tampered with. The method of verifying whether the second information has been tampered with may be, for example:
[0184] The sending device performs authentication processing on the second information, uses the second information as a parameter, generates first authentication data AUTH1, and sends the first authentication data AUTH1 to the receiving device, so that the receiving device verifies whether the second information has been tampered with. Optionally, the third information includes the first authentication data AUTH1. The method of obtaining AUTH1 includes:
[0185] Method 1: The authentication data AUTH1 is obtained by the sending device according to the second information received by the sending device, the preset shared key PSK and KDF4, that is, AUTH1 = KDF4 (PSK, second information). Among them, the preset shared key PSK is a key shared in advance between the sending device and the receiving device, so as to verify the identities of both parties according to the preset shared key PSK to prevent the information exchanged between the sending device and the receiving device from being tampered with. It should be noted that the embodiment of the present application does not limit the method of pre-setting the preset shared key PSK. For example, it can be obtained by inputting the same number into the sending device and the receiving device respectively in advance, or after obtaining the target key KE, it can be obtained by using the same deduction algorithm.
[0186] Correspondingly, after receiving the third information, the receiving device obtains the authentication data AUTH1 and matches the authentication data AUTH1 with the first reference authentication data. Among them, the first reference authentication data is obtained by the receiving device based on the second information sent, the preset shared key PSK and KDF4, that is, the first reference authentication data = KDF4 (PSK, second information). Therefore, if the second information has not been tampered with during the sending process, that is, the second information received by the sending device is consistent with the second information sent by the receiving device, then the authentication data AUTH1 matches the reference authentication data, otherwise it does not match. Therefore, according to the result of matching the authentication data AUTH1 with the first reference authentication data, the receiving device can determine whether the second information received by the sending device is consistent with the second information sent by the receiving device. If the authentication data AUTH1 matches the reference authentication data, it means that the second information has not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0187] Method 2: The authentication data AUTH1 is obtained by the sending device according to the second information received by the sending device, the random number NONCE2, the preset shared key PSK and KDF5, that is, AUTH1=KDF5(PSK, NONCE2, second information). Correspondingly, the first reference authentication data is obtained by the receiving device according to the second information sent, the random number NONCE2 in the received third information, the preset shared key PSK and KDF5, that is, the first reference authentication data=KDF5(PSK, NONCE2, second information). Therefore, if the second information has not been tampered with during the sending process, that is, the second information received by the sending device is consistent with the second information sent by the receiving device, and the random number NONCE2 in the third information has not been tampered with, then the authentication data AUTH1 matches the reference authentication data, otherwise it does not match. Therefore, according to the result of the matching of the authentication data AUTH1 and the first reference authentication data, the receiving device can determine whether the second information received by the sending device is consistent with the second information sent by the receiving device. If the authentication data AUTH1 matches the reference authentication data, it means that the second information and the random number NONCE2 have not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0188] The embodiment of the present application may also select other methods to obtain AUTH1, which are not listed here one by one.
[0189] It should be noted that the embodiment of the present application does not limit the KDF for obtaining AUTH1 and the first reference authentication data, as long as the KDF for obtaining AUTH1 is the same as the KDF for the first reference authentication data, and the parameters for obtaining AUTH1 correspond to the parameters for the first reference authentication data. For example, AUTH1 is obtained through KDF4, and the second information received by the sending device, and the preset shared key PSK. Correspondingly, the first reference authentication data is obtained through KDF4, and the receiving device obtains the first reference authentication data according to the second information sent and the preset shared key PSK.
[0190] Optionally, the third information is information processed by an integrity protection algorithm.
[0191] Exemplarily, before executing S406, after the sending device obtains the encryption key Kenc and the integrity protection key Kint, a first message authentication code (MAC) is obtained according to the integrity protection algorithm, the integrity protection key Kint and part or all of the third information sent by the sending device, and the third information is integrity protected by the first MAC. Exemplarily, the third information includes the first MAC.
[0192] S407: The receiving device generates a target key according to the second key negotiation parameter and the target key negotiation algorithm.
[0193] In this embodiment, after receiving the key negotiation parameter KE2 from the sending device, the receiving device obtains the target key KE according to the key negotiation algorithm and the received key negotiation parameter KE2.
[0194] Optionally, the receiving device uses the same method as the sending device to obtain the encryption key Kenc and the integrity protection key Kint according to the target key KE. The second MAC is obtained according to the integrity protection algorithm, the integrity protection key Kint and part or all of the third information received by the receiving device. If the first MAC and the second MAC are consistent, it means that the third information has not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0195] Optionally, the method further includes S408: the receiving device sends fourth information to the sending device. Correspondingly, the sending device receives the fourth information.
[0196] The fourth information is used by the sending device to determine whether the key negotiation is successful.
[0197] Optionally, the fourth information is information encrypted by the encryption key Kenc. The receiving device encrypts the fourth information by using the encryption key Kenc. After receiving the fourth information, the sending device decrypts the encrypted fourth information by using the encryption key Kenc to obtain the fourth information.
[0198] Optionally, the fourth information also includes third authentication data. The method of obtaining the third authentication data AUTH3 includes:
[0199] Method 1: The receiving device obtains AUTH3 according to the K key agreement algorithms indicated in the first information received by the receiving device, the received third information, the preset shared key PSK, the random number NONCE1 and KDF6, that is, AUTH3=KDF6(PSK, K key agreement algorithms, third information, NONCE1).
[0200] Method 2: The receiving device obtains AUTH3 according to the K key agreement algorithms indicated in the first information received by the receiving device, the received third information, the preset shared key PSK and KDF7, that is, AUTH3=KDF7(PSK, K key agreement algorithms, third information).
[0201] The embodiment of the present application may also select other methods to obtain AUTH1, which are not listed here one by one.
[0202] Optionally, the fourth information is information processed by an integrity protection algorithm.
[0203] The receiving device obtains a third message authentication code MAC according to the integrity protection algorithm, the integrity protection key Kint and part or all of the fourth information sent by the receiving device, and performs integrity protection on the fourth information through the third MAC. Exemplarily, the fourth information includes the third MAC.
[0204] Optionally, the method further includes S409, the sending device verifies the fourth information.
[0205] Optionally, the sending device obtains a fourth message authentication code MAC according to the integrity protection algorithm, the integrity protection key Kint, and part or all of the fourth information received by the sending device. If the third MAC and the fourth MAC are consistent, it means that the fourth information has not been tampered with, and the subsequent operation is performed; otherwise, the receiving device discards the fourth information. The specific operation content of the subsequent operation is not limited in the embodiment of the present application.
[0206] Optionally, the fourth information includes authentication data AUTH3, and accordingly, the sending device obtains the authentication data AUTH3 and matches the authentication data AUT3 with the third reference authentication data.
[0207] The KDF and parameters for obtaining the third reference authentication data correspond to the method for obtaining AUTH3. For example:
[0208] When AUTH3 is obtained by adopting the first method, the third reference authentication data is obtained by the sending device according to the N key negotiation algorithms indicated in the first information sent by the sending device, the third information sent, the preset shared key PSK, the random number NONCE1 and KDF6, that is, the third reference authentication data = KDF6 (PSK, N key negotiation algorithms indicated in the first information sent, the third information, NONCE1). Therefore, if the first information and the third information are not tampered with during the sending process, that is, the first information and the third information received by the receiving device are respectively consistent with the first information and the third information sent by the sending device, then the authentication data AUTH3 matches the third reference authentication data; if the first information and / or the third information are tampered with during the sending process, then the authentication data AUTH3 does not match the third reference authentication data. Therefore, according to the result of the matching between the authentication data AUTH3 and the third reference authentication data, the sending device can determine whether the first information received by the receiving device is consistent with the first information sent by the sending device, and whether the third information received by the receiving device is consistent with the third information sent by the sending device. If the authentication data AUTH3 matches the reference authentication data, it means that the first information and the third information have not been tampered with, and the key negotiation between the sending device and the receiving device is successful; otherwise, the fourth information is discarded and the connection with the receiving device is disconnected.
[0209] When AUTH3 is obtained by the second method, the third reference authentication data is obtained by the sending device according to the N key negotiation algorithms indicated in the first information sent by the sending device, the third information sent, the preset shared key PSK and KDF6, that is, the third reference authentication data = KDF7 (PSK, N key negotiation algorithms indicated in the first information sent, third information). Therefore, if the first information and the third information are not tampered with during the sending process, that is, the first information and the third information received by the receiving device are respectively consistent with the first information and the third information sent by the sending device, then the authentication data AUTH3 matches the third reference authentication data; if the first information and / or the third information are tampered with during the sending process, then the authentication data AUTH3 does not match the third reference authentication data. Therefore, according to the result of the matching between the authentication data AUTH3 and the third reference authentication data, the sending device can determine whether the first information received by the receiving device is consistent with the first information sent by the sending device, and whether the third information received by the receiving device is consistent with the third information sent by the sending device. If the authentication data AUTH3 matches the reference authentication data, it means that the first information and the third information have not been tampered with, and the key negotiation between the sending device and the receiving device is successful; otherwise, the fourth information is discarded and the connection with the receiving device is disconnected.
[0210] It should be noted that the embodiment of the present application does not limit the KDF for obtaining AUTH3 and the third reference authentication data, as long as the KDF for obtaining AUTH3 is the same as the KDF for the third reference authentication data, the parameters for obtaining AUTH3 and the parameters for obtaining the third reference authentication data correspond one to one. For example, AUTH3 is obtained through KDF6, and the K key negotiation algorithms indicated in the first information received by the receiving device, the received third information, the preset shared key PSK, and the random number NONCE1. Correspondingly, the third reference authentication data is obtained through KDF6, and the sending device obtains the N key negotiation algorithms indicated in the first information sent, the sent third information, the preset shared key PSK, and the random number NONCE1.
[0211] In this embodiment, when the sending device and the receiving device perform key negotiation, the sending device notifies the receiving device of all key negotiation algorithms it supports through the first information, and the receiving device selects a key negotiation algorithm supported by itself from the key negotiation algorithms supported by the receiving device. In this way, the key negotiation algorithm selected by the receiving device is a key negotiation algorithm supported by both the sending device and the receiving device, thereby avoiding the failure of the key negotiation algorithm negotiation caused by the key negotiation algorithm selected by the receiving device not supported by the sending device, thereby improving the efficiency of the key negotiation. In addition, the key negotiation method provided in the embodiment of the present application supports the national secret algorithm.
[0212] Figure 5This is a flowchart of a key negotiation method provided by another embodiment of the present application. Figure 5 As shown, the key negotiation method in the embodiment of the present application includes:
[0213] S501: A sending device sends first information to a receiving device. Correspondingly, the receiving device receives the first information.
[0214] The first information is used to indicate N key negotiation algorithms, where N is an integer greater than or equal to 1, and the N key negotiation algorithms are algorithms supported by the sending device.
[0215] Exemplarily, the first information is carried in a negotiation message. Specifically, before two devices in a communication system transmit data, they need to perform key negotiation to obtain a target key, so as to encrypt and decrypt the transmitted data according to the target key. When a sending device and a receiving device perform key negotiation, the initiator device sends a negotiation message to the receiving device.
[0216] Optionally, the first information is also used to indicate priority information of N key negotiation algorithms; wherein the identification information of the N key negotiation algorithms contained in the first information is arranged or encapsulated according to the priority information of the N key negotiation algorithms.
[0217] Exemplarily, the priorities of the N key agreement algorithms indicated by the first information are arranged from high to low, or the priorities of the N key agreement algorithms indicated by the first information are arranged from low to high. For example, as shown in Table 2, the first information is used to indicate algorithm 1, algorithm 2, algorithm 3, algorithm 4, and algorithm 5, wherein the priority of algorithm 4 is higher than that of algorithm 2, the priority of algorithm 2 is higher than that of algorithm 5, the priority of algorithm 5 is higher than that of algorithm 1, and the priority of algorithm 1 is higher than that of algorithm 3.
[0218] S502: The receiving device determines a target key negotiation algorithm.
[0219] The target key agreement algorithm is a key agreement algorithm among the N key agreement algorithms and supported by the receiving device.
[0220] In this embodiment, the receiving device determines a key negotiation algorithm supported by itself from the N key negotiation algorithms in the first information as the target negotiation algorithm.
[0221] Optionally, the receiving device selects a key negotiation algorithm supported by the receiving device and with the highest priority for the sending device from the N key negotiation algorithms based on the priority information of the N key negotiation algorithms indicated in the received first information, and uses the key negotiation algorithm as the target negotiation algorithm.
[0222] Exemplarily, Table 3 shows all key negotiation algorithms supported by the receiving device. The first information received by the receiving device indicates the five key negotiation algorithms shown in Table 1. In the first information, the identifiers of the five algorithms are arranged in descending order of priority. Among the five key negotiation algorithms, according to Tables 1 to 3, the receiving device supports Algorithm 2, Algorithm 3, and Algorithm 5, and Algorithm 2 has a higher priority than Algorithm 3 and Algorithm 5. Therefore, the receiving device selects Algorithm 2 as the target negotiation algorithm.
[0223] Optionally, the receiving device determines, based on the N key negotiation algorithms indicated in the received first information, a key negotiation algorithm that it supports and has a relatively highest priority for itself from the N key negotiation algorithms, and uses the key negotiation algorithm as the target negotiation algorithm.
[0224] Exemplarily, Table 4 shows the priority information of the key negotiation algorithms supported by the receiving device. As shown in Table 3, the first information received by the receiving device indicates the five key negotiation algorithms shown in Table 1. Among the five key negotiation algorithms, the receiving device supports Algorithm 2, Algorithm 3 and Algorithm 5. According to Table 4, in the receiving device, Algorithm 3 has a higher priority than Algorithm 2, and Algorithm 2 has a higher priority than Algorithm 5, so the receiving device selects Algorithm 3 as the target negotiation algorithm. It should be noted that, in this embodiment, the N key negotiation algorithms supported by the sending device indicated in the first information may not be arranged according to the slice priority information, that is, the first information does not indicate the priority information of the N key negotiation algorithms supported by the sending device.
[0225] S503: The receiving device generates a first key negotiation parameter according to the target key negotiation algorithm.
[0226] The first key negotiation parameter is a key negotiation parameter corresponding to the receiving device and obtained based on the target key negotiation algorithm.
[0227] Exemplarily, the receiving device calculates the key negotiation parameter KE1 through the selected key negotiation algorithm.
[0228] S504: The receiving device sends the second information to the sending device. Correspondingly, the sending device receives the second information from the receiving device.
[0229] The second information indicates the target key negotiation algorithm and includes the first key negotiation parameter. Further optionally, the second information also indicates M key negotiation algorithms supported by the receiving device.
[0230] In this embodiment, the second information also indicates M key agreement algorithms supported by the receiving device, so that the sending device determines whether the key agreement algorithm selected by the receiving device is a key agreement algorithm supported by both the receiving device and the sending device. When it is determined that the key agreement algorithm selected by the receiving device is a key agreement algorithm supported by both the receiving device and the sending device, S505 is executed; otherwise, the second information is discarded and the connection with the receiving device is disconnected.
[0231] The second information may indicate the M key agreement algorithms in any of the following ways:
[0232] Method 1: The second information includes identifiers of M key agreement algorithms supported by the receiving device, so that the sending device obtains the M key agreement algorithms supported by the receiving device.
[0233] Exemplarily, taking the algorithm identifiers shown in Table 1 as an example, when the second information includes ID2, ID3 and ID5, the second information is used to indicate algorithm 2, algorithm 3 and algorithm 5; when the second includes ID1 and ID5, the second information is used to indicate algorithm 1 and algorithm 5.
[0234] It can be understood that Table 1 is only an example of the key agreement algorithm identifier indicated by the second information. In a specific application, the key agreement algorithm indicated by the second information may also be in other forms without limitation.
[0235] Mode 2: The second information includes a bit sequence, one bit in the bit sequence corresponds to an algorithm, and each bit in the bit sequence can indicate whether the second information indicates the algorithm corresponding to the bit by 0 or 1. For example, if the bit is 1, it can indicate that the second information indicates the algorithm corresponding to the bit, and if the bit is 0, it can indicate that the second information does not indicate the algorithm corresponding to the bit, and vice versa.
[0236] For example, taking the first information including 4 bits, the first bit of the 4 bits corresponds to algorithm 1, the second bit corresponds to algorithm 2, the third bit corresponds to algorithm 3, and the fourth bit corresponds to algorithm 4, if the 4 bits are 1001, it can indicate that the second information is used to indicate algorithm 1 and algorithm 4; if the 5 bits are 1100, it can indicate that the first algorithm negotiation request information is used to indicate algorithm 1 and algorithm 2.
[0237] Optionally, the sending device determines the priority of the key agreement algorithm supported by the receiving device according to the M key agreement algorithms supported by the receiving device indicated in the received second information, thereby determining whether the key agreement algorithm selected by the receiving device is the key agreement algorithm with the highest priority of the sending device or the receiving device among the algorithms supported by both the receiving device and the sending device. If so, execute S505; otherwise, discard the second information and disconnect the connection with the receiving device.
[0238] For example, the key agreement algorithms supported by the receiving device include Algorithm 2, Algorithm 3, Algorithm 5, and Algorithm 6. As shown in Table 4 above, for the receiving device, Algorithm 3 has a higher priority than Algorithm 6, Algorithm 6 has a higher priority than Algorithm 2, and Algorithm 2 has a higher priority than Algorithm 5.
[0239] Combining Table 2 and Table 4, it can be seen that if the receiving device selects the key negotiation algorithm with the highest priority of the sending device among the algorithms supported by both the receiving device and the sending device as the target negotiation algorithm, the target negotiation algorithm obtained by the sending device through the second information should be algorithm 2. If the target negotiation algorithm obtained by the sending device through the second information is not algorithm 2, the second information is discarded.
[0240] If the receiving device selects the key negotiation algorithm with the highest priority of the receiving device among the algorithms supported by both the receiving device and the sending device as the target negotiation algorithm, the target negotiation algorithm obtained by the sending device through the second information should be algorithm 3. If the target negotiation algorithm obtained by the sending device through the second information is not algorithm 3, the second information is discarded.
[0241] Exemplarily, the manner in which the sending device determines the priority of the key agreement algorithm supported by the receiving device includes:
[0242] Mode 1: The sending device receives priority information of M key negotiation algorithms from the receiving device. For example, the sending device and the receiving device have performed key negotiation. During the key negotiation, the receiving device indicates the priority of the key negotiation algorithm supported by the receiving device to the sending device through information. Therefore, the sending device associates and saves the priority of the key negotiation algorithm supported by the receiving device with the receiving device. Therefore, during this key negotiation process, the sending device determines the priority of the key negotiation algorithm supported by the receiving device according to the identification of the receiving device.
[0243] Method 2: The second information is also used to indicate the priority information of M key negotiation algorithms supported by the receiving device; the second information includes identification information of the M key negotiation algorithms, and the identification information is arranged or encapsulated according to the priority of the M key negotiation algorithms. Therefore, the sending device obtains the priority information of the key negotiation algorithms supported by the receiving device based on the second information.
[0244] Optionally, the second information also carries a first random number, wherein the first random number NONCE1 is a random number generated by the receiving device.
[0245] Optionally, the second information also carries an identifier of the receiving device, wherein the identifier of the receiving device is used to identify the receiving device.
[0246] S505: The sending device generates a target key according to the target key negotiation algorithm and the first key negotiation parameter.
[0247] In this embodiment, since the identifier of the target key agreement algorithm is carried in the second information, the sending device determines the key agreement algorithm selected by the receiving device through the identifier of the target key agreement algorithm, thereby generating the target key KE according to the target key agreement algorithm and the key agreement parameter KE1. In addition, the sending device calculates the key agreement parameter KE2 according to the target key agreement algorithm.
[0248] Optionally, after the sending device determines the target key agreement algorithm through the second information, it determines whether the target key agreement algorithm is one of the N key agreement algorithms indicated by the first information. If so, it obtains the target key and / or key agreement parameter KE2 according to the target key agreement algorithm; if not, the sending device discards the second information.
[0249] Optionally, the sending device obtains an encryption key and an integrity protection key according to the target key KE. The encryption key is used to encrypt information transmitted between the sending device and the receiving device. The integrity protection key is used to perform integrity protection on information transmitted between the sending device and the receiving device.
[0250] Among them, one way of sending device encryption key and integrity protection key is:
[0251] The sending device randomly generates a second random number NONCE2, and the sending device uses the target key KE, the random number NONCE1 and the random number NONCE2 as inputs of a key derivation function (KDF) KDF1 to obtain a shared key Kgt, ie, Kgt=KDF1(KE, NONCE1, NONCE2).
[0252] The sending device uses the shared key Kgt as the input of KDF2 to obtain the encryption key and the integrity protection key, that is, Kenc=KDF2(Kgt); similarly, Kint=KDF3(Kgt), where Kenc is the encryption key and Kint is the integrity protection key.
[0253] Another way is: after obtaining the target key KE, the sending device uses the target key KE as the input of KDF2 to obtain the encryption key and the integrity protection key, that is, Kenc=KDF2(KE); similarly, Kint=KDF3(KE), where Kenc is the encryption key and Kint is the integrity protection key.
[0254] It should be noted that KDF1, KDF2 and KDF3 may be the same or different. Furthermore, the present application does not restrict the KDF used to obtain the shared key Kgt, the KDF used to obtain the encryption key Kenc and the KDF used to obtain the integrity protection key Kint.
[0255] It can be understood that the method of obtaining the shared key Kgt, the encryption key Kenc, and the integrity protection key Kint shown in the embodiment of the present application is not intended to limit the present application, and other methods may be selected to obtain them. For example, Kenc = KDF2 (Kgt, ID1), Kint = KDF3 (Kgt, ID2), where ID1 is the identifier of the encryption algorithm, and ID2 is the identifier of the integrity protection algorithm.
[0256] Optionally, the method further includes S506: the sending device sends third information to the receiving device. Correspondingly, the receiving device receives the third information from the sending device.
[0257] The third information includes a second key negotiation parameter, where the second key negotiation parameter is a key negotiation parameter corresponding to the sender device and based on a target key negotiation algorithm.
[0258] Specifically, the third information carries the second random number NONCE2.
[0259] Optionally, since the second information sent by the receiving device to the sending device is not security-protected, the second information may be tampered with during the sending process. If the second information is tampered with, the key negotiation between the sending device and the receiving device will fail. Therefore, it is necessary to verify whether the second information has been tampered with. The method of verifying whether the second information has been tampered with may be, for example:
[0260] The sending device performs authentication processing on the second information, uses the second information as a parameter, generates first authentication data AUTH1, and sends the authentication data AUTH1 to the receiving device, so that the receiving device verifies whether the second information has been tampered with. Optionally, the third information includes the authentication data AUTH1. The method of obtaining AUTH1 includes:
[0261] Method 1: The authentication data AUTH1 is obtained by the sending device according to the second information received by the sending device, the preset shared key PSK and KDF4, that is, AUTH1 = KDF4 (PSK, second information). Among them, the preset shared key PSK is a key shared in advance between the sending device and the receiving device, so as to verify the identities of both parties according to the preset shared key PSK to prevent the information exchanged between the sending device and the receiving device from being tampered with. It should be noted that the embodiment of the present application does not limit the method of pre-setting the preset shared key PSK. For example, it can be obtained by inputting the same number into the sending device and the receiving device respectively in advance, or after obtaining the target key KE, it can be obtained by using the same deduction algorithm.
[0262] Correspondingly, after receiving the third information, the receiving device obtains the authentication data AUTH1 and matches the authentication data AUTH1 with the first reference authentication data. Among them, the first reference authentication data is obtained by the receiving device based on the second information sent, the preset shared key PSK and KDF4, that is, the first reference authentication data = KDF4 (PSK, second information). Therefore, if the second information has not been tampered with during the sending process, that is, the second information received by the sending device is consistent with the second information sent by the receiving device, then the authentication data AUTH1 matches the reference authentication data, otherwise it does not match. Therefore, according to the result of matching the authentication data AUTH1 with the first reference authentication data, the receiving device can determine whether the second information received by the sending device is consistent with the second information sent by the receiving device. If the authentication data AUTH1 matches the reference authentication data, it means that the second information has not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0263] Method 2: The authentication data AUTH1 is obtained by the sending device according to the second information received by the sending device, the random number NONCE2, the preset shared key PSK and KDF5, that is, AUTH1=KDF5(PSK, NONCE2, second information). Correspondingly, the first reference authentication data is obtained by the receiving device according to the second information sent, the random number NONCE2 in the received third information, the preset shared key PSK and KDF5, that is, the first reference authentication data=KDF5(PSK, NONCE2, second information). Therefore, if the second information has not been tampered with during the sending process, that is, the second information received by the sending device is consistent with the second information sent by the receiving device, and the random number NONCE2 in the third information has not been tampered with, then the authentication data AUTH1 matches the reference authentication data, otherwise it does not match. Therefore, according to the result of the matching of the authentication data AUTH1 and the first reference authentication data, the receiving device can determine whether the second information received by the sending device is consistent with the second information sent by the receiving device. If the authentication data AUTH1 matches the reference authentication data, it means that the second information and the random number NONCE2 have not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0264] The embodiment of the present application may also select other methods to obtain AUTH1, which are not listed here one by one.
[0265] It should be noted that the embodiment of the present application does not limit the KDF for obtaining AUTH1 and the first reference authentication data, as long as the KDF for obtaining AUTH1 is the same as the KDF for the first reference authentication data, and the parameters for obtaining AUTH1 correspond to the parameters for the first reference authentication data. For example, AUTH1 is obtained through KDF4, and the second information received by the sending device, and the preset shared key PSK. Correspondingly, the first reference authentication data is obtained through KDF4, and the receiving device obtains the first reference authentication data according to the second information sent and the preset shared key PSK.
[0266] Optionally, the third information is information processed by an integrity protection algorithm.
[0267] Exemplarily, before executing S406, after the sending device obtains the encryption key Kenc and the integrity protection key Kint, a first message authentication code (MAC) is obtained according to the integrity protection algorithm, the integrity protection key Kint and part or all of the third information sent by the sending device, and the third information is integrity protected by the first MAC. Exemplarily, the third information includes the first MAC.
[0268] S507: The receiving device generates a target key according to the second key negotiation parameter and the target key negotiation algorithm.
[0269] In this embodiment, after receiving the key negotiation parameter KE2 from the sending device, the receiving device obtains the target key KE according to the key negotiation algorithm and the received key negotiation parameter KE2.
[0270] Optionally, the receiving device adopts the same method as the sending device to obtain the encryption key Kenc and the integrity protection key Kint according to the target key KE. The second message authentication code MAC is obtained according to the integrity protection algorithm, the integrity protection key Kint and part or all of the third information received by the receiving device. If the first MAC and the second MAC are consistent, it means that the third information has not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0271] Optionally, the method further includes S508: the receiving device sends fourth information to the sending device. Correspondingly, the sending device receives the fourth information.
[0272] Optionally, the method further includes S509, the sending device verifies the fourth information.
[0273] In this embodiment, the fourth information also includes second authentication data AUTH2, which is authentication data obtained by the receiving device after authenticating the third information; the second authentication data AUTH2 is used to indicate whether the third information has been tampered with, and whether the third information has been tampered with is indicated by the matching result of the second authentication data AUTH2 and the second reference authentication data, and the second reference authentication data is the authentication data obtained after authenticating the third information.
[0274] This is because all key agreement algorithms supported by the receiving device are indicated in the second information. If S508 is executed, it means that the first information and the second information have not been tampered with during the sending process. Therefore, there is no need to confirm whether the first information has been tampered with.
[0275] The sending device sends the third information to the receiving device so that the receiving device can obtain the target key. However, since the receiving device does not generate the target key, it is impossible to generate an encryption key. Therefore, the sending device cannot encrypt the third information, that is, the third information is information that is not protected, so it is possible to be tampered with during the transmission process. If the third information is tampered with, the information communicated between the sending device and the receiving device may be leaked. Therefore, it is necessary to determine whether the third information has been tampered with. Therefore, the receiving device performs authentication processing on the third information and obtains the second authentication data AUTH2. Since the third information is sent by the sending device, the authentication data AUTH2 is included in the fourth information and sent to the sending device, and the sending device confirms whether the third information has been tampered with. Exemplarily, AUTH2 is obtained by the receiving device based on the received third information, the preset shared key PSK, the random number NONCE1 and KDF6, that is, AUTH2=KDF8(PSK, third information, NONCE1).
[0276] The sending device obtains AUTH2 from the fourth information, and matches the authentication data AUTH2 with the second reference authentication data, wherein the second reference authentication data is obtained by the sending device according to the third information sent by the sending device, the preset shared key PSK, the random number NONCE1 and KDF8, that is, the third reference authentication data = KDF8 (PSK, third information, NONCE1). Therefore, if the third information has not been tampered with during the sending process, that is, the third information received by the receiving device is consistent with the third information sent by the sending device, then the authentication data AUTH2 matches the second reference authentication data; if the third information has been tampered with during the sending process, then the authentication data AUTH2 does not match the second reference authentication data. Therefore, according to the result of the matching of the authentication data AUTH2 with the second reference authentication data, the sending device can determine whether the third information received by the receiving device is consistent with the third information sent by the sending device. If the authentication data AUTH2 matches the reference authentication data, it means that the third information has not been tampered with, and the key negotiation between the sending device and the receiving device is successful; otherwise, the fourth information is discarded and the connection with the receiving device is disconnected.
[0277] Figure 6 This is a flowchart of a key negotiation method provided by another embodiment of the present application. Figure 6 As shown, the key negotiation method in the embodiment of the present application includes:
[0278] S601: A sending device sends first information to a receiving device. Correspondingly, the receiving device receives the first information.
[0279] The first information is used to indicate N key negotiation algorithms, where N is an integer greater than or equal to 1, and the N key negotiation algorithms are algorithms supported by the sending device.
[0280] Exemplarily, the first information is carried in a negotiation message. Specifically, before two devices in a communication system transmit data, they need to perform key negotiation to obtain a target key, so as to encrypt and decrypt the transmitted data according to the target key. When a sending device and a receiving device perform key negotiation, the initiator device sends a negotiation message to the receiving device.
[0281] Optionally, the first information is also used to indicate priority information of N key negotiation algorithms; wherein the identification information of the N key negotiation algorithms contained in the first information is arranged or encapsulated according to the priority information of the N key negotiation algorithms.
[0282] Exemplarily, the priorities of the N key agreement algorithms indicated by the first information are arranged from high to low, or the priorities of the N key agreement algorithms indicated by the first information are arranged from low to high. For example, as shown in Table 2, the first information is used to indicate algorithm 1, algorithm 2, algorithm 3, algorithm 4, and algorithm 5, wherein the priority of algorithm 4 is higher than that of algorithm 2, the priority of algorithm 2 is higher than that of algorithm 5, the priority of algorithm 5 is higher than that of algorithm 1, and the priority of algorithm 1 is higher than that of algorithm 3.
[0283] S602: The receiving device determines a target key negotiation algorithm.
[0284] The target key agreement algorithm is a key agreement algorithm among the N key agreement algorithms and supported by the receiving device.
[0285] In this embodiment, the receiving device determines a key negotiation algorithm supported by itself from the N key negotiation algorithms in the first information as the target negotiation algorithm.
[0286] Optionally, the receiving device selects a key negotiation algorithm that is supported by the receiving device and has the highest priority for the sending device from the N key negotiation algorithms based on the priority information of the N key negotiation algorithms indicated in the received first information, and uses the key negotiation algorithm as the target negotiation algorithm.
[0287] Exemplarily, Table 3 shows all key negotiation algorithms supported by the receiving device. The first information received by the receiving device indicates the five key negotiation algorithms shown in Table 1. In the first information, the identifiers of the five algorithms are arranged in descending order of priority. Among the five key negotiation algorithms, according to Tables 1 to 3, the receiving device supports Algorithm 2, Algorithm 3, and Algorithm 5, and Algorithm 2 has a higher priority than Algorithm 3 and Algorithm 5. Therefore, the receiving device selects Algorithm 2 as the target negotiation algorithm.
[0288] Optionally, the receiving device determines, based on the N key negotiation algorithms indicated in the received first information, a key negotiation algorithm that it supports and has a relatively highest priority for itself from the N key negotiation algorithms, and uses the key negotiation algorithm as the target negotiation algorithm.
[0289] Exemplarily, Table 4 shows the priority information of the key negotiation algorithms supported by the receiving device. As shown in Table 3, the first information received by the receiving device indicates the five key negotiation algorithms shown in Table 1. Among the five key negotiation algorithms, the receiving device supports Algorithm 2, Algorithm 3 and Algorithm 5. According to Table 4, in the receiving device, Algorithm 3 has a higher priority than Algorithm 2, and Algorithm 2 has a higher priority than Algorithm 5, so the receiving device selects Algorithm 3 as the target negotiation algorithm. It should be noted that, in this embodiment, the N key negotiation algorithms supported by the sending device indicated in the first information may not be arranged according to the slice priority information, that is, the first information does not indicate the priority information of the N key negotiation algorithms supported by the sending device.
[0290] S603: The receiving device generates a first key negotiation parameter according to the target key negotiation algorithm.
[0291] The first key negotiation parameter is a key negotiation parameter corresponding to the receiving device and obtained based on the target key negotiation algorithm.
[0292] Exemplarily, the receiving device calculates the key negotiation parameter KE1 through the selected key negotiation algorithm.
[0293] S604: The receiving device sends the second information to the sending device. Correspondingly, the sending device receives the second information from the receiving device.
[0294] The second information indicates a target key negotiation algorithm and includes a first key negotiation parameter.
[0295] Optionally, the second information also carries a first random number, wherein the first random number NONCE1 is a random number generated by the receiving device.
[0296] Optionally, the second information also carries an identifier of the receiving device, wherein the identifier of the receiving device is used to identify the receiving device.
[0297] S605: The sending device generates a target key according to the target key negotiation algorithm and the first key negotiation parameter.
[0298] In this embodiment, since the identifier of the target key agreement algorithm is carried in the second information, the sending device determines the key agreement algorithm selected by the receiving device through the identifier of the target key agreement algorithm, thereby generating the target key KE according to the target key agreement algorithm and the key agreement parameter KE1. In addition, the sending device calculates the second key agreement parameter according to the target key agreement algorithm, which is recorded as KE2.
[0299] Optionally, after the sending device determines the target key agreement algorithm through the second information, it determines whether the target key agreement algorithm is one of the N key agreement algorithms indicated by the first information. If so, it obtains the target key and / or key agreement parameter KE2 according to the target key agreement algorithm; if not, the sending device discards the second information.
[0300] Optionally, the sending device obtains an encryption key and an integrity protection key according to the target key KE. The encryption key is used to encrypt information transmitted between the sending device and the receiving device. The integrity protection key is used to perform integrity protection on information transmitted between the sending device and the receiving device.
[0301] Among them, one way of sending device encryption key and integrity protection key is:
[0302] The sending device randomly generates a second random number NONCE2, and the sending device uses the target key KE, the random number NONCE1 and the random number NONCE2 as inputs of a key derivation function (KDF) KDF1 to obtain a shared key Kgt, ie, Kgt=KDF1(KE, NONCE1, NONCE2).
[0303] The sending device uses the shared key Kgt as the input of KDF2 to obtain the encryption key and the integrity protection key, that is, Kenc=KDF2(Kgt); similarly, Kint=KDF3(Kgt), where Kenc is the encryption key and Kint is the integrity protection key.
[0304] Another way is: after obtaining the target key KE, the sending device uses the target key KE as the input of KDF2 to obtain the encryption key and the integrity protection key, that is, Kenc=KDF2(KE); similarly, Kint=KDF3(KE), where Kenc is the encryption key and Kint is the integrity protection key.
[0305] It should be noted that KDF1, KDF2 and KDF3 may be the same or different. Furthermore, the present application does not restrict the KDF used to obtain the shared key Kgt, the KDF used to obtain the encryption key Kenc and the KDF used to obtain the integrity protection key Kint.
[0306] It can be understood that the method of obtaining the shared key Kgt, the encryption key Kenc, and the integrity protection key Kint shown in the embodiment of the present application is not intended to limit the present application, and other methods may be selected to obtain them. For example, Kenc = KDF2 (Kgt, ID1), Kint = KDF3 (Kgt, ID2), where ID1 is the identifier of the encryption algorithm, and ID2 is the identifier of the integrity protection algorithm.
[0307] Optionally, the method further includes S606: the sending device sends third information to the receiving device. Correspondingly, the receiving device receives the third information from the sending device.
[0308] The third information includes a second key negotiation parameter, which is a key negotiation parameter corresponding to the sending device and based on the target key negotiation algorithm. The third information is also used to indicate the N key negotiation algorithms supported by the sending device, and the receiving device determines whether the first information has been tampered with.
[0309] The third information again indicates the N key negotiation algorithms supported by the sending device. Since the third information is integrity protected, the receiving device can determine whether the third information has been tampered with by comparing the first MAC and the second MAC. If the third information has not been tampered with, if the N key negotiation algorithms supported by the sending device indicated by the third information are consistent with the N key negotiation algorithms supported by the sending device obtained from the first information, it means that the first information has not been tampered with; otherwise, it means that the first information has been tampered with, the third information is discarded, and the connection with the sending device is disconnected.
[0310] S607: The receiving device generates a target key according to the second key negotiation parameter and the target key negotiation algorithm.
[0311] In this embodiment, after receiving the key negotiation parameter KE2 from the sending device, the receiving device obtains the target key KE according to the key negotiation algorithm and the received key negotiation parameter KE2.
[0312] Optionally, the receiving device adopts the same method as the sending device to obtain the encryption key Kenc and the integrity protection key Kint according to the target key KE. The second message authentication code MAC is obtained according to the integrity protection algorithm, the integrity protection key Kint and part or all of the third information received by the receiving device. If the first MAC and the second MAC are consistent, it means that the third information has not been tampered with; otherwise, the receiving device discards the third information, disconnects the connection with the sending device, and then resends the second information.
[0313] Optionally, the method further includes S608: the receiving device sends fourth information to the sending device. Correspondingly, the sending device receives the fourth information.
[0314] Optionally, the method further includes S609, the sending device verifies the fourth information.
[0315] In this embodiment, the fourth information also includes second authentication data AUTH2, and the second authentication data is authentication data obtained by the receiving device after authenticating the third information; the second authentication data is used to indicate whether the third information has been tampered with, and whether the third information has been tampered with is indicated by the matching result between the second authentication data and the second reference authentication data, and the second reference authentication data is authentication data obtained after authenticating the third information.
[0316] The sending device sends the third information to the receiving device so that the receiving device obtains the target key. However, since the receiving device does not generate the target key, it is impossible to generate an encryption key. Therefore, the sending device cannot encrypt the third information, that is, the third information is information that is not protected, so it is possible to be tampered with during the transmission process. If the third information is tampered with, the information communicated between the sending device and the receiving device may be leaked. Therefore, it is necessary to determine whether the third information has been tampered with. Therefore, the receiving device performs authentication processing on the third information, obtains the second authentication data AUTH2, includes the authentication data AUTH2 in the fourth information, and sends it to the sending device. Since the third information is sent by the sending device, the sending device confirms whether the third information has been tampered with. Exemplarily, AUTH2 is obtained by the receiving device based on the received third information, the preset shared key PSK, the random number NONCE1 and KDF6, that is, AUTH2=KDF6(PSK, third information, NONCE1).
[0317] The sending device obtains AUTH2 from the fourth information, and matches the authentication data AUTH2 with the second reference authentication data, wherein the second reference authentication data is obtained by the sending device according to the third information sent by the sending device, the preset shared key PSK, the random number NONCE1 and KDF5, that is, the third reference authentication data = KDF6 (PSK, third information, NONCE1). Therefore, if the third information has not been tampered with during the sending process, that is, the third information received by the receiving device is consistent with the third information sent by the sending device, then the authentication data AUTH2 matches the second reference authentication data; if the third information has been tampered with during the sending process, then the authentication data AUTH2 does not match the second reference authentication data. Therefore, according to the result of the matching of the authentication data AUTH2 with the second reference authentication data, the sending device can determine whether the third information received by the receiving device is consistent with the third information sent by the sending device. If the authentication data AUTH2 matches the reference authentication data, it means that the third information has not been tampered with, and the key negotiation between the sending device and the receiving device is successful; otherwise, the connection with the receiving device is disconnected.
[0318] Figure 7 This is a flowchart of a key negotiation method provided by another embodiment of the present application. Figure 7 As shown, the key negotiation method in the embodiment of the present application includes:
[0319] S701, sixth information. Correspondingly, the receiving device receives the sixth information.
[0320] In this embodiment, compared with the first information, the sixth information does not indicate the N key agreement algorithms supported by the sending device. Therefore, after receiving the sixth information, the receiving device cannot know the key agreement algorithms supported by the sending device.
[0321] S702: The receiving device determines a first target key agreement algorithm.
[0322] The first target key agreement algorithm is a key agreement algorithm determined by the receiving device from M key agreement algorithms.
[0323] In this embodiment, since the receiving device does not know the key agreement algorithms supported by the sending device, the receiving device determines the first target key agreement algorithm from the M key agreement algorithms supported by the receiving device.
[0324] S703: The receiving device generates a first key negotiation parameter according to the first target key negotiation algorithm.
[0325] In this embodiment, the receiving device generates a private key, which is only known by the receiving device, and generates a public key through the selected key negotiation algorithm. The public key is the key negotiation parameter KE1.
[0326] S704: The receiving device sends the second information to the sending device. Correspondingly, the sending device receives the second information from the receiving device.
[0327] The second information is used to indicate M key negotiation algorithms, the first target key negotiation parameter, and the first key negotiation parameter supported by the receiving device.
[0328] S705. The sending device determines whether to negotiate the target key according to the first target key negotiation algorithm. If so, execute S706; if not, execute S710.
[0329] In this embodiment, since the receiving device does not know the key agreement algorithms supported by the sending device when selecting the first target key agreement algorithm, the first target key agreement algorithm may not be a key agreement algorithm supported by the sending device. Therefore, after receiving the second message, the sending device confirms whether the first target key agreement algorithm is a key agreement algorithm supported by it, and if so, executes S706, otherwise, executes S710.
[0330] Optionally, the sending device may also determine whether the first target key negotiation is a key negotiation algorithm with the highest priority corresponding to the sending device among the algorithms supported by the sending device and the receiving device. If so, execute S706; otherwise, execute S710.
[0331] Optionally, the second information also indicates the priority information of the key negotiation algorithm among the M key negotiation algorithms supported by the receiving device, so the sending device can obtain the priority information of the key negotiation algorithm among the M key negotiation algorithms supported by the receiving device according to the second information. Therefore, the sending device can also determine whether the first target key negotiation is the key negotiation algorithm with the highest priority corresponding to the receiving device among the algorithms supported by the sending device and the receiving device, and if so, execute S706, otherwise, execute S710.
[0332] S706: The sending device generates a target key according to the first target key negotiation algorithm and the first key negotiation parameter.
[0333] In this embodiment, the sending device generates a target key KE according to the first target key negotiation algorithm and the key negotiation parameter KE1. In addition, the sending device generates a private key, which is known only to the sending device, and then calculates the corresponding public key according to the first target key negotiation algorithm, that is, the second key negotiation parameter, which is recorded as KE2.
[0334] S707: The sending device sends the third information to the receiving device. Correspondingly, the receiving device receives the third information from the sending device.
[0335] The third information includes a second key negotiation parameter.
[0336] S708: The receiving device generates a target key according to the second key negotiation parameter and the first target key negotiation algorithm.
[0337] In this embodiment, the third information includes the key negotiation parameter KE2. After receiving the third information, the receiving device generates a target key KE according to the key negotiation parameter KE2 and the first target key negotiation algorithm.
[0338] S709: The receiving device sends the fourth information to the sending device. Correspondingly, the sending device receives the fourth information.
[0339] The fourth information is used to enable the sending device to determine whether the key negotiation is successful.
[0340] S710: The sending device determines a second target key agreement algorithm.
[0341] The second target key agreement algorithm is a key agreement algorithm supported by both the sending device and the receiving device and determined by the sending device from N key agreement algorithms and M key agreement algorithms.
[0342] In this embodiment, the sending device is aware of the M key agreement algorithms supported by the receiving device. Therefore, the sending device selects a key agreement algorithm supported by both the sending device and the receiving device from the N key agreement algorithms supported by itself and the M key agreement algorithms supported by the receiving device as the second target key agreement algorithm.
[0343] Optionally, the sending device may also select a key agreement algorithm supported by both the sending device and the receiving device and having the highest priority for the sending device from the N key agreement algorithms supported by itself and the M key agreement algorithms supported by the receiving device as the second target key agreement algorithm.
[0344] Optionally, the second information further indicates the priority information of the key negotiation algorithm among the M key negotiation algorithms supported by the receiving device.
[0345] Optionally, the sending device may also select a key agreement algorithm supported by both the sending device and the receiving device and having the highest priority for the sending device from the N key agreement algorithms supported by itself and the M key agreement algorithms supported by the receiving device as the second target key agreement algorithm.
[0346] Optionally, the second information also indicates the priority information of the key negotiation algorithm among the M key negotiation algorithms supported by the receiving device. Therefore, the sending device can also select a key negotiation algorithm supported by both the sending device and the receiving device and with the highest priority for the corresponding receiving device from the N key negotiation algorithms supported by itself and the M key negotiation algorithms supported by the receiving device as the second target key negotiation algorithm.
[0347] S711. The sending device sends seventh information to the receiving device.
[0348] The seventh information is used to indicate the second target key agreement algorithm selected by the sending device.
[0349] Exemplarily, the sending device sends the second target key agreement algorithm to the receiving device through the seventh information. After receiving the seventh information, the receiving device executes Figure 4 In steps S403-S408, the only difference is that the target key agreement algorithm is the second target key agreement algorithm, that is, the receiving device obtains the second target key agreement algorithm according to the seventh information, and then generates a private key, which is only known to the receiving device. Through the second key agreement algorithm, a public key is generated, and the public key is the key agreement parameter KE1. The receiving device sends the second information to the sending device, wherein the second information includes the key agreement parameter KE1.
[0350] After receiving the second information, the sending device obtains the key negotiation parameter KE1, and the sending device generates a private key, which is known only to the sending device. The sending device obtains the target key KE according to the key negotiation parameter KE1, the private key corresponding to the sending device, and the second target key negotiation algorithm. In addition, the sending device generates a public key according to the generated private key through the second key negotiation algorithm, and the public key is the key negotiation parameter KE2. The sending device sends the third information to the receiving device, wherein the third information includes the key negotiation parameter KE2.
[0351] After receiving the third information, the receiving device obtains the key negotiation parameter KE2, and generates a private key that only the receiving device knows. The receiving device obtains the target key KE based on the key negotiation parameter KE2, the corresponding private key of the receiving device and the second target key negotiation algorithm.
[0352] Optionally, the seventh information is used to indicate the second target key negotiation algorithm and the second key negotiation parameter selected by the sending device. After the sending device determines the second target key negotiation algorithm, it generates a private key that is known only to the sending device, and generates a key negotiation parameter KE2 through the second target key negotiation algorithm. The sending device sends the key negotiation parameter KE2 and the second target key negotiation algorithm to the receiving device, so that the receiving device can directly obtain the key negotiation parameter KE2 through the seventh information, thereby eliminating the need for the sending device to send another message to indicate the key negotiation parameter KE2, reducing the information interaction between the sending device and the receiving device, and improving the key negotiation efficiency.
[0353] After receiving the seventh information, the receiving device can obtain the key negotiation parameter KE2 and the second target key negotiation algorithm of the sending device. The receiving device generates a private key that is only known to the receiving device, and then generates the key negotiation parameter KE1 according to the second target key negotiation algorithm. After that, the receiving device generates the target key KE according to the key negotiation parameter KE2 and the second target key negotiation algorithm. Then, the receiving device sends the second information to the sending device, wherein the second information includes the key negotiation parameter KE1.
[0354] Optionally, the second information also includes a first random number NONCE1 randomly generated by the receiving device.
[0355] Optionally, the second information may also include fourth authentication data, which is obtained by the receiving device based on the received seventh information, the preset shared key PSK and KDF9, that is, the fourth reference authentication data = KDF9 (PSK, the seventh information received by the receiving device). After receiving the second information, the sending device compares the fourth authentication data with the fourth reference authentication data, wherein the fourth reference authentication data is obtained by the sending device based on the sent seventh information, the preset shared key PSK and KDF9. Therefore, the fourth authentication data matches the fourth reference authentication data, indicating that the seventh information has not been tampered with during the sending process; otherwise, the second information is discarded and the connection with the receiving device is disconnected. Optionally, the second information is information for integrity protection.
[0356] Wherein, if the seventh information is not tampered with during the sending process, the sending device sends the third information to the receiving device, and the third information is information that has been encrypted and integrity protected. Wherein, the third information includes the fifth authentication data, wherein the fifth authentication data is obtained by the sending device according to the corresponding second information in S704 received by the sending device, the preset shared key PSK, the second information carrying the fourth authentication data received by the sending device, and KDF10, that is, the fourth reference authentication data = KDF9 (PSK, the corresponding second information in S704 received by the sending device, the second information carrying the fourth authentication data received by the sending device). After receiving the third information, the sending device compares the fifth authentication data with the fifth reference authentication data, wherein the fifth reference authentication data is obtained by the receiving device according to the corresponding second information in S704 sent, the preset shared key PSK, the second information carrying the fourth authentication data sent, and KDF10. Therefore, the fifth authentication data matches the fifth reference authentication data, indicating that the corresponding second information in S704 and the second information carrying the fourth authentication data have not been tampered with during the sending process; otherwise, the third information is discarded and the connection with the receiving device is disconnected.
[0357] After receiving the second information, the sending device obtains the key negotiation parameter KE1, and obtains the target key KE according to the key negotiation parameter KE1 and the second target key negotiation algorithm.
[0358] Optionally, the seventh information also includes a second random number NONCE2 randomly generated by the sending device.
[0359] It can be understood that in the above-mentioned embodiments, the method or step implemented by the sending device can also be implemented by a component that can be used for the receiving device, and the method or step implemented by the receiving device can also be implemented by a component that can be used for the sending device.
[0360] Figure 8 This is a schematic diagram of the structure of a key agreement device provided in one embodiment of the present application. Figure 8 As shown, the key negotiation device 800 described in this embodiment can be the sender device or the receiver device mentioned in the above method embodiment. The key negotiation device can be used to implement the method corresponding to the sender device or the receiver device described in the above method embodiment, and refer to the description in the above method embodiment for details.
[0361] The key agreement device 800 may include one or more processors 801, which may also be referred to as a processing unit, and may implement certain control or processing functions. The processor 801 may be a general-purpose processor or a dedicated processor, etc. For example, it may be a baseband processor or a central processing unit. The baseband processor may be used to process the communication protocol and communication data, and the central processing unit may be used to control the communication device, execute the software program, and process the data of the software program.
[0362] In an optional design, the processor 801 may also store instructions 803 or data (such as intermediate data), wherein the instructions 803 may be executed by the processor, so that the key agreement apparatus 800 executes the method corresponding to the sender device or the receiver device described in the above method embodiment.
[0363] In yet another possible design, key agreement apparatus 800 may include a circuit, which may implement the functions of sending, receiving, or communicating in the aforementioned method embodiments.
[0364] Optionally, the key negotiation device 800 may include one or more memories 802, on which instructions 804 may be stored. The instructions may be executed on the processor, so that the key negotiation device 800 executes the method described in the above method embodiment.
[0365] Optionally, data may also be stored in the memory. The processor and memory may be provided separately or integrated together.
[0366] Optionally, the key negotiation device 800 may further include a transceiver 805 and / or an antenna 806. The processor 801 may be referred to as a processing unit, and controls the key negotiation device (sender device or receiver device). The transceiver 805 may be referred to as a transceiver unit, a transceiver, a transceiver circuit, or a transceiver, and is used to implement the transceiver function of the key negotiation device.
[0367] In one design, if the key negotiation device 800 is used to implement operations corresponding to the receiving device in the above embodiments, for example, the transceiver 805 may receive first information from the sending device, and the processor 801 may determine that the receiving device performs key negotiation with the sending device based on the first information.
[0368] In another design, if the key agreement device 800 is used to implement operations corresponding to the sender device in the above embodiments, for example, the processor 801 may determine first information indicating the key agreement algorithm capabilities supported by the sender device; and the transceiver 805 may send the first information to the receiver device.
[0369] Among them, the specific implementation process of the above-mentioned transceiver 805 and the processor 801 can refer to the relevant description of the above-mentioned embodiments, and will not be repeated here.
[0370] The processor 801 and the transceiver 805 described in the present application can be implemented in an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFIC), a mixed signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, etc. The processor and the transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), N-type metal oxide semiconductor (NMOS), P-type metal oxide semiconductor (positive channel metal oxide semiconductor, PMOS), bipolar junction transistor (BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.
[0371] Although in the above embodiment, the key negotiation apparatus 800 is described by taking a sender device or a receiver device as an example, the scope of the key negotiation apparatus described in the present application is not limited to the sender device or the receiver device, and the structure of the key negotiation apparatus may not be limited to the sender device or the receiver device. Figure 8 The key negotiation device 800 may be an independent device or may be a part of a larger device. For example, the device may be:
[0372] (1) Independent integrated circuit IC, or chip, or chip system or subsystem;
[0373] (2) having a set of one or more ICs, and optionally, the IC set may also include a storage component for storing data and / or instructions;
[0374] (3) ASIC, such as modem (MSM);
[0375] (4) Modules that can be embedded in other devices;
[0376] (5) Receivers, terminals, cellular phones, wireless devices, handsets, mobile units, network equipment, etc.;
[0377] (6)Others
[0378] Fig. 9 A schematic diagram of the structure of a key agreement device provided in another embodiment of the present application. The device may be a sender device, or a component of a sender device (e.g., an integrated circuit, a chip, etc.), or may be other communication modules, for implementing Figure 4-Figure 6 The method embodiment shown corresponds to the operations or steps of the sending device. Fig. 9 As shown, the key agreement device provided by this embodiment includes: a first sending module 901, a first receiving module 902 and a first processing module 903. Among them,
[0379] A first sending module 901 is used to send first information to a receiving device, where the first information is used to indicate N key negotiation algorithms, where N is an integer greater than or equal to 1, and the N key negotiation algorithms are algorithms supported by the sending device;
[0380] A first receiving module 902 is configured to receive second information from a receiving device, where the second information is used to indicate a target key negotiation algorithm and includes a first key negotiation parameter, where the target key negotiation algorithm is a key negotiation algorithm among N key negotiation algorithms and supported by the receiving device, and the first key negotiation parameter is a key negotiation parameter corresponding to the receiving device and obtained based on the target key negotiation algorithm;
[0381] The first processing module 903 is used to generate a target key according to a target key negotiation algorithm and a first key negotiation parameter.
[0382] Optionally, the first sending module 901 is further used for:
[0383] Sending third information to the receiving device, the third information including a second key negotiation parameter, where the second key negotiation parameter is a key negotiation parameter corresponding to the sending device and based on a target key negotiation algorithm.
[0384] Optionally, when the first sending module 901 sends the third information to the receiving device, it is specifically used to:
[0385] The third information processed by the integrity protection algorithm is sent to the receiving device.
[0386] Optionally, the first information is also used to indicate priority information of N key agreement algorithms;
[0387] The first information includes identification information of N key negotiation algorithms, and the identification information is arranged or encapsulated according to priority information of the N key negotiation algorithms.
[0388] Optionally, the second information is further used to indicate M key agreement algorithms supported by the receiving device, where M is an integer greater than or equal to 1;
[0389] Generating a target key according to a target key negotiation algorithm and a first key negotiation parameter, including:
[0390] Determining that the target key agreement algorithm is a key agreement algorithm with the highest priority corresponding to the receiving device among the M key agreement algorithms;
[0391] A target key is generated according to a target key negotiation algorithm and a first key negotiation parameter.
[0392] Optionally, the first receiving module 902 is further configured to:
[0393] Receive priority information of M key agreement algorithms from a receiving device.
[0394] Optionally, the second information is also used to indicate priority information of M key agreement algorithms supported by the receiving device;
[0395] The second information includes identification information of the M key negotiation algorithms, and the identification information is arranged or encapsulated according to the priority of the M key negotiation algorithms.
[0396] Optionally, the first sending module 901 is further used for:
[0397] The first authentication data is sent to the receiving device, where the first authentication data is authentication data obtained by the sending device performing authentication processing on the second information.
[0398] Optionally, the first receiving module 902 is further configured to:
[0399] receiving fourth information sent by a receiving device;
[0400] The first processing module 903 is further used for:
[0401] verifying the fourth information;
[0402] The fourth information includes second authentication data, which is data from a receiving device obtained by authenticating the third information.
[0403] Optionally, the first receiving module 902 is further configured to:
[0404] receiving fourth information sent by a receiving device;
[0405] The first processing module 903 is further used for:
[0406] verifying the fourth information;
[0407] The fourth information includes third authentication data, which is data from the receiving device obtained by authenticating the N key agreement algorithms indicated in the first information and the third information.
[0408] Optionally, the fourth information is fourth information processed by an integrity protection algorithm.
[0409] Optionally, the authentication process also includes performing authentication processing according to a preset shared key.
[0410] Optionally, the third information also indicates N key negotiation algorithms supported by the sending device.
[0411] Optionally, when the first sending module 901 sends the first information to the receiving device, it is specifically used to:
[0412] The first information is broadcasted to a receiving device.
[0413] Specifically, the device provided in this embodiment can be used to execute the technical solution of any of the above-mentioned method embodiments, and its implementation principle and technical effects are similar, which will not be repeated here.
[0414] Fig.10 A schematic diagram of the structure of a key agreement device provided in another embodiment of the present application. The device may be a receiving device, or a component of a receiving device (e.g., an integrated circuit, a chip, etc.), or may be other communication modules, for implementing Figure 4-Figure 6 The method embodiment shown corresponds to the operations or steps of the receiving device. Fig.10 As shown, the key agreement device provided by this embodiment includes: a second receiving module 1001, a second processing module 1002 and a second sending module 1003.
[0415] in,
[0416] The second receiving module 1001 is used to receive first information from a sending device, where the first information indicates N key agreement algorithms supported by the sending device, where N is an integer greater than or equal to 1;
[0417] The second processing module 1002 is used to determine a target key negotiation algorithm, and generate a first key negotiation parameter according to the target key negotiation algorithm, wherein the target key negotiation algorithm is a key negotiation algorithm among N key negotiation algorithms and supported by the receiving device; the first key negotiation parameter is a key negotiation parameter corresponding to the receiving device and obtained based on the target key negotiation algorithm;
[0418] The second sending module 1003 is used to send second information to the sending device, where the second information indicates a target key negotiation algorithm and includes a first key negotiation parameter;
[0419] The second receiving module 1001 is used to receive third information from a sending device, where the third information indicates a second key negotiation parameter, where the second key negotiation parameter corresponds to a key negotiation parameter of the sending device obtained based on a target key negotiation algorithm;
[0420] The second processing module 1002 is further configured to generate a target key according to the second key negotiation parameter and the target key negotiation algorithm.
[0421] Optionally, the third information is third information processed by an integrity protection algorithm.
[0422] Optionally, the first information is further used to indicate priority information of N key agreement algorithms; wherein the first information includes identification information of the N key agreement algorithms, and the identification information is arranged or encapsulated according to the priority information of the N key agreement algorithms;
[0423] The second processing module 1002 determines the target key negotiation algorithm:
[0424] A key agreement algorithm with the highest priority corresponding to the sending device is determined from the N key agreement algorithms as the target key agreement algorithm.
[0425] Optionally, when the second processing module 1002 determines the target key agreement algorithm, it is specifically used to:
[0426] A key agreement algorithm with the highest priority corresponding to the receiving device is determined from the N key agreement algorithms as the target key agreement algorithm.
[0427] Optionally, the second information further indicates priority information of M key agreement algorithms supported by the receiving device;
[0428] The second information includes identification information of M key negotiation algorithms, and the identification information is arranged or encapsulated according to priority information of the M key negotiation algorithms.
[0429] Optionally, the second receiving module 1001 is further used for:
[0430] Receive first authentication data from a sending device; the first authentication data is authentication data obtained by the sending device performing authentication processing on the second information.
[0431] Optionally, the second sending module 1003 is further used for:
[0432] The fourth information is sent to the sending device, where the fourth information includes second authentication data, and the second authentication data is authentication data obtained by the receiving device through authentication processing on the third information.
[0433] Optionally, the second sending module 1003 is further used for:
[0434] The fourth information is sent to the sending device, where the fourth information includes third authentication data, and the third authentication data is authentication data obtained by the receiving device by performing authentication processing on the N key agreement algorithms indicated in the first information and the third information.
[0435] Optionally, when the second sending module 1003 sends the fourth information to the sending device, it is specifically used to:
[0436] The fourth information processed by the integrity protection algorithm is sent to the sending device.
[0437] Optionally, the authentication process also includes performing authentication processing according to a preset key.
[0438] Optionally, the third information also indicates N key negotiation algorithms supported by the sending device.
[0439] Specifically, the device provided in this embodiment can be used to execute the technical solution of any of the above-mentioned method embodiments, and its implementation principles and technical effects are similar, which will not be repeated here.
[0440] Fig.11 This is a schematic diagram of the structure of a communication system provided in one embodiment of the present application. Fig.11 As shown, the communication system 1100 described in this embodiment may include: a sending device 1101 and a receiving device 1102.
[0441] In another possible implementation, the sending device 1101 may use Figure 8 or Fig. 9 The structure of the device embodiment shown can correspondingly execute the technical solution of the sending device related to any of the above-mentioned method embodiments. The implementation principles and technical effects are similar and will not be repeated here.
[0442] In another possible implementation, the receiving device 1102 may use Figure 8 or Fig.10 The structure of the device embodiment shown can correspondingly execute the technical solution of the receiving device related to any of the above-mentioned method embodiments. The implementation principles and technical effects are similar and will not be repeated here.
[0443] In another possible implementation, the sending device 1101 may use Figure 8 or Fig. 9 The structure of the device embodiment shown in the figure can correspondingly execute the technical solution of the sender device of any of the above method embodiments, and its implementation principle and technical effect are similar, which will not be repeated here. The receiving device 1102 can adopt Figure 8 or Fig.10The structure of the device embodiment shown can correspondingly execute the technical solution of the receiving device related to any of the above-mentioned method embodiments. The implementation principles and technical effects are similar and will not be repeated here.
[0444] If the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), disk or optical disk and other media that can store program codes.
[0445] The present application also provides a computer-readable storage medium in which a computer program is stored. When the computer program is executed on one or more processors, Figure 3-Figure 7 The method described in any one of the embodiments.
[0446] The embodiment of the present application also provides a chip system, the chip system includes at least one processor, a memory and an interface circuit, the interface circuit is used to provide information input and / or output for the at least one processor, the at least one memory stores a computer program, when the computer program is run on one or more processors, the execution Figure 3-Figure 7 The method described in any one of the embodiments.
[0447] The present application also provides a smart cockpit product, wherein the smart cockpit product comprises the above Figure 8 or Fig.10 The key agreement device provided or the above Figure 8 or Fig. 9 A key negotiation device is provided, wherein the key negotiation device can execute Figure 3-Figure 7 A method executed by a sending device or a receiving device corresponding to the key negotiation device in any one of the embodiments.
[0448] The present application also provides a smart terminal, which includes the above-mentioned Figure 8 or Fig.10 The key agreement device provided or the above Figure 8 or Fig. 9 A key negotiation device is provided, wherein the key negotiation device can execute Figure 3-Figure 7 The method is performed by a sending device or a receiving device corresponding to the key negotiation device in any one of the embodiments. Further, the intelligent terminal can be a transportation tool or an intelligent device, including a drone, an unmanned transport vehicle, an intelligent car or a robot.
[0449] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the unit described as a separate component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or it may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative work.
[0450] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive Solid State Disk (SSD)), etc.
[0451] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A key negotiation method, characterized in that: The method comprises: Broadcasting first information, where the first information carries N key agreement algorithms supported by the sending device, where the N key agreement algorithms are arranged according to priority, and N is an integer greater than or equal to 1; receiving second information from a receiving device, where the second information carries a target key agreement algorithm and a first key agreement parameter, where the target key agreement algorithm is a key agreement algorithm with the highest priority among the N key agreement algorithms supported by the sending device and supported by the receiving device, and the first key agreement parameter is a public key generated by the receiving device according to the target key agreement algorithm; A target key is generated according to the target key negotiation algorithm and the first key negotiation parameter.
2. The method according to claim 1, characterized in that The method further comprises: Sending third information to the receiving device, where the third information includes a second key negotiation parameter, where the second key negotiation parameter is a public key generated by the sending device according to the target key negotiation algorithm.
3. The method according to claim 2, characterized in that The third information is information processed by an integrity protection algorithm.
4. The method according to any one of claims 1 to 3, characterized in that: The first information carries N key agreement algorithms supported by the sending device, and the N key agreement algorithms are arranged according to priority, including: The first information includes identification information of the N key negotiation algorithms, and the identification information is arranged or encapsulated according to priority information of the N key negotiation algorithms.
5. The method according to any one of claims 2 to 4, characterized in that: The third information also includes first authentication data, where the first authentication data is authentication data obtained by the sending device performing authentication processing on the second information.
6. The method according to any one of claims 2 to 5, characterized in that: The method further comprises: receiving and verifying fourth information from the recipient device; The fourth information includes second authentication data, and the second authentication data is data obtained by authenticating the third information.
7. The method according to any one of claims 2 to 5, characterized in that: The method comprises: receiving and verifying fourth information sent from the receiving device; The fourth information includes third authentication data, and the third authentication data is authentication data obtained by performing authentication processing on the N key agreement algorithms indicated in the first information and the third information.
8. The method according to claim 6 or 7, characterized in that: The fourth information is information processed by an integrity protection algorithm.
9. The method according to any one of claims 5 to 8, characterized in that: The authentication process also includes performing authentication processing according to a preset shared key.
10. A communication device, the communication device being a sender device or being applied to a sender device, characterized in that: The communication device comprises: A transceiver unit, configured to broadcast first information, where the first information carries N key agreement algorithms supported by the sender device, where the N key agreement algorithms are arranged according to priority, and N is an integer greater than or equal to 1; The transceiver unit is configured to receive second information from a receiving device, where the second information carries a target key agreement algorithm and a first key agreement parameter, where the target key agreement algorithm is a key agreement algorithm with the highest priority among the N key agreement algorithms supported by the sending device and supported by the receiving device, and the first key agreement parameter is a public key generated by the receiving device according to the target key agreement algorithm; A processing unit is used to generate a target key according to the target key negotiation algorithm and the first key negotiation parameter.
11. The communication device according to claim 10, characterized in that: The communication device further comprises: The transceiver unit is used to send third information to the receiving device, where the third information includes a second key negotiation parameter, and the second key negotiation parameter is a public key generated by the sending device according to the target key negotiation algorithm.
12. The communication device according to claim 11, characterized in that: The third information is information processed by an integrity protection algorithm.
13. The communication device according to any one of claims 10 to 12, characterized in that: The first information carries N key agreement algorithms supported by the sending device, and the N key agreement algorithms are arranged according to priority, including: The first information includes identification information of the N key negotiation algorithms, and the identification information is arranged or encapsulated according to priority information of the N key negotiation algorithms.
14. The communication device according to any one of claims 11 to 13, characterized in that: The third information also includes first authentication data, where the first authentication data is authentication data obtained by the sending device performing authentication processing on the second information.
15. The communication device according to any one of claims 11 to 14, characterized in that: The communication device further comprises: The transceiver unit is used to receive fourth information from the receiving device; The processing unit is used to verify the fourth information; The fourth information includes second authentication data, and the second authentication data is data obtained by authenticating the third information.
16. The communication device according to any one of claims 11 to 14, characterized in that: The method comprises: The transceiver unit is used to receive fourth information sent from the receiving device; The processing unit is used to verify the fourth information The fourth information includes third authentication data, and the third authentication data is authentication data obtained by performing authentication processing on the N key agreement algorithms indicated in the first information and the third information.
17. The communication device according to claim 15 or 16, characterized in that: The fourth information is information processed by an integrity protection algorithm.
18. The communication device according to any one of claims 14 to 17, characterized in that: The authentication process also includes performing authentication processing according to a preset shared key.
19. A communication device, characterized in that: include: one or more processors coupled to one or more memories; one or more memories for storing computer programs or instructions; One or more processors, configured to execute computer programs or instructions stored in the one or more memories, so that the apparatus performs the method according to any one of claims 1 to 9.
20. A readable storage medium, characterized in that: The method comprises a program or an instruction, and when the program or the instruction is executed on a processor, it is a method according to any one of claims 1 to 9.
21. A computer program product, characterized in that When the computer program product is executed by a computer, the method according to any one of claims 1 to 9 is performed.
Citation Information
Cited By
Key negotiation method and device and related equipment
CN120639294A