Communication method and device, electronic equipment, storage medium and chip

By using the encrypted session key and target data channel between the smart door lock and the client, the problem of low communication security between the smart door lock and the client is solved, and higher communication security and tamper-proof are achieved.

CN119995838APending Publication Date: 2025-05-13BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311491537.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-09
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The communication method between the smart door lock and the client has problems with low security performance, which is prone to key leakage, eavesdropping and message tampering.

Method used

By establishing a secure data channel between the smart door lock and the client, the target message is encrypted using a pre-generated session key and sent to the other party through the target data channel. The session key is generated based on the master key and the first shared key of the second terminal. The master key is obtained after decrypting the encrypted device information obtained from the cloud server according to the device security code.

Benefits of technology

Improve the communication security between the smart door lock and the client, prevent key leakage and message tampering, and ensure the security and accuracy of the communication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995838A_ABST
    Figure CN119995838A_ABST
Patent Text Reader

Abstract

The invention relates to a communication method and device, electronic equipment, a storage medium and a chip, and relates to the technical field of communication, the method is applied to a first terminal, and the method comprises the following steps: determining a to-be-sent target message; and generating a target transmission message according to a pre-generated first session key and the to-be-sent target message. The first session key is generated according to a master key of the second terminal and a first shared key, the master key is obtained by decrypting encrypted device information acquired from a cloud server according to a device security code, and the device security code is preset by a user; the encrypted equipment information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the equipment security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal. And sending the target transmission message to the second terminal. The security of communication between the first terminal and the second terminal can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a communication method, device, electronic device, storage medium and chip. Background Art

[0002] With the rapid development of the smart home industry, smart door locks are becoming more and more popular as a highly intelligent smart home product. As a smart security product, smart door locks have high requirements for communication security. However, the communication method between smart door locks and clients in related technologies has low security performance and there is a problem of key leakage. In addition, during the communication process between smart door locks and clients, eavesdropping and message tampering are prone to occur. Summary of the invention

[0003] In order to overcome the problems existing in the related art, the present disclosure provides a communication method, a device, an electronic device, a storage medium and a chip.

[0004] According to a first aspect of an embodiment of the present disclosure, a communication method is provided, which is applied to a first terminal, and the method includes:

[0005] Determine the target message to be sent;

[0006] Generate a target transmission message according to a pre-generated first session key and a target message to be sent; the first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting encrypted device information obtained from a cloud server according to a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal;

[0007] The target transmission message is sent to the second terminal.

[0008] Optionally, the target transmission message includes an encrypted message and a first message authentication code; and generating the target transmission message according to the pre-generated first session key and the target message to be sent includes:

[0009] Encrypting the target message to be sent according to the first session key to obtain an encrypted message and a first message authentication code;

[0010] The sending the target transmission message to the second terminal comprises:

[0011] The encrypted message and the first message authentication code are sent to the second terminal, where the first message authentication code is used to verify the target message.

[0012] Optionally, the target transmission message further includes a target identifier, where the target identifier is used to indicate the number of times the first terminal sends the message; and the method further includes:

[0013] Obtain the target identifier generated by a preset counter;

[0014] The sending the target transmission message to the second terminal comprises:

[0015] The encrypted message, the first message authentication code and the target identifier are sent to the second terminal.

[0016] Optionally, the first session key is generated in the following manner:

[0017] Acquire encrypted device information from the cloud server, the encrypted device information including the master key encrypted using the device security code;

[0018] The first session key is generated according to the encryption device information and the first shared key.

[0019] Optionally, the first shared key is generated in the following manner:

[0020] Randomly generate a first public key and a first private key of the first terminal;

[0021] receiving a second public key of the second terminal sent by the second terminal;

[0022] The first shared key is generated according to the first private key and the second public key.

[0023] Optionally, the method further comprises:

[0024] Obtaining the device security code;

[0025] Decrypt the encrypted device information according to the device security code to obtain the master key;

[0026] Generating the first session key according to the encryption device information and the first shared key comprises:

[0027] The first session key is generated based on the master key and the first shared key.

[0028] Optionally, the method further comprises:

[0029] Generate a second message authentication code according to the first session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal;

[0030] sending the second message authentication code to the second terminal, so that the second terminal authenticates the first terminal according to the second message authentication code;

[0031] Determining the target message to be sent includes:

[0032] When the identity authentication is passed, a target message to be sent is determined.

[0033] Optionally, the method further comprises:

[0034] Randomly generate device verification code;

[0035] Establishing a target data channel according to the device verification code;

[0036] The sending the target transmission message to the second terminal comprises:

[0037] The target transmission message is sent to the second terminal through the target data channel.

[0038] Optionally, establishing a target data channel according to the device verification code includes:

[0039] Generate a third message authentication code according to the device authentication code;

[0040] Obtaining a fourth message authentication code from the second terminal according to the device authentication code;

[0041] In a case where the third message authentication code matches the fourth message authentication code, the target data channel is established.

[0042] Optionally, the acquiring a fourth message authentication code from the second terminal according to the device authentication code includes:

[0043] A fourth message authentication code is received from the second terminal, where the fourth message authentication code is generated by the second terminal according to the input device verification code.

[0044] Optionally, the method further comprises:

[0045] Randomly generate a third public key and a third private key of the first terminal;

[0046] Sending the third public key to the second terminal, and receiving a fourth public key sent by the second terminal;

[0047] Generate a second shared key according to the third private key and the fourth public key;

[0048] Generating a third message authentication code according to the device authentication code comprises:

[0049] The third message authentication code is generated according to the device authentication code and the second shared key.

[0050] Optionally, the method further comprises:

[0051] generating a first random number;

[0052] Generating the third message authentication code according to the device authentication code and the second shared key comprises:

[0053] The third message authentication code is generated according to the device authentication code, the second shared key and the first random number.

[0054] Optionally, after acquiring a fourth message authentication code from the second terminal according to the device authentication code, the method further includes:

[0055] Receiving a second random number sent by the second terminal;

[0056] Determine whether the third message authentication code matches the fourth message authentication code according to the first random number and the second random number.

[0057] Optionally, the method further comprises:

[0058] Decrypting the fourth message authentication code according to the second shared key to obtain the candidate verification code and the candidate random number;

[0059] The determining, according to the first random number and the second random number, whether the third message authentication code matches the fourth message authentication code comprises:

[0060] In a case where the candidate verification code matches the device verification code, and the candidate random number matches the second random number, it is determined that the third message authentication code matches the fourth message authentication code.

[0061] Optionally, the method further comprises:

[0062] Generate the master key according to the device verification code and the second shared key;

[0063] Encrypting the master key according to the device security code to obtain the encrypted device information;

[0064] The encrypted device information is sent to the cloud server.

[0065] According to a second aspect of an embodiment of the present disclosure, a communication method is provided, which is applied to a second terminal, and the method includes:

[0066] receiving a target transmission message sent by a first terminal;

[0067] The target transmission message is decrypted according to the pre-generated second session key to obtain the target message; the target transmission message is obtained by the first terminal encrypting the target message according to the pre-generated first session key, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal.

[0068] Optionally, the target transmission message includes an encrypted message and a first message authentication code; and the receiving the target transmission message sent by the first terminal includes:

[0069] The encrypted message and the first message authentication code are received; the encrypted message and the first message authentication code are obtained by encrypting the target message according to the first session key, and the first message authentication code is used to verify the target message.

[0070] Optionally, the method further comprises:

[0071] generating a fifth message authentication code based on the second session key and the target message;

[0072] In case the first message authentication code and the fifth message authentication code do not match, the target message is discarded.

[0073] Optionally, the target transmission message further includes a target identifier, where the target identifier is used to indicate the number of times the first terminal sends the message; and receiving the target transmission message sent by the first terminal includes:

[0074] Receiving the encrypted message, the first message authentication code and the target identifier;

[0075] In the case where the target identifier is the same as a historical identifier, the target message is discarded, and the historical identifier is an identifier in a message received from the first terminal before receiving the target transmission message.

[0076] Optionally, the second session key is generated in the following manner:

[0077] Randomly generate a second public key and a second private key of the second terminal;

[0078] receiving a first public key of the first terminal sent by the first terminal;

[0079] Generate a third shared key according to the first public key and the second private key;

[0080] Obtaining the master key;

[0081] The second session key is generated according to the master key and the third shared key.

[0082] Optionally, the method further comprises:

[0083] Receiving a second message authentication code sent by the first terminal;

[0084] generating a sixth message authentication code according to the second session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal;

[0085] If the sixth message authentication code matches the second message authentication code, passing the identity authentication of the first terminal;

[0086] The receiving a target transmission message sent by the first terminal comprises:

[0087] When the identity authentication of the first terminal is passed, a target transmission message sent by the first terminal is received.

[0088] Optionally, the method further comprises:

[0089] Get the input device verification code;

[0090] Establishing a target data channel according to the device verification code;

[0091] The receiving a target transmission message sent by the first terminal comprises:

[0092] The target transmission message is received through the target data channel.

[0093] Optionally, establishing a target data channel according to the device verification code includes:

[0094] Generate a fourth message authentication code according to the device authentication code;

[0095] Receiving a third message authentication code sent by the first terminal;

[0096] In a case where the third message authentication code matches the fourth message authentication code, the target data channel is established.

[0097] According to a third aspect of an embodiment of the present disclosure, a communication device is provided, applied to a first terminal, the device including:

[0098] A first determining module is configured to determine a target message to be sent;

[0099] a first generating module, configured to generate a target transmission message according to a pre-generated first session key and a target message to be sent; the first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting encrypted device information obtained from a cloud server according to a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal;

[0100] The first sending module is configured to send the target transmission message to the second terminal.

[0101] Optionally, the target transmission message includes an encrypted message and a first message authentication code; and the first generating module is configured to:

[0102] Encrypting the target message to be sent according to the first session key to obtain an encrypted message and a first message authentication code;

[0103] The first sending module is configured as follows:

[0104] The encrypted message and the first message authentication code are sent to the second terminal, where the first message authentication code is used to verify the target message.

[0105] Optionally, the target transmission message further includes a target identifier, where the target identifier is used to indicate the number of times the first terminal sends the message; and the device further includes:

[0106] A first acquisition module is configured to acquire the target identifier generated by a preset counter;

[0107] The first sending module is configured as follows:

[0108] The encrypted message, the first message authentication code and the target identifier are sent to the second terminal.

[0109] Optionally, the first session key is generated in the following manner:

[0110] Acquire encrypted device information from the cloud server, the encrypted device information including the master key encrypted using the device security code;

[0111] The first session key is generated according to the encryption device information and the first shared key.

[0112] Optionally, the first shared key is generated in the following manner:

[0113] Randomly generate a first public key and a first private key of the first terminal;

[0114] receiving a second public key of the second terminal sent by the second terminal;

[0115] The first shared key is generated according to the first private key and the second public key.

[0116] Optionally, the device further comprises:

[0117] A second acquisition module is configured to acquire the device security code;

[0118] A first decryption module is configured to decrypt the encrypted device information according to the device security code to obtain the master key;

[0119] The first generating module is configured as follows:

[0120] The first session key is generated based on the master key and the first shared key.

[0121] Optionally, the device further comprises:

[0122] A second generating module is configured to generate a second message authentication code according to the first session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal;

[0123] A second sending module is configured to send the second message authentication code to the second terminal, so that the second terminal authenticates the first terminal according to the second message authentication code;

[0124] The first determining module is configured to:

[0125] When the identity authentication is passed, a target message to be sent is determined.

[0126] Optionally, the device further comprises:

[0127] A third generating module is configured to randomly generate a device verification code;

[0128] An establishing module, configured to establish a target data channel according to the device verification code;

[0129] The first sending module is configured as follows:

[0130] The target transmission message is sent to the second terminal through the target data channel.

[0131] Optionally, the establishing module is configured to:

[0132] Generate a third message authentication code according to the device authentication code;

[0133] Obtaining a fourth message authentication code from the second terminal according to the device authentication code;

[0134] In a case where the third message authentication code matches the fourth message authentication code, the target data channel is established.

[0135] Optionally, the establishing module is configured to:

[0136] A fourth message authentication code is received from the second terminal, where the fourth message authentication code is generated by the second terminal according to the input device verification code.

[0137] Optionally, the device further comprises:

[0138] a fourth generating module, configured to randomly generate a third public key and a third private key of the first terminal;

[0139] a third sending module, configured to send the third public key to the second terminal, and receive a fourth public key sent by the second terminal;

[0140] a fifth generating module, configured to generate a second shared key according to the third private key and the fourth public key;

[0141] The establishment module is configured to:

[0142] The third message authentication code is generated according to the device authentication code and the second shared key.

[0143] Optionally, the device further comprises:

[0144] a sixth generating module, configured to generate a first random number;

[0145] The establishment module is configured to:

[0146] The third message authentication code is generated according to the device authentication code, the second shared key and the first random number.

[0147] Optionally, the device further comprises:

[0148] A receiving module, configured to receive a second random number sent by the second terminal after obtaining a fourth message authentication code from the second terminal according to the device verification code;

[0149] The second determination module is configured to determine whether the third message authentication code matches the fourth message authentication code according to the first random number and the second random number.

[0150] Optionally, the device further comprises:

[0151] A second decryption module is configured to decrypt the fourth message authentication code according to the second shared key to obtain the candidate verification code and the candidate random number;

[0152] The second determining module is configured to:

[0153] In a case where the candidate verification code matches the device verification code, and the candidate random number matches the second random number, it is determined that the third message authentication code matches the fourth message authentication code.

[0154] Optionally, the device further comprises:

[0155] a seventh generating module, configured to generate the master key according to the device verification code and the second shared key;

[0156] an encryption module, configured to encrypt the master key according to the device security code to obtain the encrypted device information;

[0157] The fourth sending module is configured to send the encrypted device information to the cloud server.

[0158] According to a fourth aspect of an embodiment of the present disclosure, a communication device is provided, which is applied to a second terminal, and the device includes:

[0159] A first receiving module is configured to receive a target transmission message sent by a first terminal;

[0160] A decryption module is configured to decrypt the target transmission message according to a pre-generated second session key to obtain a target message; the target transmission message is obtained by the first terminal encrypting the target message according to a pre-generated first session key, the first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal.

[0161] Optionally, the target transmission message includes an encrypted message and a first message authentication code; and the first receiving module is configured to:

[0162] The encrypted message and the first message authentication code are received; the encrypted message and the first message authentication code are obtained by encrypting the target message according to the first session key, and the first message authentication code is used to verify the target message.

[0163] Optionally, the device further comprises:

[0164] a first generating module, configured to generate a fifth message authentication code according to the second session key and the target message;

[0165] In case the first message authentication code and the fifth message authentication code do not match, the target message is discarded.

[0166] Optionally, the target transmission message further includes a target identifier, where the target identifier is used to indicate the number of times the first terminal sends the message; and the first receiving module is configured to:

[0167] Receiving the encrypted message, the first message authentication code and the target identifier;

[0168] In the case where the target identifier is the same as a historical identifier, the target message is discarded, and the historical identifier is an identifier in a message received from the first terminal before receiving the target transmission message.

[0169] Optionally, the second session key is generated in the following manner:

[0170] Randomly generate a second public key and a second private key of the second terminal;

[0171] receiving a first public key of the first terminal sent by the first terminal;

[0172] Generate a third shared key according to the first public key and the second private key;

[0173] Obtaining the master key;

[0174] The second session key is generated according to the master key and the third shared key.

[0175] Optionally, the device further comprises:

[0176] A second receiving module is configured to receive a second message authentication code sent by the first terminal;

[0177] A second generating module is configured to generate a sixth message authentication code according to the second session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal;

[0178] a verification module configured to pass the identity authentication of the first terminal if the sixth message authentication code matches the second message authentication code;

[0179] The first receiving module is configured as follows:

[0180] When the identity authentication of the first terminal is passed, a target transmission message sent by the first terminal is received.

[0181] Optionally, the device further comprises:

[0182] An acquisition module is configured to acquire an input device verification code;

[0183] An establishing module, configured to establish a target data channel according to the device verification code;

[0184] The first receiving module is configured as follows:

[0185] The target transmission message is received through the target data channel.

[0186] Optionally, the establishing module is configured to:

[0187] Generate a fourth message authentication code according to the device authentication code;

[0188] Receiving a third message authentication code sent by the first terminal;

[0189] In a case where the third message authentication code matches the fourth message authentication code, the target data channel is established.

[0190] According to a fifth aspect of an embodiment of the present disclosure, there is provided an electronic device, including:

[0191] a memory having a computer program stored thereon;

[0192] A processor is used to execute the computer program in the memory to implement the steps of the method described in the first aspect of the embodiment of the present disclosure.

[0193] According to a sixth aspect of an embodiment of the present disclosure, there is provided an electronic device, including:

[0194] a memory having a computer program stored thereon;

[0195] A processor is used to execute the computer program in the memory to implement the steps of the method described in the second aspect of the embodiment of the present disclosure.

[0196] According to a seventh aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored. When the program instructions are executed by a processor, the steps of the method described in the first aspect of the embodiment of the present disclosure are implemented.

[0197] According to an eighth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored. When the program instructions are executed by a processor, the steps of the method described in the second aspect of the embodiment of the present disclosure are implemented.

[0198] According to a ninth aspect of an embodiment of the present disclosure, a chip is provided, including a processor and an interface; the processor is used to read instructions to execute the method described in the first aspect of the embodiment of the present disclosure.

[0199] According to a tenth aspect of an embodiment of the present disclosure, a chip is provided, comprising a processor and an interface; the processor is used to read instructions to execute the method described in the second aspect of the embodiment of the present disclosure.

[0200] The technical solution provided by the embodiments of the present disclosure may have the following beneficial effects:

[0201] The present disclosure is applied to a first terminal, first determining a target message to be sent, then generating a target transmission message based on a pre-generated first session key and the target message to be sent, and sending the target transmission message to a second terminal. The first session key is generated based on a master key and a first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server based on a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server by the first terminal after encrypting the master key based on the device security code, and the first shared key is generated based on a first private key of the first terminal and a second public key of the second terminal. The present disclosure decrypts the encrypted device information obtained from the cloud server based on a device security code pre-set by a user to obtain a master key, generates a first session key based on the master key, then generates a target transmission message based on the first session key and the target message to be sent, and sends it to the second terminal, which can improve the security of communication between the first terminal and the second terminal.

[0202] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0203] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0204] Figure 1 The figure is a schematic diagram of device interaction according to an exemplary embodiment.

[0205] Figure 2 The present invention is a flow chart showing a communication method according to an exemplary embodiment.

[0206] Figure 3 The figure is a flow chart showing another communication method according to an exemplary embodiment.

[0207] Figure 4 The figure is a flow chart showing another communication method according to an exemplary embodiment.

[0208] Figure 5 The present invention is a flow chart showing a communication method according to an exemplary embodiment.

[0209] Figure 6 The figure is a flow chart showing another communication method according to an exemplary embodiment.

[0210] Figure 7 The figure is a flow chart showing another communication method according to an exemplary embodiment.

[0211] Figure 8 The figure is a flow chart showing another communication method according to an exemplary embodiment.

[0212] Fig. 9 The figure is a flow chart showing another communication method according to an exemplary embodiment.

[0213] Fig.10 The present invention is a flowchart of a method for establishing a secure data channel according to an exemplary embodiment.

[0214] Fig.11 The figure is a flowchart of a two-way authentication according to an exemplary embodiment.

[0215] Fig.12 The present invention is a flowchart of uploading a master key according to an exemplary embodiment.

[0216] Fig.13 The present invention is a flowchart of logging into a smart door lock according to an exemplary embodiment.

[0217] Fig.14 The present invention is a flowchart showing a secure communication according to an exemplary embodiment.

[0218] Fig.15 It is a block diagram of a communication device according to an exemplary embodiment.

[0219] Fig.16 It is a block diagram of another communication device according to an exemplary embodiment.

[0220] Fig.17 It is a block diagram of another communication device according to an exemplary embodiment.

[0221] Fig.18 It is a block diagram of another communication device according to an exemplary embodiment.

[0222] Fig.19 It is a block diagram of another communication device according to an exemplary embodiment.

[0223] Fig. 20It is a block diagram of another communication device according to an exemplary embodiment.

[0224] Fig.21 It is a block diagram of another communication device according to an exemplary embodiment.

[0225] Fig. 22 It is a block diagram of another communication device according to an exemplary embodiment.

[0226] Fig.23 It is a block diagram of another communication device according to an exemplary embodiment.

[0227] Fig.24 It is a block diagram of another communication device according to an exemplary embodiment.

[0228] Fig.25 It is a block diagram of another communication device according to an exemplary embodiment.

[0229] Fig.26 It is a block diagram of another communication device according to an exemplary embodiment.

[0230] Fig. 27 It is a block diagram of another communication device according to an exemplary embodiment.

[0231] Fig.28 It is a block diagram of another communication device according to an exemplary embodiment.

[0232] Fig.29 It is a block diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION

[0233] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0234] It should be noted that all actions of acquiring signals, information or data in the present disclosure are carried out in compliance with the relevant data protection laws and policies of the country where the device is located and with the authorization given by the owner of the corresponding device.

[0235] Before introducing a communication method, device, electronic device, storage medium and chip shown in the embodiments of the present disclosure, the application scenarios of the embodiments of the present disclosure are first introduced.

[0236] In the related art, in order to realize the scenario of multi-terminal control of smart door locks, the server will save the master key of the smart door lock for multi-terminal synchronization. The master key is usually stored directly in the cloud server. When the cloud server is hacked, there may be a risk of key leakage. In addition, a fixed preset key is usually used in the communication process between the client and the smart door lock. Once the preset key is leaked, the communication process is vulnerable to monitoring and the security of the communication process cannot be guaranteed.

[0237] The first terminal and the second terminal in the embodiment of the present disclosure can be mobile terminals such as smart phones, tablet computers, smart TVs, smart watches, PDAs (Personal Digital Assistants), portable computers, etc., and can also be smart home devices, such as sweeping robots, air purifiers, air conditioners, lighting, speakers, robots, etc. The terminal can be connected to any Internet of Things such as NB-IOT, EMTC or MMTC, and can also be connected to Wi-Fi (Wireless Fidelity), Bluetooth, Near Field Communication (NFC), 2G, 3G, 4G, 5G and other mobile communication networks. This disclosure is not limited to this.

[0238] Take the first terminal as the client and the second terminal as the smart door lock as an example. Figure 1 is a device interaction diagram according to an embodiment of the present disclosure, such as Figure 1 As shown, the client 12 can access the cloud server 11 through the wide area network, and establish a secure link channel with the smart door lock 13 through near field communication. The client 12 acts as an intermediary to complete the identity authentication between the smart door lock 13 and the cloud server 11, connect the smart door lock 13 to the Internet of Things platform, and encrypt the master key of the smart door lock 13 and the user information and upload them to the cloud server to complete the binding of the smart door lock 13 and the user account. After logging in to the user account and accessing the cloud server, another client 14 can download the encrypted information of the smart door lock 13. After obtaining the decryption key through the device security code pre-set by the user, the master key of the smart door lock 13 is decrypted, thereby completing multi-terminal communication with the smart door lock 13.

[0239] Figure 2 is a flow chart of a communication method according to an exemplary embodiment. Figure 2 As shown, applied to the first terminal, the method may include the following steps.

[0240] In step S101, a target message to be sent is determined.

[0241] In step S102, a target transmission message is generated according to the pre-generated first session key and the target message to be sent. The first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal.

[0242] In step S103, the target transmission message is sent to the second terminal.

[0243] For example, before the first terminal and the second terminal communicate and interact, the user account can be registered through the target terminal to complete the binding of the user account and the second terminal, and the user account can be logged in on the first terminal to complete the identity authentication of the user account and the second terminal. The target terminal for registering the user account can be the first terminal or other terminals except the first terminal, and this disclosure does not specifically limit this.

[0244] In some embodiments, during the process of registering a user account, the first terminal can generate a master key for the second terminal, encrypt the master key according to the device security code set by the user, obtain encrypted device information, and upload the encrypted device information to the cloud server for the terminal that logs in to the user account to obtain. In this way, even if the server is compromised, the security of the master key can be guaranteed.

[0245] In other embodiments, when the user logs in to the user account on the second terminal, the user may be requested to enter a device security code, and then the encrypted device information is decrypted according to the device security code to obtain the master key.

[0246] In other embodiments, when the user logs in to the user account on the second terminal, a first shared key can also be generated. For example, the first terminal can randomly generate a first public key and a first private key of the first terminal, and send the first public key to the second terminal. And the second public key of the second terminal sent by the second terminal can be received, and then the first shared key is generated by a third preset encryption algorithm according to the first private key of the first terminal and the second public key of the second terminal. Among them, the third preset encryption algorithm can be Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman (ECDHE) key exchange algorithm, etc. Correspondingly, the second terminal can randomly generate a second public key and a second private key of the second terminal, and send the second public key of the second terminal to the first terminal. And the third shared key can be generated by a third preset encryption algorithm according to the first public key of the first terminal and the second private key of the second terminal. It should be noted that the first shared key and the second shared key can be symmetric keys, that is, the first shared key and the second shared key can be the same.

[0247] In other embodiments, the first session key can be generated based on the master key and the first shared key. For example, the master key can be encrypted using the first shared key to obtain an encrypted master key, and then the first session key can be derived through a key derivation function (KDF). Since the corresponding shared key is randomly generated each time a user account is logged in, the session key generated based on the shared key is also randomly generated, rather than a fixed preset key, which avoids the problem of key leakage and message eavesdropping, and improves the security of communication.

[0248] During the communication interaction between the first terminal and the second terminal, the first terminal can determine the target message to be sent, encrypt the target message according to the first session key, obtain the target transmission message, and then send the target transmission message to the second terminal. After receiving the target transmission message, the second terminal can decrypt the target transmission message according to the second session key to obtain the target message. The second session key is generated according to the second shared key and the master key, and the second session key and the first session key can be the same. Since the session key is randomly generated each time you log in, rather than a fixed preset key, the problem of key leakage and message eavesdropping is avoided, which can improve the security of message transmission.

[0249] In other embodiments, the second terminal may determine the target message to be sent, encrypt the target message according to the second session key to obtain the target transmission message, and then send the target transmission message to the first terminal. After receiving the target transmission message, the first terminal may decrypt the target transmission message according to the first session key to obtain the target message. In other words, the first terminal may send a message to the second terminal, or receive a message sent by the second terminal. Similarly, the second terminal may send a message to the first terminal, or the second terminal may receive a message sent by the first terminal.

[0250] In summary, the present disclosure is applied to the first terminal, first determining the target message to be sent, then generating the target transmission message according to the pre-generated first session key and the target message to be sent, and sending the target transmission message to the second terminal. Among them, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal. The present disclosure decrypts the encrypted device information obtained from the cloud server according to the device security code pre-set by the user to obtain the master key, generates the first session key according to the master key, and then generates the target transmission message according to the first session key and the target message to be sent, and sends it to the second terminal, which can improve the security of communication between the first terminal and the second terminal.

[0251] According to some embodiments of the present disclosure, the target transmission message includes an encrypted message and a first message authentication code. Accordingly, one implementation of step S102 may be:

[0252] The target message to be sent is encrypted according to the first session key to obtain an encrypted message and a first message authentication code.

[0253] Accordingly, one implementation of step S103 may be:

[0254] The encrypted message and the first message authentication code are sent to the second terminal, and the first message authentication code is used to verify the target message.

[0255] For example, the first terminal can use the first session key to encrypt the target message through the first preset encryption algorithm to obtain an encrypted message and a first message authentication code. The first preset encryption algorithm can be, for example, the AES128-CCM algorithm. Accordingly, after receiving the encrypted message and the first message authentication code, the second terminal can decrypt the encrypted message according to the second session key to obtain the target message, and can verify the target message according to the first message authentication code. If the verification is successful, the target message can be retained. If the verification fails, it means that the target message has been tampered with, and the target message can be discarded. In this way, tampering attacks on the target message can be prevented, and the security and accuracy of communication can be improved.

[0256] In some embodiments, after decrypting and obtaining the target message, the second terminal can encrypt the target message according to the second session key to obtain the fifth message authentication code. Since the second session key and the first session key are equal, the first message authentication code and the fifth message authentication code are equal if the target message has not been tampered with. If the first message authentication code and the fifth message authentication code are equal, it means that the target message has not been tampered with, and it can be determined that the target message verification is successful. If the first message authentication code and the fifth message authentication code are not equal, it means that the target message has been tampered with, and it can be determined that the target message verification has failed.

[0257] In a possible implementation, the second session key can be generated based on the master key and the second shared key. For example, the second terminal can obtain the stored master key locally, encrypt the master key with the second shared key to obtain an encrypted master key, and then derive the second session key through a key derivation function (KDF). The second session key and the first session key can be the same.

[0258] Figure 3 is a flow chart of another communication method according to an exemplary embodiment. Figure 3 As shown, the method may further include the following steps.

[0259] In step S104, a target identifier generated by a preset counter is obtained.

[0260] Accordingly, another implementation of step S103 may be:

[0261] The encrypted message, the first message authentication code and the target identifier are sent to the second terminal.

[0262] For example, the target transmission message may further include a target identifier. The first terminal may maintain a preset counter, and the target identifier generated by the preset counter may be used to represent the number of times the first terminal sends a message. For example, the identifier generated by the preset counter may be a number that increases in sequence, and before each message is sent, the number generated by the preset counter may be increased by one.

[0263] After receiving the encrypted message, the first message authentication code and the target identifier sent by the first terminal, the second terminal can determine the relationship between the target identifier and the historical identifier, wherein the historical identifier is an identifier in the message received from the first terminal before receiving the target transmission message. If the target identifier is different from the historical identifier, the target message can be retained. If the target identifier is the same as the historical identifier, indicating that the target message is a replayed message, the target message can be discarded to prevent a message replay attack. Taking the historical identifiers including 1, 2, and 3 as an example, if the target identifier is any one of 1, 2, and 3, the target message can be discarded, and if the target identifier is 4, the target message can be retained.

[0264] For example, after a user logs in to a user account on a first terminal and a communication connection is established between the first terminal and a second terminal, identity authentication may be performed between the first terminal and the second terminal.

[0265] In some embodiments, the first terminal may obtain the encrypted device information from the cloud server, and generate the first session key according to the encrypted device information and the first shared key. The encrypted device information includes a master key encrypted using a device security code. For example, the master key may be encrypted using the first shared key to obtain an encrypted master key, and then the first session key may be derived using a key derivation function.

[0266] In other embodiments, the first terminal may request the user to input a device security code, and then decrypt the encrypted device information according to the device security code to obtain the master key. For example, the first terminal may generate a message digest using a second preset encryption algorithm for the device security code, and decrypt the encrypted device information using the message digest as a decryption key to obtain the master key. The second preset encryption algorithm may be an algorithm such as HASH or MD5.

[0267] In other embodiments, the first shared key is generated in the following manner: first, a first public key and a first private key of the first terminal are randomly generated, and the first public key is sent to the second terminal. And the second public key of the second terminal sent by the second terminal can be received, and then the first shared key is generated by a third preset encryption algorithm according to the first private key of the first terminal and the second public key of the second terminal. Among them, the third preset encryption algorithm can be Diffie-Hellman or elliptic curve Diffie-Hellman key exchange algorithm, etc. Correspondingly, the second terminal can randomly generate the second public key and the second private key of the second terminal, and send the second public key of the second terminal to the first terminal. And the third shared key can be generated by a third preset encryption algorithm according to the first public key of the first terminal and the second private key of the second terminal. It should be noted that the first shared key and the second shared key can be symmetric keys, that is, the first shared key and the second shared key can be the same.

[0268] Since a corresponding shared key is randomly generated each time a user logs into a user account, the session key generated based on the shared key is also randomly generated rather than a fixed preset key, thus avoiding the problem of key leakage and message eavesdropping and improving the security of communication.

[0269] In other embodiments, the first terminal may generate a second message authentication code based on the first session key and preset shared information, and send the second message authentication code to the second terminal. The preset shared information is information shared by the first terminal and the second terminal, for example, it may be a MAC (English: Media Access Control Address, Chinese: Media Access Control) address, IP (English: Internet Protocol Address, Chinese: Internet Protocol) address, device ID (Identification), etc. sent by the second terminal to the first terminal when the first terminal and the second terminal establish a communication connection. Correspondingly, the second terminal may also generate a sixth message authentication code based on the second session key and the preset shared information, and authenticate the first terminal based on the second message authentication code. If the identity authentication is passed, the first terminal may execute step S101.

[0270] In a possible implementation, since the first session key and the second session key are the same, the second message authentication code generated by the first terminal according to the first session key and the preset shared information and the sixth message authentication code generated by the second terminal according to the second session key and the preset shared information should also be the same. Therefore, when the sixth message authentication code and the second message authentication code are the same, it can be considered that the sixth message authentication code and the second message authentication code match, and when the sixth message authentication code and the second message authentication code are different, it can be considered that the sixth message authentication code and the second message authentication code do not match. If the sixth message authentication code and the second message authentication code match, the identity authentication of the first terminal can be passed, and if the sixth message authentication code and the second message authentication code do not match, the identity authentication of the first terminal may not be passed.

[0271] For example, after the first terminal completes identity authentication and establishes a secure connection with the cloud server, it can register on the second terminal to establish a secure target data channel to transmit data with the second terminal through the target data channel.

[0272] First, the first terminal can establish a near field communication connection with the second terminal, and the specific connection method includes but is not limited to Bluetooth, Wifi (English: Wireless Fidelity, Chinese: Wireless Fidelity), Zigbee, Thread, etc. Then the first terminal can randomly generate a device verification code, establish a target data channel according to the device verification code, and send the target transmission message to the second terminal through the target data channel.

[0273] In some embodiments, a third message authentication code may be generated based on the device authentication code, and a fourth message authentication code sent by the second terminal may be received, wherein the fourth message authentication code is generated by the second terminal based on the input device authentication code. If the third message authentication code and the fourth message authentication code match, a target data channel may be established.

[0274] For example, the first terminal and the second terminal may exchange device verification codes in a manner other than near field communication connection, and specific methods include but are not limited to NFC (English: Near Field Communication, Chinese: Near Field Communication), QR code scanning, keyboard input of numbers, etc. Taking the QR code scanning method as an example, the first terminal may randomly generate a QR code as a device verification code, and the second terminal may obtain the device verification code by scanning the QR code. Taking the keyboard input of numbers as an example, the first terminal may randomly generate a target random number as a device verification code, and the user may enter the target random number into the second terminal through the keyboard of the second terminal, so that the second terminal may obtain the device verification code. In this way, by randomly generating a device verification code, and by exchanging device verification codes between the first terminal and the second terminal in a manner other than near field communication connection, it is possible to ensure that the device verification code is not obtained by an attacker, thereby improving the security of the established target data channel.

[0275] In some other embodiments, the third message authentication code may be obtained in the following manner:

[0276] First, the third public key and the third private key of the first terminal can be randomly generated, and then the third public key can be sent to the second terminal, and the fourth public key sent by the second terminal can be received, and then the second shared key can be generated according to the third private key and the fourth public key through the third preset encryption algorithm. Among them, the third preset encryption algorithm can be Diffie-Hellman or elliptic curve Diffie-Hellman key exchange algorithm, etc. Further, the third message authentication code can be generated according to the device verification code and the second shared key.

[0277] Correspondingly, the fourth message authentication code can be obtained in the following manner: the second terminal can generate a fourth public key and a fourth private key of the second terminal, and then send the fourth public key to the first terminal, and receive the fourth public key sent by the first terminal, and then generate a fourth shared key according to the fourth private key and the third public key through a third preset encryption algorithm. Further, the fourth message authentication code can be generated according to the device verification code and the fourth shared key.

[0278] In some other embodiments, the first terminal may also generate a first random number, and then generate a third message authentication code according to the device verification code, the second shared key and the first random number. Correspondingly, the second terminal may also generate a second random number, and then generate a fourth message authentication code according to the device verification code, the fourth shared key and the second random number.

[0279] In some other embodiments, the first terminal and the second terminal may first exchange the third message authentication code and the fourth message authentication code, and then exchange the first random number and the second random number. Through the random challenge method, the third message authentication code and the fourth message authentication code, as well as the first random number and the second random number, can authenticate the identity of the other end.

[0280] In one possible implementation, the first terminal may decrypt the received fourth message authentication code according to the second shared key to obtain a candidate verification code and a candidate random number. When the candidate verification code matches the device verification code, and the candidate random number matches the second random number, it can be determined that the third message authentication code matches the fourth message authentication code. In the following three cases, it can be determined that the third message authentication code matches the fourth message authentication code. Case 1: The candidate verification code and the device verification code do not match, and the candidate random number and the second random number match; Case 2: The candidate verification code and the device verification code match, and the candidate random number and the second random number do not match; Case 3: The candidate verification code and the device verification code do not match, and the candidate random number and the second random number do not match.

[0281] If the third message authentication code and the fourth message authentication code match, it means that the first terminal and the second terminal have the same shared key (that is, the second shared key and the fourth shared key are the same) and the device verification code, then a target data channel can be established between the first terminal and the second terminal, thereby ensuring the security of the target security channel.

[0282] For example, after the target secure channel is established, two-way authentication can be performed between the second terminal and the cloud server. The second terminal can obtain the device certificate chain of the second terminal in advance, for example, by using a security chip, and writing the manufacturer certificate, device certificate, and device private key into the security chip in a factory trusted environment. The security chip has a hardware encryption and decryption module, which completes calculations that require the device private key inside the chip and ensures that the device private key cannot be read.

[0283] The first terminal can apply for a third random number from the cloud server and send it to the second terminal through the target data channel, wherein the third random number can be set with an expiration time to ensure the security of the authentication process. After receiving the third random number, the second terminal can perform a hash calculation on the third random number and use the device private key of the second terminal to generate the first signature information, and then send the device certificate chain and signature information to the cloud server.

[0284] The cloud server can verify the device certificate chain based on the root certificate, and use the public key in the device certificate to verify the first signature information. If the verification is successful, the first signature information can be used as a random number for hash calculation, and the cloud server's private key can be used to generate the second signature information. The cloud server certificate chain and the second signature information are then sent to the second terminal. The second terminal can use the root certificate to verify the cloud server certificate chain and verify the second signature information. After the verification is successful, the two-way authentication between the second terminal and the cloud server is completed. The present disclosure does not limit the source of the signature data in the above-mentioned two-way authentication process, as long as the data used for each authentication is consistent.

[0285] Figure 4 is a flow chart of another communication method according to an exemplary embodiment. Figure 4 As shown, the method also includes:

[0286] In step S105, a master key is generated according to the device verification code and the second shared key.

[0287] In step S106, the master key is encrypted according to the device security code to obtain encrypted device information.

[0288] In step S107, the encrypted device information is sent to the cloud server.

[0289] For example, after completing the two-way authentication between the second terminal and the cloud server, the master key can be derived using the key derivation function (KDF), and the device verification code can be used as the salt of the KDF algorithm to enhance the security of the master key. The first terminal can then request the user to enter the device security code, where the device security code can be numbers, letters, QR codes, fingerprints, face data, etc. Then, a message digest can be generated for the device security code using a second preset encryption algorithm, and the message digest can be used as an encryption key to encrypt the master key to obtain encrypted device information, and then the encrypted device information can be further uploaded to the cloud server for acquisition on the terminal of the logged-in user account. In this way, by encrypting the master key using the device security code and storing the encrypted device information obtained after encryption on the cloud server, the security of the master key can be guaranteed even if the server is compromised. The second terminal can encrypt the master key using a fourth preset encryption algorithm and store it locally.

[0290] In summary, the present disclosure is applied to the first terminal, first determining the target message to be sent, then generating the target transmission message according to the pre-generated first session key and the target message to be sent, and sending the target transmission message to the second terminal. Among them, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal. The present disclosure decrypts the encrypted device information obtained from the cloud server according to the device security code pre-set by the user to obtain the master key, generates the first session key according to the master key, and then generates the target transmission message according to the first session key and the target message to be sent, and sends it to the second terminal, which can improve the security of communication between the first terminal and the second terminal.

[0291] Figure 5is a flow chart of a communication method according to an exemplary embodiment. Figure 5 As shown, applied to the second terminal, the method may include the following steps.

[0292] In step S201, a target transmission message sent by a first terminal is received.

[0293] In step S202, the target transmission message is decrypted according to the pre-generated second session key to obtain the target message. The target transmission message is obtained by the first terminal encrypting the target message according to the pre-generated first session key, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal.

[0294] For example, before the second terminal and the first terminal communicate and interact, a user account can be registered first to complete the binding of the user account and the second terminal, and the user account can be logged in on the first terminal to complete the identity verification of the user account and the second terminal. The terminal for registering the user account can be the first terminal or not.

[0295] In some embodiments, during the process of registering a user account, the master key of the second terminal can be encrypted according to the device security code set by the user to obtain encrypted device information, and the encrypted device information is uploaded to the cloud server for acquisition by the terminal that logs in to the user account. In this way, even if the server is compromised, the security of the master key can be guaranteed.

[0296] In other embodiments, when the user logs in to the user account on the second terminal, the user may be requested to enter a device security code, and then the encrypted device information is decrypted according to the device security code to obtain the master key.

[0297] In other embodiments, when the user logs in to the user account on the second terminal, a first shared key can also be generated. For example, the first terminal can randomly generate a first public key and a first private key of the first terminal, and send the first public key to the second terminal. And the second public key of the second terminal sent by the second terminal can be received, and then the first shared key is generated by a third preset encryption algorithm according to the first private key of the first terminal and the second public key of the second terminal. Among them, the third preset encryption algorithm can be Diffie-Hellman or elliptic curve Diffie-Hellman key exchange algorithm, etc. Correspondingly, the second terminal can randomly generate a second public key and a second private key of the second terminal, and send the second public key of the second terminal to the first terminal. And the third shared key can be generated by a third preset encryption algorithm according to the first public key of the first terminal and the second private key of the second terminal. It should be noted that the first shared key and the second shared key can be symmetric keys, that is, the first shared key and the second shared key can be the same.

[0298] In other embodiments, the first session key can be generated according to the master key and the first shared key. For example, the master key can be encrypted using the first shared key to obtain an encrypted master key, and then the first session key can be derived through a key derivation function. Since the corresponding shared key is randomly generated each time a user account is logged in, the session key generated according to the shared key is also randomly generated, rather than a fixed preset key, which avoids the problem of key leakage and message eavesdropping, and improves the security of communication.

[0299] During the communication interaction between the first terminal and the second terminal, the first terminal can determine the target message to be sent, encrypt the target message according to the first session key, obtain the target transmission message, and then send the target transmission message to the second terminal. After receiving the target transmission message, the second terminal can decrypt the target transmission message according to the second session key to obtain the target message. The second session key is generated according to the second shared key and the master key, and the second session key and the first session key can be the same. Since the session key is randomly generated each time you log in, rather than a fixed preset key, the problem of key leakage and message eavesdropping is avoided, which can improve the security of message transmission.

[0300] According to some embodiments of the present disclosure, the target transmission message includes an encrypted message and a first message authentication code. Accordingly, one implementation of step S201 may be:

[0301] An encrypted message and a first message authentication code are received. The encrypted message and the first message authentication code are obtained by encrypting a target message according to a first session key, and the first message authentication code is used to verify the target message.

[0302] Figure 6is a flow chart of another communication method according to an exemplary embodiment. Figure 6 As shown, the method also includes:

[0303] In step S203, a fifth message authentication code is generated according to the second session key and the target message.

[0304] In step S204, when the first message authentication code and the fifth message authentication code do not match, the target message is discarded.

[0305] For example, the first terminal can use the first session key to encrypt the target message through the first preset encryption algorithm to obtain an encrypted message and a first message authentication code. The first preset encryption algorithm can be, for example, the AES128-CCM algorithm. Accordingly, after receiving the encrypted message and the first message authentication code, the second terminal can decrypt the encrypted message according to the second session key to obtain the target message, and can verify the target message according to the first message authentication code. If the verification is successful, the target message can be retained. If the verification fails, it means that the target message has been tampered with, and the target message can be discarded. In this way, tampering attacks on the target message can be prevented, and the security and accuracy of communication can be improved.

[0306] In some embodiments, after decrypting and obtaining the target message, the second terminal can encrypt the target message according to the second session key to obtain the fifth message authentication code. Since the second session key and the first session key are equal, the first message authentication code and the fifth message authentication code are equal if the target message has not been tampered with. If the first message authentication code and the fifth message authentication code are equal, it means that the target message has not been tampered with, and it can be determined that the target message verification is successful. If the first message authentication code and the fifth message authentication code are not equal, it means that the target message has been tampered with, and it can be determined that the target message verification has failed.

[0307] Figure 7 is a flow chart of another communication method according to an exemplary embodiment. Figure 7 As shown, step S201 can also be implemented in the following manner:

[0308] In step S2011, an encrypted message, a first message authentication code and a target identifier are received.

[0309] In step S2012, when the target identifier is the same as the historical identifier, the target message is discarded, and the historical identifier is an identifier in a message received from the first terminal before receiving the target transmission message.

[0310] For example, the target transmission message may further include a target identifier. The first terminal may maintain a preset counter, and the target identifier generated by the preset counter may be used to represent the number of times the first terminal sends a message. For example, the identifier generated by the preset counter may be a number that increases in sequence, and before each message is sent, the number generated by the preset counter may be increased by one.

[0311] After receiving the encrypted message, the first message authentication code and the target identifier sent by the first terminal, the second terminal can determine the relationship between the target identifier and the historical identifier, wherein the historical identifier is an identifier in the message received from the first terminal before receiving the target transmission message. If the target identifier is different from the historical identifier, the target message can be retained. If the target identifier is the same as the historical identifier, indicating that the target message is a replayed message, the target message can be discarded to prevent a message replay attack. Taking the historical identifiers including 1, 2, and 3 as an example, if the target identifier is any one of 1, 2, and 3, the target message can be discarded, and if the target identifier is 4, the target message can be retained.

[0312] In other embodiments, the second session key may be generated based on the master key and the second shared key. For example, the second terminal may obtain the stored master key locally, encrypt the master key using the second shared key to obtain an encrypted master key, and then derive the second session key through a key derivation function. The second session key and the first session key may be the same.

[0313] Figure 8 is a flow chart of another communication method according to an exemplary embodiment. Figure 8 As shown, the method may also include:

[0314] In step S205, a second message authentication code sent by the first terminal is received.

[0315] In step S206, a sixth message authentication code is generated according to the second session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal.

[0316] In step S207, when the sixth message authentication code and the second message authentication code match, the identity authentication of the first terminal is passed.

[0317] Accordingly, one implementation of step S201 may be:

[0318] When the identity authentication of the first terminal is passed, a target transmission message sent by the first terminal is received.

[0319] In other embodiments, the first terminal may generate a second message authentication code based on the first session key and preset shared information, and send the second message authentication code to the second terminal. The preset shared information is information shared by the first terminal and the second terminal, for example, the MAC address, IP address, device ID, etc. sent by the second terminal to the first terminal when the first terminal and the second terminal establish a communication connection. Correspondingly, the second terminal may also generate a sixth message authentication code based on the second session key and the preset shared information, and authenticate the first terminal based on the second message authentication code, and execute step S201 if the authentication is successful.

[0320] In a possible implementation, since the first session key and the second session key are the same, the second message authentication code generated by the first terminal according to the first session key and the preset shared information, and the sixth message authentication code generated by the second terminal according to the second session key and the preset shared information should also be the same. Therefore, when the sixth message authentication code and the second message authentication code are the same, it can be considered that the sixth message authentication code and the second message authentication code match, and when the sixth message authentication code and the second message authentication code are different, it can be considered that the sixth message authentication code and the second message authentication code do not match. If the sixth message authentication code and the second message authentication code match, the identity authentication of the first terminal can be passed, and if the sixth message authentication code and the second message authentication code do not match, the identity authentication of the first terminal may not be passed.

[0321] Fig. 9 is a flow chart of another communication method according to an exemplary embodiment. Fig. 9 As shown, the method may also include:

[0322] In step S208, the input device verification code is obtained.

[0323] In step S209, a target data channel is established according to the device verification code.

[0324] Accordingly, one implementation of step S201 may be:

[0325] Receive target transmission messages through the target data channel.

[0326] In some embodiments, step S209 may be implemented by the following steps:

[0327] A fourth message authentication code is generated according to the device authentication code.

[0328] Receive a third message authentication code sent by the first terminal.

[0329] When the third message authentication code matches the fourth message authentication code, a target data channel is established.

[0330] For example, after the first terminal completes identity authentication and establishes a secure connection with the cloud server, it can register on the second terminal to establish a secure target data channel to transmit data with the second terminal through the target data channel.

[0331] First, the first terminal can establish a near field communication connection with the second terminal, and the specific connection method includes but is not limited to Bluetooth, Wifi, Zigbee, Thread, etc. Then the first terminal can randomly generate a device verification code, establish a target data channel according to the device verification code, and send the target transmission message to the second terminal through the target data channel.

[0332] In some embodiments, a third message authentication code may be generated based on the device authentication code, and a fourth message authentication code sent by the second terminal may be received, wherein the fourth message authentication code is generated by the second terminal based on the input device authentication code. If the third message authentication code and the fourth message authentication code match, a target data channel may be established.

[0333] For example, the first terminal and the second terminal may exchange device verification codes in a manner other than near field communication connection, and specific methods include but are not limited to NFC, QR code scanning, keyboard input of numbers, etc. Taking the QR code scanning method as an example, the first terminal may randomly generate a QR code as a device verification code, and the second terminal may obtain the device verification code by scanning the QR code. Taking the keyboard input of numbers as an example, the first terminal may randomly generate a target random number as a device verification code, and the user may enter the target random number into the second terminal through the keyboard of the second terminal, so that the second terminal may obtain the device verification code. In this way, by randomly generating a device verification code, and by exchanging device verification codes between the first terminal and the second terminal in a manner other than near field communication connection, it is possible to ensure that the device verification code is not obtained by an attacker, thereby improving the security of the established target data channel.

[0334] In summary, the present disclosure is applied to the first terminal, first determining the target message to be sent, then generating the target transmission message according to the pre-generated first session key and the target message to be sent, and sending the target transmission message to the second terminal. Among them, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal. The present disclosure decrypts the encrypted device information obtained from the cloud server according to the device security code pre-set by the user to obtain the master key, generates the first session key according to the master key, and then generates the target transmission message according to the first session key and the target message to be sent, and sends it to the second terminal, which can improve the security of communication between the first terminal and the second terminal.

[0335] A specific embodiment is given below by taking the first terminal as a client and the second terminal as a smart door lock as an example.

[0336] Step 1: Establish a secure data channel.

[0337] Reference Fig.10 , a secure data channel can be established between the client and the smart door lock through steps a to f.

[0338] a. Before the authentication process of the smart door lock begins, the client and the cloud can first complete identity authentication and establish a secure connection (such as https connection) to access the IoT cloud service through the wide area network.

[0339] b. The smart door lock enters the network configuration mode and sends out a broadcast of unconfigured network to the surrounding area. The broadcast includes the unique identification code of the smart door lock. The device identification code may include at least one of the MAC address, IP address, and device ID of the smart door lock. The client can obtain the basic identity information of the device based on the device identification code.

[0340] c. The client and the smart door lock establish a connection through near-field communication. The specific connection methods include but are not limited to Bluetooth, Wifi, Zigbee, Thread, etc.

[0341] d. The client and the smart door lock exchange "out-of-band data" (OOB) in a way other than near-field communication. Specific methods include but are not limited to NFC, QR code scanning, keyboard input, etc. To ensure that OOB is not obtained by attackers, each authentication needs to be randomly generated.

[0342] e. The client and the smart door lock generate a public and private key pair respectively, send their own public keys to each other, and use the Diffie-Hellman or elliptic curve Diffie-Hellman key exchange algorithm to calculate the shared key.

[0343] f. The client and the smart door lock each generate a set of random numbers, and combine OOB with HMAC (English: Hash-based Message Authentication Code, Chinese: Hash Operation Message Authentication Code) and other algorithms, and use the shared key to generate a message authentication code. After that, the client and the smart door lock first exchange message authentication codes and then exchange random numbers, and verify that both parties have the same shared key and OOB information through random challenges.

[0344] The smart door lock in this example supports Bluetooth communication and has a numeric keypad. First, the client establishes a Bluetooth connection with the door lock by scanning the unprovisioned network broadcast of the door lock. Then the client generates a random 6-digit pairing code as OOB, and the smart door lock uses the keyboard to enter the pairing code. Next, the client and the smart door lock exchange keys through Bluetooth communication and use OOB and random numbers to complete the random challenge.

[0345] Step 2: Two-way authentication between smart door lock and cloud.

[0346] a. Before authentication begins, the smart door lock needs to obtain the certificate chain issued by the IoT root server. Common methods include using a security chip to write the manufacturer certificate, device certificate, and device private key into the security chip in a factory trusted environment. The security chip has a hardware encryption and decryption module that completes calculations that require the device private key inside the chip and ensures that the device private key cannot be read.

[0347] b. The client requests a set of random numbers from the cloud server and sends them to the smart door lock through the secure channel established in step 1. The random number needs to have an expiration time set, after which the cloud server will not respond to subsequent authentication processes.

[0348] c. The smart door lock performs hash calculation on the random number and generates signature information using the device private key. The smart door lock transfers the device certificate chain and device signature to the cloud through the client. The cloud uses the root certificate to verify the device certificate chain and uses the public key in the device certificate to verify the device signature.

[0349] d. After the cloud verification is successful, the device signature is used as a random number for hash calculation, and the cloud server private key is used to generate signature information. The cloud server certificate and signature are sent to the smart door lock through the client. The smart door lock also uses the root certificate to verify the cloud server certificate chain and verify the cloud signature. After the verification is successful, the two-way authentication is completed.

[0350] In the above process, there is no restriction on the source of the signature data, as long as the data used in each authentication is guaranteed to be consistent.

[0351] In some possible implementations, refer to Fig.11 ,The smart door lock reads the certificate chain cert_dev from the security chip, which may contain multiple levels of certificates, with the intermediate level indicated by “ca…”.,The client acts as an intermediary and requests a random number from the cloud, and sends the random number to the smart door lock through the Bluetooth channel.

[0352] The smart door lock calls the signature instruction of the security chip, uses the device private key to sign the hash value of the random number to obtain sign_dev, and then transparently transmits the device certificate chain and device signature to the cloud. The cloud first uses the only trusted root root to verify the device certificate chain step by step. After the verification is successful, the device public key pub_dev is taken out from the device certificate. The cloud then uses the same algorithm to obtain the hash value of the random number and uses the device public key to verify the device signature.

[0353] After the cloud signature verification is successful, the cloud server's private key is used to sign the random number to obtain sign_cloud, and the cloud server certificate and signature are transparently transmitted to the smart door lock. The smart door lock also uses the unique trust root to verify the cloud server certificate chain step by step, and takes out the cloud server public key pub_cloud to verify the cloud server signature. After the signature verification is passed, the two-way authentication between the smart door lock and the cloud is completed.

[0354] Step 3: Encrypt and upload the device master key.

[0355] a. The client and the smart door lock use the key derivation function (KDF) to derive the device master key from the shared key generated in step 1. The first set of "out-of-band data" can be used as the salt of the KDF algorithm to enhance security.

[0356] b. The client requests the user to enter a second set of "out-of-band data" (OOB), which can be numbers, letters, QR codes, fingerprints, face data, etc. Use algorithms such as HASH and MD (English: Message-Digest Algorithm, Chinese: Information Digest) 5 to generate a message digest as the encryption key for the device master key.

[0357] c. The client encrypts the master key using the key derived from the second set of "out-of-band data" and uploads it to the cloud. The device encrypts the master key using an algorithm and places it in its secure storage area.

[0358] After the above process is completed, the device registration process is completed and the smart door lock is bound to the user account.

[0359] In some possible implementations, refer to Fig.12, the smart door lock and the client use the "HMAC-based key derivation function" (HKDF), use the first OOB as the "salt" and eShareKey as the input key to derive the device master key LTMK. After that, the client requests the user to enter the "device security code" as the second OOB, uses the hash value of the OOB as the encryption key, and stores the encrypted device master key encrypt_ltmk in the cloud. At the same time, the smart door lock encrypts the master key through the established encryption algorithm and saves it locally. The cloud completes the binding operation between the smart door lock and the user's device, and the device registration process is completed.

[0360] Step 4: Log in to the smart door lock through multi-terminal authentication.

[0361] a. The client logs in to the user account, completes identity authentication and establishes a secure connection. At the same time, the client establishes a near-field connection with the smart door lock.

[0362] b. The client pulls the encrypted device information from the cloud and requests the user to enter a second set of "out-of-band data". A message digest is generated using algorithms such as HASH and MD5, which is used as the decryption key to decrypt the device master key.

[0363] c. The client and the smart door lock generate a public-private key pair respectively, send their own public keys to each other, and use the Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman (ECDHE) key exchange algorithm to calculate the shared key. After combining the shared key with the device master key, the key derivation function (KDF) is used to derive the session key. Because the shared key for each key exchange is different, the uniqueness of the session key can be guaranteed.

[0364] d. The client uses the session key to generate a message authentication code for the public information of both parties and sends it to the smart door lock. After the smart door lock successfully verifies using the session key, the login process is completed.

[0365] The client in this step can be the client used to register the device in steps 1 to 3, or it can be the client of one or more other logged-in user accounts. When logging in to the smart door lock, it is necessary to obtain the cloud encryption information and the second set of "out-of-band data" to obtain the real device master key.

[0366] In some possible implementations, refer to Fig.13, the client logs in to the user account and establishes a Bluetooth connection with the smart door lock. Then it requests the device key from the server and asks the user to enter a 6-digit "device security code" as the second set of OOB, and uses the hash value of OOB as the decryption key to obtain the device master key LTMK. After that, the client and the smart door lock calculate the shared key eShareKey through the Elliptic Curve Diffie-Hellman (ECDHE) key exchange algorithm, and use the "HMAC-based key derivation function" (HKDF) to derive the session key session_key from eShareKey+LTMK. Finally, the client uses the session key to encrypt the shared information of both parties using the aes128-ccm algorithm, and obtains the message authentication code (Message Authentication Code, MIC) and sends it to the smart door lock. The smart door lock completes the login process after successful verification using the session key.

[0367] Step 5: The smart door lock communicates securely with the client.

[0368] a. The client and the door lock each maintain a counter (Frame Cnt), which is incremented by one before each message is sent. When receiving, it determines whether the counter of the other party's message is monotonically increasing, and refuses to process messages that are less than or equal to the currently saved count value. This operation can prevent replay attacks on current and past messages.

[0369] b. The sender encrypts the message using the session key and generates a message authentication code. A counter can be used as a one-time number (nonce) in the encryption algorithm. This method can prevent attackers from tampering with the message.

[0370] In some possible implementations, refer to Fig.14 Each message sent between the smart door lock and the client is accompanied by a message counter. When a replay attack occurs, the message will be discarded. At the same time, the session key is used to encrypt the message with the aes128-ccm algorithm and obtain the message authentication code MIC. Because the attacker cannot obtain the session key, when a message tampering attack occurs, the MIC value does not match and the message is discarded. The format of the message can be shown in Table 1.

[0371] domain Frame Cnt Encrypt Data MIC length 4 bytes Lengthening 4 bytes

[0372] Table 1

[0373] Fig.15 is a block diagram of a communication device according to an exemplary embodiment. Fig.15 As shown, applied to a first terminal, the device 300 may include:

[0374] The first determining module 301 is configured to determine a target message to be sent.

[0375] The first generating module 302 is configured to generate a target transmission message according to a pre-generated first session key and a target message to be sent. The first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal.

[0376] The first sending module 303 is configured to send the target transmission message to the second terminal.

[0377] In some embodiments, the target transmission message includes an encrypted message and a first message authentication code. The first generation module 302 is configured to:

[0378] The target message to be sent is encrypted according to the first session key to obtain an encrypted message and a first message authentication code.

[0379] The first sending module 303 is configured as follows:

[0380] The encrypted message and the first message authentication code are sent to the second terminal, and the first message authentication code is used to verify the target message.

[0381] Fig.16 is a block diagram of another communication device according to an exemplary embodiment. Fig.16 As shown, the target transmission message also includes a target identifier, and the target identifier is used to indicate the number of times the first terminal sends the message. The device 300 also includes:

[0382] The first acquisition module 304 is configured to acquire a target identifier generated by a preset counter.

[0383] The first sending module 303 is configured as follows:

[0384] The encrypted message, the first message authentication code and the target identifier are sent to the second terminal.

[0385] In some other embodiments, the first session key is generated by:

[0386] The encrypted device information is obtained from the cloud server, where the encrypted device information includes a master key encrypted using the device security code.

[0387] A first session key is generated based on the encrypted device information and the first shared key.

[0388] In some other embodiments, the first shared key is generated by:

[0389] A first public key and a first private key of the first terminal are randomly generated.

[0390] A second public key of the second terminal sent by the second terminal is received.

[0391] A first shared key is generated according to the first private key and the second public key.

[0392] Fig.17 is a block diagram of another communication device according to an exemplary embodiment. Fig.17 As shown, the device 300 also includes:

[0393] The second acquisition module 305 is configured to acquire a device security code.

[0394] The first decryption module 306 is configured to decrypt the encrypted device information according to the device security code to obtain a master key.

[0395] The first generating module 302 is configured to:

[0396] A first session key is generated based on the master key and the first shared key.

[0397] Fig.18 is a block diagram of another communication device according to an exemplary embodiment. Fig.18 As shown, the device 300 also includes:

[0398] The second generating module 307 is configured to generate a second message authentication code according to the first session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal.

[0399] The second sending module 308 is configured to send the second message authentication code to the second terminal, so that the second terminal performs identity authentication on the first terminal according to the second message authentication code.

[0400] The first determining module 301 is configured to:

[0401] When the identity authentication is successful, the target message to be sent is determined.

[0402] Fig.19 is a block diagram of another communication device according to an exemplary embodiment. Fig.19 As shown, the device 300 also includes:

[0403] The third generating module 309 is configured to randomly generate a device verification code.

[0404] The establishing module 310 is configured to establish a target data channel according to the device verification code.

[0405] The first sending module 303 is configured as follows:

[0406] The target transmission message is sent to the second terminal through the target data channel.

[0407] In some other embodiments, the establishing module 310 is configured to:

[0408] A third message authentication code is generated according to the device authentication code.

[0409] According to the device verification code, a fourth message authentication code is obtained from the second terminal.

[0410] When the third message authentication code matches the fourth message authentication code, a target data channel is established.

[0411] In some other embodiments, the establishing module 310 is configured to:

[0412] A fourth message authentication code is received from the second terminal, where the fourth message authentication code is generated by the second terminal according to the input device authentication code.

[0413] Fig. 20 is a block diagram of another communication device according to an exemplary embodiment. Fig. 20 As shown, the device 300 also includes:

[0414] The fourth generating module 311 is configured to randomly generate a third public key and a third private key of the first terminal.

[0415] The third sending module 312 is configured to send the third public key to the second terminal, and receive the fourth public key sent by the second terminal.

[0416] The fifth generating module 313 is configured to generate a second shared key according to the third private key and the fourth public key.

[0417] The establishment module 310 is configured to:

[0418] A third message authentication code is generated according to the device authentication code and the second shared key.

[0419] Fig.21 is a block diagram of another communication device according to an exemplary embodiment. Fig.21 As shown, the device 300 also includes:

[0420] The sixth generating module 314 is configured to generate a first random number.

[0421] The establishment module 310 is configured to:

[0422] A third message authentication code is generated according to the device authentication code, the second shared key and the first random number.

[0423] Fig. 22is a block diagram of another communication device according to an exemplary embodiment. Fig. 22 As shown, the device 300 also includes:

[0424] The receiving module 315 is configured to receive a second random number sent by the second terminal after acquiring the fourth message authentication code from the second terminal according to the device verification code.

[0425] The second determination module 316 is configured to determine whether the third message authentication code matches the fourth message authentication code according to the first random number and the second random number.

[0426] Fig.23 is a block diagram of another communication device according to an exemplary embodiment. Fig.23 As shown, the device 300 also includes:

[0427] The second decryption module 317 is configured to decrypt the fourth message authentication code according to the second shared key to obtain a candidate verification code and a candidate random number.

[0428] The second determination module 316 is configured to:

[0429] When the candidate verification code matches the device verification code, and the candidate random number matches the second random number, it is determined that the third message authentication code matches the fourth message authentication code.

[0430] Fig.24 is a block diagram of another communication device according to an exemplary embodiment. Fig.24 As shown, the device 300 also includes:

[0431] The seventh generating module 318 is configured to generate a master key according to the device verification code and the second shared key.

[0432] The encryption module 319 is configured to encrypt the master key according to the device security code to obtain encrypted device information.

[0433] The fourth sending module 320 is configured to send the encrypted device information to the cloud server.

[0434] Fig.25 is a block diagram of a communication device according to an exemplary embodiment. Fig.25 As shown, applied to a second terminal, the device 400 includes:

[0435] The first receiving module 401 is configured to receive a target transmission message sent by a first terminal.

[0436] The decryption module 402 is configured to decrypt the target transmission message according to the pre-generated second session key to obtain the target message. The target transmission message is obtained by the first terminal encrypting the target message according to the pre-generated first session key, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal.

[0437] In some embodiments, the target transmission message includes an encrypted message and a first message authentication code. The first receiving module 401 is configured to:

[0438] An encrypted message and a first message authentication code are received. The encrypted message and the first message authentication code are obtained by encrypting a target message according to a first session key, and the first message authentication code is used to verify the target message.

[0439] Fig.26 is a block diagram of another communication device according to an exemplary embodiment. Fig.26 As shown, the device 400 also includes:

[0440] The first generating module 403 is configured to generate a fifth message authentication code according to the second session key and the target message.

[0441] The discarding module 404 is configured to discard the target message when the first message authentication code and the fifth message authentication code do not match.

[0442] In some other embodiments, the target transmission message further includes a target identifier, and the target identifier is used to indicate the number of times the first terminal sends the message. The first receiving module 401 is configured to:

[0443] An encrypted message, a first message authentication code, and a target identifier are received.

[0444] In the case where the target identifier is the same as the historical identifier, the target message is discarded, and the historical identifier is an identifier in a message received from the first terminal before receiving the target transmission message.

[0445] In some other embodiments, the second session key is generated by:

[0446] A second public key and a second private key of the second terminal are randomly generated.

[0447] A first public key of the first terminal sent by the first terminal is received.

[0448] A third shared key is generated according to the first public key and the second private key.

[0449] Get the master key.

[0450] A second session key is generated based on the master key and the third shared key.

[0451] Fig. 27 is a block diagram of another communication device according to an exemplary embodiment. Fig. 27 As shown, the device 400 also includes:

[0452] The second receiving module 405 is configured to receive a second message authentication code sent by the first terminal.

[0453] The second generating module 406 is configured to generate a sixth message authentication code according to the second session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal.

[0454] The verification module 407 is configured to pass the identity authentication of the first terminal when the sixth message authentication code matches the second message authentication code.

[0455] The first receiving module 401 is configured as follows:

[0456] When the identity authentication of the first terminal is passed, a target transmission message sent by the first terminal is received.

[0457] Fig.28 is a block diagram of another communication device according to an exemplary embodiment. Fig.28 As shown, the device 400 also includes:

[0458] The acquisition module 408 is configured to acquire the input device verification code.

[0459] The establishing module 409 is configured to establish a target data channel according to the device verification code.

[0460] The first receiving module 401 is configured to:

[0461] Receive target transmission messages through the target data channel.

[0462] In some other embodiments, the establishing module 409 is configured to:

[0463] A fourth message authentication code is generated according to the device authentication code.

[0464] Receive a third message authentication code sent by the first terminal.

[0465] When the third message authentication code matches the fourth message authentication code, a target data channel is established.

[0466] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0467] In summary, the present disclosure is applied to the first terminal, first determining the target message to be sent, then generating the target transmission message according to the pre-generated first session key and the target message to be sent, and sending the target transmission message to the second terminal. Among them, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal. The present disclosure decrypts the encrypted device information obtained from the cloud server according to the device security code pre-set by the user to obtain the master key, generates the first session key according to the master key, and then generates the target transmission message according to the first session key and the target message to be sent, and sends it to the second terminal, which can improve the security of communication between the first terminal and the second terminal.

[0468] The present disclosure also provides a computer-readable storage medium having computer program instructions stored thereon, and the program instructions, when executed by a processor, implement the steps of the communication method provided by the present disclosure.

[0469] Fig.29 5 is a block diagram of an electronic device according to an exemplary embodiment. For example, the electronic device 500 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0470] Reference Fig.29 , the electronic device 500 may include one or more of the following components: a processing component 502 , a memory 504 , a power component 506 , a multimedia component 508 , an audio component 510 , an input / output interface 512 , a sensor component 514 , and a communication component 516 .

[0471] The processing component 502 generally controls the overall operation of the electronic device 500, such as operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 502 may include one or more processors 520 to execute instructions to complete all or part of the steps of the above-mentioned communication method. In addition, the processing component 502 may include one or more modules to facilitate the interaction between the processing component 502 and other components. For example, the processing component 502 may include a multimedia module to facilitate the interaction between the multimedia component 508 and the processing component 502.

[0472] The memory 504 is configured to store various types of data to support operations on the electronic device 500. Examples of such data include instructions for any application or method operating on the electronic device 500, contact data, phone book data, messages, pictures, videos, etc. The memory 504 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0473] The power supply component 506 provides power to the various components of the electronic device 500. The power supply component 506 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 500.

[0474] The multimedia component 508 includes a screen that provides an output interface between the electronic device 500 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 508 includes a front camera and / or a rear camera. When the electronic device 500 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each front camera and rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.

[0475] The audio component 510 is configured to output and / or input audio signals. For example, the audio component 510 includes a microphone (MIC), and when the electronic device 500 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive an external audio signal. The received audio signal can be further stored in the memory 504 or sent via the communication component 516. In some embodiments, the audio component 510 also includes a speaker for outputting audio signals.

[0476] The input / output interface 512 provides an interface between the processing component 502 and the peripheral interface modules, which may be keyboards, click wheels, buttons, etc. These buttons may include but are not limited to: a home button, a volume button, a start button, and a lock button.

[0477] The sensor assembly 514 includes one or more sensors for providing various aspects of status assessment for the electronic device 500. For example, the sensor assembly 514 can detect the open / closed state of the electronic device 500, the relative positioning of components, such as the display and keypad of the electronic device 500, and the sensor assembly 514 can also detect the position change of the electronic device 500 or a component of the electronic device 500, the presence or absence of user contact with the electronic device 500, the orientation or acceleration / deceleration of the electronic device 500, and the temperature change of the electronic device 500. The sensor assembly 514 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 514 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 514 may also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0478] The communication component 516 is configured to facilitate wired or wireless communication between the electronic device 500 and other devices. The electronic device 500 can access a wireless network based on a communication standard, such as WiFi, 2G or 3G, or a combination thereof. In an exemplary embodiment, the communication component 516 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 516 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.

[0479] In an exemplary embodiment, the electronic device 500 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above-mentioned communication methods.

[0480] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 504 including instructions, and the instructions can be executed by a processor 520 of an electronic device 500 to perform the above communication method. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0481] In addition to being an independent electronic device, the above-mentioned electronic device can also be a part of an independent electronic device. For example, in one embodiment, the electronic device can be an integrated circuit (IC) or a chip, wherein the integrated circuit can be an IC or a collection of multiple ICs; the chip can include but is not limited to the following types: GPU (Graphics Processing Unit), CPU (Central Processing Unit), FPGA (Field Programmable Gate Array), DSP (Digital Signal Processor), ASIC (Application Specific Integrated Circuit), SOC (System on Chip, SoC, system on chip or system-level chip), etc. The above-mentioned integrated circuit or chip can be used to execute executable instructions (or codes) to implement the above-mentioned communication method. The executable instructions can be stored in the integrated circuit or chip, or can be obtained from other electronic devices or devices, for example, the integrated circuit or chip includes a processor, a memory, and an interface for communicating with other electronic devices. The executable instruction may be stored in the memory, and when the executable instruction is executed by the processor, the above-mentioned communication method is implemented; alternatively, the integrated circuit or chip may receive the executable instruction through the interface and transmit it to the processor for execution, so as to implement the above-mentioned communication method.

[0482] In another exemplary embodiment, a computer program product is also provided. The computer program product includes a computer program executable by a programmable device, and the computer program has a code portion for executing the above communication method when executed by the programmable device.

[0483] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the present disclosure. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present disclosure are indicated by the following claims.

[0484] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A communication method, characterized in that: Applied to a first terminal, the method includes: Determine the target message to be sent; Generate a target transmission message according to a pre-generated first session key and a target message to be sent; the first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting encrypted device information obtained from a cloud server according to a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal; The target transmission message is sent to the second terminal.

2. The method according to claim 1, characterized in that The target transmission message includes an encrypted message and a first message authentication code; the generating the target transmission message according to the pre-generated first session key and the target message to be sent includes: Encrypting the target message to be sent according to the first session key to obtain the encrypted message and the first message authentication code; The sending the target transmission message to the second terminal comprises: The encrypted message and the first message authentication code are sent to the second terminal, where the first message authentication code is used to verify the target message.

3. The method according to claim 2, characterized in that The target transmission message also includes a target identifier, where the target identifier is used to indicate the number of times the first terminal sends the message; The method further comprises: Obtain the target identifier generated by a preset counter; The sending the target transmission message to the second terminal comprises: The encrypted message, the first message authentication code and the target identifier are sent to the second terminal.

4. The method according to claim 1, characterized in that: The first session key is generated by: Acquire encrypted device information from the cloud server, the encrypted device information including the master key encrypted using the device security code; The first session key is generated according to the encryption device information and the first shared key.

5. The method according to claim 4, characterized in that The first shared key is generated in the following manner: Randomly generate a first public key and a first private key of the first terminal; receiving a second public key of the second terminal sent by the second terminal; The first shared key is generated according to the first private key and the second public key.

6. The method according to claim 5, characterized in that The method further comprises: Obtaining the device security code; decrypting the encrypted device information according to the device security code to obtain the master key; Generating the first session key according to the encryption device information and the first shared key comprises: The first session key is generated based on the master key and the first shared key.

7. The method according to claim 6, characterized in that The method further comprises: Generate a second message authentication code according to the first session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal; sending the second message authentication code to the second terminal, so that the second terminal authenticates the first terminal according to the second message authentication code; Determining the target message to be sent includes: When the identity authentication is passed, a target message to be sent is determined.

8. The method according to claim 1, characterized in that The method further comprises: Randomly generate device verification code; Establishing a target data channel according to the device verification code; The sending the target transmission message to the second terminal comprises: The target transmission message is sent to the second terminal through the target data channel.

9. The method according to claim 8, characterized in that The establishing of the target data channel according to the device verification code comprises: Generate a third message authentication code according to the device authentication code; Obtaining a fourth message authentication code from the second terminal according to the device authentication code; In a case where the third message authentication code matches the fourth message authentication code, the target data channel is established.

10. The method according to claim 9, characterized in that The acquiring, according to the device verification code, a fourth message authentication code from the second terminal comprises: A fourth message authentication code is received from the second terminal, where the fourth message authentication code is generated by the second terminal according to the input device verification code.

11. The method according to claim 9, characterized in that The method further comprises: Randomly generate a third public key and a third private key of the first terminal; Sending the third public key to the second terminal, and receiving a fourth public key sent by the second terminal; Generate a second shared key according to the third private key and the fourth public key; Generating a third message authentication code according to the device authentication code comprises: The third message authentication code is generated according to the device authentication code and the second shared key.

12. The method according to claim 11, characterized in that The method further comprises: generating a first random number; Generating the third message authentication code according to the device authentication code and the second shared key comprises: The third message authentication code is generated according to the device authentication code, the second shared key and the first random number.

13. The method according to claim 12, characterized in that After acquiring a fourth message authentication code from the second terminal according to the device authentication code, the method further includes: Receiving a second random number sent by the second terminal; Determine whether the third message authentication code matches the fourth message authentication code according to the first random number and the second random number.

14. The method according to claim 13, characterized in that The method further comprises: Decrypting the fourth message authentication code according to the second shared key to obtain a candidate verification code and a candidate random number; The determining, according to the first random number and the second random number, whether the third message authentication code matches the fourth message authentication code comprises: In a case where the candidate verification code matches the device verification code, and the candidate random number matches the second random number, it is determined that the third message authentication code matches the fourth message authentication code.

15. The method according to any one of claims 11 to 14, characterized in that The method further comprises: Generate the master key according to the device verification code and the second shared key; Encrypting the master key according to the device security code to obtain the encrypted device information; The encrypted device information is sent to the cloud server.

16. A communication method, characterized in that: Applied to the second terminal, the method includes: receiving a target transmission message sent by the first terminal; The target transmission message is decrypted according to the pre-generated second session key to obtain the target message; the target transmission message is obtained by the first terminal encrypting the target message according to the pre-generated first session key, the first session key is generated according to the master key and the first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to the device security code, the device security code is pre-set by the user, the encrypted device information is the encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to the first private key of the first terminal and the second public key of the second terminal.

17. The method according to claim 16, characterized in that The target transmission message includes an encrypted message and a first message authentication code; The receiving a target transmission message sent by the first terminal comprises: receiving the encrypted message and a first message authentication code; The encrypted message and the first message authentication code are obtained by encrypting the target message according to the first session key, and the first message authentication code is used to verify the target message.

18. The method according to claim 17, characterized in that The method further comprises: generating a fifth message authentication code based on the second session key and the target message; In case the first message authentication code and the fifth message authentication code do not match, the target message is discarded.

19. The method according to claim 17, characterized in that The target transmission message also includes a target identifier, where the target identifier is used to indicate the number of times the first terminal sends the message; The receiving a target transmission message sent by the first terminal comprises: Receiving the encrypted message, the first message authentication code and the target identifier; In the case where the target identifier is the same as a historical identifier, the target message is discarded, and the historical identifier is an identifier in a message received from the first terminal before receiving the target transmission message.

20. The method according to claim 16, characterized in that The second session key is generated by: Randomly generate a second public key and a second private key of the second terminal; receiving a first public key of the first terminal sent by the first terminal; Generate a third shared key according to the first public key and the second private key; Obtaining the master key; The second session key is generated according to the master key and the third shared key.

21. The method according to claim 16, characterized in that The method further comprises: Receiving a second message authentication code sent by the first terminal; generating a sixth message authentication code according to the second session key and preset shared information, where the preset shared information is information shared by the first terminal and the second terminal; If the sixth message authentication code matches the second message authentication code, passing the identity authentication of the first terminal; The receiving a target transmission message sent by the first terminal comprises: When the identity authentication of the first terminal is passed, a target transmission message sent by the first terminal is received.

22. The method according to claim 16, characterized in that The method further comprises: Get the input device verification code; Establishing a target data channel according to the device verification code; The receiving a target transmission message sent by the first terminal comprises: The target transmission message is received through the target data channel.

23. The method according to claim 22, characterized in that The establishing of the target data channel according to the device verification code comprises: Generate a fourth message authentication code according to the device authentication code; Receiving a third message authentication code sent by the first terminal; In a case where the third message authentication code matches the fourth message authentication code, the target data channel is established.

24. A communication device, characterized in that: Applied to a first terminal, the device includes: A first determining module is configured to determine a target message to be sent; a first generating module, configured to generate a target transmission message according to a pre-generated first session key and a target message to be sent; the first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting encrypted device information obtained from a cloud server according to a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal; The first sending module is configured to send the target transmission message to the second terminal.

25. A communication device, characterized in that: Applied to a second terminal, the device includes: A first receiving module is configured to receive a target transmission message sent by a first terminal; A decryption module is configured to decrypt the target transmission message according to a pre-generated second session key to obtain a target message; the target transmission message is obtained by the first terminal encrypting the target message according to a pre-generated first session key, the first session key is generated according to a master key and a first shared key of the second terminal, the master key is obtained by decrypting the encrypted device information obtained from the cloud server according to a device security code, the device security code is pre-set by a user, the encrypted device information is encrypted information sent to the cloud server after the first terminal encrypts the master key according to the device security code, and the first shared key is generated according to a first private key of the first terminal and a second public key of the second terminal.

26. An electronic device, characterized in that: include: a memory having a computer program stored thereon; A processor, configured to execute the computer program in the memory to implement the steps of the method according to any one of claims 1 to 15 or 16 to 23.

27. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the program instructions are executed by a processor, the steps of the method described in any one of claims 1-15 or 16-23 are implemented.

28. A chip, characterized in that: The method comprises a processor and an interface; the processor is used to read instructions to execute the method according to any one of claims 1-15 or 16-23.