Key generation method and electronic equipment

Through a key generation method, the target public key of the target device and the private key of the first device are used to generate the target key, which solves the problem of cumbersome networking and pairing in the prior art, and realizes efficient and secure multi-device communication.

CN120017255AActive Publication Date: 2025-05-16LENOVO (BEIJING) LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510065723.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-16
Estimated Expiration
2045-01-15

AI Technical Summary

Technical Problem

Due to security considerations, the existing multi-device networking method requires pairing and trust determination one by one. The process is cumbersome and difficult to meet the efficiency and security while improving.

Method used

By a key generation method, in response to establishing a connection with the second device, a target public key of the target device is obtained and a target key is generated based on the public key and the private key of the first device is used to encrypt and decrypt communication data with the target device. The method also includes sharing public key data in the device group, simplifying communication connections between multiple devices.

Benefits of technology

It realizes that when networking between multiple devices, the pairing and trust determination process is simplified, networking efficiency and communication efficiency are improved, and security is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017255A_ABST
    Figure CN120017255A_ABST
Patent Text Reader

Abstract

The invention provides a key generation method and electronic equipment, and relates to the technical field of computers. The method applied to a first device comprises the following steps: in response to establishment of a first connection with a second device, obtaining a target public key of a target device shared by the second device; generating a target key based on the target public key and a first private key of the first device, wherein the target key is used for encrypting and / or decrypting communication data between the first device and the target device; wherein the target device is at least one device in a device group where the second device is located, and the second device can share the public key data of the at least one device in the device group with the first device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to a key generation method and electronic device. Background Art

[0002] Currently, users are using more and more electronic devices, such as personal computers (PCs), tablets, mobile phones, and watches. With the increase in electronic devices and the introduction of various interactive functions between devices, people have higher requirements for the efficiency and security of multi-device networking. However, in order to ensure security, the existing multi-device networking method requires multiple devices to be paired and trusted one by one, which is a cumbersome process. Summary of the invention

[0003] The present disclosure provides a key generation method and an electronic device.

[0004] According to a first aspect of the present disclosure, a key generation method is provided, which is applied to a first device, and the method includes: in response to establishing a first connection with a second device, obtaining a target public key of a target device shared by the second device; generating a target key based on the target public key and a first private key of the first device, and the target key is used to encrypt and / or decrypt communication data between the first device and the target device; wherein the target device is at least one device in a device group where the second device is located, and the second device can share public key data of at least one device in the device group with the first device.

[0005] In one possible implementation, obtaining the target public key of the target device shared by the second device includes at least one of the following: sending a connection request for establishing the first connection to the second device, so that the second device shares the public key of at least one device matching the type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device; obtaining the public key of at least one device shared by the second device matching its permission information; sending the device information of the first device to the second device, so that the second device shares the public key of at least one device matching the device information, wherein the second device can share the public key data of each device in the device group with the first device.

[0006] In one possible implementation, obtaining the target public key of the target device shared by the second device includes at least one of the following: when the first connection is a first type of connection, obtaining the second public key of the target device shared by the second device; when the first connection is a second type of connection, obtaining public key data of each device in the device group shared by the second device; when the first connection is a third type of connection, obtaining the third public key of the third device in the device group shared by the second device; when the second device has the first authority, obtaining the public key data of each device in the device group shared by the second device; when the second device has the second authority, obtaining the fourth public key of the fourth device in the device group shared by the second device, wherein the authority level of the fourth device is lower than the authority level of the second device; when the second device has the third authority, obtaining the second public key of the target device shared by the second device.

[0007] In one possible implementation, generating a target key based on the target public key and the first private key of the first device includes at least one of the following: generating a first key based on the second public key of the second device itself shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the second device; generating a second key based on the third public key of a third device in the device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the third device; generating a third key based on the fourth public key of a fourth device in the device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the fourth device; generating a plurality of keys corresponding to each device based on the public key data of each device in the device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and each device, respectively.

[0008] In one possible implementation, a key generation method also includes at least one of the following: after establishing a first connection with a second device, sharing its own first public key with the second device so that the target device generates a corresponding target key based on its own private key and the first public key; storing the generated target key in a secure encryption processor of the first device; in response to obtaining communication data communicated with the target device, encrypting the communication data based on the target key and / or decrypting feedback data for the communication data fed back by the target device.

[0009] According to a second aspect of the present disclosure, a key generation method is provided, which is applied to a second device, and the method includes: in response to establishing a first connection with a first device, sharing a target public key of a target device with the first device; sending the first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key, and the target key is used to encrypt and / or decrypt communication data between the first device and the target device; wherein the target device is at least one device in a device group where the second device is located, and the second device can share public key data of at least one device in the device group with the first device.

[0010] In one possible implementation, sharing the target public key of the target device with the first device includes at least one of the following: obtaining a connection request sent by the first device for establishing the first connection, and sharing the public key of at least one device in the device group with the first device based on the type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device; obtaining the permission information of the second device itself, and sharing the public key of at least one device in the device group with the first device based on the permission information; obtaining the device information of the first device, and sharing the public key of at least one device in the device group with the first device based on the device information, wherein the second device can share the public key data of each device in the device group with the first device.

[0011] In one possible implementation, sharing the target public key of the target device with the first device includes at least one of the following: when the first connection is a first type of connection, sharing its own second public key with the first device; when the first connection is a second type of connection, sharing the public key data of each device in the device group with the first device; when the first connection is a third type of connection, sharing the third public key of the third device in the device group with the first device; when the second device has a first authority, sharing the public key data of each device in the device group with the first device; when the second device has a second authority, sharing the fourth public key of the fourth device in the device group with the first device, wherein the authority level of the fourth device is lower than the authority level of the second device; when the second device has the third authority, sharing its own second public key with the first device; when the first device is a temporary device, sharing its own second public key with the first device; when the first device is a trusted device, sharing the public key data of each device in the device group with the first device.

[0012] In one possible implementation, sending the first public key shared by the first device to the target device so that the target device generates a corresponding target key based on its own private key and the first public key, including at least one of the following: generating a second key based on the first public key shared by the first device and its own second private key, for encrypting and / or decrypting communication data between the first device and the second device; sending the first public key shared by the first device to a third device in the device group, so that the third device generates a third key based on its own third private key and the first public key, for encrypting and / or decrypting communication data between the first device and the third device; sending the first public key shared by the first device to a fourth device in the device group, so that the fourth device generates a fourth key based on its own fourth private key and the first public key, for encrypting and / or decrypting communication data between the first device and the fourth device; sending the first public key shared by the first device to each device in the device group, so that each device in the device group generates multiple keys based on its own private key and the first public key, for respectively encrypting and / or decrypting communication data between the first device and each device.

[0013] According to a third aspect of the present disclosure, there is provided an electronic device, including:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores instructions that can be executed by the at least one processor, and the instructions can be executed by the at least one processor to perform the method described in the present disclosure.

[0017] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the method described in the present disclosure.

[0018] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The above and other objects, features and advantages of the exemplary embodiments of the present disclosure will become readily understood by reading the detailed description below with reference to the accompanying drawings. In the accompanying drawings, several embodiments of the present disclosure are shown in an exemplary and non-limiting manner, in which:

[0020] In the drawings, the same or corresponding reference numerals represent the same or corresponding parts.

[0021] Figure 1 A schematic diagram of a key generation method according to an embodiment of the present disclosure is shown. Figure 1 ;

[0022] Figure 2 A schematic diagram of a key generation method according to an embodiment of the present disclosure is shown. Figure 2 ;

[0023] Figure 3 A schematic diagram showing a method for generating a key according to an embodiment of the present disclosure Figure 1 ;

[0024] Figure 4 A schematic diagram of a scenario of a key generation method in the prior art is shown;

[0025] Figure 5 A schematic diagram showing a method for generating a key according to an embodiment of the present disclosure Figure 2 ;

[0026] Figure 6 A schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0027] In order to make the purpose, features, and advantages of the present disclosure more obvious and easy to understand, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.

[0028] Figure 1 A schematic diagram of a key generation method according to an embodiment of the present disclosure is shown. Figure 1 ,like Figure 1 As shown, a key generation method is applied to a first device, comprising:

[0029] Step S101, in response to establishing a first connection with a second device, obtaining a target public key of a target device shared by the second device.

[0030] In this embodiment, the second device is any device in the device group, the first device is a device that wants to communicate with at least one target device in the device group where the second device is located, and the second device can share the public key data of at least one device in the device group with the first device. Among them, the device group is a trust chain group, each device stores the public key data of all devices, and can share the public key data of all devices with the device newly added to the device group. In other embodiments, the permissions of each device in the trust chain group can be the same or different. If the permissions of each device in the trust chain group are different, the devices with different permissions can store different types of data of other devices in the device group, and the data that can be shared is also different.

[0031] In this embodiment, if the first device wants to communicate and connect with at least one target device in the device group where the second device is located, it needs to first establish a first connection with the second device, and the first connection may be a WIFIDirect connection. In one example, the first device may send a connection request to the second device, and the second device generates and displays a PIN (Personal Identification Number) in response to the connection request, and the first device sends the PIN to the second device. If the second device determines that the PIN generated by itself is the same as the PIN sent by the first device, it sends information that the PIN verification is passed to the first device, so that the first device and the second device establish a first connection; the first device may also establish a first connection with the second device via NFC (Near Field Communication); the present disclosure does not limit the manner in which the first device and the second device establish a first connection.

[0032] In this embodiment, in response to establishing a first connection with a second device, at least one of the following is included: in response to receiving pairing success information sent by the second device, the pairing success information indicates that the identification information (such as a PIN code) sent by the first device to the second device is successfully paired with the identification information generated by the second device; in response to a status flag in the first device indicating the connection status between the first device and the second device becoming a successful connection, the status flag is created by triggering a connection request sent by the first device to the second device, and if the status flag becomes a successful connection, it proves that a first connection has been successfully established between the first device and the second device; in response to receiving connection success information input by the user indicating that the first device and the second device are successfully connected, after the user determines that the first device and the second device are successfully connected, the connection success information can be input into the first device, and the first device determines to establish a first connection with the second device based on the connection success information input by the user.

[0033] In this embodiment, the first device can obtain the target public key of at least one target device in the device group shared by the second device through the first connection. The target device may be unique or non-unique. The target device may be the second device itself or other devices in the device group. The number of target public keys corresponds to the number of target devices, and the target public keys correspond one-to-one to the target devices. For example, target device A corresponds to target public key A, target device B corresponds to target public key B, and so on.

[0034] In this embodiment, the target public key of the target device shared by the second device is an asymmetric public key, and the asymmetric public key can be generated by the corresponding target device through the x25519 elliptic curve algorithm and the SM2 algorithm.

[0035] Step S102: Generate a target key based on the target public key and a first private key of the first device.

[0036] In this embodiment, after the first device obtains the target public key of the target device shared by the second device, it can generate a target key based on the target public key and the first private key of the first device, and the target key is used to encrypt and / or decrypt the communication data between the first device and the target device. The number of target keys corresponds to the number of target public keys. If the number of target public keys is unique, the target key is unique; if the target public key is not unique, the target key is not unique. The first device can encrypt the communication data based on the target key and send the encrypted data to the target device, or it can decrypt the encrypted data sent by the target device based on the target key to obtain the required communication data. In one example, the first device can encrypt the communication data based on the target key by using the AES (Advanced Encryption Standard) algorithm, or it can decrypt the encrypted data sent by the target device based on the target key by using the AES algorithm to obtain the required communication data.

[0037] Figure 3 A schematic diagram showing a method for generating a key according to an embodiment of the present disclosure Figure 1 ,like Figure 3As shown, devices A, B, and C form a device group, and device D is a first device that wants to communicate and connect with at least one target device in the device group. If the second device is device A, and the target devices are devices A, B, and C, the first device D can respond to establishing a first connection with the second device A, obtain the target public keys of devices A, B, and C shared by the second device A, and then generate target keys (key A, key B, key C) corresponding to devices A, B, and C respectively based on the target public keys of devices A, B, and C and the first private key of the first device D. When the first device communicates with at least one of devices A, B, and C, it can encrypt and / or decrypt corresponding communication data using corresponding keys among key A, key B, and key C. As a result, the first device D can achieve communication connection with all devices in the device group through only one interaction with the second device A, thereby improving the networking efficiency and communication efficiency between multiple devices.

[0038] Figure 4 A schematic diagram of a key generation method in the prior art is shown. Figure 4 As shown, in the existing key generation method, if the first device D needs to communicate with devices A, B, and C, it needs to establish communication connections with devices A, B, and C respectively, which is more complicated than the key generation method in the present disclosure.

[0039] In another embodiment, the “obtaining the target public key of the target device shared by the second device” in step S101 includes at least one of the following:

[0040] A connection request for establishing a first connection is sent to a second device so that the second device shares a public key of at least one device that matches the type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device. In this embodiment, the connection request includes the type of communication connection, such as a temporary connection, a permanent connection, a designated connection, etc. Each type of communication connection corresponds to a different target device. For example, the target device corresponding to the temporary connection may be only the second device, the target device corresponding to the permanent connection may be all devices in the device group where the second device is located, and the target device corresponding to the designated connection may be the device specified by the device identifier carried in the connection request sent by the first device. The second device may determine the public key of at least one matching device based on the type of communication connection in the connection request, and then share the public key of at least one matching device with the first device.

[0041] Obtain the public key of at least one device that matches the permission information shared by the second device. In this embodiment, the permissions of each device in the device group can be the same or different, and the device public keys that can be shared by devices with different permissions are also different. In one example, if the permissions of each device in the device group are consistent, they can all share the device public key of the entire group; for the device with the highest permission, the public keys of all devices in the device group can be shared; for devices with other permissions, their own public keys and the public keys of devices with lower permission levels than the device can be shared. Therefore, the second device can share the corresponding public key with the first device based on its own permission information.

[0042] The device information of the first device is sent to the second device so that the second device shares the public key of at least one device matching the device information, wherein the second device can share the public key data of each device in the device group with the first device. In this embodiment, the device information of the first device may include temporary devices, trusted devices, unfamiliar devices, etc. For temporary devices and unfamiliar devices, the second device may only share the public key of device A; for trusted devices or frequently connected devices, the device public keys of all devices in the entire device group may be shared. Therefore, the second device may share the public key of at least one matching device based on the device information of the first device.

[0043] In the present disclosure, the target public key of the target device shared by the second device is determined based on the connection request, permission information, device information, etc., which is more flexible and can adapt to various user needs and usage scenarios.

[0044] In another embodiment, the “obtaining the target public key of the target device shared by the second device” in step S101 includes at least one of the following:

[0045] When the first connection is a first type connection, the second device shares its own second public key. In this embodiment, the first type connection is a temporary connection, and the second device only shares its own public key with the first device, so the first device obtains its own second public key shared by the second device. Figure 3 As shown, the first device D only obtains the second public key of the second device A.

[0046] When the first connection is a second type connection, the public key data of each device in the device group shared by the second device is obtained. In this embodiment, the second type connection is a permanent connection, and the second device shares the public keys of all devices in the device group with the first device, so the first device obtains the public key data of each device in the device group shared by the second device. Figure 3 As shown, the first device D will obtain the public key data of the second device A, device B and device C sent by the second device A.

[0047] When the first connection is a third type connection, the third public key of the third device in the device group shared by the second device is obtained. In this embodiment, the third type connection is a designated connection. If the first device specifies to connect to the third device in the device group, the second device sends the public key of the third device to the first device. Therefore, the first device obtains the third public key of the third device in the device group shared by the second device. The third device is different from the second device. Figure 3 As shown, if the third device designated by the first device D is device B and device C, the first device D will obtain the public key data of device B and device C sent by the second device A.

[0048] When the second device has the first authority, the public key data of each device in the device group shared by the second device is obtained. In this embodiment, if the second device has the highest first authority, or the authorities of each device in the device group are the same, the second device will send the public key data of all devices in the device group to the first device, so the first device will obtain the public key data of each device in the device group shared by the second device. Figure 3 As shown, the first device D will obtain the public key data of the second device A, device B and device C sent by the second device A.

[0049] When the second device has the second permission, the fourth public key of the fourth device in the device group shared by the second device is obtained, wherein the permission level of the fourth device is lower than the permission level of the second device. In this embodiment, the level of the second permission is lower than the level of the first permission, and the second device will share the fourth public key of the fourth device in the device group whose permission level is lower than the second permission. Therefore, the first device will obtain the fourth public key of the fourth device in the device group shared by the second device. In one example, when the second device has the second permission, the second device will also share its own public key with the first device. Therefore, the first device will also obtain the second public key of the second device. Figure 3 As shown, if the authority levels of the devices in the device group are device B, device A, and device C from high to low, the second device A will share the public key of device C and / or device A, and the first device D will obtain the public key of device C and / or device A sent by the second device A.

[0050] When the second device has the third authority, the second device obtains the second public key shared by the second device. In this embodiment, the third authority is the lowest authority level, and the second device can only share its own public key. Therefore, the first device will obtain the second public key shared by the second device. Figure 3 As shown, the first device D obtains the second public key of the second device A sent by the second device A.

[0051] In another embodiment, step S102 “generating a target key based on the target public key and the first private key of the first device” includes at least one of the following:

[0052] A first key is generated based on the second public key shared by the second device and the first private key of the first device, so as to encrypt and / or decrypt the communication data between the first device and the second device. In this embodiment, if the first connection is a first type of connection, or the second device has the third authority, the first device can only receive the second public key shared by the second device, and generate a first key based on the second public key shared by the second device and the first private key of the first device, and the first key is used to encrypt and / or decrypt the communication data between the first device and the second device. Figure 3 As shown, the first key generated by the first device D can only be used for communication between the first device D and the second device A.

[0053] A second key is generated based on the third public key of the third device in the device group shared by the second device and the first private key of the first device, and is used to encrypt and / or decrypt the communication data between the first device and the third device. In this embodiment, if the first connection is a third type of connection, the first device will obtain the third public key of the third device in the device group shared by the second device, the third device specifies the device that the first device wants to connect to, and generates a second key based on the third public key of the third device in the device group shared by the second device and the first private key of the first device, and the second key is used to encrypt and / or decrypt the communication data between the first device and the third device. Figure 3 As shown, if the third device is device B, the second key generated by the first device D can only be used for communication between the first device D and the second device B.

[0054] A third key is generated based on the fourth public key of the fourth device in the device group shared by the second device and the first private key of the first device, so as to encrypt and / or decrypt the communication data between the first device and the fourth device. In this embodiment, if the second device has the second permission, the first device will obtain the fourth public key of the fourth device in the device group shared by the second device, and the permission level of the fourth device is lower than the permission level of the second device, and generate a third key based on the fourth public key and the first private key of the first device, and the third key is used to encrypt and / or decrypt the communication data between the first device and the fourth device. Figure 3 As shown, if the authority levels of the devices in the device group are device B, device A, and device C from high to low, the first device D will obtain the public key of device C and / or device A sent by the second device A, and the generated third key is used to encrypt and / or decrypt the communication data between the first device D and device C and / or device A.

[0055] Based on the public key data of each device in the device group shared by the second device and the first private key of the first device, multiple keys corresponding to each device are respectively generated, which are respectively used to encrypt and / or decrypt the communication data between the first device and each device. In this embodiment, if the first connection is a second type of connection, or the second device has the first authority, the first device will receive the public key data of each device in the device group shared by the second device, and based on the public key data of each device in the device group shared by the second device and the first private key of the first device, multiple keys corresponding to each device are respectively generated, which are respectively used to encrypt and / or decrypt the communication data between the first device and each device. Figure 3 As shown, the first device D will receive the public key data of the second device A, device B and device C, and generate the keys corresponding to the second device A, device B and device C respectively in combination with the first private key of the first device D, thereby realizing encryption and / or decryption of communication data between the first device D and any device in the device group.

[0056] In another embodiment, a key generation method further includes at least one of the following:

[0057] After establishing a first connection with a second device, the first public key is shared with the second device, so that the target device generates a corresponding target key based on its own private key and the first public key. In this embodiment, after establishing a first connection with a second device, the first device shares its own first public key with the second device, and the second device can share the first public key with the target device in the device group, so that the target device generates a corresponding target key based on its own private key and the first public key. The target key can encrypt and / or decrypt the communication data between the first device and the target device. Figure 3 As shown, the first device D can send the first public key to the second device A, and the second device A can determine the target device based on the connection type in the connection request, the permission information of the second device A, or the device information of the first device D. If the target device is device A and device C, the second device A sends the first public key to device C, and device A and device C generate a target key based on the first public key and their own private keys. The target key is used to encrypt and / or decrypt the communication data between device D and device A or device C.

[0058] The generated target key is stored in the secure encryption processor of the first device. In this embodiment, the secure encryption processor may be a TPM (Trusted Platform Module), which is a chip integrated into a computer motherboard and is intended to protect the data stored therein from external attacks and malware. Storing the target key in the secure encryption processor can ensure the security of the target key and further improve the security of networking between multiple devices.

[0059] In response to obtaining the communication data for communication with the target device, the communication data is encrypted based on the target key and / or the feedback data for the communication data fed back by the target device is decrypted. In this embodiment, the first device can encrypt the communication data based on the target key and send the encrypted data to the target device, or can decrypt the feedback data for the communication data fed back by the target device based on the target key to obtain the required feedback data.

[0060] In one possible implementation, a key generation method further includes at least one of the following:

[0061] Request the target public key of other devices except the target device from the second device, and generate the target key corresponding to the other devices based on the target public key of the other devices and the first private key of the first device, where the other devices are devices except the target device in the device group where the second device is located. Thus, the first device can exchange public keys and generate the target key with any device in the device group where the second device is located at any time based on demand.

[0062] The target key for communicating with the target device that has no communication demand within the target period is deleted. Thus, the storage space of the target key can be released according to demand, ensuring the availability of the storage space.

[0063] Figure 2 A schematic diagram of a key generation method according to an embodiment of the present disclosure is shown. Figure 2 ,like Figure 2 As shown, a key generation method is applied to a second device, comprising:

[0064] Step S201, in response to establishing a first connection with a first device, sharing a target public key of a target device with the first device.

[0065] In this embodiment, the second device is any device in the device group, the first device is a device that wants to communicate with at least one target device in the device group where the second device is located, and the second device can share the public key data of at least one device in the device group with the first device. Among them, the device group is a trust chain group, each device stores the public key data of all devices, and can share the public key data of all devices with the device newly added to the device group. In other embodiments, the permissions of each device in the trust chain group can be the same or different. If the permissions of each device in the trust chain group are different, the devices with different permissions can store different types of data of other devices in the device group, and the data that can be shared is also different.

[0066] In this embodiment, the first connection established between the second device and the first device may be a WIFIDirect connection. In one example, the first device may send a connection request to the second device, the second device generates and displays a PIN (Personal Identification Number) in response to the connection request, the first device sends the PIN to the second device, and if the second device determines that the PIN generated by itself is the same as the PIN sent by the first device, it sends information that the PIN verification is passed to the first device, so that the first device and the second device establish a first connection; the second device may also establish a first connection with the first device via NFC (Near Field Communication); the present disclosure does not limit the manner in which the second device and the first device establish a first connection.

[0067] In this embodiment, in response to establishing a first connection with a first device, at least one of the following is included: in response to receiving pairing success information sent by the first device, the pairing success information indicates that the identification information (such as a PIN code) sent by the first device to the second device is successfully paired with the identification information generated by the second device; in response to a status flag in the second device indicating the connection status between the first device and the second device becoming a successful connection, the status flag is created by triggering a connection request sent by the first device to the second device, and if the status flag becomes a successful connection, it proves that a first connection has been successfully established between the first device and the second device; in response to receiving connection success information input by a user indicating that the first device and the second device are successfully connected, after the user determines that the first device and the second device are successfully connected, the connection success information can be input into the second device, and the second device determines to establish a first connection with the second device based on the connection success information input by the user.

[0068] In this embodiment, the second device can share the target public key of the target device to the first device through the first connection. The target device may be unique or non-unique. The target device may be the second device itself or other devices in the device group. The number of target public keys corresponds to the number of target devices, and the target public key corresponds to the target device one-to-one. For example, target device A corresponds to target public key A, target device B corresponds to target public key B, and so on.

[0069] In this embodiment, the target public key of the target device shared with the first device is an asymmetric public key, and the asymmetric public key can be generated by the corresponding target device through the x25519 elliptic curve algorithm and the SM2 algorithm.

[0070] Step S202: Send the first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key.

[0071] In this embodiment, after the second device shares the target public key of the target device with the first device, it is also necessary to send the first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key. The target key is used to encrypt and / or decrypt the communication data between the first device and the target device. The target device can encrypt the communication data based on the target key and send the encrypted data to the first device, or it can decrypt the encrypted data sent by the first device based on the target key to obtain the required communication data.

[0072] Figure 3 A schematic diagram showing a method for generating a key according to an embodiment of the present disclosure Figure 1 ,like Figure 3 As shown, devices A, B, and C form a device group, and device D is a first device that wants to communicate and connect with at least one target device in the device group. If the second device is device A, and the target devices are devices A, B, and C, then the second device A can respond to establishing a first connection with the first device D by sharing the target public keys of devices A, B, and C with the first device D, and then send the first public key shared by the first device D to the target devices A, B, and C, so that the target devices A, B, and C generate corresponding target keys (key A, key B, key C) based on their own private keys and the first public key. At least one of the target devices A, B, and C can encrypt and / or decrypt corresponding communication data using the corresponding keys among key A, key B, and key C when communicating with the first device D. As a result, the target devices A, B, and C do not need to interact with the first device D separately to communicate and connect with the first device D. The target device A only needs to interact with the first device D to realize the communication connection between all target devices and the first device D, thereby improving the networking efficiency and communication efficiency between multiple devices.

[0073] In another embodiment, “sharing the target public key of the target device to the first device” in step S201 includes at least one of the following:

[0074] A connection request for establishing a first connection sent by a first device is obtained, and a public key of at least one device in a device group is shared with the first device based on the type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device. In this embodiment, the connection request includes the type of communication connection, such as a temporary connection, a permanent connection, a designated connection, etc. Each type of communication connection corresponds to a different target device. For example, the target device corresponding to a temporary connection may be only the second device, the target device corresponding to a permanent connection may be all devices in the device group where the second device is located, and the target device corresponding to a designated connection may be the device specified by the device identifier carried in the connection request sent by the first device. The second device may determine the public key of at least one matching device based on the type of communication connection in the connection request, and then share the public key of at least one matching device with the first device.

[0075] The second device obtains its own permission information, and shares the public key of at least one device in the device group with the first device based on the permission information. In this embodiment, the permissions of the devices in the device group may be the same or different, and the device public keys that can be shared by devices with different permissions are also different. In one example, if the permissions of the devices in the device group are consistent, they can all share the device public key of the entire group; for the device with the highest permission, the public keys of all devices in the device group can be shared; for devices with other permissions, their own public keys and the public keys of devices with lower permission levels than the device can be shared. Therefore, the second device can share the corresponding public key with the first device based on its own permission information.

[0076] The device information of the first device is obtained, and the public key of at least one device in the device group is shared with the first device based on the device information, wherein the second device can share the public key data of each device in the device group with the first device. In this embodiment, the device information of the first device may include temporary devices, trusted devices, unfamiliar devices, etc. For temporary devices and unfamiliar devices, the second device may only share the public key of device A; for trusted devices or frequently connected devices, the device public keys of all devices in the entire device group may be shared. Therefore, the second device may share the public key of at least one matching device based on the device information of the first device.

[0077] In the present disclosure, the second device can determine the target public key of the target device based on the connection request, permission information, device information, etc., which is more flexible and can adapt to various user needs and usage scenarios.

[0078] In another embodiment, “sharing the target public key of the target device to the first device” in step S201 includes at least one of the following:

[0079] When the first connection is a first type connection, the second device shares its own second public key with the first device. In this embodiment, the first type connection is a temporary connection, and the second device only shares its own public key with the first device. Figure 3 As shown, the second device A only sends its own second public key to the first device D.

[0080] When the first connection is a second type connection, the public key data of each device in the device group is shared with the first device. In this embodiment, the second type connection is a permanent connection, and the second device shares the public keys of all devices in the device group with the first device. Figure 3 As shown, the second device A sends the public key data of the second device A, device B and device C to the first device D.

[0081] When the first connection is a third type of connection, the third public key of the third device in the device group is shared with the first device. In this embodiment, the third type of connection is a designated connection. If the first device specifies to connect to the third device in the device group, the second device sends the public key of the third device to the first device. Figure 3 As shown, if the third device designated by the first device D is devices B and C, the second device A sends the public key data of devices B and C to the first device D.

[0082] When the second device has the first authority, the public key data of each device in the device group is shared with the first device. In this embodiment, if the second device has the highest first authority, or the authorities of each device in the device group are the same, the second device will send the public key data of all devices in the device group to the first device. Figure 3 As shown, the second device A sends the public key data of the second device A, device B and device C to the first device D.

[0083] When the second device has the second permission, the fourth public key of the fourth device in the device group is shared with the first device, wherein the permission level of the fourth device is lower than the permission level of the second device. In this embodiment, the level of the second permission is lower than the level of the first permission, and the second device will share the fourth public key of the fourth device in the device group whose permission level is lower than the second permission. In one example, when the second device has the second permission, the second device will also share its own public key with the first device. Figure 3 As shown, if the authority levels of the devices in the device group are device B, device A, and device C from high to low, the second device A will share the public key of device C and / or device A.

[0084] When the second device has the third authority, it shares its second public key with the first device. In this embodiment, the third authority is the lowest authority level, and the second device can only share its own public key. Figure 3 As shown, the second device A can only share its own public key with the first device D.

[0085] In the case where the first device is a temporary device, the second device shares its own second public key with the first device. In this embodiment, if the first device is a temporary device, that is, a device that may only be connected to the target device a small number of times, the second device shares its own second public key with the first device. Figure 3 As shown, the second device A shares its public key with the first device D.

[0086] In the case where the first device is a trusted device, the public key data of each device in the device group is shared with the first device. In this embodiment, if the first device is a trusted device, the second device shares the public key data of each device in the device group with the first device. Figure 3 As shown, the second device A sends the public key data of the second device A, device B and device C to the first device D.

[0087] In another embodiment, step S202 of “sending the first public key shared by the first device to the target device so that the target device generates a corresponding target key based on its own private key and the first public key” includes at least one of the following:

[0088] A second key is generated based on the first public key shared by the first device and its own second private key to encrypt and / or decrypt the communication data between the first device and the second device. In this embodiment, if the first connection is a first type of connection, or the second device has the third authority, the second device only needs to generate a second key based on the first public key shared by the first device and its own second private key to encrypt and / or decrypt the communication data between the first device and the second device.

[0089] The first public key shared by the first device is sent to the third device in the device group, so that the third device generates a third key based on its own third private key and the first public key, for encrypting and / or decrypting the communication data between the first device and the third device. In this embodiment, if the first connection is a third type of connection, the second device sends the first public key shared by the first device to the third device in the device group, the third device specifies the device that the first device wants to connect to, and the third device generates the third key based on its own third private key and the first public key.

[0090] The first public key shared by the first device is sent to the fourth device in the device group, so that the fourth device generates a fourth key based on its own fourth private key and the first public key, which is used to encrypt and / or decrypt the communication data between the first device and the fourth device. In this embodiment, the second device has the second authority, and the second device sends the first public key shared by the first device to the fourth public key of the fourth device in the device group. The authority level of the fourth device is lower than the authority level of the second device, and the fourth device generates the fourth key based on its own fourth private key and the first public key.

[0091] The first public key shared by the first device is sent to each device in the device group, so that each device in the device group generates multiple keys based on its own private key and the first public key, which are respectively used to encrypt and / or decrypt communication data between the first device and each device. In this embodiment, if the first connection is a second type of connection, or the second device has the first authority, the second device sends the first public key shared by the first device to all devices in the device group, and all devices in the device group generate multiple keys based on their own private key and the first public key.

[0092] In one possible implementation, a key generation method further includes: sending the target public key of other devices except the target device to the first device, and sending the first public key of the target device to other devices, so that the other devices generate corresponding target keys based on their own private keys and the first public key, and the other devices are devices except the target device in the device group where the second device is located. In this way, the other devices can exchange public keys with the first device at any time based on demand and generate target keys. In order to facilitate the understanding of a key generation method of the present disclosure embodiment, the following is combined with Figure 5 A key generation method disclosed in the present invention is explained:

[0093] Figure 5 A schematic diagram showing a method for generating a key according to an embodiment of the present disclosure Figure 2 ,like Figure 5 As shown, devices A, B, and C form a device group, and device D is a first device that wants to communicate and connect with at least one target device in the device group, wherein the second device is device A, and the target devices are devices A, B, and C. The first device D sends a connection request to the second device A, and the second device A generates and displays a PIN code based on the connection request. The first device D enters the PIN code and performs device information and connection type marking (temporary device, trusted device, first type connection, second type connection, etc.), and then sends the PIN code to the second device A. If the second device A determines that the PIN code generated by itself is the same as the PIN code entered by the first device D, the first device establishes a first connection with the second device; then the first device D sends its public key PK DSend to the second device A, the second device A will PK D Save to TPM and based on PK D and the private key SK of the second device A A Generate symmetric encryption key S AD If the first device D is a temporary device or the first connection is a first type connection, the second device A only sends its own public key PK A Sent to the first device D, the first device D will PK A Save to TPM and based on PK A and the private key SK of the first device D itself D Generate symmetric encryption key S AD If the first device D is a trusted device or the first connection is a second type connection, the second device A sends the public keys of all devices in the device group to the first device D, including (PK A ,PK B ,PK C ), the first device D will (PK A ,PK B ,PK C ) is saved to TPM and based on (PK A ,PK B ,PK C ) and the private key SK of the first device D itself D Generate a symmetric encryption key (S AD , S BD , S CD ); and if the first device D is a trusted device or the first connection is a second type connection, the second device A also needs to transfer the public key PK of the first device D D Send to device B and device C, device B and device C respectively send PK D Save to its own TPM, and device B based on PK D And its own private key SK B Generate symmetric encryption key S BD , device C based on PK D And its own private key SK C Generate symmetric encryption key S CD If the first device D wants to communicate with the device C, based on the symmetric encryption key S corresponding to the device C CD Encrypt the message data and send the encrypted data to device C. Device C uses the symmetric encryption key S it has generated CD The encrypted data is decrypted to obtain the message data, thereby realizing encrypted communication between the first device D and the device C.

[0094] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device and a readable storage medium.

[0095] Figure 6 A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0096] like Figure 6 As shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0097] A number of components in the device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the device 800 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0098] The computing unit 801 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 801 performs the various methods and processes described above, such as a key generation method. For example, in some embodiments, a key generation method may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on the device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by the computing unit 801, one or more steps of a key generation method described above may be performed. Alternatively, in other embodiments, the computing unit 801 may be configured to perform a key generation method in any other appropriate manner (e.g., by means of firmware).

[0099] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0100] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0101] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0102] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0103] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0104] A computer system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server combined with a blockchain.

[0105] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.

[0106] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the present disclosure, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0107] The above is only a specific embodiment of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art who is familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present disclosure, which should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.

Claims

1. A key generation method, applied to a first device, the method comprising: In response to establishing a first connection with a second device, obtaining a target public key of a target device shared by the second device; generating a target key based on the target public key and a first private key of the first device, wherein the target key is used to encrypt and / or decrypt communication data between the first device and the target device; The target device is at least one device in the device group where the second device is located, and the second device can share the public key data of at least one device in the device group with the first device.

2. The method according to claim 1, wherein: Obtaining a target public key of a target device shared by the second device includes at least one of the following: sending a connection request for establishing the first connection to the second device, so that the second device shares a public key of at least one device matching the type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device; Obtaining a public key of at least one device shared by the second device and matching the permission information thereof; The device information of the first device is sent to the second device, so that the second device shares a public key of at least one device matching the device information, wherein the second device can share the public key data of each device in the device group with the first device.

3. The method according to claim 1 or 2, wherein: Obtaining a target public key of a target device shared by the second device includes at least one of the following: When the first connection is a first type of connection, obtaining a second public key of the second device shared by the second device; When the first connection is a second type of connection, obtaining public key data of each device in the device group shared by the second device; When the first connection is a third type of connection, obtaining a third public key of a third device in the device group shared by the second device; When the second device has the first authority, obtaining public key data of each device in the device group shared by the second device; When the second device has a second authority, obtaining a fourth public key of a fourth device in the device group shared by the second device, wherein the authority level of the fourth device is lower than the authority level of the second device; In a case where the second device has the third authority, a second public key of the second device shared by the second device is obtained.

4. The method according to claim 1, wherein: Generating a target key based on the target public key and a first private key of the first device includes at least one of the following: Generate a first key based on the second public key shared by the second device and the first private key of the first device, so as to encrypt and / or decrypt communication data between the first device and the second device; generating a second key based on a third public key of a third device in the device group shared by the second device and a first private key of the first device, for encrypting and / or decrypting communication data between the first device and the third device; generating a third key based on a fourth public key of a fourth device in the device group shared by the second device and a first private key of the first device, for encrypting and / or decrypting communication data between the first device and the fourth device; Based on the public key data of each device in the device group shared by the second device and the first private key of the first device, multiple keys corresponding to each device are generated respectively, so as to be used for encrypting and / or decrypting the communication data between the first device and each device respectively.

5. The method according to claim 1, further comprising at least one of the following: After establishing a first connection with a second device, sharing its first public key with the second device, so that the target device generates a corresponding target key based on its own private key and the first public key; storing the generated target key in a secure cryptographic processor of the first device; In response to obtaining the communication data communicated with the target device, the communication data is encrypted based on the target key and / or feedback data for the communication data fed back by the target device is decrypted.

6. A key generation method, applied to a second device, the method comprising: In response to establishing a first connection with a first device, sharing a target public key of a target device with the first device; Sending the first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key, wherein the target key is used to encrypt and / or decrypt communication data between the first device and the target device; The target device is at least one device in the device group where the second device is located, and the second device can share the public key data of at least one device in the device group with the first device.

7. The method according to claim 6, wherein: Sharing the target public key of the target device with the first device includes at least one of the following: obtaining a connection request sent by the first device for establishing the first connection, and sharing a public key of at least one device in the device group with the first device based on type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device; obtaining permission information of the second device itself, and sharing a public key of at least one device in the device group with the first device based on the permission information; The device information of the first device is obtained, and a public key of at least one device in the device group is shared with the first device based on the device information, wherein the second device can share the public key data of each device in the device group with the first device.

8. The method according to claim 6 or 7, wherein: Sharing the target public key of the target device with the first device includes at least one of the following: When the first connection is a first type of connection, sharing the second public key of the first device with the first device; When the first connection is a second type of connection, sharing public key data of each device in the device group with the first device; When the first connection is a third type of connection, sharing a third public key of a third device in the device group with the first device; When the second device has the first authority, sharing the public key data of each device in the device group with the first device; In a case where the second device has a second authority, sharing a fourth public key of a fourth device in the device group with the first device, wherein the authority level of the fourth device is lower than the authority level of the second device; When the second device has the third authority, share its second public key with the first device; In the case where the first device is a temporary device, sharing the second public key of the first device with the first device; In the case that the first device is a trusted device, the public key data of each device in the device group is shared with the first device.

9. The method according to claim 6, wherein: Sending the first public key shared by the first device to the target device so that the target device generates a corresponding target key based on its own private key and the first public key, includes at least one of the following: Generate a second key based on the first public key shared by the first device and the second private key of the first device, so as to encrypt and / or decrypt communication data between the first device and the second device; Sending the first public key shared by the first device to a third device in the device group, so that the third device generates a third key based on its own third private key and the first public key, for encrypting and / or decrypting communication data between the first device and the third device; Sending the first public key shared by the first device to a fourth device in the device group, so that the fourth device generates a fourth key based on its own fourth private key and the first public key, for encrypting and / or decrypting communication data between the first device and the fourth device; The first public key shared by the first device is sent to each device in the device group, so that each device in the device group generates multiple keys based on its own private key and the first public key, which are used to encrypt and / or decrypt communication data between the first device and each device.

10. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions can be executed by the at least one processor to perform the method of any one of claims 1-5 and / or the method of any one of claims 6-9.

Citation Information

Patent Citations

  • Group key agreement method and communication method in instant communication

    CN106850195A

  • Wireless ad hoc network encryption communication method and terminal thereof

    CN110381504A

  • Distributed key management method, electronic equipment and storage medium

    CN117041952A

  • Establishing secure peer networking in trust webs on open networks using shared secret device key

    US20030044020A1

  • Network configuration method based on wi-fi sensing, embedded chip system, and medium

    WO2024083235A1