Key generation method and electronic device
By generating target keys between devices and using public and private keys to encrypt communication data, the cumbersome problem of networking between multiple devices is solved, achieving efficient and secure networking and communication.
Patent Information
- Application Number
- CN202510065723.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-01-15
AI Technical Summary
现有的多设备间组网方式由于安全性考虑,需要一一进行配对和信任确定,导致过程繁琐,影响组网效率。
After establishing a connection between the first and second devices, a target key is generated. The target public and private keys are then used to encrypt and decrypt communication data, enabling efficient communication between multiple devices.
It simplifies the networking process between multiple devices, improves networking and communication efficiency, and enhances security.
Smart Images

Figure CN120017255B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer, and particularly relates to a key generation method and an electronic device. BACKGROUND
[0002] Currently, the electronic devices used by users are increasing, such as personal computers (PCs), tablets, mobile phones and watches, and with the increase of electronic devices and the proposal of various interaction functions between devices, people have higher demands for the efficiency and security of networking between multiple devices. However, in order to ensure security, the existing networking mode between multiple devices needs to be paired and trusted one by one between multiple devices, which is relatively cumbersome. SUMMARY
[0003] The present disclosure provides a key generation method and an electronic device.
[0004] According to a first aspect of the present disclosure, a key generation method is provided, applied to a first device, and the method comprises: obtaining a target public key of a target device shared by a second device in response to establishing a first connection with the second device; generating a target key based on the target public key and a first private key of the first device, the target key being used for encrypting and / or decrypting communication data between the first device and the target device; wherein the target device is at least one device in a device group to which the second device belongs, and the second device can share public key data of at least one device in the device group to the first device.
[0005] In an implementable manner, obtaining the target public key of the target device shared by the second device comprises at least one of the following: sending a connection request for establishing the first connection to the second device, so that the second device shares the public key of at least one device matching the type information of the connection request, wherein each device in the device group can share the public key data of the device to the first device; obtaining the public key of at least one device matching the permission information shared by the second device; sending the device information of the first device to the second device, so that the second device shares the public key of at least one device matching the device information, wherein the second device can share the public key data of each device in the device group to the first device.
[0006] In an implementation, obtaining the target public key of the target device shared by the second device comprises at least one of: obtaining a second public key of the second device shared by itself in a case that the first connection is a first type connection; obtaining public key data of each device in the device group shared by the second device in a case that the first connection is a second type connection; obtaining a third public key of a third device in the device group shared by the second device in a case that the first connection is a third type connection; obtaining the public key data of each device in the device group shared by the second device in a case that the second device has a first privilege; obtaining a fourth public key of a fourth device in the device group shared by the second device in a case that the second device has a second privilege, wherein the privilege level of the fourth device is lower than the privilege level of the second device; and obtaining the second public key of the second device shared by itself in a case that the second device has a third privilege.
[0007] In an implementation, generating the target key based on the target public key and the first private key of the first device comprises at least one of: generating a first key based on the second public key of the second device shared by itself and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the second device; generating a second key based on the third public key of the third device in the device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the third device; generating a third key based on the fourth public key of the fourth device in the device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the fourth device; and generating a plurality of keys corresponding to each device in the device group shared by the second device based on the public key data of each device and the first private key of the first device, respectively, for encrypting and / or decrypting communication data between the first device and each device.
[0008] In an implementation, a key generation method further comprises at least one of: sharing a first public key of the first device with the second device after establishing the first connection with the second device, so that the target device generates a corresponding target key based on a private key of the target device and the first public key; saving the generated target key in a secure cryptographic processor of the first device; and encrypting communication data obtained for communication with the target device based on the target key and / or decrypting feedback data fed back by the target device for the communication data.
[0009] According to a second aspect of the present disclosure, a key generation method is provided, applied to a second device, the method comprising: in response to establishing a first connection with a first device, sharing a target public key of a target device with the first device; sending a first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on a private key of the target device and the first public key, the target key being used for encrypting and / or decrypting communication data between the first device and the target device; wherein the target device is at least one device in a device group to which the second device belongs, and the second device can share public key data of at least one device in the device group with the first device.
[0010] In an implementation, the sharing of the target public key of the target device with the first device comprises at least one of: obtaining a connection request sent by the first device for establishing the first connection, and sharing the public key of at least one device in the device group with the first device based on type information of the connection request, wherein each device in the device group can share public key data of the device with the first device; obtaining permission information of the second device itself, and sharing the public key of at least one device in the device group with the first device based on the permission information; obtaining device information of the first device, and sharing the public key of at least one device in the device group with the first device based on the device information, wherein the second device can share public key data of each device in the device group with the first device.
[0011] In an implementation, the sharing of the target public key of the target device with the first device comprises at least one of: in a case where the first connection is a first type of connection, sharing a second public key of the second device with the first device; in a case where the first connection is a second type of connection, sharing public key data of each device in the device group with the first device; in a case where the first connection is a third type of connection, sharing a third public key of a third device in the device group with the first device; in a case where the second device has a first permission, sharing public key data of each device in the device group with the first device; in a case where the second device has a second permission, sharing a fourth public key of a fourth device in the device group with the first device, wherein the fourth device has a permission level lower than that of the second device; in a case where the second device has a third permission, sharing a second public key of the second device with the first device; in a case where the first device is a temporary device, sharing a second public key of the second device with the first device; in a case where the first device is a trusted device, sharing public key data of each device in the device group with the first device.
[0012] In an implementation, the first public key shared by the first device is sent to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key, including at least one of: generating a second key based on the first public key shared by the first device and its own second private key, for encrypting and / or decrypting communication data between the first device and the second device; sending the first public key shared by the first device to a third device in the device group, so that the third device generates a third key based on its own third private key and the first public key, for encrypting and / or decrypting communication data between the first device and the third device; sending the first public key shared by the first device to a fourth device in the device group, so that the fourth device generates a fourth key based on its own fourth private key and the first public key, for encrypting and / or decrypting communication data between the first device and the fourth device; and sending the first public key shared by the first device to each device in the device group, so that each device in the device group generates a plurality of keys based on its own private key and the first public key, for respectively encrypting and / or decrypting communication data between the first device and each device.
[0013] According to a third aspect of the present disclosure, an electronic device is provided, comprising:
[0014] at least one processor; and
[0015] a memory connected with the at least one processor in communication; wherein,
[0016] the memory stores instructions executable by the at least one processor, the instructions executable by the at least one processor to perform the method of the present disclosure.
[0017] According to a fourth aspect of the present disclosure, a non-transitory computer readable storage medium storing computer instructions is provided, the computer instructions for causing the computer to perform the method of the present disclosure.
[0018] It should be understood that the contents described in this part are not intended to identify key or important features of the embodiments of the present disclosure, nor are they used to limit the scope of the present disclosure. Other features of the present disclosure will become apparent through the following description. BRIEF DESCRIPTION OF DRAWINGS
[0019] The above and other objects, features and advantages of the exemplary embodiments of the present disclosure will be more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which:
[0020] In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts.
[0021] Figure 1 A flowchart illustrating a key generation method according to an embodiment of this disclosure is shown. Figure 1 ;
[0022] Figure 2 A flowchart illustrating a key generation method according to an embodiment of this disclosure is shown. Figure 2 ;
[0023] Figure 3 This illustration shows a scenario illustrating a key generation method according to an embodiment of the present disclosure. Figure 1 ;
[0024] Figure 4 A schematic diagram illustrating a scenario of key generation methods in the prior art is shown;
[0025] Figure 5 This illustration shows a scenario illustrating a key generation method according to an embodiment of the present disclosure. Figure 2 ;
[0026] Figure 6 A schematic diagram of the composition structure of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0027] To make the objectives, features, and advantages of this disclosure more apparent and understandable, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.
[0028] Figure 1 A flowchart illustrating a key generation method according to an embodiment of this disclosure is shown. Figure 1 ,like Figure 1 As shown, a key generation method is applied to a first device, comprising:
[0029] Step S101: In response to establishing a first connection with the second device, obtain the target public key of the target device shared by the second device.
[0030] In the embodiment, the second device is any one of the devices in the device group, the first device is a device that wants to establish a communication connection with at least one target device in the device group where the second device is located, and the second device can share public key data of at least one device in the device group with the first device. The device group is a trust chain group, each device stores public key data of all devices, and can share the public key data of all devices with a device newly added to the device group. In other embodiments, the permissions of the devices in the trust chain group can be the same or different. If the permissions of the devices in the trust chain group are different, the devices with different permissions can store different types of data of other devices in the device group, and can share different data.
[0031] In the embodiment, the first device wants to establish a communication connection with at least one target device in the device group where the second device is located, and needs to first establish a first connection with the second device. The first connection can be a WIFI Direct connection. In an example, the first device can send a connection request to the second device, the second device generates and displays a PIN code (Personal Identification Number) in response to the connection request, the first device sends the PIN code to the second device, and if the second device determines that the PIN code generated by itself is the same as the PIN code sent by the first device, the second device sends information that the PIN code verification is passed to the first device, so that the first device establishes the first connection with the second device. The first device can also establish the first connection with the second device through NFC (Near Field Communication). The present disclosure does not limit the manner in which the first device establishes the first connection with the second device.
[0032] In the embodiment, in response to establishing the first connection with the second device, at least one of the following is included: in response to receiving pairing success information sent by the second device, the pairing success information indicating that the identification information (such as the PIN code) sent by the first device to the second device is successfully paired with the identification information generated by the second device; in response to a state flag in the first device indicating a connection state between the first device and the second device changing to connection success, the state flag being triggered to be created by the connection request sent by the first device to the second device, if the state flag changes to connection success, it proves that the first device and the second device have successfully established the first connection; in response to receiving connection success information input by a user indicating that the first device and the second device are successfully connected, the user can input the connection success information to the first device after determining that the first device and the second device are successfully connected, and the first device determines to establish the first connection with the second device based on the connection success information input by the user.
[0033] In this embodiment, the first device can obtain, through the first connection, target public keys of at least one target device in the device group shared by the second device, the target devices can or can not be unique, the target devices can be the second device itself or other devices in the device group, the number of target public keys corresponds to the number of target devices, and each target public key corresponds to one target device, for example, target device A corresponds to target public key A, target device B corresponds to target public key B, and so on.
[0034] In this embodiment, the target public keys of the target devices shared by the second device are asymmetric public keys, which can be generated by the corresponding target devices through an x25519 elliptic curve algorithm and an SM2 algorithm.
[0035] In step S102, a target key is generated based on the target public key and the first private key of the first device.
[0036] In this embodiment, after the first device obtains the target public keys of the target devices shared by the second device, the first device can generate target keys based on the target public keys and the first private key of the first device, and the target keys are used to encrypt and / or decrypt communication data between the first device and the target devices. The number of target keys corresponds to the number of target public keys, and if the number of target public keys is unique, the number of target keys is also unique; if the number of target public keys is not unique, the number of target keys is also not unique. The first device can encrypt the communication data based on the target keys and send the encrypted data to the target devices, or decrypt the encrypted data sent by the target devices based on the target keys to obtain the required communication data. In an example, the first device can encrypt the communication data based on the target keys through an AES (Advanced Encryption Standard) algorithm, or decrypt the encrypted data sent by the target devices based on the target keys through the AES algorithm to obtain the required communication data.
[0037] Figure 3 A scene diagram of a key generation method according to an embodiment of the present disclosure is shown. Figure 1 As shown in FIG. 1, a first device 100 and a second device 200 are connected through a first connection 110. Figure 3As shown, the devices A, B, and C form a device group, and the device D is a first device that wants to establish a communication connection with at least one target device in the device group. If the second device is the device A, and the target devices are the devices A, B, and C, the first device D can, in response to establishing a first connection with the second device A, obtain the target public keys of the devices A, B, and C shared by the second device A, and then generate target keys (key A, key B, and key C) corresponding to the devices A, B, and C, respectively, based on the target public keys of the devices A, B, and C and the first private key of the first device D. When the first device communicates with at least one of the devices A, B, and C, the first device can use the corresponding key among the keys A, B, and C to encrypt and / or decrypt the corresponding communication data, thereby enabling the first device D to establish a communication connection with all devices in the device group through only one interaction with the second device A, and improving the networking efficiency and communication efficiency among multiple devices.
[0038] Figure 4 A scene diagram of a key generation method in the prior art is shown as follows. Figure 4 In the prior art key generation method, if the first device D needs to communicate with the devices A, B, and C, the first device D needs to establish a communication connection with the devices A, B, and C, respectively, which is relatively cumbersome compared with the key generation method in the present disclosure.
[0039] In another embodiment, the "obtaining, by the first device, the target public key of the target device shared by the second device" in step S101 includes at least one of the following:
[0040] The second device is sent a connection request for establishing a first connection, so that the second device shares the public key of at least one device matching the type information of the connection request, wherein each device in the device group can share the public key data of each device with the first device. In this embodiment, the connection request includes the type of communication connection, such as temporary connection, permanent connection, designated connection, etc., and each type of communication connection corresponds to different target devices, such as the target device corresponding to the temporary connection can be only the second device, the target device corresponding to the permanent connection can be all devices in the device group where the second device is located, and the target device corresponding to the designated connection can be the device specified by the device identifier carried in the connection request sent by the first device. The second device can determine the public key of at least one device that matches based on the type of communication connection in the connection request, and then share the public key of the at least one device that matches with the first device.
[0041] The second device shares the public key of at least one device matching the permission information of the second device. In the embodiment, the permissions of the devices in the device group can be the same or different, and the public keys that can be shared by the devices with different permissions are also different. In an example, if the permissions of the devices in the device group are the same, the public keys of all the devices in the device group can be shared; for the device with the highest permission, the public keys of all the devices in the device group can be shared; for the devices with other permissions, the public keys of the devices with lower permission levels than the devices can be shared, and therefore, the second device can share the corresponding public keys to the first device based on the permission information of the second device.
[0042] The device information of the first device is sent to the second device, so that the second device shares the public key of at least one device matching the device information, and the second device can share the public key data of each device in the device group to the first device. In the embodiment, the device information of the first device can include a temporary device, a trusted device, and a stranger device, and for the temporary device and the stranger device, the second device can share only the public key of the device A; for the trusted device or the frequently connected device, the public keys of all the devices in the device group can be shared, and therefore, the second device can share the public key of at least one device matching the device information based on the device information of the first device.
[0043] In the disclosure, the target public key of the target device shared by the second device is determined based on the connection request, the permission information, and the device information, which is more flexible and can adapt to various user needs and use scenarios.
[0044] In another embodiment, the "obtaining the target public key of the target device shared by the second device" in step S101 includes at least one of the following:
[0045] In the case where the first connection is a first type connection, the second public key of the second device shared by the second device is obtained. In the embodiment, the first type connection is a temporary connection, and the second device only shares the public key of the second device itself to the first device, and therefore, the first device obtains the second public key of the second device shared by the second device. As shown in Figure 3 , the first device D only obtains the second public key of the second device A.
[0046] In the case where the first connection is a second type connection, the public key data of each device in the device group shared by the second device is obtained. In the embodiment, the second type connection is a permanent connection, and the second device shares the public keys of all the devices in the device group to the first device, and therefore, the first device obtains the public key data of each device in the device group shared by the second device. As shown in Figure 3 , the first device D obtains the public key data of the second device A, the device B, and the device C sent by the second device A.
[0047] In the case that the first connection is a third type connection, a third public key of a third device in the device group shared by the second device is obtained. In the embodiment, the third type connection is a designated connection, for example, the first device designates to connect with the third device in the device group, and then the second device sends the public key of the third device to the first device, so that the first device obtains the third public key of the third device in the device group shared by the second device, and the third device is different from the second device. As shown in Figure 3 If the third device designated by the first device D is device B and device C, the first device D obtains the public key data of device B and device C sent by the second device A.
[0048] In the case that the second device has the first authority, the public key data of each device in the device group shared by the second device is obtained. In the embodiment, the second device has the highest first authority, or the authorities of each device in the device group are the same, so that the second device sends the public key data of all devices in the device group to the first device, and thus the first device obtains the public key data of each device in the device group shared by the second device. As shown in Figure 3 The first device D obtains the public key data of the second device A, device B and device C sent by the second device A.
[0049] In the case that the second device has the second authority, a fourth public key of a fourth device in the device group shared by the second device is obtained, and the authority level of the fourth device is lower than the authority level of the second device. In the embodiment, the level of the second authority is lower than the level of the first authority, so that the second device shares the fourth public key of the fourth device in the device group whose authority level is lower than the second authority, and thus the first device obtains the fourth public key of the fourth device in the device group shared by the second device. In an example, in the case that the second device has the second authority, the second device also shares the public key of itself to the first device, and thus the first device also obtains the second public key of the second device. As shown in Figure 3 If the authority levels of the devices in the device group are device B, device A and device C from high to low, the second device A shares the public key of device C and / or device A, and the first device D obtains the public key of device C and / or device A sent by the second device A.
[0050] In the case that the second device has the third authority, the second public key of itself shared by the second device is obtained. In the embodiment, the third authority is the lowest authority level, and the second device can only share the public key of itself, so that the first device obtains the second public key of the second device shared by the second device. As shown in Figure 3 The first device D obtains the second public key of the second device A sent by the second device A.
[0051] In another embodiment, the step S102 of "generating a target key based on the target public key and the first private key of the first device" comprises at least one of:
[0052] generating a first key based on the second public key of the second device shared by itself and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the second device. In this embodiment, if the first connection is the first type of connection, or the second device has the third authority, the first device can only receive the second public key of the second device shared by itself, and generate the first key based on the second public key of the second device shared by itself and the first private key of the first device, the first key being used for encrypting and / or decrypting communication data between the first device and the second device. As shown in Figure 3 the first device D can only use the first key generated by the first device D for communication between the first device D and the second device A.
[0053] generating a second key based on the third public key of a third device in a device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the third device. In this embodiment, if the first connection is the third type of connection, the first device can obtain the third public key of the third device in the device group shared by the second device, the third device being a device that the first device wants to connect to, and generate the second key based on the third public key of the third device in the device group shared by the second device and the first private key of the first device, the second key being used for encrypting and / or decrypting communication data between the first device and the third device. As shown in Figure 3 if the third device is the device B, the second key generated by the first device D can only be used for communication between the first device D and the second device B.
[0054] generating a third key based on the fourth public key of a fourth device in a device group shared by the second device and the first private key of the first device, for encrypting and / or decrypting communication data between the first device and the fourth device. In this embodiment, the second device has the second authority, the first device can obtain the fourth public key of the fourth device in the device group shared by the second device, the fourth device having an authority level lower than that of the second device, and generate the third key based on the fourth public key and the first private key of the first device, the third key being used for encrypting and / or decrypting communication data between the first device and the fourth device. As shown in Figure 3 if the authority levels of the devices in the device group are device B, device A and device C from high to low, the first device D can obtain the public keys of the device C and / or the device A sent by the second device A, and generate the third key for encrypting and / or decrypting communication data between the first device D and the device C and / or the device A.
[0055] The first device generates a plurality of keys corresponding to each device in the device group shared by the second device based on the public key data of each device in the device group shared by the second device and the first private key of the first device, respectively, for respectively encrypting and / or decrypting the communication data between the first device and each device. In this embodiment, if the first connection is a second type connection or the second device has a first authority, the first device receives the public key data of each device in the device group shared by the second device, and generates a plurality of keys corresponding to each device in the device group shared by the second device based on the public key data of each device in the device group shared by the second device and the first private key of the first device, respectively, for respectively encrypting and / or decrypting the communication data between the first device and each device. As shown in Figure 3 FIG. 1, the first device D receives the public key data of the second device A, the device B and the device C, and generates the keys corresponding to the second device A, the device B and the device C based on the first private key of the first device D, so as to realize the encryption and / or decryption of the communication data between the first device D and any device in the device group.
[0056] In another embodiment, the key generation method further includes at least one of the following:
[0057] After establishing the first connection with the second device, the first public key of the first device is shared with the second device, so that the target device generates a corresponding target key based on the private key of the target device and the first public key. In this embodiment, after establishing the first connection with the second device, the first device shares the first public key with the second device, and the second device can share the first public key with the target device in the device group, so that the target device generates a corresponding target key based on the private key of the target device and the first public key. The target key can be used to encrypt and / or decrypt the communication data between the first device and the target device. As shown in Figure 3 FIG. 1, the first device D can send the first public key to the second device A, and the second device A can determine the target device based on the connection type in the connection request, the authority information of the second device A or the device information of the first device D. For example, if the target devices are the device A and the device C, the second device A sends the first public key to the device C, and the device A and the device C generate the target key based on the first public key and the private key of the device A and the device C, respectively. The target key is used to encrypt and / or decrypt the communication data between the device D and the device A or the device C.
[0058] The generated target key is stored in the secure encryption processor of the first device. In this embodiment, the secure encryption processor can be a TPM (Trusted Platform Module). The TPM is a chip integrated into the mainboard of a computer, which is designed to protect the data stored therein from external attacks and malicious software. Storing the target key in the secure encryption processor can ensure the security of the target key and further improve the security of the networking between multiple devices.
[0059] In response to obtaining the communication data for communicating with the target device, the communication data is encrypted based on the target key and / or feedback data fed back by the target device for the communication data is decrypted. In this embodiment, the first device can encrypt the communication data based on the target key and send the encrypted data to the target device, or decrypt the feedback data fed back by the target device for the communication data based on the target key to obtain the required feedback data.
[0060] In an implementation, a key generation method further includes at least one of the following:
[0061] The target public key of another device other than the target device is requested from the second device, and the target key corresponding to the other device is generated based on the target public key of the other device and the first private key of the first device, the other device being a device other than the target device in a device group in which the second device is located. In this way, the first device can exchange public keys with any device in the device group in which the second device is located and generate a target key at any time based on demand.
[0062] The target key for communicating with the target device having no communication demand in the target period is deleted. In this way, the storage space of the target key can be released according to demand, and the availability of the storage space can be ensured.
[0063] Figure 2 A flowchart of a key generation method according to an embodiment of the present disclosure is shown Figure 2 As shown in Figure 2 A key generation method applied to a second device includes the following steps:
[0064] In response to establishing a first connection with a first device, the target public key of a target device is shared with the first device.
[0065] In this embodiment, the second device is any one of the devices in a device group, and the first device is a device that wants to communicate with at least one target device in the device group in which the second device is located. The second device can share the public key data of at least one device in the device group with the first device. The device group is a trust chain group, and each device stores the public key data of all devices and can share the public key data of all devices with a device newly added to the device group. In other embodiments, the permissions of the devices in the trust chain group can be the same or different. If the permissions of the devices in the trust chain group are different, the devices with different permissions can store different types of data of other devices in the device group and share different data.
[0066] In this embodiment, the first connection established by the second device with the first device can be a WIFI Direct connection. In an example, the first device can send a connection request to the second device, the second device generates and displays a PIN code (Personal Identification Number) in response to the connection request, the first device sends the PIN code to the second device, and if the second device determines that the PIN code generated by itself is the same as the PIN code received from the first device, the second device sends information indicating that the PIN code verification is passed to the first device, so that the first device and the second device establish the first connection; the second device can also establish the first connection with the first device through NFC (Near Field Communication); the present disclosure does not limit the manner in which the second device establishes the first connection with the first device.
[0067] In this embodiment, in response to establishing the first connection with the first device, at least one of the following is included: in response to receiving pairing success information sent by the first device, the pairing success information indicating that the identification information (such as the PIN code) sent by the first device to the second device is successfully paired with the identification information generated by the second device; in response to a state flag in the second device indicating the connection state between the first device and the second device changing to connection success, the state flag being triggered to be created by the connection request sent by the first device to the second device, if the state flag changes to connection success, it proves that the first device and the second device have successfully established the first connection; in response to receiving connection success information input by a user indicating that the first device and the second device are successfully connected, the user can input the connection success information to the second device after determining that the first device and the second device are successfully connected, and the second device determines to establish the first connection with the second device based on the connection success information input by the user.
[0068] In this embodiment, the second device can share the target public key of the target device with the first device through the first connection, the target device can or can not be unique, the target device can be the second device itself or other devices in the device group, the number of target public keys corresponds to the number of target devices, and the target public key corresponds to the target device one by one, for example, target device A corresponds to target public key A, target device B corresponds to target public key B, and so on.
[0069] In this embodiment, the target public key of the target device shared with the first device is an asymmetric public key, which can be generated by the corresponding target device through an x25519 elliptic curve algorithm and an SM2 algorithm.
[0070] In step S202, the first public key shared by the first device is sent to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key.
[0071] In this embodiment, after the second device shares the target public key of the target device with the first device, the first public key shared by the first device also needs to be sent to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key, and the target key is used to encrypt and / or decrypt the communication data between the first device and the target device. The target device can encrypt the communication data based on the target key and send the encrypted data to the first device, or decrypt the encrypted data sent by the first device based on the target key to obtain the required communication data.
[0072] Figure 3 A scene diagram of a key generation method according to an embodiment of the present disclosure is shown Figure 3 As shown in Figure 3 Devices A, B, and C form a device group, and device D is a first device that wants to communicate with at least one target device in the device group. If the second device is device A, and the target devices are devices A, B, and C, the second device A can share the target public keys of devices A, B, and C with the first device D in response to establishing a first connection with the first device D, and then send the first public key shared by the first device D to the target devices A, B, and C, so that the target devices A, B, and C generate corresponding target keys (key A, key B, and key C) based on their own private keys and the first public key. At least one of the target devices A, B, and C can use the corresponding key among the keys A, B, and C to encrypt and / or decrypt the corresponding communication data when communicating with the first device D. In this way, the target devices A, B, and C do not need to interact with the first device D to communicate with the first device D. Instead, the target device A only needs to interact with the first device D to achieve communication connection between all target devices and the first device D, thereby improving the networking efficiency and communication efficiency between multiple devices.
[0073] In another embodiment, the step of "sharing the target public key of the target device with the first device" in step S201 includes at least one of the following:
[0074] obtain a connection request for establishing a first connection sent by a first device, and share a public key of at least one device in a device group with the first device based on type information of the connection request, wherein each device in the device group can share public key data of each device with the first device. In this embodiment, the connection request includes a type of communication connection, such as a temporary connection, a permanent connection, a designated connection, and the like, and each type of communication connection corresponds to different target devices, such as a target device corresponding to a temporary connection that can only be the second device, a target device corresponding to a permanent connection that can be all devices in the device group in which the second device is located, and a target device corresponding to a designated connection that can be a device specified by a device identifier carried in the connection request sent by the first device. The second device can determine the public key of at least one matched device based on the type of communication connection in the connection request, and then share the public key of the at least one matched device with the first device.
[0075] obtain permission information of the second device itself, and share the public key of at least one device in the device group with the first device based on the permission information. In this embodiment, the permissions of each device in the device group can be the same or different, and the public keys of devices that can be shared are also different. In an example, if the permissions of each device in the device group are consistent, the device group can share the public keys of all devices; for a device with the highest permission, the public keys of all devices in the device group can be shared; for other devices with lower permissions, the public keys of the devices themselves and the devices with lower permission levels than the device can be shared. Therefore, the second device can share the corresponding public key with the first device based on the permission information of the second device.
[0076] obtain device information of the first device, and share the public key of at least one device in the device group with the first device based on the device information, wherein the second device can share public key data of each device in the device group with the first device. In this embodiment, the device information of the first device can include a temporary device, a trusted device, a stranger device, and the like. For temporary devices and stranger devices, the second device can only share the public key of device A; for trusted devices or frequently connected devices, the second device can share the public keys of all devices in the device group. Therefore, the second device can share the public key of at least one matched device based on the device information of the first device.
[0077] In this disclosure, the second device can determine the target public key of the target device based on the connection request, the permission information, and the device information, and has higher flexibility and can adapt to various user needs and use scenarios.
[0078] In another embodiment, the step of "sharing the target public key of the target device with the first device" in step S201 includes at least one of the following:
[0079] In the case that the first connection is a first type connection, the second device shares its own second public key to the first device. In this embodiment, the first type connection is a temporary connection, and the second device only shares its own public key to the first device. As shown in FIG. 3, the second device A only sends its own second public key to the first device D. Figure 3
[0080] In the case that the first connection is a second type connection, the second device shares public key data of each device in the device group to the first device. In this embodiment, the second type connection is a permanent connection, and the second device shares public key data of all devices in the device group to the first device. As shown in FIG. 4, the second device A sends public key data of the second device A, the device B and the device C to the first device D. Figure 3
[0081] In the case that the first connection is a third type connection, the second device shares a third public key of a third device in the device group to the first device. In this embodiment, the third type connection is a designated connection, and the second device sends the third public key of the third device to the first device if the first device designates to connect with the third device in the device group. As shown in FIG. 5, if the third device designated by the first device D is the device B and the device C, the second device A sends public key data of the device B and the device C to the first device D. Figure 3
[0082] In the case that the second device has a first authority, the second device shares public key data of each device in the device group to the first device. In this embodiment, the second device has the highest first authority, or the authorities of each device in the device group are the same, and the second device sends public key data of all devices in the device group to the first device. As shown in FIG. 6, the second device A sends public key data of the second device A, the device B and the device C to the first device D. Figure 3
[0083] In the case that the second device has a second authority, the second device shares a fourth public key of a fourth device in the device group to the first device, wherein the authority level of the fourth device is lower than the authority level of the second device. In this embodiment, the second authority has a lower level than the first authority, and the second device shares the fourth public key of the fourth device in the device group whose authority level is lower than the second authority. In an example, in the case that the second device has the second authority, the second device also shares its own public key to the first device. As shown in FIG. 7, if the authority levels of the devices in the device group from high to low are the device B, the device A and the device C, the second device A shares the public key of the device C and / or the device A. Figure 3
[0084] In the case that the second device has a third authority, the second device shares its own second public key to the first device. In this embodiment, the third authority is the lowest authority level, and the second device can only share its own public key.Figure 3 As shown, the second device A shares its own public key to the first device D.
[0085] In the case that the first device is a temporary device, the second public key of the second device is shared to the first device. In this embodiment, if the first device is a temporary device, i.e. a device that can only connect to the target device for a few times, the second device shares its own second public key to the first device. As shown, Figure 5 As shown, the second device A shares its own public key to the first device D.
[0086] In the case that the first device is a trusted device, the public key data of each device in the device group is shared to the first device. In this embodiment, if the first device is a trusted device, the second device shares the public key data of each device in the device group to the first device. As shown, Figure 5 As shown, the second device A sends the public key data of the second device A, the device B and the device C to the first device D.
[0087] In another embodiment, the step S202 of "sending the first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key" comprises at least one of the following:
[0088] generating a second key based on the first public key shared by the first device and its own second private key, for encrypting and / or decrypting the communication data between the first device and the second device. In this embodiment, if the first connection is a first type connection, or the second device has a third authority, the second device only needs to generate a second key based on the first public key shared by the first device and its own second private key, for encrypting and / or decrypting the communication data between the first device and the second device.
[0089] sending the first public key shared by the first device to a third device in the device group, so that the third device generates a third key based on its own third private key and the first public key, for encrypting and / or decrypting the communication data between the first device and the third device. In this embodiment, if the first connection is a third type connection, the second device sends the first public key shared by the first device to a third device in the device group, the third device is a device that the first device wants to connect to, and the third device generates a third key based on its own third private key and the first public key.
[0090] The first public key shared by the first device is sent to a fourth device in the device group, so that the fourth device generates a fourth key based on a fourth private key of the fourth device and the first public key, for encrypting and / or decrypting communication data between the first device and the fourth device. In this embodiment, the second device has the second authority, and the second device sends the first public key shared by the first device to a fourth public key of the fourth device in the device group, the fourth device has an authority level lower than the authority level of the second device, and the fourth device generates the fourth key based on the fourth private key of the fourth device and the first public key.
[0091] The first public key shared by the first device is sent to each device in the device group, so that each device in the device group generates a plurality of keys based on a private key of the device and the first public key, for respectively encrypting and / or decrypting communication data between the first device and the device. In this embodiment, if the first connection is a second type connection, or the second device has the first authority, the second device sends the first public key shared by the first device to all devices in the device group, and all devices in the device group generate a plurality of keys based on their own private keys and the first public key.
[0092] In an implementable manner, a key generation method further includes: sending a target public key of a device other than the target device to the first device, and sending the first public key of the target device to the other device, so that the other device generates a corresponding target key based on its own private key and the first public key, the other device being a device other than the target device in a device group in which the second device is located. Thus, the other device can exchange the public key with the first device and generate the target key at any time as needed. In order to facilitate the understanding of the key generation method of the embodiments of the present disclosure, the following will be combined with Figure 2 A key generation method of the present disclosure is explained:
[0093] Figure 5 A scene diagram of a key generation method of an embodiment of the present disclosure is shown Figure 6 As shown in Figure 6 Devices A, B, and C form a device group, and device D is a first device that wants to communicate with at least one target device in the device group, wherein the second device is device A, the target device is device A, B, and C, the first device D sends a connection request to the second device A, the second device A generates a PIN code based on the connection request and displays it, the first device D inputs the PIN code and marks the device information and the connection type (temporary device, trusted device, first type connection, second type connection, etc.), and then sends the PIN code to the second device A. If the second device A determines that the PIN code generated by itself is the same as the PIN code input by the first device D, the first device and the second device establish a first connection; then the first device D sends its public key PK DSend to the second device A, the second device A will PK D Save to TPM and based on PK D The private key SK of the second device A A Generate symmetric encryption key S AD If the first device D is a temporary device or the first connection is a first type connection, then the second device A will only share its own public key PK. A Send to the first device D, the first device D will PK A Save to TPM and based on PK A And the private key SK of the first device D itself D Generate symmetric encryption key S AD If the first device D is a trusted device or the first connection is a second type connection, then the second device A will send the public keys of all devices in the device group to the first device D, including (PK). A PK B PK C The first device D will (PK) A PK B PK C Save to TPM and according to (PK) A PK B PK C ) and the private key SK of the first device D itself D Generate a symmetric encryption key (S AD S BD S CD Furthermore, if the first device D is a trusted device or the first connection is a second type connection, the second device A also needs to pass the public key PK of the first device D. D Send to devices B and C, respectively. Device B and device C will then send the PK. D Saved to its own TPM, and device B is based on PK. D and its own private key SK B Generate symmetric encryption key S BD Device C is based on PK D and its own private key SK C Generate symmetric encryption key S CD If the first device D wants to communicate with device C, it does so based on the symmetric encryption key S corresponding to device C. CD The message data is encrypted and sent to device C. Device C uses its own generated symmetric encryption key S. CD The encrypted data is decrypted to obtain the message data, thereby enabling encrypted communication between the first device D and device C.
[0094] According to embodiments of this disclosure, this disclosure also provides an electronic device and a readable storage medium.
[0095] A schematic block diagram of an example electronic device 800 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present disclosure described and / or claimed in this document.
[0096] As shown, the device 800 includes a computing unit 801 that can perform various suitable actions and processes in accordance with computer programs stored in a read-only memory (ROM) 802 or loaded into a random access memory (RAM) 803 from a storage unit 808. Various programs and data needed in the operation of the device 800 can also be stored in the RAM 803. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other by a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0097] Various components in the device 800 are connected to the I / O interface 805, including an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; the storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the device 800 to exchange information / data with other devices through computer networks, such as the Internet, and / or various telecommunication networks.
[0098] The computing unit 801 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs various methods and processes described above, such as a key generation method. For example, in some embodiments, a key generation method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded onto the RAM 803 and executed by the computing unit 801, one or more steps of a key generation method described above can be performed. Alternatively, in other embodiments, the computing unit 801 can be configured to perform a key generation method by any other suitable means, such as by means of firmware.
[0099] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0100] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces the functions / operations specified in the flowcharts and / or the block diagrams. The program code can be entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine or entirely on a remote machine or server.
[0101] In the context of this disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0102] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0103] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0104] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server combined with a blockchain.
[0105] It should be understood that the various forms of flow shown above can be used to reorder, add, or delete steps. For example, the steps described in the present disclosure can be performed in parallel, in series, or in a different order, as long as the desired results of the technical solutions of the present disclosure can be achieved, which are not limited herein.
[0106] In addition, the terms "first", "second", are only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present disclosure, the meaning of "multiple" is two or more, unless otherwise specifically limited.
[0107] The above is only a specific embodiment of the present disclosure, but the protection scope of the present disclosure is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present disclosure, which should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A key generation method, applied to a first device, the method comprising: In response to establishing a first connection with the second device, obtain the target public key of the target device shared by the second device; A target key is generated based on the target public key and the first private key of the first device. The target key is used to encrypt and / or decrypt communication data between the first device and the target device. The target device is at least one device in the device group to which the second device is located, and the second device is able to share the public key data of at least one device in the device group with the first device; Wherein, obtaining the target public key of the target device shared by the second device includes at least one of the following: A connection request for establishing the first connection is sent to the second device, such that the second device shares the public key of at least one device that matches the type information of the connection request, wherein each device in the device group is able to share the public key data of the respective device or at least one device with the first device; Obtain the public key of at least one device that matches the permission information shared by the second device; The device sends device information of the first device to the second device, so that the second device shares the public key of at least one device that matches the device information, wherein the second device is able to share the public key data of at least one device in the device group with the first device.
2. The method according to claim 1, wherein, Obtaining the target public key of the target device shared by the second device includes at least one of the following: If the first connection is a first type of connection, obtain the second public key shared by the second device. If the first connection is a second type connection, obtain the public key data of each device in the device group shared by the second device; If the first connection is a third type connection, obtain the third public key of the third device in the device group shared by the second device; If the second device has the first permission, obtain the public key data of each device in the device group shared by the second device; When the second device has the second permission, obtain the fourth public key of the fourth device in the device group shared by the second device, wherein the permission level of the fourth device is lower than the permission level of the second device; If the second device has third permissions, obtain its own second public key shared by the second device.
3. The method according to claim 1, wherein, A target key is generated based on the target public key and the first private key of the first device, including at least one of the following: A first key is generated based on the second public key shared by the second device and the first private key of the first device, for use in encrypting and / or decrypting communication data between the first device and the second device. A second key is generated based on the third public key of the third device in the device group shared by the second device and the first private key of the first device, for use in encrypting and / or decrypting communication data between the first device and the third device; A third key is generated based on the fourth public key of the fourth device in the device group shared by the second device and the first private key of the first device, for use in encrypting and / or decrypting communication data between the first device and the fourth device. Based on the public key data of each device in the device group shared by the second device and the first private key of the first device, multiple keys are generated for each device to encrypt and / or decrypt communication data between the first device and each other.
4. The method of claim 1, further comprising at least one of the following: After establishing a first connection with the second device, the first public key is shared with the second device so that the target device can generate a corresponding target key based on its own private key and the first public key; The generated target key is stored in the secure encryption processor of the first device; In response to obtaining communication data for communicating with the target device, the communication data is encrypted based on the target key and / or the feedback data from the target device regarding the communication data is decrypted.
5. A key generation method, applied to a second device, the method comprising: In response to establishing a first connection with the first device, the target public key of the target device is shared with the first device; The first public key shared by the first device is sent to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key. The target key is used to encrypt and / or decrypt the communication data between the first device and the target device. The target device is at least one device in the device group to which the second device is located, and the second device is able to share the public key data of at least one device in the device group with the first device; Wherein, sharing the target public key of the target device with the first device includes at least one of the following: Obtain a connection request sent by the first device to establish the first connection, and share the public key of at least one device in the device group with the first device based on the type information of the connection request, wherein each device in the device group is able to share the public key data of each device or at least one device with the first device; Obtain the permission information of the second device itself, and share the public key of at least one device in the device group with the first device based on the permission information; The device obtains the device information of the first device, and shares the public key of at least one device in the device group with the first device based on the device information, wherein the second device is able to share the public key data of at least one device in the device group with the first device.
6. The method according to claim 5, wherein, Sharing the target public key of the target device with the first device includes at least one of the following: If the first connection is a first type of connection, share its second public key with the first device; If the first connection is a second type connection, the public key data of each device in the device group is shared with the first device; In the case that the first connection is a third type connection, the third public key of the third device in the device group is shared with the first device; When the second device has the first permission, the public key data of each device in the device group is shared with the first device. When the second device has the second permission, the fourth public key of the fourth device in the device group is shared with the first device, wherein the permission level of the fourth device is lower than the permission level of the second device; If the second device has third permissions, it shares its second public key with the first device. If the first device is a temporary device, share your second public key with the first device; If the first device is a trusted device, the public key data of each device in the device group is shared with the first device.
7. The method according to claim 5, wherein, Sending the first public key shared by the first device to the target device, so that the target device generates a corresponding target key based on its own private key and the first public key, including at least one of the following: A second key is generated based on the first public key shared by the first device and its own second private key, for use in encrypting and / or decrypting communication data between the first device and the second device; The first public key shared by the first device is sent to the third device in the device group, so that the third device generates a third key based on its own third private key and the first public key, which is used to encrypt and / or decrypt communication data between the first device and the third device. The first public key shared by the first device is sent to the fourth device in the device group, so that the fourth device generates a fourth key based on its own fourth private key and the first public key, which is used to encrypt and / or decrypt communication data between the first device and the fourth device. The first public key shared by the first device is sent to each device in the device group, so that each device in the device group generates multiple keys based on its own private key and the first public key, which are used to encrypt and / or decrypt communication data between the first device and each other.
8. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor to perform the method of any one of claims 1-4, and / or the method of any one of claims 5-7.
Citation Information
Patent Citations
Wireless ad hoc network encryption communication method and terminal thereof
CN110381504A
Distributed key management method, electronic equipment and storage medium
CN117041952A