Offline key pool instant expansion method based on key derivation and storage medium

By using the instant expansion method of the key derivation function HKDF to calculate the new key in offline key pools, the problems of limited expansion of the key pool and high key management complexity are solved, and the automatic maintenance of the key pool and the high system's attack resistance are realized.

CN120017286APending Publication Date: 2025-05-16STATE GRID SHANDONG ELECTRIC POWER CO
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510205296.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the existing offline key pool scheme, the scalability of the key pool is limited, resulting in frequent reuse of keys, increasing the risk of attack, and the complexity of key management is high, requiring frequent manual updates, which increases maintenance costs and potential key synchronization problems.

Method used

The real-time expansion method based on key derivation is adopted. By setting a threshold detection mechanism, the number of keys in the key pool is monitored in real time. When the remaining keys are lower than the threshold, the new key is calculated using the key derivation function HKDF, overwrite the original key, and realize the real-time expansion of the offline key pool.

Benefits of technology

Automatic maintenance of key pools is realized, avoiding reuse of keys and frequent manual updates, reducing the complexity of key synchronization and distribution, and improving the system's attack resistance and convenience of key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017286A_ABST
    Figure CN120017286A_ABST
Patent Text Reader

Abstract

The invention discloses an offline key pool instant expansion method based on key derivation, and relates to the technical field of information security. The method comprises the following steps: monitoring the number of keys of a key pool in real time by setting a threshold detection mechanism, and if the number is lower than a preset threshold, triggering key expansion; a key derivation function based on HMAC is adopted, a used key in a key pool is used as an initial key material IKM, a pseudo-random key PRK is calculated in combination with a shared key K and a hash function H, and a plurality of output key materials OKM are generated based on the PRK and context information Info; the new key is stored in the key pool by adopting an overlay writing strategy, so that the security is improved; the method supports dynamic threshold adjustment and multi-stage expansion of the key pool, can reduce key management cost, avoids repeated use of the key, improves system security, and is suitable for a non-networking or low-frequency networking security communication environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the technical field of information security, and in particular to an offline key pool instant expansion method based on key derivation and a storage medium. Background Art

[0002] In the field of information security, key management is an important component of the encryption system, especially in offline environments. Since keys cannot be dynamically updated through the network, the capacity and expansion capability of the key pool become key factors affecting security.

[0003] The offline key pool is a physically or logically isolated key storage mechanism, which is mostly used to store pre-generated keys and provide key support in a specific secure communication environment. The application scenarios of the offline key pool include: power system secure communication (such as encrypted communication between substations and dispatching centers in smart grids), military and government secure communications (such as confidential data transmission), Internet of Vehicles and Internet of Things devices (such as V2X vehicle-mounted communications, sensor networks, etc.), blockchain and financial security (such as cold wallets, transaction signatures, etc.).

[0004] However, in the existing offline key pool scheme, the traditional offline key pool generally pre-stores a limited number of keys. As the system runs, the keys are gradually consumed, and the key pool must be updated manually or regularly, otherwise it will not be able to continue to provide encryption support; at the same time, if the keys in the key pool are frequently reused, attackers can infer the keys through plaintext ciphertext pair analysis, side channel attacks, etc., thereby undermining the security of communications; in addition, key management is highly complex, and key pool updates require manual intervention or the import of new keys from external storage media. This method not only increases maintenance costs, but may also lead to untimely key synchronization problems, affecting system availability.

[0005] In response to the above problems, some existing solutions have been improved, including: regularly distributing new keys through online servers, but this solution relies on network connections and cannot meet the needs of completely offline scenarios; or generating a large number of keys in the initial stage and storing them in the device, but this solution is limited by storage resources and still cannot solve the key leakage problem; or using hardware modules to dynamically generate keys, but this solution is costly and difficult to implement on some embedded or resource-constrained devices.

[0006] Therefore, there is an urgent need for an efficient, instant, and low-cost key pool expansion method to improve the storage efficiency of the offline key pool, reduce the risk of key leakage, and enhance the convenience of key management. Summary of the invention

[0007] In view of the above existing problems, the present invention is proposed.

[0008] The present invention provides an offline key pool instant expansion method based on key derivation and a storage medium to solve the existing scheme of using an offline key pool for encrypted communication. Since the scalability of the key pool is limited and the probability of the same key being cracked if used multiple times will be greatly increased, users often need to frequently update the key pool; this method is not only cumbersome to operate, but also brings unnecessary time loss to communication.

[0009] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0010] In a first aspect, an embodiment of the present invention provides an offline key pool instant expansion method based on key derivation, which comprises:

[0011] Step S1, setting a threshold detection mechanism to monitor the number of keys in the key pool in real time. If the remaining keys are lower than a predetermined threshold, a key update is triggered;

[0012] Step S2, selecting a shared key K, using a preset hash function H for preprocessing, and deciding to compress or pad the key according to the length of the key K and the block size of the hash function H;

[0013] Step S3, calculating multiple key copies according to the key K, and participating in function calculation as part of the key derivation function HKDF;

[0014] Step S4, calculating the value of the hash-based message authentication code HMAC, using the used key in the key pool as the initial key material IKM, using the function H and a copy of the key K to perform hash calculation on IKM, and obtaining the value of HMAC, which is a fixed-length digest and is used as the pseudo-random key PRK;

[0015] Step S5, deriving a plurality of output key materials OKM based on the pseudo-random key PRK according to the set context information Info and the target key length length;

[0016] Step S6, overwrite the original key with the newly generated key to achieve instant expansion of the offline key pool.

[0017] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, the threshold detection mechanism adopts a fixed threshold or a dynamic threshold algorithm, wherein the dynamic threshold is adjusted in real time based on the key pool usage rate or the adaptive security policy.

[0018] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, the key copy calculation step includes:

[0019] 1) Use the shared key K to combine the internal padding byte ipad and the external padding byte opad to perform operations, including XOR operations, to generate two key copies Kin and Kout respectively;

[0020] 2) Calculate HMAC(Kout,HMAC(Kin,IKM)) to generate the pseudo-random key PRK.

[0021] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, wherein: the HMAC calculation step uses SHA-256 as the hash function, wherein:

[0022] If the length of the shared key K is greater than 512 bits, SHA256 is used to compress it to make it fit the length;

[0023] If the length of K is less than 512 bits, it is used directly without additional padding.

[0024] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, the output key material OKM generation process includes:

[0025] Set one or more fixed context strings Info;

[0026] HMAC(PRK,Info||i) is used to calculate OKM. If the required key length exceeds the output length of a single HMAC calculation, multiple rounds of calculations are performed and the results are concatenated to meet the length requirement.

[0027] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, when the newly generated key is stored in the key pool, an overwrite write strategy is adopted to ensure that the old key will not be reused, while avoiding the security risks caused by the expansion of storage space.

[0028] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, the method is applied to a secure communication system that is not connected to the Internet or is connected to the Internet at a low frequency, and includes:

[0029] Offline encrypted storage device;

[0030] Smart grid terminals;

[0031] Vehicle-to-everything (V2X) equipment;

[0032] Military security system.

[0033] As a preferred solution of the offline key pool instant expansion method based on key derivation described in the present invention, the method supports a multi-level expansion mechanism of the key pool. After the primary key pool is exhausted, the secondary key pool is used as a backup key source, and the key pool capacity is dynamically supplemented according to the same key derivation mechanism.

[0034] In a second aspect, an embodiment of the present invention provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the offline key pool instant expansion method based on key derivation as described in the first aspect of the present invention is implemented.

[0035] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the offline key pool instant expansion method based on key derivation as described in the first aspect of the present invention is implemented.

[0036] The beneficial effects of the present invention are as follows: the present invention adopts a key derivation algorithm, does not need to pre-store a large number of keys, can instantly generate new keys when the key pool is close to being exhausted, and realizes key pool expansion in an offline environment.

[0037] The present invention derives different new keys each time, thereby avoiding the risk of repeated use of keys caused by a fixed number of keys in a traditional key pool and improving the system's anti-attack capability.

[0038] The present invention and the scheme avoid frequent manual key update operations, realize automatic maintenance of the key pool, and reduce the complexity of key synchronization and distribution.

[0039] The present invention and method can be widely used in scenarios such as smart grid, military communication, Internet of Vehicles, Internet of Things, blockchain, etc., to provide a safe and reliable key management solution for offline devices.

[0040] In summary, the present invention provides a safe, efficient and low-cost offline key pool expansion solution that can meet the needs of high-security communication systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0042] Figure 1 It is a key derivation flow chart of HKDF of the offline key pool instant expansion method based on key derivation of the present invention.

[0043] Figure 2 It is a structural diagram of the OKM of the offline key pool instant expansion method based on key derivation of the present invention. DETAILED DESCRIPTION

[0044] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0045] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0046] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0047] An offline key pool is a physically or logically isolated key storage medium. Here, "offline" means that a large number of keys are pre-stored in the key pool, which provides the required keys for secure communication in a relatively isolated or non-connected environment. The offline key pool has the functions of key generation, storage, management and retrieval, and can record all operations involving keys for easy tracking and auditing, and implement strict access control policies to ensure that only authorized users or systems can access the keys.

[0048] However, in the existing scheme of using offline key pool for encrypted communication, since the scalability of the key pool is limited and the probability of cracking the same key will be greatly increased if it is used multiple times, users often need to update the key pool frequently. This method is not only cumbersome to operate, but also brings unnecessary time loss to communication.

[0049] Therefore, the present invention proposes an offline key pool instant expansion scheme based on key derivation. When the number of keys in the key pool is lower than a predetermined threshold, the key derivation algorithm is used to regenerate the used keys, and the newly generated keys are used to overwrite the original keys, thereby achieving instant expansion of the offline key pool.

[0050] Glossary:

[0051] Key derivation function (HMAC-based Extract-and-ExpandKey Derivation Function, referred to as HKDF);

[0052] Message Authentication Code (Hash-based Message Authentication Code, referred to as HMAC);

[0053] Initial Keying Material (IKM);

[0054] Pseudo-random key (PRK)

[0055] Output Key Material (OKM).

[0056] Example 1, reference Figure 1 and Figure 2 This embodiment provides a specific implementation scheme for key expansion using HKDF, which specifically includes the following steps:

[0057] Step 1: Key pool capacity monitoring

[0058] Set the threshold detection mechanism of the key pool to monitor the number of available keys in the key pool in real time;

[0059] When the number of available keys N_remain in the key pool is lower than the set threshold T_threshold, the key pool expansion operation is triggered;

[0060] The threshold can be a fixed value or calculated based on a dynamic policy, for example:

[0061] Adjust T_threshold according to the key consumption rate;

[0062] Predict future key needs based on historical usage data.

[0063] Step 2: Key derivation process initialization

[0064] Select a shared key K as the initial key material (InitialKeyingMaterial, IKM);

[0065] Select a hash function H (such as SHA256) as the HMAC calculation function;

[0066] If the key K is longer than 512 bits, H(K) is used for compression to make it compatible with HMAC calculation requirements;

[0067] If the length of K is less than 512 bits, it is used directly.

[0068] Step 3: Calculate the PRK (Pseudo-Random Key)

[0069] Calculate HMAC(Kout,HMAC(Kin,IKM)) to generate a pseudo-random key (PRK):

[0070] Calculate Kin and Kout:

[0071] Kin=K⊕ipad (where ipad is 0x36 repeated 64 times)

[0072] Kout = K⊕opad (where opad is 0x5C repeated 64 times)

[0073] Calculation of PRK:

[0074] PRK=HMAC(Kout,HMAC(Kin,IKM)),

[0075] The PRK serves as the basic material for key derivation and can be used to generate multiple new keys.

[0076] Step 4: Generate new output key material (OKM)

[0077] Set one or more context information Info, for example:

[0078] Version number, protocol identifier, device ID, etc. to ensure that different keys are generated in different scenarios.

[0079] Calculate OKM(OutputKeyMaterial):

[0080] Use HMAC to calculate OKM, and concatenate multiple HMAC results until the required key length L_output is met:

[0081] OKM1=HMAC(PRK,Info||1),

[0082] OKM2=HMAC(PRK,OKM1||Info||2), ...

[0084] Splice OKM1, OKM2, ..., OKM n Until L_output is satisfied;

[0085] The generated OKM is stored in the key pool as a new key.

[0086] Step 5: Key pool update

[0087] Write the generated new key to the key pool and use the overwrite write strategy:

[0088] If there is still space in the key pool: append the new key to the key pool;

[0089] If the key pool is full: overwrite the earliest used key to ensure the continued availability of the key pool and prevent key storage expansion.

[0090] This embodiment also provides a computer device, which is applicable to a method for instant expansion of an offline key pool based on key derivation, and includes: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute computer executable instructions to implement a method for instant expansion of an offline key pool based on key derivation as proposed in the above embodiment.

[0091] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.

[0092] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, an offline key pool instant expansion method based on key derivation proposed in the above embodiment is implemented; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, referred to as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, referred to as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, referred to as EPROM), programmable read-only memory (Programmable Red-Only Memory, referred to as PROM), read-only memory (Read-Only Memory, referred to as ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0093] Embodiment 2: This embodiment provides an offline key pool extension suitable for smart grid secure communication, which is applied to smart grid terminal devices, such as secure communication between a substation and a dispatching center.

[0094] The key pool is stored in the terminal device, and the key expansion scheme is as follows:

[0095] 1. Set the initial capacity of the key pool of the smart grid terminal N_init = 1000, and set the dynamic threshold T_threshold = 200.

[0096] 2. When the number of remaining keys is lower than T_threshold, the key expansion mechanism is triggered:

[0097] Use the device's unique ID as Info;

[0098] Calculate PRK and generate new key based on HKDF;

[0099] A key rotation strategy is adopted to ensure that new keys are used first and old keys are gradually phased out.

[0100] This method can ensure the continuous availability of the key pool when the terminal device is not connected to the Internet.

[0101] Embodiment 3, this embodiment provides an offline key expansion suitable for blockchain cold wallets, which is applied to blockchain cold wallets. Its main requirement is to store private keys offline to prevent hacker attacks:

[0102] 1. When initializing the cold wallet, set the initial private key pool size to 500;

[0103] 2. Set security policy: When the number of remaining private keys is less than 50, trigger the key expansion mechanism;

[0104] 3. Generate a new private key using HKDF and store it in a secure storage area:

[0105] Use the mnemonic seed as K;

[0106] Use the BIP32 derivation mechanism to generate new keys;

[0107] Combine HMACSHA512 for multi-layer key derivation to ensure security;

[0108] 4. This solution can effectively reduce the risk of key reuse and improve the long-term security of the wallet.

[0109] In summary, the offline key pool instant expansion method based on key derivation of the present invention generates new keys through HKDF, can dynamically expand the key pool, and is suitable for a variety of secure communication scenarios.

[0110] Compared with the traditional offline key management method, this solution:

[0111] No need to store a large number of keys additionally, reducing the complexity of key management;

[0112] Improve the automation level of key updates to avoid security risks caused by manual operations;

[0113] Applicable to a variety of offline environments, such as smart grid, military communications, blockchain, etc.

[0114] Improve key security and reduce security risks caused by key reuse.

[0115] The present invention provides an efficient, secure and low-cost key pool expansion solution, which can meet the strict requirements of modern secure communication systems for key management.

[0116] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for instant expansion of offline key pool based on key derivation, characterized in that: include, Step S1, setting a threshold detection mechanism to monitor the number of keys in the key pool in real time. If the remaining keys are lower than a predetermined threshold, a key update is triggered; Step S2, selecting a shared key K, using a preset hash function H for preprocessing, and deciding to compress or pad the key according to the length of the key K and the block size of the hash function H; Step S3, calculating multiple key copies according to the key K, and participating in function calculation as part of the key derivation function HKDF; Step S4, calculating the value of the hash-based message authentication code HMAC, using the used key in the key pool as the initial key material IKM, using the function H and a copy of the key K to perform hash calculation on IKM, and obtaining the value of HMAC, which is a fixed-length digest and is used as the pseudo-random key PRK; Step S5, deriving a plurality of output key materials OKM based on the pseudo-random key PRK according to the set context information Info and the target key length length; Step S6, overwrite the original key with the newly generated key to achieve instant expansion of the offline key pool.

2. The method for instant expansion of an offline key pool based on key derivation according to claim 1, characterized in that: The threshold detection mechanism adopts a fixed threshold or a dynamic threshold algorithm, wherein the dynamic threshold is adjusted in real time based on the key pool usage rate or the adaptive security policy.

3. The method for instant expansion of an offline key pool based on key derivation as claimed in claim 2, characterized in that: The key copy calculation step comprises: 1) Use the shared key K to combine the internal padding byte ipad and the external padding byte opad to perform operations, including XOR operations, to generate two key copies Kin and Kout respectively; 2) Calculate HMAC to generate a pseudo-random key PRK.

4. The method for instant expansion of an offline key pool based on key derivation as claimed in claim 3, characterized in that: The HMAC calculation step uses SHA-256 as the hash function, where: If the length of the shared key K is greater than 512 bits, SHA256 is used to compress it to make it fit the length; If the length of K is less than 512 bits, it is used directly without additional padding.

5. The method for instant expansion of an offline key pool based on key derivation as claimed in claim 4, characterized in that: The output key material OKM generation process includes: Set one or more fixed context strings Info; HMAC(PRK,Info||i) is used to calculate OKM. If the required key length exceeds the output length of a single HMAC calculation, multiple rounds of calculations are performed and the results are concatenated to meet the length requirement.

6. The method for instant expansion of an offline key pool based on key derivation as claimed in claim 5, characterized in that: When the newly generated key is stored in the key pool, an overwrite write strategy is adopted.

7. The method for instant expansion of offline key pool based on key derivation as claimed in claim 6, characterized in that: The method is applied to safety communication systems that are not connected to the Internet or are connected to the Internet at a low frequency, including: Offline encrypted storage device; Smart grid terminals; Vehicle-to-everything (V2X) equipment; Military security system.

8. The method for instant expansion of offline key pool based on key derivation as claimed in claim 7, characterized in that: This method supports a multi-level expansion mechanism of the key pool. After the primary key pool is exhausted, the secondary key pool is used as a backup key source, and the key pool capacity is dynamically supplemented according to the same key derivation mechanism.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the offline key pool instant expansion method based on key derivation according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the offline key pool instant expansion method based on key derivation according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Key management method and key distribution system

    CN121690568A

  • Key management method and key distribution system

    CN121690568B