Method for joining trust ring
By establishing a trust ring between devices, using the same account device certificate and trust root data for verification and encryption and decryption, the problem of browsing cloud identity authentication in the existing technology is solved, and the data security of the interconnection between devices and users is enhanced.
Patent Information
- Application Number
- CN202311667846.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-06
- Publication Date
- 2025-06-06
AI Technical Summary
In the prior art, the identity authentication of the interconnection between the device and the user depends on the account password. Cloud verification poses the risk of counterfeiting users. Users cannot control the security of cloud data, resulting in concerns about privacy data leakage.
By establishing a trust ring between the device to be authenticated and the trusted device, using the same account device certificate for verification, and receiving trust root data (including root key and root certificate) is received to join the trust ring. The signature of trusted root data is jointly performed by the same account CA, trusted ring CA and cloud server to ensure the legality and validity of the root certificate.
By verifying the device certificate of the same account of the trust device and the device to be verified, ensure that the device belongs to the same account name, avoiding devices with different accounts joining the trust ring, and enhancing data security. At the same time, trust root data is used for encryption and decryption to ensure the security of the root key and avoid data being manipulated in the cloud.
Smart Images

Figure CN120110672A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and specifically provides a method for joining a trust ring. Background Art
[0002] At present, the identity authentication for the interconnection between devices and users is based on account authentication. Devices logged in with the same account can interconnect and transfer data. However, since the account and password are verified in the cloud, there is a possibility of impersonation of users in the cloud, and user data or devices can be accessed without an account and password. In addition, after user data is uploaded to the cloud, the data completely relies on the protection of cloud services. Users have no control over cloud data leakage, illegal access, and other behaviors. Therefore, there are news reports of background data leakage from time to time, which makes users very worried about the security of their privacy data.
[0003] Accordingly, the art needs a new method for adding a trust ring to solve the above problems. Summary of the invention
[0004] In order to overcome the above-mentioned defects, the present application is proposed to provide a method for adding a trust ring that solves or at least partially solves the technical problem of poor data security in the prior art.
[0005] In a first aspect, the present application provides a method for joining a trust ring, which is performed by a device to be authenticated, and the method includes:
[0006] Obtaining verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring;
[0007] Receiving the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the CA with the same account, the trusted ring CA and the cloud server;
[0008] According to the trust root data, join the trust ring.
[0009] In a technical solution of the above method for adding a trust ring, the root certificate is obtained by the following steps:
[0010] The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information;
[0011] The trusted device sends the first signature information to a cloud server, so that the cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate;
[0012] The trust device receives the root certificate sent by the cloud server.
[0013] In a technical solution of the above-mentioned method for adding a trust ring, the verification of obtaining a trusted device based on a device certificate of the same account includes:
[0014] The same-account device certificate is sent to the trusted device, so that the trusted device verifies the received same-account device certificate of the device to be authenticated based on its own same-account device certificate.
[0015] In a technical solution of the above method for joining a trust ring, joining the trust ring according to the trust root data includes:
[0016] Based on the trusted ring CA, verify the signature of the root certificate and determine whether the device sending the root certificate is the trusted device;
[0017] After the verification is passed, confirm to join the trust ring.
[0018] In one technical solution of the above-mentioned method for joining a trust ring, the root key is received in ciphertext form, wherein the root key is encrypted by the trusted device based on the same account device certificate of the device to be authenticated;
[0019] The method further comprises:
[0020] Based on the device certificate of the same account of the device to be authenticated, the ciphertext is decrypted to obtain the root key.
[0021] In a second aspect, the present application provides a method for joining a trust ring, the method comprising:
[0022] The device to be authenticated sends its own device certificate with the same account to the trusted device, wherein the trusted device is a device that already exists in the trust ring;
[0023] The trusted device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account;
[0024] If the verification is successful, the trusted device sends the trusted root data to the device to be authenticated, wherein the trusted root data includes a root key and a root certificate;
[0025] The device to be authenticated joins the trust ring according to the trust root data.
[0026] In a technical solution of the above method for adding a trust ring, the root certificate is obtained by the following steps:
[0027] The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information;
[0028] The trusted device sends the first signature information to a cloud server;
[0029] The cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate;
[0030] The trust device receives the root certificate sent by the cloud server.
[0031] In a technical solution of the above method for joining a trust ring, the device to be authenticated joins the trust ring according to the trust root data, including:
[0032] The device to be authenticated verifies the signature of the root certificate based on the trusted ring CA, and determines whether the device sending the trusted device root certificate is the trusted device;
[0033] After the verification is passed, the device to be authenticated confirms to join the trust ring.
[0034] In a technical solution of the above method for adding a trust ring, the method further includes:
[0035] The trusted device encrypts the root key based on the device certificate with the same account number of the device to be authenticated, so that the root key is sent in ciphertext form;
[0036] The device to be authenticated decrypts the ciphertext based on its own device certificate with the same account number, so that the device to be authenticated obtains the root key.
[0037] In a third aspect, the present application provides a device to be authenticated, the device to be authenticated comprising:
[0038] A data sending module, wherein the data sending module is configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring;
[0039] A data receiving module, wherein the data receiving module is configured to receive the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the same account CA, the trusted ring CA and the cloud server;
[0040] A data processing module, wherein the data processing module is configured to join the trust ring according to the trust root data.
[0041] In a fourth aspect, the present application provides a data protection system, comprising at least a cloud server, a device to be authenticated, and a trusted device, wherein the data protection system is used to execute any one of the technical solutions in the above-mentioned method of joining a trust ring.
[0042] In a fifth aspect, the present application provides an electronic device, comprising one or more memories and one or more processors, wherein the memories are used to store computer programs; the processors are used to call the computer programs so that the electronic device executes any technical solution in the above-mentioned method of joining a trust ring.
[0043] In a sixth aspect, the present application provides a computer-readable storage medium, comprising computer instructions; when the computer instructions are executed on an electronic device, the electronic device is enabled to execute any technical solution in the above-mentioned method of joining a trust ring.
[0044] In a seventh aspect, the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute any one of the above-mentioned technical solutions for joining a trust ring.
[0045] Solution 1. A method for joining a trust ring, performed by a device to be authenticated, characterized in that the method comprises:
[0046] Obtaining verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring;
[0047] Receiving the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the CA with the same account, the trusted ring CA and the cloud server;
[0048] According to the trust root data, join the trust ring.
[0049] Solution 2. The method according to Solution 1, characterized in that the root certificate is obtained by the following steps:
[0050] The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information;
[0051] The trusted device sends the first signature information to the cloud server, so that the cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate;
[0052] The trust device receives the root certificate sent by the cloud server.
[0053] Solution 3. The method according to Solution 1 is characterized in that the verification of obtaining a trusted device based on a device certificate with the same account includes:
[0054] The same-account device certificate is sent to the trusted device, so that the trusted device verifies the received same-account device certificate of the device to be authenticated based on its own same-account device certificate.
[0055] Solution 4. The method according to Solution 1, characterized in that adding the trust ring according to the trust root data comprises:
[0056] Based on the trusted ring CA, verify the signature of the root certificate and determine whether the device sending the root certificate is the trusted device;
[0057] After the verification is passed, confirm to join the trust ring.
[0058] Scheme 5. The method according to Scheme 4, characterized in that:
[0059] The root key is received in ciphertext form, wherein the root key is encrypted by the trusted device based on the device certificate of the same account as the device to be authenticated;
[0060] The method further comprises:
[0061] Based on the device certificate of the same account of the device to be authenticated, the ciphertext is decrypted to obtain the root key.
[0062] Solution 6. A method for joining a trust ring, characterized in that the method comprises:
[0063] The device to be authenticated sends its own device certificate with the same account to the trusted device, wherein the trusted device is a device that already exists in the trust ring;
[0064] The trusted device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account;
[0065] If the verification is successful, the trusted device sends the trusted root data to the device to be authenticated, wherein the trusted root data includes a root key and a root certificate;
[0066] The device to be authenticated joins the trust ring according to the trust root data.
[0067] Solution 7. The method according to Solution 6 is characterized in that the root certificate is obtained by the following steps:
[0068] The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information;
[0069] The trusted device sends the first signature information to the cloud server;
[0070] The cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate;
[0071] The trust device receives the root certificate sent by the cloud server.
[0072] Solution 8. The method according to Solution 6 is characterized in that the device to be authenticated joins the trust ring according to the trust root data, comprising:
[0073] The device to be authenticated verifies the signature of the root certificate based on the trusted ring CA, and determines whether the device sending the trusted device root certificate is the trusted device;
[0074] After the verification is passed, the device to be authenticated confirms to join the trust ring.
[0075] Solution 9. The method according to Solution 6, characterized in that the method further comprises:
[0076] The trusted device encrypts the root key based on the device certificate with the same account number of the device to be authenticated, so that the root key is sent in ciphertext form;
[0077] The device to be authenticated decrypts the ciphertext based on its own device certificate with the same account number, so that the device to be authenticated obtains the root key.
[0078] Solution 10. A device to be authenticated, characterized in that the device to be authenticated comprises:
[0079] A data sending module, wherein the data sending module is configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring;
[0080] A data receiving module, wherein the data receiving module is configured to receive the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the same account CA, the trusted ring CA and the cloud server;
[0081] A data processing module, wherein the data processing module is configured to join the trust ring according to the trust root data.
[0082] Scheme 11. A data protection system, characterized in that the system includes at least a device to be authenticated, a trusted device and a cloud server, and the data protection system is used to execute any one of the methods described in Schemes 1-9.
[0083] Solution 12. An electronic device, comprising one or more memories and one or more processors, wherein the memory is used to store a computer program; the processor is used to call the computer program so that the electronic device executes the method described in any one of Solutions 1-9.
[0084] Solution 13. A computer-readable storage medium, characterized in that it includes computer instructions; when the computer instructions are executed on an electronic device, the electronic device is enabled to execute any one of the methods described in Solutions 1-9.
[0085] The above one or more technical solutions of the present application have at least one or more of the following beneficial effects:
[0086] In the technical solution for implementing this application, the verification of the trusted device is obtained based on the same-account device certificate. After the verification is passed, the trusted root data sent by the trusted device is received, so that the device to be authenticated joins the trust ring according to the trusted root data. In this application, the root certificate sent by the trusted device is obtained after the root key is signed by the same-account CA of the account service and the trusted ring CA of the trust ring service. These two signatures ensure the legitimacy and validity of the root certificate finally generated in the trust ring; in this application, data is interacted between devices, which avoids the situation where data is manipulated in the cloud and ensures the security of data.
[0087] Furthermore, in the process of obtaining the verification of the trusted device based on the same-account device certificate, the trusted device verifies the same-account device certificate of the received device to be authenticated based on its own same-account device certificate. This application first verifies the same-account device certificates of the trusted device and the device to be authenticated to ensure that the device to be authenticated to be added to the trust ring and the trusted device already in the trust ring belong to the same account name. After this verification process, it prevents devices under different account names from joining the trust ring established by other accounts, further ensuring data security.
[0088] Furthermore, the signature of the root certificate is verified based on the trusted ring CA to determine whether the device that sent the root certificate is a trusted device; after the verification is passed, the device to be authenticated confirms to join the trusted ring. This application further ensures data security by authenticating the trusted device on the device to be authenticated, combined with the above-mentioned authentication of the device to be authenticated on the trusted device, through mutual authentication between the two devices.
[0089] Furthermore, the root key of the trusted device is encrypted by the trusted device based on the device certificate of the same account as the device to be authenticated. The device to be authenticated receives the root key ciphertext and decrypts it based on its device certificate of the same account to obtain the root key. In this application, based on the device certificate of the same account as the device to be authenticated, the root key is encrypted on the trusted device side, and the root key ciphertext is decrypted on the device to be authenticated. This encryption strategy ensures that the root key ciphertext can only be decrypted by the specified device to be authenticated, further ensuring the security of the data.
[0090] Furthermore, in the process of signing the root key of the trusted device to obtain the root certificate of the device to be authenticated, the root key is first signed based on the CA of the same account of the account service, and then the first signature information is sent to the server. The server signs the first signature information for the second time based on the trusted ring CA of the trust ring service, and finally the trusted device receives the root certificate issued by the server. In this application, only the root certificate obtained after two signatures is valid. Using a valid root certificate for identity authentication or data transmission can ensure data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] The disclosure of the present application will become more easily understood with reference to the accompanying drawings. It is easy for those skilled in the art to understand that these drawings are only for illustrative purposes and are not intended to limit the scope of protection of the present application. In addition, similar numbers in the drawings are used to represent similar components, among which:
[0092] Figure 1 This is a flowchart of the main steps of a method for joining a trust ring according to an embodiment of the present application;
[0093] Figure 2 This is a schematic diagram of the data interaction timing of a method for joining a trust ring according to an embodiment of the present application;
[0094] Figure 3 is an implementation example diagram of a method for obtaining a root certificate according to an embodiment of the present application;
[0095] Figure 4 is an implementation example diagram of a method for joining a trust ring according to an embodiment of the present application;
[0096] Figure 5 is an example diagram of an implementation of data protection by a device in a trust ring according to an embodiment of the present application;
[0097] Figure 6 is a schematic diagram of the main structure of a device to be authenticated according to an embodiment of the present application;
[0098] Figure 7 is a schematic diagram of the internal structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0099] Some embodiments of the present application are described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present application and are not intended to limit the protection scope of the present application.
[0100] In the description of the present application, "module" and "processor" may include hardware, software or a combination of the two. A module may include hardware circuits, various suitable sensors, communication ports, memory, and may also include software parts, such as program code, or a combination of software and hardware. The processor may be a central processing unit, a microprocessor, an image processor, a digital signal processor or any other suitable processor. The processor has data and / or signal processing functions. The processor may be implemented in software, hardware or a combination of the two. Non-temporary computer-readable storage media include any suitable medium that can store program code, such as a disk, a hard disk, an optical disk, a flash memory, a read-only memory, a random access memory, etc. The term "A and / or B" means all possible combinations of A and B, such as only A, only B or A and B. The term "at least one A or B" or "at least one of A and B" has a similar meaning to "A and / or B" and may include only A, only B or A and B. The singular terms "one" and "the" may also include plural forms.
[0101] The relevant user personal information that may be involved in the various embodiments of this application is strictly in accordance with the requirements of laws and regulations, following the principles of legality, legitimacy and necessity, based on the reasonable purposes of business scenarios, to process the personal information that users actively provide during the use of products / services or generated due to the use of products / services, as well as the personal information obtained with the user's authorization.
[0102] The user personal information processed by this application will vary depending on the specific product / service scenario, and will be based on the specific scenario in which the user uses the product / service. It may involve the user's account information, device information, driving information, vehicle information or other related information. The applicant will treat the user's personal information and its processing with a high degree of diligence.
[0103] This application attaches great importance to the security of user personal information and has taken reasonable and feasible security protection measures that meet industry standards to protect user information and prevent personal information from being accessed, disclosed, used, modified, damaged or lost without authorization.
[0104] Please refer to the attached Figure 1 , Figure 1 FIG. 1 is a flow chart of the main steps of a method for joining a trust ring according to an embodiment of the present application. Figure 1As shown, the method for joining a trust ring of the present application mainly includes steps S11 to S14:
[0105] Step S11: The device to be authenticated sends its own device certificate with the same account to the trusted device.
[0106] In this embodiment, the device to be authenticated is a device that has not joined the trust ring and is undergoing identity authentication to join the trust ring. Similarly, the trusted device is a device that has joined the trust ring, where the trust ring is a trust chain composed of mutually trusted devices, and the devices in the trust ring are all trusted devices.
[0107] In this embodiment, the same-account device certificate includes the device information of the device to be authenticated and the ID information of the user account. In one implementation, the same-account device certificate can be obtained based on the following steps: first, the server issues a device certificate for the device to be authenticated based on the device CA, wherein the device CA is used to sign the certificate of the device or application, and the device certificate includes the device information of the device to be authenticated; then, the device certificate and the user account password are sent to the server. After the server verifies the user account password, the server issues a same-account device certificate for the device to be authenticated based on the same-account CA of the account service, and the same-account device certificate includes the device information of the device to be authenticated and the user account ID information, so as to bind the user account with the device.
[0108] Step S12: The trusting device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account.
[0109] In this embodiment, the device certificate with the same account number of the trusted device itself and the device certificate with the same account number of the device to be authenticated in the above step S11 are obtained in the same way and have the same function.
[0110] In this embodiment, the device certificate with the same account of the device to be authenticated is verified based on the device certificate with the same account of the trusted device. It can be determined whether the two devices belong to the same user account by verifying whether the part of the information related to the user account ID contained in the two devices is consistent.
[0111] Step S13: If the verification is successful, the trusted device sends the trusted root data to the device to be authenticated.
[0112] In this embodiment, the trusted root data includes at least the root key and root certificate of the trusted device. The trusted device can send the root key and root certificate to the device to be authenticated in batches to further ensure data security. For example, the root certificate is first sent for verification by the device to be authenticated, and the root key is sent after the verification is passed; the root key and root certificate can also be sent to the device to be authenticated at one time to improve the efficiency of identity authentication. The specific transmission method is not limited here. The trusted root data can also include a trusted device certificate issued by the trusted device to the device to be authenticated. The certificate is usually associated with the device certificate of the same account of the device to prove that the device to be authenticated is a trusted device that has passed the verification.
[0113] In this embodiment, the root certificate is obtained by the server signing the root key based on the trusted ring CA of the trusted ring service, wherein the trusted ring CA is the root CA, which has the highest level of the entire PKI system and is a starting point of trust. In one implementation, the root certificate of the trusted device is obtained by the following steps: the trusted device signs the root key for the first time based on the same account CA of the account service; the trusted ring CA signs the root key for the second time based on the first signature; and the root certificate is obtained after two signatures.
[0114] Step S14: The device to be authenticated joins the trust ring according to the trust root data.
[0115] In this embodiment, since the trusted device has verified and passed the identity of the device to be authenticated through the above steps, the next process of joining the trust ring depends on the device to be authenticated. The device to be authenticated can also verify the identity of the trusted device again, and only choose to join the trust ring after the verification is passed.
[0116] In one embodiment, the device to be authenticated needs to verify the identity of the trusted device, and the verification process includes at least the following steps: the device to be authenticated verifies the signature of the root certificate of the trusted device based on the trusted ring CA to determine whether the device sending the root certificate is the trusted device. The trusted ring CA can come from the trusted device, for example, it can be included in the trusted root data and sent to the device to be authenticated together with the root key and root certificate; it can also come from the cloud server. When the device to be authenticated receives the root certificate of the trusted device, it sends a request to the cloud server to call the trusted ring CA. The cloud server responds to the request and sends the trusted ring CA to the device to be authenticated.
[0117] In this embodiment, after the device to be authenticated joins the trust ring, its role is changed to a trusted device, and the received trust root data can be used to invite other devices to be authenticated to join the trust ring. Therefore, it can be seen that the trust ring manages the devices to be authenticated based on the transfer of root keys and root certificates.
[0118] From the above description of the embodiments of the present application, it can be seen that in the present application, the root certificate sent by the trusted device is obtained after the root key is signed by the same-account CA of the account service and the trusted ring CA of the trust ring service. These two signatures ensure the legitimacy and validity of the finally generated root certificate in the trust ring; the present application performs identity authentication based on the same-account device certificate and trusted root data, and there is no need to upload private data to the cloud, which avoids the manipulation of data in the cloud and ensures the security of the data.
[0119] Please refer to the attached Figure 2 , Figure 2 1 is a schematic diagram of the data interaction sequence of a method for joining a trust ring according to an embodiment of the present application. Figure 2 Based on the Figure 3 , Figure 3 FIG. 1 is an implementation example diagram of a method for obtaining a root certificate according to an embodiment of the present application. Figure 3 In the implementation example shown, the root certificate is obtained by following the steps below:
[0120] 1. The device CA creates a device certificate request (CSR), which contains the device's public key and some other information, such as the device's identification information. After the device CA confirms the device's identity, it signs the device's CSR to generate a device certificate. The generated device certificate is returned to the device.
[0121] 2.1. Use the device certificate to verify whether the account password comes from a specific device.
[0122] 2.2. Send the device certificate and account password to the account service center in the cloud;
[0123] 2.3. The Account Service Center verifies whether the account password is correct and sends the verification result to the CA with the same account;
[0124] 2.4. If the verification result is correct, the CA with the same account will sign the data information and account password contained in the device certificate to obtain the device certificate with the same account to prove that the device is bound to the specified user account name;
[0125] 3.1. The device generates a root key and signs the root key for the first time based on the CA with the same account to obtain the first signature information to prove that the root key is issued from the designated device with the same account. The first signature information includes the signature result and the public key of the root key.
[0126] 3.2. Send the first signature information to the server to obtain the device key certificate and confirm that the root key comes from the specified device with the same account;
[0127] 3.3. The server signs the first signature information for the second time based on the trusted ring CA to obtain a compliant root certificate.
[0128] 3.4. Return the root certificate to the device.
[0129] In the attached Figure 2 Based on the Figure 4 , Figure 4 FIG. 1 is an implementation example diagram of a method for joining a trust ring according to an embodiment of the present application. Figure 4 In the implementation example shown, the new mobile phone 2 (device to be authenticated) is added to the trust ring where the old mobile phone 1 (trusted device) is located by the following method of adding the trust ring:
[0130] a. New phone 2 sends a request to join the trust ring to old phone 1;
[0131] b. Old mobile phone 1 confirms the request;
[0132] c. The old mobile phone 1 notifies the new mobile phone 2 of the confirmation result;
[0133] d. New phone 2 sends its own device certificate with the same account to old phone 1;
[0134] e. The old mobile phone 1 verifies the device certificate of the new mobile phone 2 based on its own device certificate of the same account to determine whether the two belong to the same account;
[0135] f. After the old phone 1 passes the identity authentication of the new phone 2, the old phone 1 sends the root certificate to the new phone 2;
[0136] g. The new phone 2 reversely verifies the signature information of the root certificate based on the trusted ring CA of the server to determine whether the root certificate comes from the designated trusted device. In practice, there is a possibility that the new phone 2 actively requests to be added to the trusted ring of the old phone 1 by mistake. Therefore, the purpose of this setting is to eliminate the possibility that the new phone 2 is added to the wrong trusted ring due to human error.
[0137] h. New mobile phone 2 notifies old mobile phone 1 of the identity verification result of old mobile phone 1;
[0138] i. The old phone 1 uses the device certificate of the same account of the new phone 2 to encrypt the root key;
[0139] j. The old mobile phone 1 sends the root key ciphertext and the trusted device certificate issued for the new mobile phone 2 to the new mobile phone 2;
[0140] k. New mobile phone 2 uses its own device certificate with the same account to decrypt the root key ciphertext and obtain the root key;
[0141] l. New phone 2 confirms to join the trust ring and sends the confirmation result to old phone 1 and the server.
[0142] It should be understood that the description in this implementation example is only used to explain the present invention, and the above description does not have a limiting effect.
[0143] Please refer to the attached Figure 5 , Figure 5 FIG. 1 is a flow chart of the main steps of protecting data by a device in a trust ring according to an embodiment of the present application. Figure 5 As shown in the figure, the process of data protection by devices in the trust ring can be described as:
[0144] The trusted device of the data sender uses its own root key to encrypt the data to be transmitted, and then sends the obtained ciphertext data to the data receiver; the trusted device of the data receiver uses its own root key to decrypt the received ciphertext data to obtain the data to be transmitted.
[0145] In this embodiment, since the trusted device of the data sender and the trusted device of the data receiver are in the same trust ring, they both have the same root key. In addition to the trusted device, the data receiver may also include other devices that are not in the trust ring. Since these devices do not have the same root key as the trusted device, they cannot decrypt the received ciphertext data. Figure 5 In the implementation example shown, mobile phone 3 does not belong to the trust ring where mobile phone 1 and mobile phone 2 are located, so mobile phone 3 does not have the same root key as mobile phone 1 and mobile phone 2. Even if mobile phone 3 receives the encrypted data sent by mobile phone 1, it still cannot decrypt it.
[0146] The above describes the method for joining a trust ring provided by the present application. It should be pointed out that although the various steps are described in a specific order in the above embodiments, those skilled in the art can understand that in order to achieve the effect of the present application, different steps do not have to be executed in such an order. They can be executed simultaneously (in parallel) or in other orders. These changes are within the scope of protection of the present application.
[0147] Furthermore, the present application also provides a device to be authenticated.
[0148] See attached Figure 6 , Figure 6 FIG. 1 is a main structural block diagram of a device to be authenticated according to an embodiment of the present application. Figure 6As shown, the device to be authenticated in the embodiment of the present application mainly includes a data sending module 11, a data receiving module 12 and a data processing module 13. In some embodiments, one or more of the data sending module 11, the data receiving module 12 and the data processing module 13 can be combined into one module. In some embodiments:
[0149] The data sending module 11 is configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring;
[0150] The data receiving module 12 is configured to receive the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the CA with the same account, the trusted ring CA and the cloud server;
[0151] The data processing module 13 is configured to join the trust ring according to the trust root data.
[0152] The above-mentioned equipment to be authenticated is used to execute Figures 1 to 5 The embodiment of the method for adding a trust ring shown in the figure has similar technical principles, technical problems solved and technical effects produced. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process and related instructions of the device to be authenticated can refer to the contents described in the embodiment of the method for adding a trust ring, and will not be repeated here.
[0153] It is understood by those skilled in the art that all or part of the processes in the method for implementing the above-mentioned embodiment of the present application can also be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of each of the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable storage medium may include: any entity or device, medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory, random access memory, electric carrier signal, telecommunication signal and software distribution medium that can carry the computer program code. It should be noted that the content contained in the computer-readable storage medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable storage media do not include electric carrier signals and telecommunication signals.
[0154] Furthermore, the present application also provides a data protection system, which includes at least a cloud server, a device to be authenticated, and a trusted device, and the system is used to execute any one of the technical solutions in the above-mentioned method of joining a trust ring.
[0155] It is understood by those skilled in the art that each module in the device can be adaptively split or merged. Such splitting or merging of specific modules will not cause the technical solution to deviate from the principle of the present application, and therefore, the technical solutions after splitting or merging will fall within the protection scope of the present application.
[0156] Furthermore, the present application also provides an electronic device, see the attached Figure 7 , Figure 7 It is a schematic diagram of the internal structure of an electronic device according to an embodiment of the present application. The electronic device includes one or more memories and one or more processors. The memories are used to store computer programs; the processors are used to call computer programs so that the electronic device executes any one of the technical solutions in the method of adding a trusted ring. Among them, the processor can adopt a general central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), a graphics processing unit (GPU) or one or more integrated circuits to execute related programs to implement the method in any one of the implementation methods of the present application. The processor can also be an integrated circuit electronic device with signal processing capabilities. In the implementation process, the appendix of this application Figure 1 To Attachment Figure 5Each step of the method in any of the implementations can be completed by an integrated logic circuit of hardware in the processor or by instructions in the form of software. The above-mentioned processor can also be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The various methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory, and combines its hardware to complete the functions required to be performed by the units included in the data processing device of the embodiment of the present application, or executes the attached embodiment of the present application. Figure 1 To Attachment Figure 5 Each step of the method in any one of the implementations.
[0157] Furthermore, the present application also provides a computer-readable storage medium. In a computer-readable storage medium embodiment according to the present application, the computer-readable storage medium can be configured to store a program for executing the method of adding a trusted ring in the above-mentioned method embodiment, and the program can be loaded and run by the processor to implement any one of the technical solutions in the above-mentioned method of adding a trusted ring. For ease of explanation, only the parts related to the embodiment of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiment of the present application. The computer-readable storage medium can be a storage device formed by various electronic devices. Optionally, the computer-readable storage medium in the embodiment of the present application is a non-temporary computer-readable storage medium.
[0158] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product, which includes one or more computer instructions. When loading and executing computer instructions on a computer, the process or function described in accordance with the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. Computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center.
[0159] So far, the technical solutions of the present application have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments. Without departing from the principles of the present application, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present application.
Claims
1. A method for joining a trust ring, performed by a device to be authenticated, It is characterized in that The method comprises: Obtaining verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring; Receiving the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the CA with the same account, the trusted ring CA and the cloud server; According to the trust root data, join the trust ring.
2. The method according to claim 1, It is characterized in that The root certificate is obtained by the following steps: The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information; The trusted device sends the first signature information to the cloud server, so that the cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate; The trust device receives the root certificate sent by the cloud server.
3. The method according to claim 1, It is characterized in that The verification of obtaining a trusted device based on a device certificate of the same account includes: The same-account device certificate is sent to the trusted device, so that the trusted device verifies the received same-account device certificate of the device to be authenticated based on its own same-account device certificate.
4. The method according to claim 1, It is characterized in that The adding the trust ring according to the trust root data comprises: Based on the trusted ring CA, verify the signature of the root certificate and determine whether the device sending the root certificate is the trusted device; After the verification is passed, confirm to join the trust ring.
5. The method according to claim 4, It is characterized in that The root key is received in ciphertext form, wherein the root key is encrypted by the trusted device based on the device certificate of the same account as the device to be authenticated; The method further comprises: Based on the device certificate of the same account of the device to be authenticated, the ciphertext is decrypted to obtain the root key.
6. A method of joining a trust ring, It is characterized in that The method comprises: The device to be authenticated sends its own device certificate with the same account to the trusted device, wherein the trusted device is a device that already exists in the trust ring; The trusted device verifies the received device certificate of the device to be authenticated based on its own device certificate of the same account; If the verification is successful, the trusted device sends the trusted root data to the device to be authenticated, wherein the trusted root data includes a root key and a root certificate; The device to be authenticated joins the trust ring according to the trust root data.
7. The method according to claim 6, It is characterized in that The root certificate is obtained by the following steps: The trusted device signs the root key for the first time based on the CA with the same account to obtain the first signature information; The trusted device sends the first signature information to the cloud server; The cloud server performs a second signature on the first signature information based on the trusted ring CA to obtain the root certificate; The trust device receives the root certificate sent by the cloud server.
8. The method according to claim 6, It is characterized in that The device to be authenticated joins the trust ring according to the trust root data, including: The device to be authenticated verifies the signature of the root certificate based on the trusted ring CA, and determines whether the device sending the trusted device root certificate is the trusted device; After the verification is passed, the device to be authenticated confirms to join the trust ring.
9. The method according to claim 6, It is characterized in that The method further comprises: The trusted device encrypts the root key based on the device certificate with the same account number of the device to be authenticated, so that the root key is sent in ciphertext form; The device to be authenticated decrypts the ciphertext based on its own device certificate with the same account number, so that the device to be authenticated obtains the root key.
10. A device to be authenticated, It is characterized in that The device to be authenticated includes: A data sending module, wherein the data sending module is configured to obtain verification of a trusted device based on a device certificate of the same account, wherein the trusted device is a device that already exists in the trust ring; A data receiving module, wherein the data receiving module is configured to receive the trusted root data sent by the trusted device, wherein the trusted root data includes a root key and a root certificate, and the root certificate is obtained after the root key is signed by the same account CA, the trusted ring CA and the cloud server; A data processing module, wherein the data processing module is configured to join the trust ring according to the trust root data.