Method and device for establishing covert channel of transport layer security protocol
By establishing a hidden channel in the TLS protocol and using random number and digital signature verification methods, the problem of insufficient security of the TLS protocol in the face of multiple attack methods is solved, and the security and robustness of the communication channel are significantly improved.
Patent Information
- Application Number
- CN202411873396.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-06-13
AI Technical Summary
In the prior art, there are many attack methods in the Transport Layer Security Protocol (TLS), which leads to insufficient security and robustness of communication content.
By establishing a transmission layer security protocol hidden channel between the initiator and the participant, the key value is obtained using random number preprocessing, and the security of the channel is ensured through digital signature verification.
Enhanced the security and robustness of communication channels based on the transport layer security protocol, effectively preventing man-in-the-middle attacks and other forms of tampering and eavesdropping.
Smart Images

Figure CN120150982A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of information transmission security, and in particular, to a method and device for establishing a covert channel for a transport layer security protocol. Background Art
[0002] A covert channel is a communication channel that is not designed for information transfer but is used to secretly transmit information in violation of normal communication policies or security policies. Such channels are typically used to transmit sensitive or secret information without being detected by potential attackers or eavesdroppers. Establishing a covert channel at the transport layer mainly involves using certain specific fields in the transport layer protocol to attach specific information. For example, the TCP Sequence Number field can be replaced or modified to transmit specific covert information.
[0003] However, in the prior art, the Transport Layer Security (TLS) protocol aims to provide security and data integrity guarantees for Internet communications. The TLS protocol adopts a master-slave architecture model and uses technologies such as data encryption and digital signatures to create a secure connection between application programs at both ends of the network through the network, preventing eavesdropping and tampering when exchanging data. Due to the importance of the TLS protocol, various attacks against TLS have emerged. For example, man-in-the-middle attacks, POODLE attacks, CRIME attacks, DROWN attacks, and SSL Stripping attacks. Among them, a man-in-the-middle attack means that the attacker is located between the two communication parties and can intercept, tamper with, and retransmit the communication data between the two parties, resulting in the theft of communication content.
[0004] To address these problems, there is an urgent need for a more secure method and device for establishing a covert channel for a transport layer security protocol, which can enable the communication content transmitted relying on the transport layer security protocol to be securely transmitted, so as to enhance the security and robustness of the transport layer security protocol. Summary of the Invention
[0005] To enable the communication content transmitted relying on the transport layer security protocol to be securely transmitted, this application provides a method and device for establishing a covert channel for a transport layer security protocol.
[0006] In a first aspect, a method for establishing a covert channel for a transport layer security protocol provided by this application adopts the following technical solution:
[0007] A method for establishing a covert channel for a transport layer security protocol, applied to an initiator, includes:
[0008] Determine two random numbers, and perform preprocessing on each of the random numbers to obtain a first value and a second value;
[0009] Send the first value and the second value to the participant, so that the participant uses the private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value, wherein the third value and the fourth value are generated by the participant, and the private key is stored in the participant;
[0010] Receive the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participant;
[0011] When it is determined according to the signature value that the security level of the digital certificate is secure, calculate a first key and a second key by using the first value, the second value, the third value, and the fourth value.
[0012] Further, the determining two random numbers and preprocessing each of the random numbers to obtain a first value and a second value includes:
[0013] Determine a preset numerical length, and randomly generate two random numbers according to the preset numerical length;
[0014] Preprocess each of the random numbers by using a first preset processing formula to obtain a first value and a second value, wherein the first preset processing formula is:
[0015] X = g x mod p
[0016] wherein X is the value corresponding to the random number, x is the random number, g is the generator, p is a prime number, and the generator g is an integer.
[0017] Further, the determining the security level of the digital certificate according to the signature value includes:
[0018] Obtain the public key corresponding to the private key, and decrypt the signature value by using the public key to obtain decryption data;
[0019] Perform hash processing on the digital certificate to obtain hash data, and compare whether the hash data is consistent with the decryption data;
[0020] When the hash data is consistent with the decryption data, determine that the security level of the digital certificate is secure;
[0021] When the hash data is inconsistent with the decryption data, determine that the security level of the digital certificate is insecure.
[0022] Further, the method further includes:
[0023] When it is determined that the security level of the digital certificate is insecure according to the signature value, terminate the establishment of the covert channel.
[0024] In a second aspect, a method for establishing a Transport Layer Security (TLS) protocol covert channel, which is applied to a participating party, includes:
[0025] Determine two random numbers, and perform preprocessing on each of the random numbers to obtain a third value and a fourth value;
[0026] Receive a first value and a second value sent by an initiator;
[0027] Determine a digital certificate and the signature private key corresponding to the digital certificate, and use the signature private key to perform a digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value;
[0028] Send the digital certificate, the signature value, the third value, and the fourth value to the initiator, so that when the initiator determines that the security level of the digital certificate is secure according to the signature value, calculate a first key and a second key by using the first value, the second value, the third value, and the fourth value.
[0029] Further, the determining two random numbers and performing preprocessing on each of the random numbers to obtain a third value and a fourth value includes:
[0030] Determine a preset numerical length, and randomly generate two random numbers according to the preset numerical length;
[0031] Perform preprocessing on each of the random numbers by using a second preset processing formula to obtain a third value and a fourth value, where the second preset processing formula is:
[0032] Y = g y mod p
[0033] where Y is the value corresponding to the random number, y is the random number, g is a generator, p is a prime number, and the generator g is an integer.
[0034] Further, the using the signature private key to perform a digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value includes:
[0035] Perform a digital signature on the first value, the second value, the third value, and the fourth value by using a preset signature formula and the signature private key to obtain a signature value, where the preset signature formula is:
[0036] σ = sign(sk, X||X′||Y||Y′)
[0037] Wherein, σ is the signature value, sk is the signature private key, X is the first value, X′ is the second value, Y is the third value, and Y′ is the fourth value.
[0038] Further, the method further includes:
[0039] Receiving a first key and a second key fed back by the initiator;
[0040] Verifying the first key and the second key.
[0041] In a third aspect, an apparatus for establishing a covert channel for a transport layer security protocol provided by the present application is applied to an initiator and includes:
[0042] A first determination module, configured to determine two random numbers, and perform preprocessing on each of the random numbers to obtain a first value and a second value;
[0043] A first sending module, configured to send the first value and the second value to a participant, so that the participant uses a private key to perform digital signature on the first value, the second value, a third value, and a fourth value to obtain a signature value, wherein the third value and the fourth value are generated by the participant, and the private key is stored in the participant;
[0044] A first receiving module, configured to receive the third value, the fourth value, the signature value, and a digital certificate corresponding to the signature value fed back by the participant;
[0045] A calculation module, configured to, when the first receiving module determines that the security level of the digital certificate is secure according to the signature value, calculate a first key and a second key by using the first value, the second value, the third value, and the fourth value.
[0046] In a fourth aspect, the present disclosure provides an apparatus for establishing a covert channel for a transport layer security protocol, which is applied to a participant and includes:
[0047] A second determination module, configured to determine two random numbers, and perform preprocessing on each of the random numbers to obtain a third value and a fourth value;
[0048] A second receiving module, configured to receive a first value and a second value sent by an initiator;
[0049] A signature module, configured to determine a digital certificate and a signature private key corresponding to the digital certificate, and use the signature private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value;
[0050] A second sending module, configured to send the digital certificate, the signature value, the third value, and the fourth value to the initiator, so that when the initiator determines that the security level of the digital certificate is secure based on the signature value, the first key and the second key are calculated by using the first value, the second value, the third value, and the fourth value.
[0051] In a third aspect, the present disclosure provides a computer device, including a memory and a processor. The memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of a method for establishing a transport layer security protocol covert channel in any one of the above embodiments are implemented.
[0052] In a fourth aspect, the present disclosure provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for establishing a transport layer security protocol covert channel in any one of the above embodiments is run.
[0053] In the above method for establishing a transport layer security protocol covert channel, the initiator determines two random numbers, and preprocesses each random number to obtain a first value and a second value; the first value and the second value are sent to the participant, so that the participant uses the private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value, where the third value and the fourth value are generated by the participant, and the private key is stored in the participant; the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participant are received; when it is determined that the security level of the digital certificate is secure according to the signature value, the first key and the second key are calculated by using the first value, the second value, the third value, and the fourth value. The initiator and the participant can use the first key as the key material of the transport layer security protocol, and use the second key as the key material of the covert channel to establish a covert channel in the transport layer security protocol, enhancing the security and robustness of the communication channel based on the transport layer security protocol. Description of the Drawings
[0054] Figure 1 is a flowchart of a method for establishing a transport layer security protocol covert channel in an embodiment.
[0055] Figure 2 is another flowchart of a method for establishing a transport layer security protocol covert channel in an embodiment.
[0056] Figure 3 is still another flowchart of a method for establishing a transport layer security protocol covert channel in an embodiment.
[0057] Figure 4 is a flowchart of the covert channel startup process of a method for establishing a transport layer security protocol covert channel in an embodiment.
[0058] Figure 5 It is a schematic diagram of a system model in a method for establishing a transport layer security protocol covert channel in an embodiment.
[0059] In the accompanying drawings, the same components are denoted by the same reference numerals, and the drawings are not drawn to actual scale. Detailed implementation manners
[0060] In order to enable those skilled in the art to better understand the technical solutions of the present disclosure, and to fully understand how the present disclosure uses technical means to solve technical problems and the implementation process of achieving corresponding technical effects and implement accordingly, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The embodiments of the present disclosure and each feature in the embodiments can be combined with each other without conflict, and the formed technical solutions are all within the protection scope of the present disclosure. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure.
[0061] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0062] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0063] Embodiment 1
[0064] Please refer to Figure 1 , in an implementation manner of the present application, a method for establishing a transport layer security protocol covert channel, which is applied to an initiator, includes:
[0065] Step 111: Determine two random numbers, and perform preprocessing on each of the random numbers to obtain a first value and a second value.
[0066] Determine the precision range of the random numbers, and then randomly generate two random numbers according to the above precision range. Then, the preprocessing of the random numbers can include: rounding to a specified number of decimal places, taking the integer part (rounding towards zero, rounding down, rounding up), scaling (multiplying by a certain coefficient), translation (adding / subtracting a certain constant), and bit operations (such as taking the complement, shifting).
[0067] In this embodiment, determine the length of the random numbers, randomly generate two random numbers according to the length of the random numbers, and then perform preprocessing on each random number. Specifically:
[0068] X = g x mod p
[0069] where X is the value corresponding to the random number, x is the random number, g is the generator, p is a prime number, and the generator g is an integer.
[0070] In this embodiment, the length of the random numbers can be 256 bits, 32 bits, 48 bits, or any length, and no specific limitation is made here.
[0071] Step 112: Send the first value and the second value to the participating parties, so that the participating parties use the private key to perform digital signatures on the first value, the second value, the third value, and the fourth value to obtain signature values. Among them, the third value and the fourth value are generated by the participating parties, and the private key is stored in the participating parties.
[0072] In this embodiment, there are two participating parties, which are respectively called the initiating party (referred to as "Participating Party A" in this embodiment) and Participating Party B (refer to Figure 5 ). Then, after the initiating party calculates the first value and the second value, it sends the first value and the second value to the participating parties. So that the participating parties use the private key to perform digital signatures on the first value, the second value, the third value, and the fourth value to obtain signature values. Among them, the third value and the fourth value are generated by the participating parties, and the private key is stored in the participating parties. Specifically:
[0073] The participating parties determine the length of the random numbers, randomly generate two random numbers according to the length of the random numbers, and then calculate the third value and the fourth value respectively through the two random numbers. For example:
[0074] Y = g y mod p
[0075] Among them, Y is the value corresponding to the random number, y is the random number, g is the generator, p is the prime number, and the generator g is an integer.
[0076] After the participating party calculates the third value and the fourth value, the participating party obtains a digital certificate and writes the first value, the second value, the third value, and the fourth value into the digital certificate; further, the private key sk corresponding to the digital certificate is determined, and the first value, the second value, the third value, and the fourth value are digitally signed using the private key sk, and the signature value is obtained as:
[0077] σ = sign(sk, X||X′||Y||Y′)
[0078] Among them, σ is the signature value, sk is the signature private key, X is the first value, X′ is the second value, Y is the third value, and Y′ is the fourth value.
[0079] Finally, the participating party sends the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value to the initiating party, providing a data basis for step 113.
[0080] In this embodiment, the length of the random number generated by the participating party is the same as the length of the random number generated by the initiating party.
[0081] In one embodiment, when the length of the random number generated by the participating party is different from the length of the random number generated by the initiating party, the length of the random number of the participating party is adjusted so that the length of the random number generated by the participating party is the same as the length of the random number generated by the initiating party.
[0082] Step 113, receiving the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participating party.
[0083] Step 114, when it is determined that the security level of the digital certificate is secure according to the signature value, calculate the first key and the second key using the first value, the second value, the third value, and the fourth value.
[0084] In this embodiment, the initiating party verifies the security level of the digital certificate according to the signature value, including: the initiating party verifies the signature value using the digital certificate. Specifically, the initiating party determines the public key and decrypts the signature value using the public key to obtain the decrypted value. Then the initiating party performs a hash process on the content of the digital certificate to obtain a hash value; further, compares whether the hash value and the decrypted value are consistent; when the hash value and the decrypted value are inconsistent, it means that the initiating party determines that the content of the digital certificate may have been tampered with, that is, the security level of the digital certificate is insecure; when the hash value and the decrypted value are consistent, it means that the initiating party determines that the security level of the digital certificate is secure.
[0085] When the initiator determines that the security level of the digital certificate is secure, the initiator calculates the first key and the second key using the first value, the second value, the third value, and the fourth value. Substitute the first value, the second value, the third value, and / or the fourth value into the key calculation formula according to the key calculation formula to calculate the first key and the second key. The calculation formula for calculating the first key is:
[0086] Z = g X mod p
[0087] Where Z is the first key, g is the generator, p is the prime number, and X is the value corresponding to the random number (i.e., the first value).
[0088] The calculation formula for the second key is:
[0089] Z’ = g X' mod p
[0090] Where Z’ is the first key, g is the generator, p is the prime number, and X‘ is the value corresponding to the random number (i.e., the second value).
[0091] It should be understood that although Figure 1 the steps in the flowchart of Figure 1 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover,
[0092] At least a part of the steps in can include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0092] In this embodiment, the initiator determines two random numbers, and preprocesses each random number to obtain the first value and the second value; the participant uses the private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain the signature value. Among them, the third value and the fourth value are generated by the participant, and the private key is stored in the participant; when it is determined that the security level of the digital certificate is secure according to the signature value, the first key and the second key are calculated using the first value, the second value, the third value, and the fourth value. The initiator and the participant use the first key as the key material of the transport layer security protocol, and use the second key as the key material of the covert channel to establish a covert channel in the transport layer security protocol, enhancing the security and robustness of the communication channel based on the transport layer security protocol.
[0093] In one embodiment, determining two random numbers and preprocessing each of the random numbers to obtain a first value and a second value includes:
[0094] 1-1) Determining a preset numerical length and randomly generating two random numbers according to the preset numerical length.
[0095] 1-2) Preprocessing each of the random numbers using a first preset processing formula to obtain a first value and a second value, where the first preset processing formula is:
[0096] X = g x mod p
[0097] where X is the value corresponding to the random number, x is the random number, g is the generator, p is a prime number, and the generator g is an integer.
[0098] In one embodiment, determining the security level of the digital certificate according to the signature value includes:
[0099] 2-1) Obtaining the public key corresponding to the private key and decrypting the signature value using the public key to obtain decrypted data.
[0100] In this embodiment, the public key and the private key are the core components of an asymmetric key pair. The private key is commonly used to sign data, while the public key is used to verify the authenticity of the signature. Furthermore, the public key and the signature algorithm are used to verify the validity of the signature value. That is, step 2-2) is performed.
[0101] 2-2) Performing a hash process on the digital certificate to obtain hash data, and comparing whether the hash data is consistent with the decrypted data.
[0102] Specifically, performing a hash process on the digital certificate to obtain hash data, and comparing whether the Harry data is consistent with the decrypted data to confirm whether it is generated by the corresponding private key, thereby confirming the integrity of the data and the authenticity of the source. In this embodiment, if the signature verification passes, it indicates that the data has not been tampered with during transmission and indeed comes from the claimed sender. If the verification fails, it indicates that the data may have been tampered with or does not come from the claimed sender.
[0103] 2-3) When the hash data is consistent with the decrypted data, determining that the security level of the digital certificate is secure.
[0104] 2-4) When the hash data is inconsistent with the decrypted data, determining that the security level of the digital certificate is insecure.
[0105] In one embodiment, the method further includes:
[0106] 3-1) When it is determined that the security level of the digital certificate is insecure based on the signature value, terminate the establishment of the covert channel.
[0107] In this embodiment, in order to establish a covert channel on the Transport Layer Security (TLS) protocol, it is necessary to determine whether the covert channel is secure at this time according to the security level of the digital certificate. When the startup of the covert channel is in an insecure state, immediately terminate the establishment of the covert channel.
[0108] Embodiment 2
[0109] Please refer to Figure 2 In an implementation manner of the present application, a method for establishing a covert channel of the Transport Layer Security protocol, which is applied to a participating party, includes:
[0110] Including:
[0111] Step 211, determine two random numbers, and perform preprocessing on each of the random numbers to obtain a third value and a fourth value.
[0112] In this embodiment, determine the length of the random number, randomly generate two random numbers according to the length of the random number, and then perform preprocessing on each random number. Specifically:
[0113] Y = g y mod p
[0114] Where Y is the value corresponding to the random number, y is the random number, g is the generator, p is a prime number, and the generator g is an integer.
[0115] In this embodiment, the length of the random number can be 256 bits, or 32 bits, or 48 bits, or any length, and no specific limitation is made here.
[0116] Step 212, receive the first value and the second value sent by the initiator.
[0117] In this embodiment, before the participating party signs the digital certificate, the initiator determines the length of the random number, randomly generates two random numbers according to the length of the random number, and then performs preprocessing on each random number. Specifically:
[0118] X = g x mod p
[0119] Where X is the value corresponding to the random number, x is the random number, g is the generator, p is a prime number, and the generator g is an integer.
[0120] In this embodiment, the length of the random number can be 256 bits, or 32 bits, or 48 bits, or any length, and no specific limitation is made here.
[0121] In this embodiment, the length of the random number generated by the participant is the same as that generated by the initiator.
[0122] Subsequently, the initiator sends the calculated first value and second value to the participant, and the participant receives the first value and second value sent by the initiator.
[0123] Step 213: Determine the digital certificate and the signature private key corresponding to the digital certificate, and use the signature private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value.
[0124] In this embodiment, when the participant calculates the third value and the fourth value, and receives the first value and the second value sent by the initiator, the participant obtains the digital certificate, writes the first value, the second value, the third value, and the fourth value into the digital certificate; further determines the private key sk corresponding to the digital certificate, and uses the private key sk to perform digital signature on the first value, the second value, the third value, and the fourth value, and the obtained signature value is:
[0125] σ = sign(sk, X||X′||Y||Y′)
[0126] Where, σ is the signature value, sk is the signature private key, X is the first value, X′ is the second value, Y is the third value, and Y′ is the fourth value.
[0127] Step 214: Send the digital certificate, the signature value, the third value, and the fourth value to the initiator, so that when the initiator determines that the security level of the digital certificate is secure according to the signature value, calculate the first key and the second key using the first value, the second value, the third value, and the fourth value.
[0128] After the participant determines the signature value of the digital certificate, the participant sends the digital certificate, the signature value, the third value, and the fourth value to the initiator. The initiator receives the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participant. Further, verify the security level of the digital certificate according to the signature value. Specifically, the initiator determines the public key, uses the public key to decrypt the signature value to obtain a decrypted value. Subsequently, the initiator performs a hash process on the content on the digital certificate to obtain a hash value; further compare whether the hash value and the decrypted value are consistent; when the hash value and the decrypted value are inconsistent, it means that the initiator determines that there is a possibility that the content on the digital certificate has been tampered with, that is, the security level of the digital certificate is insecure; when the hash value and the decrypted value are consistent, it means that the initiator determines that the security level of the digital certificate is secure.
[0129] In practical applications, when the initiating party determines that the security level of the digital certificate is secure, the initiating party calculates the first key and the second key using the first value, the second value, the third value, and the fourth value. Substitute the first value, the second value, the third value, and / or the fourth value into the key calculation formula according to the key calculation formula to calculate the first key and the second key. The calculation formula for calculating the first key is:
[0130] Z = g X mod p
[0131] Where Z is the first key, g is the generator, p is a prime number, and X is the value corresponding to the random number (i.e., the first value).
[0132] The calculation formula for the second key is:
[0133] Z' = g X‘ mod p
[0134] Where Z' is the second key, g is the generator, p is a prime number, and X' is the value corresponding to the random number (i.e., the second value).
[0135] It should be understood that although Figure 1 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figure 1 at least a part of the steps in
[0136] can include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0137] In one embodiment, determining two random numbers and preprocessing each of the random numbers to obtain a third value and a fourth value includes:
[0138] 4-1) Determining a preset numerical length and randomly generating two random numbers according to the preset numerical length.
[0139] 4-2) Using a second preset processing formula to preprocess each of the random numbers to obtain a third value and a fourth value, where the second preset processing formula is:
[0140] Y = g y mod p
[0141] where Y is the value corresponding to the random number, y is the random number, g is the generator, p is a prime number, and the generator g is an integer.
[0142] In one embodiment, using the signature private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value includes:
[0143] 5-1) Using a preset signature formula and the signature private key to perform digital signature on the first value, the second value, the third value, and the fourth value to obtain a signature value, where the preset signature formula is:
[0144] σ = sign(sk, X||X′||Y||Y′)
[0145] where σ is the signature value, sk is the signature private key, X is the first value, X′ is the second value, Y is the third value, and Y′ is the fourth value.
[0146] In one embodiment, the method further includes:
[0147] 6-1) Receiving a first key and a second key fed back by the initiator.
[0148] When the initiator confirms the security of the covert channel, the initiator sends a feedback message of successful verification to the participant. In order to further enable the participant to verify the accuracy of the covert channel, the first key and the second key can be further sent to the participant. At this time, the participant receives the first key and the second key fed back by the initiator.
[0149] 6-2) Verifying the first key and the second key.
[0150] Specifically, the participant calculates a third key and a fourth key, which are respectively:
[0151] w = g X mod p
[0152] Wherein, w is the third key, g is a generator, p is a prime number, and X is the value corresponding to a random number (i.e., the first value).
[0153] The calculation formula for the fourth key is:
[0154] w’ = g X‘ mod p
[0155] Wherein, w’ is the fourth key, g is a generator, p is a prime number, and X‘ is the value corresponding to a random number (i.e., the second value).
[0156] When the first key is the same as the third key, and the second key is the same as the fourth key, it indicates the accuracy of the covert channel, and the participating parties then determine to enable the covert channel.
[0157] Embodiment III
[0158] Another embodiment of the method for establishing a transport layer security protocol covert channel in this embodiment includes:
[0159] Step 311, the initiator determines two random numbers, and preprocesses each of the random numbers to obtain a first value and a second value.
[0160] Step 312, the initiator sends the first value and the second value to the participating party, so that the participating party uses the private key to perform digital signatures on the first value, the second value, the third value, and the fourth value to obtain signature values, wherein the third value and the fourth value are generated by the participating party, and the private key is stored in the participating party.
[0161] In this embodiment, steps 311 to 312 are similar to steps 111 to 112 in the above embodiment. To avoid repetition, they will not be elaborated here.
[0162] Step 313, the participating party determines two random numbers, and preprocesses each of the random numbers to obtain a third value and a fourth value.
[0163] Step 314, the participating party receives the first value and the second value sent by the initiator.
[0164] Step 315, the participating party determines a digital certificate and the signature private key corresponding to the digital certificate, and uses the signature private key to perform digital signatures on the first value, the second value, the third value, and the fourth value to obtain signature values.
[0165] Step 316: The participating party sends the digital certificate, the signature value, the third value, and the fourth value to the initiating party, so that when the initiating party determines that the security level of the digital certificate is secure based on the signature value, the first key and the second key are calculated using the first value, the second value, the third value, and the fourth value.
[0166] In this embodiment, steps 313 to 316 are similar to steps 211 to 214 in the above embodiment. To avoid repetition, they will not be elaborated here.
[0167] Step 317: The initiating party receives the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participating party.
[0168] Step 318: When the initiating party determines that the security level of the digital certificate is secure based on the signature value, the first key and the second key are calculated using the first value, the second value, the third value, and the fourth value.
[0169] In this embodiment, steps 317 to 318 are similar to steps 113 to 114 in the above embodiment. To avoid repetition, they will not be elaborated here.
[0170] In this embodiment, the initiating party determines two random numbers, and preprocesses each random number to obtain the first value and the second value; the first value and the second value are sent to the participating party, so that the participating party uses the private key to digitally sign the first value, the second value, the third value, and the fourth value to obtain the signature value, where the third value and the fourth value are generated by the participating party and the private key is stored in the participating party; the initiating party receives the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participating party; when it is determined that the security level of the digital certificate is secure based on the signature value, the first key and the second key are calculated using the first value, the second value, the third value, and the fourth value. The initiating party and the participating party can use the first key as the key material for the transport layer security protocol and the second key as the key material for the covert channel to establish a covert channel in the transport layer security protocol, enhancing the security and robustness of the communication channel based on the transport layer security protocol.
[0171] Embodiment Four
[0172] The existing Transport Layer Security (TLS) protocol aims to provide security and data integrity guarantees for Internet communications. The TLS protocol adopts a master-slave architecture model and uses technologies such as data encryption and digital signatures to create a secure connection between application programs at both ends of the network through the network, preventing eavesdropping and tampering when exchanging data. Due to the importance of the TLS protocol, there have been numerous attack methods against TLS. Therefore, in this embodiment, by establishing a covert channel in the TLS protocol, the security of the TLS protocol is greatly enhanced, and at the same time, the communication volume of the protocol is not increased.
[0173] Please refer to Figure 3 , the solution of this embodiment is applied to the network communication transmission security protocol. The solution includes two participating parties, which are respectively called the initiator (referred to as "Participant A" in this embodiment) and Participant B (refer to Figure 5 ). While executing the TLS protocol between A and B, the solution of this embodiment is executed. The solution of this embodiment is a two-party interactive protocol, and its specific process is as follows:
[0174] 1. Participant A selects two random numbers x and x' with a length of 256 bits; and then calculates: X = g x mod p, X' = g x ‘ mod p.
[0175] 2. Participant A sends X and X' to Participant B.
[0176] 3. Participant B selects two random numbers y and y' with a length of 256 bits, and then calculates: Y = g y mod p, Y' = g y ‘ mod p.
[0177] 4. Participant B uses the signature private key sk corresponding to its own digital certificate cer to digitally sign X, X', σ, and Y', and obtains the signature value: σ = sign(sk, X||X′||Y||Y′).
[0178] 5. Participant B sends Y, Y', cer, and the signature value σ to Participant A.
[0179] 6. Participant A verifies the signature value σ using the digital certificate cer. If the verification fails, it notifies Participant B that the verification fails and exits the entire process; if not, it notifies Participant B that the verification is successful and calculates: Z = g X mod p, Z' = g X‘ mod p.
[0180] 7. If Party B receives a verification failure message sent by Party A, Party B exits the entire process; if Party B receives a verification success message sent by Party A, Party B calculates Z = g X mod p, Z’ = g X‘ mod p.
[0181] After the above process is completed, Party A and Party B use Z as the key material for tls; and use Z′ as the key material for the covert channel.
[0182] In this embodiment, Party B can initiate the use of the covert channel, and its process is as Figure 4 shown, including:
[0183] 1. Party B sends a covert channel enabling request to Party A.
[0184] 2. Party A selects a random number r and reads the current local time (including date) t.
[0185] 3. Party A sends (r, t) to Party B.
[0186] 4. Party B verifies that the time is within a reasonable range. If the verification fails, Party B exits the process; if the verification is successful, Party B uses the signature private key sk corresponding to its own digital certificate cer to digitally sign r and t, and obtains the signature value: σ = sign(sk, r||t).
[0187] 5. Party B sends cer and σ to Party A.
[0188] 6. Party A uses the digital certificate cer to verify the digital signature σ. If the verification fails, Party A notifies Party B that the verification fails and exits the entire process. If the verification is successful, Party A notifies Party B that the initiation of the covert channel is successful. Party A calculates Z = g X mod p, Z’ = g X‘ mod p, and enters step 8>.
[0189] 7. If Party B receives a verification failure message sent by Party A, Party B exits the entire process; if Party B does not receive a message from Party A indicating the successful initiation of the covert channel, Party B calculates Z = g X mod p, Z’ = g X ‘ mod p, and then enters step 8>.
[0190] 8. Party A and Party B use Z and Z’ to generate the encryption key and integrity protection key for the use of the covert channel.
[0191] In this embodiment, a method for establishing a covert channel in the TLS protocol can enhance the security of the communication channel based on the TLS protocol.
[0192] Embodiment 5
[0193] In this embodiment, a computer device is provided. The computer device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program, and a database is deployed on the non-volatile storage medium. The database is used to store all the data involved in a method for establishing a covert channel of the Transport Layer Security protocol. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with other computer devices on which application software is deployed. When the computer program is executed by the processor, it implements a method for establishing a covert channel of the Transport Layer Security protocol. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, a touchpad, or a mouse, etc.
[0194] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of a method for establishing a covert channel of the Transport Layer Security protocol described in any of the above embodiments.
[0195] Embodiment 6
[0196] In this embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it executes a method for establishing a covert channel of the Transport Layer Security protocol described in any of the above embodiments.
[0197] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0198] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0199] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A method for establishing a transport layer security protocol covert channel, applied to an initiator, characterized in that: include: Determine two random numbers, and preprocess each of the random numbers to obtain a first value and a second value; Sending the first value and the second value to the participant, so that the participant uses a private key to digitally sign the first value, the second value, the third value, and the fourth value to obtain a signature value, wherein the third value and the fourth value are generated by the participant, and the private key is stored in the participant; Receive the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participant; When the security level of the digital certificate is determined to be secure according to the signature value, a first key and a second key are calculated using the first value, the second value, the third value, and the fourth value.
2. A method for establishing a transport layer security protocol covert channel according to claim 1, characterized in that: The determining of two random numbers and preprocessing each of the random numbers to obtain a first value and a second value includes: Determine a preset numerical length, and randomly generate two random numbers according to the preset numerical length; The random numbers are preprocessed using a first preset processing formula to obtain a first value and a second value, wherein the first preset processing formula is: X=g x mod p Wherein, X is the value corresponding to the random number, x is the random number, g is the generator, p is a prime number, and the generator g is an integer.
3. A method for establishing a transport layer security protocol covert channel according to claim 1, characterized in that: Determining the security level of the digital certificate according to the signature value includes: Obtaining a public key corresponding to the private key, and using the public key to decrypt the signature value to obtain decrypted data; Performing hash processing on the digital certificate to obtain hash data, and comparing the hash data with the decrypted data to see whether they are consistent; When the hash data is consistent with the decrypted data, determining that the security level of the digital certificate is secure; When the hash data is inconsistent with the decrypted data, the security level of the digital certificate is determined to be unsafe.
4. The method for establishing a transport layer security protocol covert channel according to claim 1, characterized in that: The method further comprises: When it is determined according to the signature value that the security level of the digital certificate is insecure, establishing the covert channel is terminated.
5. A method for establishing a transport layer security protocol covert channel, applied to a participant, characterized in that: include: Determine two random numbers, and pre-process the random numbers to obtain a third value and a fourth value; Receiving a first value and a second value sent by an initiator; Determine a digital certificate and a signature private key corresponding to the digital certificate, and use the signature private key to digitally sign the first value, the second value, the third value, and the fourth value to obtain a signature value; The digital certificate, the signature value, the third numerical value and the fourth numerical value are sent to the initiator, so that when the initiator determines that the security level of the digital certificate is secure based on the signature value, the first key and the second key are calculated using the first numerical value, the second numerical value, the third numerical value and the fourth numerical value.
6. A method for establishing a transport layer security protocol covert channel according to claim 5, characterized in that: The determining of two random numbers and preprocessing each of the random numbers to obtain a third value and a fourth value includes: Determine a preset numerical length, and randomly generate two random numbers according to the preset numerical length; The random numbers are preprocessed using a second preset processing formula to obtain a third value and a fourth value, wherein the second preset processing formula is: Y=g y mod p Wherein, Y is the numerical value corresponding to the random number, y is the random number, g is the generator, p is a prime number, and the generator g is an integer.
7. A method for establishing a transport layer security protocol covert channel according to claim 5 or 6, characterized in that: The step of using the signature private key to digitally sign the first value, the second value, the third value, and the fourth value to obtain a signature value includes: The first value, the second value, the third value, and the fourth value are digitally signed using a preset signature formula and the signature private key to obtain a signature value, wherein the preset signature formula is: σ=sign(sk,X||X′||Y||Y′) Among them, σ is the signature value, sk is the signature private key, X is the first value, X′ is the second value, Y is the third value, and Y′ is the fourth value.
8. A method for establishing a transport layer security protocol covert channel according to claim 5 or 6, characterized in that: The method further comprises: Receive the first key and the second key fed back by the initiator; The first key and the second key are verified.
9. A device for establishing a transport layer security protocol covert channel, applied to an initiator, characterized in that: include: A first determination module, used to determine two random numbers, and pre-process each of the random numbers to obtain a first value and a second value; a first sending module, configured to send the first value and the second value to a participant, so that the participant uses a private key to digitally sign the first value, the second value, the third value, and the fourth value to obtain a signature value, wherein the third value and the fourth value are generated by the participant, and the private key is stored in the participant; A first receiving module, configured to receive the third value, the fourth value, the signature value, and the digital certificate corresponding to the signature value fed back by the participant; A calculation module is used to calculate a first key and a second key using the first value, the second value, the third value and the fourth value when the first receiving module determines that the security level of the digital certificate is secure according to the signature value.
10. A device for establishing a covert channel of a transport layer security protocol, applied to a participant, characterized in that: include: A second determination module, used to determine two random numbers, and pre-process the random numbers to obtain a third value and a fourth value; A second receiving module, used for receiving a first value and a second value sent by an initiator; A signature module, used to determine a digital certificate and a signature private key corresponding to the digital certificate, and use the signature private key to digitally sign the first value, the second value, the third value, and the fourth value to obtain a signature value; The second sending module is used to send the digital certificate, the signature value, the third numerical value and the fourth numerical value to the initiator, so that when the initiator determines that the security level of the digital certificate is safe according to the signature value, the first key and the second key are calculated using the first numerical value, the second numerical value, the third numerical value and the fourth numerical value.