An offline symmetric key synchronization method, system, storage medium and program product

CN120238298BActive Publication Date: 2026-09-25BEIJING BEIDOU HONGPENG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510270777.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2026-09-25
Estimated Expiration
2045-03-07

AI Technical Summary

Technical Problem

[0004]鉴于此,本发明实施例提供了一种离线对称密钥同步方法、系统、存储介质和程序产品,以消除或改善现有技术中存在的一个或更多个缺陷,解决了现有技术中无法在离线状态下建立多台设备之间的可信信道以同步待同步密钥的问题

Benefits of technology

[0015]本发明的有益效果至少是:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238298B_ABST
    Figure CN120238298B_ABST
Patent Text Reader

Abstract

The application provides an offline symmetric key synchronization method, system, storage medium and program product, and the method comprises the following steps: an intelligent password key accesses an upper computer to receive a device authentication certificate of a synchronization participating device and a signature key pair for signing the device authentication certificate by a signature private key and sending the device authentication certificate to the synchronization participating device and then using a signature public key to perform identity authentication; after accessing a master device and passing the identity authentication, the master device password chip generates a to-be-synchronized key; in the upper computer, an auxiliary device code and a preset device synchronization security rule are obtained; after accessing the auxiliary device and passing the identity authentication, an encryption public key generated by an auxiliary device password chip is received; after accessing the master device and passing the identity authentication, an encryption file generated by encrypting the to-be-synchronized key by using the encryption public key is saved; and after accessing the auxiliary device and passing the identity authentication, the to-be-synchronized key is obtained by decrypting the encryption file by using an encryption private key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cryptography, and in particular to an offline symmetric key synchronization method, system, storage medium, and program product. Background Technology

[0002] Current symmetric encryption key synchronization schemes include online and offline scenarios. In the online scenario, a trusted key center synchronizes symmetric encryption keys through authentication and asymmetric keys. The communication protocol uses asymmetric keys for negotiation before the symmetric keys are exchanged. In the offline scenario, traditional encryption machine backups involve first authenticating the administrator, then generating, exporting, and importing key files.

[0003] In existing technologies, it is impossible to establish a trusted channel for key synchronization in an offline state without internet access, and authentication is impossible without console and command-line interaction; it is also impossible to establish a trusted channel between more than two hardware devices in an offline state to synchronize the stream cipher key to be synchronized through a trusted channel, so that the hardware devices can use stream cipher for encryption and decryption. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide an offline symmetric key synchronization method, system, storage medium, and program product to eliminate or improve one or more defects existing in the prior art, and solve the problem that the prior art cannot establish a trusted channel between multiple devices in an offline state to synchronize the key to be synchronized.

[0005] One aspect of the present invention provides an offline symmetric key synchronization method, the method comprising the following steps: The system receives device authentication certificates and signature key pairs for encrypting the device authentication certificates from multiple participating synchronization devices via a host computer through a USB interface; the multiple participating synchronization devices include a master device and an auxiliary device; the signature key pair includes a signature private key and a signature public key. The system connects to the master device among the participating synchronization devices via USB interface and transmits the master device authentication certificate and the master device's signature public key to the master device. After confirming that the master device verifies the signature of the master device authentication certificate based on the signature public key and passes the verification, the system obtains the synchronization key generated by the master device's cryptographic chip from the master device and saves it to the master device's security domain. The auxiliary device identifier and preset device synchronization security rules are obtained from the host computer via the USB interface. The auxiliary device is connected via the USB interface and the auxiliary device authentication certificate and the auxiliary device signature public key are transmitted to the auxiliary device. After it is determined that the auxiliary device has verified the signature of the auxiliary device authentication certificate based on the signature public key and the verification is successful, the encryption public key in the encryption key pair generated by the auxiliary device cryptographic chip in the auxiliary device is received and stored. The device connects to the main device via a USB interface. After confirming that the main device has verified the signature of the main device's authentication certificate based on the signature public key and the signature is verified, the encryption public key is transmitted to the main device. The device receives and stores the encrypted file generated by the main device encrypting the key to be synchronized based on the encryption public key. The device connects to the auxiliary device via a USB interface. After confirming that the auxiliary device has verified the signature of the auxiliary device's authentication certificate based on the signature public key, the encrypted file is transmitted to the auxiliary device. The device receives the key to be synchronized obtained by decrypting the encrypted file using the private key in the generated encryption key pair and saves it in the security domain of the auxiliary device.

[0006] In some embodiments, the process of the host computer allocating device authentication certificates to multiple participating synchronization devices includes: the smart cryptographic key generating the signature key pair and the device authentication certificate request, and writing the device identifiers of multiple devices to be synchronized into the device authentication certificate request; After connecting to the host computer via USB interface and sending the device authentication certificate request and the signature key pair to the certificate authority of the host computer, the device authentication certificates of multiple participating synchronization devices are received.

[0007] In some embodiments, the process by which the master device cryptographic chip generates the key to be synchronized includes: The master device's cryptographic chip randomly generates data encryption key pairs; The initialized master device random number generator generates a random number, which is then used as the synchronization key for the stream cipher algorithm.

[0008] In some embodiments, the process of receiving and storing the public key of the encryption key pair generated by the cryptographic chip of the auxiliary device includes: The auxiliary device is initialized, and the integrity of the auxiliary device's cryptographic chip is ensured. A key generation algorithm is executed in the cryptographic chip of the auxiliary device to generate the encryption key pair; the encryption key pair contains one encryption public key and one encryption private key. The encrypted private key is stored in the cryptographic chip of the auxiliary device, and the encrypted public key is transmitted to the auxiliary device through a preset interface and written into the preset storage area of ​​the smart cryptographic key; The smart cryptographic key is subjected to encryption and decryption tests to verify the usability of the encrypted public key.

[0009] In some embodiments, the process by which the master device verifies the signature of the master device authentication certificate based on the signing public key includes: The master device's password chip generates a random number, which is then sent to the smart password key. After PIN password verification, the smart password key generates a random number. After signing the random number generated by the master device's cryptographic chip, the random number of the smart cryptographic key, and the master device identifier with the signing private key, the signature value constructed by signing the two random numbers and the master device identifier with the smart cryptographic key and the signing public key are returned to the master device. The master device cryptographic chip checks the validity of the signature public key and the master device authentication certificate, and verifies the output and received random numbers of the master device, the random numbers of the smart cryptographic key, the master device identifier, and the received signature value, as well as the integrity of the original text.

[0010] In some embodiments, the method further includes: The first message authentication code is obtained by calculating the preset shared key and the synchronization key generated by the master device's cryptographic chip. The second message authentication code is calculated using the preset shared key and the key to be synchronized obtained after the encrypted file is decrypted by the encryption private key; The first message authentication code and the second message authentication code are compared to determine the consistency and integrity of the key to be synchronized during transmission.

[0011] In some embodiments, the method further includes: The process of generating and transmitting the key to be synchronized, the process of authenticating multiple participating synchronization devices, and the process of generating and transmitting the encryption key pair are stored as logs.

[0012] On the other hand, the present invention also provides an offline symmetric key synchronization system, the system comprising: The host computer is used to assign device authentication certificates for multiple participating synchronization devices and signature key pairs for encrypting the device authentication certificates to the smart cryptographic key, and to transmit auxiliary device identifiers and preset device synchronization security rules to the smart cryptographic key; the smart cryptographic key is used to execute the offline symmetric key synchronization method described above, and to receive the device authentication certificates for multiple participating synchronization devices and the signature key pairs for encrypting the device authentication certificates from the host computer via a USB interface; it connects to the master device among the participating synchronization devices via a USB interface and transmits the master device authentication certificate and signature public key to the master device; after confirming that the master device verifies the signature of the master device authentication certificate based on the signature public key and passes the verification, it obtains the synchronization key generated by the master device cryptographic chip from the master device and saves it to the master device security domain; it obtains the auxiliary device identifier and preset device synchronization security rules from the host computer via a USB interface, and connects to the master device via a USB interface. The system connects to the auxiliary device and transmits the auxiliary device authentication certificate and signature public key to the auxiliary device. After confirming that the auxiliary device has successfully verified the signature of the auxiliary device authentication certificate based on the signature public key, it receives and stores the encryption public key from the encryption key pair generated by the auxiliary device's cryptographic chip. The system then connects to the master device via a USB interface. After confirming that the master device has successfully verified the signature of the master device authentication certificate based on the signature public key, it transmits the encryption public key to the master device. The system receives and stores the encrypted file generated by the master device encrypting the key to be synchronized using the encryption public key. Finally, the system connects to the auxiliary device via a USB interface. After confirming that the auxiliary device has successfully verified the signature of the auxiliary device authentication certificate based on the signature public key, it transmits the encrypted file to the auxiliary device. The system receives the key to be synchronized obtained by the auxiliary device decrypting the encrypted file using the encryption private key from the generated encryption key pair and saves it to the auxiliary device's security domain. The master device is used to verify the signature of the master device authentication certificate based on the signature public key, and after the signature is verified, the master device cryptographic chip generates a key to be synchronized and saves it to the master device security domain; and to generate an encrypted file by verifying the signature of the master device authentication certificate based on the signature public key and encrypting the key to be synchronized based on the encryption public key. Multiple auxiliary devices are used to receive the auxiliary device authentication certificate and signature public key transmitted by the auxiliary device identifier, verify the signature of the auxiliary device authentication certificate based on the signature public key, the encryption public key in the encryption key pair generated by the auxiliary device cryptographic chip, and after verifying the signature of the auxiliary device authentication certificate based on the signature public key and passing the verification, receive the encrypted file, and decrypt the encrypted file using the encryption private key in the generated encryption key pair to obtain the key to be synchronized.

[0013] On the other hand, the present invention also provides a computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implement the steps of any of the methods described above.

[0014] On the other hand, the present invention also provides a computer program product, including a computer program / instructions, characterized in that the computer program / instructions, when executed by a processor, implement the steps of any of the methods described above.

[0015] The beneficial effects of the present invention are at least as follows: The offline symmetric key synchronization method and system of this invention establishes a trusted channel by using the smart cryptographic key as an information transmission carrier to realize the transmission of the key to be synchronized between multiple participating synchronization devices in an offline state; it connects to the host computer via a USB interface, receives and stores the device authentication certificates and device key pairs assigned by the host computer to multiple participating synchronization devices, and writes the master device identifier and auxiliary device identifier of the participating synchronization devices into the device authentication certificate and associates them with the smart cryptographic key identifier; the host computer associates the smart cryptographic key with multiple participating synchronization devices, including master devices and auxiliary devices; the host computer controls and manages the slave devices to achieve efficient collaboration and data interaction between the devices; the master device password... The chip's synchronization key is obtained by generating two sets of random numbers, enhancing its randomness and security, and reducing transmission risks. The chip connects to the host computer via a USB interface to update the device identifiers and preset device synchronization security rules of the participating devices. The smart password key obtains the device identifiers and security rules of the participating devices, enabling secure transmission of the synchronization key between multiple participating devices. The security domain is a strictly protected area; storing data in the security domain protects it from infringement and alteration, increasing data security. The synchronization key is encrypted using the public key of the auxiliary device, and the encrypted file is decrypted using the private key, achieving secure transmission of the synchronization key between multiple participating devices.

[0016] Additional advantages, objects, and features of the invention will be set forth in part in the description which follows, and will also become apparent in part to those skilled in the art upon studying the description, or may be learned by practice of the invention. The objects and other advantages of the invention can be realized and obtained by means of the structures specifically pointed out in the description and drawings.

[0017] Those skilled in the art will understand that the objectives and advantages achievable with the present invention are not limited to those specifically described above, and that the above and other objectives achievable with the present invention will become clearer from the following detailed description. Attached Figure Description

[0018] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, are not intended to limit the scope of the invention. In the drawings: Figure 1 This is a flowchart illustrating an embodiment of the offline symmetric key synchronization method of the present invention.

[0019] Figure 2 This is a schematic diagram of the offline symmetric key synchronization method according to an embodiment of the present invention.

[0020] Figure 3 This is a schematic diagram illustrating the process of identity authentication for multiple participating synchronization devices according to an embodiment of the present invention. Detailed Implementation

[0021] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and accompanying drawings. Here, the illustrative embodiments and descriptions of this invention are used to explain the invention, but are not intended to limit the invention.

[0022] It should also be noted that, in order to avoid obscuring the invention with unnecessary details, only the structures and / or processing steps closely related to the solution according to the invention are shown in the accompanying drawings, while other details that are not closely related to the invention are omitted.

[0023] It should be emphasized that the term "including / comprises" as used herein refers to the presence of a feature, element, step, or component, but does not exclude the presence or addition of one or more other features, elements, steps, or components.

[0024] It should also be noted that, unless otherwise specified, the term "connection" in this article can refer not only to a direct connection, but also to an indirect connection involving an intermediary.

[0025] In the following description, embodiments of the invention will be illustrated with reference to the accompanying drawings. In the drawings, the same reference numerals represent the same or similar parts, or the same or similar steps.

[0026] In the existing technology, current symmetric encryption key synchronization schemes include online and offline scenarios. In the online scenario, a trusted key center synchronizes symmetric encryption keys through identity authentication and asymmetric keys. The communication protocol uses asymmetric keys for negotiation before the symmetric keys are exchanged. In offline scenarios, traditional encryption machine backups involve administrator authentication followed by key file generation, export, and import. This prevents the establishment of a trusted channel between two or more hardware devices and the synchronization of stream cipher keys without network connectivity. This hinders hardware devices from using stream ciphers for encryption and decryption, making authentication impossible without console and command-line interaction. This invention proposes an offline key-based synchronization method, system, storage medium, and program product. It receives device authentication certificates and signature key pairs for encrypting the authentication certificates from multiple participating devices via a USB interface. The system connects to the master device among the participating devices via USB and transmits its authentication certificate and signature public key to it. After the master device verifies the signature of the master device's authentication certificate using the signature public key, the system retrieves the key to be synchronized generated by the master device's cryptographic chip and saves it to the master device's security domain. Finally, it obtains the key from the host computer via USB. The auxiliary device identifier and preset device synchronization security rules are described. The auxiliary device is connected via a USB interface and its authentication certificate and signature public key are transmitted. After the auxiliary device verifies the signature of the authentication certificate based on the signature public key, the encryption public key generated by the auxiliary device's cryptographic chip is received and stored. The main device is connected via a USB interface, and after the main device verifies the signature of the authentication certificate based on the signature public key, the encryption public key is transmitted to the main device. The main device receives and stores the encrypted file generated by encrypting the key to be synchronized using the encryption public key. The auxiliary device is connected via a USB interface, and after the auxiliary device verifies the signature of the authentication certificate based on the signature public key, the encrypted file is transmitted to the auxiliary device. The main device receives and stores the encrypted file obtained by decrypting the encrypted file using the encryption private key generated by the auxiliary device and stores it in the auxiliary device's security domain.

[0027] Figure 1 This is a flowchart illustrating an embodiment of the offline symmetric key synchronization method of the present invention. Specifically, this application provides an offline symmetric key synchronization method, which is executed on a smart cryptographic key, and includes the following steps S101 to S105: Step S101: Receive device authentication certificates and signature key pairs for encrypting the device authentication certificates from multiple participating synchronization devices assigned by the host computer via the USB interface; the multiple participating synchronization devices include master devices and auxiliary devices; the signature key pair includes a signature private key and a signature public key.

[0028] Step S102: Connect to the master device in the participating synchronization devices via USB interface and transmit the master device authentication certificate and the master device's signature public key to the master device. After confirming that the master device verifies the signature of the master device authentication certificate based on the signature public key and passes the verification, obtain the key to be synchronized generated by the master device's cryptographic chip from the master device and save it to the master device's security domain.

[0029] Step S103: Obtain the auxiliary device identifier and preset device synchronization security rules from the host computer via the USB interface, connect to the auxiliary device via the USB interface and transmit the auxiliary device authentication certificate and the auxiliary device's signature public key to the auxiliary device. After confirming that the auxiliary device has verified the signature of the auxiliary device authentication certificate based on the signature public key and passed the verification, receive and store the encryption public key in the encryption key pair generated by the auxiliary device cryptographic chip in the auxiliary device.

[0030] Step S104: Connect to the master device via USB interface. After confirming that the master device has verified the signature of the master device's authentication certificate based on the signature public key, transmit the encryption public key to the master device. Receive and store the encrypted file generated by the master device after encrypting the key to be synchronized based on the encryption public key.

[0031] Step S105: Connect the auxiliary device via USB interface. After confirming that the auxiliary device has verified the signature of the auxiliary device authentication certificate based on the signature public key, transmit the encrypted file to the auxiliary device. After the auxiliary device decrypts the encrypted file using the encrypted private key in the generated encryption key pair, save the synchronization key obtained to the security domain of the auxiliary device.

[0032] In step S101, the smart password key (secure TF card) includes a secure storage area and a password chip; the host computer is used by the slave computer for control, monitoring, parameter setting, and data processing. In this application, the host computer interacts with the smart password key via a USB interface; the host computer assigns a device authentication certificate and a signature key pair to each of the multiple participating synchronization devices. The multiple participating synchronization devices include one master device and multiple auxiliary devices, and the master device performs the first initialization operation in sequence. The synchronization key generated by the master device is synchronized to the auxiliary devices; the master device has a master device identifier, and the auxiliary devices have auxiliary device identifiers. The master device identifier and the auxiliary device identifier are device codes set at the factory, which are unique identification codes of the devices and can be viewed through the device version query log. The smart password key identifier uses the smart password key serial number, and the device authentication certificate includes the master device authentication certificate. The smart key, along with the auxiliary device authentication certificate and the signing key pair (including a signing private key and a signing public key), binds the smart key identifier to multiple device identifiers by writing the master device identifier and the auxiliary device identifier into the auxiliary device authentication certificate. This allows the smart key to write device information from multiple participating devices into the smart key, enabling multi-device key synchronization based on the device information. Each time the smart key is transmitted to the master and auxiliary devices via a preset interface, authentication is required. The signing private key signs the device authentication certificate of the next device to be connected. The signed device authentication certificate and the signing public key are stored in the smart key and transmitted to the device through the preset interface. The signing public key then authenticates the signed device authentication certificate. If the authentication is successful, the smart key allows access to the participating devices for data reception and transmission.

[0033] In some embodiments, the process of the host computer assigning device authentication certificates to multiple participating synchronization devices includes steps S1011 to S1012: Step S1011: The smart cryptographic key generates a signature key pair and a device authentication certificate request, and writes the device identifiers of multiple devices to be synchronized into the device authentication certificate request; Step S1012: After connecting to the host computer via USB interface and sending the device authentication certificate request and signature key pair to the certificate authority of the host computer, receive device authentication certificates from multiple participating synchronization devices.

[0034] In some embodiments, the process by which the master device verifies the signature of the master device authentication certificate based on the signing public key includes steps S11 to S13: Step S11: The master device's password chip generates a random number - sends it to the smart password key and performs PIN password verification, after which the smart password key generates a random number.

[0035] Step S12: After signing the random number generated by the master device's cryptographic chip, the random number of the smart cryptographic key, and the master device identifier with the signing private key, the signature value constructed by signing the two random numbers and the master device identifier with the smart cryptographic key and the signing public key are returned to the master device.

[0036] Step S13: The master device cryptographic chip checks the validity of the signature public key and the master device authentication certificate, and verifies the output and received random numbers of the master device, the random number of the smart cryptographic key, the master device identifier, and the received signature value, as well as the integrity of the original text.

[0037] Specifically, the random number generated by the cryptographic chip ensures that each device has a unique identifier and prevents the smart key from confusing multiple participating synchronization devices. The PIN password used for PIN verification is set by the password administrator who manages the smart key. After PIN verification, the smart key generates a random number. The random number and PIN verification ensure that the participating synchronization devices associated with the smart key can perform subsequent operations. The method of generating random numbers improves the security of the key synchronization process. The signature value contains the signing public key, which allows the device to use the signing public key to verify the validity of the signature, ensuring that the key synchronization operation is based on trusted parties and the integrity and security of packet data during transmission.

[0038] In step S102, the smart password key is connected to the master device via the USB interface. The master device is the device that performs the initialization operation for the first time in sequence during the key synchronization process among multiple participating synchronization devices. The key to be synchronized generated by the master device is synchronized to multiple auxiliary devices. After the master device successfully authenticates the smart password key, the master device password chip in the master device generates the key to be synchronized.

[0039] In some embodiments, the process of the master device cryptographic chip generating the key to be synchronized includes steps S1021 to S1022: Step S1021: Randomly generate a data encryption key pair using the master device's cryptographic chip.

[0040] Step S1022: Use the initialized master device random number generator to generate a random number and use it as the synchronization key for the stream cipher algorithm.

[0041] Specifically, the data encryption key pair generated by the master device cryptographic chip can prevent attackers from predicting or copying the key to be synchronized and ensure the security of the key to be synchronized. The initialized master device random number generator ensures that the generated random number is different each time. Stream cipher algorithms include, but are not limited to, RC4, ZUC and ChaCha20.

[0042] In step S103, after the smart cryptographic key is connected to the master device, it obtains the auxiliary device identifiers of the remaining auxiliary devices among the multiple participating synchronization devices from the host computer to update the list of devices for key synchronization. The device synchronization security rules are set by the host computer to ensure the security and integrity of the key synchronization process, including but not limited to the transmission format rules, file format rules, data writing rules, and data reading rules of each device. After the smart cryptographic key authenticates the user, the auxiliary device cryptographic chip deployed in the auxiliary device generates an encryption key pair, which is a set of SM2 asymmetric key pairs. The encryption public key is written into the smart cryptographic key.

[0043] In some embodiments, the process of receiving and storing the public key of the encryption key pair generated by the cryptographic chip of the auxiliary device includes steps S1031 to S1034: Step S1031: Initialize the auxiliary device and ensure the integrity of the auxiliary device's cryptographic chip.

[0044] Step S1032: Execute a key generation algorithm in the auxiliary device cryptographic chip and generate an encryption key pair; the encryption key pair contains an encryption public key and an encryption private key.

[0045] Step S1033: Store the encrypted private key in the cryptographic chip of the auxiliary device, and transmit the encrypted public key to the auxiliary device through a preset interface and write it into the preset storage area of ​​the smart key; Step S1034: Perform encryption and decryption tests on the smart key to verify the availability of the encryption public key.

[0046] In steps S104 and S105, the public key in the smart key encrypts the key to be synchronized in the master device, generating an encrypted file. This encrypted file is stored in the smart key and transmitted to the auxiliary device for decryption using the private key in the auxiliary device. The key to be synchronized is then obtained and saved in the auxiliary device's security domain, thus completing the key synchronization process between the master and auxiliary devices. The security domain is a protected area, including specific storage partitions in the hardware module and software-defined secure storage areas.

[0047] Furthermore, the consistency and integrity of the synchronization key generated in the master device and the synchronization key obtained after decryption by the auxiliary device are compared to examine whether the synchronization key has been tampered with during transmission among multiple participating synchronization devices. In some embodiments, the method further includes steps S1 to S3: Step S1: Calculate the first message authentication code using the preset shared key and the synchronization key generated by the master device's cryptographic chip.

[0048] Step S2: Calculate the second message authentication code using the preset shared key and the key to be synchronized obtained after decrypting the encrypted file with the encrypted private key.

[0049] Step S3: Compare the first message authentication code and the second message authentication code to determine the consistency and integrity of the key to be synchronized during transmission.

[0050] In some embodiments, the method further includes: The process of generating and transmitting the key to be synchronized, the process of authenticating multiple participating synchronization devices, and the process of generating and transmitting encryption key pairs are stored as logs.

[0051] On the other hand, the present invention also provides an offline symmetric key synchronization system, the system comprising: The host computer is used to assign device authentication certificates and signature key pairs for encrypting the device authentication certificates to multiple participating synchronization devices to the smart cryptographic key, and to transmit auxiliary device identifiers and preset device synchronization security rules to the smart cryptographic key. The smart cryptographic key is used to execute any of the above-mentioned offline symmetric key synchronization methods, receiving and storing the device authentication certificates and signature key pairs for encrypting the device authentication certificates assigned by the host computer via a USB interface; connecting to the master device among the participating synchronization devices via a USB interface and transmitting the master device authentication certificate and signature public key to the master device; after confirming that the master device has verified the signature of the master device authentication certificate based on the signature public key and passed the verification, obtaining the synchronization key generated by the master device's cryptographic chip and saving it to the master device's security domain; and obtaining the auxiliary device identifier and preset device synchronization security rules from the host computer via a USB interface. The system connects to the auxiliary device via USB and transmits the auxiliary device authentication certificate and signature public key to the auxiliary device. After confirming that the auxiliary device's authentication certificate signature is verified and passed by the auxiliary device using the signature public key, it receives and stores the encryption public key from the encryption key pair generated by the auxiliary device's cryptographic chip. It then connects to the master device via USB and, after confirming that the master device's authentication certificate signature is verified and passed by the signature public key, transmits the encryption public key to the master device. It receives and stores the encrypted file generated by the master device after encrypting the key to be synchronized using the encryption public key. Finally, it connects to the auxiliary device via USB and, after confirming that the auxiliary device's authentication certificate signature is verified and passed by the signature public key, transmits the encrypted file to the auxiliary device. It receives the key to be synchronized obtained by the auxiliary device decrypting the encrypted file using the encryption private key from the generated encryption key pair and saves it to the auxiliary device's security domain. The master device is used to verify the signature of the master device authentication certificate based on the signature public key. After the signature is verified, the master device cryptographic chip generates the key to be synchronized and saves it to the master device security domain. The master device also verifies the signature of the master device authentication certificate based on the signature public key and encrypts the key to be synchronized based on the encryption public key to generate an encrypted file. Multiple auxiliary devices are used to receive the auxiliary device authentication certificate and signature public key transmitted by the auxiliary device identifier, verify the signature of the auxiliary device authentication certificate based on the signature public key, the encryption public key in the encryption key pair generated by the auxiliary device cryptographic chip, and after verifying the signature of the auxiliary device authentication certificate based on the signature public key and passing the verification, receive the encrypted file, and decrypt the encrypted file using the encryption private key in the generated encryption key pair to obtain the key to be synchronized.

[0052] The master device is used to verify the signature of the master device authentication certificate based on the signature public key in the master device. After the signature is verified, the master device cryptographic chip deployed in the master device generates the key to be synchronized. The encryption public key encrypts the key to be synchronized to generate an encrypted file.

[0053] Multiple auxiliary devices are used to verify the signature of the auxiliary device authentication certificate based on the signature public key in the auxiliary device. After the verification is successful, the auxiliary device cryptographic chip deployed in the auxiliary device generates an encryption key pair, which includes an encryption public key and an encryption private key. After the signature of the auxiliary device authentication certificate is verified based on the signature public key in the auxiliary device, the encrypted file is decrypted using the encryption private key to obtain the key to be synchronized.

[0054] On the other hand, the present invention also provides a computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implements the steps of any of the above methods.

[0055] On the other hand, the present invention also provides a computer program product, including a computer program / instructions, characterized in that the computer program / instructions, when executed by a processor, implement the steps of any of the above methods.

[0056] The present invention will now be described with reference to a specific embodiment: 1. Figure 2 This is a schematic diagram of the offline symmetric key synchronization method according to an embodiment of the present invention. Device 1 is used as the master device, and device 2 is used as the auxiliary device. The host computer distributes the smart cryptographic key to all participating synchronization devices with device authentication certificates and signature key pairs, and binds them with the device serial numbers of the devices to be synchronized. The master device is initialized for the first time in sequence, and there can be multiple auxiliary devices. The device serial number binding process refers to binding the smart cryptographic key identifier with the device identifier of the pre-synchronization operation in the host computer. The device identifier is set at the factory and can be viewed through the version query log.

[0057] 2. The smart password key connects to the main device via a USB interface for authentication. The authentication process mainly involves verifying the device authentication certificate and the storage device serial number of the preset value.

[0058] 3. After successful authentication, the master device generates a synchronization key and stores it in the security domain, ready to be synchronized to the auxiliary device. The synchronization key generates two sets of random numbers through the cryptographic chip in the device, which serve as the synchronization key for the stream cipher algorithm (ZUC algorithm). The encryption is performed using the SM4 algorithm of the cryptographic chip to generate an encrypted file, which is then stored in the security domain.

[0059] 4. After the smart key is connected to the host computer via USB interface to configure synchronization parameters, it is connected to the auxiliary device via USB interface for authentication. After successful authentication, the auxiliary device generates an encryption key pair and puts the encryption public key into the smart key. The synchronization parameters include the identifiers of other paired auxiliary devices and the device synchronization security rules between the participating devices. The encryption key pair is a set of SM2 asymmetric key pairs generated by the cryptographic chip in the auxiliary device.

[0060] 5. The smart password key is reconnected to the main device via the USB interface. After successful authentication, the encryption public key encrypts the key to be synchronized to generate an encrypted file file1, which is then synchronized to the smart password key.

[0061] 6. The smart password key is reconnected to the auxiliary device via the USB interface. After authentication, the encrypted file file1 is obtained. The encrypted private key is used to decrypt the file, and the key to be synchronized is obtained and stored in the security domain.

[0062] 7. Figure 3 This is a schematic diagram illustrating the authentication process of multiple participating synchronization devices according to an embodiment of the present invention. After signing the device authentication certificate with a signing private key and sending it to multiple participating synchronization devices, when using the signing public key for authentication, the cryptographic chips of the multiple participating synchronization devices generate a random number R. b-- The smart key is sent for PIN verification; after the smart key undergoes PIN verification by the password security administrator, a random number R is generated within the smart key. a Then call the SM2 key of the device authentication certificate to pair with the random number R. b R a The device identifier is used to sign the device, returning the signature value TokenAB and the signing public key I. a After receiving the signature value TokenAB, the cryptographic chip checks the received I... a It verifies the validity of the device authentication certificate, confirms the possession of a valid signature key pair corresponding to the smart password key, and uses the existing R... a and the R in the signature value a Verify the signature of the smart key contained in the signature value, check the smart key identifier, and verify the random number R sent to the smart key. b--The signature value is verified by checking whether it matches the random number contained in the signature data, and whether the value of the identifier field in the signature data is equal to the smart key identifier; the expression for the signature value is: TokenAB=R a |||SID||sS(SID 1 / / R a / / R b ); In summary, this invention provides an offline symmetric key synchronization method, system, storage medium, and program product. The method is executed on a smart key. After connecting to a host computer via a USB interface, it receives and stores device authentication certificates for multiple participating synchronization devices and a signature key pair used to encrypt the device authentication certificates. The device identifiers and smart key identifiers of the participating synchronization devices are written into the corresponding device authentication certificates. The signature key pair includes a signing private key and a signing public key, used to sign the device authentication certificates using the signing private key and send them to multiple participating synchronization devices, then using the signing public key for authentication. After connecting to the master device among the participating synchronization devices via the USB interface and passing authentication, the method deploys the... The synchronization key generated by the master device's cryptographic chip is saved to the master device's security domain; the auxiliary device identifier and preset device synchronization security rules are obtained by connecting to the host computer via the USB interface; after connecting to the auxiliary device via the USB interface and passing authentication, the public key of the encryption key pair generated by the auxiliary device's cryptographic chip is received and stored; after connecting to the master device via the USB interface and passing authentication, the encrypted file generated by encrypting the synchronization key with the public key is received and stored; after connecting to the auxiliary device via the USB interface and passing authentication, the synchronization key obtained by decrypting the encrypted file with the private key of the encryption key pair is saved to the auxiliary device's security domain.

[0063] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the aforementioned edge computing server deployment method. The computer-readable storage medium can be a tangible storage medium, such as random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, floppy disks, hard disks, removable storage disks, CD-ROMs, or any other form of storage medium known in the art.

[0064] Those skilled in the art will understand that the exemplary components, systems, and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Whether implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention. When implemented in hardware, it can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the desired tasks. The programs or code segments can be stored in a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried in a carrier wave.

[0065] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.

[0066] In this invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with or in place of features of other embodiments.

[0067] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, various modifications and variations of the embodiments of the present invention are possible. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. An offline symmetric key synchronization method, characterized in that, The method includes the following steps: The system receives device authentication certificates and signature key pairs for encrypting the device authentication certificates from multiple participating synchronization devices via a host computer through a USB interface; the multiple participating synchronization devices include a master device and an auxiliary device; the signature key pair includes a signature private key and a signature public key. The system connects to the master device among the participating synchronization devices via USB interface and transmits the master device authentication certificate and the master device's signature public key to the master device. After confirming that the master device verifies the signature of the master device authentication certificate based on the signature public key and passes the verification, the system obtains the synchronization key generated by the master device's cryptographic chip from the master device and saves it to the master device's security domain. The auxiliary device identifier and preset device synchronization security rules are obtained from the host computer via the USB interface. The auxiliary device is connected via the USB interface and the auxiliary device authentication certificate and the auxiliary device signature public key are transmitted to the auxiliary device. After it is determined that the auxiliary device has verified the signature of the auxiliary device authentication certificate based on the signature public key and the verification is successful, the encryption public key in the encryption key pair generated by the auxiliary device cryptographic chip in the auxiliary device is received and stored. The device connects to the main device via a USB interface. After confirming that the main device has verified the signature of the main device's authentication certificate based on the signature public key and the signature is verified, the encryption public key is transmitted to the main device. The device receives and stores the encrypted file generated by the main device encrypting the key to be synchronized based on the encryption public key. The device connects to the auxiliary device via a USB interface. After confirming that the auxiliary device has verified the signature of the auxiliary device's authentication certificate based on the signature public key, the encrypted file is transmitted to the auxiliary device. The device receives the key to be synchronized obtained by decrypting the encrypted file using the private key in the generated encryption key pair and saves it in the security domain of the auxiliary device.

2. The offline symmetric key synchronization method according to claim 1, characterized in that, The process of the host computer assigning device authentication certificates to multiple devices participating in synchronization includes: The smart cryptographic key generates the signature key pair and the device authentication certificate request, and writes the device identifiers of multiple devices to be synchronized into the device authentication certificate request; After connecting to the host computer via USB interface and sending the device authentication certificate request and the signature key pair to the certificate authority of the host computer, the device authentication certificates of multiple participating synchronization devices are received.

3. The offline symmetric key synchronization method according to claim 1, characterized in that, The process by which the master device cryptographic chip generates the key to be synchronized includes: The master device's cryptographic chip randomly generates data encryption key pairs; The initialized master device random number generator generates a random number, which is then used as the synchronization key for the stream cipher algorithm.

4. The offline symmetric key synchronization method according to claim 1, characterized in that, The process of receiving and storing the public key of the encryption key pair generated by the cryptographic chip of the auxiliary device includes: The auxiliary device is initialized, and the integrity of the auxiliary device's cryptographic chip is ensured. A key generation algorithm is executed in the cryptographic chip of the auxiliary device to generate the encryption key pair; the encryption key pair contains one encryption public key and one encryption private key. The encrypted private key is stored in the cryptographic chip of the auxiliary device, and the encrypted public key is transmitted to the auxiliary device through a preset interface and written into the preset storage area of ​​the smart cryptographic key; The smart cryptographic key is subjected to encryption and decryption tests to verify the usability of the encrypted public key.

5. The offline symmetric key synchronization method according to claim 1, characterized in that, The process by which the master device verifies the signature of the master device authentication certificate based on the signing public key includes: The main device's password chip generates a random number and sends it to the smart password key. After PIN password verification, the smart password key generates a random number. After signing the random number generated by the master device's cryptographic chip, the random number of the smart cryptographic key, and the master device identifier with the signing private key, the signature value constructed by signing the two random numbers and the master device identifier with the smart cryptographic key and the signing public key are returned to the master device. The master device cryptographic chip checks the validity of the signature public key and the master device authentication certificate, and verifies the output and received random numbers of the master device, the random numbers of the smart cryptographic key, the master device identifier, and the received signature value, as well as the integrity of the original text.

6. The offline symmetric key synchronization method according to claim 1, characterized in that, The method further includes: The first message authentication code is obtained by calculating the preset shared key and the synchronization key generated by the master device's cryptographic chip. The second message authentication code is calculated using the preset shared key and the key to be synchronized obtained after the encrypted file is decrypted by the encryption private key; The first message authentication code and the second message authentication code are compared to determine the consistency and integrity of the key to be synchronized during transmission.

7. The offline symmetric key synchronization method according to claim 1, characterized in that, The method further includes: The process of generating and transmitting the key to be synchronized, the process of authenticating multiple participating synchronization devices, and the process of generating and transmitting the encryption key pair are stored as logs.

8. An offline symmetric key synchronization system, characterized in that, The system includes: The host computer is used to assign device authentication certificates for multiple participating synchronization devices and signature key pairs for encrypting the device authentication certificates to the smart cryptographic key, and to transmit auxiliary device identifiers and preset device synchronization security rules to the smart cryptographic key. A smart cryptographic key is used to execute the offline symmetric key synchronization method as described in any one of claims 1 to 7. It receives and stores device authentication certificates of multiple participating synchronization devices allocated by the host computer and a signature key pair used to encrypt the device authentication certificates via a USB interface. It connects to the master device among the participating synchronization devices via the USB interface and transmits the master device authentication certificate and signature public key to the master device. After confirming that the master device verifies the signature of the master device authentication certificate based on the signature public key and passes the verification, it obtains the synchronization key generated by the master device cryptographic chip from the master device and saves it to the master device security domain. It obtains the auxiliary device identifier and preset device synchronization security rules from the host computer via the USB interface, connects to the auxiliary device via the USB interface and transmits the auxiliary device authentication certificate and signature public key to the auxiliary device. Upon determining the auxiliary device's identity, it... After the auxiliary device verifies the signature of the auxiliary device authentication certificate based on the signature public key and passes the verification, it receives and stores the encryption public key from the encryption key pair generated by the auxiliary device's cryptographic chip. It then connects to the master device via a USB interface. After confirming that the master device has verified the signature of the master device authentication certificate based on the signature public key and passed the verification, it transmits the encryption public key to the master device. It receives and stores the encrypted file generated by the master device encrypting the key to be synchronized using the encryption public key. Finally, it connects to the auxiliary device via a USB interface. After confirming that the auxiliary device has verified the signature of the auxiliary device authentication certificate based on the signature public key and passed the verification, it transmits the encrypted file to the auxiliary device. The auxiliary device receives the key to be synchronized obtained by decrypting the encrypted file using the encryption private key from the generated encryption key pair and saves it to the auxiliary device's security domain. The master device is used to verify the signature of the master device authentication certificate based on the signature public key, and after the signature is verified, the master device cryptographic chip generates a key to be synchronized and saves it to the master device security domain; and to generate an encrypted file by verifying the signature of the master device authentication certificate based on the signature public key and encrypting the key to be synchronized based on the encryption public key. Multiple auxiliary devices are used to receive the auxiliary device authentication certificate and signature public key transmitted by the auxiliary device identifier, verify the signature of the auxiliary device authentication certificate based on the signature public key, the encryption public key in the encryption key pair generated by the auxiliary device cryptographic chip, and after verifying the signature of the auxiliary device authentication certificate based on the signature public key and passing the verification, receive the encrypted file, and decrypt the encrypted file using the encryption private key in the generated encryption key pair to obtain the key to be synchronized.

9. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method as described in any one of claims 1 to 7.

10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Emergency communication wireless Mesh ad hoc network identity authentication and data security transmission method

    CN118338291A

  • Offline identity authentication and authority management method and system

    CN119397511A