Secure communication connection establishment method, data transmission method, device and equipment
By using encryption cards in management nodes and terminal nodes, the support of custom key negotiation algorithms is achieved, solving the problem that existing SLB technology does not support custom key negotiation algorithms, and improving user experience and secure data transmission capabilities.
Patent Information
- Application Number
- CN202311856374.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
The existing SLB technology does not support custom key negotiation algorithms, which cannot meet the secure data transmission needs of some users.
Set up an encryption card in the management node and terminal node. A key negotiation algorithm different from the node's own key negotiation algorithm is configured in the encryption card. Through steps such as broadcasting communication messages and association request messages, a secure communication connection establishment based on the target key negotiation algorithm is achieved.
It realizes the support of user-defined key negotiation algorithm, improves user experience, and meets the secure data transmission needs of some users.
Smart Images

Figure CN120239107A_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technologies, and in particular, to a method for establishing a secure communication connection, a data transmission method, a device, and an apparatus. Background Art
[0002] At present, the SparkLink Alliance has provided a wireless short-range communication protocol architecture. One of the wireless short-range access technologies provided in this protocol architecture is the SparkLink-Basic (SLB for short). However, before data transmission is achieved between a terminal node device and a management node device by means of the SLB technology, a key negotiation operation needs to be performed.
[0003] In the existing technical solutions, the key negotiation algorithm applied for the key negotiation operation has been pre-built into the terminal node device and the management node device. When secure communication needs to be achieved between the terminal node device and the management node device, the two negotiate a session key on the basis of an insecure channel by means of the pre-built key negotiation algorithm, thereby establishing a secure communication channel.
[0004] However, in the existing key negotiation operation process, the applied key negotiation algorithm is fixed. When a user wants to customize the key negotiation algorithm, the SLB technology does not support it, reducing the user experience. Summary of the Invention
[0005] This application provides a method for establishing a secure communication connection, a data transmission method, a device, and an apparatus, which are used to solve the problem that the existing SLB technology does not support customizing the key negotiation algorithm, thereby being unable to meet the secure data transmission requirements of some users.
[0006] On the one hand, this application provides a method for establishing a secure communication connection, which is applied to a management node. An encryption card is provided in the management node, and at least one key negotiation algorithm different from the key negotiation algorithm of the management node itself is configured in the encryption card. The method includes:
[0007] Broadcasting a communication message, where the communication message includes the identification information of the management node and the at least one key negotiation algorithm built into the encryption card;
[0008] Receiving an association request message sent by a terminal node, where the association request message carries the identification of the terminal node, a target key negotiation algorithm, first key negotiation parameters, a first random number, and the security capabilities of the terminal node;
[0009] If the target key agreement algorithm is included in the at least one key agreement algorithm, a security context request message is sent to the terminal node according to a preset algorithm selection policy, service type, the first key agreement parameter, the first random number, and the security capability of the terminal node. The security context request message carries a second key agreement parameter, a second random number, an identifier of the master key, a target algorithm, a message integrity code length, and a first authentication parameter. The target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm;
[0010] Receive a security context response message sent by the terminal node. The security context response message includes a second authentication parameter;
[0011] After both the integrity check and the parameter check of the security context response message pass, a connection establishment message is sent to the terminal node. The connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key;
[0012] Receive a connection establishment completion message sent by the terminal node.
[0013] In a possible design of the first aspect, the sending a security context request message to the terminal node according to a preset algorithm selection policy, service type, the first key agreement parameter, the first random number, and the security capability of the terminal node includes:
[0014] Select the target algorithm with the highest priority from the capability algorithms locally stored in the management node according to the security capability of the terminal node, the algorithm selection policy, and the service type;
[0015] Generate a public key as the second key agreement parameter according to the generated private key and the target key agreement algorithm;
[0016] Generate the second random number using a random number generator;
[0017] Calculate a shared key according to the first key agreement parameter and the target key agreement algorithm;
[0018] Calculate a master key according to the shared key, the second random number, and the first random number using the key derivation function, and generate an identifier of the master key;
[0019] Derive a security key for the signaling plane and a security key for the user plane from the master key using the key derivation function;
[0020] Calculate the first authentication parameter according to the association request message, the second random number, the shared key, and the pre-provisioned shared key;
[0021] Carry the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter in the security context request message and send them to the terminal node.
[0022] In a possible design of the first aspect, the signaling plane algorithm includes: an encryption algorithm and an integrity protection algorithm for the signaling plane;
[0023] The user plane algorithm includes: an encryption algorithm and an integrity protection algorithm for the user plane, or an authenticated encryption algorithm for the user plane.
[0024] In a possible design of the first aspect, after receiving the association request message sent by the terminal node, the method further includes:
[0025] Determine whether the number of terminal nodes currently connected to the management node is less than a preset number threshold;
[0026] If the number of terminal nodes currently connected to the management node is less than the number threshold, determine whether the target key negotiation algorithm is included in the at least one key negotiation algorithm;
[0027] If the number of terminal nodes currently connected to the management node is greater than or equal to the number threshold, discard the association request message.
[0028] In a possible design of the first aspect, before the broadcast communication message, the method further includes:
[0029] In response to the data transmission mode selected by the user to be through the encryption card, read the at least one key negotiation algorithm supported by the encryption card from the encryption card.
[0030] In a second aspect, the present application provides a method for establishing a secure communication connection, which is applied to a terminal node. At least one key negotiation algorithm different from the key negotiation algorithm of the terminal node itself is configured in the encryption card of the terminal node. The method includes:
[0031] Detect a received communication message broadcast by the management node. The communication message includes the identification information of the management node and at least one key negotiation algorithm;
[0032] Select a target key negotiation algorithm from the encryption card according to the communication message;
[0033] Send an association request message to the management node, where the association request message carries the identifier of the terminal node, the target key negotiation algorithm, the first key negotiation parameter generated according to the target key negotiation algorithm, the security capability of the terminal node, and the first random number;
[0034] Receive a security context request message sent by the management node, where the security context request message carries the second key negotiation parameter, the second random number, the identifier of the master key, and the target algorithm, and the target algorithm includes a key derivation function, a signaling plane algorithm, a user plane algorithm, a message integrity code length, and the first authentication parameter;
[0035] After both the integrity check and parameter check of the security context request message pass, send a security context response message to the management node, where the security context response message carries the second authentication parameter;
[0036] Receive a connection establishment message sent by the management node, where the connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key;
[0037] After the integrity verification of the connection establishment message passes, return a connection establishment completion message to the management node.
[0038] In a possible design of the second aspect, before sending the association request message to the management node, the method further includes:
[0039] Generate a corresponding public key as the first key negotiation parameter according to the generated private key and the target key negotiation algorithm;
[0040] Generate the first random number using a random number generator.
[0041] In a possible design of the second aspect, before sending the security context response message to the management node, the method further includes:
[0042] Calculate a shared key according to the second key negotiation parameter and the target key negotiation algorithm;
[0043] Calculate the master key using the key derivation function according to the shared key, the second random number, and the first random number;
[0044] Derive the security key for the signaling plane and the security key for the user plane from the master key using the key derivation function.
[0045] In a possible design of the second aspect, the method further includes:
[0046] Verify the integrity of the security context request message according to the message integrity code length in the security context request message;
[0047] After the integrity verification of the security context request message passes, calculate the second authentication parameter according to the first random number, the shared key, and the pre-provisioned shared key;
[0048] Verify the first authentication parameter in the security context request message according to the second authentication parameter.
[0049] In a third aspect, the present application provides a data transmission method, which is applied to a management node. An encryption card is provided in the management node, and at least one key negotiation algorithm different from the key negotiation algorithm of the management node itself is configured in the encryption card. The method includes:
[0050] After establishing a secure communication connection between the management node and the terminal node using the key negotiation algorithm in the encryption card, perform user plane data transmission with the terminal node through the encryption card.
[0051] In a fourth aspect, the present application provides a data transmission method, which is applied to a terminal node. An encryption card is provided in the terminal node, and at least one key negotiation algorithm different from the key negotiation algorithm of the terminal node itself is configured in the encryption card. The method includes:
[0052] After establishing a secure communication connection between the terminal node and the management node using the key negotiation algorithm in the encryption card, perform user plane data transmission with the management node through the encryption card.
[0053] In a fifth aspect, the present application provides a secure communication connection establishment device. An encryption card is provided in the secure communication connection establishment device, and at least one key negotiation algorithm different from the key negotiation algorithm of the secure communication connection establishment device itself is configured in the encryption card. The secure communication connection establishment device includes:
[0054] A sending module, configured to broadcast a communication message, where the communication message includes identification information of the secure communication connection establishment device and the at least one key negotiation algorithm built in the encryption card;
[0055] A receiving module, configured to receive an association request message sent by a terminal node, where the association request message carries the identification of the terminal node, a target key negotiation algorithm, a first key negotiation parameter, a first random number, and the security capabilities of the terminal node;
[0056] A processing module, configured to, if the target key negotiation algorithm is included in the at least one key negotiation algorithm, send a security context request message to the terminal node according to a preset algorithm selection policy, service type, the first key negotiation parameter, the first random number, and the security capability of the terminal node. The security context request message carries a second key negotiation parameter, a second random number, an identifier of the master key, a target algorithm, a message integrity code length, and a first authentication parameter. The target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm;
[0057] The receiving module is further configured to receive a security context response message sent by the terminal node, where the security context response message includes a second authentication parameter;
[0058] The sending module is further configured to, after both the integrity check and the parameter check of the security context response message pass, send a connection establishment message to the terminal node. The connection establishment message includes a temporary identifier generated by the management node for the terminal node and a validity period of the master key;
[0059] The receiving module is further configured to receive a connection establishment completion message sent by the terminal node.
[0060] In a sixth aspect, the present application provides a device for establishing a secure communication connection. An encryption card is provided in the device for establishing a secure communication connection, and at least one key negotiation algorithm different from the key negotiation algorithm of the device for establishing a secure communication connection itself is configured in the encryption card. The device for establishing a secure communication connection includes:
[0061] A receiving module, configured to detect and receive a communication message broadcast by a management node. The communication message includes identification information of the management node and at least one key negotiation algorithm;
[0062] A processing module, configured to select a target key negotiation algorithm from the encryption card according to the communication message;
[0063] A sending module, configured to send an association request message to the management node. The association request message carries an identifier of the terminal node, the target key negotiation algorithm, a first key negotiation parameter generated according to the target key negotiation algorithm, the security capability of the terminal node, and a first random number;
[0064] The receiving module is further configured to receive a security context request message sent by the management node. The security context request message carries a second key negotiation parameter, a second random number, an identifier of the master key, and a target algorithm. The target algorithm includes a key derivation function, a signaling plane algorithm, a user plane algorithm, a message integrity code length, and a first authentication parameter;
[0065] The sending module is further configured to send a security context response message to the management node after both the integrity check and parameter check of the security context request message pass. The second authentication parameter is carried in the security context response message;
[0066] The receiving module is further configured to receive a connection establishment message sent by the management node. The connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key;
[0067] The sending module is further configured to return a connection establishment completion message to the management node after the integrity verification of the connection establishment message passes.
[0068] In a seventh aspect, the present application provides a data transmission device. An encryption card is provided in the data transmission device. At least one key negotiation algorithm different from the key negotiation algorithm of the data transmission device itself is configured in the encryption card. The data transmission device includes:
[0069] A transmission module, configured to perform user plane data transmission with the terminal node through the encryption card after a secure communication connection is established between the data transmission device and the terminal node using the key negotiation algorithm in the encryption card.
[0070] In an eighth aspect, the present application provides a data transmission device. An encryption card is provided in the data transmission device. At least one key negotiation algorithm different from the key negotiation algorithm of the data transmission device itself is configured in the encryption card. The data transmission device includes:
[0071] A transmission module, configured to perform user plane data transmission with the management node through the encryption card after a secure communication connection is established between the data transmission device and the management node using the key negotiation algorithm in the encryption card.
[0072] In a ninth aspect, the present application provides a management node device, including:
[0073] A transceiver, a processor, a memory, and an encryption card;
[0074] Wherein, computer execution instructions are stored in the memory;
[0075] The processor is configured to execute the computer execution instructions stored in the memory to implement the method according to any one of the first aspect or the third aspect.
[0076] In a tenth aspect, the present application provides a terminal node device, including:
[0077] A transceiver, a processor, a memory, and an encryption card;
[0078] Among them, computer-executable instructions are stored in the memory;
[0079] The processor is configured to execute the computer-executable instructions stored in the memory to implement the method described in any one of the second aspect or the fourth aspect.
[0080] In an eleventh aspect, the present application provides a computer-readable storage medium storing computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method described in any one of the first aspect to the fourth aspect.
[0081] In a twelfth aspect, the present application provides a computer program product including a computer program, and when the computer program is executed by a processor, it is used to implement the method described in any one of the first aspect to the fourth aspect.
[0082] The method, apparatus, and device for establishing a secure communication connection provided by the present application relate to communication technologies. In this solution, it includes a management node and a terminal node. Among them, encryption card devices are respectively built into the management node and the terminal node, and the encryption card supports a user-defined key negotiation algorithm. At the same time, this key negotiation algorithm is different from the key negotiation algorithms built into the management node and the terminal node themselves, breaking through the limitations of the original SLB technology, thereby meeting the actual application requirements of users. The G node and the T node execute the sending of an association request message and the sending and response of a secure context request message based on the selected target key negotiation algorithm, thereby completing the establishment of a secure communication connection. In this process, the G node and the T node respectively read the built-in key negotiation algorithm in the encryption card and jointly determine the target key negotiation algorithm to be applied subsequently. At the same time, both the key negotiation and the operation of configuring key information are carried out in combination with the key negotiation algorithm in the encryption card. After the secure communication connection is established, during the data transmission process, the G node and the T node add a data header to the data to be transmitted using other data processing algorithms built into the encryption card, thereby realizing the security of data transmission and meeting the requirements in actual applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0083] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0084] Figure 1 It is a schematic flow chart of the method for establishing an existing secure communication connection provided by the present application;
[0085] Figure 2 It is a schematic diagram of an application scenario of the method for establishing a secure communication connection provided by the present application;
[0086] Figure 3 Schematic flowchart of the first embodiment of the method for establishing a secure communication connection provided by this application;
[0087] Figure 4 Schematic flowchart of the second embodiment of the method for establishing a secure communication connection provided by this application;
[0088] Figure 5 Schematic flowchart of the third embodiment of the method for establishing a secure communication connection provided by this application;
[0089] Figure 6 Schematic flowchart of the fourth embodiment of the method for establishing a secure communication connection provided by this application;
[0090] Figure 7 Schematic flowchart of the fifth embodiment of the method for establishing a secure communication connection provided by this application;
[0091] Figure 8 Schematic flowchart of the sixth embodiment of the method for establishing a secure communication connection provided by this application;
[0092] Figure 9 Schematic flowchart of the seventh embodiment of the method for establishing a secure communication connection provided by this application;
[0093] Figure 10 Schematic flowchart of the first embodiment of the data transmission method provided by this application;
[0094] Figure 11 Schematic flowchart of the method for establishing a secure communication connection provided by this application;
[0095] Figure 12 Schematic structural diagram of the first embodiment of the device for establishing a secure communication connection provided by this application;
[0096] Figure 13 Schematic structural diagram of the second embodiment of the device for establishing a secure communication connection provided by this application;
[0097] Figure 14 Schematic structural diagram of the first embodiment of the data transmission device provided by this application;
[0098] Figure 15 Schematic structural diagram of the second embodiment of the data transmission device provided by this application;
[0099] Figure 16 Schematic structural diagram of a management node device provided by this application;
[0100] Figure 17 Schematic structural diagram of a terminal node device provided by this application.
[0101] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and will be described in more detail hereinafter. These drawings and the written description are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Description of the Embodiments
[0102] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0103] With the rapid development of communication technology, the SparkLink Alliance provides a wireless short-range communication protocol architecture. In this architecture, one of the provided wireless short-range access technologies is SLB, which can handle high-rate, large-transmission, and high-quality connection scenarios. However, before data transmission is achieved between a Terminal (abbreviated as: T) node device and a Grant (abbreviated as: G) node device based on the SLB technology, a secure communication connection needs to be established and a key negotiation operation needs to be performed.
[0104] In the existing technical solutions, when performing a key negotiation operation between a T node device without a security context and a G node device, the algorithm applied is a pre-built key negotiation algorithm. Figure 1 Schematic flow diagram of the method for establishing an existing secure communication connection provided for the present application. As Figure 1 shown, when the T node has no security context, the process of establishing a secure communication connection with the G node includes:
[0105] S101: The G node broadcasts the key negotiation algorithm capability;
[0106] S102: The T node sends an association request message to the G node;
[0107] S103: The G node sends a security context request message to the T node;
[0108] S104: The T node returns a security context response message to the G node;
[0109] S105: The G node sends an association establishment message to the T node;
[0110] S106: The T node returns an association completion message to the G node.
[0111] However, in the above existing method flow for establishing a secure communication connection, the key negotiation algorithms applied by the G node and the T node are both pre-set by the SLB technology and cannot be changed. When a user wants to perform a key negotiation operation with a different key negotiation algorithm, the existing SLB technology does not support it, resulting in a reduced user experience.
[0112] To address the above problems, the inventors found during the research on the method for establishing a secure communication connection that on both the existing G node and T node sides, the authentication and secure context negotiation processes are carried out with the aid of pre-set key negotiation algorithms, resulting in a poor user experience. When a user wants to achieve a secure communication connection between the G node and the T node by means other than the built-in key negotiation algorithm, the operation of re-setting the internal chip structure and content of the G node and T node devices is complex and unrealistic. Accordingly, the inventors considered whether it is possible to add encryption card devices to the G node and T node sides respectively without damaging the original structure and content of the G node and T node devices. Among them, the encryption card is built with a key negotiation algorithm that meets the user's needs, and the G node and T node devices can establish a secure communication connection based on the encryption card. Specifically, when the user chooses to implement secure data transmission in the form of an encryption card, the G node reads the key negotiation algorithm built in the encryption card, forms a notification message with its own identification information, and broadcasts it to the T node. Based on the key negotiation algorithm carried in the broadcast message of the G node, the T node combines it with the key negotiation algorithm built in its own encryption card to select the target key negotiation algorithm. The secure communication connection between the G node and the T node is then established with the determined target key negotiation algorithm to achieve the transmission of secure data, thus meeting all the requirements of practical applications and enhancing the user experience.
[0113] Figure 2 Schematic diagram of the application scenario of the method for establishing a secure communication connection provided by this application. As Figure 2As shown in the figure, the application scenario of the solution provided by this application includes a G node 201 and a T node 202. Among them, an encryption card 2011 is built into the G node 201, and an encryption card 2021 is built into the T node 202. The T node 202 has no security context. Between the G node 201 and the built-in encryption card 2011, and between the T node 202 and the built-in encryption card 2021, the communication function is implemented in ways such as SD, NM, or serial port. Before data transmission is implemented between the T node 202 and the G node 201, a secure communication connection needs to be established between the T node 202 and the G node 201. During the establishment process, the G node 201 pre-broadcasts a notification message carrying the built-in key negotiation algorithm and identification information of the encryption card 2011 to the T node 202. Based on the key negotiation algorithm in the built-in encryption card 2021, the T node 202 selects a target key negotiation algorithm and sends an association request message to the G node. Subsequently, a request and response operation for the security context is performed between the G node 201 and the T node 202 to establish a secure communication connection. Although Figure 2 only one G node 201 and one T node 202 are shown in the figure, it should be understood that there may be two or more G nodes 201 and T nodes 202. The G node 201 and the T node 202 are connected through a communication network.
[0114] The technical solution of this application and how the technical solution of this application solves the above technical problems will be described in detail below with specific embodiments. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0115] In the following specific embodiments, the T node that establishes a secure communication connection with the G node has no security context. Therefore, an authentication and security context negotiation process should be carried out between the G node and the T node. At the same time, there can be multiple G nodes and T nodes that establish a secure communication connection in the following specific embodiments. For example, multiple T nodes without a security context send association requests to the G node at the same time. For the sake of easy understanding, in the following text, one G node and one T node are taken as examples for description.
[0116] Figure 3 It is a schematic flowchart of the first embodiment of the method for establishing a secure communication connection provided by this application.
[0117] As Figure 3 shown, the process of the method for establishing a secure communication connection may include:
[0118] S301: Broadcast a communication message, where the communication message includes the identification information of the management node and at least one key negotiation algorithm built into the encryption card.
[0119] In this step, the management node (i.e., the G node) broadcasts a communication message to the terminal node (i.e., the T node). Among them, the communication message broadcast by the G node includes the identification information of the G node and at least one key negotiation algorithm built into the encryption card.
[0120] Specifically, according to the different roles in the SparkLink access layer, SparkLink devices are divided into G nodes and T nodes. A G node can manage a certain number of T nodes. The G node and the T nodes connected to it together form a communication domain.
[0121] In the communication message broadcast by the G node, there are two key parts in total. The first key part is the identification information of the G node, which can uniquely determine the identity information of the G node. For example, the identification information is denoted as DomainID, so that the T node can uniquely determine the target G node to be connected and achieve precise connection.
[0122] The second key part is at least one key negotiation algorithm set in the encryption card built into the G node. The at least one key negotiation algorithm set is different from the key negotiation algorithm of the G node itself. For example, the key negotiation algorithms built into the G node itself are 1, 2, 3, while the key negotiation algorithms built into the encryption card are 4, 5, 6. At the same time, the key negotiation algorithms set in the encryption card built into the G node are arranged in the order of priority, and the key negotiation algorithm with a higher priority is ranked in the front. In a possible implementation, the key negotiation algorithms built into the encryption card support user customization.
[0123] Among them, the key negotiation algorithm is a protocol for secure data transmission, which allows the G node and the T node to establish a shared secret key simultaneously without exchanging the real password.
[0124] On this basis, the communication connection between the G node and the built-in encryption card can be realized in ways such as a Secure Digital Memory Card (abbreviation: SD card), a Network Management (abbreviation: NM) interface, or a serial port. For example, the key negotiation algorithm is built into the SD card. The G node sends a read command for the key negotiation algorithm to it. After receiving the command, the SD card returns the response data to the G node, that is, all the key negotiation algorithms built into the SD card.
[0125] Based on the real-time broadcast of the communication message on the G node side, the T node side receives it in real time, thus laying a foundation for the subsequent connection of secure communication.
[0126] S302: Detect and receive the communication message broadcast by the management node. The communication message includes the identification information of the management node and at least one key negotiation algorithm.
[0127] In this step, based on step S301, during the process that the G node broadcasts a notification message carrying the G node identification information and at least one key negotiation algorithm built in the encryption card, at least one T node without a security context detects and receives the communication message broadcast by the G node.
[0128] Among them, the communication between the G node and the T node is realized in the way of connecting through a wireless communication network, without the need to use cables or network connections. When a G node broadcasts a communication message in real time, the T node can detect and receive it in real time. In this broadcast communication message, it includes the identification information of the G node and at least one key negotiation algorithm. After the T node receives the broadcast message of the G node, it will perform the operation of selecting a target key negotiation algorithm. It should be noted that if the T node is pre-configured with a whitelist, the T node should only be able to connect to the G nodes in the whitelist.
[0129] S303: Select a target key negotiation algorithm from the encryption card according to the communication message.
[0130] In this step, based on step S302, after the T node with a built-in encryption card detects and receives the communication message broadcast by the G node, it selects a target key negotiation algorithm from the encryption card according to the communication message.
[0131] Among them, based on the communication message broadcast by the G node, the T node obtains the key negotiation algorithm capabilities of the G node, that is, at least one key negotiation algorithm carried in the broadcast message. At the same time, based on the key negotiation algorithms set in the built-in encryption card of the T node, a target key negotiation algorithm is selected.
[0132] Specifically, the selected target key negotiation algorithm should be a key negotiation algorithm supported by the built-in encryption card of the T node and have the highest priority among the key negotiation algorithms supported by the encryption card on the G node side. For example, the key negotiation algorithms supported by the encryption card on the G node side are arranged in the order of priority as key negotiation algorithm A, key negotiation algorithm B, and key negotiation algorithm C. The key negotiation algorithms supported by the built-in encryption card of the T node are arranged in the order of priority as key negotiation algorithm B, key negotiation algorithm C, and key negotiation algorithm D. Therefore, the selected target key negotiation algorithm is key negotiation algorithm B, which has the highest priority among the key negotiation algorithms supported by the encryption card on the G node side and is also a key negotiation algorithm supported by the encryption card on the T node side.
[0133] S304: Send an association request message to the management node. The association request message carries the identification of the terminal node, the target key negotiation algorithm, the first key negotiation parameter generated according to the target key negotiation algorithm, the security capabilities of the terminal node, and the first random number.
[0134] In this step, based on step S303, after the T node selects a target key negotiation algorithm from the encryption card according to the communication message, the T node sends an association request message to the management node.
[0135] Among them, the association request message carries the identifier of the T node, the target key negotiation algorithm, the first key negotiation parameter generated according to the target key negotiation algorithm, the security capabilities of the T node, and the first random number.
[0136] Specifically, the identifier of the T node can uniquely determine the identity information of the T node. After the G node receives it, it can quickly know which T node sent the association request message.
[0137] The target key negotiation algorithm is selected by the T node from the encryption card according to the communication message based on step S303.
[0138] The first key negotiation parameter is generated based on the target key negotiation algorithm. Specifically, the T node first generates the corresponding private key based on the built-in private key generation method of the device, and then generates the corresponding public key according to the target key negotiation algorithm, and this public key is used as the first key negotiation parameter.
[0139] The security capabilities of the T node mainly include the key derivation function, encryption algorithm, integrity protection algorithm, and authenticated encryption algorithm supported by the T node.
[0140] Among them, the key derivation function is a function whose function is to generate one or more keys from a key.
[0141] The encryption algorithm converts the original data to be transmitted into ciphertext through a certain algorithm, that is, encrypts the data, so that unauthorized devices cannot read and understand the data content, thereby protecting the confidentiality of the data and preventing the data from being stolen or tampered with.
[0142] The role of the integrity protection algorithm is to ensure that the information or data is not tampered with without authorization or can be quickly detected after being tampered with during the process of transmitting, storing information or data. When exchanging information daily, both parties exchanging information hope that the information or data sent can reach the other party accurately. Commonly used integrity protection algorithms include hash algorithms, digital signature algorithms, etc.
[0143] The first random number is generated by the T node using a secure random number generator to ensure the randomness of the first random number.
[0144] S305: Receive the association request message sent by the terminal node. The association request message carries the identifier of the terminal node, the target key negotiation algorithm, the first key negotiation parameter, the first random number, and the security capabilities of the terminal node.
[0145] In this step, based on step S304, after the T node sends an association request message to the G node, the G node receives the association request message sent by the T node.
[0146] Among them, the association request message carries the identifier of the T node, the target key negotiation algorithm, the first key negotiation parameter, the first random number, and the security capabilities of the T node. The specific meaning of each parameter can refer to step S303 and will not be elaborated here.
[0147] S306: If at least one of the key negotiation algorithms includes the target key negotiation algorithm, then according to the preset algorithm selection strategy, service type, the first key negotiation parameter, the first random number, and the security capabilities of the terminal node, send a security context request message to the terminal node. The security context request message carries the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter. The target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm.
[0148] In this step, based on step S305, after the G node receives the association request message sent by the T node, the G node determines whether the algorithm is one of the at least one key negotiation algorithms carried in the G node's broadcast notification message based on the target key negotiation algorithm carried in the association request message sent by the T node, that is, the G node determines whether the key negotiation algorithm selected by the T node is among the key negotiation algorithms carried in the broadcast message.
[0149] If at least one of the key negotiation algorithms includes the target key negotiation algorithm, the G node then sends a security context request message to the terminal node according to the preset algorithm selection strategy, service type, the first key negotiation parameter, the first random number, and the security capabilities of the terminal node.
[0150] Among them, the preset algorithm selection strategy can be implemented through a list of algorithms sorted by priority. For example, the priority list of key derivation functions preconfigured by the G node, the priority list of signaling plane encryption algorithms, the priority list of signaling plane integrity protection algorithms, the priority list of user plane encryption algorithms, and the priority list of user plane integrity protection algorithms, etc.
[0151] The service type refers to what type of data transmission the T node specifically wants to achieve with the G node. For example, different service types such as music, radio, video, etc. These different service types correspond to different preset algorithm selection strategies respectively.
[0152] In the sent security context request message, carry the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter.
[0153] Among them, the second key negotiation parameter is generated by the target key negotiation algorithm. Specifically, the G node first generates the corresponding private key based on the private key generation method built into the device, and then generates the corresponding public key according to the target key negotiation algorithm, and this public key is used as the second key negotiation parameter.
[0154] The second random number is generated by the G node using a secure random number generator to ensure the randomness of the second random number.
[0155] The identifier of the master key is first calculated by the key derivation function to obtain the master key, and then the G node generates the identifier of the master key based on the master key.
[0156] The target algorithm is jointly determined based on the algorithm preference strategy pre-configured by the G node and the service type. Specifically, the target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm. Among them, the key derivation function is the key derivation function with the highest priority built into the G node. The signaling plane algorithm includes the signaling plane encryption algorithm and the integrity protection algorithm with the highest priority built into the G node. The user plane algorithm includes the user plane encryption algorithm and the integrity protection algorithm with the highest priority, or the authenticated encryption algorithm with the highest priority for the user plane. Among them, the algorithms selected for the signaling plane and the user plane can be different.
[0157] The Message Integrity Code (MIC) can be used to check the integrity of the message, that is, to confirm whether the message has been tampered with. When the selected integrity algorithm or authenticated encryption algorithm supports multiple MIC lengths, the G node selects the MIC length for signaling plane integrity protection according to the MIC length supported by the selected signaling plane integrity protection algorithm and the pre-configured MIC length preference strategy for signaling plane integrity protection. The signaling plane MIC length preference strategy can be implemented through a list of MIC lengths arranged in priority order. The MIC length of the user plane is determined according to the MIC length supported by the user plane integrity protection algorithm or the authenticated encryption algorithm, and the service characteristics of the T node (such as service type and service packet size), and the G node sends the MIC length of the user plane to the T node.
[0158] The first authentication parameter is generated by the G node based on the selected key derivation function, and the parameters applied are the pre-shared key, the shared key, the second random number, and the association request message.
[0159] S307: Receive the security context request message sent by the management node. The security context request message carries the second key negotiation parameter, the second random number, the identifier of the master key, and the target algorithm. The target algorithm includes a key derivation function, a signaling plane algorithm, a user plane algorithm, the message integrity code length, and the first authentication parameter.
[0160] In this step, based on step S306, after the G node sends a security context request message to the T node, the T node receives the security context request message sent by the G node.
[0161] Among them, the security context request message carries the second key negotiation parameter, the second random number, the identifier of the master key, and the target algorithms. The target algorithms include a key derivation function, a signaling plane algorithm, a user plane algorithm, the message integrity code length, and the first authentication parameter. The specific meaning of each parameter can refer to step S306 and will not be elaborated here.
[0162] When the carried user plane integrity algorithm identifier is empty (all 0s), it indicates that the user plane integrity protection is not started. When the carried signaling plane encryption algorithm identifier is empty (all 0s), it indicates that the signaling plane encryption protection is not started. When the carried user plane encryption algorithm identifier is empty (all 0s), it indicates that the user plane encryption protection is not started. When the carried user plane protection algorithm is an authenticated encryption algorithm, it indicates that the user plane encryption and integrity protection are started.
[0163] S308: After both the integrity check and parameter check of the security context request message pass, send a security context response message to the management node. The security context response message carries the second authentication parameter.
[0164] In this step, based on step S307, after the T node receives the security context request message sent by the G node, it performs an integrity check and parameter check on the security context request message. After both the integrity check and parameter check pass, the T node sends a security context response message carrying the second authentication parameter to the management node.
[0165] Among them, the second authentication parameter is generated by the T node based on the selected key derivation function. The parameters applied are the pre-shared key, the shared key, the first random number, the security context request message, and the key negotiation algorithm capabilities of the G node.
[0166] S309: Receive the security context response message sent by the terminal node. The security context response message includes the second authentication parameter.
[0167] In this step, based on step S308, after the T node sends a security context response message to the G node, the G node receives the security context response message sent by the T node.
[0168] Among them, the security context response message includes the second authentication parameter. How the second authentication parameter is calculated specifically can refer to step S308 and will not be elaborated here.
[0169] S310: After both the integrity check and parameter check of the security context response message pass, send a connection establishment message to the terminal node. The connection establishment message includes the temporary identifier generated by the management node for the terminal node and the validity period of the master key.
[0170] In this step, based on step S309, after the G node receives the security context response message sent by the T node, if the security context response message is encrypted, the G node first decrypts the security context response message and performs the integrity check and parameter check on the security context response message. After the check passes, the G node sends a connection establishment message to the T node. If the check fails, the G node sends a message indicating that the association establishment fails to the T node.
[0171] Among them, after the check passes, the connection establishment message sent by the G node to the T node includes the temporary identifier generated by the G node for the T node and the validity period of the master key. The temporary identifier can be expressed as T-ID, and this temporary identifier is a physical layer identifier. The validity period of the master key represents the survival period of this master key. When the survival period ends, this master key loses its effective function.
[0172] The G node uses the integrity protection algorithm and integrity protection key of the signaling plane to perform integrity protection on the association establishment message. The message integrity code generated by the integrity protection is carried in the association establishment message. When the signaling plane encryption protection algorithm is started, the G node uses the encryption algorithm and encryption key of the signaling plane to perform encryption protection on the association establishment message.
[0173] S311: Receive the connection establishment message sent by the management node. The connection establishment message includes the temporary identifier generated by the management node for the terminal node and the validity period of the master key.
[0174] In this step, based on step S310, the G node sends a connection establishment message to the T node, and the T node then receives the corresponding connection establishment message.
[0175] Among them, the received connection establishment message includes the temporary identifier generated by the G node for the T node and the validity period of the master key. The specific meanings of the temporary identifier and the validity period of the master key can refer to step S310 and will not be elaborated here.
[0176] S312: After the integrity verification of the connection establishment message passes, return a connection establishment completion message to the management node.
[0177] In this step, based on step S311, after the T node receives the connection establishment message sent by the G node, the T node performs integrity verification on the connection establishment message. After the verification passes, the T node returns a connection establishment completion message to the G node.
[0178] Among them, if the association establishment message sent by the G node is encrypted, the T node first decrypts the association establishment message, and then checks the integrity of the association establishment message. If the integrity verification of the association establishment message fails, the message is discarded. If the integrity verification of the association establishment message passes, the T node sends an association completion message to the G node.
[0179] S313: Receive the connection establishment completion message sent by the terminal node.
[0180] In this step, based on step S312, after the T node returns the connection establishment completion message to the G node, the G node receives the connection establishment completion message sent by the T node.
[0181] Among them, if the T node encrypts the sent connection establishment completion message, the G node decrypts the connection establishment completion message and checks the integrity of the message. If the integrity verification fails, the G node discards the message. If the integrity verification passes, the G node and the T node save the security context negotiated securely. Specifically, the security context includes G node identification information, T node identification information, master key, master key validity period, master key identifier, target key negotiation algorithm, signaling plane encryption algorithm and integrity protection algorithm, signaling plane encryption key and integrity protection key, user plane encryption algorithm and integrity protection algorithm or user plane authenticated encryption algorithm, user plane encryption key and integrity protection key or user plane authenticated encryption key, key derivation counter.
[0182] There is an expiration deletion mechanism for the security context, and the node that needs to save the security context has a clock. At the same time, the G node saves the correspondence between the T node identification information and the pre-shared key. The T node saves the correspondence between the G node identification information and the pre-shared key.
[0183] If the T node receives the message indicating the failure of association establishment sent by the G node, the T node re-sends an association request message to the G node.
[0184] The method for establishing a secure communication connection provided by this application mainly describes how the G node and the T node establish a secure communication connection based on the encryption card. Among them, encryption card devices are set on both the G node and the T node side. In this encryption card, a key negotiation algorithm different from the key negotiation algorithms of the G node and the T node themselves is built in. The G node and the T node negotiate the security context based on the determined target key negotiation algorithm to establish a secure communication connection. In this process, the encryption card supports the setting of custom key negotiation algorithms, which can break through the fixity of the built-in key negotiation algorithm in the original SLB technology, so as to meet the needs of actual applications and improve the user experience.
[0185] Figure 4This is a schematic flowchart of the second embodiment of the method for establishing a secure communication connection provided by this application. As Figure 4 shown, based on the above embodiment, according to a preset algorithm selection policy, service type, first key negotiation parameter, first random number, and the security capabilities of the terminal node, a security context request message is sent to the terminal node. The process of this method for establishing a secure communication connection may include:
[0186] S401: According to the security capabilities of the terminal node, the algorithm selection policy, and the service type, select the target algorithm with the highest priority from the capability algorithms locally stored by the management node.
[0187] In this step, when the G node receives the association request message sent by the T node, the G node first selects the target algorithm with the highest priority from the capability algorithms locally stored by the G node according to the security capabilities, algorithm selection policy, and service type carried in the association request message.
[0188] Among them, the security capabilities of the T node include the key derivation function, encryption algorithm, integrity protection algorithm, and authenticated encryption algorithm supported by the T node.
[0189] The algorithm preference strategy can be implemented through an algorithm list sorted by priority, such as the key derivation function priority list, signaling plane encryption algorithm priority list, signaling plane integrity protection algorithm priority list, user plane encryption algorithm priority list, user plane integrity protection algorithm priority list, etc. pre-configured by the G node.
[0190] Based on the combination of the algorithm preference strategy and the service type, the G node selects the target algorithm with the highest priority from the capability algorithms locally stored. Among them, the service type specifically refers to what service data transmission the T node wants to achieve with the G node. For example, music, news, video, etc. Different service types will correspond to different algorithm preference strategies.
[0191] The target algorithm includes a key derivation function, an encryption algorithm and an integrity protection algorithm for the signaling plane, an encryption algorithm and an integrity protection algorithm for the user plane, or an authenticated encryption algorithm for the user plane. Among them, the algorithms selected for the signaling plane and the user plane can be different, that is, the priorities of the encryption algorithms and integrity protection algorithms for the signaling plane and the user plane can be different. At the same time, the signaling plane cannot select an authenticated encryption algorithm, and the user plane can only select an authenticated encryption algorithm when both encryption and integrity protection are enabled. In a possible implementation manner, the G node can configure the priority to determine whether to preferentially select an authenticated encryption algorithm or independent integrity protection and encryption algorithms when the user plane encryption and integrity protection are enabled.
[0192] S402: According to the generated private key and the target key negotiation algorithm, generate a public key as the second key negotiation parameter.
[0193] In this step, based on step S401, after the G node selects the target algorithm with the highest priority from the capability algorithms stored locally in the G node based on the association request message sent by the T node, the G node first generates a private key. Based on the private key, the G node generates a public key as the second key negotiation parameter based on the target key negotiation algorithm.
[0194] Among them, the way the G node generates the private key is based on the algorithm for generating the private key stored locally in the G node. For example, asymmetric encryption algorithms, elliptic curve algorithms, etc. For the private key generated by the G node, the G node generates a public key by means of the target key negotiation algorithm built into the encryption card. This public key will be used as the second key negotiation parameter. In one possible implementation, this public key can be represented as KEg.
[0195] It should be noted that the G node should generate a new key pair corresponding to the key negotiation algorithm each time, and the key pair should not be a weak key pair.
[0196] S403: Generate a second random number using a random number generator.
[0197] In this step, based on step S402, after the G node generates a public key as the second key negotiation parameter according to the generated private key and the target key negotiation algorithm, the G node uses a random number generator to generate a second random number. In one possible implementation, the second random number can be represented as NONCEg.
[0198] Among them, the random number generator is pre-configured in the G node device. For example, the random number generator can be a pseudo-random number generator (Pseudo-Random Number Generator, abbreviated as: PRNG). PRNG is a random number generator based on a deterministic algorithm. It generates a series of seemingly random numbers through an initial seed. The random number generator can also be a true random number generator (True Random Number Generator, abbreviated as: TRNG). TRNG is a random number generator based on a physical process. It uses the randomness of the physical process to generate random numbers. At the same time, the random number generator can also be a hash function. A hash function is a function that maps input data of any length to an output of a fixed length. If the input data is random, then the output should also be random. Which specific random number generator to apply needs to be determined based on the random number generator built into the G node device.
[0199] S404: Calculate the shared key according to the first key negotiation parameter and the target key negotiation algorithm.
[0200] In this step, based on step S403, after the G node generates a second random number based on the random number generator, the G node calculates the shared key according to the first key negotiation parameter and the target key negotiation algorithm.
[0201] Among them, the first key negotiation parameter is generated by the T node based on the target key negotiation algorithm in combination with the private key. The target key negotiation algorithm is jointly determined by the T node based on at least one key negotiation algorithm carried in the broadcast notification message of the G node and the key negotiation algorithms supported by the built-in encryption card. Based on the first key negotiation parameter and the target key negotiation algorithm, the shared key is calculated. In a possible implementation, the shared key can be represented as K KE .
[0202] S405: According to the shared key, the second random number, and the first random number, use the key derivation function to calculate the master key and generate an identifier for the master key.
[0203] In this step, based on step S404, after the G node calculates the shared key based on the first key negotiation parameter and the target key negotiation algorithm, it then calculates the master key according to the shared key, the second random number, and the first random number using the key derivation function, and generates an identifier for the master key.
[0204] Specifically, the calculation method of the master key Kgt is as follows:
[0205] Kgt = KDF(K KE , NONCEt, NONCEg)
[0206] Among them, K KE represents the shared key, NONCEt represents the first random number, NONCEg represents the second random number, and KDF represents the key derivation function.
[0207] Based on the calculated master key Kgt, the G node generates an identifier for Kgt, that is, Kgt ID.
[0208] S406: According to the master key, use the key derivation function to deduce the security key for the signaling plane and the security key for the user plane.
[0209] In this step, based on step S405, after the G node calculates the master key according to the shared key, the second random number, and the first random number using the key derivation function, it then deduces the security key for the signaling plane and the security key for the user plane according to the master key using the key derivation function.
[0210] Among them, according to the selected key derivation function, the security keys for the signaling plane and the user plane are further derived from the master key Kgt. The security keys for the signaling plane include the encryption key and the integrity protection key for the signaling plane. The security keys for the user plane include the encryption key and the integrity protection key for the user plane, or the authentication and encryption key for the user plane.
[0211] S407: Calculate the first authentication parameter based on the association request message, the second random number, the shared key, and the pre-provisioned shared key.
[0212] In this step, based on step S407, after the G node derives the security keys for the signaling plane and the user plane from the master key using the key derivation function, the G node calculates the first authentication parameter according to the association request message, the second random number, the shared key, and the pre-provisioned shared key sent by the T node.
[0213] Specifically, the calculation method of the first authentication parameter AUTHg is as follows:
[0214] AUTHg = AUF(PSK, K KE , NONCEg, association request message)| 高32比特
[0215] Among them, PSK represents the pre-shared key, K KE represents the shared key, and NONCEg represents the second random number.
[0216] For the T node accessing using the password method, the G node needs to first query whether there is PSK information corresponding to the T node ID according to the T node ID. If not, the G node generates the PSK according to the password. The calculation method of the PSK is as follows:
[0217] PSK = KDF(Kgt, password, T node ID, G node ID, NONCEt, NONCEg)
[0218] Among them, Kgt represents the master key, the T node ID represents the fixed identity of the T node, that is, the media access layer identifier. The G node ID represents the fixed identity of the G node, that is, the media access layer identifier. NONCEt represents the first random number, and NONCEg represents the second random number.
[0219] Before generating the PSK, the G node can send a prompt to the user, indicating that there is a new T node that needs to be associated with the G node. After the user confirms, the G node then generates the PSK.
[0220] S408: Carry the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter in the security context request message and send it to the terminal node.
[0221] In this step, based on step S407, after the G node calculates the first authentication parameter according to the association request message, the second random number, the shared key, and the pre-provisioned shared key, the G node then carries the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter in the security context request message and sends it to the terminal node, i.e., the T node.
[0222] Among them, if the target algorithm includes the integrity protection algorithm for the signaling plane, the G node uses the selected integrity protection algorithm for the signaling plane and the integrity protection key Ks.int to perform integrity protection on the security context request message, that is, calculates the MIC and includes the MIC in the security context request message.
[0223] The method for establishing a secure communication connection provided by this application mainly describes how the G node generates a security context request message to the T node based on the association request message sent by the T node. Among them, the security context request message includes the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter. The second key negotiation parameter is generated based on the determined target key negotiation algorithm, and the target key negotiation parameter is built into the encryption card on the G node side, thereby meeting the actual application requirements of users and improving the user experience.
[0224] In a possible implementation manner, the signaling plane algorithms include: the encryption algorithm and the integrity protection algorithm for the signaling plane;
[0225] The user plane algorithms include: the encryption algorithm and the integrity protection algorithm for the user plane, or the authenticated encryption algorithm for the user plane.
[0226] Specifically, the signaling plane algorithms include: the encryption algorithm and the integrity protection algorithm for the signaling plane. The signaling plane is responsible for transmitting control signaling, and the user plane transmits actual data. The user plane and the signaling plane are divided according to the type of data. In a communication system, there are both a user plane and a signaling plane. The user plane is the real service data, such as voice data or packet service data. The signaling plane is for signaling and is used to control the establishment, maintenance, and release of a call flow.
[0227] The encryption algorithm for the signaling plane is mainly used to encrypt the messages transmitted by the signaling plane. For example, symmetric encryption algorithms, advanced encryption standards, asymmetric encryption algorithms, etc.
[0228] The integrity protection algorithm for the signaling plane is mainly used to implement the integrity protection of the messages transmitted by the signaling plane and prevent the messages from being tampered with during the transmission process.
[0229] The user plane algorithms include: the encryption algorithm and integrity protection algorithm for the user plane, or the authentication and encryption algorithm for the user plane.
[0230] The encryption algorithm for the user plane is mainly used to encrypt the data transmitted on the user plane.
[0231] The integrity protection algorithm for the user plane is mainly used to protect the integrity of the data transmitted on the user plane and prevent the data from being tampered with during the transmission process.
[0232] In this embodiment, it mainly describes the specific contents included in the signaling plane algorithm and user plane algorithm among the target algorithms with the highest priority selected from the capability algorithms stored locally in the G node based on the security capabilities, algorithm selection strategies, and service types of the T node on the G node side. Among them, the signaling plane is provided with an encryption algorithm and an integrity protection algorithm, which can achieve the confidentiality and integrity of the signaling plane data transmitted between the G node and the T node. At the same time, the encryption algorithm and integrity protection algorithm set for the user plane or the authentication and encryption algorithm set for the user plane can achieve the confidentiality and integrity of the user plane data transmitted between the G node and the T node, thereby laying a foundation for establishing a secure communication connection between the G node and the T node.
[0233] Figure 5 It is a schematic flowchart of the third embodiment of the method for establishing a secure communication connection provided by this application. As Figure 5 shown, on the basis of any of the above embodiments, after receiving the association request message sent by the terminal node, the process of the method for establishing a secure communication connection further includes:
[0234] S501: Determine whether the number of terminal nodes currently connected to the management node is less than a preset number threshold.
[0235] In this step, after the G node receives the association request message sent by the T node, the G node needs to first determine whether the number of T nodes currently connected to the G node is less than the preset number threshold.
[0236] Among them, the preset number threshold of the G node is determined in advance based on the actual situation. For example, if the preset number threshold of a certain G node is 4, then the G node can only establish communication connections with 4 T nodes at the same time. When a fifth T node wants to establish a communication connection with it, the G node cannot establish a communication connection with it.
[0237] S502: If the number of terminal nodes currently connected to the management node is less than the number threshold, determine whether at least one key negotiation algorithm includes a target key negotiation algorithm.
[0238] In this step, based on step S501, after the G node determines whether the number of currently connected T nodes is less than a preset number threshold, if the number of currently connected T nodes is less than the number threshold, it determines whether at least one key negotiation algorithm includes a target key negotiation algorithm.
[0239] Among them, in the association request message sent by the T node, the target key negotiation algorithm is carried. After the G node determines that the number of currently connected T nodes is less than the number threshold, it compares at least one key negotiation algorithm carried in the previous broadcast communication message with the target key negotiation algorithm to determine whether at least one key negotiation algorithm includes the target key negotiation algorithm. If so, the G node generates a subsequent context security request message based on the target key negotiation algorithm. If not, the G node discards the message.
[0240] S503: If the number of terminal nodes currently connected to the management node is greater than or equal to the number threshold, discard the association request message.
[0241] In this step, based on step S501, after the G node determines whether the number of currently connected T nodes is less than a preset number threshold, if the number of currently connected T nodes of the G node is greater than or equal to the number threshold, the G node discards the association request message.
[0242] Among them, after the number of currently connected T nodes of the G node is greater than or equal to the number threshold, the G node cannot respond to the association request message and can only discard the association request message.
[0243] The method for establishing a secure communication connection provided by this application mainly shows that after the G node receives the association request from the T node, the first operation to be performed is to determine whether the number of T nodes currently connected to the G node is less than a preset number threshold. When it is less than the preset number threshold, the G node can respond to the association request message and determine whether the selected target key negotiation algorithm is in at least one key negotiation algorithm in the previous broadcast communication message. When it is greater than or equal to the preset number threshold, the G node cannot respond to the association request message sent by the T node and chooses to discard it. This process will be a key step in determining whether a secure communication connection can be established between the G node and the T node.
[0244] Figure 6 It is a schematic flowchart of the fourth embodiment of the method for establishing a secure communication connection provided by this application. As Figure 6 shown, on the basis of any of the above embodiments, before the broadcast communication message, the process of the method for establishing a secure communication connection further includes:
[0245] S601: In response to the data transmission mode selected by the user to be through the encryption card, read at least one key negotiation algorithm supported by the encryption card.
[0246] In this step, the premise for the G node to broadcast a communication message is that the data transmission mode selected by the user is an encryption card. At this time, in response to the data transmission mode selected by the user to transmit data through the encryption card, the G node reads at least one key negotiation algorithm supported by the encryption card from the encryption card.
[0247] Among them, the data transmission mode is divided into the form of an encryption card and the form of a non-encryption card. The non-encryption card form is a process of negotiating a security context and establishing a secure communication connection between the G node and the T node based on the key negotiation algorithm built into the G node itself. The form of the encryption card is a process of negotiating a security context between the encryption card and the T node based on the key negotiation algorithm built into the encryption card, so as to establish a secure communication connection.
[0248] When the data transmission mode selected by the user is an encryption card, the G node responds to this operation by the user, reads at least one key negotiation algorithm supported by the encryption card from the encryption card, and broadcasts the communication message in combination with the identification information of the G node. Among them, the at least one key negotiation algorithm read is different from the key negotiation algorithm built into the G node itself.
[0249] The method for establishing a secure communication connection provided by this application mainly describes the premise for triggering the G node to implement broadcasting of communication messages. When the data transmission mode is in the form of an encryption card, the G node automatically reads at least one key negotiation algorithm from the encryption card and broadcasts the communication message in combination with the identification information of the node. Through the broadcast of this communication message, the T node can detect and receive in real time to determine whether to send an association request message to the G node, thereby completing the subsequent establishment of a secure communication connection. The encryption card provides a novel form for the user to establish a secure communication connection, effectively meeting the actual application needs of the user and improving the user's satisfaction.
[0250] Figure 7 It is a schematic flowchart of the fifth embodiment of the method for establishing a secure communication connection provided by this application. As Figure 7 shown, before the terminal node sends an association request message to the management node, the method flow for establishing the secure communication connection further includes:
[0251] S701: Generate a corresponding public key as the first key negotiation parameter according to the generated private key and the target key negotiation algorithm.
[0252] In this step, before the T node sends an association request message to the G node, the T node first generates a private key, and combines it with the target key negotiation algorithm to generate a corresponding public key as the first key negotiation parameter.
[0253] Among them, the way for the T node to generate the private key is based on the algorithm for generating the private key stored locally in the T node. For example, asymmetric encryption algorithms, elliptic curve algorithms, etc. After the T node generates the private key, it uses the target key negotiation algorithm built into the encryption card to generate the public key, and this public key will be used as the first key negotiation parameter. In a possible implementation, this public key can be represented as KEt.
[0254] It should be noted that the T node should generate a new key pair corresponding to the key negotiation algorithm each time, and the key pair should not be a weak key pair.
[0255] S702: Use a random number generator to generate a first random number.
[0256] In this step, based on step S701, after the T node generates the corresponding public key as the first key negotiation parameter according to the generated private key and the target key negotiation algorithm, it uses the random number generator to generate a first random number. In a possible implementation, the first random number can be represented as NONCEt.
[0257] Among them, the random number generator is pre-configured in the T node device. For example, the random number generator can be a pseudo-random number generator, a true random number generator, and a hash function, etc. Which specific random number generator to apply needs to be determined based on the built-in random number generator in the T node device.
[0258] The method for establishing a secure communication connection provided by this application mainly describes how to generate the first key negotiation parameter and the first random number carried in the association request message before the T node sends the association request message to the G node. Among them, the first key negotiation parameter is generated based on the private key generated by the T node in combination with the target key negotiation parameter, and the first random number is generated by means of a random number generator, thereby ensuring the randomness of the random number. Through the generation of these parameters, data support is provided for the T node to send the association request message.
[0259] Figure 8 It is a schematic flowchart of Embodiment 6 of the method for establishing a secure communication connection provided by this application. As Figure 8 shown, before the terminal node sends a secure context response message to the management node, the process of the method for establishing a secure communication connection further includes:
[0260] S801: Calculate the shared key according to the second key negotiation parameter and the target key negotiation algorithm.
[0261] In this step, before the T node sends a secure context response message to the G node, the T node calculates the shared key according to the second key negotiation parameter and the target key negotiation algorithm.
[0262] Among them, the second key negotiation parameter is carried in the security context request message sent by the G node, and the target key negotiation algorithm is jointly determined by the T node and the G node during the association request message process. Based on the second key negotiation parameter and the target key negotiation algorithm, the shared key can be calculated.
[0263] S802: Calculate the master key by using a key derivation function according to the shared key, the second random number, and the first random number.
[0264] In this step, based on step S801, after the T node calculates the shared key according to the second key negotiation parameter and the target key negotiation algorithm, it calculates the master key by using a key derivation function according to the obtained shared key, the second random number, and the first random number.
[0265] Among them, the method of calculating the master key is the same as that on the G node side, and the steps can be referred to and will not be elaborated here.
[0266] S803: Deduce the security key for the signaling plane and the security key for the user plane by using a key derivation function according to the master key.
[0267] In this step, based on step S802, after the T node calculates the master key, it deduces the security key for the signaling plane and the security key for the user plane by using a key derivation function according to the obtained master key.
[0268] Among them, the method by which the T node deduces the security key for the signaling plane and the security key for the user plane by using a key derivation function based on the master key is the same as the method by which the G node deduces the security key for the signaling plane and the security key for the user plane by using a key derivation function based on the master key, and step S406 can be referred to and will not be elaborated here.
[0269] The method for establishing a secure communication connection provided by this application mainly shows that before the T node sends a security context response message to the G node, it needs to calculate the master key based on the second key negotiation parameter and the target key negotiation algorithm carried in the security context request message sent by the G node, and on this basis, deduce the security key for the signaling plane and the security key for the user plane by using a key derivation function. Through this process, the T node can obtain the same security keys for the signaling plane and the user plane as the G node, thus laying a foundation for the subsequent establishment of a secure communication connection.
[0270] Figure 9 This is a schematic flowchart of the seventh embodiment of the method for establishing a secure communication connection provided by this application. As Figure 9 shown, on the basis of any of the above embodiments, the process of the method for establishing a secure communication connection further includes:
[0271] S901: Verify the integrity of the security context request message according to the message integrity code length in the security context request message.
[0272] In this step, when the T node calculates the shared key, the security key for the signaling plane, and the security key for the user plane in the same way as the G node according to the key derivation function selected by the G node, it then verifies the integrity of the security context request message according to the message integrity code length in the security context request message.
[0273] Among them, if the message integrity code length calculated by the T node is consistent with the message integrity code length carried in the G node's security context request message, the integrity of the security context request message passes the verification, and then the T node performs the verification of the authentication parameters. If they are inconsistent, the T node discards the message and resends the association request message to the G node.
[0274] S902: After the integrity verification of the security context request message passes, calculate the second authentication parameter according to the first random number, the shared key, and the pre-provisioned shared key.
[0275] In this step, after the integrity verification of the security context request message based on step S901 passes, calculate the second authentication parameter according to the first random number, the shared key, and the pre-provisioned shared key.
[0276] Specifically, the calculation method of the second authentication parameter AUTHt is as follows:
[0277] AUTHt = AUF(PSK, K KE , the security context request message, NONCEt, the G node key negotiation algorithm capabilities) | 高32位
[0278] Among them, AUTHt represents the second authentication parameter, PSK represents the pre-provisioned shared key, K KE represents the shared key, the security context request message is the security context request message sent by the G node to the T node, NONCEt represents the first random number, and the G node key negotiation algorithm capabilities represent the key negotiation algorithms supported by the encryption card on the G node side and the capability algorithms supported by the G node itself, such as the key derivation function, the signaling plane encryption algorithm and integrity protection algorithm, the user plane encryption algorithm and integrity protection algorithm, or the user plane authentication encryption algorithm. AUF represents the key derivation function.
[0279] If the T node accesses using the password method, the T node first needs to query whether there is PSK information corresponding to the G node's identity information according to the G node's identity information. If not, the T node generates the PSK according to the password, and the PSK calculation method is as follows:
[0280] PSK = KDF(Kgt, password, T node ID, G node ID, NONCEt, NONCEg)
[0281] Among them, PSK represents the pre - configured shared key, KDF represents the key derivation function, which is consistent with the above - mentioned AUF. Kgt represents the master key, T node ID represents the identity information of the T node, G node ID represents the identity information of the G node, NONCEt represents the first random number, and NONCEg represents the second random number.
[0282] S903: Verify the first authentication parameter in the security context request message according to the second authentication parameter.
[0283] In this step, based on the second authentication parameter calculated in step S902, the T node verifies the first authentication parameter in the security context request message according to the second authentication parameter.
[0284] Among them, if the verification passes, the T node sends a security context response message to the G node, and the second authentication parameter is carried in the security context response message. At the same time, the T node uses the integrity protection algorithm and integrity protection key of the signaling plane to perform integrity protection on the security context response message, and the message integrity code generated by the integrity protection is carried in the security context response message. When the signaling plane encryption protection algorithm is started, the T node uses the encryption algorithm and encryption key of the signaling plane to perform encryption protection on the security context response message.
[0285] If the verification fails, the T node discards the message and resends the association request message to the G node.
[0286] When the first authentication parameter fails the verification multiple times, if the T node accessing through the password method has a pre - configured shared key PSK, the T node can prompt the user to confirm whether to delete the pre - shared key PSK on the T node. If the T node accessing through the password method does not have a pre - configured shared key PSK, the T node can prompt the user to delete the pre - shared key PSK on the G node at the G node.
[0287] The method for establishing a secure communication connection provided by this application mainly describes how the T node verifies the integrity and accuracy of the security context request message sent by the G node. Before the T node sends a security context response message to the G node, the T node verifies the integrity of the message based on the message integrity code length, and at the same time verifies the accuracy of the message according to the comparison between the second authentication parameter and the first authentication parameter, so as to provide a secure basic guarantee for the subsequent communication connection and data transmission between the G node and the T node, and further meet the user's needs.
[0288] Figure 10 It is a schematic flowchart of the first embodiment of the data transmission method provided by this application. AsFigure 10 As shown in the figure, the process of the data transmission method may include:
[0289] S1001: After establishing a secure communication connection between the management node and the terminal node using the key negotiation algorithm in the encryption card, user plane data is transmitted between the encryption card and the terminal node.
[0290] In this step, when a secure communication connection is established between the G node and the T node using the key negotiation algorithm in the encryption card, the G node then transmits user plane data between the encryption card and the T node. Among them, the processing that the encryption card can perform on the user plane data to be transmitted includes:
[0291] For example, in addition to at least one built-in key negotiation algorithm, the encryption card on the G node side also has at least one built-in encryption algorithm. This encryption algorithm can encrypt the data packet to be transmitted on the user plane to form a ciphertext, and form a data packet header for the data packet to be transmitted. Finally, the encrypted ciphertext and the data packet header are sent to the T node together.
[0292] When the G node receives the ciphertext data sent from the T node side, the G node first sends the received ciphertext data to the encryption card for decryption processing. After the decryption operation is completed, the decrypted data is returned to the G node.
[0293] Among them, when the encryption card on the G node side encrypts the data packet to be transmitted, the encryption card replaces the data packet with a key negotiation signaling to perform key negotiation. At the same time, when the G node receives the ciphertext data, the encryption card on the G node side performs the corresponding signaling packet decryption operation and then returns the decrypted data to the G node.
[0294] In a possible implementation manner, after establishing a secure communication connection between the terminal node and the management node using the key negotiation algorithm in the encryption card, user plane data is transmitted between the encryption card and the management node.
[0295] Correspondingly, when a secure communication connection is established between the T node and the G node using the key negotiation algorithm in the encryption card, the T node then transmits user plane data between the encryption card and the G node. Among them, the processing that the encryption card can perform on the user plane data to be transmitted includes:
[0296] For example, in addition to at least one built-in key negotiation algorithm, the encryption card on the T node side also has at least one built-in encryption algorithm. This encryption algorithm can encrypt the data packet to be transmitted on the user plane to form a ciphertext, and form a data packet header for the data packet to be transmitted. Finally, the encrypted ciphertext and the data packet header are sent to the G node together.
[0297] After the T node receives the ciphertext data sent from the G node side, the T node first sends the received ciphertext data to the encryption card for decryption processing. After the decryption operation is completed, the decrypted data is returned to the T node.
[0298] Among them, when the encryption card on the T node side encrypts the data packet to be transmitted, the encryption card replaces the data packet with a key negotiation signaling for key negotiation. At the same time, when the T node receives the ciphertext data, the encryption card on the T node side performs the corresponding signaling packet decryption operation and then returns the decrypted data to the T node.
[0299] The data transmission method provided in this application mainly describes how to implement the transmission of user plane data after a secure communication connection is established between the G node and the T node using the key negotiation algorithm in the encryption card. After the secure context negotiation and association between the G node and the T node are completed, the G node and the T node save the negotiated secure context. Before transmitting the user plane data, the G node and the T node send the user plane data packets to be transmitted to the encryption card for a series of encryption operation processes respectively, so as to ensure the security of data transmission. On this basis, the G node and the T node send the encrypted ciphertext together with the data packet header to each other, and at the same time send the received ciphertext data to the encryption card for decryption, so as to ensure the security and accuracy of the user plane data transmission process and improve the user experience.
[0300] Figure 11 It is a schematic flow diagram of the method for establishing a secure communication connection provided in this application. As Figure 11 shown, the schematic flow diagram of the method for establishing a secure communication connection includes a G node and a T node without a secure context. In the actual application process, it may include multiple G nodes and multiple T nodes. Here, taking the establishment of a secure communication connection between one G node and one T node as an example, the specific process of establishing a secure communication connection may include:
[0301] S1101: Encryption card algorithm capabilities;
[0302] Among them, an encryption card device is built in on the G node side, and at least one key negotiation algorithm is pre-set in the encryption card. When the user chooses to implement a secure communication connection between the G node and the T node in the form of an encryption card, the G node reads at least one key negotiation algorithm built in the encryption card.
[0303] S1102: Broadcast key negotiation algorithm capabilities;
[0304] Among them, based on step S1101, after the G node reads at least one key negotiation algorithm built in the encryption card, it broadcasts the key negotiation algorithm capabilities to the T node.
[0305] S1103: Key negotiation;
[0306] Among them, when the T node detects and receives the broadcast message from the G node, the T node performs a key negotiation operation based on the key negotiation algorithm built into the encryption card.
[0307] S1104: Association request message;
[0308] Among them, based on step S1103, after the T node completes the key negotiation operation in combination with the encryption card, the T node sends an association request message to the G node.
[0309] S1105: Key request;
[0310] Among them, after the G node receives the association request message sent by the T node, the G node sends a key request to the encryption card.
[0311] S1106: Configure key information;
[0312] Among them, based on the key request, the G node completes the configuration operation of the key information in combination with the encryption card.
[0313] S1107: Secure context request message;
[0314] Among them, after the G node completes the configuration operation of the key information in combination with the encryption card, the G node sends a secure context request message to the T node.
[0315] S1108: Key request;
[0316] Among them, when the T node receives the secure context request message sent by the G node, the T node sends a key request to the encryption card.
[0317] S1109: Key response;
[0318] Among them, based on the encryption card receiving the key request, the T node completes the key response operation in combination with the encryption card.
[0319] S1110: Secure context response message;
[0320] Among them, after the T node completes the key response operation in combination with the encryption card, the T node sends a secure context response message to the G node.
[0321] S1111: Association establishment message;
[0322] Among them, after the G node receives the secure context response message sent by the T node, the G node returns an association establishment message to the T node.
[0323] S1112: Association completion message.
[0324] Among them, the G node receives the association completion message returned by the T node.
[0325] Based on any of the above embodiments, in a possible implementation, if multiple T nodes send association request messages to the G node at the same time, the G node needs to determine whether there is pre-configured group identification information corresponding to the fixed identification information of the T node in the G node according to the T node identification information. If there is group identification information, the G node then determines whether there is a group key GK and a group algorithm Galgorithm in the group where the T node is located.
[0326] When there is no group key GK in the group where the T node is located, the G node generates a random number RAND, and generates the group key GK according to the random number RAND and the group identification information. The calculation method of the group key GK is as follows:
[0327] GK = KDF(RAND, group ID)
[0328] Where KDF is the key derivation function with the highest priority supported by the G node, and group ID represents the group identification information. Based on the group key GK, the G node generates an identifier GK ID of the group key GK.
[0329] The G node initializes COUNTERg to 0. When the encryption protection of the unicast signaling plane is not enabled, the G node calculates the key Kg for protecting the confidentiality of the group key GK according to the shared key Kgt and COUNTERg using the selected key derivation function. The calculation method of the key Kg for protecting the confidentiality of the group key GK is as follows:
[0330] Kg = KDF(Kgt, COUNTERg, "group key")
[0331] Where KDF represents the key derivation function selected by the G node, Kgt represents the shared key, and group key represents the group key.
[0332] Then, the G node performs an exclusive OR operation on GK and Kg to obtain GKc. The specific calculation method of GKc is as follows:
[0333] GKc = GK ⊕ Kg
[0334] When the group algorithm has not been determined for the group where the T node is located, the G node selects the group algorithm according to the pre-configured algorithm preference strategy among the algorithms supported by all T nodes in the group. Among them, the group algorithm includes the key derivation function with the highest priority, the encryption algorithm and integrity protection algorithm of the signaling plane, the encryption algorithm and integrity protection algorithm of the user plane, or the authenticated encryption algorithm of the user plane.
[0335] The G node further derives the security keys of the multicast signaling plane from the group key GK according to the selected key derivation function, that is, the encryption key and integrity protection key of the signaling plane, the security keys of the multicast user plane, that is, the encryption key and integrity protection key of the user plane, or the authenticated encryption key of the user plane.
[0336] When the subsequent G node sends an association establishment message to the T node, the association establishment message carries temporary identification information, namely T-ID, the validity period of Kgt, GKc or GK, the identifier GK ID of the group key GK, the group algorithm Galgorithm, and the validity period of the group key GK, namely GK expiration. Among them, GKc is carried when the encryption protection of the unicast signaling plane is not enabled, and GK is carried when the encryption protection of the unicast signaling plane is enabled.
[0337] When the T node receives the association establishment message sent by the G node, when the encryption protection of the unicast signaling plane is not enabled, the T node calculates Kg based on Kgt, and the calculation method of Kg is as follows:
[0338] Kg = KDF(Kgt, COUNTERg, "group key")
[0339] Among them, Kgt represents the master key, and COUNTERg is initialized to 0. The T node performs an exclusive OR operation on GKc and Kg to obtain, that is, GK = GKc ⊕ Kg.
[0340] After the security context negotiation and association are completed, the G node and multiple T nodes save the negotiated security context. Among them, the security context includes fixed identification information, temporary identification information, the master key Kgt, the validity period of the master key Kgt, the master key identifier Kgt ID, the target key negotiation algorithm, the encryption algorithm and integrity protection algorithm of the signaling plane, the encryption key and integrity protection key of the signaling plane, the encryption algorithm and integrity protection algorithm of the user plane or the authentication encryption algorithm of the user plane, the encryption key and integrity protection key of the user plane or the authentication encryption key of the user plane, the key derivation counter counter and COUNTERg, a part of the freshness parameter in the password algorithm input during unicast GFN, the group key GK, the group key identifier GK ID, the group algorithm Galgorithm, the validity period of the group key GK expiration, and a part of the freshness parameter in the password algorithm input during multicast GGFN.
[0341] Figure 12 It is a schematic structural diagram of the first embodiment of the security communication connection establishment device provided by the present application. As Figure 12 shown, an encryption card is provided in the security communication connection establishment device 1200, and at least one key negotiation algorithm different from the key negotiation algorithm of the security communication connection establishment device 1200 itself is configured in the encryption card. The security communication connection establishment device 1200 includes:
[0342] A sending module 1201, configured to broadcast a communication message, where the communication message includes identification information of a security communication connection establishment device and at least one key negotiation algorithm built in an encryption card;
[0343] A receiving module 1202, configured to receive an association request message sent by a terminal node, where the association request message carries the identification of the terminal node, a target key negotiation algorithm, first key negotiation parameters, a first random number, and the security capability of the terminal node;
[0344] A processing module 1203, configured to, if the at least one key negotiation algorithm includes the target key negotiation algorithm, send a security context request message to the terminal node according to a preset algorithm selection strategy, service type, first key negotiation parameters, the first random number, and the security capability of the terminal node. The security context request message carries second key negotiation parameters, a second random number, an identifier of a master key, a target algorithm, a message integrity code length, and a first authentication parameter. The target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm;
[0345] The receiving module 1202 is further configured to receive a security context response message sent by the terminal node, where the security context response message includes a second authentication parameter;
[0346] The sending module 1201 is further configured to, after both the integrity check and parameter check of the security context response message pass, send a connection establishment message to the terminal node. The connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key;
[0347] The receiving module 1202 is further configured to receive a connection establishment completion message sent by the terminal node.
[0348] Optionally, the processing module 1203 is further configured to:
[0349] Select the target algorithm with the highest priority from the capability algorithms locally stored in the management node according to the security capability of the terminal node, the algorithm selection strategy, and the service type;
[0350] Generate a public key as the second key negotiation parameter according to the generated private key and the target key negotiation algorithm;
[0351] Generate a second random number using a random number generator;
[0352] Calculate a shared key according to the first key negotiation parameters and the target key negotiation algorithm;
[0353] Calculate a master key according to the shared key, the second random number, and the first random number using a key derivation function, and generate an identifier of the master key;
[0354] Derive the security key for the signaling plane and the security key for the user plane from the master key using a key derivation function;
[0355] Calculate the first authentication parameter based on the association request message, the second random number, the shared key, and the pre-provisioned shared key.
[0356] Optionally, the sending module 1201 is further configured to:
[0357] Carry the second key negotiation parameter, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter in the security context request message and send it to the terminal node.
[0358] Optionally, the signaling plane algorithms include: the encryption algorithm and the integrity protection algorithm for the signaling plane;
[0359] The user plane algorithms include: the encryption algorithm and the integrity protection algorithm for the user plane, or, the authentication encryption algorithm for the user plane.
[0360] Optionally, the processing module 1203 is further configured to:
[0361] Determine whether the number of terminal nodes currently connected to the management node is less than a preset number threshold;
[0362] If the number of terminal nodes currently connected to the management node is less than the number threshold, determine whether at least one key negotiation algorithm includes the target key negotiation algorithm;
[0363] If the number of terminal nodes currently connected to the management node is greater than or equal to the number threshold, discard the association request message.
[0364] Optionally, the processing module 1203 is further configured to:
[0365] In response to the data transmission mode selected by the user to be through the encryption card, read at least one key negotiation algorithm supported by the encryption card from the encryption card.
[0366] The security communication connection establishment device provided by the embodiments of the present application can be used to execute the security communication connection establishment method in the above-mentioned embodiments, and its implementation principle and technical effects are similar, which will not be elaborated here.
[0367] Figure 13 This is the structural schematic diagram of the second embodiment of the security communication connection establishment device provided by the present application. As Figure 13 shown, an encryption card is provided in the security communication connection establishment device 1300, and at least one key negotiation algorithm different from the key negotiation algorithm of the security communication connection establishment device 1300 itself is configured in the encryption card. The security communication connection establishment device 1300 includes:
[0368] A receiving module 1301, configured to detect communication messages broadcast by a receiving management node, where the communication messages include identification information of the management node and at least one key negotiation algorithm;
[0369] A processing module 1302, configured to select a target key negotiation algorithm from an encryption card according to the communication message;
[0370] A sending module 1303, configured to send an association request message to the management node, where the association request message carries the identification of the terminal node, the target key negotiation algorithm, first key negotiation parameters generated according to the target key negotiation algorithm, the security capabilities of the terminal node, and a first random number;
[0371] The receiving module 1301 is further configured to receive a security context request message sent by the management node, where the security context request message carries second key negotiation parameters, a second random number, an identifier of the master key, and a target algorithm, and the target algorithm includes a key derivation function, a signaling plane algorithm, a user plane algorithm, a message integrity code length, and a first authentication parameter;
[0372] The sending module 1303 is further configured to send a security context response message to the management node after both the integrity check and the parameter check of the security context request message pass, where the security context response message carries a second authentication parameter;
[0373] The receiving module 1301 is further configured to receive a connection establishment message sent by the management node, where the connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key;
[0374] The sending module 1303 is further configured to return a connection establishment completion message to the management node after the integrity verification of the connection establishment message passes.
[0375] Optionally, the processing module 1302 is further configured to:
[0376] Generate a corresponding public key as the first key negotiation parameter according to the generated private key and the target key negotiation algorithm;
[0377] Generate a first random number using a random number generator.
[0378] Optionally, the processing module 1302 is further configured to:
[0379] Calculate a shared key according to the second key negotiation parameters and the target key negotiation algorithm;
[0380] Calculate the master key using the key derivation function according to the shared key, the second random number, and the first random number;
[0381] Deduce the security keys for the signaling plane and the user plane using the key derivation function according to the master key.
[0382] Optionally, the processing module 1302 is further configured to:
[0383] Verify the integrity of the security context request message according to the message integrity code length in the security context request message;
[0384] After the integrity verification of the security context request message passes, calculate a second authentication parameter according to the first random number, the shared key, and the pre-provisioned shared key;
[0385] Verify the first authentication parameter in the security context request message according to the second authentication parameter.
[0386] The security communication connection establishment device provided by the embodiments of the present application can be used to execute the security communication connection establishment method in the above-described embodiments. The implementation principles and technical effects are similar and will not be elaborated here.
[0387] Figure 14 FIG. 18 is a schematic structural diagram of Embodiment 1 of the data transmission device provided by the present application. As Figure 14 shown, an encryption card is provided in the data transmission device 1400, and at least one key negotiation algorithm different from the key negotiation algorithm of the data transmission device 1400 itself is configured in the encryption card. The data transmission device 1400 includes:
[0388] A transmission module 1401, configured to perform user plane data transmission with the terminal node through the encryption card after establishing a secure communication connection between the data transmission device and the terminal node using the key negotiation algorithm in the encryption card.
[0389] The data transmission device provided by the embodiments of the present application can be used to execute the data transmission method in the above-described embodiments. The implementation principles and technical effects are similar and will not be elaborated here.
[0390] Figure 15 FIG. 30 is a schematic structural diagram of Embodiment 2 of the data transmission device provided by the present application. As Figure 15 shown, an encryption card is provided in the data transmission device 1500, and at least one key negotiation algorithm different from the key negotiation algorithm of the data transmission device 1500 itself is configured in the encryption card. The data transmission device 1400 includes:
[0391] A transmission module 1501, configured to perform user plane data transmission with the management node through the encryption card after establishing a secure communication connection between the data transmission device and the management node using the key negotiation algorithm in the encryption card.
[0392] The data transmission device provided by the embodiments of the present application can be used to execute the data transmission method in the above-described embodiments. The implementation principles and technical effects are similar and will not be elaborated here.
[0393] Figure 16 A schematic structural diagram of a management node device provided for this application. As Figure 16 shown, the management node device may specifically include a transceiver 1600, a processor 1601, a memory 1602, and an encryption card 1603. Among them, the transceiver 1600 is used to implement data transmission between the management node device and the terminal node device, and the memory 1601 stores computer execution instructions; the processor 1601 executes the computer execution instructions stored in the memory 1602 to implement the method for establishing a secure communication connection and the data transmission method in the above embodiments. The encryption card 1603 stores at least one key negotiation algorithm.
[0394] Figure 17 A schematic structural diagram of a terminal node device provided for this application. As Figure 17 shown, the management node device may specifically include a transceiver 1700, a processor 1701, a memory 1702, and an encryption card 1703. Among them, the transceiver 1700 is used to implement data transmission between the management node device and the terminal node device, and the memory 1701 stores computer execution instructions; the processor 1701 executes the computer execution instructions stored in the memory 1702 to implement the method for establishing a secure communication connection or the data transmission method in the above embodiments. The encryption card 1703 stores at least one key negotiation algorithm.
[0395] This embodiment provides a computer-readable storage medium. Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, they are used to implement the method for establishing a secure communication connection or the data transmission method in the above embodiments.
[0396] The embodiment of this application further provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the method for establishing a secure communication connection or the data transmission method provided in any one of the above embodiments.
[0397] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily think of other implementation schemes of this application. This application aims to cover any variations, uses, or adaptive changes of this application. These variations, uses, or adaptive changes follow the general principles of this application and include the common general knowledge or conventional technical means in the technical field not disclosed in this application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of this application are pointed out by the following claims.
[0398] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A method for establishing a secure communication connection, characterized in that, Applied to a management node, where an encryption card is provided in the management node, and at least one key negotiation algorithm different from the key negotiation algorithm of the management node itself is configured in the encryption card. The method includes: Broadcasting a communication message, where the communication message includes the identification information of the management node and the at least one key negotiation algorithm built in the encryption card; Receiving an association request message sent by a terminal node, where the association request message carries the identification of the terminal node, a target key negotiation algorithm, first key negotiation parameters, a first random number, and the security capabilities of the terminal node; If the target key negotiation algorithm is included in the at least one key negotiation algorithm, then according to a preset algorithm selection strategy, service type, the first key negotiation parameters, the first random number, and the security capabilities of the terminal node, sending a security context request message to the terminal node, where the security context request message carries second key negotiation parameters, a second random number, an identifier of the master key, a target algorithm, the message integrity code length, and a first authentication parameter, and the target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm; Receiving a security context response message sent by the terminal node, where the security context response message includes a second authentication parameter; After both the integrity check and parameter check of the security context response message pass, sending a connection establishment message to the terminal node, where the connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key; Receiving a connection establishment completion message sent by the terminal node.
2. The method according to claim 1, characterized in that The step of sending a security context request message to the terminal node according to a preset algorithm selection strategy, service type, the first key negotiation parameters, the first random number, and the security capabilities of the terminal node includes: Selecting the highest-priority target algorithm from the capability algorithms locally stored in the management node according to the security capabilities of the terminal node, the algorithm selection strategy, and the service type; Generating a public key as the second key negotiation parameter according to the generated private key and the target key negotiation algorithm; Generating the second random number using a random number generator; Calculating a shared key according to the first key negotiation parameters and the target key negotiation algorithm; Calculating a master key according to the shared key, the second random number, and the first random number using the key derivation function, and generating an identifier of the master key; Deriving the security key of the signaling plane and the security key of the user plane from the master key using the key derivation function; Calculating the first authentication parameter according to the association request message, the second random number, the shared key, and a pre-provisioned shared key; Carrying the second key negotiation parameters, the second random number, the identifier of the master key, the target algorithm, the message integrity code length, and the first authentication parameter in the security context request message and sending it to the terminal node.
3. The method according to claim 1 or 2, characterized in that, The signaling plane algorithms include: the encryption algorithm and the integrity protection algorithm of the signaling plane; The user plane algorithms include: the encryption algorithm and the integrity protection algorithm of the user plane, or the authentication and encryption algorithm of the user plane.
4. The method according to claim 1 or 2, characterized in that, After receiving the association request message sent by the receiving terminal node, the method further includes: Determining whether the number of terminal nodes currently connected to the management node is less than a preset number threshold; If the number of terminal nodes currently connected to the management node is less than the number threshold, determining whether the target key negotiation algorithm is included in the at least one key negotiation algorithm; If the number of terminal nodes currently connected to the management node is greater than or equal to the number threshold, discarding the association request message.
5. The method according to claim 4, wherein Before broadcasting the communication message, the method further includes: In response to the data transmission mode selected by the user to be through the encryption card, reading the at least one key negotiation algorithm supported by the encryption card from the encryption card.
6. A method for establishing a secure communication connection, characterized in that, Applied to a terminal node, an encryption card is provided in the terminal node, and at least one key negotiation algorithm different from the key negotiation algorithm of the terminal node itself is configured in the encryption card. The method includes: Detecting a communication message broadcast by the receiving management node, where the communication message includes the identification information of the management node and at least one key negotiation algorithm; Selecting a target key negotiation algorithm from the encryption card according to the communication message; Sending an association request message to the management node, where the association request message carries the identification of the terminal node, the target key negotiation algorithm, the first key negotiation parameter generated according to the target key negotiation algorithm, the security capabilities of the terminal node, and the first random number; Receiving a security context request message sent by the management node, where the security context request message carries the second key negotiation parameter, the second random number, the identifier of the master key, and the target algorithm, and the target algorithm includes a key derivation function, a signaling plane algorithm, a user plane algorithm, a message integrity code, the message integrity code length, and the first authentication parameter; After both the integrity check and the parameter check of the security context request message pass, sending a security context response message to the management node, where the security context response message carries the second authentication parameter; Receiving a connection establishment message sent by the management node, where the connection establishment message includes the temporary identifier generated by the management node for the terminal node and the validity period of the master key; After the integrity verification of the connection establishment message passes, returning a connection establishment completion message to the management node.
7. The method according to claim 6, characterized in that, Before sending the association request message to the management node, the method further includes: Generating a corresponding public key as the first key negotiation parameter according to the generated private key and the target key negotiation algorithm; Generating the first random number using a random number generator.
8. The method according to claim 6 or 7, characterized in that, Before sending the security context response message to the management node, the method further includes: Calculating a shared key according to the second key negotiation parameter and the target key negotiation algorithm; Based on the shared key, the second random number, and the first random number, use the key derivation function to calculate the master key; Based on the master key, use the key derivation function to derive the security key for the signaling plane and the security key for the user plane.
9. The method according to claim 8, wherein The method further includes: According to the message integrity code length in the security context request message, verify the integrity of the security context request message; After the integrity verification of the security context request message passes, calculate the second authentication parameter according to the first random number, the shared key, and the pre-provisioned shared key; Verify the first authentication parameter in the security context request message according to the second authentication parameter.
10. A data transmission method, characterized in that, Applied to a management node, an encryption card is provided in the management node, and at least one key negotiation algorithm different from the key negotiation algorithm of the management node itself is configured in the encryption card. The method includes: After establishing a secure communication connection between the management node and the terminal node using the key negotiation algorithm in the encryption card, perform user plane data transmission with the terminal node through the encryption card.
11. A data transmission method, characterized in that, Applied to a terminal node, an encryption card is provided in the terminal node, and at least one key negotiation algorithm different from the key negotiation algorithm of the terminal node itself is configured in the encryption card. The method includes: After establishing a secure communication connection between the terminal node and the management node using the key negotiation algorithm in the encryption card, perform user plane data transmission with the management node through the encryption card.
12. An apparatus for establishing a secure communication connection, characterized in that, An encryption card is provided in the establishment device of the secure communication connection, and at least one key negotiation algorithm different from the key negotiation algorithm of the establishment device of the secure communication connection itself is configured in the encryption card. The establishment device of the secure communication connection includes: A sending module, configured to broadcast a communication message, where the communication message includes the identification information of the establishment device of the secure communication connection and the at least one key negotiation algorithm built in the encryption card; A receiving module, configured to receive an association request message sent by a terminal node, where the association request message carries the identification of the terminal node, a target key negotiation algorithm, a first key negotiation parameter, a first random number, and the security capabilities of the terminal node; A processing module, configured to, if the at least one key negotiation algorithm includes the target key negotiation algorithm, send a security context request message to the terminal node according to a preset algorithm selection policy, service type, the first key negotiation parameter, the first random number, and the security capabilities of the terminal node. The security context request message carries a second key negotiation parameter, a second random number, an identifier of the master key, a target algorithm, a message integrity code length, and a first authentication parameter. The target algorithm includes a key derivation function, a signaling plane algorithm, and a user plane algorithm; The receiving module is further configured to receive a security context response message sent by the terminal node, where the security context response message includes a second authentication parameter; The sending module is further configured to send a connection establishment message to the terminal node after both the integrity check and the parameter check of the security context response message pass. The connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key; The receiving module is further configured to receive a connection establishment completion message sent by the terminal node.
13. An apparatus for establishing a secure communication connection, characterized in that, An encryption card is provided in the security communication connection establishment device. At least one key negotiation algorithm different from the key negotiation algorithm of the security communication connection establishment device itself is configured in the encryption card. The security communication connection establishment device includes: A receiving module, configured to detect and receive a communication message broadcast by the management node. The communication message includes the identification information of the management node and at least one key negotiation algorithm; A processing module, configured to select a target key negotiation algorithm from the encryption card according to the communication message; A sending module, configured to send an association request message to the management node. The association request message carries the identification of the terminal node, the target key negotiation algorithm, a first key negotiation parameter generated according to the target key negotiation algorithm, the security capability of the terminal node, and a first random number; The receiving module is further configured to receive a security context request message sent by the management node. The security context request message carries a second key negotiation parameter, a second random number, an identifier of the master key, and a target algorithm. The target algorithm includes a key derivation function, a signaling plane algorithm, a user plane algorithm, a message integrity code length, and a first authentication parameter; The sending module is further configured to send a security context response message to the management node after both the integrity check and the parameter check of the security context request message pass. The security context response message carries a second authentication parameter; The receiving module is further configured to receive a connection establishment message sent by the management node. The connection establishment message includes a temporary identifier generated by the management node for the terminal node and the validity period of the master key; The sending module is further configured to return a connection establishment completion message to the management node after the integrity verification of the connection establishment message passes.
14. A data transmission device, characterized in that, An encryption card is provided in the data transmission device. At least one key negotiation algorithm different from the key negotiation algorithm of the data transmission device itself is configured in the encryption card. The data transmission device includes: A transmission module, configured to perform user plane data transmission with the terminal node through the encryption card after establishing a security communication connection between the data transmission device and the terminal node using the key negotiation algorithm in the encryption card.
15. A data transmission device, characterized in that, An encryption card is provided in the data transmission device. At least one key negotiation algorithm different from the key negotiation algorithm of the data transmission device itself is configured in the encryption card. The data transmission device includes: A transmission module, configured to perform user plane data transmission with the management node through the encryption card after establishing a security communication connection between the data transmission device and the management node using the key negotiation algorithm in the encryption card.
16. A management node device, characterized in that, including: A transceiver, a processor, a memory, and an encryption card; Wherein, computer-executable instructions are stored in the memory; The processor is configured to execute the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 5, or claim 10.
17. A terminal node device, characterized in that, Comprising: A transceiver, a processor, a memory, and an encryption card; Wherein, computer-executable instructions are stored in the memory; The processor is configured to execute the computer-executable instructions stored in the memory to implement the method according to any one of claims 6 to 9, or claim 11.
18. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 1 to 11.
Citation Information
Cited By
Terminal access method and system based on star flash protocol
CN120456028A
A terminal access method and system based on Star Flash protocol
CN120456028B