Bluetooth connection authentication method and system
Through the key negotiation process based on the national secret algorithm, the complexity and security issues in the Bluetooth connection authentication process are solved, and fast and secure identity authentication is achieved.
Patent Information
- Application Number
- CN202510658966.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-07-15
AI Technical Summary
The existing Bluetooth connection authentication process is complicated, resulting in long pairing time, prone to conflicts and failures, and cannot meet security needs in special scenarios.
The identity mutual recognition process based on the national secret algorithm is adopted, and through key negotiation between the terminal and the Bluetooth device, it directly connects and performs two-way identity authentication, avoiding the standard pairing process, and the authentication is completed in just two data exchanges.
It realizes the convenience, speed and security of Bluetooth connection, avoids complex standard pairing processes and conflicts, and ensures the rapid success of certification.
Smart Images

Figure CN120321619A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Bluetooth authentication, and particularly relates to a Bluetooth connection authentication method and system. Background Art
[0002] When a terminal device (hereinafter referred to as the terminal) communicates with a Bluetooth device via Bluetooth, identity authentication is usually required, that is: a device pairing code (PIN code) is preset on the Bluetooth device. When the terminal searches for and selects the Bluetooth device, the user only needs to input the PIN code of the Bluetooth device on the terminal, and the terminal and the Bluetooth device will interact to complete the pairing of the two devices, thereby achieving identity authentication. For the above "interaction process" between the terminal and the Bluetooth device, the traditional method is to use the standard pairing process defined by the Bluetooth specification, which can meet most Bluetooth communication requirements, but has the following disadvantages:
[0003] 1. Since the standard pairing process is relatively complex and there is a lot of interaction between the terminal and the Bluetooth device, the pairing time is relatively long;
[0004] 2. Since the pairing process is a standard process, when multiple connections are initiated simultaneously in the background by the system of the same terminal, or when multiple applications on the same terminal initiate connections simultaneously, some conflicts may occur, resulting in a certain probability of pairing failure. At this time, the user needs to repeatedly perform operations such as deleting configuration information, re-entering the pairing code, and waiting for the pairing result until the pairing is successful, which reduces the user experience;
[0005] 3. In some special occasions, or in scenarios where national cryptographic algorithms are required, the existing standard pairing mechanism may not meet the application requirements. Summary of the Invention
[0006] Therefore, the present invention provides a Bluetooth connection authentication method and system, aiming to solve the technical problem that it is difficult to ensure the convenience, speed, and security of Bluetooth authentication in the prior art.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] According to a first aspect of the present invention, the present invention provides a Bluetooth connection authentication method, the method comprising:
[0009] The terminal initiates a connection to a target Bluetooth device selected by the user, and the target Bluetooth device is directly communicatively connected to the terminal;
[0010] The terminal and the target Bluetooth device perform mutual identity authentication based on a national cryptographic algorithm; the mutual identity authentication includes a first identity authentication of the terminal for the target Bluetooth device and a second identity authentication of the target Bluetooth device for the terminal;
[0011] When both the first identity authentication and the second identity authentication are successful, the identity mutual recognition is successful and subsequent communication is executed;
[0012] When the first identity authentication and / or the second identity authentication fails, the identity mutual recognition is ended and subsequent communication is cut off.
[0013] Optionally, the terminal initiates a connection to a target Bluetooth device selected by the user, and the target Bluetooth device is directly communicatively connected to the terminal, including:
[0014] The terminal displays at least one searched Bluetooth device;
[0015] The user selects the target Bluetooth device and inputs the PIN code corresponding to the target Bluetooth device to initiate a connection to the target Bluetooth device;
[0016] The target Bluetooth device does not require standard Bluetooth pairing and is directly successfully connected to the terminal.
[0017] Optionally, the terminal and the target Bluetooth device perform identity mutual recognition based on the national cryptography algorithm, including:
[0018] The terminal generates a temporary first key pair; the first key pair includes a first private key and a first public key; the terminal sends the first public key to the Bluetooth chip in the target Bluetooth device;
[0019] The Bluetooth chip forwards the first public key to the national cryptography algorithm module in the target Bluetooth device;
[0020] After receiving the first public key, the national cryptography algorithm module generates a temporary second key pair; the second key pair includes a second private key and a second public key;
[0021] The national cryptography algorithm module calculates first authentication data based on the key information, and the target Bluetooth device sends the second public key and the first authentication data to the terminal;
[0022] The terminal decrypts the first authentication data using the key information and determines whether the first identity authentication of the terminal for the target Bluetooth device is successful according to the decryption result;
[0023] After the first identity authentication is successful, the terminal calculates second authentication data and sends the second authentication data to the target Bluetooth device;
[0024] The national cryptography algorithm module in the target Bluetooth device decrypts the second authentication data and determines whether the second identity authentication of the target Bluetooth device for the terminal is successful according to the decryption result;
[0025] The target Bluetooth device returns the authentication status to the terminal.
[0026] Optionally, the national cryptography algorithm module calculates first authentication data based on key information, including:
[0027] The national cryptography algorithm module uses the PIN code as the user ID and calculates a first hash value and a second hash value;
[0028] Based on the first hash value, the second hash value, the second private key, the first public key, and the second public key, a session key is calculated using the SM2 key agreement algorithm;
[0029] The first data block is encrypted using the session key with SM4 to obtain the first authentication data.
[0030] Optionally, the terminal decrypts the first authentication data using the key information and determines whether the first identity authentication of the terminal for the target Bluetooth device is successful, including:
[0031] The terminal calculates the first hash value and the second hash value using the PIN code input by the user;
[0032] Based on the first hash value, the second hash value, the first private key, the first public key, and the second public key, a session key is calculated using the SM2 key agreement algorithm;
[0033] The first authentication data is decrypted using the session key to obtain a first data block to be verified;
[0034] Determine whether the first data block to be verified is the same as the first data block;
[0035] If the first data block to be verified is the same as the first data block, the first identity authentication of the terminal for the target Bluetooth device is successful;
[0036] If the first data block to be verified is not the same as the first data block, the first identity authentication of the terminal for the target Bluetooth device fails.
[0037] Optionally, the terminal calculates second authentication data, including:
[0038] The terminal encrypts a second data block using the session key with SM4 to obtain the second authentication data.
[0039] Optionally, the national cryptography algorithm module in the target Bluetooth device decrypts the second authentication data and determines whether the second identity authentication of the target Bluetooth device for the terminal is successful, including:
[0040] The national cryptography algorithm module decrypts the second authentication data by using the session key to obtain a second data block to be verified;
[0041] Determine whether the second data block to be verified is the same as the second data block;
[0042] If the second data block to be verified is the same as the second data block, the second identity authentication of the target Bluetooth device for the terminal is successful;
[0043] If the first data block to be verified is not the same as the first data block, the second identity authentication of the target Bluetooth device for the terminal fails.
[0044] Optionally, when the identity mutual recognition is successful, subsequent communication is performed, including:
[0045] The subsequent communication encrypts / decrypts the transmission data between the terminal and the target Bluetooth device by using the session key.
[0046] Optionally, the method further includes:
[0047] When the number of consecutive failures of the first identity authentication and / or the second identity authentication exceeds a preset number of failure times, the target Bluetooth device enables a self-locking function.
[0048] According to a second aspect of the present invention, the present invention provides a Bluetooth connection authentication system, and the system includes a terminal and a target Bluetooth device;
[0049] The terminal is used to initiate a connection to a target Bluetooth device selected by a user;
[0050] The target Bluetooth device is used to directly communicate and connect with the terminal;
[0051] The terminal and the target Bluetooth device are further used to perform identity mutual recognition based on a national cryptography algorithm; the identity mutual recognition includes a first identity authentication of the terminal for the target Bluetooth device and a second identity authentication of the target Bluetooth device for the terminal;
[0052] When both the first identity authentication and the second identity authentication are successful, the identity mutual recognition is successful, and subsequent communication is performed;
[0053] When the first identity authentication and / or the second identity authentication fails, the identity mutual recognition is ended, and subsequent communication is cut off.
[0054] The present invention adopts the above technical solutions and at least has the following beneficial effects:
[0055] Through the solution of the present invention, the terminal initiates a connection to the target Bluetooth device selected by the user, and the target Bluetooth device is directly communicatively connected to the terminal; the terminal and the target Bluetooth device perform mutual identity authentication based on the national cryptographic algorithm; the mutual identity authentication includes the first identity authentication of the terminal for the target Bluetooth device and the second identity authentication of the target Bluetooth device for the terminal; when both the first identity authentication and the second identity authentication are successful, the mutual identity authentication is successful and subsequent communication is performed; when the first identity authentication and / or the second identity authentication fails, the mutual identity authentication is ended and subsequent communication is cut off. Thus, the standard Bluetooth pairing process is no longer used, and key negotiation is performed based on the national cryptographic algorithm. The terminal and the Bluetooth device can complete the identity authentication process only through two data exchanges, ensuring the convenience, speed, and security of the Bluetooth connection.
[0056] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. Brief Description of the Drawings
[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0058] Figure 1 The flowchart of the Bluetooth connection authentication method provided by an embodiment of the present invention is shown;
[0059] Figure 2 The brief schematic diagram of the Bluetooth connection authentication system provided by an embodiment of the present invention is shown;
[0060] Figure 3 The brief schematic diagram of the Bluetooth connection authentication system provided by another embodiment of the present invention is shown. Detailed Embodiments
[0061] The following will describe the exemplary embodiments of the present disclosure in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0062] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0063] An embodiment of the present invention provides a Bluetooth connection authentication method, as Figure 1 shown, which may at least include the following steps S101 to S103:
[0064] Step S101, the terminal initiates a connection to a target Bluetooth device selected by the user, and the target Bluetooth device directly communicates with the terminal.
[0065] In an embodiment of the present invention, the target Bluetooth device is pre-set with a PIN code (device pairing code). When the terminal needs to connect to the target Bluetooth device, it searches for Bluetooth devices and displays them to the user; the user selects the target Bluetooth device to communicate with and inputs the PIN code corresponding to the target Bluetooth device to initiate a connection to the target Bluetooth device; the target Bluetooth device does not require standard Bluetooth pairing and directly connects successfully to the terminal, enters the communication state, and starts the subsequent identity authentication process.
[0066] It should be noted that the identity authentication in the embodiment of the present invention is based on the premise that both the target Bluetooth device and the terminal hold the same PIN code, and the PIN code will not be leaked during the identity authentication process, ensuring the security of the Bluetooth connection.
[0067] Step S102, the terminal and the target Bluetooth device perform mutual identity recognition based on the national cryptography algorithm.
[0068] The mutual identity recognition process in the embodiment of the present invention includes a first identity authentication of the terminal for the target Bluetooth device and a second identity authentication of the target Bluetooth device for the terminal.
[0069] Specifically, the mutual identity recognition process may at least include the following steps S102-1 to S102-8:
[0070] Step S102-1, the terminal generates a temporary first key pair; the terminal sends the first public key to the Bluetooth chip in the target Bluetooth device.
[0071] The terminal can use the SM2 algorithm (elliptic curve public key cryptography algorithm) to generate a temporary first key pair. Among them, the first key pair includes a first private key dA and a first public key PA.
[0072] Step S102-2: The Bluetooth chip forwards the first public key PA to the national cryptography algorithm module in the target Bluetooth device. The national cryptography algorithm module, as a functional module in the target Bluetooth device, can be implemented by means of hardware, software, or a combination of both.
[0073] Step S102-3: After receiving the first public key PA, the national cryptography algorithm module generates a temporary second key pair. The second key pair includes a second private key dB and a second public key PB.
[0074] Step S102-4: The national cryptography algorithm module calculates the first authentication data based on the key information, and the target Bluetooth device sends the second public key and the first authentication data to the terminal.
[0075] Specifically, the national cryptography algorithm module uses the PIN code as the user ID to calculate the first hash value ZA and the second hash value ZB. Using the first hash value ZA, the second hash value ZB, the second private key dB, the first public key PA, and the second public key PB as parameters, it calculates the session key SK using the SM2 key agreement algorithm. It uses the session key SK to perform SM4 encryption on the first data block to obtain the first authentication data AuthData1. Furthermore, the target Bluetooth device sends the second public key PB generated by its own national cryptography algorithm module and the first authentication data AuthData1 to the terminal.
[0076] Taking the first data block 0180000000000000000000000000000 as an example, the first authentication data can be expressed as AuthData1 = SM4_ENC(SK, 0180000000000000000000000000000).
[0077] It should be noted that since different key pairs are used in each calculation, which is random, the elliptic curve point RA used in the calculation process of the embodiments of the present invention can be directly replaced by the first public key PA without separate calculation.
[0078] Step S102-5: The terminal decrypts the first authentication data using the key information and determines whether the first identity authentication of the terminal for the target Bluetooth device is successful according to the decryption result.
[0079] Specifically, the terminal uses the PIN code input by the user to obtain the first hash value ZA and the second hash value ZB. Based on the first hash value ZA, the second hash value ZB, the first private key dA, the first public key PA, and the second public key PB as parameters, it calculates the session key SK using the SM2 key agreement algorithm.
[0080] It should be noted that since different key pairs are used in each calculation and there is randomness, the elliptic curve point RB used in the calculation process of the embodiments of the present invention can be directly replaced by the second public key PB without separate calculation.
[0081] Further, the session key SK is used to decrypt the first authentication data AuthData1 to obtain the first data block to be verified; it is judged whether the first data block to be verified is the same as the first data block; if the first data block to be verified is the same as the first data block, the first identity authentication of the terminal for the target Bluetooth device is successful; if the first data block to be verified is different from the first data block, the first identity authentication of the terminal for the target Bluetooth device fails.
[0082] Taking the first data block 0180000000000000000000000000000 as an example, if the decrypted first data block to be verified is 0180000000000000000000000000000, it is considered that the first identity authentication of the terminal for the target Bluetooth device is successful, otherwise the authentication fails.
[0083] Step S102-6, after the first identity authentication is successful, the terminal calculates the second authentication data and sends the second authentication data to the target Bluetooth device.
[0084] The terminal uses the session key SK to perform SM4 encryption on the second data block to obtain the second authentication data AuthData2. Furthermore, the terminal sends the second authentication data AuthData2 to the national cryptography algorithm module of the target Bluetooth device.
[0085] Taking the second data block 0280000000000000000000000000000 as an example, the second authentication data can be expressed as AuthData2 = SM4_ENC(SK, 0280000000000000000000000000000).
[0086] Step S102-7, the national cryptography algorithm module in the target Bluetooth device decrypts the second authentication data and judges whether the second identity authentication of the target Bluetooth device for the terminal is successful according to the decryption result.
[0087] The national cryptography algorithm module uses the session key SK to decrypt the second authentication data AuthData2 to obtain the second data block to be verified; it is judged whether the second data block to be verified is the same as the second data block; if the second data block to be verified is the same as the second data block, the second identity authentication of the target Bluetooth device for the terminal is successful; if the first data block to be verified is different from the first data block, the second identity authentication of the target Bluetooth device for the terminal fails.
[0088] Taking the second data block 0280000000000000000000000000000 as an example, if the decrypted second data block to be verified is 0280000000000000000000000000000, it is considered that the second identity authentication of the target Bluetooth device for the terminal is successful; otherwise, the authentication fails.
[0089] Step S102-8, the target Bluetooth device returns the authentication status to the terminal.
[0090] The target Bluetooth device returns the authentication status (authentication successful or authentication failed) to the terminal. After successful authentication, the subsequent communication uses the session key SK to encrypt / decrypt the transmission data between the terminal and the target Bluetooth device.
[0091] Step S103, when both the first identity authentication and the second identity authentication are successful, the identity mutual recognition is successful, and the subsequent communication is executed; when the first identity authentication and / or the second identity authentication fails, the identity mutual recognition is ended, and the subsequent communication is cut off.
[0092] Furthermore, when the number of consecutive failures of the first identity authentication and / or the second identity authentication exceeds the preset number of failure times, the target Bluetooth device enables the self-locking function.
[0093] That is to say, in the above identity mutual recognition process, if the identity authentication of any party fails, the identity mutual recognition process ends; if the number of consecutive identity authentication failures reaches the preset number of failure times (for example, 3 times), the target Bluetooth device self-locks and no longer accepts the identity authentication to prevent brute-force cracking attacks.
[0094] It should be noted that in practical applications, the preset number of failure times can be set according to actual needs, and the present invention does not limit this.
[0095] The embodiment of the present invention provides a Bluetooth connection authentication method, which no longer uses the standard Bluetooth pairing process and executes the key negotiation process based on the national cryptographic algorithm; the terminal and the Bluetooth device complete the identity authentication process only through two data exchanges, and the authentication process is relatively simple; no PIN code is transmitted during the entire authentication process, and the terminal and the Bluetooth device each use their own PIN codes to participate in the authentication. If the PIN codes held by both parties are inconsistent, different session keys (SKs) will be calculated by both parties, and the identity authentication will fail; during the authentication process, both parties randomly generate different key pairs, the public key is transmitted to the other party, and the private key is not transmitted over the network, which ensures that the data exchanged between the two parties is different each time the authentication is performed, and the SK generated each time is also different, effectively preventing replay attacks; in this way, both the rapidity and the security of the identity authentication are ensured.
[0096] Furthermore, as Figure 1For the specific implementation, an embodiment of the present invention provides a Bluetooth connection authentication system. As Figure 2 shown, the system may include: a terminal 210 and a target Bluetooth device 220.
[0097] The terminal 210 can be used to initiate a connection to a target Bluetooth device selected by the user.
[0098] The target Bluetooth device 220 can be used to communicate directly with the terminal.
[0099] The terminal 210 and the target Bluetooth device 220 can also be used to perform mutual identity authentication based on the national cryptography algorithm. The mutual identity authentication includes the first identity authentication of the terminal 210 for the target Bluetooth device 220 and the second identity authentication of the target Bluetooth device 220 for the terminal 210. When both the first identity authentication and the second identity authentication are successful, the mutual identity authentication is successful and subsequent communication is performed. When the first identity authentication and / or the second identity authentication fails, the mutual identity authentication ends and subsequent communication is cut off.
[0100] Optionally, the terminal 210 can also display at least one searched Bluetooth device; receive the target Bluetooth device selected by the user, and initiate a connection to the target Bluetooth device 220 based on the PIN code corresponding to the target Bluetooth device input by the user.
[0101] The target Bluetooth device 220 can also be used to directly connect successfully to the terminal 210 without requiring standard Bluetooth pairing.
[0102] Optionally, as Figure 3 shown, a Bluetooth connection authentication system provided by another embodiment of the present invention. The target Bluetooth device 220 includes: a Bluetooth chip 221 and a national cryptography algorithm module 222.
[0103] The terminal 210 can also be used to generate a temporary first key pair. The first key pair includes a first private key and a first public key. The first public key is sent to the Bluetooth chip 221 in the target Bluetooth device 220.
[0104] The Bluetooth chip 221 can be used to forward the public key to the national cryptography algorithm module 222 in the target Bluetooth device 220.
[0105] The national cryptography algorithm module 222 can be used to generate a temporary second key pair after receiving the first public key. The second key pair includes a second private key and a second public key. Calculate the first authentication data based on the key information.
[0106] The target Bluetooth device 220 can also be used to send the second public key and the first authentication data to the terminal 210.
[0107] The terminal 210 can also be used to decrypt the first authentication data using the key information, and determine whether the first identity authentication of the terminal for the target Bluetooth device 220 is successful according to the decryption result; after the first identity authentication is successful, calculate the second authentication data and send the second authentication data to the target Bluetooth device 220;
[0108] The national cryptography algorithm module 222 can also be used to decrypt the second authentication data, and determine whether the second identity authentication of the target Bluetooth device 220 for the terminal 210 is successful according to the decryption result;
[0109] The target Bluetooth device 220 can also be used to return the authentication status to the terminal 210.
[0110] Optionally, the national cryptography algorithm module 222 can also be used to use the PIN code as the user ID, calculate the first hash value and the second hash value; based on the first hash value, the second hash value, the second private key, the first public key and the second public key, use the SM2 key agreement algorithm to calculate the session key; use the session key to perform SM4 encryption on the first data block to obtain the first authentication data.
[0111] Optionally, the terminal 210 can also be used to use the PIN code input by the user to calculate the first hash value and the second hash value; based on the first hash value, the second hash value, the first private key, the first public key and the second public key, use the SM2 key agreement algorithm to calculate the session key; use the session key to decrypt the first authentication data to obtain the first data block to be verified; determine whether the first data block to be verified is the same as the first data block; if the first data block to be verified is the same as the first data block, the first identity authentication of the terminal 210 for the target Bluetooth device 220 is successful; if the first data block to be verified is not the same as the first data block, the first identity authentication of the terminal 210 for the target Bluetooth device 220 fails.
[0112] Optionally, the terminal 210 can also be used to perform SM4 encryption on the second data block using the session key to obtain the second authentication data.
[0113] Optionally, the national cryptography algorithm module 222 can also be used to decrypt the second authentication data using the session key to obtain the second data block to be verified; determine whether the second data block to be verified is the same as the second data block; if the second data block to be verified is the same as the second data block, the second identity authentication of the target Bluetooth device 220 for the terminal 210 is successful; if the first data block to be verified is not the same as the first data block, the second identity authentication of the target Bluetooth device 220 for the terminal 210 fails.
[0114] Optionally, after the mutual identity authentication between the terminal 210 and the target Bluetooth device 220 is successful, the subsequent communication can use the session key to encrypt / decrypt the transmitted data.
[0115] Optionally, the target Bluetooth device 220 can also be used to enable a self-locking function when the number of consecutive failures of the first identity authentication and / or the second identity authentication exceeds a preset number of failures.
[0116] It should be noted that for other corresponding descriptions of the various functional modules involved in the Bluetooth connection authentication system provided by the embodiments of the present invention, reference can be made to Figure 1 the corresponding description of the method shown, which will not be elaborated here.
[0117] Those skilled in the art can clearly understand that the specific working processes of the above-described system, device, module, and unit can refer to the corresponding processes in the foregoing method embodiments. For the sake of brevity, they will not be described in detail here.
[0118] In addition, in each embodiment of the present invention, the functional units can be physically independent of each other, or two or more functional units can be integrated together, or all the functional units can be integrated in a processing unit. The above-mentioned integrated functional units can be implemented in the form of hardware, or in the form of software or firmware.
[0119] Those of ordinary skill in the art can understand that if the integrated functional unit is implemented in the form of software and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computing device (such as a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present invention when running the instructions. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, etc., which can store program codes.
[0120] Alternatively, all or part of the steps of implementing the foregoing method embodiments can be completed by hardware related to program instructions (such as a computing device such as a personal computer, a server, or a network device). The program instructions can be stored in a computer-readable storage medium. When the program instructions are executed by the processor of the computing device, the computing device executes all or part of the steps of the methods described in the embodiments of the present invention.
[0121] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that within the spirit and principle of the present invention, it is still possible to modify the technical solutions described in the foregoing embodiments, or to equivalently replace some or all of the technical features therein; and these modifications or replacements do not cause the corresponding technical solutions to deviate from the protection scope of the present invention.
Claims
1. A Bluetooth connection authentication method, characterized in that, The method includes: The terminal initiates a connection to a target Bluetooth device selected by the user, and the target Bluetooth device is directly communicatively connected to the terminal; The terminal and the target Bluetooth device perform mutual identity authentication based on national cryptography algorithms; the mutual identity authentication includes a first identity authentication of the terminal for the target Bluetooth device and a second identity authentication of the target Bluetooth device for the terminal; When both the first identity authentication and the second identity authentication are successful, the mutual identity authentication is successful, and subsequent communication is performed; When the first identity authentication and / or the second identity authentication fails, the mutual identity authentication is ended and subsequent communication is cut off.
2. The method according to claim 1, characterized in that, The terminal initiates a connection to a Bluetooth device selected by the user, and the target Bluetooth device is directly communicatively connected to the terminal, including: The terminal displays at least one searched Bluetooth device; The user selects the target Bluetooth device and inputs the PIN code corresponding to the target Bluetooth device to initiate a connection to the target Bluetooth device; The target Bluetooth device does not require standard Bluetooth pairing and is directly connected successfully to the terminal.
3. The method according to claim 1, wherein The terminal and the target Bluetooth device perform mutual identity authentication based on national cryptography algorithms, including: The terminal generates a temporary first key pair; the first key pair includes a first private key and a first public key; the terminal sends the first public key to the Bluetooth chip in the target Bluetooth device; The Bluetooth chip forwards the public key to the national cryptography algorithm module in the target Bluetooth device; After receiving the first public key, the national cryptography algorithm module generates a temporary second key pair; the second key pair includes a second private key and a second public key; The national cryptography algorithm module calculates first authentication data based on key information, and the target Bluetooth device sends the second public key and the first authentication data to the terminal; The terminal decrypts the first authentication data using the key information and determines whether the first identity authentication of the terminal for the target Bluetooth device is successful according to the decryption result; After the first identity authentication is successful, the terminal calculates second authentication data and sends the second authentication data to the target Bluetooth device; The national cryptography algorithm module in the target Bluetooth device decrypts the second authentication data and determines whether the second identity authentication of the target Bluetooth device for the terminal is successful according to the decryption result; The target Bluetooth device returns the authentication status to the terminal.
4. The method according to claim 3, wherein The national cryptography algorithm module calculates first authentication data based on key information, including: The national cryptography algorithm module uses the PIN code as the user ID and calculates a first hash value and a second hash value; Based on the first hash value, the second hash value, the second private key, the first public key, and the second public key, a session key is calculated using the SM2 key agreement algorithm; The first data block is encrypted using the session key with SM4 to obtain the first authentication data.
5. The method according to claim 4, characterized in that, The terminal decrypts the first authentication data using the key information and determines whether the first identity authentication of the terminal for the target Bluetooth device is successful according to the decryption result, including: The terminal calculates the first hash value and the second hash value by using the PIN code input by the user; Based on the first hash value, the second hash value, the first private key, the first public key, and the second public key, the session key is calculated by using the SM2 key agreement algorithm; The first authentication data is decrypted by using the session key to obtain a first data block to be verified; It is determined whether the first data block to be verified is the same as the first data block; If the first data block to be verified is the same as the first data block, the first identity authentication of the terminal for the target Bluetooth device is successful; If the first data block to be verified is different from the first data block, the first identity authentication of the terminal for the target Bluetooth device fails.
6. The method according to claim 5, characterized in that, The terminal calculates the second authentication data, including: The terminal performs SM4 encryption on the second data block by using the session key to obtain the second authentication data.
7. The method according to claim 6, wherein The national cryptography algorithm module in the target Bluetooth device decrypts the second authentication data, and determines whether the second identity authentication of the target Bluetooth device for the terminal is successful according to the decryption result, including: The national cryptography algorithm module decrypts the second authentication data by using the session key to obtain a second data block to be verified; It is determined whether the second data block to be verified is the same as the second data block; If the second data block to be verified is the same as the second data block, the second identity authentication of the target Bluetooth device for the terminal is successful; If the first data block to be verified is different from the first data block, the second identity authentication of the target Bluetooth device for the terminal fails.
8. The method according to claim 3, characterized in that When the mutual identity authentication is successful, subsequent communication is performed, including: The subsequent communication encrypts / decrypts the transmission data between the terminal and the target Bluetooth device by using the session key.
9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: When the number of consecutive failures of the first identity authentication and / or the second identity authentication exceeds a preset number of failure times, the target Bluetooth device enables the self-locking function.
10. A Bluetooth connection authentication system, characterized in that, The system includes a terminal and a target Bluetooth device; The terminal is used to initiate a connection to a target Bluetooth device selected by the user; The target Bluetooth device is used to directly communicate with the terminal; The terminal and the target Bluetooth device are further used to perform mutual identity authentication based on the national cryptography algorithm; the mutual identity authentication includes the first identity authentication of the terminal for the target Bluetooth device and the second identity authentication of the target Bluetooth device for the terminal; When both the first identity authentication and the second identity authentication are successful, the mutual identity authentication is successful, and subsequent communication is performed; When the first identity authentication and / or the second identity authentication fails, the mutual identity authentication is ended, and the subsequent communication is cut off.