Authentication method based on EAP, communication device and communication system
By storing multiple PSK sets in the communication device and negotiating the target PSK, the problem of insufficient flexibility in the EAP-GPSK authentication method is solved, and higher authentication flexibility is achieved.
Patent Information
- Application Number
- CN202410246941.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-04
- Publication Date
- 2025-09-05
AI Technical Summary
In the authentication method based on EAP-GPSK, both parties to the communication need to configure the same pre-shared key, resulting in low flexibility and difficulty in adapting to diverse authentication needs.
A collection of multiple PSKs is stored in the communication device in advance, and the target PSK is determined through negotiation, supporting the selection and use of multiple PSKs, improving the flexibility of the EAP authentication solution.
By storing multiple PSK collections, the flexibility of the EAP authentication solution is improved and adapted to diverse authentication needs.
Smart Images

Figure CN120602932A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an authentication method, communication equipment, and communication system based on the Extensible Authentication Protocol (EAP). Background Art
[0002] The Extensible Authentication Protocol (EAP) is an authentication framework protocol that operates between the data link layer and the network layer. It can be used to authenticate wireless network access or implement point-to-point authentication of communication devices. EAP supports multiple authentication methods, such as EAP-general pre-shared key (EAP-GPSK) and EAP-transport layer security (EAP-TLS). During EAP execution, the communicating parties negotiate and select an EAP authentication method, which is then used to complete authentication.
[0003] EAP-GPSK is currently the mainstream EAP authentication method. Currently, in EAP-GPSK-based authentication methods, both communicating parties must be configured with the same pre-shared key (PSK). They can only derive session keys based on this PSK to complete mutual identity authentication, which is relatively inflexible. Summary of the Invention
[0004] The present application provides an EAP-based authentication method, communication device, and communication system.
[0005] In a first aspect, an EAP-based authentication method is provided. A first communications device negotiates with the second communications device to determine a target PSK by sending an EAP request message to the second communications device and / or receiving an EAP response message from the second communications device. The first communications device pre-stores a PSK set, which includes multiple PSKs. The target PSK is one of the PSKs in the PSK set. The first communications device authenticates the second communications device based on the target PSK.
[0006] This application pre-stores a PSK set including multiple PSKs in a communication device. When the communication device needs to perform an EAP authentication process with other communication devices, the target PSK to be ultimately used in the PSK set is determined through negotiation. This application solution supports the selection and use of multiple PSKs, thereby improving the flexibility of the EAP authentication solution.
[0007] Optionally, the PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
[0008] In this implementation mode, the key pool number corresponding to each key pool can globally uniquely indicate the key pool, and the key identifier corresponding to each PSK can uniquely indicate the PSK in the key pool where the PSK is located. Therefore, the key pool number and key identifier can globally uniquely indicate a PSK.
[0009] Optionally, the key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and then sent to the first communication device. For a key pool generated by a key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generated the key pool.
[0010] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0011] Alternatively, different PSKs in the PSK set are identified by using different key identifiers.
[0012] In this implementation mode, a key identifier can be used to globally uniquely indicate a PSK.
[0013] In a first possible implementation manner of the first aspect above, the PSK set includes multiple key pools, and the first communications device negotiates with the second communications device to determine a target PSK by sending an EAP request message to the second communications device and / or receiving an EAP response message sent by the second communications device. The implementation process includes: the first communications device sending a first EAP request message to the second communications device, the first EAP request message including a key pool number list and a first identity of the first communications device, the key pool number list including multiple key pool numbers, and the multiple key pool numbers respectively indicating multiple key pools in the PSK set; the first communications device receiving a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key pool number and a second identity of the second communications device, the target key pool number being a key pool number in the key pool number list; the first communications device obtaining a target key pool indicated by the target key pool number from the PSK set, and selecting a PSK from the target key pool as the target PSK; and the first communications device sending a second EAP request message to the second communications device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0014] In this implementation mode, the communicating parties first negotiate a key pool, and then negotiate to determine the target PSK in the negotiated key pool.
[0015] In combination with the first possible implementation method of the above-mentioned first aspect, the first EAP response message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool. An implementation method in which the first communication device selects a PSK from the target key pool as the target PSK includes: the first communication device obtains multiple candidate PSKs indicated by the multiple key identifiers from the target key pool, and selects a PSK from the multiple candidate PSKs as the target PSK.
[0016] In conjunction with the first possible implementation of the first aspect above, the second EAP request message also includes a first message authentication code value. The first message authentication code value is calculated by the first communications device based on the first authentication information based on a session key, the session key being obtained based on the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. The first message authentication code value is used by the second communications device to authenticate the first communications device. The first communications device receives a second EAP response message corresponding to the second EAP request message sent by the second communications device, the second EAP response message including the second message authentication code value. An implementation method for the first communications device to authenticate the second communications device based on the target PSK includes the first communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0017] In a second possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine the target PSK by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device sends a first EAP request message to the second communication device, the first EAP request message including a target key pool number and a first identity of the first communication device, the target key pool number indicating a target key pool in the PSK set; the first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key identifier and a second identity of the second communication device, the target key identifier indicating a PSK in the target key pool; the first communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0018] In this implementation, the first communication device selects a key pool, and then the first communication device and the second communication device negotiate to determine a target PSK in the selected key pool.
[0019] In combination with the second possible implementation manner of the first aspect above, the first EAP request message also includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0020] In conjunction with the second possible implementation of the first aspect above, the first EAP response message also includes a first message authentication code value. The implementation method for the first communications device to authenticate the second communications device based on the target PSK includes: the first communications device verifying the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Furthermore, the first communications device sends a second EAP request message to the second communications device, where the second EAP request message includes a second message authentication code value, the second message authentication code value being calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value being used by the second communications device to authenticate the first communications device.
[0021] In a third possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine the target PSK by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device sends a first EAP request message to the second communication device, the first EAP request message including the first identity of the first communication device; the first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key pool number and the second identity of the second communication device, the target key pool number indicating a target key pool in the PSK set; the first communication device obtains a target key pool indicated by the target key pool number from the PSK set, and selects a PSK from the target key pool as the target PSK; the first communication device sends a second EAP request message to the second communication device, the second EAP request message including the target key identifier corresponding to the target PSK.
[0022] In this implementation, the second communication device selects a key pool, and then the first communication device and the second communication device negotiate to determine a target PSK in the selected key pool.
[0023] In combination with the third possible implementation method of the above-mentioned first aspect, the first EAP response message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool. An implementation method in which the first communication device selects a PSK from the target key pool as the target PSK includes: the first communication device obtains multiple candidate PSKs indicated by the multiple key identifiers from the target key pool, and selects a PSK from the multiple candidate PSKs as the target PSK.
[0024] In conjunction with the third possible implementation of the first aspect above, the second EAP request message also includes a first message authentication code value, the first message authentication code value being calculated by the first communications device based on the first authentication information using a session key, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a first identity identifier, and the first message authentication code value being used by the second communications device to authenticate the first communications device. The first communications device receives a second EAP response message corresponding to the second EAP request message sent by the second communications device, the second EAP response message including the second message authentication code value. An implementation method for the first communications device to authenticate the second communications device based on the target PSK includes the first communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0025] In a fourth possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine the target PSK in the PSK set by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device uses a key in the target key pool in the PSK set as the target PSK; the first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a target key pool number corresponding to the target key pool, a target key identifier corresponding to the target PSK, and a first identity identifier of the first communication device.
[0026] In this implementation mode, the key pool and the target PSK are directly selected by the first communication device.
[0027] In conjunction with the fourth possible implementation of the first aspect above, a first communications device receives a first EAP response message corresponding to a first EAP request message sent by a second communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device. An implementation method in which the first communications device authenticates the second communications device based on a target PSK includes: the first communications device verifies the first message authentication code value based on a session key and first authentication information, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier. Furthermore, the first communications device sends a second EAP request message to the second communications device, the second EAP request message including a second message authentication code value, the second message authentication code value being calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value being used by the second communications device to authenticate the first communications device.
[0028] In a fifth possible implementation of the first aspect, a process in which a first communications device negotiates with a second communications device to determine a target PSK in a PSK set by sending an EAP request message to the second communications device and / or receiving an EAP response message sent by the second communications device includes: the first communications device sending a first EAP request message to the second communications device, the first EAP request message including a first identity of the first communications device. The first communications device receives a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key pool number, a target key identifier, and a second identity of the second communications device, the target key pool number indicating a target key pool in the PSK set, and the target key identifier indicating a PSK in the target key pool. The first communications device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0029] In this implementation mode, the key pool and the target PSK are directly selected by the second communication device.
[0030] In conjunction with the fifth possible implementation of the first aspect above, the first EAP response message also includes a first message authentication code value, and the first communications device performs identity authentication on the second communications device based on the target PSK, including: the first communications device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Furthermore, the first communications device sends a second EAP request message to the second communications device, where the second EAP request message includes a second message authentication code value, the second message authentication code value being calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value being used by the second communications device to authenticate the first communications device.
[0031] In a sixth possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine a target PSK in a PSK set by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device sends a first EAP request message to the second communication device, the first EAP request message including a key identifier list and a first identity identifier of the first communication device, the key identifier list including multiple key identifiers, and the multiple key identifiers respectively indicating multiple PSKs in the PSK set; the first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key identifier and a second identity identifier of the second communication device, the target key identifier being a key identifier in the key identifier list; the first communication device uses the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0032] In this implementation, the first communication device provides a key identification list, and then the second communication device selects a target PSK according to the key identification list.
[0033] In conjunction with the sixth possible implementation of the first aspect above, the first EAP response message also includes a first message authentication code value, and the first communications device authenticates the second communications device based on the target PSK, including: the first communications device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a key identifier list, a target key identifier, and a second identity identifier. Furthermore, the first communications device sends a second EAP request message to the second communications device, the second EAP request message including a second message authentication code value, the second message authentication code value calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communications device to authenticate the first communications device.
[0034] In a seventh possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine a target PSK in the PSK set by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device sends a first EAP request message to the second communication device, the first EAP request message including a first identity of the first communication device; the first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a key identifier list and a second identity of the second communication device, the key identifier list including multiple key identifiers, the multiple key identifiers respectively indicating multiple PSKs in the PSK set; the first communication device selects a PSK from the multiple PSKs indicated by the key identifier list as the target PSK; the first communication device sends a second EAP request message to the second communication device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0035] In this implementation, the second communication device provides a key identification list, and then the first communication device selects a target PSK according to the key identification list.
[0036] In conjunction with the seventh possible implementation of the first aspect above, the second EAP request message also includes a first message authentication code value, the first message authentication code value being calculated by the first communications device based on the first authentication information based on a session key, the session key being obtained based on the target PSK, the first authentication information including a key identifier list, a target key identifier, and a first identity identifier, and the first message authentication code value being used by the second communications device to authenticate the first communications device. The first communications device receives a second EAP response message corresponding to the second EAP request message sent by the second communications device, the second EAP response message including the second message authentication code value. An implementation method for the first communications device to authenticate the second communications device based on the target PSK includes: the first communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0037] In an eighth possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine the target PSK in the PSK set by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device uses a key in the PSK set as the target PSK; the first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a target key identifier corresponding to the target PSK and a first identity identifier of the first communication device.
[0038] In this implementation mode, the first communication device directly selects the target PSK.
[0039] In conjunction with the eighth possible implementation of the first aspect above, a first communications device receives a first EAP response message corresponding to a first EAP request message sent by a second communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device. An implementation method in which the first communications device authenticates the second communications device based on a target PSK includes: the first communications device verifies the first message authentication code value based on a session key and first authentication information, the session key being obtained based on the target PSK, and the first authentication information including the target key identifier and the second identity identifier. Furthermore, the first communications device sends a second EAP request message to the second communications device, the second EAP request message including a second message authentication code value, the second message authentication code value being calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value being used by the second communications device to authenticate the first communications device.
[0040] In a ninth possible implementation manner of the first aspect above, the first communication device negotiates with the second communication device to determine a target PSK in a PSK set by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, including: the first communication device sends a first EAP request message to the second communication device, the first EAP request message including a first identity identifier of the first communication device; the first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key identifier and a second identity identifier of the second communication device, the target key identifier indicating a PSK in the PSK set; the first communication device uses the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0041] In this implementation mode, the target PSK is directly selected by the second communication device.
[0042] In conjunction with the ninth possible implementation of the first aspect above, the first EAP response message also includes a first message authentication code value, and the first communications device authenticates the second communications device based on the target PSK, including: the first communications device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a target key identifier and a second identity identifier. Furthermore, the first communications device sends a second EAP request message to the second communications device, the second EAP request message including a second message authentication code value, the second message authentication code value calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value used by the second communications device to authenticate the first communications device.
[0043] In a second aspect, an EAP-based authentication method is provided. A second communication device receives an EAP request message from a first communication device and / or sends an EAP response message to the first communication device, thereby negotiating with the first communication device to determine a target PSK. The second communication device pre-stores a PSK set, which includes multiple PSKs, and the target PSK is one of the PSKs in the PSK set. The second communication device authenticates the first communication device based on the target PSK.
[0044] This application pre-stores a PSK set including multiple PSKs in a communication device. When the communication device needs to perform an EAP authentication process with other communication devices, the target PSK to be ultimately used in the PSK set is determined through negotiation. This application solution supports the selection and use of multiple PSKs, thereby improving the flexibility of the EAP authentication solution.
[0045] Optionally, the PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
[0046] Optionally, the key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and sent to the second communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
[0047] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0048] Alternatively, different PSKs in the PSK set are identified by using different key identifiers.
[0049] In a first possible implementation manner of the second aspect above, the PSK set includes multiple key pools, and the second communication device negotiates with the first communication device to determine the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device. The implementation process includes: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message includes a key pool number list and a first identity of the first communication device, the key pool number list including multiple key pool numbers; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message includes a target key pool number and a second identity of the second communication device, the target key pool number is a key pool number in the key pool number list, and the target key pool number indicates a target key pool in the PSK set; the second communication device receives a second EAP request message sent by the first communication device, the second EAP request message includes a target key identifier, and the target key identifier indicates a PSK in the target key pool; and the second communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0050] In this implementation mode, the communicating parties first negotiate a key pool, and then negotiate to determine the target PSK in the negotiated key pool.
[0051] In combination with the first possible implementation manner of the second aspect above, the first EAP response message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0052] In conjunction with the first possible implementation of the second aspect, the second EAP request message further includes a first message authentication code value, and the second communications device authenticates the first communications device based on a target PSK, including: the second communications device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. Furthermore, the second communications device sends a second EAP response message corresponding to the second EAP request message to the first communications device, the second EAP response message including a second message authentication code value, the second message authentication code value calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0053] In a second possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine an implementation process of the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message includes a target key pool number and a first identity of the first communication device, and the target key pool number indicates a target key pool in the PSK set; the second communication device obtains a target key pool indicated by the target key pool number from the PSK set, and selects a PSK from the target key pool as a target PSK; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message includes a target key identifier corresponding to the target PSK and the second identity of the second communication device.
[0054] In this implementation, the first communication device selects a key pool, and then the first communication device and the second communication device negotiate to determine a target PSK in the selected key pool.
[0055] In combination with the second possible implementation manner of the above-mentioned second aspect, the first EAP request message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool. An implementation manner in which the second communication device selects a PSK from the target key pool as the target PSK includes: the second communication device obtains multiple candidate PSKs indicated by the multiple key identifiers from the target key pool, and selects a PSK from the multiple candidate PSKs as the target PSK.
[0056] In conjunction with the second possible implementation of the second aspect above, the first EAP response message also includes a first message authentication code value, the first message authentication code value being calculated by the second communications device based on the first authentication information using a session key, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier, and the first message authentication code value being used by the first communications device to authenticate the second communications device. Furthermore, the second communications device receives a second EAP request message sent by the second communications device, the second EAP request message including the second message authentication code value. The implementation of the second communications device authenticating the first communications device based on the target PSK includes the second communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0057] In a third possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message including the first identity of the first communication device; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a target key pool number and a second identity of the second communication device, the target key pool number indicating a target key pool in the PSK set; the second communication device receives a second EAP request message sent by the first communication device, the second EAP request message including a target key identifier, the target key identifier indicating a PSK in the target key pool; the second communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0058] In this implementation, the second communication device selects a key pool, and then the first communication device and the second communication device negotiate to determine a target PSK in the selected key pool.
[0059] In combination with the third possible implementation manner of the above-mentioned second aspect, the first EAP response message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0060] In conjunction with the third possible implementation of the second aspect above, the second EAP request message also includes a first message authentication code value, and the second communications device authenticates the first communications device based on the target PSK, including: the second communications device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. Furthermore, the second communications device sends a second EAP response message corresponding to the second EAP request message to the first communications device, the second EAP response message including a second message authentication code value, the second message authentication code value calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0061] In a fourth possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine an implementation process of the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message includes a target key pool number, a target key identifier, and a first identity identifier of the first communication device, the target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool; the second communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0062] In this implementation mode, the key pool and the target PSK are directly selected by the first communication device.
[0063] In conjunction with a fourth possible implementation of the second aspect, a second communications device sends a first EAP response message corresponding to a first EAP request message to a first communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device. The first message authentication code value is calculated by the second communications device based on a session key based on first authentication information, the session key being obtained based on a target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier. The first message authentication code value is used by the first communications device to authenticate the second communications device. The second communications device receives a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value. An implementation method for the second communications device to authenticate the first communications device based on the target PSK includes: the second communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0064] In a fifth possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message including the first identity of the first communication device; the second communication device uses a key in a target key pool in the PSK set as a target PSK; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a target key pool number, a target key identifier, and the second identity of the second communication device, the target key pool number indicating a target key pool in the PSK set, and the target key identifier indicating a PSK in the target key pool.
[0065] In this implementation mode, the key pool and the target PSK are directly selected by the second communication device.
[0066] In conjunction with the fifth possible implementation of the second aspect above, the first EAP response message also includes a first message authentication code value, the first message authentication code value being calculated by the second communications device based on the first authentication information using a session key, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier, and the first message authentication code value being used by the first communications device to authenticate the second communications device. Furthermore, the second communications device receives a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value. An implementation method for the second communications device to authenticate the first communications device based on the target PSK includes the second communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0067] In a sixth possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine an implementation process of the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message includes a key identifier list and a first identity identifier of the first communication device, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; the second communication device selects a PSK from the multiple PSKs indicated by the key identifier list as a target PSK; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message includes a target key identifier corresponding to the target PSK and the second identity identifier of the second communication device.
[0068] In this implementation, the first communication device provides a key identification list, and then the second communication device selects a target PSK according to the key identification list.
[0069] In conjunction with the sixth possible implementation of the second aspect above, the first EAP response message also includes a first message authentication code value, the first message authentication code value being calculated by the second communications device based on the first authentication information based on a session key, the session key being obtained based on the target PSK, the first authentication information including a key identifier list, a target key identifier, and a second identity identifier, and the first message authentication code value being used by the first communications device to authenticate the second communications device. Furthermore, the second communications device receives a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value. An implementation method for the second communications device to authenticate the first communications device based on the target PSK includes the second communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0070] In a seventh possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message including the first identity of the first communication device; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a key identifier list and the second identity of the second communication device, the key identifier list including multiple key identifiers, and the multiple key identifiers respectively indicating multiple PSKs in the PSK set; the second communication device receives a second EAP request message sent by the first communication device, the second EAP request message including a target key identifier, the target key identifier being a key identifier in the key identifier list; the second communication device uses the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0071] In this implementation, the second communication device provides a key identification list, and then the first communication device selects a target PSK according to the key identification list.
[0072] In conjunction with the seventh possible implementation of the second aspect, the second EAP request message further includes a first message authentication code value, and the second communications device authenticates the first communications device based on the target PSK, including: the second communications device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a key identifier list, a target key identifier, and the first identity identifier. Furthermore, the second communications device sends a second EAP response message corresponding to the second EAP request message to the first communications device, the second EAP response message including a second message authentication code value, the second message authentication code value calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0073] In an eighth possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine an implementation process of the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message includes a target key identifier and a first identity identifier of the first communication device, and the target key identifier indicates a PSK in the PSK set; the second communication device uses the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0074] In this implementation mode, the first communication device directly selects the target PSK.
[0075] In conjunction with an eighth possible implementation of the second aspect, a second communications device sends a first EAP response message corresponding to a first EAP request message to a first communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device. The first message authentication code value is calculated by the second communications device based on first authentication information based on a session key, the session key being obtained based on a target PSK, the first authentication information including a target key identifier and a second identity identifier, and the first message authentication code value is used by the first communications device to authenticate the second communications device. The second communications device receives a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value. An implementation method for the second communications device to authenticate the first communications device based on the target PSK includes: the second communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0076] In a ninth possible implementation manner of the second aspect above, the second communication device negotiates with the first communication device to determine the implementation process of the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: the second communication device receives a first EAP request message sent by the first communication device, the first EAP request message including the first identity of the first communication device; the second communication device uses a key in the PSK set as the target PSK; the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including the target key identifier corresponding to the target PSK and the second identity of the second communication device.
[0077] In this implementation mode, the target PSK is directly selected by the second communication device.
[0078] In conjunction with the ninth possible implementation of the second aspect, the first EAP response message further includes a first message authentication code value, the first message authentication code value being calculated by the second communications device based on the first authentication information based on a session key, the session key being obtained based on the target PSK, the first authentication information including a target key identifier and a second identity identifier, and the first message authentication code value being used by the first communications device to authenticate the second communications device; the second communications device receives a second EAP request message sent by the first communications device, the second EAP request message including the second message authentication code value. An implementation method in which the second communications device authenticates the first communications device based on the target PSK includes: the second communications device verifying the second message authentication code value based on the session key and the second authentication information.
[0079] In a third aspect, a communication device is provided. The communication device includes multiple functional modules that interact with each other to implement the method of the first aspect and its respective embodiments, and / or the method of the second aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.
[0080] In a fourth aspect, a communication device is provided, comprising: a memory, a network interface, and at least one processor,
[0081] The memory is used to store program instructions,
[0082] After the at least one processor reads the program instructions stored in the memory, the communication device executes the method in the above-mentioned first aspect and its various embodiments, and / or the method in the above-mentioned second aspect and its various embodiments.
[0083] In a first scenario, the communication device is a first communication device, and after the at least one processor reads the program instructions stored in the memory, the first communication device performs the following operations:
[0084] By sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, a target PSK is determined through negotiation with the second communication device, where a PSK set is pre-stored in the first communication device, the PSK set includes multiple PSKs, and the target PSK is one of the PSKs in the PSK set; based on the target PSK, the second communication device is authenticated.
[0085] Optionally, the PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
[0086] Optionally, the key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and then sent to the first communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
[0087] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0088] Alternatively, different PSKs in the PSK set are identified by using different key identifiers.
[0089] In a first possible implementation manner of the fourth aspect, the PSK set includes multiple key pools, and after the program instructions are read by the at least one processor, the first communications device performs the following operations:
[0090] Sending a first EAP request message to the second communication device, the first EAP request message including a key pool number list and a first identity of the first communication device, the key pool number list including multiple key pool numbers, the multiple key pool numbers respectively indicating multiple key pools in the PSK set; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key pool number and a second identity of the second communication device, the target key pool number being a key pool number in the key pool number list; obtaining a target key pool indicated by the target key pool number from the PSK set, and selecting a PSK from the target key pool as the target PSK; sending a second EAP request message to the second communication device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0091] In combination with the first possible implementation manner of the fourth aspect, the first EAP response message further includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool. After the program instructions are read by the at least one processor, the first communications device performs the following operations:
[0092] A plurality of candidate PSKs indicated by the plurality of key identifiers are obtained from the target key pool, and a PSK is selected from the plurality of candidate PSKs as the target PSK.
[0093] In combination with the first possible implementation of the fourth aspect, the second EAP request message further includes a first message authentication code value, where the first message authentication code value is calculated by the first communications device based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the first identity identifier. After the program instructions are read by the at least one processor, the first communications device performs the following operations:
[0094] Receive a second EAP response message corresponding to the second EAP request message sent by the second communication device, where the second EAP response message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0095] In a second possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0096] Sending a first EAP request message to the second communication device, the first EAP request message including a target key pool number and a first identity of the first communication device, the target key pool number indicating a target key pool in the PSK set; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key identifier and a second identity of the second communication device, the target key identifier indicating a PSK in the target key pool; and using the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0097] In combination with the second possible implementation manner of the above-mentioned fourth aspect, the first EAP request message also includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0098] In combination with the second possible implementation manner of the fourth aspect, the first EAP response message further includes a first message authentication code value, and after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0099] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier; and a second EAP request message is sent to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
[0100] In a third possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0101] Sending a first EAP request message to the second communication device, the first EAP request message including the first identity of the first communication device; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key pool number and the second identity of the second communication device, the target key pool number indicating a target key pool in the PSK set; obtaining a target key pool indicated by the target key pool number from the PSK set, and selecting a PSK from the target key pool as the target PSK; sending a second EAP request message to the second communication device, the second EAP request message including the target key identifier corresponding to the target PSK.
[0102] In combination with the third possible implementation manner of the fourth aspect, the first EAP response message further includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool. After the program instructions are read by the at least one processor, the first communications device performs the following operations:
[0103] A plurality of candidate PSKs indicated by the plurality of key identifiers are obtained from the target key pool, and a PSK is selected from the plurality of candidate PSKs as the target PSK.
[0104] In combination with the third possible implementation of the fourth aspect, the second EAP request message further includes a first message authentication code value, where the first message authentication code value is calculated by the first communication device based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the first identity identifier, and the first message authentication code value is used by the second communication device to authenticate the first communication device; and after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0105] Receive a second EAP response message corresponding to the second EAP request message sent by the second communication device, where the second EAP response message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0106] In a fourth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0107] Using a key in the target key pool in the PSK set as the target PSK; sending a first EAP request message to the second communication device, where the first EAP request message includes a target key pool number corresponding to the target key pool, a target key identifier corresponding to the target PSK, and a first identity identifier of the first communication device.
[0108] In combination with the fourth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0109] The method further comprises: receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communication device; verifying the first message authentication code value based on a session key and first authentication information, the session key being obtained based on the target PSK, the first authentication information including the target key pool number, the target key identifier, and the second identity identifier; and sending a second EAP request message to the second communication device, the second EAP request message including a second message authentication code value, the second message authentication code value being calculated by the first communication device based on the session key and the second authentication information, the second message authentication code value being used by the second communication device to authenticate the first communication device.
[0110] In a fifth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0111] Sending a first EAP request message to the second communication device, where the first EAP request message includes a first identity of the first communication device; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a target key pool number, a target key identifier, and a second identity of the second communication device, where the target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool; and using the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0112] In combination with the fifth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0113] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier; and a second EAP request message is sent to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
[0114] In a sixth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0115] Sending a first EAP request message to the second communication device, the first EAP request message including a key identifier list and a first identity identifier of the first communication device, the key identifier list including multiple key identifiers, and the multiple key identifiers respectively indicating multiple PSKs in the PSK set; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key identifier and a second identity identifier of the second communication device, the target key identifier being a key identifier in the key identifier list; and using the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0116] In combination with the sixth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0117] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the second identity identifier; and a second EAP request message is sent to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
[0118] In a seventh possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0119] Sending a first EAP request message to the second communication device, the first EAP request message including the first identity of the first communication device; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a key identifier list and the second identity of the second communication device, the key identifier list including multiple key identifiers, the multiple key identifiers respectively indicating multiple PSKs in the PSK set; selecting a PSK from the multiple PSKs indicated by the key identifier list as the target PSK; sending a second EAP request message to the second communication device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0120] In combination with the seventh possible implementation of the fourth aspect, the second EAP request message further includes a first message authentication code value, where the first message authentication code value is calculated by the first communication device based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the first identity identifier, and the first message authentication code value is used by the second communication device to authenticate the first communication device; and after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0121] Receive a second EAP response message corresponding to the second EAP request message sent by the second communication device, where the second EAP response message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0122] In an eighth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0123] A key in the PSK set is used as the target PSK; and a first EAP request message is sent to the second communication device, where the first EAP request message includes a target key identifier corresponding to the target PSK and a first identity identifier of the first communication device.
[0124] In combination with the eighth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0125] The method further comprises: receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communication device; verifying the first message authentication code value based on a session key and first authentication information, the session key being obtained based on the target PSK, the first authentication information including the target key identifier and the second identity identifier; and sending a second EAP request message to the second communication device, the second EAP request message including a second message authentication code value, the second message authentication code value being calculated by the first communication device based on the session key and the second authentication information, the second message authentication code value being used by the second communication device to authenticate the first communication device.
[0126] In a ninth possible implementation of the fourth aspect, after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0127] Sending a first EAP request message to the second communication device, where the first EAP request message includes a first identity of the first communication device; receiving a first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a target key identifier and a second identity of the second communication device, where the target key identifier indicates a PSK in the PSK set; and using the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0128] In combination with the ninth possible implementation of the fourth aspect, the first EAP response message further includes a first message authentication code value, and after the program instructions are read by the at least one processor, the first communication device performs the following operations:
[0129] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key identifier and the second identity identifier; and a second EAP request message is sent to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
[0130] In a second scenario, the communication device is a second communication device, and after the at least one processor reads the program instructions stored in the memory, the second communication device performs the following operations:
[0131] By receiving an EAP request message sent by a first communication device and / or sending an EAP response message to the first communication device, a target PSK is determined through negotiation with the first communication device, where a PSK set is pre-stored in the second communication device, the PSK set includes multiple PSKs, and the target PSK is a PSK in the PSK set; based on the target PSK, the first communication device is authenticated.
[0132] Optionally, the PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
[0133] Optionally, the key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and then sent to the second communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
[0134] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0135] Optionally, different PSKs in the PSK set are identified by different key identifiers.
[0136] In a first possible implementation manner of the fourth aspect, the PSK set includes multiple key pools, and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0137] Receive a first EAP request message sent by the first communication device, the first EAP request message including a key pool number list and a first identity of the first communication device, the key pool number list including multiple key pool numbers; send a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a target key pool number and a second identity of the second communication device, the target key pool number being a key pool number in the key pool number list, and the target key pool number indicating a target key pool in the PSK set; receive a second EAP request message sent by the first communication device, the second EAP request message including a target key identifier, the target key identifier indicating a PSK in the target key pool; and use the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0138] In combination with the first possible implementation manner of the above-mentioned fourth aspect, the first EAP response message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0139] In combination with the first possible implementation manner of the fourth aspect, the second EAP request message further includes a first message authentication code value, and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0140] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the first identity identifier; and a second EAP response message corresponding to the second EAP request message is sent to the first communications device, where the second EAP response message includes a second message authentication code value, where the second message authentication code value is calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0141] In a second possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0142] Receive a first EAP request message sent by the first communication device, where the first EAP request message includes a target key pool number and a first identity of the first communication device, where the target key pool number indicates a target key pool in the PSK set; obtain a target key pool indicated by the target key pool number from the PSK set, and select a PSK from the target key pool as the target PSK; and send a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key identifier corresponding to the target PSK and a second identity of the second communication device.
[0143] In combination with the second possible implementation manner of the fourth aspect, the first EAP request message further includes a key identifier list, where the key identifier list includes multiple key identifiers, where the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool. After the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0144] A plurality of candidate PSKs indicated by the plurality of key identifiers are obtained from the target key pool, and a PSK is selected from the plurality of candidate PSKs as the target PSK.
[0145] In combination with the second possible implementation of the fourth aspect, the first EAP response message further includes a first message authentication code value, where the first message authentication code value is calculated by the second communication device based on the session key and the first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device; and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0146] Receive a second EAP request message sent by the second communication device, where the second EAP request message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0147] In a third possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0148] Receive a first EAP request message sent by the first communication device, the first EAP request message including a first identity of the first communication device; send a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a target key pool number and a second identity of the second communication device, the target key pool number indicating a target key pool in the PSK set; receive a second EAP request message sent by the first communication device, the second EAP request message including a target key identifier, the target key identifier indicating a PSK in the target key pool; and use the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0149] In combination with the third possible implementation manner of the above-mentioned fourth aspect, the first EAP response message also includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0150] In combination with the third possible implementation manner of the fourth aspect, the second EAP request message further includes a first message authentication code value, and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0151] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the first identity identifier; and a second EAP response message corresponding to the second EAP request message is sent to the first communications device, where the second EAP response message includes a second message authentication code value, where the second message authentication code value is calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0152] In a fourth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0153] Receive a first EAP request message sent by the first communication device, where the first EAP request message includes a target key pool number, a target key identifier, and a first identity identifier of the first communication device, where the target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool; and use the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0154] In combination with the fourth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0155] Sending a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device, the first message authentication code value being calculated by the second communications device based on a session key and first authentication information, the session key being obtained based on the target PSK, the first authentication information including the target key pool number, the target key identifier, and the second identity identifier, the first message authentication code value being used by the first communications device to authenticate the second communications device; receiving a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value; and verifying the second message authentication code value based on the session key and the second authentication information.
[0156] In a fifth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0157] The method includes receiving a first EAP request message sent by the first communication device, where the first EAP request message includes a first identity of the first communication device; using a key in a target key pool in the PSK set as the target PSK; and sending a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key pool number, a target key identifier, and a second identity of the second communication device, where the target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool.
[0158] In combination with a fifth possible implementation of the fourth aspect, the first EAP response message further includes a first message authentication code value, where the first message authentication code value is calculated by the second communication device based on the session key and the first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device; and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0159] Receive a second EAP request message sent by the first communication device, where the second EAP request message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0160] In a sixth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0161] The method comprises: receiving a first EAP request message sent by the first communication device, where the first EAP request message includes a key identifier list and a first identity identifier of the first communication device, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; selecting a PSK from the multiple PSKs indicated by the key identifier list as the target PSK; and sending a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key identifier corresponding to the target PSK and a second identity identifier of the second communication device.
[0162] In combination with a sixth possible implementation of the fourth aspect, the first EAP response message further includes a first message authentication code value, where the first message authentication code value is calculated by the second communication device based on a session key and the first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device; and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0163] Receive a second EAP request message sent by the first communication device, where the second EAP request message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0164] In a seventh possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0165] Receive a first EAP request message sent by the first communication device, where the first EAP request message includes a first identity of the first communication device; send a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a key identifier list and a second identity of the second communication device, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; receive a second EAP request message sent by the first communication device, where the second EAP request message includes a target key identifier, where the target key identifier is a key identifier in the key identifier list; and use the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0166] In combination with the seventh possible implementation manner of the fourth aspect, the second EAP request message further includes a first message authentication code value, and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0167] The first message authentication code value is verified based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the first identity identifier; and a second EAP response message corresponding to the second EAP request message is sent to the first communications device, where the second EAP response message includes a second message authentication code value, where the second message authentication code value is calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0168] In an eighth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0169] Receive a first EAP request message sent by the first communication device, where the first EAP request message includes a target key identifier and a first identity identifier of the first communication device, where the target key identifier indicates a PSK in the PSK set; and use the PSK indicated by the target key identifier in the PSK set as the target PSK.
[0170] In combination with the eighth possible implementation manner of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0171] Sending a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device, the first message authentication code value being calculated by the second communications device based on a session key and first authentication information, the session key being obtained based on the target PSK, the first authentication information including the target key identifier and the second identity identifier, the first message authentication code value being used by the first communications device to authenticate the second communications device; receiving a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value; and verifying the second message authentication code value based on the session key and the second authentication information.
[0172] In a ninth possible implementation of the fourth aspect, after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0173] Receive a first EAP request message sent by the first communication device, the first EAP request message including a first identity of the first communication device; use a key in the PSK set as the target PSK; and send a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a target key identifier corresponding to the target PSK and a second identity of the second communication device.
[0174] In conjunction with a ninth possible implementation of the fourth aspect, the first EAP response message further includes a first message authentication code value, where the first message authentication code value is calculated by the second communication device based on the session key and the first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key identifier and the second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device; and after the program instructions are read by the at least one processor, the second communication device performs the following operations:
[0175] Receive a second EAP request message sent by the first communication device, where the second EAP request message includes a second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0176] In a fifth aspect, a communication system is provided, which includes a first communication device and a second communication device, wherein a first PSK set is pre-stored in the first communication device, and a second PSK set is pre-stored in the second communication device, and the first PSK set and the second PSK set respectively include multiple PSKs.
[0177] The first communication device is used to execute the method in the above-mentioned first aspect and its various embodiments, and the second communication device is used to execute the method in the above-mentioned second aspect and its various embodiments.
[0178] In a sixth aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor, the method of the above-mentioned first aspect and its various embodiments is implemented, and / or the method of the above-mentioned second aspect and its various embodiments is implemented.
[0179] In the seventh aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the method of the above-mentioned first aspect and its various embodiments, and / or implements the method of the above-mentioned second aspect and its various embodiments.
[0180] In an eighth aspect, a chip is provided, which includes a programmable logic circuit and / or program instructions. When the chip is running, it implements the method of the above-mentioned first aspect and its various embodiments, and / or the method of the above-mentioned second aspect and its various embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0181] Figure 1 This is a schematic diagram of the process of quantum key distribution;
[0182] Figure 2 This is a schematic diagram of the implementation process of the EAP-GPSK authentication method;
[0183] Figure 3 This is a schematic diagram of the implementation process of the EAP authentication method based on quantum key;
[0184] Figure 4 This is a schematic diagram of a PSK acquisition method provided in an embodiment of the present application;
[0185] Figure 5 This is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0186] Figure 6 This is a schematic diagram of an implementation flow of an EAP-based authentication method provided in an embodiment of the present application;
[0187] Figure 7 This is a schematic diagram of the implementation process of an EAP-PSKP authentication method provided in an embodiment of the present application;
[0188] Figure 8 This is a flowchart of the PPK negotiation process between two communicating parties as provided by the IPsec draft.
[0189] Figure 9 This is a schematic diagram of a PPK key pool negotiation process provided by an embodiment of the present application;
[0190] Figure 10 This is another PPK key pool negotiation process diagram provided in an embodiment of the present application;
[0191] Figure 11 This is another PPK key pool negotiation process diagram provided in an embodiment of the present application;
[0192] Figure 12 This is a schematic structural diagram of a first communication device provided in an embodiment of the present application;
[0193] Figure 13 is a structural diagram of a second communication device provided in an embodiment of the present application;
[0194] Figure 14This is a hardware structure diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0195] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0196] In order to facilitate readers' understanding of the present application, some technologies involved in the present application are first described below.
[0197] 1. EAP is an authentication framework protocol that runs between the data link layer and the network layer. It can be used to implement access authentication for wireless networks or point-to-point authentication for communication devices. EAP can be applied not only to wireless LANs but also to wired LANs, but it is more frequently used in wireless LANs. As an authentication framework, EAP does not specifically refer to a specific authentication mechanism. EAP provides some common functions and allows the communicating parties to negotiate the authentication mechanism they wish to use. These authentication mechanisms are called EAP authentication methods (or EAP methods). Currently, the mainstream EAP authentication methods include EAP-GPSK, EAP-TLS, and EAP Tunnel TLS (EAP-TTLS). During the EAP execution process, the communicating parties negotiate and select an EAP authentication method through message exchange, and then complete the authentication using this EAP authentication method.
[0198] 2. Quantum communication, one of the cutting-edge fields in current physics, is one of the first areas of quantum information science to achieve practical application. The core of quantum communication is quantum key distribution (QKD). Based on the fundamental physical principles of quantum mechanics, it solves the challenge of secure key distribution and enables theoretically unconditionally secure confidential communication. With the development of quantum cryptography, QKD, as a typical application of quantum cryptography, has become a research hotspot. QKD is achieved by building a quantum network and constructing a quantum key pool (QKP) on each quantum device in the network. Quantum devices are physical devices that follow the laws of quantum mechanics and process information based on the principles of quantum computing. Quantum devices use qubits (qubits) to store and process data. Qubits have more states than binary systems.
[0199] Quantum key distribution (QKD) is a secure key distribution technology that leverages the Heisenberg uncertainty principle and the no-cloning theorem of quantum mechanics. During QKD, a quantum key (QK) is generated by one quantum device and transmitted to another quantum device via a quantum network. This allows both devices to generate the same quantum key. During QKD, the quantum key is transmitted in the form of a quantum state. QKD offers unconditional security: even with unlimited computing resources, an eavesdropper cannot decipher the quantum key using any decryption algorithm. The security of QKD is based on the unpredictability of the key source and the detectability of channel eavesdropping. The unpredictability of the key source refers to the fact that the QKD key source is a true quantum random number and, therefore, cannot be predicted. The detectability of channel eavesdropping refers to the fact that the quantum state transmitted into the channel satisfies the no-cloning theorem, and eavesdropping on the channel perturbs the quantum state, making it detectable by the receiver. The QKD system continuously generates keys for the application side.
[0200] In the QKD network application framework, applications using quantum keys need to have an application interface to obtain quantum keys from quantum devices. According to the definition of European Telecommunications Standards Institute (ETSI) GS QKD 004V2.1.1, the application interface has five different application scenarios. Here we use the OPEN_CONNECT interface as an example. For example, Figure 1 This is a flow chart of quantum key distribution. Figure 1 As shown in the figure, communication device A and communication device B are connected to the same QKD system, where communication device A is connected to quantum device A in the QKD system, and communication device B is connected to quantum device B in the QKD system. Communication device A communicates with quantum device A through application A, and communication device B communicates with quantum device B through application B. Quantum devices A and B are the QKD key management layer, responsible for sending quantum keys to applications. Figure 1 In the application scenario shown, the quantum key distribution process includes the following steps 101 to 106.
[0201] Step 101: Application A calls the OPEN_CONNECT interface to initiate a QKD key transmission connection to quantum device A and specifies the source application (application A, i.e. Figure 1 Src shown), target application (application B, i.e. Figure 1 Dst) and quality of service (QoS) parameters shown.
[0202] Step 102: Quantum device A transmits the quantum key and the key identifier corresponding to the quantum key to application A.
[0203] Step 103: Quantum device A establishes a session connection with quantum device B, specifies the source application, destination application, and QoS parameters, and sends the quantum key and key identifier to quantum device B through the quantum channel.
[0204] Step 104: Application A sends a key identifier to application B via a classic channel.
[0205] Step 105: Application B calls the OPEN_CONNECT interface to initiate a QKD key transmission connection to quantum device B, and specifies the source application, destination application, QoS parameters, and key identifier.
[0206] Step 106: Quantum device B transmits the quantum key indicated by the key identifier to application B.
[0207] If application A and application B no longer have the need to obtain the quantum key, application A disconnects the QKD key transmission connection with quantum device A, application B disconnects the QKD key transmission connection with quantum device B, and application A stops transmitting the key identifier to application B.
[0208] 3. A message authentication code (MAC) is used to verify the integrity of a message (untampered) and the reliability of the message source (not false or forged data). The authentication principle of a message authentication code is as follows: the sender and receiver agree on a shared key in advance. The sender uses the shared key to generate a MAC value for a message of any length, and then transmits the message and the MAC value to the receiver. The receiver uses the shared key to generate a MAC value for the message and compares the generated MAC value with the MAC value received from the sender. If the MAC values match, the receiver determines that the message is indeed from the sender and has not been tampered with (verification passed). Conversely, if the MAC values are inconsistent, the receiver can determine that the message is not from the sender or has been tampered with during transmission (verification failed).
[0209] EAP-GPSK (specifically, the request for comments (RFC) number 5433 (abbreviated as RFC 5433) document) is a PSK authentication scheme commonly used in existing EAP. For example, Figure 2 This is a schematic diagram of the implementation process of the EAP-GPSK authentication method. Figure 2As shown, the communicating parties exchange EAP-Request (EAP-Request) and EAP-Response (EAP-Response) messages to complete mutual identity authentication. The communicating parties include an EAP server and an EAP client. The EAP server is typically the authenticator, while the EAP client is typically the authenticated party. The EAP server sends EAP-Request messages to the EAP client, and the EAP client sends EAP-Response messages to the EAP server.
[0210] See also Figure 2 First, the communicating parties exchange EAP request messages (EAP-Request / Identity) and EAP response messages (EAP-Response / Identity) of the Identity type to negotiate the use of the EAP-GPSK authentication method for identity authentication. During the EAP-GPSK process, the communicating parties exchange the GPSK-1 message (EAP-Request / GPSK-1), the GPSK-2 message (EAP-Response / GPSK-2), the GPSK-3 message (EAP-Request / GPSK-3), and the GPSK-4 message (EAP-Response / GPSK-4). Finally, after the EAP server and EAP client complete mutual identity authentication, the EAP server sends an EAP-Authentication Success message (EAP-Success) to the EAP client. The following describes the GPSK-1, GPSK-2, GPSK-3, and GPSK-4 messages, respectively, from the perspectives of message content and message transmission process.
[0211] The message contents of the GPSK-1 message, the GPSK-2 message, the GPSK-3 message, and the GPSK-4 message are as follows.
[0212] GPSK-1 message: ID_Server, RAND_Server, CSuite_List
[0213] GPSK-2 message: SEC_SK(ID_Peer, ID_Server, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0214] GPSK-3 message: SEC_SK(RAND_Peer, RAND_Server, ID_Server, CSuite_Sel,
[0215] [ENC_PK(PD_Payload_Block)])
[0216] GPSK-4 message: SEC_SK([ENC_PK(PD_Payload_Block)])
[0217] Among them, ID_Server represents the identity of the EAP server. RAND_Server represents the random number generated by the EAP server. CSuite_List (ciphersuites list) represents the encryption suite list. ID_Peer represents the identity of the EAP client. RAND_Peer represents the random number generated by the EAP client. CSuite_Sel (ciphersuites selected) represents the encryption suite selected from CSuite_List. In the embodiment of the present application, SEC_X(Y) = Y||MAC_X(Y), "||" represents string concatenation, SEC_X(Y) represents content Y and the MAC value of content Y. MAC_X(Y) represents the MAC value calculated based on content Y using symmetric key X. ENC_X(Y) represents the encrypted content obtained by encrypting content Y using symmetric key X. PD_Payload_Block represents the encrypted data block. "[]" represents optional content.
[0218] It should be understood that the above-mentioned message content provided in the embodiment of the present application is only an exemplary description. In actual applications, the GPSK-1 message, GPSK-2 message, GPSK-3 message and GPSK-4 message can also be in other content forms, which are not limited here.
[0219] The message transmission process of GPSK-1 message, GPSK-2 message, GPSK-3 message and GPSK-4 message is as follows.
[0220] GPSK-1 message: The EAP server sends a GPSK-1 message to the EAP client. The GPSK-1 message includes the EAP server's identity, a random number generated by the EAP server, and a cipher suite list. The cipher suite list includes multiple cipher suites. Each cipher suite includes multiple algorithms supported by EAP to implement different functions, such as key derivation functions, encryption algorithms, and MAC algorithms.
[0221] GPSK-2 message: The EAP client sends a GPSK-2 message to the EAP server. The GPSK-2 message includes the EAP client's identity, a random number generated by the EAP client, the target cipher suite selected by the EAP client, parameters from the GPSK-1 message, and a MAC value calculated using the key SK based on the content of the GPSK-2 message. Optionally, the GPSK-2 message also includes an encrypted data block (i.e., ENC_PK(PD_Payload_Block)) symmetrically encrypted using the key PK. The MAC value is used for integrity protection, allowing the EAP server to verify whether the parameters in the GPSK-1 message and the GPSK-2 message have been tampered with during transmission and to authenticate the peer's identity. Both the keys SK and PK are derived from the PSK between the EAP client and the EAP server. In the current EAP-GPSK authentication method, there is only one PSK between the EAP client and the EAP server. Therefore, once the EAP client's and server's identities are determined, a unique PSK is determined. The EAP client and EAP server use the PSK to verify each other's identity, that is, by verifying the MAC value to prove that the other party has the same PSK as their own.
[0222] GPSK-3 message: The EAP server sends a GPSK-3 message to the EAP client. The GPSK-3 message includes the identity of the EAP server, the random number generated by the EAP server, the random number generated by the EAP client and the target encryption suite, as well as the MAC value calculated based on the message content of the GPSK-3 message using the key SK. Optionally, the GPSK-3 message also includes an encrypted data block (i.e., ENC_PK (PD_Payload_Block)) obtained by symmetrically encrypting the data block using the key PK. The MAC value is used for integrity protection so that the EAP client can verify the identity of the other party. Some parameters in the GPSK-1 message and the GPSK-2 message are carried in the GPSK-3 message to make the calculated MAC value random.
[0223] GPSK-4 message: The EAP client sends a GPSK-4 message to the EAP server. The GPSK-4 message is used to send some encrypted information, such as an encrypted data block (i.e., ENC_PK (PD_Payload_Block)) obtained by symmetric encryption of a data block using the key PK.
[0224] However, in the current EAP-GPSK authentication method, a PSK must be uniquely determined based on the identity of the EAP client and the EAP server. That is, only one PSK can exist between the communicating parties, and the selection and use of multiple PSKs cannot be supported, resulting in low flexibility.
[0225] In the traditional EAP-GPSK process, it is necessary to manually configure an independent PSK for each communicating pair, which requires a lot of work. Therefore, it is possible to consider introducing QKD technology and use quantum keys as the PSK for EAP authentication. For example, Figure 3 This is a schematic diagram of the implementation process of quantum key-based EAP authentication. Similarly, the communicating parties exchange EAP request (EAP-Request) and EAP response (EAP-Response) messages to complete mutual identity authentication. The communicating parties include an EAP server and an EAP client. The EAP server sends an EAP request message to the EAP client, and the EAP client sends an EAP response message to the EAP server. Here, quantum key-based EAP authentication is referred to as EAP-QK authentication.
[0226] See also Figure 3 First, the communicating parties need to exchange EAP request messages (EAP-Request / Identity) and EAP response messages (EAP-Response / Identity) of the Identity type to negotiate the use of EAP-QK authentication to complete identity authentication. In the EAP-QK process, the communicating parties need to obtain the same quantum key from the QKD system as the PSK. In addition, the communicating parties need to exchange QK-1 messages (EAP-Request / QK-1), QK-2 messages (EAP-Response / QK-2), QK-3 messages (EAP-Request / QK-3), and QK-4 messages (EAP-Response / QK-4). Finally, after the EAP server and EAP client complete mutual identity authentication, the EAP server sends an EAP authentication success message (EAP-Success) to the EAP client.
[0227] The message contents of the QK-1 message, the QK-2 message, the QK-3 message, and the QK-4 message are as follows.
[0228] QK-1 message: SAE_ID_Server, RAND_Server, CSuite_List
[0229] QK-2 message: SEC_SK(SAE_ID_Peer, SAE_ID_Server, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, ENC_PK(ID_Peer, [PD_Payload_Block]))
[0230] QK-3 message: SEC_SK(RAND_Peer, RAND_Server, SAE_ID_Server, CSuite_Sel, ENC_PK(ID_Server, [PD_Payload_Block]))
[0231] QK-4 message: SEC_PK (PD_Payload_Block)
[0232] SAE_ID_Server represents the Secure Application Entity (SAE) identifier corresponding to the EAP server. RAND_Server represents the random number generated by the EAP server. CSuite_List represents the list of cipher suites. SAE_ID_Peer represents the SAE identifier corresponding to the EAP client. RAND_Peer represents the random number generated by the EAP client. CSuite_Sel represents the cipher suite selected from CSuite_List. Key_ID represents the quantum key identifier. ID_Peer represents the EAP client's identity. ID_Server represents the EAP server's identity.
[0233] See also Figure 3 The implementation process of the EAP-QK authentication method includes the following 11 steps.
[0234] Steps 1 and 2 are consistent with EAP-GPSK authentication and are used to negotiate an EAP authentication method, specifically EAP-QK authentication. In step 1, the EAP server sends an EAP-Request / Identity message to the EAP client. In step 2, the EAP client sends an EAP-Response / Identity message to the EAP server.
[0235] In step 3, the EAP server sends a QK-1 message to the EAP client. The QK-1 message includes the SAE identifier corresponding to the EAP server, a random number generated by the EAP server, and a list of cipher suites. The SAE identifier is used to distinguish different applications in the QKD key management layer.
[0236] In step 4, the EAP client uses the SAE identifier corresponding to the EAP client and the SAE identifier corresponding to the EAP server in the QK-1 message to apply for the quantum key from the QKD key management layer (such as QKD-1) on the local side.
[0237] In step 5, the QKD key management layer (such as QKD-1) returns a quantum key and quantum key identifier to the EAP client.
[0238] In step 6, the EAP client sends a QK-2 message to the EAP server. The QK-2 message includes a quantum key identifier, the SAE identifier corresponding to the EAP client, the identity identifier of the EAP client, etc. Specifically, the QK-2 message includes a quantum key identifier, the SAE identifier corresponding to the EAP client, a random number generated by the EAP client, the target encryption suite selected by the EAP client, the parameters in the QK-1 message, and the encrypted data generated using the key PK (including the identity identifier of the EAP client), as well as a MAC value calculated based on the message content of the GPSK-2 message using the key SK. The MAC value is used for integrity protection, so that the EAP server can verify whether the parameters in the QK-1 message and the parameters in the QK-2 message have been tampered with during transmission and to verify the identity of the other party. Both the key SK and the key PK are keys derived from quantum keys.
[0239] In step 7, the EAP server uses the SAE identifier corresponding to the EAP server, the SAE identifier corresponding to the EAP client, and the quantum key identifier to apply for the quantum key from the QKD key management layer (such as QKD-2) of the local end.
[0240] In step 8, the QKD key management layer (such as QKD-2) returns the quantum key to the EAP server.
[0241] In step 9, the EAP server sends a QKD-3 message to the EAP client. The QKD-3 message includes the EAP server's identity, among other things. Specifically, the QKD-3 message includes the SAE identifier corresponding to the EAP server, a random number generated by the EAP server, a random number generated by the EAP client, the target cipher suite, encrypted data generated using the key PK (including the EAP server's identity), and a MAC value calculated using the key SK based on the QK-3 message's content. The MAC value is used for integrity protection, allowing the EAP server to verify the peer's identity.
[0242] In step 10, the EAP client sends a QKD-4 message to the EAP server. The QKD-4 message is used to send some encrypted information.
[0243] In step 11, the EAP server sends an EAP authentication success message to the EAP client.
[0244] Based on the implementation process of the above EAP-QK authentication method, it can be seen that the quantum key acquisition process is tightly coupled with the EAP process. During the EAP process, the EAP client and EAP server need to obtain the same quantum key from the QKD system based on the SAE identifier corresponding to the EAP client and the SAE identifier corresponding to the EAP server. This solution has poor scalability. If the quantum key acquisition method changes, for example, the communicating parties need to use other information besides their corresponding SAE identifiers to obtain the quantum key, the above solution will no longer be applicable.
[0245] Based on this, the present application provides a technical solution for implementing multi-PSK negotiation in EAP while completely decoupling the key acquisition process from the EAP process. In the technical solution provided by the present application, before executing the EAP process, each communicating party pre-stores a PSK set, which includes multiple PSKs. The PSKs in the PSK sets pre-stored by each communicating party are not bound to the identities or application identifiers of the communicating parties before the communicating parties execute the EAP process. That is, the PSKs in the PSK set are not bound to the identities or application identifiers of the communicating parties. This is different from the above-mentioned EAP-GPSK authentication method and EAP-QK authentication method. In this way, the PSKs in the PSK set pre-stored by each communicating party can be used to communicate with different communicating parties holding the same PSK. The present application uses the example of the communicating parties including a first communication device and a second communication device. For ease of distinction, the present application will uniformly refer to the PSK set pre-stored in the first communication device as the first PSK set, and the PSK set pre-stored in the second communication device as the second PSK set. The multiple PSKs in the first PSK set are completely identical or partially identical to the multiple PSKs in the second PSK set. The technical solution provided by the present application is as follows: for the first communication device, the first communication device acts as an authentication end (or authentication initiator), and the first communication device sends an EAP request message to the second communication device, and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine the target PSK; for the second communication device, the second communication device acts as an authenticated end (or authentication responder), and the second communication device receives an EAP request message sent by the first communication device, and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the target PSK. The target PSK is a PSK included in both the first PSK set and the second PSK set. Afterwards, the first communication device performs identity authentication on the second communication device based on the target PSK; and the second communication device performs identity authentication on the first communication device based on the target PSK. This application pre-stores a PSK set including multiple PSKs in a communication device. When the communication device needs to perform an EAP authentication process with other communication devices, the target PSK to be ultimately used in the PSK set is determined through negotiation. This application solution supports the selection and use of multiple PSKs, thereby improving the flexibility of the EAP authentication solution.
[0246] In some embodiments, the first PSK set and / or the second PSK set include one or more key pools, each of which includes one or more PSKs. Different key pools are identified by different key pool numbers, i.e., the key pool number corresponding to each key pool can globally uniquely indicate the key pool. Different PSKs in the same key pool are identified by different key identifiers, i.e., the key identifier corresponding to each PSK can uniquely indicate the PSK within the key pool in which the PSK resides. In this implementation, the use of the key pool number and key identifier can globally uniquely indicate a PSK.
[0247] In this application, when there are multiple categories of PSKs between communicating parties, and each category contains multiple PSKs, dividing the key pool by category helps distinguish between different categories of PSKs. In addition, when communicating parties need to negotiate a target PSK from multiple PSKs, limiting the range of PSKs to be negotiated by using the key pool number is more convenient and faster than limiting the range of PSKs to be negotiated by using a key identifier list, and significantly reduces the amount of data required to specify.
[0248] Optionally, the key pool in the communication device is obtained by pre-configuration or pre-negotiation. Alternatively, the key pool in the communication device is generated by a key distribution network and sent to the communication device. In particular, for a key pool generated by a key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generated the key pool. In particular, the key distribution network is, for example, a QKD network, and the key distribution device is, for example, a QKD device. In particular, for a key pool generated by a QKD network, the key pool number corresponding to the key pool can be used to indicate the QKD device pair that generated the key pool (i.e., a pair of QKD devices in the QKD network that are used to generate the same key pool).
[0249] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0250] There are many ways for communication devices to obtain PSK, such as through traditional manual configuration of classical keys, or through the handshake negotiation of previous security protocols (such as TLS) and then reuse of classical keys, or through QKD devices to obtain quantum keys. In the scenario of obtaining PSK through QKD devices, PSK may also have different generators. For example, the two communicating parties obtain PSK through different QKD networks (belonging to different operators), or obtain PSK through different QKD device pairs in the same QKD network. For example, refer to Figure 4 , Figure 4It is a schematic diagram of a PSK acquisition method provided by an embodiment of the present application. Due to the difficulty in making a unified plan for the key identifier corresponding to the PSK between different methods of obtaining PSK, this may cause a conflict in the key identifier corresponding to the PSK. Therefore, the present application uses a key pool to distinguish different methods of obtaining PSK and / or different key generators. For example, the present application designs the key pool number in a hierarchical manner, such as the first bit of the key pool number is used to indicate whether the PSK in the key pool is a classical key or a quantum key; when the PSK in the key pool is a quantum key, the following X bit is used to indicate the QKD network that generates the key pool, and the following Y bit is used to indicate the QKD device pair that generates the key pool (such as: the QKD device identifier that sends the QKD key to the EAP client + the QKD device identifier that sends the QKD key to the EAP server). The present application designs the key pool number according to actual needs, such as designing the key pool number in a hierarchical manner according to different scenarios and types, so that the key pool number is scalable.
[0251] In other implementations, different PSKs in the PSK set are identified by using different key identifiers. In this implementation, the key identifier can globally uniquely indicate a PSK.
[0252] The following is a detailed introduction to this application solution from multiple perspectives, including application scenarios, method flow, software devices, hardware devices, and systems.
[0253] The following is an example of an application scenario of the embodiment of the present application.
[0254] For example, Figure 5 This is a schematic diagram of an application scenario provided by an embodiment of the present application. Figure 5 As shown, the application scenario includes a first communication device and a second communication device. The first communication device and the second communication device are two end devices participating in mutual communication. The first communication device and the second communication device support EAP authentication mode.
[0255] The first communication device and the second communication device in the embodiment of the present application are a physical device or virtual device for sending a signal, or receiving a signal, or sending and receiving a signal, including but not limited to network devices such as routers, switches, base stations, or terminal devices such as hosts, servers, and user terminals. Optionally, the first communication device and the second communication device communicate via a wireless network, a wired network, a removable storage medium, or other dedicated data communication technology. Wherein, the wireless network includes but is not limited to any combination of the Internet, Bluetooth, a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile network, a private network, or a virtual private network. The removable storage medium is, for example, a universal serial bus (USB) flash drive, a mobile hard disk, or other removable storage medium, and the present application is not limited thereto.
[0256] Alternatively, see Figure 5 , this application scenario also includes one or more key distribution systems. The first communication device and the second communication device are connected to the same key distribution system. The key distribution system is a physical device or software service for storing, managing and providing PSK, and the key distribution system is used to distribute keys to communication devices (first communication device and second communication device) connected to the key distribution system. For example, the key distribution system includes a database (software service) for storing keys in the first communication device and the second communication device. The first communication device and the second communication device obtain keys through the key distribution system, which is equivalent to obtaining keys through their respective key databases. The key databases of the first communication device and the second communication device should come from the same key distribution system. In the same key distribution system, one key corresponds to only one key identifier. For example, in a quantum communication scenario, the key distribution system includes an independent physical device (such as a QKD device) that stores, manages and provides quantum keys. In a case such as Figure 5 In the illustrated application scenario, a first communication device and a second communication device are each connected to a key management entity (KME): the first device is connected to KME_A, and the second device is connected to KME_B. Both KMEs (KME_A and KME_B) belong to the same key distribution system. Keys are transferred between the KMEs and the communication devices via a key acquisition interface.
[0257] The following is an example of the method flow of the embodiment of the present application.
[0258] For example, Figure 66 is a flow chart of an implementation of an EAP-based authentication method 600 provided in an embodiment of the present application. The method 600 involves a first communication device and a second communication device. Optionally, the first communication device in the method 600 is, for example, Figure 5 The first communication device in method 600 is, for example, Figure 5 In the EAP process, the communicating parties are referred to as an EAP client (EAP peer) and an EAP server (EAP server). In the embodiments of the present application, the first communication device is used as the EAP server, and the second communication device is used as the EAP client. In actual applications, the first communication device can also be used as the EAP client, and the second communication device can be used as the EAP server. This embodiment of the present application does not limit this.
[0259] In method 600, a first PSK set is pre-stored in the first communication device, and the first PSK set includes multiple PSKs. A second PSK set is pre-stored in the second communication device, and the second PSK set includes multiple PSKs. Figure 6 As shown, an EAP request message is sent by the first communication device to the second communication device, and / or an EAP response message is sent by the second communication device to the first communication device, so that the first communication device and the second communication device negotiate to determine a target PSK. The target PSK is a PSK that exists in both the first PSK set and the second PSK set. That is, the first communication device determines the target PSK in the first PSK set through negotiation with the second communication device, and the second communication device determines the target PSK in the second PSK set through negotiation with the first communication device. Afterwards, the first communication device authenticates the second communication device based on the target PSK, and the second communication device authenticates the first communication device based on the target PSK. The authentication of one communication device on another communication device includes verifying whether the other party holds the same target PSK as itself and whether the message transmitted between the two communicating parties has been tampered with.
[0260] In an embodiment of the present application, by pre-storing a first PSK set including multiple PSKs in the first communication device, and by pre-storing a second PSK set including multiple PSKs in the second communication device, when an EAP authentication process needs to be performed between the first communication device and the second communication device, a target PSK that exists in both the first PSK set and the second PSK set is determined through negotiation for identity authentication of both parties. The embodiment of the present application supports the selection and use of multiple PSKs, thereby improving the flexibility of the EAP authentication scheme.
[0261] Optionally, taking the first communication device as the EAP server and the second communication device as the EAP client as an example, the EAP-based authentication method provided in the embodiment of the present application is referred to as the EAP-PSKP authentication method, and the EAP request message and EAP response message exchanged between the two communicating parties in the embodiment of the present application are referred to as PSKP messages. Figure 7 This is a schematic diagram of the implementation process of an EAP-PSKP authentication method provided in the embodiment of the present application. Figure 7 As shown, the communicating parties complete mutual identity authentication by exchanging EAP request (EAP-Request) messages and EAP response (EAP-Response) messages.
[0262] See also Figure 7 First, the first two steps of the handshake are similar to the first two steps of the EAP-GPSK authentication method. The communicating parties need to pass each other the EAP request message (EAP-Request / Identity) and EAP response message (EAP-Response / Identity) of the Identity type to negotiate the use of the EAP-PSKP authentication method (the method provided in the embodiment of the present application) to complete the identity authentication. In the EAP-PSKP process, the communicating parties need to pass each other the PSKP-1 message (EAP-Request / PSKP-1), PSKP-2 message (EAP-Response / PSKP-2), PSKP-3 message (EAP-Request / PSKP-3) and PSKP-4 message (EAP-Response / PSKP-4) to negotiate the target PSK and use the target PSK for two-way identity authentication. Finally, after the communicating parties complete mutual identity authentication, the EAP server sends an EAP authentication success message (EAP-Success) to the EAP client. Optionally, the PSKP-1 message, PSKP-2 message, PSKP-3 message and PSKP-4 message are modified based on the GPSK-1 message, GPSK-2 message, GPSK-3 message and GPSK-4 message respectively. In the message content description of the PSKP message, the meanings of the English abbreviations and symbols are the same as the Chinese and English abbreviations and symbols in the above-mentioned message content description for EAP-GPSK, and the key derivation process and applicable encryption suite are also the same as those defined in EAP-GPSK [RFC 5433], and will not be repeated in the embodiments of the present application.
[0263] Optionally, there are multiple implementation schemes of the EAP-PSKP authentication method provided in the embodiments of this application. This application uses the following multiple embodiments to illustrate different implementation schemes of the EAP-PSKP authentication method. In each of the following embodiments of this application, the first EAP request message corresponds to Figure 7 The PSKP-1 message (EAP-Request / PSKP-1) in the first EAP response message corresponds to Figure 7 The PSKP-2 message (EAP-Response / PSKP-2) in the second EAP request message corresponds to Figure 7 The PSKP-3 message (EAP-Request / PSKP-3) in the second EAP response message corresponds to Figure 7 The PSKP-4 message (EAP-Response / PSKP-4) in the .
[0264] In the first embodiment of the present application, a first PSK set pre-stored in a first communication device includes multiple key pools, and a second PSK set pre-stored in a second communication device includes multiple key pools. Different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers. The communicating parties first negotiate a key pool and then determine a target PSK within the negotiated key pool. The specific interaction process between the communicating parties includes steps 801 to 804.
[0265] In step 801, a first communications device sends a first EAP request message to a second communications device. The first EAP request message includes a key pool number list and a first identity of the first communications device. The key pool number list includes multiple key pool numbers, and the multiple key pool numbers respectively indicate multiple key pools in a first PSK set.
[0266] Optionally, the first EAP request message also includes a random number generated by the first communications device and one or more cipher suites in a list of cipher suites supported by the first communications device. The cipher suite list includes multiple cipher suites, each of which includes multiple algorithms for implementing different functions, such as a key derivation function, an encryption algorithm, and a MAC algorithm. The MAC algorithm is used to protect the integrity of the message data. For example, the structure of the cipher suite list is shown in Table 1.
[0267] Table 1
[0268] Cipher suite identifier Key length encryption algorithm MAC length MAC algorithm Key derivation function 0x0001 32 AES-GCM-256 32 AES-CMAC-256 GKDF 0x0002 32 NULL 64 HMAC-SHA512 GKDF
[0269] Optionally, a possible message structure of the first EAP request message is as follows:
[0270] ID_Server, RAND_Server, PSK_pool_ID_List, CSuite_List
[0271] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, PSK_pool_ID_List is the key pool number list, and CSuite_List is the encryption suite list.
[0272] In step 802, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key pool number and a second identity of the second communication device. The target key pool number is a key pool number in the key pool number list.
[0273] After receiving the first EAP request message, the second communication device first selects a target key pool in the second PSK set according to the key pool number list, and then carries the target key pool number corresponding to the target key pool in the first EAP response message and sends it to the first communication device.
[0274] Optionally, the first EAP response message also includes a key identifier list, a random number generated by the second communications device, and one or more of the target encryption suites selected by the second communications device. The key identifier list includes multiple key identifiers, each of which indicates a plurality of PSKs in the target key pool. Optionally, the key identifier list includes key identifiers corresponding to some of the PSKs in the target key pool. For example, if there are 100 PSKs in the target key pool, the key identifier list includes key identifiers corresponding to 10 of the 100 PSKs.
[0275] In an embodiment of the present application, the second communication device clearly indicates through a key identification list which PSKs exist in the target key pool in the second PSK set for the first communication device to select, thereby avoiding the situation where the target PSK selected by the first communication device is not in the second PSK set, thereby improving the PSK negotiation efficiency of the communicating parties.
[0276] Optionally, a possible message structure of the first EAP response message is as follows:
[0277] ID_Peer, RAND_Peer, PSK_pool_ID_Sel, Key_ID_List, CSuite_Sel
[0278] Among them, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, PSK_pool_ID_Sel is the selected target key pool number, Key_ID_List is the key identifier list, and CSuite_Sel is the selected target encryption suite.
[0279] In step 803, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a target key identifier corresponding to the target PSK.
[0280] After receiving the first EAP response message, the first communications device obtains the target key pool indicated by the target key pool number from the first PSK set and selects a PSK from the target key pool as the target PSK. Optionally, if the first EAP response message includes a key identifier list, the first communications device obtains multiple candidate PSKs indicated by multiple key identifiers in the target key identifier list from the target key pool and selects one PSK from the multiple candidate PSKs as the target PSK. The first communications device then sends the target key identifier corresponding to the selected PSK to the second communications device in a second EAP request message. The second communications device then uses the PSK indicated by the target key identifier in the target key pool of the second PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0281] Optionally, the second EAP request message also includes a first message authentication code value, which is calculated by the first communications device based on the first authentication information using a session key. The session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message and the first EAP response message, enabling the second communications device to verify whether the contents in the first EAP request message and the first EAP response message have been tampered with. The first message authentication code value is used by the second communications device to authenticate the first communications device.
[0282] Optionally, a first possible message structure of the second EAP request message is as follows:
[0283] SEC_SK(RAND_Peer, RAND_Server, ID_Peer, ID_Server, PSK_pool_ID_List, PSK_pool_ID_Sel, Key_ID_List, Key_ID_Sel, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0284] Among them, Key_ID_Sel is the selected target key identifier, and [ENC_PK(PD_Payload_Block)] is an optional encrypted data block.
[0285] Optionally, a second possible message structure of the second EAP request message is as follows:
[0286] Key_ID_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Peer, ID_Server, PSK_pool_ID_List, PSK_pool_ID_Sel, Key_ID_List, Key_ID_Sel, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0287] In the first message structure of the second EAP request message, SEC_X(Y) = Y||MAC_X(Y), indicating that content Y and the MAC value of content Y are sent together. That is, the content of the first EAP request message and the first EAP response message are duplicated and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the content of the first EAP request message and the first EAP response message are no longer duplicated and transmitted. Instead, the second EAP request message only sends the newly added content (including at least Key_ID_Sel) and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0288] In step 804, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device, where the second EAP response message includes a second message authentication code value.
[0289] The second message authentication code value is calculated by the second communication device based on the session key from the second authentication information. The second message authentication code value is used by the first communication device to authenticate the second communication device. This embodiment of the application does not limit the content of the second authentication information. For example, part or all of the content of the first EAP request message, the first EAP response message, and the second EAP request message may be used as the calculation content for the second message authentication code value to increase the randomness of the MAC value.
[0290] Optionally, when the second EAP request message includes the first message authentication code value, the second communications device authenticates the first communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the second EAP request message uses the first message structure described above, the second communications device verifies whether the contents of the first EAP request message and the first EAP response message copied in the second EAP request message are consistent with the contents of the first EAP request message and the first EAP response message actually received and sent by the second communications device, and verifies the received MAC value. If verification is successful, the second communications device sends the second message authentication code value to the first communications device in a second EAP response message.
[0291] Optionally, a first possible message structure of the second EAP response message is as follows:
[0292] SEC_SK(RAND_Peer, RAND_Server, ID_Peer, [CSuite_Sel], [PSK_pool_ID_Sel], Key_ID_Sel,
[0293] [ENC_PK(PD_Payload_Block)])
[0294] Optionally, a second possible message structure of the second EAP response message is as follows:
[0295] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Peer, [CSuite_Sel],
[0296] [PSK_pool_ID_Sel], Key_ID_Sel, [ENC_PK(PD_Payload_Block)])
[0297] In the first message structure of the second EAP response message, portions of the first EAP request message, the first EAP response message, and the second EAP request message are copied and transmitted in the second EAP response message. In the second message structure of the second EAP response message, the contents of the first EAP request message, the first EAP response message, and the second EAP request message are no longer copied and transmitted. The second EAP response message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0298] After receiving the second EAP response message, the first communications device authenticates the second communications device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the first communications device returns an EAP-Success message to the second communications device, completing mutual authentication between the two communicating devices.
[0299] In a second embodiment of the present application, a first PSK set pre-stored in a first communication device includes a key pool, and a second PSK set pre-stored in a second communication device includes a key pool. Different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers. One of the communicating parties first selects a key pool, and then the communicating parties negotiate to determine a target PSK within the selected key pool.
[0300] In a first possible implementation, the first communication device selects a key pool, and then the first communication device and the second communication device negotiate to determine a target PSK in the selected key pool. The specific interaction process between the two communication parties includes the following steps 901 to 904.
[0301] In step 901, a first communication device sends a first EAP request message to a second communication device. The first EAP request message includes a target key pool number and a first identity of the first communication device. The target key pool number indicates a target key pool in a first PSK set.
[0302] Optionally, the first EAP request message further includes a key identifier list, a random number generated by the first communication device, and one or more of a list of encryption suites supported by the first communication device. The key identifier list includes multiple key identifiers, each of which is used to indicate a plurality of PSKs in the target key pool.
[0303] Optionally, a possible message structure of the first EAP request message is as follows:
[0304] ID_Server, RAND_Server, PSK_pool_ID, Key_ID_List, CSuite_List
[0305] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, PSK_pool_ID is the selected target key pool number, Key_ID_List is the key identifier list, and CSuite_List is the encryption suite list.
[0306] In step 902, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key identifier corresponding to the target PSK and a second identity identifier of the second communication device.
[0307] After receiving the first EAP request message, the second communications device first obtains the target key pool indicated by the target key pool number from the second PSK set, obtains the target key pool indicated by the target key pool number from the second PSK set, and selects a PSK from the target key pool as the target PSK. Optionally, if the first EAP request message includes a key identifier list, the second communications device obtains multiple candidate PSKs indicated by multiple key identifiers in the key identifier list from the target key pool, and selects a PSK from the multiple candidate PSKs as the target PSK. The second communications device then sends the target key identifier corresponding to the selected PSK to the first communications device in the first EAP response message. The first communications device then uses the PSK indicated by the target key identifier in the target key pool of the first PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0308] Optionally, the first EAP response message also includes a first message authentication code value, which is calculated by the second communications device based on the first authentication information using a session key. The session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0309] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0310] Optionally, a first possible message structure of the first EAP response message is as follows:
[0311] SEC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID_list, Key_ID_Sel, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0312] Among them, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, Key_ID_Sel is the selected target key identifier, CSuite_Sel is the selected target encryption suite, and [ENC_PK(PD_Payload_Block)] is an optional encrypted data block.
[0313] Optionally, a second possible message structure of the first EAP response message is as follows:
[0314] ID_Peer, RAND_Peer, Key_ID_Sel, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, PSK_poo l_ID, Key_ID_list, Key_ID_Sel, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0315] In the first message structure of the first EAP response message, the content of the first EAP request message is duplicated and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer duplicated and transmitted. The first EAP response message only sends the newly added content in this interaction (including at least Key_ID_Sel) and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0316] In step 903, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0317] The second message authentication code value is calculated by the first communications device based on the session key from the second authentication information. The second message authentication code value is used by the second communications device to authenticate the first communications device. This embodiment of the application does not limit the content of the second authentication information. For example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0318] Optionally, when the first EAP response message includes the first message authentication code value, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0319] Optionally, a first possible message structure of the second EAP request message is as follows:
[0320] SEC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], Key_ID_Sel, CSuite_Sel,
[0321] [ENC_PK(PD_Payload_Block)])
[0322] Optionally, a second possible message structure of the second EAP request message is as follows:
[0323] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], Key_ID_Sel, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0324] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0325] In step 904, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0326] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0327] Optionally, a possible message structure of the second EAP response message is as follows:
[0328] SEC_SK([ENC_PK(PD_Payload_Block)])
[0329] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0330] In a second possible implementation, the second communication device selects a key pool, and then the first communication device and the second communication device negotiate to determine a target PSK in the selected key pool. The specific interaction process between the two communication parties includes the following steps 1001 to 1004.
[0331] In step 1001, a first communication device sends a first EAP request message to a second communication device, where the first EAP request message includes a first identity of the first communication device.
[0332] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0333] Optionally, a possible message structure of the first EAP request message is as follows:
[0334] ID_Server, RAND_Server, CSuite_List
[0335] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, and CSuite_List is the encryption suite list.
[0336] In step 1002, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key pool number and a second identity of the second communication device. The target key pool number indicates a target key pool in the second PSK set.
[0337] After receiving the first EAP request message, the second communication device first selects a target key pool in the second PSK set, and then carries the target key pool number corresponding to the target key pool in the first EAP response message and sends it to the first communication device.
[0338] Optionally, the first EAP response message further includes a key identifier list, a random number generated by the second communication device, and one or more of a target encryption suite selected by the second communication device, wherein the key identifier list includes multiple key identifiers, each of which indicates a plurality of PSKs in the target key pool.
[0339] Optionally, a possible message structure of the first EAP response message is as follows:
[0340] ID_Peer, RAND_Peer, PSK_pool_ID, Key_ID_List, CSuite_Sel
[0341] Among them, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, PSK_pool_ID is the selected target key pool number, Key_ID_List is the key identifier list, and CSuite_Sel is the selected target encryption suite.
[0342] In step 1003, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a target key identifier corresponding to the target PSK.
[0343] After receiving the first EAP response message, the first communications device obtains the target key pool indicated by the target key pool number from the first PSK set and selects a PSK from the target key pool as the target PSK. Optionally, if the first EAP response message includes a key identifier list, the first communications device obtains multiple candidate PSKs indicated by multiple key identifiers in the target key identifier list from the target key pool and selects one PSK from the multiple candidate PSKs as the target PSK. The first communications device then sends the target key identifier corresponding to the selected PSK to the second communications device in a second EAP request message. The second communications device then uses the PSK indicated by the target key identifier in the target key pool of the second PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0344] Optionally, the second EAP request message also includes a first message authentication code value, which is calculated by the first communications device based on the first authentication information using a session key. The session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message and the first EAP response message, enabling the second communications device to verify whether the contents in the first EAP request message and the first EAP response message have been tampered with. The first message authentication code value is used by the second communications device to authenticate the first communications device.
[0345] Optionally, a first possible message structure of the second EAP request message is as follows:
[0346] SEC_SK(RAND_Peer, RAND_Server, ID_Peer, ID_Server, PSK_pool_ID, Key_ID_List, Key_ID_Sel, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0347] Among them, Key_ID_Sel is the selected target key identifier, and [ENC_PK(PD_Payload_Block)] is an optional encrypted data block.
[0348] Optionally, a second possible message structure of the second EAP request message is as follows:
[0349] Key_ID_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Peer, ID_Server, PSK_pool_ID, Key_ID_List, Key_ID_Sel, CSuite_List, CSuite_Sel,
[0350] [ENC_PK(PD_Payload_Block)])
[0351] In the first message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are duplicated and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer duplicated and transmitted. Instead, the second EAP request message only contains the newly added content (including at least the Key_ID_Sel) and the MAC value (the calculation method of the MAC value remains unchanged) in this interaction, thereby reducing the message length.
[0352] In step 1004, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device, where the second EAP response message includes a second message authentication code value.
[0353] The second message authentication code value is calculated by the second communication device based on the session key from the second authentication information, and the second message authentication code value is used by the first communication device to authenticate the second communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or complete content of the first EAP request message, the first EAP response message, and the second EAP request message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0354] Optionally, when the second EAP request message includes the first message authentication code value, the second communications device authenticates the first communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the second EAP request message uses the first message structure described above, the second communications device verifies whether the contents of the first EAP request message and the first EAP response message copied in the second EAP request message are consistent with the contents of the first EAP request message and the first EAP response message actually received and sent by the second communications device, and verifies the received MAC value. If verification is successful, the second communications device sends the second message authentication code value to the first communications device in a second EAP response message.
[0355] Optionally, a first possible message structure of the second EAP response message is as follows:
[0356] SEC_SK(RAND_Peer, RAND_Server, ID_Peer, [CSuite_Sel], [PSK_pool_ID], Key_ID_Sel,
[0357] [ENC_PK(PD_Payload_Block)])
[0358] Optionally, a second possible message structure of the second EAP response message is as follows:
[0359] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Peer, [CSuite_Sel],
[0360] [PSK_pool_ID], Key_ID_Sel, [ENC_PK(PD_Payload_Block)])
[0361] In the first message structure of the second EAP response message, portions of the first EAP request message, the first EAP response message, and the second EAP request message are copied and transmitted in the second EAP response message. In the second message structure of the second EAP response message, the contents of the first EAP request message, the first EAP response message, and the second EAP request message are no longer copied and transmitted. The second EAP response message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0362] After receiving the second EAP response message, the first communications device authenticates the second communications device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the first communications device returns an EAP-Success message to the second communications device, completing mutual authentication between the two communicating devices.
[0363] In a third embodiment of the present application, a first PSK set pre-stored in a first communication device includes a key pool, and a second PSK set pre-stored in a second communication device includes a key pool. Different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers. Either the same communicating party directly selects a key pool and a target PSK, or one communicating party directly selects a key pool, and the other party directly selects a target PSK from the selected key pool.
[0364] In a first possible implementation, the first communication device directly selects the key pool and the target PSK. The specific interaction process between the two communicating parties includes the following steps 1201 to 1204.
[0365] In step 1201, a first communication device sends a first EAP request message to a second communication device. The first EAP request message includes a target key pool number, a target key identifier, and a first identity identifier of the first communication device.
[0366] The first communications device uses a key from the target key pool in the first PSK set as the target PSK. The target key pool number is the key pool number corresponding to the target key pool selected by the first communications device in the first PSK set. The target key identifier is the key identifier corresponding to the target key selected by the first communications device in the target key pool. Specifically, the target key pool number indicates the target key pool in the first PSK set, and the target key identifier indicates a PSK in the target key pool. After receiving the first EAP request message, the second communications device uses the PSK indicated by the target key identifier in the target key pool of the second PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0367] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0368] Optionally, a possible message structure of the first EAP request message is as follows:
[0369] ID_Server, RAND_Server, PSK_pool_ID, Key_ID, CSuite_List
[0370] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, PSK_pool_ID is the selected target key pool number, Key_ID is the selected target key identifier, and CSuite_List is the encryption suite list.
[0371] In step 1202, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a first message authentication code value and a second identity of the second communication device.
[0372] The first message authentication code value is calculated by the second communications device based on the first authentication information using a session key, where the session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0373] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0374] Optionally, a first possible message structure of the first EAP response message is as follows:
[0375] SEC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0376] Wherein, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, and CSuite_Sel is the selected target encryption suite.
[0377] Optionally, a second possible message structure of the first EAP response message is as follows:
[0378] ID_Peer, RAND_Peer, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel,
[0379] [ENC_PK(PD_Payload_Block)])
[0380] In the first message structure of the first EAP response message, the content of the first EAP request message is copied and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer copied and transmitted. The first EAP response message only sends the new content in this interaction and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0381] In step 1203, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0382] The second message authentication code value is calculated by the first communication device based on the session key from the second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0383] After receiving the first EAP response message, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on the session key derived from the target PSK and the first authentication information. For example, if the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0384] Optionally, a first possible message structure of the second EAP request message is as follows:
[0385] SEC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], [Key_ID], CSuite_Sel,
[0386] [ENC_PK(PD_Payload_Block)])
[0387] Optionally, a second possible message structure of the second EAP request message is as follows:
[0388] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], [Key_ID], CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0389] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0390] In step 1204, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0391] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0392] Optionally, a possible message structure of the second EAP response message is as follows:
[0393] SEC_SK([ENC_PK(PD_Payload_Block)])
[0394] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0395] In a second possible implementation, the second communication device directly selects the key pool and the target PSK. The specific interaction process between the two communicating parties includes the following steps 1301 to 1304.
[0396] In step 1301, a first communication device sends a first EAP request message to a second communication device, where the first EAP request message includes a first identity of the first communication device.
[0397] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0398] Optionally, a possible message structure of the first EAP request message is as follows:
[0399] ID_Server, RAND_Server, CSuite_List
[0400] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, and CSuite_List is the encryption suite list.
[0401] In step 1302, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key pool number, a target key identifier, and a second identity identifier of the second communication device.
[0402] The target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool. After receiving the first EAP request message, the second communications device first selects a target key pool in the second PSK set, then selects a PSK in the target key pool as the target PSK. It then sends the target key pool number and the target key identifier corresponding to the target PSK to the first communications device in the first EAP response message. After receiving the first EAP response message, the first communications device uses the PSK indicated by the target key identifier in the target key pool of the first PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0403] Optionally, the first EAP response message also includes a first message authentication code value. The first message authentication code value is calculated by the second communications device based on the first authentication information using a session key, where the session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0404] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0405] Optionally, a first possible message structure of the first EAP response message is as follows:
[0406] SEC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0407] Among them, ID_Peer is the second identity identifier, PSK_pool_ID is the selected target key pool number, Key_ID is the selected target key identifier, RAND_Peer is the random number generated by the second communication device, and CSuite_Sel is the selected target encryption suite.
[0408] Optionally, a second possible message structure of the first EAP response message is as follows:
[0409] ID_Peer, PSK_pool_ID, Key_ID, RAND_Peer, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0410] In the first message structure of the first EAP response message, the content of the first EAP request message is copied and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer copied and transmitted. The first EAP response message only sends the new content in this interaction and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0411] In step 1303, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0412] The second message authentication code value is calculated by the first communication device based on the session key from the second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0413] Optionally, when the first EAP response message includes the first message authentication code value, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0414] Optionally, a first possible message structure of the second EAP request message is as follows:
[0415] SEC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], [Key_ID], CSuite_Sel,
[0416] [ENC_PK(PD_Payload_Block)])
[0417] Optionally, a second possible message structure of the second EAP request message is as follows:
[0418] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], [Key_ID], CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0419] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0420] In step 1304, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0421] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0422] Optionally, a possible message structure of the second EAP response message is as follows:
[0423] SEC_SK([ENC_PK(PD_Payload_Block)])
[0424] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0425] In a third possible implementation, the first communication device directly selects a key pool, and the second communication device directly selects a target PSK from the key pool selected by the first communication device. The specific interaction process between the two communication parties includes the following steps 1401 to 1404.
[0426] In step 1401, a first communications device sends a first EAP request message to a second communications device. The first EAP request message includes a target key pool number and a first identity of the first communications device. The target key pool number indicates a target key pool in a first PSK set.
[0427] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0428] Optionally, a possible message structure of the first EAP request message is as follows:
[0429] ID_Server, PSK_pool_ID, RAND_Server, CSuite_List
[0430] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, PSK_pool_ID is the selected target key pool number, and CSuite_List is the encryption suite list.
[0431] In step 1402, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key identifier corresponding to the target PSK and a second identity identifier of the second communication device.
[0432] After receiving the first EAP request message, the second communications device first obtains the target key pool indicated by the target key pool number from the second PSK set, then obtains the target key pool indicated by the target key pool number from the second PSK set, and selects a PSK from the target key pool as the target PSK. The second communications device then sends the first EAP response message, along with the target key identifier corresponding to the selected PSK, to the first communications device. The first communications device then uses the PSK indicated by the target key identifier in the target key pool of the first PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0433] Optionally, the first EAP response message also includes a first message authentication code value, which is calculated by the second communications device based on the first authentication information using a session key. The session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0434] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0435] Optionally, a first possible message structure of the first EAP response message is as follows:
[0436] SEC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0437] Among them, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, Key_ID is the selected target key identifier, CSuite_Sel is the selected target encryption suite, and [ENC_PK(PD_Payload_Block)] is an optional encrypted data block.
[0438] Optionally, a second possible message structure of the first EAP response message is as follows:
[0439] ID_Peer, Key_ID, RAND_Peer, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, PSK_pool_ID, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel,
[0440] [ENC_PK(PD_Payload_Block)])
[0441] In the first message structure of the first EAP response message, the content of the first EAP request message is copied and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer copied and transmitted. The first EAP response message only sends the new content in this interaction and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0442] In step 1403, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0443] The second message authentication code value is calculated by the first communications device based on the session key from the second authentication information. The second message authentication code value is used by the second communications device to authenticate the first communications device. This embodiment of the application does not limit the content of the second authentication information. For example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0444] Optionally, when the first EAP response message includes the first message authentication code value, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0445] Optionally, a first possible message structure of the second EAP request message is as follows:
[0446] SEC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], [Key_ID], CSuite_Sel,
[0447] [ENC_PK(PD_Payload_Block)])
[0448] Optionally, a second possible message structure of the second EAP request message is as follows:
[0449] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, [PSK_pool_ID], [Key_ID], CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0450] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0451] In step 1404, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0452] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0453] Optionally, a possible message structure of the second EAP response message is as follows:
[0454] SEC_SK([ENC_PK(PD_Payload_Block)])
[0455] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0456] In a fourth embodiment of the present application, different PSKs in a first PSK set pre-stored in a first communication device are identified using different key identifiers, and different PSKs in a second PSK set pre-stored in a second communication device are identified using different key identifiers. One of the communicating parties provides a list of key identifiers, and the other party selects a target PSK within a range indicated by the list of key identifiers.
[0457] In a first possible implementation, the first communication device provides a key identification list, and the second communication device selects a target PSK based on the key identification list. The specific interaction process between the two communicating parties includes the following steps 1501 to 1504.
[0458] In step 1501, a first communication device sends a first EAP request message to a second communication device. The first EAP request message includes a key identifier list and a first identity identifier of the first communication device.
[0459] The key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the first PSK set.
[0460] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0461] Optionally, a possible message structure of the first EAP request message is as follows:
[0462] ID_Server, Key_ID_List, RAND_Server, CSuite_List
[0463] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, PSK_pool_ID is the selected target key pool number, Key_ID_List is the key identifier list, and CSuite_List is the encryption suite list.
[0464] In step 1502, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key identifier corresponding to the target PSK and a second identity identifier of the second communication device.
[0465] After receiving the first EAP request message, the second communications device selects a PSK from the multiple PSKs indicated by the key identifier list in the second PSK set as the target PSK. The second communications device then sends the first EAP response message, along with the target key identifier corresponding to the selected PSK, to the first communications device. The first communications device then uses the PSK indicated by the target key identifier in the target key pool of the first PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0466] Optionally, the first EAP response message also includes a first message authentication code value, which is calculated by the second communications device based on the first authentication information using a session key. The session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a key identifier list, a target key identifier, and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0467] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0468] Optionally, a first possible message structure of the first EAP response message is as follows:
[0469] SEC_SK(ID_Peer, ID_Server, Key_ID_list, Key_ID_Sel, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0470] Among them, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, Key_ID_list is the key identifier list, Key_ID_Sel is the selected target key identifier, CSuite_Sel is the selected target encryption suite, and [ENC_PK(PD_Payload_Block)] is an optional encrypted data block.
[0471] Optionally, a second possible message structure of the first EAP response message is as follows:
[0472] ID_Peer, RAND_Peer, Key_ID_Sel, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, Key_ID_list, Key_ID_Sel, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel,
[0473] [ENC_PK(PD_Payload_Block)])
[0474] In the first message structure of the first EAP response message, the content of the first EAP request message is copied and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer copied and transmitted. The first EAP response message only sends the new content in this interaction and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0475] In step 1503, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0476] The second message authentication code value is calculated by the first communication device based on the session key from the second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0477] Optionally, when the first EAP response message includes the first message authentication code value, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0478] Optionally, a first possible message structure of the second EAP request message is as follows:
[0479] SEC_SK(RAND_Peer, RAND_Server, ID_Server, Key_ID_Sel, CSuite_Sel,
[0480] [ENC_PK(PD_Payload_Block)])
[0481] Optionally, a second possible message structure of the second EAP request message is as follows:
[0482] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, Key_ID_Sel, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0483] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0484] In step 1504, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0485] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0486] Optionally, a possible message structure of the second EAP response message is as follows:
[0487] SEC_SK([ENC_PK(PD_Payload_Block)])
[0488] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0489] In a second possible implementation, the second communication device provides a key identification list, and the first communication device selects a target PSK based on the key identification list. The specific interaction process between the two communication parties includes the following steps 1601 to 1604.
[0490] In step 1601, a first communication device sends a first EAP request message to a second communication device, where the first EAP request message includes a first identity of the first communication device.
[0491] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0492] Optionally, a possible message structure of the first EAP request message is as follows:
[0493] ID_Server, RAND_Server, CSuite_List
[0494] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, and CSuite_List is the encryption suite list.
[0495] In step 1602, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a key identifier list and a second identity identifier of the second communication device.
[0496] After receiving the first EAP request message, the second communications device obtains key identifiers corresponding to multiple PSKs from the second PSK set to generate a key identifier list. The key identifier list includes multiple key identifiers, each of which indicates a plurality of PSKs in the second PSK set. The second communications device then sends the key identifier list to the first communications device along with the first EAP response message.
[0497] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0498] Optionally, a first possible message structure of the first EAP response message is as follows:
[0499] ID_Peer, RAND_Peer, Key_ID_List, CSuite_Sel
[0500] Among them, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, Key_ID_List is the key identifier list, and CSuite_Sel is the selected target encryption suite.
[0501] In step 1603, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a target key identifier corresponding to the target PSK.
[0502] After receiving the first EAP response message, the first communications device retrieves multiple PSKs indicated by the key identifier list from the first PSK set and selects one of these PSKs as the target PSK. The first communications device then sends the target key identifier corresponding to the selected PSK along with the target key identifier in a second EAP request message to the second communications device. The second communications device then uses the PSK indicated by the target key identifier in the target key pool of the second PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0503] Optionally, the second EAP request message also includes a first message authentication code value, which is calculated by the first communications device based on the first authentication information using a session key. The session key is derived based on the target PSK, such as by being derived from the target PSK. The first authentication information includes a key identifier list, a target key identifier, and a first identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message and the first EAP response message, enabling the second communications device to verify whether the contents in the first EAP request message and the first EAP response message have been tampered with. The first message authentication code value is used by the second communications device to authenticate the first communications device.
[0504] Optionally, a first possible message structure of the second EAP request message is as follows:
[0505] SEC_SK(RAND_Peer, RAND_Server, ID_Peer, ID_Server, Key_ID_List, Key_ID_Sel, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0506] Among them, Key_ID_Sel is the selected target key identifier, and [ENC_PK(PD_Payload_Block)] is an optional encrypted data block.
[0507] Optionally, a second possible message structure of the second EAP request message is as follows:
[0508] Key_ID_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Peer, ID_Server, Key_ID_List, Key_ID_Sel, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0509] In the first message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are duplicated and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer duplicated and transmitted. Instead, the second EAP request message only contains the newly added content (including at least the Key_ID_Sel) and the MAC value (the calculation method of the MAC value remains unchanged) in this interaction, thereby reducing the message length.
[0510] In step 1604, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device, where the second EAP response message includes a second message authentication code value.
[0511] The second message authentication code value is calculated by the second communication device based on the session key from the second authentication information, and the second message authentication code value is used by the first communication device to authenticate the second communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or complete content of the first EAP request message, the first EAP response message, and the second EAP request message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0512] Optionally, when the second EAP request message includes the first message authentication code value, the second communications device authenticates the first communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the second EAP request message uses the first message structure described above, the second communications device verifies whether the contents of the first EAP request message and the first EAP response message copied in the second EAP request message are consistent with the contents of the first EAP request message and the first EAP response message actually received and sent by the second communications device, and verifies the received MAC value. If verification is successful, the second communications device sends the second message authentication code value to the first communications device in a second EAP response message.
[0513] Optionally, a first possible message structure of the second EAP response message is as follows:
[0514] SEC_SK(RAND_Peer, RAND_Server, ID_Peer, [CSuite_Sel], Key_ID_Sel,
[0515] [ENC_PK(PD_Payload_Block)])
[0516] Optionally, a second possible message structure of the second EAP response message is as follows:
[0517] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Peer, [CSuite_Sel], Key_ID_Sel, [ENC_PK(PD_Payload_Block)])
[0518] In the first message structure of the second EAP response message, portions of the first EAP request message, the first EAP response message, and the second EAP request message are copied and transmitted in the second EAP response message. In the second message structure of the second EAP response message, the contents of the first EAP request message, the first EAP response message, and the second EAP request message are no longer copied and transmitted. The second EAP response message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0519] After receiving the second EAP response message, the first communications device authenticates the second communications device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the first communications device returns an EAP-Success message to the second communications device, completing mutual authentication between the two communicating devices.
[0520] In a fifth embodiment of the present application, different PSKs in a first PSK set pre-stored in a first communication device are identified using different key identifiers, and different PSKs in a second PSK set pre-stored in a second communication device are identified using different key identifiers. One of the communicating parties directly selects a target PSK.
[0521] In a first possible implementation, the first communication device directly selects the target PSK. The specific interaction process between the two communicating parties includes the following steps 1701 to 1704.
[0522] In step 1701, a first communication device sends a first EAP request message to a second communication device. The first EAP request message includes a target key identifier corresponding to a target PSK and a first identity identifier of the first communication device.
[0523] The first communications device selects a key in the first PSK set as the target PSK. The target key identifier is the key identifier corresponding to the target key selected by the first communications device in the first PSK set. That is, the target key identifier indicates a PSK in the target key pool. After receiving the first EAP request message, the second communications device selects the PSK indicated by the target key identifier in the second PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0524] Optionally, the first EAP request message further includes a random number generated by the first communication device and one or more encryption suites in a list supported by the first communication device.
[0525] Optionally, a possible message structure of the first EAP request message is as follows:
[0526] ID_Server, Key_ID, RAND_Server, CSuite_List
[0527] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, Key_ID is the selected target key identifier, and CSuite_List is the encryption suite list.
[0528] In step 1702, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a first message authentication code value and a second identity of the second communication device.
[0529] The first message authentication code value is calculated by the second communications device based on the first authentication information using a session key, where the session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key identifier and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0530] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0531] Optionally, a first possible message structure of the first EAP response message is as follows:
[0532] SEC_SK(ID_Peer, ID_Server, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel,
[0533] [ENC_PK(PD_Payload_Block)])
[0534] Wherein, ID_Peer is the second identity identifier, RAND_Peer is the random number generated by the second communication device, and CSuite_Sel is the selected target encryption suite.
[0535] Optionally, a second possible message structure of the first EAP response message is as follows:
[0536] ID_Peer, RAND_Peer, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0537] In the first message structure of the first EAP response message, the content of the first EAP request message is copied and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer copied and transmitted. The first EAP response message only sends the new content in this interaction and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0538] In step 1703, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0539] The second message authentication code value is calculated by the first communication device based on the session key from the second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0540] After receiving the first EAP response message, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on the session key derived from the target PSK and the first authentication information. For example, if the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0541] Optionally, a first possible message structure of the second EAP request message is as follows:
[0542] SEC_SK(RAND_Peer, RAND_Server, ID_Server, [Key_ID], CSuite_Sel,
[0543] [ENC_PK(PD_Payload_Block)])
[0544] Optionally, a second possible message structure of the second EAP request message is as follows:
[0545] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, [Key_ID], CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0546] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0547] In step 1704, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0548] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0549] Optionally, a possible message structure of the second EAP response message is as follows:
[0550] SEC_SK([ENC_PK(PD_Payload_Block)])
[0551] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0552] In a second possible implementation, the second communication device directly selects the target PSK. The specific interaction process between the two communicating parties includes the following steps 1801 to 1804.
[0553] In step 1801, a first communication device sends a first EAP request message to a second communication device, where the first EAP request message includes a first identity of the first communication device.
[0554] Optionally, a possible message structure of the first EAP request message is as follows:
[0555] ID_Server, RAND_Server, CSuite_List
[0556] Among them, ID_Server is the first identity identifier, RAND_Server is the random number generated by the first communication device, and CSuite_List is the encryption suite list.
[0557] In step 1802, the second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device. The first EAP response message includes a target key identifier and a second identity identifier of the second communication device.
[0558] The target key identifier indicates a PSK in the second PSK set. After receiving the first EAP request message, the second communications device first selects a PSK in the second PSK set as the target PSK. It then sends the target key identifier corresponding to the target PSK to the first communications device in the first EAP response message. After receiving the first EAP response message, the first communications device uses the PSK indicated by the target key identifier in the first PSK set as the target PSK. This completes the negotiation and determination of the target PSK between the communicating parties.
[0559] Optionally, the first EAP response message also includes a first message authentication code value. The first message authentication code value is calculated by the second communications device based on the first authentication information using a session key, where the session key is derived from the target PSK, such as by being derived from the target PSK. The first authentication information includes a target key identifier and a second identity identifier. Optionally, the first authentication information includes all contents in the first EAP request message, enabling the first communications device to verify whether the contents in the first EAP request message have been tampered with. The first message authentication code value is used by the first communications device to authenticate the second communications device.
[0560] Optionally, the first EAP response message further includes a random number generated by the second communication device and one or more target encryption suites selected by the second communication device.
[0561] Optionally, a first possible message structure of the first EAP response message is as follows:
[0562] SEC_SK(ID_Peer, ID_Server, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel,
[0563] [ENC_PK(PD_Payload_Block)])
[0564] Among them, ID_Peer is the second identity identifier, Key_ID is the selected target key identifier, RAND_Peer is the random number generated by the second communication device, and CSuite_Sel is the selected target encryption suite.
[0565] Optionally, a second possible message structure of the first EAP response message is as follows:
[0566] ID_Peer, RAND_Peer, Key_ID, CSuite_Sel, [ENC_PK(PD_Payload_Block)], MAC_SK(ID_Peer, ID_Server, Key_ID, RAND_Peer, RAND_Server, CSuite_List, CSuite_Sel,
[0567] [ENC_PK(PD_Payload_Block)])
[0568] In the first message structure of the first EAP response message, the content of the first EAP request message is copied and transmitted in the first EAP response message. In the second message structure of the first EAP response message, the content of the first EAP request message is no longer copied and transmitted. The first EAP response message only sends the new content in this interaction and the MAC value (the calculation method of the MAC value remains unchanged), thereby reducing the message length.
[0569] In step 1803, the first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value.
[0570] The second message authentication code value is calculated by the first communication device based on the session key from the second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device. This embodiment of the application does not limit the content of the second authentication information; for example, partial or full content of the first EAP request message and the first EAP response message may be used as content for calculating the second message authentication code value to increase the randomness of the MAC value.
[0571] Optionally, when the first EAP response message includes the first message authentication code value, the first communications device authenticates the second communications device based on the target PSK by verifying the first message authentication code value based on a session key and the first authentication information, where the session key is derived based on the target PSK. For example, when the first EAP response message uses the first message structure described above, the first communications device verifies whether the content of the first EAP request message copied in the first EAP response message is consistent with the content of the first EAP request message actually sent by the first communications device, and verifies the received MAC value. If verification is successful, the first communications device sends the second message authentication code value to the second communications device in a second EAP request message.
[0572] Optionally, a first possible message structure of the second EAP request message is as follows:
[0573] SEC_SK(RAND_Peer, RAND_Server, ID_Server, [Key_ID], CSuite_Sel,
[0574] [ENC_PK(PD_Payload_Block)])
[0575] Optionally, a second possible message structure of the second EAP request message is as follows:
[0576] [ENC_PK(PD_Payload_Block)], MAC_SK(RAND_Peer, RAND_Server, ID_Server, [Key_ID], CSuite_Sel, [ENC_PK(PD_Payload_Block)])
[0577] In the first message structure of the second EAP request message, portions of the first EAP request message and the first EAP response message are copied and transmitted in the second EAP request message. In the second message structure of the second EAP request message, the contents of the first EAP request message and the first EAP response message are no longer copied and transmitted. The second EAP request message may only send the MAC value and the optional encrypted data block, thereby reducing the message length.
[0578] In step 1804, the second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device.
[0579] After receiving the second EAP request message, the second communication device authenticates the first communication device based on the target PSK by verifying the second message authentication code value based on the session key and the second authentication information. If the verification succeeds, the second communication device can transmit any encrypted information to the first communication device using the second EAP response message.
[0580] Optionally, a possible message structure of the second EAP response message is as follows:
[0581] SEC_SK([ENC_PK(PD_Payload_Block)])
[0582] Afterwards, the first communication device returns an EAP-Success message to the second communication device, thus completing the two-way identity authentication of the communicating parties.
[0583] The order of the steps in the EAP-based authentication method provided in the embodiments of the present application can be adjusted appropriately, and the number of steps can be increased or decreased as needed. Any variation that can be readily conceived by a person skilled in the art within the scope of the present application should be covered by the scope of protection of the present application. For example, the key pool-based negotiation scheme provided in the embodiments of the present application can also be used with other communication security protocols, such as the Internet Protocol security (IPsec) protocol.
[0584] The current IPsec draft (draft-smyslov-ipsecme-ikev2-qr-alt-09) proposes a post-quantum PSK (post-quantum pre-shared key, PPK) negotiation process. For example, Figure 8 This is a flowchart of the PPK negotiation process between two communicating parties provided by the IPsec draft. Figure 8 As shown, N(USE_PPK_ALT) is a Status-type Internet Key Exchange (IKEv2) notification message. Both communicating parties exchange N(USE_PPK_ALT) messages to indicate their mutual agreement to negotiate a PPK. The initiator then sends a list of PPK identity numbers (PPK_ID_1 to PPK_ID_n) to the responder. The responder selects a PPK from the list and returns its selected PPK identity number, PPK_ID_i, to the initiator. The symbol [] indicates optional content.
[0585] The key pool negotiation solution provided in the embodiment of the present application can be applied to PPK key negotiation. For example, after the two communicating parties mutually agree to conduct PPK key negotiation, an IKEv2 notification message of the Status type named PPK_Pool_IDENTITY is added to negotiate the key pool number PPK_Pool_ID. For example, Figure 9 This is a schematic diagram of a PPK key pool negotiation process provided by an embodiment of the present application. Figure 9 As shown, the communication initiator sends a PPK key pool number list (from PPK_Pool_ID_1 to PPK_Pool_ID_n) to the communication responder, and then the communication responder selects a PPK key pool from the PPK key pool number list and returns the selected PPK key pool number PPK_Pool_ID_i to the communication initiator. For another example, Figure 10 This is another PPK key pool negotiation process diagram provided by the embodiment of the present application. Figure 10 As shown, the communication initiator (Initiator) directly specifies the PPK key pool number PPK_Pool_ID to the communication responder (Responder). For another example, Figure 11 This is another PPK key pool negotiation process diagram provided by the embodiment of this application. Figure 11 As shown, the communication responder (Responder) directly specifies the PPK key pool number PPK_Pool_ID to the communication initiator (Initiator).
[0586] The following is an example of the software device in the embodiment of the present application.
[0587] For example, Figure 12 This is a schematic diagram of the structure of a first communication device provided in an embodiment of the present application. Figure 12 As shown, the first communication device 1200 includes but is not limited to a transceiver module 1201 and a processing module 1202 .
[0588] Among them, the transceiver module 1201 is used to negotiate with the second communication device to determine the target PSK by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device. A PSK set is pre-stored in the first communication device, and the PSK set includes multiple PSKs. The target PSK is a PSK in the PSK set; the processing module 1202 is used to authenticate the second communication device based on the target PSK.
[0589] Optionally, the PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
[0590] Optionally, the key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and sent to the first communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
[0591] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0592] Alternatively, different PSKs in the PSK set are identified by using different key identifiers.
[0593] In a first possible implementation, the PSK set includes multiple key pools. The transceiver module 1201 is configured to send a first EAP request message to a second communications device, the first EAP request message including a key pool number list and a first identity of the first communications device. The key pool number list includes multiple key pool numbers, each of which indicates a plurality of key pools in the PSK set. The transceiver module 1201 is configured to receive a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key pool number and a second identity of the second communications device. The target key pool number is a key pool number in the key pool number list. The processing module 1202 is configured to obtain a target key pool indicated by the target key pool number from the PSK set and select a PSK from the target key pool as a target PSK. The transceiver module 1201 is configured to send a second EAP request message to the second communications device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0594] In combination with the first possible implementation manner, the first EAP response message also includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool. The processing module 1202 is configured to obtain multiple candidate PSKs indicated by the multiple key identifiers from the target key pool, and select a PSK from the multiple candidate PSKs as the target PSK.
[0595] In combination with the first possible implementation, the second EAP request message also includes a first message authentication code value, which is calculated by the first communication device based on the session key and the first authentication information, the session key is obtained based on the target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. The transceiver module 1201 is configured to receive a second EAP response message corresponding to the second EAP request message sent by the second communication device, the second EAP response message including the second message authentication code value; and verify the second message authentication code value based on the session key and the second authentication information.
[0596] In a second possible implementation, the transceiver module 1201 is configured to send a first EAP request message to a second communications device, the first EAP request message including a target key pool number and a first identity of the first communications device, the target key pool number indicating a target key pool in a PSK set; and receive a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key identifier and a second identity of the second communications device, the target key identifier indicating a PSK in the target key pool. The processing module 1202 is configured to use the PSK indicated by the target key identifier in the target key pool as a target PSK.
[0597] In combination with the second possible implementation manner, the first EAP request message further includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0598] In conjunction with the second possible implementation, the first EAP response message also includes a first message authentication code value. Processing module 1202 is configured to verify the first message authentication code value based on a session key and first authentication information. The session key is obtained based on a target PSK. The first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Transceiver module 1201 is configured to send a second EAP request message to a second communications device. The second EAP request message includes a second message authentication code value. The second message authentication code value is calculated by the first communications device based on the second authentication information based on the session key. The second message authentication code value is used by the second communications device to authenticate the first communications device.
[0599] In a third possible implementation, transceiver module 1201 is configured to send a first EAP request message to a second communications device, the first EAP request message including the first identity of the first communications device; and receive a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key pool number and the second identity of the second communications device, the target key pool number indicating a target key pool in a PSK set. Processing module 1202 is configured to obtain a target key pool indicated by the target key pool number from the PSK set and select a PSK from the target key pool as a target PSK. Transceiver module 1201 is configured to send a second EAP request message to the second communications device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0600] In combination with the third possible implementation, the first EAP response message also includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool. The processing module 1202 is configured to obtain multiple candidate PSKs indicated by the multiple key identifiers from the target key pool, and select a PSK from the multiple candidate PSKs as the target PSK.
[0601] In conjunction with the third possible implementation, the second EAP request message also includes a first message authentication code value, the first message authentication code value being calculated by the first communications device based on the first authentication information using a session key, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a first identity identifier, and the first message authentication code value being used by the second communications device to authenticate the first communications device; the transceiver module 1201 is configured to receive a second EAP response message corresponding to the second EAP request message sent by the second communications device, the second EAP response message including the second message authentication code value; and the processing module 1202 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0602] In a fourth possible implementation, the processing module 1202 is configured to use a key in a target key pool in the PSK set as a target PSK; and send a first EAP request message to the second communication device, where the first EAP request message includes a target key pool number corresponding to the target key pool, a target key identifier corresponding to the target PSK, and a first identity identifier of the first communication device.
[0603] In conjunction with the fourth possible implementation, the transceiver module 1201 is configured to receive a first EAP response message corresponding to a first EAP request message sent by a second communication device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communication device. The processing module is configured to verify the first message authentication code value based on a session key and first authentication information, the session key being obtained based on a target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier. The transceiver module 1201 is configured to send a second EAP request message to the second communication device, the second EAP request message including a second message authentication code value, the second message authentication code value being calculated by the first communication device based on the session key and the second authentication information, the second message authentication code value being used by the second communication device to authenticate the first communication device.
[0604] In a fifth possible implementation, the transceiver module 1201 is configured to send a first EAP request message to a second communications device, the first EAP request message including a first identity of the first communications device; and receive a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key pool number, a target key identifier, and a second identity of the second communications device, the target key pool number indicating a target key pool in a PSK set, and the target key identifier indicating a PSK in the target key pool. The processing module 1202 is configured to use the PSK indicated by the target key identifier in the target key pool as a target PSK.
[0605] In conjunction with the fifth possible implementation, processing module 1202 is configured to verify the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on a target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a second identity identifier. Transceiver module 1201 is configured to send a second EAP request message to a second communications device, where the second EAP request message includes a second message authentication code value. The second message authentication code value is calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communications device to authenticate the first communications device.
[0606] In a sixth possible implementation, the transceiver module 1201 is configured to send a first EAP request message to a second communication device, the first EAP request message including a key identifier list and a first identity of the first communication device, the key identifier list including multiple key identifiers, each of which indicates a plurality of PSKs in a PSK set; and receive a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a target key identifier and a second identity of the second communication device, the target key identifier being a key identifier in the key identifier list. The processing module 1202 is configured to use a PSK indicated by the target key identifier in the PSK set as a target PSK.
[0607] In conjunction with the sixth possible implementation, processing module 1202 is configured to verify the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes a key identifier list, a target key identifier, and a second identity identifier. Transceiver module 1201 is configured to send a second EAP request message to a second communications device, where the second EAP request message includes a second message authentication code value. The second message authentication code value is calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communications device to authenticate the first communications device.
[0608] In a seventh possible implementation, transceiver module 1201 is configured to send a first EAP request message to a second communication device, the first EAP request message including a first identity of the first communication device; and receive a first EAP response message corresponding to the first EAP request message sent by the second communication device, the first EAP response message including a key identifier list and a second identity of the second communication device, the key identifier list including multiple key identifiers, each of which indicates a plurality of PSKs in a PSK set. Processing module 1202 is configured to select a PSK as a target PSK from the multiple PSKs indicated by the key identifier list. Transceiver module 1201 is configured to send a second EAP request message to the second communication device, the second EAP request message including a target key identifier corresponding to the target PSK.
[0609] In conjunction with the seventh possible implementation, the second EAP request message also includes a first message authentication code value, the first message authentication code value is calculated by the first communication device based on the first authentication information based on a session key, the session key is obtained based on the target PSK, the first authentication information includes a key identifier list, a target key identifier, and a first identity identifier, and the first message authentication code value is used by the second communication device to authenticate the first communication device; the transceiver module 1201 is configured to receive a second EAP response message corresponding to the second EAP request message sent by the second communication device, the second EAP response message including the second message authentication code value; and the processing module 1202 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0610] In an eighth possible implementation, the processing module 1202 is configured to use a key in the PSK set as a target PSK. The transceiver module 1201 is configured to send a first EAP request message to the second communication device, where the first EAP request message includes a target key identifier corresponding to the target PSK and a first identity identifier of the first communication device.
[0611] In conjunction with the eighth possible implementation, the transceiver module 1201 is configured to receive a first EAP response message corresponding to a first EAP request message sent by a second communication device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communication device. The processing module 1202 is configured to verify the first message authentication code value based on a session key and first authentication information, the session key being obtained based on a target PSK, the first authentication information including a target key identifier and a second identity identifier. The transceiver module 1201 is configured to send a second EAP request message to the second communication device, the second EAP request message including a second message authentication code value, the second message authentication code value being calculated by the first communication device based on the session key and the second authentication information, the second message authentication code value being used by the second communication device to authenticate the first communication device.
[0612] In a ninth possible implementation, the transceiver module 1201 is configured to send a first EAP request message to a second communications device, the first EAP request message including a first identity of the first communications device; and receive a first EAP response message corresponding to the first EAP request message sent by the second communications device, the first EAP response message including a target key identifier and a second identity of the second communications device, the target key identifier indicating a PSK in a PSK set. The processing module 1202 is configured to use the PSK indicated by the target key identifier in the PSK set as a target PSK.
[0613] In conjunction with the ninth possible implementation, the first EAP response message also includes a first message authentication code value. Processing module 1202 is configured to verify the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on a target PSK, and the first authentication information includes a target key identifier and a second identity identifier. Transceiver module 1201 is configured to send a second EAP request message to a second communications device. The second EAP request message includes a second message authentication code value. The second message authentication code value is calculated by the first communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the second communications device to authenticate the first communications device.
[0614] For example, Figure 13 This is a schematic diagram of the structure of a second communication device provided in an embodiment of the present application. Figure 13 As shown, the second communication device 1300 includes but is not limited to a transceiver module 1301 and a processing module 1302 .
[0615] The transceiver module 1301 is configured to negotiate with the first communication device to determine a target PSK by receiving an EAP request message from the first communication device and / or sending an EAP response message to the first communication device. The second communication device pre-stores a PSK set including multiple PSKs, and the target PSK is one of the PSKs in the PSK set. The processing module 1302 is configured to authenticate the first communication device based on the target PSK.
[0616] Optionally, the PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
[0617] Optionally, the key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and sent to the second communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
[0618] Optionally, all PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
[0619] Optionally, different PSKs in the PSK set are identified by different key identifiers.
[0620] In a first possible implementation, the PSK set includes multiple key pools. The transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device, the first EAP request message including a key pool number list and a first identity of the first communications device, the key pool number list including multiple key pool numbers; send a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a target key pool number and a second identity of the second communications device, the target key pool number being a key pool number in the key pool number list and indicating a target key pool in the PSK set; and receive a second EAP request message sent by the first communications device, the second EAP request message including a target key identifier indicating a PSK in the target key pool. The processing module 1302 is configured to use the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0621] In combination with the first possible implementation manner, the first EAP response message further includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0622] In conjunction with the first possible implementation, the second EAP request message also includes a first message authentication code value. Processing module 1302 is configured to verify the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on a target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. Transceiver module 1301 is configured to send a second EAP response message corresponding to the second EAP request message to the first communications device. The second EAP response message includes a second message authentication code value. The second message authentication code value is calculated by the second communications device based on the second authentication information based on the session key. The second message authentication code value is used by the first communications device to authenticate the second communications device.
[0623] In a second possible implementation, transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device. The first EAP request message includes a target key pool number and a first identity of the first communications device. The target key pool number indicates a target key pool in a PSK set. Processing module 1302 is configured to obtain a target key pool indicated by the target key pool number from the PSK set and select a PSK from the target key pool as a target PSK. Transceiver module 1301 is configured to send a first EAP response message corresponding to the first EAP request message to the first communications device. The first EAP response message includes a target key identifier corresponding to the target PSK and a second identity of the second communications device.
[0624] In combination with the second possible implementation, the first EAP request message also includes a key identifier list, where the key identifier list includes multiple key identifiers, where the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool. Processing module 1302 is configured to obtain multiple candidate PSKs indicated by the multiple key identifiers from the target key pool, and select a PSK from the multiple candidate PSKs as the target PSK.
[0625] In conjunction with the second possible implementation, the first EAP response message also includes a first message authentication code value, which is calculated by the second communication device based on the first authentication information using a session key, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device. The transceiver module 1301 is configured to receive a second EAP request message sent by the second communication device, the second EAP request message including the second message authentication code value. The processing module 1302 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0626] In a third possible implementation, the transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device, the first EAP request message including a first identity of the first communications device; send a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a target key pool number and a second identity of the second communications device, the target key pool number indicating a target key pool in the PSK set; and receive a second EAP request message sent by the first communications device, the second EAP request message including a target key identifier indicating a PSK in the target key pool. The processing module 1302 is configured to use the PSK indicated by the target key identifier in the target key pool as the target PSK.
[0627] In combination with the third possible implementation manner, the first EAP response message further includes a key identifier list, the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
[0628] In conjunction with the third possible implementation, the second EAP request message also includes a first message authentication code value. Processing module 1302 is configured to verify the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on a target PSK, and the first authentication information includes a target key pool number, a target key identifier, and a first identity identifier. Transceiver module 1301 is configured to send a second EAP response message corresponding to the second EAP request message to the first communications device. The second EAP response message includes a second message authentication code value. The second message authentication code value is calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value is used by the first communications device to authenticate the second communications device.
[0629] In a fourth possible implementation, transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device. The first EAP request message includes a target key pool number, a target key identifier, and a first identity identifier of the first communications device. The target key pool number indicates a target key pool in a PSK set, and the target key identifier indicates a PSK in the target key pool. Processing module 1302 is configured to use the PSK indicated by the target key identifier in the target key pool as a target PSK.
[0630] In conjunction with the fourth possible implementation, the transceiver module 1301 is configured to send a first EAP response message corresponding to a first EAP request message to a first communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device, the first message authentication code value being calculated by the second communications device based on first authentication information using a session key, the session key being obtained based on a target PSK, the first authentication information including a target key pool number, a target key identifier, and the second identity identifier, the first message authentication code value being used by the first communications device to authenticate the second communications device; and receive a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value. The processing module 1302 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0631] In a fifth possible implementation, transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device, the first EAP request message including a first identity of the first communications device. Processing module 1302 is configured to use a key in a target key pool in a PSK set as a target PSK. Transceiver module 1301 is configured to send a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a target key pool number, a target key identifier, and a second identity of the second communications device. The target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool.
[0632] In conjunction with the fifth possible implementation, the first EAP response message also includes a first message authentication code value, which is calculated by the second communication device based on the first authentication information using a session key, the session key being obtained based on the target PSK, the first authentication information including a target key pool number, a target key identifier, and a second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device. The transceiver module 1301 is configured to receive a second EAP request message sent by the first communication device, the second EAP request message including the second message authentication code value. The processing module 1302 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0633] In a sixth possible implementation, a transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device, the first EAP request message including a key identifier list and a first identity of the first communications device, the key identifier list including multiple key identifiers, each of which indicates a plurality of PSKs in a PSK set. A processing module 1302 is configured to select a PSK from the multiple PSKs indicated by the key identifier list as a target PSK. The transceiver module 1301 is configured to send a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a target key identifier corresponding to the target PSK and a second identity of the second communications device.
[0634] In conjunction with the sixth possible implementation, the first EAP response message also includes a first message authentication code value, the first message authentication code value being calculated by the second communication device based on the first authentication information based on a session key, the session key being obtained based on the target PSK, the first authentication information including a key identifier list, a target key identifier, and a second identity identifier, and the first message authentication code value being used by the first communication device to authenticate the second communication device; the transceiver module 1301 is configured to receive a second EAP request message sent by the first communication device, the second EAP request message including the second message authentication code value; and the processing module 1302 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0635] In a seventh possible implementation, a transceiver module 1301 is configured to receive a first EAP request message sent by a first communication device, the first EAP request message including a first identity of the first communication device; send a first EAP response message corresponding to the first EAP request message to the first communication device, the first EAP response message including a key identifier list and a second identity of the second communication device, the key identifier list including multiple key identifiers, each of which indicates a plurality of PSKs in a PSK set; and receive a second EAP request message sent by the first communication device, the second EAP request message including a target key identifier, the target key identifier being a key identifier in the key identifier list. A processing module 1302 is configured to use a PSK indicated by the target key identifier in the PSK set as a target PSK.
[0636] In conjunction with the seventh possible implementation, the second EAP request message also includes a first message authentication code value. Processing module 1302 is configured to verify the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on a target PSK, and the first authentication information includes a key identifier list, a target key identifier, and a first identity identifier. Transceiver module 1301 is configured to send a second EAP response message corresponding to the second EAP request message to the first communications device. The second EAP response message includes a second message authentication code value, the second message authentication code value being calculated by the second communications device based on the second authentication information based on the session key, and the second message authentication code value being used by the first communications device to authenticate the second communications device.
[0637] In an eighth possible implementation, a transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device, where the first EAP request message includes a target key identifier and a first identity identifier of the first communications device, where the target key identifier indicates a PSK in a PSK set. A processing module 1302 is configured to use the PSK indicated by the target key identifier in the PSK set as a target PSK.
[0638] In conjunction with the eighth possible implementation, after the program instructions are read by at least one processor, the transceiver module 1301 is configured to send a first EAP response message corresponding to a first EAP request message to a first communications device, the first EAP response message including a first message authentication code value and a second identity identifier of the second communications device, the first message authentication code value being calculated by the second communications device based on first authentication information using a session key, the session key being obtained based on a target PSK, the first authentication information including a target key identifier and a second identity identifier, and the first message authentication code value being used by the first communications device to authenticate the second communications device; and receive a second EAP request message sent by the first communications device, the second EAP request message including a second message authentication code value. The processing module 1302 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0639] In a ninth possible implementation, the transceiver module 1301 is configured to receive a first EAP request message sent by a first communications device, the first EAP request message including a first identity of the first communications device. The processing module 1302 is configured to use a key in a PSK set as a target PSK. The transceiver module 1301 is configured to send a first EAP response message corresponding to the first EAP request message to the first communications device, the first EAP response message including a target key identifier corresponding to the target PSK and a second identity of the second communications device.
[0640] In conjunction with the ninth possible implementation, the first EAP response message also includes a first message authentication code value, the first message authentication code value being calculated by the second communication device based on the first authentication information based on a session key, the session key being obtained based on the target PSK, the first authentication information including a target key identifier and a second identity identifier, and the first message authentication code value being used by the first communication device to authenticate the second communication device; the transceiver module 1301 is configured to receive a second EAP request message sent by the first communication device, the second EAP request message including the second message authentication code value; and the processing module 1302 is configured to verify the second message authentication code value based on the session key and the second authentication information.
[0641] Regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0642] The following is an illustration of the hardware device of the embodiment of the present application.
[0643] For example, Figure 14 This is a hardware structure diagram of a communication device provided in an embodiment of the present application. Figure 14As shown, the communication device 1400 includes a processor 1401 and a memory 1402 , and the memory 1401 and the memory 1402 are connected via a bus 1403 . Figure 14 The processor 1401 and the memory 1402 are described as being independent of each other. Optionally, the processor 1401 and the memory 1402 are integrated together. Figure 5 Come and see, Figure 14 The communication device 1400 is Figure 5 The first communication device or the second communication device shown.
[0644] Memory 1402 is used to store computer programs, including operating systems and program code. Memory 1402 is various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical storage, registers, optical disk storage, optical disc storage, magnetic disk, or other magnetic storage devices.
[0645] Processor 1401 is a general-purpose processor or a dedicated processor. Processor 1401 may be a single-core processor or a multi-core processor. Processor 1401 includes at least one circuit to execute the actions performed by the first communication device and / or the second communication device in the above method embodiments provided in the embodiments of the present application.
[0646] Optionally, communication device 1400 further includes a network interface 1404, which is connected to processor 1401 and memory 1402 via bus 1403. Network interface 1404 enables communication device 1400 to communicate with a quantum device or other communication devices. Processor 1401 can interact with the quantum device through network interface 1404 to obtain quantum keys, etc., and communicate with other communication devices.
[0647] Optionally, communication device 1400 further includes an input / output (I / O) interface 1405, which is connected to processor 1401 and memory 1402 via bus 1403. Processor 1401 can receive input commands or data through I / O interface 1405. I / O interface 1405 is used to connect communication device 1400 to input devices, such as a keyboard and a mouse. Optionally, in some possible scenarios, the network interface 1404 and I / O interface 1405 are collectively referred to as a communication interface.
[0648] Optionally, the communication device 1400 further includes a display 1406, which is connected to the processor 1401 and the memory 1402 via the bus 1403. The display 1406 can be used to display intermediate results and / or final results generated by the processor 1401 executing the above method. In one possible implementation, the display 1406 is a touch screen display to provide a human-computer interaction interface.
[0649] The bus 1403 is any type of communication bus for interconnecting the internal components of the communication device 1400, such as a system bus. The embodiments of the present application illustrate the example of interconnecting the aforementioned components within the communication device 1400 via the bus 1403. Alternatively, the aforementioned components within the communication device 1400 may be communicatively connected to each other using other connection methods besides the bus 1403, such as interconnecting the aforementioned components within the communication device 1400 via a logical interface within the communication device 1400.
[0650] The above-mentioned devices can be provided on separate chips, or at least partially or entirely on the same chip. Whether to provide each device independently on different chips or to integrate them on one or more chips often depends on the product design requirements. The embodiments of this application do not limit the specific implementation of the above-mentioned devices.
[0651] Figure 14 The communication device 1400 shown is merely exemplary. During implementation, the communication device 1400 includes other components, which are not listed here one by one. Figure 14 The communication device 1400 shown can implement EAP-based authentication by executing all or part of the steps of the method provided in the above embodiment.
[0652] The following is an example of the system in the embodiment of the present application.
[0653] An embodiment of the present application provides a communication system, which includes a first communication device and a second communication device. The first communication device pre-stores a first PSK set, and the second communication device pre-stores a second PSK set. The first PSK set and the second PSK set respectively include multiple PSKs.
[0654] The first communication device is used to execute the steps executed by the first communication device in the above method embodiment, and the second communication device is used to execute the steps executed by the first communication device and / or the second communication device in the above method embodiment.
[0655] An embodiment of the present application further provides a computer-readable storage medium having instructions stored thereon. When the instructions are executed by a processor, the steps performed by the first communication device and / or the second communication device in the above method embodiment are implemented.
[0656] An embodiment of the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the computer program implements the steps performed by the first communication device and / or the second communication device in the above method embodiment.
[0657] An embodiment of the present application further provides a chip, which includes a programmable logic circuit and / or program instructions. When the chip is running, it implements the steps performed by the first communication device and / or the second communication device in the above method embodiment.
[0658] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
[0659] In the embodiments of the present application, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.
[0660] In this application, the term "and / or" simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0661] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0662] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. An authentication method based on the Extensible Authentication Protocol (EAP), characterized in that: The method comprises: The first communication device negotiates with the second communication device to determine a target pre-shared key (PSK) by sending an EAP request message to the second communication device and / or receiving an EAP response message sent by the second communication device, wherein a PSK set is pre-stored in the first communication device, the PSK set including multiple PSKs, and the target PSK is one of the PSKs in the PSK set; The first communication device performs identity authentication on the second communication device based on the target PSK.
2. The method according to claim 1, characterized in that The PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
3. The method according to claim 2, characterized in that The key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and then sent to the first communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
4. The method according to claim 2 or 3, characterized in that All PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
5. The method according to claim 1, wherein Different PSKs in the PSK set are identified by using different key identifiers.
6. The method according to any one of claims 2 to 4, characterized in that: The PSK set includes multiple key pools, and the first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device to negotiate with the second communication device to determine a target PSK, including: The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a key pool number list and a first identity of the first communication device, where the key pool number list includes multiple key pool numbers, and the multiple key pool numbers respectively indicate multiple key pools in the PSK set; The first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a target key pool number and a second identity of the second communication device, where the target key pool number is a key pool number in the key pool number list; The first communication device obtains the target key pool indicated by the target key pool number from the PSK set, and selects a PSK from the target key pool as the target PSK; The first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a target key identifier corresponding to the target PSK.
7. The method according to any one of claims 2 to 4, characterized in that: The first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine a target PSK, including: The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a target key pool number and a first identity identifier of the first communication device, where the target key pool number indicates a target key pool in the PSK set; The first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a target key identifier and a second identity identifier of the second communication device, where the target key identifier indicates a PSK in the target key pool; The first communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
8. The method according to claim 7, characterized in that The first EAP request message further includes a key identifier list, where the key identifier list includes multiple key identifiers, each of which is used to indicate a plurality of PSKs in the target key pool; and the target key identifier is a key identifier in the key identifier list.
9. The method according to any one of claims 2 to 4, characterized in that: The first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine a target PSK, including: The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a first identity identifier of the first communication device; The first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a target key pool number and a second identity of the second communication device, where the target key pool number indicates a target key pool in the PSK set; The first communication device obtains the target key pool indicated by the target key pool number from the PSK set, and selects a PSK from the target key pool as the target PSK; The first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a target key identifier corresponding to the target PSK.
10. The method according to claim 6 or 9, characterized in that The first EAP response message further includes a key identifier list, where the key identifier list includes multiple key identifiers, where the multiple key identifiers respectively indicate multiple PSKs in the target key pool, and the first communications device selects a PSK from the target key pool as the target PSK, including: The first communication device obtains a plurality of candidate PSKs indicated by the plurality of key identifiers from the target key pool, and selects one PSK from the plurality of candidate PSKs as the target PSK.
11. The method according to claim 6, 9 or 10, characterized in that The second EAP request message further includes a first message authentication code value, where the first message authentication code value is calculated by the first communication device based on a session key based on first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the first identity identifier, and the first message authentication code value is used by the second communication device to authenticate the first communication device. The method further includes: The first communication device receives a second EAP response message corresponding to the second EAP request message sent by the second communication device, where the second EAP response message includes a second message authentication code value; The first communication device performs identity authentication on the second communication device based on the target PSK, including: The first communication device verifies the second message authentication code value based on the session key and second authentication information.
12. The method according to any one of claims 2 to 4, characterized in that: The first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine a target PSK in the PSK set, including: The first communication device uses a key in the target key pool in the PSK set as the target PSK; The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a target key pool number corresponding to the target key pool, a target key identifier corresponding to the target PSK, and a first identity identifier of the first communication device.
13. The method according to claim 12, characterized in that The method further comprises: The first communication device receives, by the second communication device, a first EAP response message corresponding to the first EAP request message, where the first EAP response message includes a first message authentication code value and a second identity identifier of the second communication device; The first communication device performs identity authentication on the second communication device based on the target PSK, including: The first communication device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier; The method further comprises: The first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the session key and second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
14. The method according to any one of claims 2 to 4, characterized in that: The first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine a target PSK in the PSK set, including: The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a first identity identifier of the first communication device; The first communications device receives, the first EAP response message corresponding to the first EAP request message sent by the second communications device, where the first EAP response message includes a target key pool number, a target key identifier, and a second identity identifier of the second communications device, the target key pool number indicating a target key pool in the PSK set, and the target key identifier indicating a PSK in the target key pool; The first communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
15. The method according to claim 7, 8 or 14, characterized in that The first EAP response message further includes a first message authentication code value, and the first communication device performs identity authentication on the second communication device based on the target PSK, including: The first communication device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier; The method further comprises: The first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the session key and second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
16. The method according to claim 5, characterized in that The first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine a target PSK in the PSK set, including: The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a key identifier list and a first identity identifier of the first communication device, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; The first communication device receives a first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a target key identifier and a second identity identifier of the second communication device, where the target key identifier is a key identifier in the key identifier list; The first communication device uses the PSK indicated by the target key identifier in the PSK set as the target PSK.
17. The method according to claim 16, characterized in that The first EAP response message further includes a first message authentication code value, and the first communication device performs identity authentication on the second communication device based on the target PSK, including: The first communication device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the second identity identifier; The method further comprises: The first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a second message authentication code value, where the second message authentication code value is calculated by the first communication device based on the session key and second authentication information, and the second message authentication code value is used by the second communication device to authenticate the first communication device.
18. The method according to claim 5, characterized in that The first communication device sends an EAP request message to the second communication device and / or receives an EAP response message sent by the second communication device, and negotiates with the second communication device to determine a target PSK in the PSK set, including: The first communication device sends a first EAP request message to the second communication device, where the first EAP request message includes a first identity identifier of the first communication device; The first communication device receives, the first EAP response message corresponding to the first EAP request message sent by the second communication device, where the first EAP response message includes a key identifier list and a second identity identifier of the second communication device, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; The first communication device selects a PSK from a plurality of PSKs indicated by the key identification list as the target PSK; The first communication device sends a second EAP request message to the second communication device, where the second EAP request message includes a target key identifier corresponding to the target PSK.
19. The method according to claim 18, characterized in that The second EAP request message further includes a first message authentication code value, where the first message authentication code value is calculated by the first communication device based on a session key based on first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the first identity identifier, and the first message authentication code value is used by the second communication device to authenticate the first communication device. The method further includes: The first communication device receives a second EAP response message corresponding to the second EAP request message sent by the second communication device, where the second EAP response message includes a second message authentication code value; The first communication device performs identity authentication on the second communication device based on the target PSK, including: The first communication device verifies the second message authentication code value based on the session key and second authentication information.
20. An authentication method based on the Extensible Authentication Protocol (EAP), characterized in that: The method comprises: The second communication device negotiates with the first communication device to determine a target pre-shared key (PSK) by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, wherein a PSK set is pre-stored in the second communication device, the PSK set including multiple PSKs, and the target PSK is one of the PSKs in the PSK set; The second communication device performs identity authentication on the first communication device based on the target PSK.
21. The method according to claim 20, characterized in that The PSK set includes one or more key pools, each key pool includes one or more PSKs, wherein different key pools are identified by different key pool numbers, and different PSKs in the same key pool are identified by different key identifiers.
22. The method according to claim 21, characterized in that The key pool is obtained through pre-configuration or pre-negotiation, or the key pool is generated by a key distribution network and then sent to the second communication device; wherein, for the key pool generated by the key distribution network, the key pool number corresponding to the key pool is used to indicate the key distribution network and / or key distribution device that generates the key pool.
23. The method according to claim 21 or 22, characterized in that All PSKs in the same key pool are classical keys or quantum keys, and the key pool number corresponding to the key pool is used to indicate whether the PSKs in the key pool are classical keys or quantum keys.
24. The method according to claim 20, characterized in that Different PSKs in the PSK set are identified by different key identifiers.
25. The method according to any one of claims 21 to 23, characterized in that The PSK set includes multiple key pools, and the second communication device negotiates with the first communication device to determine the PSK by receiving an EAP request message sent by the first communication device and / or sending an EAP response message to the first communication device, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a key pool number list and a first identity identifier of the first communication device, where the key pool number list includes multiple key pool numbers; The second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key pool number and a second identity of the second communication device, where the target key pool number is a key pool number in the key pool number list, and the target key pool number indicates a target key pool in the PSK set; The second communication device receives a second EAP request message sent by the first communication device, where the second EAP request message includes a target key identifier, where the target key identifier indicates a PSK in the target key pool; The second communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
26. The method according to any one of claims 21 to 23, characterized in that The second communication device receives an EAP request message sent by the first communication device and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the PSK, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a target key pool number and a first identity identifier of the first communication device, where the target key pool number indicates a target key pool in the PSK set; The second communication device obtains the target key pool indicated by the target key pool number from the PSK set, and selects a PSK from the target key pool as the target PSK; The second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key identifier corresponding to the target PSK and a second identity identifier of the second communication device.
27. The method according to claim 26, characterized in that The first EAP request message further includes a key identifier list, where the key identifier list includes multiple key identifiers, where the multiple key identifiers are respectively used to indicate multiple PSKs in the target key pool, and the second communication device selects a PSK from the target key pool as the target PSK, including: The second communication device obtains a plurality of candidate PSKs indicated by the plurality of key identifiers from the target key pool, and selects one PSK from the plurality of candidate PSKs as the target PSK.
28. The method according to any one of claims 21 to 23, characterized in that The second communication device receives an EAP request message sent by the first communication device and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the PSK, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a first identity identifier of the first communication device; The second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key pool number and a second identity of the second communication device, where the target key pool number indicates a target key pool in the PSK set; The second communication device receives a second EAP request message sent by the first communication device, where the second EAP request message includes a target key identifier, where the target key identifier indicates a PSK in the target key pool; The second communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
29. The method according to claim 25 or 28, characterized in that The first EAP response message further includes a key identifier list, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the target key pool; the target key identifier is a key identifier in the key identifier list.
30. The method according to claim 25, 28 or 29, characterized in that The second EAP request message further includes a first message authentication code value, and the second communication device performs identity authentication on the first communication device based on the target PSK, including: The second communication device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the first identity identifier; The method further comprises: The second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device, where the second EAP response message includes a second message authentication code value, where the second message authentication code value is calculated by the second communication device based on the session key and the second authentication information, and the second message authentication code value is used by the first communication device to authenticate the second communication device.
31. The method according to any one of claims 21 to 23, characterized in that The second communication device receives an EAP request message sent by the first communication device and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the PSK, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a target key pool number, a target key identifier, and a first identity identifier of the first communication device, where the target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool; The second communication device uses the PSK indicated by the target key identifier in the target key pool as the target PSK.
32. The method according to claim 31, characterized in that The method further comprises: The second communications device sends a first EAP response message corresponding to the first EAP request message to the first communications device, where the first EAP response message includes a first message authentication code value and a second identity identifier of the second communications device, where the first message authentication code value is calculated by the second communications device based on a session key on first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier, and the first message authentication code value is used by the first communications device to authenticate the second communications device; The second communication device receives a second EAP request message sent by the first communication device, where the second EAP request message includes a second message authentication code value; The second communication device performs identity authentication on the first communication device based on the target PSK, including: The second communication device verifies the second message authentication code value based on the session key and second authentication information.
33. The method according to any one of claims 21 to 23, characterized in that The second communication device receives an EAP request message sent by the first communication device and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the PSK, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a first identity identifier of the first communication device; The second communication device uses a key in the target key pool in the PSK set as the target PSK; The second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key pool number, a target key identifier, and a second identity identifier of the second communication device, where the target key pool number indicates a target key pool in the PSK set, and the target key identifier indicates a PSK in the target key pool.
34. The method according to claim 26, 27 or 33, characterized in that The first EAP response message further includes a first message authentication code value, the first message authentication code value is calculated by the second communication device based on a session key on first authentication information, the session key is obtained based on the target PSK, the first authentication information includes the target key pool number, the target key identifier, and the second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device; the method further includes: The second communication device receives a second EAP request message sent by the first communication device, where the second EAP request message includes a second message authentication code value; The second communication device performs identity authentication on the first communication device based on the target PSK, including: The second communication device verifies the second message authentication code value based on the session key and second authentication information.
35. The method according to claim 24, wherein The second communication device receives an EAP request message sent by the first communication device and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the PSK, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a key identifier list and a first identity identifier of the first communication device, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; The second communication device selects a PSK from the multiple PSKs indicated by the key identification list as the target PSK; The second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a target key identifier corresponding to the target PSK and a second identity identifier of the second communication device.
36. The method according to claim 35, characterized in that The first EAP response message further includes a first message authentication code value, the first message authentication code value is calculated by the second communication device based on a session key on first authentication information, the session key is obtained based on the target PSK, the first authentication information includes the key identifier list, the target key identifier, and the second identity identifier, and the first message authentication code value is used by the first communication device to authenticate the second communication device; the method further includes: The second communication device receives a second EAP request message sent by the first communication device, where the second EAP request message includes a second message authentication code value; The second communication device performs identity authentication on the first communication device based on the target PSK, including: The second communication device verifies the second message authentication code value based on the session key and second authentication information.
37. The method according to claim 24, wherein The second communication device receives an EAP request message sent by the first communication device and / or sends an EAP response message to the first communication device, and negotiates with the first communication device to determine the PSK, including: The second communication device receives a first EAP request message sent by the first communication device, where the first EAP request message includes a first identity identifier of the first communication device; The second communication device sends a first EAP response message corresponding to the first EAP request message to the first communication device, where the first EAP response message includes a key identifier list and a second identity identifier of the second communication device, where the key identifier list includes multiple key identifiers, and the multiple key identifiers respectively indicate multiple PSKs in the PSK set; The second communication device receives a second EAP request message sent by the first communication device, where the second EAP request message includes a target key identifier, where the target key identifier is a key identifier in the key identifier list; The second communication device uses the PSK indicated by the target key identifier in the PSK set as the target PSK.
38. The method according to claim 37, wherein The second EAP request message further includes a first message authentication code value, and the second communication device performs identity authentication on the first communication device based on the target PSK, including: The second communication device verifies the first message authentication code value based on a session key and first authentication information, where the session key is obtained based on the target PSK, and the first authentication information includes the key identifier list, the target key identifier, and the first identity identifier; The method further comprises: The second communication device sends a second EAP response message corresponding to the second EAP request message to the first communication device, where the second EAP response message includes a second message authentication code value, where the second message authentication code value is calculated by the second communication device based on the session key and the second authentication information, and the second message authentication code value is used by the first communication device to authenticate the second communication device.
39. A communication device, characterized in that: include: memory, a network interface, and at least one processor, The memory is used to store program instructions, After the at least one processor reads the program instructions stored in the memory, it causes the communication device to execute the method according to any one of claims 1 to 38.
40. A communication system, characterized in that The communication system includes a first communication device and a second communication device, wherein the first communication device pre-stores a first pre-shared key (PSK) set, and the second communication device pre-stores a second PSK set, wherein the first PSK set and the second PSK set each include multiple PSKs; The first communication device is used to execute the method according to any one of claims 1 to 19, and the second communication device is used to execute the method according to any one of claims 20 to 38.
41. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 38 is implemented.
Citation Information
Cited By
Post-quantum secure media access control security (macsec) pre-shared key auto-refresh
US20260081767A1