Equipment authentication method and device applied to TCP (Transmission Control Protocol) connection
By modifying the SYN message Option of the TCP connection and the encryption verification process, combining it with the symmetric key to generate ciphertext data, and using the target party's SYN ACK message sequence number as the challenge random number, the reliability and security issues of device authentication in the TCP connection are solved, and efficient device authentication is achieved.
Patent Information
- Application Number
- CN202510925085.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-09-12
AI Technical Summary
Existing knocking technology has problems such as inaccurate IP addresses in TCP connections and easy loss and replay of UDP knocking packets, resulting in unreliable device authentication.
By modifying the Option field in the SYN message and using symmetric key encryption to generate ciphertext data, device authentication is performed during the TCP handshake process. The sequence number of the target party's SYN ACK message is used as a random challenge number to prevent replay attacks.
This enables more accurate device authentication in TCP connections, improves overall reliability and security, and avoids knock packet loss and replay attacks.
Smart Images

Figure CN120639422A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a device authentication method and apparatus applied to a TCP connection. Background Art
[0002] TCP ports are exposed to the internet, accessible to any user and posing a significant threat to attackers. Zero Trust solutions introduce knocking technology. Its core concept is to temporarily open the firewall only after receiving a "knocking request" in a specific format, and then close it after use. Existing knocking technology uses Single Packet Authorization (SPA), or sends a port sequence, temporarily granting access after server-side verification.
[0003] In practice, knocking is typically performed using independent UDP packets. The firewall is then opened to allow the IP address of the knocking party to pass through, and then the firewall is closed after a period of time. Because NAT technology is common, multiple users may have the same address behind NAT, making filtering based solely on the knocking party's IP address inaccurate. Furthermore, independent UDP knock packets may be lost, causing knock failure. Independent UDP knock packets can also be intercepted and replayed, potentially allowing authentication to be deceived.
[0004] Therefore, in order to meet actual needs, a device authentication technology applied to TCP connections is now provided. Summary of the Invention
[0005] In response to the defects in the existing technology, the purpose of this application is to provide a device authentication method and device for TCP connection. By modifying the Option options of the SYN message and coordinating with a specific encryption verification process, the technical effect of TCP knocking is achieved to meet the actual work requirements of device authentication.
[0006] In order to achieve the above objectives, the technical solution adopted by this application is:
[0007] In a first aspect, the present application provides a device authentication method applied to a TCP connection, the method comprising the following steps:
[0008] The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, and generates corresponding first ciphertext data by combining it with the symmetric key encryption;
[0009] The first terminal device adds the first ciphertext data to the Option option of the SYN message corresponding to the first handshake in the TCP connection, and then sends the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device;
[0010] The second terminal receives the SYN message corresponding to the first handshake in the TCP connection sent by the first terminal device and the first ciphertext data, and obtains the sequence number of the SYN message corresponding to the first handshake in the TCP connection;
[0011] The second terminal device encrypts and generates corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key;
[0012] When the first ciphertext data is consistent with the second ciphertext data, it is determined that the TCP SYN message knocking is completed between the first terminal device and the second terminal; otherwise, the response is terminated.
[0013] On the basis of the above technical solution, the method further comprises the following steps:
[0014] After the TCP SYN message knocking is completed between the first terminal device and the second terminal, the second terminal device returns a SYN ACK message corresponding to the second handshake in the TCP connection to the first terminal device.
[0015] On the basis of the above technical solution, the method further comprises the following steps:
[0016] The first terminal device obtains the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and generates corresponding third ciphertext data by combining it with the symmetric key encryption;
[0017] The first terminal device adds the third ciphertext data to the Option option of the ACK message corresponding to the third handshake in the TCP connection, and then sends the ACK message corresponding to the third handshake in the TCP connection and the third ciphertext data to the second terminal device;
[0018] The second terminal receives the ACK message and the third ciphertext data corresponding to the third handshake in the TCP connection sent by the first terminal device, and obtains the sequence number of the ACK message corresponding to the third handshake in the TCP connection;
[0019] The second terminal device encrypts and generates corresponding fourth ciphertext data based on the sequence number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key;
[0020] When the third ciphertext data is consistent with the fourth ciphertext data, it is determined that the TCP three-way handshake is completed between the first terminal device and the second terminal and service communication is established; otherwise, the response is terminated.
[0021] On the basis of the above technical solution, the method further comprises the following steps:
[0022] The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, generates corresponding encrypted data by combining it with the symmetric key encryption, and intercepts the first 8 bytes to obtain the corresponding first ciphertext data;
[0023] The second terminal device encrypts and generates corresponding encrypted data based on the serial number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key, and intercepts the first 8 bytes to obtain the corresponding second ciphertext data.
[0024] On the basis of the above technical solution, the method further comprises the following steps:
[0025] The first terminal device obtains the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, generates corresponding encrypted data by combining it with the symmetric key encryption, and intercepts the first 8 bytes to obtain the corresponding third ciphertext data;
[0026] The second terminal device encrypts and generates corresponding encrypted data based on the serial number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key, and intercepts the first 8 bytes to obtain the corresponding fourth ciphertext data.
[0027] In a second aspect, the present application provides a device authentication apparatus for a TCP connection, the apparatus comprising:
[0028] A first authentication module, which is used to control the first terminal device to obtain the sequence number in the TCP SYN message and generate corresponding first ciphertext data in combination with the symmetric key encryption;
[0029] The first authentication module is further configured to control the first terminal device to add the first ciphertext data to an Option option of the SYN message corresponding to the first handshake in the TCP connection, and then send the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device;
[0030] a second authentication module, configured to control the second terminal to receive the SYN message and the first ciphertext data corresponding to the first handshake in the TCP connection sent by the first terminal device, and obtain the sequence number of the SYN message corresponding to the first handshake in the TCP connection;
[0031] The second authentication module is further configured to control the second terminal device to encrypt and generate corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key;
[0032] The authentication determination module is used to determine that the TCP SYN message knocking is completed between the first terminal device and the second terminal when the first ciphertext data is consistent with the second ciphertext data, and otherwise terminate the response.
[0033] Based on the above technical solution, the second authentication module is also used to control the second terminal device to return the SYN ACK message corresponding to the second handshake in the TCP connection to the first terminal device after the TCP SYN message knocking is completed between the first terminal device and the second terminal.
[0034] On the basis of the above technical solution, the first authentication module is further used for the first terminal device to obtain the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and generate corresponding third ciphertext data by combining with the symmetric key encryption;
[0035] The first authentication module is further configured to control the first terminal device to add the third ciphertext data to an Option option of an ACK message corresponding to the third handshake in the TCP connection, and then send the ACK message corresponding to the third handshake in the TCP connection and the third ciphertext data to the second terminal device;
[0036] The second authentication module is further configured to receive, by the second terminal, the ACK message and the third ciphertext data corresponding to the third handshake in the TCP connection sent by the first terminal device, and obtain the sequence number of the ACK message corresponding to the third handshake in the TCP connection;
[0037] The second authentication module is further configured to control the second terminal device to encrypt and generate corresponding fourth ciphertext data based on the sequence number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key;
[0038] The authentication determination module is further configured to determine that the TCP three-way handshake is completed between the first terminal device and the second terminal and service communication is established when the third ciphertext data is consistent with the fourth ciphertext data; otherwise, terminate the response.
[0039] Based on the above technical solution, the first authentication module is further used to control the first terminal device to obtain the sequence number in the SYN message corresponding to the first handshake in the TCP connection, and generate corresponding encrypted data by combining with the symmetric key encryption, and intercept the first 8 bytes to obtain the corresponding first ciphertext data;
[0040] The second authentication module is also used to control the second terminal device to encrypt and generate corresponding encrypted data based on the serial number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key, and intercept the first 8 bytes to obtain the corresponding second ciphertext data.
[0041] Based on the above technical solution, the first authentication module is further used to control the first terminal device to obtain the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and generate corresponding encrypted data by combining it with the symmetric key encryption, and intercept the first 8 bytes to obtain the corresponding third ciphertext data;
[0042] The second authentication module is also used to control the second terminal device to encrypt and generate corresponding encrypted data based on the serial number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key, and intercept the first 8 bytes to obtain the corresponding fourth ciphertext data.
[0043] Compared with the prior art, the advantages of this application are:
[0044] By modifying the Option options of the SYN message and coordinating it with a specific encryption verification process, the technical effect of TCP knocking is achieved, meeting the actual work requirements of device authentication.
[0045] During the third handshake in the TCP connection, the requester uses the sequence number of the target party's corresponding SYN ACK message to encrypt and generate the corresponding ciphertext data, and feeds it back to the target party, thereby achieving the technical effect of anti-replay and further improving the overall reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0047] Figure 1 A schematic diagram of the system architecture of a device authentication method applied to a TCP connection according to an embodiment of the present application;
[0048] Figure 2This is a schematic diagram of the message header structure of a SYN message corresponding to the first handshake in a TCP connection in a device authentication method applied to a TCP connection in an embodiment of the present application;
[0049] Figure 3 A schematic diagram of the message header structure of a SYN ACK message corresponding to the second handshake in a TCP connection in a device authentication method applied to a TCP connection according to an embodiment of the present application;
[0050] Figure 4 This is a schematic diagram of the message header structure of an ACK message corresponding to the third handshake in a TCP connection in a device authentication method applied to a TCP connection in an embodiment of the present application;
[0051] Figure 5 This is a flow chart of device identity authentication and symmetric key distribution in a device authentication method applied to a TCP connection according to an embodiment of the present application;
[0052] Figure 6 This is a flow chart of terminal device mutual access authentication in a device authentication method applied to a TCP connection in an embodiment of the present application;
[0053] Figure 7 This is a structural block diagram of a device authentication apparatus applied to a TCP connection according to an embodiment of the present application. DETAILED DESCRIPTION
[0054] Explanation of terms:
[0055] TCP: Transmission Control Protocol;
[0056] SYN: Synchronize Sequence Numbers, synchronization sequence number;
[0057] ACK: Acknowledge character, confirmation character;
[0058] SPA: Single Packet Authorization, single packet authorization;
[0059] UDP: User Datagram Protocol, User Datagram Protocol;
[0060] IP: Internet Protocol, Internet interconnection protocol;
[0061] NAT: Network Address Translation;
[0062] CA: Certificate Authority, certification center;
[0063] TD: Terminal Device, terminal device.
[0064] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0065] The embodiments of the present application are further described in detail below with reference to the accompanying drawings.
[0066] The embodiment of the present application provides a device authentication method and apparatus for TCP connection, which realizes the technical effect of TCP knocking by modifying the Option option of the SYN message and cooperating with a specific encryption verification process, thereby meeting the actual work requirements of device authentication.
[0067] To achieve the above technical effects, the overall idea of this application is as follows:
[0068] A device authentication method applied to a TCP connection, the method comprising the following steps:
[0069] S1. The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, and generates the corresponding first ciphertext data by combining it with the symmetric key encryption;
[0070] S2. The first terminal device adds the first ciphertext data to the Option option of the SYN message corresponding to the first handshake in the TCP connection, and then sends the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device;
[0071] S3. The second terminal receives the SYN message and the first ciphertext data corresponding to the first handshake in the TCP connection sent by the first terminal device, and obtains the sequence number of the SYN message corresponding to the first handshake in the TCP connection;
[0072] S4. The second terminal device encrypts and generates corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key;
[0073] S5. When the first ciphertext data is consistent with the second ciphertext data, it is determined that the TCP SYN message knocking is completed between the first terminal device and the second terminal; otherwise, the response is terminated.
[0074] The embodiments of the present application are further described in detail below with reference to the accompanying drawings.
[0075] First, see Figures 1 to 6 As shown, the present application provides a device authentication method applied to a TCP connection, the method comprising the following steps:
[0076] S1. The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, and generates the corresponding first ciphertext data by combining it with the symmetric key encryption;
[0077] S2. The first terminal device adds the first ciphertext data to the Option option of the SYN message corresponding to the first handshake in the TCP connection, and then sends the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device;
[0078] S3. The second terminal receives the SYN message and the first ciphertext data corresponding to the first handshake in the TCP connection sent by the first terminal device, and obtains the sequence number of the SYN message corresponding to the first handshake in the TCP connection;
[0079] S4. The second terminal device encrypts and generates corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key;
[0080] S5. When the first ciphertext data is consistent with the second ciphertext data, it is determined that the TCP SYN message knocking is completed between the first terminal device and the second terminal; otherwise, the response is terminated.
[0081] In the embodiment of the present application, by modifying the Option option of the SYN message and coordinating it with a specific encryption verification process, the technical effect of TCP knocking is achieved, meeting the actual work requirements of device authentication.
[0082] Furthermore, the method further comprises the following steps:
[0083] After the TCP SYN message knocking is completed between the first terminal device and the second terminal, the second terminal device returns a SYN ACK message corresponding to the second handshake in the TCP connection to the first terminal device.
[0084] Furthermore, the method further comprises the following steps:
[0085] The first terminal device obtains the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and generates corresponding third ciphertext data by combining it with the symmetric key encryption;
[0086] The first terminal device adds the third ciphertext data to the Option option of the ACK message corresponding to the third handshake in the TCP connection, and then sends the ACK message corresponding to the third handshake in the TCP connection and the third ciphertext data to the second terminal device;
[0087] The second terminal receives the ACK message and the third ciphertext data corresponding to the third handshake in the TCP connection sent by the first terminal device, and obtains the sequence number of the ACK message corresponding to the third handshake in the TCP connection;
[0088] The second terminal device encrypts and generates corresponding fourth ciphertext data based on the sequence number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key;
[0089] When the third ciphertext data is consistent with the fourth ciphertext data, it is determined that the TCP three-way handshake is completed between the first terminal device and the second terminal and service communication is established; otherwise, the response is terminated.
[0090] It should be noted that during the third handshake in the TCP connection, the requester uses the sequence number of the target party's corresponding SYN ACK message to encrypt and generate the corresponding ciphertext data, and feeds it back to the target party.
[0091] At this time, the ciphertext data is not generated based on the serial number of the requesting party's message, which aims to achieve the technical effect of anti-replay and further improve the overall reliability.
[0092] Furthermore, the method further comprises the following steps:
[0093] The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, generates corresponding encrypted data by combining it with the symmetric key encryption, and intercepts the first 8 bytes to obtain the corresponding first ciphertext data;
[0094] The second terminal device encrypts and generates corresponding encrypted data based on the serial number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key, and intercepts the first 8 bytes to obtain the corresponding second ciphertext data.
[0095] It should be noted that you can also choose to intercept the first 4 bytes. The specific solution can be selected according to the actual situation. Intercepting the first 4 bytes is slightly less difficult to crack than intercepting the first 8 bytes.
[0096] Furthermore, the method further comprises the following steps:
[0097] The first terminal device obtains the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, generates corresponding encrypted data by combining it with the symmetric key encryption, and intercepts the first 8 bytes to obtain the corresponding third ciphertext data;
[0098] The second terminal device encrypts and generates corresponding encrypted data based on the serial number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key, and intercepts the first 8 bytes to obtain the corresponding fourth ciphertext data.
[0099] The technical solution of the embodiments of the present application, for TCP communication, does not require a separate UDP packet for knocking. Instead, the requester transmits the knock data within the Option field of the TCP SYN header. This way, the knock is targeted only at the current TCP connection, which is more accurate and eliminates the need to disable firewalls. The knock data is embedded within the communication data packet, eliminating the problem of knock packet loss.
[0100] To mitigate the risk of knock data replay, the sequence in the target's TCP SYN-ACK packet is used as the challenge random number. In the ACK packet of the third handshake, the requester again includes authentication data in the TCP Option. Because the sequence in the TCP SYN-ACK packet is the one sent by the target, the requester cannot spoof the knock by replaying it. The knock data is included in the TCP Option, eliminating the need to modify the TCP-based application layer protocol, making it compatible with various existing application protocols.
[0101] Compared with the prior art, the technical solutions of the embodiments of the present application overcome the following technical difficulties:
[0102] Difficulty 1:
[0103] The current TCP Option standard doesn't define the data format for "knock authentication," so the TCP protocol itself doesn't support this capability. Currently, mainstream "knock authentication" solutions mostly use the UDP single-packet authorization mechanism, but this approach suffers from instability issues such as easy loss of knock packets and inability to retransmit them.
[0104] The solution of the technical solution of the embodiment of this application is:
[0105] The authentication data format in the TCP Option is customized, enabling the TCP communication protocol to natively support the knocking authentication mechanism, avoiding the problem of single UDP packet loss and achieving more reliable authorization control.
[0106] Difficulty 2:
[0107] Mainstream operating system kernels (such as Linux and Windows) do not provide user-space programs with interfaces for inserting or customizing TCP options. Therefore, traditional applications cannot control or extend the TCP option field.
[0108] The solution of the technical solution of the embodiment of this application is:
[0109] Through kernel module development, the original TCP packets can be processed directly from the kernel layer, and customized "knock verification data" can be injected into the TCP Option field to achieve precise control and expansion at the protocol stack level.
[0110] Difficulty 3:
[0111] The total length of a TCP Option is limited to 40 bytes, making it impossible to carry a complete digital signature. Digital signatures, as an asymmetric encryption and authentication mechanism, are large in size and require the transmission of the entire signature for verification, making them difficult to embed directly in a TCP Option.
[0112] The solution of the technical solution of the embodiment of this application is:
[0113] We introduce a centralized authentication method, pre-distributing a unified symmetric key to each terminal through a certification center. During communication, both parties use this key to encrypt the sequence number of the TCP message, ensuring that the encrypted result is consistent. We only intercept the first 8 bytes of ciphertext and embed them in the TCP Option for identity verification, balancing security and space constraints.
[0114] Innovation summary:
[0115] Through kernel customization and lightweight encryption, authentication information is natively embedded in the TCP layer protocol, breaking through the limitations of the existing protocol stack and building a highly reliable, highly secure, and low-overhead "knock verification" mechanism.
[0116] It should be noted that when implementing the technical solutions of the embodiments of the present application, a system architecture, i.e., a hardware device foundation, is required, as follows:
[0117] Each terminal device in the SDN network must complete terminal device authentication with the authentication center and obtain the symmetric key K used for TCP communication between terminal devices. Each terminal device regularly authenticates with the authentication center to regularly update the symmetric key K.
[0118] Authentication Center (AC): responsible for verifying the identity of terminal devices and distributing symmetric keys.
[0119] Terminal Device (TD): The device that needs to be authenticated.
[0120] Symmetric key (K): A symmetric key shared by all terminal devices and used for TCP communication knock authentication between terminals.
[0121] In specific implementation, the complete device authentication process is as follows:
[0122] The first stage is the generation of terminal device keys:
[0123] (1) The terminal device generates a public-private key pair and device identification data;
[0124] Private key d generated by the terminal device td , and save it locally on the terminal device.
[0125] (2) Public key Q generated by the terminal device td , and input it into the authentication center together with the device identification data.
[0126] In the second stage, the authentication center generates a symmetric key:
[0127] (3) The authentication center generates a symmetric key K, which is used for subsequent TCP communication knocking authentication between terminal devices.
[0128] Specifically, the symmetric key generation process is as follows:
[0129] The authentication center uses the existing AES standard, selects the AES-128 key length, and provides a cryptographically secure random source to generate the symmetric key K through the operating system or programming language. Symmetric keys can also be generated using symmetric encryption algorithms such as DES and SM4.
[0130] Key data: K = RNG (L)
[0131] The authentication center saves the symmetric key K to local storage.
[0132] In the third stage, the terminal device initiates an authentication request to the authentication center:
[0133] (4) The terminal device generates a random number R v As validation data;
[0134] The terminal device generates a random number R by providing a cryptographically secure random source through the operating system or programming language. v As verification data; this random number is used to verify the identity of the terminal device.
[0135] The terminal device uses the private key d td R v Sign and generate signature data Sig td ;
[0136] The terminal device uses the existing asymmetric encryption algorithm ECC standard, selects the curve parameter P-256, and uses the private key d td R v Perform ECDSA signature and generate signature data Sig td ; At the same time, asymmetric encryption algorithms such as RSA can also be used for data signing.
[0137] Terminal equipment to R v The signing process is as follows:
[0138] Signature: Sig td =Sign(d td ,R v )
[0139] (5) The terminal device identifies the local device and verifies the data R v With signature data Sig td Add it to the authentication request application message and send it to the authentication center.
[0140] In the fourth stage, the authentication center verifies the verification data and sends a Challenge request:
[0141] (6) The authentication center receives the authentication request sent by the terminal device and obtains the device identification data and verification data R v With signature data Sig td ;
[0142] The authentication center uses the terminal device public key Q td Parsing signature data Sig td , generate parsing data R v ';
[0143] The authentication center uses the existing asymmetric encryption algorithm ECC standard and the device public key Q td To Sig td Perform ECDSA verification and generate parsing data R v ';
[0144] The authentication center parses the signature data Sig td The process is as follows:
[0145] Parsing the data: R v =Verify(Q td ,Sig td )
[0146] If R v 'with R v If they are inconsistent, the authentication center will close the authentication request connection;
[0147] (7) If R v 'with Rv If they are consistent, the authentication center generates a Challenge random number Rc;
[0148] The authentication center generates the Challenge random number R by providing a cryptographically secure random source through the operating system or programming language. c ; This random number is used for anti-replay challenge verification.
[0149] (8) The authentication center sends the Challenge random number R c Sent to the terminal device.
[0150] If necessary, the random number R c Encryption is performed, and the actual encryption process can be selected according to actual needs.
[0151] In the fifth stage, the terminal device responds to the Challenge request:
[0152] (9) The terminal device receives the Challenge request message sent by the authentication center and obtains the Challenge random number R c ;
[0153] The terminal device uses the existing asymmetric encryption algorithm ECC standard, selects the curve parameter P-256, and uses the private key d td R c Perform ECDSA signature and generate signature data Sig c ; At the same time, asymmetric encryption algorithms such as RSA can also be used for data signing.
[0154] The terminal device responds to the Challenge random number R c The signing process is as follows:
[0155] Signature: Sig c =Sign(d td ,R c )
[0156] (10) The terminal device will sign the data Sig c Add it to the request application message and send it to the authentication center.
[0157] In the sixth stage, the authentication center verifies the Challenge response:
[0158] (11) The authentication center receives the Challenge verification response message sent by the terminal device and obtains the signature data Sig c ;
[0159] The authentication center uses the device public key Q td Parsing signature data Sig c , get the analytical data R c';
[0160] The authentication center uses the existing asymmetric encryption algorithm ECC standard and the device public key Q td To Sig c Perform ECDSA verification and generate parsing data R c ';
[0161] The authentication center parses the signature data Sig c The process is as follows:
[0162] Parsing the data: R c =Verify(Q td ,Sig c )
[0163] If R c 'with R c If they are inconsistent, the authentication center will close the authentication request connection;
[0164] (12) If R c 'with R c If they are consistent, the authentication center sends the symmetric key K to the terminal device.
[0165] In the seventh stage, the certification center issues the symmetric key:
[0166] (12) The authentication center uses the terminal device public key Q td Encrypt the symmetric key K to generate ciphertext data C k ;
[0167] The authentication center uses the existing asymmetric encryption algorithm ECC standard, selects the curve parameter P-256, and uses the terminal device public key Q td Perform ECIES encryption on the symmetric key K to generate ciphertext data C k ; At the same time, asymmetric encryption algorithms such as RSA can also be used for data encryption.
[0168] The encryption process is as follows:
[0169] Ciphertext data: C k =Encrypt(Q td ,K)
[0170] (13) The authentication center sends the encrypted data C k Sent to the terminal device.
[0171] In the eighth stage, the terminal device decrypts the symmetric key and saves it:
[0172] (14) The terminal device receives the encrypted data C sent by the authentication center k ;
[0173] The terminal device uses the device private key d td For ciphertext data C k Decrypt to obtain the symmetric key K;
[0174] The terminal device uses the existing asymmetric encryption algorithm ECC standard and uses the device private key d td For ciphertext data C k Perform ECIES decryption to obtain the symmetric key K;
[0175] The decryption process is as follows:
[0176] Symmetric key: K = Decrypt(d td ,C k )
[0177] The terminal device saves the symmetric key to local storage.
[0178] It should be noted that in actual operation, the execution cycle of each of the above eight stages can be set with a time, that is, each stage is configured with a corresponding execution start time and an execution time for executing the corresponding action, thereby limiting the starting time point of each stage and the time consumed to execute the corresponding action.
[0179] Specifically, the TCP knocking and anti-replay authentication process for communication between internal terminal devices in the embodiment of the present application is as follows:
[0180] In the first stage, terminal device A sends a TCP SYN packet to knock on the door:
[0181] A1, terminal device A obtains the Sequence Number R in the TCP SYN message A ;
[0182] Terminal device A uses the symmetric key K to A Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C A ;
[0183] Terminal device A uses the existing symmetric encryption algorithm AES standard, selects AES-128-CBC mode, and uses the symmetric key K to encrypt the Sequence Number R in the TCP SYN message. A Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C A ; At the same time, symmetric encryption algorithms such as DES and SM4 can also be used for data encryption.
[0184] The encryption process is as follows:
[0185] Ciphertext data: C A =FirstByte(Encrypt(K,RA ),8)
[0186] A2, terminal device A sends the ciphertext data C A Add it to the Option field of the TCP SYN packet;
[0187] Terminal device A sends the encrypted data C A Sent to terminal device B.
[0188] In the second stage, terminal device B verifies the TCP SYN packet knocking:
[0189] A3, terminal device B receives the first TCP packet SYN message sent by terminal device A and obtains the Sequence Number R A With the ciphertext data C A ;
[0190] Terminal device B uses the symmetric key K to A Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C RA ;
[0191] Terminal device B uses the existing symmetric encryption algorithm AES standard, selects AES-128-CBC mode, and uses the symmetric key K to encrypt R A Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C RA ;
[0192] The encryption process is as follows:
[0193] Ciphertext data: C RA =FirstByte(Encrypt(K,R A ),8)
[0194] Verification C RA with C A Inconsistency, not responding to requests;
[0195] Verification C RA with C A If they are consistent, the TCP SYN packet knocking is completed;
[0196] A4, terminal device B returns the second TCP packet SYN+ACK message to terminal device A.
[0197] In the third stage, terminal device A calculates the anti-replay verification:
[0198] A5, terminal device A receives the SYN+ACK message returned by terminal device B and obtains the Sequence Number R in the SYN+ACK message B ;
[0199] Terminal device A uses the symmetric key K to B Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C B ;
[0200] Terminal device A uses the existing symmetric encryption algorithm AES standard, selects AES-128-CBC mode, and uses the symmetric key K to encrypt the Sequence Number R in the returned SYN+ACK message. B Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C B ;
[0201] At the same time, symmetric encryption algorithms such as DES and SM4 can also be used for data encryption.
[0202] The encryption process is as follows:
[0203] Ciphertext data: C B =FirstByte(Encrypt(K,R B ),8)
[0204] A6, terminal device A sends the ciphertext data C B Add it to the Option option of the third TCP ACK packet;
[0205] End device A will verify value C B Sent to terminal device B.
[0206] In the fourth stage, terminal device B verifies anti-replay:
[0207] A7, terminal device B receives the ACK message sent by terminal device A and obtains the ciphertext data C from the TCP Option option B ;
[0208] Terminal device B uses the symmetric key K to B Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C RB ;
[0209] Terminal device B uses the existing symmetric encryption algorithm AES standard, selects AES-128-CBC mode, and uses the symmetric key K to encrypt R B Encrypt and intercept the first 8 bytes of the ciphertext data to generate ciphertext data C RB ;
[0210] The encryption process is as follows:
[0211] Ciphertext data: C RB=FirstByte(Encrypt(K,R B ),8)
[0212] Verification C RB with C B Inconsistency, not responding to requests;
[0213] A8, Verify C RB with C B If the two parties are consistent, the TCP three-way handshake is completed and business communication is established.
[0214] The technical effects of the embodiments of this application are as follows:
[0215] (1) A challenge random number is transmitted in the Option option of the SYN-ACK message header. The requester calculates authentication data based on the challenge and transmits it to the target in the third packet of the TCP handshake. The target verifies the authentication result of the challenge random number. This prevents attackers from intercepting and replaying TCP messages to launch attacks.
[0216] (2) In a simplified solution, the challenge random number is not transmitted in the SYN ACK, and the ACK Sequence of the TCP message is used as the challenge random number, which can also prevent the attack of TCP message replay.
[0217] (3) During the TCP connection establishment phase, the signature data is transmitted in the TCP header Option without affecting the application layer protocol.
[0218] It should be noted that in the embodiments of this application:
[0219] The authentication center can be an independent device or deployed on the target device B. Here, the authentication center is deployed on the target device B as an example to illustrate the implementation process.
[0220] In the Windows or Linux operating system, start an application to implement the terminal to authentication center authentication function.
[0221] Source device A registers with the authentication center and uploads its public key to the authentication center;
[0222] Source device A authenticates with the authentication center and obtains the symmetric key K. This step is performed regularly and the symmetric key K is updated regularly.
[0223] In Windows or Linux operating systems, both communicating devices A and B run background services to implement the functions of terminal device A signing and device B verifying.
[0224] When source device A initiates a TCP connection to target device B, a TCP three-way handshake is required.
[0225] (1) Device A sends a TCP SYN request to target device B. The R A =Sequencenumber, encrypt R using symmetric key K A , get C A , and is transmitted in a TCP Option.
[0226] (2) When the target device B receives the TCP SYN request, it obtains the Sequence number as the verification random number R A , device B uses its own symmetric authentication key K to encrypt R A , and the encrypted result C RA , and TCP option C A Compare. If the comparison results are consistent, verification is successful, and the next step is for Device B to send a SYN ACK response message. Otherwise, Device B does not respond.
[0227] Since the sequence number of TCP SYN is generated by terminal A, it cannot prevent replay.
[0228] (3) Target device B sends a SYN ACK response. The sequence number of the SYN ACK is randomly generated by target device B and is used as the challenge random number in the third handshake.
[0229] (4) Device A sends a third handshake ACK response to the target device B. The processing flow is the same as the first SYN packet.
[0230] The difference is that the first packet uses the requester, and the sequence of device A is a random number; the third packet ACK uses the sequence in the second packet SYN ACK message as a random number, which is generated by the target party, that is, the target device B.
[0231] In summary, the technical advantages of this application are:
[0232] (1) Use the Sequence in the TCP SYN message as a random number, and send the Sequence's authentication data in the TCP Option data. The target party verifies the authentication data and implements TCP SYN packet knocking.
[0233] Using a sequence as a random number has the following advantages: First, it eliminates the need to transmit a separate random number, keeping the authentication data as short as possible and allowing it to be sent within a TCP option. A TCP option can transmit a maximum of 40 bytes. Second, it associates the authentication data with the current TCP connection, preventing the authentication data from being copied to another TCP connection to complete the knock.
[0234] (2) The Sequence in the TCP SYN ACK message sent by the target is used as the challenge random number. The requester transmits the encrypted data of the target Sequence in the Option option of the third data packet, and the target verifies the encrypted data.
[0235] Note: The sequence in the SYN-ACK message is randomly generated by the target party. Even if the TCP SYN message is replayed, the replay can be identified by the three-way handshake.
[0236] Second, see Figure 7 As shown, an embodiment of the present application provides a device authentication apparatus for a TCP connection, the apparatus comprising:
[0237] A first authentication module, which is used to control the first terminal device to obtain the sequence number in the TCP SYN message and generate corresponding first ciphertext data in combination with the symmetric key encryption;
[0238] The first authentication module is further configured to control the first terminal device to add the first ciphertext data to an Option option of the SYN message corresponding to the first handshake in the TCP connection, and then send the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device;
[0239] a second authentication module, configured to control the second terminal to receive the SYN message and the first ciphertext data corresponding to the first handshake in the TCP connection sent by the first terminal device, and obtain the sequence number of the SYN message corresponding to the first handshake in the TCP connection;
[0240] The second authentication module is further configured to control the second terminal device to encrypt and generate corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key;
[0241] The authentication determination module is used to determine that the TCP SYN message knocking is completed between the first terminal device and the second terminal when the first ciphertext data is consistent with the second ciphertext data, and otherwise terminate the response.
[0242] In the embodiment of the present application, by modifying the Option option of the SYN message and coordinating it with a specific encryption verification process, the technical effect of TCP knocking is achieved, meeting the actual work requirements of device authentication.
[0243] Furthermore, the second authentication module is also used to control the second terminal device to return a SYN ACK message corresponding to the second handshake in the TCP connection to the first terminal device after the TCP SYN message knocking is completed between the first terminal device and the second terminal.
[0244] Furthermore, the first authentication module is further configured to enable the first terminal device to obtain a sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and to generate corresponding third ciphertext data by encrypting the symmetric key;
[0245] The first authentication module is further configured to control the first terminal device to add the third ciphertext data to an Option option of an ACK message corresponding to the third handshake in the TCP connection, and then send the ACK message corresponding to the third handshake in the TCP connection and the third ciphertext data to the second terminal device;
[0246] The second authentication module is further configured to receive, by the second terminal, the ACK message and the third ciphertext data corresponding to the third handshake in the TCP connection sent by the first terminal device, and obtain the sequence number of the ACK message corresponding to the third handshake in the TCP connection;
[0247] The second authentication module is further configured to control the second terminal device to encrypt and generate corresponding fourth ciphertext data based on the sequence number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key;
[0248] The authentication determination module is further configured to determine that the TCP three-way handshake is completed between the first terminal device and the second terminal and service communication is established when the third ciphertext data is consistent with the fourth ciphertext data; otherwise, terminate the response.
[0249] It should be noted that during the third handshake in the TCP connection, the requester uses the sequence number of the target party's corresponding SYN ACK message to encrypt and generate the corresponding ciphertext data, and feeds it back to the target party.
[0250] At this time, the ciphertext data is not generated based on the serial number of the requesting party's message, which aims to achieve the technical effect of anti-replay and further improve the overall reliability.
[0251] Furthermore, the first authentication module is further configured to control the first terminal device to obtain a sequence number in the SYN message corresponding to the first handshake in the TCP connection, generate corresponding encrypted data using symmetric key encryption, and intercept the first 8 bytes to obtain the corresponding first ciphertext data;
[0252] The second authentication module is also used to control the second terminal device to encrypt and generate corresponding encrypted data based on the serial number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key, and intercept the first 8 bytes to obtain the corresponding second ciphertext data.
[0253] Furthermore, the first authentication module is further configured to control the first terminal device to obtain a sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, generate corresponding encrypted data using symmetric key encryption, and intercept the first 8 bytes to obtain the corresponding third ciphertext data;
[0254] The second authentication module is also used to control the second terminal device to encrypt and generate corresponding encrypted data based on the serial number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key, and intercept the first 8 bytes to obtain the corresponding fourth ciphertext data.
[0255] To sum up, the device authentication apparatus for TCP connection provided in the embodiment of the present application has similar technical principles as the device authentication method for TCP connection mentioned in the first aspect in terms of technical issues, technical solutions and technical effects, and will not be elaborated here.
[0256] In the description of this application, it should be noted that the terms "upper" and "lower" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application. Unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or an indirect connection through an intermediate medium, or it can be internal communication between two elements. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances.
[0257] It should be noted that, in this application, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element.
[0258] The foregoing is merely a specific embodiment of the present application, which enables those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined in the embodiments of the present application can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown in the embodiments of the present application, but will conform to the widest range consistent with the principles and novel features applied for in the embodiments of the present application.
Claims
1. A device authentication method applied to a TCP connection, characterized in that: The method comprises the following steps: The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, and generates corresponding first ciphertext data by combining it with the symmetric key encryption; The first terminal device adds the first ciphertext data to the Option option of the SYN message corresponding to the first handshake in the TCP connection, and then sends the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device; The second terminal receives the SYN message corresponding to the first handshake in the TCP connection sent by the first terminal device and the first ciphertext data, and obtains the sequence number of the SYN message corresponding to the first handshake in the TCP connection; The second terminal device encrypts and generates corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key; When the first ciphertext data is consistent with the second ciphertext data, it is determined that the TCP SYN message knocking is completed between the first terminal device and the second terminal; otherwise, the response is terminated.
2. The device authentication method applied to a TCP connection according to claim 1, wherein: The method further comprises the following steps: After the TCP SYN message knocking is completed between the first terminal device and the second terminal, the second terminal device returns a SYN ACK message corresponding to the second handshake in the TCP connection to the first terminal device.
3. The device authentication method applied to a TCP connection according to claim 2, wherein: The method further comprises the following steps: The first terminal device obtains the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and generates corresponding third ciphertext data by combining it with the symmetric key encryption; The first terminal device adds the third ciphertext data to the Option option of the ACK message corresponding to the third handshake in the TCP connection, and then sends the ACK message corresponding to the third handshake in the TCP connection and the third ciphertext data to the second terminal device; The second terminal receives the ACK message and the third ciphertext data corresponding to the third handshake in the TCP connection sent by the first terminal device, and obtains the sequence number of the ACK message corresponding to the third handshake in the TCP connection; The second terminal device encrypts and generates corresponding fourth ciphertext data based on the sequence number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key; When the third ciphertext data is consistent with the fourth ciphertext data, it is determined that the TCP three-way handshake is completed between the first terminal device and the second terminal and service communication is established; otherwise, the response is terminated.
4. The device authentication method applied to a TCP connection according to claim 1, wherein: The method further comprises the following steps: The first terminal device obtains the sequence number in the SYN message corresponding to the first handshake in the TCP connection, generates corresponding encrypted data by combining it with the symmetric key encryption, and intercepts the first 8 bytes to obtain the corresponding first ciphertext data; The second terminal device encrypts and generates corresponding encrypted data based on the serial number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key, and intercepts the first 8 bytes to obtain the corresponding second ciphertext data.
5. The device authentication method applied to a TCP connection according to claim 3, wherein: The method further comprises the following steps: The first terminal device obtains the sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, generates corresponding encrypted data by combining it with the symmetric key encryption, and intercepts the first 8 bytes to obtain the corresponding third ciphertext data; The second terminal device encrypts and generates corresponding encrypted data based on the serial number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key, and intercepts the first 8 bytes to obtain the corresponding fourth ciphertext data.
6. A device authentication apparatus for TCP connection, characterized in that: The device comprises: A first authentication module, which is used to control the first terminal device to obtain the sequence number in the TCP SYN message and generate corresponding first ciphertext data in combination with the symmetric key encryption; The first authentication module is further configured to control the first terminal device to add the first ciphertext data to an Option option of the SYN message corresponding to the first handshake in the TCP connection, and then send the SYN message corresponding to the first handshake in the TCP connection and the first ciphertext data to the second terminal device; a second authentication module, configured to control the second terminal to receive the SYN message and the first ciphertext data corresponding to the first handshake in the TCP connection sent by the first terminal device, and obtain the sequence number of the SYN message corresponding to the first handshake in the TCP connection; The second authentication module is further configured to control the second terminal device to encrypt and generate corresponding second ciphertext data based on the sequence number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key; The authentication determination module is used to determine that the TCP SYN message knocking is completed between the first terminal device and the second terminal when the first ciphertext data is consistent with the second ciphertext data, and otherwise terminate the response.
7. The device authentication apparatus for TCP connection according to claim 6, wherein: The second authentication module is further configured to control the second terminal device to return a SYN ACK message corresponding to the second handshake in the TCP connection to the first terminal device after the TCP SYN message knocking is completed between the first terminal device and the second terminal device.
8. The device authentication apparatus for TCP connection according to claim 7, wherein: The first authentication module is further configured for the first terminal device to obtain a sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, and to generate corresponding third ciphertext data by encrypting the symmetric key; The first authentication module is further configured to control the first terminal device to add the third ciphertext data to an Option option of an ACK message corresponding to the third handshake in the TCP connection, and then send the ACK message corresponding to the third handshake in the TCP connection and the third ciphertext data to the second terminal device; The second authentication module is further configured to receive, by the second terminal, the ACK message and the third ciphertext data corresponding to the third handshake in the TCP connection sent by the first terminal device, and obtain the sequence number of the ACK message corresponding to the third handshake in the TCP connection; The second authentication module is further configured to control the second terminal device to encrypt and generate corresponding fourth ciphertext data based on the sequence number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key; The authentication determination module is further configured to determine that the TCP three-way handshake is completed between the first terminal device and the second terminal and service communication is established when the third ciphertext data is consistent with the fourth ciphertext data; otherwise, terminate the response.
9. The device authentication apparatus for TCP connection according to claim 6, wherein: The first authentication module is further configured to control the first terminal device to obtain a sequence number in the SYN message corresponding to the first handshake in the TCP connection, generate corresponding encrypted data using symmetric key encryption, and intercept the first 8 bytes to obtain the corresponding first ciphertext data; The second authentication module is also used to control the second terminal device to encrypt and generate corresponding encrypted data based on the serial number of the SYN message corresponding to the first handshake in the TCP connection and the symmetric key, and intercept the first 8 bytes to obtain the corresponding second ciphertext data.
10. The device authentication apparatus for TCP connection according to claim 8, wherein: The first authentication module is further configured to control the first terminal device to obtain a sequence number of the SYN ACK message corresponding to the second handshake in the TCP connection, generate corresponding encrypted data using symmetric key encryption, and intercept the first 8 bytes to obtain the corresponding third ciphertext data; The second authentication module is also used to control the second terminal device to encrypt and generate corresponding encrypted data based on the serial number of the ACK message corresponding to the third handshake in the TCP connection and the symmetric key, and intercept the first 8 bytes to obtain the corresponding fourth ciphertext data.
Citation Information
Patent Citations
Long connection verification method, device and equipment and readable storage medium
CN114979237A
TCP port hiding method
CN117375908A
Single packet authentication method and device, equipment and storage medium
CN117675252A
Zero-trust network access (ZTNA) secure traffic forwarding
US20250220001A1