Key generation method, Bluetooth device, master control device and electronic equipment

A high-security target key is generated through key negotiation and encryption algorithm between the Bluetooth device and the main control device, which solves the security risks and resource consumption problems in Bluetooth communication and improves data transmission security and device performance.

CN120659049AActive Publication Date: 2025-09-16SHANGHAI IMILAB TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511021254.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-09-16
Estimated Expiration
2045-07-23

AI Technical Summary

Technical Problem

Existing Bluetooth communications lack a data transmission encryption mechanism, posing a security risk. In addition, complex encryption algorithms can cause reduced processing power and slower response speeds for resource-constrained devices.

Method used

Key agreement based on two key pairs and public key encryption communication of the first encryption algorithm are adopted to generate a target key with a high security level, reduce the overhead of additional encryption and decryption resources, and reduce delays.

Benefits of technology

This improves the security of data transmission between the Bluetooth device and the main control device, reduces the consumption of computing resources and memory, and avoids a decrease in processing power and a slow response speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120659049A_ABST
    Figure CN120659049A_ABST
Patent Text Reader

Abstract

The invention provides a key generation method, a Bluetooth device, a master control device and electronic equipment, and relates to the field of Bluetooth communication. The method comprises the following steps: a Bluetooth device sends a handshake request to a master control device; wherein the handshake request comprises a first public key in a first key pair held by the Bluetooth device; the first public key is used for the main control device to encrypt the first public key and a second public key in a second key pair held by the main control device based on a first encryption algorithm to obtain first data; in response to the received first data from the main control device, decrypting the first data based on the first encryption algorithm to obtain a second public key; obtaining a target key according to a first private key and a second public key in the first key pair; wherein the target key is the same as a key determined by the master control device based on the first public key and a second private key in the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the master control device. According to the invention, the security and efficiency of data transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of Bluetooth communication, and in particular to a key generation method, a Bluetooth device, a main control device, and an electronic device. Background Art

[0002] The connection between a SoC (System on Chip) and a Bluetooth chip typically relies on standard hardware connection protocols. However, these protocols primarily focus on hardware specifications and power requirements, without providing corresponding encryption processes for upper-layer transmission information. As a result, data transmission presents potential security risks and is susceptible to malicious attacks or data tampering. Summary of the Invention

[0003] The present disclosure provides a key generation method, a Bluetooth device, a main control device, and an electronic device to solve or alleviate one or more technical problems in the prior art.

[0004] In a first aspect, the present disclosure provides a key generation method, applied to a Bluetooth device, comprising: Sending a handshake request to the master control device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; the first public key is used by the master control device to encrypt the first public key and a second public key in a second key pair held by the master control device based on a first encryption algorithm to obtain first data; In response to receiving the first data from the main control device, decrypting the first data based on the first encryption algorithm to obtain a second public key; A target key is obtained based on the first private key and the second public key in the first key pair; wherein the target key is the same as the key determined by the main control device based on the second private key in the first public key and the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0005] In a second aspect, the present disclosure provides a key generation method, applied to a master control device, comprising: receiving a handshake request from a Bluetooth device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; encrypting the first public key and the second public key of the second key pair held by the main control device based on the first encryption algorithm to obtain the first data; sending first data to the Bluetooth device; A target key is obtained based on the first public key and the second private key in the second key pair; wherein the target key is the same as the key determined by the Bluetooth device based on the first private key and the second public key in the first key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0006] In a third aspect, a Bluetooth device is provided, comprising: a handshake request module, configured to send a handshake request to the master control device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; the first public key is used by the master control device to encrypt the first public key and a second public key in a second key pair held by the master control device based on a first encryption algorithm to obtain first data; a decryption module, configured to, in response to receiving first data from the main control device, decrypt the first data based on a first encryption algorithm to obtain a second public key; A first key determination module is used to obtain a target key based on the first private key and the second public key in the first key pair; wherein the target key is the same as the key determined by the main control device based on the second private key in the first public key and the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0007] In a fourth aspect, a main control device is provided, including: a request receiving module, configured to receive a handshake request from a Bluetooth device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; an encryption module, configured to encrypt the first public key and the second public key of the second key pair held by the main control device based on a first encryption algorithm to obtain first data; A data sending module, configured to send first data to a Bluetooth device; A second key determination module is used to obtain a target key based on the first public key and the second private key in the second key pair; wherein the target key is the same as the key determined by the Bluetooth device based on the first private key and the second public key in the first key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0008] According to a fifth aspect, an electronic device is provided, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform any method in the embodiments of the present disclosure.

[0009] In a sixth aspect, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute any method according to the embodiments of the present disclosure.

[0010] The beneficial effects of the technical solution provided by the present disclosure include at least: the main control device encrypts and transmits the first public key in the received first key pair and the second public key in the second key pair held by itself based on the first encryption algorithm, and the Bluetooth device decrypts and obtains the second public key based on the first encryption algorithm, so that the main control device can obtain the same target key based on the first public key and the second private key and the Bluetooth device can obtain the same target key based on the first private key matching the first public key and the second public key matching the second private key. Based on the key negotiation of the two key pairs and the encrypted communication of the public keys by the first encryption algorithm, hybrid encryption is implemented, which can generate a target key with a high security level and reduce the overhead of additional encryption and decryption resources, thereby improving the security of data transmission between the Bluetooth device and the main control device based on the target key with a high security level. The communication process does not require complex authentication processes and protocol design, thereby reducing delays and computing power requirements, and avoiding the reduction in processing power and slow response speed due to limited resources of the Bluetooth device.

[0011] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings represent the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments provided in accordance with the present disclosure and should not be regarded as limiting the scope of the present disclosure.

[0013] Figure 1 is a schematic diagram of an exemplary application scenario of an embodiment of the present disclosure; Figure 2 is a flowchart of a key generation method according to an embodiment of the present disclosure; Figure 3 is a schematic diagram of an application example of the key generation method according to an embodiment of the present disclosure; Figure 4 is a flowchart of a key generation method according to another embodiment of the present disclosure; Figure 5 is a schematic block diagram of a Bluetooth device provided by an embodiment of the present disclosure; Figure 6 is a schematic block diagram of a Bluetooth device provided by another embodiment of the present disclosure; Figure 7 is a schematic block diagram of a main control device provided by an embodiment of the present disclosure; Figure 8 is a schematic block diagram of a main control device provided by another embodiment of the present disclosure; Figure 9 4 is a block diagram of a cluster used to implement the key generation method according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0014] The present disclosure will be described in further detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0015] In addition, numerous specific details are provided in the following detailed description to better illustrate the present disclosure. Those skilled in the art will appreciate that the present disclosure can be practiced without certain specific details. In some instances, methods, means, components, circuits, etc. well known to those skilled in the art are not described in detail in order to highlight the main purpose of the present disclosure.

[0016] To facilitate understanding of the key generation method provided by the embodiments of the present disclosure, the following describes the related technologies of the embodiments of the present disclosure. First, the connection between the SoC (System on Chip) and the Bluetooth chip in the related art uses hardware connection protocols, such as I2C (Inter-Integrated Circuit) and SPI (Serial Peripheral Interface). These hardware connection protocols lack encryption mechanisms for data transmission, leaving the transmitted data exposed to the network without protection, making it extremely vulnerable to man-in-the-middle attacks and other malicious attacks. This security risk not only affects the confidentiality of data, but may also lead to the leakage of sensitive information, resulting in serious consequences for users and enterprises.

[0017] Secondly, while introducing encryption mechanisms can significantly enhance data transmission security, complex encryption algorithms such as RSA (Rivest-Shamir-Adleman) require increased computing resources and memory. For resource-constrained devices (such as some embedded systems or Bluetooth Low Energy devices), this can lead to reduced processing power, slower response times, and even disrupt normal device operation. Furthermore, increased energy consumption can shorten device battery life, limiting its application scenarios.

[0018] Finally, during authentication and connection establishment, complex authentication processes and a lack of efficient protocol design can lead to significant delays. This delay not only affects device response time, resulting in a poor user experience, but can also have serious consequences in certain real-time applications (such as medical monitoring and industrial automation).

[0019] The embodiment of the present disclosure provides a key generation method, which can be applied to a Bluetooth device and a main control device to solve at least one of the above-mentioned technical problems. Exemplarily, the key generation method of the embodiment of the present disclosure is based on the key negotiation of two key pairs and the encrypted communication of the public key by the first encryption algorithm to achieve hybrid encryption, generate a target key with a high security level during the connection establishment process, and reduce the overhead of additional encryption and decryption resources and reduce delays. In addition, the protection of board-level module communication can be achieved based on the target key with a high security level, thereby improving the security of data transmission between the Bluetooth device and the main control device. By improving the security of the target key, the complexity requirements of the encryption algorithm are correspondingly reduced, thereby reducing the consumption of computing resources and memory, and avoiding problems such as reduced processing power, slow response speed, and shortened device battery life.

[0020] In order to facilitate understanding of the technical solutions of the embodiments of the present disclosure, the application scenarios of the embodiments of the present disclosure are first introduced. For example, the main control device and the Bluetooth device in the embodiments of the present disclosure can be deployed in an electronic device, and the electronic device can specifically be any form of product with Bluetooth communication function. For example, the electronic device can be an Internet of Things device, such as smart cameras, smart speakers, thermostats and other smart home products, or sensors, industrial robots, etc. The electronic device can also be a digital computer, such as a personal digital assistant, a cellular phone, a smart phone, a wearable device and other similar computing devices. The electronic device can also be a vehicle-mounted device, such as a vehicle-mounted central control screen, a vehicle-mounted smart speaker, etc.

[0021] For example, the electronic device may comprise a To-C (To Customer) device. Specifically, the main control device and Bluetooth device may be deployed in the To-C device. By applying the methods of the embodiments of this disclosure to the To-C device, the stringent cost and performance constraints in To-C scenarios can be addressed, thereby improving product performance.

[0022] Exemplarily, the above-mentioned electronic device may include an on-board device. Specifically, the main control device and the Bluetooth device may be deployed on the on-board device, and the on-board device is connected to the vehicle-mounted system via the Bluetooth device. The user can input data into the input unit of the on-board device (for example, through voice, touch screen, etc., and the input data may include vehicle control data, configuration data, etc.). In the embodiment of the present disclosure, the main control device may encrypt the input data based on the target key generated by the key generation method and send it to the Bluetooth device. The Bluetooth device may decrypt the input data based on the target key and securely transmit it to the vehicle-mounted system via the Bluetooth protocol, thereby achieving control of the vehicle. Accordingly, the Bluetooth device may receive vehicle data from the vehicle-mounted system via Bluetooth, encrypt the vehicle data based on the target key, and send it to the main control device. The main control device may decrypt the vehicle data based on the target key, thereby synchronizing the vehicle data to the main control device. The main control device controls the output unit of the on-board device to output the vehicle data, thereby facilitating the user to obtain relevant data. It can be seen that in the embodiment of the present disclosure, the vehicle-mounted device can use a high-security level target key to communicate internally, thereby ensuring the security of data interacting between the vehicle-mounted device and the vehicle system, and eliminating the possibility of driving safety problems caused by attacks on the vehicle-mounted device; and it can reduce latency and computing power requirements, avoiding the reduction in processing power and slow response speed due to limited resources of the Bluetooth device.

[0023] Optionally, the Bluetooth device may include any component capable of Bluetooth connection and data transmission, such as a Bluetooth chip, a Bluetooth module, etc.

[0024] Optionally, the main control device may include any component that can be used to drive a Bluetooth module. Optionally, the main control device may also be used to control an electronic device. Exemplarily, the main control device may include a main control chip, such as a SoC.

[0025] Figure 1 is a schematic diagram of an exemplary application scenario of the present disclosure, such as Figure 1 As shown, the main control device in the embodiment of the present disclosure can adopt SoC, the Bluetooth device can adopt Bluetooth module, the SoC and the Bluetooth module can be set in PCB (Printed Circuit Board), and data can be transmitted between the two. The connection between the SoC and the Bluetooth module can rely on standard hardware connection protocols, such as I2C (Inter-Integrated Circuit), SPI (Serial Peripheral Interface), etc., through these protocols, hardware specifications and level requirements can be paid attention to.

[0026] Figure 21 is a schematic diagram of a key generation method according to an embodiment of the present disclosure. The method is applied to a Bluetooth device, and specifically, the method includes the following steps S210 to S230: Step S210: Send a handshake request to the main control device; wherein the handshake request includes the first public key in the first key pair held by the Bluetooth device; the first public key is used by the main control device to encrypt the first public key and the second public key in the second key pair held by the main control device based on the first encryption algorithm to obtain the first data.

[0027] After the Bluetooth device and the main control device are manufactured, they need to be paired to enable communication and data transfer between them. In the disclosed embodiment, the Bluetooth device sends a handshake request to the main control device, requesting pairing between the main control device and the Bluetooth device. The handshake request includes the first public key of the first key pair held by the Bluetooth device, paving the way for the Bluetooth device and the main control device to subsequently generate the same target key.

[0028] In the embodiment of the present disclosure, the handshake request sent by the Bluetooth device includes the first public key in the first key pair, and the main control device can encrypt the first public key and the second public key in the second key pair based on the first encryption algorithm.

[0029] Optionally, when the master control device and the Bluetooth device are produced in the factory, the encryption program and the decryption program of the first encryption algorithm can be written into the master control device and the Bluetooth device respectively. The first encryption algorithm of the master control device and the Bluetooth device is the same. If key-based encryption and decryption are required, the encryption key of the master control device and the decryption key of the Bluetooth device are the same or matched, so that during the handshake process between the master control device and the Bluetooth device, the Bluetooth device can decrypt the first data encrypted by the matching master control device.

[0030] Optionally, the first encryption algorithm needs to implement encryption and decryption based on a key. Optionally, the key of the first encryption algorithm may be written into the main control device and the Bluetooth device respectively during the production stage.

[0031] In actual applications, when a factory produces a main control device, the key of the first encryption algorithm can be encrypted and then written into the main control device or directly written into the main control device; when a factory produces a Bluetooth device, the key of the first encryption algorithm can be encrypted and then written into the Bluetooth device or directly written into the Bluetooth device.

[0032] In one implementation, when a factory produces a master control device, it can encrypt the key used to implement the first encryption algorithm and then write the ciphertext into the master control device. When the master control device uses the first encryption algorithm, the key used to implement the first encryption algorithm is obtained by decrypting the ciphertext, thereby ensuring the security of the first encryption algorithm and avoiding the leakage of the key used to implement the first encryption algorithm, which may cause a third party to impersonate the master control device through the key to perform a handshake process.

[0033] To encrypt the key used to implement the first encryption algorithm, the complexity of the key used to implement the first encryption algorithm can be increased. For example, a true random number generator (TRNG) or a key derivation function (KDF) can be used to generate the key used to implement the first encryption algorithm. Furthermore, / or the key used to implement the first encryption algorithm can be securely stored, for example, using a hardware security module (HSM) or an efuse (electronic fuse). Furthermore, / or the key used to implement the first encryption algorithm can be encrypted using a preset encryption algorithm. For example, the key used to implement the first encryption algorithm can be encrypted using a private key of an encryption algorithm such as AES (Advanced Encryption Standard) or ECC (Elliptic Curve Cryptography). When the master control device uses the first encryption algorithm, the key used to implement the first encryption algorithm is decrypted using the public key of the encryption algorithm such as AES or ECC to obtain the key used to implement the first encryption algorithm.

[0034] For example, during the production phase, the key used to implement the first encryption algorithm can be encrypted, and the resulting ciphertext can be written to an efuse (electronic fuse) in the master control device. During use, the master control device decrypts the ciphertext in the efuse to obtain the key used to implement the first encryption algorithm (e.g., a private key used for performing encryption calculations based on the first encryption algorithm), thereby ensuring the security of the first encryption algorithm and further improving the security of the first data.

[0035] Optionally, upon initial power-up (or power-on), the Bluetooth device starts up and generates a first key pair. The first key pair may include a paired first public key and a paired first private key. Similarly, upon initial power-up, the master control device starts up and generates a second key pair. The second key pair may include a paired second public key and a paired second private key. The first key pair and the second key pair may be independently generated by the Bluetooth device and the master control device, respectively, based on a preset algorithm.

[0036] In an embodiment of the present disclosure, when the main control device receives a handshake request sent by the Bluetooth device, the main control device can encrypt the first public key in the handshake request and the second public key in the second key pair held by the main control device based on the first encryption algorithm to obtain first data. The first data can be understood as a data packet, which includes the encrypted first public key and second public key, and the main control device sends the first data to the Bluetooth device.

[0037] Step S220: In response to receiving the first data from the main control device, decrypt the first data based on the first encryption algorithm to obtain a second public key.

[0038] In an embodiment of the present disclosure, the Bluetooth device may locally store a first encryption algorithm or a key for decryption based on the first encryption algorithm. After the Bluetooth device receives the first data replied by the main control device, it uses the first encryption algorithm to decrypt the received first data, so that the Bluetooth device can obtain the second public key held by the main control device in the decrypted first data.

[0039] In one implementation, when a factory produces a Bluetooth device, it can encrypt the key used to implement the first encryption algorithm (for example, the public key used for decryption based on the first encryption algorithm) and then write the ciphertext into the Bluetooth device. When the Bluetooth device uses the first encryption algorithm (for example, decryption based on the first encryption algorithm), the key used to implement the first encryption algorithm is obtained by decrypting the ciphertext, thereby ensuring the security of the first encryption algorithm and avoiding the leakage of the key used to implement the first encryption algorithm, which may cause a third party to decrypt the data exchanged in the handshake process through the key, thereby cracking the target key.

[0040] In one implementation, when a factory produces a Bluetooth device, the key for implementing the first encryption algorithm can be written directly into the Bluetooth device, for example, in plain text. Since the first encryption algorithm in the Bluetooth device is used to decrypt the first data, the security requirements are lower than those of the first encryption algorithm in the main control device. Therefore, when the Bluetooth device is produced in the factory, the key for implementing the first encryption algorithm can be written directly into the Bluetooth device, thereby reducing the delay in the handshake process and the computing power requirements for the Bluetooth device, and avoiding the reduction in processing power and slow response speed due to limited resources of the Bluetooth device. For example, when a factory produces a Bluetooth device, the key stored in the cloud (i.e., the key for implementing the first encryption algorithm) can be directly written into the efuse or into the firmware. During use, the Bluetooth device can read the data in the efuse or firmware to obtain the key for implementing the first encryption algorithm (such as the public key for decryption), so that the Bluetooth device can decrypt the first data.

[0041] Optionally, if the first encryption algorithm cannot decrypt the first data, or the decryption fails, it may indicate that the Bluetooth device and the main control device do not match, and the communication function of the Bluetooth device is turned off, thereby completing the protection of the board-level module communication. It is impossible to disguise the main control device or Bluetooth device through hardware replacement or man-in-the-middle attack to deceive the main control device or Bluetooth device to work normally.

[0042] Step S230: Obtain a target key based on the first private key and the second public key in the first key pair; wherein the target key is the same as the key determined by the main control device based on the second private key in the first public key and the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0043] In the embodiment of the present disclosure, the Bluetooth device can obtain the target key based on the first private key and the second public key in the first key pair. At the same time, the main control device can obtain the same target key as the Bluetooth device based on the second private key in the first public key and the second key pair. Subsequent communications between the main control device and the Bluetooth device can uniformly use the same target key for encrypted communication.

[0044] Optionally, in the subsequent data transmission stage between the main control device and the Bluetooth device, the target key can be used to encrypt and transmit data sent by the main control device and / or the Bluetooth device to the other party, and can also be used to decrypt data received by the main control device and / or the Bluetooth device from the other party.

[0045] Optionally, the target key may include a key for encrypting and sending data to be sent, and a key for decrypting data to be received. The above two keys in the target key match, and the communication between the main control device and the Bluetooth device can uniformly use the same target key for encryption and decryption.

[0046] Optionally, the master control device or the Bluetooth device can encrypt the data to be sent to the other party based on the target key. When the master control device or the Bluetooth device cannot decrypt the received data through the target key, the communication function of the master control device or the Bluetooth device can be turned off, thereby completing the protection of board-level module communication. The master control device or the Bluetooth device cannot be disguised by hardware replacement or man-in-the-middle attack to deceive the master control device or the Bluetooth device into working normally.

[0047] The above method provided by the embodiment of the present disclosure is that the main control device encrypts and transmits the first public key in the received first key pair and the second public key in the second key pair held by itself based on the first encryption algorithm, and the Bluetooth device decrypts based on the first encryption algorithm to obtain the second public key, so that the main control device can obtain the same target key based on the first public key and the second private key and the Bluetooth device can obtain the same target key based on the first private key matching the first public key and the second public key matching the second private key. Based on the key negotiation of the two key pairs and the encrypted communication of the public keys by the first encryption algorithm, hybrid encryption is achieved, and a high-security level target key is generated during the connection establishment process, and the overhead of additional encryption and decryption resources is reduced, reducing delays. In addition, the protection of board-level module communication can be achieved based on the high-security level target key, which improves the security of data transmission between the Bluetooth device and the main control device. By improving the security of the target key, the complexity requirements of the encryption algorithm are correspondingly reduced, thereby reducing the consumption of computing resources and memory, avoiding problems such as reduced processing power, slow response speed, and shortened device battery life.

[0048] In some embodiments, the handshake request further includes identification information of the Bluetooth device; wherein the identification information of the Bluetooth device is used by the main control device to decrypt data in the electronic fuse in the main control device to obtain a key for implementing the first encryption algorithm.

[0049] Optionally, the identification information of the Bluetooth device may include an ID (Identifier, unique identifier), version information, and the like.

[0050] In the embodiment of the present disclosure, when the factory produces the main control device, it can generate a ciphertext and write it into efuse based on the identification information of the Bluetooth device paired with the main control device and the private key stored in the cloud. When the main control device receives a handshake request, it can decrypt the data in efuse based on the identification information of the Bluetooth device in the handshake request to obtain the key for implementing the first encryption algorithm. When the decryption key cannot decrypt the data in efuse, it can be said that the main control device and the Bluetooth device are not paired, and the communication function is turned off.

[0051] Optionally, when the factory produces the master control device, it can also generate a unique key and write it into efuse based on the identification information of the Bluetooth device paired with the master control device, the identification information of the master control device and the private key stored in the cloud. When the master control device receives a handshake request, it can generate a decryption key based on the identification information of the Bluetooth device and the identification information of the master control device in the handshake request, decrypt the data in the efuse, and obtain the key used to implement the first encryption algorithm.

[0052] Optionally, when the factory produces the main control device, it can also encrypt the private key stored in the cloud according to the identification information of multiple different Bluetooth devices to generate multiple keys for implementing the first encryption algorithm. When the main control device receives a handshake request, it can decrypt the stored data according to the identification information of the Bluetooth device in the handshake request. Among the multiple keys for implementing the first encryption algorithm, the key that can be successfully decrypted is the key corresponding to the current Bluetooth device for implementing the first encryption algorithm. The main control device can then use the key corresponding to the Bluetooth device according to the identification information of the Bluetooth device to encrypt the first data, thereby further improving the security of the key used to implement the first encryption algorithm in the main control device.

[0053] Optionally, the master control device can also verify the legitimacy and security of the Bluetooth device through the identification information of the Bluetooth device. For example, when the master control device is manufactured, the ID of the Bluetooth device that matches the master control device can be stored. When the master control device receives a handshake request, it can verify the ID of the Bluetooth device in the handshake request based on the stored ID, or verify whether the Bluetooth device matches the master control device based on the version information. If the verification is successful, the master control device can encrypt the first public key and the second public key of the second key pair held by the master control device based on the first encryption algorithm to obtain the first data. Conversely, if the verification fails, the communication function is disabled.

[0054] According to the above embodiment, the main control device can obtain the key for implementing the first encryption algorithm through the identification information of the Bluetooth device, and in this process can determine whether the main control device and the Bluetooth device match, while improving the security of the first encryption algorithm.

[0055] In some embodiments, step S230, obtaining the target key according to the first private key and the second public key in the first key pair, includes: When the first public key obtained by decrypting the first data based on the first encryption algorithm is the same as the first public key in the first key pair, the target key is obtained according to the first private key and the second public key in the first key pair.

[0056] In an embodiment of the present disclosure, the Bluetooth device can decrypt the first data based on the first encryption algorithm to obtain the decrypted first public key and the second public key. When the decrypted first public key is the same as the first public key in the first key pair held by the Bluetooth device, it can be determined that the decrypted second public key is the second public key held by the main control device, so that the Bluetooth device or the main control device has not been replaced or attacked, the Bluetooth device and the main control device are matched, and a handshake can be successfully performed. The Bluetooth device obtains the target key based on the first private key and the second public key in the first key pair.

[0057] According to the above embodiment, the consistency between the decrypted first public key and the first public key held by the Bluetooth device is verified, and the enhanced identity authentication mechanism is used to improve the security and efficiency of the handshake process, thereby ensuring the integrity of the first data and enhancing the reliability of data link communication.

[0058] In some embodiments, the key generation method may further include: When a first public key obtained by decrypting the first data based on the first encryption algorithm is different from the first public key in the first key pair, the communication function is disabled.

[0059] In the embodiment of the present disclosure, when the decrypted first public key is different from the first public key in the first key pair held by the Bluetooth device, it means that the decrypted second public key is also different from the second public key held by the matching main control device, and the Bluetooth device and the main control device are not matched, so the Bluetooth device or the main control device has been replaced or attacked, and the Bluetooth device and the main control device cannot shake hands. Turning off the communication function of the Bluetooth device can complete the protection of the Bluetooth device and the main control device.

[0060] According to the above embodiment, by turning off the communication function when the decrypted first public key is different from the first public key in the first key pair held by the Bluetooth device, the protection of board-level module communication is completed, and the main control device or Bluetooth device cannot be disguised by hardware replacement or man-in-the-middle attack to deceive the main control device or Bluetooth device into working normally.

[0061] In actual applications, the main control device and the Bluetooth device are deployed in the vehicle computer. Through the above embodiment, the communication functions of the main control device and the Bluetooth device of the vehicle computer can be turned off, thereby preventing the main control device and / or the Bluetooth device from being replaced with a third-party chip, directly inputting control information to forge control commands to control the vehicle, and ensuring the safety of vehicle driving.

[0062] In some embodiments, the first encryption algorithm includes a first asymmetric encryption algorithm. Accordingly, step S220, decrypting the first data based on the first encryption algorithm to obtain the second public key, includes: The first data is decrypted based on the third public key of the first asymmetric encryption algorithm to obtain the second public key; the third public key of the first asymmetric encryption algorithm matches the third private key held by the main control device matched with the Bluetooth device for encrypting the first public key and the second public key.

[0063] In an embodiment of the present disclosure, when a matching master control device and a Bluetooth device are produced in a factory, a third private key of the first asymmetric encryption algorithm can be written into the master control device, and a third public key of the first asymmetric encryption algorithm can be written into the Bluetooth device. The third private key and the third public key are matched, so that during the handshake process between the master control device and the Bluetooth device, the Bluetooth device can decrypt the data encrypted by the matching master control device.

[0064] After the main control device receives the handshake request, the main control device can encrypt the first public key in the handshake request and the second public key in the second key pair held by the main control device based on the third private key of the first asymmetric encryption algorithm to obtain the first data and send the first data to the Bluetooth device.

[0065] Accordingly, when the Bluetooth device receives the first data from the master device, it can decrypt it using the third public key held by the Bluetooth device. The third public key matches the third private key held by the master device that is paired with the Bluetooth device. If the third public key can be used for decryption, it can be confirmed that the Bluetooth device and the master device are matched, and the Bluetooth device and the master device can subsequently generate the same target key. If the third public key cannot be used for decryption, it can be confirmed that the Bluetooth device and the master device are not matched. The communication function of the Bluetooth device can be disabled to complete the protection of the Bluetooth device and the master device.

[0066] Optionally, when the master device is manufactured, a unique third private key can be generated based on the master device's unique information (e.g., ID) and the private key stored in the cloud device and written to the efuse. During use, the master device generates a decryption key based on the master device's unique information, decrypts the data in the efuse, and obtains the third private key, thereby ensuring the security of the first data during transmission.

[0067] Optionally, because the third public key in the Bluetooth device is used to decrypt the first data and has lower security requirements than the third private key in the main control device, the third public key can be written directly into the Bluetooth device when the Bluetooth device is manufactured at the factory, thereby reducing latency and the computing power requirements of the Bluetooth device, and avoiding the reduction in processing power and slow response speed due to limited resources of the Bluetooth device. For example, when the Bluetooth device is manufactured at the factory, the third public key can be written directly into the efuse or firmware. During use, the Bluetooth device can read data in the efuse or firmware to obtain the third public key.

[0068] Optionally, the first asymmetric encryption algorithm may adopt any asymmetric encryption algorithm in the related art, for example, the first encryption algorithm may adopt RSA, ECC, SM2, SM9, etc.

[0069] According to the above embodiment, the security of the first data transmission during the handshake process can be enhanced, and at the same time, the protection of board-level module communication is completed, and the main control device or Bluetooth device cannot be disguised by hardware replacement or man-in-the-middle attack to deceive the main control device or Bluetooth device to work normally.

[0070] In some embodiments, the generation method of the above-mentioned first key pair includes: determining a first random number; determining the first private key in the first key pair based on the first random number; determining the first public key in the first key pair based on the base point information jointly held by the Bluetooth device and the main control device, and the first random number.

[0071] Optionally, the method for generating the second key pair in the main control device can be similar to the method for generating the above-mentioned first key pair, including: determining a second random number; determining the second private key in the second key pair based on the second random number; determining the second public key in the second key pair based on the base point information jointly held by the Bluetooth device and the main control device, and the second random number.

[0072] Because the first private key held by the Bluetooth device is determined based on the first random number, and the second public key held by the master device is determined based on the second random number and base point information, the target key derived from the first private key and the second public key is related to the first random number, the second random number, and the base point information. Similarly, the target key derived from the first public key and the second private key is also related to the first random number, the second random number, and the base point information. This approach allows the Bluetooth device and the master device to generate the same target key using unpredictable random numbers, thereby improving the usability and security of the target key.

[0073] In some embodiments, the generation of the first random number and the second random number is subject to time constraints. For example, the formats of the first random number and the second random number are changed at intervals of a certain length, such as by changing the length, data type, etc. of the first random number and the second random number. The Bluetooth device can verify whether the second public key is available based on the format of the received second public key. In this way, even if a third party performs the above-mentioned handshake process by cracking the algorithm and disguising the key as the main control device, it will not be able to generate a second public key that can pass verification due to the time delay in the cracking process. Therefore, the security of the handshake process can be further improved, thereby improving the availability and security of the target key.

[0074] In some embodiments, the base point information changes dynamically, for example, dynamically changes to points on different curves, or different points on the same curve, thereby increasing the difficulty of cracking the base point information.

[0075] In some embodiments, the base point information can be information about points on an elliptic curve. While generating a public key based on a point on an elliptic curve and a random number is computationally simple, deducing the point on the elliptic curve based on the public key is extremely difficult. This can further enhance the security of the handshake process, thereby improving the availability and security of the target key. In some embodiments, the first key pair and the second key pair can be generated based on the ECDH (Elliptic Curve Diffie-Hellman) algorithm. Accordingly, the Bluetooth device and the master control device can each generate the target key based on the ECDH algorithm.

[0076] In some embodiments, the key generation method may further include: encrypting the second data to be transmitted based on the target key and the third encryption algorithm, and sending the encrypted second data to the main control device; In response to receiving the third data from the master device, the third data is decrypted based on the target key and the fourth encryption algorithm.

[0077] In the embodiment of the present disclosure, after the Bluetooth device successfully completes the first handshake and generates the target key, it can directly use the target key to encrypt the second data to be transmitted and decrypt the third data received from the main control device.

[0078] Accordingly, in response to receiving the second data from the Bluetooth device, the master device may decrypt the second data based on the target key, encrypt the third data to be transmitted based on the target key, and send the encrypted third data to the Bluetooth device.

[0079] Optionally, the target key may include a key for encrypting and sending the second data, and a key for decrypting the third data. The above two keys in the target key match, and the communication between the main control device and the Bluetooth device can uniformly use the same target key for encryption and decryption.

[0080] Optionally, any encryption algorithm in the related art can be used as the third encryption algorithm and / or the fourth encryption algorithm. For example, the third encryption algorithm can include RSA, AES, ECC, or ChaCha20, and the fourth encryption algorithm can also include RSA, AES, ECC, or ChaCha20.

[0081] Optionally, the third encryption algorithm and the fourth encryption algorithm may be the same algorithm or different algorithms. For example, the third encryption algorithm and the fourth encryption algorithm may both be AES encryption algorithms, and both the Bluetooth device and the main control device may use the AES encryption algorithm to further encrypt the second data and the third data before sending. Alternatively, the third encryption algorithm may be the AES encryption algorithm, and the fourth encryption algorithm may be the ECC algorithm.

[0082] In some embodiments, the third encryption algorithm and the fourth encryption algorithm can be determined based on data bandwidth. For example, when the bandwidth for data exchange between the Bluetooth device and the main control device is low, a preset first encryption algorithm and target key can be used to encrypt or decrypt the second and third data to be transmitted. The first encryption algorithm can be a more complex encryption algorithm. When the bandwidth for data exchange between the Bluetooth device and the main control device is high, a preset second encryption algorithm and target key can be used to encrypt or decrypt the second and third data to be transmitted. The second encryption algorithm can be a less complex encryption algorithm. Because the bandwidth for data exchange between the Bluetooth device and the main control device is high, if the encryption algorithm is complex, the encryption or decryption will consume excessive resources, affecting the performance of the Bluetooth device and the main control device and causing transmission speed bottlenecks. Therefore, using a less complex encryption algorithm and target key to encrypt the second and third data can reduce encryption or decryption overhead, achieve a larger transmission bandwidth, and improve data transmission efficiency. In other words, by selecting two encryption algorithms, it is possible to balance data transmission efficiency and security, thereby improving the performance of electronic devices. Each group of encryption algorithms may include one encryption algorithm (ie, the third encryption algorithm and the fourth encryption algorithm are the same), or may include different encryption algorithms (eg, including a third encryption algorithm and a fourth encryption algorithm).

[0083] In some embodiments, due to different security requirements for the second and third data, the Bluetooth device and the master control device may use different encryption algorithms to further encrypt the second and third data before sending them. For example, if the master control device and the Bluetooth device are deployed in a vehicle-mounted device, the master control device needs to send vehicle control data, configuration data, and other data (i.e., third data) to the Bluetooth device, while the Bluetooth device needs to send current vehicle data (e.g., regularly transmitted vehicle log data) to the master control device. Therefore, the security requirements for the third data are higher than those for the second data. Therefore, the master control device may use a more secure encryption algorithm (e.g., AES) and a target key to encrypt the third data and send the encrypted third data to the Bluetooth device, thereby further improving the security of the third data sent by the master control device. Accordingly, the Bluetooth device may use a more computationally efficient encryption algorithm (e.g., ECC, ChaCha20, etc.), thereby reducing latency and the computing power requirements of the Bluetooth device, and improving the efficiency of data encryption and decryption.

[0084] According to the above embodiment, through symmetrically encrypted communication between the main control device and the Bluetooth device, the security and efficiency of data transmission between the Bluetooth device and the main control device can be improved, while reducing the delay and computing power requirements, avoiding the processing power reduction and slow response speed due to the limited resources of the Bluetooth device.

[0085] To better understand the technical solution of the disclosed embodiment, a specific application example is provided below. In this application example, the key generation method includes the key security storage process at the factory stage, the handshake process between the Bluetooth device and the main control chip, and the normal data communication process.

[0086] During the secure key storage process at the factory, the control terminal securely stores the RSA private key, ensuring its storage security. Specifically, during factory production, a unique key is generated based on device-specific information (such as the chip ID) and the private key stored in the cloud and written to the efuse. During use, the chip generates a decryption key based on the device-specific information, decrypts the data in the efuse, and obtains the original private key. This original private key is the private key of the RSA algorithm (i.e., the third private key of the first encryption algorithm described above).

[0087] In the handshake process between the Bluetooth device and the main control device, the first handshake process between the Bluetooth module and the main control device generates the corresponding untransmitted AES key (i.e., the target key). RSA encryption can be used for handshake verification, which has high security. In addition, the AES key is dynamically generated each time to reduce security risks. The handshake data flow in the power-on stage can include the following steps: Step 1: After powering up, the Bluetooth device boots up and generates its ECDH key pair A (i.e., the first key pair), consisting of a private key and a public key (i.e., the first public key and the first private key). The Bluetooth device prepares public key A (i.e., the first public key) as part of the handshake request. The master device boots up and generates its ECDH key pair B (i.e., the second key pair), consisting of a private key and a public key (i.e., the second public key and the second private key).

[0088] Step 2: The Bluetooth device sends a handshake request to the master device, including the generated public key A. At this time, the handshake request may also include other necessary information, such as the identity or version number of the Bluetooth device.

[0089] Step 3: After receiving the handshake request, the main control device encrypts the received A public key and the self-generated B public key (i.e., the second public key) using the locally stored RSA private key (i.e., the third private key of the first encryption algorithm).

[0090] Step 4: The main control device sends the encrypted data back to the Bluetooth device. At this time, the data packet contains the RSA-encrypted public keys A and B.

[0091] Step 5: After receiving the reply message from the master device, the Bluetooth device decrypts the received data using its locally stored RSA public key (i.e., the third public key of the first encryption algorithm). After decryption, the Bluetooth device obtains the reply A public key and the master device's B public key.

[0092] Step 6: The Bluetooth device verifies that the decrypted public key A matches the expected one by comparing the locally stored public key A with the decrypted data from the received message. If the verification is successful, the Bluetooth device considers the authentication successful. Otherwise, the Bluetooth device shuts down the communication function and terminates the handshake process.

[0093] Step 7: Both devices (the Bluetooth device and the master) negotiate a key using their respective private keys and the other's public key. Specifically, the Bluetooth device uses its A private key and the master's B public key to calculate a shared session key C (the target key). The master similarly uses its B private key and the Bluetooth's A public key to calculate the same non-transmitted session key C (the target key).

[0094] Step 8: At this point, both devices have the same shared AES session key, C. This key is used for subsequent encrypted communications, ensuring data security during transmission. The handshake is now complete, and all subsequent communications between the two parties will be encrypted using the shared session key, C.

[0095] In the regular data communication process, regular data communication uses AES shared session key C for encryption and decryption, which has high transmission efficiency and low hardware resource load. The regular communication process can specifically include the following steps: Step 1: The Bluetooth / master device communication message is encrypted using the shared session key C and sent to the peer end.

[0096] Step 2: The communication message received by the master / Bluetooth device is decrypted using the shared session key C to complete normal data parsing.

[0097] In some embodiments, Figure 3 FIG. 1 is a schematic diagram of an application example of the key generation method according to an embodiment of the present disclosure. Figure 3 As shown, the key generation method may include the following steps S301 to S310: Step S301: When the Bluetooth device is powered on, a first key pair is generated; wherein the first key pair includes a first public key and a first private key; At the same time, in step S302, when the main control device is powered on, a second key pair is generated; wherein the second key pair includes a second public key and a second private key; Step S303: The Bluetooth device sends the first public key in the first key pair to the main control device; Step S304: The main control device encrypts the first public key and the second public key using the third private key; Step S305: The main control device sends first data to the Bluetooth device; wherein the first data includes the encrypted first public key and the second public key; Step S306: The Bluetooth device decrypts the first data using the third public key and verifies the first public key; wherein the verification method includes: if the first public key obtained by decryption is different from the first public key in the first key pair, the verification is deemed to have failed; if the first public key obtained by decryption is the same as the first public key in the first key pair, the verification is deemed to have succeeded; If the verification fails, step S307 is executed, the Bluetooth device is turned off and external communication is stopped; If the verification is successful, step S308 is executed, and the Bluetooth device generates a target key using the first private key and the second public key; Step S309: The main control device generates a target key using the first public key and the second private key; wherein the target keys generated by the Bluetooth device and the main control device are the same; Step S310: Both parties implement AES encrypted communication through the target key.

[0098] It can be seen that the key generation method provided by the embodiment of the present disclosure is that the main control device encrypts and transmits the first public key in the received first key pair and the second public key in the second key pair held by itself based on the first encryption algorithm, and the Bluetooth device decrypts based on the first encryption algorithm, and verifies the consistency of the decrypted first public key and the first public key held by itself, so that the main control device based on the first public key and the second private key and the Bluetooth device based on the first private key matching the first public key and the second public key matching the second private key can obtain the same target key. The enhanced authentication mechanism is used to improve the security and efficiency of the handshake process, ensure the integrity of the first data, enhance the reliability of data link communication, and complete the protection of board-level module communication. It is impossible to disguise the main control device or Bluetooth device through hardware replacement or man-in-the-middle attack to deceive the main control device or Bluetooth device to work normally. At the same time, based on the key negotiation of two key pairs and the encrypted communication of the public key by the first encryption algorithm, hybrid encryption is achieved, which can generate a high-security target key and reduce the overhead of additional encryption and decryption resources. Therefore, the security of data transmission between the Bluetooth device and the main control device can be improved based on the high-security target key. The communication process does not require complex authentication processes and protocol designs, thereby reducing delays and computing power requirements, and avoiding the reduction of processing capabilities and slow response speeds due to limited resources of the Bluetooth device.

[0099] Figure 4 FIG4 is a schematic diagram of a key generation method according to another embodiment of the present disclosure. The method is applied to a master control device, and specifically, the method includes the following steps S410 to S440: Step S410: receiving a handshake request from a Bluetooth device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; Step S420: Encrypt the first public key and the second public key of the second key pair held by the main control device based on the first encryption algorithm to obtain the first data; Step S430: sending first data to the Bluetooth device; Step S440: Obtain a target key based on the first public key and the second private key in the second key pair; wherein the target key is the same as the key determined by the Bluetooth device based on the first private key and the second public key in the first key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0100] In some embodiments, the key generation method may further include: Based on the second encryption algorithm, the data in the electronic fuse in the main control device is decrypted to obtain a key for implementing the first encryption algorithm; wherein the data in the electronic fuse is written into the electronic fuse when the main control device is produced.

[0101] In some embodiments, decrypting data in an electronic fuse in a master control device based on a second encryption algorithm to obtain a key for implementing a first encryption algorithm includes: Determining a key of a second encryption algorithm based on identification information of the main control device and / or identification information of the Bluetooth device; Based on the key of the second encryption algorithm and the second encryption algorithm, the data in the electronic fuse is decrypted to obtain the key for implementing the first encryption algorithm.

[0102] In some embodiments, the first encryption algorithm includes a first asymmetric encryption algorithm. Accordingly, step S420, encrypting the first public key and the second public key of the second key pair held by the master device based on the first encryption algorithm to obtain the first data, includes: The first public key and the second public key in the second key pair held by the main control device are encrypted based on the third private key of the first asymmetric encryption algorithm to obtain the first data; the third private key of the first asymmetric encryption algorithm is matched with the third public key held by the Bluetooth device matched with the main control device for decrypting the first public key and the second public key.

[0103] In some embodiments, the second key pair is generated by: determining a second random number; determining a second private key in a second key pair based on the second random number; Based on the base point information held jointly by the Bluetooth device and the main control device, and the second random number, a second public key in the second key pair is determined.

[0104] In some embodiments, the key generation method may further include: In response to receiving second data from the Bluetooth device, decrypting the second data based on the target key and the third encryption algorithm; and / or, The third data to be transmitted is encrypted based on the target key and the fourth encryption algorithm, and the encrypted third data is sent to the Bluetooth device.

[0105] For a specific example of the key generation method applied to the master control device in the embodiment of the present disclosure, reference can be made to the relevant description of the master control device in the aforementioned embodiment, and corresponding beneficial effects are achieved.

[0106] Figure 5 : is a schematic block diagram of a Bluetooth device according to an embodiment of the present disclosure. Figure 5 As shown, Bluetooth devices may include: A handshake request module 510 is configured to send a handshake request to the master device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; the first public key is used by the master device to encrypt the first public key and a second public key in a second key pair held by the master device based on a first encryption algorithm to obtain first data; a decryption module 520 for, in response to receiving the first data from the main control device, decrypting the first data based on the first encryption algorithm to obtain a second public key; The first key determination module 530 is used to obtain a target key based on the first private key and the second public key in the first key pair; wherein the target key is the same as the key determined by the main control device based on the second private key in the first public key and the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0107] In some embodiments, the first key determination module 530 is also used to: when the first public key obtained by decrypting the first data based on the first encryption algorithm is the same as the first public key in the first key pair, obtain the target key according to the first private key and the second public key in the first key pair.

[0108] In some embodiments, as Figure 6 As shown, the Bluetooth device may further include a communication closing module 610, which is configured to close the communication function when the first public key obtained by decrypting the first data based on the first encryption algorithm is different from the first public key in the first key pair.

[0109] In some embodiments, the handshake request further includes identification information of the Bluetooth device; wherein the identification information of the Bluetooth device is used by the main control device to decrypt data in the electronic fuse in the main control device to obtain a key for implementing the first encryption algorithm.

[0110] In some embodiments, the first encryption algorithm includes a first asymmetric encryption algorithm; the decryption module 520 is also used to: decrypt the first data based on the third public key of the first asymmetric encryption algorithm to obtain the second public key; the third public key of the first asymmetric encryption algorithm matches the third private key held by the main control device matched with the Bluetooth device for encrypting the first public key and the second public key.

[0111] In some embodiments, the first key pair is generated by: determining a first random number; determining a first private key in a first key pair based on the first random number; Based on the base point information held jointly by the Bluetooth device and the main control device, and the first random number, a first public key in the first key pair is determined.

[0112] In some embodiments, as Figure 6As shown, the Bluetooth device may further include a first communication module 620, which is configured to: Encrypting the second data to be transmitted based on the target key and the third encryption algorithm, and sending the encrypted second data to the main control device; and / or, In response to receiving the third data from the master device, the third data is decrypted based on the target key and the fourth encryption algorithm.

[0113] Figure 7 FIG is a schematic block diagram of a main control device according to an embodiment of the present disclosure. Figure 7 As shown, the main control device may include: The request receiving module 710 is configured to receive a handshake request from a Bluetooth device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; an encryption module 720 configured to encrypt the first public key and the second public key of the second key pair held by the main control device based on the first encryption algorithm to obtain first data; A data sending module 730, configured to send first data to a Bluetooth device; The second key determination module 740 is used to obtain a target key based on the first public key and the second private key in the second key pair; wherein the target key is the same as the key determined by the Bluetooth device based on the first private key and the second public key in the first key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

[0114] In some embodiments, as Figure 8 As shown, the main control device may further include a key decryption module 810, which is used to: Based on the second encryption algorithm, the data in the electronic fuse in the main control device is decrypted to obtain a key for implementing the first encryption algorithm; wherein the data in the electronic fuse is written into the electronic fuse when the main control device is produced.

[0115] In some embodiments, the key decryption module 810 is further configured to: Determining a key of a second encryption algorithm based on identification information of the main control device and / or identification information of the Bluetooth device; Based on the key of the second encryption algorithm and the second encryption algorithm, the data in the electronic fuse is decrypted to obtain the key for implementing the first encryption algorithm.

[0116] In some embodiments, the first encryption algorithm includes a first asymmetric encryption algorithm; the encryption module 720 is further configured to: The first public key and the second public key in the second key pair held by the main control device are encrypted based on the third private key of the first asymmetric encryption algorithm to obtain the first data; the third private key of the first asymmetric encryption algorithm is matched with the third public key held by the Bluetooth device matched with the main control device for decrypting the first public key and the second public key.

[0117] In some embodiments, the second key pair is generated by: determining a second random number; determining a second private key in a second key pair based on the second random number; Based on the base point information held jointly by the Bluetooth device and the main control device, and the second random number, a second public key in the second key pair is determined.

[0118] In some embodiments, as Figure 8 As shown, the main control device may further include a second communication module 820, and the second communication module 820 is used to: In response to receiving second data from the Bluetooth device, decrypting the second data based on the target key and the third encryption algorithm; and / or, The third data to be transmitted is encrypted based on the target key and the fourth encryption algorithm, and the encrypted third data is sent to the Bluetooth device.

[0119] For the description of specific functions and examples of each module and submodule of the device in the embodiment of the present disclosure, please refer to the relevant description of the corresponding steps in the above method embodiment, which will not be repeated here.

[0120] In the technical solutions disclosed herein, the acquisition, storage, and application of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0121] Figure 9 FIG. 1 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. Figure 9 As shown, the electronic device includes: a memory 910 and a processor 920. The memory 910 stores a computer program that can be executed on the processor 920. The number of memory 910 and processor 920 can be one or more. The memory 910 can store one or more computer programs. When the one or more computer programs are executed by the electronic device, the electronic device performs the method provided by the above method embodiment. The electronic device may also include: a communication interface 930 for communicating with external devices and performing data exchange.

[0122] If the memory 910, processor 920, and communication interface 930 are implemented independently, the memory 910, processor 920, and communication interface 930 can be connected to each other via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 9 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0123] Optionally, in a specific implementation, if the memory 910, the processor 920 and the communication interface 930 are integrated on one end, the memory 910, the processor 920 and the communication interface 930 can communicate with each other through an internal interface.

[0124] It should be understood that the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the Advanced RISC Machines (ARM) architecture.

[0125] Furthermore, optionally, the above-mentioned memory may include a read-only memory and a random access memory, and may also include a non-volatile random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM) and direct memory bus random access memory (DR RAM).

[0126] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the process or function described in the embodiment of the present disclosure is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, data subscriber line (DSL)) or wireless (e.g., infrared, Bluetooth, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a digital versatile disc (DVD)), or a semiconductor medium (e.g., a solid-state drive (SSD)). It is worth noting that the computer-readable storage medium mentioned in the present disclosure may be a non-volatile storage medium, in other words, a non-transient storage medium.

[0127] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0128] In the description of the embodiments of the present disclosure, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present disclosure. Moreover, the specific features, structures, materials, or characteristics described may be combined in any appropriate manner in any one or more embodiments or examples. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification, as well as features of different embodiments or examples, unless they are mutually inconsistent.

[0129] In the description of the embodiments of the present disclosure, unless otherwise specified, " / " means or. For example, A / B can mean A or B. "And / or" in this document is only a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.

[0130] In the description of the embodiments of the present disclosure, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise specified, "plurality" means two or more.

[0131] The above description is merely an exemplary embodiment of the present disclosure and is not intended to limit the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present disclosure shall be included in the scope of protection of the present disclosure.

Claims

1. A key generation method, applied to a Bluetooth device, characterized in that: include: Sending a handshake request to the master control device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; the first public key is used by the master control device to encrypt the first public key and a second public key in a second key pair held by the master control device based on a first encryption algorithm to obtain first data; In response to receiving first data from the main control device, decrypting the first data based on the first encryption algorithm to obtain the second public key; A target key is obtained based on the first private key and the second public key in the first key pair; wherein the target key is the same as the key determined by the main control device based on the first public key and the second private key in the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

2. The method according to claim 1, characterized in that Obtaining a target key according to the first private key and the second public key in the first key pair includes: When the first public key obtained by decrypting the first data based on the first encryption algorithm is the same as the first public key in the first key pair, the target key is obtained according to the first private key and the second public key in the first key pair.

3. The method according to claim 2, characterized in that The method further comprises: When a first public key obtained by decrypting the first data based on the first encryption algorithm is different from the first public key in the first key pair, the communication function is disabled.

4. The method according to any one of claims 1 to 3, characterized in that The handshake request also includes identification information of the Bluetooth device; wherein the identification information of the Bluetooth device is used by the main control device to decrypt data in the electronic fuse in the main control device to obtain a key for implementing the first encryption algorithm.

5. The method according to any one of claims 1 to 3, characterized in that The first encryption algorithm includes a first asymmetric encryption algorithm; The decrypting the first data based on the first encryption algorithm to obtain the second public key includes: The first data is decrypted based on the third public key of the first asymmetric encryption algorithm to obtain the second public key; the third public key of the first asymmetric encryption algorithm is matched with the third private key held by the main control device matched with the Bluetooth device for encrypting the first public key and the second public key.

6. The method according to any one of claims 1 to 3, characterized in that The first key pair is generated in the following manner: determining a first random number; determining a first private key in the first key pair based on the first random number; The first public key in the first key pair is determined based on the base point information held jointly by the Bluetooth device and the main control device, and the first random number.

7. The method according to any one of claims 1 to 3, characterized in that The method further comprises: encrypting the second data to be transmitted based on the target key and a third encryption algorithm, and sending the encrypted second data to the main control device; In response to receiving the third data from the master device, the third data is decrypted based on the target key and a fourth encryption algorithm.

8. A key generation method, applied to a master control device, characterized in that: include: receiving a handshake request from a Bluetooth device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; encrypting the first public key and the second public key of the second key pair held by the main control device based on a first encryption algorithm to obtain first data; sending the first data to the Bluetooth device; A target key is obtained based on the first public key and the second private key in the second key pair; wherein the target key is the same as the key determined by the Bluetooth device based on the first private key and the second public key in the first key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

9. The method according to claim 8, characterized in that The method further comprises: Based on a second encryption algorithm, the data in the electronic fuse in the main control device is decrypted to obtain a key for implementing the first encryption algorithm; wherein the data in the electronic fuse is written into the electronic fuse when the main control device is produced.

10. The method according to claim 9, characterized in that The decrypting of data in the electronic fuse in the main control device based on the second encryption algorithm to obtain a key for implementing the first encryption algorithm includes: determining a key of the second encryption algorithm based on the identification information of the main control device and / or the identification information of the Bluetooth device; Based on the key of the second encryption algorithm and the second encryption algorithm, the data in the electronic fuse is decrypted to obtain the key for implementing the first encryption algorithm.

11. The method according to any one of claims 8 to 10, characterized in that The first encryption algorithm includes a first asymmetric encryption algorithm; Encrypting the first public key and the second public key of the second key pair held by the main control device based on a first encryption algorithm to obtain first data includes: The first public key and the second public key in the second key pair held by the main control device are encrypted based on the third private key of the first asymmetric encryption algorithm to obtain the first data; the third private key of the first asymmetric encryption algorithm is matched with the third public key held by the Bluetooth device matched with the main control device for decrypting the first public key and the second public key.

12. The method according to any one of claims 8 to 10, characterized in that The second key pair is generated by: determining a second random number; determining a second private key in the second key pair based on the second random number; The second public key in the second key pair is determined based on the base point information held jointly by the Bluetooth device and the main control device, and the second random number.

13. The method according to any one of claims 8 to 10, characterized in that The method further comprises: In response to receiving second data from the Bluetooth device, decrypting the second data based on the target key and a third encryption algorithm; The third data to be transmitted is encrypted based on the target key and a fourth encryption algorithm, and the encrypted third data is sent to the Bluetooth device.

14. A Bluetooth device, characterized in that: include: a handshake request module, configured to send a handshake request to a master control device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; the first public key is used by the master control device to encrypt the first public key and a second public key in a second key pair held by the master control device based on a first encryption algorithm to obtain first data; a decryption module, configured to, in response to receiving first data from the main control device, decrypt the first data based on the first encryption algorithm to obtain the second public key; a first key determination module, configured to obtain a target key based on the first private key and the second public key in the first key pair; wherein the target key is the same as the key determined by the main control device based on the first public key and the second private key in the second key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

15. A main control device, characterized in that: include: a request receiving module, configured to receive a handshake request from a Bluetooth device; wherein the handshake request includes a first public key in a first key pair held by the Bluetooth device; an encryption module, configured to encrypt the first public key and the second public key of the second key pair held by the main control device based on a first encryption algorithm to obtain first data; a data sending module, configured to send the first data to the Bluetooth device; a second key determination module, configured to obtain a target key based on the first public key and the second private key in the second key pair; wherein the target key is the same as the key determined by the Bluetooth device based on the first private key and the second public key in the first key pair, and the target key is used for encrypted communication between the Bluetooth device and the main control device.

16. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 13.

17. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-13.

Citation Information

Patent Citations

  • Method for interaction between Bluetooth equipment, and Bluetooth equipment

    CN109688573A

  • Key determination method and device, electronic equipment and computer readable storage medium

    CN117560150A

  • Communication method and system, electronic equipment and storage medium

    CN119652611A

  • Firmware protection method and system based on security coprocessor

    CN120068051A

  • Access right management system, communication processor and method, and computer program

    JP2004015507A