Communication method and related device
By negotiating and determining the Key Derivation Function (KDF) and fresh parameters to generate a key, the problem of insufficient privacy of authentication keys in the EAP authentication process is solved, and network compatibility and security are improved to adapt to terminals with different security capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2026-03-31
AI Technical Summary
The existing EAP authentication process lacks sufficient privacy of authentication keys, leading to the theft of communication data. Furthermore, it is difficult to adapt to terminals with different security capabilities, resulting in some terminals being unable to access the enterprise network and causing a poor user experience.
By negotiating and determining the Key Derivation Function (KDF), terminals with different security capabilities can be adapted, improving network compatibility. The negotiated KDF is used for key derivation, and the first key is generated by combining fresh parameters and node identifiers, thereby enhancing security and compatibility.
It improves network compatibility and user experience, enhances communication security, adapts to terminals with different security capabilities, and improves the access security capabilities of enterprise networks.
Smart Images

Figure CN121770731A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a communication method and related apparatus. Background Technology
[0002] In the era of rapid development of mobile internet, our tools are more convenient to use than traditional computers, especially desktop workstations and servers. However, we also face greater risks, and communication security has gradually become a key issue in the field of communications. Especially for wireless transmission, nodes and access points (APs) need to first detect each other in a complex space and complete the access process to enable data transmission between them.
[0003] During the process of a terminal connecting to an Access Point (AP), considering internal network security, an authentication server is needed to authenticate the terminal's identity. The Extensible Authentication Protocol (EAP) is a widely used protocol for authenticating terminals connecting to an AP, defining the exchange of authentication information between the terminal, the AP, and the authentication server. During EAP authentication, the AP and the terminal obtain a consistent authentication key, which is typically generated uniformly according to the EAP's specifications. The AP and the terminal can then derive a session key based on the authentication key to achieve secure communication.
[0004] However, the confidentiality of the authentication keys determined in the current EAP authentication process is not high enough. There have been cases where communication data between terminals and APs has been stolen due to compromised authentication keys. Moreover, as the types of terminals accessing the network increase and their security capabilities expand, using a unified method to generate authentication keys is difficult to adapt to terminals with different security capabilities. This makes it difficult for some terminals with incompatible security capabilities to access the enterprise network, resulting in a poor user experience. Summary of the Invention
[0005] This application provides a communication method and related apparatus. In this application, the first node and the second node can negotiate and determine a key derivation function (KDF). The second node and the third node can deduce the authentication key based on the negotiated KDF, so that the association and authentication process can be adapted to terminals with different security capabilities, thereby improving network compatibility and enhancing the user experience.
[0006] In a first aspect, this application provides a communication method, comprising: negotiating with a first node to determine a first KDF, performing an authentication process with a third node, and, if the authentication process is successful, determining a first key based at least on the first KDF and key information.
[0007] This method can be applied to a second node, which is a device with communication capabilities. In practice, the method can be executed by software modules, hardware modules, or a combination of both within the second node, such as a chip or processor. For ease of description, the following explanation uses the second node as the executing entity.
[0008] The first node is the node that the second node requests to associate with; that is, the first node is the node being associated with, and the second node is the node requesting to associate with the first node. For example, the second node can send an association request (or access request) to the first node to request association with it. The third node is used for authentication; that is, the third node can authenticate the identity of the node. Optionally, the third node and the first node belong to the same device, or the third node and the first node have a communication connection. This communication connection can be manifested in the fact that the third node can send and receive messages with the first node. Alternatively, in some solutions, the communication connection between the third node and the first node can be understood as the ability for point-to-point message transmission between the third node and the first node.
[0009] In this application, when a second node requests association with a first node, the second node needs to execute an authentication process and perform key deduction. Before deducing the key, the second node can negotiate and determine a Key Validation Principle (KDF) with the first node, and perform key deduction based on the negotiated first KDF. Since the first KDF is negotiated, the first KDF negotiated with the first node may be different for second nodes with different security capabilities. This allows the association and authentication process to adapt to terminals with different security capabilities, improving network compatibility and enhancing the user experience.
[0010] For example, if the first and third nodes support KDF functions KDF1 and KDF2 respectively, for a second node that supports KDF1, the first and second nodes can negotiate to determine that KDF1 is the first KDF. Similarly, for a second node that supports KDF2, the first and second nodes can negotiate to determine that KDF2 is the first KDF. In this way, two second nodes with different security capabilities can both associate with the first node and deduce the first key.
[0011] In some solutions, the first node is the management node in the enterprise network, which can be regarded as the access point, while the third node is used to provide authentication services for the enterprise network. This application can improve the compatibility of the security capabilities of nodes requesting association with the enterprise network while authenticating the identity of nodes accessing the enterprise network, thereby improving the user experience of the enterprise network.
[0012] In one possible implementation of the first aspect, the first key is a key shared with the third node. That is, the third node also determines the first key based on the same parameters. Thus, when the parameter values are the same, the first key determined by the second node is consistent with the first key determined by the third node.
[0013] In another possible implementation of the first aspect, the key information is shared between the second and third nodes. In other words, the third and second nodes can obtain the same key information in advance.
[0014] For example, the key information can be a transport layer security (TLS) key between the second and third nodes, such as a TLS master key, or a key derived from the TLS master key.
[0015] As another example, the key information can be the password corresponding to the second node. For instance, the second node can log in with a corresponding account (or username), and this account can have a predefined password. This password can serve as key information shared between the second and third nodes. Furthermore, the key information also includes the aforementioned account.
[0016] In another possible implementation of the first aspect, the authentication process is performed with the third node, including: the second node interacting with the first node to exchange a first authentication message, and the first node interacting with the authentication service to exchange a second authentication message.
[0017] The above implementation describes an interaction method for the authentication process, in which the second node can interact with the first node to exchange a first authentication message, and the first node also interacts with the third node to exchange a second authentication message, thereby enabling the identity of the second node to be authenticated by the third node.
[0018] In another possible implementation of the first aspect, determining the first key is based at least on the first KDF and key information, including: determining the first key based on the first KDF and key information, as well as the identifier of the first node and / or the identifier of the second node.
[0019] The above implementation introduces the identifier of the first node and / or the identifier of the second node to participate in the generation of the first key, defining a new way to generate the first key and improving security.
[0020] Furthermore, the identifier of the first node is used to identify the identity of the first node in the communication system, such as the identifier (ID) of a certain protocol layer of the first node. For example, the communication protocol stack between the first node and the second node includes multiple protocol layers, which can be referred to as layer 1, layer 2, layer 3, etc., and the identifier of the first node can be the layer 2 ID (L2ID) of the second node.
[0021] Similarly, the identity identifier of the second node is used to identify the identity of the second node in the communication system, such as the L2ID of the second node.
[0022] In another possible implementation of the first aspect, determining the first key based at least on the first KDF and key information includes: determining the first key based on the first KDF and key information, as well as a first freshness parameter and / or a second freshness parameter. The first freshness parameter is generated by the second node, and the second freshness parameter is derived from the first node.
[0023] By introducing fresh parameters generated by the first node and / or the second node into the generation process of the first key in the above implementation method, a new way of generating the first key is defined, which improves security.
[0024] Optionally, the first fresh parameter can be sent to the first node. That is, the first fresh parameter and the second fresh parameter are exchanged between the first node and the second node.
[0025] Furthermore, the first fresh parameter and the second fresh parameter are fresh parameters exchanged between the first node and the second node during the security context negotiation process. In other words, the first fresh parameter and the second fresh parameter are exchanged between the first node and the second node before the authentication process. Thus, an attacker needs to obtain these first and second fresh parameters during the association phase in order to crack the first key, increasing the difficulty of cracking the first key and enhancing security.
[0026] In another possible implementation of the first aspect, determining the first key based on the first KDF, key information, a first freshness parameter, and a second freshness parameter includes: determining the second key based on the first KDF, key information, a first freshness parameter, and a second freshness parameter, and determining the first key based on the first KDF and the second key.
[0027] In the above implementation, the derivation process of the first key is divided into two stages: first, an intermediate key (i.e., the second key) is derived based on partial information; then, the first key is further derived based on the intermediate key. This defines a new method for generating the first key, improving security.
[0028] Further, the first key is determined based on the first KDF and the second key, including: determining the first key based on the first KDF, the second key, the identifier of the first node, and the identifier of the second node.
[0029] In another possible implementation of the first aspect, before determining the first key based at least on the first KDF and key information, the method further includes: receiving a third fresh parameter from the first node, the third fresh parameter being determined by the third node. Determining the first key based at least on the first KDF and key information includes: determining the first key based on the first KDF, key information, and the third fresh parameter.
[0030] By introducing fresh parameters determined by a third node into the generation process of the first key in the above implementation method, a new way of generating the first key is defined, which improves security.
[0031] In another possible implementation of the first aspect, determining the first key based on the first KDF, key information, and a third freshness parameter includes: determining the second key based on the first KDF, key information, and a third freshness parameter, and determining the first key based on the first KDF and the second key.
[0032] Further, the first key is determined based on the first KDF and the second key, including: determining the first key based on the first KDF, the second key, the identifier of the first node, and the identifier of the second node.
[0033] In another possible implementation of the first aspect, the authentication process belongs to the authentication process defined by the TLS-based EAP authentication protocol, and the key information includes the TLS master key.
[0034] In another possible implementation of the first aspect, the authentication process belongs to the authentication process defined by the EAP authentication protocol based on account password, and the key information includes the password corresponding to the second node. Further, the key information also includes the account corresponding to the second node.
[0035] In yet another possible implementation of the first aspect, before interacting with the first node to exchange authentication messages, the method further includes: receiving an authentication method indication from the first node, the authentication method indication being used to indicate an authentication method. The authentication method is related to the authentication process.
[0036] In the above implementation, before the authentication process, the first node can send an authentication method instruction to indicate the method of authenticating the second node, so that the second node can execute the corresponding authentication process in accordance with the authentication method indicated by the first node.
[0037] Furthermore, this authentication method indicates that the authentication process is defined by the EAP authentication protocol. This application newly defines a first key generation method in the EAP authentication process, improving compatibility with the security capabilities of the second node.
[0038] Optionally, the authentication method indication may be carried in a broadcast message, or it may be carried in other messages (such as the second message, fourth message, etc. hereinafter). For example, the first node may send a broadcast message, such as a communication domain system message, carrying the authentication method indication. The second node may receive the broadcast message to obtain the authentication method indication and thus execute the corresponding authentication process.
[0039] In another possible implementation of the first aspect, the first node and the second node communicate via a first communication protocol. During the authentication process, the format of the first authentication message exchanged between the second node and the first node is the frame format defined by the first authentication protocol. Further, the first authentication message is carried on the data portion of a first protocol data unit (PDU) transmitted between the first node and the second node, and the format of the first PDU is the PDU format specified by the first communication protocol.
[0040] The above implementation describes a compatible message for the first authentication protocol within the first communication protocol. The first node and the second node communicate using the first communication protocol. When they need to exchange authentication messages, the authentication message is encapsulated within the data portion of the PDU of the first communication protocol.
[0041] Furthermore, the protocol stack of the first communication protocol includes multiple protocol layers, and each protocol layer has a corresponding PDU. The aforementioned first PDU can be a PDU of one of the protocol layers. Taking the first communication protocol as StarSpark as an example, the StarSpark protocol stack architecture from top to bottom is: application layer, network and transport layer, data link layer (including link control layer and media access layer), and physical layer. The physical layer is layer one, the data link layer is layer two (i.e., L2), and the data link layer can include two sub-layers, and so on for the remaining layers. The aforementioned first PDU can be a link control layer PDU or a data link layer PDU.
[0042] In another possible implementation of the first aspect, the data portion of the first PDU further includes a first message type field, which indicates the message type of the first authentication message carried by the data portion of the first PDU, and indicates one of the following message types: start, completion, online, logout, or data.
[0043] In another possible implementation of the first aspect, the data portion of the first PDU further includes a data length field, which indicates the data length of the first authentication message carried by the data portion of the first PDU.
[0044] In yet another possible implementation of the first aspect, negotiating and determining the first KDF with the first node includes: performing a security context negotiation procedure with the first node. During the security context negotiation procedure, the second node negotiates and determines the first KDF with the first node.
[0045] In another possible implementation of the first aspect, the security context negotiation process with the first node includes: sending a first message to the first node and receiving a second message from the first node. The first message includes the security capabilities of the second node, which indicate the security algorithms supported by the second node, including KDF. The second message includes indication information for the first KDF.
[0046] In yet another possible implementation of the first aspect, the security context negotiation process further includes: sending a third message to the first node and receiving a fourth message from the first node. The third message is used in response to the second message, and the fourth message is used to indicate whether an association has been established between the first node and the second node.
[0047] In another possible implementation of the first aspect, the first message further includes a first key negotiation parameter related to a session key between the first node and the second node, and the second message further includes a second key negotiation parameter used to determine a session key between the first node and the second node.
[0048] Furthermore, the session key includes a signaling plane encryption key, a signaling plane integrity protection key, a user plane encryption key, a user plane integrity protection key, and a user plane authentication encryption key.
[0049] In another possible implementation of the first aspect, the first message further includes a first fresh parameter, and the second message further includes a second fresh parameter.
[0050] In another possible implementation of the first aspect, the first key is used to verify information that has been transmitted by the first node and the second node.
[0051] It's important to emphasize the difference between information verification and security protection. Security protection occurs simultaneously with information transmission. For example, encryption and security measures are usually completed concurrently with message transmission; the information is encrypted during message delivery. Similarly, checksums used to verify information integrity are typically carried within the same message or several related messages (considering message segmentation). In contrast, information verification usually occurs after successful transmission. For instance, it might be triggered at some point after the message has been received, to verify the message or its content. Therefore, the information verified by the first key is information transmitted previously (e.g., before the first key was received or before it was saved).
[0052] For example, the information that has been transmitted includes, but is not limited to, the following: information transmitted during the negotiation of the first KDF, information transmitted during the security context negotiation process (where a security context negotiation process exists), and information transmitted between security context negotiation processes (e.g., broadcast messages).
[0053] Therefore, the above implementation provides a new application of the first key, which is beneficial to forward information security.
[0054] In another possible implementation of the first aspect, the method further includes: receiving a first verification parameter from a first node, and verifying the first verification parameter. The first verification parameter is related to a first key and first information to be verified. The first information to be verified pertains to information that has already been transmitted between the first node and the second node.
[0055] As a possible example, the first information to be verified includes at least a portion of the information sent to the first node during the security context negotiation process. The security context negotiation process is described above; it is understood that the security context negotiation process includes a process of negotiating a first KDF with the first node. Further, the first information to be verified also includes a portion of the information sent by the first node to the second node during the security context negotiation process, and / or the information sent by the first node in a broadcast message.
[0056] For example, the first verification parameter HASHg is calculated as follows: HASHg = KDF(RK, NONCEg, first message content, third message content). Here, KDF identifies the first KDF, RK is the first key, NONCEg is the second fresh parameter (carried in the second message), the first message content includes part or all of the first message content, and the third message content includes part or all of the third message content. Furthermore, the second node can determine a check value based on the same input parameters and compare the check value with the first verification parameter to verify whether the first verification parameter is correct.
[0057] When the first verification parameter is verified to be correct, it indicates that the first key determined by the first node and the third node are consistent, and that the information previously transmitted between the first node and the second node has not been tampered with.
[0058] In another possible implementation of the first aspect, the method further includes: generating a second verification parameter based on a first key and second verification information, and sending the second verification parameter to a first node. The second verification information is information that has already been transmitted between the first node and the second node.
[0059] As one possible example, the second information to be verified includes at least part of the information received from the first node during the security context negotiation process, which includes a process of negotiating with the first node to obtain the first KDF.
[0060] Secondly, this application provides a communication method, comprising: negotiating and determining a first Key Authentication Function (KDF) with a second node; sending security parameters to a third node; exchanging a first authentication message with the second node and a second authentication message with the third node; and receiving a first key from the third node. The second node is a node requesting association with the first node, and the third node is used for authentication, such as authenticating a node accessing the network (e.g., the second node). The security parameters include indication information of the first KDF, and the first key is associated with the first KDF and key information.
[0061] This method can be applied to a first node, which is a device with communication capabilities. In practice, the method can be executed by software modules, hardware modules, or a combination of both within the first node, such as a chip or processor. For ease of description, the following explanation uses the first node as the executing entity.
[0062] In the application process, when a second node requests association with a first node, the second node can negotiate and determine a first Key Validation Principle (KDF) with the first node. This first KDF can serve as the KDF for deducing the authentication key. The first node can report the indication information of the first KDF to a third node. During the deduction of the first key between the third node and the second node, the key deduction is performed based on the negotiated first KDF. Because the first KDF is negotiated and determined, the first KDF negotiated and determined by the second node with the first node may be different for second nodes with different security capabilities. This allows the association and authentication process to adapt to terminals with different security capabilities, improving network compatibility and enhancing the user experience.
[0063] In one possible implementation of the second aspect, the security parameters also include a first fresh parameter, which is derived from the second node, and the first key is also associated with the first fresh parameter.
[0064] In another possible implementation of the second aspect, the security parameters also include a second fresh parameter, which is generated by the first node, and the first key is also associated with the second fresh parameter.
[0065] The aforementioned implementation methods can be combined. For example, the security parameters include a first fresh parameter and a second fresh parameter, and the first key is related to both the first fresh parameter and the second fresh parameter.
[0066] In another possible implementation of the second aspect, the first key is also associated with a third freshness parameter. The third freshness parameter is the freshness parameter determined by the third node.
[0067] Furthermore, the method also includes: receiving a third fresh parameter from a third node and sending the third fresh parameter to a second node.
[0068] In the above implementation, the third node can send the third fresh parameter to the second node through the first node, so that the second node can obtain the third fresh parameter and generate the first key using the same parameters as the third node.
[0069] In another possible implementation of the second aspect, the first key is also associated with the identifier of the first node and / or the identifier of the second node.
[0070] In another possible implementation of the second aspect, the first authentication message and the second authentication message belong to the messages defined by the TLS-based EAP authentication protocol, and the key information includes the TLS master key.
[0071] In another possible implementation of the second aspect, the first authentication message and the second authentication message belong to the EAP authentication protocol defined by the account password, and the key information includes the password corresponding to the second node. Further, the key information also includes the account corresponding to the second node.
[0072] In yet another possible implementation of the second aspect, the method further includes: sending an authentication method indication. The authentication method indication is used to indicate an authentication method.
[0073] Furthermore, the authentication method indicator is used to indicate EAP authentication, and the first authentication message and the second authentication message are messages defined by the authentication protocol of EAP authentication.
[0074] In another possible implementation of the second aspect, the first node and the second node communicate via a first communication protocol. The format of the first authentication message exchanged between the first node and the second node during the authentication process is the frame format defined by the first authentication protocol. The first authentication message carries the data portion of the first PDU transmitted between the first node and the second node, and the format of the first PDU is the PDU format specified by the first communication protocol.
[0075] In another possible implementation of the second aspect, the data portion of the first PDU further includes a first message type field, which indicates the message type of the first authentication message carried by the data portion of the first PDU. The first message type field indicates one of the following message types: start, completion, online, logout, or data.
[0076] In another possible implementation of the second aspect, the data portion of the first PDU further includes a data length field, which indicates the data length of the first authentication message carried by the data portion of the first PDU.
[0077] In another possible implementation of the second aspect, the first node and the third node communicate via a second communication protocol. The information transmitted between the first node and the third node is encapsulated in data packets, the format of which is specified by the first communication protocol, which differs from the second communication protocol. The data packets are carried on the payload of a second protocol data unit (PDU) transmitted between the first node and the third node, and the second PDU is formatted according to the second communication protocol.
[0078] In the above embodiment, the first node and the third node communicate using the second communication protocol. Since the first node also supports the first communication protocol, the messages encapsulated in the first communication protocol transmitted between the first node and the third node can be transmitted in the data portion of the messages encapsulated in the second communication protocol. That is, the format of the second PDU transmitted between the first node and the third node is the format specified by the second communication protocol, but the payload portion of the second PDU carries the messages of the first communication protocol.
[0079] For example, the second communication protocol is the Ethernet communication protocol, while the first communication protocol is the StarSpark communication protocol. Information transmitted between the first and third nodes is encapsulated using the StarSpark message format, and the StarSpark message is carried in the payload of the Ethernet message. The messages transmitted between the first and third nodes are Ethernet messages. This is equivalent to using the second communication protocol's messages to overwrite the first communication protocol's messages, allowing information transmitted using the first communication protocol to be transmitted using the second communication protocol, thus improving compatibility between different communication protocols.
[0080] In another possible implementation of the second aspect, the payload portion of the second PDU further includes a second message type field, which indicates the message type of the data packets carried by the payload portion of the second PDU. For example, the second message type field indicates one of the following message types: security parameter reporting or authentication key distribution. The security parameter reporting message includes the aforementioned security parameters. The authentication key distribution message includes the aforementioned first key.
[0081] In another possible implementation of the second aspect, negotiating and determining the first KDF with the second node includes: conducting a security context negotiation process with the second node. During the security context negotiation process, the first node may negotiate and determine the first key derivation arithmetic with the second node.
[0082] In another possible implementation of the second aspect, the security context negotiation process with the first node includes: receiving a first message from the second node and sending a second message to the second node. The first message includes the security capabilities of the second node, which indicate the security algorithms supported by the second node, including KDF (Security Defender). The second message includes indication information for the first KDF.
[0083] In another possible implementation of the second aspect, the security context negotiation process with the first node further includes: receiving a third message from the second node and sending a fourth message to the second node. The third message is used in response to the second message, and the fourth message is used to indicate whether an association has been established between the first node and the second node.
[0084] In yet another possible implementation of the second aspect, the first message further includes a first key negotiation parameter used to determine a session key between the first node and the second node. The second message also includes a second key negotiation parameter related to the session key between the first node and the second node.
[0085] In another possible implementation of the second aspect, the first message further includes a first fresh parameter, and the second message further includes a second fresh parameter.
[0086] In another possible implementation of the second aspect, the first key is used to verify information that has been transmitted by the first node and the second node.
[0087] In another possible implementation of the second aspect, the method further includes: receiving a second verification parameter from a second node and verifying the second verification parameter. The second verification parameter is related to the first key and information already transmitted between the first and second nodes.
[0088] In another possible implementation of the second aspect, the method further includes: generating a first verification parameter based on a first key, information already transmitted between the first node and the second node, and sending the first verification parameter to the second node.
[0089] Thirdly, this application provides a communication method, comprising: receiving security parameters from a first node, performing an authentication process with a second node, and, if the authentication process is successful, determining a first key based at least on a first KDF and key information.
[0090] The security parameters include indication information from the first KDF. This authentication process is executed jointly with the second node; that is, the second node also participates in the authentication process. Furthermore, this authentication process is used to authenticate the second node.
[0091] This method can be applied to a third node, which is an authentication device with communication capabilities. In practice, this method can be executed by a software module, a hardware module, or a combination of both, such as a chip or processor. For ease of description, the following explanation uses a third node as the executing entity.
[0092] In one possible implementation of the third aspect, the authentication process is performed with the second node, including: interacting with the first node to exchange a second authentication message, wherein the first node is used to interact with the second node to exchange a first authentication message.
[0093] In another possible implementation of the third aspect, after determining the first key based at least on the first KDF and key information, the method further includes: sending the first key to the first node.
[0094] In another possible implementation of the third aspect, determining the first key is based at least on the first KDF and key information, including: determining the first key based on the first KDF, key information, a first freshness parameter and / or a second freshness parameter.
[0095] Optionally, the first freshness parameter may be included in the safety parameters, and the second freshness parameter may also be included in the safety parameters. That is, the safety parameters may also include the first freshness parameter and / or the second freshness parameter.
[0096] In another possible implementation of the third aspect, determining the first key based on the first KDF, key information, first freshness parameter, and second freshness parameter includes: determining the second key based on the first KDF, key information, first freshness parameter, and second freshness parameter, and determining the first key based on the first KDF and the second key.
[0097] In another possible implementation of the third aspect, determining the first key is based at least on the first KDF and key information, including: determining a third freshness parameter, and determining the first key based on the first KDF, key information and the third freshness parameter.
[0098] In another possible implementation of the third aspect, determining the first key based on the first KDF, key information, and third freshness parameter includes: determining the second key based on the first KDF, key information, and third freshness parameter, and determining the first key based on the first KDF and the second key.
[0099] Furthermore, the aforementioned determination of the first key based on the first KDF and the second key includes: determining the first key based on the first KDF, the second key, the identifier of the first node, and the identifier of the second node.
[0100] Optionally, the identifier of the first node can be carried in the security parameters, and the identifier of the second node can also be carried in the security parameters. That is, the security parameters also include the identifier of the first node and / or the identifier of the second node.
[0101] In another possible implementation of the third aspect, after determining the third freshness parameter, the method further includes: sending the third freshness parameter to the first node.
[0102] In another possible implementation of the third aspect, the authentication process belongs to the authentication process defined by the TLS-based EAP authentication protocol, and the key information includes the TLS master key.
[0103] In another possible implementation of the third aspect, the authentication process belongs to the authentication process defined by the EAP authentication protocol based on account and password, and the key information includes the account and password corresponding to the second node.
[0104] In another possible implementation of the third aspect, the first node and the third node communicate via a second communication protocol. The information transmitted between the first node and the third node is encapsulated in data packets, and the format of the data packets is specified by the first communication protocol, which is different from the second communication protocol. The data packets are carried on the payload of the second protocol data unit (PDU) transmitted between the first node and the third node, and the format of the second PDU is specified by the second communication protocol.
[0105] In another possible implementation of the third aspect, the payload portion of the second PDU further includes a second message type field, which indicates the message type of the data packets carried by the payload portion of the second PDU. For example, the second message type field indicates one of the following message types: security parameter reporting or authentication key distribution. The security parameter reporting message includes the aforementioned security parameters. The authentication key distribution message includes the aforementioned first key.
[0106] Fourthly, this application provides a communication method, comprising: performing an authentication process with a third node, and, if the authentication process is successful, determining a first key based at least on a first freshness parameter, a second freshness parameter, and key information. Wherein, the first node is a node to which the second node requests association, the first freshness parameter is generated by the second node, and the second freshness parameter originates from the first node. The third node and the first node belong to the same device, or the third node and the first node are communicatively connected.
[0107] The above method is applied to a second node, for example, executed by the second node or a module within the second node. This provides a novel way to determine the first key, using first and second fresh parameters exchanged between the first and second nodes to participate in the generation of the first key. These first and second fresh parameters, as fresh values, participate in the derivation process of the first key, further ensuring the privacy and uniqueness of the derived first key and helping to improve the security performance of the node.
[0108] Optionally, the method further includes: determining a first fresh parameter and sending the first fresh parameter to the first node.
[0109] In one possible implementation of the fourth aspect, determining the first key based at least on a first freshness parameter, a second freshness parameter, and key information includes: determining the first key based at least on a first KDF, the first freshness parameter, the second freshness parameter, and key information. The first KDF may be determined through negotiation between a first node and a second node, or the first KDF may be predefined, or the first KDF may be determined through negotiation between a second node and a third node.
[0110] In some solutions, some possible implementations of the first aspect can be combined with the content of the fourth aspect to form a variety of possible implementations.
[0111] Fifthly, this application provides a communication method, comprising: sending security parameters to a third node, exchanging a first authentication message with a second node and exchanging a second authentication message with the third node, and receiving a first key from the third node. The security parameters include a first freshness parameter and a second freshness parameter, and the first key is associated with the first freshness parameter, the second freshness parameter, and key information. The first node is the node requested for association by the second node, and the third node is used for authentication.
[0112] The above method is applied to the first node, for example, executed by the first node or a module within the first node. This provides a novel way to determine the first key, using first and second fresh parameters exchanged between the first and second nodes to participate in the generation of the first key. These first and second fresh parameters, as fresh values, participate in the derivation process of the first key, further ensuring the privacy and uniqueness of the derived first key and helping to improve the security performance of the node.
[0113] Optionally, the method further includes: determining a second fresh parameter and sending the second fresh parameter to a second node. It further includes: receiving a first fresh parameter from the second node.
[0114] In one possible implementation of the fifth aspect, the first key is generated via a first KDF. The first KDF may be determined through negotiation between the first node and the second node, or the first KDF may be predefined, or the first KDF may be determined through negotiation between the second node and the third node.
[0115] In some solutions, some possible implementations of the second aspect mentioned above can be combined with the content of the fifth aspect to form a variety of possible implementations.
[0116] Sixthly, this application provides a communication method, comprising: receiving security parameters from a first node, performing an authentication process with a second node, and, if the authentication process is successful, determining a first key based on a first fresh parameter, a second fresh parameter, and key information. The first fresh parameter is generated by the second node, and the second fresh parameter is generated by the first node. The security parameters include the first and second fresh parameters, and the first node and the second node have a communication connection.
[0117] The above method applies a third node, for example, executed by the third node or a module within the third node. This provides a novel way to determine the first key, using first and second fresh parameters exchanged between the first and second nodes to participate in the generation of the first key. These first and second fresh parameters, as fresh values, participate in the derivation process of the first key, further ensuring the privacy and uniqueness of the derived first key and helping to improve the security performance of the node.
[0118] In one possible implementation of the sixth aspect, determining the first key based at least on a first freshness parameter, a second freshness parameter, and key information includes: determining the first key based at least on a first KDF, the first freshness parameter, the second freshness parameter, and key information. The first KDF may be determined through negotiation between a first node and a second node, or the first KDF may be predefined, or the first KDF may be determined through negotiation between a second node and a third node.
[0119] In some solutions, some possible implementations of the aforementioned third aspect can be combined with the content of the sixth aspect to form a variety of possible implementations.
[0120] In a seventh aspect, this application provides a communication device, which includes a unit or module for performing the method described in the first aspect or any possible implementation of the first aspect.
[0121] And / or, the communication device includes a unit or module for performing the method described in the second aspect or any possible implementation of the second aspect.
[0122] And / or, the communication device includes a unit or module for performing the method described in the third aspect or any possible implementation of the third aspect.
[0123] And / or, the communication device includes a unit or module for performing the method described in the fourth aspect or any possible implementation of the fourth aspect.
[0124] And / or, the communication device includes a unit or module for performing the method described in the fifth aspect or any possible implementation of the fifth aspect.
[0125] And / or, the communication device includes a unit or module for performing the method described in the sixth aspect or any possible implementation of the sixth aspect.
[0126] For example, the communication device includes a processing unit and a communication unit. The processing unit performs one or more operations such as negotiation, processing, determination, generation, calculation, encryption, and decryption. The communication unit performs one or more operations such as sending and receiving.
[0127] Eighthly, this application provides a node including a processor and a memory, the memory for storing computer instructions, and the processor for calling the computer instructions stored in the memory to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the fourth aspect or any possible implementation of the fourth aspect.
[0128] In a ninth aspect, this application provides a node comprising at least one processor and at least one memory, wherein the at least one memory is used to store computer instructions, and the at least one processor is used to invoke the computer instructions stored in the memory to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the fifth aspect or any possible implementation of the fifth aspect.
[0129] In a tenth aspect, this application provides a node comprising at least one processor and at least one memory, wherein the at least one memory is used to store computer instructions, and the at least one processor is used to invoke the computer instructions stored in the memory to implement the method described in the third aspect or any possible implementation of the third aspect, or to implement the method described in the sixth aspect or any possible implementation of the sixth aspect.
[0130] In the eleventh aspect, this application provides a chip including at least one processor and an interface circuit. The interface circuit is used to receive signals from other communication devices (including nodes) and transmit them to the processor, or to send signals from the processor to other communication devices (including nodes). The processor implements the aforementioned communication method through logic circuits or executing code instructions.
[0131] For example, the processor is configured to implement the method described in the first aspect or any possible implementation of the first aspect, and / or to implement the method described in the second aspect or any possible implementation of the second aspect, and / or the method described in the third aspect or any possible implementation of the third aspect, and / or the method described in the fourth aspect or any possible implementation of the fourth aspect, and / or the method described in the fifth aspect or any possible implementation of the fifth aspect, and / or the method described in the sixth aspect or any possible implementation of the sixth aspect.
[0132] In a twelfth aspect, this application provides a communication system, which includes a first node and a second node. The first node is used to implement the method described in the first aspect or any possible implementation of the first aspect, and the second node is used to implement the method described in the second aspect or any possible implementation of the second aspect.
[0133] In one possible implementation of the twelfth aspect, the communication system further includes a third node for implementing the method described in the third aspect or any possible implementation of the third aspect. Optionally, the node and the third node may be integrated in the same device.
[0134] In a thirteenth aspect, this application provides a communication system, which includes a first node and a second node. The first node is used to implement the method described in the fourth aspect or any possible implementation of the fourth aspect, and the second node is used to implement the method described in the fifth aspect or any possible implementation of the fifth aspect.
[0135] In one possible implementation of the thirteenth aspect, the communication system further includes a third node for implementing the method described in the sixth aspect or any possible implementation of the sixth aspect. Optionally, the node and the third node may be integrated in the same device.
[0136] In a fourteenth aspect, this application provides a terminal, which includes the communication device described in the seventh aspect, or the node described in the eighth aspect, or the node described in the ninth aspect, or the node described in the tenth aspect, or the chip described in the eleventh aspect, or the communication system described in the twelfth aspect, or the communication system described in the thirteenth aspect. Optionally, the terminal may be a handheld terminal, a vehicle, a robot, a drone, or other intelligent device or vehicle.
[0137] In a fifteenth aspect, this application provides a readable storage medium for storing a computer program that, when executed by a processor, causes a communication device including a processor to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect, or to implement the method described in the fourth aspect or any possible implementation of the fourth aspect, or to implement the method described in the fifth aspect or any possible implementation of the fifth aspect, or to implement the method described in the sixth aspect or any possible implementation of the sixth aspect.
[0138] In a sixteenth aspect, this application provides a computer program product that, when executed by a processor, causes a communication device including the processor to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect, or to implement the method described in the fourth aspect or any possible implementation of the fourth aspect, or to implement the method described in the fifth aspect or any possible implementation of the fifth aspect, or to implement the method described in the sixth aspect or any possible implementation of the sixth aspect.
[0139] For some of the beneficial effects of the technical solutions in aspects two through sixteen of this application, please refer to the beneficial effects of the technical solutions in aspect one. Attached Figure Description
[0140] The accompanying drawings used in the description of the embodiments will be briefly introduced below.
[0141] Figure 1 This is a schematic diagram of the architecture of a communication system;
[0142] Figure 2 This is a schematic diagram of the connection relationship between nodes in a wireless BMS scenario;
[0143] Figure 3 This is a schematic diagram illustrating the connection relationships between nodes in a smart home scenario.
[0144] Figure 4 This is a schematic diagram of the architecture of another communication system;
[0145] Figure 5 This is a flowchart illustrating a communication method provided in an embodiment of this application;
[0146] Figure 6 This is a flowchart illustrating a security context negotiation process;
[0147] Figure 7 This is a flowchart illustrating the EAP certification process;
[0148] Figure 8 This is a schematic diagram of a transmission unit of a second communication protocol compatible with a message of a first communication protocol, provided in an embodiment of this application.
[0149] Figure 9 This is a schematic diagram of a transmission unit of a second communication protocol that is compatible with a first communication protocol, as provided in another embodiment of this application.
[0150] Figure 10 This is a schematic diagram of a transmission unit compatibility authentication protocol for a first communication protocol provided in an embodiment of this application;
[0151] Figure 11 This is a schematic diagram of a key derivation method provided in an embodiment of this application;
[0152] Figure 12 This is a schematic diagram of another key derivation method provided in the embodiments of this application;
[0153] Figure 13 This is a flowchart illustrating another communication method provided in an embodiment of this application;
[0154] Figure 14 This is a flowchart illustrating another communication method provided in an embodiment of this application;
[0155] Figure 15 This is a flowchart illustrating another communication method provided in an embodiment of this application;
[0156] Figure 16 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0157] Figure 17 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0158] The following section will introduce some of the technical terms.
[0159] 1. Node
[0160] A node is a device with communication capabilities, including but not limited to one or more of user equipment, network equipment, and industrial equipment. User equipment includes one or more of handheld terminals, wearable terminals, vehicles, in-vehicle equipment, sensing devices, smart home devices, or leisure and entertainment devices. Handheld terminals include, but are not limited to, mobile phones, tablets, or laptops. Wearable devices include, but are not limited to, headphones, smart bracelets, smartwatches, or smart glasses. Vehicles include, but are not limited to, vehicles, ships, aircraft, rail transit (such as subways and high-speed trains), or logistics robots (such as automated guided vehicles (AGVs)). In-vehicle equipment includes, but is not limited to, domain controllers (DCs), screens, microphones, speakers, electronic keys, keyless entry, start system controllers, battery management systems (BMS), battery packs, or battery cells. Sensing devices include, but are not limited to, cameras, radar, lidar, light sensors, temperature sensors, or humidity sensors. Smart home devices include, but are not limited to, projectors, smart TVs, smart refrigerators, smart home gateways, or security equipment. Leisure and entertainment equipment includes, but is not limited to, virtual reality (VR) devices, mixed reality (MR) devices, massage chairs, home theaters, gaming controllers, or 4D cinema cabins. Network equipment includes, but is not limited to, routers, switches, or base stations. Industrial equipment includes, but is not limited to, industrial robots or robotic arms.
[0161] This application is applicable to a variety of networks, and nodes will be used in this document to represent devices in these networks.
[0162] Exemplary, this application can be applied to wired communication networks, wireless communication networks, or networks formed by a combination of wired and wireless communication. For example, wireless communication networks include networks connected via communication technologies such as SparkLink (or NearLink), 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB), or short-range wireless communication systems. And / or, wireless communication networks include long-range connectivity technologies, such as communication technologies based on Long Term Evolution (LTE), 5th generation mobile networks (or 5th generation wireless systems, 5th-Generation, abbreviated as 5G or 5G technology), Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), and Universal Mobile Telecommunications System (UMTS), etc. For example, wired communication networks include networks connected via the following communication technologies: fiber optic connection technology, in-vehicle wired communication technology, controller area network (CAN), local interconnect network (LIN), CAN flexible data rate (CAN FD), or in-vehicle Ethernet, or one or more of these.
[0163] The nodes in this application embodiment can be applied to various scenarios such as smart cars, smart homes, smart terminals, smart manufacturing, smart showrooms, mobile internet (MI), industrial control, self-driving, transportation safety, or the Internet of Things (IoT).
[0164] It should be understood that in certain application scenarios or network types, devices with communication capabilities may not be referred to as nodes. However, for ease of description, devices with communication capabilities are collectively referred to as nodes in this application embodiment.
[0165] 2. Key Derivation Function (KDF)
[0166] Key Derivation Functions (KDFs), also known as key derivation algorithms, key derivation functions, and key inference functions, are used to derive (or derive) one or more secret values from a given secret value. For example, a new secret value DK derived from the secret value Key can be represented as: DK = KDF(Key). Of course, Key here is just an example; in actual implementations, other parameters can participate in the key derivation process.
[0167] The key derivation algorithms involved in the embodiments of this application may include hash algorithms, password-based key derivation functions (PBKDF), scrypt algorithms, etc. For example, hash algorithms include algorithms called hash-based message authentication codes (HMAC) and password-based message authentication codes (CMAC). Specifically, the hash algorithm used in HMAC can be one of the following: Chinese national cryptographic algorithms (such as SM3), SHA-256, SHA-1, etc. These different HMACs are usually labeled as: HMAC-SM3, HMAC-SHA 256, HMAC-SHA1, etc. CMAC can be combined with other cryptographic algorithms, for example, combined with the Advanced Encryption Standard (AES) to form the AES-CMAC algorithm. The PBKDF algorithm includes the first generation PBKDF1 and the second generation PBKDF2.
[0168] It should be understood that some KDF algorithms can perform hash transformations on the input secret value using hash algorithms. Therefore, KDF functions can also accept an algorithm identifier as input, indicating which hash algorithm to use. It should be noted that KDF is not only used for deriving secret values, but also for generating authentication and identity information.
[0169] 3. Session key
[0170] A session key is a key used to securely protect information transmitted between two communicating parties. Security protection includes one or more of the following: confidentiality protection, integrity protection, and authentication encryption. Confidentiality protection requires the use of an encryption key or an authentication encryption key. Integrity protection requires the use of an integrity protection key or an authentication encryption key.
[0171] 4. Freshness parameters
[0172] Freshness parameters are used in encryption, integrity protection, key derivation, key negotiation, and other processes; they can also be called freshness or freshness parameters. Generally, the specific value of the freshness parameter changes after each generation, ensuring that the value of the freshness parameter determined this time is different from that of the previous generation, thus improving security.
[0173] For example, fresh parameters may include random numbers (such as NONCE), counter values, etc.
[0174] The foregoing explanation of the technical terms may be used in the embodiments described below.
[0175] The following describes the architecture and business scenarios of communication systems to which the embodiments of this application can be applied. It should be noted that the system architecture and business scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. It should be understood that as system architectures evolve and new business scenarios emerge, the technical solutions provided in this application are also applicable to similar technical problems.
[0176] This application can be applied to communication systems, which transmit information using electrical signals (or optical signals). A communication system typically includes multiple nodes that can establish communication connections to transmit information. Nodes in a communication system may have different identities and / or different capabilities. In one exemplary communication system, nodes are distinguished as master nodes and slave nodes. The master node has stronger communication capabilities and the ability to manage slave nodes, and can establish links with multiple slave nodes, enabling communication between master nodes and between master nodes and slave nodes to achieve various functions.
[0177] Communication systems can include wired and wireless communication systems. Wireless communication systems include short-range and long-range wireless communication systems. Examples of short-range communication systems include StarSpeed communication systems, 802.11b / g, and Bluetooth. Examples of long-range wireless communication systems include LTE and 5G. The following section uses the StarSpeed communication system as an example to introduce the architecture of a communication system, combined with... Figure 1 The communication system includes management nodes and terminal nodes. Among them:
[0178] Management nodes possess both communication and management capabilities, and are sometimes referred to as G nodes, access points, or authorized nodes. Management capabilities include communication management, such as connection management, resource scheduling, or information security management. For example, a management node can send resource management information or data scheduling information, such as access layer resource management information.
[0179] Terminal nodes, also known as T-nodes in some scenarios, have communication capabilities and can transmit services with management nodes. In some solutions, terminal nodes are nodes that receive resource management information (or data scheduling information) and send data according to the resource management information (or data scheduling information). For example, terminal nodes may include user equipment (UE), such as barcode scanners, radio frequency identification (RFID), sensors, global positioning system (GPS), lidar, and battery cells.
[0180] It should be understood that the identities of management nodes and terminal nodes are not absolute. The identities shown herein are merely exemplary names used to distinguish the operation of communicating nodes in a possible connection scenario. In some scenarios, a node may belong to two or more communication domains simultaneously, acting as a terminal node in some domains and as a management node in others. For ease of understanding, such a node is referred to as a G(T) node in some embodiments.
[0181] Combination Figure 1 Terminal nodes and management nodes can establish associations. Establishing an association requires executing a specific association process. Before executing this process, the management node can send a broadcast message, which the terminal node can use to detect the management node. Furthermore, a terminal node can request to associate with the management node. After the terminal node and management node complete the corresponding association process, an association relationship can be established.
[0182] It should be noted that, in Figure 1 In this diagram, the connection between the management node and the terminal node is represented by a dashed line. However, in some schemes, the connection includes two links: a communication link to the management node and a communication link to the terminal node. The communication link to the management node is the communication link from the management node to the terminal node, and can carry one or more of the following: data channel, control information, broadcast channel, synchronization signal, etc., from the management node to the terminal node; this can be called a G-link. The communication link to the terminal node is the communication link from the terminal node to the management node, and can carry one or more of the following: data channel, access channel, or feedback signal, etc., from the terminal node to the management node; this can be called a T-link.
[0183] Optionally, communication between the management node and the terminal nodes may include unicast, multicast, and / or broadcast communication. In some schemes, such as... Figure 1 As shown, a management node can connect to one or more terminal nodes. In the StarFlash communication system, a management node supports connecting to multiple terminal nodes, and a terminal node also supports associating with multiple management nodes.
[0184] This application supports the Spark Link / NearLink protocol, or it supports IEEE protocols such as IEEE 802.11be / WiFi 7 / EHT (extremely high throughput), IEEE 802.11bn / WiFi 8 / UHR (ultra-high reliability), IEEE IMMW (Integrated mmWave), IEEE 802.15.4ab / U WB (ultra-wideband), and IEEE 802.11bf / Sensing.
[0185] The communication system used in this application can be used in scenarios such as vehicles, smart homes, smart showrooms, and energy storage management.
[0186] Taking vehicle scenarios as an example, this communication system can be applied to wireless battery management system (BMS) scenarios or tire pressure monitoring scenarios. For wireless BMS scenarios, please refer to [link to relevant documentation]. Figure 2 As shown, the battery array management system (BAMS) is the management node, i.e., the G1 node, the battery cluster management system (BCMS) is the G(T) node (dual identity node), and the battery management unit (BMU) is the T node.
[0187] For smart home scenarios, see [examples]. Figure 3 As shown. Figure 3 In this system, the gateway or customer premises equipment (CPE) is designated as the G node, the sub-router, large screen, mobile phone, and air conditioner are designated as the G(T) nodes, and the water heater, smart curtain, speaker, microphone, printer, and smart door lock are designated as the T nodes.
[0188] To enhance control over nodes accessing the network, communication systems typically introduce authentication nodes (often referred to as third-party nodes for easy identification) to authenticate the identities of nodes within the network. Please see [link to relevant documentation]. Figure 4 , Figure 4 This is a schematic diagram of the architecture of another communication system, which includes a first node 10 (which can be regarded as a management node), a second node 20 (which can be regarded as a terminal node) and a third node 30.
[0189] In this system, the first node 10 can be associated with by other nodes, while the second node 20 can request to associate with the first node 10. During the process of the second node 20 associating with the first node 10, the third node 30 can authenticate the identity of the second node 20. It should be understood that the third node 30 here refers to a functional module capable of performing identity authentication. In specific embodiments, the third node 30 may be a physical device or a virtual device. For example, the third node may include authentication devices, authentication services, etc., where authentication devices include, for example, a Radius server, a portal server, an access controller (AC), an authentication node, or an authentication server, etc., and authentication services include, for example, a third-party Radius, an SMS server, etc.
[0190] It should be noted that, Figure 4 The devices shown are merely examples. In some implementations, the third node 30 can be integrated with the first node 10 in the same device; however, this application also applies to cases where they are configured separately. Similarly, the first node 10 and the second node 20 may also be integrated into the same device; likewise, this application also applies to cases where they are configured separately.
[0191] In some scenarios (such as in enterprise networks), to ensure internal network security during the association process between the second node and the first node, a third node is needed to authenticate the network nodes. During authentication, the first and second nodes obtain a consistent authentication key, which is typically generated uniformly according to the authentication protocol. The first and second nodes can then derive a session key based on this authentication key to achieve secure communication. Currently, the confidentiality of authentication keys is insufficient, and the method of generating authentication keys does not consider the differences in security capabilities among nodes accessing the network.
[0192] In view of this, this application provides a communication method and related apparatus. In this application, the first node and the second node can negotiate and determine the KDF. The second node and the third node can deduce the authentication key based on the negotiated KDF, so that the association and authentication process can be adapted to terminals with different security capabilities, thereby improving network compatibility and enhancing the user experience.
[0193] The methods provided in the embodiments of this application will be described below.
[0194] Please see Figure 5 , Figure 5 This is a flowchart illustrating a communication method provided in an embodiment of this application. Optionally, this method can be applied to a communication system, such as... Figure 4 The communication system shown. (As shown) Figure 5 The communication method shown may include one or more steps S501 to S506. It should be understood that, for ease of description, the method is described in the order of steps S501 to S506, and is not intended to limit the execution to this specific order. This application embodiment does not limit the order of execution, the execution time, or the number of executions of the above one or more steps. Steps S501 to S506 are as follows:
[0195] Step S501: The second node negotiates with the first node to determine the first KDF.
[0196] The first and second nodes have communication capabilities and can be independent devices or modules within independent devices. The first node is the associated node, while the second node is the node that requests to associate with the first node. In some scenarios, the first node may be called a management node (or access point, G node), and the second node may be called a terminal node (or T node).
[0197] Optionally, the first node can send a broadcast message carrying its information. Taking the StarScan communication protocol as an example, this broadcast message can be a communication domain system message. The second node can receive the broadcast message, thereby becoming aware of the first node and requesting association with it.
[0198] The first Key Derivative Array (KDF) indicates a specific key derivation algorithm, such as HMAC-SM3, HMAC-SHA256, or AES-CAMC. Referring to Table 1, the first and second nodes can negotiate and determine that the GHA1 algorithm (i.e., the HMAC-SM3 algorithm) is the first KDF. Since the first KDF is determined through negotiation between the first and second nodes, it belongs to the KDFs supported by the second node; naturally, the first node should also support this first KDF. It should be noted that the KDFs shown in Table 1 are merely examples; in actual implementations, there may be many more types of KDFs, and their names, identifiers, and descriptions may have different designs.
[0199] It should be understood that the value illustration tables proposed in this application, such as Table 1, and Tables 2 and 3 below, are exemplary descriptions made to facilitate understanding of the solution of this application, and are not intended to limit the implementation of the solution of this application to the values illustrated in the tables. This application is equally applicable to other values, field designs, attribute designs in the tables, attribute sorting, etc.
[0200] The following are several ways to negotiate and determine the first KDF:
[0201] In Method 1, the second node sends its security capabilities to the first node. These capabilities indicate the algorithms supported by the second node. The first node can then select a first KDF (Key-Definition Array) based on these capabilities. Further, the first node sends the indication information of the selected first KDF to the second node.
[0202] As an example of a possible security capability, a security capability includes one or more fields, each indicating whether a second node supports a certain type (or types) of KDF. For example, a security capability including field K1 indicates whether a second node supports GHA1. When field K1 takes the first value (e.g., 1) or does not take the second value (e.g., not 0), it indicates that the second node supports the GHA1 algorithm.
[0203] When selecting the first KDF, if both the second node and the first node support multiple KDFs, the first KDF can be selected based on the algorithm optimization strategy and / or service type. This first KDF can be the KDF with the highest priority. For example, referring to Table 1, taking the algorithm optimization strategy where GHA1 has a higher priority than GHA2 as an example, if the security capabilities of the second node indicate that the second node supports both GHA1 and GHA2, and the first node also supports both GHA1 and GHA2, the first node can select the higher-priority GHA1 as the first KDF.
[0204] Method 2: The first node sends its security capabilities to the second node. These capabilities indicate the algorithms supported by the first node. The second node can then select a first KDF based on these capabilities. Further, the second node sends the selected first KDF indication information back to the first node.
[0205] Method 3: The second node sends the indication information of the first KDF to the first node. The first KDF is either a KDF that the second node only supports, or a KDF that the second node selects from multiple KDFs. In the latter case, the second node may select the KDF based on its own needs, such as choosing the KDF with the lowest power consumption or the KDF with the lowest computing power consumption. Further, if the first node supports the first KDF, it reports a successful negotiation to the second node. Of course, if the first node does not support the first KDF, it reports a KDF negotiation failure to the second node, and the first and second nodes no longer continue the association process, or the second node re-initiates KDF negotiation.
[0206] Method 4: The first node sends the indication information of the first KDF to the second node. The first KDF is either a KDF that the first node only supports or a KDF selected by the first node from multiple KDFs. Further, if the second node supports the first KDF, it sends a successful negotiation notification to the first node. Of course, if the second node does not support the first KDF, it sends a failed KDF negotiation notification to the first node. In this case, the first and second nodes do not continue the association process, or the first node re-initiates the KDF negotiation.
[0207] Of course, the above method of negotiating the first KDF is only an example. In the specific implementation, the first node and the second node can negotiate to obtain the first KDF through other methods.
[0208] In some possible implementations, the first KDF can be performed during the security context negotiation process. The following example uses the aforementioned method 1, combined with... Figure 6 This document presents a flowchart illustrating a security context negotiation process. A first node and a second node negotiate the security context, including: the second node sending message T1 (or first message; parameter notation shown in this document is for illustrative purposes only) to the first node. Message T1 carries the second node's security capabilities. Correspondingly, the first node receives message T1 from the second node and, based at least on the second node's security capabilities, determines a first security feature (KDF). For example, if the second node supports only one KDF, that KDF is used as the first KDF. When the second node supports one or more KDFs, the first node selects the highest-priority first KDF based on an algorithmic optimization strategy and / or service type, etc.
[0209] Furthermore, the first node can send a second message T2 (or second message) to the second node, which carries indication information of the first KDF. Correspondingly, upon receiving the second message T2, the second node obtains the indication information of the first KDF, thus determining the first KDF. In this way, the first node and the second node negotiate and determine the first KDF through security context negotiation.
[0210] It should be understood that the message names and symbols used here are merely examples, and in actual implementation, the names of messages, information, nodes, and algorithms can be replaced. For instance, message T1 can be called an association request message, used to request association with a first node, including information about the second node, such as its ID and security capabilities. Message T2 can be called a security context request message.
[0211] In some possible implementations, the security context negotiation process may also include more messages, such as one or more of messages T3 (or the third message), T4 (or the fourth message), and T5. In this case, the information exchanged during the negotiation of the first KDF may be carried in parts of messages T1-T5, which is not specifically limited here.
[0212] In some possible implementations, message T1 further includes a first key negotiation parameter, based on which the first node can determine a session key between the first node and the second node. Message T2 further includes a second key negotiation parameter, based on which the second node can determine a session key between the first node and the second node.
[0213] In some possible implementations, message T1 further includes a first fresh parameter, which is generated by the second node and can be carried in message T1 and sent to the first node. And / or, message T2 further includes a second fresh parameter, which is generated by the first node and can be carried in message T2 and sent to the second node. Of course, the first fresh parameter can also be carried in other messages sent from the second node to the first node, such as messages T3, T5, etc., and this application is equally applicable to these cases. Furthermore, the second fresh parameter can also be carried in other messages sent from the first node to the second node, such as broadcast messages, message T4, etc.
[0214] Step S502: The first node sends security parameters to the third node. Accordingly, the third node receives the security parameters.
[0215] The security parameters include information used to generate the first key. Examples include the KDF (Key Development Function) instruction for generating the first key, or the input parameters used in generating the first key. Several possible scenarios are illustrated below:
[0216] Scenario 1: The security parameters include indication information for the first KDF. For example, the security parameters may include the algorithm name or algorithm identifier of the first KDF. Another example is when the first node sends a security parameter reporting message (or a full parameter reporting message) to the third node. This message includes one or more fields. Taking field K2 as an example, field K2 indicates whether one or more KDFs are determined to be the first KDF (i.e., the first KDF determined through negotiation between the first and second nodes). For instance, field K2 might indicate GHA1. When field K2 takes the third value (e.g., 1) or does not take the fourth value (e.g., not 0), it indicates that the first KDF is GHA1.
[0217] Alternatively, in some schemes, the security parameters may not include the indication information of the first KDF. In this case, the KDF used by the third node when generating the first key can be obtained through other means, and does not necessarily have to be reported by the first node. For example, the KDF used by the third node when generating the first key can be predefined, such as specifying in the communication protocol which KDF the third node uses as the KDF for generating the key. Another example is that the first KDF can be determined through negotiation between the third node and the second node. Optionally, in this scheme, step S201 may or may not be executed.
[0218] Scenario 2: The security parameters include a first freshness parameter and / or a second freshness parameter. That is, the first node must report at least one freshness parameter. Here, the freshness parameter, also called the freshness value, is a parameter used during key derivation to ensure the freshness or uniqueness of the derived key. For example, the freshness parameter may include one or more of the following: a random number (such as NONCE), a counter value, a specific identifier (such as a timestamp), or a transmission unit sequence number.
[0219] In one possible implementation, the first fresh parameter is generated by the second node, which can then send it to the first node. For example, the first fresh parameter can be included in message T1 and sent to the first node. The second fresh parameter is generated by the first node. Further, this second fresh parameter can be sent to the second node, for example, included in message T2.
[0220] In some schemes, the first fresh parameter and the second fresh parameter are fresh parameters exchanged between the first node and the second node. For example, the first fresh parameter is generated by the second node, and the second node needs to provide this first fresh parameter to the first node. Similarly, the second fresh parameter is generated by the first node, and the first node needs to provide this first fresh parameter to the second node.
[0221] Scenario 3: The security parameters include one or more of the identifiers of the first node and the second node. Among them:
[0222] The identifier of the first node is used to indicate the first node, such as the node's identifier in the communication network or the node's device identifier. The node's identifier in the communication network may include, for example, an ID of a specific communication protocol layer, the node's Media Access Control (MAC) address, or the node's network access license number. The node's device identifier is used to uniquely identify the node's device itself, such as the node's serial number or device model. Optionally, the node's identifier can be fixed or random.
[0223] As one possible implementation, node identifiers are used to distinguish nodes in a network; for example, the identifier of the first node is the ID of the first communication protocol layer of the first node.
[0224] For example, the communication protocol stack between the first node and the second node includes multiple protocol layers, which can be referred to as layer 1, layer 2, layer 3, etc. The identifier of the first node can be the layer 2 ID (L2ID) of the second node.
[0225] For another example, taking the communication protocol between the first node and the second node as the StarSpark communication protocol, the StarSpark protocol stack architecture from top to bottom is as follows: application layer, network and transport layer, data link layer (including link control layer and media access layer), and physical layer. The physical layer is layer one, the data link layer is layer two (i.e., L2), and the data link layer can include two sub-layers, and so on for the remaining layers. The identifier of the first node here can be the data link layer ID of the first node. Alternatively, the identifier of the first node can be the physical layer identifier (phy-ID) of the first node.
[0226] The identifier of the second node is used to indicate the second node, such as the L2ID of the second node, the phy-ID of the second node, etc. For related designs, please refer to the possible designs of the identifier of the first node.
[0227] The aforementioned scenarios can be combined. For example, security parameters may include indication information of the first KDF, a first freshness parameter, a second freshness parameter, the identifier of the first node, and the identifier of the second node. Alternatively, security parameters may include indication information of the first KDF, the identifier of the first node, and the identifier of the second node.
[0228] In some solutions, when security parameters include multiple pieces of information, these pieces of information can be sent in a single message or separately in different messages. Furthermore, the names of the messages and information shown in this application are merely examples; in actual implementations, the names can be designed in other ways.
[0229] In some possible implementations, security parameters are triggered to be sent at specific times. For example, after the first node receives message T5, it may report the security parameters to the third node. As another example, when the first node receives a message indicating the start of authentication (e.g., the authentication message - start below), it sends the security parameters to the third node.
[0230] In some possible implementations, the first node communicates with the second node using a first communication protocol, while the first node and the third node communicate using a second communication protocol. In some cases, the first and second communication protocols are different. In other cases, the first and second communication protocols are the same.
[0231] When the first and second communication protocols differ, some messages transmitted between the first and third nodes require the use of transmission units defined by the second communication protocol to carry the information (such as messages) that the second communication protocol needs to transmit. For example, if the first communication protocol is the StarSpark communication protocol and the second is the Ethernet communication protocol, the aforementioned security parameters are parameters defined in the StarSpark communication protocol that need to be reported. These parameters are carried in security parameter reporting messages, which are also StarSpark messages. Since the first and third nodes communicate using Ethernet, Ethernet messages are needed to carry these StarSpark messages.
[0232] Optionally, the information transmitted between the first node and the third node is encapsulated in data packets (such as security parameter reporting packets and authentication key distribution packets mentioned below). The format of the data packets is as specified by the first communication protocol, including, for example, a header, a data portion, and a trailer, wherein the header and / or trailer are optional. This data packet is carried on the payload portion of the second protocol data unit (PDU) transmitted between the first node and the third node. The format of the second PDU is as specified by the second communication protocol. The data packet carried on the payload portion includes at least the data portion of the original data packet, and optionally includes a header and / or trailer. Figure 8 The second PDU includes a header, a payload, and a trailer (optionally included), and at least a portion of the message (i.e., data message) of the first communication protocol may be carried in the payload of the second PDU.
[0233] Furthermore, the payload portion of the second PDU also includes a second message type field, which indicates the message type of the data packets carried by the payload portion of the second PDU. For example, referring to Table 2, the second message type field indicates one of the following message types: security parameter reporting or authentication key distribution. The security parameter reporting message includes the aforementioned security parameters. The authentication key distribution message includes the first key (described below).
[0234] Optionally, the payload portion of the second PDU may further include a second message length field, the value of which is used to indicate the data length of the message of the first communication protocol carried by the second PDU.
[0235] Optionally, the data length of the second message type field and the data length of the second data length field can be designed according to actual needs.
[0236] In some possible implementations, the data packets transmitted between the first node and the third node can be encapsulated into a data structure including payload content, which is carried in the payload portion of the second PDU, such as... Figure 8 As shown. Optionally, this data structure also includes a second message type field and / or a second message length field. Of course, Figure 8 The method of transmitting information using the first communication protocol shown is merely an example.
[0237] As yet another possible example, combining Figure 9 When carrying data packets of the first communication protocol on the second PDU, only the data portion of the data packet can be carried in the payload portion of the second PDU. Further optionally, if the data packet includes a header, the header can be carried in the header of the second PDU by updating existing values of existing fields, converting them to values of other fields, adding new data or new fields, or redefining the data. Similarly, if the data packet has a trailer, the trailer can be carried in the trailer of the second PDU by updating existing values of existing fields, converting them to values of other fields, adding new data or new fields, or redefining the data.
[0238] Optionally, the header of the second PDU may also include first indication information, which is used to indicate the second communication protocol. For example, the header of the second PDU may include a field K3, and when the value of field K3 is the fifth value, it indicates the second communication protocol.
[0239] Step S503: The second and third nodes execute the authentication process.
[0240] The third node is used for authentication. This authentication process is related to the authentication method; in the authentication process, the second and third nodes need to send and receive authentication messages.
[0241] As one possible implementation, the second and third nodes cannot communicate directly; in this case, both the second and third nodes exchange messages with the first node. Combined with... Figure 7In one EAP authentication process, the second node sends a start message (i.e., authentication message - start) to the first node, such as the start message of the Extended Authentication Protocol over Local Area Network (EAP over LAN, EAPOL). The first node and the second node exchange authentication data messages (i.e., authentication messages - data), such as EAP-request / identity, EAPOL-response / identity, EAP-request / protected EAP (PEAP), EAP-response / PEAP, etc. Optionally, the first node and the second node can also exchange success (or failure) messages, such as EAP-success.
[0242] The first node is also used to exchange authentication data packets (authentication packet-data) with the third node. Taking Radius authentication as an example, the first node and the third node can exchange access request (Radius-access-request), access challenge (Radius-access-challenge), and access acceptance (Radius-access-accept) packets. For ease of description, the authentication packet exchanged between the second node and the first node is called the first authentication packet, and the authentication packet exchanged between the first node and the third node is called the second authentication packet.
[0243] In some other possible implementations, the second node may communicate with the third node without going through the first node. In this case, some or all of the authentication messages in the authentication process may not be forwarded through the first node.
[0244] The authentication process is related to the authentication method (or protocol) used by the third or second node. (The aforementioned...) Figure 7The EAP authentication method was used as an example in the introduction. In actual implementation, the authentication process may employ other authentication methods. Furthermore, one authentication method may support multiple authentication protocols. Taking EAP as an example, EAP may include one or more of the following protocols: EAP-MD5, EAP-TLS, EAP-tunneled TLS (TTLS), EAP-lightweight EAP (LEAP), EAP-PEAP, etc. These protocols are broadly divided into two categories: TLS-based EAP (such as EAP-TLS, EAP-PEAP, or EAP-TTLS) and account / password-based EAP (such as EAP-MD5 or EAP-LEAP). It should be understood that the EAP protocols listed above are merely examples; in actual implementation, EAP may include more or fewer authentication protocols.
[0245] In some possible implementations, before executing the authentication process, the first node may send an authentication method indication to the second node, which indicates the authentication method. Accordingly, the second node may receive the authentication method indication and execute the authentication process using the corresponding authentication method.
[0246] For example, the authentication method indicator is used to indicate EAP authentication, so the second and third nodes perform the EAP-based authentication process. In some schemes, there is also a distinction between enterprise and personal versions of the authentication method; for instance, the authentication method indicator may also be used to indicate enterprise version - EAP authentication.
[0247] Optionally, the authentication method indication can be carried in a broadcast message. For example, the authentication method indication can be carried in a communication domain system message, and this application also applies to cases where it is carried in other broadcast messages. Alternatively, the authentication method indication can be carried in other messages, such as the aforementioned messages T2 and T4.
[0248] The above implementation uses the example of the first node sending an authentication method instruction. In some implementation examples, the authentication method can also be determined through negotiation. For example, the first node sends its authentication capabilities to the second node, indicating the multiple authentication methods it supports. The second node can then select a specific authentication method and send an authentication method instruction to the first node. Alternatively, the second node sends its authentication capabilities to the first node, indicating the multiple authentication methods it supports. The first node can then select a specific authentication method and send an authentication method instruction to the second node.
[0249] As mentioned earlier, in some authentication processes, the first node and the second node need to exchange first authentication messages. Since the first node and the second node communicate using a predefined communication protocol (for ease of description, referred to as the first communication protocol), it is necessary to define the format (such as frame format) of the transmission unit used to transmit the first authentication message.
[0250] In some possible implementations, the first node and the second node communicate via a first communication protocol. During the authentication process, the format of the first authentication message exchanged between the second node and the first node is the frame format defined by the first authentication protocol. Further, the first authentication message is carried on the data portion of a first protocol data unit (PDU) transmitted between the first node and the second node, and the format of the first PDU is the PDU format specified by the first communication protocol.
[0251] Please see Figure 10 The first communication protocol specifies that the PDU includes a header, a data portion, and a trailer (optionally included). Authentication messages transmitted between the first node and the second node can be carried in the data portion of the PDU. Of course, multiple first PDUs can be transmitted between the first node and the second node to transmit multiple authentication messages in the authentication process.
[0252] Furthermore, the protocol stack of the first communication protocol includes multiple protocol layers, and each protocol layer has a corresponding PDU. The aforementioned first PDU can be a PDU of one of the protocol layers. Taking the first communication protocol as StarSpark as an example, the StarSpark protocol stack architecture from top to bottom is: application layer, network and transport layer, data link layer (including link control layer and media access layer), and physical layer. The aforementioned first PDU can be a link control layer PDU or a data link layer PDU.
[0253] In some possible implementations, the data portion of the first PDU further includes a first message type field, which indicates the message type of the authentication message carried by the data portion of the first PDU. For example, the first message type field indicates one of the following message types: start, completion, online, logout, or data. As shown in Table 3, for a given first PDU, when the value of the first message type field carried by its data portion is 0x01, it indicates that the authentication message it carries is an authentication message - start. Similarly, for a given first PDU, when the value of the first message type field carried by its data portion is 0x02, it indicates that the authentication message it carries is an authentication message - completion.
[0254]
[0255] In some possible implementations, the authentication process may or may not succeed. Optionally, if the authentication process succeeds, the first node, third node, etc., perform the steps described below. Conversely, if the authentication process fails, the identity of the second node is untrusted, and the second node cannot fully utilize the services provided by the first node, such as being unable to access controlled network resources through the first node.
[0256] Optionally, the data length of the first message type field and the data length of the first data length field can be designed according to actual needs. For example... Figure 10 The first message type field can occupy 1 byte, while the first data length field can occupy 2 bytes.
[0257] Step S504: The second node determines the first key based at least on the first KDF and key information.
[0258] Optionally, the first KDF is a KDF negotiated and determined by the first node and the second node, and the first node indicates the first KDF to the third node. Alternatively, the first KDF is predefined and used to deduce the first key KDF. Alternatively, the first KDF is a KDF negotiated and determined between the second node and the third node.
[0259] The key information is used to generate the first key, and this information may be a secret value. Furthermore, the key information is shared between the second and third nodes. In other words, the third and second nodes may have access to the same key information beforehand. For example, the key information may include a TLS key between the second and third nodes, or it may include the password (or account information) corresponding to the second node.
[0260] As a possible example, the authentication process performed between the second and third nodes belongs to the authentication process defined by the TLS-based EAP authentication protocol, and the key information includes the TLS master key.
[0261] As another possible example, the authentication process follows the EAP authentication protocol defined by account and password, and the key information includes the password corresponding to the second node. Furthermore, the key information also includes the account corresponding to the second node.
[0262] For example, the first key is calculated as follows: RK = KDF(key information), where RK represents the first key, and KDF in this formula represents the first KDF. In some schemes, the first key is a symmetric key or shared key generated by the second node and the server respectively, and in some scenarios it may be called an authentication key (the name is only for example).
[0263] In some possible implementations, other parameters may be introduced during the determination of the first key. For example, the parameters involved in generating the first key may include one or more of the following: a first freshness parameter, a second freshness parameter, a third freshness parameter, the identifier of the first node, and the identifier of the second node. Some of the above parameters may be included in the security parameters. For ease of understanding, several possible scenarios for generating the first key are described below:
[0264] Scenario 1: The second node generates a first key based on the first KDF, key information, a first fresh parameter, and a second fresh parameter. For example, the first key is calculated as follows: RK = KDF(key information, NONCEt, NONCEg), where RK represents the first key, KDF in this formula is the aforementioned first KDF, NONCEt is the first fresh parameter from the second node, and NONCEg is the second fresh parameter from the first node. It should be understood that the order and number of parameters among the multiple inputs to KDF in the calculation method shown in this application are merely examples.
[0265] Optionally, when deriving the first key, the second node can form a multi-layered key derivation system, obtaining the first key through multiple derivations. Furthermore, in each of the multiple derivations, the second node uses the first KDF as the key derivation function.
[0266] As one possible implementation, the second node determines the second key (which can be regarded as an intermediate key) based on the first KDF, key information, first fresh parameter and second fresh parameter, and then determines the first key based on the first KDF and the second key (optionally including additional input information).
[0267] Taking the additional input information as the identifiers of the first node and the second node as an example, the calculation method of the first key is as follows:
[0268] MK = KDF(key information, NONCEt, NONCEg),
[0269] RK = KDF(MK, identifier of the first node, identifier of the second node).
[0270] Here, MK represents the second key, and the other parameters can be found in the previous description.
[0271] Combination Figure 11 Taking the TLS master key as the key information, the L2ID of the first node as the identifier of the first node, and the L2ID of the second node as the identifier of the second node as an example, the calculation method of the first key is as follows:
[0272] MK = KDF(TLS master key, NONCEt, NONCEg),
[0273] RK = KDF(MK, L2ID of the first node, L2ID of the second node).
[0274] Similarly, combining Figure 12 Taking the account and password corresponding to the second node as the key information, the L2ID of the first node as the identifier of the first node, and the L2ID of the second node as the identifier of the second node as the identifier of the second node, the calculation method of the first key is as follows:
[0275] MK = KDF(username, password, NONCEt, NONCEg),
[0276] RK = KDF(MK, L2ID of the first node, L2ID of the second node).
[0277] Optionally, the above description uses the case where both the first and second fresh parameters are used as an example. In actual implementation, only the first or second fresh parameter may be used during the derivation of the first key. Alternatively, the first and third fresh parameters, or the second and third fresh parameters, may be used. This article only provides illustrative examples of the combinations used, and other possible combinations have not been described in detail.
[0278] In scenario 2, the second node generates the first key based on the first key derivation function, key information, and a third fresh parameter. The third fresh parameter can be determined by the third node. Further, the third node can send the third fresh parameter to the first node, which then forwards it to the second node, allowing the second node to obtain the third fresh parameter. For example, the first key is calculated as follows: RK = KDF(key information, R AND), where RAND is the third fresh parameter from the first node, determined by the third node.
[0279] Optionally, when deriving the first key, the second node can obtain the first key through multiple derivations. Furthermore, in each of the multiple derivations, the second node uses the first KDF as the key derivation function.
[0280] As one possible implementation, the second node determines the second key (which can be regarded as an intermediate key) based on the first key derivation function, key information and the third fresh parameter, and then determines the first key based on the first KDF and the second key (optionally including additional input information).
[0281] Taking the additional input information as the identifiers of the first node and the second node as an example, the calculation method of the first key is as follows:
[0282] MK = KDF(key information, RAND),
[0283] RK = KDF(MK, identifier of the first node, identifier of the second node).
[0284] Of course, the key information can be a TLS master key, or an account and / or password; for related combinations, please refer to the description of Case 1 above.
[0285] Step S505: The third node determines the first key based at least on the first KDF and key information.
[0286] Optionally, the first KDF is a KDF negotiated and determined by the first node and the second node, and the first node indicates the first KDF to the third node. Alternatively, the first KDF is predefined and used to deduce the first key KDF. Alternatively, the first KDF is a KDF negotiated and determined between the second node and the third node.
[0287] As a possible example, the authentication process performed between the second and third nodes belongs to the authentication process defined by the TLS-based EAP authentication protocol, and the key information includes the TLS master key.
[0288] As another possible example, the authentication process follows the EAP authentication protocol defined by account and password, and the key information includes the password corresponding to the second node. Furthermore, the key information also includes the account corresponding to the second node.
[0289] For example, the first key is calculated as follows: RK = KDF (key information), where RK represents the first key, and KDF in the formula is the aforementioned first KDF.
[0290] In some possible implementations, other parameters may be introduced into the process of determining the first key. For example, the parameters involved in generating the first key may include one or more of the following: a first freshness parameter, a second freshness parameter, a third freshness parameter, the identifier of the first node, and the identifier of the second node.
[0291] For relevant examples, please refer to the description of step S504.
[0292] Optionally, in some schemes, such as Figure 5 The communication method shown also includes step S506, which is as follows:
[0293] Step S506: The third node sends the first key to the first node.
[0294] Accordingly, the first node receives the first key from the third node. Thus, both the first and second nodes obtain the first key.
[0295] Optionally, the first key can be carried in a message, for example, transmitted in an authentication key issuance message (or authentication key issuance message). This first message is the key determined between the third node and the second node after the authentication process is executed, and can be used as the authentication key. Of course, the names of messages, keys, information, and messages shown in this application are only for illustrative purposes, and in specific implementations, the names may be designed in other ways.
[0296] In one possible implementation, the first key is not used as a session key. The session key is used to securely protect transmitted information, such as through encryption, integrity protection, or authentication encryption, or one or more of these methods. Furthermore, the session key between the first node and the second node can be determined through negotiation between them. For example, in a security context negotiation process, the first node and the second node determine their session key by exchanging key negotiation parameters. Since the session key is negotiated directly between the two nodes without involving other devices, this method of determining the session key further enhances the communication security between the first node and the second node.
[0297] In one possible implementation, the first key is used to verify information that has already been transmitted between the first node and the second node. That is, the information verified by the first key is information transmitted previously (e.g., before the first key was received, or before the first key was saved). Verifying previously transmitted information using the first key helps ensure the security of forward communication between the first node and the second node.
[0298] For example, the information that has been transmitted includes, but is not limited to, the following: information transmitted during the negotiation of the first KDF, information transmitted during the security context negotiation process (where a security context negotiation process exists), and information transmitted between security context negotiation processes (e.g., broadcast messages).
[0299] As a possible verification example, the first node sends a first verification parameter to the second node based on a first key and the first verification information to be verified. Correspondingly, the second node receives the first verification parameter from the first node and verifies it. The first verification information to be verified is information that has already been transmitted between the first and second nodes.
[0300] As a possible example, the first information to be verified includes at least a portion of the information sent by the second node to the first node during the security context negotiation process. The security context negotiation process is described above; it is understood that the security context negotiation process includes a process of negotiating a first KDF with the first node. Further, the first information to be verified also includes a portion of the information sent by the first node to the second node during the security context negotiation process, and / or the information sent by the first node in a broadcast message.
[0301] For example, the first verification parameter HASHg is calculated as follows: HASHg = KDF(RK, NONCEg, message T1 content, message T3 content). Here, KDF identifies the first KDF, RK is the first key, NONCEg is the second fresh parameter (carried in the second message), message T1 content includes part or all of message T1 content, and message T3 content includes part or all of message T3 content. Furthermore, the second node can determine a check value based on the same input parameters and compare the check value with the first verification parameter to verify whether the first verification parameter is correct.
[0302] In some possible implementations, HASHg is carried in message T6, which is a message sent by the first node to the second node. Optionally, message T6 also carries a third freshness parameter.
[0303] As another possible verification example, the second node generates a second verification parameter based on the first key and the second verification information, and sends the second verification parameter to the first node. The second verification information is information that has already been transmitted between the first and second nodes.
[0304] As one possible example, the second information to be verified includes at least a portion of the information received from the first node during the security context negotiation process. Understandably, the security context negotiation process includes a process of negotiating a first KDF with the first node. Further, the first information to be verified also includes a portion of the information sent by the second node to the first node during the security context negotiation process, and / or the information sent by the first node in a broadcast message.
[0305] For example, the calculation method of the second verification parameter HASHt is as follows: HASHt = KDF(RK, key negotiation algorithm capability of the first node, authentication method indication, NONCEt, content of message T2, content of message T4), where KDF is used to indicate the KDF algorithm used. The input of KDF includes RK, key negotiation algorithm capability of the first node, authentication method indication, NONCEt, content of message T2, and content of message T4. The specific information is as follows: RK is the first key, the key negotiation algorithm capability of the first node can be carried in the broadcast message, the authentication method indication can be carried in the broadcast message, and NONCEt is the first fresh parameter.
[0306] In some possible implementations, HASHt is carried in message T7, which is a message sent by the second node to the first node.
[0307] exist Figure 5 In the illustrated embodiment, the first node and the second node negotiate to determine the KDF. The second node and the third node can deduce the authentication key based on the negotiated KDF, so that the second node with different security capabilities has the opportunity to associate with the first node and be authenticated, thereby improving network compatibility and user experience.
[0308] above Figure 5 The illustrated embodiments have multiple possible implementation methods, which are described below in conjunction with... Figure 13 , Figure 14 and Figure 15 Three possible implementation methods are described below. It should be understood that... Figure 13 , Figure 14 and Figure 15 For some of the concepts and logic in the text, please refer to Figure 5 Description of the illustrated embodiments.
[0309] Please see Figure 13 , Figure 13 This is a flowchart illustrating another communication method provided in an embodiment of this application. Optionally, this method can be applied to a communication system, such as the one described above. Figure 4 The communication system shown. (As shown) Figure 13 The communication method shown may include one or more steps S1301 to S1315. It should be understood that, for ease of description, steps S1301 to S1315 are described in this order, and it is not intended to limit the execution to this specific order. This application embodiment does not limit the order of execution, the execution time, or the number of executions of the above one or more steps. Steps S1301 to S1315 are as follows:
[0310] Step S1301: The first node sends a broadcast message.
[0311] Accordingly, the second node can receive this broadcast message, such as a communication domain system message. The broadcast message carries the first node's key negotiation algorithm capabilities and authentication method indication. This authentication method indication is used to indicate Enterprise Edition (EAP) authentication.
[0312] The second node can request to associate with the first node. In one possible implementation, when the authentication method is Enterprise Edition, for example, when the authentication method indicator is used to indicate Enterprise Edition-EAP authentication, the first and second nodes perform a security context negotiation process, but omit the calculation and verification process of authentication parameters in the security context negotiation process. Optionally, in the security context negotiation process, the first and second nodes negotiate to generate a session key. Further, the session key includes a signaling plane session key and a user plane session key. In some schemes, the first and second nodes initiate encryption and integrity protection for the signaling plane.
[0313] In one possible instance, the first node executes a security context negotiation process as described in steps S1302 and S1306. Specifically:
[0314] Step S1302: The second node sends message T1 to the first node. Correspondingly, the first node receives message T1 from the second node.
[0315] Message T1 carries the security capabilities of the second node and a first freshness parameter. The first freshness parameter, NONCEt, is exemplified here. The security capabilities of the second node indicate the cryptographic algorithms (including KDF) supported by the second node.
[0316] Step S1303: The first node sends message T2 to the second node. Correspondingly, the second node receives message T2 from the first node.
[0317] Message T2 carries the cryptographic algorithm (including KDF) selected by the first node, i.e., the cryptographic algorithm used between the selected first node and the second node. For example, message T2 carries indication information of the first KDF.
[0318] For example, message T2 also carries a second fresh parameter, exemplarily represented as NONCEg.
[0319] Step S1304: The second node sends message T3 to the first node. Correspondingly, the first node receives message T3 from the second node.
[0320] Message T3 is used in response to message T2.
[0321] Step S1305: The first node sends message T4 to the second node. Correspondingly, the second node receives message T4 from the first node.
[0322] The message T4 is used to indicate whether a relationship has been established. For example, when message T4 carries information such as a temporary ID assigned by the first node to the second node, it indicates that a relationship has been established.
[0323] Step S1306: The second node sends message T5 to the first node. Correspondingly, the first node receives message T5 from the second node.
[0324] The T5 message is used to indicate that the association is complete.
[0325] like Figure 13 As shown, the authentication process is executed after the security context flow. The second and third nodes exchange authentication messages, which may be forwarded through the first node.
[0326] Step S1307: The second node sends an authentication message to the first node - Start.
[0327] Optionally, this authentication message - start - also belongs to the authentication process.
[0328] Step S1308: The first node sends a security parameter reporting message to the third node.
[0329] Accordingly, the third node receives a security parameter reporting message. This security parameter reporting message carries the first KDF (Knowledge Defender) determined during the security context negotiation process. Figure 13 In this context, we have KDF), NONCEg, NONCEt, the L2ID of the second node, and the L2ID of the first node.
[0330] Optionally, step S1308 may also be performed after step S1306 and before step S1307.
[0331] Step S1309: The second and third nodes execute the authentication process.
[0332] This authentication process is, for example, the EAP authentication process. Further, after the authentication process is successful, the second and third nodes each derive their keys, as shown in steps S1310 and S1311:
[0333] Step S1310: The second node generates the second key and derives the first key.
[0334] The second node generates a second key, which may be called the authentication master key.
[0335] For TLS-based EAP authentication protocols such as EAP-TLS, EAP-PEAP, and EAP-TTLS, the second node generates a second key MK based on the TLS key (such as the TLS master key) and the second fresh parameter NONCEg and the first fresh parameter NONCEt. For example, the second key is calculated as follows: MK = KDF(TLS master key, NONCEg, NONCEt).
[0336] For EAP authentication based on account and password, the second node generates a second key MK based on the account, password, and second fresh parameter NONCEg, and the first fresh parameter NONCEt. For example, the second key is calculated as follows: MK = KDF(account, password, NONCEg, NON CEt).
[0337] Furthermore, the second node derives the first key RK from the second key MK. For example, the first key RK is calculated as follows: RK = KDF(MK, L2ID of the second node, L2ID of the first node).
[0338] Step S1311: The third node generates the second key and derives the first key.
[0339] See the description of step S1310.
[0340] Step S1312: The third node sends a key distribution message to the first node.
[0341] Accordingly, the first node receives the key distribution message. The key distribution message includes the first key RK.
[0342] Further, the first node and the second node perform a session key confirmation process, as shown in steps S1313 and S1314:
[0343] Step S1313: The first node sends message T6. Correspondingly, the second node receives message T6 from the first node.
[0344] Message T6 carries a second verification parameter (exemplarily represented by HASHg), which is calculated by the first node based on the second key and the information transmitted between the first and second nodes. For example, HASHg is calculated as follows:
[0345] HASHg = KDF(RK, NONCEg, content of message T1, content of message T3), see above for related parameter descriptions.
[0346] Optionally, the second node verifies HASHg. Further, if HASHg passes verification, the second node executes step S1311.
[0347] Step S1314: The second node sends message T7. Correspondingly, the first node receives message T7 from the second node.
[0348] Message T7 carries a first verification parameter (exemplarily represented by HASHt), which is calculated by the second node based on the second key and the information transmitted between the first and second nodes. For example, HASHt is calculated as follows:
[0349] HASHt = KDF(RK, Key negotiation algorithm capability of the first node, authentication method indicator, NONCEt, content of message T2, content of message T4).
[0350] Optionally, the first node verifies HASHt. Further, if HASHg passes verification, the second node executes step S1315.
[0351] Step S1315: The first node opens the controlled port, allowing the second node to access the permitted resources.
[0352] Optionally, a controlled port, such as a first communication port, may be used by the second node to access resources.
[0353] exist Figure 13 In the illustrated embodiment, the second and third nodes use the first KDF negotiated and determined between the first and second nodes to deduce the first key, and use the first fresh parameters and second fresh parameters that have been interacted between the first and second nodes to deduce the first key. This provides a new way to deduce the first key, which is compatible with second nodes with different security capabilities, improves network compatibility and enhances the security of the first key.
[0354] Please see Figure 14 , Figure 14 This is a flowchart illustrating another communication method provided in an embodiment of this application. Optionally, this method can be applied to a communication system, such as the one described above. Figure 4 The communication system shown. (As shown) Figure 14 The communication method shown may include one or more steps S1401 to S1416. It should be understood that, for ease of description, steps S1401 to S1416 are described in this order, and it is not intended to limit the execution to this specific order. This application embodiment does not limit the order of execution, the execution time, or the number of executions of the above one or more steps. Steps S1401 to S1416 are as follows:
[0355] Steps S1401-S1407 can be referred to the aforementioned steps S1301-S1307. However, message T1 may not carry the first fresh parameter NONCEt, and message T2 may not carry the second fresh parameter NONCEg.
[0356] Step S1408: The first node sends a security parameter reporting message to the third node.
[0357] Accordingly, the third node receives a security parameter reporting message. This security parameter reporting message carries the first KDF (Knowledge Defender) determined during the security context negotiation process. Figure 13 The L2ID of the second node and the L2ID of the first node are represented as KDF.
[0358] Optionally, step S1308 may also be performed after step S1306 and before step S1307.
[0359] Step S1409: The second and third nodes execute the authentication process.
[0360] Step S1410: The third node determines a third random number. This third random number is, for example, denoted as RAND.
[0361] Step S1411: The third node generates the second key and derives the first key.
[0362] For TLS-based EAP authentication, such as EAP-TLS, EAP-PEAP, and EAP-TTLS, the third node generates a second key MK based on the TLS key (such as the TLS master key) and the third fresh parameter RAND. For example, the second key is calculated as follows: MK = KDF(TLS master key, RAND).
[0363] For EAP authentication based on account and password, the third node generates a second key MK based on the account, password, and third fresh parameter. For example, the second key is calculated as follows: MK = KDF(account, password, RAND).
[0364] Furthermore, the third node derives the first key RK from the second key MK. For example, the first key RK is calculated as follows: RK = KDF(MK, L2ID of the second node, L2ID of the first node).
[0365] Step S1412: The third node sends a key distribution message to the first node.
[0366] Accordingly, the first node receives the key distribution message. The key distribution message includes the first key RK and the third fresh parameter RAND.
[0367] Further, the first node and the second node perform a session key confirmation process, as shown in steps S1313 and S1314:
[0368] Step S1413: The first node sends message T6. Correspondingly, the second node receives message T6 from the first node.
[0369] Message T6 carries a second check parameter (such as HUSHg) and a third freshness parameter RAND. See step S1313 for a related description.
[0370] Step S1414: The second node generates the second key and derives the first key.
[0371] See the relevant description of step S1411.
[0372] Steps S1415 and S1416 can be found in [reference needed]. Figure 13 Steps S1314 and S1315 in the illustrated embodiment.
[0373] exist Figure 13 In the illustrated embodiment, the second and third nodes use the first KDF negotiated and determined between the first and second nodes to deduce the first key, and use the third fresh parameters determined by the third node to deduce the first key. This provides a new way to deduce the first key, which is compatible with second nodes with different security capabilities, improves network compatibility and enhances the security of the first key.
[0374] As mentioned above, in some schemes, the KDF used when generating the first key is predefined. A possible implementation is described below. Please see... Figure 15 , Figure 15 This is a flowchart illustrating another communication method provided in this application embodiment, including one or more steps S1501 to S1515. For a description of steps S1501 to S1515, please refer to the foregoing. Figure 13 The explanation. With Figure 13 The difference in the illustrated embodiments is that, Figure 15 In the illustrated embodiment, the security parameters reported by the first node include a second fresh parameter and a first fresh parameter determined by the first node and the second node respectively, such as NONCEg and NONCEt. The security parameters may not include the indication information of the first KDF. In other words, the security parameter reporting message sent in step S1508 includes the first fresh parameter NONCEt and the second fresh parameter NONCEg, but does not include the indication information of the first KDF. Further, when determining the first key, the second node and the third node can use a predefined KDF to determine the first key based on the first fresh parameter, the second fresh parameter, and the key information.
[0375] In some schemes, the first and second nodes can continue to negotiate the key derivation function, but the negotiated key derivation function is not used by the second and third nodes to generate the first key.
[0376] The methods of the embodiments of this application have been described in detail above. The apparatus of the embodiments of this application is provided below.
[0377] It should be understood that the division of units in the apparatus provided in this application embodiment is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units in the apparatus can be implemented by a processor calling software. For example, the apparatus includes a processor connected to a memory, which stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit of the apparatus. The processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is either internal or external to the apparatus.
[0378] Alternatively, the units in the device can be implemented as hardware circuits. The functionality of some or all of the units can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the above units is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the above units.
[0379] In the embodiments of this application, each unit in the device may be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, graphics processing unit (GPU), neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), microprocessor unit (MPU), digital signal processor (DSP), ASIC, FPGA, or a combination of at least two of these processor forms.
[0380] Furthermore, the units in the above devices can be integrated in whole or in part, or they can be implemented independently. In one implementation, these units are integrated together as a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or for implementing the functions of the units in the device. The at least one processor can be of different types, such as including a CPU and an FPGA, or including a CPU and an artificial intelligence processor, or including a CPU and a GPU, etc. Several possible devices are listed below.
[0381] Please see Figure 16 , Figure 16 This is a schematic diagram of a communication device provided in an embodiment of this application. Optionally, the communication device 160 can be an independent device, such as a node. Alternatively, the communication device 160 can also be a component within an independent device (such as a node), such as a chip or integrated circuit. The communication device 160 is used to implement the aforementioned communication method, for example... Figure 5 , Figure 13 , Figure 14 , Figure 15 The communication method and its possible implementations are shown in the embodiments.
[0382] For example, the communication device 160 includes a processing unit 1601 and a communication unit 1602. The processing unit 1601 is used to perform one or more operations such as authentication, negotiation, processing, determination, generation, calculation, encryption, and decryption, while the communication unit 1602 is used to perform one or more operations such as sending and receiving. It should be understood that the unit division here is only illustrative; in a specific implementation, some units may be combined, or a single unit may be divided into multiple units. For example, the processing unit 1601 may include an acquisition unit and a calculation unit; the acquisition unit is used to acquire data from the upper layer, and the calculation unit is used to perform a calculation process.
[0383] In one possible design, the communication device 160 is used to implement the method on the second node side of the aforementioned communication method.
[0384] In one possible implementation, processing unit 1601 and communication unit 1602 are configured to: negotiate and determine a first KDF with a first node, and perform an authentication process with a third node. Processing unit 1601 is further configured to determine a first key based at least on the first KDF and key information if the authentication process is successful.
[0385] In another possible implementation, the processing unit 1601 is used to interact with the first node to send a first authentication message, and the first node is used to interact with the authentication service to send a second authentication message.
[0386] In another possible implementation, the processing unit 1601 is used to determine the first key based on the first KDF and key information, as well as the identifier of the first node and / or the identifier of the second node.
[0387] In another possible implementation, processing unit 1601 is used to determine a first key based on a first KDF and key information, as well as a first fresh parameter and / or a second fresh parameter. The first fresh parameter is generated by a second node, and the second fresh parameter comes from a first node.
[0388] In another possible implementation, the processing unit 1601 is configured to determine a second key based on the first KDF, key information, a first freshness parameter, and a second freshness parameter, and to determine a first key based on the first KDF and the second key.
[0389] Furthermore, the processing unit is specifically used to determine the first key based on the first KDF, the second key, the identifier of the first node, and the identifier of the second node.
[0390] In another possible implementation, the communication unit 1602 is further configured to receive a third fresh parameter from the first node, the third fresh parameter being determined by the third node. The processing unit 1601 is configured to determine a first key based on the first KDF, key information, and the third fresh parameter.
[0391] In another possible implementation, the processing unit 1601 is used to determine a second key based on a first KDF, key information and a third freshness parameter, and to determine a first key based on the first KDF and the second key.
[0392] Furthermore, the processing unit is specifically used to determine the first key based on the first KDF, the second key, the identifier of the first node, and the identifier of the second node.
[0393] In one possible implementation, the communication unit 1602 is further configured to receive an authentication method indication from the first node, the authentication method indication being used to indicate the authentication method. The authentication method is related to the authentication process.
[0394] In another possible implementation, processing unit 1601 and communication unit 1602 are used to perform a security context negotiation process with the first node. During the security context negotiation process, the second node negotiates and determines a first security context agreement (KDF) with the first node.
[0395] In another possible implementation, the communication unit 1602 is configured to send a first message to the first node and receive a second message from the first node. The first message includes the security capabilities of the second node, which indicate the security algorithms supported by the second node, including KDF (Security Defender). The second message includes indication information for the first KDF.
[0396] In another possible implementation, the communication unit 1602 is further configured to send a third message to the first node and receive a fourth message from the first node. The third message is used in response to the second message, and the fourth message is used to indicate whether an association has been established between the first node and the second node.
[0397] In another possible implementation, the communication unit 1602 is further configured to receive a first verification parameter from the first node, and the processing unit 1601 is further configured to verify the first verification parameter. The first verification parameter is related to a first key and information that has been transmitted between the first node and the second node.
[0398] In another possible implementation, the processing unit 1601 is further configured to generate a second verification parameter based on the first key and the information already transmitted between the first node and the second node, and the communication unit 1602 is further configured to send the second verification parameter to the first node.
[0399] In another possible design, the communication device 160 is used to implement the method on the first node side of the aforementioned communication method.
[0400] In one possible implementation, processing unit 1601 and communication unit 1602 are used to negotiate and determine a first KDF with a second node. Communication unit 1602 is also used to send security parameters to a third node. Communication unit 1602 is also used to interact with the second node to exchange a first authentication message and with the third node to exchange a second authentication message, and to receive a first key from the third node.
[0401] In another possible implementation, the communication unit 1602 is also configured to receive a third fresh parameter from a third node and send the third fresh parameter to a second node.
[0402] In yet another possible implementation, the communication unit 1602 is further configured to send an authentication method indication. The authentication method indication is used to indicate the authentication method.
[0403] In another possible implementation, processing unit 1601 and communication unit 1602 conduct a security context negotiation process with the second node. During the security context negotiation process, the first node may negotiate with the second node to determine a first key derivation arithmetic.
[0404] In another possible implementation, the security context negotiation process with the first node includes: receiving a first message from the second node and sending a second message to the second node. The first message includes the security capabilities of the second node, which indicate the security algorithms supported by the second node, including KDF (Knowledge Defender). The second message includes indication information for the first KDF.
[0405] In another possible implementation of the second aspect, the communication unit 1602 is further configured to receive a third message from the second node and send a fourth message to the second node. The third message is used in response to the second message, and the fourth message is used to indicate whether an association has been established between the first node and the second node.
[0406] In another possible implementation, the communication unit 1602 is further configured to receive a second verification parameter from the second node, and the processing unit 1601 is further configured to verify the second verification parameter. The second verification parameter is related to the first key and information already transmitted between the first and second nodes.
[0407] In another possible implementation, the processing unit 1601 is further configured to generate a first verification parameter based on the first key and the information already transmitted between the first node and the second node, and the communication unit 1602 is further configured to send the first verification parameter to the second node.
[0408] In another possible design, the communication device 160 is used to implement the method on the third node side of the aforementioned communication method.
[0409] In one possible implementation, communication unit 1602 is used to receive security parameters from the first node. Processing unit 1601 and communication unit 1602 are used to perform an authentication process with the second node. Processing unit 1601 is also used to determine a first key based at least on the first KDF and key information.
[0410] In another possible implementation, the communication unit 1602 is also used to interact with the first node to exchange a second authentication message, and the first node is used to interact with the second node to exchange a first authentication message.
[0411] In yet another possible implementation, the communication unit 1602 is also used to send a first key to the first node.
[0412] In another possible implementation, the processing unit 1601 is further configured to determine the first key based on the first KDF, key information, first freshness parameter and / or second freshness parameter.
[0413] In another possible implementation, the processing unit 1601 is further configured to determine a second key based on the first KDF, key information, a first freshness parameter, and a second freshness parameter, and to determine a first key based on the first KDF and the second key.
[0414] In another possible implementation, the processing unit 1601 is further configured to determine a third freshness parameter and to determine a first key based on the first KDF, the key information and the third freshness parameter.
[0415] In another possible implementation, the processing unit 1601 is further configured to determine a second key based on the first KDF, key information and a third freshness parameter, and to determine a first key based on the first KDF and the second key.
[0416] Furthermore, the processing unit 1601 is also used to determine the first key based on the first KDF, the second key, the identifier of the first node, and the identifier of the second node.
[0417] In yet another possible implementation, the communication unit 1602 is also used to send a third fresh parameter to the first node.
[0418] Please see Figure 17 , Figure 17This is a schematic diagram of a communication device provided in an embodiment of this application. The communication device 170 can be an independent device, such as a node or a third node, or a component included within an independent device, such as a chip, software module, or integrated circuit. The communication device 170 may include at least one processor 1701 and a memory 1703. Optionally, it may also include a communication interface 1702. Further optionally, it may also include a connection line 1704, wherein the processor 1701, the communication interface 1702, and / or the memory 1703 are connected via the connection line 1704, and / or communicate with each other via the connection line 1704 to transmit control signals and / or data signals.
[0419] in:
[0420] Processor 1701 is a module that performs arithmetic and / or logical operations, and may specifically include one or more of the following modules: filter, modem, power amplifier, low noise amplifier (LNA), baseband processor, radio frequency processor, radio frequency circuit, central processing unit (CPU), application processor (AP), microcontroller unit (MCU), electronic control unit (ECU), graphics processing unit (GPU), microprocessor unit (MPU), application specific integrated circuit (ASIC), image signal processor (ISP), digital signal processor (DSP), field programmable gate array (FPGA), complex programmable logic device (CPLD), or coprocessor, etc.
[0421] Communication interface 1702 can be used to provide information input or output to at least one processor, or to receive and / or transmit signals to externally transmitted signals. For example, communication interface 1702 may include interface circuitry. For instance, communication interface 1702 may include a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, general wireless transmission, vehicular short-range communication technology, and other short-range wireless communication technologies, etc.). Optionally, communication interface 1702 may also include a radio frequency transmitter, antenna, etc. If communication interface 1702 includes an antenna, the number of antennas may be one or more.
[0422] As one possible design, if the communication device 170 is a standalone device, the communication interface 1702 may include a receiver and a transmitter. The receiver and transmitter may be the same component or different components. When the receiver and transmitter are the same component, this component may be referred to as a transceiver.
[0423] As another possible design, if the communication device 170 is a chip or circuit, the communication interface 1702 may include an input interface and an output interface. The input interface and the output interface may be the same interface or they may be different interfaces.
[0424] Alternatively, the functionality of the communication interface 1702 can be implemented via a transceiver circuit or a dedicated transceiver chip.
[0425] The memory 1703 provides storage space, in which data such as the operating system and computer programs can be stored. The memory 1703 can be one or a combination of several of the following: random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).
[0426] The functions and actions of each module or unit in the communication device 170 listed above are merely illustrative examples.
[0427] The functional units in the communication device 170 can be used to implement the aforementioned communication method, for example... Figure 5 , Figure 13 , Figure 14 The communication method and its possible implementations are illustrated in the embodiments. For example, the communication device 170 is used to execute the method executed by the first node, the second node, or the third node.
[0428] Optionally, the processor 1701 may be a processor specifically designed to perform the aforementioned methods (for ease of distinction, referred to as a dedicated processor), or a processor that performs the aforementioned methods by calling a computer program (for ease of distinction, referred to as a dedicated processor). Optionally, at least one processor may include both dedicated processors and general-purpose processors.
[0429] Optionally, if the communication device 170 includes at least one memory 1703, and the processor 1701 implements the aforementioned communication method by calling a computer program, the computer program can be stored in the memory 1703.
[0430] This application also provides a chip, which includes logic circuitry and a communication interface. The communication interface is used to receive or transmit signals; the logic circuitry is used to receive or transmit signals through the communication interface. The chip is used to implement the aforementioned communication method, for example... Figure 5 , Figure 13 , Figure 14 , Figure 15 The communication method and its possible implementations are shown in the embodiments.
[0431] This application also provides a computer-readable storage medium storing instructions that, when executed on at least one processor (or communication device), implement the aforementioned communication method, for example... Figure 5 , Figure 13 , Figure 14 , Figure 15 The communication method and its possible implementations are shown in the embodiments.
[0432] This application also provides a computer program product, which includes computer instructions for implementing the aforementioned communication method, for example... Figure 5 , Figure 13 , Figure 14 , Figure 15 The communication method and its possible implementations are shown in the embodiments.
[0433] This application also provides a terminal, which includes the aforementioned communication device 160 and / or communication equipment 170.
[0434] In one possible implementation, the terminal includes a terminal node. Further, the terminal also includes a first management node and / or a second management node. Further, the terminal also includes a control node.
[0435] For example, the terminal can include intelligent terminals or transportation tools such as vehicles, robots, drones, ships, and vessels. Among them, "vehicle" is a broad concept, which can include transportation tools (such as commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (such as forklifts, trailers, tractors, etc.), engineering vehicles (such as excavators, bulldozers, cranes, etc.), agricultural equipment (such as lawnmowers, harvesters, etc.). As another example, "robot" can be an automated guided vehicle (AGV), a walking conversational robot, a service robot, etc.
[0436] It should be noted that, in the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.
[0437] In this embodiment, the names of information and devices are exemplarily chosen for ease of understanding of the content of this solution. In specific implementations, their names may be designed differently. Furthermore, the names of the same thing may also be designed differently in different scenarios (e.g., different communication layers).
[0438] In the embodiments of this application, "at least one" refers to one or more items, and "more than one" refers to two or more items. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items.
[0439] For example, at least one of a, b, or c can be represented as: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or multiple. "AND / OR" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects have an "OR" relationship.
[0440] Furthermore, unless otherwise stated, the ordinal numbers such as "first," "second," "T1," and "T2" used in the embodiments of this application are for distinguishing multiple objects and are not used to limit the order, timing, priority, or importance of multiple objects. Similarly, terms like "first node" and "second node" are merely for convenience in describing nodes in different implementations and do not indicate differences in their execution operations, importance, structure, etc.
[0441] In the above embodiments, the term "when..." can be interpreted, depending on the context, as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". The above descriptions are merely optional embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.
[0442] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
Claims
1. A communication method characterized by comprising: The method comprises: negotiating a first key derivation function (KDF) with a first node, the first node being a node requested by a second node for association; performing an authentication procedure with a third node, the third node being the same device as the first node or being communicatively connected to the first node; determining a first key based at least on the first KDF and key information, in a case that the authentication procedure is passed.
2. The method of claim 1, wherein, The performing of the authentication procedure with the third node comprises: the second node interacting with the first node a first authentication message, the first node interacting with the authentication service a second authentication message.
3. The method according to claim 1 or 2, characterized in that, The determining of the first key based at least on the first KDF and key information comprises: determining the first key based on the first KDF, the key information, an identity of the first node and an identity of the second node.
4. The method according to any one of claims 1 to 3, characterized in that, The determining of the first key based at least on the first KDF and key information comprises: determining the first key based on the first KDF, the key information, a first freshness parameter and a second freshness parameter; the first freshness parameter being generated by the second node, and the second freshness parameter being from the first node.
5. The method of claim 4, wherein, The determining of the first key based on the first KDF, the key information, a first freshness parameter and a second freshness parameter comprises: determining a second key based on the first KDF, the key information, a first freshness parameter and a second freshness parameter; determining the first key based on the first KDF, the second key, an identity of the first node and an identity of the second node.
6. The method according to any one of claims 1 to 3, characterized in that, Before the determining of the first key based at least on the first KDF and key information, the method further comprises: receiving a third freshness parameter from the first node, the third freshness parameter being determined by the third node; The determining of the first key based at least on the first KDF and key information comprises: determining the first key based on the first KDF, the key information and the third freshness parameter.
7. The method of claim 6, wherein, The determining of the first key based on the first KDF, the key information and the third freshness parameter comprises: determining a second key based on the first KDF, the key information and the third freshness parameter; determining the first key based on the first KDF, the second key, an identity of the first node and an identity of the second node.
8. The method of any of claims 1-7, wherein: the authentication procedure is an authentication procedure defined by an Extensible Authentication Protocol (EAP) authentication protocol based on a Transport Layer Security (TLS) protocol, and the key information comprises a TLS master key; or, the authentication procedure is an authentication procedure defined by an EAP authentication protocol based on a username and password, and the key information comprises a username and a password corresponding to the second node.
9. The method according to any one of claims 1 to 8, characterized in that, Before the performing of the authentication procedure with the third node, the method further comprises: receiving an authentication mode indication from the first node, the authentication mode indication indicating an EAP authentication, and the authentication procedure being a procedure defined by an authentication protocol of the EAP authentication.
10. The method according to any one of claims 1 to 9, characterized in that, The first key is used to verify information that has been transmitted by the first node and the second node.
11. The method according to any one of claims 1 to 10, characterized in that, The method further comprises: receiving a first check parameter from the first node, the first check parameter being related to the first key and first to-be-checked information, the first to-be-checked information including information sent to the first node at least partially in a security context negotiation process, the security context negotiation process including a process of negotiating the first KDF with the first node; verifying the first check parameter.
12. The method according to any one of claims 1 to 11, characterized in that, The method further comprises: generating a second check parameter based on the first key, the first node, and second to-be-checked information, the second to-be-checked information including information received from the first node at least partially in a security context negotiation process, the security context negotiation process including a process of negotiating the first KDF with the first node; sending the second check parameter to the first node.
13. A method of communication, comprising: The method comprises: negotiating a first key derivation function KDF with a second node, the second node being a node requesting association with the first node; sending a security parameter to a third node, the security parameter including indication information of the first KDF; interacting a first authentication message with the second node and a second authentication message with the third node, the third node being used for authentication; receiving a first key from the third node, the first key (RK) being related to the first KDF and key information.
14. The method of claim 13, wherein, The security parameter further includes a first freshness parameter and a second freshness parameter, the first freshness parameter being from the second node, and the second freshness parameter being generated by the first node; The first key is further related to the first freshness parameter and the second freshness parameter.
15. The method of claim 13, wherein, The first key is further related to a third freshness parameter, and the method further comprises: receiving the third freshness parameter from the third node; sending the third freshness parameter to the second node.
16. The method according to any one of claims 13-15, characterized in that, The first key is further related to an identity of the first node and an identity of the second node.
17. The method of any of claims 13-16, wherein The first authentication message and the second authentication message are messages defined by an Extensible Authentication Protocol EAP authentication protocol based on a Transport Layer Security TLS, and the key information includes a TLS master key. Alternatively, the first authentication message and the second authentication message are messages defined by an EAP authentication protocol based on an account password, and the key information includes an account and a password corresponding to the second node.
18. The method of claim 17, wherein, The method further comprises: sending an authentication mode indication, the authentication mode indication being used to indicate an EAP authentication, and the first authentication message and the second authentication message being messages defined by an authentication protocol of the EAP authentication.
19. The method according to any one of claims 13-18, characterized in that, The first key is used to check information that has been transmitted by the first node and the second node.
20. The method according to any one of claims 13-19, characterized by, The method further comprises: receiving a second check parameter from the second node, the second check parameter being related to the first key and information that has been transmitted between the first node and the second node; verifying the second check parameter.
21. The method according to any one of claims 13-20, characterized in that, The method further comprises: generating a first check parameter based on the first key, information that has been transmitted between the first node and the second node; sending the first check parameter to the second node.
22. A method of communication, comprising: The method comprises: receiving a security parameter from a first node, the second node being communicatively connected with the first node, the security parameter comprising an indication of a first key derivation function KDF; performing an authentication procedure with the second node; determining a first key based on at least the first KDF and key information, if the authentication procedure is passed.
23. The method of claim 22, wherein, The performing an authentication procedure with the second node comprises: interacting with the first node a second authentication message, the first node being configured to interact with the second node a first authentication message.
24. The method of claim 22 or 23, wherein, After the determining a first key based on at least the first KDF and key information, the method further comprises: sending the first key to the first node.
25. The method of any one of claims 22-24, wherein, The security parameter further comprises a first freshness parameter and a second freshness parameter; The determining a first key based on at least the first KDF and key information comprises: determining the first key based on the first KDF, the key information, the first freshness parameter and the second freshness parameter.
26. The method of claim 25, wherein, The security parameter further comprises an identity of the first node and an identity of the second node; The determining a first key based on the first KDF, the key information, the first freshness parameter and the second freshness parameter comprises: determining a second key based on the first KDF, the key information, the first freshness parameter and the second freshness parameter; determining the first key based on the first KDF, the second key, the identity of the first node and the identity of the second node.
27. The method of any one of claims 22-24, wherein, The determining a first key based on at least the first KDF and key information comprises: determining a third freshness parameter; determining the first key based on the first KDF, the key information and the third freshness parameter.
28. The method of claim 27, wherein, The security parameter further comprises an identity of the first node and an identity of the second node; The determining a first key based on the first KDF, the key information and the third freshness parameter comprises: determining a second key based on the first KDF, the key information and the third freshness parameter; determining the first key based on the first KDF, the second key, the identity of the first node and the identity of the second node.
29. The method of claim 27 or 28, wherein, After the determining a third freshness parameter, the method further comprises: sending the third freshness parameter to the first node.
30. The method of any of claims 22-29, wherein the authentication procedure is an authentication procedure defined by an Extensible Authentication Protocol EAP authentication protocol based on a Transport Layer Security TLS, and the key information comprises a TLS master key; or, the authentication procedure is an authentication procedure defined by an EAP authentication protocol based on a username and password, and the key information comprises a username and a password corresponding to the second node.
31. A communications device, characterized by The communication device comprises a processing unit and a communication unit, the communication device is configured to implement the method of any of claims 1-12, or for implementing the method of any of claims 13-21, or for implementing the method of any of claims 22-30.
32. A node, characterized by The node comprises at least one processor and at least one memory, The at least one memory is configured to store computer instructions, The at least one processor is configured to invoke the computer instructions stored in the memory so that the method of any of claims 1-12 is performed, or so that the method of any of claims 13-21 is performed.
33. A node, characterized by The node comprises a processor and a memory, The memory is configured to store computer instructions, The processor is configured to invoke the computer instructions stored in the memory so that the method of any of claims 22-30 is performed.
34. A communication system, characterized by The communication system comprises a first node and a second node, The first node is configured to perform the method of any of claims 1-12, The second node is configured to perform the method of any of claims 13-21.
35. The communication system of claim 34, wherein, The communication system further comprises a third node configured to perform the method of any of claims 22-30.
36. A computer-readable storage medium, characterized in that, The computer readable storage medium is configured to store computer instructions; The instructions, when executed by a processor, cause the method of any of claims 1-12 to be performed, or the method of any of claims 13-21 to be performed, or the method of any of claims 22-30 to be performed.