Communication method and related device

By introducing a third node and adopting two-way authentication with digital certificates and signature mechanisms, the problem of fake AP attacks in enterprise networks is solved, and trusted verification of node identities and network security are improved.

CN121770751APending Publication Date: 2026-03-31HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, enterprise network authentication methods are insufficient to prevent fake AP attacks, leading to data leakage of access users. Relying solely on authentication servers to authenticate the identity of terminals is insufficient to ensure network security.

Method used

A third node is introduced for authentication, and a two-way authentication mechanism based on digital certificates is adopted. The identity of the node is verified through the certificates and signatures between the first, second and third nodes to ensure the trustworthiness of the node identity.

Benefits of technology

It significantly improves the security performance of nodes, reduces the possibility of attackers accessing the network, and ensures the security and stability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121770751A_ABST
    Figure CN121770751A_ABST
Patent Text Reader

Abstract

A communication method and a related device are applied to the technical field of communication. In the application, a first node receives a certificate and a signature of a second node, and sends the certificate and the signature of the first node and the certificate and the signature of the second node to a third node. The third node may authenticate the second node and the first node. Furthermore, bidirectional authentication of the ternary peer-to-peer architecture of the first node, the second node and the third node is supported, and the safety performance of the nodes can be further improved. The present application supports a star flash protocol, or the present application supports an IEEE protocol, such as an IEEE 802.11 be / WiFi 7 / EHT protocol, an IEEE 802.11 bn / WiFi 8 / UHR protocol, an IEEE IMMW protocol, and an IEEE 802.15. 4ab / UWB protocol, such as an IEEE 802.11 bf / Sensing protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a communication method and related apparatus. Background Technology

[0002] In the era of rapid development of mobile internet, our tools are more convenient to use than traditional computers, especially desktop workstations and servers. However, we also face greater risks, and communication security has gradually become a key issue in the field of communications. Especially for wireless transmission, nodes and access points (APs) need to first detect each other in a complex space and complete the access process to enable data transmission between them.

[0003] For enterprise networks, internal network security is paramount, often requiring secure authentication of users to ensure the trustworthiness of incoming terminals. Typically, enterprise network authentication involves an authentication server verifying the terminal's identity after it connects to the access point (AP). However, since the connection process involves multiple nodes, such as the terminal, the AP, and the authentication server, relying solely on the authentication server for terminal authentication is insufficient to guarantee network security. For instance, authentication servers alone are vulnerable to fake AP attacks, where attackers impersonate APs. When a terminal connects to a fake AP, it can easily lead to data leakage for the connected user. Summary of the Invention

[0004] This application provides a communication method and related apparatus. In this application, a third node can authenticate the second and first nodes, and this authentication is based on digital certificates, which is highly reliable and can significantly improve the security performance of the nodes and ensure network security. Furthermore, this application supports a two-way authentication mechanism in a three-way peer-to-peer architecture of the first, second, and third nodes. The first, second, and third nodes all use certificates for two-way authentication, which can further improve the security performance of the nodes.

[0005] In a first aspect, this application provides a communication method, comprising: receiving first information and a first signature from a second node, and sending second information and a second signature to a third node. The first information includes a certificate of the second node, the first signature is a signature of the first information, the second information includes the first information, the first signature, and a certificate of the first node, and the second signature is a signature of the second information; the certificate of the first node, the certificate of the second node, the first signature, and the second signature are used for authentication.

[0006] This method can be applied to a first node, which is a device with communication capabilities. In practice, the method can be executed by software modules, hardware modules, or a combination of both within the first node, such as a chip or processor. For ease of description, the following explanation uses the first node as the executing entity.

[0007] In this application, the first information (including the certificate of the second node) and the first signature can be used to authenticate the identity of the second node, and the second information (including the certificate of the first node) and the second signature can be used to authenticate the identity of the second node. The first node obtains the first information and the first signature, and sends the first information, the first signature, the second information, and the second signature to the third node. The third node can authenticate the identities of the first node and the second node based on the first information, the first signature, the second information, and the second signature. Thus, the third node authenticates the identities of the first node and the second node based on digital certificates, ensuring that the identities of both the first node and the second node are trustworthy. This reduces the possibility of attackers accessing the network and also reduces the possibility of nodes being associated with fake access points, ensuring that the identities of both the second node and the first node in the network are trustworthy. Moreover, the authentication process is based on digital certificates and signature mechanisms, ensuring high reliability. In summary, this application can significantly improve the security performance of nodes and guarantee network security.

[0008] In one possible implementation of the first aspect, the first node is the node that the second node requests to associate with; that is, the first node is the node being associated with (which can be considered an access point), and the second node is the node requesting to associate with the first node. Exemplarily, the second node may send an association request (or access request) to the first node, thereby requesting to associate with the first node. This application can significantly improve the security performance of nodes during network access, preventing attackers from accessing the network and avoiding association between nodes and fake access points.

[0009] In another possible implementation of the first aspect, the third node is a node with authentication capabilities, capable of authenticating the first and second nodes. In some scenarios, this is referred to as an authentication node, authentication server, authentication service, etc. By authenticating the nodes accessing the network and the network access points through the third node, it ensures that only trusted and authorized nodes can access the network, and that access to the secure network guarantees network security. Optionally, the third node has a communication connection with the second node, or the third node and the first node belong to the same device. This communication connection can be manifested in the fact that the third node and the first node can send and receive messages.

[0010] In yet another possible implementation of the first aspect, the communication method further includes: receiving third information and a third signature from a third node, the third information including the certificate of the third node, and the third signature being a signature of the third information.

[0011] The aforementioned third information (including the third node's certificate) and third signature can be used to authenticate the third node's identity. Thus, the first node can authenticate the third node or provide the aforementioned information to other nodes for authentication, ensuring the third node's information is reliable and guaranteeing the trustworthiness of the identities of multiple nodes communicated by the first node, further enhancing node security and ensuring network security.

[0012] In another possible implementation of the first aspect, after receiving the first information and the first signature from the second node, the method further includes: authenticating the second node based on the second node's certificate and the first signature.

[0013] For example, the second node's certificate may be issued by a Certificate Authority (CA). The second node can generate a public-private key pair, providing the public key to the CA. The CA uses its own private key to sign the information to be signed, including the information to be signed and the signature in the digital certificate. The information to be signed includes the public key, and optionally also includes one or more of the following: the identity of the second node, information about the CA, and the validity period of the certificate. The first node can verify the signature in the digital certificate based on the CA's public key, thereby checking the certificate's correctness.

[0014] For example, the certificate includes a public key, and the first signature is generated based on the private key and the first information. The first node can verify the first signature based on the public key and the first information in the certificate. If the verification of the first signature is successful, it indicates that the identity of the source of the first information (i.e., the second node) is trustworthy and that the first information has not been tampered with.

[0015] For example, if the second node's certificate is verified successfully and the first signature is verified successfully, it indicates that the second node's identity is trustworthy, and the first node can continue to perform subsequent operations. Conversely, if the second node's identity is not trustworthy, the first node can discard messages received from the second node, disconnect from the second node, add the second node to its blacklist, or stop performing subsequent steps, etc., to ensure the security of the nodes.

[0016] In the above implementation, the first node can authenticate the second node through certificates and signatures, which can improve the security performance of the first node, prevent attackers from accessing the network, and improve the security of the network.

[0017] In another possible implementation of the first aspect, after receiving the third information and the third signature from the third node, the method further includes: authenticating the third node based on the third node's certificate and the third signature.

[0018] For example, the first node can verify the certificate of the third node to determine whether the certificate of the third node is trustworthy. For instance, the certificate of the third node includes information signed by a certificate authority, and the first node can verify the certificate based on the public key of the certificate authority of the third node.

[0019] For example, the first node can verify the third signature. For example, the third node's certificate includes a public key, and the first node can verify the third signature based on the public key in the third node's certificate and the third information. If the verification of the third signature is successful, it indicates that the identity of the source of the third information (i.e., the third node) is trustworthy and that the third information has not been tampered with.

[0020] In the above implementation, while the first node provides its own certificate and signature to other nodes for authentication, it can also authenticate the third node through its certificate and signature. This enables peer-to-peer two-way authentication between the first node and the third node, improves the security performance of the first node, prevents the first node from communicating with the third node disguised by the attacker, and enhances network security.

[0021] In yet another possible implementation of the first aspect, the communication method further includes sending fourth information and a fourth signature to the second node. The fourth information includes third information, a third signature, a certificate of the third node, and a certificate of the first node; the fourth signature is a signature of the fourth information; and the certificates of the first node, the third node, the third signature, and the fourth signature are used for authentication.

[0022] In the above implementation, the first node can provide the second node with its own certificate, third signature, third certificate, and fourth signature, so that the second node can authenticate the first and third nodes. This helps to achieve a peer-to-peer two-way authentication mechanism, improves the security performance of the second node, prevents the second node from communicating with untrusted nodes, and enhances network security.

[0023] In another possible implementation of the first aspect, the third information further includes the authentication result of the third node on the first node and / or the authentication result of the third node on the second node.

[0024] As one possible implementation, the authentication result of the third node to the first node may include one or more of the following: the verification result of the second signature, or the verification result of the first node's certificate. For example, the verification result of the second signature may include whether the verification passed or failed. Similarly, the verification result of the first node's certificate may include whether the certificate verification passed or failed. If the verification fails, the verification result of the first node's certificate may also include a reason for failure, such as one or more of the following: the certificate has expired, the certificate has been revoked, or the certificate is invalid.

[0025] As another possible implementation, the authentication result of the third node on the second node may include one or more of the following: the verification result of the first signature, or the verification result of the second node's certificate. For example, the verification result of the first signature may include whether the verification passed or failed. Similarly, the verification result of the second node's certificate may include whether the certificate verification passed or failed. If the verification fails, the verification result of the second node's certificate may also include a reason for failure, such as one or more of the following: the certificate has expired, the certificate has been revoked, or the certificate is invalid.

[0026] In the above embodiments, by carrying the authentication result in the third information, feedback on the success or failure of authentication (optionally including the reason for failure) can be provided. This facilitates the first node to trigger corresponding security operations based on the authentication result, forming a closed-loop authentication management system and improving network security. For example, if the authentication of the second node is successful, it indicates that the first node and the second node can proceed with subsequent communication processes; otherwise, the first node can disconnect from the second node or cease subsequent communication processes to ensure the communication security of the first node. As another example, if the authentication of the first node fails, the first node can provide feedback or a prompt to trigger the administrator or management device to update the first node's certificate, preventing network access problems and improving network stability.

[0027] In yet another possible implementation of the first aspect, the communication method further includes: sending an authentication method indication, the authentication method indication being used to indicate that the authentication method is a certificate authentication method.

[0028] Optionally, the authentication method indication can be carried in a unicast message, multicast message, or broadcast message. For example, the first node can send broadcast messages periodically or aperiodically, carrying the authentication method indication. Alternatively, the first node can send the authentication method indication in a message sent to the second node.

[0029] Taking the StarFlash communication system as an example, the first node can be a management node, and the second node can be a terminal node. The management node sends communication domain system messages via broadcast, which carry authentication method instructions. The terminal node receives the communication domain system messages, requests association from the management node, and performs the authentication process with the management node and authentication node using the authentication method indicated.

[0030] In some scenarios, the above authentication process is carried out in the enterprise network. For example, the authentication method indicator is used to indicate that the authentication method is: Enterprise Edition - Certificate Authentication Method.

[0031] In the above implementation, before the authentication process, the first node can send an authentication method instruction to indicate the method of authenticating the second node, so that the second node can execute the corresponding authentication process in accordance with the authentication method indicated by the first node.

[0032] In another possible implementation of the first aspect, the first information further includes the public key of the second node, which is used to determine the first key, which is used to verify the information negotiated in the security context negotiation process.

[0033] In the above implementation, the second node may carry a first public key in the first information. This public key can be used to obtain a negotiated key with another node, or to further derive other keys based on the negotiated key. The first key, which may be a negotiated key or a key derived from a negotiated key, is used to verify the information transmitted between the first node and the second node during the security context negotiation process.

[0034] The security context negotiation process is a procedure between the first node and the second node. Verifying the security context negotiation process between the first and second nodes using a first key ensures the information security of both nodes and helps improve the communication security of the first node.

[0035] In some schemes, a security context negotiation process is used to negotiate the security contexts of the first and second nodes. The security context includes, but is not limited to, one or more of the following: security keys, security algorithms, or security parameters. Security keys include, for example, shared keys, master keys, encryption keys, integrity protection keys, authentication encryption keys, identity authentication keys, and identification (ID) encryption keys. Security algorithms include, for example, key negotiation algorithms, key derivation functions (KDFs), authentication encryption algorithms, encryption algorithms, integrity protection algorithms, and message digest algorithms. Security parameters include, for example, freshness parameters, node IDs, information used for encryption, timestamp information, and key validity periods.

[0036] In some schemes, the security context negotiation process is performed before the authentication process. That is, before receiving the first information and the first signature from the second node, the first node and the second node conduct a security context negotiation process. At this time, the identity of the second node has not yet been authenticated. Therefore, a first key can be negotiated and determined during the second node's authentication process. This first key is determined based on identity authentication. Using the first key to verify the information transmitted in the security context negotiation process can ensure the security of the first node's forward information and help improve the communication security of the first node.

[0037] In yet another possible implementation of the first aspect, the first information further includes a first freshness parameter used to determine the first key.

[0038] The above implementation introduces a first freshness parameter provided by the second node into the generation process of the first key, defining a new way to generate the first key and improving security. Using the first freshness parameter as a freshness value in the determination process of the first key can enhance the privacy and uniqueness of the first key, thus helping to improve the security performance of the node.

[0039] In yet another possible implementation of the first aspect, the second information further includes a second freshness parameter, and the third information also includes a second freshness parameter. The second freshness parameter is used to determine the first key.

[0040] The above implementation introduces a second freshness parameter provided by the first node into the generation process of the first key, defining a new way to generate the first key and improving security. Incorporating the second freshness parameter as a freshness value into the determination process of the first key enhances the privacy and uniqueness of the first key, thus contributing to improved node security performance.

[0041] It should be understood that the above embodiments can be combined. For example, a first freshness parameter and a second freshness parameter can be used in the process of determining the first key. Thus, by using the freshness parameters provided by the first node and the second node as freshness values ​​in the process of determining the first key, the privacy and uniqueness of the first key can be improved, which helps to enhance the security performance of the nodes.

[0042] In another possible implementation of the first aspect, before receiving the first information and the first signature from the second node, the method further includes: sending a third fresh parameter to the second node, wherein the first information also includes the third fresh parameter.

[0043] The above implementation provides a challenge-response-based anti-replay mechanism. A replay attack refers to an attack technique where an attacker steals data sent from another device to a target device and resends it to the target device, thereby deceiving the target device and gaining its trust. To prevent attackers from using replay attacks, the first node can send a third fresh parameter to the second node. The first information provided by the second node to the first node includes this third fresh parameter. This third fresh parameter is a fresh parameter specifically sent to the second node and used only by the second node. The third fresh parameter can indicate the uniqueness of this first information and / or identify the second node. If an attacker steals the first information and the first signature and resends it to the first node, since the third fresh parameter in the first information sent by the attacker has already been used, the first node can detect that the first information has already been received. This reduces the likelihood of a successful replay attack and improves the security performance of both the first and second nodes.

[0044] Optionally, the third fresh parameter is the same as the second fresh parameter. That is, the first node will participate in generating the second fresh parameter of the first key and apply it to the anti-replay mechanism. This can avoid the repeated calculation process of determining the fresh parameter and reduce the computational load of the first node.

[0045] In yet another possible implementation of the first aspect, the first information further includes a first timestamp determined by the second node. The first timestamp is unique and can be selected to indicate a moment associated with the first information, such as the moment when the first information was generated or sent, and the moment can be accurate to the second, microsecond, or millisecond level.

[0046] The above implementation provides a timestamp-based anti-replay mechanism. The purpose of the timestamp is to prevent replay, avoiding attackers from copying the information sent from the second node to the first node and resending it to the first node. Since a timestamp can uniquely identify a moment and is carried in the signed first information to prevent tampering, the above implementation can reduce the possibility of a successful replay attack and improve the security performance of the first and second nodes.

[0047] Optionally, the first timestamp may be included in the second information. Further, the first timestamp may be used in generating the first key.

[0048] In another possible implementation of the first aspect, the second information further includes information about the first KDF and / or information about the first key negotiation algorithm, wherein the first KDF is negotiated by the first node and the second node, and the first key negotiation algorithm is negotiated by the first node and the second node. The first key negotiation algorithm is used to negotiate the key, and the first KDF is used to derive the key.

[0049] In the above implementation, the first KDF and the first key negotiation algorithm are negotiated and determined. For a second node with different security capabilities, the first KDF and the first key negotiation algorithm negotiated and determined by it may be different from those of the first node. This allows the authentication process among the first node, the second node, and the third node to be adapted to the first node and the second node with different security capabilities, thereby improving network compatibility and enhancing the user experience.

[0050] For example, a first key negotiation algorithm is used to determine a negotiation master key, and a first KDF is used to determine a first key based on the negotiation master key.

[0051] In another possible implementation of the first aspect, the first node communicates with the second node using a first communication protocol, and the first node communicates with the third node using a second communication protocol, wherein the first communication protocol and the second communication protocol are different.

[0052] The above embodiments provide an application scenario for this application. This application can be applied to complex networks that support multiple communication protocols, and supports authentication of network access nodes, network access points, and authentication nodes in complex communication networks, exhibiting strong compatibility. For example, the first communication protocol is the StarFlash communication protocol, and the second communication protocol is the Ethernet communication protocol.

[0053] In another possible implementation of the first aspect, the first communication protocol is different from the second communication protocol. The information transmitted between the first node and the third node is encapsulated in a data packet. The format of the data packet is the format specified by the first communication protocol. The data packet is carried on the payload of the protocol data unit (PDU) transmitted between the first node and the third node. The format of the PDU is the format specified by the second communication protocol.

[0054] In the above embodiment, the first node and the third node communicate using the second communication protocol. Since the first node also supports the first communication protocol, messages encapsulated using the first communication protocol and transmitted between the first node and the authentication node can be encapsulated in the payload of messages using the second communication protocol for transmission. That is, the PDU transmitted between the first node and the third node has the format specified by the second communication protocol, but the payload of the PDU carries messages from the first communication protocol.

[0055] For example, the second communication protocol is the Ethernet communication protocol, while the first communication protocol is the StarSpark communication protocol. Information transmitted between the first node and the third node is encapsulated using the StarSpark message format, and the StarSpark message is carried in the payload of the Ethernet message. The messages transmitted between the first node and the third node are Ethernet messages. This is equivalent to using the second communication protocol's messages to overwrite the first communication protocol's messages, allowing information transmitted using the first communication protocol to be transmitted using the second communication protocol, thus improving compatibility between different communication protocols.

[0056] In another possible implementation of the first aspect, the payload portion of the PDU further includes a message type field, the value of which indicates the type of data message carried by the payload portion of the PDU.

[0057] For example, the message type field indicates one of the following message types: certificate authentication request, certificate authentication response, certificate authentication complete, or key issuance. It should be understood that the message names above are merely examples, and in specific implementations, the message names can be replaced. Furthermore, terms such as message, message, and packet are different names for data units in different scenarios and can be substituted without conflict.

[0058] In another possible implementation of the first aspect, the first node communicates with the second node using a first communication protocol, and the first node communicates with the third node using a second communication protocol, wherein the first and second communication protocols are the same. The above implementation provides another application scenario, and this application is also applicable to networks supporting a single communication protocol. For example, both the first and second communication protocols are StarScan communication protocols.

[0059] In another possible implementation of the first aspect, receiving the first information and the first signature from the second node includes: receiving an access authentication request from the second node, the access authentication request including the first information and the first signature. That is, the first information and the first signature can be carried and transmitted in the access authentication request. Optionally, the first information can be considered as all data fields in the access authentication request except for the first signature.

[0060] In another possible implementation of the first aspect, sending the second information and the second signature to the third node includes: sending a certificate authentication request to the third node, the certificate authentication request including the second information and the second signature. That is, the second information and the second signature can be carried in the certificate authentication request and transmitted. Optionally, the second information can be considered as all data fields in the certificate authentication request except for the second signature.

[0061] In another possible implementation of the first aspect, receiving third information and a third signature from a third node includes: receiving a certificate authentication response from the third node, the certificate authentication response including the third information and the third signature. That is, the third information and the third signature can be carried and transmitted in the certificate authentication response. Optionally, the third information can be considered as all data fields in the certificate authentication response except for the third signature.

[0062] In another possible implementation of the first aspect, sending the fourth information and the fourth signature to the second node includes: sending an access authentication response to the second node, the access authentication response including the fourth information and the fourth signature. That is, the fourth information and the fourth signature can be carried and transmitted in the access authentication response. Optionally, the fourth information can be considered as all data fields in the access authentication response except for the fourth signature.

[0063] In yet another possible implementation of the first aspect, after sending the fourth information and the fourth signature to the second node, the communication method further includes: receiving a first message from the second node. The first message is used to indicate that access authentication is complete, for example, referred to as an access authentication completion message.

[0064] In the above implementation, the second node can report the completion of access authentication to the first node, so that the first node can perform the corresponding operations after the access authentication is completed. This enables closed-loop management of the access authentication process on the first node side, thereby improving network stability.

[0065] In another possible implementation of the first aspect, after sending the fourth information and the fourth signature to the second node (e.g., after receiving the first message from the second node), the communication method further includes sending a second message to the third node, the second message indicating that certificate authentication is complete, for example, referred to as a certificate authentication complete message.

[0066] In the above implementation, the first node can report the completion of certificate authentication to the third node, so that the third node can perform the corresponding operations after the access authentication is completed. This is beneficial to realize closed-loop management of the certificate authentication process on the third node side and improve the stability of the network.

[0067] Secondly, this application provides a communication method, comprising: sending first information and a first signature to a first node; receiving fourth information and a fourth signature from the first node; authenticating the first node based on the first node's certificate and the fourth signature; and authenticating a third node based on the third node's certificate and the third signature. The first information includes the certificate of a second node, and the first signature is a signature of the first information; the certificate and the first signature of the second node are used for authentication. The fourth information includes third information, a third signature, and the certificate of the first node; the fourth signature is a signature of the fourth information, and the third signature is a signature of the third information; the third information includes the certificate of the third node; the third node is communicatively connected to the first node, and the third node is used for authentication.

[0068] In this context, the third node is used for authentication, meaning that the third node is used to authenticate the identity of other nodes, such as by using certificates, signatures, or other authentication methods to authenticate nodes in the network.

[0069] This method can be applied to a second node, which is a device with communication capabilities. In practice, the method can be executed by software modules, hardware modules, or a combination of both within the second node, such as a chip or processor. For ease of description, the following explanation uses the second node as the executing entity.

[0070] In this application, the first information (including the second node's certificate) and the first signature can be used to authenticate the identity of the second node, and the fourth information (including the third node's certificate, the second node's certificate, and the third signature) and the fourth signature can be used to authenticate the identity of the third node and the identity of the second node. The second node can authenticate the identity of the first node based on the first node's certificate and the fourth signature, and also authenticate the identity of the first node based on the third node's certificate and the third signature. This ensures that both the first node it communicates with and the third node used for authentication are legitimate, reducing the possibility of the second node accessing an unreliable network. Furthermore, the authentication process is based on digital certificates and signature mechanisms, ensuring high reliability. In summary, this application can significantly improve the security performance of nodes and guarantee network security.

[0071] In addition, the second node provides the first node with its certificate and first signature, enabling the second node's identity to be authenticated by other nodes, thus realizing a two-way authentication mechanism in the ternary peer-to-peer architecture and significantly improving the communication security performance of the nodes.

[0072] In one possible implementation of the second aspect, the first node is the node that the second node requests to associate with; that is, the first node is the node being associated with (which can be regarded as an access point), and the second node is the node that requests to associate with the first node.

[0073] In another possible implementation of the second aspect, the third node is a node with authentication capabilities, capable of authenticating the first and second nodes, and is referred to in some scenarios as an authentication node, authentication server, authentication service, etc.

[0074] In another possible implementation of the second aspect, the third node has a communication connection with the second node. This communication connection can be manifested in the fact that the third node and the first node can send and receive messages. In some solutions, the third node and the second node can be integrated into the same device, and they can communicate with each other through software, hardware, or program communication interfaces.

[0075] In another possible implementation of the second aspect, the third information includes the second information and the second signature. The second information includes the first information, the first signature, and the certificate of the first node. The second signature is a signature of the second information. In the above implementation, the certificate of the first node may be specifically carried in the second information, which is included in the third information. The third information is included in the fourth information, so the fourth information includes the certificate of the first node. This nesting of information makes it easier for each node to check its integrity through signatures, thus improving communication security.

[0076] In another possible implementation of the second aspect, the third information also includes the authentication result of the third node on the first node and / or the authentication result of the third node on the second node.

[0077] In another possible implementation of the second aspect, before sending the first information and the first signature to the first node, the method further includes: receiving an authentication method indication from the first node, the authentication method indication being used to indicate that the authentication method is a certificate authentication method.

[0078] In some scenarios, the above authentication process is carried out in the enterprise network. For example, the authentication method indicator is used to indicate that the authentication method is: Enterprise Edition - Certificate Authentication Method.

[0079] In another possible implementation of the second aspect, the third information further includes the public key of the third node, and the method further includes: using a first key negotiation algorithm to determine a first key based on the public key of the third node and the private key of the second node.

[0080] Furthermore, the first key is used to verify the information negotiated during the security context negotiation process.

[0081] The security context negotiation process is a process conducted between the first node and the second node. By verifying the security context negotiation process between the first node and the third node using a first key (optionally obtained through key derivation or other processes), the information security of the first and second nodes can be guaranteed, thus improving the communication security of the first node.

[0082] In some schemes, the security context negotiation process is used to negotiate the security contexts of the first node and the second node. In other schemes, the security context negotiation process is performed before the authentication process; that is, the second node and the first node perform the security context negotiation process before the first information and the first signature are sent to the first node.

[0083] In another possible implementation of the second aspect, the first key negotiation algorithm is a key negotiation algorithm negotiated and determined by the first node and the second node. For example, the first key negotiation algorithm is negotiated and determined during the security context negotiation process.

[0084] In another possible implementation of the second aspect, the first information further includes the public key of the second node, which is associated with the private key of the second node. By carrying the public key of the second node in the first information, the third node can easily obtain a negotiated key consistent with that of the second node based on the public key of the second node and its own private key.

[0085] In another possible implementation of the second aspect, the first information further includes a first freshness parameter. Determining the first key based on the public key of the third node and the private key of the second node using a first key negotiation algorithm includes: determining a negotiation key based on the public key of the third node and the private key of the second node using the first key negotiation algorithm, and determining the first key based at least on the negotiation key and the first freshness parameter.

[0086] The above implementation introduces a first freshness parameter provided by the second node into the generation process of the first key, defining a new way to generate the first key and improving security. Using the first freshness parameter as a freshness value in the determination process of the first key can enhance the privacy and uniqueness of the first key, thus helping to improve the security performance of the node.

[0087] In another possible implementation of the second aspect, the fourth information further includes a second freshness parameter, which is generated by the first node. Determining the first key using a first key negotiation algorithm based on the public key of the third node and the private key of the second node includes: determining a negotiation key using the first key negotiation algorithm based on the public key of the third node and the private key of the second node, and determining the first key based at least on the negotiation key and the second freshness parameter.

[0088] The above implementation introduces a second freshness parameter provided by the first node into the generation process of the first key, defining a new way to generate the first key and improving security. Incorporating the second freshness parameter as a freshness value into the determination process of the first key enhances the privacy and uniqueness of the first key, thus contributing to improved node security performance.

[0089] In another possible implementation of the second aspect, the first information includes a first freshness parameter, and the third information further includes a second freshness parameter. Determining the first key using a first key negotiation algorithm based on the public key of the third node and the private key of the second node includes: determining a negotiation key using the first key negotiation algorithm based on the public key of the third node and the private key of the second node, and determining the first key based at least on the negotiation key, the first freshness parameter, and the second freshness parameter.

[0090] The above implementation introduces a first freshness parameter and a second freshness parameter into the generation process of the first key, defining a new way to generate the first key and improving security. Using the first and second freshness parameters as freshness values ​​in the determination process of the first key enhances the privacy and uniqueness of the first key, thus contributing to improved node security.

[0091] In another possible implementation of the second aspect, determining the first key is based at least on the negotiation key, the first fresh parameter, and the second fresh parameter, including: determining an intermediate key based on the first key derivation function KDF, the negotiation key, the first fresh parameter, and the second fresh parameter, and determining the first key based at least on the first KDF and the intermediate key.

[0092] The above implementation introduces a first fresh parameter and a second fresh parameter into the generation process of the first key, defining a new way to generate the first key. In the process of generating the first key, an intermediate key is first derived based on the negotiation key, the first fresh parameter, and the second fresh parameter, and then the first key is derived based on the intermediate key. The key system with multiple layers of derivation and multiple fresh parameters involved in the derivation can improve the privacy and uniqueness of the first key, which helps to improve the security performance of the node.

[0093] In another possible implementation of the second aspect, the first key is determined at least based on the negotiation key, the first fresh parameter, and the second fresh parameter, including: determining an intermediate key based on the first key derivation function KDF, the negotiation key, the first fresh parameter, and the second fresh parameter, and determining the first key based on the first KDF, the intermediate key, the identifier of the first node, and the identifier of the second node.

[0094] The above implementation introduces a first freshness parameter, a second freshness parameter, the identifier of the first node, and the identifier of the second node into the generation process of the first key, defining a new way to generate the first key. In the process of generating the first key, an intermediate key is first derived based on the negotiation key, the first freshness parameter, and the second freshness parameter, and then the first key is derived based on the intermediate key, the identifier of the first node, and the identifier of the second node. The key system with multiple layers of derivation and multiple parameters involved in the derivation can improve the privacy and uniqueness of the first key, and help improve the security performance of the node.

[0095] In another possible implementation of the second aspect, before sending the first information and the first signature to the first node, the method further includes: determining a first timestamp, wherein the first information also includes the first timestamp. The first timestamp is unique and can be selected to indicate a moment related to the first information, such as the moment when the first information was generated or when the first information was sent, and the moment can be accurate to the second, microsecond, or millisecond level.

[0096] The above implementation provides a timestamp-based anti-replay mechanism, where the timestamp is used to prevent replay attacks. Because a timestamp uniquely identifies a moment and is carried within the signed first information to prevent tampering, the above implementation reduces the likelihood of a successful replay attack, thus improving the security performance of both the first and second nodes.

[0097] Optionally, the first timestamp can participate in the process of deriving the first key, for example, as one of the inputs in the process of deriving the intermediate key based on the negotiated key. Alternatively, it can participate in the process of deriving the first key based on the intermediate key as one of the inputs.

[0098] In another possible implementation of the second aspect, before sending the first information and the first signature to the first node, the method further includes: receiving a third fresh parameter from the first node, wherein the first information also includes the third fresh parameter.

[0099] The above implementation provides a challenge-response-based anti-replay mechanism. The third freshness parameter can indicate the uniqueness of the first information and / or mark the second node. If an attacker steals the first information and the first signature and resends it to the first node, the first node can detect that the first information has already been received because the third freshness parameter in the first information sent by the attacker has been used. This reduces the possibility of a successful replay attack and improves the security performance of the first and second nodes.

[0100] Optionally, the third fresh parameter is the same as the second fresh parameter. That is, the first node will participate in generating the second fresh parameter of the first key and apply it to the anti-replay mechanism. This can avoid the repeated calculation process of determining the fresh parameter and reduce the computational load of the first node.

[0101] In another possible implementation of the second aspect, sending the first information and the first signature to the first node includes: sending an access authentication request to the first node, the access authentication request including the first information and the first signature. That is, the first information and the first signature can be carried and transmitted in the access authentication request. Optionally, the first information can be regarded as all data fields in the access authentication request except for the first signature.

[0102] In another possible implementation of the second aspect, receiving the fourth information and the fourth signature from the first node includes: receiving an access authentication response from the first node, the access authentication response including the fourth information and the fourth signature. That is, the fourth information and the fourth signature can be carried and transmitted in the access authentication response. Optionally, the fourth information can be considered as all data fields in the access authentication response except for the fourth signature.

[0103] Thirdly, this application provides a communication method, comprising: receiving second information and a second signature from a first node; authenticating the first node based on the first node's certificate and the second signature; authenticating the second node based on the second node's certificate and the first signature; and sending third information and a third signature to the first node. The second information includes the first information, the first signature, and the certificate of the first node; the first information includes the certificate of the second node; the first signature is a signature of the first information; and the second signature is a signature of the second information. The third information includes the certificate of the third node; the third signature is a signature of the third information; and the certificate and the third signature of the third node are used for authentication.

[0104] This method can be applied to a third node, which is a device with communication and authentication capabilities, capable of authenticating the first and second nodes. In some scenarios, it is referred to as an authentication node, authentication server, or authentication service. In specific implementation, this method can be executed by software modules, hardware modules, or a combination of both within the first node, such as by a chip or processor module within the third node. For ease of description, the following explanation uses the third node as the executing entity.

[0105] In this application, the second information (including the certificate of the second node, the first signature, and the certificate of the second node) and the first signature can be used to authenticate the identity of the second node and the identity of the third node, while the third information (including the certificate of the third node) and the third signature can be used to authenticate the identity of the third node. The third node can authenticate the identity of the first node based on the certificate of the first node and the second signature, and authenticate the identity of the second node based on the certificate of the second node and the first signature. This ensures that the identities of the first node it communicates with and the second nodes connected to by the first node are both valid, reducing the possibility of the second node accessing an unreliable network. Moreover, the above authentication process is based on digital certificates and signature mechanisms, ensuring high reliability. In summary, this application can significantly improve the security performance of nodes and guarantee network security.

[0106] In addition, the third node provides the first node with its own certificate and third signature, enabling the third node's identity to be authenticated by other nodes. This achieves a two-way authentication mechanism in the ternary peer-to-peer architecture, significantly improving the communication security performance of the nodes.

[0107] In another possible implementation of the third aspect, the third information also includes the authentication results of the first node and / or the authentication results of the second node.

[0108] In another possible implementation of the third aspect, the first information further includes the public key of the second node, and the method further includes: determining a first key based on the public key of the second node and the private key of the third node using a first key negotiation algorithm. Further, the first key is used to verify the information negotiated in the security context negotiation process.

[0109] In another possible implementation of the third aspect, the first information includes a first freshness parameter. Determining the first key based on the public key of the second node and the private key of the third node using a first key negotiation algorithm includes: determining a negotiation key based on the public key of the second node and the private key of the third node using the first key negotiation algorithm, and determining the first key based at least on the negotiation key and the first freshness parameter.

[0110] In another possible implementation of the third aspect, the third information further includes a second freshness parameter. Determining the first key using a first key negotiation algorithm based on the public key of the second node and the private key of the third node includes: determining a negotiation key using the first key negotiation algorithm based on the public key of the second node and the private key of the third node, and determining the first key based at least on the negotiation key and the second freshness parameter.

[0111] In another possible implementation of the third aspect, the first information includes a first freshness parameter, and the third information further includes a second freshness parameter. Determining the first key based on the public key of the second node and the private key of the third node using a first key negotiation algorithm includes: determining a negotiation key based on the public key of the second node and the private key of the third node using the first key negotiation algorithm, and determining the first key based at least on the negotiation key, the first freshness parameter, and the second freshness parameter.

[0112] In another possible implementation of the third aspect, determining the first key is based at least on the negotiation key, the first freshness parameter, and the second freshness parameter, including: determining an intermediate key based on the first KDF, the negotiation key, the first freshness parameter, and the second freshness parameter, and determining the first key based at least on the first KDF and the intermediate key.

[0113] In another possible implementation of the third aspect, the first key is determined at least based on the negotiation key, the first freshness parameter, and the second freshness parameter, including: determining an intermediate key based on the first KDF, the negotiation key, the first freshness parameter, and the second freshness parameter, and determining the first key based on the first KDF, the intermediate key, the identifier of the first node, and the identifier of the second node.

[0114] In another possible implementation of the third aspect, the second information further includes information about the first KDF and / or information about the first key negotiation algorithm, wherein the first KDF is negotiated by the first node and the second node, and the first key negotiation algorithm is negotiated by the first node and the second node.

[0115] In another possible implementation of the third aspect, the first node and the second node communicate using a first communication protocol, and the first node and the third node communicate using a second communication protocol, wherein the first communication protocol and the second communication protocol are different.

[0116] In another possible implementation of the third aspect, the information transmitted between the first node and the third node is encapsulated in a data packet, the format of which is specified by the first communication protocol, and the data packet is carried on the payload of the PDU transmitted between the first node and the third node, the format of which is specified by the second communication protocol.

[0117] In another possible implementation of the third aspect, the payload portion of the PDU also includes a message type field, the value of which is used to indicate the type of data message carried by the payload portion of the PDU.

[0118] In another possible implementation of the third aspect, receiving the second information and the second signature from the first node includes: receiving a certificate authentication request from the first node, the certificate authentication request including the second information and the second signature.

[0119] In another possible implementation of the third aspect, sending third information and third signature to the first node includes: sending a certificate authentication response to the first node, the certificate authentication response including the third information and third signature.

[0120] Fourthly, this application provides a communication device, which includes units or modules for performing the methods described in the first aspect or any possible implementation of the first aspect.

[0121] And / or, the communication device includes a unit or module for performing the method described in the second aspect or any possible implementation of the second aspect.

[0122] And / or, the communication device includes a unit or module for performing the method described in the third aspect or any possible implementation of the third aspect.

[0123] For example, the communication device includes a processing unit and a communication unit. The processing unit performs one or more operations such as negotiation, processing, determination, generation, calculation, encryption, and decryption. The communication unit performs one or more operations such as sending and receiving.

[0124] Fifthly, this application provides a node including a processor and a memory, the memory for storing computer instructions, and the processor for calling the computer instructions stored in the memory to implement the method described in the first aspect or any possible implementation of the first aspect, and / or to implement the method described in the second aspect or any possible implementation of the second aspect, and / or to implement the method described in the third aspect or any possible implementation of the third aspect.

[0125] In a sixth aspect, this application provides a chip including a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices (including nodes) and transmit them to the processor, or to send signals from the processor to other communication devices (including nodes). The processor implements the aforementioned communication method through logic circuits or executing code instructions.

[0126] For example, the processor is used to implement the method described in the first aspect or any possible implementation of the first aspect, and / or to implement the method described in the second aspect or any possible implementation of the second aspect, and / or the method described in the third aspect or any possible implementation of the third aspect.

[0127] In a seventh aspect, this application provides a communication system, which includes a first node and a second node. The first node is used to implement the method described in the first aspect or any possible implementation of the first aspect, and the second node is used to implement the method described in the second aspect or any possible implementation of the second aspect.

[0128] In one possible implementation of the seventh aspect, the communication system further includes a third node for implementing the method described in the third aspect or any possible implementation thereof. Optionally, the first node and the third node may be integrated in the same device.

[0129] Eighthly, this application provides a terminal, which includes the communication device described in the fourth aspect, or the node described in the fifth aspect, or the chip described in the sixth aspect, or the communication system described in the seventh aspect. Optionally, the terminal may be a handheld terminal, wearable device, vehicle, robot, drone, or other intelligent device or vehicle.

[0130] Ninthly, this application provides a readable storage medium for storing a computer program that, when executed by a processor, causes a communication device including a processor to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect.

[0131] In a tenth aspect, this application provides a computer program product that, when executed by a processor, causes a communication device including a processor to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect.

[0132] For some of the beneficial effects of the technical solutions in aspects two through ten of this application, please refer to the beneficial effects of the technical solutions in aspect one. Attached Figure Description

[0133] The accompanying drawings used in the description of the embodiments will be briefly introduced below.

[0134] Figure 1 This is a schematic diagram of the architecture of a communication system;

[0135] Figure 2 This is a schematic diagram of the architecture of another communication system;

[0136] Figure 3 This is a schematic diagram of a network architecture provided in an embodiment of this application;

[0137] Figure 4 This is a flowchart illustrating a communication method provided in an embodiment of this application;

[0138] Figure 5 This is a flowchart illustrating a security context negotiation process;

[0139] Figure 6 This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0140] Figure 7 This is a schematic diagram of a transmission unit of a second communication protocol compatible with a message of a first communication protocol, provided in an embodiment of this application.

[0141] Figure 8 This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0142] Figure 9 This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0143] Figure 10 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0144] Figure 11 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation

[0145] The following section will introduce some of the technical terms.

[0146] 1. Node

[0147] A node is a device with communication capabilities, including but not limited to one or more of user equipment, network equipment, and industrial equipment. User equipment includes one or more of handheld terminals, wearable terminals, vehicles, in-vehicle equipment, sensing devices, smart home devices, or leisure and entertainment devices. Handheld terminals include, but are not limited to, mobile phones, tablets, or laptops. Wearable devices include, but are not limited to, headphones, smart bracelets, smartwatches, or smart glasses. Vehicles include, but are not limited to, vehicles, ships, aircraft, rail transit (such as subways and high-speed trains), or logistics robots (such as automated guided vehicles (AGVs)). In-vehicle equipment includes, but is not limited to, domain controllers (DCs), screens, microphones, speakers, electronic keys, keyless entry, start system controllers, battery management systems (BMS), battery packs, or battery cells. Sensing devices include, but are not limited to, cameras, radar, lidar, light sensors, temperature sensors, or humidity sensors. Smart home devices include, but are not limited to, projectors, smart TVs, smart refrigerators, smart home gateways, or security equipment. Leisure and entertainment equipment includes, but is not limited to, virtual reality (VR) devices, mixed reality (MR) devices, massage chairs, home theaters, gaming controllers, or 4D cinema cabins. Network equipment includes, but is not limited to, routers, switches, or base stations. Industrial equipment includes, but is not limited to, industrial robots or robotic arms.

[0148] This application is applicable to a variety of networks, and nodes will be used in this document to represent devices in these networks.

[0149] Exemplary, this application can be applied to wired communication networks, wireless communication networks, or networks formed by a combination of wired and wireless communication. For example, wireless communication networks include networks connected via communication technologies such as SparkLink (or NearLink), 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB), or short-range wireless communication systems. And / or, wireless communication networks include long-range connectivity technologies, such as communication technologies based on Long Term Evolution (LTE), 5th generation mobile networks (or 5th generation wireless systems, 5th-Generation, abbreviated as 5G or 5G technology), Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), and Universal Mobile Telecommunications System (UMTS), etc. For example, wired communication networks include networks connected via the following communication technologies: fiber optic connection technology, in-vehicle wired communication technology, controller area network (CAN), local interconnect network (LIN), CAN flexible data rate (CAN FD), or in-vehicle Ethernet, or one or more of these.

[0150] The nodes in this application embodiment can be applied to various scenarios such as smart cars, smart homes, smart terminals, smart manufacturing, smart showrooms, mobile internet (MI), industrial control, self-driving, transportation safety, or the Internet of Things (IoT).

[0151] It should be understood that in certain application scenarios or network types, devices with communication capabilities may not be referred to as nodes. However, for ease of description, devices with communication capabilities are collectively referred to as nodes in this application embodiment.

[0152] 2. Certificate and Signature Mechanism

[0153] A certificate, also known as a digital certificate, is a digital authentication method used in internet communication to identify and authenticate the identities of parties involved. Certificates are typically issued by a Certificate Authority (CA). An applicant generates a public-private key pair (including a private key and a public key) and provides the CA with their identity and the public key from the public-private key pair. The CA then issues a certificate to the applicant corresponding to that public key. The purpose of the certificate is to prove that the applicant listed in the certificate legitimately owns the public key listed in the certificate. The digital signature of the CA prevents attackers from forging and tampering with the certificate.

[0154] When an applicant sends information to a destination device, they sign the information with their private key and provide a certificate issued by a CA (Certificate Authority). The destination device can verify the signature of the certificate based on the CA's public key and use the public key in the certificate to verify the signature of the information sent by the applicant, thereby ensuring that the source of the information is indeed the applicant and that the applicant's identity is trustworthy.

[0155] 3. Key negotiation algorithm

[0156] Key negotiation is the process by which two communicating parties exchange a set of parameters to negotiate and obtain a key. The algorithm used for key negotiation is called a key negotiation algorithm. Key negotiation algorithms include the Diffie-Hellman key exchange (DH) algorithm, the DH (ECDH) algorithm based on Elliptic Curve Cryptosystems (ECC), the Two-Basis Password Exponential Key Exchange (TBPEKE) algorithm, Chinese national cryptographic algorithms (such as SM2), and the Oakley algorithm, among others.

[0157] It should be noted that a key negotiation algorithm can also be regarded as a key negotiation protocol. That is, for the two parties communicating, the key negotiation algorithm defines the rules for key generation.

[0158] 4. Key Derivation Function (KDF)

[0159] Key Derivation Functions (KDFs), also known as key derivation algorithms, key derivation functions, and key inference functions, are used to derive (or derive) one or more secret values ​​from a given secret value. For example, a new secret value DK derived from the secret value Key can be represented as: DK = KDF(Key). Of course, Key here is just an example; in actual implementations, other parameters can participate in the key derivation process.

[0160] The key derivation algorithms involved in the embodiments of this application may include hash algorithms, password-based key derivation functions (PBKDF), scrypt algorithms, etc. For example, hash algorithms include algorithms called hash-based message authentication codes (HMAC) and cipher-based message authentication codes (CMAC). Specifically, the hash algorithm used in HMAC can be one of the following: Chinese national cryptographic algorithms (such as SM3), SHA-256, SHA-1, etc. These different HMACs are usually labeled as: HMAC-SM3, HMAC-SHA 256, HMAC-SHA1, etc. CMAC can be combined with other cryptographic algorithms, for example, combined with the Advanced Encryption Standard (AES) to form the AES-CMAC algorithm. The PBKDF algorithm includes the first generation PBKDF1 and the second generation PBKDF2.

[0161] It should be understood that some KDF algorithms can perform hash transformations on the input secret value using hash algorithms. Therefore, KDF functions can also accept an algorithm identifier as input, indicating which hash algorithm to use. It should be noted that KDF is not only used for deriving secret values, but also for generating authentication and identity information.

[0162] 5. Safety Protection

[0163] Security protection includes one or more of the following: confidentiality protection, integrity protection, and authentication encryption. Confidentiality protection requires the use of an encryption key or an authentication encryption key. Integrity protection requires the use of an integrity protection key or an authentication encryption key.

[0164] 6. Freshness parameters

[0165] Freshness parameters are used in encryption, integrity protection, key derivation, key negotiation, and other processes; they can also be called freshness or freshness-related parameters. Generally, the specific value of a freshness parameter changes after each generation, ensuring that the value of the freshness parameter determined each time is different from the value determined previously, thus improving security.

[0166] For example, fresh parameters may include random numbers (such as NONCE), counter values, etc.

[0167] The foregoing explanation of the technical terms may be used in the embodiments described below.

[0168] The following describes the architecture and business scenarios of communication systems to which the embodiments of this application can be applied. It should be noted that the system architecture and business scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. It should be understood that as system architectures evolve and new business scenarios emerge, the technical solutions provided in this application are also applicable to similar technical problems.

[0169] This application can be applied to communication systems, which are systems that transmit information using electrical signals (or optical signals). A communication system typically includes multiple nodes that can establish communication connections to transmit information. Nodes in a communication system may have different identities and / or different capabilities. Communication systems can include wired communication systems and wireless communication systems. Wireless communication systems include short-range wireless communication systems and long-range wireless communication systems. Examples of short-range communication systems include Starlink, 802.11b / g, and Bluetooth. Examples of long-range wireless communication systems include LTE and 5G.

[0170] The following is combined with Figure 1 Taking the StarFlash communication system as an example, this paper introduces the architecture of a communication system. Figure 1 The communication system shown includes a management node and terminal nodes. Among them:

[0171] Management nodes possess both communication and management capabilities, and are sometimes referred to as G nodes, access points, or authorized nodes. Management capabilities include communication management, such as connection management, resource scheduling, or information security management. For example, a management node can send resource management information or data scheduling information, such as access layer resource management information.

[0172] Terminal nodes, also known as T-nodes in some scenarios, have communication capabilities and can transmit services with management nodes. In some solutions, terminal nodes are nodes that receive resource management information (or data scheduling information) and send data according to the resource management information (or data scheduling information). For example, terminal nodes may include user equipment (UE), such as barcode scanners, radio frequency identification (RFID), sensors, global positioning system (GPS), lidar, and battery cells.

[0173] It should be understood that the identities of management nodes and terminal nodes are not absolute. The identities shown herein are merely exemplary names used to distinguish the operation of communicating nodes in a possible connection scenario. In some scenarios, a node may belong to two or more communication domains simultaneously, acting as a terminal node in some domains and as a management node in others. For ease of understanding, such a node is referred to as a G(T) node in some embodiments.

[0174] Combination Figure 1 Terminal nodes and management nodes can establish associations. Establishing an association requires executing an association process. Before executing the association process, the management node can send a broadcast message, and the terminal node can detect the management node based on the broadcast message. Furthermore, the terminal node can request to associate with the management node. After the terminal node and management node complete the association process, an association relationship can be established.

[0175] It should be noted that, in Figure 1 In this diagram, the connection between the management node and the terminal node is represented by a dashed line. However, in some schemes, the connection includes two links: a communication link to the management node and a communication link to the terminal node. The communication link to the management node is the communication link from the management node to the terminal node, and can carry one or more of the following: data channel, control information, broadcast channel, synchronization signal, etc., from the management node to the terminal node; this can be called a G-link. The communication link to the terminal node is the communication link from the terminal node to the management node, and can carry one or more of the following: data channel, access channel, or feedback signal, etc., from the terminal node to the management node; this can be called a T-link.

[0176] Optionally, communication between the management node and the terminal nodes may include unicast, multicast, and / or broadcast communication. In some schemes, such as... Figure 1 As shown, a management node can connect to one or more terminal nodes. In the StarFlash communication system, a management node supports connecting to multiple terminal nodes, and a terminal node also supports associating with multiple management nodes.

[0177] This application supports the Spark Link / NearLink protocol, or it supports IEEE protocols such as IEEE 802.11be / WiFi 7 / EHT (extremely high throughput), IEEE 802.11bn / WiFi 8 / UHR (ultra-high reliability), IEEE IMMW (Integrated mmWave), IEEE 802.15.4ab / UWB (ultra-wideband), and IEEE 802.11bf / Sensing.

[0178] The communication system used in this application can be used in scenarios such as smart parks, smart homes, smart exhibition halls, smart factories, and smart buildings.

[0179] To enhance control over nodes accessing the network, communication systems typically employ a third node for authenticating these nodes. Please refer to [link to relevant documentation]. Figure 2 , Figure 2 This is a schematic diagram of the architecture of another communication system, which includes a first node 10 (which can be regarded as a management node), a second node 20 (which can be regarded as a terminal node) and a third node 30.

[0180] In this system, the first node 10 can be associated with by other nodes, the second node 20 can request to associate with the first node 10, and the third node 30 can authenticate the second node 20, and further authenticate the first node 10. It should be understood that the third node 30 here refers to a functional module capable of performing identity authentication. In specific implementations, the third node 30 may be a physical device or a virtual device. For example, the third node may include authentication devices (or authentication nodes), authentication services, etc., where authentication devices include, for example, a RADIUS server, a portal server, an access controller (AC), etc., and authentication services include, for example, a third-party RADIUS server, an SMS server, etc.

[0181] It should be noted that, Figure 2 The devices shown are merely examples. In some implementations, the third node 30 can be integrated with the first node 10 in the same device; however, this application also applies to cases where they are configured separately. Similarly, the first node 10 and the second node 20 may also be integrated into the same device; likewise, this application also applies to cases where they are configured separately.

[0182] In some scenarios (such as in enterprise networks), the first node can act as a network-side node, providing network resource access services to end nodes. See also... Figure 3 , Figure 3 This is a schematic diagram of a network architecture provided in an embodiment of this application, including user terminals, access devices, controlled resources, and authentication services, and optionally network facilities. The devices in the access device layer can be regarded as first nodes (such as G nodes), the devices in the user terminal layer can be regarded as second nodes (such as T nodes), and the authentication service (which can be regarded as a third node) may include authentication servers and / or third-party authentication servers. For example, the user terminal level includes, but is not limited to, one or more of the following: visitor, customer, dumb terminal, ordinary enterprise user, high-security enterprise user, or police wireless local area network (PWL) terminal user. The access device level includes, but is not limited to, one or more of the following: access point (AP), radio unit (RU), fat AP, or mobile AP. The controlled resources include, but are not limited to, one or more of the following: enterprise intranet, third-party service, or Internet. The authentication devices include, but are not limited to, one or more of the following: RADIUS server, portal server, or AC. The third-party authentication services include, but are not limited to, one or more of the following: third-party RADIUS, SMS server, or third-party service (referring to authentication service). The network infrastructure level includes, but is not limited to, one or more of the following: aggregation switch, gateway firewall, access switch, or core switch. The access devices, authentication services, network infrastructure (optional), and controlled resources can be connected via wired and / or wireless communication links. Wired communication links include, for example, Ethernet, and wireless communication links include, for example, fourth-generation (4G) and / or fifth-generation (5G) communication systems. Access devices and user terminals can be connected via wireless communication links, such as those based on the StarScan communication protocol.

[0183] exist Figure 3 In the network architecture shown, devices at the access device level can provide access points to devices at the user terminal level, enabling these devices to access controlled resources. Before accessing controlled resources, after a user terminal connects to the device, an authentication service is needed to verify the identity of the user terminal before accessing the network, considering internal network security. This is to prevent attackers from impersonating legitimate devices to access controlled resources. However, the current method of authenticating user terminals has security vulnerabilities.

[0184] In view of this, this application provides a communication method and related apparatus. In this application, the third node can authenticate the second node and the first node, and this authentication is based on digital certificates, which has high reliability and can significantly improve the security performance of the nodes and ensure network security. Furthermore, this application supports bidirectional authentication in a three-way peer-to-peer architecture of the first node, the second node, and the third node. The first node, the second node, and the third node all use certificates for bidirectional authentication, which can further improve the security performance of the nodes.

[0185] The methods provided in the embodiments of this application will be described below.

[0186] Please see Figure 4 , Figure 4 This is a flowchart illustrating a communication method provided in an embodiment of this application. For ease of understanding, the first node, the second node, and the third node are used as exemplary execution entities to describe the communication method. Optionally, this method can be applied to a communication system, such as... Figure 1 , Figure 2 or Figure 3 The communication system shown. (As shown) Figure 4 The communication method shown may include some or all of the steps S401 to S410. It should be understood that, for ease of description, the steps S401 to S410 are described in this order, and it is not intended to limit the execution to this specific order. This application embodiment does not limit the order of execution, the execution time, or the number of executions of one or more of the above steps. Steps S401 to S410 are as follows:

[0187] Step S401: The second node sends the first information and the first signature to the first node. Correspondingly, the first node receives the first information and the first signature from the second node.

[0188] The first piece of information includes the certificate of the second node, which is used to authenticate the second node. For example... Figure 4 The information corresponding to the signature is described below the information provided. In some schemes, the second node's certificate includes the second node's public key, which, together with the second node's private key, forms a public-private key pair used for the certificate and signing mechanism. Optionally, the second node's certificate is issued by a CA. Further, the CA can perform authentication or cooperate with authentication services to issue certificates, for example, issuing a certificate to the second node if the second node has the corresponding permissions (such as the permission to access specific resources).

[0189] The first signature is a signature of the first information. For example, the second node generates the first signature based on the privacy key (which, together with the public key in the certificate, forms a public-private key pair) and the first information. Based on the public key in the certificate and the first signature, the second node can verify the first information, check the correctness of the first signature, and determine whether the first information has been tampered with.

[0190] In some possible implementations, the first information may also include one or more of the following: the public key of the second node, a first timestamp, a first freshness parameter, or a third freshness parameter. These will be described in detail below:

[0191] (1) The public key of the second node is the exchange parameter used for key negotiation, and is the public key of the key negotiation algorithm provided by the second node. The public key of the second node can be determined based on the private key of the second node. For example, taking the DH algorithm, the second node generates the private key of the first node and uses the key negotiation algorithm to calculate the public key of the first node based on the private key of the first node. The other party in the key negotiation, taking the third node as an example, also generates a private key and uses the same key negotiation algorithm to calculate the public key based on the private key. The second node and the third node can exchange public keys and use the key negotiation algorithm to calculate a consistent negotiation key using the public key provided by the other party and their own private key.

[0192] The second node sends its public key to the first node, facilitating the negotiation between the second node and the authentication server to obtain a consistent negotiation key. Based on this negotiation key, the second node and the authentication server (or other nodes trusted by the authentication server) can perform secure protection and / or security verification of information, thereby further enhancing the node's security performance.

[0193] Since the initial information is signed, its source can be verified and its integrity can be guaranteed based on the signature. Protecting the public key exchanged during key negotiation with certificates and signature mechanisms can prevent man-in-the-middle attacks during key negotiation, further enhancing the security of the key negotiation process and improving the security performance of the nodes.

[0194] (2) The first timestamp is a timestamp determined by the second node, which typically indicates a specific moment. The first timestamp can uniquely identify a moment, possessing uniqueness and reducing the likelihood of a successful replay attack. Furthermore, this first timestamp can be carried in the signed first information to prevent tampering, further enhancing the security performance of both the first and second nodes.

[0195] In some schemes, the first timestamp is used to indicate the moment associated with the first piece of information, such as the moment the first piece of information was generated or sent. This moment can be accurate to the second, microsecond, or millisecond level, and can be predefined or designed according to the specific circumstances.

[0196] (3) The first fresh parameter is a fresh parameter, such as a random number, a counter value, or other parameters that can have freshness.

[0197] Optionally, the first freshness parameter is used to determine the first key, which is a key shared between the second and third nodes and can be used for security protection or security verification. In one possible implementation, the first key is used to verify information negotiated in the security context negotiation process (described below).

[0198] (4) The third fresh parameter is a fresh parameter, such as a random number, a counter value, or other parameters that can have freshness.

[0199] The third fresh parameter is provided by the first node to the second node. Before step S401, the first node sends the third fresh parameter to the second node. Correspondingly, the second node receives the third fresh parameter and sends it back to the first node. This third fresh parameter is a fresh parameter specifically sent to the second node and used only by the second node. The third fresh parameter can indicate the uniqueness of the information carrying the third information parameter and / or identify the second node. If an attacker steals the information sent by the second node to the first node and resends it to the first node, the first node can detect the replay attack because the stolen third fresh parameter has already been received by the first node. This prevents attackers from using replay attacks to infiltrate the network and improves the security performance of the nodes and the network.

[0200] Sending the third fresh parameter along with the first message can prevent the third fresh parameter from being tampered with and can also prevent the first message from being stolen and used for replay attacks, thus improving the security of the node.

[0201] The above information may be partially or fully contained in the first information. The combination of these information will not be described in detail here, but will be introduced in conjunction with specific implementation methods in the following text.

[0202] In some possible implementations, the first information and the first signature may be carried in one or a group of messages for easy distinction and referred to as message M1. For example, message M1 may include multiple data fields, with the first signature carried in the field corresponding to the first signature, and the first information can be considered as all the data fields of message M1 except for the first signature. In some schemes, message M1 is referred to as an access authentication request.

[0203] In some possible implementations, before step S401, the first node may send an authentication method indication. This indication specifies the method by which the first node authenticates nodes accessing it; this can be understood as the method for authenticating a second node. Further, the authentication method indication may indicate that the first node's authentication method includes certificate authentication. In some scenarios, the above authentication process is performed in an enterprise network; for example, the authentication method indication may specify the authentication method as: Enterprise Edition - Certificate Authentication.

[0204] Optionally, the authentication method indication can be carried in unicast, multicast, or broadcast messages. For example, the first node can send broadcast messages periodically or aperiodically, carrying the authentication method indication. Alternatively, the first node can send the authentication method indication in a message sent to the second node (e.g., a message during a security context negotiation process).

[0205] Taking the StarFlash communication system as an example, the first node can be a management node, and the second node can be a terminal node. The management node sends broadcast messages, such as communication domain system messages, which carry authentication method instructions. The terminal node receives the broadcast message, requests association from the management node, and performs the authentication process with the management node and authentication node using the indicated authentication method.

[0206] Step S402: The first node authenticates the second node based on the second node's certificate and the first signature.

[0207] Specifically, the first node verifies the second node's certificate and the first signature, thereby authenticating the second node. If the second node's certificate verification passes (e.g., the certificate is valid or legitimate), then the second node's certificate is trustworthy. Conversely, if the second node's certificate is untrustworthy, authentication of the second node fails. Similarly, if the first signature verification passes, the second node's identity is trustworthy, and authentication succeeds. Otherwise, authentication of the second node fails.

[0208] In some possible scenarios, the second node's authentication succeeds if both the certificate and the first signature are verified. Conversely, if either the certificate or the signature fails verification, the second node's authentication fails.

[0209] Optionally, if the second node fails authentication, the first node may not execute subsequent processes (such as step S403 and subsequent processes), or disconnect from the second node, or discard the information received from the second node, or delete the security context of the second node, etc. Furthermore, if N authentication attempts fail, the first node may add the second node to a blacklist to avoid attacks from the second node, where N can be predefined, pre-set, or calculated.

[0210] As a certificate verification implementation, the second node's certificate can be issued by a Certificate Authority (CA) and bears the CA's signature (which is based on the CA's private key). The first node can verify the second node's certificate by checking the signature in the first node's certificate using the CA's public key.

[0211] As a certificate verification implementation, the second node's certificate includes a public key, and the first signature is generated based on the second node's private key and the first information. The first node can verify the first signature based on the public key and the first information in the certificate. If the first signature verification is successful, it indicates that the identity of the source of the first information (i.e., the second node) is trustworthy and that the first information has not been tampered with. It should be understood that the public and private keys here are public-private key pairs in the certificate and signature system, which belong to a different mechanism than the public and private keys used in the key negotiation process.

[0212] In some schemes, step S402 is an optional step. Figure 4 (Used as a dashed box). In this case, the first node does not authenticate the second node; instead, the third node authenticates both the first node and the second node.

[0213] Step S403: The first node sends the second information and the second signature to the third node.

[0214] Accordingly, the third node receives the second information and the second signature from the first node.

[0215] The second information includes the first information, the first signature, and the certificate of the first node. The first information includes the certificate of the second node, and optionally also includes one or more of the following: the public key of the second node, the first timestamp, the first freshness parameter, or the third freshness parameter.

[0216] The second signature is a signature of the second information. The certificates of the first node, the second node, the first signature, and the second signature are used for authentication.

[0217] It should be understood that the second information carries the first information and the first signature to facilitate the third node's verification of the first signature and the second node's certificate. In some schemes, the second node may also carry information D0 and signature S0 (parameter representation is for example only) in the first information for the third node to verify the signature. In this case, the second information may not carry the first information and the first signature, but instead carry information D0 and signature S0 for the third node to authenticate the second node. For example, information D0 may include one or more of the second node's certificate, the second node's public key, a second freshness parameter, or a first timestamp, etc., and signature S0 is the signature of information D0.

[0218] In some possible implementations, the second information may also include one or more of the following: a second freshness parameter, indication information of the first KDF, indication information of the first key negotiation algorithm, or the node identifier. These will be described in detail below:

[0219] (1) The second fresh parameter is a fresh parameter, such as a random number, a counter value or other parameters that can have freshness.

[0220] Optionally, the second freshness parameter is used to determine the first key, which is a key shared between the second and third nodes and can be used for security protection or security verification. In one possible implementation, the first key is used to verify information negotiated in the security context negotiation process (described below).

[0221] Optionally, the second freshness parameter is the same as the third freshness parameter. That is, the first node will participate in generating the second freshness parameter of the first key, and it will also be used in the anti-replay mechanism. This avoids the repeated calculation process of determining the freshness parameter and reduces the computational load of the first node.

[0222] (2) The indication information of the first KDF algorithm is used to indicate the first KDF algorithm. The first KDF algorithm is used by the third node to perform key derivation, for example, to derive a key consistent with that of the second node.

[0223] Furthermore, the first KDF is negotiated between the first node and the second node, for example, during the security context negotiation process. Thus, for a second node and a first node with different security capabilities, the first KDF negotiated between them may be different. This allows the authentication process among the first, second, and third nodes to adapt to first and second nodes with different security capabilities, improving network compatibility and enhancing the user experience.

[0224] (3) The instruction information for the first key negotiation algorithm is used to indicate the first key negotiation algorithm. This first key negotiation algorithm is used by the third node to perform key negotiation, for example, to negotiate a negotiation key with the second node.

[0225] Furthermore, the first key negotiation algorithm is negotiated between the first node and the second node, for example, during the security context negotiation process. Thus, for second nodes and first nodes with different security capabilities, the first key negotiation algorithm they negotiate may be different. This allows the authentication process among the first, second, and third nodes to adapt to first and second nodes with different security capabilities, improving network compatibility and enhancing the user experience.

[0226] (4) The node identifier includes the identifier of the first node and / or the identifier of the second node. The node identifier is used to indicate the node, such as the node's identifier in the communication network, the node's device identifier, etc. The node's identifier in the communication network is, for example, the ID of a certain communication protocol layer, the node's media access control (MAC) address, the node's network access license number, etc. The node's device identifier is used to uniquely identify the node's device itself, such as the node's production serial number, device model, etc. Optionally, the node identifier can be fixed or random.

[0227] As one possible implementation, node identifiers are used to distinguish nodes in a network; for example, the identifier of the first node is the ID of the first communication protocol layer of the first node.

[0228] For example, the communication protocol stack between the first node and the second node includes multiple protocol layers, which can be referred to as layer 1, layer 2, layer 3, etc. The identifier of the first node can be the layer 2 ID (L2ID) of the second node.

[0229] For another example, taking the communication protocol between the first node and the second node as the StarSpark communication protocol, the StarSpark protocol stack architecture from top to bottom is as follows: application layer, network and transport layer, data link layer (including link control layer and media access layer), and physical layer. The physical layer is layer one, the data link layer is layer two (i.e., L2), and the data link layer can include two sub-layers, and so on for the remaining layers. The identifier of the first node here can be the data link layer ID of the first node. Alternatively, the identifier of the first node can be the physical layer identifier (phy-ID) of the first node.

[0230] Similar to the identifier of the first node, the identifier of the second node is used to indicate the second node, such as the L2ID of the second node, the phy-ID of the second node, etc. For related designs, please refer to the possible designs of the identifier of the first node.

[0231] The above information may be partially or entirely carried in the second information. The combination of these information will not be explained here, but will be described in detail below with reference to specific implementation methods.

[0232] In some possible implementations, the second information and the second signature may be carried in one or more messages for easy distinction, referred to as message M2. For example, message M2 may include multiple data fields, with the second signature carried in the field corresponding to the second signature, and the second information can be considered as all the data fields of message M2 except for the second signature. In some schemes, message M2 is referred to as a certificate authentication request.

[0233] Optionally, if the first information and the first signature are carried in message M1, message M2 may carry message M1, thereby making message M2 include the first information and the first signature.

[0234] Step S404: The third node authenticates the second node based on the second node's certificate and the first signature.

[0235] Specifically, the third node verifies the second node's certificate and verifies the second node's signature on the information (such as the first signature), thereby authenticating the second node.

[0236] For example, if the certificate verification of the second node passes (e.g., the certificate is valid or legal), then the certificate of the second node is trustworthy. Conversely, the certificate of the second node may be untrustworthy, and the authentication of the second node will fail. As another example, taking the verified signature as the first signature, if the verification of the first signature passes, then the identity of the second node is trustworthy, and authentication passes. Conversely, authentication of the second node will fail. Alternatively, the first signature can be replaced with the second node's signature on other information, such as the signature S0 on information D0.

[0237] In some possible scenarios, the second node's authentication succeeds if both the certificate and the first signature are verified. Conversely, if either the certificate or the signature fails verification, the second node's authentication fails.

[0238] As a certificate verification implementation, the second node's certificate can be issued by a Certificate Authority (CA) and bears the CA's signature (which is based on the CA's private key). The third node can verify the second node's certificate by using the CA's public key to verify the signature in the first node's certificate.

[0239] As a certificate verification implementation, the second node's certificate includes a public key, and the first signature is generated based on the second node's private key and the first information. The third node can verify the first signature based on the public key and the first information in the certificate. If the first signature verification is successful, it indicates that the source of the first information (i.e., the second node) is trustworthy and that the first information has not been tampered with. It should be understood that the public and private keys here are public-private key pairs in the certificate and signature system, which belong to a different mechanism than the public and private keys used in the key negotiation process.

[0240] In some possible implementations, the third node authenticates the second node based on the second node's certificate and the second node's signature, thereby obtaining the authentication result for the second node.

[0241] For example, the authentication result of the third node to the second node includes one or more of the following: the verification result of the first signature, or the verification result of the second node's certificate. For instance, the verification result of the first signature may include whether the verification passed or failed. Similarly, the verification result of the second node's certificate may include whether the certificate verification passed or failed. If the verification fails, the verification result of the second node's certificate may optionally also include a reason for failure, such as indicating that the certificate has expired, the certificate has been revoked, or the certificate is invalid, or one or more of these reasons. In the above implementation, by carrying the authentication result in the third information, the success or failure of identity verification (optionally including the reason for failure) can be fed back, facilitating the first node to trigger corresponding security operations based on the authentication result, forming a closed-loop authentication management system, and improving network security.

[0242] Optionally, if the second node fails authentication, the third node may not execute subsequent procedures (such as step S405 and subsequent procedures), or instruct the first node to disconnect from the second node, or instruct the first node to discard the information received from the second node. Furthermore, if authentication fails M times, the third node may add the second node to a blacklist to avoid attacks from the second node, where M can be predefined, pre-set, or calculated.

[0243] Step S405: The third node authenticates the first node based on the first node's certificate and second signature.

[0244] Specifically, the third node verifies the first node's certificate and the second signature, thereby authenticating the first node. For example, if the first node's certificate verification passes (e.g., the certificate is valid or legal), then the first node's certificate is trustworthy. Conversely, if the first node's certificate is untrustworthy, the first node's authentication fails. As another example, taking the verified signature as the second signature, if the second signature verification passes, then the first node's identity is trustworthy, and authentication succeeds. Otherwise, the first node's authentication fails.

[0245] In some possible scenarios, the first node's authentication succeeds if both the certificate and signature verification of the first node pass. Conversely, if either the certificate or the signature verification fails, the first node's authentication fails.

[0246] As a certificate verification implementation, the first node's certificate can be issued by a Certificate Authority (CA) and bears the CA's signature (which is based on the CA's private key). The third node can verify the first node's certificate by checking the signature in the first node's certificate using the CA's public key.

[0247] As a certificate verification implementation, the first node's certificate includes a public key, and the second signature is generated based on the first node's private key and the second information. The third node can verify the second signature based on the public key in the certificate and the first information. If the second signature verification is successful, it indicates that the source of the second information (i.e., the first node) is trustworthy and that the second information has not been tampered with.

[0248] In some possible implementations, the third node authenticates the first node based on the first node's certificate and signature, thus obtaining the authentication result for the first node.

[0249] For example, the authentication result of the third node on the first node may include one or more of the following: the verification result of the second signature, or the verification result of the first node's certificate. For instance, the verification result of the second signature may include whether the verification passed or failed. Similarly, the verification result of the first node's certificate may include whether the certificate verification passed or failed. If the verification fails, the verification result of the first node's certificate may optionally also include a reason for failure, such as indicating that the certificate has expired, the certificate has been revoked, or the certificate is invalid, or one or more of the following.

[0250] Optionally, if the first node fails authentication, the third node may not execute subsequent processes (such as step S405 and subsequent processes), or disconnect from the first node, or discard the information received from the first node. Furthermore, if authentication fails K times, the third node may add the first node to a blacklist to avoid attacks from the first node, where K can be predefined, pre-set, or calculated.

[0251] In some possible implementations, where the first (or second) information includes the public key of the second node (where the public key refers to the public key used for key negotiation), the third node can determine the negotiation key based on the second node's public key. Specifically, the third node generates its own private key and, using the first key negotiation algorithm, determines the negotiation key based on the third node's private key and the second node's public key. Thus, the third node and the second node can perform security protection and / or information verification based on the negotiation key. Of course, the negotiation key can directly participate in security protection and / or information verification, or the negotiation key can derive (or generate) a key, and the derived key can participate in security protection and / or information verification.

[0252] For example, the public key of the second node can be represented as Pubt, and the private key of the third node can be represented as PriAC. The third node can generate a negotiation key based on PriAC and Pubt using a first key negotiation algorithm, which can be represented as DH key for example.

[0253] In some possible implementations, the third node can derive a first key based on the negotiated key. This first key serves as an example of a derived key. In some scenarios, the first key is a shared key between the second and third nodes, which can be considered an authentication key. The following describes some possible implementations for deriving the first key:

[0254] In the first implementation, the third node generates an intermediate key based on the negotiated key, and then generates a first key based on the intermediate key. Optionally, fresh parameters or other parameters may be involved in the generation of the intermediate and first keys.

[0255] As one possible design, the third node generates an intermediate key based on the negotiated key and the first input parameter, and generates a first key based on the intermediate key and the second input parameter. An exemplary calculation method is as follows: MK = KDF(DH key, P1), RK = KDF(MK, P2). Here, KDF can be the KDF indicated by the indication information of the first KDF, MK represents the intermediate key, P1 represents the first input parameter, P2 identifies the second input parameter, and RK represents the first key.

[0256] Optionally, the first input parameter includes one or more of the following: a first fresh parameter, a second fresh parameter, a third fresh parameter, a first timestamp, or a fresh parameter determined by a third node, or may also include other parameters not listed. The second input parameter includes one or more of the following: the identifier of the first node, the identifier of the second node, a first timestamp, or may also include other parameters not listed. Optionally, if the first and second input parameters include a parameter determined by a third node, the third node may provide the parameter determined by the third node to the second node so that the second node can generate a consistent first key. For example, if the first input parameter (or the second fresh parameter) includes the parameter rand1 determined by the third node, the third node may send rand1 to the second node; of course, the sending of rand1 may be forwarded through the first node.

[0257] As one possible design, the third node determines the intermediate key based on the negotiated key, the first freshness parameter, and the second freshness parameter, and determines the first key based on the intermediate key, the identifier of the first node, and the identifier of the second node.

[0258] For example, the intermediate key MK is calculated as follows: MK = KDF(DH key, Nt, Ng), where Nt represents the first freshness parameter and Ng represents the second freshness parameter. Other representations are described above. The key RK is calculated as follows: RK = KDF(MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node is the identifier of the first node, and the L2ID of the second node is the identifier of the second node.

[0259] It should be noted that the above describes the derivation process of the first key in multiple steps. However, in actual implementation, these multiple steps may not all actually exist. For example, the first key may be obtained directly through a corresponding calculation method, and the above multiple steps are merely an intermediate process in the calculation. For example, the calculation method of the first key is as follows: RK = KDF{KDF[DH(PriAC, Pubt), Nt, Ng], L2ID of the first node, L2ID of the second node}, where DH(PriAC, Pubt) is used to obtain DHkey.

[0260] In the second implementation method, the third node generates a first key based on the negotiated key and the first KDF. For example, the key RK (which can be regarded as the first key) is calculated as follows: RK = KDF(DH key, fresh parameter). The fresh parameter can be one or more of the first fresh parameter, the second fresh parameter, or a fresh parameter determined by the third node. Optionally, if the fresh parameter is a fresh parameter determined by the third node, the third node can provide the fresh parameter to the second node.

[0261] In some possible implementations, the first key is used to verify the information transmitted during the security context negotiation process (the specific verification process is described below). The security context negotiation process is a process between the first node and the second node. Verifying the security context negotiation process between the first node and the second node using the first key can ensure the information security of the first node and the second node, and help improve the communication security of the first node.

[0262] Step S406: The third node sends the third information and the third signature to the first node.

[0263] Accordingly, the first node receives the third information and the third signature from the third node.

[0264] The third information includes the certificate of the third node. The third signature is a signature of the third information.

[0265] In some possible implementations, the third information may also include one or more of the following: second information, second signature, authentication result, second freshness parameter, and the public key of the third node. The second information and second signature are described above. The authentication result includes the authentication result for the second node and / or the authentication result for the third node, as detailed above. The public key of the third node is a parameter corresponding to the private key of the third node, serving as the key negotiation public key provided by the third node during the key negotiation process, used by the first node to determine the negotiation key.

[0266] Optionally, if parameters determined by a third node are input during the process of determining the first key, the parameters determined by the third node can be carried in the third information and sent to the second node.

[0267] In some possible implementations, the third information and the third signature may be carried in one or more messages, referred to as message M3 for easy distinction. For example, message M3 may include multiple data fields, with the third signature carried in the field corresponding to the third signature, and the third information can be considered as all the data fields of message M3 except for the third signature. In some schemes, message M3 is referred to as a certificate authentication response.

[0268] Optionally, if the second information and the second signature are carried in message M2, message M3 may carry message M2, thereby including the second information and the second signature in message M3.

[0269] In some schemes, step S406 is an optional step. Figure 4 (Used as dashed lines). In this case, the third node may not have sent its certificate and signature to the first node. For example, the third information may only carry one or more of the following: the second information, the second signature, the authentication result, the second freshness parameter, and the third node's public key.

[0270] Step S407: The first node authenticates the third node based on the third node's certificate and third signature.

[0271] Specifically, the first node verifies the third node's certificate and verifies the third node's signature on the information (such as a third signature), thereby authenticating the third node.

[0272] For example, if the certificate verification of the third node passes (e.g., the certificate is valid or legal), then the certificate of the third node is trustworthy. Conversely, the certificate of the third node may be untrustworthy, and the authentication of the third node will fail. As another example, if the verification of the third signature passes, then the identity of the third node is trustworthy, and authentication will pass. Conversely, authentication of the third node will fail.

[0273] In some possible schemes, third-node authentication succeeds if both the certificate and signature verification are successful. Conversely, authentication fails if either the certificate or the signature verification fails.

[0274] As a certificate verification implementation, the third-node's certificate can be issued by a Certificate Authority (CA) and bears the CA's signature (which is based on the CA's private key). The first node can verify the third-node's certificate by checking the signature in the third-node's certificate using the CA's public key.

[0275] As a certificate verification implementation, the third-node's certificate includes a public key, and the third signature is generated based on the third-node's private key and third information. The first node can verify the first signature based on the public key and third information in the certificate. If the first signature verification is successful, it indicates that the identity of the source of the third information (i.e., the third node) is trustworthy and that the third information has not been tampered with. It should be understood that the public and private keys here are public-private key pairs in the certificate and signature system, which belong to a different mechanism than the public and private keys used in the key negotiation process.

[0276] In some possible implementations, the first node authenticates the third node based on the third node's certificate and third signature, thereby obtaining an authentication result for the third node. For example, the authentication result for the third node may include one or more of the following: verification result of the third signature, or verification result of the third node's certificate.

[0277] Optionally, if the third node fails authentication, the first node may not execute subsequent processes (such as step S409 and subsequent processes), or disconnect from the third node, or discard the information received from the third node. Furthermore, if authentication fails L times, the first node may add the third node to a blacklist to avoid attacks from the third node, where L can be predefined, pre-set, or calculated.

[0278] In some schemes, step S407 is an optional step. Figure 4 (Used as a dashed box). In this case, the first node does not authenticate the third node.

[0279] Step S408: The first node sends the fourth information and the fourth signature to the second node.

[0280] Accordingly, the second node receives the fourth information and the fourth signature from the first node.

[0281] The fourth information includes the third information, the third signature, and the certificate of the first node. The fourth signature is a signature of the third information.

[0282] Optionally, the fourth information may also include a second freshness parameter, or the second freshness parameter may also be included in the third information, such that the fourth information carries the second freshness parameter.

[0283] In some possible implementations, the fourth information and the fourth signature may be carried in one or more messages, referred to as message M4 for easy distinction. For example, message M4 may include multiple data fields, with the fourth signature carried in the field corresponding to the fourth signature, and the fourth information can be considered as all the data fields of message M4 except for the third signature. In some schemes, message M4 is referred to as an access authentication response.

[0284] Optionally, if the third information and the third signature are carried in message M3, message M4 may carry message M3, thereby including the third information and the third signature in message M4.

[0285] In some schemes, step S406 is an optional step. Figure 4 (Used as dashed lines). In this case, the third node may not have sent its certificate and signature to the first node. For example, the third information may only carry one or more of the following: the second information, the second signature, the authentication result, the second freshness parameter, and the third node's public key.

[0286] In some schemes, step S408 is an optional step. Figure 4 (Used as dashed lines). In this case, the first node may not have sent the third node's certificate and third signature to the second node, or it may not have sent the second node's certificate and fourth signature. For example, the fourth message may only carry one or more of the following: the third message, the third signature, the authentication result, the second freshness parameter, and the third node's public key.

[0287] Step S409: The second node authenticates the third node based on the third node's certificate and third signature.

[0288] Specifically, the second node verifies the certificate of the third node and verifies the third node's signature on the information (such as a third signature), thereby authenticating the third node.

[0289] For example, if the certificate verification of the third node passes (e.g., the certificate is valid or legal), then the certificate of the third node is trustworthy. Conversely, the certificate of the third node may be untrustworthy, and the authentication of the third node will fail. As another example, if the verification of the third signature passes, then the identity of the third node is trustworthy, and authentication will pass. Conversely, authentication of the third node will fail.

[0290] In some possible schemes, third-node authentication succeeds if both the certificate and signature verification are successful. Conversely, authentication fails if either the certificate or the signature verification fails.

[0291] For a detailed description, please refer to the relevant instructions on the authentication of the third node by the first node in step S407.

[0292] In some schemes, step S409 is an optional step. Figure 4 (Used as a dashed box). In this case, the second node does not authenticate the third node.

[0293] Step S410: The second node authenticates the first node based on the first node's certificate and the fourth signature.

[0294] Specifically, the second node verifies the first node's certificate and the second signature, thereby authenticating the first node. For example, if the first node's certificate verification passes (e.g., the certificate is valid or legal), then the first node's certificate is trustworthy. Conversely, if the first node's certificate is untrustworthy, the first node's authentication fails. As another example, taking the verified signature as the second signature, if the second signature verification passes, then the first node's identity is trustworthy, and authentication succeeds. Otherwise, the first node's authentication fails.

[0295] In some possible scenarios, the first node's authentication succeeds if both the certificate and signature verification of the first node pass. Conversely, if either the certificate or the signature verification fails, the first node's authentication fails.

[0296] For a detailed description, please refer to the relevant instructions on the third node authenticating the first node in step S405.

[0297] In some schemes, step S410 is an optional step. Figure 4 (Used as a dashed box). In this case, the second node does not authenticate the first node.

[0298] In some possible implementations, where the fourth (or third) information includes the public key of the third node (where the public key refers to the public key used for key negotiation), the second node can determine the negotiation key based on the third node's public key. Specifically, the second node uses the first key negotiation algorithm to determine the negotiation key based on the second node's private key and the third node's public key. Thus, the third node and the second node can perform security protection and / or information verification based on the negotiation key. Of course, the negotiation key can directly participate in security protection and / or information verification, or the negotiation key can derive (or generate) a key, and the derived key can participate in security protection and / or information verification.

[0299] For example, the public key of the third node can be represented as PubAC, and the private key of the second node can be represented as Prit. The second node can generate a negotiation key based on Prit and PubAC using a first key negotiation algorithm, which can be represented as DH key for example.

[0300] In some possible implementations, the second node may derive a first key based on the negotiated key, which serves as an example of a derived key. Some possible implementations for deriving the first key are described below:

[0301] In the first implementation, the second node generates an intermediate key based on the negotiated key, and then generates a first key based on the intermediate key. Optionally, fresh parameters or other parameters may be involved in the generation of the intermediate and first keys.

[0302] As one possible design, the second node generates an intermediate key based on the negotiated key and the first input parameter, and generates a first key based on the intermediate key and the second input parameter. An exemplary calculation method is as follows: MK = KDF(DH key, P1), RK = KDF(MK, P2). Here, KDF can be the KDF indicated by the indication information of the first KDF, MK represents the intermediate key, P1 represents the first input parameter, P2 identifies the second input parameter, and RK represents the first key.

[0303] Optionally, the first input parameter includes one or more of the following: a first fresh parameter, a second fresh parameter, a third fresh parameter, a first timestamp, or a fresh parameter determined by a third node, or may also include other parameters not listed. The second input parameter includes one or more of the following: the identifier of the first node, the identifier of the second node, a first timestamp, or may also include other parameters not listed. Optionally, if the first and second input parameters include a parameter determined by a third node, the third node may provide the parameter determined by the third node to the second node so that the second node can generate a consistent first key. For example, if the first input parameter (or the second fresh parameter) includes the parameter rand1 determined by the third node, the third node may send rand1 to the second node; of course, the sending of rand1 may be forwarded through the first node.

[0304] As one possible design, the third node determines the intermediate key based on the negotiated key, the first freshness parameter, and the second freshness parameter, and determines the first key based on the intermediate key, the identifier of the first node, and the identifier of the second node.

[0305] For example, the intermediate key MK is calculated as follows: MK = KDF(DH key, Nt, Ng), where Nt represents the first freshness parameter and Ng represents the second freshness parameter. Other representations are described above. The key RK is calculated as follows: RK = KDF(MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node is the identifier of the first node, and the L2ID of the second node is the identifier of the second node.

[0306] It should be noted that the above describes the derivation process of the first key in multiple steps. However, in actual implementation, these multiple steps may not all actually exist. For example, the first key may be obtained directly through a corresponding calculation method, and the above multiple steps are merely an intermediate process in the calculation. For example, the calculation method of the first key is as follows: RK = KDF{KDF[DH(PriAC, Pubt), Nt, Ng], L2ID of the first node, L2ID of the second node}, where DH(PriAC, Pubt) is used to obtain DHkey.

[0307] In the second implementation method, the second node generates a first key based on the negotiated key and the first KDF. For example, the key RK (which can be regarded as the first key) is calculated as follows: RK = KDF(DH key, fresh parameter). The fresh parameter can be one or more of the first fresh parameter, the second fresh parameter, or a fresh parameter determined by the third node. Optionally, if the fresh parameter is a fresh parameter determined by the third node, the third node can provide the fresh parameter to the second node.

[0308] In some possible implementations, the first key is used to verify the information transmitted during the security context negotiation process (the specific verification process is described below). The security context negotiation process is a process between the first node and the second node. Verifying the security context negotiation process between the first node and the second node using the first key can ensure the information security of the first node and the second node, and help improve the communication security of the first node.

[0309] In some possible implementations, after sending the fourth information and the fourth signature to the second node, the second node may send a first message, or message M8, to the first node. Accordingly, the first node receives the first message from the second node. The first message is used to indicate that access authentication is complete, and is referred to as an access authentication complete message, for example.

[0310] In some possible implementations, after sending the fourth information and fourth signature to the second node (e.g., after receiving the first message from the second node), the first node also sends a second message, or message M9, to the third node. Accordingly, the third node receives the second message from the first node. The second message is used to indicate that certificate authentication is complete, and is referred to as, for example, as a certificate authentication complete (message).

[0311] exist Figure 4 In the illustrated embodiment, the first node obtains first information and a first signature, and sends the first information, first signature, second information, and second signature to the third node. The third node can authenticate the identities of the first node and the second node based on the first information, first signature, second information, and second signature. Thus, the third node's authentication of the identities of the first node and the second node based on digital certificates ensures that both the first and second nodes are trustworthy, reducing the possibility of attackers accessing the network and the possibility of nodes being associated with fake access points, ensuring that the identities of both the second and first nodes in the network are trustworthy. Furthermore, the authentication process, based on digital certificates and signature mechanisms, offers high reliability. In summary, this application can significantly improve the security performance of nodes and ensure network security.

[0312] Furthermore, among the first, second, and third nodes, each node uses the certificates and signatures of the other two nodes to authenticate their identities, thus implementing a two-way authentication mechanism in the three-element peer-to-peer architecture, which significantly improves the communication security performance of the nodes.

[0313] The process of the method provided in this application has been described above. Below are some possible designs that can be combined with the above embodiments.

[0314] The security context negotiation process was mentioned in the foregoing embodiments. The following section will combine... Figure 5 This section provides an example of how to introduce security contexts.

[0315] The security context negotiation process is a procedure between the first and second nodes. In some schemes, the security context negotiation process is used to negotiate and obtain the security context of the first and second nodes. The security context includes, but is not limited to, one or more of the following: security keys, security algorithms, or security parameters. Security keys include, for example, one or more of the following: shared keys, master keys, encryption keys, integrity protection keys, authentication encryption keys, identity authentication keys, and identification (ID) encryption keys. Security algorithms include, for example, key negotiation algorithms, key derivation functions (KDFs), authentication encryption algorithms, encryption algorithms, integrity protection algorithms, and message digest algorithms. Security parameters include, for example, freshness parameters, node IDs, information used for encryption, timestamp information, and key validity periods.

[0316] In one possible design, such as Figure 5 As shown, the security context negotiation process includes: the second node sending message T1 (or first message; the parameter notation shown in this document is for illustrative purposes only) to the first node, with message T1 carrying the second node's security capabilities. Correspondingly, the first node receives message T1 from the second node and, based at least on the second node's security capabilities, determines the first KDF. For example, if the second node only supports one KDF, then that KDF is used as the first KDF. When the second node supports one or more KDFs, the first node selects the first KDF with the highest priority based on algorithmic optimization strategies and / or service type, etc.

[0317] Furthermore, the first node can send a second message T2 (or second message) to the second node, which carries indication information of the first KDF. Correspondingly, upon receiving the second message T2, the second node obtains the indication information of the first KDF, thus determining the first KDF. In this way, the first node and the second node negotiate and determine the first KDF through security context negotiation.

[0318] It should be understood that the message names and symbols used here are merely examples, and in actual implementation, the names of messages, information, nodes, and algorithms can be replaced. For instance, message T1 can be called an association request message, used to request association with a first node, including information about the second node, such as its ID and security capabilities. Message T2 can be called a security context request message.

[0319] In some possible implementations, the security context negotiation process may also include one or more of the following messages: message T3 (or third message, security context request message), message T4 (or fourth message, security context request message), message T5 (or association establishment message, association completion message), etc.

[0320] In some possible implementations, prior to the security context negotiation process, the first node may send its key negotiation algorithm capability (optionally included in the security capabilities). The second node may receive the first node's key negotiation algorithm capability and select a first key negotiation algorithm; message T1 may optionally also include indication information for the first key negotiation algorithm. For example, the first node's key negotiation algorithm capability may be carried in a broadcast message, multicast message, or unicast message.

[0321] Optionally, the authentication method indication can be sent in a broadcast message, or in messages such as message T2, message T4, etc.

[0322] In some possible designs, the first key is used to verify information transmitted between the first and second nodes. For example, it can be used to verify one or more pieces of information transmitted in broadcast messages, security context negotiation processes, etc.

[0323] Combination Figure 6 , Figure 6 This is a flowchart illustrating another communication method provided in this application. The security context negotiation process can be found in [reference needed]. Figure 4 The method and authentication process shown can be found in [reference needed]. Figure 4 The method flow is shown. Figure 6 The method shown also includes steps S61 to S67, as follows:

[0324] In step S61, the third node sends message M5 to the first node. Correspondingly, the first node receives message M5 from the third node.

[0325] Message M5 includes a first key; the process for determining the first key can be found in [link to relevant documentation]. Figure 4 The relevant description in the illustrated embodiment. Optionally, message M5 may be referred to as a key delivery (message).

[0326] Step S62: The first node generates the first verification parameter based on the first information to be verified and the first key.

[0327] The first information to be verified includes the second key and information transmitted between the first node and the second node. For example, the first information to be verified includes one or more of the following: the first key, the fourth fresh parameter, the content of message T1, or the content of message T3, etc. It is understood that the first information to be verified used by the first node includes information received by the first node, or information interacted between the first node and the second node. Optionally, the fourth fresh parameter is determined by the first node, and the first node sends this fourth fresh parameter to the second node during the security context negotiation process, for example, by carrying it in message T2.

[0328] Furthermore, the generation of the first verification parameter also requires the use of a KDF (Knowledge, Function, and Dependency), which can be replaced by a hash algorithm. For example, the first verification parameter can be represented as HASHg. An exemplary calculation method for HASHg is as follows:

[0329] HASHg = KDF(RK, NONCEg, message T1 content, message T3 content), where KDF indicates the KDF algorithm used. The inputs of KDF include RK, NONCEg, message T1 content, and message T3 content, with the following meanings: Rk is the first key, and NONCEg is the fourth fresh parameter. It should be understood that the order and number of parameters among the multiple inputs of KDF here are only examples. In actual implementation, the number of information items included in the first information to be verified can be more or less, and the order of its inputs can also be designed in other ways.

[0330] In step S63, the first node sends message M6 to the second node. Correspondingly, the second node receives message M6.

[0331] Message M6 includes the first verification parameter. In some schemes, message M5 may be called a session key confirmation request.

[0332] Step S64: The second node verifies the first verification parameter.

[0333] That is, the second node performs information verification based on the first verification parameter and the first information to be verified. For example, the second node generates a first check code based on the first information to be verified it has obtained (including the second key and the information transmitted between the first node and the second node), and compares the first check code with the first verification parameter to determine whether the value of the first information to be verified on the first node side and the value on the second node side are the same, thereby verifying whether the first information to be verified has been tampered with.

[0334] In step S65, the second node generates the second verification parameters based on the second information to be verified and the first key.

[0335] The second information to be verified includes the first key and information transmitted between the first node and the second node. For example, the second information to be verified includes one or more of the following: the first key, the key negotiation algorithm capability of the first node, authentication method indication, the fifth fresh parameter, the content of message T2, or the content of message T4, etc. It is understood that the second information to be verified used by the second node includes information received by the second node. Optionally, the fifth fresh parameter is determined by the second node, and the second node sends this fifth fresh parameter to the first node during the security context negotiation process, for example, by carrying it in message T1.

[0336] Furthermore, the generation of the second verification parameter also requires the use of a KDF (Knowledge, Function, and Derivative), which can be replaced by a hash algorithm. For example, the second verification parameter can be represented as HASHt. An exemplary calculation method for HASHt is as follows:

[0337] HASHt = KDF(RK, First Node's Key Negotiation Algorithm Capability, Authentication Method Indicator, NONCEt, Message T2 Content, Message T4 Content), where KDF indicates the KDF algorithm used. The inputs to KDF include RK, the first node's key negotiation algorithm capability, the authentication method indicator, NONCEt, Message T2 Content, and Message T4 Content. Specifically, RK is the first key; the first node's key negotiation algorithm capability and authentication method indicator can optionally be carried in the broadcast message; and NONCEt is the fifth fresh parameter. It should be understood that the order and number of parameters among the multiple inputs of KDF here are merely examples. In actual implementation, the number of information items included in the second verification information can be more or less, and the order of its inputs can also be designed differently.

[0338] In step S66, the second node sends message M7 to the first node. Correspondingly, the first node receives message M7.

[0339] Message M7 includes a second verification parameter. In some schemes, message M5 may be referred to as a session key confirmation response.

[0340] Step S67: The first node verifies the second verification parameter.

[0341] In other words, the first node performs information verification based on the second verification parameter and the second information to be verified. For example, the second node generates a second check code based on the second information to be verified it has acquired (including the second key and the information transmitted between the first and second nodes), and compares the second check code with the second verification parameter to determine whether the value of the second information to be verified on the first node side and the value on the second node side are the same, thereby verifying whether the second information to be verified has been tampered with.

[0342] In one possible implementation, the information verification process on the second node side is executed first, followed by the information verification process on the second node side. If the first verification parameter is successfully verified, the second node generates a second verification parameter based on the second information to be verified. Optionally, if the information verification fails, the second node may terminate the association process, cease responding to subsequent processes, or discard the information currently being transmitted with the first node, etc.

[0343] In one possible implementation, the first node can verify whether the second verification parameter is correct. If the verification is successful, the first node opens the controlled port, allowing the second node to access the corresponding resource.

[0344] Figure 6 An exemplary description is provided of a process for verifying information transmitted between a first node and a second node based on a first key. By verifying the first key, forward security of information transmitted between the first node and the second node can be guaranteed, thereby improving the communication security performance of the nodes.

[0345] In some solutions, such as Figure 6 The security context negotiation process shown is executed before the authentication process. Specifically, before receiving the first information and first signature from the second node, the first and second nodes engage in a security context negotiation process. At this point, the second node's identity has not yet been authenticated. Therefore, a first key can be negotiated and determined during the second node's authentication process. This first key is determined based on identity authentication. Verifying the information transmitted during the security context negotiation process using this first key ensures the security of the node's forward information and helps improve the node's communication security performance.

[0346] In some possible designs, the first node communicates with the second node using a first communication protocol, and the first node communicates with the third node using a second communication protocol. In some cases, the first and second communication protocols are different. In other cases, the first and second communication protocols are the same.

[0347] Furthermore, when the first and second communication protocols differ, the transmission units defined by the second communication protocol are needed to carry the information (such as messages) that the first communication protocol needs to transmit for the messages transmitted between the first and third nodes. For example, if the first communication protocol is the StarSpark communication protocol and the second communication protocol is the Ethernet communication protocol, the aforementioned second information, third signature, third information, third signature, and message M5 are information that the StarSpark communication protocol needs to transmit, and these parameters are carried in the StarSpark data messages. Since the first and third nodes communicate using the Ethernet communication protocol, Ethernet messages are needed to carry the StarSpark data messages.

[0348] In one possible implementation, the information transmitted between the first node and the third node is encapsulated in a data packet. The format of the data packet is specified by the first communication protocol. The data packet is carried in the payload of the protocol data unit (PDU) transmitted between the first node and the third node. The format of the PDU is specified by the second communication protocol.

[0349] like Figure 7 The second communication protocol defines a PDU, which includes a header, a payload, and a trailer (optionally included). The first communication protocol's message (data message) includes a data portion, and optionally also includes a header and a trailer. At least a portion of the first communication protocol's message (i.e., data message) (e.g., the data portion, or the data portion and the header, or the data portion, the header, and the trailer) may be carried in the payload portion of the PDU.

[0350] Combination Figure 7 The payload portion of the PDU in the second communication protocol also includes a message type field, which indicates the message type of the data packets carried by the payload portion of the PDU. For example, referring to Table 1, the message type field indicates one of the following message types: certificate authentication request, authentication response, authentication completion, or key issuance.

[0351] Table 1 Second Message Type

[0352] Value Indicated message type 0x01 Certificate authentication request 0x02 Certificate Authentication Response 0x03 Certificate authentication completed 0x04 Key distribution other Reserved

[0353] Combination Figure 7 The payload portion of the PDU also includes a message length field, the value of which indicates the data length of the data message of the first communication protocol carried by the PDU. Optionally, the data length of the message type field and / or the data length field can be designed according to requirements.

[0354] above Figure 4 The embodiments and subsequent possible designs illustrate a variety of possible implementations, which are described below in conjunction with... Figure 8 and Figure 9 Two possible implementations are described below. It should be understood that... Figure 8 and Figure 9 For some of the concepts and logic in the text, please refer to Figure 4 The illustrated embodiments and their possible designs are described.

[0355] Please see Figure 8 , Figure 8 This is a flowchart illustrating another communication method provided in an embodiment of this application. Optionally, this method can be applied to a communication system, such as... Figure 1 , Figure 2 or Figure 3 The communication system shown. (As shown) Figure 8 The communication method shown may include one or more steps S801 to S821. It should be understood that, for ease of description, the method is described in the order of steps S801 to S821, and is not intended to limit the execution to this specific order. This application embodiment does not limit the order of execution, the execution time, or the number of executions of the above one or more steps. Steps S801 to S821 are as follows:

[0356] Step 801: The first node sends a broadcast message.

[0357] Accordingly, the second node can receive the broadcast message, such as a communication domain system message. Optionally, the broadcast message carries the first node's key negotiation algorithm capabilities and authentication method indication. This authentication method indication is used to indicate certificate authentication, such as indicating Enterprise Edition certificate authentication.

[0358] Optionally, the second node may request to associate with the first node.

[0359] Step 802: The first node and the second node conduct a security context negotiation process.

[0360] In the security context negotiation process, the first and second nodes negotiate cryptographic algorithms (including KDF and key negotiation algorithms). Simultaneously, session keys for the signaling plane and user plane are generated, and signaling plane encryption and integrity protection are initiated.

[0361] In one possible implementation, the calculation and verification of authentication parameters are omitted during the security context negotiation process between the first and second nodes. Optionally, the first and second nodes negotiate and generate a session key during the security context negotiation process. Further, the session key includes a signaling plane session key and a user plane session key.

[0362] After the first and second nodes complete the security context negotiation, the certificate authentication process is executed:

[0363] Step 803: The second node sends message M1 to the first node. Correspondingly, the first node receives message M1 from the second node.

[0364] Message M1 carries a first timestamp, a random number Nt, the public key Pubt of the second node, the certificate of the second node, and a first signature. The first signature is a signature of specified data fields in message M1, excluding the field corresponding to the first signature itself. These specified data fields can be predefined or pre-set. For example, the specified fields can be all data fields except those corresponding to the first signature; that is, the first signature is a signature of message M1 excluding the first signature (i.e., the first timestamp, the random number Nt, the public key Pubt of the second node, and the certificate of the second node). Figure 4 In the embodiments, for ease of description, the information covered by the first signature is referred to as the first information.

[0365] As one possible implementation, the second node generates a temporary private key Prit and a corresponding public key Pubt according to the key negotiation algorithm. The second node generates a random number Nt. The first node also determines a first timestamp, which may indicate, for example, the time when message M1 was generated or sent. The above information is carried in message M1.

[0366] In some schemes, when the second node connects to the first node based on the StarScan communication protocol, the second node can be called the T node, the certificate of the second node can be called the T certificate, and the first signature can be called the T signature.

[0367] In some schemes, message M1 is referred to as an access authentication request.

[0368] Step 804: The first node verifies the certificate of the second node and verifies the first signature.

[0369] Step 805: The first node sends message M2 to the third node. Accordingly, the third node receives message M2 from the first node.

[0370] Message M2 carries message M1, random number Ng, certificate of the first node, second signature, and indication information of KDF and key negotiation algorithm determined in the security context negotiation process, as well as the identifier of the first node (such as L2ID) and the identifier of the second node (such as L2ID).

[0371] The second signature is a signature of specified data fields in message M2, excluding the field corresponding to the second signature itself. These specified data fields can be predefined or pre-set. For example, the specified fields can be all data fields except those corresponding to the second signature; that is, the second signature signs all data fields in message M2 except for the fields corresponding to the second signature. Figure 4 In the embodiments, for ease of description, the information covered by the second signature is referred to as the second information.

[0372] In some schemes, when the second node and the first node are connected based on the StarScan communication protocol, the first node can be called the G node, the certificate of the first node can be called the G certificate, and the second signature can be called the G signature.

[0373] In some schemes, message M2 may be referred to as an authentication request.

[0374] Step 806: The third node verifies the certificate of the first node and verifies the second signature.

[0375] Step 807: The third node verifies the certificate of the second node and verifies the first signature.

[0376] Step 808: The third node generates a negotiation key using a key negotiation algorithm based on Pubt and PriAC.

[0377] Specifically, the third node can generate a temporary private key PriAC (i.e., the third node's private key) and generate a corresponding public key PubAC (i.e., the third node's public key) according to the key negotiation algorithm. The third node then uses the key negotiation algorithm based on PriAC and PubAC to generate a DH key.

[0378] It should be understood that the suffix "AC" is used here to exemplarily represent parameters related to the third node, similarly using "t" as a suffix to exemplarily represent parameters related to the second node, and "g" as a suffix to exemplarily represent parameters related to the first node. However, the above representations are not intended to limit the solution. In fact, the representations of parameters, information, and messages in this application are only for ease of description. In some solutions, parameters, information, or messages may be represented by other names or mathematical representations. The representations in this application are merely examples.

[0379] Step 809: The third node generates MK and derives RK.

[0380] For related descriptions, please refer to Figure 4 The example shown includes a description of how the first key was generated.

[0381] The third node generates an intermediate key MK based on the negotiated key and the first input parameter, and generates a first key based on the intermediate key MK and the second input parameter.

[0382] For example, the intermediate key MK is calculated as follows: MK = KDF(DH key, Nt, Ng), where Nt represents the first freshness parameter (a random number determined by the second node), and Ng represents the second freshness parameter (a random number determined by the first node). In some schemes, a first timestamp can optionally be added to MK.

[0383] The key RK is calculated as follows: RK = KDF(MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node is the identifier of the first node, and the L2ID of the first node is the identifier of the second node. The meanings of other mathematical identifiers are as described above.

[0384] Step 810: The third node sends message M3 to the first node. Accordingly, the first node receives message M3.

[0385] Message M3 carries message M2, the authentication result, the third node's public key PubAC, the third node's certificate, and a third signature. The third signature is a signature of specified data fields in message M3, excluding the field corresponding to the third signature itself. These specified data fields can be predefined or pre-set. For example, the specified fields can be all data fields except those corresponding to the third signature; that is, the third signature signs message M3 excluding the fields corresponding to the third signature. Figure 4 For ease of description, the information covered by the third signature in the embodiments is referred to as the third information.

[0386] Optionally, the authentication result may include one or more of the following: the result of verifying the first signature, the result of verifying the second node's certificate, the result of verifying the second signature, and the result of verifying the first node's certificate. See the foregoing for related information.

[0387] In some schemes, the third node includes an AC (Accounting Center), the certificate of the third node can be called an AC certificate, and the third signature can be called an AC signature.

[0388] In some schemes, message M3 can be referred to as a certificate authentication response.

[0389] Step 811: The first node verifies the certificate of the third node and verifies the third signature.

[0390] Step 812: The first node sends message M4 to the second node. Accordingly, the second node receives message M4 from the first node.

[0391] Message M4 carries message M3, the certificate of the first node, and a fourth signature. For example, the fourth signature is a signature of specified data fields in message M4, excluding the field corresponding to the fourth signature itself. These specified data fields can be predefined or pre-set. For instance, the specified fields can be all data fields except those corresponding to the fourth signature; that is, the fourth signature signs message M4 except for the fields corresponding to the fourth signature. Figure 4 For ease of description, the information covered by the fourth signature in the embodiments is referred to as the fourth information.

[0392] In some schemes, message M4 can be referred to as the access authentication response.

[0393] In some schemes, the first node is called the G node, the certificate of the first node can be called the G certificate, and the fourth signature can be called the G signature.

[0394] Step 813: The second node verifies the second node's certificate and verifies the fourth signature.

[0395] Step 814: The second node verifies the certificate of the third node and verifies the third signature.

[0396] Step 815: The second node generates a negotiation key using a key negotiation algorithm based on PubAC and Prit.

[0397] Specifically, the second node generates a DH key using a key negotiation algorithm based on PriAC and Pubt. Optionally, this key negotiation algorithm is the one determined with the first node during the security context negotiation process, and for ease of distinction, it can be referred to as the first key negotiation algorithm.

[0398] It should be understood that, provided the public key used for key negotiation during the interaction has not been tampered with, the negotiation key DH key determined by the second node is consistent with the negotiation key DH key determined by the third node.

[0399] Step 816: The second node generates MK and derives RK.

[0400] For related descriptions, please refer to Figure 4 The example shown includes a description of how the first key was generated.

[0401] The second node generates an intermediate key MK based on the negotiated key and the first input parameter, and generates a first key based on the intermediate key MK and the second input parameter. For example, the intermediate key MK is calculated as follows: MK = KDF(DH key, Nt, Ng), where Nt represents the first freshness parameter (a random number determined by the second node), and Ng represents the second freshness parameter (a random number determined by the first node). In some schemes, a first timestamp can optionally be added to MK for generation.

[0402] The key RK is calculated as follows: RK = KDF(MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node is the identifier of the first node, and the L2ID of the first node is the identifier of the second node. The meanings of other mathematical identifiers are as described above.

[0403] Step 817: The second node sends message M8 to the first node. Correspondingly, the first node receives message M8 from the second node.

[0404] In some schemes, message M8 can be called the access authentication completion message, used to indicate that access authentication is complete.

[0405] Step 818: The first node sends message M9 to the third node. Accordingly, the third node receives message M9 from the first node.

[0406] In some schemes, message M9 can be called certificate authentication complete message, used to indicate that certificate authentication is complete.

[0407] In some schemes, steps S816 and S817 are optional steps.

[0408] Step 819: The third node sends message M5 to the first node. Accordingly, the first node receives message M5 from the third node.

[0409] Message M5 carries a first key RK, sometimes referred to as the authentication key. In some schemes, the first key is used to verify information transmitted between the first node and the second node.

[0410] For example, message M5 may be referred to as a key delivery message or an authentication key delivery message.

[0411] In some schemes, the first node and the second node perform a session key verification process. Optionally, the session key verification process is used to verify the security of the session key determined in the security context negotiation process. The session key verification process is as follows:

[0412] Step 820: The first node sends message M6 to the second node. Accordingly, the second node receives message M6 from the first node.

[0413] Optionally, message M6 includes a first verification parameter, which can be generated based on a first key and information transmitted between the first node and the second node. See relevant examples. Figure 6 The example shown.

[0414] Step 821: The second node sends message M7 to the first node. Accordingly, the first node receives message M7 from the second node.

[0415] Optionally, message M7 includes a second verification parameter, which can be generated based on the second key and information transmitted between the first and second nodes. See relevant examples. Figure 6 The example shown.

[0416] Optionally, the first node verifies the second verification parameter. If the HASHg verification passes, the first node opens a controlled port, allowing the second node to access permitted resources. Optionally, the controlled port may be, for example, a first communication port, through which the second node can access resources.

[0417] exist Figure 8In the illustrated embodiment, each of the first, second, and third nodes uses the certificates and signatures of the other two nodes to authenticate their identities, implementing a two-way authentication mechanism in a three-way peer-to-peer architecture. This significantly improves the communication security performance of the nodes and enhances the security and stability of the network. Furthermore, a timestamp-based anti-replay mechanism is used to further improve network stability.

[0418] Please see Figure 9 , Figure 9 This is a flowchart illustrating another communication method provided in an embodiment of this application. Optionally, this method can be applied to a communication system, such as... Figure 1 , Figure 2 or Figure 3 The communication system shown. (As shown) Figure 9 The communication method shown may include steps S801 to S821, and multiple steps in step S901. It should be understood that... Figure 9 The order of description shown is merely an example and is not intended to limit the use of any particular method. Figure 9 The steps are executed in the order shown. This application embodiment does not limit the order of execution, execution time, or number of executions of one or more of the above steps. Figure 9 The communication methods shown include:

[0419] Step 801: The first node sends a broadcast message.

[0420] Accordingly, the second node can receive the broadcast message. Optionally, the second node can request to associate with the first node.

[0421] Step 802: The first node and the second node conduct a security context negotiation process.

[0422] After the first and second nodes complete the security context negotiation, the certificate authentication process is executed:

[0423] Step 901: The first node sends message M10 to the second node. Correspondingly, the second node receives message M10 from the first node.

[0424] Message M10 includes a random number Ng, which is generated by the first node. This random number Ng can subsequently be used in determining the first key; see the preceding section for details. Figure 4 , Figure 8 The following are descriptions of examples.

[0425] Specifically, the first node generates a random number Ng and sends a message M10 to the second node, with message M10 carrying the random number Ng.

[0426] Step 804: The second node sends message M1 to the first node. Correspondingly, the first node receives message M1 from the second node.

[0427] Message M1 carries a random number Ng, a random number Nt, the public key Pubt of the second node, the certificate of the second node, and a first signature. The first signature is a signature of the specified data fields in message M1, excluding the field itself (i.e., the field corresponding to the first signature). For related information, please refer to the aforementioned description of step S804.

[0428] Steps S805 and S821 are described above. (Relative to...) Figure 8 The embodiment shown, Figure 9 In the illustrated embodiment, the replay mechanism is implemented using the random number Ng determined by the first node. Since message M1 carries the random number Ng, and message M2 carries message M1, message M2 no longer needs to carry the random number Ng field separately; instead, it can include the random number Ng by carrying message M2.

[0429] exist Figure 9 In the illustrated embodiment, each of the three nodes (first, second, and third) uses the certificates and signatures of the other two nodes to authenticate their identities, implementing a two-way authentication mechanism in a three-way peer-to-peer architecture. This significantly improves the communication security performance of the nodes and enhances the security and stability of the network. Furthermore, a replay protection mechanism is implemented using a random number provided by the first node, further improving network stability.

[0430] The methods of the embodiments of this application have been described in detail above. The apparatus of the embodiments of this application is provided below.

[0431] It should be understood that the division of units in the apparatus provided in this application embodiment is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units in the apparatus can be implemented by a processor calling software. For example, the apparatus includes a processor connected to a memory, which stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit of the apparatus. The processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is either internal or external to the apparatus.

[0432] Alternatively, the units in the device can be implemented as hardware circuits. The functionality of some or all of the units can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the above units is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the above units.

[0433] In the embodiments of this application, each unit in the device may be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, graphics processing unit (GPU), neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), microprocessor unit (MPU), digital signal processor (DSP), ASIC, FPGA, or a combination of at least two of these processor forms.

[0434] Furthermore, the units in the above devices can be integrated in whole or in part, or they can be implemented independently. In one implementation, these units are integrated together as a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or for implementing the functions of the units in the device. The at least one processor can be of different types, such as including a CPU and an FPGA, or including a CPU and an artificial intelligence processor, or including a CPU and a GPU, etc. Several possible devices are listed below.

[0435] Please see Figure 10 , Figure 10This is a schematic diagram of a communication device provided in an embodiment of this application. Optionally, the communication device 100 can be an independent device, such as a node. Alternatively, the communication device 100 can also be a component within an independent device (such as a node), such as a chip or integrated circuit. The communication device 100 is used to implement the aforementioned communication method, for example... Figure 4 , Figure 6 , Figure 8 , Figure 9 The communication method and its possible implementations are shown in the embodiments.

[0436] Exemplarily, the communication device 100 includes a transmitting unit 1001 and a receiving unit 1002. Optionally, it also includes a processing unit 1003. The transmitting unit 1001 is used to transmit information, the receiving unit 1002 is used to receive information, and the processing unit 1001 is used to process the received information or to process the received information. Exemplarily, the processing unit 1001 is used to perform one or more operations such as authentication, negotiation, processing, determination, generation, calculation, encryption, and decryption. It should be understood that the unit division here is only illustrative; in specific implementations, some units may be combined, or a single unit may be divided into multiple units. For example, the transmitting unit 1001 and the receiving unit 1002 may be combined to form a communication unit. Furthermore, the processing unit 1001 may include an acquisition unit and a calculation unit; the acquisition unit is used to acquire data, and the calculation unit is used to perform a calculation process.

[0437] In one possible design, the communication device 100 is used to implement the method on the first node side of the aforementioned communication method.

[0438] In one possible implementation, the receiving unit 1002 is used to receive first information and a first signature from the second node, and the sending unit 1001 is used to send second information and a second signature to the third node. The first information includes the certificate of the second node, the first signature is a signature of the first information, the second information includes the first information, the first signature, and the certificate of the first node, and the second signature is a signature of the second information. The certificate of the first node, the certificate of the second node, the first signature, and the second signature are used for authentication.

[0439] In another possible implementation, the receiving unit 1002 is further configured to receive third information and a third signature from a third node, wherein the third information includes the certificate of the third node and the third signature is a signature of the third information.

[0440] In another possible implementation, the processing unit 1003 is used to authenticate the second node based on the second node's certificate and the first signature.

[0441] In another possible implementation, the processing unit 1003 is also used to authenticate the third node based on the third node's certificate and third signature.

[0442] In another possible implementation, the sending unit 1001 is further configured to send fourth information and a fourth signature to the second node. The fourth information includes third information, a third signature, a certificate of the third node, and a certificate of the first node. The fourth signature is a signature of the fourth information. The certificates of the first node and the third node, the third signature, and the fourth signature are used for authentication.

[0443] In another possible implementation, the sending unit 1001 is further configured to send an authentication method indication, which indicates that the authentication method is a certificate authentication method.

[0444] In some scenarios, the above authentication process is carried out in the enterprise network. For example, the authentication method indicator is used to indicate that the authentication method is: Enterprise Edition - Certificate Authentication Method.

[0445] In yet another possible implementation, the sending unit 1001, the receiving unit 1002, and the processing unit 1003 are further configured to: perform a security context negotiation process.

[0446] In another possible implementation, the sending unit 1001 is further configured to send a third fresh parameter to the second node, and the first information also includes the third fresh parameter.

[0447] In another possible implementation, the sending unit 1001 is used to send a certificate authentication request to the third node, the certificate authentication request including second information and a second signature. That is, the second information and the second signature can be carried in the certificate authentication request and transmitted.

[0448] In another possible implementation, the receiving unit 1002 is used to receive a certificate authentication response from a third node, the certificate authentication response including third information and a third signature. That is, the third information and the third signature can be carried in the certificate authentication response and transmitted.

[0449] In another possible implementation, the sending unit 1001 is used to send an access authentication response to the second node, the access authentication response including fourth information and a fourth signature. That is, the fourth information and the fourth signature can be carried in the access authentication response and transmitted.

[0450] In another possible implementation, the receiving unit 1002 is used to receive a first message from the second node, such as message M8. The first message is used to indicate that access authentication is complete, for example, it is called an access authentication completion message.

[0451] In another possible implementation, the sending unit 1001 is used to send a second message, such as message M9, to the third node. The second message is used to indicate that certificate authentication is complete, for example, it is called a certificate authentication complete message.

[0452] For a detailed description, please refer to the description in the foregoing method embodiments.

[0453] In another possible design, the communication device 100 is used to implement the method on the second node side of the aforementioned communication method.

[0454] In one possible implementation, the sending unit 1001 is used to send first information and a first signature to a first node, and the receiving unit 1002 is used to receive fourth information and a fourth signature from the first node, authenticate the first node based on the first node's certificate and the fourth signature, and authenticate the third node based on the third node's certificate and the third signature. The first information includes the certificate of the second node, and the first signature is a signature of the first information; the second node's certificate and the first signature are used for authentication. The fourth information includes third information, a third signature, and the first node's certificate; the fourth signature is a signature of the fourth information, and the third signature is a signature of the third information; the third information includes the certificate of the third node; the third node is communicatively connected to the first node, and the third node is used for authentication.

[0455] In another possible implementation, the receiving unit 1002 is further configured to receive an authentication method indication from the first node, the authentication method indication being used to indicate that the authentication method is a certificate authentication method.

[0456] In some scenarios, the above authentication process is carried out in the enterprise network. For example, the authentication method indicator is used to indicate that the authentication method is: Enterprise Edition - Certificate Authentication Method.

[0457] In another possible implementation, the third information also includes the public key of the third node. The processing unit 1003 is used to determine the first key based on the public key of the third node and the private key of the second node using a first key negotiation algorithm.

[0458] In yet another possible implementation, the sending unit 1001, the receiving unit 1002, and the processing unit 1003 are further configured to: perform a security context negotiation process.

[0459] In another possible implementation, the first information includes a first freshness parameter. The processing unit 1003 is further configured to: determine a negotiation key based on the public key of the third node and the private key of the second node using a first key negotiation algorithm, and determine a first key based at least on the negotiation key and the first freshness parameter.

[0460] In another possible implementation, the fourth information includes a second freshness parameter, which is generated by the first node. The processing unit 1003 is further configured to: determine a negotiation key based on the public key of the third node and the private key of the second node using a first key negotiation algorithm, and determine a first key based at least on the negotiation key and the second freshness parameter.

[0461] In another possible implementation, the first information includes a first freshness parameter, and the third information further includes a second freshness parameter. The processing unit 1003 is further configured to: determine a negotiation key based on the public key of the third node and the private key of the second node using a first key negotiation algorithm, and determine the first key based at least on the negotiation key, the first freshness parameter, and the second freshness parameter.

[0462] In another possible implementation, the processing unit 1003 is further configured to: determine an intermediate key based on a first key derivation function (KDF), a negotiation key, a first fresh parameter, and a second fresh parameter, and determine a first key based at least on the first KDF and the intermediate key.

[0463] In another possible implementation, the processing unit 1003 is further configured to: determine an intermediate key based on the first key derivation function KDF, the negotiation key, the first fresh parameter and the second fresh parameter, and determine the first key based on the first KDF, the intermediate key, the identifier of the first node and the identifier of the second node.

[0464] In yet another possible implementation, the processing unit 1003 is further configured to: determine a first timestamp, wherein the first information further includes the first timestamp.

[0465] In another possible implementation, the receiving unit 1002 is further configured to receive a third fresh parameter from the first node, wherein the first information also includes the third fresh parameter. Optionally, the third fresh parameter is the same as the second fresh parameter.

[0466] In another possible implementation, the sending unit 1001 is used to send an access authentication request to the first node, the access authentication request including first information and a first signature. That is, the first information and the first signature can be carried in the access authentication request and transmitted.

[0467] In another possible implementation, the receiving unit 1002 is configured to receive an access authentication response from the first node, the access authentication response including fourth information and a fourth signature. That is, the fourth information and the fourth signature can be carried in the access authentication response and transmitted.

[0468] In another possible implementation, the sending unit 1001 is also used to send a first message, such as message M8, which is used to indicate that access authentication is complete.

[0469] For a detailed description, please refer to the description in the foregoing method embodiments.

[0470] In another possible design, the communication device 100 is used to implement the method on the third node side of the aforementioned communication method.

[0471] In one possible implementation, the receiving unit 1002 is used to receive second information and a second signature from the first node. The processing unit 1003 is used to: authenticate the first node based on the first node's certificate and the second signature, and authenticate the second node based on the second node's certificate and the first signature. The sending unit 1001 is used to send third information and a third signature to the first node. The second information includes the first information, the first signature, and the first node's certificate; the first information includes the second node's certificate; the first signature is a signature of the first information; and the second signature is a signature of the second information. The third information includes the third node's certificate; the third signature is a signature of the third information; and the third node's certificate and third signature are used for authentication.

[0472] In another possible implementation, the first information also includes the public key of the second node. The processing unit 1003 is further configured to: determine a first key based on the public key of the second node and the private key of the third node using a first key negotiation algorithm.

[0473] In another possible implementation, the first information includes a first freshness parameter. The processing unit 1003 is further configured to use a first key negotiation algorithm to determine a negotiation key based on the public key of the second node and the private key of the third node, and to determine a first key based at least on the negotiation key and the first freshness parameter.

[0474] In another possible implementation, the third information further includes a second freshness parameter. The processing unit 1003 is also configured to determine a negotiation key based on the public key of the second node and the private key of the third node using a first key negotiation algorithm, and to determine a first key based at least on the negotiation key and the second freshness parameter.

[0475] In another possible implementation, the first information includes a first freshness parameter, and the third information further includes a second freshness parameter. The processing unit 1003 is also configured to use a first key negotiation algorithm to determine a negotiation key based on the public key of the second node and the private key of the third node, and to determine the first key based at least on the negotiation key, the first freshness parameter, and the second freshness parameter.

[0476] In another possible implementation, the processing unit 1003 is further configured to determine an intermediate key based on the first KDF, the negotiation key, the first freshness parameter, and the second freshness parameter, and to determine the first key based at least on the first KDF and the intermediate key.

[0477] In another possible implementation, the processing unit 1003 is further configured to determine an intermediate key based on the first KDF, the negotiation key, the first freshness parameter, and the second freshness parameter, and to determine the first key based on the first KDF, the intermediate key, the identifier of the first node, and the identifier of the second node.

[0478] In another possible implementation, the receiving unit 1002 is further configured to receive a certificate authentication request from the first node, the certificate authentication request including second information and a second signature.

[0479] In another possible implementation, the sending unit 1001 is further configured to send a certificate authentication response to the first node, the certificate authentication response including third information and a third signature.

[0480] In another possible implementation, the receiving unit 1002 is further configured to receive a second message, such as message M9. The second message is used to indicate that certificate authentication is complete.

[0481] For a detailed description, please refer to the description in the foregoing method embodiments.

[0482] Please see Figure 11 , Figure 11 This is a schematic diagram of a communication device provided in an embodiment of this application. The communication device 110 can be a standalone device, such as a node or server, or a component included within a standalone device, such as a chip, software module, or integrated circuit. In some embodiments, the communication device 110 can also be referred to as a communication apparatus. The communication device 110 may include at least one processor 1101 and a memory 1103. Optionally, it may also include a communication interface 1102. Further optionally, it may also include a connection line 1104, wherein the processor 1101, the communication interface 1102, and / or the memory 1103 are connected via the connection line 1104, and / or communicate with each other via the connection line 1104 to transmit control signals and / or data signals.

[0483] in:

[0484] Processor 1101 is a module that performs arithmetic and / or logical operations, and may specifically include one or more of the following modules: filter, modem, power amplifier, low noise amplifier (LNA), baseband processor, radio frequency processor, radio frequency circuit, central processing unit (CPU), application processor (AP), microcontroller unit (MCU), electronic control unit (ECU), graphics processing unit (GPU), microprocessor unit (MPU), application specific integrated circuit (ASIC), image signal processor (ISP), digital signal processor (DSP), field programmable gate array (FPGA), complex programmable logic device (CPLD), or coprocessor, etc.

[0485] The communication interface 1102 can be used to provide information input or output to at least one processor, or to receive and / or transmit signals to externally transmitted signals. For example, the communication interface 1102 may include interface circuitry. For instance, the communication interface 1102 may include a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, general wireless transmission, vehicular short-range communication technology, and other short-range wireless communication technologies, etc.). Optionally, the communication interface 1102 may also include a radio frequency transmitter, an antenna, etc. If the communication interface 1102 includes an antenna, the number of antennas can be one or more.

[0486] As one possible design, if the communication device 110 is a standalone device, the communication interface 1102 may include a receiver and a transmitter. The receiver and transmitter may be the same component or different components. When the receiver and transmitter are the same component, this component may be referred to as a transceiver.

[0487] As another possible design, if the communication device 110 is a chip or circuit, the communication interface 1102 may include an input interface and an output interface. The input interface and the output interface may be the same interface or they may be different interfaces.

[0488] Alternatively, the functions of the communication interface 1102 can be implemented by a transceiver circuit or a dedicated transceiver chip.

[0489] The memory 1103 provides storage space, in which data such as the operating system and computer programs can be stored. The memory 1103 can be one or a combination of several of the following: random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).

[0490] The functions and actions of each module or unit in the communication device 110 listed above are merely illustrative examples.

[0491] The functional units in communication device 110 can be used to implement the aforementioned communication method, for example... Figure 4 , Figure 6 , Figure 8 or Figure 9 The communication method and its possible implementations are illustrated in the embodiments. For example, the communication device 110 is used to execute the method executed by the first node, the second node, or the authentication server.

[0492] Optionally, the processor 1101 may be a processor specifically designed to perform the aforementioned methods (for ease of distinction, referred to as a dedicated processor), or a processor that performs the aforementioned methods by calling a computer program (for ease of distinction, referred to as a dedicated processor). Optionally, at least one processor may include both dedicated processors and general-purpose processors.

[0493] Optionally, if the communication device 110 includes at least one memory 1103, and the processor 1101 implements the aforementioned communication method by calling a computer program, the computer program can be stored in the memory 1103.

[0494] This application also provides a chip, which includes logic circuitry and a communication interface. The communication interface is used to receive or transmit signals; the logic circuitry is used to receive or transmit signals through the communication interface. The chip is used to implement the aforementioned communication method, for example... Figure 4 , Figure 6 , Figure 8 , Figure 9 The communication method and its possible implementations are shown in the embodiments.

[0495] This application also provides a computer-readable storage medium storing instructions that, when executed on at least one processor (or communication device), implement the aforementioned communication method, for example... Figure 4 , Figure 6 , Figure 8 , Figure 9 The communication method and its possible implementations are shown in the embodiments.

[0496] This application also provides a computer program product, which includes computer instructions for implementing the aforementioned communication method, for example... Figure 4 , Figure 6 , Figure 8 , Figure 9 The communication method and its possible implementations are shown in the embodiments.

[0497] This application also provides a terminal, which includes the aforementioned communication device 160 and / or communication equipment 170.

[0498] It should be noted that, in the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.

[0499] In this embodiment, the names of information and devices are exemplarily chosen for ease of understanding of the content of this solution. In specific implementations, their names may be designed differently. Furthermore, the names of the same thing may also be designed differently in different scenarios (e.g., different communication layers).

[0500] In the embodiments of this application, "at least one" refers to one or more items, and "more than one" refers to two or more items. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items.

[0501] For example, at least one of a, b, or c can be represented as: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or multiple. "AND / OR" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects have an "OR" relationship.

[0502] Furthermore, unless otherwise stated, the ordinal numbers such as "first," "second," "T1," and "T2" used in the embodiments of this application are for distinguishing multiple objects and are not used to limit the order, timing, priority, or importance of multiple objects. Similarly, terms like "first node" and "second node" are merely for convenience in describing nodes in different implementations and do not indicate differences in their execution operations, importance, structure, etc.

[0503] In the above embodiments, the term "when..." can be interpreted, depending on the context, as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". The above are merely optional embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.

[0504] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

Claims

1. An access authentication method characterized by, The method is applied to a first node, and the access authentication method comprises: receiving first information and a first signature from a second node, the first information comprising a certificate of the second node, and the first signature being a signature of the first information; sending second information and a second signature to a third node, the second information comprising the first information, the first signature and a certificate of the first node, the second signature being a signature of the second information, and the certificate of the first node, the certificate of the second node, the first signature and the second signature being used for authentication; receiving third information and a third signature from the third node, the third information comprising a certificate of the third node, and the third signature being a signature of the third information.

2. The method of claim 1, wherein, After receiving the first information and the first signature from the second node, the method further comprises: authenticating the second node based on the certificate of the second node and the first signature.

3. The method according to claim 1 or 2, characterized in that, After receiving the third information and the third signature from the third node, the method further comprises: authenticating the third node based on the certificate of the third node and the third signature.

4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: sending fourth information and a fourth signature to the second node, the fourth information comprising the third information, the third signature, the certificate of the third node and the certificate of the first node, the fourth signature being a signature of the fourth information, and the certificate of the first node, the certificate of the third node, the third signature and the fourth signature being used for authentication.

5. The method of claim 4, wherein, The third information further comprises an authentication result of the first node by the third node and / or an authentication result of the second node by the third node.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: sending an authentication mode indication, the authentication mode indication being used to indicate that the authentication mode is a certificate authentication mode.

7. The method according to any one of claims 1 to 6, characterized in that, The first information further comprises a public key of the second node, the public key of the second node being used to determine a first key, and the first key being used to verify information transmitted in a security context negotiation process.

8. The method according to any one of claims 1 to 7, characterized in that, The third information further comprises a public key of the third node, the public key of the third node being used to determine the first key, and the first key being used to verify information negotiated in a security context negotiation process.

9. The method according to any one of claims 1 to 8, characterized in that, The first information further comprises a first freshness parameter, and the first freshness parameter is used to determine the first key.

10. The method according to any one of claims 1 to 9, characterized in that, The second information further comprises a second freshness parameter, and the third information further comprises the second freshness parameter. The second freshness parameter is used to determine the first key.

11. The method according to any one of claims 1 to 10, characterized in that, Before receiving the first information and the first signature from the second node, the method further comprises: sending a third freshness parameter to the second node, and the first information further comprises the third freshness parameter.

12. The method according to any one of claims 1 to 11, characterized in that, The first information further comprises a first timestamp determined by the second node.

13. The method according to any one of claims 1 to 12, characterized in that, The second information further comprises information of a first key derivation function (KDF) and / or information of a first key negotiation algorithm, the first KDF being negotiated by the first node and the second node, and the first key negotiation algorithm being negotiated by the first node and the second node, the first key negotiation algorithm being used to negotiate a key, and the first KDF being used to derive a key.

14. The method according to any one of claims 1 to 13, characterized in that, The first node communicates with the second node using a first communication protocol, and the first node and the third node communicate using a second communication protocol, the first communication protocol being different from the second communication protocol.

15. The method of claim 14, wherein, Information transmitted between the first node and the third node is encapsulated in a data packet, the data packet being in a format defined by the first communication protocol, The data packet is carried in a payload portion of a protocol data unit (PDU) transmitted between the first node and the third node, the PDU being in a format defined by the second communication protocol.

16. The method according to claim 14 or 15, characterized in that The payload portion of the PDU further includes a packet type field, a value of the packet type field being used to indicate a type of the data packet carried in the payload portion of the PDU.

17. The method of claim 4, wherein, The receiving the first information and the first signature from the second node includes: receiving an access authentication request from the second node, the access authentication request including the first information and the first signature; The sending the second information and the second signature to the third node includes: sending a certificate authentication request to the third node, the certificate authentication request including the second information and the second signature; The receiving the third information and the third signature from the third node includes: receiving a certificate authentication response from the third node, the certificate authentication response including the third information and the third signature; The sending the fourth information and the fourth signature to the second node includes: sending an access authentication response to the second node, the access authentication response including the fourth information and the fourth signature.

18. An access authentication method characterized by, The access authentication method is applied to a second node, and the access authentication method includes: sending first information and a first signature to a first node, the first information including a certificate of the second node, and the first signature being a signature of the first information, the certificate of the second node and the first signature being used for authentication; receiving fourth information and a fourth signature from the first node, the fourth information including third information, a third signature and a certificate of the first node, and the fourth signature being a signature of the fourth information, the third signature being a signature of the third information, the third information including a certificate of a third node, the third node being in communication connection with the first node and being used for authentication; authenticating the first node based on the certificate of the first node and the fourth signature; authenticating the third node based on the certificate of the third node and the third signature.

19. The method of claim 18, wherein, The third information includes second information and a second signature, The second information includes the first information, the first signature and the certificate of the first node, and the second signature being a signature of the second information.

20. The method of claim 18 or 19, wherein, The third information further includes an authentication result of the first node by the third node and / or an authentication result of the second node by the third node.

21. The method according to any one of claims 18-20, characterized by, Before sending the first information and the first signature to the first node, the method further includes: receiving an authentication mode indication from the first node, the authentication mode indication being used to indicate that the authentication mode is a certificate authentication mode.

22. The method according to any one of claims 18-21, characterized by, The third information further comprises a public key of the third node, and the method further comprises: determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure.

23. The method according to any one of claims 18-22, characterized by, The first information further comprises a public key of the second node, the public key of the second node being related to the private key of the second node.

24. The method of claim 22, wherein, The first information further comprises the first fresh parameter; and the determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure. The first information further comprises the first fresh parameter; and the determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises:

25. The method of claim 22, wherein, determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure. The first information further comprises the first fresh parameter; and the determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure.

26. The method of claim 25, wherein, The determining the first key based on the first key agreement algorithm, the public key of the third node and the private key of the second node comprises: determining an intermediate key based on a first key derivation function (KDF), the first key, the first fresh parameter and the second fresh parameter; determining the first key based on the first KDF, the intermediate key, an identity of the first node and an identity of the second node.

27. The method of any one of claims 18-26, wherein, Before sending the first information and the first signature to the first node, the method further comprises: determining a first timestamp, and the first information further comprises the first timestamp.

28. The method of any one of claims 18-27, wherein, Before sending the first information and the first signature to the first node, the method further comprises: receiving a third fresh parameter from the first node, and the first information further comprises the third fresh parameter.

29. An access authentication method characterized by, The access authentication method is applied to a third node, and the access authentication method comprises: receiving second information and a second signature from a first node, the second information comprising the first information, the first signature and a certificate of the first node, the first information comprising a certificate of the second node, the first signature being a signature of the first information, and the second signature being a signature of the second information; authenticating the first node based on the certificate of the first node and the second signature; authenticating the second node based on the certificate of the second node and the first signature; sending third information and a third signature to the first node, the third information comprising a certificate of the third node, and the third signature being a signature of the third information, the certificate of the third node and the third signature being used for authentication.

30. A communications device, characterized by The communication apparatus comprises units or modules for performing the method of any of claims 1-17, or units or modules for performing the method of any of claims 18-28, or units or modules for performing the method of claim 29.

31. A communications device, characterized by The communication apparatus comprises a processor and a memory, the memory is configured to store computer instructions, and the processor is configured to invoke the computer instructions stored in the memory, so that the communication apparatus implements the method of any of claims 1-17, or implements the method of any of claims 18-28, or implements the method of claim 29.

32. A communications device, characterized by The communication apparatus comprises a logic circuit and an interface, the interface is configured to input and / or output information, and the logic circuit is configured to make the communication apparatus implement the method of any of claims 1-17, or implement the method of any of claims 18-28, or implement the method of claim 29.

33. A communication system, characterized by The communication system comprises a first node, a second node and a third node, the first node is configured to implement the method of any of claims 1-17, the second node is configured to implement the method of any of claims 18-28, and the third node is configured to implement the method of claim 29.

34. A readable storage medium characterized by, The readable storage medium is configured to store a computer program, when the computer program is executed by a processor, the communication apparatus comprising the processor executes the method of any of claims 1-29.

35. A computer program product, characterised in that, When the computer program product is executed by a processor, the communication apparatus comprising the processor executes the method of any of claims 1-29.