Communication method, device and system, electronic equipment, computer readable storage medium and computer program product
By using nodes to verify legitimacy and allocate encryption keys during encrypted calls with shared keys between terminals, the problem of low communication security caused by newly added terminals independently applying for keys is solved, thus achieving highly secure multi-terminal encrypted calls.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHENGDU TD TECH LTD
- Filing Date
- 2024-10-22
- Publication Date
- 2026-04-24
AI Technical Summary
In end-to-end encryption scenarios, existing technologies allow newly added terminals to independently apply for session keys, resulting in low communication security and failing to effectively improve communication security.
Encrypted calls are made using a shared key between the first and second terminals. The first node forwards the shared key, and after the second node verifies the legitimacy of the first terminal, it distributes the encrypted shared key to the third terminal, ensuring that the third terminal can securely join the encrypted call.
It improves communication security, reduces the risk of key leakage, meets the video distribution requirements in end-to-end encrypted scenarios, and enhances the security of multi-terminal calls.
Smart Images

Figure CN121923797A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a communication method, apparatus, system, electronic device, computer-readable storage medium, and computer program product. Background Technology
[0002] With the development of communication technology, security has become paramount. In security-sensitive industries, customers require communication systems to support higher levels of security protection. To ensure that business data is not eavesdropped on, end-to-end encryption is typically used, meaning that the calling terminal encrypts the data and the called terminal decrypts it, with no plaintext in between.
[0003] Currently, when a business needs to support call (e.g., voice, video) distribution in an end-to-end encrypted scenario, the relevant technology involves multiple terminals applying for session keys from a key center separately. However, the key application process is decoupled from the session signaling and is carried out independently. Therefore, a newly added terminal only needs to know the relevant information of the session to request a session key from the key center, which leads to lower communication security.
[0004] Therefore, existing technologies cannot effectively improve the security of communications. Summary of the Invention
[0005] This application provides a communication method, apparatus, system, electronic device, computer-readable storage medium, and computer program product to improve communication security.
[0006] In a first aspect, embodiments of this application provide a communication method applied to a first terminal, the method comprising: conducting an encrypted call with a second terminal based on a shared key between the second terminal;
[0007] Determine a first encryption result, which is associated with the shared key;
[0008] A first request is sent to a first node, so that the first node sends a second request to a second node based on the first request. The first request is used to request service forwarding, and the second request is used to request a key. Both the first request and the second request include the first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal. When verifying the legitimacy of the first terminal, the second encryption result is sent to a third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key.
[0009] The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
[0010] In one possible design, determining the first encryption result includes:
[0011] Based on the first transmission key shared by the first terminal and the second node, the identity information of the third terminal and the third encryption result received from the first node are encrypted to obtain the first encryption result;
[0012] The third encryption result is used to indicate the shared key.
[0013] In one possible design, the method further includes:
[0014] A third request is sent to the first node, so that the first node sends a fourth request to the second node according to the third request. The third request is used to request session establishment, and the fourth request is used to request a key. Both the third and fourth requests include the fourth encryption result, and the fourth encryption result is used to indicate the identity information of the first terminal and the identity information of the second terminal.
[0015] The second node receives a third encryption result sent by the first node, the third encryption result being obtained by the second node encrypting the shared key according to the first transmission key, the shared key being determined by the second node;
[0016] The third encryption result is decrypted based on the first transmission key to obtain the shared key; wherein, the shared key is used by the second terminal to decrypt the fifth encryption result based on the second transmission key shared by the second terminal and the second node, and the fifth encryption result is obtained by the second node encrypting the shared key based on the second transmission key.
[0017] In one possible design, determining the first encryption result includes:
[0018] Based on the first transmission key shared by the first terminal and the second node, the shared key and the identity information of the third terminal are encrypted to obtain the first encryption result.
[0019] In one possible design, the method further includes:
[0020] Based on the first transmission key, the identity information of the first terminal and the identity information of the second terminal are encrypted to obtain the fourth encryption result.
[0021] In one possible design, the second encryption result is obtained by the second node encrypting the shared key according to the third transmission key shared by the third terminal and the second node, and the shared key is obtained by the second node decrypting the first encryption result according to the first transmission key shared by the first terminal and the second node.
[0022] In one possible design, the method further includes:
[0023] Based on the shared key, an encrypted call is made with the third terminal; or...
[0024] Based on the shared key, encrypted calls are made with the second terminal and the third terminal, respectively.
[0025] Secondly, embodiments of this application provide a communication method applied to a second node, the method comprising:
[0026] During an encrypted call between a first terminal and a second terminal based on a shared key, a second request is received from a first node. The second request is used to request a key and includes a first encryption result, which is associated with the shared key.
[0027] Based on the first encryption result, the first terminal is verified to be legitimate;
[0028] If the first terminal is verified to be legitimate, a second encryption result is sent to the third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key.
[0029] The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
[0030] In one possible design, the step of verifying the legitimacy of the first terminal based on the first encryption result includes:
[0031] If the first encryption result is successfully decrypted based on the first transmission key shared by the first terminal and the second node, the first terminal is determined to be legitimate.
[0032] In one possible design, the step of sending a second encrypted result to the third terminal through the first node if the first terminal is verified to be legitimate includes:
[0033] If the first terminal is verified to be legitimate, then the second encryption result is determined;
[0034] The second encryption result is sent to the first node, so that the first node sends the second encryption result to the third terminal.
[0035] In one possible design, determining the second encryption result includes:
[0036] Based on the first transmission key shared by the first terminal and the second node, the first encryption result is decrypted to obtain a third encryption result, and based on the first transmission key, the third encryption result is decrypted to obtain the shared key; or, based on the first transmission key shared by the first terminal and the second node, the first encryption result is decrypted to obtain the shared key.
[0037] The shared key is encrypted using the third transmission key shared by the third terminal and the second node to obtain the second encryption result.
[0038] In one possible design, the method further includes:
[0039] Receive a fourth request sent by the first node, the fourth request being used to request a key, the fourth request including a fourth encryption result;
[0040] Based on the first transmission key shared by the first terminal and the second node, the fourth encryption result is decrypted to obtain the identity information of the first terminal and the identity information of the second terminal;
[0041] The shared key between the first terminal and the second terminal is determined based on the identity information of the first terminal and the identity information of the second terminal;
[0042] The third encryption result is obtained by encrypting the shared key according to the first transmission key, and the third encryption result is sent to the first terminal through the first node. The fifth encryption result is obtained by encrypting the shared key according to the second transmission key shared by the second terminal and the second node, and the fifth encryption result is sent to the second terminal through the first node.
[0043] Thirdly, embodiments of this application provide a communication method applied to a first node, the method comprising:
[0044] The system receives a first request sent by a first terminal, the first request being used to request service forwarding, the first request including a first encryption result, the first encryption result being determined by the first terminal during an encrypted call between the first terminal and the second terminal based on a shared key;
[0045] Based on the first request, a second request is sent to the second node. The second request is used to request a key and includes the first encryption result. The first encryption result is used by the second node to perform legitimate verification of the first terminal.
[0046] If the second encryption result is received from the second node, the second encryption result is sent to the third terminal. The second encryption result is sent by the second node to the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key.
[0047] The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
[0048] In one possible design, the method further includes:
[0049] The system receives a third request sent by the first terminal, the third request being used to request session establishment, the third request including a fourth encryption result, the fourth encryption result being used to indicate the identity information of the first terminal and the identity information of the second terminal;
[0050] A fourth request is sent to the second node according to the third request. The fourth request is used to request a key and includes the fourth encryption result.
[0051] The system receives a third encryption result and a fifth encryption result sent by the second node, and sends the third encryption result to the first terminal and the fifth encryption result to the second terminal, respectively. The third encryption result is obtained by the second node encrypting a shared key based on a first transmission key shared by the first terminal and the second node. Both the third encryption result and the fifth encryption result are used to indicate the shared key. In a fourth aspect, this application provides a communication device applied to a first terminal, the device comprising:
[0052] The processing module is used to conduct encrypted calls with the second terminal based on a shared key between the two terminals.
[0053] The processing module is further configured to determine a first encryption result, the first encryption result being associated with the shared key;
[0054] The sending module is used to send a first request to a first node, so that the first node sends a second request to a second node according to the first request. The first request is used to request service forwarding, and the second request is used to request a key. Both the first request and the second request include the first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal. When verifying the legitimacy of the first terminal, the second encryption result is sent to a third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key.
[0055] The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
[0056] Fifthly, this application provides a communication device applied to a second node, the device comprising:
[0057] The receiving module is configured to receive a second request sent by a first node during an encrypted call between a first terminal and a second terminal based on a shared key. The second request is used to request a key and includes a first encryption result, which is associated with the shared key.
[0058] The processing module is used to perform a legality verification on the first terminal based on the first encryption result;
[0059] The sending module is used to send a second encryption result to a third terminal through the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key.
[0060] The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
[0061] Sixthly, this application provides a communication device applied to a first node, the device comprising:
[0062] The receiving module is used to receive a first request sent by a first terminal. The first request is used to request service forwarding. The first request includes a first encryption result, which is determined by the first terminal during an encrypted call between the first terminal and the second terminal based on a shared key.
[0063] The sending module is configured to send a second request to the second node according to the first request. The second request is used to request a key and includes the first encryption result. The first encryption result is used by the second node to perform legitimate verification on the first terminal.
[0064] The sending module is further configured to send the second encryption result to the third terminal when it receives the second encryption result sent by the second node. The second encryption result is sent by the second node to the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key.
[0065] The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
[0066] In a seventh aspect, embodiments of this application provide a communication system, including: a first terminal, a second terminal, a third terminal, a first node, and a second node;
[0067] The first terminal is used to perform the communication method as described in the first aspect of the claim;
[0068] The second node is used to perform the communication method as described in the second aspect;
[0069] The first node is used to perform the communication method as described in the third aspect;
[0070] The second terminal is used to decrypt the fifth encryption result sent by the first node according to the second transmission key shared by the second terminal and the second node, so as to obtain the shared key;
[0071] The third terminal is used to decrypt the second encryption result sent by the first node according to the first transmission key shared by the third terminal and the second node, so as to obtain the shared key.
[0072] Eighthly, embodiments of this application provide an electronic device, including: a processor and a memory communicatively connected to the processor;
[0073] The memory stores computer-executed instructions;
[0074] The processor executes computer execution instructions stored in the memory to implement the communication method as described in any one of the first, second, and third aspects.
[0075] Ninthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the communication method as described in any one of the first, second, and third aspects.
[0076] In a tenth aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method as described in any one of the first, second, and third aspects.
[0077] The communication method, apparatus, system, electronic device, computer-readable storage medium, and computer program product provided in this application conduct encrypted calls with a second terminal based on a shared key between the second terminal and the third terminal; determine a first encryption result, the first encryption result being associated with the shared key; send a first request to a first node, causing the first node to send a second request to the second node based on the first request, the first request being used to request service forwarding, the second request being used to request a key, both the first request and the second request including the first encryption result; the first encryption result is used by the second node to perform legitimate verification of the first terminal, and when the first terminal is verified to be legitimate, a second encryption result is sent to a third terminal through the first node, the second encryption result being used by the third terminal to determine the shared key; wherein, the shared key is used by the third terminal to conduct encrypted calls with at least one of the first terminal and the second terminal. This application ensures the security of communication between terminals by introducing a shared key between the first and second terminals for encrypted calls. In order to meet the business requirements of supporting video distribution in end-to-end encryption scenarios, when a third terminal joins the communication between the first and second terminals, the first terminal can initiate a service forwarding request, use the first encryption result to verify the legitimacy of the first terminal, and after the verification is valid, forward the encryption result of the shared key allocated by the second node to the third terminal through the first node, and securely synchronize the shared key to the third terminal, thereby improving the security of communication. Attached Figure Description
[0078] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0079] Figure 1 Application scenario diagram of the communication method provided in this application;
[0080] Figure 2 This is a flowchart of a communication method provided in one embodiment of this application;
[0081] Figure 3 This is an encrypted session interaction diagram provided in another embodiment of this application;
[0082] Figure 4 This is an encrypted session interaction diagram provided in another embodiment of this application;
[0083] Figure 5 A flowchart of a communication method provided in another embodiment of this application;
[0084] Figure 6 A flowchart of a communication method provided in another embodiment of this application;
[0085] Figure 7 This is a schematic diagram of an apparatus for a communication method provided in one embodiment of this application;
[0086] Figure 8 This is a schematic diagram of an apparatus for a communication method provided in another embodiment of this application;
[0087] Figure 9 This is a schematic diagram of an apparatus for a communication method provided in another embodiment of this application;
[0088] Figure 10 This is a schematic diagram of the structure of a communication system provided in one embodiment of this application;
[0089] Figure 11 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application.
[0090] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation
[0091] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0092] It should be noted that during the implementation of this application plan, all applicable laws and regulations will be strictly followed. All aspects of the collection, storage, use, processing, transfer, provision and public disclosure of user information and customer data will be carried out in a legal and compliant manner to ensure that there is no risk of illegality or violation of regulations throughout the process, and to resolutely safeguard social public order and good morals.
[0093] It should be noted that any mention of software tools, component designs, etc., in the embodiments described in this application is intended as an exemplary reference to clearly illustrate the feasibility of the implementation path of the technical solution of this application, and not to indicate that the applicant has actually adopted or necessarily adopted the solution. These mentioned external elements are only used to aid understanding and do not constitute a limitation or constraint on the specific implementation content of this application.
[0094] To clearly understand the technical solution of this application, the solutions of the prior art will be described in detail first.
[0095] In security-sensitive industries, customers require communication systems to support higher levels of security protection. To ensure that business data is not eavesdropped, session keys are usually encrypted end-to-end, that is, the calling terminal encrypts and the called terminal decrypts, with no plaintext in between. Session keys are usually centrally distributed by a key center, and then encrypted communication between terminals is achieved based on the session keys.
[0096] Current technology involves multiple terminals separately requesting session keys from a key center. This key request process is decoupled from session signaling and conducted independently. Furthermore, for newly joined terminals, this technology only requires knowledge of the session information to request a session key from the key center. This makes the session key transmission process vulnerable to attacks and fails to effectively guarantee the security of data transmission between terminals.
[0097] Therefore, in order to solve the aforementioned technical problems and ensure the security of key transmission, thereby improving communication security, during the encrypted call between the first terminal and the second terminal using a shared key, the first terminal or the second terminal can invite a third terminal to join the encrypted call. This is done by using the first node to forward the shared key between the first terminal and the second node, and requesting the shared key of the third terminal to join the communication from the second node. To ensure communication security, the second node verifies the legitimacy of the first terminal's identity. After confirming the legitimacy of the first terminal, the second node distributes the shared key for joining the communication between the first terminal and the second terminal to the third terminal, and forwards the encrypted shared key to the third terminal through the first node. The third terminal then decrypts the shared key to obtain it, enabling it to join the encrypted call between the first terminal and / or the second terminal.
[0098] Figure 1 This is a diagram illustrating an application scenario that can implement the communication method provided in this application, such as... Figure 1As shown in the diagram, the scenario corresponding to the communication method provided in this application includes a first terminal 101, a server first node (here referred to as the first node, such as a business server) 102, a key center (here referred to as the second node) 103, a second terminal 104, and a third terminal 105. The server is used to request service forwarding or to request a key; the key center is used to generate and distribute keys, that is, to allocate a shared key to the terminals that need to communicate, and to encrypt the shared key to obtain the session key corresponding to each terminal, and then distribute the session key to each terminal. Specifically, the first terminal 101 requests the server 102 to establish a session with the second terminal 104; the server 102 requests a key from the key center 103; the key center 103 creates a shared key and encrypts the shared key based on the transmission key with the first terminal (e.g., the first transmission key) to obtain a third encryption result, and encrypts the shared key based on the transmission key with the second terminal (e.g., the second transmission key) to obtain a fifth encryption result; then the server 102 sends the third encryption result to the first terminal 101 and the fifth encryption result to the second terminal 104; the first terminal 101 and the second terminal 104 decrypt the encryption results of the shared key respectively, and conduct an encrypted call using the shared key.
[0099] During an encrypted call between a first terminal and a second terminal using a shared key, the first or second terminal can invite a third terminal to join the encrypted call: The first terminal 101 generates a first encrypted result; the first terminal 101 sends a service forwarding request to the server 102; the server 102 requests a key from the key center 103, both the service forwarding request and the requested key containing the first encrypted result; the key center 103 decrypts the first encrypted result and then verifies the legitimacy of the first terminal, confirming its identity. After verifying legitimacy, the key center 103 generates a second encrypted result containing the shared key based on the transmission key with the third terminal (e.g., the third transmission key) and sends it to the server 102; the server 102 transmits the second encrypted result to the third terminal 105. The third terminal can obtain the shared key by decrypting the result using the transmission key with the key center. Thus, the third terminal 105 joins the encrypted call between the first terminal 101 and the second terminal 104. In this case, the parties involved in the encrypted call can be three people simultaneously; or the first terminal 101 can end the call after the third terminal 105 joins the encrypted call of the first terminal 101 and the second terminal 104; or the second terminal 104 can end the call after the third terminal 105 joins the encrypted call of the first terminal 101 and the second terminal 104.
[0100] The technical solution of this application and how it solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0101] Figure 2 A flowchart of a communication method provided in one embodiment of the application is shown below. Figure 2 As shown, the execution entity in this embodiment is a communication identification device, which can be implemented through a computer program; it can also be implemented through a medium storing the relevant computer program, such as a USB flash drive and / or optical disc; or it can be implemented through a physical device integrating or installing the relevant computer program, such as a chip or communication device. The communication device can be a server, server cluster, or other electronic device. The communication method provided in this embodiment is as follows: Figure 2 As shown, it includes the following steps:
[0102] Step 201: Conduct an encrypted call with the second terminal based on the shared key between the two terminals.
[0103] The second terminal refers to the terminal that receives the request; correspondingly, the terminal that initiates the service is called the first terminal.
[0104] A shared key refers to a key that communication terminals share, used for encrypting and decrypting transmitted data, or for authentication.
[0105] Optionally, the shared key can be created by a key center. The key center generates the shared key corresponding to the terminal by identifying the terminal's identity information and using the transmission key shared with the terminal. Here, the transmission key refers to the shared cipher used during data transmission between the terminal and the second node, and is typically created by the second node. The first transmission key can be the transmission key shared between the first terminal and the second node. The second node refers to the server that processes key requests, such as a server that generates or determines keys, which could be a key center, etc. Here, the key center is considered the second node, and will not be elaborated further below.
[0106] A key center is used to generate and distribute keys. It is a centralized system for managing, storing, and distributing keys. It can also be created through other key distribution systems. There are no restrictions on the method of creating shared keys here.
[0107] Specifically, in this embodiment, the first terminal establishes a session with the second terminal through a server. During this process, the first and second terminals distribute key results containing a shared key through a key center and obtain the shared key respectively. The first terminal uses the shared key to encrypt the original data used for the session and sends the generated ciphertext to the second terminal. After receiving the ciphertext, the second terminal uses the same shared key to decrypt the ciphertext, thereby recovering the original data. This completes the encrypted call process between the first and second terminals. There are many ways for terminals to communicate; establishing a session through a server is one such method and is not limited here.
[0108] Step 202: Determine the first encryption result, which is associated with the shared key.
[0109] The first encryption result refers to the key result used to verify the identity information of the initiating terminal.
[0110] Accordingly, the first encryption result can be generated by the first terminal encrypting the identity information of the third terminal and the shared key of the first terminal using the first transmission key. The first encryption result is determined by the first terminal, but can also be determined by other calling terminals; this is not limited here. The first transmission key refers to the transmission cipher between the first terminal and the second node.
[0111] Step 203: Send a first request to the first node so that the first node sends a second request to the second node based on the first request. The first request is used to request service forwarding, and the second request is used to request a key. Both the first request and the second request include a first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal. When verifying the legitimacy of the first terminal, the second encryption result is sent to the third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key.
[0112] The shared key is used for encrypted calls between the third terminal and at least one of the first and second terminals.
[0113] The first node refers to the intermediary used to respond to business requests. The intermediary can be a server or its network device; no specific limitation is made here. The server is used as the first node, and will not be elaborated further below.
[0114] The first request is a service forwarding request sent from the first terminal to the first node.
[0115] The second request is a request for a key sent by the first node to the second node after the first node receives the first request sent by the first terminal. (For example, the second request can be directly determined based on the first encryption result in the first request, or the fourth request can be determined based on the first encryption result in the first request through the network protocol for communication between the first node and the second node; no specific limitation is made here).
[0116] The second encryption result refers to the result of encrypting the shared key using the transmission keys of the second node and the third terminal.
[0117] A third terminal refers to a new terminal that joins a session that is currently in the process of two or more terminal sessions. There can be one or more terminals.
[0118] A valid verification can be understood as assuming that if the first transmission key can be successfully decoded, it means that the request was made by the first terminal and not an illegal request.
[0119] For example, Figure 3 This is an interactive schematic diagram of the communication method provided in the embodiments of this application. Figure 3 The interactive flow for establishing a session is shown, with the specific steps as follows (S301-S308):
[0120] S301: The first terminal determines the first encryption result.
[0121] S302: The first terminal sends a first request to the first node, such as a service forwarding request, carrying the first encrypted result.
[0122] S303: The first terminal sends a second request to the second node, such as requesting a key, carrying the first encryption result.
[0123] S304: The second terminal decrypts the first encryption result to confirm the legitimacy of the first terminal's identity and decrypts the shared key.
[0124] S305: The second node uses the third transmission key to generate a second encryption result for the shared key.
[0125] S306: The first node receives the second encrypted result forwarded by the second node.
[0126] S307: The second node forwards the second encryption result to the third terminal.
[0127] S308: The third terminal uses the third transmission key to decrypt the second encryption result and obtains the shared key K1.
[0128] Specifically, in this embodiment, during the encrypted session between the first terminal and the second terminal, the first terminal requests access to the session from the server for the third terminal. The first terminal's cryptographic module generates a first encryption result; the first terminal then initiates a service forwarding request to the server, which may carry the first encryption result. The server parses the service forwarding request and, based on the key information in the identification message, sends a request key to the key center, requesting the shared key of the third terminal; the key center uses its transmission key with the first terminal to decrypt the first encryption result, confirming the legitimacy of the first terminal's identity information; the key center generates a second encryption result and sends it to the third terminal through the server; the third terminal uses its transmission key with the key center to decrypt the second encryption result, thereby generating the same shared key as the first terminal. After receiving the original encrypted data of the session from the first terminal or the second terminal, the third terminal uses the same shared key to decrypt the encrypted data used for the session, thereby recovering the original data. Therefore, a third terminal can join the encrypted session between the first terminal and the second terminal to realize a three-terminal session; wherein, after the third terminal joins the session, at least one of the first terminal and the second terminal retains a session with the third terminal; for example, after the third terminal joins the session, the second terminal can end the session and the first terminal can start a session with the third terminal; or, after the third terminal joins the session, the first terminal can end the session and the first terminal can start a session with the second terminal.
[0129] In this embodiment, to meet the business requirements of supporting video distribution in end-to-end encryption scenarios, when a third terminal joins the communication between the first terminal and the second terminal, the first terminal can send a first request to the first node, and then the first node can send a second request to the second node. The first encryption result can be used to verify the legitimacy of the first terminal. After the legitimacy is verified, the security of the entire communication process is further enhanced. Furthermore, by using the encryption result of the shared key distributed to the third terminal by the first node and the forwarding of the shared key distributed by the second node, the indirect distribution of the shared key is securely synchronized to the third terminal, ensuring the security of multi-terminal communication and reducing the risk of key leakage.
[0130] In one possible design, based on the above embodiments, determining the first encryption result can be achieved in at least two of the following ways:
[0131] Method 1, determine the first encryption result, including:
[0132] Based on the first transmission key shared by the first terminal and the second node, the identity information of the third terminal and the third encryption result received from the first node are encrypted to obtain the first encryption result; wherein, the third encryption result is used to indicate the shared key.
[0133] The third encryption result refers to the encryption result of the shared key of the called terminal; this can be the encryption result of the shared key of the third terminal, which will not be elaborated further below.
[0134] In this embodiment, the second node receives the third encryption result and encrypts the identity information of the third terminal and the third encryption result according to the first transmission key to obtain the first encryption result.
[0135] Method 2, determining the first encryption result, also includes:
[0136] Based on the first transmission key shared by the first terminal and the second node, the shared key and the identity information of the third terminal are encrypted to obtain the first encryption result.
[0137] Specifically, in the encrypted session between the first terminal and the second terminal, the first terminal requests access to the third terminal from the server. When the first terminal establishes a session, it sends a key request to the key terminal through the server. The request is made by the key center and the first terminal's transmission key center to parse the key request message, identify the first terminal's identity information, and retrieve the transmission key shared by the first terminal and the second node from the key center's storage module. This transmission key can be the first transmission key, which is then sent to the first terminal via the network protocol. The key center encrypts the shared key based on the first transmission key, generates a third encryption result, and sends the third encryption result to the first terminal.
[0138] When a third terminal joins an encrypted call between the first and second terminals: The encryption module of the first terminal can encrypt the third terminal's identity information and the third encryption result using the first transmission key to obtain a first encryption result. Alternatively, the first terminal decrypts the third encryption result to obtain a shared key, and its encryption module can then encrypt the shared key and the third terminal's identity information using the first transmission key to generate a first encryption result. Or, the first terminal decrypts the third encryption result to obtain a shared key, and its encryption module can then encrypt the first terminal's identity information, the shared key, and the third terminal's identity information using the first transmission key to generate a first encryption result.
[0139] The storage module in the key center is a crucial component of the key management system. It is responsible for the secure storage of keys, ensuring that they are not illegally obtained or tampered with during storage. Various network protocols exist for key transmission, which will not be limited here.
[0140] In this embodiment, not only is the identity information of the third terminal encrypted, but the encryption result of the third terminal or the shared key of the first terminal is also encrypted. This dual encryption mechanism further improves the security of encrypted calls and avoids the risk of leakage of session content that may be caused by directly transmitting the key.
[0141] In one possible design, based on the above embodiments, the method further includes:
[0142] A third request is sent to the first node, so that the first node sends a fourth request to the second node based on the third request. The third request is used to request session establishment, and the fourth request is used to request a key. Both the third and fourth requests include a fourth encryption result, which is used to indicate the identity information of the first terminal and the identity information of the second terminal.
[0143] The third encryption result sent by the first node is received. The third encryption result is obtained by the second node encrypting the shared key according to the first transmission key. The shared key is determined by the second node.
[0144] The third encryption result is decrypted based on the first transmission key to obtain the shared key; wherein, the shared key is used by the second terminal to decrypt the fifth encryption result based on the second transmission key shared by the second terminal and the second node, and the fifth encryption result is obtained by the second node encrypting the shared key based on the second transmission key.
[0145] The third request is a request established between the terminal and the first node before an encrypted call is made with the second terminal. The third request can be a business request or can be used for session establishment.
[0146] The fourth request refers to the key request that the first node sends to the second node after receiving the third request.
[0147] The fourth encryption result refers to the result of encrypting the identity information of the terminal to be encrypted, and is mainly used for the authentication of the terminal.
[0148] The fifth encryption result refers to the encryption result of the shared key of the second terminal that initiated the call.
[0149] The second transmission key refers to the shared password used during data transmission between the second terminal and the first node.
[0150] In one possible design, the method also includes:
[0151] Based on the first transmission key, the identity information of the first terminal and the identity information of the second terminal are encrypted to obtain the fourth encryption result.
[0152] In this embodiment, the first terminal first encrypts its own identity information and the identity information of the second terminal using the first transmission key to obtain a fourth encryption result. Then, the first terminal sends a third request carrying the fourth encryption result to the first node to request session establishment. After receiving the third request, the first node determines a fourth request for requesting the key based on the third request (for example, directly determining the fourth request based on the fourth encryption result in the third request, or determining the fourth request based on the fourth encryption result in the third request through the network protocol for communication between the first and second nodes; no specific limitation is made here), and sends the fourth request to the second node carrying the fourth encryption information. The second node decrypts the fourth encryption result using the first transmission key to confirm the identity information of the first and second terminals. The second node encrypts the shared key using the first transmission key to obtain a third encryption result, and simultaneously encrypts the shared key using the second transmission key to obtain a fifth encryption result. The second node then sends the third encryption result to the first terminal through the first node, and the fifth encryption result to the second terminal through the first node.
[0153] The first terminal receives the third encryption result and decrypts it using the first transmission key to obtain the shared key for encrypted communication between the first and second terminals. The second terminal receives the fifth encryption result and decrypts it using the second transmission key to obtain the shared key for encrypted communication between the second and first terminals. The first and second terminals encrypt and decrypt the session content using the shared key, thereby achieving encrypted communication and improving communication security.
[0154] For example, Figure 4 This is an interactive schematic diagram of the communication method provided in the embodiments of this application. Figure 4 The diagram illustrates the interaction between a third terminal joining a session between a first terminal and a second terminal, with steps S401-S408 as follows:
[0155] Step S401: The first terminal sends a third request to the first node, carrying the fourth encryption result.
[0156] Step S402: The first node sends a fourth request to the second node, carrying the fourth encryption result.
[0157] Step S403: The second node confirms the identity information of the first terminal and the second terminal based on the first transmission key.
[0158] Step S404: The second node creates a shared key based on the identity information of the first terminal and the second terminal.
[0159] Step S405: The second node encrypts the shared key using the first transmission key and the second transmission key to obtain the third transmission key and the fifth transmission key.
[0160] Step S406: The first node receives the third and fifth encryption results forwarded by the second node.
[0161] Step S407: The first node sends the third encryption result to the first terminal; the first terminal uses the first transmission key to decrypt the third encryption result and obtains the shared key K1.
[0162] Step S408: The first node sends the fifth encryption result to the second terminal; the second terminal uses the second transmission key to decrypt the fifth encryption result and obtains the shared key K1.
[0163] Specifically, the first terminal requests an encrypted session with the second terminal from the server. The first terminal obtains a first transmission key from its own cryptographic storage module. The first terminal's cryptographic module uses the first transmission key to encrypt the identity information of both the first and second terminals, generating a fourth encryption result. The first terminal sends a session establishment request to the first node, carrying the fourth encryption result. The server receives the session establishment request and parses the message. After parsing the current session content and finding key information, the server sends a key request to the key center, carrying the fourth encryption result. The key request requests the creation of a third and fifth encryption result. The key center matches the first and second transmission keys from its encryption module and uses the first transmission key to decrypt the fourth encryption result, confirming the identity information of the first and second terminals. After confirming the terminal identity information, the key center creates a shared key and uses the first and second transmission keys to encrypt the shared key, generating a third and fifth encryption result, which are then sent to the server. The server receives the third encryption result and sends it to the first terminal. The first terminal decrypts the third encryption result using the transmission key shared with the key center to obtain the shared key. The server receives the fifth encryption result and sends it to the second terminal. The second terminal decrypts the fifth encryption result using the transmission key shared with the key center, thus obtaining the shared key. In this way, the first terminal and the second terminal can decrypt each other's encrypted session ciphertext using the shared key, achieving an encrypted session between the first terminal and the second terminal.
[0164] In this embodiment, to enhance the security of end-to-end sessions, when a first terminal initiates a session, it establishes the session by initiating a third request and uses a fourth encryption result to verify the identities of both the first and second terminals. After verifying the terminal identities, the second node should encrypt the shared key using the first and second transmission keys respectively to obtain a third and a fifth encryption result. The first terminal then decrypts the third encryption result using the first transmission key, and the second terminal decrypts the fifth encryption result using the second transmission key to obtain the shared key; the shared key is then used to establish an encrypted session between the first and second terminals. In this session method, both terminal identity information and the shared key are transmitted in encrypted form. Even if the information is intercepted by a third party, it is difficult to obtain the shared key used in the terminal session, thus effectively ensuring the security of terminal transmissions.
[0165] In one possible design, the method also includes:
[0166] The second encryption result is obtained by the second node encrypting the shared key using the third transmission key shared between the third terminal and the second node. The shared key is obtained by the second node decrypting the first encryption result using the first transmission key shared between the first terminal and the second node.
[0167] Specifically, the key center matches a first transmission key from its encryption module and decrypts the first encryption result using the first transmission key. If the decryption result is a shared key or a third encryption result, the key center needs to use the first transmission key to decrypt the third encryption result to obtain the shared key. The key center matches a third transmission key from its encryption module and then encrypts the shared key using the third transmission key to obtain a second encryption result. The key center sends the second encryption result to the third terminal through a server. The third terminal also obtains the third transmission key shared with the key center from its own key storage module and uses the third transmission key to decrypt the second encryption result to obtain the same shared key as the first terminal.
[0168] In this embodiment, the encryption result of the shared key is transmitted via the first node, ensuring the security of key transmission. The original shared key can be directly recovered by decrypting it using the transmitted key; this provides an efficient and fast key processing method for terminal communication.
[0169] As an optional implementation, the method includes:
[0170] Encrypted calls can be made with a third terminal based on a shared key; or...
[0171] Encrypted calls are made with the second and third terminals respectively, based on the shared key.
[0172] Specifically, the first terminal and the second terminal are in an encrypted session. When the first terminal or the second terminal requests to establish a session with the third terminal, the first terminal or the second terminal sends a request to the server to establish a session with the third terminal. The server then sends a request key to the key center based on the session establishment request. The third terminal distributes the same shared key as the first terminal and joins the session with the first terminal or the second terminal using the shared key. For example, the third terminal receives the original encrypted data of the session sent by the server; it can decrypt the original encrypted data of the session using the shared key. After successful decryption, the third terminal can receive the session content between the first terminal and the second terminal, thereby joining the session between the first terminal and the second terminal, achieving a three-terminal session. Alternatively, after the third terminal joins the session, the second terminal ends the session, achieving a two-terminal session between the first terminal and the third terminal. Or, after the third terminal joins the session, the first terminal ends the session, achieving a two-terminal session between the second terminal and the third terminal.
[0173] It should be noted that, Figure 3 This can serve as an example of a communication method; Figure 4 It can also be used as an example of a communication method; Figure 4 + Figure 3 This can be used as an embodiment of a communication method; for example, the implementation process may include:
[0174] Steps 401 to 408;
[0175] Steps 301 to 308.
[0176] In this embodiment, to enhance the security of transmission between terminals, encrypted sessions are implemented across all three terminals based on a shared key; alternatively, encrypted sessions are implemented with the second and third terminals separately based on the shared key. This method of encrypting sessions using a shared key allows for flexible encrypted communication with multiple terminals, thereby meeting the communication needs between different terminals.
[0177] Figure 5 A flowchart of a communication method provided in one embodiment of the application is shown below. Figure 5 As shown, the execution entity in this embodiment is a communication identification device, which can be implemented through a computer program; it can also be implemented through a medium storing the relevant computer program, such as a USB flash drive and / or optical disc, or it can be implemented through a physical device integrating or installing the relevant computer program, such as a chip or communication device. The communication device can be a server, server cluster, or other electronic device. A communication method applied to the second node includes the following steps:
[0178] Step 501: During the encrypted call between the first terminal and the second terminal based on the shared key, a second request is received from the first node. The second request is used to request a key and includes a first encryption result, which is associated with the shared key.
[0179] Step 502: Verify the legitimacy of the first terminal based on the first encryption result;
[0180] Step 503: If the first terminal is verified to be legitimate, the second encryption result is sent to the third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key.
[0181] The shared key is used for encrypted calls between the third terminal and at least one of the first and second terminals.
[0182] Specifically, the first terminal requests the server to establish a session with the second terminal. During the session, the first terminal uses a shared key to encrypt the original session data and sends the encrypted ciphertext to the server. The second terminal receives the encrypted session ciphertext and decrypts it using the shared key, thus establishing an encrypted session between the first and second terminals. The first terminal then requests the server to add a third terminal to the encrypted session between itself and the second terminal. The cryptographic module within the first terminal generates a first encryption result. During the session between the first and second terminals, the server receives a first request from the first terminal to initiate a service. This first request can be used for service forwarding and includes the first encryption result. The server parses the content of the first request based on the message and finds that it contains the first encryption result. The key center receives a second request from the server, which requests a key and carries the first encryption result. The key center uses its transmission key with the first terminal to decrypt the first encryption result. If the first encryption result is successfully decrypted, the identity of the first terminal is confirmed as legitimate. After the legitimacy verification, the key center matches a third transmission key in its internal key storage module and encrypts the shared key using the third transmission key to generate a second encryption result, which is then sent to the server. The server sends the second encryption result to the third terminal. The third terminal retrieves the third transmission key from its internal key storage module and decrypts the second encryption result, obtaining the same shared key as the first terminal. The third terminal can then join the encrypted session between the first and second terminals using the shared key; after the third terminal joins the session, at least one of the first and second terminals must maintain a session with the third terminal.
[0183] In this embodiment, to ensure the security of terminal communication, a first encryption result is introduced as a verification method. The first encryption result is associated with a shared key. By decrypting the first encryption result, the legitimacy of the terminal applying to join the session and the shared key can be confirmed. After the second node completes the verification of the second terminal's legitimacy, it can determine the second encryption result based on the shared key obtained from the first encryption result. The third terminal then decrypts the second encryption result and obtains the same shared key as the first terminal. Therefore, only terminals holding the correct shared key can be verified as legitimate, effectively preventing unauthorized access by unauthorized terminals and enhancing the overall security of the communication system.
[0184] In one possible design, based on the above embodiments, the method includes: performing a legality verification on the first terminal according to the first encryption result, including:
[0185] If the first encryption result is successfully decrypted based on the first transmission key shared by the first terminal and the second node, the first terminal is determined to be legitimate.
[0186] In this embodiment, the second node decrypts the first encryption result based on the first transmission key. If the third encryption result and the third terminal identity information can be decrypted, or the first terminal identity information, the first terminal's shared key, and the third terminal identity information can be decrypted, then the first terminal's identity can be confirmed as legitimate.
[0187] In one possible design, the approach includes:
[0188] If the first terminal is verified to be legitimate, the second encrypted result is sent to the third terminal through the first node, including:
[0189] If the first terminal is verified to be legitimate, then the second encryption result is determined;
[0190] Send the second encrypted result to the first node so that the first node can send the second encrypted result to the third terminal.
[0191] In this embodiment, if the second node can decrypt the third encryption result or the shared key of the first terminal, the first terminal is considered legitimate. After verifying the legitimacy of the first terminal, the second node matches the third transmission key in its internal storage module and encrypts the shared key according to the third transmission key to obtain the second encryption result. The second node then sends the second encryption result to the third terminal through the first node.
[0192] In one possible design, the method includes the determined second encryption result, comprising:
[0193] Based on the first transmission key shared by the first terminal and the second node, the first encryption result is decrypted to obtain the third encryption result, and based on the first transmission key, the third encryption result is decrypted to obtain the shared key; or, based on the first transmission key shared by the first terminal and the second node, the first encryption result is decrypted to obtain the shared key.
[0194] The shared key is encrypted using the third transmission key shared by the third terminal and the second node to obtain the second encryption result.
[0195] In this embodiment, the second node decrypts the first encryption result using the first transmission key to obtain a third encryption result or a shared key. If the decryption result is the third encryption result, it needs to be decrypted using the first transmission key to obtain the shared key of the first terminal. After obtaining the shared key of the first terminal, the key center encrypts the shared key using the third transmission key to obtain a second encryption result.
[0196] Specifically, when a first terminal and a second terminal are in an encrypted session and the first terminal needs to request a session with a third terminal from the server, the first terminal obtains a first transmission key from its internal key storage module. The first terminal's encryption module then encrypts the first terminal's identity information, the shared key, and the third terminal's identity information using the first transmission key to generate a first encrypted result. Alternatively, the first terminal's encryption module encrypts a third encrypted result and the third terminal's identity information using the first transmission key to generate a first encrypted result. The first terminal sends a key request to the key center through the server, carrying the first encrypted result. The key center identifies the current key request through message parsing and decrypts the first encrypted result using the first transmission key shared with the first terminal. Successful decoding of the first encrypted result confirms the legitimacy of the first terminal. After verifying the legitimacy of the first terminal, the key center matches the first and third transmission keys from its key storage module based on the first and third terminal's identity information. The key center decrypts the first encrypted result using the first transmission key. The decryption result may contain the third encrypted result corresponding to the first terminal and the third terminal's identity information. The key center decrypts the third encrypted result using the first transmission key to obtain the shared key. Alternatively, the decryption result of the first encryption result by the key center may include the identity information of the first terminal, the shared key corresponding to the first terminal, and the identity information of the third terminal. The key center then encrypts the shared key according to the third transmission key to obtain the second encryption result.
[0197] In this embodiment, to reduce the risk of terminal calls being disrupted, the second node verifies the legitimacy of the first terminal's identity based on the first encryption result. After verifying the legitimacy of the first terminal's identity, the key center creates a third encryption result using the third transmission key and the shared key, and forwards it to the third terminal through the first node. The third terminal then decrypts the result to obtain the shared key, enabling it to join the encrypted call between the first terminal and / or the second terminal. Sending the second encryption result to the third terminal via the first node also effectively ensures the security of key transmission, thereby guaranteeing the security of the communication session.
[0198] In one possible design, based on the above embodiments, the method includes:
[0199] Receive the fourth request sent by the first node. The fourth request is used to request the key and includes the fourth encryption result.
[0200] Based on the first transmission key shared by the first terminal and the second node, the fourth encryption result is decrypted to obtain the identity information of the first terminal and the identity information of the second terminal.
[0201] Based on the identity information of the first terminal and the identity information of the second terminal, a shared key between the first terminal and the second terminal is determined;
[0202] The third encryption result is obtained by encrypting the shared key with the first transmission key, and the third encryption result is sent to the first terminal through the first node. The fifth encryption result is obtained by encrypting the shared key with the second terminal and the second node with the second transmission key, and the fifth encryption result is sent to the second terminal through the first node.
[0203] Specifically, the first terminal requests the server to establish a session with the second terminal, and the first terminal obtains a first transmission key from its own password storage module. The first terminal's password module uses the first transmission key to encrypt the identity information of both the first and second terminals to generate a fourth encryption result. The first terminal sends a request key to the server, carrying the fourth encryption result. This fourth encryption result is the result of the first terminal's encryption module encrypting the identity information of both the first and second terminals during session establishment. After analyzing the message and identifying it as a request key, the server sends a request key to the key center, carrying the fourth encryption result. The key request requests the creation of a third and fifth encryption result. The key center matches the first and second transmission keys from its own encryption module. The key center uses the first transmission key to decrypt the fourth encryption result, confirming the identity information of both the first and second terminals. The key center creates a shared key between the first terminal and the second terminal based on their identities. The key center uses its first transmission key with the first terminal to encrypt the shared key, thereby obtaining a third encryption result, which is then sent to the first terminal via the server. The key center uses its second transmission key with the second terminal to encrypt the shared key, thereby obtaining a fifth encryption result, which is then sent to the second terminal via the server.
[0204] In this embodiment, to enhance the security of the terminal session, the second node confirms the identity information of the first and second terminals based on the fourth encryption result, and determines the shared key using the identity information of the first and second terminals. To ensure the security of key transmission, the second node encrypts the shared key using its transmission key with the corresponding terminal, and then sends it to the terminal through the first node. This method of encrypting the shared key across multiple terminals reduces the risk of key cracking; it enhances the security of the transmission path between terminals in the prior art, and also effectively protects the security of the encrypted session.
[0205] Figure 6 A flowchart of a third communication method provided in one embodiment of the application is shown. The method includes: applied to a first node, and the method includes the following steps:
[0206] Step 601: Receive a first request sent by the first terminal. The first request is used to request service forwarding. The first request includes a first encryption result. The first encryption result is determined by the first terminal during the encrypted call between the first terminal and the second terminal based on the shared key.
[0207] Step 602: Based on the first request, send a second request to the second node. The second request is used to request a key and includes the first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal.
[0208] Step 603: If the second encryption result is received from the second node, then the second encryption result is sent to the third terminal. The second encryption result is sent by the second node to the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key.
[0209] The shared key is used for encrypted calls between the third terminal and at least one of the first and second terminals.
[0210] Specifically, during the encrypted session between the first terminal and the second terminal, either the first terminal requests the third terminal to join the session, or the second terminal requests the third terminal to join the session; this is not limited to either. The encryption module inside the first terminal generates a first encryption result. This first encryption result can be the encryption result of the first terminal's encryption module using a first transmission key to encrypt the first terminal's identity information, a shared key, and the third terminal's identity information. Alternatively, the first encryption result can be the result of the first terminal's encryption module encrypting a third encryption result using the first transmission key and the third terminal's identity information. The first transmission key is obtained from the key storage module of the key center. The server receives a first request from the first terminal, which is used for service forwarding and carries the first encryption result. The server parses the content of the first request into a message indicating service forwarding and the inclusion of the first encryption result. The server then sends a second request to the key center, which requests a key from the key center and also includes the first encryption result. The key center matches the first transmission key in its internal password storage module based on the first terminal's identity information and uses the first transmission key to decrypt the first encryption result. Successful decoding of the first encryption result confirms the legitimacy of the first terminal's identity. After the key center verifies the legitimacy of the first terminal's identity, if the shared key is directly obtained after decrypting the first encryption result, the key center matches the third transmission key in its internal password storage module based on the third terminal's identity information. The key center uses its third transmission key, shared with the third terminal, to encrypt the shared key, thereby obtaining the second encryption result. Alternatively, if the third encryption result is obtained after decrypting the first encryption result, the key center first uses its first transmission key, shared with the first terminal, to decrypt the third encryption result, obtaining the shared key; the key center then uses its transmission key, shared with the third terminal, to encrypt the shared key, thereby obtaining the second encryption result. The server receives the second encryption result sent by the key center; the third terminal receives the second encryption result sent by the server; the third terminal decrypts the second encryption result using its shared transmission key with the key center to obtain the shared key. The third terminal's shared transmission key with the key center can be used as the third transmission key. This shared key can be used in sessions established with the first or second terminal that are currently in a call.
[0211] In this embodiment, to achieve a secure encrypted session between the first terminal or the second terminal and the third terminal, a first node receives a first request sent by the first terminal, which includes a first encryption result. The first node then sends a second request to the second node based on the first request, the second request being used to request a key. The second node verifies the legitimacy of the first terminal's identity based on the first encryption result. After the legitimacy verification is completed, the key center creates a second encryption result based on the shared key. The third terminal obtains the shared key based on the second encryption result, and thus, the third terminal can join the session between the first terminal and the second terminal based on the shared key. The shared key remains encrypted throughout the communication process; from the first terminal to the second node, and then to the third terminal, each step is transmitted in encrypted form, effectively preventing key leakage. This dual verification mechanism ensures that only legitimate terminals can initiate service forwarding requests, enhancing the security of multi-terminal sessions.
[0212] In one possible design, based on the above embodiments, the method further includes:
[0213] The system receives a third request sent by the first terminal. The third request is used to request the establishment of a session. The third request includes a fourth encryption result, which is used to indicate the identity information of the first terminal and the identity information of the second terminal.
[0214] A fourth request is sent to the second node based on the third request. The fourth request is used to request the key and includes the fourth encryption result.
[0215] The third encryption result and the fifth encryption result sent by the second node are received, and the third encryption result is sent to the first terminal and the fifth encryption result is sent to the second terminal respectively. The third encryption result is obtained by the second node encrypting the shared key according to the first transmission key shared by the first terminal and the second node. Both the third encryption result and the fifth encryption result are used to indicate the shared key.
[0216] The third request is sent before the first request and is used for session establishment.
[0217] Specifically, the first terminal requests the server to establish a session with the second terminal. The first terminal's cryptographic module uses a first transmission key to encrypt the identity information of both the first and second terminals, generating a fourth encryption result. The server receives a third request sent by the first terminal, identifies it as a service forwarding request through message parsing, and carries the fourth encryption result. The server sends a fourth request to the key center, which identifies it as a key request through message parsing, and carries the fourth encryption result. The key request is for the creation of third and fifth encryption results. The key center matches the first and second transmission keys from its encryption module. The key center decrypts the fourth encryption result using its transmission key with the first terminal to authenticate the session terminals, confirming the legitimacy of both the first and second terminals. After verifying the legitimacy of the session terminals, the key center creates a shared key between the first and second terminals. The key center uses its first transmission key with the first terminal to encrypt the shared key, thus obtaining the third encryption result. The first terminal receives the third encryption result sent by the server; the key center uses its transmission key with the second terminal to encrypt the shared key, thus obtaining the fifth encryption result. The second terminal receives the fifth encryption result sent by the key center through the server.
[0218] In this embodiment, during the encrypted session between the first and second terminals, to ensure the security of communication between them, the second node needs to decrypt the fourth encryption result using the first transmission key to verify the legitimacy of both terminals before creating a shared key. To ensure the security of the shared key transmission, the shared key is encrypted using the first transmission key to generate a third encryption result; then, the shared key is encrypted using the second transmission key to generate a fifth encryption result, which is then transmitted to the corresponding terminal via the first node. This effectively improves the security of the session transmission. Since different transmission paths correspond to different key results, only by obtaining the key information from both terminals can the session content be cracked, thereby reducing the risk of key leakage.
[0219] In one possible design, this application provides a communication method comprising the following steps:
[0220] Step S1: The first terminal sends a third request to the first node, so that the first node sends a fourth request to the second node based on the third request. The third request is used to request session establishment, and the fourth request is used to request a key and carries a fourth encryption result.
[0221] In step S2, the second node confirms the identity information of the first terminal and the second terminal based on the fourth encryption result.
[0222] In step S3, the second node creates a shared key between the first terminal and the second terminal, and generates a third encryption result and a fifth encryption result. The first node receives the third encryption result and the fifth encryption result sent by the second node to the first terminal and the second terminal.
[0223] In step S4, the first terminal and the third terminal decrypt the third encryption result and the fifth encryption result using the transmission key to obtain the shared key, thereby enabling the first terminal and the second terminal to have a session.
[0224] In step S5, the first terminal requests to join a session with the third terminal at the first node and creates a first encrypted result for the first node; it also sends a first request to the server, and the first node sends a second request to the second node. Both the first and second requests carry the first encrypted result.
[0225] In step S6, the second node verifies the legitimacy of the first terminal based on the first encryption result and decrypts the shared key based on the first transmission key.
[0226] Step S7: The second node confirms the second encryption result based on the shared key.
[0227] In step S8, the first node receives the second encryption result sent by the second node and sends it to the third terminal.
[0228] In step S9, the third terminal receives the second encryption result sent by the first node and decrypts the second encryption result to obtain the shared key. Using the shared key, the third terminal can join the session between the first and second terminals.
[0229] In this embodiment, the implementation method and technical effect of steps S1-S9 are similar to the implementation method of the corresponding scheme in the above embodiments, and will not be repeated here.
[0230] Figure 7 This is a schematic diagram of the structure of a communication device provided in one embodiment of this application. The communication device provided in this embodiment is located in a communication equipment. The communication equipment can be an electronic device. The fraud transaction identification device 700 provided in this embodiment includes: a processing module 701 and a sending module 702.
[0231] The processing module 701 is used to conduct encrypted calls with the second terminal based on the shared key between the two terminals;
[0232] Processing module 701 is further configured to determine a first encryption result, the first encryption result being associated with a shared key;
[0233] The sending module 702 is used to send a first request to a first node, so that the first node sends a second request to a second node according to the first request. The first request is used to request service forwarding, and the second request is used to request a key. Both the first request and the second request include a first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal. When verifying the legitimacy of the first terminal, the second encryption result is sent to the third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key. The shared key is used by the third terminal to conduct encrypted calls with at least one of the first terminal and the second terminal.
[0234] In one possible design, the processing module 701 includes: a first encryption result determination unit, configured to encrypt the identity information of the third terminal and the third encryption result received from the first node according to the first transmission key shared by the first terminal and the second node, to obtain a first encryption result; wherein the third encryption result is used to indicate the shared key.
[0235] In one possible design, the sending module 702 includes: a third request sending unit, used to send a third request to the first node so that the first node sends a fourth request to the second node according to the third request. The third request is used to request session establishment, and the fourth request is used to request a key. Both the third request and the fourth request include a fourth encryption result, and the fourth encryption result is used to indicate the identity information of the first terminal and the identity information of the second terminal.
[0236] The third encryption result receiving unit is used to receive the third encryption result sent by the first node. The third encryption result is obtained by the second node encrypting the shared key according to the first transmission key. The shared key is determined by the second node.
[0237] The shared key unit is used to decrypt the third encryption result according to the first transmission key to obtain the shared key; wherein, the shared key is used by the second terminal to decrypt the fifth encryption result according to the second transmission key shared by the second terminal and the second node, and the fifth encryption result is obtained by the second node encrypting the shared key according to the second transmission key.
[0238] In one possible design, the processing module 701 includes: a first encryption result determination unit, which encrypts the shared key and the identity information of the third terminal according to the first transmission key shared by the first terminal and the second node to obtain the first encryption result.
[0239] In one possible design, the processing module 701 includes: a fourth encryption result determination unit, used to encrypt the identity information of the first terminal and the identity information of the second terminal according to the first transmission key, to obtain a fourth encryption result.
[0240] In one possible design, the second encryption result is obtained by the second node encrypting a shared key using a third transmission key shared between the third terminal and the second node. The shared key is obtained by the second node decrypting the first encryption result using a first transmission key shared between the first terminal and the second node.
[0241] In one possible design, the processing module 701 includes a call unit for making encrypted calls with a third terminal based on a shared key; or, making encrypted calls with a second terminal and a third terminal respectively based on a shared key.
[0242] Figure 8 This is a schematic diagram of the structure of a communication device provided in another embodiment of this application. The communication device provided in this embodiment is located in a communication equipment. The communication equipment can be an electronic device. The fraud transaction identification device 800 provided in this embodiment includes: a receiving module 801, a processing module 802, and a sending module 803.
[0243] The receiving module 801 is used to receive a second request sent by the first node during an encrypted call between the first terminal and the second terminal based on a shared key. The second request is used to request a key and includes a first encryption result, which is associated with the shared key.
[0244] The processing module 802 is used to perform legal verification on the first terminal based on the first encryption result;
[0245] The sending module 803 is used to send a second encryption result to the third terminal through the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key.
[0246] The shared key is used for encrypted calls between the third terminal and at least one of the first and second terminals.
[0247] In one possible design, the processing module 802 is used to determine that the first terminal is legitimate if the first encryption result is successfully decrypted based on the first transmission key shared by the first terminal and the second node.
[0248] In one possible design, the sending module 803 is used to determine the second encryption result if the first terminal is verified to be legitimate; and send the second encryption result to the first node so that the first node sends the second encryption result to the third terminal.
[0249] In one possible design, the sending module 803 includes a shared key determination unit, used to decrypt the first encryption result according to the first transmission key shared by the first terminal and the second node to obtain a third encryption result, and to decrypt the third encryption result according to the first transmission key to obtain a shared key; or, to decrypt the first encryption result according to the first transmission key shared by the first terminal and the second node to obtain a shared key.
[0250] The second encryption result determination unit encrypts the shared key based on the third transmission key shared by the third terminal and the second node to obtain the second encryption result.
[0251] In one possible design, the receiving module 801 includes a fourth encryption result determination unit for receiving a fourth request sent by the first node, the fourth request being for requesting a key and including a fourth encryption result.
[0252] The terminal identity information determination unit is used to decrypt the fourth encryption result based on the first transmission key shared by the first terminal and the second node to obtain the identity information of the first terminal and the identity information of the second terminal.
[0253] A shared key unit is used to determine a shared key between the first terminal and the second terminal based on the identity information of the first terminal and the identity information of the second terminal.
[0254] The third encryption result determination unit is used to encrypt the shared key according to the first transmission key to obtain a third encryption result, and send the third encryption result to the first terminal through the first node.
[0255] The fifth encryption result determination unit is used to encrypt the shared key according to the second transmission key shared by the second terminal and the second node to obtain the fifth encryption result, and send the fifth encryption result to the second terminal through the first node.
[0256] Figure 9 This is a schematic diagram of a communication device provided in another embodiment of this application. The communication device provided in this embodiment is located in a communication equipment. The communication equipment can be an electronic device. The fraud transaction identification device 900 provided in this embodiment includes: a receiving module 901 and a sending module 902.
[0257] The receiving module 901 is used to receive a first request sent by the first terminal. The first request is used to request service forwarding. The first request includes a first encryption result, which is determined by the first terminal during the encrypted call between the first terminal and the second terminal based on a shared key.
[0258] The sending module 902 is used to send a second request to the second node according to the first request. The second request is used to request a key and includes a first encryption result. The first encryption result is used by the second node to perform legitimate verification of the first terminal.
[0259] The sending module 902 is also used to send the second encryption result to the third terminal when it receives the second encryption result sent by the second node. The second encryption result is sent by the second node to the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key. The shared key is used by the third terminal to conduct encrypted calls with at least one of the first terminal and the second terminal.
[0260] The receiving module 901 includes a third request unit for receiving a third request sent by the first terminal. The third request is used to request session establishment. The third request includes a fourth encryption result, which is used to indicate the identity information of the first terminal and the identity information of the second terminal.
[0261] The fourth request unit sends a fourth request to the second node based on the third request. The fourth request is used to request a key and includes a fourth encryption result.
[0262] The shared key unit receives the third encryption result and the fifth encryption result sent by the second node, and sends the third encryption result to the first terminal and the fifth encryption result to the second terminal, respectively. The third encryption result is obtained by the second node encrypting the shared key according to the first transmission key shared by the first terminal and the second node. Both the third encryption result and the fifth encryption result are used to indicate the shared key.
[0263] Figure 10 This is a schematic diagram of the structure of a communication system provided in an embodiment of this application. The communication system structure provided in this embodiment includes: a first terminal, a second terminal, a third terminal, a first node, and a second node.
[0264] It should be noted that the communication system provided in this application can implement all the method steps implemented in the above-described communication method embodiments and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiments will not be described in detail here.
[0265] Figure 11 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, as shown below. Figure 11 As shown, the electronic device 1100 provided in this embodiment includes: a processor 1101 and a memory 1102 communicatively connected to the processor.
[0266] The memory 1102 is used to store computer execution instructions; the processor 1101 is used to execute the computer execution instructions stored in the memory 1102 to implement the communication method provided in any of the above embodiments. For details, please refer to the relevant descriptions in the above method embodiments, which will not be elaborated upon here.
[0267] The program may include program code, which includes computer-executable instructions. Memory 1102 may include high-speed RAM, and may also include non-volatile memory, such as at least one disk storage device.
[0268] In this embodiment, the memory 1102 and the processor 1101 are connected via a bus. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 11 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0269] This application also provides a computer-readable storage medium storing computer-executable instructions. When executed by a processor, these instructions are used to implement the communication method provided in any of the above embodiments. For example, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, or optical data storage device.
[0270] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the communication method identification method provided in any of the above embodiments.
[0271] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0272] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0273] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0274] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0275] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0276] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0277] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as these combinations of technical features do not contradict each other, they should be considered within the scope of this specification. Those skilled in the art, upon considering the specification and practicing the invention disclosed herein, will readily conceive of other embodiments of this application. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary technical means in the art not disclosed in this application. The specification and embodiments are considered exemplary only, and the true scope and spirit of this application are indicated by the following claims. It should be understood that this application is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A communication method, characterized in that, Applied to a first terminal, the method includes: Encrypted calls are made with the second terminal based on the shared key between the two terminals; Determine a first encryption result, which is associated with the shared key; A first request is sent to a first node, so that the first node sends a second request to a second node based on the first request. The first request is used to request service forwarding, and the second request is used to request a key. Both the first request and the second request include the first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal. When verifying the legitimacy of the first terminal, the second encryption result is sent to a third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key. The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
2. The method according to claim 1, characterized in that, Determining the first encryption result includes: Based on the first transmission key shared by the first terminal and the second node, the identity information of the third terminal and the third encryption result received from the first node are encrypted to obtain the first encryption result; The third encryption result is used to indicate the shared key.
3. The method according to claim 1 or 2, characterized in that, The method further includes: A third request is sent to the first node, so that the first node sends a fourth request to the second node according to the third request. The third request is used to request session establishment, and the fourth request is used to request a key. Both the third and fourth requests include the fourth encryption result, and the fourth encryption result is used to indicate the identity information of the first terminal and the identity information of the second terminal. The third encryption result sent by the first node is received. The third encryption result is obtained by the second node encrypting the shared key according to the first transmission key. The shared key is determined by the second node. The third encryption result is decrypted based on the first transmission key to obtain the shared key; wherein, the shared key is used by the second terminal to decrypt the fifth encryption result based on the second transmission key shared by the second terminal and the second node, and the fifth encryption result is obtained by the second node encrypting the shared key based on the second transmission key.
4. The method according to claim 1, characterized in that, Determining the first encryption result includes: Based on the first transmission key shared by the first terminal and the second node, the shared key and the identity information of the third terminal are encrypted to obtain the first encryption result.
5. The method according to claim 3, characterized in that, The method further includes: Based on the first transmission key, the identity information of the first terminal and the identity information of the second terminal are encrypted to obtain the fourth encryption result.
6. The method according to claim 1 or 2, characterized in that, The second encryption result is obtained by the second node encrypting the shared key according to the third transmission key shared by the third terminal and the second node. The shared key is obtained by the second node decrypting the first encryption result according to the first transmission key shared by the first terminal and the second node.
7. The method according to claim 1 or 2, characterized in that, The method further includes: Based on the shared key, an encrypted call is made with the third terminal; or... Based on the shared key, encrypted calls are made with the second terminal and the third terminal, respectively.
8. A communication method, characterized in that, Applied to the second node, the method includes: During an encrypted call between a first terminal and a second terminal based on a shared key, a second request is received from a first node. The second request is used to request a key and includes a first encryption result, which is associated with the shared key. Based on the first encryption result, the first terminal is verified to be legitimate; If the first terminal is verified to be legitimate, a second encryption result is sent to the third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key. The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
9. The method according to claim 8, characterized in that, The step of verifying the legitimacy of the first terminal based on the first encryption result includes: If the first encryption result is successfully decrypted based on the first transmission key shared by the first terminal and the second node, the first terminal is determined to be legitimate.
10. The method according to claim 8 or 9, characterized in that, If the first terminal is verified to be legitimate, then sending the second encryption result to the third terminal through the first node includes: If the first terminal is verified to be legitimate, then the second encryption result is determined; The second encryption result is sent to the first node, so that the first node sends the second encryption result to the third terminal.
11. The method according to claim 10, characterized in that, Determining the second encryption result includes: Based on the first transmission key shared by the first terminal and the second node, the first encryption result is decrypted to obtain a third encryption result, and based on the first transmission key, the third encryption result is decrypted to obtain the shared key; or, based on the first transmission key shared by the first terminal and the second node, the first encryption result is decrypted to obtain the shared key. The shared key is encrypted using the third transmission key shared by the third terminal and the second node to obtain the second encryption result.
12. The method according to claim 8 or 9, characterized in that, The method further includes: Receive a fourth request sent by the first node, the fourth request being used to request a key, the fourth request including a fourth encryption result; Based on the first transmission key shared by the first terminal and the second node, the fourth encryption result is decrypted to obtain the identity information of the first terminal and the identity information of the second terminal; The shared key between the first terminal and the second terminal is determined based on the identity information of the first terminal and the identity information of the second terminal; The third encryption result is obtained by encrypting the shared key according to the first transmission key, and the third encryption result is sent to the first terminal through the first node. The fifth encryption result is obtained by encrypting the shared key according to the second transmission key shared by the second terminal and the second node, and the fifth encryption result is sent to the second terminal through the first node.
13. A communication method, characterized in that, Applied to the first node, the method includes: The system receives a first request sent by a first terminal, the first request being used to request service forwarding, the first request including a first encryption result, the first encryption result being determined by the first terminal during an encrypted call between the first terminal and the second terminal based on a shared key; Based on the first request, a second request is sent to the second node. The second request is used to request a key. The second request includes the first encryption result. The first encryption result is used by the second node to perform legitimate verification of the first terminal. If the second encryption result is received from the second node, the second encryption result is sent to the third terminal. The second encryption result is sent by the second node to the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key. The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
14. The method according to claim 13, characterized in that, The method further includes: The system receives a third request sent by the first terminal, the third request being used to request session establishment, the third request including a fourth encryption result, the fourth encryption result being used to indicate the identity information of the first terminal and the identity information of the second terminal; A fourth request is sent to the second node according to the third request. The fourth request is used to request a key and includes the fourth encryption result. The third encryption result and the fifth encryption result sent by the second node are received, and the third encryption result is sent to the first terminal and the fifth encryption result is sent to the second terminal, respectively. The third encryption result is obtained by the second node encrypting the shared key according to the first transmission key shared by the first terminal and the second node. Both the third encryption result and the fifth encryption result are used to indicate the shared key.
15. A communication device, characterized in that, Applied to a first terminal, the device includes: The processing module is used to conduct encrypted calls with the second terminal based on a shared key between the two terminals. The processing module is further configured to determine a first encryption result, the first encryption result being associated with the shared key; The sending module is used to send a first request to a first node, so that the first node sends a second request to a second node according to the first request. The first request is used to request service forwarding, and the second request is used to request a key. Both the first request and the second request include the first encryption result. The first encryption result is used by the second node to verify the legitimacy of the first terminal. When verifying the legitimacy of the first terminal, the second encryption result is sent to a third terminal through the first node. The second encryption result is used by the third terminal to determine the shared key. The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
16. A communication device, characterized in that, Applied to the second node, the device includes: The receiving module is configured to receive a second request sent by a first node during an encrypted call between a first terminal and a second terminal based on a shared key. The second request is used to request a key and includes a first encryption result, which is associated with the shared key. The processing module is used to perform a legality verification on the first terminal based on the first encryption result; The sending module is used to send a second encryption result to a third terminal through the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key. The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
17. A communication device, characterized in that, Applied to the first node, the device includes: The receiving module is used to receive a first request sent by a first terminal. The first request is used to request service forwarding. The first request includes a first encryption result, which is determined by the first terminal during an encrypted call between the first terminal and the second terminal based on a shared key. The sending module is configured to send a second request to the second node according to the first request. The second request is used to request a key and includes the first encryption result. The first encryption result is used by the second node to perform legitimate verification on the first terminal. The sending module is further configured to send the second encryption result to the third terminal when it receives the second encryption result sent by the second node. The second encryption result is sent by the second node to the first node when verifying the legitimacy of the first terminal. The second encryption result is used by the third terminal to determine the shared key. The shared key is used for encrypted calls between the third terminal and at least one of the first terminal and the second terminal.
18. A communication system, characterized in that, This includes a first terminal, a second terminal, a third terminal, a first node, and a second node; Wherein, the first terminal is used to execute the communication method as described in any one of claims 1 to 7; The second node is used to perform the communication method as described in any one of claims 8-12; The first node is used to perform the communication method as described in claim 13 or 14; The second terminal is used to decrypt the fifth encryption result sent by the first node according to the second transmission key shared by the second terminal and the second node, so as to obtain the shared key; The third terminal is used to decrypt the second encryption result sent by the first node according to the first transmission key shared by the third terminal and the second node, so as to obtain the shared key.
19. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the communication method as described in any one of claims 1 to 14.
20. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, implement the communication method as described in any one of claims 1 to 14.
21. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the communication method as described in any one of claims 1 to 14.