A chip-based method for recovering a key after a terminal power-off restart
Patent Information
- Application Number
- CN202611037388.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-13
- Publication Date
- 2026-09-15
AI Technical Summary
迄今为止,尚未见有方案能够同时兼顾上述三项需求,这也正是本发明旨在克服的现有技术缺陷所在
[0046]1. This invention only writes the root key ciphertext and subsequent plaintext master access key to the Flash when the terminal first accesses the network. During normal communication, a large number of temporary key files are stored in RAM. The key recovery process after power failure and restart does not require additional erase and write operations to the Flash. Only after the second successful access is performed, the master access key is updated and written once. This invention significantly reduces the frequency of Flash erase and write operations, effectively delays the performance degradation of the storage medium, and ensures the long-term reliable operation of the security chip.
Smart Images

Figure CN122764488A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum secure communication technology, and in particular to a chip-based method for key recovery after a terminal power failure and restart. Background Technology
[0002] In applications with stringent key security requirements, such as quantum secure communication and high-level encrypted private networks, terminal devices typically embed dedicated security chips to handle the permanent storage of root keys and various cryptographic operations. Current mainstream designs store core long-term keys, such as the root key, in Flash-type non-volatile memory within the security chip, leveraging its power-off retention capability to ensure the persistent availability of critical key materials. However, the physical characteristics of Flash memory limit its rewrite cycles, typically to tens of thousands to hundreds of thousands. Frequently writing session keys or pairing temporary keys that require high-frequency changes to Flash significantly accelerates the performance degradation of the storage medium, potentially leading to premature memory block failure and impacting the overall chip lifespan. Therefore, the industry generally stores dynamically generated communication pairing keys in the chip's Random Access Memory (RAM) working memory to circumvent the limitations of Flash's rewrite endurance.
[0003] However, RAM is a volatile storage medium, and its contents are immediately lost when the terminal device experiences an abnormal power outage, system crash, or software reset. Once the terminal restarts, all communication key materials previously residing in RAM are lost, and the encrypted communication link between the terminal and the aggregated security gateway is immediately interrupted. During the restart and recovery phase, since there are no usable keys in RAM, the terminal cannot use the previously paired keys to complete the secure handshake. Existing solutions to this problem typically follow this approach:
[0004] The root key plaintext, stored in Flash memory, or a static key derived from the root key using a fixed algorithm, is directly invoked to perform the access authentication and key negotiation process after a reboot. While this approach can quickly restore communication, the root key or its fixed derived key is reused multiple times during reboots, significantly increasing the key reuse window. Attackers can then use methods such as traffic interception, replay attacks, and side-channel analysis to accumulate sufficient effective information, thereby increasing the success rate of cracking the key and severely weakening the overall security of the system.
[0005] In summary, existing key management architectures consistently struggle to achieve a balance between protecting Flash write / erase cycles, ensuring rapid key recovery after reboot, and mitigating security risks associated with key reuse. Specifically, ensuring that the terminal can independently and securely regain a usable communication key after a power outage and reboot without triggering frequent Flash write / erase cycles, while simultaneously preventing the root key from being exposed to security risks due to repeated use, remains a critical technical challenge in the field of key management for high-security terminal devices. To date, no solution has been found that simultaneously addresses all three requirements, which is precisely the deficiency in existing technologies that this invention aims to overcome. Summary of the Invention
[0006] Purpose of the invention: This application provides a chip-based method for key recovery after a terminal power failure and restart to solve the problems mentioned in the background art.
[0007] Technical Solution: This invention provides a chip-based method for key recovery after a terminal power failure and restart. The participants in the method include: a terminal containing a chip, an aggregated security gateway, a root key center, and a key center. The method includes:
[0008] Step 1: The root key center generates a set of root keys for the terminal and encrypts and writes them into the terminal;
[0009] Step 2: When the terminal is put into use for the first time, it requests the root key center to perform the first access operation through the aggregated security gateway. After the root key center authenticates the terminal's first access, the terminal decrypts and obtains the root key, and then edits the chip's storage space.
[0010] Step 3: After the terminal is powered off and restarted, it requests a secondary access operation from the aggregated security gateway. After the secondary access authentication of the aggregated security gateway is successful, it triggers a key download process from the key center to obtain a new communication key file and sends it to the terminal. The terminal updates the chip's storage space based on the new communication key file.
[0011] As an improvement to the present invention, the specific process of step 1 includes:
[0012] The terminal sends its device ID to the root key center via the aggregated security gateway to request the corresponding root key. The root key center generates a set of root keys for the terminal based on the device ID, denoted as the initial root key file file0 and the backup root key file file1. The root key center generates encryption keys k00 and k01 locally and performs encryption operations on the initial root key file file0 and the backup root key file file1 respectively, resulting in the initial root key ciphertext FILE0 = file0 ⊕ k00 and the backup root key ciphertext FILE1 = file1 ⊕ k01. The root key center sends the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 to the terminal, and the terminal's chip writes them into the local flash memory.
[0013] The root key center associates and stores the device ID with the initial root key file file0 and the backup root key file file1, the encryption key k00, the encryption key k01, the initial root key ciphertext FILE0, and the backup root key ciphertext FILE1 locally to form the first association information.
[0014] As an improvement to the present invention, the specific process of step 2 includes:
[0015] Step 2-1: When the terminal's chip is first put into use, it generates a hash function locally, calculates the first hash value H1 of the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1, records the first hash value parameter string str1 and the input random number s1, and generates the first access request req1, which is sent to the root key center via the aggregated security gateway.
[0016] Step 2-2: The root key center receives the first access request req1, obtains the device ID', hash value H1', hash value parameter string str1', and input random number s1', and uses the device ID' as an index to address the corresponding initial root key ciphertext FILE0 and backup root key ciphertext FILE1, and performs authentication operation on the first access of the terminal;
[0017] Steps 2-3: In response to the message indicating successful initial access authentication, the terminal performs the decryption operation of the root key ciphertext to obtain the initial root key file file0 and the backup root key file file1 in plaintext state, and proceeds to the next step;
[0018] In response to the message of failure of the first access authentication, the terminal erases the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 burned in the flash memory locally. The terminal's first access to the root key fails, and it returns to step 1 to re-request the root key from the root key center.
[0019] Steps 2-4: The terminal edits the chip's storage space: the flash storage space is divided into a root key pool, a paired primary access key pool, and a backup access key pool; a paired key pool is allocated from the memory storage space.
[0020] The terminal writes the initial root key file file0 into the primary access key pool in flash memory as the primary access key file, renumbers it as index0, and sends the index0 indicating the number of the initial root key file file0 to the aggregated security gateway. The aggregated security gateway updates the correspondence between the index0 and the initial root key file file0 locally; the backup access key pool is empty.
[0021] The terminal writes the backup root key file file1 into the pairing key pool in memory as the initial communication key file ckfile0.
[0022] As an improvement to the present invention, the specific process of step 2-1 includes:
[0023] The chip generates an irreducible polynomial p1(x) locally and obtains an input random number s1 from the local source. The string consisting of the coefficients of each term in the irreducible polynomial p1(x), excluding the highest term, is denoted as str1. The chip uses the irreducible polynomial p1(x) and the input random number s1 to generate the first hash function h. p1,s1 The initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 are input into the first hash function h. p1,s1 The first hash value H1=h is obtained. p1,s1 (FILE0, FILE1); Record the string str1 and the input random number s1 as the first hash value parameter;
[0024] The terminal generates an initial access request req1 based on the device ID, the first hash value H1, the first hash value parameter string str1, and the input random number s1, and sends it to the root key center via the aggregated security gateway to request the execution of the initial access operation.
[0025] As an improvement to the present invention, the specific process of step 2-2 includes:
[0026] The root key center generates a hash function h based on the string str1' and the input random number s1'. p1’,s1’ Input the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 into the hash function h. p1’,s1’ Calculate the hash value H1''=h p1’,s1’ (FILE0,FILE1);
[0027] The root key center compares the received hash value H1' with the calculated hash value H1'': if they match, the initial access authentication is successful, an access code RID is generated for the device, and updated to the first association information. The access code RID, encryption key k00, and encryption key k01 are sent to the terminal via the aggregated security gateway. The device ID, access code RID, initial root key file file0, and backup root key file file1 are also sent to the aggregated security gateway, which stores them locally. Otherwise, the initial access authentication fails, and the result of the initial access authentication failure is sent to the terminal via the aggregated security gateway.
[0028] As an improvement of the present invention, in steps 2-3, the specific process by which the terminal performs the decryption operation of the root key ciphertext to obtain the initial root key file file0 and the backup root key file file1 in plaintext state includes:
[0029] Based on the message indicating successful initial access authentication, the terminal obtains the network access code RID', decryption key k00, and decryption key k01. Using decryption key k00' and decryption key k01', the terminal performs decryption operations on the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 in flash memory, respectively, to obtain the initial root key file file0 and the backup root key file file1 in plaintext state.
[0030] As an improvement to the present invention, step 2 further includes:
[0031] When the terminal does not experience a power outage and restart, the terminal monitors the key usage of the initial communication key file ckfile0. When the key usage of the initial communication key file ckfile0 reaches the threshold M, the terminal requests the key center to download a new communication key file to supplement the pairing key pool via the aggregated security gateway.
[0032] As an improvement of the present invention, in step 3, the specific process of requesting a secondary access operation from the aggregated security gateway after the terminal is powered off and restarted includes:
[0033] Whenever the terminal experiences a power outage and restart, the terminal's chip's flash reads the primary access key file from the primary access key pool and pushes it into the pairing key pool in memory as the second communication key file. This second communication key file is the initial root key file file0, and a secondary access request req2 is generated.
[0034] The chip generates an irreducible polynomial p2(x) locally and obtains an input random number s2 from the local source. The string representing the coefficients of each term in the irreducible polynomial p2(x), excluding the highest term, is denoted as str2. The chip uses the irreducible polynomial p2(x) and the input random number s2 to generate a second hash function h. p2,s2Input the second communication key file into the second hash function h p2,s2 The second hash value H2 = h is obtained. p2,s2 (file0); Record the string str2 and the input random number s2 as the second hash value parameter;
[0035] The terminal obtains the communication key K2 from the second communication key file and records the index idx-K2 of the communication key K2 in file0; it uses the communication key K2 to perform encryption operations on the network access code RID, device ID, second hash value H2, second hash value parameter string str2 and input random number s2 to obtain secondary access information mes2=[RID, ID, H2, str2, s2]⊕K2; it merges the secondary access information mes2, number index0 and index idx-K2 to generate a secondary access request req2 and sends it to the aggregated security gateway.
[0036] As an improvement of the present invention, in step 3, after the secondary access authentication of the aggregated security gateway is passed, the specific process of triggering the key download process from the key center to obtain a new communication key file and sending it to the terminal includes:
[0037] The aggregated security gateway performs secondary access authentication based on the secondary access request req2:
[0038] (a1) The aggregated security gateway learns from index0 that the second communication key file currently used by the terminal is the initial root key file file0. Then, it deletes the backup root key file file1 corresponding to the device ID locally, and obtains the decryption key K2' from the initial root key file file0 based on index idx-K2'. It performs a decryption operation on the secondary access information mes2' to obtain the network access code RID', device ID', hash value H2', hash value parameter string str2' and input random number s2'. It compares whether the network access code RID corresponding to the local device ID is consistent with the received network access code RID'. If yes, it proceeds to step (a2); otherwise, the terminal's secondary access request fails, all key files in the local flash and memory are cleared, and it returns to step 1 to request the root key again.
[0039] (a2) The aggregated security gateway generates a hash function h based on the string str2' and the input random number s2'. p2’,s2’ Input the locally stored initial root key file file0 into the hash function h p2’,s2’ Calculate the hash value H2''=h p2’,s2’ (file0);
[0040] The aggregated security gateway compares the received hash value H2' with the calculated hash value H1'': if they match, the secondary access authentication passes; otherwise, the secondary access authentication fails, and the aggregated security gateway sends the result of the secondary access authentication failure to the terminal. The terminal clears all key files in its local flash and memory and returns to step 1 to request the root key again.
[0041] Based on the successful secondary access authentication, the aggregated security gateway requests the download of the first communication key file ckfile1 to the nth communication key file ckfilen from the key center, where n≥2. It obtains encryption keys k1 to kn from the initial root key file file0, records the indices idx-k1 to idx-kn of the encryption keys k1 to kn in the initial root key file file0, and encrypts the first communication key file ckfile1 to the nth communication key file ckfilen using the encryption keys k1 to kn to obtain the ciphertext of the first communication key file CKFILE1 to the nth communication key file ciphertext CKFILEn. It then sends the first communication key file ciphertext CKFILE1 to the nth communication key file ciphertext CKFILEn and the indices idx-k1 to idx-kn to the terminal.
[0042] As an improvement of the present invention, in step 3, the specific process of the terminal updating the chip's storage space based on the new communication key file includes:
[0043] The terminal obtains the first communication key file ciphertext CKFILE1' to the nth communication key file ciphertext CKFILEn' and the indices idx-k1' to idx-kn'. Based on the indices idx-k1' to idx-kn', it obtains the decryption keys k1' to kn' from the second communication key file in the paired key pool in memory. It then performs a decryption operation on the first communication key file ciphertext CKFILE1' to the nth communication key file ciphertext CKFILEn' to obtain the first communication key file ckfile1' to the nth communication key file ckfilen'.
[0044] The terminal selects the first communication key file ckfile1' from the communication key files ckfile1' to ckfilen' or arbitrarily selects the m-th communication key file ckfilem' and writes it into the main access key pool in flash as the new main access key file, where 1≤m≤n. The original main access key files in the main access key pool are pushed into the backup access key pool as backup access key files, and the remaining communication key files are written into the communication key pool in memory as updated communication key files.
[0045] Beneficial effects:
[0046] 1. This invention only writes the root key ciphertext and subsequent plaintext master access key to the Flash when the terminal first accesses the network. During normal communication, a large number of temporary key files are stored in RAM. The key recovery process after power failure and restart does not require additional erase and write operations to the Flash. Only after the second successful access is performed, the master access key is updated and written once. This invention significantly reduces the frequency of Flash erase and write operations, effectively delays the performance degradation of the storage medium, and ensures the long-term reliable operation of the security chip.
[0047] 2. After a power outage and restart, the terminal uses the primary access key file (i.e., the initial root key file) stored in Flash as a temporary second communication key to perform secondary access authentication. This process only involves comparing the hash value of the root key file and does not directly transmit the root key plaintext. After successful authentication, the key center immediately issues a new communication key file to replace the original primary access key, ensuring that the root key material completes its mission after one authentication and will not be used for any subsequent access operations, thus eliminating the security vulnerability of key reuse from the root. After a power outage and restart, the terminal can independently construct a secondary access request based on the primary access key file stored in Flash. The aggregated security gateway can complete access authentication locally based on the second association information stored during the first access, without needing to interact with the root key center again. This significantly reduces the processing burden of the root key center, reduces signaling transmission latency, and improves the communication recovery efficiency after the terminal restarts.
[0048] 4. This invention divides the Flash storage space into a root key pool, a primary access key pool, and a backup access key pool, and divides the memory storage space into paired key pools to form a multi-level key storage system. When the primary access key is updated, the original primary access key is automatically downgraded to a backup access key and stored in the backup access key pool. Even if the new primary access key fails to be written to disk, the terminal can still call the backup key to perform access, effectively avoiding the risk of the terminal being permanently disconnected from the network due to a single write failure, and greatly improving the fault tolerance of the system. Attached Figure Description
[0049] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0050] Figure 1 This is a schematic diagram showing the connections between the participants in the method of this application;
[0051] Figure 2 This is a flowchart illustrating the method described in this application;
[0052] Figure 3This is a schematic diagram of the storage space of the terminal chip after the initial access of this application;
[0053] Figure 4 This is a schematic diagram of the storage space of the terminal chip during power failure and restart in this application;
[0054] Figure 5 This is a schematic diagram of the storage space of the terminal chip after secondary access in this application. Detailed Implementation
[0055] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0056] In view of the problems mentioned in the background art, the present invention provides a key recovery method for a chip-based terminal after power failure and restart, as shown in Figure 1. The participants in the method include: a terminal containing a chip, an aggregated security gateway, a root key center, and a key center. The aggregated security gateway is sequentially communicatively connected to the root key center, the key center, and the terminal. The root key center can communicate with the key center, and the terminal can also establish a wired or wireless connection with the root key center when needed.
[0057] like Figure 2 As shown, the method of the present invention includes the following steps:
[0058] Step 1: The root key center generates a set of root keys for the terminal and encrypts and writes them into the terminal.
[0059] Specifically, the terminal sends its device ID to the root key center via the aggregated security gateway, requesting the corresponding root key. The root key center generates a set of root keys for the terminal based on the device ID. Each root key is a key file of varying size generated by the root key center for each terminal, depending on the terminal type. For terminals containing a chip, the root key is ultimately written into the chip in encrypted form. Because the terminal's chip has limited hardware resources, only one set of encrypted root key files can be written. Therefore, the root key center generates at least two root key files in this set. The first root key file is designated as the initial root key file (file0), and the remaining root key files are designated as backup root key files (file1). This does not limit the number of root key files generated. The size of each root key file is determined by considering factors such as hardware resources and terminal traffic; this file size is not limited in this invention.
[0060] Subsequently, the root key center generates encryption keys k00 and k01 locally to perform encryption operations on the initial root key file file0 and the backup root key file file1, respectively, resulting in the initial root key ciphertext FILE0 = file0 ⊕ k00 and the backup root key ciphertext FILE1 = file1 ⊕ k01. The root key center sends the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 to the terminal, and the terminal's chip writes them into its local flash memory.
[0061] As mentioned above, the root key center also needs to associate and store the device ID with the initial root key file file0 and the backup root key file file1, the encryption key k00, the encryption key k01 and the initial root key ciphertext FILE0, and the backup root key ciphertext FILE1 locally to form the first association information, which can be used to address other parameters by any parameter.
[0062] Step 2: When the terminal is put into use for the first time, it requests the root key center to perform the first access operation through the aggregated security gateway. After the root key center authenticates the terminal's first access, the terminal decrypts and obtains the root key, and then edits the chip's storage space.
[0063] Specifically, this step includes:
[0064] Step 2-1: When the terminal's chip is first put into use, it generates a hash function locally to calculate the first hash value H1 of the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1. The specific process is as follows:
[0065] The chip generates an irreducible polynomial p1(x) locally and obtains an input random number s1 from the local source. The string consisting of the coefficients of each term in the irreducible polynomial p1(x), excluding the highest term, is denoted as str1. The chip uses the irreducible polynomial p1(x) and the input random number s1 to generate the first hash function h. p1,s1 The initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 are input into the first hash function h. p1,s1 The first hash value H1=h is obtained. p1,s1 (FILE0, FILE1); Record the string str1 and the input random number s1 as the first hash value parameter.
[0066] The terminal generates an initial access request req1 based on the device ID, the first hash value H1, the first hash value parameter string str1, and the input random number s1, and sends it to the root key center via the aggregated security gateway to request the execution of the initial access operation.
[0067] Step 2-2: The root key center receives the initial access request req1, obtains the device ID', hash value H1', hash value parameter string str1', and input random number s1', and uses the device ID' as an index to address the corresponding initial root key ciphertext FILE0 and backup root key ciphertext FILE1, and performs authentication operations for the terminal's initial access:
[0068] The root key center generates a hash function h based on the string str1' and the input random number s1'. p1’,s1’ Input the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 into the hash function h. p1’,s1’ Calculate the hash value H1''=h p1’,s1’ (FILE0,FILE1);
[0069] The root key center compares the received hash value H1' with the calculated hash value H1'': if they match, the initial access authentication is successful, an access code RID is generated for the device, and updated to the first association information. The access code RID, encryption key k00, and encryption key k01 are sent to the terminal via the aggregated security gateway. The device ID, access code RID, initial root key file file0, and backup root key file file1 are also sent to the aggregated security gateway, which stores them locally. Otherwise, the initial access authentication fails, and the result of the initial access authentication failure is sent to the terminal via the aggregated security gateway.
[0070] Steps 2-3: In response to the initial successful access authentication message, the terminal performs the decryption operation of the root key ciphertext, obtaining the initial root key file file0 and the backup root key file file1 in plaintext state, and proceeds to the next step; the specific process is as follows:
[0071] Based on the successful initial access authentication message, the terminal obtains the network access code RID', decryption key k00, and decryption key k01. Using decryption key k00' and decryption key k01', the terminal performs decryption operations on the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 in flash memory, respectively, to obtain the initial root key file file0 and the backup root key file file1 in plaintext state. At this point, the initial access operation of the root key is completed.
[0072] In response to the message of initial access authentication failure, the terminal erases the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 burned into the flash memory locally. The terminal's initial access to the root key has failed, and it needs to return to step 1 to re-request the root key from the root key center.
[0073] Steps 2-4: As Figure 3As shown, the terminal edits the chip's storage space: the flash storage space is divided into a root key pool, a paired primary access key pool, and a backup access key pool; a paired key pool is allocated from the memory storage space.
[0074] The terminal writes the initial root key file file0 into the primary access key pool in flash memory as the primary access key file, renumbers it as index0, and sends the index0 indicating the initial root key file file0 to the aggregated security gateway. The aggregated security gateway updates the correspondence between the index0 and the initial root key file file0 locally, so that the index0 can clearly indicate the initial root key file file0; at this time, the backup access key pool is empty.
[0075] The terminal writes the backup root key file file1 into the pairing key pool in memory as the initial communication key file ckfile0, which is used for subsequent communication with the outside world.
[0076] During normal use of the terminal device (i.e., without power outages or restarts), the terminal uses the initial communication key file ckfile0 from the paired key pool in memory to conduct encrypted communication with the outside world. It monitors the key usage of the initial communication key file ckfile0. When the key usage of ckfile0 reaches a threshold M, it requests a new first communication key file from the key center via the aggregated security gateway to replenish the paired key pool. It should be noted that the new first communication key file should overwrite the master access key file pushed into the paired key pool.
[0077] Step 3: After the terminal is powered off and restarted, the terminal requests a secondary access operation from the aggregated security gateway. After the secondary access authentication of the aggregated security gateway is successful, it triggers a key download process from the key center to obtain a new communication key file and sends it to the terminal. The terminal updates the chip's storage space based on the new communication key file.
[0078] Specifically, after a power outage and restart, the initial communication key file ckfile0 stored in the pairing key pool in memory will be lost. This results in the terminal having no communication key to use during communication, leading to communication anomalies. Therefore:
[0079] Step 3-1: As Figure 4 As shown, whenever the terminal experiences a power outage and restart, the flash memory in the terminal's chip reads the main access key file (i.e., file0) from the main access key pool and pushes it into the pairing key pool in memory as a new communication key file, denoted as the second communication key file. The second communication key file is the initial root key file file0, and a secondary access request req2 is generated and sent to the aggregated security gateway.
[0080] The specific process of generating the secondary access request req2 includes:
[0081] The chip generates an irreducible polynomial p2(x) locally and obtains an input random number s2 from the local source. The string representing the coefficients of each term in the irreducible polynomial p2(x), excluding the highest term, is denoted as str2. The chip uses the irreducible polynomial p2(x) and the input random number s2 to generate a second hash function h. p2,s2 Input the second communication key file into the second hash function h p2,s2 The second hash value H2 = h is obtained. p2,s2 (file0); Record the string str2 and the input random number s2 as the parameters of the second hash value.
[0082] The terminal obtains the communication key K2 from the second communication key file and records the index idx-K2 of the communication key K2 in the second communication key file; it uses the communication key K2 to perform encryption operations on the network access code RID, device ID, second hash value H2, second hash value parameter string str2 and input random number s2 to obtain secondary access information mes2=[RID, ID, H2, str2,s2]⊕K2; it merges the secondary access information mes2, number index0 and index idx-K2 to generate a secondary access request req2 and sends it to the aggregated security gateway.
[0083] Step 3-2: The aggregated security gateway performs secondary access authentication based on the secondary access request req2.
[0084] (a1) Based on index0, the aggregated security gateway can know from the local storage that the second communication key file currently used by the terminal is the initial root key file file0 indicated by index0. Then, it deletes the backup root key file file1 corresponding to the device ID locally and releases the storage space. Based on index idx-K2', it obtains the decryption key K2' from the initial root key file file0 and performs a decryption operation on the secondary access information mes2' to obtain the network access code RID', device ID', hash value H2', hash value parameter string str2' and input random number s2'. It compares whether the network access code RID corresponding to the device ID on the local storage is consistent with the received network access code RID'. If yes, it proceeds to step (a2); otherwise, the terminal's secondary access request fails, and all key files in the local flash and memory need to be cleared. It then returns to step 1 to request the root key again.
[0085] (a2) The aggregated security gateway generates a hash function h based on the string str2' and the input random number s2'. p2’,s2’ Input the locally stored initial root key file file0 into the hash function h p2’,s2’Calculate the hash value H2''=h p2’,s2’ (file0);
[0086] The aggregated security gateway compares the received hash value H2' with the calculated hash value H1'': if they match, the secondary access authentication passes; otherwise, the secondary access authentication fails, and the aggregated security gateway sends the result of the secondary access authentication failure to the terminal. The terminal needs to clear all key files in its local flash and memory and return to step 1 to request the root key again.
[0087] Step 3-3: Based on the successful secondary access authentication, the aggregated security gateway requests the download of the first communication key file ckfile1 to the nth communication key file ckfilen (n≥2) from the key center. It obtains encryption keys k1 to kn from the initial root key file file0, records the indices idx-k1 to idx-kn of the encryption keys k1 to kn in the initial root key file file0, and encrypts the first communication key file ckfile1 to the nth communication key file ckfilen using the encryption keys k1 to kn to obtain the ciphertext CKFILE1 to the nth communication key file ciphertext CKFILEn. It then sends the first communication key file ciphertext CKFILE1 to the nth communication key file ciphertext CKFILEn and the indices idx-k1 to idx-kn to the terminal.
[0088] Steps 3-4: The terminal obtains the first communication key file ciphertext CKFILE1' to the nth communication key file ciphertext CKFILEn' and the indices idx-k1' to idx-kn'. Based on the indices idx-k1' to idx-kn', it obtains the decryption keys k1' to kn' from the second communication key file in the paired key pool in memory. It performs a decryption operation on the first communication key file ciphertext CKFILE1' to the nth communication key file ciphertext CKFILEn' to obtain the first communication key file ckfile1' to the nth communication key file ckfilen'.
[0089] Steps 3-5: (e.g.) Figure 5 As shown, the terminal updates its local storage space: The terminal selects the first communication key file ckfile1' from the communication key files ckfile1' to ckfilen', or arbitrarily selects the m-th communication key file ckfilem' (1≤m≤n) and writes it into the main access key pool in flash as the new main access key file (ckfile1' or ckfilem'). The original main access key file (file0) in the main access key pool is pushed into the backup access key pool as a backup access key file to avoid disk write failure and no access key available; the remaining communication key files are written into the communication key pool in memory as updated communication key files.
Claims
1. A key recovery method for a chip-based terminal after power failure and restart, characterized in that, The participants in the method include: a terminal containing a chip, an aggregated security gateway, a root key center, and a key center; the method includes: Step 1: The root key center generates a set of root keys for the terminal and encrypts and writes them into the terminal; Step 2: When the terminal is put into use for the first time, it requests the root key center to perform the first access operation through the aggregated security gateway. After the root key center authenticates the terminal's first access, the terminal decrypts and obtains the root key, and then edits the chip's storage space. Step 3: After the terminal is powered off and restarted, it requests a secondary access operation from the aggregated security gateway. After the secondary access authentication of the aggregated security gateway is successful, it triggers a key download process from the key center to obtain a new communication key file and sends it to the terminal. The terminal updates the chip's storage space based on the new communication key file.
2. The key recovery method for a chip-based terminal after power failure and restart according to claim 1, characterized in that, The specific process of step 1 includes: The terminal sends its device ID to the root key center via the aggregated security gateway to request the corresponding root key. The root key center generates a set of root keys for the terminal based on the device ID, denoted as the initial root key file file0 and the backup root key file file1. The root key center generates encryption keys k00 and k01 locally and performs encryption operations on the initial root key file file0 and the backup root key file file1 respectively, resulting in the initial root key ciphertext FILE0 = file0 ⊕ k00 and the backup root key ciphertext FILE1 = file1 ⊕ k01. The root key center sends the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 to the terminal, and the terminal's chip writes them into the local flash memory. The root key center associates and stores the device ID with the initial root key file file0 and the backup root key file file1, the encryption key k00, the encryption key k01, the initial root key ciphertext FILE0, and the backup root key ciphertext FILE1 locally to form the first association information.
3. The key recovery method for a chip-based terminal after power failure and restart according to claim 2, characterized in that, The specific process of step 2 includes: Step 2-1: When the terminal's chip is first put into use, it generates a hash function locally, calculates the first hash value H1 of the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1, records the first hash value parameter string str1 and the input random number s1, and generates the first access request req1, which is sent to the root key center via the aggregated security gateway. Step 2-2: The root key center receives the first access request req1, obtains the device ID', hash value H1', hash value parameter string str1', and input random number s1', and uses the device ID' as an index to address the corresponding initial root key ciphertext FILE0 and backup root key ciphertext FILE1, and performs authentication operation on the first access of the terminal; Steps 2-3: In response to the message indicating successful initial access authentication, the terminal performs the decryption operation of the root key ciphertext to obtain the initial root key file file0 and the backup root key file file1 in plaintext state, and proceeds to the next step; In response to the message of failure of the first access authentication, the terminal erases the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 burned in the flash memory locally. The terminal's first access to the root key fails, and it returns to step 1 to re-request the root key from the root key center. Steps 2-4: The terminal edits the chip's storage space: the flash storage space is divided into a root key pool, a paired primary access key pool, and a backup access key pool; a paired key pool is allocated from the memory storage space. The terminal writes the initial root key file file0 into the primary access key pool in flash memory as the primary access key file, renumbers it as index0, and sends the index0 indicating the number of the initial root key file file0 to the aggregated security gateway. The aggregated security gateway updates the correspondence between the index0 and the initial root key file file0 locally; the backup access key pool is empty. The terminal writes the backup root key file file1 into the pairing key pool in memory as the initial communication key file ckfile0.
4. The key recovery method for a chip-based terminal after power failure and restart according to claim 3, characterized in that, The specific process of step 2-1 includes: The chip generates an irreducible polynomial p1(x) locally and obtains an input random number s1 from the local source. The string consisting of the coefficients of each term in the irreducible polynomial p1(x), excluding the highest term, is denoted as str1. The chip uses the irreducible polynomial p1(x) and the input random number s1 to generate the first hash function h. p1,s1 The initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 are input into the first hash function h. p1,s1 The first hash value H1=h is obtained. p1,s1 (FILE0, FILE1); Record the string str1 and the input random number s1 as the first hash value parameter; The terminal generates an initial access request req1 based on the device ID, the first hash value H1, the first hash value parameter string str1, and the input random number s1, and sends it to the root key center via the aggregated security gateway to request the execution of the initial access operation.
5. The key recovery method for a chip-based terminal after power failure and restart according to claim 4, characterized in that, The specific process of step 2-2 includes: The root key center generates a hash function h based on the string str1' and the input random number s1'. p1’,s1’ Input the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 into the hash function h. p1’,s1’ Calculate the hash value H1''=h p1’,s1’ (FILE0,FILE1); The root key center compares the received hash value H1' with the calculated hash value H1'': if they match, the initial access authentication is successful, an access code RID is generated for the device, and updated to the first association information. The access code RID, encryption key k00, and encryption key k01 are sent to the terminal via the aggregated security gateway. The device ID, access code RID, initial root key file file0, and backup root key file file1 are also sent to the aggregated security gateway, which stores them locally. Otherwise, the initial access authentication fails, and the result of the initial access authentication failure is sent to the terminal via the aggregated security gateway.
6. The key recovery method for a chip-based terminal after power failure and restart according to claim 5, characterized in that, In steps 2-3, the specific process by which the terminal performs the decryption operation of the root key ciphertext to obtain the initial root key file file0 and the backup root key file file1 in plaintext state includes: Based on the message indicating successful initial access authentication, the terminal obtains the network access code RID', decryption key k00, and decryption key k01. Using decryption key k00' and decryption key k01', the terminal performs decryption operations on the initial root key ciphertext FILE0 and the backup root key ciphertext FILE1 in flash memory, respectively, to obtain the initial root key file file0 and the backup root key file file1 in plaintext state.
7. The key recovery method for a chip-based terminal after power failure and restart according to claim 3, characterized in that, Step 2 also includes: When the terminal does not experience a power outage and restart, the terminal monitors the key usage of the initial communication key file ckfile0. When the key usage of the initial communication key file ckfile0 reaches the threshold M, the terminal requests the key center to download a new communication key file to supplement the pairing key pool via the aggregated security gateway.
8. The key recovery method for a chip-based terminal after power failure and restart according to claim 3, characterized in that, In step 3, the specific process of the terminal requesting a second access operation from the aggregated security gateway after power failure and restart includes: Whenever the terminal experiences a power outage and restart, the terminal's chip's flash reads the primary access key file from the primary access key pool and pushes it into the pairing key pool in memory as the second communication key file. This second communication key file is the initial root key file file0, and a secondary access request req2 is generated. The chip generates an irreducible polynomial p2(x) locally and obtains an input random number s2 from the local source. The string representing the coefficients of each term in the irreducible polynomial p2(x), excluding the highest term, is denoted as str2. The chip uses the irreducible polynomial p2(x) and the input random number s2 to generate a second hash function h. p2,s2 Input the second communication key file into the second hash function h p2,s2 The second hash value H2 = h is obtained. p2,s2 (file0); Record the string str2 and the input random number s2 as the second hash value parameter; The terminal obtains the communication key K2 from the second communication key file and records the index idx-K2 of the communication key K2 in file0; it uses the communication key K2 to perform encryption operations on the network access code RID, device ID, second hash value H2, second hash value parameter string str2 and input random number s2 to obtain secondary access information mes2=[RID, ID, H2, str2, s2]⊕K2; it merges the secondary access information mes2, number index0 and index idx-K2 to generate a secondary access request req2 and sends it to the aggregated security gateway.
9. The key recovery method for a chip-based terminal after power failure and restart according to claim 8, characterized in that, In step 3, after the secondary access authentication of the aggregated security gateway is successful, the specific process of triggering a key download process from the key center to obtain a new communication key file and sending it to the terminal includes: The aggregated security gateway performs secondary access authentication based on the secondary access request req2: (a1) The aggregated security gateway learns from index0 that the second communication key file currently used by the terminal is the initial root key file file0. Then, it deletes the backup root key file file1 corresponding to the device ID locally, and obtains the decryption key K2' from the initial root key file file0 based on index idx-K2'. It performs a decryption operation on the secondary access information mes2' to obtain the network access code RID', device ID', hash value H2', hash value parameter string str2' and input random number s2'. It compares whether the network access code RID corresponding to the local device ID is consistent with the received network access code RID'. If yes, it proceeds to step (a2); otherwise, the terminal's secondary access request fails, all key files in the local flash and memory are cleared, and it returns to step 1 to request the root key again. (a2) The aggregated security gateway generates a hash function h based on the string str2' and the input random number s2'. p2’,s2’ Input the locally stored initial root key file file0 into the hash function h p2’,s2’ Calculate the hash value H2''=h p2’,s2’ (file0); The aggregated security gateway compares the received hash value H2' with the calculated hash value H1'': if they match, the secondary access authentication passes; otherwise, the secondary access authentication fails, and the aggregated security gateway sends the result of the secondary access authentication failure to the terminal. The terminal clears all key files in its local flash and memory and returns to step 1 to request the root key again. Based on the successful secondary access authentication, the aggregated security gateway requests the download of the first communication key file ckfile1 to the nth communication key file ckfilen from the key center, where n≥2. It obtains encryption keys k1 to kn from the initial root key file file0, records the indices idx-k1 to idx-kn of the encryption keys k1 to kn in the initial root key file file0, and encrypts the first communication key file ckfile1 to the nth communication key file ckfilen using the encryption keys k1 to kn to obtain the ciphertext of the first communication key file CKFILE1 to the nth communication key file ciphertext CKFILEn. It then sends the first communication key file ciphertext CKFILE1 to the nth communication key file ciphertext CKFILEn and the indices idx-k1 to idx-kn to the terminal.
10. The key recovery method for a chip-based terminal after power failure and restart according to claim 9, characterized in that, In step 3, the specific process by which the terminal updates the chip's storage space based on the new communication key file includes: The terminal obtains the first communication key file ciphertext CKFILE1' to the nth communication key file ciphertext CKFILEn' and the indices idx-k1' to idx-kn'. Based on the indices idx-k1' to idx-kn', it obtains the decryption keys k1' to kn' from the second communication key file in the paired key pool in memory. It then performs a decryption operation on the first communication key file ciphertext CKFILE1' to the nth communication key file ciphertext CKFILEn' to obtain the first communication key file ckfile1' to the nth communication key file ckfilen'. The terminal selects the first communication key file ckfile1' from the communication key files ckfile1' to ckfilen' or arbitrarily selects the m-th communication key file ckfilem' and writes it into the main access key pool in flash as the new main access key file, where 1≤m≤n. The original main access key files in the main access key pool are pushed into the backup access key pool as backup access key files, and the remaining communication key files are written into the communication key pool in memory as updated communication key files.