Network communication method, apparatus, computer device, and computer program

The network communication method addresses inefficiencies in establishing encrypted connections by using compressed digital certificates for integrity verification, resulting in improved communication efficiency and reduced transmission time.

JP2025518427AActive Publication Date: 2025-06-17TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023571536
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-04-18
Filing Date
2023-08-10
Publication Date
2025-06-17
Estimated Expiration
2043-08-10

AI Technical Summary

Technical Problem

The existing methods for establishing encrypted communication connections in network communication are inefficient when large digital certificates are involved, leading to increased transmission time and potential connection failures.

Method used

A network communication method that involves sending an encrypted communication connection request to a first communication device, receiving a second digital certificate, sending a key negotiation request, and receiving a compressed digital certificate, which is then used for integrity verification to generate an encrypted communication key for secure communication.

Benefits of technology

This method reduces the data transmission time and improves communication efficiency by compressing digital certificates during the key negotiation process, thereby enhancing the success rate of encrypted communication connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025518427000001_ABST
    Figure 2025518427000001_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communications, and relates to a network communication method, apparatus, computer device, and storage medium. The method includes: sending an encrypted communication connection request to a first communication device, where the encrypted communication connection request is used to instruct the first communication device to return a first digital certificate (step (202)); receiving a second digital certificate from the first communication device, where the second digital certificate is the digital certificate actually received by a second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request (step (204)); sending a first key negotiation request to the first communication device, and receiving a compressed digital certificate returned by the first communication device in response to the first key negotiation request, where the compressed digital certificate is obtained by compressing the first digital certificate (step (206)); performing integrity verification based on the second digital certificate and the compressed digital certificate (step (208)); generating an encrypted communication key when the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful (step (210)); and performing encrypted communication with the first communication device based on the encrypted communication key (step (212)).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims priority based on a Chinese patent application with an application number of 2023104244485 filed on April 18, 2023, and an invention title of "Network Communication Method, Apparatus, Computer Device, and Storage Medium", and incorporates all of its contents by reference into the present invention.

[0002] The present invention relates to the field of communication technologies, and more specifically, to network communication methods, apparatuses, computer devices, and storage media.

Background Art

[0003] With the development of network communication, in order to improve the security of network communication, communication devices need to establish an encrypted communication connection with each other. In the procedure of establishing an encrypted communication connection, it is necessary to authenticate communication devices by transmitting digital certificates. With the development of quantum computers, in order to improve the security of network communication in the quantum computer era, in the procedure of establishing an encrypted communication connection, the transmitted digital certificate needs to support a quantum-resistant algorithm.

[0004] In the prior art, when the packet of the digital certificate transmitted in the procedure of establishing an encrypted communication connection is large, usually, the packet of the digital certificate is divided into a plurality of small packets, and each divided small packet is transmitted to achieve the purpose of transmitting the digital certificate.

[0005] However, when a large digital certificate packet is divided and a plurality of divided small packets are transmitted, the transmission time becomes long and it is easy to fail in connection establishment, so the communication efficiency decreases.

Summary of the Invention

[0006] Therefore, in view of the above technical problems, it is necessary to provide a network communication method, apparatus, computer device, computer-readable storage medium, and computer program product.

[0007] In one aspect of the present invention, there is provided a network communication method executed by a second communication device, the method including: sending an encrypted communication connection request to a first communication device, where the encrypted communication connection request is used to instruct the first communication device to return a first digital certificate; receiving a second digital certificate from the first communication device, where the second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request; sending a first key negotiation request to the first communication device, and receiving a compressed digital certificate returned by the first communication device in response to the first key negotiation request, where the compressed digital certificate is obtained by compressing the first digital certificate; performing integrity verification based on the second digital certificate and the compressed digital certificate; generating an encrypted communication key when the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful; and performing encrypted communication with the first communication device based on the encrypted communication key.

[0008] In another aspect of the present invention, there is provided a network communication device, comprising: a connection request transmission module that transmits an encrypted communication connection request to a first communication device, wherein the encrypted communication connection request is used to instruct the first communication device to return a first digital certificate; a certificate reception module that receives a second digital certificate from the first communication device, wherein the second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request; a negotiation request transmission module that transmits a first key negotiation request to the first communication device and receives a compressed digital certificate returned by the first communication device in response to the first key negotiation request, wherein the compressed digital certificate is obtained by compressing the first digital certificate; a verification module that performs integrity verification based on the second digital certificate and the compressed digital certificate; a first key generation module that generates an encrypted communication key when the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful; and a first encrypted communication module that performs encrypted communication with the first communication device based on the encrypted communication key.

[0009] In another aspect of the present invention, there is provided a computer device including a memory storing computer-readable instructions and one or more processors, wherein the processor realizes the steps in the above network communication method when executing the computer-readable instructions.

[0010] In another aspect of the present invention, there is provided one or more readable storage media storing computer-readable instructions, wherein the computer-readable instructions realize the steps in the above network communication method when executed by a processor.

[0011] In another aspect of the present invention, there is provided a computer program product comprising computer-readable instructions which, when executed by one or more processors, implement the steps in the network communication method described above.

[0012] In another aspect of the present invention, there is provided a network communication method executed by a first communication device, the method comprising: receiving an encrypted communication connection request transmitted by a second communication device; transmitting a first digital certificate to the second communication device in response to the encrypted communication connection request such that the second communication device actually receives the second digital certificate, wherein the second digital certificate is used for authenticating the first communication device; receiving a first key negotiation request transmitted by the second communication device; transmitting a compressed digital certificate to the second communication device in response to the first key negotiation request, wherein the compressed digital certificate is obtained by compressing the first digital certificate and is used for performing consistency verification with the second digital certificate; generating an encrypted communication key when the consistency verification is successful and the authentication is successful; and performing encrypted communication with the second communication device based on the encrypted communication key.

[0013] In another aspect of the present invention, there is provided a network communication device, comprising: a connection request receiving module configured to receive an encrypted communication connection request transmitted by a second communication device; a certificate transmission module configured to transmit a first digital certificate to the second communication device in response to the encrypted communication connection request so that the second communication device actually receives a second digital certificate, wherein the second digital certificate is used for authenticating the first communication device; a negotiation request receiving module configured to receive a first key negotiation request transmitted by the second communication device; a negotiation request response module configured to transmit a compressed digital certificate to the second communication device in response to the first key negotiation request, wherein the compressed digital certificate is obtained by compressing the first digital certificate and is used for performing integrity verification with the second digital certificate; a second key generation module configured to generate an encrypted communication key when the integrity verification is successful and the authentication is successful; and a second encrypted communication module configured to perform encrypted communication with the second communication device based on the encrypted communication key.

[0014] In another aspect of the present invention, there is provided a computer device including a memory storing computer-readable instructions and one or more processors, wherein the processors, when executing the computer-readable instructions, implement the steps in the above network communication method.

[0015] In another aspect of the present invention, there is provided one or more readable storage media storing computer-readable instructions, wherein the computer-readable instructions, when executed by a processor, implement the steps in the above network communication method.

[0016] In another aspect of the present invention, there is provided a computer program product comprising computer-readable instructions which, when executed by one or more processors, implement the steps in the network communication method described above.

[0017] Details of one or more embodiments of the present invention are presented in the following drawings and description. Other features, objects, and advantages of the present invention will become apparent from the specification, drawings, and claims.

Brief Description of the Drawings

[0018] To more clearly illustrate the technology according to embodiments of the present invention, the following briefly introduces the drawings necessary for the description of the embodiments. It should be noted that the following drawings are merely some aspects of the present invention, and those skilled in the art can obtain other drawings based on these drawings without creative work.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Embodiments for Carrying Out the Invention

[0019] In order to more clearly understand the object, technical means and advantages of the present invention, the present invention will be described in more detail below with reference to the drawings and embodiments. It should be noted that the specific embodiments described in this specification are only for explaining the present invention and do not limit the present invention.

[0020] The network communication method according to the embodiment of the present invention can be applied to the application environment shown in FIG. 1. The application environment includes a first communication device 102 and a second communication device 104. Here, the first communication device 102 communicates with the second communication device 104 via a network. The first data storage system may store data that the first communication device 102 needs to process. The first data storage system may be integrated with the first communication device 102 or may be arranged in the cloud or other servers. The second data storage system may store data that the second communication device 104 needs to process. The second data storage system may be integrated with the second communication device 104 or may be arranged in the cloud or other servers.

[0021] Specifically, when an unencrypted communication connection is established between the second communication device 104 and the first communication device 102, for example, when a TCP (Transmission Control Protocol) connection is established, the second communication device 104 may send an encrypted communication connection request to the first communication device 102 in order to perform encrypted communication with the first communication device 102. In response to the encrypted communication connection request, the first communication device 102 may send a first digital certificate to the second communication device. The encrypted communication connection request is used to instruct the first communication device 102 to return a first digital certificate for identifying the first communication device 102, and the first communication device 102 is the other device that communicates with the second communication device 104. After the first communication device 102 returns the first digital certificate to the second communication device, the second communication device 104 actually receives the second digital certificate. If the first digital certificate has not been tampered with during transmission, the second digital certificate and the first digital certificate are the same digital certificate. If the first digital certificate has been tampered with during transmission, the second digital certificate is different from the first digital certificate. The second communication device 104 sends a first key negotiation request to the first communication device 102, and in response to the first key negotiation request, the first communication device 102 returns a compressed digital certificate to the second communication device 104. The compressed digital certificate is obtained by compressing the first digital certificate. After receiving the compressed digital certificate, the second communication device 104 performs integrity verification based on the second digital certificate and the compressed digital certificate. If the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful, the second communication device generates an encrypted communication key. After the encrypted communication key is generated, the second communication device 104 and the first communication device 102 perform encrypted communication based on the encrypted communication key. It should be noted that if the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful, the first communication device also generates the encrypted communication key, and the encrypted communication key generated by the first communication device is the same as the encrypted communication key generated by the second communication device.

[0022] Here, the first communication device 102 and the second communication device 104 may be various desktop computers, notebook computers, smartphones, tablet computers, Internet of Things devices, and portable wearable devices, but are not limited thereto. The Internet of Things devices may be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, or may be independent physical servers, or may be a server cluster or distributed system composed of multiple physical servers, or may be a cloud server that provides network security services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, cloud security, and host security, CDN, and basic cloud computing services such as big data and artificial intelligence platforms. The portable wearable devices may be smart watches, smart wristbands, head-mounted devices, etc. The first communication device 102 and the second communication device 104 may be directly or indirectly connected by wired communication or wireless communication, but the present invention is not limited thereto.

[0023] The network communication method according to the present invention may be applied to a blockchain system, and the blockchain system is formed by a plurality of nodes (any form of computing device in the access network, such as a server, a user terminal) and a client.

[0024] A peer-to-peer (P2P) network is formed between nodes, and the P2P protocol is an application layer protocol that operates on top of the Transmission Control Protocol (TCP). In a blockchain system, any device such as a server or a terminal may participate as a node, and a node includes a hardware layer, an intermediate layer, an operating system layer, and an application layer. For example, the first communication device and the second communication device may be nodes within the blockchain system, and the network communication method according to the present invention is applicable to the blockchain system and can improve the communication efficiency between nodes within the blockchain system.

[0025] In some embodiments, a network communication method is provided, and as an example, it is described that the method is applied to the second communication device 104 in FIG. 1. As shown in FIG. 2, the method includes the following steps.

[0026] Step 202: Send an encrypted communication connection request to the first communication device, and the encrypted communication connection request is used to instruct the first communication device to return the first digital certificate.

[0027] Here, the digital certificate is used to identify communication devices in Internet communication. The first digital certificate is used to indicate the identification information of the first communication device. The first communication device and the second communication device communicate with each other. The first digital certificate may be a digital certificate that meets any standard. For example, it may be a digital certificate that meets the X.509 standard. A digital certificate that meets the X.509 standard may also be referred to as an X.509 digital certificate or an x509 digital certificate. X.509 is a standard format for public key infrastructure (PKI). The first digital certificate may be an X.509 digital certificate that supports quantum-resistant algorithms. In an X.509 digital certificate that supports quantum-resistant algorithms, fields such as Alt-Signature-Algorithm (signature algorithm), Subject-Alt-Public-Key-Info (public key of the certificate body), and Alt-Signature-Value (signature of the certificate issuer) are added to the extension field (X509v3 extensions) to support quantum-resistant algorithms. For example, the data structure of an X.509 digital certificate that supports quantum-resistant algorithms may be as follows.

[0028] X.509Certificate: / / X.509 digital certificate Data: / / Data field Version:3(0x2) / / Version number Serial Number:3027 / / Serial number Signature Algorithm:ecdsa-with-SHA256 / / Signature algorithm Issuer:C=CN,ST=BJ,O=XX,CN=CA_TEST / / Issuer Validity / / Expiration date Not Before:Jan 9 17:33:02 2018 GMT / / GMT (Greenwich Mean Time: Greenwich Standard Time), invalid until Jan 9 17:33:02 2018 GMT; Not After:Jan 22 17:33:02 2019 GMT / / Invalid after Jan 22 17:33:02 2019 GMT; Subject:C=CN,ST=BJ,O=XX,CN=ServerCRT_TEST / / Name of certificate owner Subject Public Key Info: / / Public key algorithm, parameters and values of certificate owner; Public Key Algorithm:id-ecPublicKey Public-Key:(256 bit) [...omitted for brevity...] X509v3 extensions: / / Extension fields X509v3 Basic Constraints: CA:FALSE Alt-Signature-Algorithm: / / Alternative signature algorithm sha512WithDillithiun2 Subject-Alt-Public-Key-Info: / / Public key of certificate body Public Key: 00:00:00:01:00:00:00:07:00:00:00:03:1c:ba [...omitted for brevity...] / / Omitted for brevity Alt-Signature-Value: / / Signature of certificate issuer Signature: 23:82:1a:74:01:00:30:06:af:1d:d3 [...omitted for brevity...] / / Omitted for brevity Since an X.509 digital certificate that supports quantum-resistant algorithms contains the public key of the certificate body and the signature of the certificate issuer, the data volume of an X.509 digital certificate that supports quantum-resistant algorithms is large. Quantum-resistant algorithms are used to protect the security of transmitted data on quantum computers.

[0029] An encrypted communication connection request is used to request the establishment of a communication link for encrypted communication. Encrypted communication means encrypting and transmitting the data to be transmitted during communication. In other words, encrypted communication means sending and receiving encrypted data during communication, encrypting the data to be transmitted when sending data, and receiving and decrypting the encrypted data.

[0030] Specifically, when the first communication device and the second communication device have established an unencrypted communication link, the encrypted communication connection request may be transmitted via the unencrypted communication link. An unencrypted communication link is used to transmit data in a plaintext transmission method. The unencrypted communication link may be, for example, a communication link established via a TCP connection.

[0031] In some embodiments, when the data volume of the first digital certificate is larger than the data volume threshold, the encrypted communication connection request is used to instruct the first communication device to return the first digital certificate for the first communication device to identify itself. The first communication device is the other device that communicates with the second communication device. The data volume threshold may be set as needed and may be determined according to, for example, the data volume of the MTU (Maximum Transmission Unit). For example, the data volume threshold may be the data volume of the MTU or the product of the data volume of the MTU and a predetermined coefficient. The predetermined coefficient is a numerical value between 0.5 and 1 and may be, for example, 0.8 or 1.

[0032] In some embodiments, the second communication device sends an encrypted communication connection request to the first communication device to implement encrypted communication with the first communication device. In response to the encrypted communication connection request, the first communication device obtains a first digital certificate and sends the first digital certificate to the second communication device.

[0033] Step 204: Receive a second digital certificate from the first communication device. The second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request.

[0034] Specifically, in response to the encrypted communication connection request, the first communication device obtains a first digital certificate and sends the first digital certificate to the second communication device via an unencrypted communication link. Since the unencrypted communication link cannot guarantee the security of data transmission, the first digital certificate may be tampered with during transmission. As a result, the second digital certificate transmitted to and received by the second communication device may not be the first digital certificate. If it has not been tampered with, the second digital certificate, which is the digital certificate received by the second communication device, is the first digital certificate.

[0035] Step 206: Send a first key negotiation request to the first communication device, and receive a compressed digital certificate returned by the first communication device in response to the first key negotiation request. The compressed digital certificate is obtained by compressing the first digital certificate.

[0036] Here, the key negotiation request is used to trigger the key negotiation between the first communication device and the second communication device. The purpose of the key negotiation is to obtain a common key through negotiation. After obtaining the common key through negotiation, before transmitting data, the first communication device and the second communication device encrypt the data to be transmitted with this common key and transmit the encrypted result. Here, the common key is also referred to as the encrypted communication key.

[0037] The second communication device may send a first key negotiation request to the first communication device while the first communication device is transmitting the first digital certificate, or may send a first key negotiation request to the first communication device after receiving the complete second digital certificate.

[0038] Specifically, the first communication device has a first public key and a first private key. The first public key can decrypt data encrypted with the first private key, and the first private key can also decrypt data encrypted with the first public key. The second communication device has a second public key and a second private key. The second public key can decrypt data encrypted with the second private key, and the second private key can also decrypt data encrypted with the second public key. During the key negotiation between the first communication device and the second communication device, the data sent from the first communication device to the second communication device may be encrypted with the second public key, and the data sent from the second communication device to the first communication device may be encrypted with the first public key. For example, the first key negotiation request may be encrypted with the first public key.

[0039] In some embodiments, the compressed digital certificate may be pre-generated by the first communication device or may be generated by the first communication device in response to the first key negotiation request. Specifically, the first communication device obtains the first digital certificate in response to the first key negotiation request, compresses at least a part of the content in the first digital certificate, obtains a compressed digital certificate corresponding to the first digital certificate, and transmits the compressed digital certificate to the second communication device.

[0040] In some embodiments, the first communication device may compress all the contents included in the first digital certificate to obtain a compressed digital certificate. For example, the first communication device may perform a hash calculation on all the contents included in the first digital certificate, and use the result of the hash calculation as the compressed digital certificate. Alternatively, the first communication device may compress the first content in the first digital certificate, for example, perform a hash calculation, to obtain the first compressed content corresponding to the first content. Thereafter, the first communication device may replace the first content in the first digital certificate with the first compressed content corresponding to the first content to obtain a compressed digital certificate corresponding to the first digital certificate.

[0041] Step 208: Perform integrity verification based on the second digital certificate and the compressed digital certificate.

[0042] Specifically, the compressed digital certificate is obtained by compressing the first digital certificate according to a predetermined compression method. The predetermined compression method includes, but is not limited to, a predetermined compression encoding algorithm. The predetermined compression encoding algorithm includes, but is not limited to, a hash algorithm. The hash algorithm includes, but is not limited to, SHA256, the Chinese cryptographic algorithm SM2, or the Chinese cryptographic algorithm SM3. Since the compressed digital certificate is obtained by compressing the first digital certificate, the data volume of the compressed digital certificate is smaller than that of the first digital certificate. Therefore, it can be said that the compressed digital certificate is a short certificate corresponding to the first digital certificate. Taking as an example that the first digital certificate is an x509 digital certificate of a quantum-resistant algorithm and the predetermined compression method is SHA256, the calculation method of the short certificate corresponding to the first digital certificate is: short certificate = SHA256(x509 digital certificate of a quantum-resistant algorithm). Since the hash algorithm has collision resistance, the x509 digital certificate of the quantum-resistant algorithm corresponds one-to-one with the short certificate, and the short certificate obtained by the hash algorithm has a unique size of only dozens of bytes. Therefore, the amount of transmitted data can be reduced in the network transmission process, and the communication efficiency can be improved. The first communication device has a short certificate calculation module, and the short certificate calculation module compresses the input digital certificate according to a predetermined compression method to generate a corresponding short certificate. As shown in Figure 3, the x509 digital certificate of the quantum-resistant algorithm is input into the short certificate calculation module, and a short certificate is output.

[0043] In some embodiments, the second communication device may compress the second digital certificate according to the predetermined compression method, and use the result of the compression as a comparison digital certificate. When the comparison digital certificate and the compressed digital certificate match, it is determined that the second digital certificate and the first digital certificate match. Otherwise, it is determined that the second digital certificate and the first digital certificate do not match.

[0044] In some embodiments, there is a predetermined decompression method corresponding to a predetermined compression method. When the second communication device obtains the compressed digital certificate by decryption, the second communication device may decompress the compressed digital certificate according to the predetermined decompression method to obtain the first digital certificate. Then, the first digital certificate is compared with the second digital certificate. If they match as a comparison result, it is determined that the second digital certificate matches the first digital certificate. Otherwise, it is determined that the second digital certificate does not match the first digital certificate.

[0045] Step 210: When the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful, generate an encrypted communication key.

[0046] Here, the encrypted communication key is a symmetric key, that is, the data encrypted by the encrypted communication key can be decrypted by the encrypted communication key.

[0047] Specifically, when the integrity verification is successful, it indicates that the second digital certificate is the first digital certificate, that is, the first digital certificate has been accurately transmitted to the second communication device. When the integrity verification is successful, the second communication device may authenticate the first communication device via the second digital certificate. This can prevent invalid authentication from being performed when the second digital certificate does not match the first digital certificate. When the authentication is successful, the second communication device generates an encrypted communication key and performs encrypted communication with the first communication device using the encrypted communication key.

[0048] In some embodiments, when the second digital certificate matches the first digital certificate, the first communication device and the second communication device each generate the same key, which is the encrypted communication key. When the second digital certificate does not match the first digital certificate, the second communication device may send a negotiation failure notification to the first communication device, and the second communication device may re-execute the step of sending an encrypted communication connection request to the first communication device.

[0049] In some embodiments, the second communication device generates a first random number, encrypts the first random number using the first public key of the first communication device to obtain a first encrypted random number. The first key negotiation request may include the first encrypted random number. In response to the first key negotiation request, the first communication device generates a second random number, encrypts the second random number using the second public key of the second communication device to obtain a second encrypted random number, and may send the second encrypted random number to the second communication device. The first communication device may decrypt the second encrypted random number using the first private key to obtain the second random number, and generate an encrypted communication key based on the first random number and the second random number. The second communication device may decrypt the first encrypted random number using the second private key to obtain the first random number, and generate an encrypted communication key based on the first random number and the second random number. The first communication device and the second communication device generate the same encrypted communication key. The method for generating the encrypted communication key based on the first random number and the second random number is not limited herein. For example, the first random number and the second random number may be used as the encrypted communication key, or a hash calculation may be performed on the first random number and the second random number, and the result of the hash calculation may be used as the encrypted communication key.

[0050] Step 212: Perform encrypted communication between the first communication device based on the encrypted communication key.

[0051] Specifically, the encrypted communication key is a symmetric key, that is, the data encrypted by the encrypted communication key can be decrypted by the encrypted communication key. When the first communication device and the second communication device generate the encrypted communication key, the data transmitted from the first communication device to the second communication device is encrypted by the encrypted communication key, and the data transmitted from the second communication device to the first communication device is also encrypted by the encrypted communication key. After receiving the data encrypted by the encrypted communication key transmitted by the second communication device, the first communication device decrypts the received data with the encrypted communication key. After receiving the data encrypted by the encrypted communication key transmitted by the first communication device, the second communication device decrypts the received data with the encrypted communication key. Thereby, the first communication device and the second communication device realize encrypted communication.

[0052] In the above network communication method, an encrypted communication connection request is sent to the first communication device. The encrypted communication connection request is used to instruct the first communication device to return the first digital certificate. The second digital certificate is received from the first communication device. The second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request. A first key negotiation request is sent to the first communication device, and the compressed digital certificate returned by the first communication device in response to the first key negotiation request is received. The compressed digital certificate is obtained by compressing the first digital certificate. Integrity verification is performed based on the second digital certificate and the compressed digital certificate. When the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful, an encrypted communication key is generated, and encrypted communication is performed with the first communication device based on the encrypted communication key. Instead of sending the first digital certificate in the key negotiation procedure, before sending the first key negotiation request, that is, before performing key negotiation, the first digital certificate is sent, and after sending the first key negotiation request, that is, in the key negotiation procedure, by transmitting the compressed digital certificate corresponding to the first digital certificate, the amount of data transmitted in the key negotiation procedure can be reduced, the failure rate of key negotiation can be reduced, and the success rate of key negotiation can be improved. Therefore, the establishment efficiency of the encrypted communication connection can be improved, and the communication efficiency can be improved.

[0053] Also, when the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful, by generating an encrypted communication key, it becomes an encrypted communication key generated in a secure case, and the security of the encrypted communication can be improved.

[0054] In some embodiments, the first digital certificate returned by the first communication device is the one returned by the first communication device in response to an encrypted communication connection request when the data volume of the first digital certificate is greater than the data volume threshold. Specifically, in response to an encrypted communication connection request, when the data volume of the first digital certificate is greater than the data volume threshold, the first communication device transmits the first digital certificate to the second communication device.

[0055] In some embodiments, the data volume of the digital certificate of the first certificate type is greater than the data volume threshold, and the data volume of the digital certificate of the second certificate type is less than or equal to the data volume threshold. The data volume threshold may be set as needed, for example, determined according to the data volume of the MTU (Maximum Transmission Unit). For example, the data volume threshold may be the data volume of the MTU, or may be the product of the data volume of the MTU and a predetermined coefficient. The predetermined coefficient is a numerical value between 0.5 and 1, and may be, for example, 0.8 or 1, etc.

[0056] In some embodiments, in response to an encrypted communication connection request, the first communication device determines the certificate type of the first digital certificate. When the certificate type of the first digital certificate is the first certificate type, the first communication device transmits the first digital certificate to the second communication device. For example, the first communication device transmits the first request response result for the encrypted communication connection request to the second communication device, and the first request response result includes the first digital certificate. Since the first request response result may be transmitted by the first communication device via an unencrypted communication link, the response result actually received by the second communication device may or may not match the first request response result. The second communication device transmits a first key negotiation request to the first communication device in response to the received response result.

[0057] In some embodiments, the data volume of a digital certificate that does not support quantum-resistant algorithms is below the data volume threshold, and the data volume of a digital certificate that supports quantum-resistant algorithms may be greater than the data volume threshold or may be below the data volume threshold. When the first communication device determines, in response to an encrypted communication connection request, that the first digital certificate belongs to a digital certificate that does not support quantum-resistant algorithms, it determines that the certificate type of the first digital certificate is the second certificate type. When it is determined that the first digital certificate belongs to a digital certificate that supports quantum-resistant algorithms, the data volume of the first digital certificate is calculated. When the data volume of the first digital certificate is greater than the data volume threshold, it is determined that the certificate type of the first digital certificate is the first certificate type. When the data volume of the first digital certificate is below the data volume threshold, it is determined that the certificate type of the first digital certificate is the second certificate type. Taking the first digital certificate being an x509 digital certificate as an example, FIG. 4 shows the principle of determining the certificate type. In FIG. 4, a non-quantum-resistant x509 digital certificate means an x509 digital certificate that does not support quantum-resistant algorithms, and a quantum-resistant x509 digital certificate means an x509 digital certificate that supports quantum-resistant algorithms. "Small certificate" indicates that the certificate type is the second certificate type, and "large certificate" indicates that the certificate type is the first certificate type.

[0058] In this embodiment, when the data volume is relatively large, the data transmission time increases. Therefore, when the data volume of the first digital certificate is greater than the data volume threshold, the first communication device returns the first digital certificate. By doing so, instead of transmitting the first digital certificate with a relatively large data volume in the key negotiation procedure, by transmitting the first digital certificate with a relatively large data volume before the key negotiation, the delay of data transmission in the key negotiation procedure can be reduced, the interruption of the key negotiation procedure due to a large transmission delay can be reduced, the probability of successful key negotiation can be improved, and the communication efficiency can be improved.

[0059] In some embodiments, the network communication method further includes: when the data volume of the first digital certificate is less than or equal to the data volume threshold, receiving a response result without the first digital certificate returned by the first communication device; in response to the response result, sending a second key negotiation request to the first communication device; receiving the first digital certificate returned by the first communication device in response to the second key negotiation request; authenticating the first communication device based on the received first digital certificate; when the authentication is successful, generating an encrypted communication key; and performing encrypted communication with the first communication device based on the encrypted communication key.

[0060] Here, the response result without the first digital certificate may also be referred to as a second request response result. The second request response result does not include the first digital certificate. The data volume of the digital certificate of the second certificate type is less than or equal to the data volume threshold.

[0061] Specifically, in response to an encrypted communication connection request, when the data volume of the first digital certificate is less than or equal to the data volume threshold, the first communication device returns a response result without the first digital certificate to the second communication device. For example, in response to an encrypted communication connection request, when the first communication device determines that the certificate type of the first digital certificate is the second certificate type, the first communication device transmits a second request response result for the encrypted communication connection to the second communication device. After receiving the second request response result, the second communication device sends a second key negotiation request to the first communication device. In response to the second key negotiation request, the first communication device sends the first digital certificate to the second communication device. The second communication device authenticates the first communication device with the first digital certificate. When the authentication is successful, the second communication device generates an encrypted communication key and performs encrypted communication with the second communication device based on the encrypted communication key.

[0062] In some embodiments, the second communication device has a third digital certificate, and the third digital certificate is used to identify the second communication device. In the key negotiation phase, the first communication device may authenticate the second communication device with the third digital certificate. Specifically, when the certificate type of the third digital certificate is the first certificate type, before the second communication device sends a first key negotiation request to the first communication device, the second communication device may send the third digital certificate to the first communication device via an unencrypted communication link. After the second communication device sends a first key negotiation request to the first communication device, the second communication device may compress the third digital certificate and obtain the compressed certificate. The compression process may refer to the process of compressing the first digital certificate, and the process of obtaining the compressed certificate may refer to the process of obtaining the compressed digital certificate. The second communication device transmits the compressed certificate to the first communication device, generates a third random number, encrypts the third random number using the first public key to obtain a third encrypted random number, and transmits the third encrypted random number to the first communication device. The first communication device performs integrity verification using the compressed certificate. If the integrity verification is successful, the first communication device authenticates the second communication device. Therefore, the first communication device authenticates the second communication device, and the second communication device also authenticates the first communication device. When the authentication of both the first communication device and the second communication device is successful, the first communication device decrypts the third encrypted random number using the first private key to obtain the third random number, and generates an encrypted communication key based on the first random number, the second random number, and the third random number. The first communication device generates an encrypted communication key based on the first random number, the second random number, and the third random number.

[0063] In this embodiment, when the data volume of the first digital certificate is less than or equal to the data volume threshold, after the second key negotiation request triggers key negotiation, the first digital certificate is transmitted. Thereby, when the data volume is relatively small, there is no need to transmit the compressed digital certificate after transmitting the first digital certificate. By directly transmitting the first digital certificate in the key negotiation phase, the transmission process can be simplified, unnecessary data transmission can be avoided, and the communication efficiency can be improved.

[0064] The network communication method according to the present invention may be used to improve the procedure for establishing a TLS connection or an SSL connection to improve the efficiency of establishing a TLS connection or an SSL connection. Here, both TLS (Transport Layer Security) and SSL (Secure Socket Layer) are encryption protocols for encrypting data and verifying connections when moving data over the Internet. TLS is an updated version of SSL, and in TLS, some of the security vulnerabilities present in the SSL protocol have been corrected. TLS connections and SSL connections establish encrypted communication links. When the first digital certificate is an X.509 digital certificate that supports a quantum-resistant algorithm, the improved TLS protocol or SSL protocol may be referred to as a quantum-resistant algorithm TLS protocol or SSL protocol.

[0065] Taking as an example the improvement of the procedure for establishing a TLS connection using the network communication method according to the present invention, FIG. 5 shows a sequence diagram of a procedure that is not the improved TLS connection establishment procedure using the network communication method according to the present invention, and FIG. 6 shows a sequence diagram of the improved TLS connection establishment procedure using the network communication method according to the present invention. In the procedure for establishing a TLS connection, it may be understood that the first communication device is on the client side and the second communication device is on the server side. The procedure for establishing a TLS connection, that is, the key negotiation procedure, may include, but is not limited to, a ClientHello (transmission of client-side encryption information) phase, a ServerHello (transmission of server-side encryption information) phase, a ClientKeyExchange (random number exchange) phase, or a Change Cipher Spec (encryption communication notification) phase. In the ClientHello phase, the second communication device sends a key negotiation request to the first communication device, and in the ServerHello phase, the first communication device sends the first digital certificate of the first communication device to the second communication device. In the ClientKeyExchange phase, the second communication device generates a third random number, encrypts the third random number with the first public key, and sends it to the first communication device. The Change Cipher Spec phase is used to notify data transmission using the encryption communication key.

[0066] As can be seen from FIG. 6, the improved procedure for establishing a TLS connection includes a preprocessing phase and a TLS handshake phase, that is, a key negotiation phase. In the preprocessing phase, the second communication device sends an encrypted communication connection request to the first communication device, and the first communication device determines whether to return the first digital certificate to the second communication device based on the size of the first digital certificate. The preprocessing phase is also referred to as the big data transmission phase.

[0067] FIG. 7 shows a sequence diagram of an improved TLS connection establishment procedure when the certificate type of the first digital certificate is the first certificate type. In the preprocessing phase, when the certificate type of the first digital certificate is the first certificate type, the first communication device returns the first digital certificate to the second communication device, and the first communication device transmits the compressed digital certificate to the second communication device in the ServerHello of the TLS handshake phase.

[0068] FIG. 8 shows a sequence diagram of an improved TLS connection establishment procedure when the certificate type of the first digital certificate is the second certificate type. In the preprocessing phase, when the certificate type of the first digital certificate is the second certificate type and the first communication device does not return the first digital certificate to the second communication device, the first communication device transmits the first digital certificate to the second communication device in the ServerHello of the TLS handshake phase. When the TLS handshake is successful, that is, when the negotiation of the encrypted communication key is successful, the first communication device and the second communication device perform encrypted communication.

[0069] In some embodiments, the first digital certificate includes first content and content index information corresponding to the first content, and the compressed digital certificate is obtained by compressing the first content using a predetermined compression method. The step of performing consistency verification based on the second digital certificate and the compressed digital certificate includes: compressing the second content indicated by the content index information in the second digital certificate using a predetermined compression method to obtain second compressed content; in the second digital certificate, updating the second content with the second compressed content to obtain a comparison digital certificate; and performing consistency verification on the comparison digital certificate and the compressed digital certificate.

[0070] Here, the content index information is index information for retrieving the first content from the first digital certificate. When the content in the first digital certificate is in the form of key-value pairs, the content index information may include at least one key, and the first content includes values corresponding to each key included in the content index information in the first digital certificate. The data volume of the compressed digital certificate is below the data volume threshold. The first content belongs to a part of the content in the first data certificate. For example, when the first digital certificate is a digital certificate supporting a quantum-resistant algorithm, the first content may be part or all of the content supporting the quantum-resistant algorithm in the first digital certificate.

[0071] Specifically, the second communication device compresses the second content indicated by the content index information in the second digital certificate according to a predetermined compression method to obtain the second compressed content, replaces the second content indicated by the content index information in the second digital certificate with the second compressed content, and may determine the replaced second digital certificate as the comparison digital certificate. The second communication device compares the comparison digital certificate with the compressed digital certificate, and if they match as a comparison result, determines that the second digital certificate matches the first digital certificate. The compressed digital certificate may be generated by the first communication device.

[0072] In some embodiments, the first communication device responds to the first key negotiation request sent by the second communication device, determines the first content to be compressed from the first digital certificate, compresses the first content according to a predetermined compression method to obtain the first compressed content, replaces the first content in the first digital certificate with the first compressed content, and the replaced first digital certificate is the compressed digital certificate.

[0073] In this embodiment, by compressing the first content in the first digital certificate to obtain the compressed digital certificate, instead of compressing all the data, specific data in the first digital certificate is compressed, achieving the purpose of compression and improving the efficiency of compression.

[0074] In some embodiments, the first content is for supporting a quantum-resistant algorithm in a first digital certificate. The first digital certificate supports a quantum-resistant algorithm, and the content index information is index information of the content supporting the quantum-resistant algorithm. The second communication device may compress the content supporting the quantum-resistant algorithm indicated by the content index information in the second digital certificate according to a predetermined compression method to obtain second compressed content.

[0075] Here, the first digital certificate supports a quantum-resistant algorithm, the first digital certificate includes content supporting the quantum-resistant algorithm, and the content index information is index information of the content supporting the quantum-resistant algorithm in the first digital certificate.

[0076] Specifically, the content supporting the quantum-resistant algorithm may include at least one of the public key of the first communication device or the signature of the certificate issuer that issues the first digital certificate. The first content may include at least one of the public key of the first communication device or the signature of the certificate issuer that issues the first digital certificate, and the content index information of the first content may include at least one of public key index information or signature index information. When the public key of the first communication device and the signature of the certificate issuer that issues the first digital certificate are included in the first content, the second communication device may search the second digital certificate for at least one of the public key indicated by the public key index information and the signature indicated by the signature index information, and determine the retrieved content as the content indicated by the content index information.

[0077] In some embodiments, the content index information may be transmitted from the first communication device to the second communication device. For example, in response to an encrypted communication connection request, the first communication device transmits a first request response result for the encrypted communication connection request to the second communication device, and the first request response result includes the content index information and the first digital certificate.

[0078] In this embodiment, usually, since the data volume of the content supporting the quantum-resistant algorithm is large, by compressing the content supporting the quantum-resistant algorithm, the data volume can be effectively reduced and the compression effect can be improved.

[0079] In some embodiments, a network communication method is provided, and as an example, it is described that the method is applied to the first communication device 102 in FIG. 1. As shown in FIG. 9, the method includes the following steps.

[0080] Step 902: Receive an encrypted communication connection request sent by a second communication device.

[0081] Here, the second communication device sends an encrypted communication connection request to the first communication device in order to realize encrypted communication with the first communication device. In response to the encrypted communication connection request, the first communication device obtains a first digital certificate and sends the first digital certificate to the second communication device.

[0082] Step 904: In response to the encrypted communication connection request, transmit the first digital certificate to the second communication device so that the second communication device actually receives the second digital certificate, and the second digital certificate is used to authenticate the first communication device.

[0083] Specifically, the first communication device sends the first digital certificate to the second communication device via an unencrypted communication link in response to the encrypted communication connection request. The second communication device actually receives the second digital certificate.

[0084] Step 906: Receive a first key negotiation request sent by a second communication device.

[0085] Step 908: In response to the first key negotiation request, send a compressed digital certificate to the second communication device. The compressed digital certificate is obtained by compressing the first digital certificate and is used for performing consistency verification with the second digital certificate.

[0086] Specifically, when the second communication device receives the second data certificate, it sends a first key negotiation request to the first communication device. In response to the first key negotiation request, the second communication device compresses some or all of the content in the first digital certificate to obtain a compressed digital certificate, and sends the compressed digital certificate to the second communication device. The second communication device receives the compressed digital certificate returned by the first communication device, compresses the second digital certificate to obtain a comparison digital certificate, and performs consistency verification on the comparison digital certificate and the compressed digital certificate.

[0087] Step 910: If the consistency verification is successful and the authentication is successful, generate an encrypted communication key.

[0088] Specifically, if the consistency verification is successful, the second communication device may authenticate the first terminal based on the second digital certificate. If the authentication is successful, the second communication device may send information indicating that the authentication is successful to the first communication device and instruct the first communication device and the second communication device to perform encrypted communication. If the consistency verification is successful and the authentication is successful, the second communication device generates an encrypted communication key, sends a key generation request to the first communication device, and the first communication device generates an encrypted communication key in response to the key generation request.

[0089] Step 912: Perform encrypted communication with the second communication device based on the encrypted communication key.

[0090] Specifically, the encrypted communication key is a symmetric key, that is, the data encrypted by the encrypted communication key can be decrypted by the encrypted communication key. When the first communication device and the second communication device generate the encrypted communication key, the data transmitted from the first communication device to the second communication device is encrypted by the encrypted communication key, and the data transmitted from the second communication device to the first communication device is also encrypted by the encrypted communication key. After receiving the data encrypted by the encrypted communication key transmitted by the second communication device, the first communication device decrypts the received data with the encrypted communication key. After receiving the data encrypted by the encrypted communication key transmitted by the first communication device, the second communication device decrypts the received data with the encrypted communication key. Thus, the first communication device and the second communication device realize encrypted communication.

[0091] In the above network communication method, an encrypted communication connection request sent by a second communication device is received, and in response to the encrypted communication connection request, a first digital certificate is transmitted to the second communication device so that the second communication device actually receives the second digital certificate. The second digital certificate is used to authenticate the first communication device. A first key negotiation request sent by the second communication device is received, and in response to the first key negotiation request, a compressed digital certificate is transmitted to the second communication device. The compressed digital certificate is obtained by compressing the first digital certificate and is used to perform consistency verification with the second digital certificate. When the consistency verification is successful and the authentication is successful, an encrypted communication key is generated, and encrypted communication is performed with the second communication device based on the encrypted communication key. Instead of transmitting the first digital certificate in the key negotiation procedure, before transmitting the first key negotiation request, that is, before performing key negotiation, the first digital certificate is transmitted, and after transmitting the first key negotiation request, that is, in the key negotiation procedure, by transmitting the compressed digital certificate corresponding to the first digital certificate, the amount of data transmitted in the key negotiation procedure can be reduced, the failure rate of key negotiation can be reduced, and the success rate of key negotiation can be improved. Therefore, the establishment efficiency of the encrypted communication connection can be improved, and the communication efficiency can be improved.

[0092] In some embodiments, the step of transmitting the first digital certificate to the first communication device in response to the encrypted communication connection request includes, when the data amount of the first digital certificate is greater than the data amount threshold, the step of transmitting the first digital certificate to the second communication device in response to the encrypted communication connection request.

[0093] Specifically, when the certificate type of the first digital certificate is the first certificate type, a first request response result for an encrypted communication connection request is sent to the second communication device, and the first request response result includes the first digital certificate. The data volume of the digital certificate of the first certificate type is larger than the data volume threshold. Here, the second digital certificate means the digital certificate included in the response result actually received by the second communication device after the first communication device returns the first request response result to the second communication device.

[0094] Specifically, in response to an encrypted communication connection request, when the data volume of the first digital certificate is larger than the data volume threshold, the first communication device sends a first request response result for the encrypted communication connection request to the second communication device via an unencrypted communication link. Since the first request response result is transmitted by the first communication device via an unencrypted communication link, the response result actually received by the second communication device may or may not match the first request response result.

[0095] In this embodiment, when the data volume is relatively large, the data transmission time increases. Therefore, when the data volume of the first digital certificate is larger than the data volume threshold, the first communication device returns the first digital certificate. By doing so, instead of transmitting the first digital certificate with a relatively large data volume in the key negotiation procedure, the first digital certificate with a relatively large data volume is transmitted before the key negotiation, thereby reducing the delay of data transmission in the key negotiation procedure, reducing the interruption of the key negotiation procedure due to a large transmission delay, improving the probability of successful key negotiation, and improving the communication efficiency.

[0096] In some embodiments, when the certificate type of the first digital certificate is the first certificate type, it is determined that the data volume of the first digital certificate is larger than the data volume threshold.

[0097] Specifically, when the certificate type of the first digital certificate is the first certificate type, the first communication device transmits a first request response result for an encrypted communication connection request to the second communication device via an unencrypted communication link. The first request response result includes the first digital certificate.

[0098] In this embodiment, by determining whether the data volume of the first digital certificate is greater than a data volume threshold based on the certificate type, the efficiency of determining whether the data volume of the first digital certificate is greater than the data volume threshold can be improved.

[0099] In some embodiments, when the data volume of the first digital certificate is less than or equal to the data volume threshold, in response to the encrypted communication connection request, a response result that does not include the first digital certificate is returned to the second communication device. The second key negotiation request transmitted by the second communication device is received, and in response to the second key negotiation request, the first digital certificate is transmitted to the second communication device. The second key negotiation request is returned by the second communication device in response to the response result that does not include the first digital certificate. The first digital certificate is used for the second communication device to authenticate the first communication device. When the authentication is successful, an encrypted communication key is generated, and encrypted communication is performed with the second communication device based on the encrypted communication key.

[0100] Specifically, the response result that does not include the first digital certificate may be referred to as a second request response result. The second request response result is used to trigger the second communication device to transmit a second key negotiation request to the first communication device. The first communication device transmits the first digital certificate to the second communication device in response to the second key negotiation request. When the second communication device receives the first digital certificate, it authenticates the first communication device with the first digital certificate. When the authentication is successful, an encrypted communication key is generated, a key generation request is transmitted to the first communication device, the first communication device generates an encrypted communication key in response to the key generation request, and the first communication device and the second communication device perform encrypted communication based on the encrypted communication key.

[0101] In this embodiment, when the data volume of the first digital certificate is less than or equal to the data volume threshold, after the second key negotiation request triggers key negotiation, the first digital certificate is transmitted. Thereby, when the data volume is relatively small, by directly transmitting the first digital certificate in the key negotiation phase, the security of data transmission can be ensured, the failure of negotiation due to a large data volume can be reduced, and the communication efficiency can be improved.

[0102] In some embodiments, the method further includes determining that the data volume of the first digital certificate is less than or equal to the data volume threshold when the certificate type of the first digital certificate is the second certificate type.

[0103] In this embodiment, by determining whether the data volume of the first digital certificate is greater than the data volume threshold based on the certificate type, the efficiency of determining whether the data volume of the first digital certificate is greater than the data volume threshold can be improved.

[0104] In some embodiments, the step of transmitting the compressed digital certificate to the second communication device in response to the first key negotiation request includes determining the first content from the first digital certificate in response to the first key negotiation request, compressing the first content using a predetermined compression method to obtain the first compressed content, updating the first content with the first compressed content in the first digital certificate to obtain the compressed digital certificate, and transmitting the compressed digital certificate to the second communication device.

[0105] Here, the first content may be the content of any part of the first digital certificate. The data volume of the compressed digital certificate is less than or equal to the data volume threshold.

[0106] Specifically, in response to a first key negotiation request, the first communication device determines first content to be compressed from a first digital certificate, compresses the first content according to a predetermined compression method to obtain first compressed content, updates the first content in the first digital certificate with the first compressed content, obtains a compressed digital certificate, and transmits the compressed digital certificate to the second communication device.

[0107] In this embodiment, by compressing the first content in the first digital certificate to obtain a compressed digital certificate, data can be compressed and the compression efficiency can be improved.

[0108] In some embodiments, the first digital certificate supports a quantum-resistant algorithm, and the step of determining the first content from the first digital certificate includes obtaining content for supporting the quantum-resistant algorithm from the first digital certificate and obtaining the first content.

[0109] Here, the first digital certificate supports a quantum-resistant algorithm, the first digital certificate includes content for supporting the quantum-resistant algorithm, and the content index information is index information of the content for supporting the quantum-resistant algorithm in the first digital certificate.

[0110] Specifically, the content for supporting the quantum-resistant algorithm may include at least one of the public key of the first communication device or the signature of the certificate issuer that issues the first digital certificate. The first content may include at least one of the public key of the first communication device or the signature of the certificate issuer that issues the second digital certificate. The content index information of the first content may include at least one of public key index information or signature index information.

[0111] In some embodiments, in response to a first key negotiation request transmitted by the second communication device, the first communication device obtains content for supporting a quantum-resistant algorithm from the first digital certificate and obtains the first content.

[0112] In this embodiment, usually, since the amount of data of the content supporting the quantum-resistant algorithm is large, by compressing the content supporting the quantum-resistant algorithm, the amount of data can be effectively reduced and the compression effect can be improved.

[0113] In some embodiments, a network communication method is provided, and as an example, it is described that the method is applied to the first communication device and the second communication device in FIG. 1. As shown in FIG. 10, the method includes the following steps.

[0114] Step 1002: The second communication device sends an encrypted communication connection request to the first communication device.

[0115] Step 1004: The first communication device determines the certificate type of the first digital certificate in response to the encrypted communication connection request.

[0116] Step 1006: If the certificate type of the first digital certificate is the first certificate type, the first communication device sends a first request response result to the second communication device, and the first request response result includes the first digital certificate, and the amount of data of the digital certificate of the first certificate type is larger than the data amount threshold.

[0117] Step 1008: The second communication device actually receives the second digital certificate, and the second digital certificate is the digital certificate included in the actually received response result.

[0118] Step 1010: The second communication device sends a first key negotiation request to the first communication device.

[0119] Here, the first key negotiation request includes a first random number.

[0120] Step 1012: The first communication device sends a compressed digital certificate to the second communication device in response to the first key negotiation request.

[0121] Here, the compressed digital certificate is obtained by compressing the first digital certificate.

[0122] Step 1014: The second communication device compresses the second digital certificate to obtain a comparison digital certificate, and performs consistency verification on the comparison digital certificate and the compressed digital certificate.

[0123] Step 1016: In the consistency verification, the first communication device is authenticated based on the second digital certificate.

[0124] Step 1018: If the certificate type of the first digital certificate is the second certificate type, the first communication device transmits a second request response result for the encrypted communication connection request to the second communication device, and the second request response result does not include the first digital certificate, and the data volume of the digital certificate of the second certificate type is below the data volume threshold.

[0125] Here, the second key negotiation request includes the first random number.

[0126] Step 1020: The second communication device transmits a second key negotiation request to the first communication device in response to the received second request response result.

[0127] Step 1022: The first communication device transmits the first digital certificate to the second communication device in response to the second key negotiation request transmitted by the second communication device.

[0128] Step 1024: The second communication device authenticates the first communication device based on the first digital certificate.

[0129] Step 1026: If the authentication is successful, the first communication device and the second communication device generate an encrypted communication key.

[0130] Step 1028: The first communication device and the second communication device perform encrypted communication based on an encrypted communication key.

[0131] In this embodiment, when the certificate type of the first digital certificate is the first certificate type, a complete digital certificate is transmitted before key negotiation, and a compressed digital certificate is transmitted in the key negotiation procedure. When the data certificate is relatively large, the amount of data transmitted in the key negotiation procedure is reduced. When the certificate type of the first digital certificate is the second certificate type, a complete digital certificate is transmitted in the key negotiation procedure, that is, when the digital certificate is relatively small, by transmitting a complete digital certificate in the key negotiation procedure, the failure rate of key negotiation can be reduced and the success rate of key negotiation can be improved. Therefore, the efficiency of establishing an encrypted communication connection can be improved, and the communication efficiency can be improved.

[0132] Note that each step in the flowchart according to the above embodiments is sequentially displayed according to the indication of the arrow, but these steps are not necessarily sequentially executed according to the indication of the arrow. Unless explicitly stated in this specification, the execution of these steps is not limited to a strict order and may be executed in other orders. Also, at least a part of the steps in the flowchart according to the above embodiments may include a plurality of steps or a plurality of stages, and these steps or stages are not necessarily executed at the same timing and may be executed at different timings. The execution order of these steps or stages is not necessarily sequential, and may be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.

[0133] Based on the same inventive concept, embodiments of the present invention further provide a network communication device for implementing the above network communication method. The embodiments for problem solving provided by the device are the same as those described in the above method. Therefore, specific limitations in one or more embodiments of the network communication device provided below may refer to the limitations of the network communication method in the above description.

[0134] In some embodiments, a network communication device is provided. As shown in FIG. 11, the network communication device includes a connection request sending module 1102, a certificate receiving module 1104, a negotiation request sending module 1106, a verification module 1108, a first key generation module 1110, and a first encrypted communication module 1112.

[0135] The connection request sending module 1102 sends an encrypted communication connection request to the first communication device. The encrypted communication connection request is used to instruct the first communication device to return a first digital certificate.

[0136] The certificate receiving module 1104 receives a second digital certificate from the first communication device. The second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request.

[0137] The negotiation request sending module 1106 sends a first key negotiation request to the first communication device and receives a compressed digital certificate returned by the first communication device in response to the first key negotiation request. The compressed digital certificate is obtained by compressing the first digital certificate.

[0138] The verification module 1108 performs consistency verification based on the second digital certificate and the compressed digital certificate.

[0139] When the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful, the first key generation module 1110 generates an encrypted communication key.

[0140] The first encrypted communication module 1112 performs encrypted communication with the first communication device based on the encrypted communication key.

[0141] In some embodiments, the first digital certificate returned by the first communication device is returned by the first communication device in response to an encrypted communication connection request when the data volume of the first digital certificate is greater than the data volume threshold.

[0142] In some embodiments, when the data volume of the first digital certificate is less than or equal to the data volume threshold, the device receives a response result that does not include the first digital certificate returned by the first communication device, and in response to the response result, sends a second key negotiation request to the first communication device, receives the first digital certificate returned by the first communication device in response to the second key negotiation request, authenticates the first communication device based on the received first digital certificate, generates an encrypted communication key when the authentication is successful, and performs encrypted communication with the first communication device based on the encrypted communication key.

[0143] In some embodiments, the first digital certificate includes the first content and content index information corresponding to the first content. The compressed digital certificate is obtained by compressing the first content using a predetermined compression method. The verification module 1108 compresses the second content indicated by the content index information in the second digital certificate using the predetermined compression method to obtain the second compressed content, updates the second content to the second compressed content in the second digital certificate to obtain a comparison digital certificate, and performs integrity verification on the comparison digital certificate and the compressed digital certificate.

[0144] In some embodiments, the first digital certificate supports a quantum-resistant algorithm, and the first content is the content for supporting the quantum-resistant algorithm in the first digital certificate.

[0145] In some embodiments, a network communication device is provided. As shown in FIG. 12, the network communication device includes a connection request receiving module 1202, a certificate transmission module 1204, a negotiation request receiving module 1206, a negotiation request response module 1208, a second key generation module 1210, and a second encrypted communication module 1212.

[0146] The connection request receiving module 1202 receives an encrypted communication connection request transmitted by a second communication device.

[0147] The certificate transmission module 1204 transmits the first digital certificate to the second communication device in response to the encrypted communication connection request so that the second communication device actually receives the second digital certificate. The second digital certificate is used to authenticate the first communication device.

[0148] The negotiation request receiving module 1206 receives a first key negotiation request transmitted by a second communication device.

[0149] The negotiation request response module 1208 transmits a compressed digital certificate to the second communication device in response to the first key negotiation request. The compressed digital certificate is obtained by compressing the first digital certificate and is used to perform consistency verification with the second digital certificate.

[0150] The second key generation module 1210 generates an encrypted communication key when the consistency verification is successful and the authentication is successful.

[0151] The second encrypted communication module 1212 performs encrypted communication with the second communication device based on the encrypted communication key.

[0152] In some embodiments, when the data volume of the first digital certificate is greater than the data volume threshold, the certificate transmission module 1204 transmits the first digital certificate to the second communication device in response to the encrypted communication connection request.

[0153] In some embodiments, the device determines that the data volume of the first digital certificate is greater than the data volume threshold when the certificate type of the first digital certificate is the first certificate type.

[0154] In some embodiments, when the data volume of the first digital certificate is less than or equal to the data volume threshold, the device returns a response result that does not include the first digital certificate to the second communication device in response to the encrypted communication connection request. The device receives a second key negotiation request transmitted by the second communication device, and transmits the first digital certificate to the second communication device in response to the second key negotiation request. The second key negotiation request is returned by the second communication device in response to the response result that does not include the first digital certificate, and the first digital certificate is used by the second communication device to authenticate the first communication device. If the authentication is successful, an encrypted communication key is generated, and encrypted communication is performed with the second communication device based on the encrypted communication key.

[0155] In some embodiments, the device determines that the data volume of the first digital certificate is less than or equal to the data volume threshold when the certificate type of the first digital certificate is the second certificate type.

[0156] In some embodiments, the negotiation request response module 1208 determines the first content from the first digital certificate in response to the first key negotiation request, compresses the first content using a predetermined compression method to obtain the first compressed content, updates the first content with the first compressed content in the first digital certificate to obtain a compressed digital certificate, and transmits the compressed digital certificate to the second communication device.

[0157] In some embodiments, the first digital certificate supports a quantum-resistant algorithm. The negotiation request response module 1208 obtains the content for supporting the quantum-resistant algorithm from the first digital certificate and obtains the first content.

[0158] All or part of each module in the above network communication device may be implemented by software, hardware, and combinations thereof. Each of the above modules may be hardware-incorporated into a processor in a computer device or may be independent, or may be stored in a memory in the computer device in software for the processor to easily call the operations corresponding to each of the above modules.

[0159] In some embodiments, a computer device is provided, and the computer device may be a server and may have an internal structure shown in FIG. 13. This computer device includes a processor, a storage device, an input / output interface (abbreviated as Input / Output, I / O), and a communication interface. Here, the processor, the memory, and the input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface. Here, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and a memory. This non-volatile storage medium stores an operating system, a computer program, and a database. This memory provides an environment for the execution of the operating system and the computer program in the non-volatile storage medium. The database of this computer device is used to store data related to the network communication method. The input / output interface of this computer device is used to exchange information between the processor and an external device. The communication interface of this computer device is for communicating with an external terminal via a network connection. When this computer program is executed by the processor, it realizes the network communication method.

[0160] In some embodiments, a computer device is provided, which may be a terminal and may have an internal structure shown in FIG. 14. This computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Here, the processor, the memory, and the input / output interface are connected via a system bus, and the communication interface, the display unit, and the input device are connected to the system bus via the input / output interface. Here, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and a memory. This non-volatile storage medium stores an operating system and a computer program. This memory provides an environment for the execution of the operating system and the computer program in the non-volatile storage medium. The input / output interface of this computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal, either wired or wirelessly, and the wireless communication may be realized by WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When this computer program is executed by the processor, it realizes a network communication method. The display unit of this computer device is used to form a visually visible screen, and may be a display screen, a projection device, or a virtual reality image forming device, and the display screen may be a liquid crystal display screen or an electronic ink display screen. The input device of this computer device may be a touch layer covering the display screen, or a key, a trackball, or a trackpad installed on the case of the computer device, or an external keyboard, trackpad, mouse, etc.

[0161] A person skilled in the art would understand that the structures shown in FIGS. 13 and 14 are merely block diagrams of partial structures related to the solution means of the present invention and do not constitute a limitation of the computer device to which the solution means of the present invention is applied. A specific computer device can include more or fewer components than those shown, can combine certain components, or can have different arrangements of components.

[0162] In some embodiments, there is provided a computer device including a memory storing computer-readable instructions and one or more processors, and when the processor executes the computer-readable instructions, the steps of the above network communication method are realized.

[0163] In some embodiments, there is provided a one or more readable storage media storing computer-readable instructions, and when the computer-readable instructions are executed by a processor, the steps of the above network communication method are realized.

[0164] In some embodiments, there is provided a computer program product including computer-readable instructions, and when the computer-readable instructions are executed by one or more processors, the steps of the above network communication method are realized.

[0165] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) related to the present invention are all information and data fully authorized by the user or the parties. The collection, use, and processing of related data need to comply with the relevant laws and regulations and standards of the country and region.

[0166] A person skilled in the art would understand that implementing all or part of the process of the method in the above embodiments can be achieved by instructing the relevant hardware by a computer program stored in a non-volatile computer-readable storage medium that can include a process such as the method embodiment in the above method during execution. Here, any reference to the memory, database, or other medium used in each embodiment according to the present invention can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, and the like. Volatile memory can include random access memory (RAM) or external cache memory, etc. As a non-limiting example, RAM can be in various forms such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database related to the embodiments according to the present invention can include at least one of a relational database and a non-relational database. The non-relational database may include, but is not limited to, a blockchain-based distributed database, etc. The processor related to the embodiments according to the present invention may be a general-purpose processor, a central processor, a graphics processor, a digital signal processor, a programmable logic circuit, a data processing logic circuit based on quantum computing, etc., and is not limited thereto.

[0167] Each of the technical features of the above embodiments can be arbitrarily combined. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments have been described. However, as long as there is no contradiction in the combination of these technical features, it should be considered within the scope described in this specification.

[0168] The above embodiments only show some embodiments of the present invention, and the description is more specific and detailed. Therefore, it should not be construed as limiting the patent scope of the present invention. Those skilled in the art can make some modifications and improvements within the scope of the present invention without departing from the concept of the present invention. Therefore, the protection scope of the present invention shall be subject to the appended claims.

Claims

1. A network communication method executed by a second communication device, comprising the step of sending an encrypted communication connection request to a first communication device, wherein the encrypted communication connection request is used to instruct the first communication device to return a first digital certificate; the step of receiving a second digital certificate from the first communication device, wherein the second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request; the step of sending a first key negotiation request to the first communication device and receiving a compressed digital certificate returned by the first communication device in response to the first key negotiation request, wherein the compressed digital certificate is obtained by compressing the first digital certificate; the step of performing integrity verification based on the second digital certificate and the compressed digital certificate; the step of generating an encrypted communication key when the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful; and the step of performing encrypted communication with the first communication device based on the encrypted communication key. A method comprising the above steps.

2. The method according to claim 1, wherein the first digital certificate returned by the first communication device is returned by the first communication device in response to the encrypted communication connection request when the data amount of the first digital certificate is greater than a data amount threshold.

3. When the data amount of the first digital certificate is less than or equal to a data amount threshold, the step of receiving a response result returned by the first communication device and not including the first digital certificate; and the step of sending a second key negotiation request to the first communication device in response to the response result. Receiving the first digital certificate returned by the first communication device in response to the second key negotiation request; Authenticating the first communication device based on the received first digital certificate; When the authentication is successful, generating an encrypted communication key; Performing encrypted communication with the first communication device based on the encrypted communication key, the method according to claim 2, further comprising.

4. The first digital certificate includes first content and content index information corresponding to the first content, The compressed digital certificate is obtained by compressing the first content using a predetermined compression method, The step of performing consistency verification based on the second digital certificate and the compressed digital certificate includes: Compressing the second content indicated by the content index information in the second digital certificate using the predetermined compression method to obtain a second compressed content; In the second digital certificate, updating the second content to the second compressed content to obtain a comparison digital certificate; Performing consistency verification on the comparison digital certificate and the compressed digital certificate, the method according to claim 1.

5. The first digital certificate supports a quantum-resistant algorithm, The first content is content for supporting the quantum-resistant algorithm in the first digital certificate, the method according to claim 4.

6. A network communication method executed by a first communication device, comprising: Receiving an encrypted communication connection request transmitted by a second communication device; In response to the encrypted communication connection request, transmitting a first digital certificate to the second communication device so that the second communication device actually receives the second digital certificate, wherein the second digital certificate is used for authenticating the first communication device; Receiving a first key negotiation request transmitted by the second communication device; In response to the first key negotiation request, transmitting a compressed digital certificate to the second communication device, wherein the compressed digital certificate is obtained by compressing the first digital certificate and is used for performing consistency verification with the second digital certificate; Generating an encrypted communication key when the consistency verification is successful and the authentication is successful; Performing encrypted communication with the second communication device based on the encrypted communication key. A method comprising the above steps.

7. The step of transmitting a first digital certificate to the first communication device in response to the encrypted communication connection request includes: When the data volume of the first digital certificate is greater than a data volume threshold, transmitting a first digital certificate to the second communication device in response to the encrypted communication connection request. The method according to claim 6.

8. The method according to claim 7, further comprising: determining that the data volume of the first digital certificate is greater than a data volume threshold when the certificate type of the first digital certificate is a first certificate type.

9. When the data volume of the first digital certificate is less than or equal to a data volume threshold, returning a response result not including the first digital certificate to the second communication device in response to the encrypted communication connection request; Receiving a second key negotiation request transmitted by the second communication device, and in response to the second key negotiation request, transmitting the first digital certificate to the second communication device, wherein the second key negotiation request is returned by the second communication device in response to a response result that does not include the first digital certificate, and the first digital certificate is used by the second communication device to authenticate the first communication device; When authentication is successful, generating an encrypted communication key and performing encrypted communication with the second communication device based on the encrypted communication key, the method according to claim 6, further comprising.

10. When the certificate type of the first digital certificate is a second certificate type, determining that the data amount of the first digital certificate is less than or equal to a data amount threshold, the method according to claim 9, further comprising.

11. The step of transmitting a compressed digital certificate to the second communication device in response to the first key negotiation request is Determining first content from the first digital certificate in response to the first key negotiation request; Compressing the first content using a predetermined compression method to obtain first compressed content; Updating the first content to the first compressed content in the first digital certificate to obtain the compressed digital certificate; Transmitting the compressed digital certificate to the second communication device, the method according to claim 6, comprising.

12. The first digital certificate supports a quantum-resistant algorithm, The step of determining first content from the first digital certificate is Obtaining content for supporting a quantum-resistant algorithm from the first digital certificate to obtain first content, the method according to claim 11, comprising.

13. A network communication device configured in a second communication device, A connection request transmission module that transmits an encrypted communication connection request to a first communication device, wherein the encrypted communication connection request is used to instruct the first communication device to return a first digital certificate, and the connection request transmission module; A certificate reception module that receives a second digital certificate from the first communication device, wherein the second digital certificate is the digital certificate actually received by the second communication device after the first communication device returns the first digital certificate in response to the encrypted communication connection request, and the certificate reception module; A negotiation request transmission module that transmits a first key negotiation request to the first communication device and receives a compressed digital certificate returned by the first communication device in response to the first key negotiation request, wherein the compressed digital certificate is obtained by compressing the first digital certificate, and the negotiation request transmission module; A verification module that performs integrity verification based on the second digital certificate and the compressed digital certificate; A first key generation module that generates an encrypted communication key when the integrity verification is successful and the authentication of the first communication device based on the second digital certificate is successful; A first encrypted communication module that performs encrypted communication with the first communication device based on the encrypted communication key.

14. A network communication device configured in a first communication device, A connection request reception module that receives an encrypted communication connection request transmitted by a second communication device; A certificate transmission module that transmits a first digital certificate to the second communication device in response to the encrypted communication connection request so that the second communication device actually receives the second digital certificate, wherein the second digital certificate is used to authenticate the first communication device, and the certificate transmission module; A negotiation request receiving module that receives a first key negotiation request transmitted by the second communication device; A negotiation request response module that transmits a compressed digital certificate to the second communication device in response to the first key negotiation request, wherein the compressed digital certificate is obtained by compressing the first digital certificate and is used for performing consistency verification with the second digital certificate; A second key generation module that generates an encrypted communication key when the consistency verification is successful and the authentication is successful; An apparatus including a second encrypted communication module that performs encrypted communication with the second communication device based on the encrypted communication key.

15. A computer device including a memory storing computer-readable instructions and one or more processors, wherein when the processor executes the computer-readable instructions, the steps of the method according to any one of Claims 1 to 12 are realized.

16. A computer program including computer-readable instructions, wherein when the computer-readable instructions are executed by one or more processors, the steps of the method according to any one of Claims 1 to 12 are realized.

Citation Information

Patent Citations

  • Identity verification method for handshake process of TLCP protocol

    CN115021932A

  • Method, server and system for communication support

    JP2006311622A

  • Radio device

    JP2014014012A

  • Methods and Electronic Devices for Verifying Device Identity During Secure Pairing

    US20230023647A1