Communication method and related apparatus
The TBPEKE algorithm on elliptic curves addresses security vulnerabilities in short-distance communication by generating intermediate keys from security and common parameters, enhancing key security and reducing unauthorized access in intelligent vehicles and smart devices.
Patent Information
- Application Number
- JP2024570839
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-05-31
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-05-31
AI Technical Summary
Existing short-distance communication technologies in intelligent vehicles and smart devices face security vulnerabilities, allowing hackers to access in-vehicle information systems and threaten user privacy and security due to weak security parameters and easy cracking of shared keys.
A communication method using a Two-Basis Password Exponential Key Exchange (TBPEKE) algorithm based on elliptic curve cryptography, where intermediate parameters are generated from security and common parameters, avoiding direct use of security parameters to reduce the risk of key cracking and improve communication security.
Enhances the security of shared keys by reducing the likelihood of unauthorized access, thereby improving the confidentiality and integrity of communications between nodes.
Smart Images

Figure 2025521158000001_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of communication technology and intelligent vehicle technology, and in particular, to the field of short-distance communication technology, for example, communication in scenarios such as intelligent vehicles, smart homes, smart terminals, and smart manufacturing. Specifically, the present application relates to a communication method and related devices.
Background Art
[0002] Today, with the rapid development of informatization, mobile terminals, mobile phones, tablet computers, or other portable smart terminals are indispensable personal intelligent tools. While enjoying the convenience brought by informatization, people are also facing the threats of security vulnerabilities and privacy leakage. As an example, intelligent vehicles are used. As vehicle communication is widely applied, wireless communication also brings a series of security risks to vehicles. For example, hackers can use existing short-distance communication technologies to break into in-vehicle information systems, obtain vehicle information, or even remotely control vehicles. This poses a very high threat to user privacy and vehicle security.
[0003]
[0004] For example, when a mobile phone accesses a Wireless Fidelity (Wi-Fi) device, an 8-bit security parameter (the security parameter in this scenario is the Wi-Fi password) is directly input, and the mobile phone and the Wi-Fi device can obtain a shared key. Since the security parameter may have a small number of bits or the user uses a simple security parameter for easy memorization, the device may be easily accessed by untrusted nodes, or the key generated based on the security parameter may be cracked. It can be easily known that this access mode may cause data leakage and threaten the user's privacy and security.
[0005] Therefore, how to improve the security of the shared key and avoid access by untrusted attackers is a technical problem being studied by those skilled in the art.
Summary of the Invention
[0006] Embodiments of the present application provide a communication method and related devices for improving the security of a shared key and avoiding access by untrusted attackers.
Means for Solving the Problems
[0007] According to a first aspect, an embodiment of the present application provides a communication method. The method includes receiving, from a first node, a first message, where the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first secret key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is a first password or a pre-shared key PSK between the first node and a second node, and the first password is an agreed access password between the first node and the second node; Sending a second message to the first node, wherein the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second secret key and an intermediate parameter; Obtaining a first key based on the first key agreement parameter and the second secret key; comprising.
[0008] The PSK between the first node and the second node is a secret value shared between the first node and the second node, and the first password can be regarded as the password for the first node to access the second node. The first secret key is the secret key corresponding to the first node. For example, the first node can determine a random number as the secret key. The second secret key is the secret key corresponding to the second node. For example, the second node can determine a random number as the secret key.
[0009] Optionally, the foregoing method may be applied to the second node, which is implemented, for example, by using a chip or a software module in the second node.
[0010] In the present embodiment of the present application, the intermediate parameter is first obtained based on the security parameter and the common parameter, and the intermediate parameter is used to generate the first key agreement parameter. The security parameter is not directly used to generate a key, and the security parameter is not directly used to generate a key agreement parameter. Therefore, even if the number of bits of the security parameter is small, the confidentiality of the security parameter can be improved by using the common parameter, and the possibility that the security parameter is cracked can be reduced. Correspondingly, the security of the first key is improved. Thereby, the possibility for an attacker to access the second node can be reduced, and the communication security and data security of the node can be improved.
[0011] In a possible implementation of the first aspect, the method is Receiving a third message from a first node, wherein the third message includes first authentication information, the first authentication information is associated with a second key, and the second key is associated with a second key agreement parameter and a first private key; Verifying the first authentication information based on a first key; further comprising.
[0012] In this embodiment of the present application, the security parameters obtained by the first node need to match the security parameters of the second node. In this way, the first node and the second node can participate in the generation of consistent keys using consistent security parameters. Specifically, the parameters used by the second node to generate the first key include a second private key, a security parameter (at the first node), a common parameter, and a first private key, and the parameters used by the first node to generate the second key include a first private key, a security parameter (at the second node), a common parameter, and a second private key. Since the parameters used to generate the first key and the parameters used to generate the second key are the same, when the security parameters of the first node and the security parameters of the second node match, the generated first key and the generated second key match.
[0013] The first node can obtain the first authentication information based on the second key, and the second node verifies the authentication information based on the first key. If the verification is successful, it indicates that the first key matches the second key, that is, the second node and the first node have the same security parameters. This indicates that the identification information of the second node is trusted.
[0014] When the attacker requests access to the second node, since the attacker does not have a security parameter that matches the security parameter of the second node, the attacker cannot generate a shared key that matches the security parameter of the second node. Therefore, the attacker cannot access the second node. This can prevent the attacker from accessing the second node and prevent the second node from being normally associated with an attacker having untrusted identification information.
[0015] In yet another possible implementation of the first aspect, the first key is used to obtain one or more keys.
[0016] In a possible solution, the first key is used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, and the like.
[0017] In this way, a dedicated key can be obtained by derivation based on the first key in different scenarios. This avoids the direct use of the first key in communication and further improves the security of the first key.
[0018] In yet another possible implementation of the first aspect, the method is When the verification of the first authentication information is successful, the step of sending an association establishment message to the first node is further included.
[0019] In the foregoing embodiments, when the verification of the first authentication information is successful, the second key obtained by the first node matches the first key obtained by the second node. Therefore, this indicates that the security parameters of the first node match the security parameters of the second node, and the identification information of the first node is trusted. The association establishment message indicates that the first node has successfully accessed the second node or that the association of the first node has been completed. In this case, between the second node and the second node, the following data transmission operations, determination of communication keys, completion of communication configuration information, etc. can be performed.
[0020] In still another possible embodiment of the first aspect, the method When the verification of the integrity of the first authentication information and the third message is successful, the step of sending an association establishment message to the first node is further included.
[0021] In the foregoing embodiments, the second node can verify the message integrity of the third message. When the verification of the integrity of the third message and the verification of the first authentication information are successful, an association establishment message is sent to the first node.
[0022] In still another possible embodiment of the first aspect, the method The step of receiving the indication information of the key agreement algorithm sent by the first node, wherein the key agreement algorithm includes a Two-Basis Password Exponential Key Exchange (TBPEKE) algorithm is further included.
[0023] Optionally, the indication information of the key agreement algorithm includes the indication information of the first key agreement algorithm, and the indication information of the first key agreement algorithm indicates the TBPEKE algorithm.
[0024] The TBPEKE algorithm is a security algorithm implemented based on the elliptic curve mathematical theory, which can enable two communicating parties to create a key on an insecure channel, and the key can be used as a key for encrypting communication content in subsequent communications.
[0025] In the foregoing embodiments, the first node and the second node can separately support a plurality of key agreement algorithms. When the first node requests access to the second node, the first node can instruct the second node in the first message as to which key agreement algorithm should be used, so that the first node and the second node can agree on a key based on a consistent key agreement algorithm. This improves the key agreement efficiency.
[0026] Optionally, since different elliptic curves are used, there may be a plurality of TBPEKE algorithms. For example, the elliptic curve used by the TBPEKE algorithm includes one or more of the elliptic curves defined by SM2, Curve25519, etc. Therefore, the TBPEKE algorithm can include a TBPEKE algorithm using the elliptic curve defined by SM2, a TBPEKE algorithm using Curve25519, etc. It should be understood that the above is an exemplary description for facilitating the explanation of the TBPEKE algorithm using different elliptic curves. In a specific embodiment process, other elliptic curves may alternatively be used. Examples are not enumerated herein.
[0027] In yet another possible embodiment of the first aspect, at least one common parameter includes a first common parameter and a second common parameter.
[0028] The first common parameter and the second common parameter are related to a first elliptic curve, the first elliptic curve is an elliptic curve corresponding to a key agreement algorithm, and the key agreement algorithm includes the TBPEKE algorithm.
[0029] In the foregoing embodiments, the common parameter is a point on an elliptic curve, and the security parameter is a secret value. Due to the discrete logarithm problem of the elliptic curve, it is easy to obtain intermediate parameters by calculation based on the security parameter and the common parameter. However, it is difficult to obtain the first key agreement parameter and the common parameter to crack the security parameter. Therefore, by using the TBPEKE algorithm and the common parameter, the possibility of cracking the security parameter can be reduced, and node security can be improved.
[0030] In yet another possible embodiment of the first aspect, the first common parameter and the second common parameter belong to points on the first elliptic curve.
[0031] In yet another possible embodiment of the first aspect, the first common parameter is predefined, and the second common parameter is determined based on the first common parameter, the first random number, and the second random number, where the first random number is derived from the first node and the second random number is derived from the second node.
[0032] In a possible embodiment of the first aspect, at least one common parameter includes at least one base point, and at least one base point belongs to a group whose order is p, where p is a prime number.
[0033] Mathematically, a group represents an algebraic structure having a binary operation that satisfies the laws of closure and associativity and has an identity element and an inverse element. In this embodiment of the present application, the operation related to the group may be an operation on the first elliptic curve. The operation on the elliptic curve includes one or more operations such as an elliptic curve point multiplication operation and an elliptic curve point addition operation.
[0034] Optionally, in this embodiment of the present application, the group may be a cyclic subgroup of the elliptic curve.
[0035] The base point, also called a generator, is a parameter in the elliptic curve cryptography algorithm. The base point belongs to a point on the elliptic curve selected by the cryptographic algorithm.
[0036] Generally, the elliptic curve applicable to the cryptographic algorithm is defined over a finite field. Therefore, the points on the elliptic curve in the finite field are also limited.
[0037] The order is the number of points in the group. That is, in a group with order p, the number of points on the elliptic curve is p. Optionally, for any point A in the group, A = d * base point, where * is the elliptic curve point multiplication operation, and the value range of d is [1, p - 1].
[0038] Optionally, the above group may be a cyclic group or a cyclic subgroup related to the operation on the first elliptic curve.
[0039] Optionally, in some scenarios, the base point may be alternatively replaced by a generator.
[0040] In yet another possible implementation of the first aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes some or all elements in a group with order p, where p is a prime number.
[0041] The base point (or called a generator) of the subgroup with order p is U. For a selected number d, when the value range of d is [1, p - 1], dU is included in the group.
[0042] Optionally, at least one common parameter includes the base point U. Further optionally, at least one common parameter further includes V obtained by performing an operation on U, where V = dU and the range of d is [1, p).
[0043] In yet another possible implementation of the first aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes two points within a group whose order is p, where p is a prime number.
[0044] Optionally, the two points may be two base points. Alternatively, one of the two points is taken as the base point, and the other is taken as a second base point obtained by a calculation based on the base point. For ease of explanation, in this application, the two points are referred to as the first base point and the second base point.
[0045] In yet another possible implementation of the first aspect, when the selected key agreement algorithm is the TBPEKE algorithm, the common parameters of the TBPEKE algorithm include a cyclic group whose order is a prime number p, and two independent base points U and V within the group.
[0046] It should be understood that "independent" means that U and V are two points with different values, and it is not intended to constitute a limitation that there is no relationship between U and V. Optionally, U may be referred to as the first base point, and V may be referred to as the second base point.
[0047] In yet another possible implementation of the first aspect, the method includes receiving a first calculated value from a first node, where the first calculated value is related to a first random number and a first common parameter, the first random number is determined by the first node, and the first common parameter is predefined (e.g., predefined based on the TBPEKE algorithm), determining a second common parameter based on the second random number and the first calculated value, sending a second calculated value to the first node, where the second calculated value is related to the second random number and the first common parameter, and the second calculated value is used by the first node to determine the second common parameter, and further includes.
[0048] Optionally, the first common parameter is the aforementioned first base point, and the second common parameter is the aforementioned second base point.
[0049] In yet another possible implementation of the first aspect, the intermediate parameter satisfies the following equation. b = U + s * V, where b is the intermediate parameter, U and V are at least one common parameter, s is the security parameter, "*" is the elliptic curve point multiplication operation, and "+" is the elliptic curve point addition operation.
[0050] In a possible implementation of the first aspect, U is the first base point and V is the second base point. Further, U and V belong to a cyclic group whose order is p, where p is a prime number.
[0051] Optionally, the operation related to the group is an operation on the first elliptic curve. The first elliptic curve is the elliptic curve used by the selected key agreement algorithm. For example, if the selected key agreement algorithm is the TBPEKE algorithm, the first elliptic curve may be an elliptic curve defined by SM2, Curve25519, etc.
[0052] In the aforementioned implementation, the intermediate parameter (U + s * V) is obtained by performing point addition and point multiplication operations on the security parameter and the common parameter.
[0053] A person skilled in the art should recognize that for a selected elliptic curve Ep(a, b), given a scalar k and a point P (where point P is on the elliptic curve), it is easy to calculate R = k * P (* is the elliptic curve point multiplication operation). However, when points P and R are given (when points P and R are on the elliptic curve), it is extremely difficult to calculate which k satisfies kP = R. In the actual use of elliptic curves, in principle, P is quite large and R is also quite large. Calculating k points one by one and comparing them with R is a mathematical problem. Therefore, by using the same parameters as the TBPEKE algorithm, the possibility of cracking the security parameter s can be reduced, and node security can be improved.
[0054] In yet another possible implementation of the first aspect, the first key agreement parameter KEt satisfies the following equation: KEt = SKt * b, The first key satisfies the following equation: The first key = SKg * KEt, The second key agreement parameter KEg satisfies the following equation: KEg = SKg * b, The second key satisfies the following equation: The second key = SKt * KEg, where SKt is the first secret key and SKg is the second secret key.
[0055] Since the point multiplication operation satisfies the associative law, the first key = SKg * KEt = SKg * (SKt * b) = SKt * (SKg * b) = the second key. Therefore, the first key determined by the first node is the same as the second key determined by the second node.
[0056] Specifically, the first key = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V), the second key = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V), where "." is the multiplication operation. Therefore, the first key is the same as the second key.
[0057] The foregoing embodiments provide a possible method for obtaining the first key agreement parameter, the second key agreement parameter, the first key, and the second key when the first key agreement parameter and the second key agreement parameter are generated. Thus, instead of directly using the security parameter in calculations, intermediate parameters are first obtained based on the security parameter and the common parameter, and the intermediate parameters are used to generate the first key agreement parameter. This reduces the possibility of the security parameter being cracked, reduces the possibility of an attacker accessing the second node, and improves the communication security and data security of the nodes.
[0058] In yet another possible embodiment of the first aspect, the range of values of the first secret key (SKt) is [1, p), the range of values of the second secret key (SKg) is [1, p), and p is the degree of the elliptic curve used by the TBPEKE algorithm.
[0059] In yet another possible embodiment of the first aspect, before the step of receiving the first message from the first node, the method includes the step of broadcasting the key agreement algorithm capabilities of the second node, where the key agreement algorithm capabilities of the second node represent the key agreement algorithms supported by the second node. further includes.
[0060] In yet another possible embodiment of the first aspect, the key agreement algorithms supported by the first node are sorted according to priority.
[0061] In yet another possible embodiment of the first aspect, the first message further includes a first freshness parameter, the first message further includes a first freshness parameter, and the first authentication information is associated with a pre-shared key PSK between the first node and the second node, the second key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node.
[0062] In yet another possible implementation of the first aspect, the step of verifying the first authentication information based on the first key is the step of verifying the first authentication information based on the PSK between the first node and the second node, the first key, the second message, the first freshness parameter, and the key agreement algorithm capability of the second node including.
[0063] In the foregoing embodiments, the parameters used to generate the first authentication information include one or more of the PSK between the first node and the second node, the second key, the second message, the first freshness parameter, and the key agreement algorithm capability of the second node. In this way, when the first authentication information is verified, except that the first key and the second key need to match, the other parameters used to generate the first authentication information need to match so that the verification can succeed. In this way, the integrity of the foregoing parameters can be protected, the possibility that the second node is accessed by an attacker can be reduced, and the security can be improved.
[0064] For example, if the first freshness parameter sent from the first node to the second node is tampered with, the first freshness parameter used when the second node verifies the first authentication information is different from the first freshness parameter used when the second node generates the first authentication information. As a result, the verification of the first authentication information fails.
[0065] In yet another possible implementation of the first aspect, the second message further includes second authentication information and a second freshness parameter, and the method further includes the step of obtaining the second authentication information based on the PSK between the first node and the second node, the first key, the second freshness parameter, and the first message including.
[0066] In the foregoing embodiments, the second authentication information can be used by the first node to authenticate the identification information of the second node. For example, the second node can generate verification information based on the same parameters. If the verification information is the same as the first authentication information, it indicates that the second key generated by the first node matches the first key generated by the second node, and as a result, the identification information of the second node can be authenticated. This can avoid communication between the node and the attacker and improve node security.
[0067] In yet another possible embodiment of the first aspect, the first message further includes a first fresh parameter, the second message further includes a second fresh parameter, and the method obtaining a third key based on the first key, the first fresh parameter, and the second fresh parameter further includes.
[0068] In yet another possible embodiment of the first aspect, the PSK is pre-configured or pre-defined, or obtained based on the first password.
[0069] In yet another possible embodiment of the first aspect, the method obtaining a PSK between the first node and the second node according to the first correspondence relationship further includes.
[0070] It may be known that the second node can store the correspondence relationship between the PSK and the first node in the form of a correspondence relationship. Therefore, according to the correspondence relationship, the PSK between the first node and the second node can be obtained.
[0071] In yet another possible embodiment of the first aspect, the method determining a PSK between the first node and the second node based on the first password, the first fresh parameter, and the second fresh parameter further includes.
[0072] In a possible design, the PSK is determined based on a first password, a first key, a first freshness parameter, and a second freshness parameter. For example, when a first node is first associated with a second node, or when the second node does not obtain the PSK corresponding to the first node, the second node can determine a new PSK.
[0073] According to a second aspect, an embodiment of the present application provides a communication method. The method includes transmitting a first message to a second node, where the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first private key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is a first password or a pre-shared key PSK between the first node and the second node, and the first password is an agreed access password between the first node and the second node; receiving a second message from the second node, where the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second private key and an intermediate parameter; obtaining a second key based on the second key agreement parameter and the first private key; and.
[0074] In a possible implementation of the second aspect, the method further includes transmitting a third message to the first node, where the third message includes first authentication information, and the first authentication information is associated with the second key. optionally.
[0075] Optionally, the foregoing method may be applied to the first node, for example, by using a chip or a software module in the first node.
[0076] The PSK between the first node and the second node is a secret value shared between the first node and the second node, and the first password can be regarded as the password for the first node to access the second node.
[0077] In a possible implementation of the second aspect, the second key is used to obtain one or more keys.
[0078] In a possible solution, the second key is used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, etc.
[0079] In a possible implementation of the second aspect, the method further includes the step of receiving an association establishment message from the second node.
[0080] In yet another possible implementation of the second aspect, before the step of sending a first message to the second node, the method includes the step of selecting a first key agreement algorithm based on the key agreement algorithm capability of the second node, where the key agreement algorithm capability of the second node can indicate one or more key agreement algorithms supported by the second node further includes.
[0081] In yet another possible implementation of the second aspect, the method includes the step of sending instruction information of a key agreement algorithm to the second node, where the instruction information of the key agreement algorithm indicates the two-base password exponential function key exchange TBPEKE algorithm further includes.
[0082] The TBPEKE algorithm is a security algorithm implemented based on the elliptic curve mathematical theory, which can enable two communicating parties to create a key over an insecure channel, and the key can be used as the key for encrypting communication content in subsequent communications.
[0083] Optionally, different elliptic curves are used, so there may be multiple TBPEKE algorithms. For example, the elliptic curve used by the TBPEKE algorithm includes one or more of the elliptic curves defined by SM2, Curve25519, etc. Therefore, the TBPEKE algorithm can include a TBPEKE algorithm using the elliptic curve defined by SM2, a TBPEKE algorithm using Curve25519, etc.
[0084] In yet another possible implementation of the second aspect, at least one common parameter includes a first common parameter and a second common parameter.
[0085] The first common parameter and the second common parameter are related to a first elliptic curve, the first elliptic curve is the elliptic curve corresponding to the key agreement algorithm, and the key agreement algorithm includes the TBPEKE algorithm.
[0086] In yet another possible implementation of the second aspect, the first common parameter and the second common parameter belong to points on the first elliptic curve.
[0087] In yet another possible implementation of the second aspect, the first common parameter is predefined, and the second common parameter is determined based on the first common parameter, the first random number, and the second random number. The first random number is derived from the first node, and the second random number is derived from the second node.
[0088] In a possible implementation of the second aspect, at least one common parameter includes at least one base point, and the at least one base point belongs to a group whose order is p, where p is a prime number.
[0089] Optionally, the group may be a cyclic group or a cyclic subgroup related to the operations on the first elliptic curve.
[0090] Optionally, in some scenarios, the base point may alternatively be replaced by a generator.
[0091] In yet another possible implementation of the second aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes some or all of the elements in a group whose order is p, where p is a prime number.
[0092] The base point (or called a generator) of the subgroup whose order is p is U. For a selected number d, if the range of the value of d is [1, p - 1], dU is included in the group.
[0093] Optionally, at least one common parameter includes the base point U. Further, optionally, at least one common parameter further includes V obtained by performing an operation on U, where V = dU and the range of d is [1, p - 1].
[0094] In yet another possible implementation of the second aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes two points in a group whose order is p.
[0095] Optionally, the two points may be two base points. Alternatively, one of the two points is taken as the base point and the other is taken as a second base point obtained by a calculation based on the base point. For ease of explanation, in this application, the two points are referred to as the first base point and the second base point.
[0096] In yet another possible implementation of the second aspect, when the selected key agreement algorithm is the TBPEKE algorithm, the common parameters of the TBPEKE algorithm include a cyclic group whose order is a prime number p and two independent base points U and V in the group.
[0097] It should be understood that "independent" does not mean that U and V are two points with different values and is not intended to constitute a limitation that there is no relationship between U and V.
[0098] In yet another possible implementation of the second aspect, the method transmitting a first calculated value to a second node, wherein the first calculated value is related to a first random number and a first common parameter, the first random number is determined by the first node, and the first common parameter is predefined; receiving a second calculated value from the second node, wherein the second calculated value is related to a second random number and the first common parameter; determining a second common parameter based on the second random number and the first calculated value; and further comprising.
[0099] Optionally, the first common parameter is the aforementioned first base point, and the second common parameter is the aforementioned second base point.
[0100] In a possible implementation of the second aspect, the first key agreement algorithm is a key agreement algorithm supported by the first node, and the first key agreement algorithm has the highest priority among the key agreement algorithms supported by the second node.
[0101] In a possible implementation of the second aspect, the intermediate parameter satisfies the following equation. b = U + s * V, where b is the intermediate parameter, U and V are at least one common parameter, s is a security parameter, "*" is an elliptic curve point multiplication operation, and "+" is an elliptic curve point addition operation.
[0102] In a possible implementation of the second aspect, U is the first base point and V is the second base point. Further, U and V belong to a group with order p, where p is a prime number. The operation with respect to the group is an operation on the first elliptic curve.
[0103] The first elliptic curve is the elliptic curve used by a selected key agreement algorithm. For example, if the selected key agreement algorithm is the TBPEKE algorithm, the first elliptic curve may be an elliptic curve defined by SM2, Curve25519, etc.
[0104] In a possible implementation of the second aspect, the first key agreement parameter KEt satisfies the following formula: KEt = SKt * b, The first key satisfies the following formula: The first key = SKg * KEt, The second key agreement parameter KEg satisfies the following formula. KEg = SKg * b, The second key satisfies the following formula: The second key = SKt * KEg, where SKt is the first secret key and SKg is the second secret key.
[0105] Since the point multiplication operation satisfies the associative law, the first key = SKg * KEt = SKg * (SKt * b) = SKt * (SKg * b) = the second key. Therefore, the first key determined by the first node is the same as the second key determined by the second node.
[0106] Specifically, the first key = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V), the second key = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V), where "." is the multiplication operation. Therefore, the first key is the same as the second key.
[0107] In a possible implementation of the second aspect, the range of values of the first secret key (SKt) is [1, p), the range of values of the second secret key (SKg) is [1, p), and p is the order of the elliptic curve used by the TBPEKE algorithm.
[0108] In a possible implementation of the second aspect, before the step of sending the first message to the second node, the method receiving, at the second node, the key agreement algorithm capabilities sent by the second node, the key agreement algorithm capabilities of the second node representing the key agreement algorithms supported by the second node; further includes.
[0109] In a possible implementation of the second aspect, the key agreement algorithms supported by the first node are sorted according to priority.
[0110] In a possible implementation of the second aspect, the first message further includes a first freshness parameter, and the first authentication information is associated with a pre-shared key PSK between the first node and the second node, the second key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node.
[0111] In a possible implementation of the second aspect, the second message further includes second authentication information and a second freshness parameter, and the second authentication information is associated with the PSK between the first node and the second node, the first key, the second freshness parameter, and the first message.
[0112] In a possible implementation of the second aspect, the method verifying the second authentication information based on the PSK between the first node and the second node, the second key, the second freshness parameter, and the first message; When the verification of the second authentication information and the integrity of the second message is successful, generating the first authentication information; further includes.
[0113] In a possible implementation of the second aspect, the first message further includes a first freshness parameter, the second message further includes a second freshness parameter, and the method obtaining a fourth key based on the second key, the first freshness parameter, and the second freshness parameter further includes.
[0114] In a possible implementation of the second aspect, the PSK is pre-configured or pre-defined, or obtained based on the first password.
[0115] In yet another possible implementation of the second aspect, the method obtaining the PSK between the first node and the second node according to the second correspondence relationship further includes.
[0116] It may be known that the first node can store the correspondence relationship between the PSK and the second node in the form of a correspondence relationship. Therefore, according to the correspondence relationship, the PSK between the first node and the second node can be obtained.
[0117] In yet another possible implementation of the second aspect, the method determining the PSK between the first node and the second node based on the first password, the first freshness parameter, and the second freshness parameter further includes.
[0118] In a possible design, the PSK is determined based on a first password, a first key, a first freshness parameter, and a second freshness parameter. When the first node is first associated with the second node, or when the first node does not obtain the PSK corresponding to the second node, the first node can determine a new PSK.
[0119] According to a third aspect, an embodiment of the present application provides a communication device. The communication device includes a receiving unit, a transmitting unit, and a processing unit, and the communication device is configured to implement the method described in any implementation manner of the first aspect.
[0120] In a possible implementation manner of the third aspect, the receiving unit is configured to receive a first message from the first node, the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first private key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is a first password or a pre-shared key PSK between the first node and the second node, and the first password is an agreed access password between the first node and the second node.
[0121] The transmitting unit is further configured to transmit a second message to the first node, the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second private key and an intermediate parameter.
[0122] The processing unit is configured to obtain a first key based on the first key agreement parameter and the second private key.
[0123] In a possible implementation manner of the third aspect, the receiving unit is further configured to receive a third message from the first node, the third message includes first authentication information, the first authentication information is associated with a second key, and the second key is associated with a second key agreement parameter and a first private key.
[0124] The processing unit is further configured to verify the first authentication information based on the first key.
[0125] In yet another possible embodiment of the third aspect, the first key is used to obtain one or more keys.
[0126] In a possible solution, the first key is used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, etc. In yet another possible embodiment of the third aspect, the transmission unit transmits an association establishment message to the first node when the verification of the first authentication information is successful. is further configured as such.
[0127] In yet another possible embodiment of the third aspect, the transmission unit transmits an association establishment message to the first node when the verification of the integrity of the first authentication information and the third message is successful. is further configured as such.
[0128] In yet another possible embodiment of the third aspect, the reception unit receives instruction information of a key agreement algorithm transmitted by the first node, and the key agreement algorithm includes the TBPEKE algorithm. is further configured as such.
[0129] Optionally, the instruction information of the key agreement algorithm includes instruction information of a first key agreement algorithm, and the instruction information of the first key agreement algorithm indicates the TBPEKE algorithm.
[0130] Optionally, since different elliptic curves are used, there may be multiple TBPEKE algorithms. For example, the elliptic curve used by the TBPEKE algorithm includes one or more of the elliptic curves defined by SM2, Curve25519, etc. Therefore, the TBPEKE algorithm can include a TBPEKE algorithm using the elliptic curve defined by SM2, a TBPEKE algorithm using Curve25519, etc.
[0131] In yet another possible implementation of the third aspect, at least one common parameter includes a first common parameter and a second common parameter.
[0132] The first common parameter and the second common parameter are related to a first elliptic curve, the first elliptic curve is the elliptic curve corresponding to the key agreement algorithm, and the key agreement algorithm includes the TBPEKE algorithm.
[0133] In yet another possible implementation of the third aspect, the first common parameter and the second common parameter belong to a point on the first elliptic curve.
[0134] In yet another possible implementation of the third aspect, the first common parameter is predefined, and the second common parameter is determined based on the first common parameter, the first random number, and the second random number. The first random number is derived from the first node, and the second random number is derived from the second node.
[0135] In a possible implementation of the third aspect, at least one common parameter includes at least one base point, and at least one base point belongs to a group whose order is p, where p is a prime number.
[0136] Optionally, the group may be a cyclic group or a cyclic subgroup related to the operations on the first elliptic curve.
[0137] Optionally, in some scenarios, the base point may alternatively be replaced by a generator.
[0138] In yet another possible implementation of the third aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes some or all of the elements within a group whose order is p, where p is a prime number.
[0139] The base point (or called the generator) of the subgroup whose order is p is U. For a selected number d, when the value range of d is [1, p - 1], dU is included in the group.
[0140] Optionally, at least one common parameter includes the base point U. Further optionally, at least one common parameter further includes V obtained by performing an operation on U, where V = dU and the range of d is [1, p - 1].
[0141] In yet another possible implementation of the third aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes two points within a group whose order is p.
[0142] Optionally, the two points may be two base points. Alternatively, one of the two points is used as the base point, and the other is used as the second base point obtained by a calculation based on the base point. For ease of explanation, in this application, the two points are referred to as the first base point and the second base point.
[0143] In yet another possible implementation of the third aspect, when the selected key agreement algorithm is the TBPEKE algorithm, the common parameters of the TBPEKE algorithm include a cyclic group whose order is a prime number p, and two independent base points U and V within the group.
[0144] It should be understood that "independent" means that U and V are two points with different values, and it is not intended to constitute a limitation that there is no relationship between U and V.
[0145] In yet another possible implementation of the third aspect, the receiving unit is further configured to receive a first calculated value from the first node, the first calculated value being related to a first random number and a first common parameter, the first random number being determined by the first node, and the first common parameter being predefined.
[0146] The processing unit is further configured to determine a second common parameter based on the second random number and the first calculated value.
[0147] The transmitting unit is further configured to transmit a second calculated value to the first node, the second calculated value being related to the second random number and the first common parameter, and the second calculated value being used by the first node to determine the second common parameter.
[0148] Optionally, the first common parameter is the aforementioned first base point, and the second common parameter is the aforementioned second base point.
[0149] In yet another possible implementation of the third aspect, at least one common parameter is two points, each point being a point on the elliptic curve used by the TBPEKE algorithm.
[0150] In yet another possible implementation of the third aspect, the intermediate parameter satisfies the following equation. b = U + s * V, where b is the intermediate parameter, U and V are at least one common parameter, s is the security parameter, "*" is the elliptic curve point multiplication operation, and "+" is the elliptic curve point addition operation.
[0151] In a possible implementation of the third aspect, U is the first base point and V is the second base point. Further, U and V belong to a group whose order is p, where p is a prime number. The operations related to the group are operations on the first elliptic curve.
[0152] The first elliptic curve is the elliptic curve used by the selected key agreement algorithm. For example, if the selected key agreement algorithm is the TBPEKE algorithm, the first elliptic curve may be an elliptic curve defined by SM2, Curve25519, etc.
[0153] In yet another possible implementation of the third aspect, the first key agreement parameter KEt satisfies the following equation: KEt = SKt * b, The first key satisfies the following equation: The first key = SKg * KEt, The second key agreement parameter KEg satisfies the following equation: KEg = SKg * b, The second key satisfies the following equation: The second key = SKt * KEg, where SKt is the first secret key and SKg is the second secret key.
[0154] Since the point multiplication operation satisfies the associative law, the first key = SKg * KEt = SKg * (SKt * b) = SKt * (SKg * b) = the second key. Therefore, the first key determined by the first node is the same as the second key determined by the second node.
[0155] Specifically, the first key = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V), the second key = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V), where "." is the multiplication operation. Therefore, the first key is the same as the second key.
[0156] In yet another possible implementation of the third aspect, the range of the value of the first secret key (SKt) is [1, p), the range of the value of the second secret key (SKg) is [1, p), and p is the degree of the elliptic curve used by the TBPEKE algorithm.
[0157] In yet another possible implementation of the third aspect, the transmission unit Broadcast the key agreement algorithm capabilities of the second node, where the key agreement algorithm capabilities of the second node represent the key agreement algorithms supported by the second node. It is further configured as follows.
[0158] In yet another possible implementation of the third aspect, the key agreement algorithms supported by the first node are sorted according to priority.
[0159] In yet another possible implementation of the third aspect, the first message further includes a first freshness parameter, and the first authentication information is associated with a pre-shared key PSK between the first node and the second node, the second key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node.
[0160] In yet another possible implementation of the third aspect, the processing unit verifies the first authentication information based on the PSK between the first node and the second node, the first key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node. It is further configured as follows.
[0161] In yet another possible implementation of the third aspect, the second message further includes second authentication information and a second freshness parameter, and the processing unit obtains the second authentication information based on the PSK between the first node and the second node, the first key, the second freshness parameter, and the first message. It is further configured as follows.
[0162] In yet another possible implementation of the third aspect, the first message further includes a first freshness parameter, the second message further includes a second freshness parameter, and the processing unit Obtain a third key based on the first key, the first freshness parameter, and the second freshness parameter and is further configured as follows.
[0163] In yet another possible embodiment of the third aspect, the PSK is pre-configured or pre-defined, or obtained based on the first password.
[0164] In yet another possible embodiment of the third aspect, the processing unit obtains the PSK between the first node and the second node according to the first correspondence relationship and is further configured as follows.
[0165] It may be known that the second node can store the correspondence relationship between the PSK and the first node in the form of a correspondence relationship. Therefore, according to the correspondence relationship, the PSK between the first node and the second node can be obtained.
[0166] In yet another possible embodiment of the third aspect, the processing unit determines the PSK between the first node and the second node based on the first password, the first freshness parameter, and the second freshness parameter and is further configured as follows.
[0167] In a possible design, the PSK is determined based on the first password, the first key, the first freshness parameter, and the second freshness parameter.
[0168] According to a fourth aspect, an embodiment of the present application provides a communication device. The communication device includes a transmission unit, a reception unit, and a processing unit, and the communication device is configured to implement the method described in any embodiment of the second aspect.
[0169] In a possible implementation of the fourth aspect, the transmission unit is configured to transmit a first message to a second node, the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first secret key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is a first password or a pre-shared key PSK between the first node and the second node, and the first password is an agreed access password between the first node and the second node.
[0170] The receiving unit is further configured to receive a second message from the second node, the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second secret key and an intermediate parameter.
[0171] The processing unit is configured to obtain a second key based on the second key agreement parameter and the first secret key.
[0172] In a possible implementation of the fourth aspect, the transmission unit is further configured to transmit a third message to the first node, the third message includes first authentication information, and the first authentication information is associated with the second key.
[0173] In yet another possible implementation of the fourth aspect, the second key is used to obtain one or more keys.
[0174] In a possible solution, the second key is used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, etc.
[0175] In yet another possible implementation of the fourth aspect, the receiving unit receives an association establishment message from the second node.
[0176] In yet another possible implementation of the fourth aspect, the communication device further includes a processing unit, and the processing unit selects a first key agreement algorithm based on the key agreement algorithm capabilities of the second node, and the key agreement algorithm capabilities of the second node can indicate one or more key agreement algorithms supported by the second node. is configured as such.
[0177] In yet another possible implementation of the fourth aspect, the transmission unit further transmits the indication information of the first key agreement algorithm to the second node, and the indication information of the first key agreement algorithm is further configured to indicate the two-base password exponential function key exchange TBPEKE algorithm.
[0178] Optionally, since different elliptic curves are used, there may be multiple TBPEKE algorithms. For example, the elliptic curve used by the TBPEKE algorithm includes one or more of the elliptic curves defined by SM2, Curve25519, etc. Therefore, the TBPEKE algorithm can include the TBPEKE algorithm using the elliptic curve defined by SM2, the TBPEKE algorithm using Curve25519, etc.
[0179] In yet another possible implementation of the fourth aspect, at least one common parameter includes a first common parameter and a second common parameter.
[0180] The first common parameter and the second common parameter are related to a first elliptic curve, and the first elliptic curve is the elliptic curve corresponding to the key agreement algorithm, and the key agreement algorithm includes the TBPEKE algorithm.
[0181] In yet another possible implementation of the fourth aspect, the first common parameter and the second common parameter belong to points on the first elliptic curve.
[0182] In yet another possible implementation of the fourth aspect, the first common parameter is predefined, the second common parameter is determined based on the first common parameter, the first random number, and the second random number, the first random number is derived from the first node, and the second random number is derived from the second node.
[0183] In a possible implementation of the fourth aspect, at least one common parameter includes at least one base point, and at least one base point belongs to a group with an order of p, where p is a prime number.
[0184] Optionally, the group may be a cyclic group or a cyclic subgroup related to operations on the first elliptic curve.
[0185] Optionally, in some scenarios, the base point may be alternatively replaced by a generator.
[0186] In yet another possible implementation of the fourth aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes some or all of the elements within a group with an order of p, where p is a prime number.
[0187] The base point (or called the generator) of the subgroup with an order of p is U. For a selected number d, if the value range of d is [1, p - 1], dU is included in the group.
[0188] Optionally, at least one common parameter includes the base point U. Further optionally, at least one common parameter further includes V obtained by performing an operation on U, where V = dU and the range of d is [1, p - 1].
[0189] In yet another possible implementation of the fourth aspect, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes two points within a group with an order of p.
[0190] Optionally, the two points may be two base points. Alternatively, one of the two points is used as a base point, and the other is used as a second base point obtained by calculation based on the base point. For the sake of simplicity of explanation, in this application, the two points are referred to as the first base point and the second base point.
[0191] In yet another possible implementation of the fourth aspect, when the selected key agreement algorithm is the TBPEKE algorithm, the common parameters of the TBPEKE algorithm include a cyclic group whose order is a prime number p, and two independent base points U and V within the group.
[0192] It should be understood that "independent" means that U and V are two points with different values, and it is not intended to constitute a limitation that there is no relationship between U and V.
[0193] In yet another possible implementation of the fourth aspect, the transmitting unit is configured to transmit a first calculated value to a second node, the first calculated value being related to a first random number and a first common parameter, the first random number being determined by the first node, and the first common parameter being predefined.
[0194] The receiving unit is configured to receive a second calculated value from the second node, the second calculated value being related to a second random number and the first common parameter.
[0195] The apparatus further includes a processing unit, and the processing unit determines a second common parameter based on the second random number and the first calculated value.
[0196] Optionally, the first common parameter is the aforementioned first base point, and the second common parameter is the aforementioned second base point.
[0197] In yet another possible implementation of the fourth aspect, when the first key agreement algorithm is the two-base password exponential function key exchange (TBPEKE) algorithm, at least one common parameter is two points, and each point is a point on the elliptic curve used by the TBPEKE algorithm.
[0198] In yet another possible implementation of the fourth aspect, the first key agreement algorithm is a key agreement algorithm supported by the first node, and the first key agreement algorithm has the highest priority among the key agreement algorithms supported by the second node.
[0199] In yet another possible implementation of the fourth aspect, the intermediate parameter satisfies the following equation. b = U + s * V, where b is the intermediate parameter, U and V are at least one common parameter, s is the security parameter, "*" is the elliptic curve point multiplication operation, and "+" is the elliptic curve point addition operation.
[0200] In a possible implementation of the fourth aspect, U is the first base point and V is the second base point. Further, U and V belong to a group whose order is p, where p is a prime number. The operations related to the group are operations on the first elliptic curve.
[0201] The first elliptic curve is the elliptic curve used by the selected key agreement algorithm. For example, when the selected key agreement algorithm is the TBPEKE algorithm, the first elliptic curve may be an elliptic curve defined by SM2, Curve25519, etc.
[0202] In yet another possible implementation of the fourth aspect, the first key agreement parameter KEt satisfies the following equation: KEt = SKt * b, The first key satisfies the following equation: The first key = SKg * KE, The second key agreement parameter KEg satisfies the following equation: KEg = SKg * b, The second key satisfies the following equation: Second key = SKt * KEg, where SKt is the first secret key and SKg is the second secret key.
[0203] Since the point multiplication operation satisfies the associative law, First key = SKg * KEt = SKg * (SKt * b) = SKt * (SKg * b) = Second key. Therefore, the first key determined by the first node is the same as the second key determined by the second node.
[0204] Specifically, First key = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V), Second key = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V), where "." is the multiplication operation. Therefore, the first key is the same as the second key.
[0205] In yet another possible implementation of the fourth aspect, the value range of the first secret key (SKt) is [1, p), the value range of the second secret key (SKg) is [1, p), and p is the degree of the elliptic curve used by the TBPEKE algorithm.
[0206] In yet another possible implementation of the fourth aspect, the receiving unit is of the second node, receives the key agreement algorithm capability transmitted by the second node, and the key agreement algorithm capability of the second node represents the key agreement algorithm supported by the second node. and is further configured as such.
[0207] In yet another possible implementation of the fourth aspect, the key agreement algorithms supported by the first node are sorted according to priority.
[0208] In yet another possible implementation of the fourth aspect, the first message further includes a first freshness parameter, the first message further includes a first freshness parameter, and the first authentication information is associated with a pre-shared key PSK between the first node and the second node, a second key, a second message, the first freshness parameter, and the key agreement algorithm capability of the second node.
[0209] In yet another possible implementation of the fourth aspect, the second message further includes second authentication information and a second freshness parameter, and the second authentication information is associated with the PSK between the first node and the second node, the first key, the second freshness parameter, and the first message.
[0210] In yet another possible implementation of the fourth aspect, the processing unit verifies the second authentication information based on the PSK between the first node and the second node, the second key, the second freshness parameter, and the first message, and generates the first authentication information when the verification of the integrity of the second authentication information and the second message is successful. It is further configured as such.
[0211] In a possible implementation of the fourth aspect, the first message further includes a first freshness parameter, the second message further includes a second freshness parameter, and the processing unit obtains a fourth key based on the second key, the first freshness parameter, and the second freshness parameter It is further configured as such.
[0212] In a possible implementation of the fourth aspect, the PSK is pre-configured or pre-defined, or obtained based on a first password.
[0213] In yet another possible implementation of the fourth aspect, the processing unit obtains the PSK between the first node and the second node according to the second correspondence is further configured as follows.
[0214] In yet another possible embodiment of the fourth aspect, the processing unit is further configured to determine a PSK between the first node and the second node based on a first password, a first freshness parameter, and a second freshness parameter. is further configured as follows.
[0215] According to a fifth aspect, an embodiment of the present application discloses a communication device including a processor and a communication interface. The communication interface is configured to receive and / or transmit data, and / or the communication interface is configured to provide an input and / or an output for the processor. The processor is configured to call a computer program stored in a memory to implement the method described in any one of the first aspect or a possible embodiment of the first aspect.
[0216] According to a sixth aspect, an embodiment of the present application discloses a communication device including a processor and a communication interface. The communication interface is configured to receive and / or transmit data, and / or the communication interface is configured to provide an input and / or an output for the processor. The processor is configured to call a computer program stored in a memory to implement any one of the possible embodiments of the second aspect or the third aspect.
[0217] It should be noted that the processor / processors included in the communication device / apparatus according to the fifth aspect and / or the sixth aspect may be a processor (referred to as a dedicated processor for ease of distinction) specially configured to perform these methods, or may be a processor that performs these methods by calling a computer program, such as a general-purpose processor. Optionally, at least one processor may further include both a dedicated processor and a general-purpose processor.
[0218] Optionally, the computer program may be stored in a memory. For example, the memory may be a non-transitory memory, such as a Read Only Memory (ROM). The memory and the processor may be integrated on the same component or may be separately arranged on different components. The type of memory and the way of arranging the memory and the processor are not limited in this embodiment of the present application.
[0219] In a possible embodiment, at least one memory is arranged outside the communication device.
[0220] In another possible embodiment, at least one memory is arranged within the communication device.
[0221] In yet another possible embodiment, some of the at least one memory are arranged within the communication device and other memories are arranged outside the communication device.
[0222] In the present application, the processor and the memory may alternatively be integrated into one component. In other words, the processor and the memory may alternatively be integrated together.
[0223] According to a seventh aspect, an embodiment of the present application further provides a chip system. The chip system includes at least one processor and a communication interface. The communication interface is configured to transmit and / or receive data. The at least one processor is configured to call a computer program stored in at least one memory to enable the chip system to implement the method described in any one of the first aspect or a possible embodiment of the first aspect, or to implement the method described in any one of the second aspect or a possible embodiment of the second aspect.
[0224] According to an eighth aspect, an embodiment of the present application further provides a communication system. The communication system includes a first node and a second node. The second node includes a communication device described in any one of the third aspect or possible embodiments of the third aspect, or the second node is a node that implements any one of the first aspect or possible embodiments of the first aspect. The first node includes a communication device described in any one of the fourth aspect or possible embodiments of the fourth aspect, or the first node is a node that implements any one of the second aspect or possible embodiments of the second aspect.
[0225] According to a ninth aspect, an embodiment of the present application discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is run on a computer, the computer is enabled to perform the method described in any one of the first aspect or possible embodiments of the first aspect, or the method described in any one of the second aspect or possible embodiments of the second aspect.
[0226] According to a tenth aspect, an embodiment of the present application discloses a computer program product. When the computer program product runs on one or more processors, the method described in any one of the first aspect or possible embodiments of the first aspect is performed, or the method described in any one of the second aspect or possible embodiments of the second aspect is performed.
[0227] According to an eleventh aspect, an embodiment of the present application discloses a terminal. The terminal may be an intelligent cockpit product, a vehicle, etc., and the terminal includes the first node and / or the second node.
[0228] The second node includes a device described in any one of the third aspect or possible embodiments of the third aspect.
[0229] The first node includes a communication device described in any one of the fourth aspect or possible embodiments of the fourth aspect.
[0230] Optionally, the first node includes one or more of modules such as a camera, a screen, a microphone, a stereo, a radar, an electronic key, a passive entry, a passive start system controller, and a user equipment (UE).
[0231] Optionally, the second node includes one or more of modules such as a gateway, a base station, and an in-vehicle cockpit domain controller CDC. Alternatively, the vehicle may be replaced by a smart terminal, a transport vehicle such as a drone or a robot.
[0232] For the beneficial effects of the technical solutions provided in the second to eleventh aspects of this application, please refer to the beneficial effects of the technical solution of the first aspect. Details will not be described again in this specification.
[0233] The following briefly describes the accompanying drawings used to explain the embodiments.
Brief Description of the Drawings
[0234]
Figure 1(a)
Figure 1(b)
Figure 1(c)
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7A
Figure 7B
Figure 8
Figure 9
[0235] To facilitate understanding of the detailed implementation manners of the solutions in the embodiments of the present application, the technical terms used in the embodiments of the present application will be described first below.
[0236] 1. Node A node is an electronic device having communication capabilities and is also called a communication node. For example, a node may include an independent device such as a handheld terminal, a vehicle, an in-vehicle device, a network-side device, a user equipment, an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile console, a remote station, a remote terminal, a wireless communication device, a user agent, or a user device, or may be a component (e.g., a chip or an integrated circuit) included in an independent device. A node may be any possible smart terminal device (e.g., a mobile phone), any possible intelligent transport device (e.g., a vehicle or an unmanned aerial vehicle), any possible smart manufacturing device, any possible smart home device (e.g., a large screen or a speaker), etc.
[0237] For example, when the node is an in-vehicle device, the node may be a cockpit domain device or a module within the cockpit device, such as a cockpit domain controller (CDC), a camera, a screen, a microphone, a speaker, an electronic key, and a passive entry passive start system controller, etc. One or more of these modules. In a vehicle, the node may alternatively be a battery management system and a battery within the battery pack.
[0238] For example, when the node is a handheld terminal, the node may be a mobile phone, a wearable device, a tablet computer (pad), a computer with data transmission and reception functions (such as a notebook computer or a palmtop computer), etc.
[0239] The nodes in the embodiments of the present application can be applied to a plurality of application scenarios, such as the following application scenarios, namely, mobile internet (MI), industrial control, self-driving, transportation safety, internet of things (IoT), smart city, or smart home.
[0240] The nodes in this application may be applied to multiple types of networks. For example, the following types of networks, namely, Long Term Evolution (LTE) network, 5th Generation Mobile Communication Technology (5G), Wireless Local Area Network (such as Wi-Fi), Bluetooth (Bluetooth, BT), Zigbee, SparkLink, or one or more of in-vehicle short-range wireless communication networks.
[0241] In some application scenarios or some types of networks, the names of devices with similar communication capabilities may not be called nodes. However, for the sake of easy explanation, in the embodiments of this application, devices with communication capabilities are collectively called nodes.
[0242] 2. Security Algorithm (or also called cryptographic algorithm) (1) Key agreement algorithm Key agreement is a process in which two communicating parties exchange some parameters to obtain a key through agreement. The algorithm used for key agreement is called a key agreement algorithm or may also be called a key negotiation algorithm. Key agreement algorithms include Two-Basis Password Exponential Key Exchange (TBPEKE) algorithm, Diffie-Hellman key exchange (DH) algorithm, Diffie-Hellman (DH) algorithm based on Elliptic Curve Cryptosystems (ECC) (ECDH), Chinese cryptographic algorithm (such as SM2), Oakley algorithm, etc.
[0243] The key agreement algorithm can also be regarded as a key agreement protocol, that is, for two communicating parties, it should be noted that the key agreement algorithm defines key generation and exchange rules.
[0244] (2) Key Derivation Function (KDF) The key derivation algorithm (or what is called the key derivation algorithm) is used to derive one or more secret values from a secret value (or is called derivation or derivation). For example, the new secret value DK derived from the secret value Key may be expressed as DK = KDF(Key). Of course, key in this specification is just an example. In a specific embodiment process, other parameters may be further used in the key derivation process.
[0245] The key derivation algorithm in the embodiments of this application can include a password-based key derivation function (PBKDF), a scrypt algorithm, etc. The PBKDF algorithm further includes the first-generation PBKDF1 and the second-generation PBKDF2.
[0246] It should be understood that some KDF algorithms can perform hash transformation on the input secret value according to the hash algorithm. Therefore, the KDF function can further receive an algorithm identifier as an input to indicate the hash algorithm used.
[0247] It should be noted that KDF is not only used to derive secret values, but also used to generate authentication information, identification information, etc. In some possible embodiments, when authentication information and identification information are generated, the key derivation algorithm may also be called an authentication function (AUF, or AUTH function), and the authentication algorithm is used to obtain authentication information based on input parameters.
[0248] (3) Encryption algorithm Encryption algorithms are used to protect the confidentiality of data and can encrypt plaintext to obtain ciphertext. Encryption algorithms may include encryption operations (such as elliptic point addition operations and exclusive OR operations), or various highly secure mathematical functions. Common encryption algorithms include exclusive OR operations, data encryption standard (DES), triple data encryption algorithm (3DES), advanced encryption standard (AES), RSA encryption algorithm, data structure analysis (DSA) algorithm, Chinese encryption algorithm (such as SM4), ZUC algorithm set (ZUC algorithm, encryption algorithm 128-EEA3, or integrity algorithm 128-EIA3 of the ZUC algorithm), etc.
[0249] 3. TBPEKE algorithm In the embodiments of the present application, the TBPEKE algorithm is a security algorithm implemented based on the elliptic curve mathematical theory, which enables two communicating parties to create keys on an insecure channel, and the keys can be used as keys for encrypting communication content in subsequent communications. Optionally, in the embodiments of the present application, the elliptic curve used by the TBPEKE algorithm includes one or more of the following elliptic curves, namely, elliptic curves defined by SM2, Curve25519, etc.
[0250] The following first explains elliptic curves.
[0251] The curve equation of an elliptic curve is a binary cubic equation and has multiple forms. The most commonly used equation is as follows. E={(x,y)∈R|y2 = x 3 + ax + b, 4a 3 + 27b 2 ≠ 0}
[0252] From the curve equation, it can be easily known that the elliptic curve is symmetric about the X-axis. The discriminant 4a 3 + 27b 2 ≠ 0 means that the elliptic curve has no singular points, that is, the elliptic curve is smooth and can be derived at any point. This facilitates various operations on the elliptic curve. The details are as follows.
[0253] a. Elliptic curve point addition operation Figures 1(a), 1(b), and 1(c) are diagrams of possible point addition operations according to the present application. Refer to Figure 1(a). The elliptic curve addition operation is to mark points P and Q on the curve (in Figures 1(a), 1(b), and 1(c), as an example, an elliptic curve with a = 0 and b = 7, that is, y2 = x 3 + 7), draw a straight line passing through points P and Q and intersecting the curve at a third point -R, and continue to draw the symmetric point R of point -R with respect to the X-axis. Point R is the point obtained by adding point P and point Q, and is denoted as P + Q = R.
[0254] Note that the elliptic curve is symmetric about the X-axis. Therefore, R is the symmetric point of point -R. Since point -R is on the elliptic curve, point R is also clearly on the elliptic curve, that is, the point obtained by adding P and Q is on the elliptic curve.
[0255] Refer to Figure 1(b). When P = Q, a tangent line centered on the elliptic curve with point P as the tangent point is drawn, and the tangent line intersects the elliptic curve at another point, which is denoted as point -R. Similarly, the symmetric point R of point -R with respect to the X-axis is drawn. Point R is the point obtained by adding point P and point P, and is denoted as P + P = 2P = R.
[0256] b. Elliptic Curve Point Subtraction Operation Refer to Fig. 1(c). Since R - P = R + (-P), calculating (R - P) is equivalent to the addition operation of point R and point -P. Also, point -P is the symmetric point of point P. Therefore, when a straight line passing through point R and point -P is drawn, since the elliptic curve is symmetric with respect to the X-axis, it can be understood that the elliptic curve is tangent to the elliptic curve at point -P. Therefore, the symmetric point P of point -P with respect to the X-axis is drawn, and point P becomes the point obtained by adding point R and point -P.
[0257] c. Elliptic Curve Point Multiplication Operation To obtain the result of adding point P n times, the points on the elliptic curve are added continuously n times, and the result is denoted as nP. The number of addition times n is an integer and may also be called a scalar. The elliptic curve point multiplication operation may also be referred to as a scalar multiplication operation, and when multiple scalars are used, it may also be referred to as a multi-scalar multiplication operation.
[0258] Note that the point multiplication algorithm can have different definitions in different operation scenarios, and the embodiments depend on the specifically defined operation rules of the point multiplication algorithm. In this specification, possible calculation methods of the elliptic curve point multiplication algorithm are listed.
[0259] Hereinafter, elliptic curves applicable to cryptographic algorithms will be described.
[0260] The above elliptic curve is continuous and defined in the real number field, and is not suitable for use in the encryption process. Therefore, the elliptic curve used in the cryptographic algorithm is usually defined over a finite field. A finite field is a set of finite elements. The finite field is restricted so that the points on the elliptic curve can generate a cyclic subgroup.
[0261] Elliptic curve point addition and point multiplication in a finite field are slightly different from those in the real number field. For details, refer to the definitions in the prior art.
[0262] For a selected elliptic curve, when a scalar k and a point G are given, it is easy to calculate R = k * G (* represents the elliptic curve point multiplication operation). However, when the points G and R are given (when the points G and R are on the elliptic curve), it is extremely difficult to calculate which k satisfies kG = R. In the actual use of elliptic curves, in principle, G is quite large and R is also quite large. Calculating k point by point and comparing it with R is a mathematical problem. This is the discrete logarithm problem on the elliptic curve.
[0263] The following describes the key exchange process based on the TBPEKE algorithm.
[0264] Assume that both parties of the key exchange are the first node and the second node, and there is a security parameter s shared between the first node and the second node. The elliptic curve used by the TBPEKE algorithm is E, and U and V are two points on the elliptic curve E. When the first node and the second node perform key exchange, the following exchange steps are carried out.
[0265] Step 1: The first node calculates an intermediate parameter b, where b = (U + s * V), where "+" represents the elliptic curve point addition operation, "*" represents the elliptic curve point multiplication operation, and "." in the subsequent formula represents common multiplication. The first node generates a random number as the secret key SKt of the first node and calculates the public key PKt = SKt * (U + s * V). The public key PKt is used as the key agreement parameter KEt.
[0266] Step 2: The first node sends the key agreement parameter KEt to the second node.
[0267] Step 3: The second node calculates the intermediate parameter b, where b = (U + s * V), generates a random number as the secret key SKg of the second node, and the second node calculates the public key PKg. Here, PKg = SKg * (U + s * V), and the public key PKg is used as the key agreement parameter KEg.
[0268] Step 4: The second node sends KEg to the first node.
[0269] Step 5: The second node obtains the key K KE based on the secret key of the second node and the public key of the first node, that is, K KE = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V).
[0270] Step 6: The first node obtains the key K KE ' based on the secret key of the first node and the public key of the second node, that is, K KE ' = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V).
[0271] K KE =(SKt.SKg)*(U + s * V)=K KE ', that is, both parties obtain a consistent key K KE . The key K KE is not sent directly, and it is difficult for an attacker to obtain K KE through calculations based on the obtained U, V, KEt, and KEg. Therefore, the key K KE obtained using the TBPEKE algorithm is secure.
[0272] The foregoing description of the algorithm is merely for briefly explaining the implementation principle, and it should be understood that it is not limited whether the same parameters need to be used in the implementation mode during use. There may be other improvements and modifications in the specific implementation process of the algorithm. The algorithm mentioned in this application may be an improved algorithm and / or a modified algorithm.
[0273] 4. Fresh Parameter The fresh parameter is a parameter in the field of information security and is used to generate keys, authentication parameters, etc., and is sometimes called freshness. The fresh parameter can include one or more of random numbers, counter values, serial numbers, sequence numbers, etc. Fresh parameters generated at different moments are usually different.
[0274] It should be understood that the specific value of the fresh parameter changes every time the fresh parameter is generated. As a result, the fresh parameter (or authentication parameter, etc.) used to generate the key this time is different from the fresh parameter (or authentication parameter, etc.) used to generate the key last time. This can improve the security of the generated key.
[0275] A number once (NONCE) is a random number that is used only once (non-repetitive).
[0276] 5. Password The password may be understood as a password pre-configured or pre-defined by a node for access to another node, or as a secret value agreed upon between two nodes. Optionally, the password may be in the form of a character string (or number) containing one or more of numbers, characters, symbols, etc., and may be input via a keyboard, voice, biometric information, etc. For example, in a scenario where a mobile phone terminal accesses a router that supports the wireless fidelity (Wi-Fi) protocol, the mobile phone terminal can use the "Wi-Fi password" to access the router, and the "Wi-Fi password" can be understood as the password of the router.
[0277] For ease of understanding, this application lists several possible password usage scenarios as examples (an example where a first node requests access to a second node is used).
[0278] Scenario 1: The second node pre-defines or pre-configures the first password. The user of the first node can input the first password into the first node to access the second node. For example, a vehicle owner configures a first password for the vehicle via an administrator interface. When the vehicle owner's smartphone needs to access the vehicle, the vehicle owner can input the first password into the smartphone, and the smartphone requests to access the vehicle according to the input first password.
[0279] Scenario 2: The second node predefines or preconfigures the first password. Similarly, the first password for accessing the second node is also preconfigured at the first node. When the first node needs to access the second node, the first node can perform the access using the preconfigured first password. For example, when a vehicle is assembled, the host factory can configure the first password in the vehicle's CDC and configure the first password of the CDC in the vehicle's radar. In this way, the radar can access the CDC using the first password of the CDC.
[0280] Scenario 3: A third-party device (a device trusted by the second node, such as a network-side device, a certificate center, or an authentication server) can assign an agreed value to the second node and the first node, and the agreed value can be used by the first node to access the second node, and the agreed value can be called the access password of the second node.
[0281] It should be noted that the association between parameters indicates that there is a relationship between the parameters. For example, when parameter A is associated with parameter B, it indicates that there is a correspondence (or mapping relationship) between parameter A and parameter B, or that parameter B is used in the calculation process of parameter A (optionally, other parameters may also be used).
[0282] "Authentication", "verification", and "verify" mentioned in the embodiments of this application can mean checking whether information is correct or reasonable. "Access" mentioned in the embodiments of this application indicates the process by which the first node establishes a connection to the third node. In some specific technical scenarios, the "access" process of one node to another node can also be described as the one node being "associated with" the other node.
[0283] In addition, in the embodiments of the present application, unless otherwise specified, "*" represents an elliptic curve point multiplication operation, "+" represents an elliptic curve point addition operation, and "." represents a multiplication operation.
[0284] Hereinafter, the system architecture and service scenarios of the embodiments of the present application will be described. It should be noted that the system architecture and service scenarios described in the present application are intended to more clearly explain the technical solutions in the present application and do not constitute a limitation to the technical solutions provided in the present application. Those skilled in the art can recognize that the technical solutions provided in the present application are also applicable to similar technical problems due to the evolution of the system architecture and the emergence of new service scenarios.
[0285] FIG. 2 is a diagram of a possible communication system according to an embodiment of the present application. The communication system includes a first node 201 and a second node 202. The first node 201 may request an association with the second node 202. After the association is successful, the second node 202 may perform data transmission with the first node 201.
[0286] Optionally, the link for communication between the second node 202 and the first node 201 may include various types of connection media, including a wired link (e.g., optical fiber), a wireless link, a combination of a wired link and a wireless link, etc. For example, the second node 202 and the first node 201 can communicate with each other by using short-distance connection technologies, including SparkLink, 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB) technology, or a wireless short-distance communication system (e.g., an in-vehicle wireless short-distance communication system). As another example, the second node 202 and the first node 201 can communicate with each other by using long-distance connection technologies, such as communication technologies based on Long Term Evolution (LTE), 5th generation mobile networks or 5th generation wireless systems (abbreviated as 5th-Generation, 5G or 5G technology), global System for mobile communications (GSM), general packet radio Service (GPRS), and universal mobile telecommunications system (UMTS), including wireless access type technologies.
[0287] In some specific embodiment scenarios, the second node may be referred to as a G node, a control node, or an access point, the first node may be referred to as a T node or a terminal, the communication link from the G node to the T node may be referred to as a G link, and the communication link from the T node to the G node may be referred to as a T link.
[0288] It should be understood that the systems shown in the accompanying drawings of this application are merely examples. The number of nodes, the positions of the nodes, and the connection relationships between the nodes are shown as possible cases for ease of explanation, and are not intended to limit a specific communication system and a specific communication scenario.
[0289] The second node 202 and the first node 201 may be of the same type of device or different types of devices. For example, FIG. 3 is a diagram of a possible communication scenario. A vehicle cockpit domain controller (CDC) 302 is a control center for intelligent cockpit devices of a vehicle and can be regarded as the second node 202. A smartphone 301 is a device having data transmission and reception capabilities and can be regarded as the first node 201.
[0290] The CDC 302 can be accessed using short-range communication technology, and the smartphone 301 supports short-range communication technology. Therefore, the smartphone 301 can request access to the CDC 302. When both communicators of the short-range communication technology access by digital pairing, the identifier of the CDC 302 is directly tapped on the smartphone 301 and the pairing digits between the smartphone 301 and the CDC 302 are confirmed, so that the smartphone 301 can be connected to the CDC 302 using short-range communication technology. In this case, if an attacker disguises the identification information of the smartphone 301 and connects to the CDC 302, it will be difficult for the CDC 302 to identify the attacker. As a result, the attacker can normally access the CDC 302, and the privacy and security of the vehicle are threatened.
[0291] Similarly, in some other scenarios, it is difficult for nodes to avoid access by unconfirmed attackers. As a result, communication security is affected. For example, the CDC 302 supports access by the first password. The user enters the password into the smartphone 301. If the CDC 302 determines that the password entered by the user is correct, it may establish a connection. However, for the sake of ease of input and memory, passwords are usually short. If the password is directly used to obtain a communication key in the communication process, the attacker may use a brute-force attack or an offline attack to obtain the password of the CDC 302, threatening the privacy and security of the vehicle.
[0292] In view of this, the communication method and apparatus in the embodiments of the present application are provided to reduce the possibility that a node is normally associated with an attacker having untrusted identification information and to improve node security.
[0293] The method in the embodiments of the present application will be described in detail below.
[0294] FIG. 4 is a schematic flowchart of a communication method according to an embodiment of the present application. Optionally, this method may be implemented based on the communication system shown in FIG. 2. The communication method shown in FIG. 4 may include one or more of steps S401 to S406. For the sake of facilitating the description in the present application, the sequence from S401 to S406 is used for the description, but it should be understood that this is not intended to constitute a limitation that the method must be necessarily performed in the foregoing sequence. The execution order, execution time, execution frequency, etc. of the foregoing one or more steps are not limited in this embodiment of the present application. S401 to S406 are specifically as follows.
[0295] Step S401: The first node sends a first message to the second node. Correspondingly, the second node receives the first message from the first node. The first message includes a first key agreement parameter.
[0296] Specifically, the key agreement parameter is a parameter used in the key agreement process. For the sake of easy explanation, in the present embodiment of the present application, the key agreement parameter provided by the first node is called the first key agreement parameter.
[0297] In this embodiment of the present application, the first key agreement parameter is associated with a first secret key and an intermediate parameter, and the intermediate parameter is associated with a security parameter and a common parameter.
[0298] For the sake of easy understanding, the security parameter and the common parameter will be first explained below.
[0299] (1) The security parameter can include a shared key (including a pre-shared key, a symmetric encryption key, etc.) between the first node and the second node, a first password, a parameter pre-configured between the first node and the second node, a parameter predefined in the communication protocol, etc. A pre-shared key (PSK) is used as an example. The pre-shared key is a secret value shared between the first node and the second node. The first node can pre-define, pre-configure, or obtain through mutual agreement a PSK shared with the first node, etc.
[0300] The first password is an agreed access password between the first node and the second node, and can be understood as a password pre-configured or pre-defined by the second node (or the first node) to enable another node to access, or can be understood as a secret value agreed upon by the first node and the second node. For the related description of the first password, please further refer to the description in the technical term explanation part.
[0301] In a possible solution, if the PSK between the first node and the second node exists at the first node, the PSK is used as a security parameter. If the PSK between the first node and the second node does not exist at the first node, the first password is used as a security parameter. In other words, the first node preferentially uses the PSK to participate in the key agreement process.
[0302] The first private key is determined by the first node and is the private key of the first node. The first private key may be a random number. Optionally, when the first node and the second node perform key agreement according to the TBPEKE algorithm, the range of the value of the first private key is [1, p), where p is the degree of the elliptic curve used by the TBPEKE algorithm, or p is the degree of the group associated with the elliptic curve. It should be understood that the "TBPEKE algorithm" is an example of the algorithm name provided in the present embodiment of this application. In the embodiment process, all key agreement algorithms that use the same or similar parameters and the same or similar calculation methods are included within the scope of this application, but the key agreement algorithm may not be called the "TBPEKE algorithm" in some cases.
[0303] (2) The common parameters can be jointly used by multiple parties in the key agreement process. There may be one or more common parameters. This depends on the specific implementation. Optionally, when the first node and the second node select different key agreement algorithms to perform key agreement, the number and determination method of the common parameters may be different.
[0304] Some possible common parameter determination embodiments are listed below.
[0305] Embodiment 1: The common parameters are predefined or preconfigured. For example, the protocol defines the number of common parameters, the values of the common parameters, etc. When the first node is associated with the second node via the protocol, the key agreement parameters are determined based on the common parameters defined in the protocol. For example, the common parameters are preconfigured in multiple communication parties (e.g., the first node and the second node). For example, the common parameters are preconfigured in the second node (or the first node), and the second node can send the common parameters to another node via a message, and multiple communication parties determine the key agreement parameters based on the consistent common parameters.
[0306] Embodiment 2: The node determines parameters as common parameters. The number of common parameters is not limited in this specification. Optionally, there may be one or more common parameters.
[0307] For example, the second node can generate a random number and use the random number as a common parameter.
[0308] In another example, the second node determines two points within the group of the first elliptic curve and uses the two points as common parameters. For example, the first node selects a point as the base point (referred to as the first base point for easy distinction) and obtains a second point (which may be referred to as the second base point) by performing operations based on the base point.
[0309] Optionally, the group may be a group related to operations on the first elliptic curve, and the operations on the elliptic curve include one or more operations such as elliptic curve point multiplication operation and elliptic curve point addition operation. Further, optionally, the order corresponding to the group is p, and p may be defined by the node, the standard, the vendor, or the user. The order p in the embodiments of this application is optionally a prime number.
[0310] Embodiment 3: Some common parameters are predefined, and some parameters are determined by the node.
[0311] For example, there may be two common parameters, one of which is predefined, and the other is determined based on a known common parameter and a random number separately provided by the first node and the second node.
[0312] In a possible implementation, when the key agreement algorithm between the first node and the second node is the TBPEKE algorithm, at least one common parameter includes a group (or some elements within the group) whose order is p, and / or a first base point and a second base point within the group. Optionally, the group may be a group related to operations on a first elliptic curve, and the operations on the elliptic curve include one or more operations such as elliptic curve point multiplication operations and elliptic curve point addition operations.
[0313] In another possible implementation, the second node can receive a first calculated value from the first node. The first calculated value is related to a first random number and a first common parameter. The first random number is determined by the first node (in the present embodiment of this application, "determine" includes one or more of the operations such as receiving, copying, reading, or obtaining by generating). The first common parameter is predefined and can be obtained, for example, through protocol regulations, vendor configurations, or user inputs. The second node determines a second common parameter based on the second random number and the first calculated value. The second node sends a second calculated value to the first node, and the second calculated value is related to the second random number and the first common parameter. Further, the first node can receive the second calculated value from the first node and obtain a second common parameter that matches that of the first node based on the second calculated value and the first random number.
[0314] FIG. 5 shows a possible common parameter determination procedure according to an embodiment of the present application. The common parameters include two base points U and V, where U is a pre-defined base point, and U and V belong to a cyclic group with an order p, and p is a prime number. The elliptic curve used can be an elliptic curve defined by a selected key agreement algorithm. The procedure shown in FIG. 5 may specifically include steps S51 to S55 as follows.
[0315] Step S51: The first node generates a random number x and calculates X = x*U.
[0316] * is a point multiplication operation, and X is the first calculated value described above.
[0317] Step S52: The first node sends X to the second node. Correspondingly, the second node receives X from the first node.
[0318] Step S53: The second node generates a random number y, calculates Y = y*U, and calculates V = y*X.
[0319] "*" is a point multiplication operation, Y is the second calculated value described above, and V is the second base point. Optionally, since X = x*U, then V = y*X = y*(x*U) = (x.y)*U, where "." is a multiplication operation.
[0320] Step S54: The second node sends Y to the first node. Correspondingly, the first node receives Y from the second node.
[0321] Step S55: The first node calculates V = x*Y.
[0322] Since Y = y * U, then V = x * Y = x * (y * U) = (x.y) * U, where “.” is the multiplication operation. Therefore, the second node and the first node can determine consistent Vs using the embodiment shown in FIG. 5. For simplicity of explanation, note that FIG. 5 is described in the order from step S51 to step S52. The execution order, execution time, and number of executions of the steps are not limited in this application.
[0323] In the above, the common parameters and security parameters have been described. Below, two possible solutions for the first key agreement parameter are provided using an example where the key agreement algorithm is the TBPEKE algorithm.
[0324] Solution 1: The first node calculates an intermediate parameter b based on the first password pw and the common parameters (U and V), i.e., b = (U + pw * V), where U and V are the first base point and the second base point on the elliptic curve used by the TBPEKE algorithm. The first node generates a random number, uses the random number as the first secret key SKt, calculates the first public key PKt, and PKt = SKt * b = SKt * (U + pw * V), and the first public key PKt is used as the key agreement parameter KEt.
[0325] In some possible designs, the point addition operation and the point multiplication operation may be performed on points on the same elliptic curve. Therefore, if the parameter is not a point on the elliptic curve, the parameter may first be mapped to a point on the elliptic curve, and then the point addition operation (or point multiplication operation) is performed on the point on the elliptic curve. The first secret key SKt is used as an example. The possible mapping methods are as follows: The first node can use SKt as the horizontal coordinate (when SKt exceeds the defined range, modulo operation may be performed on SKt), and obtain the mapping point R(SKt, y) on the elliptic curve, and the point R can be used later to replace SKt. Optionally, when one SKt value corresponds to multiple y values, the conditions that need to be satisfied by the y values may be pre-agreed to determine the corresponding points.
[0326] Solution 2: The first node calculates the intermediate parameter b based on the PSK and the common parameters (U and V), that is, b = (U + PSK * V), where + represents the elliptic curve point addition operation and * represents the elliptic curve point multiplication operation. The first node generates a random number, uses the random number as the first secret key SKt, calculates the first public key PKt, and PKt = SKt * (U + PSK * V), and the first public key PKt is used as the key agreement parameter KEt.
[0327] To more clearly explain the solution, it should be noted that multiple steps are used in the foregoing solution to explain the method of obtaining the key agreement parameter KEt. In actual processing, the key agreement parameter KEt may be obtained in one step, and the intermediate parameter, the first public key, etc. may be only internal results, that is, the key agreement parameter KEt satisfies KEt = SKt * (U + s * V).
[0328] Optionally, the first node may further send to the second node instruction information of a key agreement algorithm to indicate the algorithm used in the key agreement process. The instruction information may be specifically indicated by a field (referred to as the first field for ease of explanation). For example, the first field may be a KE alg field. Different values of the first field can indicate the algorithm used by the first node in the key agreement process. Optionally, the instruction information of the key agreement algorithm may alternatively be included in the aforementioned first message.
[0329] Table 1 shows an explanation of possible values of the key agreement algorithm and instruction information according to an embodiment of the present application. As shown in Table 1, when the value of the first field is 0x003, it indicates that key agreement is performed according to the TBPEKE algorithm, and the elliptic curve used by the TBPEKE algorithm is the elliptic curve defined by the SM2 algorithm. Similarly, when the value of the first field is 0x001, it indicates that the first node selects the SM2 algorithm for key agreement. The meanings of other values can be inferred by analogy. Details are not described herein.
[0330]
Table 1
[0331] It should be understood that Table 1 shows examples of field values and does not represent restrictions on the instruction information. In a specific embodiment process, other designs may be used for the correspondence between the algorithm and the format, the number of bits, and the value of the instruction information.
[0332] In a possible solution, the second node can send the key agreement algorithm capabilities of the second node (the sending method may include broadcast, multicast, unicast, etc.), and the key agreement algorithm capabilities represent the key agreement algorithms supported by the second node. Correspondingly, the first node selects a key agreement algorithm based on the key agreement algorithm supported by the second node. The first node sends instruction information of the key agreement algorithm to the second node, and the instruction information indicates the key agreement algorithm selected by the first node.
[0333] Optionally, the second node includes in a broadcast message (also called an access message) the identification information of the second node and the key agreement algorithms supported by the second node. The key agreement algorithms are sorted according to priority. For example, algorithms with higher priority may be ranked higher. The identification information of the second node includes the identification information (identify, ID) of the second node, the domain ID (domain ID), the media access control (MAC) address, the domain name, the domain address, or another user-defined identifier, and is also called the device identifier of the second node.
[0334] To facilitate understanding, the following provides a possible solution as an example. The second node supports the SM2 algorithm (identifier: 0x001), the ECDH algorithm (identifier: 0x002), the SM2-based elliptic curve TBPEKE algorithm (identifier: 0x003), and the curve25519-based elliptic curve TBPEKE algorithm (identifier: 0x004), and the priorities of the four algorithms are 1, 2, 3, and 4 respectively (indicating that the larger the value, the higher the priority). In this case, the key agreement algorithm capabilities in the broadcast message, which belong to the second node, are "0x004, 0x003, 0x002, 0x001".
[0335] In a possible solution, the first key agreement algorithm is the key agreement algorithm supported by the first node, and the first key agreement algorithm has the highest priority among the key agreement algorithms supported by the second node. For example, the key agreement algorithms supported by the second node are algorithm A, algorithm B, algorithm C, and algorithm D, and the priorities of the four algorithms are 4, 3, 2, and 1 respectively (the larger the value, the higher the priority), and the key agreement algorithms supported by the first node are algorithm B, algorithm D, and algorithm E. In this case, the algorithms supported by both the first node and the second node are algorithm B and algorithm D. Since algorithm B has a higher priority, the first node selects algorithm B as the algorithm to be used for key agreement.
[0336] Certainly, the first node can select the algorithm with the highest priority among the key agreement algorithms supported by the first node and select the algorithms supported by both the first node and the second node. For example, the key agreement algorithms supported by the second node are algorithm A, algorithm B, algorithm C, and algorithm D, and the priorities of the four algorithms are 4, 3, 2, and 1 respectively (the larger the value, the higher the priority), and the key agreement algorithms supported by the first node are algorithm B, algorithm D, and algorithm E, and the priorities of the three algorithms are 1, 2, and 3 respectively (the larger the value, the higher the priority). In this case, the algorithms supported by both the first node and the second node are algorithm B and algorithm D. In the second node, since the priority of algorithm D is higher than the priority of algorithm B, the first node selects algorithm D as the algorithm to be used for key agreement.
[0337] Optionally, there may be another configuration for setting priorities. For example, various algorithms' priorities are defined in the protocol, and the algorithm to be used is determined based on the priorities defined in the protocol.
[0338] Optionally, the first message may further include a fresh value. For ease of distinction, hereinafter, the fresh value provided by the first node is referred to as the first fresh value. The fresh value includes at least one of a random number (e.g., NONCE), a count value, a sequence number, etc. In the embodiments of the present application, an example where the fresh value includes a NONCE is used for illustration. However, the present application is applicable to all types of fresh values. For ease of explanation, the first fresh value is represented by NONCEt.
[0339] Optionally, the first message further includes the identification information of the first node. The identification information of the first node includes the ID of the first node, the MAC address, the domain name, the domain address, or another user-defined identifier, and is also referred to as the device identifier of the first node.
[0340] Note that in a specific scenario, the first message may be referred to as an access request message (or access request information), or may be referred to as an association request message (or association request information). The name of the message or information is not limited in the embodiments of the present application. Only the message content is illustrated and expressed as an example, and the name of the message may be replaced.
[0341] In this application, for the purpose of facilitating the description of parameter transfer, it should be understood that the first message, the second message, etc. are used as carriers for transporting data. In a specific embodiment process, the first message may be one message or a plurality of messages, and the number of messages included in the first message may not be limited. Similarly, the number of messages included in the subsequent second message and the number of messages included in the subsequent third message may not be limited. For example, when the first node sends the first key agreement parameter and the first freshness parameter to the second node, the first key agreement parameter may be carried in message 1, and the first freshness parameter may be carried in message 2. In this case, the first message includes message 1 and message 2.
[0342] Step S402: The second node sends a second message to the first node. Correspondingly, the first node receives the second message from the second node. The second message includes a second key agreement parameter.
[0343] Specifically, in the embodiment of this application, the key agreement parameter provided by the second node is called the second key agreement parameter. The second key agreement parameter is associated with a second secret key and an intermediate parameter, and the intermediate parameter is associated with a security parameter and a common parameter.
[0344] The second secret key is a secret key determined by the second node. The second secret key may be a random number generated by the second node. Optionally, when the first node and the second node perform key agreement according to the TBPEKE algorithm, the value range of the second secret key is [1, p), where p is the order of the elliptic curve used by the TBPEKE algorithm, or p is the order of the group. For a detailed description of the security parameter and the common parameter, please refer to the relevant description in step S401.
[0345] In a possible solution, the second key agreement parameter can be expressed using the following formula: KEg = SKg * b, where b = (U + s * V), SKg is the second private key, b is an intermediate parameter, U and V are common parameters, and s is a security parameter. Alternatively, the second key agreement parameter is expressed using the following formula: KEg = SKg * (U + s * V).
[0346] Optionally, the second message further includes a fresh parameter. For ease of explanation, in the embodiments of the present application, the fresh parameter provided by the second node is referred to as the second fresh parameter and is represented by NONCEg in some embodiments.
[0347] Step S403: The second node obtains the first key based on the first key agreement parameter and the second private key. The first key is associated with the first key agreement parameter and the second private key.
[0348] In a possible solution, the second node obtains the first key in the following manner: The first key = SKg * KEt, where SKg is the second private key and KEt is the first key agreement parameter. The first key agreement parameter KEt satisfies the following formula, KEt = SKt * (U + s * V), so the first key K KE can satisfy the following formula: K KE = SKg * KEt = (SKt.SKg) * (U + s * V).
[0349] For ease of explanation, in the above, the process of determining the first private key and the process of calculating the first key are described separately. However, in some specific designs, the aforementioned calculation process may be encapsulated in one calculation procedure, the input of the calculation procedure is the first key agreement parameter, and the output of the calculation procedure is the first key.
[0350] Alternatively, the foregoing procedure for obtaining the first key is indicated by the TBPEKE algorithm. Accordingly, the foregoing steps may alternatively be expressed as follows. The second node obtains the first key based on the TBPEKE algorithm and the first key agreement parameters.
[0351] Optionally, the first key may be further used to obtain one or more keys. In a possible solution, the first key can be used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, etc. For example, the second node can calculate a key Kgt based on the first key. For example, Kgt = KDF(K KE , NONCEt, NONCEg), where NONCEt is a freshness parameter provided by the first node and NONCEg is a freshness parameter provided by the second node.
[0352] In a possible embodiment, the first key can be used to generate identification information authentication information for authenticating the identification information of both communication parties.
[0353] For example, the second node can obtain second identification authentication information based on the first key, and the second authentication information is used to authenticate the identification information of the second node and / or to verify whether the keys obtained by agreement between the first node and the second node match. That is, the second identification information authentication information is associated with the first key.
[0354] In some possible designs, the second authentication information can be further associated with one or more of the following parameters, namely, the key Kgt, the PSK, the first freshness parameter, the second freshness parameter, the first message, and the second message. Each of the foregoing messages may be the entire message or some data within the message. Some possible calculation methods of the second authentication information are listed below.
[0355] Calculation method 1: The second authentication information AUTHg satisfies AUTHg = AUF(K KE ), where K KE is the first key. Certainly, in addition to K KE , another parameter, for example, a freshness parameter or a message, may be further used to generate AUTHg. For example, AUTHg satisfies AUTHg = AUF(K KE , NONCEg), or AUTHg satisfies AUTHg = AUF(K KE , NONCEt), or AUTHg satisfies AUTHg = AUF(K KE , NONCEt, NONCEg).
[0356] Calculation method 2: The second authentication information AUTHg satisfies AUTHg = AUF(PSK), where in this specification, PSK is the PSK between the second node and the first node. Alternatively, PSK may be the PSK stored in the second node and corresponding to the identification information of the first node.
[0357] Certainly, in addition to PSK, another parameter, for example, a freshness parameter or a message, may be further used to generate AUTHg. For example, AUTHg satisfies AUTHg = AUF(PSK, NONCEg), or AUTHg satisfies AUTHg = AUF(PSK, NONCEt), or AUTHg satisfies AUTHg = AUF(PSK, NONCEt, NONCEg).
[0358] Calculation method 3: The second authentication information AUTHg satisfies AUTHg = AUF(PSK, K KE , NONCEg, the first message). For related parameters, please refer to the above description.
[0359] Calculation method 4: Since the number of bits of the output value of the AUF algorithm may be large, the second node can select some bits of the output value, so that the second authentication information has a uniform and short number of data bits. Thereby, the data size of the second message can be reduced and the transmission efficiency can be improved. For example, AUTHg = AUF(PSK)|Nビット It is.
[0360] The N bits can be pre - defined or pre - configured by the OEM, manufacturer, standard, or user. For example, the N bits may be the upper 32 bits, that is, AUTHg = AUF(PSK, K KE , NONCEg, the first message)| 最上位32ビット is satisfied. For example, the N bits may be the lower 16 bits, and AUTHg = AUF(PSK, NONCEg)| 最下位の16ビット is satisfied.
[0361] Calculation method 5: The authentication information key Kauth is obtained based on the first key K KE , that is, Kauth = KDF(K KE ). Optionally, the parameters used to generate Kauth may further include one or more of fresh parameters (e.g., NONCEt or NONCEg), random numbers, PSK, identification information of the first node, etc.
[0362] The identification information authentication key can be used to generate the second authentication information. Certainly, other parameters, such as fresh parameters or messages, may be further used to generate the second authentication information. In a possible solution, the second authentication information AUTHg satisfies AUTHg = AUF(Kauth, NONCEg, the first message)| Nビット is satisfied.
[0363] It should be understood that in the algorithm of this application, the sequence of parameters is merely an example. In a specific implementation process, the input sequence of parameters can be changed. Alternatively, the AUF algorithm used to generate the authentication information may be replaced by another cryptographic algorithm, such as a KDF algorithm, an encryption algorithm, or an authentication algorithm.
[0364] In the foregoing description, in some solutions, the second node uses PSK to obtain the second authentication information and the second key agreement parameter. Hereinafter, two methods for obtaining PSK will be described as examples.
[0365] Method 1: There is a correspondence between the PSK and the identification information of the first node in the second node. That is, in the second node, the PSK between the first node and the second node can correspond to the identification information of the first node. The second node can obtain the corresponding PSK based on the identification information of the first node and the correspondence (which can be called the first correspondence for ease of distinction).
[0366] Optionally, the correspondence between the PSK and the identification information of the first node may be a pre-configured and pre-defined correspondence in the second node, or a correspondence stored after the first node and the second node generate the PSK by agreement. The correspondence may be in one or more forms such as a correspondence set, a data table, a database, etc. This is not limited in this application. Table 2 shows a possible correspondence set between the PSK and the identification information of the first node according to this embodiment of the present application. The correspondence set includes a plurality of identification information of the first node, the corresponding PSK, and the PSK type. For example, for the first node whose identification information is "ID 1", the second node can determine that the PSK corresponding to the first node is "PSK 1" based on the temporary ID "ID 1.1". Furthermore, the type of "PSK 1" is pre-configured.
[0367]
Table 2
[0368] When the correspondence relationship is pre-configured, it exists between the second node and the first node, and it should be noted that the PSK pre-configured at the second node is the same as the PSK pre-configured at the first node which exists between the first node and the second node. When the correspondence relationship is stored after the PSK is generated, the method for generating the PSK by the first node and the parameters used by the first node are also the same as the method for generating the PSK by the second node and the parameters used by the second node.
[0369] Method 2: The second node generates a PSK between the second node and the first node. Optionally, the parameters used to generate the PSK may include one or more of the first password, the first freshness parameter, the second freshness parameter, the identification information of the first node, the identification information of the second node, etc. It should be understood that the parameters used by the second node to generate the PSK should be consistent with the parameters used by the first node to generate the PSK.
[0370] In some scenarios, the second message may be called a security context request message (or security context request information).
[0371] Step S404 (optional): The first node obtains a second key based on the second key agreement parameter and the first secret key.
[0372] The second key corresponds to the second key agreement parameter and the first secret key, and is the key obtained by the first node in the key agreement process.
[0373] Specifically, the first private key is the private key determined by the first node and is used to obtain the first key agreement parameter in step S401. The first private key may be a random number generated by the first node. Optionally, when the first node and the second node perform key agreement according to the TBPEKE algorithm, the range of the value of the first private key is [1, p), where p is the order of the elliptic curve used by the TBPEKE algorithm, or p is the order of the group, and the group is related to the elliptic curve.
[0374] In a possible solution, the first node obtains the second key in the following way: The second key = SKt * KEg, where SKt is the first private key and KEg is the second key agreement parameter. The second key agreement parameter KEg satisfies the following equation, KEg = SKg * (U + s * V), so the second key K KE (To distinguish it from the first key K KE more easily, it is called K KE ’) can satisfy the following equation: K KE ’ = SKt * KEg = (SKt.SKg) * (U + s * V).
[0375] K KE = (SKt.SKg) * (U + s * V) = K KE ’, and the first node and the second node obtain a consistent key K KE by exchanging the key agreement parameters.
[0376] For ease of explanation, in the above, the process of determining the second private key and the process of calculating the second key are described separately. However, in some specific designs, the aforementioned calculation process may be encapsulated into one calculation procedure, the input of the calculation procedure is the second key agreement parameter, and the output of the calculation procedure is the second key.
[0377] In another possible solution, the aforementioned procedure for obtaining the second key is indicated by the TBPEKE algorithm. Therefore, the aforementioned steps may alternatively be expressed as follows. The first node obtains the second key based on the TBPEKE algorithm and the second key agreement parameter.
[0378] Optionally, the second key may be used to obtain one or more keys. In a possible solution, the second key can be used to obtain an encryption key, an integrity key, an identification information authentication key, etc.
[0379] For example, the first node can obtain the key Kgt by a calculation based on the second key. For example, Kgt = KDF(K KE ’, NONCEt, NONCEg), where NONCEt is a freshness parameter provided by the first node and NONCEg is a freshness parameter provided by the second node.
[0380] In a possible embodiment, the first key can be used to generate identification information authentication information for authenticating the identification information of both communication parties. For example, possible embodiments are shown in step S405 and step S406.
[0381] Step S405 (optional): The first node sends a third message to the second node. Correspondingly, the second node receives the third message from the first node. The third message includes the first authentication information.
[0382] The first authentication information is used to authenticate the identification information of the first node and / or is used by the second node to verify whether the keys obtained by agreement between the second node and the first node match. The first authentication information is associated with the second key.
[0383] In some possible designs, the optional parameters used to generate the first authentication information may further include one or more of the key Kgt, PSK, the first fresh parameter, the second fresh parameter, the first message, and the second message. Each of the foregoing messages may be the entire message or some data within the message. Several possible calculation methods for the first authentication information are listed below.
[0384] Calculation method 1: The first authentication information AUTHt satisfies AUTHt = AUF(K KE ’), where K KE ’ is the second key. Certainly, in addition to K KE , another parameter, for example, a fresh parameter or a message, may also be further used to generate AUTHt. For example, AUTHt satisfies AUTHt = AUF(K KE ’, NONCEt), AUTHt = AUF(K KE ’, NONCEg), or AUTHt = AUF(K KE ’, NONCEt, NONCEg).
[0385] Calculation method 2: The first authentication information AUTHt satisfies AUTHt = AUF(PSK), where PSK is the PSK between the second node and the first node in this specification, or PSK may be stored in the first node and is the PSK corresponding to the identification information of the second node.
[0386] Certainly, in addition to PSK, another parameter, for example, a fresh parameter or a message, may also be further used to generate AUTHt. For example, AUTHt satisfies AUTHt = AUF(PSK, NONCEg), AUTHt = AUF(PSK, NONCEt), or AUTHt = AUF(PSK, NONCEt, NONCEg).
[0387] Calculation method 3: The first authentication information AUTHt satisfies AUTHt = AUF(PSK, K KE’, the second message, NONCEt, and the key agreement algorithm capabilities of the first node). For related parameters, please refer to the above description.
[0388] Calculation method 4: Since the number of bits of the output value of the AUF algorithm may be large, the first node can select some bits of the output value, so that the first authentication information has a uniform and short number of data bits. This can reduce the data size of the third message and improve the transmission efficiency. For example, AUTHt = AUF(PSK)| Nビット is as follows.
[0389] The N bits can be predefined or preconfigured by the OEM, manufacturer, standard, or user. For example, the N bits may be the top 32 bits, that is, AUTHt = AUF(PSK, K KE ’, the second message, NONCEt, and the key agreement algorithm capabilities of the first node)| 最上位32ビット is satisfied. For example, the N bits may be the bottom 16 bits, and AUTHt = AUF(PSK, NONCEg)| 最下位の16ビット is satisfied.
[0390] Calculation method 5: The authentication information key Kauth is obtained based on the second key K KE ’, that is, Kauth = KDF(K KE ’). Optionally, the parameters used to generate Kauth may further include one or more of fresh parameters (such as NONCEt or NONCEg), random numbers, PSK, and the identification information of the first node.
[0391] The identification information authentication key can be used to generate the first authentication information. Certainly, other parameters, such as fresh parameters or messages, may also be further used to generate the first authentication information. In a possible solution, the first authentication information AUTHt is AUTHt = AUF(Kauth, NONCEt, the second message, and the key agreement algorithm capabilities of the first node)|Nビット is satisfied.
[0392] Alternatively, the AUF algorithm used to generate the authentication information may be replaced by another cryptographic algorithm, for example, a KDF algorithm, an encryption algorithm, or an authentication algorithm.
[0393] Optionally, if the second message includes the second authentication information AUTHg, the first node may verify the second authentication information AUTHg based on the second key. If the first node verifies that the second authentication information AUTHg is correct, the first node generates the first authentication information AUTHt.
[0394] In a possible solution, the second node uses the same parameters as the parameters obtained by the second node to generate the verification information and used by the second node to generate AUTHg. If the verification information matches AUTHg, the first node verifies that the second authentication information AUTHg is correct. If the verification information does not match AUTHg, the verification performed by the first node on the second authentication information AUTHg fails.
[0395] Furthermore, the second message may further include integrity verification information, and the first node may verify the integrity of the second information based on the integrity verification information. If the verification of the integrity of the second authentication information and the second message is successful, the first node generates the authentication information AUTHt.
[0396] The first node may obtain the PSK according to the correspondence relationship, or may generate the PSK based on the parameters. For related descriptions, refer to the description on the second node side in step S402. Details are not described again in this specification.
[0397] In some scenarios, the third message may be called a security context response message (or security context response information).
[0398] Step S406 (Optional): The second node verifies the first authentication information based on the first key.
[0399] In an optional solution, the second node should use the same parameters as those used by the first node to generate the first authentication information to generate the verification information. If the verification information is the same as the first authentication information, the verification is successful.
[0400] For example, if the first authentication information AUTHt satisfies AUTHt = AUF(PSK, K KE ’, NONCEt, the second message)| 最上位32ビット when satisfied, the second node generates verification information check1 = AUF(PSK, K KE , NONCEt, the second message)| 最上位32ビット and if the verification information check1 is the same as AUTHt, the verification is successful.
[0401] In a possible solution, if the verification of the first authentication information is successful, the second node sends an association establishment message to the first node. Correspondingly, the first node receives the association establishment message and can establish an association with the second node.
[0402] In another possible solution, if the verification of the first authentication information fails, the second node can disconnect the communication connection from the first node and discard the first message or discard the third message, etc. For example, if the verification of the first authentication information fails, it indicates that the first key K KE of the second node is different from the second key K KE ’ of the first node. Therefore, the identification information of the first node cannot be trusted, and the first node may be a node masqueraded by an attacker. In this case, to avoid access to untrusted nodes, the communication connection between the first node and the second node is disconnected.
[0403] Optionally, one or more of the first message, the second message, the third message, the association establishment message, etc. may include a Message Authentication Code (MAC). The message authentication code is information (or a small segment of information) generated using a specific algorithm and can be used to verify the integrity of a segment of a message. Optionally, the message authentication code may be further used for authentication of identification information. Thus, the receiver can verify the integrity of the message based on the message authentication code.
[0404] Optionally, when the second node determines a cryptographic key, the association establishment message may be further encrypted using the cryptographic key to obtain a ciphertext. Correspondingly, the second node determines a decryption key corresponding to the cryptographic key, and the decryption key can be used to decrypt the ciphertext to obtain the content within the association establishment message.
[0405] In the embodiment shown in FIG. 4, the second node first obtains an intermediate parameter based on a security parameter and a common parameter, and uses the intermediate parameter to generate a first key agreement parameter. The security parameter is not directly used to generate a key, and the security parameter is not directly used to generate the key agreement parameter. Thus, even if the number of bits of the security parameter is small, the confidentiality of the security parameter can be improved by using the common parameter, and the possibility that the security parameter is cracked can be reduced. Correspondingly, the security of the first key is improved. Thereby, the possibility that an attacker accesses the second node can be reduced, and the communication security and data security of the node can be improved.
[0406] Furthermore, the security parameters obtained by the first node need to match the security parameters of the second node. In this way, the first node and the second node can participate in consistent key generation using consistent security parameters. Specifically, the parameters used by the second node to generate the first key include the second secret key, the security parameter (at the first node), the common parameter, and the first secret key, and the parameters used by the first node to generate the second key include the first secret key, the security parameter (at the second node), the common parameter, and the second secret key. Since the parameters used to generate the first key are the same as the parameters used to generate the second key, when the security parameters of the first node match the security parameters of the second node, the generated first key and the generated second key will match.
[0407] The first node can obtain the first authentication information based on the second key, and the second node verifies the authentication information based on the first key. If the verification is successful, it indicates that the first key matches the second key, that is, the second node and the first node have the same security parameters. This indicates that the identification information of the second node is trusted.
[0408] When an attacker requests access to the second node, since the attacker does not have security parameters that match the security parameters of the second node, the attacker cannot generate a shared key that matches the security parameters of the second node. Therefore, the attacker cannot access the second node. This can prevent the attacker from accessing the second node and prevent the second node from being normally associated with an attacker having untrusted identification information.
[0409] The method embodiment shown in FIG. 4 includes many possible embodiment solutions. In the following, with reference to FIGS. 6, 7A, and 7B, some of the embodiment solutions will be described using examples. It should be noted that for related concepts, operations, or logical relationships not described in FIG. 5, refer to the corresponding description of the embodiment shown in FIG. 4.
[0410] FIG. 6 is a method flowchart of a possible communication method according to an embodiment of the present application. Further, the method may be implemented based on the architecture shown in FIG. 2. The communication method shown in FIG. 6 may include steps S601 to S611. For the convenience of explanation in the present application, the sequence from S601 to S611 is used for explanation, but it should be understood that this is not intended to constitute a limitation that the method must be performed in the foregoing sequence. The execution order, execution time, execution frequency, etc. of one or more of the foregoing steps are not limited in this embodiment of the present application. S601 to S611 are specifically as follows.
[0411] Step S601: The first node selects the TPPEKE algorithm.
[0412] Specifically, the first node determines, from one or more key agreement algorithms, the key agreement algorithm to be used when the first node performs key agreement with the second node. For example, optionally selected key agreement algorithms include SM2, ECDH (elliptic curve based on curve25519), TBPEKE (elliptic curve based on SM2), and TBPEKE (elliptic curve based on curve25519).
[0413] Among possible solutions, the key agreement algorithm selected by the first node includes the TPPEKE algorithm, that is, the TPPEKE algorithm is used as the algorithm for key agreement between the first node and the second node. The elliptic curves used by the TBPEKE algorithm include one or more of the elliptic curves defined by SM2, Curve25519, etc. Therefore, the TBPEKE algorithm can include the TBPEKE algorithm using the elliptic curve defined by SM2, the TBPEKE algorithm using Curve25519, etc. It should be understood that the above is an exemplary description for facilitating the description of the TBPEKE algorithm using different elliptic curves. In a specific embodiment process, other elliptic curves may alternatively be used. Examples are not enumerated herein.
[0414] Optionally, if the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes a group (or some elements within the group) whose order is p, and / or two base points within the group, for example, the aforementioned first base point and the second base point. The group is related to the elliptic curve used by the TBPEKE algorithm.
[0415] In a possible design, the second node adds the key agreement algorithm supported by the second node to the broadcast message. The key agreement algorithms supported by the second node are sorted according to priority, and an algorithm with a higher priority can be ranked at the top. The first node selects a key agreement algorithm based on the key agreement algorithm capabilities of the second node. In some possible designs, the algorithm selected by the first node is a key agreement algorithm supported by both the first node and the second node, and has the highest priority among the key agreement algorithms supported by the second node.
[0416] Step S602: The first node generates a first secret key SKt, calculates a public key PKt, and the public key PKt is used as the first key agreement parameter KEt.
[0417] Specifically, the first node generates a random number, uses the random number as the secret key SKt, and 1 ≤ SKt < p.
[0418] The first node calculates an intermediate parameter b based on pw (the first password) and U and V (common parameters), where b = (U + pw * V). The first node calculates the public key PKt based on b and the secret key SKt, where PKt = SKt * b.
[0419] The first node uses the public key PKt as the first key agreement parameter KEt.
[0420] Step S603: The first node sends an association request message to the second node. The association request message carries the ID of the T node, the algorithm indication information KE alg, the first key agreement parameter KEt, and a random number NONCEt.
[0421] KE alg indicates the key agreement algorithm selected by the first node. NONCEt is a random number determined by the first node.
[0422] Correspondingly, the second node receives the association request message from the first node.
[0423] Step S604: The second node generates a secret key SKg, calculates a public key PKg, and the public key PKg is used as the second key agreement parameter KEg.
[0424] Specifically, the second node generates a random number, uses the random number as the secret key SKg, and 1 ≤ SKg < p.
[0425] The second node calculates b (intermediate parameter) based on pw (the first password) and U and V (common parameters), where b = (U + pw * V). The second node calculates the public key PKg based on b and the secret key SKg, where PKg = SKg * b.
[0426] The first node uses the public key PKg as the first key agreement parameter KEg.
[0427] Step S605: The second node determines the first key K KE based on the secret key SKg and the first key agreement parameter KEt.
[0428] Specifically, the second node obtains the first key in the following way: The first key = SKg * KEt. Since the first key agreement parameter KEt satisfies the following equation, KEt = SKt * (U + pw * V), the first key K KE can satisfy the following equation: K KE = SKg * KEt = (SKt.SKg) * (U + pw * V).
[0429] Optionally, the second node may further obtain another derived key based on the first key K KE . For example, the second node calculates the shared key Kgt, i.e., the shared key Kgt = KDF(K KE , NONCEt, NONCEg) based on the first key K KE , the random number NONCEt, and the random number NONCEg.
[0430] Step S606: The second node calculates the second authentication information AUTHg based on K KE and PSK.
[0431] PSK is a shared key between the second node and the first node, and may be generated based on parameters such as a password or may be pre-configured.
[0432] In a possible solution, the second authentication information is obtained by calculation in the following manner: AUTHg = AUF(PSK, K KE )| 最上位32ビット .
[0433] In yet another possible solution, the optional parameters used to generate the second authentication information may further include one or more of the key Kgt, PSK, the first freshness parameter, the second freshness parameter, the association request message, and the security context request message. For example, the second authentication information is obtained by calculation in the following manner: AUTHg = AUF(PSK, K KE , NONCEg, association request message)| 最上位32ビット .
[0434] Optionally, the second node may further generate a random number NONCEg.
[0435] Step S607: The second node sends a security context request message to the first node. The security context request message carries the second key agreement parameter KEg, the random number NONCEg, and the second authentication information AUTHg.
[0436] Correspondingly, the first node receives the security context request message from the second node.
[0437] Step S608: The first node determines the second key K KE based on the private key SKt and the second key agreement parameter KEg.
[0438] Specifically, the first node obtains the second key in the following manner: Second key = SKt * KEg. Since the second key agreement parameter KEg satisfies the following formula: KEg = SKg * (U + pw * V), the second key K KE can satisfy the following formula: KKE =SKt * KEg = (SKt.SKg) * (U + pw * V).
[0439] The first key K KE =(SKt.SKg) * (U + pw * V)=the second key K KE and the first node and the second node obtain a consistent key K KE by exchanging key agreement parameters.
[0440] Optionally, the first node may further obtain another derived key based on the second key K KE . For example, the first node calculates a shared key Kgt, i.e., the shared key Kgt = KDF(K KE , NONCEt, NONCEg) based on the second key K KE , a random number NONCEt, and a random number NONCEg.
[0441] Step S609: The first node calculates the first authentication information AUTHt based on K KE and PSK.
[0442] PSK is a shared key between the second node and the first node and may be generated based on parameters such as a password or may be pre - configured.
[0443] In a possible solution, the first authentication information is obtained by calculation in the following way. AUTHt = AUF(PSK, K KE )| 最上位32ビット .
[0444] In yet another possible solution, the optional parameters used to generate the first authentication information may further include one or more of the key Kgt, PSK, a first freshness parameter, a second freshness parameter, an association request message, and a security context request message. For example, the first authentication information is obtained by calculation in the following way. AUTHt = AUF(PSK, K KE, security context request message, NONCEt, key agreement algorithm capabilities of the second node)| 最上位32ビット .
[0445] In a possible solution, the first node verifies whether the second authentication information AUTHg is correct. If the second authentication information AUTHg is correct, the first node generates the first authentication information AUTHt.
[0446] Optionally, the security context request message includes integrity verification information. If the verification performed by the first node on the second authentication information AUTHg and the integrity of the security context request message is successful, the first node generates the first authentication information AUTHt.
[0447] Step S610: The first node sends a security context response message to the second node. The security context response message carries the first authentication information AUTHt.
[0448] Correspondingly, the second node receives the security context response message from the first node.
[0449] The second node verifies the first authentication information AUTHt. If the second node verifies that the first authentication information AUTHt is correct, the second node performs step S511.
[0450] Step S611: The second node sends an association establishment message to the first node.
[0451] In a possible solution, the security context response message includes integrity verification information. When the verification performed by the second node on the first authentication information AUTHt and the integrity of the security context response message is successful, the second node sends an association establishment message to the first node.
[0452] In the embodiment shown in FIG. 6, when the first node requests access to the second node, the first node can select the TBPEKE algorithm based on the elliptic curve theory for key agreement, and the common parameters selected by the first node in the key agreement process are located on the elliptic curve. Due to the discrete logarithm problem of the elliptic curve, it is easy to obtain intermediate parameters by calculation based on the security parameter and the common parameters. However, it is difficult to obtain the first key agreement parameter and the common parameter to crack the security parameter. Therefore, by using the TBPEKE algorithm and the common parameters, the possibility of the security parameter being cracked can be reduced, and the node security can be improved.
[0453] When the attacker requests access to the second node, since the attacker does not have a security parameter that matches the security parameter of the second node, the attacker cannot generate a shared key that matches the security parameter of the second node. Therefore, the attacker cannot access the second node. Thereby, it is possible to prevent the attacker from accessing the second node, and it is possible to prevent the second node from being normally associated with an attacker having untrustworthy identification information.
[0454] FIGS. 7A and 7B are method flowcharts of yet another possible communication method according to an embodiment of the present application. Further, the method may be implemented based on the architecture shown in FIG. 2. The communication method shown in FIGS. 7A and 7B may include steps S701 to S717. For the sake of facilitating the description in the present application, the sequence from S701 to S717 is used for the description, but it should be understood that this is not intended to constitute a limitation that the method must be necessarily performed in the foregoing sequence. The execution order, execution time, execution frequency, etc. of one or more of the foregoing steps are not limited in this embodiment of the present application. S701 to S717 are specifically as follows.
[0455] Step S701 (Optional): The first node selects a key agreement algorithm.
[0456] Specifically, the first node determines, from one or more key agreement algorithms, the key agreement algorithm to be used when the first node performs key agreement with the second node. For example, optional key agreement algorithms include SM2, ECDH (elliptic curve based on curve25519), TBPEKE (elliptic curve based on SM2), and TBPEKE (elliptic curve based on curve25519).
[0457] In a possible solution, the key agreement algorithm selected by the first node includes the TPPEKE algorithm, that is, the TPPEKE algorithm is used as the algorithm for key agreement between the first node and the second node. The elliptic curve used by the TBPEKE algorithm includes one or more of the elliptic curves defined by SM2, Curve25519, etc. Therefore, the TBPEKE algorithm can include the TBPEKE algorithm using the elliptic curve defined by SM2, the TBPEKE algorithm using Curve25519, etc. It should be understood that the above is an exemplary description to facilitate the explanation of the TBPEKE algorithm using different elliptic curves. In a specific embodiment process, other elliptic curves may alternatively be used. Examples are not enumerated in this specification.
[0458] Optionally, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes a group (or some elements within the group) whose order is p, and / or two base points within the group, for example, the aforementioned first base point and second base point. The group is related to the elliptic curve used by the TBPEKE algorithm.
[0459] In a possible design, the second node adds the key agreement algorithm supported by the second node to the broadcast message. The key agreement algorithms supported by the second node are sorted according to priority, and the algorithm with a higher priority can be ranked at the top. The first node selects a key agreement algorithm based on the key agreement algorithm capabilities of the second node. In some possible designs, the algorithm selected by the first node is a key agreement algorithm supported by both the first node and the second node, and has the highest priority among the key agreement algorithms supported by the second node.
[0460] Step S702: The first node generates a random number x and calculates X = x*U.
[0461] Optionally, step S703 is performed when the key agreement algorithm is the TPPEKE algorithm. U is a pre-defined base point.
[0462] Optionally, U belongs to a group whose order is p (optionally, p may be a prime number), and the elliptic curve corresponding to the group is the elliptic curve used by the key agreement algorithm selected by the first node. For example, when the first node selects the TBPEKE (SM2-based elliptic curve) algorithm, U is related to the SM2-based elliptic curve and belongs to a point (i.e., the second base point) within the group whose order is p.
[0463] Optionally, the first node can send information about the selected elliptic curve to the second node to explain the elliptic curve related to the first common parameter.
[0464] Step 703 (optional): The first node sends the indication information of the key agreement algorithm to the second node. Correspondingly, the second node receives the indication information of the key agreement algorithm from the first node.
[0465] For example, the key agreement algorithm selected by the first node is indicated by KEalg.
[0466] Alternatively, the first node can send to the second node the key agreement algorithm supported by the first node. Correspondingly, the second node can obtain the key agreement algorithm selected by the first node in the same selection method as the first node.
[0467] Step S704: The first node sends X to the second node. Correspondingly, the second node receives X from the first node.
[0468] Optionally, X and the indication information of the key agreement algorithm may be carried in the same message, or may be sent using different messages.
[0469] Step S705: The second node generates a random number y, calculates Y = y * U, and calculates V = y * X.
[0470] Step S706: The second node generates a secret key SKg, calculates a public key PKg, and the public key PKg is used as the second key agreement parameter KEg.
[0471] Specifically, the second node generates a random number, uses the random number as the secret key SKg, and 1 ≤ SKg < p.
[0472] The second node calculates b (intermediate parameter) based on pw (the first password), as well as U and V (common parameters), and b = (U + pw * V). The second node calculates the public key PKg based on b and the secret key SKg, where PKg = SKg * b.
[0473] The first node uses the public key PKg as the first key agreement parameter KEg.
[0474] Step S707: The second node sends Y to the first node. Correspondingly, the first node receives Y from the second node.
[0475] Step S708: The first node calculates V = x * Y.
[0476] Step S709: Generate a secret key SKt, calculate a public key PKt, and the public key PKt is used as the first key agreement parameter KEt.
[0477] Specifically, the first node generates a random number, uses the random number as the secret key SKt, and 1 ≤ SKt < p.
[0478] The first node calculates b (an intermediate parameter) based on pw (the first password), as well as U and V (common parameters), and b = (U + pw * V). The first node calculates the public key PKt based on b and the secret key SKt, where PKt = SKt * b.
[0479] The first node uses the public key PKt as the first key agreement parameter KEt.
[0480] Step S710: The first node sends an association request message to the second node. The association request message carries the first key agreement parameter KEt, a random number NONCEt, the ID of the T node (optional), and the indication information KE alg of the algorithm (optional).
[0481] NONCEt is a random number determined by the first node.
[0482] Correspondingly, the second node receives the association request message from the first node.
[0483] Step S711: The second node determines the first key K KE based on the secret key SKg and the first key agreement parameter KEt.
[0484] Specifically, the second node obtains the first key in the following manner: First key = SKg * KEt. The first key agreement parameter KEt satisfies the following equation, KEt = SKt * (U + pw * V), so the first key K KE can satisfy the following equation: K KE = SKg * KEt = (SKt.SKg) * (U + pw * V).
[0485] Optionally, the second node may further obtain another derived key based on the first key K KE . For example, the second node calculates a shared key Kgt based on the first key K KE , a random number NONCEt, and a random number NONCEg, i.e., the shared key Kgt = KDF(K KE , NONCEt, NONCEg).
[0486] Optionally, step S706 may be performed when (or after) step S711 is performed.
[0487] Step S712: The second node calculates the second authentication information AUTHg based on K KE and PSK.
[0488] PSK is a shared key between the second node and the first node and may be generated based on parameters such as a password or may be pre-configured.
[0489] In a possible solution, the second authentication information is obtained by calculation in the following manner: AUTHg = AUF(PSK, K KE ) | 最上位32ビット .
[0490] In yet another possible solution, the optional parameters used to generate the second authentication information may further include one or more of the key Kgt, PSK, first freshness parameter, second freshness parameter, association request message, and security context request message. For example, the second authentication information is obtained by calculation in the following manner: AUTHg = AUF(PSK, K KE , NONCEg, association request message)| 最上位32ビット .
[0491] Optionally, the second node may further generate a random number NONCEg.
[0492] Step S713: The second node sends a security context request message to the first node. The security context request message carries the second key agreement parameter KEg, the random number NONCEg, and the second authentication information AUTHg.
[0493] Correspondingly, the first node receives a security context request message from the second node.
[0494] Step S714: The first node determines the second key K KE based on the private key SKt and the second key agreement parameter KEg.
[0495] Specifically, the first node obtains the second key in the following manner: Second key = SKt * KEg. Since the second key agreement parameter KEg satisfies the following formula: KEg = SKg * (U + pw * V), the second key K KE can satisfy the following formula: K KE = SKt * KEg = (SKt.SKg) * (U + pw * V).
[0496] The first key K KE =(SKt.SKg) * (U + pw * V)= the second key K KEand the first node and the second node obtain a consistent key K by exchanging key agreement parameters KE therefrom.
[0497] Optionally, the first node may further obtain another derived key based on the second key K KE . For example, the first node calculates a shared key Kgt, i.e., shared key Kgt = KDF(K KE , NONCEt, NONCEg) based on the second key K KE , a random number NONCEt, and a random number NONCEg.
[0498] Step S715: The first node calculates first authentication information AUTHt based on K KE and PSK.
[0499] PSK is a shared key between the second node and the first node, and may be generated based on parameters such as a password, or may be pre-configured.
[0500] In a possible solution, the first authentication information is obtained by calculation in the following manner. AUTHt = AUF(PSK, K KE )| 最上位32ビット .
[0501] In yet another possible solution, the optional parameters used to generate the first authentication information may further include one or more of the key Kgt, PSK, a first freshness parameter, a second freshness parameter, an association request message, and a security context request message. For example, the first authentication information is obtained by calculation in the following manner. AUTHt = AUF(PSK, K KE , security context request message, NONCEt, key agreement algorithm capability of the second node)| 最上位32ビット .
[0502] In a possible solution, the first node verifies whether the second authentication information AUTHg is correct. If the second authentication information AUTHg is correct, the first node generates the first authentication information AUTHt.
[0503] Optionally, the security context request message includes integrity verification information. If the verification performed by the first node on the second authentication information AUTHg and the integrity of the security context request message is successful, the first node generates the first authentication information AUTHt.
[0504] Step S716: The first node sends a security context response message to the second node. The security context response message carries the first authentication information AUTHt.
[0505] Correspondingly, the second node receives the security context response message from the first node.
[0506] The second node verifies the first authentication information AUTHt. If the second node verifies that the first authentication information AUTHt is correct, the second node performs step S511.
[0507] Step S717 (optional): The second node sends an association establishment message to the first node.
[0508] In a possible solution, the security context response message includes integrity verification information. When the verification performed by the second node on the first authentication information AUTHt and the integrity of the security context response message is successful, the second node sends an association establishment message to the first node.
[0509] In the embodiments shown in FIGS. 7A and 7B, the first node and the second node exchange random numbers and obtain common parameters U and V by using an elliptic curve defined by the TBPEKE algorithm. When the first node requests access to the second node, the first node can select the TBPEKE algorithm based on the elliptic curve theory to perform key agreement and generate key agreement parameters in the key agreement process by using U and V. Due to the discrete logarithm problem of the elliptic curve, it is easy to obtain intermediate parameters by calculation based on the security parameter and the common parameter. However, it is difficult to obtain the first key agreement parameter and the common parameter to crack the security parameter. Therefore, by using the TBPEKE algorithm and the common parameter, the possibility of the security parameter being cracked can be reduced, and the node security can be improved.
[0510] When an attacker requests access to the second node, since the attacker does not have a security parameter that matches the security parameter of the second node, the attacker cannot generate a shared key that matches the security parameter of the second node. Therefore, the attacker cannot access the second node. Thereby, it is possible to prevent the attacker from accessing the second node and prevent the second node from being normally associated with an attacker having untrustworthy identification information.
[0511] In the embodiments shown in FIGS. 6, 7A, and 7B, the first password pw may be replaced with a PSK.
[0512] The above has described the method in the embodiments of the present application in detail. The following provides the device in the embodiments of the present application.
[0513] In order to implement the functions in the embodiments of the foregoing method, a plurality of devices provided in the embodiments of the present application, such as communication devices, may include corresponding hardware structures, corresponding software units of the hardware structures, or combinations of hardware structures and software structures for performing functions. It should be understood by those skilled in the art that, in combination with the examples described in the embodiments disclosed herein, units, algorithms, and steps can be implemented by the hardware in the embodiments of the present application or a combination of hardware and computer software. Whether a function is performed by hardware or by hardware driven by computer software depends on the specific application and design constraints of the technical solution. Those skilled in the art can implement the foregoing method embodiments by using different device implementation manners in different usage scenarios, but different implementation manners of the device should not be considered to exceed the scope of the embodiments of the present application.
[0514] In the embodiments of the present application, a device may be divided into functional units. For example, the functional units may be obtained by division based on corresponding functions, or two or more functions may be integrated into one functional unit. The integrated module may be implemented in the form of hardware or in the form of a software functional unit. It should be noted that the division into units in the embodiments of the present application is only an example and is only a logical function division. In actual implementation manners, other division methods may be used.
[0515] Several possible devices are listed below.
[0516] The above details the method in the embodiments of the present application. The following provides the devices in the embodiments of the present application.
[0517] FIG. 8 is a diagram of the structure of a communication device 80 according to an embodiment of the present application. Optionally, the communication device 80 may be an independent device, such as a node. Alternatively, the communication device 80 may be a component within an independent device (e.g., a node), such as a chip or an integrated circuit.
[0518] The communication device 80 may include one or more of a receiving unit 801, a transmitting unit 802, and a processing unit 803. The communication device 80 is configured to implement the aforementioned communication method, for example, the communication methods shown in FIGS. 4, 6, or 7A and 7B.
[0519] In a possible design, the communication device 80 includes a receiving unit 801, a transmitting unit 802, and a processing unit 803, and the communication device 80 is configured to implement the method on the second node side in the aforementioned embodiment.
[0520] In a possible implementation, the receiving unit 801 is configured to receive a first message from the first node, the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first secret key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is a first password or a pre-shared key PSK between the first node and the second node, and the first password is an agreed access password between the first node and the second node.
[0521] The transmitting unit 802 is further configured to transmit a second message to the first node, the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second secret key and an intermediate parameter.
[0522] The processing unit 803 is configured to obtain a first key based on the first key agreement parameter and the second secret key.
[0523] In yet another possible implementation, the receiving unit 801 is further configured to receive a third message from the first node, the third message includes first authentication information, the first authentication information is associated with a second key, and the second key is associated with a second key agreement parameter and a first secret key.
[0524] The processing unit 803 is further configured to verify the first authentication information based on the first key.
[0525] In yet another possible implementation, the first key is used to obtain one or more keys.
[0526] In a possible solution, the first key is used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, etc.
[0527] In yet another possible implementation, the transmitting unit 802 is further configured to transmit an association establishment message to the first node when the verification of the first authentication information is successful. is further configured as such.
[0528] In yet another possible implementation, the transmitting unit 802 is further configured to transmit an association establishment message to the first node when the verification of the integrity of the first authentication information and the third message is successful. is further configured as such.
[0529] In yet another possible implementation, the receiving unit 801 is further configured to receive instruction information of a key agreement algorithm transmitted by the first node, and the key agreement algorithm includes a TBPEKE algorithm. is further configured as such.
[0530] Optionally, the instruction information of the key agreement algorithm includes instruction information of a first key agreement algorithm, and the instruction information of the first key agreement algorithm indicates a TBPEKE algorithm.
[0531] In yet another possible embodiment, at least one common parameter includes a first common parameter and a second common parameter.
[0532] The first common parameter and the second common parameter are related to a first elliptic curve, and the first elliptic curve is an elliptic curve corresponding to a key agreement algorithm, and the key agreement algorithm includes a TBPEKE algorithm.
[0533] In yet another possible embodiment, the first common parameter and the second common parameter belong to points on the first elliptic curve.
[0534] In yet another possible embodiment, the first common parameter is predefined, and the second common parameter is determined based on the first common parameter, a first random number, and a second random number, where the first random number is derived from a first node and the second random number is derived from a second node.
[0535] In a possible embodiment, at least one common parameter includes at least one base point, and the at least one base point belongs to a group whose order is p, where p is a prime number.
[0536] Optionally, the group may be a cyclic group or a cyclic subgroup related to operations on the first elliptic curve.
[0537] Optionally, in some scenarios, the base point may alternatively be replaced by a generator.
[0538] In yet another possible embodiment, when the selected key agreement algorithm is a TBPEKE algorithm, at least one common parameter includes some or all elements within a group whose order is p, where p is a prime number.
[0539] The base point (or generator) of the subgroup with order p is U. For a selected number d, if the range of the value of d is [1, p - 1], dU is included in the group.
[0540] Optionally, at least one common parameter includes the base point U. Further optionally, at least one common parameter further includes V obtained by performing an operation on U, where V = dU and the range of d is [1, p - 1].
[0541] In yet another possible embodiment, if the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes two points within a group with order p.
[0542] Optionally, the two points may be two base points. Alternatively, one of the two points is a base point and the other is a second base point obtained by a calculation based on the base point. For ease of explanation, in this application, the two points are referred to as the first base point and the second base point.
[0543] In yet another possible embodiment, if the selected key agreement algorithm is the TBPEKE algorithm, the common parameters of the TBPEKE algorithm include a cyclic group with order prime p and two independent base points U and V within the group.
[0544] It should be understood that "independent" means that U and V are two points with different values and is not intended to constitute a limitation that there is no relationship between U and V.
[0545] In yet another possible embodiment, the receiving unit 801 is further configured to receive a first calculated value from the first node, where the first calculated value is related to a first random number and a first common parameter, the first random number is determined by the first node, and the first common parameter is predefined based on the TBPEKE algorithm.
[0546] The processing unit 803 is further configured to determine a second common parameter based on the second random number and the first calculated value.
[0547] The transmission unit 802 is further configured to transmit the second calculated value to the first node, where the second calculated value is associated with the second random number and the first common parameter, and the second calculated value is used by the first node to determine the second common parameter.
[0548] Optionally, the first common parameter is the aforementioned first base point, and the second common parameter is the aforementioned second base point.
[0549] In yet another possible embodiment, the intermediate parameter satisfies the following equation. b = U + s * V, where b is the intermediate parameter, U and V are at least one common parameter, s is the security parameter, "*" is the elliptic curve point multiplication operation, and "+" is the elliptic curve point addition operation.
[0550] In a possible embodiment, U is the first base point and V is the second base point. Further, U and V belong to a group with order p, where p is a prime number. The operations related to the group are operations on the first elliptic curve.
[0551] The first elliptic curve is the elliptic curve used by the selected key agreement algorithm. For example, if the selected key agreement algorithm is the TBPEKE algorithm, the first elliptic curve may be an elliptic curve defined by SM2, Curve25519, etc.
[0552] In yet another possible embodiment, the first key agreement parameter KEt satisfies the following equation: KEt = SKt * b, The first key satisfies the following equation: The first key = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V), The second key agreement parameter KEg satisfies the following equation: KEg = SKg * b, and The second key satisfies the following equation: Second key = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V), where SKt is the first secret key, SKg is the second secret key, and "." is the multiplication operation.
[0553] In yet another possible implementation, the range of values of the first secret key (SKt) is [1, p), the range of values of the second secret key (SKg) is [1, p), and p is the degree of the elliptic curve used by the TBPEKE algorithm.
[0554] In yet another possible implementation, the transmission unit 802 broadcasts the key agreement algorithm capabilities of the second node, and the key agreement algorithm capabilities of the second node represent the key agreement algorithms supported by the second node. is further configured as such.
[0555] In yet another possible implementation, the key agreement algorithms supported by the first node are sorted according to priority.
[0556] In yet another possible implementation, the first message further includes a first freshness parameter, and the first authentication information is associated with the pre-shared key PSK between the first node and the second node, the second key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node.
[0557] In yet another possible implementation, the processing unit 803 verifies the first authentication information based on the PSK between the first node and the second node, the first key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node. is further configured as follows.
[0558] In yet another possible embodiment, the second message further includes second authentication information and second freshness parameters, and the processing unit obtains the second authentication information based on the PSK between the first node and the second node, the first key, the second new parameter, and the first message is further configured as follows.
[0559] In yet another possible embodiment, the first message further includes a first freshness parameter, the second message further includes a second freshness parameter, and the processing unit 803 obtains a third key based on the first key, the first freshness parameter, and the second freshness parameter is further configured as follows.
[0560] In yet another possible embodiment, the PSK is pre-configured or pre-defined, or obtained based on the first password.
[0561] In yet another possible embodiment, the processing unit 803 obtains the PSK between the first node and the second node according to the first correspondence relationship is further configured as follows.
[0562] It may be known that the second node can store the correspondence relationship between the PSK and the first node in the form of a correspondence relationship. Therefore, according to the correspondence relationship, the PSK between the first node and the second node can be obtained.
[0563] In yet another possible embodiment, the processing unit determines the PSK between the first node and the second node based on the first password, the first freshness parameter, and the second freshness parameter is further configured as follows.
[0564] In a possible design, the PSK is determined based on a first password, a first key, a first freshness parameter, and a second freshness parameter.
[0565] In a possible design, the communication device 80 includes a receiving unit 801 and a transmitting unit 802, and the communication device 80 is configured to implement the method on the first node side in the foregoing embodiment.
[0566] In a possible embodiment, the transmitting unit 802 is configured to transmit a first message to a second node, the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first secret key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is the first password or a pre-shared key PSK between the first node and the second node, and the first password is an agreed access password between the first node and the second node.
[0567] The receiving unit 801 is configured to receive a second message from the second node, the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second secret key and an intermediate parameter.
[0568] The processing unit 803 is configured to obtain a second key based on the second key agreement parameter and the first secret key.
[0569] In a possible embodiment, the transmitting unit 802 is further configured to transmit a third message to the first node, the third message includes first authentication information, and the first authentication information is associated with the second key.
[0570] In yet another possible embodiment, the second key is used to obtain one or more keys.
[0571] In a possible solution, the second key is used to obtain, by derivation, an encryption key, an integrity key, an identification information authentication key, etc.
[0572] In yet another possible embodiment, the receiving unit 801 is further configured to receive an association establishment message from the second node. as further configured.
[0573] In yet another possible embodiment, the communication device further includes a processing unit 803, and the processing unit 803 is configured to select a first key agreement algorithm based on the key agreement algorithm capabilities of the second node, where the key agreement algorithm capabilities of the second node can indicate one or more key agreement algorithms supported by the second node. as configured.
[0574] In yet another possible embodiment, the transmitting unit 802 is further configured to transmit indication information of the key agreement algorithm to the second node, and the indication information of the key agreement algorithm indicates a two-base password exponential function key exchange TBPEKE algorithm.
[0575] Optionally, since different elliptic curves are used, there may be multiple TBPEKE algorithms. For example, the TBPEKE algorithm may include one or more of the elliptic curves defined by SM2, Curve25519, etc. Thus, the TBPEKE algorithm can include a TBPEKE algorithm using the elliptic curve defined by SM2, a TBPEKE algorithm using Curve25519, etc.
[0576] In yet another possible embodiment, at least one common parameter includes a first common parameter and a second common parameter.
[0577] The first common parameter and the second common parameter are related to the first elliptic curve, and the first elliptic curve is an elliptic curve corresponding to a key agreement algorithm, and the key agreement algorithm includes the TBPEKE algorithm.
[0578] In yet another possible embodiment, the first common parameter and the second common parameter belong to a point on the first elliptic curve.
[0579] In yet another possible embodiment, the first common parameter is predefined, and the second common parameter is determined based on the first common parameter, the first random number, and the second random number, where the first random number is derived from the first node and the second random number is derived from the second node.
[0580] In a possible embodiment, at least one common parameter includes at least one base point, and at least one base point belongs to a group whose order is p, where p is a prime number.
[0581] Optionally, the group may be a cyclic group or a cyclic subgroup related to the operations on the first elliptic curve.
[0582] Optionally, in some scenarios, the base point may alternatively be replaced by a generator.
[0583] In yet another possible embodiment, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes some or all of the elements within a group whose order is p, where p is a prime number.
[0584] The base point (or called a generator) of the subgroup whose order is p is U. For a selected number d, when the value range of d is [1, p - 1], dU is included in the group.
[0585] Optionally, at least one common parameter includes the base point U. Further optionally, at least one common parameter further includes V obtained by performing an operation on U, where V = dU and the range of d is [1, p - 1].
[0586] In yet another possible embodiment, when the selected key agreement algorithm is the TBPEKE algorithm, at least one common parameter includes two points within a group having an order of p.
[0587] Optionally, the two points may be two base points. Alternatively, one of the two points is taken as the base point and the other is taken as a second base point obtained by a calculation based on the base point. For ease of explanation, in this application, the two points are referred to as the first base point and the second base point.
[0588] In yet another possible embodiment, when the selected key agreement algorithm is the TBPEKE algorithm, the common parameters of the TBPEKE algorithm include a cyclic group having an order of prime number p and two independent base points U and V within the group.
[0589] It should be understood that "independent" means that U and V are two points having different values and is not intended to constitute a limitation that there is no relationship between U and V.
[0590] In yet another possible embodiment, the transmitting unit 802 is further configured to transmit a first calculated value to a second node, where the first calculated value is related to a first random number and a first common parameter, the first random number is determined by the first node, and the first common parameter is predefined.
[0591] The receiving unit 801 is further configured to receive a second calculated value from the second node, where the second calculated value is related to a second random number and the first common parameter.
[0592] The processing unit 803 is configured to determine a second common parameter based on the second random number and the first calculated value.
[0593] Optionally, the first common parameter is the aforementioned first base point, and the second common parameter is the aforementioned second base point. In yet another possible embodiment, the intermediate parameter satisfies the following equation. b = U + s * V, where b is the intermediate parameter, U and V are at least one common parameter, s is the security parameter, "*" is the elliptic curve point multiplication operation, and "+" is the elliptic curve point addition operation.
[0594] In a possible embodiment, U is the first base point and V is the second base point. Further, U and V belong to a group whose order is p, where p is a prime number. The operations related to the group are operations on the first elliptic curve.
[0595] The first elliptic curve is the elliptic curve used by the selected key agreement algorithm. For example, if the selected key agreement algorithm is the TBPEKE algorithm, the first elliptic curve may be an elliptic curve defined by SM2, Curve25519, etc.
[0596] In yet another possible embodiment, the first key agreement parameter KEt satisfies the following equation: KEt = SKt * b, The first key satisfies the following equation: The first key = SKg * KEt = SKg * (SKt * b) = (SKt.SKg) * (U + s * V), The second key agreement parameter KEg satisfies the following equation: KEg = SKg * b, The second key satisfies the following equation: The second key = SKt * KEg = SKt * (SKg * b) = (SKt.SKg) * (U + s * V), where SKt is the first secret key, SKg is the second secret key, and "." is the multiplication operation.
[0597] In yet another possible implementation, the range of values of the first secret key (SKt) is [1, p), the range of values of the second secret key (SKg) is [1, p), and p is the order of the elliptic curve used by the TBPEKE algorithm.
[0598] In yet another possible implementation, the receiving unit 801 is of the second node, receives the key agreement algorithm capabilities transmitted by the second node, and the key agreement algorithm capabilities of the second node represent the key agreement algorithms supported by the second node. is further configured as such.
[0599] In yet another possible implementation, the key agreement algorithms supported by the first node are sorted according to priority.
[0600] In yet another possible implementation, the first message further includes a first freshness parameter, and the first authentication information is associated with the pre-shared key PSK between the first node and the second node, the second key, the second message, the first freshness parameter, and the key agreement algorithm capabilities of the second node.
[0601] In yet another possible implementation, the second message further includes second authentication information and a second freshness parameter, and the second authentication information is associated with the PSK between the first node and the second node, the first key, the second freshness parameter, and the first message.
[0602] In yet another possible implementation, the processing unit 803 verifies the second authentication information based on the PSK between the first node and the second node, the second key, the second freshness parameter, and the first message, and generates the first authentication information when the verification of the integrity of the second authentication information and the second message is successful. is further configured as follows.
[0603] In a possible embodiment, the first message further includes a first freshness parameter, the second message further includes a second freshness parameter, and the processing unit 803 obtains a fourth key based on the second key, the first freshness parameter, and the second freshness parameter is further configured as follows.
[0604] In a possible embodiment, the PSK is pre-configured or pre-defined, or obtained based on the first password.
[0605] In yet another possible embodiment, the processing unit 803 obtains the PSK between the first node and the second node according to the second correspondence relationship is further configured as follows.
[0606] In yet another possible embodiment, the processing unit 803 determines the PSK between the first node and the second node based on the first password, the first freshness parameter, and the second freshness parameter is further configured as follows.
[0607] FIG. 9 is a diagram of the structure of a possible communication device 90 according to an embodiment of the present application.
[0608] The communication device 90 may be an independent device such as a vehicle, a drone, or a robot, or it may be a component included in an independent device, such as a chip, a software module, or an integrated circuit. The communication device 90 may include at least one processor 901 and a communication interface 902. Optionally, the communication device 90 may further include at least one memory 903. Also optionally, the communication device 90 may further include a connection line 904. The processor 901, the communication interface 902, and / or the memory 903 are connected via the connection line 904 and communicate with each other via the connection line 904 to transmit control and / or data signals. Optionally, the communication device 90 may further include one or more of a detection module, an output module, etc. (not shown).
[0609] Specifically, the following content is provided.
[0610] (1) The processor 901 is a module for performing arithmetic operations and / or logical operations, and may specifically include one or more of the following devices, namely, a CPU, an MCU, a GPU, an MPU, an ASIC, an FPGA, a CPLD, a coprocessor (which assists the central processing unit in completing corresponding processes and applications), an NPU, etc.
[0611] (2) The communication interface 902 can be configured to provide information input or output for at least one processor. In some possible scenarios, the communication interface 902 can include an interface circuit, and / or the communication interface 902 can be configured to receive data transmitted from the outside and / or transmit data to the outside. For example, the communication interface 902 may include a wired link interface such as an Ethernet cable, or may be a wireless link (Wi-Fi, Bluetooth, universal wireless transmission, vehicle-mounted short-range communication technology, other short-range wireless communication technologies, etc.) interface. Optionally, the communication interface 902 can further include a transmitter (for example, a radio frequency transmitter or an antenna) coupled to the interface, a receiver, and the like.
[0612] Optionally, if the communication device 90 is an independent device, the communication interface 902 can include a receiver and a transmitter. The receiver and the transmitter can be the same component or different components. When the receiver and the transmitter are the same component, the component may be called a transceiver.
[0613] Optionally, if the communication device 90 is a chip or a circuit, the communication interface 902 may include an input interface and an output interface. The input interface and the output interface may be the same interface or different interfaces.
[0614] Optionally, the function of the communication interface 902 may be implemented using a transceiver circuit or a dedicated transceiver chip, and the processor 901 may be implemented using a dedicated processing chip, a processing circuit, a processor, or a general-purpose chip.
[0615] (3) The memory 903 is configured to provide a storage space, which can store data such as an operating system and computer programs. The memory 903 can be one of or a combination of a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a compact disc read-only memory (CD-ROM), etc.
[0616] The functions and operations of the modules or units in the communication device 90 listed above are merely examples for explanation.
[0617] The functional units in the communication device 90 may be configured to implement the aforementioned communication methods, for example, the communication methods shown in FIGS. 4, 6, or FIGS. 7A and 7B. In this specification, detailed descriptions are omitted to avoid repetition.
[0618] Optionally, the processor 901 may be a processor specially configured to perform the aforementioned method (referred to as a dedicated processor for ease of distinction), or a processor that performs the aforementioned method by calling a computer program (referred to as a dedicated processor for ease of distinction). Optionally, at least one processor may further include both a dedicated processor and a general-purpose processor.
[0619] Optionally, when the communication device 90 includes at least one memory 903, if the processor 901 performs the aforementioned communication method by calling a computer program, the computer program may be stored in the memory 903.
[0620] One embodiment of the present application further provides a chip system. The chip system includes a processor and a communication interface. The communication interface is configured to receive and / or transmit data, and / or the communication interface is configured to provide an input and / or an output for the processor. The chip system is configured to implement the aforementioned communication method, for example, the methods of FIGS. 4, 6, or FIGS. 7A and 7B.
[0621] One embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium stores instructions. When the instructions are run on at least one processor, the aforementioned communication method, for example, the methods of FIGS. 4, 6, or FIGS. 7A and 7B, is implemented.
[0622] One embodiment of the present application further provides a computer program product. The computer program product includes computer instructions, and the computing instructions are used to implement the aforementioned communication method, for example, the methods of FIGS. 4, 6, or FIGS. 7A and 7B.
[0623] In the embodiments of the present application, it should be noted that the words "example" or "for example" are used to give examples, illustrations, or explanations. Any embodiment or design method described as an "example" or "for example" in the present application should not be described as being more preferable than another embodiment or design method, or having more advantages than another embodiment or design method. Exactly, the use of words such as "example" or "for example" is intended to present relative concepts in a specific way.
[0624] In the embodiments of the present application, "at least one" means one or more, and "a plurality of" means two or more. "At least one of the following items" or similar expressions mean any combination of these items, including any combination of a single item or a plurality of items.
[0625] For example, at least one of a, b, or c can represent a, b, c, (a and b), (a and c), (b and c), or (a, b, and c), and a, b, and c can be singular or plural. The term "and / or" describes the association between related objects and indicates that three relationships can exist. For example, A and / or B can represent the following three cases, namely, when only A exists, when both A and B exist, and when only B exists, and A and B can be singular or plural. The character " / " generally indicates the "or" relationship between related objects.
[0626] Furthermore, unless otherwise specified, ordinal numbers such as "first" and "second" in the embodiments of this application are used to distinguish between multiple objects, but are not intended to limit the order, time series, priority, or importance of the multiple objects. For example, the first device and the second device are merely used to facilitate the description and do not indicate a difference in structure and importance between the first device and the second device. In some embodiments, the first device and the second device may alternatively be the same device.
[0627] Depending on the context, the term "when" used in the foregoing embodiments may be interpreted as meaning "case", "after", "in response to a decision", or "in response to a detection". The foregoing description is only an optional embodiment of this application and is not intended to limit this application. Changes, equivalent substitutions, improvements, etc. made within the scope of the idea and principle of this application shall be included within the protection scope of this application.
[0628] Those skilled in the art can understand that all or part of the steps of the embodiment can be implemented by hardware or a program that instructs the related hardware. The program may be stored in a computer-readable storage medium. The storage medium may be a read-only memory, a magnetic disk, an optical disk, or the like.
Description of Reference Numerals
[0629] 80 Communication device 90 Communication device 201 First node 202 Second node 301 Smartphone 801 Receiving unit 802 Transmitting unit 803 Processing unit 901 Processor 902 Communication interface 903 Memory 904 Connection line
Claims
1. A communication method, the method comprising: Receiving, at a first node, a first message, the first message including a first key agreement parameter, the first key agreement parameter being associated with a first secret key and an intermediate parameter, the intermediate parameter being associated with a security parameter and at least one common parameter, the security parameter being a first password or a pre-shared key PSK between the first node and a second node, the first password being an agreed access password between the first node and the second node; Sending a second message to the first node, the second message including a second key agreement parameter, the second key agreement parameter being associated with a second secret key and the intermediate parameter; Obtaining a first key based on the first key agreement parameter and the second secret key; A communication method comprising the above.
2. The method according to claim 1, wherein the first key is used to obtain one or more of an encryption key, an integrity key, or an identification information authentication key.
3. Receiving, at the first node, a third message, the third message including first authentication information, the first authentication information being associated with a second key, the second key being associated with the second key agreement parameter and the first secret key; Verifying the first authentication information based on the first key; The method according to claim 1, further comprising the above.
4. Sending an association establishment message to the first node when verification of the integrity of the first authentication information and the third message is successful; The method according to claim 3, further comprising the above.
5. Receiving, at the first node, instruction information transmitted by the first node, the instruction information of the first key agreement algorithm indicating a two-base password exponential function key exchange TBPEKE algorithm; The method according to any one of claims 1 to 4, further comprising the above.
6. The at least one common parameter includes a first common parameter and a second common parameter. The first common parameter and the second common parameter are related to a first elliptic curve, the first elliptic curve is an elliptic curve corresponding to the first key agreement algorithm, and the first key agreement algorithm is the TBPEKE algorithm. The method according to any one of claims 1 to 5.
7. Receiving a first calculated value from the first node, the first calculated value being related to a first random number and the first common parameter, the first random number being determined by the first node, and the first common parameter being predefined. Determining the second common parameter based on a second random number and the first calculated value. Sending a second calculated value to the first node, the second calculated value being related to the second random number and the first common parameter. The method according to claim 6, further comprising.
8. The intermediate parameter satisfies the following formula: b = U + s * V, where b is the intermediate parameter, U and V are the at least one common parameter, s is the security parameter, * is an elliptic curve point multiplication operation, and + is an elliptic curve point addition operation. The method according to any one of claims 5 to 7.
9. The method according to any one of claims 5 to 8, wherein the at least one common parameter includes a cyclic group whose order is a prime number p, and two independent base points U and V within the cyclic group.
10. The first key agreement parameter KEt satisfies the following formula: KEt = SKt * b, The first key satisfies the following formula: First key = SKg * KEt, The second key agreement parameter KEg satisfies the following formula: KEg = SKg * b, The second key satisfies the following formula: Second key = SKt * KEg, where SKt is the first secret key and SKg is the second secret key. The method according to claim 8 or 9.
11. The method according to any one of claims 5 to 10, wherein the value range of the first secret key is [1, p), the value range of the second secret key is [1, p), and p is the order of the elliptic curve used by the TBPEKE algorithm.
12. Before the step of receiving a first message from the first node. Broadcasting the key agreement algorithm capability of the second node, wherein the key agreement algorithm capability of the second node represents a key agreement algorithm supported by the second node The method according to any one of claims 1 to 11, further comprising **Claim 13** The method according to claim 12, wherein the key agreement algorithm supported by the second node is sorted according to priority **Claim 14** The first message further includes a first freshness parameter The first authentication information is associated with the PSK, the second key, the second message, the first freshness parameter, and the key agreement algorithm capability of the second node The step of verifying the first authentication information based on the first key includes Verifying the first authentication information based on the PSK, the first key, the second message, the first freshness parameter, and the key agreement algorithm capability of the second node The method according to claim 3 or 4, comprising **Claim 15** The second message further includes second authentication information and a second freshness parameter, and the method includes Obtaining the second authentication information based on the PSK, the first key, the second freshness parameter, and the first message The method according to any one of claims 1 to 14, further comprising **Claim 16** A communication method, the method comprising Transmitting a first message to a second node, wherein the first message includes a first key agreement parameter, the first key agreement parameter is associated with a first secret key and an intermediate parameter, the intermediate parameter is associated with a security parameter and at least one common parameter, the security parameter is a first password or a pre-shared key PSK between the first node and the second node, and the first password is an agreed access password between the first node and the second node Receiving a second message from the second node, wherein the second message includes a second key agreement parameter, and the second key agreement parameter is associated with a second secret key and the intermediate parameter Obtaining a second key based on the second key agreement parameter and the first secret key A communication method including the above. **Claim 17** The method according to claim 16, wherein the second key is used to obtain one or more of an encryption key, an integrity key, or an identification information authentication key. **Claim 18** The method includes Sending a third message to the first node, wherein the third message includes first authentication information, and the first authentication information is associated with the second key The method according to claim 16, further including the above. **Claim 19** Receiving an association establishment message from the second node The method according to claim 17 or 18, further including the above. **Claim 20** Before the step of sending the first message to the second node, the method includes Selecting a first key agreement algorithm based on the key agreement algorithm capability of the second node Sending instruction information of the first key agreement algorithm to the second node, wherein the instruction information of the first key agreement algorithm indicates a two-base password exponential function key exchange (TBPEKE) algorithm The method according to any one of claims 16 to 19, further including the above. **Claim 21** The at least one common parameter includes a first common parameter and a second common parameter The first common parameter and the second common parameter are related to the first elliptic curve, the first elliptic curve is an elliptic curve corresponding to the first key agreement algorithm, and the first key agreement algorithm is the TBPEKE algorithm The method according to any one of claims 16 to 20. **Claim 22** Sending a first calculated value to the second node, wherein the first calculated value is related to a first random number and the first common parameter, the first random number is determined by the first node, and the first common parameter is predefined Receiving a second calculated value from the second node, wherein the second calculated value is related to a second random number and the first common parameter Determining the second common parameter based on the second random number and the first calculated value The method according to claim 21, further including the above. **Claim 23** The method according to any one of claims 20 to 22, wherein the first key agreement algorithm is a key agreement algorithm supported by the first node, and the first key agreement algorithm has the highest priority among the key agreement algorithms supported by the second node.
24. The intermediate parameter satisfies the following equation: b = U + s * V, where: b is the intermediate parameter, U and V are the at least one common parameter, s is the security parameter, * is an elliptic curve point multiplication operation, and + is an elliptic curve point addition operation. The method according to any one of claims 20 to 23.
25. The method according to any one of claims 20 to 24, wherein U is a first base point, V is a second base point, U and V belong to a cyclic group with order p, and p is a prime number.
26. The first key agreement parameter KEt satisfies the following equation: KEt = SKt * b The first key satisfies the following equation: First key = SKg * KEt The second key agreement parameter KEg satisfies the following equation: KEg = SKg * b The second key satisfies the following equation: Second key = SKt * KEg, where SKt is the first secret key and SKg is the second secret key. The method according to claim 24 or 25.
27. The method according to any one of claims 20 to 26, wherein the value range of the first secret key is [1, p), the value range of the second secret key is [1, p), and p is the order of the elliptic curve used by the TBPEKE algorithm.
28. Before the step of transmitting the first message to the second node, the method further includes: receiving, from the second node, the key agreement algorithm capability transmitted by the second node, wherein the key agreement algorithm capability of the second node represents the key agreement algorithm supported by the second node. The method according to any one of claims 16 to 27, further comprising the step.
29. The method according to claim 28, wherein the key agreement algorithms supported by the second node are sorted according to priority.
30. The method according to any one of claims 16 to 29, wherein the first message further includes a first freshness parameter, and the first authentication information is associated with the PSK, the second key, the second message, the first freshness parameter, and the key agreement algorithm capability of the second node.
31. The second message further includes second authentication information and a second freshness parameter, the second authentication information is associated with the PSK, the first key, the second freshness parameter, and the first message, and the method includes verifying the second authentication information based on the PSK, the second key, the second freshness parameter, and the first message; generating the first authentication information when verification of the integrity of the second authentication information and the second message is successful; The method according to claim 18, further comprising.
32. A receiving unit configured to receive a first message from a first node, the first message including a first key agreement parameter, the first key agreement parameter being associated with a first private key and an intermediate parameter, the intermediate parameter being associated with a security parameter and at least one common parameter, the security parameter being a first password or a pre-shared key PSK between the first node and a second node, the first password being an agreed access password between the first node and the second node, a receiving unit; A transmitting unit further configured to transmit a second message to the first node, the second message including a second key agreement parameter, the second key agreement parameter being associated with a second private key and the intermediate parameter, a transmitting unit; A processing unit configured to obtain a first key based on the first key agreement parameter and the second private key A communication device including.
33. The communication device according to claim 32, wherein the first key is used to obtain one or more of an encryption key, an integrity key, or an identification information authentication key.
34. The receiving unit is further configured to receive a third message from the first node, the third message including first authentication information, the first authentication information being associated with a second key, the second key being associated with the second key agreement parameter and the first secret key, The processing unit is further configured to verify the first authentication information based on the first key, The communication device according to claim 32.
35. The receiving unit is, Of a first key agreement algorithm, receives instruction information transmitted by the first node, and the instruction information of the first key agreement algorithm indicates a two-base password exponential function key exchange TBPEKE algorithm, The communication device according to any one of claims 32 to 34, further configured as such.
36. A transmitting unit configured to transmit a first message to a second node, the first message including a first key agreement parameter, the first key agreement parameter being associated with a first secret key and an intermediate parameter, the intermediate parameter being associated with a security parameter and at least one common parameter, the security parameter being a first password or a pre-shared key PSK between the first node and the second node, the first password being an agreed access password between the first node and the second node, a transmitting unit; A receiving unit further configured to receive a second message from the second node, the second message including a second key agreement parameter, the second key agreement parameter being associated with a second secret key and the intermediate parameter, a receiving unit; A processing unit configured to obtain a second key based on the second key agreement parameter and the first secret key A communication device including.
37. The communication device according to claim 36, wherein the second key is used to obtain one or more of an encryption key, an integrity key, or an identification information authentication key.
38. The transmitting unit is further configured to transmit a third message to the first node, the third message including first authentication information, the first authentication information being associated with the second key. The communication device according to claim 36.
39. The communication device further includes the processing unit, the processing unit is configured to select a first key agreement algorithm based on the key agreement algorithm capability of the second node, the transmission unit is further configured to transmit instruction information of the first key agreement algorithm to the second node, and the instruction information of the first key agreement algorithm indicates a two-base password exponential function key exchange (TBPEKE) algorithm, The communication device according to any one of claims 36 to 38.
40. A chip system, comprising at least one processor and a communication interface, the communication interface being configured to transmit and / or receive data, and the at least one processor being configured to call a computer program stored in at least one memory to enable the chip system to implement the method according to any one of claims 1 to 15 or the method according to any one of claims 16 to 31. A chip system.
41. A computer-readable storage medium, the computer-readable storage medium storing a computer program, and when the computer program runs on a computer, the computer is enabled to perform the method according to any one of claims 1 to 15 or the method according to any one of claims 16 to 31. A computer-readable storage medium.
42. A second node including the communication device according to any one of claims 32 to 35, a first node including the communication device according to any one of claims 36 to 39, A communication system comprising:
43. A vehicle including a first node and / or a second node, the second node includes the communication device according to any one of claims 32 to 35 or the second node is a node that implements the method according to any one of claims 1 to 15, the first node includes the communication device according to any one of claims 36 to 39 or the first node is a node that implements the method according to any one of claims 16 to 31, A vehicle.
44. A communication system including a second node that implements the method according to any one of claims 1 to 15, and a first node that implements the method according to any one of claims 16 to 31.
Citation Information
Patent Citations
End-to-end authentication and key negotiation method, device and system
CN109905348A
Authentication method and system in mobile-network-based end-to-end communication, and authentication center
JP2012253817A
System and method for configuring a wireless device for wireless network access
US20190261168A1