Key authentication method, device, electronic device, and storage medium
The key authentication method dynamically binds pre-shared keys to user information, enhancing efficiency and security in terminal devices lacking graphic interfaces by using a unified authentication method with an audit mechanism.
Patent Information
- Application Number
- JP2025541076
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-08-30
- Filing Date
- 2024-05-22
- Publication Date
- 2026-01-16
AI Technical Summary
Terminal devices without graphic interfaces, such as cameras and printers, cannot efficiently utilize existing user identity authentication methods like 802.1x protocol authentication or Web authentication, necessitating a more efficient pre-shared key (PSK) authentication method to securely access corporate networks.
A key authentication method that determines user information based on a key authentication request, registers a pre-shared key when needed, and binds it to user information, allowing dynamic binding and efficient authentication without manual pre-registration, while incorporating an audit mechanism to ensure security.
This method simplifies the registration process, improves authentication efficiency, and enhances security by allowing one pre-shared key to be used for multiple devices and preventing unauthorized access, thus optimizing user identity verification.
Smart Images

Figure 2026501845000001_ABST
Abstract
Description
[Technical Field]
[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims priority to a Chinese patent application bearing application number 202311108714.X and entitled "Key authentication method, device and electronic device" filed with the State Intellectual Property Office of the People's Republic of China on August 30, 2023, the entire contents of which are incorporated herein by reference.
[0002] The present application relates to the technical field of network security, and in particular to a key authentication method, device, electronic device, and storage medium. [Background technology]
[0003] Before a terminal device can access the Internet, it is generally necessary to authenticate the user's identity in order to restrict unauthorized users from accessing the network and ensure the security of network operation.
[0004] Currently, there are two user identity authentication methods: 802.1x protocol authentication and Web authentication. However, some terminal devices equipped with wireless network cards, such as cameras, game consoles, smart TVs, medical tablets, and printers, may not support either 802.1x protocol authentication or Web authentication because they do not have a graphic interface. Therefore, a pre-shared key (PSK) authentication method can be adopted to enable these terminal devices to securely access the corporate intranet according to unified authentication rules.
[0005] PSK authentication is a security authentication method based on wireless networks. When using PSK to authenticate user identity, the device administrator must create a unique PSK for each user and assign the PSK to the user. When a user accesses the wireless network, the user's identity is authenticated based on the PSK entered by the user. Summary of the Invention [Problem to be solved by the invention]
[0006] The exemplary embodiments of the present application provide a key authentication method, device, electronic device and storage medium, and the specific technical solutions are as follows: [Means for solving the problem]
[0007] According to a first aspect, the present application provides a key authentication method, the method comprising: determining user information based on a key authentication request sent from a user side, the key authentication request including the user information and an initial key; determining whether the initial key matches a first key, the first key being used to determine whether the user side needs to register a pre-shared key; When the initial key matches the first key, registering a first pre-shared key for the user side and binding the first pre-shared key to the user information.
[0008] Based on the above method, users can register based on a key request, which avoids the need to manually bind a pre-shared key to user information in advance when users register, and simplifies the registration flow.
[0009] In one possible implementation, before determining whether the initial key matches a first key, the method includes: determining whether a pre-shared key is bound to the user information; When no pre-shared key is bound to the user information, determining whether the initial key matches a first key.
[0010] According to the above embodiment, a user can register based on a key request, and when a new user obtains permission to access the Internet in advance, the service authentication side can avoid repeatedly switching between registration and authentication signals, and the functions of pre-shared key registration and authentication based on the same signal can be realized.
[0011] In one possible implementation, when a pre-shared key is bound to the user information, determining whether the initial key matches a second pre-shared key bound to the user information; and When the initial key matches the second pre-shared key bound to the user information, an authentication message related to the second pre-shared key is sent to the user side.
[0012] In one possible implementation, the authentication information associated with the second pre-shared key includes at least one of authorized virtual local area network information and quality of service information.
[0013] In one possible implementation, when the initial key does not match the second pre-shared key bound to the user information, a feedback message is sent to the user side indicating that authentication of the initial key is an error.
[0014] In one possible implementation, the feedback message includes an error type that results in an error in authenticating the initial key.
[0015] In this embodiment, the user side can adjust the initial key based on the error type in the feedback message and perform authentication again.
[0016] In one possible implementation, determining whether the initial key matches a second pre-shared key bound to the user information includes: determining encryption parameter values based on the key authentication request; encrypting the initial key in accordance with the encryption parameter value to obtain a first encryption key; encrypting the second pre-shared key in accordance with the encryption parameter value to obtain a second encryption key; determining that the initial key matches the second pre-shared key when the first encryption key matches the second encryption key.
[0017] In one possible implementation, when the initial key does not match the first key, the method comprises: determining whether the initial key matches the second key, the second key being a pre-shared key in a set of pre-shared keys; When the initial key matches the second key, binding the second key to the user information and sending an authentication message related to the second key to the user side is further included.
[0018] In this embodiment, by polling and comparing the initial key with each second key, dynamic binding of the pre-shared key to the current user information can be realized, i.e., one code can be used for many devices, and the efficiency of authenticating the user identity can be improved.
[0019] In one possible implementation, determining whether the initial key matches the second key comprises: determining encryption parameter values based on the key authentication request; encrypting the initial key in accordance with the encryption parameter value to obtain a third encryption key; determining the second key from a set of established pre-shared keys; encrypting the second key in accordance with the encryption parameter value to obtain a fourth encryption key; determining whether the third encryption key matches the fourth encryption key; When the third encryption key matches the fourth encryption key, binding the second key to the user information and sending the authentication message related to the second key to the user side is included.
[0020] In one possible implementation, when the third encryption key does not match the fourth encryption key, the next pre-shared key in the pre-shared key set to be selected is chosen as the second key.
[0021] In one possible implementation, when the initial key does not match the first key, a second feedback message indicating that the initial key authentication failed is sent to the user side.
[0022] In one possible implementation, the step of registering a first pre-shared key for the user side and binding the first pre-shared key to the user information includes: determining registration information sent by the user side; registering the first pre-shared key for the user side when determining that the registration information satisfies a preset registration rule; The method further includes transmitting the first pre-shared key to the user side and binding the first pre-shared key to the user information.
[0023] In this embodiment, by setting up a review mechanism for the first pre-shared key registration, it is possible to prevent users who do not comply with the pre-shared key registration requirements from registering a pre-shared key, thereby increasing the security of pre-shared key registration for users.
[0024] In one possible implementation, when it is determined that the registration information does not satisfy the registration rules, a manual assessment is prompted.
[0025] In one possible implementation, the registering of the first pre-shared key for the user side includes: Sending a received message to the user side, the received message including at least one of information of a registered character, a name of the registered character, a jump address, and a public key; receiving registration information sent from the user side, and determining the first pre-shared key based on the registration information and a set random generation algorithm.
[0026] In one possible implementation, after registering a first pre-shared key for the user side, an offline request is sent to the user side, and the offline request is used to request the user side to disconnect the registration connection.
[0027] According to a second aspect, the present application provides a key authentication device, the device comprising: a key query module for determining user information in a key authentication request sent from a user side, the key authentication request including the user information and an initial key; a key authentication module for determining whether an initial key sent from the user side matches a key in a service authentication side key set, the service authentication side key set including a first key, the first key being used by the key authentication module to determine whether the user side needs to register a pre-shared key; When the initial key matches the first key, a first pre-shared key is registered for the user side, and the first pre-shared key is bound to the user information.
[0028] In one possible implementation, the key authentication module further comprises: determining whether a pre-shared key is bound to the user information; When no pre-shared key is bound to the user information, the initial key is used to determine whether it matches the first key.
[0029] In one possible implementation, the key authentication module further comprises: When the initial key does not match the first key, determining whether the initial key matches the second key, the second key being a pre-shared key in a set of pre-shared keys; When the initial key matches the second key, binding the second key with the user information and sending an authentication message related to the second key to the user side; When the initial key does not match the second key, a first feedback message indicating that the initial key authentication has failed is sent to the user side.
[0030] In one possible implementation, the key authentication module specifically: determining registration information sent by the user side; determining whether the registration information satisfies a predetermined registration rule; When it is determined that the registration information satisfies the registration rule, it is used to register the first pre-shared key for the user side, send the first pre-shared key to the user side, and bind the first pre-shared key to the user information.
[0031] According to a third aspect, the present application provides an electronic device, the device comprising: a memory for storing a computer program; and a processor for implementing the steps of the key authentication method when executing a computer program stored on the memory.
[0032] According to a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored therein, the computer program implementing the steps of the key authentication method when executed by a processor.
[0033] According to a fifth aspect, the present application provides a computer program product, the computer program product including a computer program that, when executed by a processor, implements the key authentication method described above. [Effects of the Invention]
[0034] Regarding each of the second to fifth aspects and the technical effects that can be achieved by each aspect, please refer to the description of the technical effects that can be achieved by the first aspect or each possible solution in the first aspect, and the description will be omitted here. [Brief explanation of the drawings]
[0035] In order to more clearly explain the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings necessary for the description of the embodiments or the prior art. It is obvious that the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain drawings of other embodiments based on these drawings without any creative effort. The drawings herein are incorporated into the specification and constitute a part of this specification, show embodiments suitable for the present application, and are used together with the specification to interpret the principles of the present application. [Figure 1] 1 is a flowchart of a key authentication method according to an embodiment of the present application. [Figure 2] FIG. 1 is a schematic diagram of a key authentication system architecture according to an embodiment of the present application. [Figure 3] 1 is a flowchart of initial key authentication according to one embodiment of the present application. [Figure 4] 1 is a flowchart of a first pre-shared key registration examination according to one embodiment of the present application. [Figure 5] 1 is a flowchart of a key authentication method according to an embodiment of the present application. [Figure 6] 1 is a structural schematic diagram of a key authentication device according to an embodiment of the present application; [Figure 7] 1 is a structural schematic diagram of an electronic device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION
[0036] In order to clarify the objectives, technical solutions, and advantages of this application, the following describes this application in more detail in conjunction with the drawings. Specific operation methods in method embodiments may also be used in device or system embodiments. It should be noted that the term "plurality" in this application means "at least two." "And / or" describes a relationship between related objects and indicates that three relationships may exist. For example, A and / or B may represent three cases: A alone, a combination of A and B, and B alone. A being connected to B may represent two cases: A and B being directly connected, or A and B being connected via C. Furthermore, in this application, terms such as "first," "second," etc., are used solely for the purpose of distinguishing between descriptions and should not be understood as indicating or implying relative importance or order.
[0037] Hereinafter, embodiments of the present application will be described in detail with reference to the drawings.
[0038] Before a terminal device can access the Internet, it is generally necessary to authenticate the user's identity in order to restrict unauthorized users from accessing the network and ensure the security of network operation.
[0039] Currently, there are two user identity authentication methods: 802.1x protocol authentication and Web authentication. However, some terminal devices equipped with wireless network cards, such as cameras, game consoles, smart TVs, medical tablets, and printers, may not support either 802.1x protocol authentication or Web authentication because they do not have a graphic interface. Therefore, a pre-shared key authentication method can be adopted to enable these terminal devices to securely access the corporate intranet according to unified authentication rules.
[0040] PSK authentication is a security authentication method based on wireless networks. When using PSK to authenticate user identity, the device administrator must create a unique PSK for each user and assign the PSK to the user. When a user accesses the wireless network, the user's identity is authenticated based on the PSK entered by the user.
[0041] However, before authenticating a user's identity using the PSK authentication method, the device administrator must collect the media access control address (MAC address) information of each terminal device, register the PSK information of the terminal device operated by the user, bind the MAC address information to the PSK information, and send the binding result to the terminal device.
[0042] When authenticating the identities of multiple users using the PSK authentication method, each user must input a unique PSK into the terminal device to which the PSK information is bound. This limits the use of the PSK, makes it more difficult for a device administrator to maintain the PSK configuration information for multiple terminal devices, and reduces the efficiency of authenticating user identities.
[0043] In order to improve the efficiency of authenticating user identity, an exemplary embodiment of the present application provides a key authentication method, which specifically includes: first determining user information in a key authentication request sent by a user side, determining whether a pre-shared key is bound to the user information, and when determining that a pre-shared key is not bound to the user information, determining whether the initial key sent by the user side matches the first key, and if yes, registering a first pre-shared key for the user side and binding the first pre-shared key to the user information.
[0044] According to the method of the exemplary embodiment of the present application, the service authentication side can determine whether a pre-shared key is bound to the current user side based on the user information of the user side, and then decide to register a first pre-shared key corresponding to the user information for the user side, or directly authenticate the pre-shared key. In the present application, the pre-shared key registration and authentication are based on the same signal, which can avoid repeated switching between the registration signal and the authentication signal, and improve the efficiency of authenticating the user identity.
[0045] Referring to FIG. 1, it is a flowchart of a key authentication method according to an embodiment of the present application, which may include the following steps:
[0046] S1: Determine user information in a key authentication request sent from the user side, and determine whether a pre-shared key is bound to the user information.
[0047] The method according to the embodiment of the present application may be used in the system architecture shown in Figure 2, which includes a service authentication side, a terminal device, a user side, and an access device, and the method according to the present application can run on the service authentication side.
[0048] Below is a brief introduction to the above devices and their respective functions.
[0049] The service authentication side may be an authentication server that performs network authentication for a user side or a terminal device, and the authentication server is connected to the user side and responds to an authentication service request sent from the user side. The service authentication side may be a network access server, an access point (abbreviated as AP in English), or an Ethernet switch, and the present application is not specifically limited thereto.
[0050] The terminal device may be any type of terminal equipped with a wireless network card, such as a camera, a game console, a smart TV, a medical monitor, a medical tablet, a printer, or any other type of Internet of Things device, and the present application does not specifically limit the type and number of terminal devices.
[0051] The user side (client side) can run on a terminal device and provide local services to the user. After receiving the initial key entered by the user, it sends an authentication service request to the service authentication side to request a network service.
[0052] The access device is used to access network resources from a distance and includes an access point, a router, a multiplexer, a modem, etc., and is used to forward an authentication service request sent from the user side to the service authenticator.
[0053] In an embodiment of the present application, as shown in FIG. 3 , a user first determines a wireless network to connect to based on a service set identifier (SSID) signal (i.e., the name of the wireless signal transmitted from the access device). The subsequent pre-shared key registration and authentication processes of the present application are both performed based on the SSID signal. After the user determines a wireless network, they can connect to the wireless network, including a network access point or a WiFi hotspot. The user inputs an initial key in the authentication login interface on the user side, which includes all pre-shared keys registered by the user side, and application keys or non-application keys for pre-shared key registration on the user side. After the user inputs the initial key, the user side can automatically send a key authentication request to the service authentication side. To verify the identity of the user side, the service authentication side must first establish a communication connection between the user side and the access device before receiving the key authentication request sent from the user side, and then forward the key authentication request to the service authentication side via the access device. This application adopts a four-step handshake method to establish a communication connection between the user side and the access device, and the four-step handshake process is specifically as follows:
[0054] (1) The user initiates a request for encrypted communication to the access device.
[0055] (2) When the access device receives the encrypted communication request, it sends a feedback message to the user side.
[0056] (3) Upon receiving the feedback message sent from the access device, the user side verifies the certificate of the access device and determines whether to establish a communication connection with the access device.
[0057] (4) When the access device receives the random number sent from the user side, it calculates and generates a session key and sends key information to the user side, where the key information includes the encryption method (encryption rule), encryption field, random number, etc.
[0058] After establishing a communication connection with the user side, the access device can receive a key authentication request sent by the user side, and forward the key authentication request and key information to the service authentication side, so that the service authentication side can authenticate the user identity. The specific authentication process is as follows:
[0059] The service authenticator determines user information from the key authentication request. The user information may be a unique identifier that identifies the user, such as a media access control address (MAC address). The service authenticator determines whether a pre-shared key is bound to the current terminal device based on the user information, such as terminal device information.
[0060] The service authentication side can determine whether a pre-shared key is bound to the user information based on the user information. In an exemplary embodiment of the present application, the service authentication side can determine whether a pre-shared key is bound to the user information by establishing a mapping relationship between the user information and the pre-shared key. The same pre-shared key may be bound to different user information. In this case, one pre-shared key can support the use of multiple user sides, thereby increasing the number of user sides. The present application does not specifically limit the number of user information that can be bound to one pre-shared key.
[0061] If the service authentication side determines that the pre-shared key is bound to the user information, it determines that there is no need to register the pre-shared key of the current user side, and directly authenticates the pre-shared key of the current user side. The service authentication side determines whether the initial key matches the second pre-shared key bound to the user information.
[0062] In the embodiment of the present application, the steps of authenticating a pre-shared key to a user to whom the pre-shared key is bound are as follows:
[0063] The service authentication side receives the key authentication request and analyzes the key information in the key authentication request to analyze encryption parameter values such as the encryption method (encryption rule), encryption field, and random number.The service authentication side then uses the received initial key transmitted from the user side as a target pre-shared key and performs encryption on the target pre-shared key according to the encryption parameter values to obtain a first encryption key.In the embodiment of the present application, the initial key is the pre-shared key to be authenticated.
[0064] Based on the user information, the service authentication side determines a second pre-shared key in the set pre-shared key set that matches the user information, and each pre-shared key in the pre-shared key set has corresponding user information recorded therein. For example, pre-shared key 1 corresponds to user information 1, pre-shared key 2 corresponds to user information 2, and so on. The explanation is omitted here.
[0065] After determining the second pre-shared key that matches the user information, the second pre-shared key may be encrypted according to the same encryption parameter values as the target pre-shared key, and after obtaining the second encryption key, it is determined whether the first encryption key matches the second encryption key. Whether the first encryption key matches the second encryption key may be determined according to the first numerical value of the first encryption key and the second numerical value of the second encryption key, and if the first numerical value is the same as the second numerical value, it is determined that the first encryption key matches the second encryption key; otherwise, it is determined that the first encryption key does not match the second encryption key.
[0066] When the service authenticator determines that the first encryption key matches the second encryption key, it may send an authentication message related to the second pre-shared key to the access device. When the access device receives the authentication message related to the second pre-shared key, it forwards the authentication message related to the second pre-shared key to the user side. This authentication message may be an Accept message, and the Accept message includes authorization attributes such as an allowed Virtual Local Area Network (VLAN), Quality of Service (QOS), etc.
[0067] When the service authentication side determines that the first encryption key and the second encryption key fail to match, it may send a feedback message indicating that the authentication of the target pre-shared key is an error to the access device. When the access device receives the feedback information indicating that the authentication of the target pre-shared key is an error, it forwards the feedback message indicating that the authentication of the target pre-shared key is an error to the user side. This feedback message may be a Reject message. The user side can determine the error type of the key authentication error based on the Reject message, for example, the error type is an error in the entered initial key, and the user side re-enters the initial key based on the error type and re-authenticates the pre-shared key.
[0068] According to the above method, the service authentication side can directly authenticate the pre-shared key of the user side to which the pre-shared key is bound, thereby improving the efficiency of user identity authentication.
[0069] S2, when it is determined that the pre-shared key is not bound to the user information, it determines whether the initial key sent by the user side matches the first key.
[0070] In an exemplary embodiment of the present application, when the service authentication side determines that no pre-shared key is bound to the user information, it determines based on the received initial key whether the initial key matches the first key, where the first key is an application key for a pre-shared key set by the service authentication side. The service authentication side can determine based on the first key whether the current user side needs to register a pre-shared key. In a practical usage scenario, for example, in a hotel scenario, the first key may be a public key provided in a guest's room key. The application key may be a string of letters and numbers, such as x123456x. The present application does not specifically limit the character combination method of the application key and the number of application keys set.
[0071] The steps taken by the service authenticator to determine whether the initial key matches the first key are as follows:
[0072] In the key authentication request, encryption parameter values such as the encryption method (encryption rule), encryption field, and random number are analyzed.
[0073] The initial key is encrypted according to the encryption parameter value to obtain a first encrypted value, and one first key is selected from the first key set to determine whether the first key is equal to the first encrypted value. If yes, it is determined that the current user needs to register a pre-shared key; if not, the next first key is selected from the first key set, and the above steps are repeated until each first key in the first key set has been polled.
[0074] If the first key set contains one first key that is equal to the first encrypted value, i.e., the initial key matches the first key, a first pre-shared key is registered for the user and the first pre-shared key is bound to the user information. If the first key set contains no first key that is equal to the first encrypted value, i.e., the initial key fails to match the first key, a second key may be matched or a second feedback message indicating that the initial key authentication failed may be sent to the user.
[0075] The above method allows users who have a need to register a pre-shared key to register a pre-shared key, thereby improving the efficiency of authenticating user identity.
[0076] S3: Register a first pre-shared key for the user side and bind the first pre-shared key to the user information.
[0077] In the embodiment of the present application, when the service authentication side determines that there is a first key in the first key set that matches the first encrypted value, it can register a first pre-shared key for the current user side, and the specific steps of registering the first pre-shared key are as follows:
[0078] The service authentication side returns an Accept message to the access device, and the Accept message includes authorization attributes such as a registered character, a name of the registered character, a jump address, and a public key, and the public key may be the same as the initial key input by the user side.
[0079] The access device initiates redirection to the terminal based on authorization attributes such as the registered character, the name of the registered character, and the public key in the received Accept message, and causes the task to jump to the configured portal (Portal in English) registration page. The user inputs registration information on the Portal registration page, and the registration information may include information such as the user's name, email address, and mobile phone number, and the present application is not specifically limited thereto.
[0080] The service authentication side generates a first pre-shared key for the user based on the registration information entered by the user and the set random generation algorithm. The present application does not specifically limit the number of first pre-shared keys.
[0081] In order to improve the security of the first pre-shared key registration, the embodiment of the present application adds an audit mechanism for the first pre-shared key registration when registering the first pre-shared key for the user side. For the audit flow of the first pre-shared key registration, please refer to Figure 4.
[0082] The service authentication side first determines the registration information sent by the user side, and then determines whether the registration information needs to be verified based on the key authentication manager's verification mode instruction. Specifically, the service authentication side can determine whether the registration information needs to be verified by setting an verification mode flag bit or an verification field, or by any other method, and the verification mode instruction is used to modify the values of the verification mode flag bit and the verification field. For example, assuming that the service authentication side has set the verification mode flag bit, a value of 1 indicates that the registration information needs to be verified, and a value of 0 indicates that the registration information does not need to be verified. The value of the verification mode flag bit may be other values, and the present application does not specifically limit the value of the verification mode flag bit when the registration information needs to be verified.
[0083] When the service authentication side determines that registration information needs to be verified, for example, if the key authentication manager's verification mode instruction determines that the verification mode flag bit should be set to 1, the service authentication side decides to turn on the registration verification mode. The service authentication side may first verify the identity of the user side, and specifically determine whether the registration information entered by the user side satisfies the set registration rules. For example, if the user suffix in the registration information is .DS and the set registration rules only allow users with suffixes .DS, .QF, and .AB to register a pre-shared key, the service authentication side registers a first pre-shared key for the current user side, sends the first pre-shared key to the user side, and binds the first pre-shared key to the user information.
[0084] If the registration information entered by the user side does not satisfy the preset registration rules or the user's suffix cannot be extracted based on the registration information, a manual assessment can be used to determine whether to register a pre-shared key for the current user side. If the registration information fails the manual assessment, a prompt message indicating that the pre-shared key registration has failed is sent to the user side. If the registration information passes the manual assessment, a first pre-shared key is registered for the current user side, the first pre-shared key is sent to the user side, and binding of the first pre-shared key with the user information is performed.
[0085] In the embodiment of the present application, when the service authentication side determines that it is not necessary to verify the registration information, for example, when the key authentication manager's verification mode instruction is to set the verification mode flag bit to 0, it determines that it is not necessary to verify the identity of the current user side. The service authentication side automatically registers a first pre-shared key for the user side, sends the first pre-shared key to the user side, and binds the first pre-shared key to the current user information.
[0086] After assessing the pre-shared key registration corresponding to the user side, the service authentication side may send an offline request for the current user side to the access device, requesting that the connection between the current user side and the service authentication side for pre-shared key registration be terminated, so as to release system resources to ensure the registration of the next user side's pre-shared key or improve the processing efficiency of the authentication.
[0087] The above method can prevent a user who does not meet the pre-shared key registration requirements from registering a pre-shared key, thereby improving the security of pre-shared key registration for users.
[0088] In an embodiment of the present application, if the initial key fails to match the first key, the service authentication side may transmit a second feedback message indicating the failure of the initial key authentication to the user side via the access device, and the user side may send the initial key to the service authentication side again based on the received second feedback message to request registration of the pre-shared key.
[0089] In the embodiment of the present application, if matching between the initial key and the first key fails, the service authentication side may match between the initial key and the second key.
[0090] The steps for matching the initial key with the second key are as follows:
[0091] The service authentication side determines whether the initial key matches the second key, where the second key is any one of the pre-shared keys required for the network authentication of the user side, i.e., the second key is any one of the pre-shared keys in the pre-shared key set by the service authentication side. When it determines that the initial key matches the second key, the service authentication side may bind the second key to the user information and send an authentication message related to the second key to the user side. When it determines that the matching between the initial key and the second key fails, the service authentication side may forward a first feedback message indicating that the initial key authentication failed to the user side via the access device.
[0092] The specific process of determining whether the initial key matches the second key is as follows:
[0093] The service authentication side first analyzes the encryption parameter value in the key authentication request sent from the user side, and then performs encryption on the initial key based on the encryption parameter value to obtain a third encryption key, which may be the same as the first encryption key, and the present application is not specifically limited thereto.
[0094] The service authentication side selects one pre-shared key to be selected from the set pre-shared key set, sets the selected pre-shared key as a second key, and encrypts the second key according to the encryption parameter value to obtain a fourth encryption key.
[0095] Determine whether the third encryption key matches the fourth encryption key, and if the third encryption key matches the fourth encryption key, bind the second key to the user information and send an authentication message related to the second key to the user side. The authentication message related to the second key may be an Accept message, and the description thereof will be omitted here.
[0096] If the third encryption key fails to match the fourth encryption key, the next pre-shared key to be selected in the pre-shared key set is selected, and this pre-shared key to be selected is designated as the second key. The second key is encrypted according to the encryption parameter value to obtain a fifth encryption key, and it is determined whether the fifth encryption key matches the third encryption key. If the fifth encryption key matches the third encryption key, the second key is bound to the user information, and an authentication message related to the second key is sent to the user. If the fifth encryption key fails to match the third encryption key, the next pre-shared key to be selected in the pre-shared key set is selected as the second key.
[0097] By polling and comparing the initial key with each pre-shared key to be selected in the pre-shared key set, it can be determined whether a second key matching the initial key exists. Since the pre-shared key is not bound to the current user information but the initial key may be obtained from another user who has registered a pre-shared key, when the service authentication side determines that the initial key matches the second key, it may bind the second key to the current user information, thereby realizing dynamic binding between the user side and the pre-shared key in the pre-shared key authentication process, that is, realizing the function of one pre-shared key being used by multiple users (one code for multiple devices).
[0098] If the pre-shared key set does not contain a second key matching the initial key, i.e., if the matching between the initial key and the second key fails, the service authentication side may send a first feedback message indicating failure of initial key authentication to the access device. The first feedback message is a feedback message for prompting the user that the input initial key does not match the application key used to register the pre-shared key or the registered pre-shared key of another user side. When the access device receives the first feedback message, it forwards the first feedback message to the user side. The first feedback message may be a Reject message. The user side may re-input the initial key based on the Reject message, or decide to submit a pre-shared key registration request to the service authentication side, or decide to obtain a registered pre-shared key from another user side, and use the registered pre-shared key to authenticate the pre-shared key and obtain permission to access the Internet from the service authentication side.
[0099] In one possible embodiment, when the service authentication side receives the initial key, it may first determine whether the initial key matches the second key. If the initial key matches the second key, it sets the initial key as a registered pre-shared key and performs pre-shared key authentication against the initial key. If the initial key fails to match the second key, it further determines whether the initial key matches the first key.
[0100] If the initial key matches the first key, register a first pre-shared key for the current user side. If the initial key fails to match the first key, send a feedback message indicating that the initial key authentication failed to the access device. The present application does not specifically limit the order of determining whether the initial key matches the first key or the second key.
[0101] In the embodiment of the present application, the pre-shared key authentication process, which first determines whether the initial key matches the second key and then determines whether the initial key matches the first key, refers to the above-mentioned step of first determining whether the initial key matches the first key and then determining whether the initial key matches the second key, and may be appropriately adjusted according to actual application needs, and the description thereof will be omitted here.
[0102] In one possible embodiment, the service authentication side and the access device are integrated and installed, for example, both the service authentication side and the access device are installed on an access point (AP), in which case the access and authentication functions can be realized simultaneously on the same device, which simplifies deployment. The integrated installation of the service authentication side and the access device is suitable for small-scale networks.
[0103] In one possible embodiment, the service authentication side and the access device are installed separately. One service authentication side is connected to multiple access devices and provides authentication services for the multiple access devices. In this case, PSK information is configured on the service authentication side without configuring PSK information on the access device, thereby reducing subsequent maintenance of PSK configuration information. Even when expanding an existing network, there is no need to configure PSK information on the access device, making network expansion easier. Furthermore, since the number of PSK keys that can be configured on an access device is limited, when multiple access devices are collectively authenticated by the service authentication side, the number of keys on the access device can be expanded, thereby increasing the number of access users. Installing the service authentication side and the access device separately is suitable for large-scale networks.
[0104] In summary, the method according to the exemplary embodiment of the present application realizes pre-shared key registration and authentication based on the same signal, thereby avoiding the service authentication side from repeatedly switching between registration and authentication signals when a new user is authorized to access the Internet in advance. Adding a first pre-shared key registration review mechanism prevents users who do not meet the pre-shared key registration requirements from registering a pre-shared key, thereby improving the security of pre-shared key registration for users. Matching the initial key with each pre-shared key to be selected in the pre-shared key set realizes a dynamic binding function between the pre-shared key and current user information in the pre-shared key authentication process, thereby increasing the number of users that can be applied to one pre-shared key and improving the efficiency of authenticating user identities.
[0105] Referring to Figure 5, Figure 5 is a flowchart of a key authentication method according to an embodiment of the present application. The key authentication method includes: S51, determining user information based on a key authentication request sent from a user side, where the key authentication request includes user information and an initial key.
[0106] S52, determine whether the initial key matches the first key, where the first key is used to determine whether the user side needs to register a pre-shared key.
[0107] S53: When the initial key matches the first key, register a first pre-shared key for the user side, and bind the first pre-shared key with the user information.
[0108] Based on the above method, a user can register based on an initial key, which avoids the need for the user to manually bind the pre-shared key to the user information in advance when registering, and simplifies the registration flow.
[0109] Based on the method in the above embodiment, the embodiment of the present application further provides a key authentication device. Figure 6 is a structural schematic diagram of the key authentication device in the embodiment of the present application, which device includes: a key query module 501 for determining user information in a key authentication request sent from a user side and determining whether a pre-shared key is bound to the user information; a key authentication module 502 for determining whether an initial key sent by the user side matches a first key when determining that a pre-shared key is not bound to the user information, the first key being used to determine whether the user side needs to register a pre-shared key; If the result is positive, a first pre-shared key is registered for the user side, and the first pre-shared key is bound to the user information.
[0110] In one possible implementation, the key authentication module 502 specifically: Determining whether the initial key matches the second key, wherein the second key is any one of pre-shared keys required for networking authentication on the user side; If the result is positive, binding the second key with the user information and sending an authentication message related to the second key to the user side; If not, a first feedback message is sent to the user side indicating that the initial key authentication has failed.
[0111] In one possible implementation, the key authentication module 502 specifically: parsing encryption parameter values in the key authentication request; encrypting the initial key in accordance with the encryption parameter value to obtain a third encryption key; selecting one pre-shared key to be selected from the set pre-shared key set, and setting the pre-shared key to be selected as the second key; encrypting the second key in accordance with the encryption parameter value to obtain a fourth encryption key; determining whether the third encryption key matches the fourth encryption key; If the result is positive, binding the second key with the user information and sending the authentication message associated with the second key to the user side; If not, it is used to select the next pre-shared key in the set of pre-shared keys to select.
[0112] In one possible implementation, if the initial key fails to match the first key, a second feedback message indicating that the initial key authentication failed is sent to the user side.
[0113] In one possible implementation, the key authentication module 502 specifically: determining registration information sent by the user side; determining whether to review the registration information; If the result is positive, determine whether the registration information satisfies a preset registration rule, and when it is determined that the registration information satisfies the registration rule, register the first pre-shared key for the user side, send the first pre-shared key to the user side, and bind the first pre-shared key to the user information; If not, the first pre-shared key is automatically registered for the user side, the first pre-shared key is sent to the user side, and the first pre-shared key is bound to the user information.
[0114] In one possible implementation, the key query module 501 further comprises: analyzing an encryption parameter value in the key authentication request and setting the initial key as a target pre-shared key; encrypting the target pre-shared key in accordance with the encryption parameter value to obtain a first encryption key; determining the second pre-shared key from a set of pre-shared keys; encrypting the second pre-shared key in accordance with the encryption parameter value to obtain a second encryption key; determining whether the first encryption key matches the second encryption key; If so, sending an authentication message related to the second pre-shared key to the user side; If not, authentication of the target pre-shared key is used and an error feedback message is sent to the user side.
[0115] Based on the same inventive idea, an embodiment of the present application further provides an electronic device, which can realize the function of the key authentication device described above. Referring to FIG. 7, the electronic device comprises: The system includes at least one processor 601 and a memory 602 connected to the at least one processor 601. In the embodiments of the present application, the specific connection medium between the processor 601 and the memory 602 is not limited, and in FIG. 7, the processor 601 and the memory 602 are connected via a bus 600. The bus 600 is represented by a bold line in FIG. 7, and the connection method between other components is merely a schematic illustration and is not limited thereto. The bus 600 may be divided into an address bus, a data bus, a control bus, etc., and is represented by only one bold line in FIG. 7 for convenience of illustration, but this does not indicate that there is only one bus or only one bus type. Alternatively, the processor 601 may be called a controller, and the name is not limited thereto.
[0116] In an embodiment of the present application, the memory 602 stores instructions executable by at least one processor 601, and the at least one processor 601 can perform the key authentication method described above by executing the instructions stored in the memory 602. The processor 601 can realize the functions of each module in the device shown in FIG.
[0117] Here, processor 601 is the control center of this device, and can connect each part of the entire control equipment using various interfaces and lines, and realizes each function and data processing of this device by running or executing instructions stored in memory 602 and accessing data stored in memory 602, thereby monitoring the device as a whole.
[0118] In one possible design, processor 601 may include one or more processing units, and processor 601 may integrate an application processor and a modem processor, where the application processor primarily processes the operating system, user interface, application programs, etc., and the modem processor primarily processes wireless communications. As can be appreciated, the modem processor may not be integrated into processor 601. In some embodiments, processor 601 and memory 602 may be implemented on the same chip, and in some embodiments, they may be implemented separately on separate chips.
[0119] The processor 601 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, a dedicated integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware assembly, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any general processor. The steps of the key authentication method disclosed in connection with the embodiments of the present application may be directly implemented as being executed by a hardware processor, or may be executed using a combination of hardware and software modules in the processor.
[0120] The memory 602 may be used as a non-volatile computer-readable storage medium to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 602 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (RAM), a static random access memory (SRAM), a programmable read-only memory (PROM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic memory, a magnetic disk, an optical disk, etc. The memory 602 may be any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that is accessible by a computer, but is not limited to this. The memory 602 in the embodiments of the present application may further be a circuit or any other device capable of implementing a memory function, and is used to store program instructions and / or data.
[0121] By design programming the processor 601, code corresponding to the key authentication method introduced in the above-mentioned embodiment can be embedded into the chip, so that when the chip is running, it can execute the steps of the key authentication method of the embodiment shown in Figure 1. How to design programming the processor 601 is a technique known to those skilled in the art, and will not be described here.
[0122] Based on the same inventive idea, an embodiment of the present application further provides a storage medium, which stores computer instructions, which, when run on a computer, cause the computer to perform the above-mentioned key authentication method.
[0123] In some possible embodiments, each aspect of the address generation method according to the present application may be implemented in the form of a program product including program code, which, when run on a device, is used to cause the control device to perform the steps in the key authentication method according to each exemplary embodiment of the present application described herein above.
[0124] As will be appreciated by those skilled in the art, the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. The present application may also take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, magnetic disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0125] The present application has been described with reference to flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to create a machine. The instructions, executed by the processor of the computer or other programmable data processing device, thereby create an apparatus for implementing the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0126] These computer program instructions may be stored in a computer-readable memory that can cause a computer or other programmable data processing device to operate in a particular manner, whereby the instructions stored in the computer-readable memory produce an article of manufacture that includes an instruction apparatus that implements the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0127] These computer program instructions may be installed on a computer or other programmable data processing device to perform a series of operational steps on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executing on the computer or other programmable device provide steps for implementing the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0128] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application intends to include these modifications and variations.
Claims
1. 1. A key authentication method, comprising: determining user information based on a key authentication request sent from a user side, the key authentication request including the user information and an initial key; determining whether the initial key matches a first key, the first key being used to determine whether the user needs to register a pre-shared key; When the initial key matches the first key, a first pre-shared key is registered for the user side, and the first pre-shared key is bound to the user information.
2. Before determining whether the initial key matches a first key, the method further comprises: determining whether a pre-shared key is bound to the user information; and determining whether the initial key matches the first key includes:
2. The method of claim 1, further comprising determining whether the initial key matches the first key when no pre-shared key is bound to the user information.
3. After determining whether a pre-shared key is bound to the user information, the method further comprises: When a pre-shared key is bound to the user information, determining whether the initial key matches a second pre-shared key bound to the user information; 3. The method of claim 2, further comprising: when the initial key matches the second pre-shared key bound to the user information, sending an authentication message related to the second pre-shared key to the user side.
4. 4. The method of claim 3, wherein the authentication information associated with the second pre-shared key includes at least one of authorized virtual local area network information and quality of service information.
5. After determining whether the initial key matches a second pre-shared key bound to the user information, the method further comprises:
4. The method of claim 3, further comprising: sending a feedback message to the user side indicating that authentication of the initial key is an error when the initial key does not match the second pre-shared key bound to the user information.
6. The method of claim 5 , wherein the feedback message includes an error type that results in an error in authenticating the initial key.
7. determining whether the initial key matches a second pre-shared key bound to the user information includes: determining encryption parameter values based on the key authentication request; encrypting the initial key in accordance with the encryption parameter value to obtain a first encryption key; encrypting the second pre-shared key in accordance with the encryption parameter value to obtain a second encryption key; and determining that the initial key matches the second pre-shared key when the first encryption key matches the second encryption key.
8. After determining whether the initial key matches a first key, the method further comprises: when the initial key does not match the first key, determining whether the initial key matches the second key, the second key being a pre-shared key in a pre-shared key set; 2. The method of claim 1, further comprising: when the initial key matches the second key, binding the second key to the user information and sending an authentication message related to the second key to the user side.
9. determining whether the initial key matches the second key includes: determining encryption parameter values based on the key authentication request; encrypting the initial key according to the encryption parameter value to obtain a third encryption key; deriving the second key from the set of pre-shared keys; encrypting the second key in accordance with the encryption parameter value to obtain a fourth encryption key; 9. The method of claim 8, further comprising: when the third encryption key matches the fourth encryption key, binding the second key to the user information and sending the authentication message associated with the second key to the user side.
10. determining whether the initial key matches the second key includes:
10. The method of claim 9, further comprising: when the third encryption key does not match the fourth encryption key, selecting a next pre-shared key in the set of pre-shared keys to be selected as the second key.
11. The method of claim 1 , further comprising: when the initial key does not match the first key, sending a second feedback message to the user side indicating that the initial key authentication failed.
12. The step of registering a first pre-shared key for the user side and binding the first pre-shared key to the user information includes: determining registration information sent by the user side; registering the first pre-shared key for the user side when determining that the registration information satisfies a preset registration rule; The method of claim 1 , further comprising: transmitting the first pre-shared key to the user side; and binding the first pre-shared key to the user information.
13. The step of registering a first pre-shared key for the user side includes: Sending a received message to the user side, the received message including at least one of information of a registered character, a name of the registered character, a jump address, and a public key; 2. The method of claim 1, further comprising: receiving registration information sent from the user side; and determining the first pre-shared key based on the registration information and a set random generation algorithm.
14. 2. The method of claim 1, further comprising: after registering a first pre-shared key for the user side, sending an offline request to the user side, wherein the offline request is used to request the user side to disconnect a registration connection.
15. A key authentication device, a key query module for determining user information in a key authentication request sent from a user side, the key authentication request including the user information and an initial key; a key authentication module for determining whether an initial key sent from the user side matches a key in a service authentication side key set, the service authentication side key set including a first key, the first key being used by the key authentication module to determine whether the user side needs to register a pre-shared key; When the initial key matches the first key, the key authentication device registers a first pre-shared key for the user side and binds the first pre-shared key to the user information.
16. The key authentication module further comprises: determining whether a pre-shared key is bound to the user information; 16. The apparatus of claim 15, wherein when no pre-shared key is bound to the user information, the initial key is used to determine whether it matches a first key.
17. The key authentication module further comprises: determining whether the initial key matches a second key in the service authentication side key set, the second key being a pre-shared key in a pre-shared key set; When the initial key matches the second key, binding the second key with the user information and sending an authentication message related to the second key to the user side; and when the initial key does not match the second key, sending a first feedback message to the user side indicating that the initial key authentication has failed.
18. The key authentication module specifically includes: determining registration information sent by the user side; determining whether the registration information satisfies a predetermined registration rule; 16. The device of claim 15, wherein when it determines that the registration information satisfies the registration rule, the device is used to register the first pre-shared key for the user side, send the first pre-shared key to the user side, and bind the first pre-shared key to the user information.
19. An electronic device, a memory for storing a computer program; and a processor for implementing the method steps of any one of claims 1 to 14 when executing a computer program stored on said memory.
20. A computer-readable storage medium having a computer program stored therein, the computer program implementing the method steps of any one of claims 1 to 14 when executed by a processor.
Citation Information
Patent Citations
Access authentication method and device
CN108769058A
Authentication method and device, equipment and storage medium
CN110198539A
Terminal authentication method and device, computer equipment and storage medium
CN112566119A
Dynamic PSK for Hotspots
US20130212656A1
Authentication system and authentication program
WO2023090117A1