Association control method and related device
By verifying the identity of a node and performing encrypted authentication in short-range communication technology, the risk of nodes being associated with unverified attackers is solved, and data security and service stability are improved.
Patent Information
- Application Number
- JP2023505821
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-07-30
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-07-30
AI Technical Summary
In existing short-range communication technologies, the risk of nodes being associated with unverified attackers is high, resulting in data security being threatened.
After receiving the associated request of the node, verify whether its identity is a trusted node. If it is a trusted node, an encrypted authentication request will be sent to verify the authentication information, and update the failed count when the verification fails. If the count exceeds the threshold, the node will be marked as distrust.
It effectively prevents nodes from establishing association with unverified attackers, improves node data security, and ensures the stable operation of services.
Smart Images

Figure 0007675799000002 
Figure 0007675799000003 
Figure 0007675799000004
Abstract
Description
[Technical field]
[0001] The present invention relates to the field of communication technology, and in particular to the field of short-range communication technology, such as cockpit domain communication. Specifically, an association control method and related device for communication security management are provided. [Background technology]
[0002] With the rapid development of information technology, mobile terminals, whether mobile phones, tablet terminals or other portable intelligent terminals, have become indispensable personal intelligent tools. While enjoying the convenience brought by information technology, people also face threats such as security vulnerabilities and privacy leakage. Intelligent vehicles are used as an example. As vehicular communication is widely applied, it also brings a series of security risks to vehicles. For example, in existing short-range communication technologies (such as wireless fidelity Wi-Fi, Bluetooth, etc.), hackers can invade the in-vehicle information system to obtain vehicle information or even remotely control the vehicle. This poses a very large threat to the privacy of users and the security of vehicles. Millions of vehicles around the world are affected. As another example, Denial of Service (DoS) is the most common and easily received attack behavior in the vehicle communication process. A denial of service attacker deliberately attacks flaws in network protocol implementations or directly uses offensive means that violently consume the resources of the attacked object (e.g., a vehicle's control center), so that the attacked object cannot provide normal services, stops responding, or even crashes. An authentication flood attack is a type of DoS attack. An attacker sends a large number of request frames to an associated node. When a node receives a large number of request frames and exceeds the processing capacity that the node can bear, the node will crash and will not be able to continue to provide normal services, which will affect the communication between another node and the node. Therefore, to guarantee the security of communication, node association control is very important.
[0003] In the prior art, nodes requesting association may be restricted using a whitelist or blacklist technique. Specifically, if the identifier of node A is in node B's whitelist, node B may receive an association request from node A and perform the association. Correspondingly, if the identifier of node C is in node B's blacklist, node B may not receive an association request from node C or may refuse to perform the association. Specifically, for example, in a Bluetooth communication process, a Bluetooth device establishes a whitelist, so that the Bluetooth device can establish an association with a specific Bluetooth device (i.e., a Bluetooth device listed in the whitelist). However, a whitelist or blacklist usually performs filtering using an identifier (such as a device address). An attacker may change the attacker's identifier to a trusted identifier, so that the node cannot identify an unauthenticated attacker. As a result, the node may establish an association with the attacker, threatening the data security of the node.
[0004] Therefore, how to prevent nodes from establishing associations with unauthorized attackers is a hot issue being researched by those skilled in the art. Summary of the Invention
[0005] Embodiments of this application disclose an association control method and related apparatus for preventing a node from establishing an association with an unauthorized attacker and protecting the data security of the node.
[0006] According to a first aspect, an embodiment of the present application provides an association control method, the method comprising: receiving a first association request from a second node; determining that the identity of the second node is trusted and sending a first authentication request to the second node, the first authentication request including first identity authentication information, the first identity authentication information being generated based on a shared key between the first node and the second node, the shared key being considered as a first secret value shared between the first node and the second node; receiving a first authentication response from the second node, the first authentication response including second identity authentication information; performing verification on a second identity credential based on the shared key; and if verification for the second identity credential fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of verification failures for the second node.
[0007] In this embodiment of the application, after the identity of the second node is determined to be trusted, the identity of the second node needs to be further verified based on a shared key shared between the first node and the second node. In this way, even if an attacker avoids the step of "determining that the identity is trusted" by modifying the identifier, the identity authentication performed by the first node against the attacker still cannot succeed because it is difficult to forge identity authentication information. Thus, the node is prevented from establishing an association with an unauthenticated attacker, and the data security of the node is improved.
[0008] Additionally, if the validation fails, the number of validation failures is updated. The number of validation failures may be used to later determine whether the identity of the second node is trusted, such that a node that has not been validated multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, the association requests of the node (e.g., sending authentication requests) may no longer be processed, preventing the node from stalling due to processing a large number of requests and ensuring the normal operation of the services provided by the node.
[0009] In a possible implementation of the first aspect, determining that the identity of the second node is trusted comprises: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method includes obtaining first acknowledgement indication information, the first acknowledgement indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0010] In the above method, nodes requesting association may be controlled based on a blacklist or whitelist, so that identity authentication does not need to be performed for untrusted second nodes. This can prevent outages due to processing a large number of requests and ensure the normal operation of the service. Additionally, since the node will not establish an association with a node that does not undergo identity authentication, the node is prevented from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0011] In another possible implementation of the first aspect, determining that the identity of the second node is trusted comprises: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method includes obtaining first acknowledgement indication information if the identifier of the second node is not on a first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgement indication information indicates that the identity of the second node is trusted.
[0012] In yet another possible implementation of the first aspect, the first authentication response further includes second integrity check data, the second integrity check data being used to perform a message integrity check on the first authentication response. The method further includes determining that a message integrity check on the first authentication response is successful.
[0013] It can be seen that after it is determined that the identity of the second node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the second node and ensures the stable operation of the service provided by the node.
[0014] In yet another possible implementation of the first aspect, prior to receiving the first association request from the second node, the method further comprises: The method further includes determining that the first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0015] In the above method, an association request from a second node may be received only when the associated node is below a preset first association threshold. The first association threshold may limit the support capacity of the service that may be provided by the node. When the first association threshold is exceeded, the node may no longer receive or process association requests, without affecting communication between the node and another node associated with the node, and ensuring stable operation of the service provided by the node.
[0016] In yet another possible implementation of the first aspect, a method includes: If the verification for the second identity authentication information is successful, sending a first association response to the second node, the first association response being used to indicate that the first node establishes an association with the second node.
[0017] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate that the first node will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and communication may be performed.
[0018] In yet another possible implementation of the first aspect, a method includes: The method further includes resetting a first association failure counter if the verification for the second identity credentials is successful.
[0019] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset to avoid affecting subsequent determinations of the identity of the second node and to ensure the stable operation of the services provided by the node.
[0020] In yet another possible implementation of the first aspect, if the verification of the second identity authentication information based on the shared key fails, after updating the first authentication failure counter, the method further comprises: The method further includes determining that a value of the first authentication failure counter is greater than or equal to a first threshold and adding an identifier of the second node to a first blacklist.
[0021] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker who frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the node from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0022] In yet another possible implementation of the first aspect, the validity period of the first blacklist is a predefined or preset first duration.
[0023] It is understood that the predefined or preset first duration in the first blacklist may be regarded as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0024] In yet another possible implementation of the first aspect, a method includes: The method further includes removing the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0025] The above implementation describes factors related to the lifetime of the first blacklist. The lifetime of the first blacklist may be related to the number of times the second node has been added to the first blacklist. A greater number of times the second node has been added to the first blacklist indicates a longer duration of the second node on the first blacklist. Furthermore, optionally, the second node may be permanently added to the first blacklist after the number of times the second node has been added to the first blacklist exceeds a threshold.
[0026] Additionally, the first blacklist validity period may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be considered as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here. In yet another possible implementation of the first aspect, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0027] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting node resources and affecting successful association with another node.
[0028] According to a second aspect, an embodiment of the present application further provides an association method, the method comprising: determining that the identity of the first node is trusted and sending a first association request to the first node; receiving a first authentication request from a first node, the first authentication request including first identity authentication information; performing verification on the first identity authentication information based on a shared key between the second node and the first node, the shared key being a secret value shared between the first node and the second node; If verification on the first identity credential is successful, sending a first authentication response to the first node, the first authentication response including the second identity credential, the second identity credential generated based on the shared key.
[0029] In this embodiment of the application, after the identity of the first node is determined to be trusted, a first association request is sent to the first node. Then, using the shared key, a verification is performed on the identity authentication information of the first node based on the first identity authentication information in the first authentication request. After the verification is successful, a second identity authentication information is sent to the first node. The second identity authentication information may be used by the first node to verify the identity of the second node. It can be seen that after the identity is determined to be trusted, the association can be performed only after the identity authentication of both parties is successful. Thus, it is difficult for an attacker to avoid the identity authentication performed by the attacker's second node by modifying the identity such as an identifier, which prevents the node from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0030] In a possible implementation of the second aspect, determining that the identity of the first node is trusted comprises: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or Obtaining second acknowledgement indication information, the second acknowledgement indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0031] In the above method, associated nodes may be controlled using a blacklist or whitelist, and nodes may be controlled not to send association requests to untrusted first nodes, which prevents nodes from establishing associations with unauthenticated attackers and improves data security for the nodes.
[0032] In another possible implementation of the second aspect, determining that the identity of the first node is trusted comprises: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or and obtaining second acknowledgement indication information if the identifier of the first node is not on a second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on a second whitelist, wherein the second acknowledgement indication information indicates that the identity of the second node is trusted.
[0033] In yet another possible implementation of the second aspect, the first authentication request further includes first integrity check data, and the first integrity check data is used to perform a message integrity check on the first authentication request.
[0034] The method is: The method further includes determining that a message integrity check on the first authentication request was successful.
[0035] It can be seen that after it is determined that the identity of the first node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the first node and ensures the stable operation of the service provided by the node.
[0036] In yet another possible implementation of the second aspect, prior to determining that the identity of the first node is trusted and sending the first association request to the first node, the method further comprises: The method further includes determining that the second association number is less than or equal to a preset second association threshold, the second association number indicating a number of currently associated nodes.
[0037] In the above method, the association request may be sent to the first node only when the associated node is below a preset second association threshold. The second threshold may limit the number of nodes that can be associated with the node. When the second association threshold is exceeded, the node cannot be associated with another node, which does not affect communication between the node and another node associated with the node and ensures stable operation of the service provided by the node.
[0038] In yet another possible implementation of the second aspect, a method includes: The method further includes receiving a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0039] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the second node will receive a first association response from the first node. The association response is used to indicate that the first node will establish an association with the second node. Furthermore, the first response message may inform the second node that the association is successful and subsequent communication may be performed.
[0040] In yet another possible implementation of the second aspect, a method includes: The method further includes resetting a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0041] It can be seen that if the identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset to avoid affecting subsequent determinations of the identity of the first node and to ensure the stable operation of the services provided by the node.
[0042] In yet another possible implementation of the second aspect, a method includes: The method further includes updating a second authentication failure counter if verification for the first identity credential fails, the second authentication failure counter indicating a number of verification failures for the first node.
[0043] It can be seen that if the verification fails for the identity credentials of the first node, the number of identity verification failures of the first node is updated, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the first node by modifying the identity such as an identifier, which prevents the node from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0044] In yet another possible implementation of the second aspect, if the verification for the first identity credential fails, after updating the second authentication failure counter, the method further comprises: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; and adding an identifier of the first node to a second blacklist.
[0045] If the number of verification failures of the first node exceeds a preset first threshold, it indicates that the first node has not been verified multiple times, and it is found that the first node may be an attacker who frequently sends authentication requests. Therefore, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the node from establishing an association with an unauthenticated attacker, and improves the data security of the node.
[0046] In yet another possible implementation of the second aspect, the validity period of the second blacklist is a predefined or preset second duration.
[0047] It is understood that the predefined or preset second duration in the second blacklist may be considered as the validity period of the blacklist, for example, the second duration may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0048] In yet another possible implementation of the second aspect, if the verification for the first identity credential fails, after updating the second authentication failure counter, the method further comprises: determining that a value of a second authentication failure counter is less than a second threshold; and sending a second association request to the first node.
[0049] It can be understood that in the process of verifying the identity authentication information, some parameters may be lost or transmitted erroneously in the transmission process, so that the verification for the identity authentication information may also fail. Therefore, if the number of verification failures of the first node does not exceed the preset second threshold, the association request may be resent to the first node to request to establish an association with the node. In this way, the robustness of the system is improved and the stable operation of the service provided by the node is ensured.
[0050] In yet another possible implementation of the second aspect, if the verification for the first identity credential fails, after updating the second authentication failure counter, the method further comprises: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and sending a second association request to the first node.
[0051] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0052] In yet another possible implementation of the second aspect, a method includes: and removing the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to at least one of the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0053] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Furthermore, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0054] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be regarded as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the second node may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here.
[0055] In yet another possible implementation of the second aspect, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0056] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0057] According to a third aspect, an embodiment of the present application further provides an association control method. a communication unit configured to receive a first association request from a second node; and a processing unit configured to determine that the identity of the second node is trusted and to send, using the communication unit, a first authentication request to the second node, the first authentication request including first identity authentication information, the first identity authentication information being generated based on a shared key between the first node and the second node.
[0058] The communication unit is further configured to receive a first authentication response from the second node, the first authentication response including the second identity authentication information.
[0059] The processing unit is further configured to perform verification on the second identity credential based on the shared key.
[0060] The processing unit is further configured to update a first authentication failure counter if the verification for the second identity credential fails, The first authentication failure counter indicates a number of verification failures for the second node.
[0061] In this embodiment of the application, the device verifies the identity of the second node based on a shared key shared with the second node after determining that the identity of the second node is trusted. In this way, even if an attacker avoids the step of determining that the identity is trusted by the device by modifying the identifier, the identity authentication performed by the device against the attacker still cannot succeed because it is difficult to forge identity authentication information. Thus, the device is prevented from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0062] Furthermore, if the verification fails, the device updates the number of verification failures. The number of verification failures may be used to later determine whether the identity of the second node is trusted, such that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, the device may no longer process association requests for the node (e.g., sending authentication requests), preventing the device from stalling due to processing a large number of requests and ensuring normal operation of the service.
[0063] In a possible implementation of the third aspect, the processing unit specifically comprises: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method is configured to obtain first acknowledgment indication information, the first acknowledgment indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0064] The device controls nodes that request association based on a blacklist or whitelist, so that identity authentication does not need to be performed for an untrusted second node. This can prevent outages due to processing a large number of requests and ensure normal operation of the service. Additionally, the device does not establish associations with nodes that do not undergo identity authentication, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0065] In another possible implementation of the third aspect, the processing unit 702 specifically: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is configured to obtain first acknowledgment indication information if the identifier of the second node is not on a first blacklist, a type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgment indication information indicates that the identity of the second node is trusted.
[0066] In yet another possible implementation of the third aspect, the first authentication response further includes second integrity check data, which is used to perform a message integrity check on the first authentication response.
[0067] The processing unit specifically includes: and determining that a message integrity check on the first authentication response was successful. It can be seen that after it is determined that the identity of the second node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the second node and ensures the stable operation of the service provided by the device.
[0068] In yet another possible implementation of the third aspect, the processing unit comprises: The node is further configured to determine that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0069] It can be seen that a first association threshold is preset in the device. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the device. When the first association threshold is exceeded, the device may no longer receive or process association requests, without affecting the communication between the device and another node associated with the device, and ensuring the stable operation of the service provided by the device.
[0070] In yet another possible implementation of the third aspect, the communication unit comprises: and further configured to send a first association response to the second node if the verification against the second identity authentication information is successful, the first association response being used to indicate that the first node establishes an association with the second node.
[0071] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and that communication may be performed.
[0072] In yet another possible implementation of the third aspect, the processing unit comprises: The method is further configured to reset the first authentication failure counter if the second identity credential is successfully verified.
[0073] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset, to avoid affecting subsequent determination of the identity of the second node and to ensure stable operation of the service provided by the device.
[0074] In yet another possible implementation of the third aspect, the processing unit comprises: The device is further configured to determine that a value of the first authentication failure counter is greater than or equal to a first threshold and to add an identifier of the second node to a first blacklist.
[0075] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker that frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0076] In yet another possible implementation of the third aspect, the validity period of the first blacklist is a predefined or preset first duration.
[0077] It is understood that the predefined or preset first duration in the first blacklist may be regarded as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0078] In yet another possible implementation of the third aspect, the processing unit comprises: The method is further configured to remove the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0079] The above implementation describes factors related to the lifetime of the first blacklist. The lifetime of the first blacklist may be related to the number of times the second node has been added to the first blacklist. A greater number of times the second node has been added to the first blacklist indicates a longer duration of the second node on the first blacklist. Furthermore, optionally, the second node may be permanently added to the first blacklist after the number of times the second node has been added to the first blacklist exceeds a threshold.
[0080] Additionally, the validity period of the first blacklist may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, sounder, etc., the second node may be considered as a low-risk device. If the second node belongs to a mobile phone, computer, etc., the second node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here. The number of device types is not specifically limited in this application and may be designed based on a specific scenario.
[0081] In yet another possible implementation of the third aspect, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0082] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting device resources and affecting successful association with another node.
[0083] According to a fourth aspect, an embodiment of the present application further provides an association device, comprising: and a processing unit configured to determine that an identity of a first node is trusted and to send, using a communication unit, a first association request to the first node.
[0084] The communication unit is further configured to receive a first authentication request from the first node, the first authentication request including the first identity authentication information.
[0085] The processing unit is further configured to perform verification on the first identity credential based on a shared key between the second node and the first node.
[0086] The communication unit is further configured to send a first authentication response to the first node if the verification on the first identity credential is successful, the first authentication response including the second identity credential, the second identity credential being generated based on the shared key.
[0087] In this embodiment of the application, after determining that the identity of the first node is trusted, the device sends a first association request to the first node. Then, using the shared key, a verification is performed on the identity authentication information of the first node based on the first identity authentication information in the first authentication request. After the verification is successful, a second identity authentication information is sent to the first node. The second identity authentication information may be used by the first node to verify the identity of the device. It can be seen that after the identity is determined to be trusted, the association can be performed only after the identity authentication of both parties is successful. Thus, it is difficult for an attacker to avoid the identity authentication performed by the attacker's second node by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0088] In a possible implementation of the fourth aspect, the processing unit specifically comprises: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or The device is further configured to obtain second acknowledgment indication information, the second acknowledgment indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0089] In the above method, associated nodes may be controlled using a blacklist or whitelist, and the device may be controlled not to send association requests to untrusted first nodes, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0090] In another possible implementation of the fourth aspect, the processing unit specifically comprises: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is further configured to obtain second acknowledgement indication information if the identifier of the first node is not on the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on the second whitelist, wherein the second acknowledgement indication information indicates that the identity of the second node is trusted.
[0091] In yet another possible implementation of the fourth aspect, the first authentication request further includes first integrity check data, and the first integrity check data is used to perform a message integrity check on the first authentication request.
[0092] The processing unit is The method is further configured to determine that a message integrity check on the first authentication request is successful.
[0093] It can be seen that after it is determined that the identity of the first node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the first node and ensures the stable operation of the service provided by the device.
[0094] In yet another possible implementation of the fourth aspect, the processing unit comprises: The node is further configured to determine that a second number of associations is less than or equal to a preset second association threshold, the second number of associations indicating a number of currently associated nodes.
[0095] It can be seen that a second association threshold is preset in the device. An association request may be sent to the first node only when the associated node is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that can be associated with the device. When the second association threshold is exceeded, the device cannot be associated with another node, which does not affect the communication between the device and another node associated with the device and ensures the stable operation of the service provided by the device.
[0096] In yet another possible implementation of the fourth aspect, the communication unit comprises: and further configured to receive a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0097] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the device will receive a first association response from the first node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may inform the device that the association is successful and subsequent communication may be performed.
[0098] In yet another possible implementation of the fourth aspect, the processing unit comprises: Further configured to reset a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0099] It can be seen that if identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset, to avoid affecting subsequent determination of the identity of the first node and to ensure stable operation of the service provided by the device.
[0100] In yet another possible implementation of the fourth aspect, the processing unit comprises: and further configured to update a second authentication failure counter if verification fails for the first identity credential, the second authentication failure counter indicating a number of verification failures for the first node.
[0101] If the verification for the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the attacker's first node by modifying the identity such as an identifier, preventing the device from establishing an association with an unauthorized attacker and improving data security of the device.
[0102] In yet another possible implementation of the fourth aspect, the processing unit comprises: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; The node is further configured to add an identifier of the first node to a second blacklist.
[0103] If the number of verification failures of the first node exceeds a preset first threshold, indicating that the first node has not been verified multiple times, it is found that the first node may be an attacker who frequently sends association requests. Thus, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0104] In yet another possible implementation of the fourth aspect, the validity period of the second blacklist is a predefined or preset second duration.
[0105] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0106] In yet another possible implementation of the fourth aspect, the processing unit is further configured to determine that a value of a second authentication failure counter is less than a second threshold.
[0107] The communication unit is further configured to send a second association request to the first node.
[0108] If the verification of the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the first node by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthorized attacker and improves data security of the node.
[0109] In yet another possible implementation of the fourth aspect, a processor is configured to: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and transmitting a second association request to the first node.
[0110] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0111] In yet another possible implementation of the fourth aspect, a processor is configured to: and further configured to remove the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to at least one of the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0112] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Furthermore, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0113] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be regarded as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the second node may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here.
[0114] In yet another possible implementation of the fourth aspect, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0115] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0116] According to a fifth aspect, an embodiment of the present application further provides a communication apparatus, the apparatus comprising at least one processor and a communication interface, the at least one processor invoking a computer program stored in at least one memory, such that the apparatus implements a method according to the first aspect or any one of the possible implementations of the first aspect.
[0117] In a possible implementation of the fifth aspect, at least one processor invokes a computer program stored in at least one memory; receiving a first association request from a second node via the communications interface; determining that the identity of the second node is trusted and sending a first authentication request to the second node via the communication interface, the first authentication request including first identity authentication information, the first identity authentication information being generated based on a shared key between the first node and the second node, the shared key being considered as a first secret value shared between the first node and the second node; receiving a first authentication response from the second node via the communication interface, the first authentication response including second identity authentication information; performing verification on a second identity credential based on the shared key; and configured to perform an operation of: if verification for the second identity credential fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of verification failures for the second node.
[0118] In this embodiment of the application, the device verifies the identity of the second node based on a shared key shared with the second node after determining that the identity of the second node is trusted. In this way, even if an attacker avoids the step of determining that the identity is trusted by the device by modifying the identifier, the identity authentication performed by the device against the attacker is still impossible because it is difficult to forge identity authentication information. Thus, the device is prevented from establishing an association with an unauthenticated attacker, improving the data security of the device.
[0119] Furthermore, if the verification fails, the device updates the number of verification failures. The number of verification failures may be used to later determine whether the identity of the second node is trusted, such that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, the device may no longer process association requests for the node (e.g., sending authentication requests), preventing the device from stalling due to processing a large number of requests and ensuring normal operation of the service.
[0120] In another possible implementation of the fifth aspect, the processor specifically: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method is configured to obtain first acknowledgment indication information, the first acknowledgment indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0121] The device controls nodes that request association based on a blacklist or whitelist, so that identity authentication does not need to be performed for an untrusted second node. This can prevent outages due to processing a large number of requests and ensure normal operation of the service. Additionally, the device does not establish associations with nodes that do not undergo identity authentication, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0122] In yet another possible implementation of the fifth aspect, the processor specifically: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is configured to obtain first acknowledgment indication information if the identifier of the second node is not on a first blacklist, a type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgment indication information indicates that the identity of the second node is trusted.
[0123] In yet another possible implementation of the fifth aspect, the first authentication response further includes second integrity check data, which is used to perform a message integrity check on the first authentication response.
[0124] The processor is further configured to determine that a message integrity check on the first authentication response is successful.
[0125] It can be seen that after it is determined that the identity of the second node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the second node and ensures the stable operation of the service provided by the device.
[0126] In yet another possible implementation of the fifth aspect, a processor is configured to: The node is further configured to determine that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0127] It can be seen that a first association threshold is preset in the device. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the node. When the first association threshold is exceeded, the device may no longer receive or process association requests, without affecting the communication between the device and another node associated with the device, and ensuring stable operation of the service provided by the device.
[0128] In yet another possible implementation of the fifth aspect, a processor is configured to: and if the verification against the second identity authentication information is successful, further configured to send a first association response to the second node via the communication interface, the first association response being used to indicate that the first node establishes an association with the second node.
[0129] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and that communication may be performed.
[0130] In yet another possible implementation of the fifth aspect, a processor is configured to: The method is further configured to reset the first authentication failure counter if the second identity credential is successfully verified.
[0131] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset, to avoid affecting subsequent determination of the identity of the second node and to ensure stable operation of the service provided by the device.
[0132] In yet another possible implementation of the fifth aspect, a processor is configured to: The device is further configured to determine that a value of the first authentication failure counter is greater than or equal to a first threshold and to add an identifier of the second node to a first blacklist.
[0133] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker that frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the device.
[0134] In yet another possible implementation of the fifth aspect, the validity period of the first blacklist is a predefined or preset first duration.
[0135] It is understood that the predefined or preset first duration in the first blacklist may be regarded as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0136] In yet another possible implementation of the fifth aspect, a processor is configured to: The method is further configured to remove the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0137] The above implementations account for factors related to the lifetime of the blacklist. The lifetime of the blacklist may be related to the number of times the second node has been added to the blacklist. A greater number of times the second node has been added to the blacklist indicates a longer duration of the second node on the blacklist. Additionally, optionally, the second node may be permanently added to the blacklist after the number of times the second node has been added to the blacklist exceeds a threshold.
[0138] Additionally, the blacklist validity period may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be regarded as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the device may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here.
[0139] In yet another possible implementation of the fifth aspect, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0140] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting device resources and affecting successful association with another node.
[0141] According to a sixth aspect, an embodiment of the present application further provides a communication apparatus, the apparatus comprising at least one processor and a communication interface, the at least one processor invoking a computer program stored in at least one memory, such that the apparatus implements a method according to the first aspect or any one of the possible implementations of the first aspect.
[0142] In a possible implementation of the sixth aspect, at least one processor invokes a computer program stored in at least one memory; determining that the identity of the first node is trusted and sending a first association request to the first node; receiving a first authentication request from a first node, the first authentication request including first identity authentication information; performing verification on the first identity authentication information based on a shared key between the second node and the first node, the shared key being a secret value shared between the first node and the second node; and configured to perform an operation of: sending a first authentication response to the first node if verification on the first identity credential is successful, the first authentication response including the second identity credential, the second identity credential generated based on the shared key.
[0143] In this embodiment of the application, after determining that the identity of the first node is trusted, the device sends a first association request to the first node. Then, using the shared key, a verification is performed on the identity authentication information of the first node based on the first identity authentication information in the first authentication request. After the verification is successful, a second identity authentication information is sent to the first node. The second identity authentication information may be used by the first node to verify the identity of the device. It can be seen that after the identity is determined to be trusted, the association can be performed only after both identity authentications are successful. Thus, it is difficult for an attacker to avoid the identity authentication performed by the attacker's device by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the device.
[0144] In another possible implementation of the sixth aspect, a processor is configured to: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or The device is further configured to obtain second acknowledgment indication information, the second acknowledgment indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0145] In the above method, associated nodes may be controlled using a blacklist or whitelist, and the device may be controlled not to send association requests to untrusted first nodes, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0146] In yet another possible implementation of the sixth aspect, a processor is configured to: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is further configured to obtain second acknowledgement indication information if the identifier of the first node is not on the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on the second whitelist, wherein the second acknowledgement indication information indicates that the identity of the second node is trusted.
[0147] In yet another possible implementation of the sixth aspect, the first authentication request further includes first integrity check data, and the first integrity check data is used to perform a message integrity check on the first authentication request.
[0148] The processor is further configured to determine that a message integrity check on the first authentication request is successful.
[0149] It can be seen that after it is determined that the identity of the first node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the first node and ensures the stable operation of the service provided by the device.
[0150] In yet another possible implementation of the sixth aspect, a processor is configured to: The node is further configured to determine that a second number of associations is less than or equal to a preset second association threshold, the second number of associations indicating a number of currently associated nodes.
[0151] It can be seen that a second association threshold is preset in the device. An association request may be sent to the first node only when the associated node is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that can be associated with the device. When the second association threshold is exceeded, the device cannot be associated with another node, which does not affect the communication between the device and another node associated with the device and ensures the stable operation of the service provided by the device.
[0152] In yet another possible implementation of the sixth aspect, a processor is configured to: and further configured to receive a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0153] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the device will receive a first association response from the first node. The association response is used to indicate that the first node establishes an association with the second node. Furthermore, the first response message may inform the device that the association is successful and subsequent communication may be performed.
[0154] In yet another possible implementation of the sixth aspect, a processor is configured to: Further configured to reset a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0155] It can be seen that if identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset, to avoid affecting subsequent determination of the identity of the first node and to ensure stable operation of the service provided by the device.
[0156] In yet another possible implementation of the sixth aspect, a processor is configured to: and further configured to update a second authentication failure counter if verification fails for the first identity credential, the second authentication failure counter indicating a number of verification failures for the first node.
[0157] If the verification of the identity credentials of the first node fails, the device updates the number of verification failures of the identity of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the attacker's device by modifying the identity such as an identifier, preventing the device from establishing an association with an unauthorized attacker and improving data security of the device.
[0158] In yet another possible implementation of the sixth aspect, a processor is configured to: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; The node is further configured to add an identifier of the first node to a second blacklist.
[0159] If the number of verification failures of the first node exceeds a preset first threshold, indicating that the first node has not been verified multiple times, it is found that the first node may be an attacker who frequently sends authentication requests. Thus, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the device.
[0160] In yet another possible implementation of the sixth aspect, the validity period of the second blacklist is a predefined or preset second duration.
[0161] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0162] In yet another possible implementation of the sixth aspect, a processor is configured to: determining that a value of a second authentication failure counter is less than a second threshold; and transmitting a second association request to the first node.
[0163] It can be understood that in the process of verifying the identity authentication information, some parameters may be lost or transmitted erroneously in the transmission process, so that the verification for the identity authentication information may also fail. Therefore, if the number of verification failures of the first node does not exceed the preset second threshold, the association request may be resent to the first node to request to establish an association with the first node. In this way, the robustness of the system is improved and the stable operation of the service provided by the device is ensured.
[0164] In yet another possible implementation of the sixth aspect, a processor is configured to: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and transmitting a second association request to the first node.
[0165] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0166] In yet another possible implementation of the sixth aspect, a processor is configured to: and further configured to remove the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to at least one of the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0167] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Furthermore, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0168] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be regarded as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the device may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here.
[0169] In yet another possible implementation of the sixth aspect, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0170] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0171] According to a seventh aspect, an embodiment of the present application further provides an association control method, the method comprising: receiving a first association request from a second node; determining that the identity of the second node is trusted and sending a first authentication request to the second node, the first authentication request including the first integrity check data; receiving a first authentication response from the second node, the first authentication response including second integrity check data; performing a message integrity check on the first authentication response based on the second integrity check data; and if a message integrity check on the first authentication response fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of validation failures of the second node.
[0172] In this embodiment of the application, after the identity of the second node is determined to be trusted, a message integrity check must further be performed on the authentication response message from the second node before the association is performed. If the message integrity check fails, the number of verification failures is updated. The number of verification failures may be used to subsequently determine whether the identity of the second node is trusted, so that an attacker may be prevented from tampering with data (e.g., identity authentication information) in the authentication process. This prevents the node from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0173] In a possible implementation of the seventh aspect, determining that the identity of the second node is trusted comprises: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method includes obtaining first acknowledgement indication information, the first acknowledgement indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0174] In the above method, the nodes requesting association may be controlled by a blacklist or whitelist, so that identity authentication does not need to be performed for an untrusted second node, which prevents the node from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0175] In a possible implementation of the seventh aspect, determining that the identity of the second node is trusted comprises: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method includes obtaining first acknowledgement indication information if the identifier of the second node is not on a first blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgement indication information indicates that the identity of the second node is trusted.
[0176] In another possible implementation of the seventh aspect, prior to receiving the first association request from the second node, the method further comprises: The method further includes determining that the first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0177] It can be seen that a first association threshold is preset in the node. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the node. When the first association threshold is exceeded, the node may no longer receive or process association requests, without affecting the communication between the node and another node associated with the node, and ensuring the stable operation of the service provided by the node.
[0178] In yet another possible implementation of the seventh aspect, the first authentication response further includes second identity authentication information. if the integrity check on the first authentication response is successful, performing a validation on a second identity credential based on a shared key shared with the second node; and updating a first authentication failure counter if verification of the second identity credential fails, the first authentication failure counter indicating a number of verification failures of the second node.
[0179] It can be seen that after the identity of the second node is determined to be trusted, if the integrity check is successful, a verification is performed on the identity of the second node based on the shared key shared with the second node. If the verification fails, the number of verification failures is updated. The number of verification failures may be used to later determine whether the identity of the second node is trusted, so that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, association requests of the node (e.g., sending authentication requests) may no longer be processed, preventing the node from stalling due to processing a large number of requests and ensuring the normal operation of the service.
[0180] In yet another possible implementation of the seventh aspect, a method comprises: If the verification for the second identity authentication information is successful, sending a first association response to the second node, the first association response being used to indicate that the first node establishes an association with the second node.
[0181] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate that the first node will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and communication may be performed.
[0182] In yet another possible implementation of the seventh aspect, a method comprises: The method further includes resetting a first authentication failure counter if the verification for the second identity credential is successful.
[0183] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset to avoid affecting subsequent determinations of the identity of the second node and to ensure the stable operation of the services provided by the node.
[0184] In yet another possible implementation of the seventh aspect, a method comprises: The method further includes determining that a value of the first authentication failure counter is greater than or equal to a first threshold and adding an identifier of the second node to a first blacklist.
[0185] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker who frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the node from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0186] In yet another possible implementation of the seventh aspect, the validity period of the first blacklist is a predefined or preset first duration.
[0187] It is understood that the predefined or preset first duration in the first blacklist may be regarded as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0188] In yet another possible implementation of the seventh aspect, a method comprises: The method further includes removing the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0189] The above implementation describes factors related to the lifetime of the first blacklist. The lifetime of the first blacklist may be related to the number of times the second node has been added to the first blacklist. A greater number of times the second node has been added to the first blacklist indicates a longer duration of the second node on the first blacklist. Additionally, optionally, the second node may be permanently added to the blacklist after the number of times the second node has been added to the blacklist exceeds a threshold.
[0190] Additionally, the first blacklist validity period may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be considered as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here. In yet another possible implementation of the seventh aspect, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0191] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting node resources and affecting successful association with another node.
[0192] According to an eighth aspect, an embodiment of the present application further provides an association method, the method comprising: determining that the identity of the first node is trusted and sending a first association request to the first node; receiving a first authentication request from the first node, the first authentication request including first integrity check data; performing a message integrity check on the first authentication request based on the first integrity check data; The communication unit 1202 includes: if a message integrity check for the first authentication request is successful, sending a first authentication response to the first node; and the first authentication response includes second integrity check data.
[0193] In this embodiment of the application, after the identity of the second node is determined to be trusted, authentication (e.g., verification using identity credentials) must still be performed with the first node before communication can take place. To prevent an attacker from tampering with data in the authentication process, a message integrity check must first be performed on the first authentication request. Association with the first node is only allowed if the message integrity check is successful, which may prevent an attacker from tampering with message content. This prevents the node from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0194] In a possible implementation of the eighth aspect, determining that the identity of the first node is trusted comprises: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or Obtaining second acknowledgement indication information, the second acknowledgement indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0195] In the above method, associated nodes may be controlled using a blacklist or whitelist, and nodes may be controlled not to send association requests to untrusted first nodes, which prevents nodes from establishing associations with unauthenticated attackers and improves data security for the nodes.
[0196] In a possible implementation of the eighth aspect, determining that the identity of the first node is trusted comprises: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or and obtaining second acknowledgement indication information if the identifier of the first node is not on a second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on a second whitelist, wherein the second acknowledgement indication information indicates that the identity of the second node is trusted.
[0197] In another possible implementation of the eighth aspect, prior to determining that the identity of the first node is trusted and sending the first association request to the first node, the method further comprises: The method further includes determining that the second association number is less than or equal to a preset second association threshold, the second association number indicating a number of currently associated nodes.
[0198] It can be seen that a second association threshold is preset for the node. An association request may be sent to the first node only when the associated node is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that may be associated with the node. When the second association threshold is exceeded, the node cannot be associated with another node, which does not affect the communication between the node and another node associated with the node, and ensures the stable operation of the service provided by the node.
[0199] In yet another possible implementation of the eighth aspect, a method includes: The method further includes receiving a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0200] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the second node will receive a first association response from the first node. The association response is used to indicate that the first node will establish an association with the second node. Furthermore, the first response message may inform the second node that the association is successful and subsequent communication may be performed.
[0201] In yet another possible implementation of the eighth aspect, a method includes: The method further includes resetting a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0202] It can be seen that if the identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset to avoid affecting subsequent determinations of the identity of the first node and to ensure the stable operation of the services provided by the node.
[0203] In yet another possible implementation of the eighth aspect, a method includes: The method further includes updating a second authentication failure counter if a message integrity check on the first authentication response fails, the second authentication failure counter indicating a number of validation failures for the first node.
[0204] Typically, if the message integrity check on the first authentication response fails, indicating that the first authentication response message is no longer complete or has been modified by an attacker, the number of identity verification failures of the first node is updated accordingly, and the number of verification failures may be used to subsequently determine whether the identity of the first node is trusted.
[0205] In yet another possible implementation of the eighth aspect, the first authentication request message further includes first identity authentication information. If a message integrity check on the first authentication response is successful, sending the first authentication response includes: If a message integrity check on the first authentication response is successful, performing a verification on the first identity credential based on a shared key shared with the first node; If the verification for the first identity authentication information is successful, sending a first authentication response to the first node.
[0206] After it is determined that the identity of the first node is trusted, if the integrity check is successful, it is seen that a verification is performed on the identity of the first node based on the shared key shared with the first node. Thus, it is difficult for an attacker to circumvent the association control for an attacker by modifying the identity such as an identifier, which prevents the node from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0207] In yet another possible implementation of the eighth aspect, a method includes: The method further includes updating a second authentication failure counter if verification for the first identity credential fails, the second authentication failure counter indicating a number of verification failures for the first node.
[0208] If the verification of the identity authentication information of the first node fails, the number of identity verification failures of the first node is updated, and the number of verification failures may be used to subsequently determine whether the identity confirmation of the node is trusted, so that a node that has not been verified multiple times may no longer be determined to be trusted. For a node that is not determined to be trusted, association requests may no longer be sent to the node, ensuring the normal operation of the service provided by the node.
[0209] In yet another possible implementation of the eighth aspect, a method includes: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; and adding an identifier of the first node to a second blacklist.
[0210] If the number of verification failures of the first node exceeds a preset first threshold, it indicates that the first node has not been verified multiple times, and it is found that the first node may be an attacker who frequently sends authentication requests. Therefore, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the node from establishing an association with an unauthenticated attacker, and improves the data security of the node.
[0211] In yet another possible implementation of the eighth aspect, the validity period of the second blacklist is a predefined or preset second duration.
[0212] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0213] In yet another possible implementation of the eighth aspect, if the verification for the first identity credential fails, after updating the second authentication failure counter, the method further comprises: determining that a value of a second authentication failure counter is less than a second threshold; and sending a second association request to the first node.
[0214] It can be understood that in the process of verifying the identity authentication information, some parameters may be lost or transmitted erroneously in the transmission process, so that the verification for the identity authentication information may also fail. Therefore, if the number of verification failures of the first node does not exceed the preset second threshold, the association request may be resent to the first node to request to establish an association with the node. In this way, the robustness of the system is improved and the stable operation of the service provided by the node is ensured.
[0215] In yet another possible implementation of the eighth aspect, if the verification for the first identity credential fails, after updating the second authentication failure counter, the method further comprises: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and sending a second association request to the first node.
[0216] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0217] In yet another possible implementation of the eighth aspect, a method includes: and removing the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to at least one of the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0218] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Furthermore, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0219] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be considered as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the second node may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here. In yet another possible implementation of the eighth aspect, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0220] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0221] According to a ninth aspect, an embodiment of the present application further provides an association control method. a communication unit configured to receive a first association request from a second node; and a processing unit configured to determine that the identity of the second node is trusted and to send, using the communication unit, a first authentication request to the second node, the first authentication request including first integrity check data.
[0222] The communication unit is further configured to receive a first authentication response from the second node, the first authentication response including the second integrity check data.
[0223] The processing unit is further configured to perform a message integrity check on the first authentication response based on the second integrity check data.
[0224] The processing unit is further configured to update a first authentication failure counter if a message integrity check on the first authentication response fails, the first authentication failure counter indicating a number of validation failures of the second node.
[0225] In this embodiment of the application, after determining that the identity of the second node is trusted, the device is further required to perform a message integrity check on the authentication response message from the second node before the association is performed. If the message integrity check fails, the number of verification failures is updated. The number of verification failures may be used to subsequently determine whether the identity of the second node is trusted, so that an attacker may be prevented from tampering with data (e.g., identity authentication information) in the authentication process. This prevents the device from establishing an association with an unauthenticated attacker, improving the data security of the device.
[0226] In a possible implementation of the ninth aspect, the processing unit specifically comprises: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method is configured to obtain first acknowledgment indication information, the first acknowledgment indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0227] The device uses a blacklist or whitelist to control which nodes may request association, so that identity authentication does not have to be performed for an untrusted second node, which prevents the node from establishing an association with an unauthenticated attacker and improves data security for the node.
[0228] In a possible implementation of the ninth aspect, the processing unit specifically comprises: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is configured to obtain first acknowledgment indication information if the identifier of the second node is not on a first blacklist, a type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgment indication information indicates that the identity of the second node is trusted.
[0229] In another possible implementation of the ninth aspect, the processing unit The node is further configured to determine that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0230] It can be seen that a first association threshold is preset in the device. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the device. When the first association threshold is exceeded, the device may no longer receive or process association requests, without affecting the communication between the device and another node associated with the device, and ensuring the stable operation of the service provided by the device.
[0231] In yet another possible implementation of the ninth aspect, the processing unit comprises: if the integrity check on the first authentication response is successful, performing a validation on a second identity credential based on a shared key shared with the second node; and if verification for the second identity credential fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of verification failures for the second node.
[0232] The device may know that after determining that the identity of the second node is trusted, if the integrity check is successful, it performs a verification on the identity of the second node based on the shared key shared with the second node. If the verification fails, the number of verification failures is updated. The number of verification failures may be used to later determine whether the identity of the second node is trusted, such that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, association requests of the node (e.g., sending authentication requests) may no longer be processed, preventing the node from stalling due to processing a large number of requests and ensuring the normal operation of the service.
[0233] In yet another possible implementation of the ninth aspect, the communication unit comprises: and further configured to send a first association response to the second node if the verification against the second identity authentication information is successful, the first association response being used to indicate that the first node establishes an association with the second node.
[0234] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and that communication may be performed.
[0235] In yet another possible implementation of the ninth aspect, the processing unit comprises: The method is further configured to reset the first authentication failure counter if the second identity credential is successfully verified.
[0236] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset, to avoid affecting subsequent determination of the identity of the second node and to ensure stable operation of the service provided by the device.
[0237] In yet another possible implementation of the ninth aspect, the processing unit comprises: The device is further configured to determine that a value of the first authentication failure counter is greater than or equal to a first threshold and to add an identifier of the second node to a first blacklist.
[0238] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker that frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0239] In yet another possible implementation of the ninth aspect, the validity period of the first blacklist is a predefined or preset first duration.
[0240] It is understood that the predefined or preset first duration in the first blacklist may be regarded as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0241] In yet another possible implementation of the ninth aspect, the processing unit comprises: The method is further configured to remove the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0242] The above implementation describes factors related to the lifetime of the first blacklist. The lifetime of the first blacklist may be related to the number of times the second node has been added to the first blacklist. A greater number of times the second node has been added to the first blacklist indicates a longer duration of the second node on the first blacklist. Furthermore, optionally, the second node may be permanently added to the first blacklist after the number of times the second node has been added to the first blacklist exceeds a threshold.
[0243] Additionally, the validity period of the first blacklist may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be regarded as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here.
[0244] In yet another possible implementation of the ninth aspect, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0245] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting device resources and affecting successful association with another node.
[0246] According to a tenth aspect, an embodiment of the present application further provides an association device, comprising: and a processing unit configured to determine that an identity of a first node is trusted and to send, using a communication unit, a first association request to the first node.
[0247] The communication unit is further configured to receive a first authentication request from the first node, the first authentication request including the first identity authentication information and the first integrity check data.
[0248] The processing unit is further configured to perform a message integrity check on the first authentication request based on the first integrity check data.
[0249] The communication unit is further configured to send a first authentication response to the first node if the message integrity check for the first authentication request is successful, the first authentication response including the second integrity check data.
[0250] In this embodiment of the application, after determining that the identity of the second node is trusted, the device is further required to perform authentication (e.g., verification using identity credentials) with the first node before communication can take place. To prevent an attacker from tampering with data in the authentication process, a message integrity check needs to be first performed on the first authentication request. Association with the first node is only allowed if the message integrity check is successful, so that an attacker can be prevented from tampering with message content. This prevents the node from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0251] In a possible implementation of the tenth aspect, the processing unit specifically comprises: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or The device is further configured to obtain second acknowledgment indication information, the second acknowledgment indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0252] In the above method, associated nodes may be controlled using a blacklist or whitelist, and the device may be controlled not to send association requests to untrusted first nodes, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0253] In a possible implementation of the tenth aspect, the processing unit specifically comprises: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or and if the identifier of the first node is not on a second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on a second whitelist, obtain second acknowledgement indication information, the second acknowledgement indication information indicating that the identity of the second node is trusted.
[0254] In yet another possible implementation of the ninth aspect, the processing unit comprises: The node is further configured to determine that a second number of associations is less than or equal to a preset second association threshold, the second number of associations indicating a number of currently associated nodes.
[0255] It can be seen that a second association threshold is preset in the device. An association request may be sent to the first node only when the associated node is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that can be associated with the device. When the second association threshold is exceeded, the device cannot be associated with another node, which does not affect the communication between the device and another node associated with the device and ensures the stable operation of the service provided by the device.
[0256] In yet another possible implementation of the tenth aspect, the communication unit comprises: and further configured to receive a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0257] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the device will receive a first association response from the first node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may inform the device that the association is successful and subsequent communication may be performed.
[0258] In yet another possible implementation of the tenth aspect, the processing unit comprises: Further configured to reset a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0259] It can be seen that if identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset, to avoid affecting subsequent determination of the identity of the first node and to ensure stable operation of the service provided by the device.
[0260] In yet another possible implementation of the tenth aspect, the processing unit comprises: and further configured to update a second authentication failure counter if a message integrity check on the first authentication response fails, the second authentication failure counter indicating a number of validation failures for the first node.
[0261] Typically, if the message integrity check on the first authentication response fails, indicating that the first authentication response message is no longer complete or has been modified by an attacker, the number of verification failures for the first node is updated accordingly, and the number of verification failures may be used to subsequently determine whether the identity of the first node is trusted.
[0262] In yet another possible implementation of the tenth aspect, the first authentication request message further includes a first identity credential. The processing unit is further configured to perform a verification on the first identity credential based on a shared key shared with the first node if a message integrity check on the first authentication response is successful.
[0263] The communication unit is further configured to send a first authentication response to the first node if the verification on the first identity authentication information is successful.
[0264] After it is determined that the identity of the first node is trusted, if the integrity check is successful, it is seen that a verification is performed on the identity of the first node based on the shared key shared with the first node. Thus, it is difficult for an attacker to circumvent the association control performed by the attacker's device by modifying the identity such as an identifier, which prevents the node from establishing an association with an unauthorized attacker and improves the data security of the node.
[0265] In yet another possible implementation of the tenth aspect, the processing unit comprises: and further configured to update a second authentication failure counter if verification fails for the first identity credential, the second authentication failure counter indicating a number of verification failures for the first node.
[0266] If the verification for the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures may be used to subsequently determine whether the identity confirmation of the node is trusted, so that a node that has not been verified multiple times may no longer be determined to be trusted. For a node that is not determined to be trusted, an association request may no longer be sent to the node, ensuring normal operation of the service provided by the node. In yet another possible implementation of the tenth aspect, the processing unit: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; The node is further configured to add an identifier of the first node to a second blacklist.
[0267] If the number of verification failures of the first node exceeds a preset first threshold, indicating that the first node has not been verified multiple times, it is found that the first node may be an attacker who frequently sends authentication requests. Thus, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0268] In yet another possible implementation of the tenth aspect, the validity period of the second blacklist is a predefined or preset second duration.
[0269] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0270] In yet another possible implementation of the tenth aspect, the processing unit is further configured to determine that a value of a second authentication failure counter is less than a second threshold.
[0271] The communication unit is further configured to send a second association request to the first node.
[0272] If the verification of the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the first node by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthorized attacker and improves data security of the node.
[0273] In yet another possible implementation of the tenth aspect, the processing unit comprises: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and transmitting a second association request to the first node.
[0274] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0275] In yet another possible implementation of the tenth aspect, the processing unit comprises: The method is further configured to remove the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0276] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Furthermore, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0277] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be considered as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the second node may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here. In yet another possible implementation of the tenth aspect, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0278] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0279] According to an eleventh aspect, an embodiment of the present application further provides a communication device, the communication device comprising at least one processor and a communication interface, the at least one processor invoking a computer program stored in at least one memory, such that the device implements a method according to the seventh aspect or any one of the possible implementations of the seventh aspect.
[0280] According to a twelfth aspect, an embodiment of the present application further provides a communications apparatus, the apparatus comprising at least one processor and a communications interface, the at least one processor invoking a computer program stored in at least one memory, such that the apparatus implements a method according to the eighth aspect or any one of the possible implementations of the eighth aspect.
[0281] According to a thirteenth aspect, an embodiment of the present application further provides a communication system. The communication system includes a first node and a second node. The first node is an apparatus according to the third aspect or any one of the possible implementations of the third aspect, or the fifth aspect or any one of the possible implementations of the fifth aspect. The second node is an apparatus according to the fourth aspect or any one of the possible implementations of the fourth aspect, or the sixth aspect or any one of the possible implementations of the sixth aspect.
[0282] According to a fourteenth aspect, an embodiment of the present application further provides a communication system. The communication system includes a first node and a second node. The first node is an apparatus according to any one of the ninth aspect, or a possible implementation of the ninth aspect, or an eleventh aspect. The first node is an apparatus according to any one of the tenth aspect, or a possible implementation of the tenth aspect, or an apparatus according to any one of the twelfth aspect.
[0283] According to a fifteenth aspect, an embodiment of the present application discloses a computer readable storage medium, the computer readable storage medium storing a computer program, the computer program, when run on one or more processors, performing a method according to the first aspect or any one of the possible implementations of the first aspect, a method according to the second aspect or any one of the possible implementations of the second aspect, a method according to the seventh aspect or any one of the possible implementations of the seventh aspect, or a method according to the eighth aspect or any one of the possible implementations of the eighth aspect.
[0284] According to a sixteenth aspect, an embodiment of the present application discloses a chip system. The chip system includes at least one processor, a memory, and an interface circuit. The interface circuit is configured to provide information input / output to the at least one processor, and the memory stores a computer program, and when the computer program runs on the one or more processors, a method according to the first aspect or any one of the possible implementations of the first aspect, a method according to the second aspect or any one of the possible implementations of the second aspect, a method according to the seventh aspect or any one of the possible implementations of the seventh aspect, or a method according to the eighth aspect or any one of the possible implementations of the eighth aspect is performed.
[0285] According to a seventeenth aspect, an embodiment of the present application discloses a vehicle. The vehicle includes a first node (e.g., a vehicle cockpit domain controller CDC). The first node is a device according to the third aspect or any one of the possible implementations of the third aspect, or the fifth aspect or any one of the possible implementations of the fifth aspect. Furthermore, the vehicle includes a second node (e.g., at least one of a camera, a screen, a microphone, a speaker, a radar, an electronic key, a passive input passive start system controller, etc.). The second node is a device according to the fourth aspect or any one of the possible implementations of the fourth aspect, or the sixth aspect or any one of the possible implementations of the sixth aspect.
[0286] According to an eighteenth aspect, an embodiment of the present application discloses a vehicle. The vehicle includes a first node (e.g., a vehicle cockpit domain controller CDC). The first node is the device according to any one of the ninth aspect or possible implementations of the ninth aspect, or the eleventh aspect. Furthermore, the vehicle includes a second node (e.g., at least one of a camera, a screen, a microphone, a speaker, a radar, an electronic key, a passive input passive start system controller, etc.). The first node is the device according to any one of the tenth aspect or possible implementations of the tenth aspect, or the twelfth aspect. [Brief description of the drawings]
[0287] The accompanying drawings used in the embodiments of this application are described below.
[0288] [Figure 1] 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;
[0289] [Diagram 2] 1 is a schematic diagram of an application scenario of an association control method according to an embodiment of this application;
[0290] [Diagram 3] 1 is a schematic flowchart of an association control method according to an embodiment of the present application.
[0291] [Figure 4] FIG. 2 is a schematic diagram of a blacklist and a whitelist according to an embodiment of the present application.
[0292] [Figure 5A] 4 is a schematic flowchart of another association control method according to an embodiment of the present application. [Figure 5B] 4 is a schematic flowchart of another association control method according to an embodiment of the present application. [Figure 5C]4 is a schematic flowchart of another association control method according to an embodiment of the present application.
[0293] [Figure 6A] 4 is a schematic flowchart of yet another association control method according to an embodiment of the present application. [Figure 6B] 4 is a schematic flowchart of yet another association control method according to an embodiment of the present application. [Figure 6C] 4 is a schematic flowchart of yet another association control method according to an embodiment of the present application.
[0294] [Figure 7] FIG. 2 is a schematic diagram of the structure of yet another association control device according to an embodiment of the present application;
[0295] [Figure 8] FIG. 13 is a schematic diagram of the structure of yet another association device according to an embodiment of the present application;
[0296] [Figure 9] 1 is a schematic diagram of a structure of a communication device according to an embodiment of this application;
[0297] [Figure 10] FIG. 2 is a schematic diagram of the structure of another communication device according to an embodiment of this application;
[0298] [Figure 11] FIG. 2 is a schematic diagram of the structure of an association control device according to an embodiment of this application;
[0299] [Figure 12] FIG. 2 is a schematic diagram of the structure of another association device according to an embodiment of the present application;
[0300] [Figure 13] 1 is a schematic diagram of the structure of yet another communication device according to an embodiment of the present application;
[0301] [Figure 14] 1 is a schematic diagram of the structure of yet another communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0302] Hereinafter, the embodiments of this application will be described with reference to the accompanying drawings in the embodiments of this application. Please note that in this application, words such as "example", "for example" and the like are used to indicate giving an example, illustration or explanation. An embodiment or design solution described in this application using "example" or "for example" shall not be construed as being preferred or more advantageous than other embodiments or design solutions. The use of words such as "example", "for example" and the like is intended to present the related concept in a particular manner.
[0303] The following first provides a brief description of the relevant technologies and technical terms of this application for ease of understanding.
[0304] 1. Node
[0305] A node is an electronic device capable of receiving and transmitting data. For example, a node may be a vehicle Cockpit Domain device or a module within a vehicle Cockpit Domain device (e.g., one or more of the following modules: a cockpit domain controller (CDC), a camera, a screen, a microphone, a sounder, an electronic key, a passive entry / passive start system controller, etc.). In a specific implementation process, the node may be a data transit device such as a router, a repeater, a bridge, a switch, etc., or may be a terminal device such as various types of user equipment (UE), a mobile phone, a tablet computer (pad), a desktop computer, a headset, a speaker, etc., or may include machine intelligence such as a self-driving device, a transportation safety device, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a machine type communication (MTC) device, an industrial control device, a remote medical device, a smart grid device, a smart city device, etc., or may include a wearable device (such as a smart watch, a smart band, a pedometer, etc.). In some technical scenarios, the name of the device having similar data receiving and transmitting capabilities may not be "node". However, for ease of description, electronic devices having data receiving and transmitting capabilities are collectively referred to as nodes in the embodiments of this application.
[0306] 2.Shared key (SK)
[0307] In the communication process, data is transmitted between the communicating nodes. If the data needs to be kept secret, it needs to be encrypted using a key. The shared key is the same secret value stored in the nodes of both communicating parties. The shared key may be predefined or pre-configured in the nodes of both communicating parties, may be generated by both communicating parties using the same key derivation method, or may be sent to the first node and the second node by a trusted device (such as a KDC).
[0308] For example, a vehicle's cockpit domain controller (CDC) and a vehicle-mounted radar device are two nodes that can communicate with each other. When deploying the CDC and the vehicle-mounted radar, workers at the automobile factory pre-configure a shared key between the CDC and the vehicle-mounted radar. Using the shared key, the security of the communication between the vehicle's CDC and the vehicle-mounted radar can be guaranteed.
[0309] For example, a vehicle's cockpit domain controller (CDC) and the vehicle owner's mobile phone are two nodes that can communicate with each other. When the vehicle owner needs to associate with the vehicle's CDC using the mobile phone, the vehicle owner may obtain a shared key using a key derivation method. For example, the key may be generated by exchanging key agreement algorithm parameters between the mobile phone and the vehicle's CDC using a key agreement algorithm. Later, when the mobile phone requests to associate with the vehicle's CDC again, the shared key may be used to verify the identities of the two nodes.
[0310] 3. Key Derivation
[0311] Key derivation is the process of deriving one or more secret values from a single secret value. The algorithm used to derive a key is called a key derivation function (KDF), also called a key derivation algorithm. For example, a new secret value DK derived from a secret value Key may be expressed as DK=KDF(Key).
[0312] The symmetric key derivation algorithm includes password-based key derivation function (PBKDF), scrypt algorithm, etc. The PBKDF algorithm further includes a first generation PBKDF1 and a second generation PBKDF2. Optionally, for some KDF algorithms, a hash algorithm is used to perform a hash modification on the input secret value in the key derivation process. Thus, in the KDF function, an algorithm identifier may be further received as an input to indicate the specific hash algorithm to be used.
[0313] Additionally, it should be noted that "authentication", "inspection" and "verification" referred to in the embodiments of this application may mean whether the inspection is accurate or reasonable. In the embodiments of this application, "association" refers to a process in which a first node establishes a connection to a second node. In certain technical scenarios, "association" may alternatively be described as "access".
[0314] The following describes the system architecture and service scenarios in the embodiments of this application. Please note that the system architecture and service scenarios described in this application are intended to more clearly describe the technical solutions of this application, and do not constitute limitations on the technical solutions provided in this application. Those skilled in the art may know that with the evolution of system architectures and the emergence of new service scenarios, the technical solutions provided in this application may also be applicable to similar technical problems.
[0315] FIG. 1 is a schematic diagram of a communication system architecture according to an embodiment of this application. The communication system includes a first node 101 and a second node 102. The second node 202 may request to be associated with the first node 101. After successful association, the first node 101 may communicate with the second node 102 via a data link. Optionally, the data link used for communication between the first node 101 and the second node 102 may include various types of connection media, such as wireless fidelity (Wi-Fi) technology, Bluetooth, zigbee technology, another wireless link (e.g., universal wireless short range transmission technology), etc. As another example, the data link is a wired link, such as a fiber link.
[0316] Optionally, the first node 101 may be a communication initiator and may be referred to as a primary node or an access point (AP), and correspondingly, the second node 102 may be a communication receiver and may be referred to as a secondary node.
[0317] The first node 101 and the second node 102 may be the same type of device or different types of devices. Figure 2 is a schematic diagram of an application scenario of an association control method according to an embodiment of this application. A cockpit domain controller (Cockpit Domain Controller, CDC) 201 is a control center in a smart cockpit device and may be regarded as the first node 101. A smartphone 202 is a device with data transmission and reception capabilities and may be regarded as the second node 102. The CDC 201 may be associated with another Bluetooth device via Bluetooth. The smartphone 202 may request to be associated with the CDC 201 to support Bluetooth functionality.
[0318] In the existing communication process, the node is vulnerable to attacks from an attacker. For example, the attacker may forge the identity of a second node and request to be associated with the first node. If the attacker is successful in being associated with the first node, the data security of the first node is threatened. In particular, in the vehicle communication process, if the CDC 201 receives the association of the attacker, the vehicle data may be easily leaked and even attacked by the attacker, endangering the safety of driving. In another example, the attacker sends a large number of request frames to the node. When the node receives a large number of request frames and exceeds the processing capacity that the node can bear, the node will stop functioning and will not be able to continue to provide normal services, which will affect the communication between another node and the node. To solve this problem, the embodiment of this application provides the following association control method.
[0319] 3 is a schematic flowchart of an association control method according to an embodiment of this application. The association control method may be implemented based on the communication system shown in FIG 1. The method includes at least the following steps:
[0320] Step S301: The second node determines that the identity of the first node is trusted.
[0321] Specifically, the second node may determine that the identity of the first node is trusted using at least the following three methods:
[0322] Method 1: Using a blacklist and / or a whitelist, determine that the identity of a first node is trusted.
[0323] FIG. 4 is a schematic diagram of a blacklist and a whitelist according to an embodiment of this application. The blacklist 401 and the whitelist 402 store identifiers of a plurality of nodes. The identifier of a node may be an identification (ID), a media access control (MAC) address, a domain name, a domain address, or another user-defined identifier of a node. For example, the identifier "00-00-00-AA-AA-AA" in the blacklist 401 is an identifier of a node. Optionally, the blacklist may further include one or more of the addition time, expiration time, time added to the blacklist, etc. of the identifier of the node. Correspondingly, the whitelist may include one or more of the addition time, expiration time, key setting type, etc. of the identifier of the node. For ease of explanation, in the embodiment of this application, the blacklist in the second node is referred to as the second blacklist, and the whitelist in the second node is referred to as the second whitelist. It will be understood that the identifier of a node cannot be in both the second whitelist and the second blacklist.
[0324] The second node may determine whether the identity of the first node is trusted by determining whether the identifier of the first node is on a second whitelist or a second blacklist. Specifically, there may be three implementations:
[0325] Implementation 1: If the second node determines that the identifier of the first node is on a second whitelist, it may indicate that the identity of the first node is trusted.
[0326] Implementation 2: If the second node determines that the identifier of the first node is not on the second blacklist, it may indicate that the identity of the first node is trusted.
[0327] Optionally, the second node may obtain the identifier of the first node by obtaining input information or by receiving a message broadcast by the first node. For example, the first node may broadcast a message, and the broadcast message may include the identifier of the first node. After receiving the broadcast message, the second node may determine whether the identity of the first node is trusted based on the identifier of the first node, the second blacklist or the second whitelist. Optionally, the second node stores a correspondence between the identifiers of one or more other nodes and a key configuration type, and the key configuration type may be a pre-configured type and a password generation type. The pre-configured type indicates that the shared key between the first node and the second node is pre-configured or pre-defined. For example, when assembling a vehicle, an operator at a host factory pre-configures a shared key between the CDC and the microphone. The password generation type is also called the "password access type" and indicates that when an association is established by the password access method, the shared key between the first node and the second node is a shared key generated based on a password. Furthermore, nodes of different key establishment types may have different methods for determining which identities are trusted. Specifically, the following two implementations are further included:
[0328] Implementation 3: For a first node whose key configuration type is preset, if it is determined that the identifier of the first node is in the second whitelist, it indicates that the identity of the node is trusted. Optionally, if the identifier of the first node is in the second blacklist, it indicates that the identity of the first node is not trusted. For example, Table 1 shows a possible correspondence between node identifiers and key configuration types according to an embodiment of this application. When node A1 whose identifier is "66-66-66-FF-FF-FF" requests association, it can be determined that the identity of node A1 is trusted because it can be seen by referring to the whitelist 402 that the key configuration type of node A1 is preset and the identifier of node A1 is in the whitelist 402. [Table 1]
[0329] Implementation 4: For a first node whose key establishment type is password generation, if it is confirmed that the identifier of the first node is not in the second blacklist, it indicates that the identity of the first node is trusted. For example, see FIG. 1. If node A2 whose identifier is "77-77-77-GG-GG-GG" requests association, it can be determined that the identity of node A2 is trusted because it can be seen by referring to FIG. 4 that the key establishment type of node A2 is password generation type and the identifier of node A2 is not in the blacklist 401.
[0330] Method 2: Determine that the identity of the first node is trusted by obtaining a second acknowledgement indication.
[0331] The second node obtains second acknowledgement indication information. The second acknowledgement indication information indicates that the identity of the first node is trusted. The second acknowledgement indication information may be indication information obtained based on an acknowledgement action input by a user, and the acknowledgement action may be an acknowledgement of the output prompt information. For example, there is the following implementation.
[0332] Implementation 5: The second node outputs second prompt information to remind the user that the second node needs to request to be associated with the first node. The second node may determine that the identity of the first node is trusted after receiving the user's acknowledgement action and obtaining the second acknowledgement indication information. Optionally, if the second node receives the user's rejection action after outputting the second prompt information, the second node may determine that the identity of the first node is not trusted.
[0333] Method 3: Using the blacklist and / or whitelist and acknowledgement indication information, determine that the identity of the first node is trusted.
[0334] When the second node cannot determine whether the identity of the first node is trusted using the blacklist and the whitelist, the second node may use the acknowledgement indication information to determine that the identity of the first node is trusted. Specifically, when the identifier of the first node is not in the second blacklist, or when the identifier of the first node is not in the second blacklist or the second whitelist, the second acknowledgement indication information is obtained. The second acknowledgement indication information indicates that the identity of the first node is trusted. Optionally, in a specific implementation process, different key setting types may further correspond to different processes. For example, there is the following implementation.
[0335] Implementation 6: For a first node whose key establishment type is password generation, if the identifier of the first node is not on the second blacklist or the second whitelist, second acknowledgement indication information is obtained. The acknowledgement indication information indicates that the identity of the first node is trusted. Optionally, if the second acknowledgement indication information is not obtained, it may be determined that the identity of the second node is not trusted.
[0336] Optionally, the second node may predefine or set a second association threshold. The second association threshold is used to indicate the number of nodes currently associated. The second node may determine the number of associations of the second node before or after determining that the identity of the first node is trusted, or may determine the number of associations of the second node periodically or aperiodically. That is, the method includes determining whether the number of nodes currently associated with the second node is less than or equal to the second association threshold, or determining whether the number of nodes currently associated with the second node is greater than or equal to the second association threshold. If the number of currently associated nodes is greater than (or equal to) the second association threshold, the second node may not send an association request to the first node, or may subsequently cancel its association with the first node, so as not to affect communication between the second node and other nodes and to ensure stable operation of the service provided by the second node.
[0337] Step S302: The second node sends a first association request to the first node.
[0338] Specifically, the second node may send a first association request message to the first node via a wireless link (e.g., one of Wi-Fi, Bluetooth, ZigBee, or other short-range wireless links) or a wired link (e.g., optical fiber).
[0339] In response, the first node receives a first association request from the second node. Optionally, the first node may predefine or set a first association threshold. The first association threshold is used to indicate the number of nodes currently associated. The first node may determine the number of nodes currently associated with the first node before or after receiving the first association request message from the second node, or may periodically or aperiodically determine the number of nodes currently associated with the first node. That is, the method may include determining whether the number of nodes currently associated with the first node is equal to or less than the first association threshold, or determining whether the number of nodes currently associated with the first node is greater than or equal to the first association threshold. The first association threshold may limit the support capacity of services that may be provided by the first node. When the number of nodes associated with the first node is greater than (or equal to) the first association threshold, the first node may no longer receive or process association requests, and thus may not receive or process the first association requests, without affecting communication between the first node and other associated nodes, and ensuring stable operation of the service provided by the first node.
[0340] Optionally, the first association request message may include at least one of an identity of the second node, a freshness parameter obtained (or generated) by the second node, etc. The freshness parameter may include at least one of a nonce (number once, NONCE), a counter, a sequence number, etc. For ease of explanation, the freshness parameter in the first association request message is referred to as a first freshness parameter.
[0341] Step S303: The first node determines that the identity of the second node is trusted.
[0342] Specifically, the first node may determine that the identity of the second node is trusted in at least the following three ways:
[0343] Method 1: Using a blacklist and / or a whitelist to determine that the identity of the second node is trusted.
[0344] For ease of explanation, in the embodiment of this application, the blacklist in the first node is referred to as the first blacklist, and the whitelist in the first node is referred to as the first whitelist. It will be understood that in the first node, the identifier of the node cannot be in both the first whitelist and the first blacklist.
[0345] The first node may determine whether the identity of the second node is trusted by determining whether the identifier of the second node is on a first whitelist or a first blacklist. Specifically, there may be two cases:
[0346] Case 1: If the first node determines that the identifier of the second node is on the first whitelist, it may indicate that the identity of the second node is trusted.
[0347] Case 2: If the first node determines that the identifier of the second node is not on the first blacklist, it may indicate that the identity of the second node is trusted. Optionally, if the identifier of the second node is on the first blacklist, it may indicate that the identity of the second node is not trusted, and the first node may discard the first association request or ignore the request and skip subsequent steps.
[0348] Optionally, the first association request message includes an identifier of the second node, and the first node may obtain the identifier of the second node by receiving the first association request message.
[0349] Optionally, the first node stores a correspondence between the identifiers of one or more other nodes and a key configuration type, and the key configuration type may be a pre-configured type and a password-generated type. The pre-configured type indicates that the shared key between the first node and the second node is pre-configured or pre-defined. For example, when assembling a vehicle, a worker at a host factory pre-configures a shared key between the CDC and the microphone. The password-generated type indicates that the shared key between the first node and the second node is a shared key generated based on a password after an association is established by a password-access method. Furthermore, nodes of different key configuration types may have different methods of determining that an identity is trusted. During a particular implementation, there may be two cases:
[0350] Case 3: For a second node whose key configuration type is preconfigured, if the identifier of the second node is determined to be in the first whitelist, it indicates that the identity of the second node is trusted.
[0351] Case 4: For a second node with a key establishment type of password generation, if it is determined that the identifier of the second node is not on the first blacklist, indicating that the identity of the node is trusted. Optionally, if the identifier of the node is on the first blacklist, the identity of the second node is not trusted and the first node may discard the first association request or ignore the request and skip further steps.
[0352] Method 2: By obtaining the first acknowledgement indication, it is determined that the identity of the second node is trusted.
[0353] The first node obtains first acknowledgement indication information. The first acknowledgement indication information indicates that the identity of the second node is trusted. Specifically, the first acknowledgement indication information may be indication information obtained based on an acknowledgement action input by a user, and the acknowledgement action may be an acknowledgement of the output prompt information. For example, there are the following cases:
[0354] Case 5: The first node outputs the first prompt information to remind the user that the second node needs to be associated. The first node may determine that the identity of the second node is trusted after receiving the user's acknowledgement action and obtaining the first acknowledgement indication information. Furthermore, optionally, if the first node receives the user's rejection action after outputting the first prompt information, the first node may determine that the identity of the second node is not trusted, and the first node may discard the first association request or ignore the request and skip the subsequent steps.
[0355] Method 3: Using the blacklist and / or whitelist and acknowledgement indication information, determine that the identity of the second node is trusted.
[0356] When the first node cannot use the blacklist and the whitelist to determine whether the identity of the second node is trusted, the first node may use the acknowledgement indication information to determine that the identity of the second node is trusted. Specifically, when the identifier of the second node is not in the first blacklist, or when the identifier of the second node is not in the first blacklist or the first whitelist, the second acknowledgement indication information is obtained. The first acknowledgement indication information indicates that the identity of the second node is trusted. Optionally, in a specific implementation process, different key setting types may further correspond to different processes. For example, there are the following cases:
[0357] Case 6: For a second node whose key establishment type is password generation, if the identifier of the second node is not in the first blacklist or the first whitelist, a first acknowledgement indication information is obtained. The acknowledgement indication information indicates that the identity of the second node is trusted. Optionally, if the first acknowledgement indication information is not obtained, it may be determined that the identity of the second node is not trusted, and the first node may discard the first association request or ignore the request and skip subsequent steps.
[0358] Step S304: The first node sends a first authentication request to the second node.
[0359] Specifically, the first authentication request may include a first identity credential. The first identity credential is generated by the first node based on a shared key between the first node and the second node. The shared key may be a pre-shared key (PSK) between the first node and the second node.
[0360] For example, the first node may use the KDF to generate the first identity credential AUTHa based on the pre-shared key PSK, for example, AUTHa=KDF(PSK).
[0361] Optionally, when the first association request includes the first freshness parameter, the first identity credential may be generated by the first node based on the shared key and the first freshness parameter. For example, the first node generates the first identity credential AUTHa based on the pre-shared key PSK and the first freshness parameter NONCEe using the KDF. For example, AUTHa = KDF(PSK, NONCEe).
[0362] Optionally, during actual processing, the parameters used by the first node to generate the first identity authentication information may further include other information. For example, the generated first identity authentication information AUTHa may satisfy AUTHa=KDF(PSK, first association request).
[0363] Optionally, the first authentication request further includes a second freshness parameter. The second freshness parameter may be at least one of a random number, a nonce (number once, NONCE), a counter, a sequence number, etc., obtained (or generated) by the second node. Furthermore, optionally, when the first authentication request includes the second freshness parameter, the first identity authentication information AUTHa generated by the first node may further satisfy AUTHa=KDF(PSK, NONCEa, first association request), where NONCEa is the second freshness parameter of the first authentication request.
[0364] Optionally, the first authentication request may include first integrity check data, etc. The first integrity check data is check data generated according to a symmetric key and an integrity protection algorithm, and is used by the second node to perform a message integrity check on the first authentication request. During a specific implementation, the check data may also be referred to as a message authentication code (MAC).
[0365] Step S305: The second node performs verification on the first identity authentication information based on the shared key between the second node and the first node.
[0366] Specifically, the first identity authentication information is generated by the first node based on a shared key between the first node and the second node. Therefore, the second node also has the shared key, and may verify whether the first identity authentication information is correct based on the shared key.
[0367] In an optional solution, according to the protocol specification, if the first node uses a certain parameter to generate the first identity authentication information, the second node should also use the same parameter to generate the check information. If the check information is the same as the first identity authentication information, the verification is deemed successful. For example, the first identity authentication information is generated using a KDF. Therefore, the second node may use a KDF to generate the check information, which is also called a check value check1. The second node uses the check information to verify whether the first identity authentication information is correct. Hereinafter, an example is used for explanation.
[0368] For example, if the first identity credential AUTHa is KDF(PSK, NONCEe), the second node uses KDF to obtain a check value check1=KDF(PSK, NONCEe) based on PSK and the first fresh parameter NONCEe. If the check value check1 is the same as AUTHa, the verification is successful.
[0369] Optionally, before or after verifying the first identity authentication information based on the shared key between the second node and the first node, the second node performs a message integrity check on the first authentication request to prevent the content of the first authentication request from being tampered with by an attacker. Specifically, the first authentication request may include first integrity check data, and the second node may perform a message integrity check on the first authentication request based on the first integrity check data.
[0370] Optionally, if the message integrity check performed on the first authentication request fails, the second node may update the number of integrity check failures of the first node. The number of integrity check failures may then be used to determine whether the identity of the first node is trusted. Furthermore, optionally, there may be two cases in which the second node updates the number of integrity check failures of the first node:
[0371] Case 1: The second node uses a second authentication failure counter to indicate the number of verification failures of the first node. The verification to the first node may include a message integrity check and an identity authentication. Thus, if the message integrity check for the first authentication request fails or the identity authentication to the second node fails, the second node may increment the second authentication failure counter by one. The second authentication failure counter may then be used to determine whether the identity of the first node is trusted.
[0372] Case 2: The second node uses a second integrity check counter to indicate the number of integrity check failures of the first node. If the message integrity check for the first authentication request fails, the second node may increment the second integrity check counter by 1. The second integrity check counter may then be used to determine whether the identity of the first node is trusted.
[0373] Step S306: If the verification on the first identity authentication information performed by the second node is successful, the second node sends a first authentication response to the first node.
[0374] Specifically, the first authentication response may include a second identity credential. The second identity credential is generated by the second node based on a shared key between the second node and the first node. The shared key may be a pre-shared key (PSK) between the first node and the second node.
[0375] For example, the second node may use the KDF to generate a second identity credential AUTHe based on the pre-shared key PSK, for example AUTHe=KDF(PSK).
[0376] Optionally, when the first authentication request includes a second freshness parameter, a second identity credential may be generated by the second node based on the shared key and the second freshness parameter. For example, the second node uses the KDF to generate a second identity credential AUTHe based on the pre-shared key PSK and the second freshness parameter NONCEa. For example, AUTHe=KDF(PSK, NONCEa).
[0377] Optionally, during actual processing, the parameters used by the second node to generate the second identity authentication information may further include other information. For example, the generated second identity authentication information AUTHe may satisfy AUTHe=KDF(PSK, first authentication request).
[0378] Optionally, when the first association request may further include a first freshness parameter, the second identity authentication information AUTHe generated by the second node may further satisfy AUTHe=KDF(PSK, NONCEe, first authentication request), where NONCEe is the first freshness parameter of the first association request.
[0379] Optionally, the first association request may further include second integrity check data, etc. The second integrity check data is check data generated according to a symmetric key and an integrity protection algorithm, and is used by the first node to perform a message integrity check on the first association request. During a specific implementation, the check data may also be referred to as a message authentication code (MAC).
[0380] Step S307: The first node performs verification on the second identity authentication information based on the shared key.
[0381] Specifically, the second identity authentication information is generated based on a shared key between the first node and the second node, so that the first node also has the shared key and may verify whether the second identity authentication information is correct based on the shared key.
[0382] In an optional solution, according to the protocol specification, if the second node uses a certain parameter to generate the second identity authentication information, the first node should also use the same parameter to generate the check information. If the check information is the same as the first identity authentication information, the verification is deemed successful. For example, the second identity authentication information is generated using a KDF. Thus, the first node may use a KDF to generate the check information, which is also called a check value check2. Then, the first node uses the check information to verify whether the second identity authentication information is correct. Hereinafter, an example is used for explanation.
[0383] For example, if the second identity credential AUTHe is KDF(PSK, NONCEa), the first node uses KDF to obtain a check value check2=KDF(PSK, NONCEa) based on PSK and the second fresh parameter NONCEa. If the check value check2 is the same as AUTHe, the verification is successful. If the check value check2 is different from AUTHe, the verification fails.
[0384] Optionally, before or after verifying the second identity authentication information based on the shared key, the first node performs a message integrity check on the first authentication response to prevent the content of the first authentication response from being tampered with by an attacker. Specifically, the first authentication response includes second integrity check data, so that the first node may perform a message integrity check on the first authentication response based on the second integrity check data.
[0385] Optionally, if the message integrity check performed on the first authentication response fails, the first node may update the number of integrity check failures of the second node. The number of integrity check failures may then be used to determine whether the identity of the second node is trusted. Furthermore, optionally, there may be two cases in which the first node updates the number of integrity check failures of the second node:
[0386] Case 1: The first node uses a first authentication failure counter to indicate the number of verification failures of the second node. The verification to the second node includes a message integrity check and an identity authentication. Thus, if the message integrity check on the first authentication response fails or the identity authentication to the second node fails, the first node may increment the first authentication failure counter by one. The first authentication failure counter may then be used to determine whether the identity of the second node is trusted.
[0387] Case 2: The first node uses a first integrity check counter to indicate the number of integrity check failures of the second node. If the message integrity check on the first authentication response fails, the first node may increment the first integrity check counter by 1. The first integrity check counter may then be used to determine whether the identity of the second node is trusted.
[0388] Step S308: If the verification on the second identity authentication information performed by the first node fails, the first node updates a first authentication failure counter.
[0389] Specifically, the first authentication failure counter indicates the number of verification failures of the second node. For example, if verification of the second identity credential fails, the first authentication failure counter may be incremented by 1, and the number of verification failures may then be used to determine whether the identity of the second node is trusted.
[0390] Optionally, the association control method of this embodiment of this application may further include step S501 shown in Figures 5A, 5B and 5C. Step S501 is specifically as follows:
[0391] Step S501: If the value of a first authentication failure counter exceeds a first threshold, the first node adds an identifier of the second node to a first blacklist.
[0392] Specifically, the first authentication failure counter is used to indicate the number of verification failures of the second node, and the value exceeding the first threshold may be equal to or greater than the first threshold. When the value of the first authentication failure counter exceeds the first threshold, it indicates that the first node has not been verified multiple times. Therefore, the second node may be an attacker that frequently sends association requests, and the identifier of the second node is added to the first blacklist. After the identifier of the second node is added to the first blacklist, the identity of the second node is not determined to be trusted, which prevents the node from establishing an association with an unauthenticated attacker, and improves the data security of the node. It is understood that the identifier of a node cannot be in both the first blacklist and the first whitelist. Therefore, when the identifier of the second node is added to the first blacklist, if the identifier of the second node is in the first whitelist, the identifier of the first node needs to be removed from the first whitelist.
[0393] Optionally, the validity period of the first blacklist is a predefined or preset first duration, for example, the first duration of the blacklist may be 20 days, and the identifier of the second node may be removed from the blacklist 20 days after being added to the first blacklist.
[0394] Optionally, if the duration for which the identifier of the second node is added to the first blacklist exceeds a first duration, the identifier of the second node is removed from the first blacklist. The first duration is related to the number of times the identifier of the second node is added to the first blacklist and the device type of the second node. Specifically, the validity period of the first blacklist may be related to the number of times the second node is added to the first blacklist. A larger number of times the second node is added to the first blacklist indicates a longer duration of the second node in the first blacklist. Furthermore, optionally, after the number of times the second node is added to the first blacklist exceeds a certain value (e.g., exceeds 10 times), the second node may be permanently added to the first blacklist and cannot be removed. Additionally, the validity period of the first blacklist may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be regarded as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here.
[0395] It should be noted that in this application, the number of specific device types is not limited. Based on actual requirements, multiple types of devices may be defined, and corresponding blacklists and blacklist validity periods may be set. Specifically, the first blacklist may alternatively include multiple groups of blacklists, and these groups are used to perform more specific and sophisticated device management, respectively.
[0396] Optionally, the association control method of this embodiment of this application may further include step S502 shown in Figures 5A, 5B and 5C. Step S502 is specifically as follows:
[0397] Step S502: If the verification for the first identity authentication information is successful, the first node sends a first association response to the second node.
[0398] Specifically, after it is determined that the identity of the second node is trusted, if the identity authentication is successful, the first node may send a first association response to the second node. The first association response is used to indicate that the first node establishes an association with the second node. Furthermore, the first response message may be used to inform the second node that the association is successful and communication may be performed.
[0399] Optionally, the association control method of this embodiment of the present application may further include step S503 or step S504 shown in FIG. 5A, FIG. 5B, and FIG. 5C. S 503 and Step S The method may further include step 504. S 503 and Step S Specifically, 504 is as follows:
[0400] Step S503: If the verification for the first identity authentication information fails, the first node updates a second authentication failure counter.
[0401] Specifically, the second authentication failure counter indicates the number of verification failures of the first node. If verification of the identity credentials of the first node fails, the value of the second authentication failure counter may be incremented by 1. The second authentication failure counter may then be used to determine whether the identity of the first node is trusted.
[0402] Step S504: If the value of the second authentication failure counter exceeds a second threshold, the second node adds the identifier of the first node to a second blacklist.
[0403] Specifically, if the number of verification failures of the first node exceeds a preset second threshold, it indicates that the first node has not been verified multiple times. Thus, the first node may be an attacker that frequently sends authentication requests, and the identifier of the first node is added to the second blacklist. After the identifier of the first node is added to the second blacklist, the identity of the first node is not determined to be trusted, which prevents the second node from establishing an association with an unauthenticated attacker, and improves the data security of the second node. It is understood that the identifier of the first node cannot be in both the second blacklist and the second whitelist. Thus, if the identifier of the first node is in the second whitelist when the identifier of the first node is added to the second blacklist, the identifier of the first node is not determined to be trusted. 2 The identifier of the first node needs to be removed from the whitelist of
[0404] Optionally, the validity period of the second blacklist is a predefined or preset second duration. The second duration may be considered as the validity period of the blacklist. For example, the second duration of the second blacklist may be 10 days, and the identifier of the first node may be removed from the second blacklist 10 days after being added to the second blacklist.
[0405] Optionally, the second duration is related to at least one of the number of times the identifier of the first node is added to the second blacklist or the type of the first node. The validity period of the second blacklist may be related to the number of times the first node is added to the blacklist. A larger number of times the node is added to the second blacklist indicates a longer duration of the first node in the second blacklist. Furthermore, optionally, after the number of times the identifier of the first node is added to the second blacklist exceeds a certain value (e.g., exceeds 15 times), the first node may be permanently added to the first blacklist and cannot be removed. Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be regarded as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. In addition, the second node may further predefine a blacklist validity period corresponding to the first node. The details will not be described again here.
[0406] Optionally, the second node may send a second association request to the first node when it determines that the value of the second authentication failure counter is less than a second threshold. Specifically, in the process of verifying the identity authentication information, some parameters may be lost or erroneously transmitted in the transmission process, so that the verification of the identity authentication information may also fail. Therefore, if the number of verification failures of the first node does not exceed the preset second threshold, the association request may be resent to the first node to request to establish an association with the first node. In this way, the robustness of the system is improved and the stable operation of the service provided by the node is ensured.
[0407] Optionally, the second node may obtain a third acknowledgement indication information before sending the second association request. The third acknowledgement indication information may be an indication information obtained based on an acknowledgement action input by a user, and the acknowledgement action may be an acknowledgement of the output prompt information. For example, the second node may output prompt information to remind the user that the verification has failed and the association request needs to be initiated again. The second node sends the second association request to the first node after receiving the user acknowledgement action and obtaining the third acknowledgement indication information. In this way, the user verifies the identity of the first node with which association is required again, so that association with an untrusted node is avoided and communication security is guaranteed.
[0408] In the embodiment shown in Fig. 3 or Fig. 5A, Fig. 5B, and Fig. 5C, after the identity of the second node is determined to be trusted, the identity of the second node is verified based on the shared key shared with the second node. In this way, even if an attacker avoids the "determining that the identity is trusted" step by modifying the identifier, the identity authentication performed by the first node against the attacker still cannot succeed because it is difficult to forge identity authentication information. Thus, the node is prevented from establishing an association with an unauthenticated attacker, and the data security of the node is improved.
[0409] Additionally, if the validation fails, the number of validation failures is updated. The number of validation failures may be used to later determine whether the identity of the second node is trusted, such that a node that has not been validated multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, the association requests of the node (e.g., sending authentication requests) may no longer be processed, preventing the node from stalling due to processing a large number of requests and ensuring the normal operation of the service.
[0410] 6A, 6B and 6C are schematic flowcharts of an association control method according to an embodiment of this application. The association control method may be implemented based on the architecture shown in Fig. 1. The method includes, but is not limited to, the following steps:
[0411] Step S601: The second node determines that the identity of the first node is trusted.
[0412] For more details, please see the related explanation of S301.
[0413] Step S602: The second node sends a first association request to the first node.
[0414] For more details, please see the related explanation of S302.
[0415] Step S603: The first node determines that the identity of the second node is trusted.
[0416] For more details, please see the related explanation of S303.
[0417] Step S604: The first node sends a first authentication request to the second node.
[0418] Specifically, the first authentication request includes first integrity check data, etc. The first integrity check data is check data generated according to a key and an integrity protection algorithm, and is used by the second node to perform a message integrity check on the first authentication request. During a specific implementation, the check data may also be referred to as a message authentication code (MAC).
[0419] For example, the first integrity check data MAC1 may be obtained according to a Cipher-based Message Authentication Code (CMAC) algorithm using the shared key K1 and some or all of the non-MAC1 data data1 of the first authentication request, e.g., MAC1=CMAC(K1, data1).
[0420] Optionally, the first authentication request may include a first identity credential. The first identity credential is generated by the first node based on a shared key between the first node and the second node. The shared key may be a pre-shared key between the first node and the second node. For example, the first node may generate the first identity credential AUTHa based on the pre-shared key PSK using the KDF. That is, AUTHa=KDF(PSK).
[0421] Optionally, when the first association request includes the first freshness parameter, the first identity credential may be generated by the first node based on the shared key and the first freshness parameter. For example, the first node uses the KDF to generate the first identity credential AUTHa based on the pre-shared key PSK and the first freshness parameter NONCEe. For example, AUTHa = KDF (PSK, NONCEe). Furthermore, optionally, the parameters used by the first node to generate the first identity credential during the actual processing may further include other information. For example, the generated first identity credential AUTHa may satisfy AUTHa = KDF (PSK, first association request). Further, optionally, when the first authentication request includes a second freshness parameter, the first identity authentication information AUTHa generated by the first node may further satisfy AUTHa=KDF(PSK, NONCEa, first association request), where NONCEa is the second freshness parameter of the first authentication request.
[0422] Step S605: The second node performs a message integrity check on the first authentication request.
[0423] Specifically, the first authentication request may include first integrity check data, and the second node may perform a message integrity check on the first authentication request based on the first integrity check data to prevent the contents of the first authentication request from being tampered with by an attacker.
[0424] In a possible solution, the first node generates the first integrity check data in a certain way, so that the second node also generates a check value in the same manner. If the generated check value is the same as the first integrity check data, the message integrity check is successful. For example, if the first integrity check data MAC1 is obtained by the first node according to the CMAC algorithm using the shared key K1 and part or all of the data data1 that is not MAC1 of the first authentication request, the second node generates a check value check3 in the same manner, i.e., check3=CMAC(K1,data1). If check3 is the same as MAC1, it indicates that the data1 of the first authentication request has not been tampered with, and the integrity check for the first authentication request is successful.
[0425] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S606, which is specifically as follows:
[0426] Step S606: If the message integrity check for the first authentication request fails, the second node updates a second authentication failure counter.
[0427] Specifically, the second node may use a second authentication failure counter to indicate the number of verification failures of the first node. Thus, if the message integrity check for the first authentication request fails, the second node may increment the value of the second authentication failure counter by one. The second authentication failure counter may then be used to determine whether the identity of the first node is trusted.
[0428] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S607, which is specifically as follows:
[0429] Step S607: If the value of the second authentication failure counter exceeds a second threshold, the second node adds the identifier of the first node to a second blacklist.
[0430] Specifically, the second authentication failure counter may indicate a number of verification failures for the first node, the value of which may be greater than or equal to the second threshold. If the number of message integrity check failures for the first authentication request exceeds the second threshold, it may indicate that the message from the first node may have been tampered with multiple times by an attacker or may originally contain incorrect data. Thus, the identifier of the first node may be added to a second blacklist to prevent the second node from establishing an association with an unauthenticated attacker and improve data security for the second node.
[0431] Optionally, the second node may send a second association request to the first node when it determines that the value of the second authentication failure counter is less than or equal to the second threshold. Further, optionally, the second node may obtain third acknowledgement indication information before sending the second association request. The third acknowledgement indication information may be indication information obtained based on an acknowledgement action input by a user, and the acknowledgement action may be an acknowledgement of the output prompt information. For example, the second node may output prompt information to remind the user that the verification has failed and the association request needs to be initiated again. The second node sends the second association request to the first node after receiving the user acknowledgement action and obtaining the third acknowledgement indication information. In this way, the user verifies the identity of the first node with which association is required again, and as a result, association with an untrusted node is avoided and communication security is guaranteed.
[0432] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S608, which is specifically as follows:
[0433] Step S608: The second node performs verification on the first identity authentication information based on the shared key between the second node and the first node.
[0434] For more details, please see the related explanation of S305.
[0435] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S609, which is specifically as follows:
[0436] Step S609: If the verification for the first identity authentication information fails, the first node updates a second authentication failure counter.
[0437] Specifically, the second authentication failure counter indicates the number of verification failures of the first node. If verification of the identity credentials of the first node fails, the value of the second authentication failure counter may be incremented by 1. The second authentication failure counter may then be used to determine whether the identity of the first node is trusted.
[0438] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S610, which is specifically as follows:
[0439] Step S610: If the value of the second authentication failure counter exceeds a second threshold, the second node adds the identifier of the first node to a second blacklist.
[0440] Specifically, the second authentication failure counter indicates the number of verification failures of the first node, and the value exceeding the second threshold may be equal to or greater than the second threshold. If the value of the second authentication failure counter exceeds the second threshold, it indicates that the first node has not been verified multiple times. Therefore, the first node may be an attacker that frequently sends authentication requests, and the identifier of the first node is added to the second blacklist. After the identifier of the first node is added to the second blacklist, the identity of the first node is not determined to be trusted, which prevents the second node from establishing an association with an unauthenticated attacker, and improves the data security of the node.
[0441] Optionally, the second node may send a second association request to the first node when it determines that the value of the second authentication failure counter is less than the second threshold. Further, optionally, the second node may obtain third acknowledgement indication information before sending the second association request. The third acknowledgement indication information may be indication information obtained based on an acknowledgement action input by a user, and the acknowledgement action may be an acknowledgement of the output prompt information. For example, the second node may output the third prompt information to remind the user that the identity authentication to the first node has failed and the association request needs to be initiated again. The second node sends the second association request to the first node after receiving the user acknowledgement action and obtaining the third acknowledgement indication information. In this way, the user verifies the identity of the first node with which association is required again, and as a result, association with an untrusted node is avoided and communication security is guaranteed.
[0442] Optionally, in a specific implementation process, the second node may first perform the operation of S608 or the operations of S608 to S610, and then perform the operation of S605 or the operations of S605 to S607. In other words, the second node may first perform verification on the first identity authentication information based on the shared key, and then perform a message integrity check on the first authentication request.
[0443] Step S611: The second node sends a first authentication response to the first node.
[0444] Specifically, the first authentication response may further include second integrity check data, etc. The second integrity check data is check data generated according to a symmetric key and an integrity protection algorithm, and is used by the first node to perform a message integrity check on the first association request. During a specific implementation, the check data may also be called a message authentication code (MAC). For example, the second integrity check data MAC2 may be obtained according to a CMAC algorithm using a shared key K1 and a part or all of the data data2 that is not MAC2 of the first authentication response. For example, MAC=CMACK(K1, data2).
[0445] Optionally, if a message integrity check on the first authentication request is successful, the second node sends a first authentication response to the first node. Further, optionally, if a message integrity check on the first authentication request is successful and a verification on the first identity authentication information performed by the second node is successful, the first authentication response is sent to the first node.
[0446] Optionally, the first authentication response may include a second identity credential. The second identity credential is generated by the second node based on a shared key between the second node and the first node. The shared key may be a pre-shared key PSK between the first node and the second node. For example, the second node may use a KDF to generate the second identity credential AUTHe based on the pre-shared key PSK. For example, AUTHe=KDF(PSK).
[0447] Optionally, when the first authentication request includes a second fresh parameter, a second identity credential may be generated by the second node based on the shared key and the second fresh parameter. For example, the second node uses the KDF to generate a second identity credential AUTHe based on the pre-shared key PSK and the second fresh parameter NONCEa. For example, AUTHe=KDF(PSK, NONCEa). Furthermore, optionally, the parameters used by the second node to generate the second identity credential during the actual processing may further include other information. For example, the generated second identity credential AUTHe may satisfy AUTHe=KDF(PSK, second association request). Further, optionally, when the first association request may further include a first freshness parameter, the second identity authentication information AUTHe generated by the second node may further satisfy AUTHe=KDF(PSK, NONCEe, first authentication request), where NONCEe is the first freshness parameter of the first association request.
[0448] Step S612: The first node performs a message integrity check on the first authentication response.
[0449] Specifically, the first authentication response may include second integrity check data, and the first node may perform a message integrity check on the first authentication response based on the second integrity check data to prevent the contents of the first authentication response from being tampered with by an attacker.
[0450] In a possible solution, the second node generates the second integrity check data in a specific way, so that the first node also generates a check value in the same manner. If the generated check value is the same as the second integrity check data, the message integrity check is successful. For example, if the second integrity check data MAC2 is obtained by the second node according to the CMAC algorithm using the shared key K1 and some or all of the data data2 that is not MAC2 of the first authentication response, the second node generates a check value check4 in the same manner, i.e., check4=CMAC(K1,data2). If check4 is the same as MAC2, it indicates that data2 of the first authentication response has not been tampered with, and the integrity check on the first authentication response is successful.
[0451] Step S613: If the message integrity check on the first authentication response fails, the first node updates a first authentication failure counter.
[0452] Specifically, the first node may use a first authentication failure counter to indicate the number of validation failures of the second node. Thus, if a message integrity check on the first authentication response fails, the first node may increment the value of the first authentication failure counter by one. The first authentication failure counter may then be used to determine whether the identity of the second node is trusted.
[0453] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S614, which is specifically as follows:
[0454] Step S614: If the value of the first authentication failure counter exceeds a first threshold, the first node adds the identifier of the second node to a first blacklist.
[0455] Specifically, the first authentication failure counter indicates a number of verification failures of the second node, and the value exceeding the first threshold may be equal to or greater than the first threshold. If the value of the first authentication failure counter exceeds the first threshold, it may indicate that messages from the second node may have been tampered with multiple times by an attacker or may originally be incorrect data. Thus, an identifier of the second node is added to a first blacklist to prevent the first node from establishing associations with unauthenticated attackers and improve data security of the node.
[0456] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S615, which is specifically as follows:
[0457] Step S615: The first node performs verification on the second identity authentication information based on the shared key.
[0458] For more details, please see the related explanation of S307.
[0459] Optionally, the association control method shown in Figures 6A, 6B and 6C further includes step S616 or step S616 and step S617. Steps S616 and S617 are specifically as follows:
[0460] Step S616: If the message integrity check on the first authentication response fails, the first node updates a first authentication failure counter.
[0461] For more details, please see the related explanation of S308.
[0462] Step S617: If the value of the first authentication failure counter exceeds the first threshold, the first node adds the identifier of the second node to a first blacklist.
[0463] For more details, please see the related explanation of S501.
[0464] Optionally, in a specific implementation process, the first node may first perform the operation of S615 or the operations of S615 to S617, and then perform the operation of S612 or the operations of S612 and S613. In other words, the first node may first perform verification on the second identity authentication information based on the shared key, and then perform a message integrity check on the first authentication response.
[0465] Optionally, the association control method shown in FIGS. 6A, 6B and 6C further includes step S618, which is specifically as follows:
[0466] Step S618: The first node sends a first association response to the second node.
[0467] Specifically, the first association response is used to indicate that the first node will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and communication may be performed.
[0468] Optionally, if a message integrity check on the first authentication response is successful, the first node sends a first association response to the second node. Further, optionally, if a message integrity check on the first authentication response is successful and a verification on the first identity authentication information performed by the first node is successful, the first node sends a first association response to the second node.
[0469] In the embodiment shown in Figures 6A, 6B, and 6C, after it is determined that the identity of the second node is trusted, a message integrity check must still be performed on the authentication response message from the second node before the association is performed. If the message integrity check fails, the number of verification failures is updated. The number of verification failures may be used to subsequently determine whether the identity of the second node is trusted, so that an attacker may be prevented from tampering with data in the authentication process. This prevents the node from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0470] The above describes the method of the embodiment of this application in detail. The following provides the apparatus of the embodiment of this application.
[0471] 7 is a schematic diagram of the structure of an association control device 70 according to one embodiment of this application. The device 70 may be a node or a component such as a chip or integrated circuit in a node. The device 70 may include a communication unit 701 and a processing unit 702. The description of the units is as follows:
[0472] The communication unit 701 is configured to receive a first association request from a second node.
[0473] The processing unit 702 is configured to determine that the identity of the second node is trusted and to send a first authentication request to the second node using the communication unit 701. The first authentication request includes first identity authentication information, and the first identity authentication information is generated based on a shared key between the first node and the second node.
[0474] The communication unit 701 is further configured to receive a first authentication response from the second node, the first authentication response including the second identity authentication information.
[0475] The processing unit 702 is further configured to perform verification on the second identity credential based on the shared key.
[0476] The processing unit 702 is further configured to update a first authentication failure counter when the verification for the second identity credential fails. The first authentication failure counter indicates a number of verification failures for the second node.
[0477] In this embodiment of the application, the device 70 verifies the identity of the second node based on a shared key shared with the second node after determining that the identity of the second node is trusted. In this way, even if an attacker avoids the step of determining that the identity is trusted by the device 70 by modifying the identifier, the identity authentication performed by the device against the attacker still cannot be successful because it is difficult to forge identity authentication information. Thus, the device is prevented from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0478] Furthermore, if the verification fails, the device 70 updates the number of verification failures. The number of verification failures may be used to later determine whether the identity of the second node is trusted, so that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, the device 70 may no longer process association requests for the node (e.g., sending authentication requests), preventing the device 70 from stalling due to processing a large number of requests and ensuring normal operation of the service.
[0479] It should be noted that the division into the above-mentioned units is merely a logical division based on functions, and is not used as a limitation to a specific structure of the device 70. In a specific implementation, some functional modules may be subdivided into smaller functional modules, or some functional modules may be combined into one functional module. However, regardless of whether these functional modules are subdivided or combined, the procedures performed by the device 70 in the association control process are almost the same. For example, the communication unit 701 may alternatively be transformed into a receiving unit and a transmitting unit. The receiving unit is configured to implement the message receiving function of the communication unit 701, and the transmitting unit is configured to implement the message sending function of the communication unit 701. Typically, each unit corresponds to the program code (or program instructions) of the unit. When the program code corresponding to the unit runs on the processor, the unit is able to execute the corresponding procedure to implement the corresponding function.
[0480] In some implementations, the processing module 702 specifically: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method is configured to obtain first acknowledgment indication information, the first acknowledgment indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0481] The device 70 controls the nodes that request association based on a blacklist or whitelist, so that identity authentication does not need to be performed for untrusted second nodes. This can prevent outages due to processing a large number of requests and ensure normal operation of the service. Additionally, the device does not establish associations with nodes that do not undergo identity authentication, which prevents the device 70 from establishing associations with unauthenticated attackers and improves data security of the device 70.
[0482] In some implementations, the processing unit specifically: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is configured to obtain first acknowledgment indication information if the identifier of the second node is not on a first blacklist, a type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgment indication information indicates that the identity of the second node is trusted.
[0483] In yet another possible implementation, the first authentication response further includes second integrity check data, which is used to perform a message integrity check on the first authentication response.
[0484] Specifically, the processing unit 702 includes: and determining that a message integrity check on the first authentication response was successful.
[0485] It can be seen that after it is determined that the identity of the second node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the second node and ensures the stable operation of the service provided by the device.
[0486] In yet another possible implementation, the processing unit 702 may: The node is further configured to determine that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0487] It can be seen that a first association threshold is preset in the device. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the device. When the first association threshold is exceeded, the device may no longer receive or process association requests, without affecting the communication between the device and another node associated with the device, and ensuring the stable operation of the service provided by the device.
[0488] In yet another possible implementation, the communication unit 701 comprises: and further configured to send a first association response to the second node if the verification against the second identity authentication information is successful, the first association response being used to indicate that the first node establishes an association with the second node.
[0489] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and that communication may be performed.
[0490] In yet another possible implementation, the processing unit 702 may: The method is further configured to reset the first association failure counter if the second identity credential is successfully verified.
[0491] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset, to avoid affecting subsequent determination of the identity of the second node and to ensure stable operation of the service provided by the device.
[0492] In yet another possible implementation, the processing unit 702 may: The device is further configured to determine that a value of the first authentication failure counter is greater than or equal to a first threshold and to add an identifier of the second node to a first blacklist.
[0493] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker that frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the device from establishing an association with an unauthorized attacker and improves the data security of the node.
[0494] In yet another implementation, the validity period of the first blacklist is a predefined or preset first duration.
[0495] It is understood that the predefined or preset first duration in the first blacklist may be considered as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0496] In yet another possible implementation, the processing unit 702 may: removing the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0497] The above implementation describes factors related to the lifetime of the first blacklist. The lifetime of the first blacklist may be related to the number of times the second node has been added to the first blacklist. A greater number of times the second node has been added to the first blacklist indicates a longer duration of the second node on the first blacklist. Furthermore, optionally, the second node may be permanently added to the first blacklist after the number of times the second node has been added to the first blacklist exceeds a threshold.
[0498] Additionally, the validity period of the first blacklist may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include high-risk devices or low-risk devices. If the second node belongs to a microphone, sounder, etc., the second node may be considered as a low-risk device. If the second node belongs to a mobile phone, computer, etc., the second node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here. The number of device types is not specifically limited in this application and may be designed based on a specific scenario.
[0499] In yet another possible implementation, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0500] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting device resources and affecting successful association with another node.
[0501] Please note that for the implementation of each unit, please refer to the corresponding description of the embodiment shown in Figure 3 or Figure 5A, Figure 5B, and Figure 5C. The device 70 may be the first node of the embodiment shown in Figure 3 or Figure 5A, Figure 5B, and Figure 5C.
[0502] 8 is a schematic diagram of the structure of an association device 80 according to an embodiment of this application. The device 80 may be a node, or a component such as a chip or integrated circuit in a node. The device 80 may include a processing unit 801 and a communication unit 802. The description of the units is as follows:
[0503] The processing unit 801 is configured to determine that the identity of a first node is trusted and to send, using the communication unit 802, a first association request to said first node.
[0504] The communication unit 802 is further configured to receive a first authentication request from the first node, the first authentication request including the first identity authentication information.
[0505] The processing unit 801 is further configured to perform verification on the first identity credential based on a shared key between the second node and the first node.
[0506] The communication unit 802 is further configured to send a first authentication response to the first node if the verification on the first identity credential is successful, the first authentication response including the second identity credential, the second identity credential being generated based on the shared key.
[0507] In this embodiment of the application, after determining that the identity of the first node is trusted, the device sends a first association request to the first node. Then, using the shared key, a verification is performed on the identity authentication information of the first node based on the first identity authentication information in the first authentication request. After the verification is successful, a second identity authentication information is sent to the first node. The second identity authentication information may be used by the first node to verify the identity of the device. It can be seen that after the identity is determined to be trusted, the association can be performed only after the identity authentication of both parties is successful. Thus, it is difficult for an attacker to avoid the identity authentication performed by the attacker's second node by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0508] It should be noted that the division of the above-mentioned units is merely a logical division based on functions, and is not used as a limitation on a specific structure of the device 80. In a specific implementation, some functional modules may be subdivided into smaller functional modules, or some functional modules may be combined into one functional module. However, regardless of whether these functional modules are subdivided or combined, the procedures performed by the device 80 in the association control process are almost the same. For example, the communication unit 802 may alternatively be transformed into a receiving unit and a transmitting unit. The receiving unit is configured to implement the message receiving function of the communication unit 802, and the transmitting unit is configured to implement the message sending function of the communication unit 802. Typically, each unit corresponds to the program code (or program instructions) of the unit. When the program code corresponding to the unit runs on the processor, the unit is able to execute the corresponding procedure to implement the corresponding function.
[0509] In some implementations, the processing module 801 specifically: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or and obtaining second acknowledgment indication information, the second acknowledgment indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0510] In the above method, associated nodes may be controlled using a blacklist or whitelist, and the device may be controlled not to send association requests to untrusted first nodes, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0511] In some implementations, the processing module 801 specifically: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or and if the identifier of the first node is not on a second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on a second whitelist, obtain second acknowledgement indication information, the second acknowledgement indication information indicating that the identity of the second node is trusted.
[0512] In yet another possible implementation, the first authentication request further includes first integrity check data, where the first integrity check data is used to perform a message integrity check on the first authentication request.
[0513] The processing unit 801 includes: The method is further configured to determine that a message integrity check on the first authentication request is successful.
[0514] It can be seen that after it is determined that the identity of the first node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the first node and ensures the stable operation of the service provided by the device.
[0515] In yet another possible implementation, the processing unit 801 may: The node is further configured to determine that a second number of associations is less than or equal to a preset second association threshold, the second number of associations indicating a number of currently associated nodes.
[0516] It can be seen that a second association threshold is preset in the device. An association request may be sent to the first node only when the associated node is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that can be associated with the device. When the second association threshold is exceeded, the device cannot be associated with another node, which does not affect the communication between the device and another node associated with the device and ensures the stable operation of the service provided by the device.
[0517] In yet another possible implementation, the communication unit 802 includes: and further configured to receive a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0518] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the device will receive a first association response from the first node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may inform the device that the association is successful and subsequent communication may be performed.
[0519] In yet another possible implementation, the processing unit 801 may: Further configured to reset a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0520] It can be seen that if identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset, to avoid affecting subsequent determination of the identity of the first node and to ensure stable operation of the service provided by the device.
[0521] In yet another possible implementation, the processing unit 801 may: and further configured to update a second authentication failure counter if verification fails for the first identity credential, the second authentication failure counter indicating a number of verification failures for the first node.
[0522] If the verification for the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the attacker's first node by modifying the identity such as an identifier, preventing the device from establishing an association with an unauthorized attacker and improving data security of the device.
[0523] In yet another possible implementation, the processing unit 801 may: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; The node is further configured to add the identifier of the first node to the second blacklist.
[0524] If the number of failed verifications of the first node exceeds a preset first threshold, indicating that the first node has not been verified multiple times, it is found that the first node may be an attacker who frequently sends association requests. Thus, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0525] In yet another implementation, the validity period of the second blacklist is a predefined or preset second duration.
[0526] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0527] In yet another possible implementation, the processing unit 801 is further configured to determine that the value of the second authentication failure counter is less than a second threshold.
[0528] The communication unit 802 is further configured to send a second association request to the first node.
[0529] If the verification of the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the first node by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthorized attacker and improves data security of the node.
[0530] In yet another possible implementation, the processor: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and transmitting a second association request to the first node.
[0531] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0532] In yet another possible implementation, the processor: and further configured to remove the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to at least one of the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0533] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Additionally, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0534] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be considered as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the second node may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here. In yet another possible implementation, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0535] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0536] Please note that for the implementation of each unit, please refer to the corresponding description of the embodiment shown in Figure 3 or Figure 5A, Figure 5B, and Figure 5C. The device 80 may be a second node of the embodiment shown in Figure 3 or Figure 5A, Figure 5B, and Figure 5C.
[0537] 9 is a schematic diagram of a structure of a communication device according to an embodiment of this application. The communication device 90 may be a node or a component such as a chip or integrated circuit in a node. The device 90 may include at least one memory 901 and at least one processor 902. Optionally, the device may further include a bus 903. Optionally, the device may further include a communication interface 904. The memory 901, the processor 902, and the communication interface 904 are connected via the bus 903.
[0538] The memory 901 is configured to provide a storage space, which may store data, such as an operating system and computer programs, and may be one or a combination of random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).
[0539] The processor 902 is a module that performs arithmetic and / or logical operations, and may be one or a combination of processing modules such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), and a complex programmable logic device (CPLD).
[0540] The communication interface 904 is configured to receive data transmitted from the outside and / or transmit data to the outside, and may be a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, Universal Wireless Transmission, etc.). Optionally, the communication interface 1104 may include a transmitter (e.g., a radio frequency transmitter or antenna), a receiver, etc. coupled to the interface.
[0541] The processor 902 in the device 90 is configured to read the computer program stored in the memory 901 and execute the aforementioned association control method, for example the association control method described in Figure 3 or Figures 5A, 5B, and 5C.
[0542] For example, the processor 902 in the device 90 reads a computer program stored in the memory 901 and executes the following: receiving a first association request from a second node via the communication interface 904; determining that the identity of the second node is trusted and sending a first authentication request to the second node via the communication interface 904, the first authentication request including first identity authentication information, the first identity authentication information being generated based on a shared key between the first node and the second node, the shared key being considered as a first secret value shared between the first node and the second node; receiving a first authentication response from the second node via the communication interface 904, the first authentication response including second identity authentication information; performing verification on a second identity credential based on the shared key; and if the verification for the second identity credential fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of verification failures for the second node.
[0543] In this embodiment of the application, the device 90 verifies the identity of the second node based on a shared key shared with the second node after determining that the identity of the second node is trusted. In this way, even if an attacker avoids the step of determining that the identity is trusted by the device 90 by modifying the identifier, the identity authentication performed by the device 90 against the attacker still cannot be successful because it is difficult to forge identity authentication information. Thus, the device 90 is prevented from establishing an association with an unauthenticated attacker, and the data security of the device 90 is improved.
[0544] Furthermore, if the verification fails, the device 90 updates the number of verification failures. The number of verification failures may be used to later determine whether the identity of the second node is trusted, so that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, the device 90 may no longer process association requests for the node (e.g., sending authentication requests), preventing the device 90 from stalling due to processing a large number of requests and ensuring normal operation of the service.
[0545] In some implementations, the processing module 902 specifically: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method is configured to obtain first acknowledgment indication information, the first acknowledgment indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0546] The device 90 controls the nodes that request association based on a blacklist or whitelist, so that identity authentication does not need to be performed for an untrusted second node. This can prevent outages due to processing a large number of requests and ensure normal operation of the service. Additionally, the device does not establish associations with nodes that do not undergo identity authentication, which prevents the device 90 from establishing associations with unauthenticated attackers and improves data security for the device 90.
[0547] In some implementations, the processor 902 specifically: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is configured to obtain first acknowledgment indication information if the identifier of the second node is not on a first blacklist, a type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgment indication information indicates that the identity of the second node is trusted.
[0548] In yet another possible implementation, the first authentication response further includes second integrity check data, which is used to perform a message integrity check on the first authentication response.
[0549] The processor 902 is further configured to determine that a message integrity check on the first authentication response is successful.
[0550] It can be seen that after it is determined that the identity of the second node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the second node and ensures the stable operation of the service provided by the device 90.
[0551] In yet another possible implementation, the processor 902 may: The node is further configured to determine that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0552] It can be seen that a first association threshold is preset in the device 90. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the node. When the first association threshold is exceeded, the device 90 may no longer receive or process association requests, which does not affect the communication between the device 90 and another node associated with the device, and ensures the stable operation of the service provided by the device 90.
[0553] In yet another possible implementation, the processor 902 may: If the verification against the second identity authentication information is successful, it is further configured to send a first association response to the second node via the communication interface 904, where the first association response is used to indicate that the first node establishes an association with the second node.
[0554] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate to the device 90 that it will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and that communication may be performed.
[0555] In yet another possible implementation, the processor 902 may: The method is further configured to reset the first association failure counter if the second identity credential is successfully verified.
[0556] It can be seen that if identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset to avoid affecting subsequent determinations of the identity of the second node and to ensure stable operation of the service provided by device 90.
[0557] In yet another possible implementation, the processor 902 may: The device is further configured to determine that a value of the first authentication failure counter is greater than or equal to a first threshold and to add an identifier of the second node to a first blacklist.
[0558] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker that frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the device 90 from establishing an association with an unauthorized attacker and improves the data security of the device 90.
[0559] In yet another implementation, the validity period of the first blacklist is a predefined or preset first duration.
[0560] It is understood that the predefined or preset first duration in the first blacklist may be considered as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0561] In yet another possible implementation, the processor 902 may: removing the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0562] The above implementations account for factors related to the lifetime of the blacklist. The lifetime of the blacklist may be related to the number of times the second node has been added to the blacklist. A greater number of times the second node has been added to the blacklist indicates a longer duration of the second node on the blacklist. Additionally, optionally, the second node may be permanently added to the blacklist after the number of times the second node has been added to the blacklist exceeds a threshold.
[0563] Additionally, the blacklist validity period may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be regarded as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the device 90 may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here.
[0564] In yet another possible implementation, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0565] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting resources of device 90 and avoiding affecting successful association with another node.
[0566] Please note that for the specific implementation of each unit, please refer to the corresponding description of the embodiment shown in Figure 3 or Figure 5A, Figure 5B, and Figure 5C. The communication device 90 may be the first node of the embodiment shown in Figure 3 or Figure 5A, Figure 5B, and Figure 5C.
[0567] 10 is a schematic diagram of a structure of a communication device 100 according to an embodiment of this application. The communication device 100 may be a node or a component such as a chip or integrated circuit in a node. The device 100 may include at least one memory 1001 and at least one processor 1002. Optionally, the device may further include a bus 1003. Optionally, the device may further include a communication interface 1004. The memory 1001, the processor 1002, and the communication interface 1004 are connected via the bus 1003.
[0568] The memory 1001 is configured to provide a storage space, which may store data such as an operating system and computer programs. The memory 1001 may be one or a combination of RAM, ROM, EPROM, CD-ROM, etc.
[0569] The processor 1002 is a module that executes arithmetic and / or logical operations, and may specifically be one or a combination of processing modules such as a CPU, a GPU, an MPU, an ASIC, an FPGA, and a CPLD.
[0570] The communication interface 1004 is configured to receive data transmitted from an external source and / or transmit data to an external source, and may be a wired link interface, such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, etc.). Optionally, the communication interface 1104 may include a transmitter (e.g., a radio frequency transmitter or antenna), a receiver, etc. coupled to the interface.
[0571] The processor 1002 in the device 100 is configured to read a computer program stored in the memory 1001 and execute the aforementioned association control method, for example the association control method described in Figure 3 or Figures 5A, 5B, and 5C.
[0572] For example, the processor 1002 in the device 100 reads a computer program stored in the memory 1001 and executes the following: determining that an identity of a first node is trusted and sending a first association request to the first node; receiving a first authentication request from a first node, the first authentication request including first identity authentication information; performing verification on the first identity authentication information based on a shared key between the second node and the first node, the shared key being a secret value shared between the first node and the second node; and configured to perform an operation of: sending a first authentication response to the first node if verification on the first identity credential is successful, the first authentication response including the second identity credential, the second identity credential generated based on the shared key.
[0573] In this embodiment of the application, after determining that the identity of the first node is trusted, the device 100 sends a first association request to the first node. Then, using the shared key, a verification is performed on the identity authentication information of the first node based on the first identity authentication information in the first authentication request. After the verification is successful, a second identity authentication information is sent to the first node. The second identity authentication information may be used by the first node to verify the identity of the device 100. It can be seen that after the identity is determined to be trusted, the association can be performed only after the identity authentication of both parties is successful. Thus, it is difficult for an attacker to avoid the identity authentication performed by the attacker's device 100 by modifying the identity such as an identifier, which prevents the device 100 from establishing an association with an unauthenticated attacker, and improves the data security of the device 100.
[0574] In some implementations, the processing module 1002 may: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or The device is further configured to obtain second acknowledgment indication information, the second acknowledgment indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0575] In the above method, associated nodes may be controlled using a blacklist or whitelist, and device 100 may be controlled not to send association requests to untrusted first nodes, which prevents device 100 from establishing associations with unauthorized attackers and improves data security of device 100.
[0576] In another possible implementation, the processing module 1002 may: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is further configured to obtain second acknowledgement indication information if the identifier of the first node is not on the second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on the second whitelist, wherein the second acknowledgement indication information indicates that the identity of the second node is trusted.
[0577] In yet another possible implementation, the first authentication request further includes first integrity check data, where the first integrity check data is used to perform a message integrity check on the first authentication request.
[0578] The processor is further configured to determine that a message integrity check on the first authentication request is successful.
[0579] It can be seen that after it is determined that the identity of the first node is trusted, in addition to identity authentication, an integrity check needs to be performed on the message carrying the identity authentication information, to prevent the first authentication response from being tampered with by an attacker, which avoids affecting the verification of the identity authentication information of the second node, and ensures the stable operation of the service provided by the device 100.
[0580] In yet another possible implementation, the processor 1002 may: The node is further configured to determine that a second number of associations is less than or equal to a preset second association threshold, the second number of associations indicating a number of currently associated nodes.
[0581] It can be seen that a second association threshold is preset in the device 100. An association request may be sent to the first node only when the number of associated nodes is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that can be associated with the device 100. When the second association threshold is exceeded, the device 100 cannot be associated with another node, which does not affect the communication between the device 100 and another node associated with the device, and ensures the stable operation of the service provided by the device 100.
[0582] In yet another possible implementation, the processor 1002 may: and further configured to receive a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0583] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the device 100 will receive a first association response from the first node. The association response is used to indicate that the first node establishes an association with the second node. Furthermore, the first response message may inform the device 100 that the association is successful and subsequent communication may be performed.
[0584] In yet another possible implementation, the processor 1002 may: Further configured to reset a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0585] It can be seen that if the identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset to avoid affecting subsequent determination of the identity of the first node and to ensure stable operation of the service provided by the device 100.
[0586] In yet another possible implementation, the processor 1002 may: and further configured to update a second authentication failure counter if verification fails for the first identity credential, the second authentication failure counter indicating a number of verification failures for the first node.
[0587] If the verification of the identity authentication information of the first node fails, the device 100 updates the number of the first node's identity verification failures, and the number of the verification failures can be used to subsequently determine whether the node's identity is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the attacker's device 100 by modifying the identity, such as an identifier, which prevents the device 100 from establishing an association with an unauthorized attacker, and improves the data security of the device 100.
[0588] In yet another possible implementation, the processor 1002 may: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; The node is further configured to add an identifier of the first node to a second blacklist.
[0589] If the number of verification failures of the first node exceeds a preset first threshold, it indicates that the first node has not been verified multiple times, and it is found that the first node may be an attacker who frequently sends association requests. Therefore, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the device 100 from establishing an association with an unauthorized attacker, and improves the data security of the device 100.
[0590] In yet another implementation, the validity period of the second blacklist is a predefined or preset second duration.
[0591] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0592] In yet another possible implementation, the processor 1002 may: determining that a value of a second authentication failure counter is less than a second threshold; and transmitting a second association request to the first node.
[0593] It can be understood that in the process of verifying the identity authentication information, some parameters may be lost or transmitted erroneously in the transmission process, so that the verification for the identity authentication information may also fail. Therefore, if the number of verification failures of the first node does not exceed the preset second threshold, the association request may be resent to the first node to request to establish an association with the first node. In this way, the robustness of the system is improved and the stable operation of the service provided by the device 100 is ensured. In yet another possible implementation, the processor 1002: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and transmitting a second association request to the first node.
[0594] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0595] In yet another possible implementation, the processor 1002 may: and further configured to remove the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to at least one of the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0596] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Additionally, optionally, the first node may be permanently added to the second blacklist after the number of times the first node has been added to the second blacklist exceeds a threshold.
[0597] Additionally, the validity period of the second blacklist may be related to the device type of the first node. Specifically, the first node may obtain the device type of the first node in advance, and different validity periods of the second blacklist are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the first node belongs to a smart cockpit domain controller CDC, a virtual reality device AR, etc., the first node may be regarded as a low-risk device. If the first node belongs to a server, a computer, etc., the first node may be regarded as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the apparatus 100 may further predefine a blacklist validity period corresponding to the first node. Details will not be described again here.
[0598] In yet another possible implementation, if the identity of the first node is not trusted, the step of sending the first association request to the first node is not performed.
[0599] It is understood that if the identity of the first node is not trusted, the identity authentication request is no longer sent to the first node, avoiding wasting the node's resources.
[0600] Please note that for specific implementations of each module, please refer to the corresponding description of the embodiment shown in Figure 3 or Figures 5A, 5B, and 5C. The communication device 100 may be a second node of the embodiment shown in Figure 3 or Figures 5A, 5B, and 5C.
[0601] 11 is a schematic diagram of the structure of an association control device 110 according to an embodiment of this application. The device 110 may be a node or a component such as a chip or integrated circuit in a node. The device 110 may include a communication unit 1101 and a processing unit 1102. The description of the units is as follows:
[0602] The communication unit 1101 is configured to receive a first association request from a second node.
[0603] The processing unit 1102 is configured to determine that the identity of the second node is trusted and to send a first authentication request to the second node using the communication unit 1101, the first authentication request including the first integrity check data.
[0604] The communication unit 1101 is further configured to receive a first authentication response from the second node, where the first authentication response includes the second integrity check data.
[0605] The processing unit 1102 is further configured to perform a message integrity check on the first authentication response based on the second integrity check data.
[0606] The processing unit 1102 is further configured to update a first authentication failure counter if a message integrity check on the first authentication response fails. The first authentication failure counter indicates a number of verification failures of the second node.
[0607] In this embodiment of the application, after determining that the identity of the second node is trusted, the device is further required to perform a message integrity check on the authentication response message from the second node before the association is performed. If the message integrity check fails, the number of verification failures is updated. The number of verification failures may be used to subsequently determine whether the identity of the second node is trusted, so that an attacker may be prevented from tampering with data (e.g., identity authentication information) in the authentication process. This prevents the device from establishing an association with an unauthenticated attacker, improving the data security of the device.
[0608] In some implementations, the processing module 1102 specifically: determining that an identifier of the second node is on the first whitelist; determining that the identifier of the second node is not on the first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist; or The method is configured to obtain first acknowledgment indication information, the first acknowledgment indication information indicating that the identity of the second node is trusted and that the identifier of the second node is not on a first blacklist or a first whitelist.
[0609] The device uses a blacklist or whitelist to control which nodes may request association, so that identity authentication does not have to be performed for an untrusted second node, which prevents the node from establishing an association with an unauthenticated attacker and improves data security for the node.
[0610] In some implementations, the processing module 1102 specifically: determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the second node is in a first whitelist if a type of the shared key between the first node and the second node is a password generation type; or The method is configured to obtain first acknowledgment indication information if the identifier of the second node is not on a first blacklist, a type of the shared key between the first node and the second node is a password generation type, and the identifier of the second node is not on a first whitelist, wherein the first acknowledgment indication information indicates that the identity of the second node is trusted.
[0611] In yet another possible implementation, the processing unit 1102 may: The node is further configured to determine that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
[0612] It can be seen that a first association threshold is preset in the device. An association request from a second node may be received only when the associated node is below the preset first association threshold. The first threshold may limit the support capacity of the service that may be provided by the device. When the first association threshold is exceeded, the device may no longer receive or process association requests, without affecting the communication between the device and another node associated with the device, and ensuring the stable operation of the service provided by the device.
[0613] In yet another possible implementation, the processing unit 1102 may: if the integrity check on the first authentication response is successful, performing a validation on a second identity credential based on a shared key shared with the second node; and if verification for the second identity credential fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of verification failures for the second node.
[0614] The device may be seen to perform a verification on the identity of the second node based on the shared key shared with the second node after determining that the identity of the second node is trusted if the integrity check is successful. If the verification fails, the number of verification failures is updated. The number of verification failures may be used to later determine whether the identity of the second node is trusted, such that a node that has not been verified multiple times may no longer be determined to be trusted. For nodes that are not determined to be trusted, authentication requests for the node (e.g., sending authentication requests) may no longer be processed, preventing the node from stalling due to processing a large number of requests and ensuring the normal operation of the service.
[0615] In yet another possible implementation, the communication unit 1101 includes: and further configured to send a first association response to the second node if the verification against the second identity authentication information is successful, the first association response being used to indicate that the first node establishes an association with the second node.
[0616] It can be seen that after it is determined that the identity of the second node is trusted, if the identity authentication is successful, a first association response may be sent to the second node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may be used to inform the second node that the association has been successful and that communication may be performed.
[0617] In yet another possible implementation, the processing unit 1102 may: The method is further configured to reset the first association failure counter if the second identity credential is successfully verified.
[0618] It can be seen that if the identity authentication is successful after it is determined that the identity of the second node is trusted, the number of verification failures of the second node needs to be reset, to avoid affecting subsequent determination of the identity of the second node and to ensure stable operation of the service provided by the device.
[0619] In yet another possible implementation, the processing unit 1102 may: The device is further configured to determine that a value of the first authentication failure counter is greater than or equal to a first threshold and to add an identifier of the second node to a first blacklist.
[0620] If the number of failed verifications of the second node exceeds a preset first threshold, indicating that the second node has not been verified multiple times, it is found that the second node may be an attacker that frequently sends association requests. Thus, the identifier of the second node is added to the blacklist. After the identifier of the second node is added to the blacklist, the identity of the second node is not determined to be trusted, which prevents the device from establishing an association with an unauthorized attacker and improves the data security of the node.
[0621] In yet another implementation, the validity period of the first blacklist is a predefined or preset first duration.
[0622] It is understood that the predefined or preset first duration in the first blacklist may be considered as the validity period of the blacklist. For example, the first duration of the blacklist may be one week, and the identifier of the second node may be removed from the blacklist one week after being added to the blacklist.
[0623] In yet another possible implementation, the processing unit 1102 may: removing the identifier of the second node from the first blacklist if the duration for which the identifier of the second node has been added to the first blacklist exceeds a first duration, the first duration being related to at least one of the number of times the identifier of the second node has been added to the first blacklist or the type of the second node.
[0624] The above implementation describes factors related to the lifetime of the first blacklist. The lifetime of the first blacklist may be related to the number of times the second node has been added to the first blacklist. A greater number of times the second node has been added to the first blacklist indicates a longer duration of the second node on the first blacklist. Furthermore, optionally, the second node may be permanently added to the first blacklist after the number of times the second node has been added to the first blacklist exceeds a threshold.
[0625] Additionally, the first blacklist validity period may be related to the device type of the second node. Specifically, the second node may obtain the device type of the second node in advance, and different blacklist validity periods are determined based on different device types. For example, the device type may include a high-risk device or a low-risk device. If the second node belongs to a microphone, a sounder, etc., the second node may be considered as a low-risk device. If the second node belongs to a mobile phone, a computer, etc., the second node may be considered as a high-risk device. The blacklist validity period of the high-risk device is longer than the blacklist validity period of the low-risk device. Furthermore, the first node may further predefine a blacklist validity period corresponding to the second node. Details will not be described again here. In yet another possible implementation, if the identity of the second node is not trusted, the step of sending the first authentication request to the second node is not performed.
[0626] It can be seen that if the identity of the second node is not trusted, then subsequent identity authentication steps are not performed, avoiding wasting device resources and affecting successful association with another node.
[0627] It should be noted that the division into the above-mentioned units is merely a logical division based on functions, and is not used as a limitation to a specific structure of the device 110. In a specific implementation, some functional modules may be subdivided into smaller functional modules, or some functional modules may be combined into one functional module. However, regardless of whether these functional modules are subdivided or combined, the procedures performed by the device 110 in the association control process are almost the same. For example, the communication unit may alternatively be transformed into a receiving unit and a transmitting unit. The receiving unit is configured to implement the message receiving function of the communication unit, and the transmitting unit is configured to implement the message sending function of the communication unit. Typically, each unit corresponds to the program code (or program instructions) of the unit. When the program code corresponding to the unit runs on the processor, the unit is able to execute the corresponding procedure to implement the corresponding function.
[0628] Please note that for the implementation of each unit, please refer to the corresponding description of the embodiment shown in Figures 6A, 6B, and 6C. The device 110 may be the first node of the embodiment shown in Figures 6A, 6B, and 6C.
[0629] 12 is a schematic diagram of the structure of an association control device 120 according to an embodiment of this application. The device 120 may be a node or a component such as a chip or integrated circuit in a node. The device 120 may include a processing unit 1201 and a communication unit 1202. The description of the units is as follows:
[0630] The processing unit 1201 is configured to determine that an identity of a first node is trusted, and to send, using the communication unit 1202, a first association request to said first node.
[0631] The communication unit 1202 is further configured to receive a first authentication request from the first node, the first authentication request including the first identity authentication information and the first integrity check data.
[0632] The processing unit 1201 is further configured to perform a message integrity check on the first authentication request based on the first integrity check data.
[0633] The communication unit 1202 is further configured to send a first authentication response to the first node if the message integrity check for the first authentication request is successful, where the first authentication response includes the second integrity check data.
[0634] In this embodiment of the application, after determining that the identity of the second node is trusted, the device is further required to perform authentication (e.g., verification using identity credentials) with the first node before communication can take place. To prevent an attacker from tampering with data in the authentication process, a message integrity check needs to be first performed on the first authentication request. Association with the first node is only allowed if the message integrity check is successful, so that an attacker can be prevented from tampering with message content. This prevents the node from establishing an association with an unauthenticated attacker, improving the data security of the node.
[0635] In some implementations, the processing module 1201 specifically: determining that an identifier of the first node is in a second whitelist; determining that the identifier of the first node is not on a second blacklist; obtaining a second acknowledgement indication, the second acknowledgement indication indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist; or The device is further configured to obtain second acknowledgment indication information, the second acknowledgment indication information indicating that the identity of the first node is trusted and that the identifier of the first node is not on a second blacklist or a second whitelist.
[0636] In the above method, associated nodes may be controlled using a blacklist or whitelist, and the device may be controlled not to send association requests to untrusted first nodes, which prevents the device from establishing associations with unauthenticated attackers and improves data security of the device.
[0637] In some implementations, the processing module 1201 specifically: determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a preset type; determining that an identifier of the first node is in a second whitelist if a type of the shared key between the first node and the second node is a password generation type; or and if the identifier of the first node is not on a second blacklist, the type of the shared key between the first node and the second node is a password generation type, and the identifier of the first node is not on a second whitelist, obtain second acknowledgement indication information, the second acknowledgement indication information indicating that the identity of the second node is trusted.
[0638] In yet another possible implementation, the processing unit 1201 may: The node is further configured to determine that a second number of associations is less than or equal to a preset second association threshold, the second number of associations indicating a number of currently associated nodes.
[0639] It can be seen that a second association threshold is preset in the device. An association request may be sent to the first node only when the associated node is equal to or less than the preset second association threshold. The second threshold may limit the number of nodes that can be associated with the device. When the second association threshold is exceeded, the device cannot be associated with another node, which does not affect the communication between the device and another node associated with the device and ensures the stable operation of the service provided by the device.
[0640] In yet another possible implementation, the communication unit 1202 includes: and further configured to receive a first association response from the first node, the first association response being used to indicate that the first node establishes an association with the second node.
[0641] After it is determined that the identity of the first node is trusted, if the identity authentication performed by the first node on the second node is successful, the device will receive a first association response from the first node. The association response is used to indicate to the device that it will establish an association with the second node. Furthermore, the first response message may inform the device that the association is successful and subsequent communication may be performed.
[0642] In yet another possible implementation, the processing unit 1201 may: Further configured to reset a second authentication failure counter, the second authentication failure counter indicating a number of validation failures of the first node.
[0643] It can be seen that if identity authentication is successful after it is determined that the identity of the first node is trusted, the number of verification failures of the first node needs to be reset, to avoid affecting subsequent determination of the identity of the first node and to ensure stable operation of the service provided by the device.
[0644] In yet another possible implementation, the processing unit 1201 may: and further configured to update a second authentication failure counter if a message integrity check on the first authentication response fails, the second authentication failure counter indicating a number of validation failures for the first node.
[0645] Typically, if the message integrity check on the first authentication response fails, indicating that the first authentication response message is no longer complete or has been modified by an attacker, the number of verification failures for the first node is updated accordingly, and the number of verification failures may be used to subsequently determine whether the identity of the first node is trusted.
[0646] In yet another possible implementation, the first authentication request message further includes a first identity authentication information. The processing unit 1201 is further configured to perform verification on the first identity authentication information based on a shared key shared with the first node if a message integrity check on the first authentication response is successful.
[0647] The communication unit 1202 is further configured to send a first authentication response to the first node if the verification on the first identity authentication information is successful.
[0648] After it is determined that the identity of the first node is trusted, if the integrity check is successful, it is seen that a verification is performed on the identity of the first node based on the shared key shared with the first node. Thus, it is difficult for an attacker to circumvent the association control performed by the attacker's device by modifying the identity such as an identifier, which prevents the node from establishing an association with an unauthorized attacker and improves the data security of the node.
[0649] In yet another possible implementation, the processing unit 1201 may: and further configured to update a second authentication failure counter if verification fails for the first identity credential, the second authentication failure counter indicating a number of verification failures for the first node.
[0650] If the verification for the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures may be used to subsequently determine whether the identity confirmation of the node is trusted, so that it is known that a node that is not verified multiple times may no longer be determined to be trusted. For a node that is not determined to be trusted, an association request may no longer be sent to the node, ensuring normal operation of the service provided by the node. In yet another possible implementation, the processing unit 1201: determining that a value of a second authentication failure counter is greater than or equal to a second threshold; The node is further configured to add an identifier of the first node to a second blacklist.
[0651] If the number of failed verifications of the first node exceeds a preset first threshold, indicating that the first node has not been verified multiple times, it is found that the first node may be an attacker who frequently sends association requests. Thus, the identifier of the first node is added to the blacklist. After the identifier of the first node is added to the blacklist, the identity of the first node is not determined to be trusted, which prevents the device from establishing an association with an unauthenticated attacker and improves the data security of the node.
[0652] In yet another implementation, the validity period of the second blacklist is a predefined or preset second duration.
[0653] It is understood that the predefined or preset second duration of the second blacklist may be considered as the validity period of the blacklist. For example, the second duration of the blacklist may be 10 days, and the identifier of the first node may be removed from the blacklist 10 days after being added to the blacklist.
[0654] In yet another possible implementation, the processing unit 1201 is further configured to determine that the value of the second authentication failure counter is less than a second threshold.
[0655] The communication unit is further configured to send a second association request to the first node.
[0656] If the verification of the identity authentication information of the first node fails, the device updates the number of identity verification failures of the first node, and the number of verification failures can be used to subsequently determine whether the identity of the node is trusted. Thus, it is difficult for an attacker to circumvent the association control performed by the first node by modifying the identity such as an identifier, which prevents the device from establishing an association with an unauthorized attacker and improves data security of the node.
[0657] In yet another possible implementation, the processing unit 1201 may: determining that a value of a second authentication failure counter is less than a second threshold; obtaining a third acknowledgment indication; and and transmitting a second association request to the first node.
[0658] It is seen that an acknowledgment indication information needs to be obtained before the second association request is resent. The third acknowledgment indication information may be an indication information obtained based on an acknowledgment action input by the user, and the acknowledgment action may be an acknowledgment of the output prompt information. For example, the prompt information may be output to remind the user that the verification has failed and the association request needs to be initiated again. After the user acknowledgment action is received and the third acknowledgment indication information is obtained, the second association request is sent to the first node. In this way, the user verifies the identity of the first node with which association is required again, so that association with untrusted nodes is avoided and communication security is guaranteed.
[0659] In yet another possible implementation, the processing unit 1201 may: The method is further configured to remove the identifier of the first node from the second blacklist if the duration for which the identifier of the first node has been added to the second blacklist exceeds a second duration, the second duration being related to the number of times the identifier of the first node has been added to the second blacklist or the type of the first node.
[0660] The above implementation accounts for factors related to the lifetime of the second blacklist. The lifetime of the second blacklist may be related to the number of times the first node has been added to the blacklist. A greater number of times the first node has been added to the second blacklist indicates a longer duration of the first node on the second blacklist. Additionally, optionally, ...
Claims
1. A method performed by a first node, comprising: receiving a first association request from a second node, the first association request including an identity and a nonce; determining that the identity of the second node is trusted and sending a first authentication request to the second node, the first authentication request including first identity authentication information, the first identity authentication information being generated by a key derivation function that uses (i) a shared key between the first node and the second node and (ii) the first association request as input; receiving a first authentication response from the second node, the first authentication response including second identity authentication information; and performing verification on the second identity credential based on the shared key; A method comprising:
2. 2. The method of claim 1, further comprising: if the verification for the second identity credential fails, updating a first authentication failure counter, the first authentication failure counter indicating a number of verification failures for the second node.
3. Determining that the identity of the second node is trusted includes: determining that an identifier of the second node is on a first whitelist; determining that the identifier of the second node is not on a first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that an identifier of the second node is not on a first blacklist; or obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that an identifier of the second node is not on a first blacklist or a first whitelist; or 3. The method of claim 1, further comprising obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted.
4. The first authentication response further includes second integrity check data, the second integrity check data being used to perform a message integrity check on the first authentication response, and the method further comprises: The method of any one of claims 1 to 3, further comprising determining that the message integrity check on the first authentication response is successful.
5. The first authentication response further includes second integrity check data, the second integrity check data being used to perform a message integrity check on the first authentication response, and the method further comprises: The method of claim 2 or 3, further comprising updating a first authentication failure counter if the message integrity check on the first authentication response fails.
6. The method comprises:
6. The method of claim 1, further comprising: determining that a first association number is less than or equal to a preset first association threshold, the first association number indicating a number of currently associated nodes.
7. 7. The method of claim 1, further comprising: if the verification on the second identity authentication information is successful, sending a first association response to the second node, the first association response being used to indicate that the first node establishes an association with the second node.
8. 8. The method of claim 2, further comprising: resetting a first association failure counter if a message integrity check on the first authentication response is successful and the verification on the second identity authentication information is successful.
9. 9. The method according to claim 2, wherein after updating a first authentication failure counter if the verification for the second identity authentication information fails, the method further comprises adding an identifier of the second node to a first blacklist when the first authentication failure counter is greater than or equal to a first threshold.
10. The method of claim 9 , wherein the validity period of the first blacklist is a predefined or preset first duration.
11. An association control device, a communication unit configured to receive a first association request from a second node, the first association request including an identity and a nonce; a processing unit configured to determine that the identity of the second node is trusted and to send a first authentication request to the second node using the communication unit, the first authentication request including first identity authentication information, the first identity authentication information being generated by a key derivation convention that uses (i) a shared key between the first node and the second node and (ii) the first association request as input; The communication unit is further configured to receive a first authentication response from the second node, the first authentication response including second identity authentication information; The apparatus, wherein the processing unit is further configured to perform verification on the second identity credential based on the shared key.
12. 12. The apparatus of claim 11, wherein the processing unit is further configured to update a first authentication failure counter if the verification for the second identity credential fails, the first authentication failure counter indicating a number of verification failures for the second node.
13. The processing unit includes: determining that an identifier of the second node is on a first whitelist; determining that the identifier of the second node is not on a first blacklist; obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that an identifier of the second node is not on a first blacklist; or obtaining a first acknowledgement indication, the first acknowledgement indication indicating that the identity of the second node is trusted and that an identifier of the second node is not on a first blacklist or a first whitelist; or 13. The apparatus of claim 11 or 12, configured to: obtain first acknowledgement indication information, the first acknowledgement indication information indicating that the identity of the second node is trusted.
14. the first authentication response further includes second integrity check data, the second integrity check data being used to perform a message integrity check on the first authentication response; The apparatus of claim 11 or 13, wherein the processing unit is configured to determine that the message integrity check on the first authentication response is successful.
15. the first authentication response further includes second integrity check data, the second integrity check data being used to perform a message integrity check on the first authentication response; The apparatus of claim 12 or 13, wherein the processing unit is configured to update a first authentication failure counter if the message integrity check on the first authentication response fails.
16. The processing unit includes:
16. The apparatus of claim 11, further configured to determine that a first association number is less than or equal to a pre-set first association threshold, the first association number indicating a number of currently associated nodes.
17. The apparatus of any one of claims 11 to 16, wherein the communication unit is further configured to send a first association response to the second node if the verification on the second identity authentication information is successful, the first association response being used to indicate that the first node establishes an association with the second node.
18. The apparatus of any one of claims 12 to 17, wherein the processing unit is further configured to reset a first association failure counter if a message integrity check on the first authentication response is successful and the verification on the second identity authentication information is successful.
19. The processing unit includes: The apparatus of any one of claims 12 to 18, further configured to add an identifier of the second node to a first blacklist if a first authentication failure counter is greater than or equal to a first threshold.
20. 20. The apparatus of claim 19, wherein the first blacklist validity period is a predefined or preset first duration.
21. A communication device, the communication device comprising at least one processor and a communication interface, the at least one processor calling a computer program stored in at least one memory, such that the communication device is configured to implement a method according to any one of claims 1 to 10.
22. A computer-readable storage medium, the computer-readable storage medium storing a computer program, the computer program executing, when running on one or more processors, the method according to any one of claims 1 to 10.
23. A computer program comprising at least one instruction, the at least one instruction being loaded and executed by a processor to implement the operations performed in the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
A response request method and device
CN101193068A
Message pushing processing method and apparatus thereof
CN107645524A
Communication method, related equipment and system
CN109842881A
Wireless LAN communication system
JP2005012724A
Image recording apparatus
JP2006013782A