Address verification method and corresponding device

The address verification method using resolved addresses and resolution keys ensures secure and efficient communication by allowing only trusted nodes to resolve identity addresses, addressing inefficiencies in existing identity authentication methods.

JP7753623B2Active Publication Date: 2025-10-15HUAWEI TECH CO LTD

Patent Information

Application Number
JP2024503859
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-23
Publication Date
2025-10-15
Estimated Expiration
2041-07-23

AI Technical Summary

Technical Problem

The challenge of ensuring secure and efficient communication between wireless communication nodes while minimizing the risk of privacy leakage is urgent, as existing methods face inefficiencies in identity authentication and privacy protection.

Method used

An address verification method using resolved addresses and resolution keys, where only nodes with the same key can correctly resolve the identity address, ensuring secure data transmission and reducing the duration of authenticity verification.

Benefits of technology

This method enhances security and efficiency by allowing only trusted nodes to resolve the identity address, thereby reducing the time required for verification and maintaining communication performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007753623000006
    Figure 0007753623000006
  • Figure 0007753623000007
    Figure 0007753623000007
  • Figure 0007753623000008
    Figure 0007753623000008
Patent Text Reader

Abstract

An embodiment of this application provides an address verification method and a corresponding device, which is applied in the field of communication technology, in particular, related to short-range communication technology. In a specific application, a second node receives first information from a first node. The first information includes a first address to be resolved and a first resolution key index of the first node. The first resolution key index indicates a first resolution key. The second node can then determine an identity address of the first node based on the first resolution key index and the first address to be resolved. The identity address uniquely identifies the first node. The first address to be resolved includes verification information for verifying the first resolution key. The first resolution key corresponds to the first identity address. In this way, secure communication between communication nodes can be ensured, and communication efficiency and performance can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD OF THE INVENTION The present application relates to the field of communication technology, and in particular to short-range communication technology. Specifically, the present application provides an address verification method and a corresponding device. [Background technology]

[0002] With the rapid development of information technology, mobile devices, including mobile phones, tablet computers, and other portable smart devices, have become indispensable personal smart tools in our daily lives. Compared with traditional computers, especially desktop workstations and servers, these devices are more convenient to use. However, when enjoying the convenience of communication, people also face the risk of privacy leakage. When two communication nodes perform wireless communication, how to perform identity authentication to ensure communication efficiency and performance is a technical problem that needs to be solved urgently to reduce the risk of privacy leakage. Summary of the Invention

[0003] The embodiments of this application disclose an address verification method and corresponding apparatus to realize secure communication between communication nodes, reduce the risk of privacy leakage, and ensure communication efficiency and performance.

[0004] According to a first aspect, there is provided an address verification method. The method may be performed by a communication node or a chip configured within the communication node. For example, the method may be performed by a second node or a chip configured within the second node. The method includes receiving first information from a first node, the first information including a first resolved address and a first resolution key index of the first node, the first resolution key index indicating a first resolution key; and determining an identity address of the first node based on the first resolution key index and the first resolved address, the identity address uniquely identifying the first node, the first resolved address including verification information for verifying the first resolution key, and the first resolution key corresponding to the first identity address.

[0005] In this solution, the security of data transmission between communication nodes can be ensured by using a resolved address, which can only be correctly resolved by communication nodes that have the same resolution key. Therefore, the address verification method provided in this application can ensure that it is difficult to obtain the identity address of the first node, and the security of data transmission between communication nodes can be ensured.

[0006] Referring to the first aspect, in some implementation schemes of the first aspect, the step of determining an identity address of the first node based on the first resolution key index and the first address to be resolved includes the steps of determining a first resolution key based on the first resolution key index, and determining the identity address of the first node based on the first resolution key and the first address to be resolved.

[0007] In this solution, the second node does not need to determine the identity address of the first node by traversing all locally stored peer node resolution keys, or only needs to determine the identity address of the first node by traversing the peer node resolution key corresponding to the first resolution key index, and can determine the first resolution key corresponding to the second node based on the first resolution key index, and then determine the identity address of the first node based on the first resolution key and the first address to be resolved. Therefore, the calculation duration required for address verification can be reduced, and communication efficiency and performance can be ensured.

[0008] Referring to the first aspect, in some implementation methods of the first aspect, the step of determining an identity address of the first node based on the first resolution key index and the first address to be resolved includes the steps of determining that local verification information obtained based on the first resolution key is the same as verification information included in the first address to be resolved, and determining that the first identity address is the identity address of the first node.

[0009] In this solution, whether the first identity address corresponding to the first resolution key is the identity address of the first node is determined based on a comparison result between local verification information and verification information included in the received first resolved address, which ensures the authenticity verification of the address of the first node, and thereby ensures the security of data transmission between communication nodes.

[0010] Referring to the first aspect, in some implementation schemes of the first aspect, the first resolved address includes a random number, and the step of determining an identity address of the first node based on the first resolution key index and the first resolved address includes the steps of determining that local verification information obtained based on the first resolution key and the random number is the same as verification information included in the first resolved address, and determining that the first identity address is the identity address of the first node.

[0011] In this solution, the local verification information is determined based on a random number included in the first resolving address and a first resolving key, which can ensure that the identity address of the first node is difficult to obtain, thereby ensuring the security of data transmission between communication nodes.

[0012] For example, the local verification information is obtained based on a hash operation performed on the first resolution key and the random number. The hash operation is irreversible. Therefore, through the hash operation, it can be further ensured that only trusted communication nodes can resolve the received resolution target address, thereby ensuring the security of data transmission between the communication nodes.

[0013] Referring to the first aspect, in some implementations of the first aspect, there is a predefined or preconfigured correspondence between the first resolution key, the first resolution key index, and the first identity address.

[0014] A first resolution key corresponding to the first resolution key index can be determined based on the correspondence relationship, and the received first address to be resolved can be resolved by using the first resolution key. In this way, it is determined whether the identity address of the first node is the first identity address corresponding to the first resolution key index or the first resolution key. According to this solution, the first resolution key or the first identity address is determined based on a predefined or preconfigured relationship. A second node can be prevented from receiving the resolution key index, resolution key information, and identity address information sent by the first node every time the second node verifies the authenticity of the address of the first node. The duration required for a connection between communication nodes is reduced, ensuring communication efficiency and performance.

[0015] Referring to the first aspect, in some implementation manners of the first aspect, before receiving the first information from the first node, the method further includes: receiving second information from the first node, the second information including a first resolution key and a first identity address; and defining or configuring a correspondence relationship between the first resolution key, the first resolution key index, and the first identity address.

[0016] For example, the second information further includes a first resolution key index. The second node may define or configure a correspondence relationship based on the first resolution key, the first resolution key index, and the first identity address included in the received second information. In this solution, the first resolution key index, the first resolution key, and the first identity address are all from the first node, and the implementation is simple.

[0017] For example, the first resolution key index is from the control node. The control node is configured to configure a resolution key index of the first node (i.e., the first resolution key index) and a resolution key index of the second node (i.e., the second resolution key index). The control node may be, for example, a main node or an access point; alternatively, the control node may be, for example, the first node or the second node. The second node may define or configure a correspondence based on the received second information and the first resolution key index from the control node. In this solution, the resolution key indexes corresponding to different communication nodes are all from the same communication node. This facilitates centralized management of resolution key indexes and can avoid collisions of resolution key indexes of peer nodes on the local node, thereby reducing the duration required for peer node address authenticity verification and ensuring communication efficiency and performance.

[0018] For example, referring to the first aspect, in some implementations of the first aspect, the method further includes sending a first resolution key index to the first node. The second node may define or configure a correspondence relationship based on the second information and the locally generated first resolution key index. In this solution, the resolution key index of the first node (i.e., the first resolution key index) is from the second node. This can avoid collisions of resolution key indexes on the first node side on the second node, i.e., can avoid the same resolution key index from corresponding to different peer nodes on the second node, thereby reducing the duration required for peer node address reliability verification and ensuring communication efficiency and performance.

[0019] Referring to the first aspect, in some implementation manners of the first aspect, before receiving the first information from the first node, the method further includes a step of receiving third information from the first node, the third information indicating determining an identity address of the first node based on the resolution key index and the address to be resolved.

[0020] For example, the resolving key information includes a resolving key and a resolving key index, or the resolving key information includes a resolving key.

[0021] For example, the identity address information includes a public device address and / or a static device address.

[0022] According to this solution, in one aspect, the second node can determine the identity address of the first node by using the resolution key information, so as to ensure the security of data transmission between the communication nodes. In another aspect, the flexibility of determining the identity address of the first node by the second node can be improved, the calculation duration required for address authenticity verification can be reduced, and communication efficiency and performance can be ensured.

[0023] For example, the third information is included in pairing request information from the first node. For example, the pairing request information includes security information distribution information, and the security information distribution information indicates whether to transmit resolution key information and / or identity address information. In this solution, the third information is realized by using the pairing request information, which can reduce signaling overhead and simplify the implementation scheme.

[0024]

[0013] Referring to the first aspect, in some implementations of the first aspect, the method further includes a step of sending fourth information to the first node, where the fourth information indicates whether to determine the identity address of the second node based on the resolution key index and the address to be resolved. According to this solution, in one aspect, the first node can determine the identity address of the peer node by using the resolution key information, so as to ensure security of data transmission between communication nodes. In another aspect, the flexibility of determining the identity address of the peer node can be improved, the calculation duration required for verifying the identity address can be reduced, and communication efficiency and performance can be ensured.

[0025] For example, the fourth information is included in pairing response information sent to the first node. For example, the pairing response information includes security information distribution information, and the security information distribution information indicates whether to transmit resolution key information and / or identity address information. In this solution, the fourth information is realized by using the pairing response information, which can reduce signaling overhead and is simple to realize.

[0026] According to a second aspect, there is provided an address verification method. The method may be performed by a communication node or a chip configured in the communication node. For example, the method may be performed by a first node or a chip configured in the first node. The method includes: determining a first resolved address of the first node; and sending first information to a second node, the first information including the first resolved address and a first resolution key index, the first resolution key index indicating a first resolution key, the first resolved address including verification information for verifying the first resolution key, the first resolution key corresponding to an identity address of the first node, the identity address uniquely identifying the first node.

[0027] In this solution, data transmission between communication nodes can be realized by using a resolved address, which can only be correctly resolved by communication nodes that have the same resolution key. Therefore, the address verification method provided in this application can ensure that it is difficult to obtain the identity address of the first node, and ensure the security of data transmission between communication nodes.

[0028] Referring to the second aspect, in some implementations of the second aspect, the step of determining a first resolved address of the first node includes the step of determining verification information of the first resolution key based on the first resolution key and the identity address of the first node.

[0029] For example, the first node performs a cryptographic operation on the first resolution key and the identity address of the first node to obtain a cryptographic operation output value, which is verification information or a part of the verification information.

[0030] In this solution, the verification information is determined based on the first resolution key and the identity address of the first node, which can ensure that the first address to be resolved can only be correctly resolved by a communication node that has the same resolution key, thereby ensuring the security of data transmission between the communication nodes.

[0031] Referring to the second aspect, in some implementations of the second aspect, the first resolved address includes a random number, and the step of determining the first resolved address of the first node includes the step of determining verification information obtained based on the first resolution key and the random number.

[0032] In this solution, the verification information in the first resolved address is determined based on a random number contained in the first resolved address, which can ensure that the identity address of the first node is difficult to obtain, thereby ensuring the security of data transmission between communication nodes.

[0033] For example, the verification information is obtained based on a hash operation performed on the first resolution key and the random number. The hash operation is irreversible. Therefore, through the hash operation, it can be further ensured that only trusted communication nodes can resolve the received resolution target address, thereby ensuring the security of data transmission between the communication nodes.

[0034] Referring to the second aspect, in some implementation manners of the second aspect, before transmitting the first information to the second node, the method further includes a step of transmitting second information to the second node, where the second information includes the first resolution key and the identity address.

[0035] For example, the second information further includes a first resolution key index. In this solution, a correspondence between the first resolution key index, the first resolution key, and the identity address can be configured or defined. The second node can be prevented from receiving the resolution key index, resolution key information, and identity address information sent by the first node every time the second node verifies the authenticity of the address of the first node. The duration required for the connection between the communicating nodes is reduced, and communication efficiency and performance are ensured. Furthermore, in this solution, the first resolution key index, the first resolution key, and the first identity address are all from the first node, and the implementation method is simple.

[0036] For example, the first resolution key index is from the control node. The control node is configured to configure a resolution key index of the first node (i.e., the first resolution key index) and a resolution key index of the second node (i.e., the second resolution key index). The control node may be, for example, a main node or an access point; alternatively, the control node may be, for example, the first node or the second node. The second node may define or configure a correspondence based on the received second information and the first resolution key index from the control node. In this solution, the resolution key indexes corresponding to different communication nodes are all from the same communication node. This facilitates centralized management of resolution key indexes and can avoid collisions of resolution key indexes of peer nodes on the local node, thereby reducing the duration required for peer node address authenticity verification and ensuring communication efficiency and performance.

[0037] For example, the first resolution key index is from the second node. In this solution, a correspondence between the first resolution key index, the first resolution key, and the identity address can be configured or defined. The second node can be prevented from receiving the resolution key index, resolution key information, and identity address information sent by the first node every time the second node verifies the authenticity of the address of the first node. The required duration of the connection between the communicating nodes is reduced, and communication efficiency and performance are ensured. Furthermore, the resolution key index is from the second node. This can avoid a collision of the resolution key index of the first node on the second node, i.e., can prevent the same resolution key index from corresponding to different nodes on the second node, thereby reducing the required duration of the address authenticity verification of the peer node and further ensuring communication efficiency and performance.

[0038] Referring to the second aspect, in some implementation manners of the second aspect, before sending the first information to the second node, the method further includes a step of sending third information to the second node, where the third information indicates determining the identity address of the first node based on the resolution key index and the address to be resolved.

[0039] For example, the resolving key information includes a resolving key and a resolving key index, or the resolving key information includes a resolving key.

[0040] For example, the identity address information includes a public device address and / or a static device address.

[0041] According to this solution, in one aspect, the second node can determine the identity address of the first node by using the resolution key information, so as to ensure the security of data transmission between the communication nodes. In another aspect, the flexibility of determining the identity address of the first node by the second node can be improved, the calculation duration required for address authenticity verification can be reduced, and communication efficiency and performance can be ensured.

[0042] For example, the third information is included in pairing request information sent by the first node. For example, the pairing request information includes security information distribution information, and the security information distribution information indicates whether to transmit resolution key information and / or identity address information. In this solution, the third information is realized by using the pairing request information, which can reduce signaling overhead and simplify the implementation.

[0043]

[0013] Referring to the second aspect, in some implementations of the second aspect, the method further includes receiving fourth information from the second node, the fourth information indicating whether to determine the identity address of the second node based on the resolution key index and the address to be resolved. According to this solution, in one aspect, the first node can determine the identity address of the second node by using the resolution key information to ensure security of data transmission between communication nodes. In another aspect, the flexibility of the first node to determine the identity address of the second node can be improved, the calculation duration required for address reliability verification can be reduced, and communication efficiency and performance can be ensured.

[0044] For example, the fourth information is included in pairing response information from the second node. For example, the pairing response information includes security information distribution information, and the security information distribution information indicates whether to transmit resolution key information and / or identity address information. In this solution, the fourth information is realized by using the pairing response information, which can reduce signaling overhead and is simple to realize.

[0045] According to a third aspect, there is provided a communication device including a processing unit and a transceiver unit for performing a method according to the first aspect and any one of the possible implementation manners of the first aspect, or for performing a method according to the second aspect and any one of the possible implementation manners of the second aspect.

[0046] According to a fourth aspect, there is provided a communication device including at least one processor and a transceiver. The at least one processor is configured to invoke a computer program stored in at least one memory to perform the method according to the first aspect and any one of its possible implementations, or the method according to the second aspect and any one of its possible implementations. The transceiver is configured to perform functions related to transmission and reception. Optionally, the transceiver includes a receiver and a transmitter, or a transmitter machine and a receiver machine.

[0047] Referring to the fourth aspect, in some implementations of the fourth aspect, the communication device is a communication chip, and the transceiver may be an input / output circuit or port of the communication chip.

[0048] With reference to the fourth aspect, in some implementations of the fourth aspect, the communication device further includes a memory. The memory is coupled to a processor included in the communication device. The processor may be configured to execute instructions in the memory to enable the device to perform the method according to any one of the first aspect and possible implementations of the first aspect, or the method according to any one of the second aspect and possible implementations of the second aspect. Optionally, the device may further include an interface circuit, and the processing module is coupled to the interface circuit.

[0049] According to a fifth aspect, there is provided a communication device including a communication apparatus configured to perform a method according to the first aspect and any one of possible implementation manners of the first aspect, or a communication apparatus configured to perform a method according to the second aspect and any one of possible implementation manners of the second aspect.

[0050] According to a sixth aspect, there is provided a chip, the chip including one or more processors and an interface circuit, configured to execute the method according to the first aspect and any one of possible implementations thereof, or configured to execute the method according to the second aspect and any one of possible implementations thereof.

[0051] According to a seventh aspect, there is provided a communication system including a communication device configured to perform the method according to the first aspect and any one of possible implementation manners of the first aspect, and a communication device configured to perform the method according to the second aspect and any one of possible implementation manners of the second aspect.

[0052] According to an eighth aspect, there is provided a computer-readable storage medium storing a computer program or instructions which, when executed by a communication device, enables the communication device to perform a method according to the first aspect and any one of possible implementations of the first aspect, or enables the communication device to perform a method according to the second aspect and any one of possible implementations of the second aspect.

[0053] According to a ninth aspect, there is provided a computer program product, the computer program product comprising computer programs or instructions which, when executed by a communications device, enable the communications device to perform a method according to the first aspect and any one of possible implementations of the first aspect, or enable the communications device to perform a method according to the second aspect and any one of possible implementations of the second aspect. [Brief explanation of the drawings]

[0054] The following describes the accompanying drawings used in the embodiments of this application. [Figure 1] 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application; [Figure 2] 1 is a schematic diagram of an application scenario of a communication method according to an embodiment of this application; [Figure 3] 1 is a schematic flowchart of a communication method according to an embodiment of the present application; [Figure 4] FIG. 2 is a schematic diagram of a public device address according to an embodiment of the present application. [Figure 5] FIG. 2 is a schematic diagram of a static device address according to an embodiment of the present application. [Figure 6] FIG. 2 is a schematic diagram of a resolved address according to an embodiment of the present application; [Figure 7] 4 is a schematic flowchart of another communication method according to an embodiment of the present application. [Figure 8] 1 is a schematic flowchart of yet another communication method according to an embodiment of the present application. [Figure 9] 1 is a schematic flowchart of yet another communication method according to an embodiment of the present application. [Figure 10] 1 is a schematic flowchart of yet another communication method according to an embodiment of the present application. [Figure 11] 1 is a schematic flowchart of yet another communication method according to an embodiment of the present application. [Figure 12] 1 is a schematic flowchart of yet another communication method according to an embodiment of the present application. [Figure 13] FIG. 2 is a schematic diagram of pairing request information according to an embodiment of the present application; [Figure 14] FIG. 10 is a schematic diagram of pairing acknowledgement information according to an embodiment of the present application; [Figure 15] FIG. 2 is a schematic diagram of initial pairing information according to an embodiment of the present application; [Figure 16] 1 is a schematic diagram of a communication device according to an embodiment of the present application; [Figure 17] FIG. 2 is a schematic diagram of another communication device according to an embodiment of the present application. [Figure 18] 1 is a schematic diagram of the structure of a chip according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0055] Hereinafter, embodiments of this application will be described with reference to the accompanying drawings in the embodiments of this application. It should be noted that in this application, terms such as "example" or "for example" are intended to provide an example, illustration, or explanation. Any embodiment or design method described in this application as "example" or "for example" should not be described as being preferable or having more advantages than other embodiments or design methods. Strictly speaking, the use of terms such as "example," "for example," etc. is intended to present a relative concept in a specific manner.

[0056] In the embodiments of this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following items" or similar expressions means any combination of these items, including any combination of a singular item or multiple items. For example, at least one of a, b, or c may refer to a, b, c, (a and b), (a and c), (b and c), or (a, b, and c), where a, b, and c may be singular or plural. "And / or" describes an association relationship between related objects and indicates that three relationships may exist. For example, A and / or B may refer to the following three cases: only A is present, both A and B are present, and only B is present, where A and B may be singular or plural. The character " / " generally indicates an "or" relationship between related objects.

[0057] Furthermore, unless otherwise specified, ordinal numbers such as "first" and "second" used in the embodiments of this application are intended to distinguish between multiple objects and are not intended to limit the order, time sequence, priority, or importance of the multiple objects. For example, first information and second information are intended to simply distinguish between different information and do not indicate that the two types of information differ in content, priority, transmission sequence, or importance.

[0058] First, technical terms used in the embodiments of this application will be explained below.

[0059] 1. Node

[0060] A node is an electronic device or a component (e.g., a chip or integrated circuit) within an electronic device that has data processing, receiving, and transmitting capabilities. An electronic device may include an end device or a network-side device. For example, a node may be a cockpit domain device or a module within a cockpit domain device (e.g., one or more of modules such as a cockpit domain controller (CDC), camera, screen, microphone, speaker, electronic key, and passive entry / passive start controller). In a specific implementation process, the node may alternatively be a data transfer device, for example, a base station, a router, a relay, a bridge, or a switch, or may be a terminal device, for example, various types of user equipment (UE), a mobile phone, a tablet computer (pad), a desktop computer, a headset, or a speaker, or may further include a machine intelligent device, for example, a self-driving device, a transportation safety device, a smart home device (for example, one or more of an audio and video device, a security device, a smart lighting device, or an environment monitoring device), a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a machine type communication (MTC) device, an industrial control device, a remote medical device, a smart grid device, or a smart city device, or may further include a wearable device (for example, a smart watch, a smart band, or a pedometer).

[0061] In some technical scenarios, devices with similar data receiving and transmitting capabilities may not be called nodes, but for ease of explanation, electronic devices with data receiving and transmitting capabilities are collectively referred to as nodes in the embodiments of this application.

[0062] 2. Node Address

[0063] A node may have at least one of two addresses: a public device address and a random device address. Random device addresses may be further classified into static device addresses and private device addresses. Private device addresses may be further classified into non-resolvable private addresses and resolvable private addresses. Each address is described below.

[0064] 1. Public Device Address

[0065] In a communication system, a public device address is used to uniquely identify a physical device. In one design, a device's public device address is fixedly assigned and includes, for example, a 24-bit company identifier (company_id) and a 24-bit company assigned (company_assigned).

[0066] 2. Random Device Address

[0067] Random device addresses are not fixedly assigned, but are randomly generated after the device is started. Random device addresses are classified into static device addresses and private device addresses based on different purposes.

[0068] (1) Static device address

[0069] Static device addresses are randomly generated when a node is powered on. In some designs, static device addresses remain unchanged between power-on cycles; static device addresses may change between subsequent power-on cycles or may remain unchanged. If a static device address changes between subsequent power-on cycles, previously stored information, e.g., connections, is no longer valid.

[0070] (2) Private Device Address

[0071] Private device addresses are periodically updated and encrypted to improve the reliability and security of the node addresses. Private device addresses are further classified into non-resolvable private addresses and resolvable private addresses based on whether the node address is encrypted or not.

[0072] (2-1) Unresolvable private addresses

[0073] An unresolvable private address is similar to a static device address. The difference is that an unresolvable private address is updated every specific cycle. In one design, the update cycle of an unresolvable private address may be specified in the protocol as, for example, X minutes, where X is an integer. An unresolvable private address may be updated every update cycle.

[0074] (2-2) Resolvable private addresses

[0075] A resolvable private address is generated by using at least a random number and a key. In one design, the resolvable private address is generated by using a random number and a key called an identity resolving key (IRK). For example, the resolvable private address includes two parts: a random number part and a hash value obtained through a hash calculation of the random number and the IRK. The resolvable private address can be obtained through a scan only by devices with the same IRK, thereby preventing unknown devices from obtaining the resolvable private address. Because the IRK may be for encryption, the IRK may also be referred to as an encryption key.

[0076] In embodiments of this application, for example, the identity address may include one or both of the following: a public device address and a static device address; and the node address may include one or both of a public device address and a static device address, and one or more private device addresses.

[0077] 3. Solution List

[0078] To protect the addresses of nodes (and peer nodes) from being obtained, local and peer addresses and encryption keys (IRKs) may be stored in a resolving list. Each entry in the resolving list stores key / address information for a pair of nodes, and the format of the key / address information may be Local IRK|Peer IRK|Peer Device Identity Address|Address Type.

[0079] The Local IRK is a local IRK for generating a resolvable private address of the local node. For example, when sending a data packet, the node first determines whether a non-zero Local IRK exists in the resolution list. If so, it generates a resolvable private address by using the Local IRK; if not, it directly uses the identity address as the local address. The Peer IRK is an IRK of the peer node for resolving a resolvable private address of the peer node to an identity address. For example, after receiving a data packet, if the data packet includes an identity address, the peer node directly performs subsequent processing on the data, or if the data packet includes a resolvable private address, the peer node resolves the received resolvable private address by using the Peer IRK included in the resolution list. The Peer Device Identity Address and Address Type are the identity address and address type of the peer node, respectively, for uniquely identifying the peer node in the connection and / or pairing process between nodes. For example, the identity address may be one of the following addresses: a public device address, a static device address, a non-resolvable private address, and a resolvable private address.

[0080] 4. Cryptographic Algorithms

[0081] A cryptographic algorithm may be a mathematical function for one or more of encrypting, decrypting, or generating keys, deriving passwords, etc., and may also be referred to as a cryptographic function. Common cryptographic algorithms include hash algorithms, encryption algorithms, authentication algorithms, key derivation algorithms (KDFs), authentication algorithms, etc.

[0082] (1) Hash algorithm

[0083] A hashing algorithm is also called a hash function or hashing algorithm. A hashing algorithm may convert information of any size into an identifier, and it is difficult to find a reverse rule.

[0084] (2) Encryption algorithm

[0085] Encryption algorithms include symmetric encryption algorithms and asymmetric encryption algorithms. Typically, the encryption key of a symmetric encryption algorithm is the same as the decryption key, while the encryption key of an asymmetric encryption algorithm is different from the decryption key. Additionally, there are hash algorithms that do not require a key. Common symmetric encryption algorithms mainly include the data encryption standard (DES), triple data encryption algorithm (3DES), advanced encryption standard (AES), etc. Common asymmetric algorithms mainly include the RSA encryption algorithm, data structure analysis (DSA) algorithm, etc. Hash algorithms mainly include the secure hash algorithm 1 (SHA-1), message digest (MD) algorithms (e.g., MD2, MD4, or MD5), etc.

[0086] (3) Integrity protection algorithm

[0087] An integrity protection algorithm is an algorithm for protecting message integrity, and may also be called a message authentication code (MAC) algorithm or an integrity protection algorithm. For example, an integrity protection algorithm implemented according to a hash algorithm is called a hash-based message authentication code (HMAC) algorithm. The hash algorithm may be one of MD5, SHA-1, SHA-256, etc. These different HMAC implementations are usually denoted as HMAC-MD5, HMAC-SHA1, HMAC-SHA256, etc.

[0088] In some specific scenarios, data may be encrypted, and a message authentication code may also be generated for a given original text according to an authenticated encryption algorithm. Thus, the authenticated encryption algorithm may be used as both an encryption algorithm and an integrity protection algorithm. For example, the AES algorithm based on the Galois message authentication code mode (GMAC) and counter mode (AES-Galois / counter mode, AES-GCM) and the AES algorithm based on the Cipher-based Message Authentication Code (CMAC) and counter mode (AES-CMAC / counter mode, AES-CCM) may be used for message authentication and encryption. To protect message integrity, a MAC address can be generated in the authentication and encryption process.

[0089] (4) Key derivation algorithm

[0090] A key derivation algorithm, which is used to derive one or more secret values ​​from a secret value, is also called a key derivation algorithm. For example, a new secret value derived from a secret value Key may be expressed as follows: DK=KDF(Key). Common key derivation algorithms include a password-based key derivation function (PBKDF), a scrypt algorithm, etc. PBKDF algorithms further include a first-generation PBKDF1 and a second-generation PBKDF2. Optionally, in the process of deriving a key according to some KDF algorithms, a hash algorithm is used to perform a hash modification on an input secret value. As a result, an algorithm identifier may also be received as an input in the KDF function to indicate the hash algorithm used.

[0091] 5. Trust List

[0092] In an embodiment of this application, the trusted list includes one or more node addresses, and a node corresponding to a node address included in the trusted list may be understood as a node trusted by the local node. For example, according to the trusted list, only nodes included in the trusted list are allowed to scan and connect to the local node, and / or according to the trust list, the local node can also only scan and connect to specific nodes (listed in the trusted list). For example, the node addresses stored in the trusted list may be one or more of the following addresses: public device addresses and static device addresses.

[0093] The following describes the system architecture and service scenarios in the embodiments of this application. It should be noted that the system architecture and service scenarios described in this application are intended to more clearly explain the technical solutions in this application, and do not constitute limitations on the technical solutions provided in this application. Those skilled in the art may recognize that with the evolution of system architecture and the emergence of new service scenarios, the technical solutions provided in this application can also be applied to similar technical problems.

[0094] 1 is a schematic diagram of a possible architecture of a communication system according to an embodiment of this application. The communication system includes a first node 101 and a second node 102.

[0095] The first node 101 and the second node 102 may establish an association. It should be noted that in this embodiment of the application, "association," "connection," and "pairing" may all refer to the process by which the first node and the second node establish a connection. After the first node 101 and the second node 102 are successfully associated, the first node 101 may communicate with the second node 102.

[0096] The communication link between the first node 101 and the second node 102 may include various types of connection media, including a wired link (e.g., optical fiber), a wireless link, a combination of a wired link and a wireless link, etc. The first node 101 and the second node 102 may achieve communication by using various connection technologies. For example, the connection technology may be a short-range connection technology, including 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB) technology, or other possible wireless short-range communication technologies (e.g., in-vehicle wireless short-range communication technologies). In another example, the connection technology may alternatively be a long-range connection technology, including a radio access type technology, such as a Long Term Evolution (LTE)-based communication technology, a fifth generation mobile communication technology (5th generation mobile network, 5th generation wireless system, or 5th-Generation, abbreviated as 5G or 5G technology), a global system for mobile communications (GSM), a general packet radio service (GPRS), or a universal mobile telecommunications system (UMTS). Obviously, there are other wireless communication technologies that may support communication between the first node and the second node, which is not particularly limited in the embodiments of this application.

[0097] The first node 101 and the second node 102 may be the same type of device or different types of devices. For example, FIG. 2 is a schematic diagram of a possible communication scenario according to an embodiment of this application. The CDC 201 of the vehicle is a control center in the vehicle's intelligent cockpit device and may be considered as the first node 101. The smartphone 202 is a device with data reception and transmission capabilities and may be considered as the second node 102. The CDC 201 may be associated with other devices by using various types of connection technologies. The smartphone 202 supports corresponding communication functions. As a result, the smartphone 202 may establish a connection to the CDC 201 by using the corresponding communication technology. For example, in some specific implementation scenarios, the first node may also be referred to as a G node, a control node, or an access point, and the second node may also be referred to as a T node or a terminal. A communication link from the G node to the T node may be referred to as a G link, and a communication link from the T node to the G node may be referred to as a T link.

[0098] In a possible procedure for two nodes to establish a connection based on the communication system shown in Fig. 1, each of the two nodes adds the device address of the peer node to the trust list of the local node to indicate that the peer node is a device trusted by the local node. However, the device addresses stored in the trust list are fixed to a certain extent. Therefore, an attacker may obtain the device address when the node performs advertising.

[0099] To solve this problem, two nodes can exchange their resolvable private device addresses. When one node obtains another node's resolvable private device address through a scan, the node performs a hash operation using the IRK stored in the local node and the random number in the resolvable private device address obtained through the scan, and compares the hash operation result with the hash field in the resolvable private device address. When the hash operation result and the hash field are the same, this may indicate that the resolvable private device address has been successfully resolved, or this indicates that address verification for the device transmitting the resolvable private device address has been successful. In this case, the node performs the subsequent operation. The resolvable private device address is generated randomly. Therefore, it is difficult to find the device transmitting the resolvable private device address. Furthermore, the resolvable private device address can be obtained through a scan only by devices with the same IRK; devices without the IRK cannot obtain the resolvable private device address.

[0100] However, in this method, when a device stores multiple IRKs, the device must resolve resolvable private device addresses obtained through scanning by using each stored IRK until all IRKs have been tried or until a resolvable private device address obtained through scanning is successfully resolved with one of the IRKs. Using an IRK to resolve a resolvable private device address obtained through scanning takes a long time. As a result, authenticity verification of the device address takes a long time, reducing communication efficiency and performance.

[0101] In consideration of this, an embodiment of this application provides a communication method. In the method, a second node receives first information from a first node, the first information including a first resolved address and a first resolution key index of the first node, and determines an identity address of the first node based on the first resolution key index and the first resolved address, where the identity address uniquely identifies the first node. In this manner, the first node and the second node communicate with each other by using the resolved address. This can ensure security of information transmission between the communication nodes. Furthermore, the second node can determine a first resolution key based on the first resolution key index without resolving the received first resolved address by traversing all locally stored resolution keys. This reduces the duration required for authenticity verification of a device address and ensures communication efficiency and performance.

[0102] With reference to specific embodiments, the communication method provided in the embodiments of this application will be described below.

[0103] 3 is a schematic flowchart corresponding to a communication method according to an embodiment of the present application. Furthermore, the method may be implemented based on the architecture shown in FIG. 1. The method may include the following steps:

[0104] S301: A first node determines a first address to be resolved.

[0105] In a possible implementation, the first resolved address includes an address generated by encrypting the identity address of the first node using a key. Furthermore, the encryption here may be implemented according to the above-mentioned encryption algorithm or other encryption algorithms. This is not particularly limited. The identity address of the first node may uniquely identify the first node. For example, the identity address of the first node may be fixed to a certain extent. For example, the identity address of the first node may be a public device address. The public device address is fixedly assigned, and the public device address remains unchanged during different power-on cycles of the first node. FIG. 4 is a schematic diagram of a possible public device address according to an embodiment of this application. The public device address includes a company_id (24 bits) in the most significant bits (MSB) and a company_assigned (24 bits) in the least significant bits (LSB). In another example, the identity address of the first node may be a static device address. A static device address is randomly generated, remains unchanged during one power-on cycle, and may remain unchanged or change during the next power-on cycle. Figure 5 is a schematic diagram of a possible static device address according to an embodiment of this application. A static device address includes 48 bits. The two most significant bits are "11", and the remaining 46 bits are random numbers that cannot be all 0's or all 1's.

[0106] In another possible implementation, the first address to be resolved includes verification information for verifying a first resolution key. The first resolution key corresponds to the identity address of the first node. The first resolution key may be an identity resolution key (IRK), or may be a key generated according to a key derivation algorithm, or may be in another form. This is not particularly limited. For the identity address of the first node, please refer to the above description. The details will not be described again here.

[0107] For example, the first node determines verification information for verifying the first resolution key based on the first resolution key and the identity address of the first node. For example, the first node performs a cryptographic operation on the first resolution key and the identity address of the first node to obtain a cryptographic operation output value. The cryptographic operation output value is the verification information or a part of the verification information. In another example, the first node performs an irreversible encryption operation on the first resolution key and the identity address of the first node, for example, a hash operation, to obtain the verification information. The verification information satisfies a condition that the verification information is equal to ah(IRK, identity address of the first node), where ah(IRK, identity address of the first node) indicates that a hash operation is performed on the identity address of the first node by using the encryption key IRK. In particular, the hash algorithm may be, for example, one of MD5, SHA-1, SHA-256, and SM3, or may be another implementation. This is not particularly limited. It should be noted that in this implementation, the identity address of the first node may alternatively be replaced with another address, for example, an address generated by the first node according to a specific rule, which is not particularly limited.

[0108] In another example, the first address to be resolved further includes a random number. The first node obtains verification information based on the first resolution key and the random number. For example, the first node performs a cryptographic operation on the first resolution key and the random number to obtain a cryptographic operation output value. The cryptographic operation output value is the verification information. For example, the first node performs an irreversible encryption operation on the first resolution key and the random number, for example, a hash operation, to obtain the verification information. The verification information satisfies a condition that the verification information is equal to ah(IRK, random number). Here, ah(IRK, random number) indicates that a hash operation is performed on the random number by using the encryption key IRK. The hash algorithm may be one of MD5, SHA-1, SHA-256, and SM3, or may be another implementation method. This is not particularly limited. In another example, the first node encrypts the first resolution key and the random number. The specific encryption algorithm may be, for example, the encryption algorithm described above. Details will not be described again here. In this implementation, the random number may optionally include 24 bits. The two MSBs in the random number may indicate the address type of the first address to be resolved, and the value is, for example, 10. Each of the other 22 bits is a randomly generated number and has a value of 0 or 1. FIG. 6 is a schematic diagram of a possible address to be resolved according to an embodiment of this application. The address to be resolved includes 48 bits, including a 24-bit random number prand and a 24-bit hash value hash. Furthermore, the values ​​of the most significant bit and the second most significant bit in prand are 0 and 1, respectively, and each of the other 22 bits is a randomly generated number. The hash value may correspond to the above verification information, i.e., is obtained through calculation based on the resolution key and the random number prand. The specific calculation method is as described above. The details will not be described again here.

[0109] For example, the first address to be resolved may be a resolvable private address.

[0110] S302: A first node sends first information to a second node, where the first information includes a first address to be resolved and a first resolution key index, and the first resolution key index indicates a first resolution key.

[0111] In response, the second node receives the first information.

[0112] In a possible implementation, the first node may transmit the first information in an advertising manner, and the second node correspondingly receives the first information advertised by the first node.

[0113] The first address to be resolved included in the first information and the first resolution key index included in the first information may be transmitted by using the same message, or may be transmitted by using different messages. For example, the first node transmits the first address to be resolved and the first resolution key index by using message A. In another example, the first node transmits the first address to be resolved by using message A and the first resolution key index by using message B.

[0114] Optionally, the first information may further include address type information of the first resolved address, for example, the address type information of the first resolved address indicates that the address type of the first resolved address is a resolvable private address.

[0115] S303: The second node determines the identity address of the first node based on the first resolution key index and the first address to be resolved.

[0116] Specifically, the second node determines, based on the first resolution key index, a first resolution key indicated by the first resolution key index, where the first resolution key corresponds to the first identity address.

[0117] For example, there is a predefined or preconfigured correspondence between the first resolution key index, the first resolution key, and the first identity address. The second node can determine the first resolution key indicated by the first resolution key index based on the correspondence. Optionally, the correspondence may be presented, for example, by using a table. See Table 1 for example. Table 1 is a table of possible correspondences according to an embodiment of this application. In Table 1, a Peer IRK ID indicates a resolution key index of a peer node, and a Peer IRK in the same row as the Peer IRK ID indicates a resolution key of a peer node corresponding to the Peer IRK ID. A Peer Node Identity Address in the same row as the Peer IRK ID and the Peer IRK indicates an identity address corresponding to one or more of the Peer IRK ID and the Peer IRK. It should be noted that in this embodiment of this application, the first resolution key index is an example of a Peer IRK ID, the first resolution key is an example of a Peer IRK, and the first identity address is an example of a peer node identity address. Specifically, for example, the Peer IRK ID, Peer IRK, and Peer Device Identity Address included in the second row in Table 1 respectively indicate the resolution key index, resolution key, and identity address of the first node. The Peer IRK ID, Peer IRK, and Peer Device Identity Address included in the third row in Table 1 respectively indicate the resolution key index, resolution key, and identity address of another node other than the first node and the second node, for example, a third node. For other examples, refer to Table 2 for correspondence relationships. Table 2 is a table of other possible correspondence relationships according to an embodiment of this application. The second node is used as an example. The local node resolution key index indicates the resolution key index of the second node, and the local node resolution key indicates the resolution key of the second node. The "local node resolution key index" is optional in Table 2. It should be noted that the table including the correspondence relationships between the resolution key index, the resolution key, and the identity address may alternatively have other formats.For example, Table 1 may further include one or two of a local node resolution key index, a local node resolution key, and a peer node identity address type. This is not particularly limited. Optionally, in this embodiment of the present application, the table including the correspondence may be a resolution list.

[0118] It should be noted that in this embodiment of the application, the same peer node resolution key index may alternatively correspond to multiple different peer node resolution keys. For example, the Peer IRK ID included in the second row in Table 1 is the same as the Peer IRK ID included in the third row, but the Peer IRK included in the second row in Table 1 is different from the Peer IRK included in the third row. [Table 1] [Table 2]

[0119] The following describes some possible implementation methods for the second node to determine the identity address of the first node based on the first resolution key index and the first address to be resolved. It should be noted that in this embodiment of the present application, there may alternatively be other implementation methods for the second node to determine the identity address of the first node based on the first resolution key index and the first address to be resolved. This is not particularly limited.

[0120] In a possible implementation, the second node determines a first resolution key based on the received first resolution key index, decrypts the first address to be resolved by using the first resolution key, and then determines the identity address of the first node. For example, the second node determines a first resolution key based on the received first resolution key index and the correspondence between the first resolution key index and the first resolution key, decrypts the received first address to be resolved by using the first resolution key, and compares the decryption result with a locally stored peer node identity address. Note that the peer node identity address here is an identity address corresponding to the first resolution key and stored in the second node. In one aspect, if the decryption result is the same as the peer node identity address, the second node determines that the first node is a trusted device node, or determines that the peer node identity address is the identity address of the first node. Furthermore, the second node may perform subsequent operations. For example, after determining the identity address of the first node, the second node may initiate a connection to the first node. In another example, the second node compares the determined identity address of the first node with device addresses in a locally stored trust list. If the device addresses in the locally stored trust list include the identity address of the first node, this may indicate that the first node is a node trusted by the second node. The second node may then perform subsequent data transmission with the first node. In yet another example, the second node compares the identity address of the first node with device addresses in the locally stored trust list. If the locally stored trust list does not include the identity address of the first node, the second node may first add the identity address of the first node to the trust list, and then perform subsequent data transmission with the first node.In another aspect, if the decryption result is different from the peer node identity address, the second node determines that the first node is not a trusted device node, or determines that the peer node identity address corresponding to the first resolution key is not the identity address of the first node. Subsequent actions of the second node may include one or more of the following: not establishing a connection to the first node and sending a connection establishment failure message to the first node; and sending an address resolution failure message to the first node requesting to obtain the identity address of the first node.

[0121] In another possible implementation, the second node determines a first resolution key based on the received first resolution key index, then calculates local verification information, and compares the local verification information with the verification information included in the first address to be resolved. The comparison result includes the following two cases:

[0122] Case 1: The local verification information is the same as the verification information contained in the first resolved address.

[0123] In this case, the second node can determine that the first identity address corresponding to the first resolution key is the identity address of the first node. Table 2 is used as an example. If the second node determines that the local verification information is the same as the verification information included in the first resolved address, the peer node identity address (i.e., the first identity address) corresponding to the first resolved address (i.e., the peer node resolution key) in Table 2 is the identity address of the first node. Furthermore, in this case, the second node may perform subsequent operations. For specific subsequent operations, refer to the subsequent operations performed in the above implementation when the decryption result is the same as the peer node identity address. Details will not be described again here.

[0124] Case 2: The local verification information is different from the verification information contained in the first address to be resolved.

[0125] In this case, the second node can determine that the first identity address corresponding to the first resolution key is not the identity address of the first node. For the subsequent operations of the second node, when the decryption result is different from the peer node identity address, refer to the subsequent operations performed in the above implementation method. Details will not be described again here.

[0126] Furthermore, corresponding to the above implementation scheme in which the first node determines verification information for verifying the first resolution key, the following two implementation schemes in which the second node calculates local verification information are enumerated in this embodiment of this application.

[0127] Implementation Scheme 1: The second node determines a first resolution key and a first identity address corresponding to the first resolution key index, and calculates local verification information based on the first resolution key and the first identity address. For example, Table 2 is used as an example. The second node finds a peer node resolution key index corresponding to the first resolution key index in Table 2 based on the received first resolution key index. For example, if the first resolution key index received by the second node is 2, the peer node resolution key index corresponding to the first resolution key index in Table 2 is also 2. Then, the second node calculates local verification information based on the peer node resolution key and the peer node identity address corresponding to the peer node resolution key index. Furthermore, for example, the second node performs an irreversible encryption operation, such as a hash operation, on the peer node resolution key and the peer node identity address to obtain the local verification information. For details, please refer to the relevant content in step S301. The details will not be described again here.

[0128] Implementation Scheme 2: The first address to be resolved includes a random number. The second node determines a first resolution key corresponding to the first resolution key index, and calculates local verification information based on the first resolution key and the random number. For the process by which the second node determines the first resolution key corresponding to the first resolution key index, please refer to the relevant content in Implementation Scheme 1. Details will not be described again here. Then, the second node calculates local verification information based on the peer node resolution key corresponding to the peer node resolution key index and the random number included in the first address to be resolved. For example, the second node performs an irreversible encryption operation, such as a hash operation, on the peer node resolution key and the random number to obtain the local verification information. For details, please refer to the relevant content in step S301. Details will not be described again here.

[0129] It should be noted that on the second node, when the peer node resolution key index corresponding to the received first resolution key index corresponds to N peer node resolution keys (N is an integer greater than 1), the second node needs to repeat the above process of determining the identity address of the first node for the N peer node resolution keys until the identity address of the first node is determined by using one of the N peer node resolution keys or all N peer node resolution keys have been tried. For example, on the second node, peer node resolution key index 1 corresponds to three peer node resolution keys, namely Key 1, Key 2, and Key 3, and corresponds to peer node identity addresses, namely Address 1, Address 2, and Address 3. If the first resolution key index received by the second node is 1, the second node needs to separately calculate local verification information by using Key 1, Key 2, and Key 3 and the received first resolved address, and compares the verification information calculated based on different peer node resolution keys with the verification information included in the first resolved address to determine whether the received first resolved address is associated with the stored resolution key. Specifically, for example, the second node first attempts to calculate local verification information by using Key 1 and the random number included in the first resolved address. If the obtained local verification information is the same as the verification information included in the received first resolved address, it may be determined that the corresponding peer node identity address (Address 1) is the identity address of the first node. Conversely, if the obtained local verification information differs from the verification information contained in the received first resolved address, the second node continues to attempt to calculate the local verification information by using Key 2, Key 3, and the random number contained in the received first resolved address until either the identity address of the first node is determined or both Key 2 and Key 3 have been used.In this embodiment of the present application, it may be understood that if the verification information obtained through calculation based on the stored resolution key and the received first resolved address is the same as the verification information included in the first resolved address, this indicates that the received first resolved address is associated with the stored resolution key. In the above scheme, the second node can determine the first resolution key indicated by the first resolution key index by using the first resolution key index sent by the first node, and then determine the identity address of the first node, without determining the identity address of the first node by traversing all locally stored peer node resolution keys. When the first resolution key index corresponds to multiple peer node resolution keys, the second node only needs to traverse the locally stored peer node resolution keys corresponding to the first resolution key index, without determining the identity address of the first node by traversing all locally stored peer node resolution keys. Therefore, the above scheme reduces the calculation duration for address resolution, reduces the duration required for authenticity verification of device addresses, and ensures communication efficiency and performance. Furthermore, the second node receives the first resolved address of the first node, where the resolved address may be randomly generated, and a hash operation may be performed on the resolved address by using the first resolution key, thereby ensuring that the identity address of the first node is difficult to obtain, and further ensuring the security and reliability of data transmission between the first node and the second node.

[0130] In this embodiment of the present application, there is a predefined or preconfigured correspondence between the first resolution key, the first resolution key index, and the first identity address. The second node can determine a first resolution key corresponding to the first resolution key index based on the correspondence, and use the first resolution key to resolve the received first address to be resolved to determine whether the identity address of the first node is the first identity address corresponding to the first resolution key index or the first resolution key. For example, the second node determines local verification information based on the first resolution key determined based on the correspondence, and compares the local verification information with the verification information included in the first address to be resolved to determine the first identity address.

[0131] It may be understood that there is also a predefined or preconfigured correspondence between the second resolution key, the second resolution key index, and the second identity address. The first node can determine a second resolution key corresponding to the second resolution key index based on the correspondence, and resolve the received second address to be resolved by using the second resolution key to determine whether the identity address of the second node is the second identity address corresponding to the second resolution key index or the second resolution key. For example, the first node can determine local verification information based on the second resolution key determined based on the correspondence, and compare the local verification information with the verification information included in the second address to be resolved to determine the second identity address.

[0132] In a possible implementation manner, the communication method in the embodiment of this application may further include one or more of steps S701 to S704 shown in Figure 7. One or more steps may be required in some specific scenarios. Steps S701 to S704 are specifically as follows:

[0133] S701: A first node sends second information to a second node, where the second information includes a first resolution key and an identity address of the first node.

[0134] In response, the second node receives the second information.

[0135] In this embodiment of the present application, the first resolution key and the identity address of the first node included in the second information may be transmitted by using the same message, or may be transmitted by using different messages. For example, the first node transmits the first resolution key by using message C1 and transmits the identity address of the first node by using message D1. Further, optionally, message C1 is a message carrying identity authentication key information. Message D1 is a message carrying identity address information. For example, message D1 may further include an address type corresponding to the identity address of the first node. For example, the address type is a public device address type or a static device address type. In another example, the first node transmits the first resolution key and the identity address of the first node by using message E1.

[0136] S702: The second node defines or configures a correspondence relationship between the first resolution key, the first resolution key index, and the identity address of the first node. For a specific manner of obtaining the first resolution key index, see the following description. The definition or configuration here means that the second node may maintain the above correspondence relationship, but the specific storage manner is not particularly limited.

[0137] For example, the second node stores or writes the first resolution key, the first resolution key index, and the identity address of the first node in the same row in the table. For a specific implementation of the table, please refer to the description in step S303. The details will not be described again here. It should be noted that the terms "storing" and "writing" mentioned in this embodiment of the present application may indicate that the correspondence between the resolution key, the resolution key index, and the identity address may be represented in a table or written in other ways. This is not particularly limited.

[0138] S703: The second node sends fifth information to the first node, where the fifth information includes a second resolution key of the second node and an identity address of the second node.

[0139] In this embodiment of the present application, the second resolution key and the identity address of the second node refer to the above description of the first resolution key and the identity address of the first node. For example, the identity address of the second node may uniquely identify the second node.

[0140] In response, the first node receives the fifth information.

[0141] In this embodiment of the present application, the second resolution key and the identity address of the second node included in the fifth information may be transmitted by using the same message, or may be transmitted by using different messages. For example, the second node transmits the second resolution key by using message C2 and transmits the identity address of the first node by using message D2. Further, optionally, message C2 is a message carrying identity authentication key information. Message D2 is a message carrying identity address information. For example, message D2 may further include an address type corresponding to the identity address of the second node. For example, the address type is a public device address or a static device address. In another example, the second node transmits the second resolution key and the identity address of the second node by using message E2.

[0142] S704: The first node defines or configures a correspondence relationship between the second resolution key, the second resolution key index, and the identity address of the second node. For a specific manner of obtaining the second resolution key index, see the following description. The definition or configuration here means that the first node may maintain the above correspondence relationship, but the specific storage manner is not particularly limited.

[0143] For example, the first node stores or writes the second resolution key, the second resolution key index, and the identity address of the second node in the same row in the table. For the specific implementation of the table, please refer to the description in step S303. The details will not be described again here.

[0144] Optionally, the step of the method in the embodiment shown in FIG. 7 may be a previous step of the method in the embodiment shown in FIG.

[0145] In the above scheme, the local node can pre-configure the correspondence between the resolution key index, the resolution key, and the identity address of the peer node, and then determine the identity address of the peer node based on the received resolution key index of the peer node. In this way, the local node and the peer node do not need to exchange their respective resolution key indexes, resolution keys, and identity addresses every time the local node verifies the authenticity of the peer node's device address. This reduces the duration required for the connection between the nodes and ensures communication efficiency and performance.

[0146] Furthermore, before constructing the resolution key index, the node's identity address and resolution key index, the node may first obtain the resolution key index. For example, the node may obtain the resolution key index in one of the following three ways:

[0147] Scheme 1: The resolution key index of the peer node stored by the local node is from the peer node, for example, the second information further includes a first resolution key index, and the fifth information further includes a second resolution key index.

[0148] It should be noted that in this embodiment of the application, the resolution key index (e.g., the first resolution key index or the second resolution key index) may be randomly generated, assigned according to a fixed algorithm, or pre-configured before distribution. For example, the first resolution key index of the first node is configured before distribution of the first node. It should be noted that the resolution key indexes corresponding to different nodes may be generated in different manners. For example, the first resolution key index may be assigned according to a fixed algorithm, and the second resolution key index may be randomly generated.

[0149] For example, before the method in the embodiment shown in FIG. 3, the communication method in the embodiment of this application may further include one or more steps among steps S801 to S804 shown in FIG. 8. One or more steps may be required in some specific scenarios. It may be understood that the communication method shown in FIG. 8 may be a possible implementation based on the communication method shown in FIG. 7. In this implementation, the second information in FIG. 7 includes, but is not limited to, first identity authentication key information and first identity address information. The fifth information in FIG. 7 includes, but is not limited to, second identity authentication key information and second identity address information. Steps S801 to S804 are specifically as follows:

[0150] S801: A first node sends first identity authentication key information to a second node, where the first identity authentication key information includes a first resolution key and a first resolution key index.

[0151] In response, the second node receives the first identity authentication key information.

[0152] S802: The second node sends second identity authentication key information to the first node, where the second identity authentication key information includes a second resolution key and a second resolution key index.

[0153] In response, the first node receives second identity authentication key information.

[0154] S803: The first node sends first identity address information to the second node, where the first identity address information includes an identity address of the first node and an address type of the identity address.

[0155] In response, the second node receives the first identity address information.

[0156] S804: The second node sends second identity address information to the first node, where the second identity address information includes the identity address of the second node and an address type of the identity address.

[0157] Correspondingly, the first node receives the second identity address information. For specific implementation, please refer to the detailed description in the embodiment shown in Figure 6. The details will not be described again here.

[0158] Scheme 2: The resolution key index of the peer node stored by the local node is from the local node. For example, the first resolution key index is determined by the second node and sent by the second node to the first node. The second resolution key index is determined by the first node and sent by the first node to the second node. For the scheme of determining the resolution key index, please refer to the description in Solution 1. The details will not be described again here.

[0159] For example, before the method in the embodiment shown in FIG. 3, the communication method in the embodiment of this application may further include one or more steps S901 to S906 shown in FIG. 9. One or more steps may be required in some specific scenarios. It may be understood that the communication method shown in FIG. 9 may also be another possible implementation based on the communication method shown in FIG. 7. In this implementation, the second information in FIG. 7 includes, but is not limited to, first identity authentication key information, second identity authentication key response information, and first identity address information. The fifth information in FIG. 7 includes, but is not limited to, first identity authentication key response information, second identity authentication key information, and second identity address information. Steps S901 to S906 are specifically as follows:

[0160] S901: A first node sends first identity authentication key information to a second node, where the first identity authentication key information includes a first resolution key.

[0161] In response, the second node receives the first identity authentication key information.

[0162] S902: The second node sends first identity authentication key response information to the first node, where the second identity authentication key response information includes a first resolution key index corresponding to the first resolution key.

[0163] In response, the first node receives first identity authentication key response information. S903: The second node sends second identity authentication key information to the first node, where the second identity authentication key information includes a second resolution key.

[0164] In response, the first node receives second identity authentication key information.

[0165] S904: The first node sends second identity authentication key response information to the second node, where the second identity authentication key response information includes a second resolution key index corresponding to the second resolution key.

[0166] In response, the second node receives second identity authentication key response information.

[0167] S905: The first node sends first identity address information to the second node, where the first identity address information includes the identity address of the first node and an address type of the identity address. In response, the second node receives the first identity address information.

[0168] S906: The second node sends second identity address information to the first node, where the second identity address information includes the identity address of the second node and an address type of the identity address.

[0169] In response, the first node receives the second identity address information.

[0170] For specific implementation methods, please refer to the detailed description in the embodiment shown in Figure 6. The details will not be described again here.

[0171] According to the above solution, the resolution key index of a peer node stored by a local node is from the local node, which can better avoid collisions of resolution key indexes of peer nodes on the local node. In other words, it can avoid the case where the same resolution key index corresponds to different peer nodes on the local node. In this way, the duration required for peer node address authenticity verification can be reduced, and communication efficiency and performance can be ensured.

[0172] Scheme 3: The resolution key indexes of different nodes are from the same node. For example, both the first resolution key index and the second resolution key are from the first node. For example, the second information further includes the first resolution key index, and the second resolution key index is also from the first node. For example, the first node determines the second resolution key index in a manner of random number generation or fixed algorithm assignment, and sends the second resolution key index to the second node. Correspondingly, in a subsequent data transmission process, the second node may perform data transmission with the first node by using the second resolution key index.

[0173] Optionally, in this solution, the first node may be a communication initiator and may be called a main node or an access point (AP).

[0174] For example, before the method in the embodiment shown in FIG. 3, the communication method in the embodiment of this application may further include one or more steps S1001 to S1005 shown in FIG. 10. One or more steps may be required in some specific scenarios. It may be understood that the communication method shown in FIG. 10 may be another possible implementation based on the communication method shown in FIG. 7. In this implementation, the second information in FIG. 7 includes, but is not limited to, first identity authentication key information, second identity authentication key response information, and first identity address information. The fifth information in FIG. 7 includes, but is not limited to, second identity authentication key information and second identity address information. Steps S1001 to S1005 are specifically as follows:

[0175] S1001: A first node sends first identity authentication key information to a second node, where the first identity authentication key information includes a first resolution key and a first resolution key index.

[0176] In response, the second node receives the first identity authentication key information.

[0177] S1002: The second node sends second identity authentication key information to the first node, where the second identity authentication key information includes a second resolution key.

[0178] In response, the first node receives second identity authentication key information.

[0179] S1003: The first node sends second identity authentication key response information to the second node, where the second identity authentication key response information includes a second resolution key index corresponding to the second resolution key.

[0180] In response, the second node receives second identity authentication key response information.

[0181] S1004: The first node sends first identity address information to the second node, where the first identity address information includes an identity address of the first node and an address type of the identity address.

[0182] In response, the second node receives the first identity address information.

[0183] S1005: The second node sends second identity address information to the first node, where the second identity address information includes the identity address of the second node and an address type of the identity address.

[0184] In response, the first node receives the second identity address information.

[0185] For specific implementation methods, please refer to the detailed description in the embodiment shown in Figure 6. The details will not be described again here.

[0186] According to the above solution, the resolution key indexes of different nodes are from the same node, which makes it easier to manage the resolution key indexes and can better avoid the collision of the resolution key indexes of peer nodes on the local node. In this way, the duration required for peer node address authenticity verification can be reduced, and communication efficiency and performance can be ensured.

[0187] In a possible implementation manner, the communication method in the embodiment of this application may further include step S1101 or step S1101 and step S1102 in Fig. 11. One or more steps may be required in some specific scenarios. Step S1101 and step S1102 are specifically as follows:

[0188] S1101: A first node sends third information to a second node, where the third information indicates determining an identity address of the first node based on a resolution key index and a resolved address.

[0189] In response, the second node receives the third information.

[0190] It should be noted that, alternatively, the third information indicates transmitting the resolution key information and the identity address information. In other words, the third information indicating determining the identity address of the first node based on the resolution key index and the address to be resolved may be understood as indicating that the third information indicates transmitting the resolution key information and the identity address information. For clarity, an example showing that the third information determines the identity address of the first node based on the resolution key index and the address to be resolved is used for explanation. The third information indicates determining the identity address of the first node based on the resolution key index and the address to be resolved. In this case, during a subsequent data transmission between the first node and the second node, the first node transmits the first address to be resolved and the first identity address to the second node. Alternatively, during a subsequent data transmission between the first node and the second node, the second node determines a resolution key by using the first resolution key index, and then resolves the received first address to be resolved based on the first resolution key. Alternatively, during a subsequent data transmission between the first node and the second node, the second node communicates with the first node by using the first resolved address.

[0191] The resolving key information includes a resolving key and a resolving key index, or the resolving key information includes a resolving key. For example, the resolving key may be an IRK.

[0192] Furthermore, the third information may alternatively indicate not to send the resolution key information and the identity address information, or alternatively, not to determine the identity address of the first node based on the resolution key index and the resolved address. For example, when the third information indicates not to determine the identity address of the first node based on the resolution key index and the resolved address, or when the third information indicates not to send the resolution key information and the identity address information, in a subsequent data transmission process between the first node and the second node, the second node communicates with the first node without using the first resolved address, for example, directly communicates with the first node by using the identity address of the first node. Alternatively, the second node resolves the first resolved address by traversing a locally stored resolution key, and then determines the identity address of the first node.

[0193] S1102: The second node sends fourth information to the first node, where the fourth information indicates whether to send resolution key information and identity address information, or the fourth information indicates whether to determine the identity address of the second node based on the resolution key index and the address to be resolved.

[0194] In response, the first node receives the fourth information.

[0195] For example, when the fourth information indicates determining the identity address of the second node based on the resolution key index and the resolved address, or when the fourth information indicates transmitting the resolution key information and the identity address information, in the subsequent data transmission process between the first node and the second node, the first node can determine the identity address of the second node by using the second resolution key index and the second resolved address of the second node. For specific implementation manners, please refer to the detailed descriptions in other embodiments of this application. The details will not be described again here. In another example, when the fourth information indicates not determining the identity address of the second node based on the resolution key index and the resolved address, or when the fourth information indicates not transmitting the resolution key information and the identity address information, in the subsequent data transmission process between the first node and the second node, the first node communicates with the second node without using the second resolved address, for example, by using the identity address of the second node. Alternatively, the first node resolves the second address to be resolved by traversing a locally stored resolution key index, and then determines the identity address of the second node.

[0196] Optionally, the method in the embodiment shown in FIG. 11 may be a previous step of the method in the embodiment shown in FIG.

[0197] In the above scheme, in the data transmission process between the first node and the second node, data transmission between the nodes can be realized by using a resolved address. The resolved address can only be resolved by nodes with the same resolution key. Therefore, the security of data transmission between the nodes is ensured. Furthermore, the flexibility of determining the identity address of a peer node by a local node can be further improved. For example, the third information sent by the first node to the second node is used as an example. If the first node obtains a small number of resolution keys of the peer node locally stored in the second node, for example, if only one resolution key exists, the third information may indicate not to determine the identity address of the first node based on the resolution key index and the resolved address. In this way, in the process of resolving the identity address of a peer node by the second node, the calculation duration for determining a resolution key based on the resolution key index can be reduced. Furthermore, if the first node obtains a large number of resolution keys of the peer node stored locally in the second node, for example, if there are at least two resolution keys, the third information may indicate to determine the identity address of the first node based on the resolution key index and the address to be resolved. In this way, the calculation duration required by the second node to resolve the identity address of the peer node is reduced, and the efficiency of data transmission between the communicating nodes is improved. Optionally, the number of resolution keys may be determined based on a configured threshold. If the number is less than (or equal to or less than) the threshold, the number of resolution keys may be considered to be small. Otherwise, the number of resolution keys is considered to be large.

[0198] In a possible implementation, the third information may be included in the pairing request information, and the fourth information may be included in the pairing response information. This implementation can reduce signaling overhead and is simple. For example, before the method in the embodiment shown in FIG. 7, the communication method in the embodiment of this application may further include steps S1201 and S1202 shown in FIG. 12. It may be understood that the communication method shown in FIG. 12 may also be an implementation of the communication method shown in FIG. 11. In this implementation, the third information in FIG. 11 includes, but is not limited to, security information distribution information included in the pairing request information, and the fourth information in FIG. 11 includes, but is not limited to, security information distribution information included in the pairing response information. Steps S1201 and S1202 are specifically as follows.

[0199] S1201: A first node sends pairing request information to a second node, where the pairing request information includes security information distribution information, where the security information distribution information indicates sending resolution key information and identity address information, or the security information distribution information indicates determining the identity address of the first node based on the resolution key index and the address to be resolved, or the security information distribution information indicates that after the nodes are paired, the local node distributes the resolution key of the local node and the identity address of the local node to the peer node. For example, in this step, the security information distribution information indicates whether after the first node and the second node are paired, the first node distributes the resolution key of the first node and the identity address of the first node to the second node. For example, see Table 3 for the definition of the security information distribution information. The meanings of other bits other than the 0th bit and the 1st bit are not limited in this embodiment of the application. It should be noted that the security information distribution information may alternatively indicate not sending the resolution key information and the identity address information, or the security information distribution information indicates not determining the identity address of the first node based on the resolution key index and the address to be resolved, or the security information distribution information indicates that the local node does not distribute the resolution key of the local node and the identity address of the local node to the peer node after the nodes are paired. [Table 3]

[0200] For example, when the value of the 0th bit of the security information distribution information is 1, this indicates that the local node will distribute the resolution key information to the peer node after the local node and the peer node are paired. When the value of the 0th bit of the security information distribution information is 0, this indicates that the local node will not distribute the resolution key information to the peer node after the local node and the peer node are paired. It should be noted that the correspondence between the value of the 0th bit of the security information distribution information and whether to send the resolution key information to the peer node may also be expressed in other forms, without any particular limitation.

[0201] For example, when the value of the first bit of the security information distribution information is 1, this indicates that the local node will distribute the identity address of the local node to the peer node after the local node and the peer node are paired. When the value of the first bit of the security information distribution information is 0, this indicates that the local node will not distribute the identity address of the local node to the peer node after the local node and the peer node are paired. It should be noted that the correspondence between the value of the first bit of the security information distribution information and whether the identity address of the local node is sent to the peer node may also be expressed in other forms. This is not particularly limited. In a possible implementation, when the values ​​of the 0th bit and the 1st bit of the security information distribution information are 1, this may indicate that the local node needs to send resolution key information and the identity address of the local node to the peer node after the local node and the peer node are paired. Alternatively, it may be understood that in a subsequent data transmission process, the peer node can determine the identity address of the local node based on the resolution key index and the address to be resolved.

[0202] In another possible implementation, the peer node may ignore the value of the 1st bit of the security information distribution information and determine whether the local node should send a resolution key to the peer node based only on the value of the 0th bit of the security information distribution information. For example, when the value of the 0th bit in the security information distribution information sent by the local node is 1, the local node will send the resolution key information of the local node to the peer node regardless of whether the value of the 1st bit in the security information distribution information is 0 or 1. For example, for a resolution key update scenario, the local node has sent its identity address to the peer node during a previous data transmission. Therefore, only the updated resolution key needs to be sent to the peer node. In this case, the peer node can determine whether the local node should send a resolution key to the peer node based only on the value of the 0th bit of the security information distribution information.

[0203] Furthermore, optionally, the security information distribution information may further indicate a manner of acquiring the resolution key index, namely, one of the following three acquisition manners: the resolution key index of the peer node stored in the local node is from the peer node, the resolution key index of the peer node stored in the local node is from the local node, and the resolution key index of a different node is from the same node. For a specific description of the three manners of acquiring the resolution key index, please refer to the relevant content in the above embodiment of this application. The details will not be described again here. It should be noted that in this embodiment of this application, in addition to the security information distribution information, the pairing request information may further include one or more of a command code (Code), an input / output capability IOC, an out-of-band data flag (OOB data flag), an authentication request (AuthReq), a maximum encryption key size, and a cryptographic algorithm type. For example, FIG. 13 is a possible schematic diagram of the pairing request information according to an embodiment of this application. The code indicates the message type. For example, 0x02 indicates a pairing request message, 0x03 indicates a pairing response message, 0x04 indicates pairing acknowledgement information, and 0x05 indicates initial pairing information. IOC indicates the input / output capability of the node (e.g., the first node) that sends the pairing request information. Table 4 shows a possible implementation of the IOC field according to an embodiment of this application. The OOB data flag indicates whether the node that sends the OOB data flag supports the OOB pairing method. The OOB medium may be any other wireless communication standard that can transmit corresponding information, such as the near field communication (NFC) standard or quick response code.Here, AuthReq may include one or more of a binding flag (bonding_flags, BF), a man-in-the-middle (MITM) flag, a secure connections (SC) flag, and a keypress flag. The maximum encryption key size indicates the maximum size of the key that can be supported by the device transmitting the maximum encryption key size. For example, the minimum key size may be limited to 7 bytes. The encryption algorithm type may further include one or more of an encryption algorithm, an integrity protection algorithm, a key generation algorithm, and a key agreement algorithm. The command code (Code), input / output capability IOC, out-of-band data flag, authentication request (AuthReq), maximum encryption key size, and encryption algorithm type may alternatively be expressed in other formats, without any particular limitation. [Table 4]

[0204] S1202: The second node sends pairing response information to the first node, where the pairing response information includes security information distribution information. For a specific implementation of the security information distribution information, please refer to the relevant content in step S1201. The details will not be described again here.

[0205] Optionally, the pairing response information may further include one or more of a command code (Code), an input / output capability (IOC), an out-of-band data flag (OOB data flag), an authentication request (AuthReq), a maximum encryption key size, and an encryption algorithm type. For specific descriptions of the above information, please refer to the relevant content in step S1201. The details will not be described again here.

[0206] In a possible implementation manner, the security information distribution information included in the pairing request information may further indicate a manner for acquiring the resolution key index, that is, it may indicate one of the following three acquisition solutions: the resolution key index of the peer node stored in the local node is from the peer node, the resolution key index of the peer node stored in the local node is from the local node, and the resolution key indexes of different nodes are from the same node. For specific descriptions of the three acquisition solutions, please refer to the relevant contents in the above embodiments of this application. The details will not be described again here.

[0207] Optionally, the communication method shown in Figure 12 further includes step S1203 and step S1204. Step S1203 and step S1204 are specifically as follows:

[0208] S1203: The first node sends pairing acknowledgement information to the second node.

[0209] In response, the second node receives pairing acknowledgement information.

[0210] The pairing acknowledgment information is for a local node (e.g., a first node) to refer to the IOC of the peer node (e.g., a second node), select a pairing scheme and an encryption algorithm type based on the encryption algorithm type supported by the peer node, and notify the peer node to perform subsequent pairing and encryption. For example, the pairing acknowledgment information may include a first random number N1 for subsequently generating a communication link key between the nodes and a public key used for key agreement. For example, FIG. 14 is a possible schematic diagram of the pairing acknowledgment information according to an embodiment of this application. The pairing acknowledgment information includes one or more of a code, a key size, an authentication type, an encryption algorithm type, a public key, and the first random number N1. The key size may be, for example, a key size finally determined by the node initiating the pairing acknowledgment information. For the authentication type, see, for example, Table 5. Table 5 is a possible implementation of the authentication type field according to this embodiment of this application. For other parameters, see the related descriptions in steps S1201 and S1202. Details will not be described again here. [Table 5]

[0211] S1204: The second node sends initial pairing information to the first node.

[0212] In response, the first node receives the initial pairing information.

[0213] The initial pairing information includes a second random number N2 and a public key for subsequently generating a communication link key between the nodes. For example, Figure 15 is a possible schematic diagram of the initial pairing information according to an embodiment of this application. The initial pairing information includes a code, a public key, and the second random number N2.

[0214] For example, in this embodiment of the present application, whether the first node and the second node transmit their respective resolution keys (which may also be understood as identity authentication keys) and identity address information to each other may be determined by using the pairing request information and pairing response information included in the communication method in FIG. 12. If it is determined that the first node and the second node need to transmit their respective resolution keys and identity address information to each other, a security information distribution protocol may be initiated after pairing between the first node and the second node is completed. Specifically, the first node and the second node may exchange their respective resolution keys and identity addresses, and store the correspondence between the resolution keys, the resolution key indexes corresponding to the resolution keys, and the identity addresses in a local resolution table. For the manner of obtaining the resolution key index, please refer to the relevant content in other embodiments. Details will not be described again here. Then, in the data transmission process between the first node and the second node, reference is made to the communication method shown in FIG. 3. In this way, the calculation duration for resolving the received address to be resolved is reduced, and communication efficiency and performance are ensured.

[0215] It should be noted that the sequence of steps in the method embodiments of this application may be adjusted, combined or deleted based on actual requirements. The above describes the method in the embodiments of this application in detail. Below, the device provided in the embodiments of this application will be described in detail with reference to Figures 16 to 18.

[0216] 16 is a schematic block diagram of a communication device according to an embodiment of this application. As shown in FIG. 16, the communication device may include a processor and a transceiver for performing the method in any one of the above possible implementation manners. The processor may be configured to perform internal processing of the device, for example, to determine an identity address of the first node based on a first resolution key index and a first resolved address, or in another example, to determine that local verification information obtained based on the first resolution key and a random number is the same as the verification information included in the first resolved address, and to determine that the first identity address is the identity address of the first node, or in yet another example, to determine the first resolved address of the first node. The transceiver is configured to perform functions related to transmission and reception, such as transmitting information to another device or receiving information from another device.

[0217] For example, a transceiver included in a communication device may be a transmitter and a receiver, or may be a transmitter machine and a receiver machine.

[0218] In an implementation, the communication device is a communication chip, and the transceiver may be an input / output circuit or port of the communication chip.

[0219] In this embodiment of the application, the communication device may be a device of the first node or a chip configured in the first node. The communication device may be configured to perform the method performed by the first node in any possible manner of implementation. Alternatively, the communication device may be a device of the second node or a chip configured in the second node. The communication device may be configured to perform the method performed by the second node in any possible manner of implementation.

[0220] In another implementation, the communication device further comprises a module configured to perform the method in any one of the above possible implementations.

[0221] In yet another implementation, the communication device may further include a memory, as indicated by a dotted box in Fig. 17. Fig. 17 is a schematic block diagram of a communication device according to an embodiment of this application. The memory is coupled to a processor and a transceiver included in the communication device. It may be understood that the memory, the processor, and the transceiver communicate with each other through an internal connection path. Specifically, the processor may be configured to execute instructions in the memory to enable the device to perform the method in any one of the above possible implementations.

[0222] Furthermore, an embodiment of the present application further provides a chip, as shown in Figure 18. Figure 18 is a schematic diagram of the structure of the chip. The chip includes one or more processors and an interface circuit, and is configured to execute the method in any one of the above possible implementation manners. Optionally, the chip may further include a bus.

[0223] For example, the processor may be an integrated circuit chip having signal processing capabilities. For example, the processor may be a field programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. It may also be a system on a chip (SoC), a central processing unit (CPU), a network processor (NP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chip. The processor may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The steps of the methods disclosed with reference to the embodiments of this application may be directly executed and achieved by a hardware decoding processor, or may be executed and achieved by using a combination of hardware and software modules in the decoding processor. The software modules may be located in a mature storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, or a register. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with the hardware of the processor.

[0224] The interface circuit may be for transmitting or receiving data, instructions, or information. The processor may process the data, instructions, or other information received through the interface circuit and transmit the information obtained after processing through the interface circuit.

[0225] Optionally, the chip further includes memory, which may be volatile or nonvolatile memory, or may include both volatile and nonvolatile memory. The nonvolatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), and is used as an external cache. By way of example and not limitation, many forms of RAM may be used, such as static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (synchlink DRAM, SLDRAM), and direct rambus random access memory (direct rambus RAM, DR RAM).

[0226] It should be noted that the functions corresponding to the processor and the interface circuit may be realized by using a hardware design, a software design, or a combination of software and hardware, which is not limited here.

[0227] An embodiment of the present application further provides a processing device including a processor and an interface, wherein the processor is configured to execute a method performed by a first node in any possible implementation manner, or to execute a method performed by a second node in any possible implementation manner.

[0228] An embodiment of the present application further provides a communication system, including a communication device configured to perform a method performed by a first node, in any possible manner of implementation, and a communication device configured to perform a method performed by a second node, in any possible manner of implementation.

[0229] It should be noted that the memory in the systems and methods described herein may include, but is not limited to, these and any other suitable types of memory.

[0230] An embodiment of the present application further provides a computer program product, which includes computer program code that, when executed on a computer, enables the computer to perform a method performed by a first node, in any possible implementation manner, or a method performed by a second node, in any possible implementation manner.

[0231] This application further provides a computer-readable medium, which stores program code that, when executed on a computer, enables the computer to perform a method performed by a first node, in any possible implementation manner, or to perform a method performed by a second node, in any possible implementation manner.

[0232] All or part of the above embodiments may be realized using software, hardware, firmware, or any combination thereof. When software is used to realize the above embodiments, all or part of the embodiments may be realized in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the procedures or functions according to the embodiments of this application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from a computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio, or microwave) method. The computer-readable storage medium may be any available medium accessible by a computer, or a data storage device integrating one or more available media, such as a server or data center. The media that can be used may be magnetic media (e.g., floppy disk, hard disk drive, or magnetic tape), optical media (e.g., digital video disc (DVD)), semiconductor media (e.g., solid state disc (SSD)), etc.

[0233] Those skilled in the art may recognize that the units and algorithm steps in the examples described with reference to the embodiments disclosed in this specification can be realized by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to realize the described functions for each specific application, but the implementation manner should not be considered to go beyond the scope of this application.

[0234] For convenience and brevity of description, the detailed operation processes of the above systems, devices and units may be clearly understood by those skilled in the art by referring to the corresponding processes in the above method embodiments, and the details will not be described again here.

[0235] In some embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods may be implemented in other ways. For example, the described device embodiments are merely examples. For example, the division into units is merely a logical division of function, and other divisions may be used in actual implementations. For example, multiple units or components may be combined or integrated into other systems, or some features may be omitted or not implemented. Furthermore, the shown or discussed mutual couplings or direct couplings or communication connections may be realized through some interfaces. Indirect couplings or communication connections between devices or units may be realized in electronic, mechanical, or other forms.

[0236] The units described as separate parts may or may not be physically separate, and the parts shown as units may or may not be physical units. Specifically, these parts may be located in one place or distributed across multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments.

[0237] Furthermore, the functional units in the embodiments of this application may be integrated into one processing unit, or each of the units may exist physically alone, or two or more units may be integrated into one unit.

[0238] The above description is merely a specific implementation of this application and is not intended to limit the scope of protection of this application. Any variations or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in this application shall fall within the scope of protection of this application. Therefore, the scope of protection of this application shall be subject to the scope of protection of the claims.

Claims

1. A communication method performed by a second node, comprising: receiving first information from a first node, the first information including a first address to be resolved of the first node and a first resolution key index, the first resolution key index indicating a first resolution key; determining an identity address of the first node based on the first resolution key index and the first resolved address, the identity address uniquely identifying the first node; Including, the first resolved address includes verification information for verifying the first resolution key, the first resolution key corresponds to a first identity address; The first resolved address includes a random number, and determining an identity address of the first node based on the first resolution key index and the first resolved address includes: determining that local verification information obtained based on the first resolving key and the random number is the same as the verification information included in the first resolved address; determining that the first identity address is the identity address of the first node; A method comprising:

2. The method of claim 1 , wherein the local verification information is obtained based on a hash operation performed on the first solution key and the random number.

3. The method of claim 1 or 2, wherein there is a predefined or preconfigured correspondence between the first resolution key, the first resolution key index, and the first identity address.

4. before receiving the first information from the first node; receiving second information from the first node, the second information including the first resolution key and the first identity address; defining or configuring the correspondence between the first resolution key, the first resolution key index, and the first identity address; The method of claim 3 further comprising:

5. The method of claim 4 , wherein the second information further comprises the first resolution key index.

6. The method of claim 4 , further comprising the step of transmitting the first resolution key index to the first node.

7. before receiving the first information from the first node; 7. The method of claim 1, further comprising: receiving third information from the first node, the third information indicating determining the identity address of the first node based on a resolution key index and a resolved address.

8. A communication method performed by a first node, comprising: determining a first resolved address of the first node; sending first information to a second node, the first information including the first address to be resolved and a first resolution key index, the first resolution key index indicating a first resolution key; Including, the first resolved address includes verification information for verifying the first resolution key, the first resolution key corresponds to an identity address of the first node, the identity address uniquely identifying the first node; The first resolved address includes a random number, and determining the first resolved address of the first node includes: determining the verification information obtained based on the first solution key and the random number.

9. The method of claim 8 , wherein the verification information is obtained based on a hash operation performed on the first solution key and the random number.

10. Before transmitting the first information to the second node, 10. The method of claim 8, further comprising the step of: sending second information to the second node, the second information including the first resolution key and the identity address.

11. The method of claim 10 , wherein the second information further comprises the first resolution key index.

12. The method of claim 10 , further comprising receiving the first resolution key index from the second node.

13. Before transmitting the first information to the second node, 13. The method of claim 8, further comprising: sending third information to the second node, the third information indicating determining the identity address of the first node based on a resolution key index and a resolved address.

14. 14. The method of claim 8, wherein there is a predefined or preconfigured correspondence between the first resolution key, the first resolution key index and the identity address.

15. A communication device, a transceiver unit configured to receive first information from a first node, the first information including a first address to be resolved of the first node and a first resolution key index, the first resolution key index indicating a first resolution key; a processing unit configured to determine an identity address of the first node based on the first resolution key index and the first resolved address, the identity address uniquely identifying the first node; and Including, the first resolved address includes verification information for verifying the first resolution key, the first resolution key corresponds to a first identity address; the first address to be resolved includes a random number, and the processing unit: determining that local verification information obtained based on the first resolution key and the random number is the same as the verification information included in the first resolved address; The apparatus is further configured to determine that the first identity address is the identity address of the first node.

16. 16. The apparatus of claim 15, wherein a predefined or preconfigured correspondence exists between the first resolution key, the first resolution key index, and the first identity address.

17. the transceiver unit is further configured to receive second information from the first node, the second information including the first resolution key and the first identity address; 17. The apparatus of claim 16, wherein the processing unit is further configured to define or configure the correspondence between the first resolution key, the first resolution key index, and the first identity address.

18. A communication device, a processing unit configured to determine a first resolved address of the first node; a transceiver unit configured to transmit first information to a second node, the first information including the first address to be resolved and a first resolution key index, the first resolution key index indicating a first resolution key; Including, the first resolved address includes verification information for verifying the first resolution key, the first resolution key corresponds to an identity address of the first node, the identity address uniquely identifying the first node; the first address to be resolved includes a random number, and the processing unit: The apparatus is further configured to determine the obtained verification information based on the first solution key and the random number.

19. Before transmitting the first information to the second node, the transceiver unit:

20. The apparatus of claim 18, further configured to send second information to the second node, the second information including the first resolution key and the identity address.

20. 20. The apparatus of claim 19, wherein the transceiver unit is further configured to receive the first resolution key index from the second node.

21. A communication device, The communication device includes at least one processor and a transceiver, the at least one processor being configured to invoke a computer program stored in at least one memory to perform a method according to any one of claims 1 to 7 or any one of claims 8 to 14.

22. A communication device comprising a communication apparatus configured to perform a method according to any one of claims 1 to 7 or any one of claims 8 to 14.

23. A chip including one or more processors and interface circuits, 15. A chip, wherein the interface circuitry is configured to provide information input and / or output to the one or more processors, and the chip is configured to perform a method according to any one of claims 1 to 7 or any one of claims 8 to 14.

24. A communication system comprising a communication device configured to perform a method according to any one of claims 1 to 7 and a communication device configured to perform a method according to any one of claims 8 to 14.

25. 1. A computer-readable storage medium, comprising: The computer-readable storage medium stores a computer program or instructions, which, when executed by a communication device, implements the method of any one of claims 1 to 7 or any one of claims 8 to 14.

26. 1. A computer program product comprising: A computer program product which, when run on one or more processors, implements the method of any one of claims 1 to 7 or any one of claims 8 to 14.

Citation Information

Patent Citations

  • Security in communication networks

    JP2006526314A

  • Cipher processing device and cipher processing system

    JP2015033082A

  • addressable radio

    JP2016504778A

  • Image processing apparatus, image processing method, program, and concealed information processing system

    JP2018098645A

  • Communication device, communication system, communication method, and program

    JP2020136782A

Cited By

  • Address verification method and corresponding device

    KR103008189B1