Secure communication method and apparatus based on lightweight key algorithm, and device and medium
By adopting a secure communication method based on lightweight key algorithm in IoT communication, the problem of insufficient security of IoT communication is solved, the reliability and rapid recovery of key updates are achieved, and the flexibility and efficiency of communication protocols are improved.
Patent Information
- Application Number
- PCT/CN2024/122869
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-30
- Filing Date
- 2024-09-30
- Publication Date
- 2025-05-08
AI Technical Summary
In the prior art, the security of IoT communication is insufficient, and there are problems such as the consensus on key updates is not strict, the keys are easily lost and difficult to recover, resulting in IoT devices being vulnerable to attacks.
A secure communication method based on a lightweight key algorithm is adopted to generate a temporary key through the pre-shared key and a random number, and qualification authentication for key negotiation requests and replies is performed, the final security key is generated, and the message to be sent is encrypted through the key.
It improves the security of IoT communication, ensures the reliability and rapid recovery of key updates, and enhances the flexibility and efficiency of communication protocols.
Smart Images

Figure CN2024122869_08052025_PF_FP_ABST
Abstract
Description
Secure communication method, device, equipment and medium based on lightweight key algorithm Technical Field
[0001] The present application relates to the field of Internet of Things security technology, and in particular to a secure communication method, apparatus, device, and medium based on a lightweight key algorithm. Background Art
[0002] With the development of science and technology, the popularity of IoT devices has become more and more widespread, and smart devices have become an indispensable part of production and life. At the same time, IoT security issues have gradually attracted people's attention. Attacks launched against the Internet may cause device failures and system paralysis, which will have a huge impact on people's economy and even safety. However, the existing IoT security communication methods have many problems such as not strictly requiring consensus on key updates, keys are easily lost, and keys are difficult to recover after loss. The lack of secure and usable communication protocols in actual applications makes the IoT still vulnerable to potential attacks.
[0003] Summary of the Invention
[0004] The embodiments of the present application provide a secure communication method, apparatus, device, and medium based on a lightweight key algorithm, aiming to solve the problem of insufficient security in IoT communications in the prior art.
[0005] In a first aspect, an embodiment of the present application provides a secure communication method based on a lightweight key algorithm, which is applied to a first Internet of Things device, comprising: generating a first temporary key based on a pre-shared key and a generated first random number and the lightweight key algorithm; generating a key negotiation request based on the first random number, identity information, a first encryption result, and a first message signature, wherein the first encryption result is generated by the first temporary key and a session sequence number, and the first message signature is generated by the first random number, the identity information, the first temporary key, and the first encryption result, and sending the key negotiation request to a second Internet of Things device; receiving a negotiation reply message returned by the second Internet of Things device, generating a second temporary key based on a second random number carried in the negotiation reply message, and performing a signature calculation on the second temporary key to obtain a second message signature, determining whether the second message signature is the same as the first message signature, and performing qualification authentication on the negotiation reply message; if they are the same, the negotiation reply message qualification authentication passes, and generating a third random number based on the first random number and the second random number, generating a security key based on the third random number and the pre-shared key through the lightweight key algorithm, encrypting the message to be sent based on the security key to generate an encrypted message, and sending the encrypted message to the second Internet of Things device.
[0006] In the second aspect, an embodiment of the present application also provides a secure communication method based on a lightweight key algorithm, which is applied to a second Internet of Things device, comprising: receiving the key negotiation request sent by the first Internet of Things device, and performing qualification authentication on the key negotiation request; if the authentication is passed, generating the negotiation reply message, and sending the negotiation reply message to the first Internet of Things device, wherein the negotiation reply message includes the second random number; generating the security key according to the key negotiation request and the negotiation reply message; receiving the encrypted message sent by the first Internet of Things device, and verifying the legitimacy of the encrypted message, and if the verification is passed, performing corresponding processing on the encrypted message.
[0007] In a third aspect, an embodiment of the present application further provides a secure communication device based on a lightweight key algorithm, which includes a unit for executing any method as described in the first aspect, or includes a unit for executing any method as described in the second aspect.
[0008] In a fourth aspect, an embodiment of the present application further provides a computer device, which includes a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the above method when executing the computer program.
[0009] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the storage medium stores a computer program, wherein the computer program includes program instructions, and the program instructions can implement the above method when executed by a processor.
[0010] The embodiments of the present application provide a secure communication method, apparatus, device, and medium based on a lightweight key algorithm. The method includes: generating a first temporary key based on a pre-shared key and a generated first random number and the lightweight key algorithm; generating a key negotiation request based on the first random number, identity information, a first encryption result, and a first message signature, wherein the first encryption result is generated by the first temporary key and a session sequence number, and the first message signature is generated by the first random number, the identity information, the first temporary key, and the first encryption result; sending the key negotiation request to a second IoT device; receiving a negotiation reply message returned by the second IoT device, generating a second temporary key based on a second random number carried in the negotiation reply message, performing a signature calculation on the second temporary key to obtain a second message signature, determining whether the second message signature is identical to the first message signature, and performing qualification authentication on the negotiation reply message; if they are identical, the negotiation reply message passes qualification authentication, generating a third random number based on the first random number and the second random number, generating a security key based on the third random number and the pre-shared key using the lightweight key algorithm, encrypting the message to be sent based on the security key to generate an encrypted message, and sending the encrypted message to the second IoT device. The embodiment of the present application generates a temporary key for information interaction between Internet devices based on a lightweight key algorithm, and generates a final security key based on the temporary key, a preset initial key, and information such as a random number in the interaction. The message to be sent is encrypted using the security key, which not only ensures the security of communication, but also facilitates the rapid recovery of the security key when it is lost, making the communication protocol more flexible and efficient. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0012] FIG1 is a schematic block diagram of a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application;
[0013] FIG2 is a schematic diagram of a process of applying a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application to a first IoT device;
[0014] FIG3 is a schematic diagram of a sub-process of applying a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application to a first IoT device;
[0015] FIG4 is a schematic diagram of a sub-process of applying a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application to a first IoT device;
[0016] FIG5 is a schematic diagram of a process of applying a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application to a second IoT device;
[0017] FIG6 is a schematic diagram of a sub-process of applying a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application to a second IoT device;
[0018] FIG7 is a schematic diagram of a sub-process of applying a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application to a second IoT device;
[0019] FIG8 is a schematic block diagram of a secure communication device based on a lightweight key algorithm provided in an embodiment of the present application applied to a first IoT device;
[0020] FIG9 is a schematic block diagram of a secure communication device based on a lightweight key algorithm provided in an embodiment of the present application applied to a second IoT device;
[0021] FIG10 is a schematic block diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0023] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0024] It should also be understood that the terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit the present application. As used in this specification and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0025] It should be further understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0026] Please refer to Figure 1, which is a schematic block diagram of a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application. The secure communication method based on a lightweight key algorithm in this embodiment can be applied to connecting an IoT terminal device and a control center, or between terminal devices, wherein a shared key that has been pre-communicated between the terminal device and the control center or another terminal device is required to generate a subsequent security key through the shared key. This method can not only ensure the security of communication, but also facilitate the rapid recovery of the security key when the security key is lost, making the communication protocol more flexible and efficient.
[0027] Figure 2 is a flow chart of a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application applied to a first IoT device. As shown in the figure, the method includes the following steps S110-S140.
[0028] S110: Generate a first temporary key according to the pre-shared key, the generated first random number, and the lightweight key-based algorithm.
[0029] In this embodiment, the first IoT device is the device that actively initiates the key negotiation request, which can be a terminal device or a control center. The pre-shared key is the key negotiated between the terminal device and the control center during registration. The pre-shared key is held only by the terminal device and the control center, and no third party can possess it. There are many ways to negotiate a pre-shared key. For example, a network administrator can be configured to manually enter the pre-shared key for each IoT device upon network access, or a plaintext pre-shared key can be paired in a secure environment. It should be noted that the size of the pre-shared key can be modified, but must be at least 128 bits long. The first random number is a random number generated by the first IoT device using a random number generator and is at least 128 bits long. The first temporary key is a key used to temporarily encrypt data in the absence of a security key and is 128 bits long. The pre-shared key and the first random number are input into a lightweight key-based algorithm to automatically generate a first temporary key. By generating the first temporary key based on the pre-shared key, the generated first random number, and the lightweight key-based algorithm, normal communication can be ensured even in the absence of a security key.
[0030] In one embodiment, as shown in FIG3 , step S110 further includes steps S1101 - S1103 before step S110 .
[0031] S1101, initializing two preset random number generators, TinyMT and XSadd, according to the pre-shared key and the random number to obtain an initialization seed;
[0032] S1102. Obtain a first random number sequence and a second random number sequence according to the initialization seed, wherein the first random number sequence is a random number sequence generated by the TinyMT random number generator, and the second random number sequence is a random number sequence generated by the XSadd random number generator;
[0033] S1103: Perform a cyclic shift and an addition modulo operation on the first random number sequence and the second random number sequence to generate a required key.
[0034] In this embodiment, the random number shown may be a random number generated by an IoT device, or another random number generated based on two generated random numbers. For example, the random number may be a first random number, a second random number, and a third random number, and so on. The TinyMT random number generator mainly consists of two parts: an internal state iteration function and an output function, which has the advantages of high efficiency and low memory usage. The XSadd random number generator also consists of two parts: an internal state iteration function and an output function. The linear correlation between the random number sequences generated by its internal state iteration algorithm is relatively large. The preset TinyMT and XSadd random number generators are initialized according to the pre-shared key and the random number to obtain an initialization seed. Specifically, the pre-shared key and the random number are concatenated and input into a cryptographically secure hash function. After hash calculation, a 256-bit hash result is obtained as the initialization seed. The generation of the first temporary key is taken as an example:
[0035] Among them, the is the initialization seed, pski is the pre-shared key, nonce * After obtaining the initialization seed, the two random number generators TinyMT and XSadd are initialized by the initialization seed to obtain the first random number sequence and the second random number sequence. For ease of understanding, the first random number sequence is represented by X and the second random number sequence is represented by Y. Then, the first random number sequence and the second random number sequence are cyclically shifted and modulo-added to generate the required key. Specifically, the random number sequence is first grouped and output in 32-bit blocks to obtain x. i with y i For example, the output block is represented as <xi>Or xi, i = 0, 1, 2,.... Secondly, circularly shift x i left by r1 bits to obtain x'. i = x i <<< r1, circularly shift y i left by r2 bits to obtain y'. i = y i <<< r2; then add x' i and y' i and take the modulus with respect to 2 w to obtain the output: output = (x' i + y' i )(mod 2 w ). Finally, repeat the entire process four times and concatenate the results in sequence to obtain the updated 128-bit key. The obtained key is the first temporary key. Generate the corresponding random number and pre-shared key according to the required key. By selecting two uniformly distributed random number generators and generating keys, the generated keys still maintain the characteristic of uniform distribution, which can effectively prevent the adversary from inferring the internal state of the random number generator.
[0036] S120. Generate a key negotiation request according to the first random number, identity information, first encryption result, and first message signature, where the first encryption result is generated by the first temporary key and the session sequence number, and the first message signature is generated by the first random number, the identity information, the first temporary key, and the first encryption result, and send the key negotiation request to the second Internet of Things device.
[0037] In this embodiment, the identity information is the unique identity identifier belonging to each device, and the control center also has its unique identity identifier. The identity identifier is transparently public to entities in the Internet of Things environment. The session sequence number is a random number generated by the first or second Internet of Things device, and the session sequence number shows an increasing trend to avoid being affected by replay attacks, otherwise the key sequence negotiation fails. The key negotiation request is a request to negotiate a security key sent to the second Internet of Things device. The first encryption result is generated by the first temporary key and the session sequence number. For example, if the first Internet of Things device is the control center:
[0038] where, the is the first encryption result, is the first temporary key, Sidc is the session sequence number generated by the control center, and ENC is the encryption method. The first message signature is generated by the first random number, the identity information, the first temporary key, and the first encryption result. If the first Internet of Things device is still the control center:
[0039] Among them, the Sign the first message, is the first encryption result, is the first temporary key, SYN represents the identifier of the key negotiation request, MAC is a hash function with a secret key, and IDc and IDi are the identity information of the first IoT device and the second IoT device. After obtaining the first random number, identity information, and first encryption result, a key negotiation request can be generated based on the first random number, identity information, first encryption result, and the first message signature. Specifically, the key negotiation request is represented as:
[0040] SYN_REQ represents the key negotiation request. Other symbols are the same as those described above and are not further described here. Generating a key negotiation request based on the first random number, identity information, the first encryption result, and the first message signature, and sending the key negotiation request to the second IoT device, can strictly protect the security of the key negotiation request and facilitate verification by the second IoT device.
[0041] S130. Receive a negotiation response message returned by the second IoT device, generate a second temporary key based on a second random number carried in the negotiation response message, perform signature calculation on the second temporary key to obtain a second message signature, determine whether the second message signature is the same as the first message signature, and perform qualification authentication on the negotiation response message.
[0042] In this embodiment, the negotiation response message is the information sent by the second IoT device in response to the key negotiation request. The negotiation response message is generated in the same manner as the key negotiation request, both containing a random number. The random number carried in the negotiation response message is used as a second random number, and a second temporary key is generated based on the second random number. Specifically, the second random number and the pre-shared key are combined using the lightweight key-based algorithm to generate the second temporary key. The second temporary key is then used to perform a signature calculation to obtain a second message signature. The signature calculation process for obtaining the second message signature is the same as that for generating the first message signature, differing only in the random number and temporary key, and is not further described. After obtaining the second message signature, a determination is made as to whether the second message signature is identical to the first message signature. If they are identical, the negotiation response message originates from a legitimate source. If they are not, the key sequence process is terminated. The negotiation response message returned by the second IoT device is received and authenticated based on the second random number it carries to verify its legitimacy, thereby avoiding security key negotiation failures due to illegitimate sources.
[0043] S140. If they are the same, the negotiation reply message qualification authentication is passed, and a third random number is generated based on the first random number and the second random number. The third random number and the pre-shared key are combined to generate a security key through the lightweight key-based algorithm, and the message to be sent is encrypted according to the security key to generate an encrypted message, and the encrypted message is sent to the second IoT device.
[0044] In this embodiment, the security key is a 128-bit security key ultimately used for communication. When the negotiation reply message passes qualification authentication, a third random number is generated based on the first random number and the second random number. Specifically, the first random number and the second random number used in the negotiation process can be XORed to obtain the negotiated third random number. The third random number and the pre-shared key are combined using the lightweight key-based algorithm to generate a security key. The session sequence number used in the negotiation process is also recorded to facilitate subsequent legitimacy verification. The message to be sent can be encrypted using the security key to generate an encrypted message, and the encrypted message can be sent to the second IoT device. By generating a third random number based on the first random number and the second random number and combining it with the pre-shared key using the lightweight key-based algorithm to generate a security key, the data message to be transmitted can be encrypted to prevent tampering or forgery by an adversary.
[0045] In one embodiment, as shown in FIG4 , step S140 further includes steps S141 - S143 .
[0046] S141. Encrypt the message to be sent and the session sequence number using the security key to obtain primary encrypted data.
[0047] S142. Generate a message signature by using a signature algorithm on the primary encrypted data and the identity information;
[0048] S143. Generate the encrypted message according to the primary encrypted data, the message signature, and the identity identification information.
[0049] In this embodiment, the message to be sent is information that requires communication, and the message to be sent may be a data transmission message or a key update message, etc. The message type can be determined by the message identifier. The following example still uses the control center as the first IoT device. The message to be sent and the session sequence number are encrypted using the security key to obtain primary encrypted data. If the key to be sent is a data transmission message, the primary encrypted data is:
[0050] If the key to be sent is a key update message, the primary encrypted data is:
[0051] Wherein, the ENCData is the primary encrypted data, is the security key, Sidc is the session sequence number generated by the control center and incremented each time a message is sent, Data is the message to be sent, and ENC is the encryption code. It should be noted that the encrypted message of the key update can only be initiated by the control center. Therefore, if the encrypted message is a key update message, the first IoT device must be the control center and the second IoT device must be the terminal device. After obtaining the primary encrypted data, the primary encrypted data and the identity information can be used to generate a message signature through a signature algorithm. Specifically, if the key to be sent is a data transmission message, the message signature is: M dc =MAC(RN||DT||IDc||ENCData)
[0052] If the key to be sent is a key update message, the message signature is: M dc =MAC(RN||DT||IDc||ENCData)
[0053] Among them, M dc The encrypted message is generated based on the primary encrypted data, the message signature, and the identity information. Specifically, if the key to be sent is a data transmission message, the encrypted message is: Send dc =[RN||DT||IDc||ENCData||M dc ]
[0054] If the key to be sent is a key update message, the message signature is: Send dc =[RN||UPD||IDc||ENCData||M dc ]
[0055] Among them, the Send dc For encrypted data, UPD is the identifier for initiating a key synchronization update request. By generating the encrypted message based on the primary encrypted data, the message signature, and the identity information, data security can be better guaranteed to prevent data from being deciphered when intercepted.
[0056] In one embodiment, step S140 further includes step S1401.
[0057] S1401: If a key update response message sent by the second IoT device is received, update the security key according to the key update response message.
[0058] In this embodiment, the key update response message is generated by the second IoT device based on the encrypted message sent by the first IoT device. Specifically, if the encrypted message is a key update message, the second IoT device will return a corresponding key update response message. It should be noted that the first IoT device in this case must be the control center. Upon receiving the key update response message, the control center authenticates the message and verifies whether the session sequence number is greater than the stored session sequence number to verify the legitimacy of the message. If both authentications are successful, the control center confirms the successful key synchronization update, discards the previous session key, and uses the updated key carried in the key update response message in subsequent communications. If no key update request response is received or the key update response message is invalid, the control center increments the session sequence number and resends the key update request based on the previous session key until a valid key update response message is received. By updating the security key based on the key update response message, the correct synchronization of the security key can be effectively guaranteed. Even if problems such as device timing inaccuracy, device failure, or traffic data loss occur, key desynchronization is unlikely to occur, reducing reliance on timers and time accuracy.
[0059] Figure 5 is a flow chart of a secure communication method based on a lightweight key algorithm provided in an embodiment of the present application applied to a second IoT device. As shown in the figure, the method includes the following steps S210-240.
[0060] S210: Receive the key negotiation request sent by the first IoT device, and perform qualification authentication on the key negotiation request.
[0061] In this embodiment, the second IoT device, which can be a terminal device or a control center, receives the key agreement request sent by the first IoT device and performs authentication on the key agreement request. The specific process is the same as that used by the first IoT device to verify the negotiation response message. Specifically, the first random number carried in the key agreement request is obtained and a first temporary key is generated based on the first random number. Specifically, the first random number and the pre-shared key are combined using the lightweight key-based algorithm to generate the first temporary key. The first temporary key is then signature-calculated to obtain a temporary message signature. The signature calculation process for obtaining the temporary message signature is the same as that used by the first IoT device to generate the first message signature and will not be further described. After obtaining the temporary message signature, the temporary message signature is determined to be identical to the first message signature. If they are identical, the source of the key agreement request is legitimate and the session sequence number is stored. If they are not identical, the key sequence process is terminated. By receiving the key agreement request sent by the first IoT device and performing authentication on the key agreement request, the source identity of the message is authenticated and the message integrity is verified to have not been tampered with.
[0062] S220. If the authentication is successful, generate the negotiation response message, and send the negotiation response message to the first IoT device, wherein the negotiation response message includes the second random number.
[0063] In this embodiment, the generation process of the negotiation reply message is the same as that of the key agreement request, with the only difference being the random number, identifier, and session sequence number. Specifically, the generation process of the negotiation reply message is as follows:
[0064] Among them, the is the second encryption result, is the second temporary key, Sidi is the session number generated by the second IoT device, and ENC is the encryption method. is the second message signature value, SYN||ACK is the identifier of the negotiation reply message, IDi and IDc are the identity information, and nonce ** is the second random number, and SYN_RESP is the negotiation response message. If the authentication is successful, the negotiation response message is generated and sent to the first IoT device to jointly generate a security key.
[0065] S230: Generate the security key according to the key negotiation request and the negotiation response message.
[0066] In this embodiment, the method of generating the security key is the same as the method of generating the security key by the first IoT device, that is, generating a third random number based on the first random number and the second random number, and using the third random number and the pre-shared key to generate a security key through the lightweight key-based algorithm, which will not be repeated here.
[0067] S240: Receive the encrypted message sent by the first IoT device, and verify the legitimacy of the encrypted message. If the verification passes, perform corresponding processing on the encrypted message.
[0068] In this embodiment, the legitimacy of the encrypted message is determined by determining whether the source of the encrypted message is legitimate and whether the session sequence number is legitimate. For example, the source of the message can be verified using the security key carried in the encrypted message, and the session sequence number in the encrypted message can be verified using the stored session sequence number. If the verification is successful, the encrypted message can be processed accordingly. For example, if the encrypted message is a data transmission message, the data in the encrypted message can be sent to the data processing layer for processing. By verifying the legitimacy of the encrypted message and performing appropriate processing on it, communication between two IoT devices can be securely achieved.
[0069] In one embodiment, as shown in FIG6 , step S240 includes steps S241 - S242 .
[0070] S241. Authenticate the message signature of the encrypted message according to the security key. If the authentication succeeds, determine that the source of the encrypted message is legitimate, and parse the encrypted message to obtain the session sequence number.
[0071] S242: Determine whether the session sequence number is greater than the stored session sequence number. If it is greater than the stored session sequence number, the legitimacy verification of the encrypted message passes.
[0072] In this embodiment, the message signature is the signature data generated during the encrypted message generation process. The message signature of the encrypted message is authenticated using the security key. Specifically, a temporary signature of the encrypted message is calculated using the security key. The temporary signature generation method is consistent with the message signature generation method described above and will not be further described here. The temporary signature is compared with the message signature. If they match, it indicates that the message has not been modified and originated from the first IoT device. The encrypted message is then determined to be legitimate, and the encrypted message is parsed to obtain the session sequence number. If they do not match, the packet is discarded and subsequent operations cease. After determining that the encrypted message is legitimate, the security key is used to decrypt the encrypted data to obtain the primary encrypted data, and the session sequence number is obtained from the initial encrypted data. A determination is made as to whether the session sequence number is greater than the stored session sequence number. If so, the encrypted message passes the legitimacy verification and is stored. If it is equal to or less than the stored session sequence number, the encrypted message is considered expired or an attack message and is discarded. By authenticating the legitimacy of encrypted messages, various attacks such as tampering, forgery, and replay can be prevented while ensuring data confidentiality and privacy.
[0073] In one embodiment, as shown in FIG7 , step S240 includes steps S243 - S244 .
[0074] S243. If the encrypted message is a key update message, generate an updated key according to the lightweight key algorithm;
[0075] S244: Generate the key update response message according to the updated key, the key update identifier, and the identity information, and send the key update response message to the first IoT device.
[0076] In this embodiment, the encrypted message data can determine the message type based on the identifier. If the message type is a key update message, the updated key is generated based on the lightweight key algorithm. It should be noted that the encrypted message of the key update can only be initiated by the control center. Therefore, if the encrypted message is a key update message, the first Internet of Things device must be the control center and the second Internet of Things device must be the terminal device. The updated key is generated based on the lightweight key algorithm, and the key update response message is generated based on the updated key, the key update identifier and the identity information, and the key update response message is sent to the first Internet of Things device (control center). The key update response message is generated in the same way as the encrypted message, only the identifier is different, specifically: M di =MAC(RN||UPD||ACK||IDi||ENCData) Send di =[RN||UPD||ACK||IDi||ENCData||M di ]
[0077] Among them, the To update the key, UPD||ACK is the key update identifier, IDi is the terminal device's identity information, and other identifiers are the same as above and are not repeated here. Sending the key update response message to the first IoT device completes the data update. Updating the security key effectively ensures that the key is correctly and synchronously updated. Even if problems such as inaccurate device timing, device failure, and traffic data packet loss occur, it is unlikely to cause key desynchronization, reducing dependence on timers and time accuracy. Even if key desynchronization occurs, synchronization can be restored by renegotiating the key sequence.
[0078] In addition, to enhance the completeness of this application, embodiments of this application also include a secure communication method between two terminal devices based on a lightweight key algorithm. This method is similar to the secure communication method described above between a terminal device and a control center, with only minor differences. Specifically, the control center generates a pre-shared key between the two terminal devices based on the communication permissions of both parties, determining whether both parties have permission to communicate. If both parties have permission, the pre-shared key is generated and encrypted for transmission to both terminal devices. The key negotiation request between the two terminal devices is initiated by one of them, without the intervention of the control center. However, if necessary, the control center can monitor data packets between the two terminal devices and generate a key sequence between them to achieve monitoring purposes. The process of encrypting the message to be sent using the security key is the same as the encryption process described above between the terminal device and the control center, except that the message source identifier and session sequence number are different. Each secure communication channel has a pair of independent session sequence numbers that are incremented during communication. Key updates between the two terminal devices are performed slightly differently than between the terminal devices and the control center. To avoid issues such as inaccurate timing and energy consumption in the terminal devices, the timing of key updates is determined by the control center. The control center periodically sends key synchronization update requests to prompt key updates. The key synchronization update request and response are similar to the communication method between the terminal device and the control center, so they will not be repeated here.
[0079] Corresponding to the above-mentioned secure communication method based on a lightweight key algorithm, the present application also provides a secure communication device based on a lightweight key algorithm. This secure communication device based on a lightweight key algorithm includes a unit for executing the above-mentioned secure communication method based on a lightweight key algorithm. The device can be configured in a terminal such as a desktop computer, tablet computer, or laptop computer. Figure 8 is a schematic block diagram 300 of a secure communication device based on a lightweight key algorithm provided in an embodiment of the present application, applied to a first IoT device. Figure 9 is a schematic block diagram 400 of a secure communication device based on a lightweight key algorithm provided in an embodiment of the present application, applied to a first IoT device.
[0080] As shown in FIG8 , the secure communication device based on the lightweight key algorithm is applied to the first IoT device and includes a temporary generation unit 310 , a request generation unit 320 , an authentication unit 330 and an encryption unit 240 .
[0081] Temporary generation 310 is used to generate a first temporary key according to the pre-shared key, the generated first random number, and the lightweight key-based algorithm.
[0082] In one embodiment, the temporary generation 310 includes an initialization unit, a randomization unit, and an operation unit.
[0083] An initialization unit, configured to initialize two preset random number generators, TinyMT and XSadd, according to the pre-shared key and the random number, and obtain an initialization seed;
[0084] a random unit, configured to obtain a first random number sequence and a second random number sequence according to the initialization seed, wherein the first random number sequence is a random number sequence generated by the TinyMT random number generator, and the second random number sequence is a random number sequence generated by the XSadd random number generator;
[0085] The operation unit is used to perform a cyclic shift and an addition modulo operation on the first random number sequence and the second random number sequence to generate a required key.
[0086] a request generating unit 320, configured to generate a key agreement request based on the first random number, the identity information, the first encryption result, and a first message signature, wherein the first encryption result is generated using the first temporary key and the session sequence number, and the first message signature is generated using the first random number, the identity information, the first temporary key, and the first encryption result, and send the key agreement request to the second IoT device;
[0087] an authentication unit 330 configured to receive a negotiation response message returned by the second IoT device, generate a second temporary key based on a second random number carried in the negotiation response message, perform signature calculation on the second temporary key to obtain a second message signature, determine whether the second message signature is identical to the first message signature, and perform qualification authentication on the negotiation response message;
[0088] The encryption unit 340 is configured to: if the two random numbers are the same, the negotiation reply message qualification authentication is passed, and a third random number is generated based on the first random number and the second random number; the third random number and the pre-shared key are combined to generate a security key based on the lightweight key algorithm; the message to be sent is encrypting based on the security key to generate an encrypted message; and the encrypted message is sent to the second IoT device.
[0089] In one embodiment, the encryption unit 340 includes a primary encryption unit, a signature unit, a generation unit, and an update unit.
[0090] a primary encryption unit, configured to encrypt the message to be sent and the session sequence number using the security key to obtain primary encrypted data;
[0091] A signature unit, configured to generate a message signature by combining the primary encrypted data and the identity information through a signature algorithm;
[0092] a generating unit, configured to generate the encrypted message according to the primary encrypted data, the message signature, and the identity identification information;
[0093] an updating unit, configured to update the security key according to the key update response message if a key update response message is received from the second Internet of Things device.
[0094] As shown in FIG9 , the secure communication device based on the lightweight key algorithm is applied to the second IoT device and includes a receiving unit 410 , a response generating unit 420 , a key generating unit 430 and a verification unit 440 .
[0095] The receiving unit 410 is configured to receive the key negotiation request sent by the first IoT device and perform qualification authentication on the key negotiation request;
[0096] a response generating unit 420, configured to generate the negotiation response message if the authentication is successful, and send the negotiation response message to the first IoT device, wherein the negotiation response message includes the second random number;
[0097] A key generation unit 430 is configured to generate the security key according to the key negotiation request and the negotiation response message;
[0098] The verification unit 440 is configured to receive the encrypted message sent by the first IoT device, verify the legitimacy of the encrypted message, and perform corresponding processing on the encrypted message if the verification is successful.
[0099] In one embodiment, the verification unit 440 includes a parsing unit and a judgment unit.
[0100] a parsing unit, configured to authenticate the message signature of the encrypted message according to the security key, determine that the source of the encrypted message is legitimate if the authentication is successful, and parse the encrypted message to obtain the session sequence number;
[0101] The judging unit is used to judge whether the session sequence number is greater than the stored session sequence number. If it is greater than the stored session sequence number, the legitimacy verification of the encrypted message is passed.
[0102] In one embodiment, the verification unit 440 further includes a first update unit and an update response unit.
[0103] A first updating unit, configured to generate an updated key according to the lightweight key-based algorithm if the encrypted message is a key update message;
[0104] An update response unit is configured to generate the key update response message according to the update key, the key update identifier, and the identity information, and send the key update response message to the first Internet of Things device.
[0105] It should be noted that technical personnel in the relevant field can clearly understand that the specific implementation process of the above-mentioned secure communication device based on the lightweight key algorithm and each unit can refer to the corresponding description in the aforementioned method embodiment. For the convenience and conciseness of the description, it will not be repeated here.
[0106] The above-mentioned secure communication device based on the lightweight key algorithm can be implemented in the form of a computer program, and the computer program can be run on the computer device shown in FIG10 .
[0107] Please refer to Figure 10, which is a schematic block diagram of a computer device provided in an embodiment of the present application. The computer device 500 can be a terminal or a server. The terminal can be a smart phone, tablet computer, laptop computer, desktop computer, personal digital assistant, wearable device, or other electronic device with communication capabilities. The server can be a standalone server or a server cluster consisting of multiple servers.
[0108] 10 , the computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a device bus 501 , wherein the memory may include a non-volatile storage medium 503 and an internal memory 504 .
[0109] The non-volatile storage medium 503 can store an operating device 5031 and a computer program 5032. The computer program 5032 includes program instructions, which, when executed, can enable the processor 502 to execute a secure communication method based on a lightweight key algorithm.
[0110] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.
[0111] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a secure communication method based on a lightweight key algorithm.
[0112] The network interface 505 is used to communicate with other devices over a network. Those skilled in the art will appreciate that the structure shown in FIG10 is merely a block diagram of a portion of the structure related to the present invention, and does not limit the computer device 500 to which the present invention is applied. A specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different arrangement of components.
[0113] The processor 502 is configured to run a computer program 5032 stored in the memory to implement the steps of the above method.
[0114] It should be understood that in the embodiment of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0115] Those skilled in the art will appreciate that all or part of the steps in the method of the above-described embodiment can be implemented by instructing the relevant hardware through a computer program. The computer program includes program instructions, which can be stored in a storage medium that is computer-readable. The program instructions are executed by at least one processor in the computer device to implement the steps of the above-described method embodiment.
[0116] Therefore, the present application also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program, wherein the computer program includes program instructions. When the program instructions are executed by a processor, the processor performs the steps of the above method.
[0117] The storage medium may be any computer-readable storage medium that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.
[0118] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0119] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of each unit is merely a logical functional division, and other division methods may be used in actual implementation. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not implemented.
[0120] The steps in the method of the embodiment of the present application can be adjusted in order, combined, and deleted according to actual needs. The units in the device of the embodiment of the present application can be combined, divided, and deleted according to actual needs. In addition, the functional units in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into a single unit.
[0121] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, terminal, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application.
[0122] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.< / xi>
Claims
1. A secure communication method based on a lightweight key algorithm, applied to a first IoT device, characterized in that: The method comprises: Generate a first temporary key according to the pre-shared key, the generated first random number and the lightweight key algorithm; Generate a key negotiation request according to the first random number, the identity information, the first encryption result, and the first message signature, wherein the first encryption result is generated by the first temporary key and the session sequence number, the first message signature is generated by the first random number, the identity information, the first temporary key, and the first encryption result, and send the key negotiation request to the second Internet of Things device; Receive a negotiation reply message returned by the second IoT device, generate a second temporary key according to a second random number carried in the negotiation reply message, perform signature calculation on the second temporary key to obtain a second message signature, determine whether the second message signature is the same as the first message signature, and perform qualification authentication on the negotiation reply message; If they are the same, the negotiation reply message qualification authentication is passed, and a third random number is generated based on the first random number and the second random number, the third random number and the pre-shared key are used to generate a security key based on the lightweight key algorithm, and the message to be sent is encrypted according to the security key to generate an encrypted message, and the encrypted message is sent to the second Internet of Things device.
2. The method according to claim 1, characterized in that: The lightweight key algorithm includes: Initialize two preset random number generators, TinyMT and XSadd, according to the pre-shared key and the random number to obtain an initialization seed; Obtain a first random number sequence and a second random number sequence according to the initialization seed, wherein the first random number sequence is a random number sequence generated by the TinyMT random number generator, and the second random number sequence is a random number sequence generated by the XSadd random number generator; The first random number sequence and the second random number sequence are subjected to cyclic shift and addition modulo operation to generate a required key.
3. The method according to claim 1, characterized in that The step of encrypting the message to be sent according to the security key to generate an encrypted message includes: Encrypt the message to be sent and the session sequence number by using the security key to obtain primary encrypted data; Generate a message signature by using a signature algorithm to combine the primary encrypted data and the identity information; The encrypted message is generated according to the primary encrypted data, the message signature and the identity identification information.
4. The method according to claim 1, characterized in that After the step of sending the encrypted message to the second IoT device, the method further includes: If a key update response message is received from the second IoT device, The security key is updated.
5. A secure communication method based on a lightweight key algorithm, applied to a second IoT device, characterized in that: include: Receiving a key negotiation request sent by a first Internet of Things device, and performing qualification authentication on the key negotiation request; If the authentication is successful, a negotiation reply message is generated, and the negotiation reply message is sent to the first IoT device, wherein the negotiation reply message includes a second random number; generating a security key according to the key negotiation request and the negotiation response message; Receive the encrypted message sent by the first IoT device, and verify the legitimacy of the encrypted message. If the verification passes, perform corresponding processing on the encrypted message.
6. The method according to claim 5, characterized in that The step of verifying the legitimacy of the encrypted message comprises: Authenticating the message signature of the encrypted message according to the security key, determining that the source of the encrypted message is legitimate if the authentication is successful, and parsing the encrypted message to obtain the session sequence number; It is determined whether the session sequence number is greater than the stored session sequence number. If it is greater than the stored session sequence number, the legitimacy verification of the encrypted message is passed.
7. The method according to claim 5, characterized in that The step of performing corresponding processing on the encrypted message comprises: If the encrypted message is a key update message, generating an update key according to the lightweight key-based algorithm; A key update response message is generated according to the updated key, the key update identifier and the identity information, and the key update response message is sent to the first Internet of Things device.
8. A secure communication device based on a lightweight key algorithm, characterized in that: The method comprises a unit for executing the method according to any one of claims 1 to 4, or comprises a unit for executing the method according to any one of claims 5 to 7.
9. A computer device, characterized in that: The computer device includes a memory and a processor connected to the memory; the memory is used to store a computer program; the processor is used to run the computer program stored in the memory to execute the steps of the method as described in any one of claims 1 to 4 or to execute the steps of the method as described in any one of claims 5 to 7.
10. A storage medium, characterized in that: The storage medium stores a computer program, which includes program instructions. When the program instructions are executed by a processor, they can implement the steps of the method as described in any one of claims 1 to 4, or implement the steps of the method as described in any one of claims 5 to 7.
Citation Information
Patent Citations
Lightweight message transmission method for end-to-end intelligent device communication in Internet of Things cloud
CN111885058A
Lightweight access authentication method and system for power Internet of Things equipment based on IBC system
CN113704736A
Authentication method and device of electric power internet of things terminal equipment
CN116707793A
Secure communication method and device based on lightweight key algorithm, equipment and medium
CN117335981A
Lightweight and escrow-less authenticated key agreement for the internet of things
US20190215154A1
Cited By
Communication session key negotiation method, device, equipment and medium
CN120658389A