Bluetooth communication method, apparatus and system, and storage medium and electronic device
By generating different private addresses and encryption signature technologies in the cryptographic resource management system, the security problems in existing Bluetooth communication are solved, and the security of Bluetooth communication and the confidentiality and integrity of transmission are realized.
Patent Information
- Application Number
- PCT/CN2024/104586
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-15
- Filing Date
- 2024-07-10
- Publication Date
- 2025-05-22
AI Technical Summary
Existing Bluetooth communications have communication security issues, such as multiple Bluetooth address masquerading attacks and security vulnerabilities in Bluetooth protocols, resulting in risks of network identity forgery, data redirection and data breaches.
By generating different private addresses in the password resource management system, the risk of being attacked is reduced, and the transmission of password resources is ensured securely through encryption and signatures. The specific steps include obtaining the password resource application of the source Bluetooth device, matching the application key, generating the password resource, encrypting and signing, and issuing the signature and ciphertext to the corresponding device.
It realizes the generation of different private addresses in each communication, reduces the risk of being attacked, ensures the security of Bluetooth communication, and ensures the transmission confidentiality and integrity of password resources through encryption and signature.
Smart Images

Figure CN2024104586_22052025_PF_FP_ABST
Abstract
Description
Bluetooth communication method, device, system, storage medium and electronic device Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a Bluetooth communication method, a Bluetooth communication device, a Bluetooth communication system, a machine-readable storage medium, and an electronic device. Background Art
[0002] Bluetooth is a typical communication technology for IoT communications. As a local communication method, Bluetooth communication can be used in various application scenarios, such as smart home scenarios and power application scenarios.
[0003] However, the physical address (Media Access Control Address, MAC) in traditional Bluetooth communications is usually fixed, which can lead to multiple Bluetooth address spoofing attacks. In this case, malicious nodes exploit vulnerabilities in the protocol design and implementation to impersonate trusted devices, leading to security threats such as network identity forgery and data redirection. Attackers can identify devices and launch attacks by monitoring and analyzing Bluetooth communication traffic. Secondly, as a standard communication protocol, the Bluetooth protocol has security vulnerabilities. Bluetooth devices perform authentication and encryption operations during the pairing process. However, if there are security issues in the pairing process, hackers can obtain the encryption key used in the pairing process through means such as man-in-the-middle attacks, thereby eavesdropping on and decrypting Bluetooth communication data, leading to the risk of data leakage.
[0004] Therefore, existing Bluetooth communications have communication security issues.
[0005] Summary of the Invention
[0006] The purpose of the embodiments of the present invention is to provide a Bluetooth communication method, a Bluetooth communication device, a Bluetooth communication system, a machine-readable storage medium and an electronic device. The Bluetooth communication method can generate a different private address during each communication, thereby reducing the risk of attack and ensuring the security of Bluetooth communication.
[0007] In order to achieve the above-mentioned object, the first aspect of the present application provides a Bluetooth communication method applied to a cryptographic resource management system, the Bluetooth communication method comprising:
[0008] Obtaining a cryptographic resource request sent by a source Bluetooth device; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information, and multiple random numbers;
[0009] Based on the source Bluetooth device information and the destination Bluetooth device information, matching the application key of the source Bluetooth device and the application key of the destination Bluetooth device from a plurality of preset Bluetooth device application keys;
[0010] Generate a cryptographic resource based on an application key of the source Bluetooth device, an application key of the destination Bluetooth device, and a plurality of random numbers;
[0011] Encrypting the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext;
[0012] Sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on the preset master station private key to generate a first signature and a second signature;
[0013] Sending the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and sending the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the cryptographic resources;
[0014] The cryptographic resource is used to generate a private address.
[0015] In an embodiment of the present application, the cryptographic resource management system is pre-set with security chip serial numbers of multiple Bluetooth devices, the multiple random numbers include a first random number, a second random number, and a third random number, and the cryptographic resources include a Z algorithm instance, a temporary key, and a session key;
[0016] The generating of cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and a plurality of random numbers includes:
[0017] Distributing the application key of the source Bluetooth device based on the first random number to obtain a temporary key K1;
[0018] Distributing the application key of the destination Bluetooth device based on the second random number to obtain a temporary key K2;
[0019] Generate a Z algorithm instance Z1 using the Z cryptographic algorithm based on the temporary key K1, and generate a Z algorithm instance Z2 using the Z cryptographic algorithm based on the temporary key K2;
[0020] Distributing the application key of the source Bluetooth device based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key;
[0021] A cryptographic resource is obtained according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key.
[0022] In the embodiment of the present application, the process of obtaining the preset multiple Bluetooth device application keys includes:
[0023] Register multiple Bluetooth devices and obtain security chip information of each Bluetooth device, wherein the security chip information includes at least a security chip serial number;
[0024] The security chip serial numbers of the various Bluetooth devices are dispersed based on the preset service root keys to obtain application keys of the multiple Bluetooth devices.
[0025] A second aspect of the present application provides a Bluetooth communication method, applied to a source Bluetooth device, comprising:
[0026] Obtaining a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained by the Bluetooth communication method applied to the cryptographic resource management system;
[0027] Verifying the first signature using a preset master station certificate, and if the verification of the first signature is successful, decrypting the first cryptographic resource ciphertext using a preset application key of the source Bluetooth device to obtain a cryptographic resource;
[0028] Based on the password resource, Bluetooth communication is performed with the target Bluetooth device.
[0029] In the embodiment of the present application, the cryptographic resources include a Z algorithm instance, a temporary key, and a session key;
[0030] The performing Bluetooth communication with the destination Bluetooth device based on the password resource includes:
[0031] Constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource;
[0032] Based on the private address, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
[0033] In the embodiment of the present application, the temporary key includes: temporary key K1 and temporary key K2; the Z algorithm instance includes: Z algorithm instance Z1 and Z algorithm instance Z2;
[0034] The constructing of a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes:
[0035] Obtaining the current local time and region code, and generating a timestamp based on the current local time;
[0036] Based on the temporary key K1 and the Z algorithm instance Z1, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address;
[0037] Based on the temporary key K2 and the Z algorithm instance Z2, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the destination Bluetooth device address;
[0038] Constructing a private address of the source Bluetooth device based on the encrypted ciphertext of the source Bluetooth device address, the timestamp and the region code;
[0039] Based on the encrypted ciphertext of the destination Bluetooth device address, the timestamp and the regional code, a private address of the destination Bluetooth device is constructed.
[0040] In an embodiment of the present application, performing Bluetooth communication with a destination Bluetooth device based on the private address and using a session key in the cryptographic resource includes:
[0041] Sending a connection establishment request to the destination Bluetooth device based on the source Bluetooth device private address and the destination Bluetooth device private address;
[0042] When the connection establishment request is sent successfully, obtain the private address to be verified sent by the target Bluetooth device;
[0043] The legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification passes, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
[0044] In the embodiment of the present application, when the verification is successful, using the session key in the cryptographic resource to perform Bluetooth communication with the destination Bluetooth device includes:
[0045] Performing dynamic session key negotiation with a destination Bluetooth device using the session key in the cryptographic resource to obtain a temporary session key;
[0046] A secure communication channel is established based on the temporary session key to perform Bluetooth communication.
[0047] In the embodiment of the present application, after establishing the secure communication channel, the following steps are further included:
[0048] Acquiring a local channel state, and constructing a channel map and a channel priority table based on the local channel state;
[0049] Obtain your own business information and establish a business priority table based on the level and priority of your own business.
[0050] In the embodiment of the present application, it also includes:
[0051] The channel map and channel priority table are sent to all Bluetooth devices in the network in a broadcasting manner.
[0052] In the embodiment of the present application, it also includes:
[0053] Switching data channels according to a channel selection algorithm;
[0054] Using the switched data channel to obtain current channel status information and current service information;
[0055] Comparing the current channel state information with the channel priority table to obtain the priority of the current channel;
[0056] According to the priority of the current channel, the service priority table and the current service information, the service channel is switched to obtain the most suitable channel.
[0057] In an embodiment of the present application, switching the service channel according to the priority of the current channel, the service priority table and the current service information to obtain the most suitable channel includes:
[0058] According to the service priority table and current service information, query and obtain the current service priority;
[0059] Determining whether the current service priority matches the priority of the current channel;
[0060] If it is determined that the current service priority matches the priority of the current channel, then using the current channel for communication;
[0061] If it is determined that the current service priority does not match the priority of the current channel, a channel that matches the current service priority is selected from the channel priority table and the channel is used for communication.
[0062] In the embodiment of the present application, it also includes:
[0063] Periodically acquiring a channel status, and updating the channel priority table based on the channel status to obtain a new channel priority table;
[0064] The new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
[0065] In the embodiment of the present application, it also includes:
[0066] During the communication process, the size of the interactive data packet determines whether to dynamically adjust the time slot of the current communication;
[0067] When the size of the interactive data packet is greater than the preset threshold, the proportion of the time slot used for the current communication is adjusted according to the current service priority to achieve dynamic adjustment of the time slot.
[0068] In the embodiment of the present application, adjusting the proportion of the time slot used for the current communication according to the current service priority to achieve dynamic adjustment of the time slot includes:
[0069] generating a plurality of service weights according to the current service priority and the service priority table;
[0070] Based on the proportion of each service weight, the proportion of the time slot used for current communication is adjusted to achieve dynamic adjustment of the time slot.
[0071] In the embodiment of the present application, adjusting the proportion of time slots used for current communication based on the proportion of each service weight includes:
[0072] Initialize the total time slot length;
[0073] Calculate the adjusted time slot length of each connection based on the proportion of each service weight and the total time slot length;
[0074] Based on the adjusted time slot length of each connection, a time slot update is performed on each connection in the current communication to adjust the proportion of time slots used for the current communication.
[0075] A third aspect of the present application provides a Bluetooth communication method, applied to a target Bluetooth device, comprising:
[0076] Obtaining a second cryptographic resource ciphertext and a second signature, wherein the second cryptographic resource ciphertext and the second signature are obtained by the Bluetooth communication method applied to the cryptographic resource management system;
[0077] Verifying the second signature using a preset master station certificate, and if the verification of the second signature is successful, decrypting the second cryptographic resource ciphertext using a preset application key of the destination Bluetooth device to obtain the cryptographic resource;
[0078] Based on the cryptographic resource, Bluetooth communication is performed with the source Bluetooth device.
[0079] In the embodiment of the present application, the cryptographic resources include a Z algorithm instance, a temporary key, and a session key;
[0080] The performing Bluetooth communication with the source Bluetooth device based on the password resource includes:
[0081] Constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource;
[0082] Based on the private address, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device.
[0083] In the embodiment of the present application, the temporary key includes: temporary key K1 and temporary key K2; the Z algorithm instance includes: Z algorithm instance Z1 and Z algorithm instance Z2;
[0084] The constructing of a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes:
[0085] Obtaining the current local time and region code, and generating a timestamp based on the current local time;
[0086] Based on the temporary key K1 and the Z algorithm instance Z1, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address;
[0087] Based on the temporary key K2 and the Z algorithm instance Z2, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the destination Bluetooth device address;
[0088] Constructing a private address of the source Bluetooth device based on the encrypted ciphertext of the source Bluetooth device address, the timestamp and the region code;
[0089] Based on the encrypted ciphertext of the destination Bluetooth device address, the timestamp and the regional code, a private address of the destination Bluetooth device is constructed.
[0090] In an embodiment of the present application, performing Bluetooth communication with a source Bluetooth device based on the private address and using a session key in the cryptographic resource includes:
[0091] In response to a connection establishment request sent by a source Bluetooth device, obtaining a private address to be verified sent by the source Bluetooth device;
[0092] The legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification passes, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device.
[0093] In an embodiment of the present application, when the verification is successful, using the session key in the cryptographic resource to perform Bluetooth communication with the source Bluetooth device includes:
[0094] Performing dynamic session key negotiation with a source Bluetooth device using the session key in the cryptographic resource to obtain a temporary session key;
[0095] A secure communication channel is established based on the temporary session key to perform Bluetooth communication.
[0096] In the embodiment of the present application, after establishing the secure communication channel, the following steps are further included:
[0097] Acquiring a local channel state, and constructing a channel map and a channel priority table based on the local channel state;
[0098] Obtain your own business information and establish a business priority table based on the level and priority of your own business.
[0099] In the embodiment of the present application, it also includes:
[0100] The channel map information and the channel priority table are sent to all Bluetooth devices in the network in a broadcast manner.
[0101] In the embodiment of the present application, it also includes:
[0102] Periodically acquiring a channel status, and updating the channel priority table based on the channel status to obtain a new channel priority table;
[0103] The new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
[0104] A fourth aspect of the present application provides a Bluetooth communication system, including a cryptographic resource management system, a source Bluetooth device, and a destination Bluetooth device;
[0105] The source Bluetooth device is used to send a cryptographic resource request to the cryptographic resource management system; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers;
[0106] The cryptographic resource management system is used to match the application key of the source Bluetooth device and the application key of the destination Bluetooth device from the application keys of multiple preset Bluetooth devices based on the source Bluetooth device information and the destination Bluetooth device information; generate cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and multiple random numbers; encrypt the cryptographic resources using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on the preset master station private key to generate a first signature and a second signature; send the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and send the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resources; wherein the cryptographic resources are used to generate a private address.
[0107] A fifth aspect of the present application provides a Bluetooth communication device, which is applied to a cryptographic resource management system. The Bluetooth communication device includes:
[0108] An acquisition module is used to acquire a cryptographic resource request sent by a source Bluetooth device; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information, and multiple random numbers;
[0109] An application key matching module, configured to match an application key of a source Bluetooth device and an application key of a destination Bluetooth device from a plurality of preset Bluetooth device application keys based on the source Bluetooth device information and the destination Bluetooth device information;
[0110] A cryptographic resource generation module, configured to generate cryptographic resources based on an application key of the source Bluetooth device, an application key of the destination Bluetooth device, and a plurality of random numbers;
[0111] A first encryption module is configured to encrypt the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device, respectively, to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; wherein the cryptographic resource is used to generate a private address;
[0112] A first signature module is configured to sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on a preset master station private key to generate a first signature and a second signature;
[0113] The sending module is used to send the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and send the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resources.
[0114] In an embodiment of the present application, the cryptographic resource management system is pre-set with security chip serial numbers of multiple Bluetooth devices, the multiple random numbers include a first random number, a second random number, and a third random number, and the cryptographic resources include a Z algorithm instance, a temporary key, and a session key;
[0115] The password resource generation module includes:
[0116] A first dispersion processing unit, configured to perform dispersion processing on the application key of the source Bluetooth device based on the first random number to obtain a temporary key K1;
[0117] A second dispersing processing unit, configured to perform dispersing processing on the application key of the destination Bluetooth device based on the second random number to obtain a temporary key K2;
[0118] an algorithm instance unit, configured to generate a Z algorithm instance Z1 by using the Z cryptographic algorithm based on the temporary key K1, and to generate a Z algorithm instance Z2 by using the Z cryptographic algorithm based on the temporary key K2;
[0119] a third decentralized processing unit, configured to perform decentralized processing on the application key of the source Bluetooth device based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key;
[0120] The resource generation unit is used to obtain cryptographic resources according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key.
[0121] A sixth aspect of the present application provides a Bluetooth communication device, applied to a source Bluetooth device, comprising:
[0122] A first cryptographic resource acquisition module, configured to acquire a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained via the Bluetooth communication device applied to the cryptographic resource management system;
[0123] a first signature verification module, configured to verify the first signature using a preset master station certificate, and if the verification of the first signature is successful, decrypt the first cryptographic resource ciphertext using a preset application key of the source Bluetooth device to obtain the cryptographic resource;
[0124] The first Bluetooth communication module is configured to perform Bluetooth communication with a target Bluetooth device based on the password resource.
[0125] A seventh aspect of the present application provides a Bluetooth communication device, applied to a target Bluetooth device, comprising:
[0126] A second cryptographic resource acquisition module, configured to acquire a second cryptographic resource ciphertext and a second signature, the second cryptographic resource ciphertext and the second signature being obtained via the aforementioned Bluetooth communication device applied to the cryptographic resource management system;
[0127] A second signature verification module is configured to verify the second signature using a preset master station certificate, and if the second signature verification is successful, decrypt the second cryptographic resource ciphertext using a preset application key of the destination Bluetooth device to obtain the cryptographic resource;
[0128] The second Bluetooth communication module is configured to perform Bluetooth communication with a source Bluetooth device based on the password resource.
[0129] In an eighth aspect, the present application provides an electronic device, the electronic device comprising:
[0130] at least one processor;
[0131] a memory connected to the at least one processor;
[0132] The memory stores instructions that can be executed by the at least one processor, and the at least one processor implements the above-mentioned Bluetooth communication method by executing the instructions stored in the memory.
[0133] A ninth aspect of the present application provides a machine-readable storage medium having instructions stored thereon, which, when executed by a processor, configures the processor to execute the above-mentioned Bluetooth communication method.
[0134] Through the above technical solution, a cryptographic resource application sent by a source Bluetooth device is obtained in a cryptographic resource management system; the cryptographic resource application includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers; based on the source Bluetooth device information and destination Bluetooth device information, the application key of the source Bluetooth device and the application key of the destination Bluetooth device are matched from multiple preset Bluetooth device application keys; based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and multiple random numbers, a cryptographic resource is generated; wherein, the cryptographic resource is used to generate a private address; the cryptographic resource is encrypted using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; the first cryptographic resource ciphertext and the second cryptographic resource ciphertext are signed respectively based on a preset master station private key to generate a first signature and a second signature; the first signature and the first cryptographic resource ciphertext are sent to the source Bluetooth device, and the second signature and the second cryptographic resource ciphertext are sent to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resources. Since the cryptographic resources are obtained based on random numbers and application passwords, the random numbers for each communication are different, and the cryptographic resources obtained are also different, so that different private addresses can be generated in each communication, reducing the risk of attack and ensuring the security of Bluetooth communication. By encrypting and signing the cryptographic resources, the confidentiality and integrity of the cryptographic resource transmission are guaranteed. The MAC address of traditional Bluetooth is usually assigned by the device manufacturer, and there may be conflicts in the MAC addresses of different devices, resulting in communication failures. The present invention can avoid such conflicts by uniformly generating cryptographic resources through the cryptographic resource management system, thereby improving the compatibility between devices and the stability of communication. The MAC address of traditional Bluetooth is limited, and when the number of devices increases, there may be a shortage of addresses. The cryptographic resources generated by the cryptographic resource management system are temporarily generated according to business applications, and are released immediately after the business time limit is exceeded. In theory, it supports unlimited device connections.
[0135] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0136] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following detailed description, they are used to explain the embodiments of the present invention, but do not constitute a limitation of the embodiments of the present invention. In the accompanying drawings:
[0137] FIG1 schematically shows a schematic diagram of a Z algorithm Bluetooth power operation and maintenance application scenario according to an embodiment of the present application;
[0138] FIG2 schematically shows a flow chart of a Bluetooth communication method applied to a cryptographic resource management system according to an embodiment of the present application;
[0139] FIG3 schematically shows a schematic diagram of the architecture of a Z algorithm cryptographic resource management system according to an embodiment of the present application;
[0140] FIG4 schematically shows a flow chart of an example of a Z algorithm and generation and distribution of session keys according to an embodiment of the present application;
[0141] FIG5 schematically shows a private address generation process diagram according to an embodiment of the present application;
[0142] FIG6 schematically shows a private address verification process diagram according to an embodiment of the present application;
[0143] FIG7 schematically shows a diagram of a Bluetooth private address generation framework according to an embodiment of the present application;
[0144] FIG8 schematically shows a schematic diagram of an operation and maintenance solution according to an embodiment of the present application;
[0145] FIG9 schematically shows a diagram of a Bluetooth management application software framework according to an embodiment of the present application;
[0146] FIG10 schematically illustrates a secure communication channel establishment process according to an embodiment of the present application;
[0147] FIG11 schematically shows a schematic diagram of an application scenario of intelligent power distribution operation and maintenance according to an embodiment of the present application;
[0148] FIG12 schematically shows a schematic diagram of a home Bluetooth application scenario according to an embodiment of the present application;
[0149] FIG13 schematically shows a schematic diagram of a multi-master and multi-slave Bluetooth network application scenario according to an embodiment of the present application;
[0150] FIG14 schematically shows a control flow chart according to an embodiment of the present application;
[0151] FIG15 schematically shows a flow chart of generating a channel priority table according to an embodiment of the present application;
[0152] FIG16 schematically shows a flow chart of a Bluetooth communication method applied to a source Bluetooth device according to an embodiment of the present application;
[0153] FIG17 schematically shows a flow chart of a Bluetooth communication method applied to a destination Bluetooth device according to an embodiment of the present application;
[0154] FIG18 schematically shows a block diagram of a Bluetooth communication device applied to a cryptographic resource management system according to an embodiment of the present application;
[0155] FIG19 schematically shows a structural block diagram of a Bluetooth communication device applied to a source Bluetooth device according to an embodiment of the present application;
[0156] FIG20 schematically shows a structural block diagram of a Bluetooth communication device applied to a destination Bluetooth device according to an embodiment of the present application;
[0157] FIG21 schematically shows an internal structure diagram of a computer device according to an embodiment of the present application.
[0158] Description of Reference Numerals
[0159] 510-acquisition module; 520-application key matching module; 530-cryptographic resource generation module; 540-first encryption module; 550-first signature module; 560-issuance module; 610-first cryptographic resource acquisition module; 620-first signature verification module; 630-first Bluetooth communication module; 710-second cryptographic resource acquisition module; 720-second signature verification module; 730-second Bluetooth communication module; A01-processor; A02-network interface; A03-internal memory; A04-display screen; A05-input device; A06-non-volatile storage medium; B01-operating system; B02-computer program. DETAILED DESCRIPTION
[0160] The following describes the specific implementation of the embodiment of the present invention in detail with reference to the accompanying drawings. It should be understood that the specific implementation described herein is only used to illustrate and explain the embodiment of the present invention and is not used to limit the embodiment of the present invention.
[0161] It should be noted that if there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or suggesting their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the fact that they can be implemented by ordinary technicians in this field. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0162] This embodiment fully adopts the design concept of deep integration of user keys, algorithms and task applications, and provides a Bluetooth communication method based on a unified algorithm architecture and algorithm derivation rules (unified algorithm architecture + algorithm derivation rules) in combination with application requirements to ensure the security of cryptographic resources, Bluetooth address generation, access authentication and service data channels, thereby improving the transmission efficiency and reliability of the wireless communication system.
[0163] It should be noted that the Bluetooth communication method in this embodiment can be applied to various Bluetooth communication scenarios. In order to facilitate the description of the solution, the following mainly uses the power operation and maintenance application scenario as an example for description.
[0164] Please refer to Figure 1, which schematically shows a schematic diagram of the Z algorithm Bluetooth power operation and maintenance application scenario according to an embodiment of the present application. For the power operation and maintenance application scenario, the handheld game console / mobile phone obtains cryptographic resources from the cryptographic resource management platform through a secure access gateway, and the handheld game console / mobile phone communicates with the integrated terminal, detection platform, electricity meter, smart switch or other terminal devices through the Z algorithm Bluetooth module. The Bluetooth communication method in the present invention can achieve the following functions: Security management: Through Bluetooth connection, the device is authenticated and access controlled to prevent unauthorized personnel from operating. In addition, Bluetooth encrypts and securely transmits data to protect the security of device data. Device configuration and debugging: Bluetooth is used for device configuration and debugging. Operation and maintenance personnel connect to the device via Bluetooth and perform device parameter setting, calibration and debugging through the matching mobile phone / handheld game console application. Device monitoring and fault diagnosis: Through the Bluetooth module installed on the power equipment, the operating status and performance of the equipment are monitored in real time. Collect current, voltage collection, equipment operating status parameters, etc., and transmit the data to the monitoring system via Bluetooth. Reading and adjusting operating parameters: Realize remote operation and control of power equipment. Through the Bluetooth module connected to the equipment, operation and maintenance personnel can use mobile devices such as mobile phones / handheld game consoles to remotely control the equipment's switches, adjust parameters, etc., thereby improving operation and maintenance efficiency and reducing operational risks.
[0165] Please refer to Figures 2 and 3. Figure 2 schematically illustrates a flow chart of a Bluetooth communication method applied to a cryptographic resource management system according to an embodiment of the present application. Figure 3 schematically illustrates an architecture diagram of a Z algorithm cryptographic resource management system according to an embodiment of the present application. The cryptographic resource platform in Figure 3 is provided with a cryptographic resource management system. This embodiment provides a Bluetooth communication method applied to a cryptographic resource management system, the Bluetooth communication method comprising the following steps:
[0166] Step 210: Obtain a cryptographic resource request sent by a source Bluetooth device; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information, and multiple random numbers;
[0167] In this embodiment, before initiating a communication connection, the Bluetooth device needs to first apply for a session key and a Z algorithm instance from the cryptographic resource management platform, that is, send a cryptographic resource application. All Bluetooth devices are set with the Internet Protocol (IP) address and port of the cryptographic resource management system to facilitate connection with the cryptographic resource management system. The cryptographic resource management system manages the device and Bluetooth module, including information such as the device area, time, unique identifier, device machine code, security chip identity document (ID), Bluetooth module, etc. The above-mentioned source Bluetooth device information includes information such as the device ID and device name. Correspondingly, the destination Bluetooth device information includes information such as the device ID and device name. The above-mentioned source Bluetooth device refers to the device that submits the cryptographic resource application, and the destination Bluetooth device is the Bluetooth device to which the source Bluetooth device wants to connect.
[0168] It should be noted that the above-mentioned random number can be generated by a hardware noise source generating device, or can be a random number composed of a timestamp or an operation and maintenance area certificate. The method of generating the random number is not limited in this embodiment.
[0169] Step 220: Based on the source Bluetooth device information and the destination Bluetooth device information, match the application key of the source Bluetooth device and the application key of the destination Bluetooth device from a plurality of preset Bluetooth device application keys;
[0170] In this embodiment, the cryptographic resource management system pre-stores multiple Bluetooth device application keys. After receiving a cryptographic resource request, the corresponding application key can be matched based on the source and destination Bluetooth device information in the cryptographic resource request. Correspondingly, the application key can also be pre-written into each Bluetooth device.
[0171] In some embodiments, the process of obtaining the preset multiple Bluetooth device application keys includes:
[0172] First, multiple Bluetooth devices are registered and security chip information of each Bluetooth device is obtained, wherein the security chip information includes at least a security chip serial number.
[0173] Then, the security chip serial numbers of the respective Bluetooth devices are dispersed based on the preset service root key to obtain application keys of the plurality of Bluetooth devices.
[0174] In this embodiment, the security chip is a device that can independently generate keys and perform encryption and decryption. It has an independent processor and storage unit inside, which can store keys and feature data. When the security chip is used for encryption, the key is stored in the hardware, and the stolen data cannot be decrypted, thereby protecting business privacy and data security. Please refer to Figure 4, which schematically shows an example of the Z algorithm and a flow chart of the generation and distribution of session keys according to an embodiment of the present application. Taking Bluetooth device A and Bluetooth device B as an example, Bluetooth device A is provided with security chip A, and Bluetooth device B is provided with security chip B. The cryptographic resource management system issues security chips A and B, and uses the business root key to disperse the serial number of security chip A to generate the application key K of security chip A. A , the application key K of security chip B is generated by distributing the serial number of security chip B B At the same time, the master site certificate is sent to the security chip; Bluetooth device A and Bluetooth device B are registered in the password resource management system, security chip A is bound to Bluetooth device A, and security chip B is bound to Bluetooth device B.
[0175] It should be noted that the decentralized processing mentioned in this embodiment refers to decentralized processing using a cryptographic decentralized algorithm, which belongs to the existing technology and will not be described in detail here.
[0176] Step 230: Generate cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device, and multiple random numbers;
[0177] In some embodiments, the cryptographic resource management system is pre-set with security chip serial numbers of multiple Bluetooth devices, the multiple random numbers include a first random number, a second random number, and a third random number, and the cryptographic resources include a Z algorithm instance, a temporary key, and a session key;
[0178] The generating of cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and a plurality of random numbers includes:
[0179] First, the application key of the source Bluetooth device is dispersed based on the first random number to obtain a temporary key K1;
[0180] Then, the application key of the destination Bluetooth device is dispersed based on the second random number to obtain a temporary key K2;
[0181] Then, based on the temporary key K1, the Z cryptographic algorithm is used to generate a Z algorithm instance Z1, and based on the temporary key K2, the Z cryptographic algorithm is used to generate a Z algorithm instance Z2;
[0182] Then, the application key of the source Bluetooth device is dispersed based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key;
[0183] Finally, the cryptographic resource is obtained according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key.
[0184] In this embodiment, the Z-cipher algorithm is a domestically developed symmetric encryption algorithm based on a block cipher structure. It uses nonlinear S-boxes and confusion functions, as well as iterative round functions. It has the advantages of simple structure, high nonlinearity, and fast encryption speed. The Z-cipher algorithm adopts a design concept that deeply integrates user keys and algorithms. It uses a unified algorithm architecture and algorithm derivation rules (unified algorithm architecture + algorithm derivation rules) to provide different block algorithms for different users under the user key drive. Each algorithm instance is a customized, personalized, reversible cryptographic transformation.
[0185] To facilitate the explanation of the solution, take the above Bluetooth device A and Bluetooth device B as an example, Bluetooth device A is the source Bluetooth device, and Bluetooth device B is the destination Bluetooth device. The random numbers R1, R2, and R3 can be generated by a hardware noise source generator; the cryptographic resource management system retrieves the information of Bluetooth devices A and B, and then uses the random number R1 to disperse the application key K A Generate a temporary key K1 and disperse the application key K through the random number R2 B Generate a temporary key K2; generate Z algorithm instance Z1 and Z algorithm instance Z2 for generating Bluetooth addresses based on temporary key K1 and temporary key K2 respectively, where Z algorithm instance Z1 and temporary key K1 are used to generate the private address of Bluetooth device A, where Z algorithm instance Z2 and temporary key K2 are used to generate the private address of Bluetooth device B; use the security chip serial number and random number R3 of Bluetooth device B to apply key K A Distribute and generate session key K3.
[0186] The password resource is sent to the source Bluetooth device and the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the password resource; wherein the password resource is used to generate a private address.
[0187] In this embodiment, after obtaining the cryptographic resources, the cryptographic resource management system distributes the cryptographic resources to the source Bluetooth device and the destination Bluetooth device. The source Bluetooth device and the destination Bluetooth device generate private addresses based on the cryptographic resources to achieve Bluetooth communication. The above distribution process can be direct or encrypted.
[0188] In order to ensure the confidentiality and integrity of the password resource transmission, the password resource can be sent after encryption. The sending of the password resource to the source Bluetooth device and the destination Bluetooth device so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the password resource includes:
[0189] Step 240: Encrypt the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; wherein the cryptographic resource is used to generate a private address;
[0190] Step 250: Sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on the preset master station private key to generate a first signature and a second signature;
[0191] Step 260: Send the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and send the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the cryptographic resources.
[0192] In this embodiment, the above-mentioned preset master station private key is a private key pre-written in the password resource management system. In order to facilitate the description of the solution, take the above-mentioned Bluetooth device A and Bluetooth device B as examples, respectively using the application key K A and application key K B Encrypt the cryptographic resources (key resources include Z algorithm instance Z1, Z algorithm instance Z2, temporary key K1, temporary key K2, session key K3). The encryption process is:
[0193] E1=Enc(K A , Z1+Z2+K1+K2+K3),
[0194] E2=Enc(K B , Z1+Z2+K1+K2+K3);
[0195] Here, E1 is the first cryptographic resource ciphertext, and E2 is the second cryptographic resource ciphertext. Enc (Encryption) refers to encryption technology, an algorithm for encrypting data. After encryption, the cryptographic resource ciphertext is signed using the master's private key. The signing process is: S1 = Sign(E1), S2 = Sign(E2); where S1 is the first signature and S2 is the second signature. Finally, E1 and S1 are sent to Bluetooth device A, and E2 and S2 are sent to Bluetooth device B.
[0196] By using random numbers to disperse device keys to generate session keys, cryptographic resources are encrypted and signed based on device information and random number generation algorithm instances to ensure the confidentiality and integrity of cryptographic resource transmission.
[0197] In the above implementation process, a cryptographic resource application sent by a source Bluetooth device is obtained in a cryptographic resource management system; the cryptographic resource application includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers; based on the source Bluetooth device information and destination Bluetooth device information, the application key of the source Bluetooth device and the application key of the destination Bluetooth device are matched from multiple preset Bluetooth device application keys; based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and multiple random numbers, a cryptographic resource is generated; wherein, the cryptographic resource is used to generate a private address; the cryptographic resource is encrypted using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; the first cryptographic resource ciphertext and the second cryptographic resource ciphertext are signed respectively based on a preset master station private key to generate a first signature and a second signature; the first signature and the first cryptographic resource ciphertext are sent to the source Bluetooth device, and the second signature and the second cryptographic resource ciphertext are sent to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resource. Since the cryptographic resources are obtained based on random numbers and application passwords, the random numbers for each communication are different, and the cryptographic resources obtained are also different, so that different private addresses can be generated in each communication, reducing the risk of attack and ensuring the security of Bluetooth communication. By encrypting and signing the cryptographic resources, the confidentiality and integrity of the cryptographic resource transmission are guaranteed. The MAC address of traditional Bluetooth is usually assigned by the device manufacturer, and the MAC addresses of different devices may conflict, resulting in communication failures. In this embodiment, the unified generation of cryptographic resources by the cryptographic resource management system can avoid such conflicts, improve the compatibility between devices and the stability of communication. The MAC address of traditional Bluetooth is limited, and when the number of devices increases, there may be a shortage of addresses. The cryptographic resources generated by the cryptographic resource management system are temporarily generated according to business applications, and are released immediately after the business time limit is exceeded. In theory, it supports unlimited device connections.
[0198] Cryptographic resources include Z algorithm instances. Cryptographic resources based on multiple parameters (including device region, time, unique identifier, device machine code, chip ID, Bluetooth module and other information) of the Z algorithm instance can increase the security of Bluetooth communication pairing negotiation. The MAC address of traditional Bluetooth is usually fixed, and attackers can identify devices and attack by monitoring and analyzing Bluetooth communication traffic. However, using the Bluetooth MAC address generated by the Z algorithm instance can generate a different private address for each communication, reducing the risk of attack. The MAC address of traditional Bluetooth is a unique identifier for the device. Attackers can track the location and activity of the device by tracking the MAC address of the device. Using the Bluetooth MAC address of the Z algorithm instance can prevent the device from being tracked and increase user privacy protection.
[0199] It should be noted that the cryptographic resource management system is responsible for the online distribution of cryptographic resources. For power operation and maintenance scenarios, handheld devices, terminals, meters, and other power equipment are configured with an initial Z cryptographic algorithm instance upon shipment. This initial Z cryptographic algorithm instance is randomly assigned based on region. Each operation and maintenance communication updates the Z cryptographic algorithm for the terminal device.
[0200] This embodiment also provides a Bluetooth communication method. Please refer to Figure 16, which schematically shows a flow chart of a Bluetooth communication method applied to a source Bluetooth device according to an embodiment of the present application. The Bluetooth communication method is applied to the source Bluetooth device and includes the following steps:
[0201] Obtain cryptographic resources, which are obtained through the above-mentioned Bluetooth communication method applied to the cryptographic resource management system; accordingly, in some embodiments, the cryptographic resources are obtained when the cryptographic resource management system encrypts and signs the cryptographic resources and then sends them to the Bluetooth device.
[0202] Step 310: Obtain a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained by the Bluetooth communication method applied to the cryptographic resource management system;
[0203] Step 320: Verify the first signature using the preset master station certificate. If the verification of the first signature is successful, decrypt the first cryptographic resource ciphertext using the preset application key of the source Bluetooth device to obtain the cryptographic resource.
[0204] Among them, the first cryptographic resource ciphertext is obtained by the cryptographic resource management system using the application key of the source Bluetooth device to encrypt the cryptographic resource; the first signature is obtained by the cryptographic resource management system signing the first cryptographic resource ciphertext based on the preset master station private key.
[0205] In this embodiment, the above-mentioned preset master certificate is pre-written into the Bluetooth device and is used to verify the signature. To facilitate the description of the solution, taking the above-mentioned Bluetooth device A and Bluetooth device B as an example, Bluetooth devices A and B respectively use the master certificate to verify the cryptographic resource, that is, use the preset master certificate to verify the first signature. After the verification is successful, they use the application key K A and application key K B Decrypt and obtain Z algorithm instance Z1, Z algorithm instance Z2, temporary key K1, temporary key K2, and session key K3.
[0206] Step 330: Perform Bluetooth communication with the destination Bluetooth device based on the password resource.
[0207] The cryptographic resources include a Z algorithm instance, a temporary key, and a session key. The process of performing Bluetooth communication with a destination Bluetooth device includes the following steps:
[0208] First, construct a private address based on the Z algorithm instance and temporary key in the cryptographic resource;
[0209] Then, based on the private address, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
[0210] In this embodiment, after obtaining the password resource, Bluetooth communication can be performed based on the password resource. Taking the above example, Bluetooth device A generates a Bluetooth private address MAC based on the temporary key K1 and the Z algorithm instance Z1. A , Bluetooth device B generates Bluetooth private address MAC based on temporary key K2 and Z algorithm instance Z2 B ; Bluetooth device A and Bluetooth device B use session key K3 as session key to communicate.
[0211] In some embodiments, the temporary key includes: a temporary key K1 and a temporary key K2; the Z algorithm instance includes: a Z algorithm instance Z1 and a Z algorithm instance Z2; and constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes the following steps:
[0212] The first step is to obtain the current local time and region code, and generate a timestamp based on the current local time;
[0213] In the second step, based on the temporary key K1 and the Z algorithm instance Z1, the random code consisting of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address;
[0214] Step 3: Encrypt the random code consisting of the timestamp and the region code based on the temporary key K2 and the Z algorithm instance Z2 to obtain the encrypted ciphertext of the destination Bluetooth device address;
[0215] Step 4: construct a private address of the source Bluetooth device based on the encrypted ciphertext, timestamp and region code of the source Bluetooth device address;
[0216] The fifth step is to construct a private address of the destination Bluetooth device based on the encrypted ciphertext, timestamp and region code of the destination Bluetooth device address.
[0217] In this embodiment, the Bluetooth device address is a unique identifier of the device and has a length of 48 bits. The address type and meaning are shown in Table 1.
[0218] Table 1 Bluetooth address resolution table
[0219] Private addresses include non-resolvable private addresses and resolvable private addresses. If a Bluetooth device uses a non-resolvable private address, it must change upon each connection. This provides greater randomness, protecting the device's privacy and making it difficult to track. To generate a resolvable private address, the device must have a local identity resolution key or a peer identity resolution key. A resolvable private address is generated using a temporary key and a randomly generated 24-bit nonce. To ensure address compatibility, the Z algorithm is used to generate a 24-bit data portion as the custom portion of the non-resolvable private address. By using the specific Z cryptographic algorithm to generate Bluetooth device addresses, a highly secure Bluetooth address generation solution is provided, effectively preventing security threats such as network identity forgery and data redirection, and enhancing the authenticity and credibility of Bluetooth communication entities.
[0220] Please refer to Figure 5, which schematically illustrates a private address generation process according to an embodiment of the present application. In the figure, IRK is the end key, which refers to the temporary keys K1 and K2 in the cryptographic resources. The 24-bit random number in the figure refers to the time plus the regional code used by the device. The timestamp is 22 bits, the regional code is 2 bits, and the Z cryptographic operation encrypts the timestamp to form a 24-bit ciphertext, which together constitute the 48-bit Bluetooth private address. The private addresses generated by the source Bluetooth device and the destination Bluetooth device are both 24-bit ciphertext + timestamp + regional code.
[0221] In some embodiments, please refer to Figure 6, which schematically illustrates a private address verification process according to an embodiment of the present application. The method of performing Bluetooth communication with a destination Bluetooth device based on the private address and using the session key in the cryptographic resource includes:
[0222] First, based on the private address of the source Bluetooth device and the private address of the destination Bluetooth device, a connection establishment request is sent to the destination Bluetooth device;
[0223] Then, if the connection establishment request is sent successfully, obtain the private address to be verified sent by the target Bluetooth device;
[0224] Finally, the legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification passes, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
[0225] In this embodiment, for the scenario of one master and multiple slaves, the service device needs to establish an address resolution list, which mainly includes fields such as construction time, Bluetooth device address resolution key (Identity Resolving Key, IRK), end device identity address, address type, etc. The Bluetooth device maintains, manages and updates the list items according to the current session. Each time a data packet is received, the legitimacy of the address is first verified based on the address resolution list, and illegal addresses are directly discarded. When two Bluetooth devices are connected, they both perform legitimacy resolution on each other's addresses. If the resolved ciphertext and plaintext timestamp + regional code are consistent, the verification is qualified.
[0226] The method, if verification is successful, employing the session key in the cryptographic resource to conduct Bluetooth communication with the destination Bluetooth device includes: utilizing the session key in the cryptographic resource to conduct dynamic session key negotiation with the destination Bluetooth device to obtain a temporary session key; and establishing a secure communication channel based on the temporary session key for Bluetooth communication. This method enables encrypted data transmission over the air interface using a suitable encryption algorithm and the temporary session key, ensuring that data transmitted via Bluetooth communication is encrypted during transmission, thereby protecting the confidentiality of the data.
[0227] In the above implementation process, a private address is constructed based on the encrypted ciphertext, timestamp and regional code of the Bluetooth device address, which reduces the system maintenance cost, has high reliability and security, and has a flexible framework that can adapt to different application scenarios and needs. By verifying the private address, the source address verification can be strengthened, Bluetooth address spoofing attacks can be prevented, and the security and reliability of Bluetooth communication can be improved. By integrating the Z cryptographic algorithm into the Bluetooth address generation process, the security of the key in the Bluetooth device is guaranteed, and the key security of the Bluetooth device is improved. A private address generation and authentication mechanism using Z cryptography. By integrating the Z cryptographic algorithm into the Bluetooth address generation process, while solving the problem of address authentication, the security of the key in the Bluetooth device is guaranteed. Address authentication and key exchange can be performed without exposing the private key, effectively protecting the security of the private key and improving the usability and maintainability of the device. It can adapt to different application scenarios and needs and can better meet the needs of different users.
[0228] Integrating the Z cryptographic algorithm into the Bluetooth address generation process effectively obfuscates the key and encryption / decryption algorithms, thereby ensuring the security of keys in Bluetooth devices while simultaneously resolving address authentication issues. The Z cryptographic algorithm is a powerful encryption algorithm with a high degree of security and attack resistance, effectively protecting keys in Bluetooth devices from theft or cracking. Using the Z cryptographic private address generation and authentication mechanism, address authentication and key exchange can be performed without exposing the private key, effectively protecting the security of the private key. Compared to other solutions supported by secure hardware, the Bluetooth address generation method using the Z cryptographic algorithm can reduce equipment and maintenance costs, and does not require an additional hardware cryptographic module, making it easier to deploy and maintain. Using the Z cryptographic private address generation and authentication mechanism can simplify the address generation and authentication process for Bluetooth devices, improving device usability and maintainability.
[0229] Please refer to Figure 7, which schematically shows a diagram of a Bluetooth private address generation framework according to an embodiment of the present application. The cryptographic resource management platform provides resource retrieval services for Bluetooth devices within its jurisdiction and is responsible for issuing cryptographic resources required for private address generation to Bluetooth devices.
[0230] The following describes the working principle of the framework using the scenario of Bluetooth device A accessing Bluetooth device B.
[0231] Initial conditions:
[0232] (1) Bluetooth devices A and B have been configured with the IP address of the cryptographic resource management platform;
[0233] (2) Bluetooth devices A and B are configured with an initial Z cryptographic algorithm instance;
[0234] (3) Bluetooth devices A and B are registered in the cryptographic resource management platform and contain device attribute information.
[0235] Unresolvable private address generation process:
[0236] (1) Device A sends attribute information such as geographic location and a communication request to the cryptographic resource management platform;
[0237] (2) The cryptographic resource management platform analyzes the service request information of Bluetooth device A and retrieves the information of Bluetooth device B based on the service request information;
[0238] (3) The cryptographic resource management platform generates Z cryptographic resources Z1 and Z2 for Bluetooth device A and Bluetooth device B according to the cryptographic policy, and then distributes the cryptographic resources to Bluetooth device A and Bluetooth device B;
[0239] (4) After Bluetooth device A and Bluetooth device B receive the Z password resource, Bluetooth device A generates a Bluetooth private address based on the Z password algorithm: MAC A=Enc(N, Z1), Bluetooth device B generates host private address: MAC B =Enc(N, Z2); where N is a random code consisting of a timestamp and a region code.
[0240] (5) When Bluetooth device A accesses Bluetooth device B, first, the dynamic address MAC of device B is calculated B =Enc(N, Z2), then assign MAC to the destination address and source address of the frame respectively A and MAC B The data packet is sent to Bluetooth device B. After receiving the data frame, Bluetooth device B first verifies the legitimacy of the address based on the Z algorithm and rejects access from illegal addresses.
[0241] The following describes the establishment of a secure Bluetooth air interface communication channel using a specific use case. Power plant operation and maintenance equipment (mobile phones / handheld devices) serves as the carrier for power utility business applications (APPs). The Bluetooth management application, as a foundational application, supports configuration management, usage data collection, meter Bluetooth verification, and inter-device communication, providing a callable secure air interface communication channel for other advanced business applications. A secure Bluetooth operation and maintenance solution based on the Z algorithm: The master station issues operation and maintenance tasks to maintenance equipment, which connects to the terminal via Bluetooth via the Bluetooth management application. Operation and maintenance personnel use the maintenance equipment to query status, set parameters, and control power terminals via Bluetooth wireless communication based on the maintenance task, maintenance area, and maintenance equipment authorization code. This improves operation and maintenance efficiency by coordinating operation and maintenance tasks issued by the master station. Secure authorization of maintenance equipment and operation and maintenance records ensure the security and accountability of operation and maintenance operations. The overall architecture of the operation and maintenance solution is shown in Figure 8.
[0242] The Bluetooth management application is responsible for managing the communication control of the Bluetooth channel of the operation and maintenance equipment. The Bluetooth channel supports multiple masters and multiple slaves, multiple channels and multiple connections. The same operation and maintenance equipment supports connecting to multiple Bluetooth terminal devices. The Bluetooth management application provides Bluetooth communication management interfaces in two encoding formats, A-XDR encoding rules and JSON, for related business applications. Functions such as Bluetooth parameter setting, data sending and receiving are implemented through the message interface. The Bluetooth management application software architecture is modularly designed according to its functions and is mainly divided into four parts: device management, port management, message management and exception maintenance, as shown in Figure 9, which schematically shows a framework diagram of the Bluetooth management application software according to an embodiment of the present application.
[0243] The device management module consists of two parts: device management tasks and device operation interface. The device management task periodically reads various status information of Bluetooth devices by calling the standard driver interface to update the port link status in real time, reads port data and distributes related data to the port queue; the device operation interface provides encapsulation of some operation interfaces of Bluetooth devices, including Bluetooth device parameter settings, Bluetooth module switches, port parameter configuration, port scanning startup, Bluetooth device node information reading, etc.
[0244] The port management module primarily manages multiple Bluetooth connections. Business applications trigger their creation by calling the Bluetooth port configuration interface, and their status is updated in the device management task's port maintenance module. Device ports primarily include master-slave mode, port number, connection status, peer address, and receive and send data buffers. Bluetooth management applications register with the system management service via Message Queuing Telemetry Transport (MQTT) messages according to specifications and respond to common messages such as heartbeat checks to ensure the application's normal service status. Message queue priority control, based on the priority field of MQTT send and receive interface messages, enables message sequencing of different priorities.
[0245] Abnormal maintenance is responsible for the abnormal management of Bluetooth modules or channels, and the device management module synchronizes the connection status to the abnormal maintenance task. When communication abnormalities occur continuously, the power control interface is actively called to reset the module. The port connection status is monitored, and when there is a long-term abnormal connection status or no data communication, the connection is actively disconnected and the connection is scanned. When a business application is configured with too many ports, the Bluetooth management application actively clears inactive port information to improve work efficiency. After establishing an authenticated connection between devices, a secure Bluetooth air interface encrypted communication channel will be established to ensure the confidentiality and integrity of data transmission. As shown in Figure 10, Figure 10 schematically shows the process of establishing a secure communication channel according to an embodiment of the present application.
[0246] The operation and maintenance equipment applies for operation and maintenance area credentials and Z algorithm instances from the security resource management platform (which is equipped with a cryptographic resource management system). The request information carries the Bluetooth private address and geographic location information. The security resource management platform verifies the legitimacy of the operation and maintenance terminal address based on the policy. After the verification is passed, the Z algorithm instance is issued to the operation and maintenance equipment and the power terminal. The operation and maintenance equipment and the power terminal begin the verification and negotiation process based on the private Z instance. After the authentication is completed, an initial communication connection is established. The Bluetooth module of the operation and maintenance equipment and the Bluetooth module of the power terminal send operation and maintenance area credentials and operation and maintenance permissions to each other for respective verification. After the two-way authentication between the operation and maintenance equipment and the power terminal is successful, data encryption and decryption are performed based on the temporary session key after the authentication of the Z algorithm instance and the dynamic session key negotiation, and finally a secure communication channel is established. Advanced services can choose to transmit plaintext, ciphertext, plaintext+MAC, and ciphertext+MAC according to different data security levels for secure data transmission.
[0247] The following describes the security authentication communication process using a specific application scenario:
[0248] Please refer to Figure 11, which schematically shows a schematic diagram of an intelligent power distribution operation and maintenance application scenario according to an embodiment of the present application. In the intelligent power distribution operation and maintenance scenario, the operation and maintenance terminal accesses the secure access gateway via 4G. The secure access gateway deploys the Z password resource management service program. The operation and maintenance terminal deploys a secure Bluetooth component. The intelligent fusion terminal, energy meter, and smart switch can also deploy a secure Bluetooth component. The specific security authentication communication process is as follows:
[0249] Step 1: The operation and maintenance terminal sends a converged terminal access request to the secure access gateway. The request message carries the Bluetooth private address and geographic location information.
[0250] Step 2: The secure access gateway verifies the legitimacy of the operation and maintenance terminal address based on the access policy. If the address is illegal, access is denied.
[0251] Step 3: The secure access gateway searches for intelligent converged terminals in the area, generates Z algorithm instances for the intelligent converged terminals and operation and maintenance handheld devices, and then distributes them to the operation and maintenance handheld devices and converged terminals.
[0252] Step 4: The operation and maintenance handheld generates its own private MAC address and the private MAC address of the converged terminal based on the received Z algorithm instance, and initiates an access request to the intelligent converged terminal based on the addresses;
[0253] Step 5: After receiving the request packet, the converged terminal verifies the legitimacy of the address according to the private address verification method. If the verification fails, the access is denied.
[0254] Step 6: After the address validity is verified, dynamic session key negotiation is performed, and data encryption and decryption are performed based on the negotiated temporary session key, and the secure channel is established.
[0255] Please refer to Figure 12, which schematically illustrates a home Bluetooth application scenario according to an embodiment of the present application. Address generation and verification mechanisms are deployed on all Bluetooth communication nodes. A secure Bluetooth service component is deployed on the home indoor gateway. The secure Bluetooth service component is responsible for distributing the Z cryptographic algorithm instances required by all nodes in the intranet. At the same time, secure Bluetooth components are deployed on all nodes to implement private address generation and verification functions. The specific steps are as follows:
[0256] Step 1: Register the basic information of the Bluetooth device (such as a Bluetooth speaker) to be accessed on the intranet in the secure Bluetooth service component through the management software;
[0257] Step 2: Install the secure Bluetooth component on each node and deploy the initial Z cryptographic algorithm instance Z 10 , configure the indoor gateway address;
[0258] Step 3: When a mobile phone is connected to a Bluetooth device via Bluetooth, the secure Bluetooth component initiates an access request Q1 to the indoor gateway. The source address of the request packet is MAC. A1 =Enc(MAC1, Z 10 ), the result of Enc calculation is the private address of MAC1, which is completed by the secure Bluetooth component. At the same time, the request packet can carry information such as timestamp and request type;
[0259] Step 4: After receiving request Q1, the secure Bluetooth service component of the indoor gateway extracts the source MAC address from the data frame and verifies the legitimacy of the address based on the Z cryptographic algorithm. If the address verification result is legal, it proceeds to step 5. Otherwise, further communication requests are rejected and the access ends.
[0260] Step 5: The secure Bluetooth service component calculates MAC=Enc(MAC3, Z according to the accessed Bluetooth device address MAC3) 30 ), Z 30 The initial Z cryptographic algorithm instance of the accessed Bluetooth device;
[0261] Step 6: After receiving the response information, the mobile phone can send a request to the Bluetooth device according to the assigned Z algorithm instance. The Bluetooth device verifies the legitimacy of the access device address based on the distributed Z algorithm instance and rejects the connection if it is illegal.
[0262] Step 7: After the address legitimacy is verified, dynamic session key negotiation is performed, and data encryption and decryption are performed based on the negotiated temporary session key. The secure channel is established, enabling mobile devices to manage and control smart home devices.
[0263] For a multi-master and multi-slave Bluetooth network, which includes multiple master devices and multiple slave devices, please refer to Figure 13, which schematically shows a schematic diagram of a multi-master and multi-slave Bluetooth network application scenario according to an embodiment of the present application. It should be noted that, in order to facilitate the description of the solution, the master device in the figure corresponds to the source Bluetooth device, and the slave device corresponds to the destination Bluetooth device. This embodiment also provides a channel and time slot control method based on service priority adjustment based on channel state information. As shown in Figure 14, the master device and the slave device respectively obtain the local channel state, establish a channel priority table and establish a service priority table, and then the master and slave devices establish a connection. The master device updates the service priority table according to the connection, and then performs dynamic channel switching. Correspondingly, the slave device follows the channel switching, and then the master and slave devices perform data interaction based on the new channel.
[0264] For the master device, please refer to Figure 15, which schematically shows a flow chart of generating a channel priority table according to an embodiment of the present application. In some embodiments, after establishing a secure communication channel, the Bluetooth communication method further includes the following steps:
[0265] First, the local channel state is obtained, and a channel map and a channel priority table are constructed based on the local channel state;
[0266] In this embodiment, each Bluetooth device regularly analyzes the status of each channel, generates a channel map, and performs channel quality analysis on each signal, including signal quality, interference, and noise levels. Based on the analysis results, the Bluetooth device establishes its own channel priority table, which records the priority order of each channel for that device. In the channel priority table, devices with higher channel quality are assigned higher priority and receive preferential data transmission. Devices with lower channel quality are assigned lower priority and may experience data transmission delays or have their transmission rate limited.
[0267] Then, obtain your own business information and establish a business priority table based on the level and priority of your own business.
[0268] In this embodiment, after establishing a connection, the Bluetooth device establishes a service priority table based on its own service level and priority. The service level and priority of all Bluetooth devices established for the connection are uniformly agreed upon, that is, the service priority corresponding to the same service in different Bluetooth devices is the same.
[0269] When establishing a service priority table, the master device considers factors such as the importance, urgency, and timeliness of different services and prioritizes them accordingly. Within the service priority table, higher-priority services receive more resources and attention to ensure timely and reliable processing. For lower-priority services, the master device may limit their resource allocation or place them at the back of the queue to ensure the smooth execution of higher-priority services. This service priority table allows for better management of devices in a multi-master, multi-slave Bluetooth network, ensuring the timely processing and execution of important services while improving the efficiency and reliability of the entire network.
[0270] The method further includes: sending the channel map and channel priority table to all Bluetooth devices in the network in a broadcasting manner.
[0271] In this embodiment, in a multi-master multi-slave Bluetooth network, each Bluetooth device sends channel map information and a channel priority table to all Bluetooth devices in the network by broadcasting, so that other devices can understand the available channels and corresponding frequency hopping sequences. The channel map information includes parameters such as the frequency range, channel spacing, and frequency hopping sequence of all available channels, so that devices can select the best channel for communication. During the broadcast process, the device will continuously broadcast the channel map information and the channel priority table to the surrounding area. After receiving this information, other devices can store it locally for use when needed. Sending the channel map information and the channel priority table by broadcasting can promote communication and collaboration between devices in a multi-master multi-slave Bluetooth network, making the network more open and transparent, thereby improving the efficiency and reliability of the entire network. The slave device selects the appropriate channel and frequency hopping sequence based on the received channel map information to communicate with the master device.
[0272] In some embodiments, the Bluetooth communication method further includes the following steps:
[0273] First, the data channel is switched according to the channel selection algorithm;
[0274] Then, the switched data channel is used to obtain current channel state information and current service information;
[0275] Then, comparing the current channel state information with the channel priority table to obtain the priority of the current channel;
[0276] Finally, the service channel is switched according to the priority of the current channel, the service priority table and the current service information to obtain the most suitable channel.
[0277] The switching of the service channel to obtain the most suitable channel according to the priority of the current channel, the service priority table and the current service information includes:
[0278] The first step is to query and obtain the current service priority according to the service priority table and the current service information;
[0279] The second step is to determine whether the current service priority matches the priority of the current channel;
[0280] In the third step, if it is determined that the current service priority matches the priority of the current channel, the current channel is used for communication;
[0281] In the fourth step, if it is determined that the current service priority does not match the priority of the current channel, a channel that matches the current service priority is selected from the channel priority table, and the channel is used for communication.
[0282] In this embodiment, after the master and slave devices establish a connection, they first switch channels according to the default CSA #2 channel switching protocol, and then exchange channel status information and current service information through the data channel. The master device compares the current channel with the channel priority table to know the priority of the current channel. Then, based on the level of channel priority, the service channel is switched, and the master device selects the most appropriate channel to communicate with the slave device. The channel switching process is to query the current service priority from the service priority table, and then select a channel that matches the service priority from the channel priority table for communication based on the service priority. This can better manage devices in a multi-master and multi-slave Bluetooth network, ensure the timely processing and execution of important services, and improve the efficiency and reliability of the entire network.
[0283] In some embodiments, the Bluetooth communication method further includes the following steps:
[0284] First, periodically obtain channel status, and update the channel priority table based on the channel status to obtain a new channel priority table;
[0285] Then, the new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
[0286] In this embodiment, after the master and slave devices establish a connection, each device will regularly analyze its own channel status and then update the channel priority table and broadcast it. The master device connected to it will dynamically adjust the frequency hopping channel according to the updated channel priority table.
[0287] In some embodiments, the Bluetooth communication method further includes:
[0288] First, during the communication process, the size of the interactive data packet is used to determine whether to dynamically adjust the time slot of the current communication;
[0289] Then, when the size of the interactive data packet is greater than a preset threshold, the proportion of the time slot used for the current communication is adjusted according to the current service priority to achieve dynamic adjustment of the time slot.
[0290] In this embodiment, after a master-slave connection is established, the master device can also decide whether to dynamically adjust the time slot based on the size of the exchanged data packets. If the exchanged data volume exceeds a preset threshold, further improving communication efficiency is necessary. The master device will adjust the time slot, adjusting the proportion of the current communication time slot based on the current service priority and dynamically allocating it. If there are many devices currently connected, the master device may consider not allocating time slots to low-priority connections in the current time slot to ensure the timely processing and execution of high-priority connections. This can improve the efficiency and reliability of the entire network and ensure the timely processing and execution of important services.
[0291] For the convenience of calculation, the adjustment of the proportion of time slots used for current communication according to the current business priority specifically includes: generating multiple business weights according to the current business priority and the business priority table; and then adjusting the proportion of time slots used for current communication based on the proportion of each business weight to achieve dynamic adjustment of time slots.
[0292] In this embodiment, when adjusting the time slot ratio according to the service priority, it is not easy to quantify according to the priority, so the service weight is generated according to the service priority, and the algorithm for adjusting the time slot length according to the weight ratio can dynamically adjust the time slot length according to the connection priority and weight ratio.
[0293] Specifically, adjusting the proportion of time slots used for current communication based on the proportion of each service weight includes:
[0294] First, initialize the total time slot length;
[0295] Then, the adjusted time slot length of each connection is calculated according to the proportion of each service weight and the total time slot length;
[0296] Finally, based on the adjusted time slot length of each connection, the time slot of each connection in the current communication is updated to adjust the proportion of time slots used by the current communication.
[0297] In this embodiment, the total time slot length TotalSlotLength is first initialized to the time slot upper limit value, and the default value of the total weight TotalWeighted is 100. Then the priority Priority_i of each connection is updated in real time according to the service priority table. Calculate the weight ratio of each connection: WeightedRatio_i = Priority_i / TotalWeighted, where Priority_i is the weight of the i-th connection, and TotalWeighted is the sum of the priority weights of all connections. Calculate the adjusted time slot length of each connection: AdjustedSlotLength_i = TotalSlotLength*WeightedRatio_i. Based on the calculated time slot length of each connection, the time slot of each connection is updated. If the service changes, it is necessary to recalculate the time slot length required for each connection and perform the above adjustment process.
[0298] In the above implementation process, a service priority table is generated based on service priorities. This table is used for dynamic channel adjustment. Different channel priorities can be set according to different service types and requirements, thereby flexibly adjusting channel resource allocation to adapt to various application scenarios. Adjusting channels based on service priorities can more efficiently utilize channel resources, improving communication efficiency and data transmission rates. By adjusting channel priorities, important services can be better guaranteed communication, thereby improving system stability and reliability. Automatically adjusting channel priorities based on actual service needs and changes in the network environment can better adapt to real-time changing application scenarios and enhance the system's adaptability and intelligence.
[0299] Among them, adjusting time slots based on weights has the following technical advantages over conventional time slot adjustment:
[0300] 1. Flexibility: The time slot length can be flexibly adjusted according to the priority and urgency of the task, thus better adapting to various application scenarios and real-time changing task requirements.
[0301] 2. Fairness: By adjusting the time slots according to task weights, it can ensure that each task has a fair communication opportunity and avoid some tasks being affected by communication conflicts.
[0302] 3. Efficiency: Adjusting time slots based on task weights can more efficiently utilize communication resources, improve system efficiency and performance, and prevent low-priority services from occupying network resources, thereby improving the efficiency and reliability of the entire network.
[0303] 4. Reliability: By adjusting time slots according to task weights, important tasks can be better guaranteed communication, thereby improving the stability and reliability of the system.
[0304] Corresponding to the source Bluetooth device, this embodiment also provides a Bluetooth communication method. Please refer to Figure 17, which schematically shows a flow chart of a Bluetooth communication method applied to a destination Bluetooth device according to an embodiment of the present application. The Bluetooth communication method is applied to the destination Bluetooth device and includes the following steps:
[0305] Acquire cryptographic resources, which are obtained through the above-mentioned Bluetooth communication method applied to the cryptographic resource management system; when the cryptographic resource management system encrypts and signs the cryptographic resources and then sends them to the Bluetooth device, the cryptographic resources are acquired.
[0306] Step 410: Obtain a second cryptographic resource ciphertext and a second signature, wherein the second cryptographic resource ciphertext and the second signature are obtained by the Bluetooth communication method applied to the cryptographic resource management system.
[0307] Step 420: Verify the second signature using the preset master certificate. If the second signature verification succeeds, decrypt the second cryptographic resource ciphertext using the preset application key of the destination Bluetooth device to obtain the cryptographic resource.
[0308] Among them, the second cryptographic resource ciphertext is obtained by the cryptographic resource management system using the application key of the source Bluetooth device to encrypt the cryptographic resource; the second signature is obtained by the cryptographic resource management system signing the second cryptographic resource ciphertext based on the preset master station private key.
[0309] In this embodiment, the above-mentioned preset master certificate is pre-written into the Bluetooth device and is used to verify the signature. To facilitate the description of the solution, taking the above-mentioned Bluetooth device A and Bluetooth device B as an example, Bluetooth devices A and B respectively use the master certificate to verify the cryptographic resource, that is, use the preset master certificate to verify the first signature. After the verification is successful, they use the application key K A and application key K B Decrypt and obtain Z algorithm instance Z1, Z algorithm instance Z2, temporary key K1, temporary key K2, and session key K3.
[0310] Step 430: Perform Bluetooth communication with the source Bluetooth device based on the password resource.
[0311] The steps include:
[0312] First, construct a private address based on the Z algorithm instance and temporary key in the cryptographic resource;
[0313] Then, based on the private address, Bluetooth communication is performed with the source Bluetooth device using the session key in the cryptographic resource.
[0314] In this embodiment, after obtaining the password resource, Bluetooth communication can be performed based on the password resource. Taking the above example, Bluetooth device A generates a Bluetooth private address MAC based on the temporary key K1 and the Z algorithm instance Z1. A , Bluetooth device B generates Bluetooth private address MAC based on temporary key K2 and Z algorithm instance Z2 B ; Bluetooth device A and Bluetooth device B use session key K3 as session key to communicate.
[0315] In some embodiments, the temporary key includes: a temporary key K1 and a temporary key K2; the Z algorithm instance includes: a Z algorithm instance Z1 and a Z algorithm instance Z2; and constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes the following steps:
[0316] The first step is to obtain the current local time and region code, and generate a timestamp based on the current local time;
[0317] In the second step, based on the temporary key K1 and the Z algorithm instance Z1, the random code consisting of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address;
[0318] Step 3: Encrypt the random code consisting of the timestamp and the region code based on the temporary key K2 and the Z algorithm instance Z2 to obtain the encrypted ciphertext of the destination Bluetooth device address;
[0319] Step 4: construct a private address of the source Bluetooth device based on the encrypted ciphertext, timestamp and region code of the source Bluetooth device address;
[0320] The fifth step is to construct a private address of the destination Bluetooth device based on the encrypted ciphertext, timestamp and region code of the destination Bluetooth device address.
[0321] It should be noted that, in this embodiment, the process of generating the private address is the same as the process of generating the private address in the source Bluetooth device, and will not be repeated here.
[0322] In some embodiments, performing Bluetooth communication with a source Bluetooth device based on the private address and using a session key in the cryptographic resource includes:
[0323] First, in response to a connection establishment request sent by a source Bluetooth device, a private address to be verified sent by the source Bluetooth device is obtained;
[0324] Then, the legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification passes, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device.
[0325] The step of using the session key in the cryptographic resource to perform Bluetooth communication with the source Bluetooth device includes:
[0326] The first step is to use the session key in the cryptographic resource to negotiate a dynamic session key with the source Bluetooth device to obtain a temporary session key;
[0327] The second step is to establish a secure communication channel based on the temporary session key to perform Bluetooth communication.
[0328] It should be noted that, in this embodiment, the process of address legitimacy verification is the same as the process of address legitimacy verification in the source Bluetooth device, and will not be repeated here.
[0329] In some embodiments, after establishing the secure communication channel, the method further includes:
[0330] First, the local channel state is obtained, and a channel map and a channel priority table are constructed based on the local channel state;
[0331] Then, obtain your own business information and establish a business priority table based on the level and priority of your own business.
[0332] The method further includes: sending the channel map information and the channel priority table to all Bluetooth devices in the network in a broadcasting manner.
[0333] It should be noted that, in this embodiment, the process of establishing the channel map, channel priority table service and priority table is the same as the process of establishing the channel map, channel priority table service and priority table in the source Bluetooth device, and will not be repeated here.
[0334] In some embodiments, the following steps are further included:
[0335] First, periodically obtain channel status, and update the channel priority table based on the channel status to obtain a new channel priority table;
[0336] Then, the new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
[0337] It should be noted that, in this embodiment, the process of updating the channel priority table is the same as the process of updating the channel priority table in the source Bluetooth device, and will not be repeated here.
[0338] This embodiment also provides a Bluetooth communication system, including a cryptographic resource management system, a source Bluetooth device, and a destination Bluetooth device;
[0339] The source Bluetooth device is used to send a cryptographic resource request to the cryptographic resource management system; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers;
[0340] The cryptographic resource management system is used to match the application key of the source Bluetooth device and the application key of the destination Bluetooth device from the application keys of multiple preset Bluetooth devices based on the source Bluetooth device information and the destination Bluetooth device information; generate cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and multiple random numbers; wherein the cryptographic resources are used to generate a private address; encrypt the cryptographic resources using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on the preset master station private key to generate a first signature and a second signature; send the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and send the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resources.
[0341] This embodiment also provides a Bluetooth communication device. Please refer to Figure 18, which schematically shows a block diagram of the structure of a Bluetooth communication device applied to a cryptographic resource management system according to an embodiment of the present application. The Bluetooth communication device is applied to a cryptographic resource management system and includes an acquisition module 510, an application key matching module 520, a cryptographic resource generation module 530, a first encryption module 540, a first signature module 550, and a sending module 560, wherein:
[0342] An acquisition module 510 is configured to acquire a cryptographic resource request sent by a source Bluetooth device; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information, and multiple random numbers;
[0343] An application key matching module 520 is configured to match an application key of a source Bluetooth device and an application key of a destination Bluetooth device from a plurality of preset Bluetooth device application keys based on the source Bluetooth device information and the destination Bluetooth device information;
[0344] A cryptographic resource generation module 530, configured to generate a cryptographic resource based on an application key of the source Bluetooth device, an application key of the destination Bluetooth device, and a plurality of random numbers;
[0345] A first encryption module 540 is configured to encrypt the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device, respectively, to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; wherein the cryptographic resource is used to generate a private address;
[0346] A first signature module 550 is configured to sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on a preset master station private key to generate a first signature and a second signature;
[0347] The sending module 560 is used to send the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and send the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resources.
[0348] The password resource generation module 530 includes:
[0349] A first dispersion processing unit, configured to perform dispersion processing on the application key of the source Bluetooth device based on the first random number to obtain a temporary key K1;
[0350] A second dispersing processing unit, configured to perform dispersing processing on the application key of the destination Bluetooth device based on the second random number to obtain a temporary key K2;
[0351] an algorithm instance unit, configured to generate a Z algorithm instance Z1 by using the Z cryptographic algorithm based on the temporary key K1, and to generate a Z algorithm instance Z2 by using the Z cryptographic algorithm based on the temporary key K2;
[0352] a third decentralized processing unit, configured to perform decentralized processing on the application key of the source Bluetooth device based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key;
[0353] The resource generation unit is used to obtain cryptographic resources according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key.
[0354] The Bluetooth communication device includes a processor and a memory. The above-mentioned acquisition module 510, application key matching module 520, cryptographic resource generation module 530, first encryption module 540, first signature module 550 and sending module 560 are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize corresponding functions.
[0355] The processor contains a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be configured, and the risk of attack can be reduced by adjusting kernel parameters, ensuring the security of Bluetooth communications.
[0356] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0357] This embodiment provides a Bluetooth communication device. Please refer to Figure 19, which schematically shows a block diagram of a Bluetooth communication device applied to a source Bluetooth device according to an embodiment of the present application. The Bluetooth communication device is applied to the source Bluetooth device and includes a first cryptographic resource acquisition module 610, a first signature verification module 620, and a first Bluetooth communication module 630, wherein:
[0358] A first cryptographic resource acquisition module 610 is configured to acquire a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained via the Bluetooth communication device applied to the cryptographic resource management system;
[0359] A first signature verification module 620 is configured to verify the first signature using a preset master station certificate, and if the first signature verification is successful, decrypt the first cryptographic resource ciphertext using a preset application key of the source Bluetooth device to obtain the cryptographic resource;
[0360] The first Bluetooth communication module 630 is configured to perform Bluetooth communication with a destination Bluetooth device based on the password resource.
[0361] The Bluetooth communication device includes a processor and a memory. The above-mentioned first cryptographic resource acquisition module 610, first signature verification module 620 and first Bluetooth communication module 630 are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.
[0362] The processor contains a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be configured, and the risk of attack can be reduced by adjusting kernel parameters, ensuring the security of Bluetooth communications.
[0363] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0364] This embodiment provides a Bluetooth communication device. Please refer to Figure 20, which schematically shows a block diagram of the structure of a Bluetooth communication device applied to a destination Bluetooth device according to an embodiment of the present application. The Bluetooth communication device is applied to the destination Bluetooth device and includes a second cryptographic resource acquisition module 710, a second signature verification module 720, and a second Bluetooth communication module 730, wherein:
[0365] A second cryptographic resource acquisition module 710 is configured to acquire a second cryptographic resource ciphertext and a second signature, wherein the second cryptographic resource ciphertext and the second signature are obtained by the Bluetooth communication device applied to the cryptographic resource management system;
[0366] A second signature verification module 720 is configured to verify the second signature using a preset master station certificate, and if the second signature verification succeeds, decrypt the second cryptographic resource ciphertext using a preset application key of the destination Bluetooth device to obtain the cryptographic resource;
[0367] The second Bluetooth communication module 730 is configured to perform Bluetooth communication with the source Bluetooth device based on the password resource.
[0368] The Bluetooth communication device includes a processor and a memory. The above-mentioned second cryptographic resource acquisition module 710, second signature verification module 720, second Bluetooth communication module 730, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.
[0369] The processor contains a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be configured, and the risk of attack can be reduced by adjusting kernel parameters, ensuring the security of Bluetooth communications.
[0370] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0371] An embodiment of the present invention provides a machine-readable storage medium on which a program is stored. When the program is executed by a processor, the Bluetooth communication method is implemented.
[0372] An embodiment of the present invention provides a processor, which is used to run a program, wherein the Bluetooth communication method is executed when the program is run.
[0373] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be shown in Figure 21. The computer device includes a processor A01, a network interface A02, a display screen A04, an input device A05, and a memory (not shown) connected via a system bus. The processor A01 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes an internal memory A03 and a non-volatile storage medium A06. The non-volatile storage medium A06 stores an operating system B01 and a computer program B02. The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A06. The network interface A02 of the computer device is used to communicate with an external terminal via a network connection. When executed by the processor A01, the computer program implements a Bluetooth communication method. The display screen A04 of the computer device may be a liquid crystal display or an electronic ink display. The input device A05 of the computer device may be a touch layer covering the display screen, or may be a key, trackball, or touchpad provided on the computer device housing, or may be an external keyboard, touchpad, or mouse.
[0374] Those skilled in the art will understand that the structure shown in Figure 21 is merely a block diagram of a portion of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0375] In one embodiment, the Bluetooth communication method provided in this application can be implemented in the form of a computer program, which can be run on a computer device as shown in Figure 21. The memory of the computer device can store various program modules that constitute the Bluetooth communication device, such as the acquisition module 510, application key matching module 520, cryptographic resource generation module 530, first encryption module 540, first signature module 550, and issuance module 560 shown in Figure 18. Or the first cryptographic resource acquisition module 610, first signature verification module 620, and first Bluetooth communication module 630 shown in Figure 19. Or the computer program composed of the second cryptographic resource acquisition module 710, second signature verification module 720, and second Bluetooth communication module 730 shown in Figure 20 causes the processor to execute the steps of the Bluetooth communication method of each embodiment of the present application described in this specification.
[0376] The computer device shown in FIG21 can execute step 210 through the acquisition module 510 in the Bluetooth communication device shown in FIG18 . The computer device can execute step 220 through the application key matching module 520, execute step 230 through the cryptographic resource generation module 530, execute step 240 through the first encryption module 540, execute step 250 through the first signature module 550, and execute step 260 through the issuing module 560.
[0377] The computer device shown in Figure 21 can perform step 310 via the first cryptographic resource acquisition module 610 in the Bluetooth communication device shown in Figure 19. The computer device can perform step 320 via the first signature verification module 620 and step 330 via the first Bluetooth communication module 630.
[0378] The computer device shown in Figure 21 can execute step 410 via the second cryptographic resource acquisition module 710 in the Bluetooth communication device shown in Figure 20. The computer device can execute step 420 via the second signature verification module 720. The computer device can execute step 430 via the second Bluetooth communication module 730.
[0379] An embodiment of the present application provides an electronic device comprising: at least one processor; and a memory connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the at least one processor implements the aforementioned Bluetooth communication method by executing the instructions stored in the memory. When the processor executes the instructions, the following steps are implemented: Applied to a cryptographic resource management system, the Bluetooth communication method includes:
[0380] Obtaining a cryptographic resource request sent by a source Bluetooth device; the cryptographic resource request includes source Bluetooth device information, destination Bluetooth device information, and multiple random numbers;
[0381] Based on the source Bluetooth device information and the destination Bluetooth device information, matching the application key of the source Bluetooth device and the application key of the destination Bluetooth device from a plurality of preset Bluetooth device application keys;
[0382] Generate a cryptographic resource based on an application key of the source Bluetooth device, an application key of the destination Bluetooth device, and a plurality of random numbers;
[0383] Encrypting the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext;
[0384] Sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on the preset master station private key to generate a first signature and a second signature;
[0385] Sending the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and sending the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the cryptographic resources;
[0386] The cryptographic resource is used to generate a private address.
[0387] In one embodiment, the cryptographic resource management system is pre-set with security chip serial numbers of multiple Bluetooth devices, the multiple random numbers include a first random number, a second random number, and a third random number, and the cryptographic resources include a Z algorithm instance, a temporary key, and a session key;
[0388] The generating of cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and a plurality of random numbers includes:
[0389] Distributing the application key of the source Bluetooth device based on the first random number to obtain a temporary key K1;
[0390] Distributing the application key of the destination Bluetooth device based on the second random number to obtain a temporary key K2;
[0391] Generate a Z algorithm instance Z1 using the Z cryptographic algorithm based on the temporary key K1, and generate a Z algorithm instance Z2 using the Z cryptographic algorithm based on the temporary key K2;
[0392] Distributing the application key of the source Bluetooth device based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key;
[0393] A cryptographic resource is obtained according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key.
[0394] In one embodiment, the process of obtaining the preset multiple Bluetooth device application keys includes:
[0395] Register multiple Bluetooth devices and obtain security chip information of each Bluetooth device, wherein the security chip information includes at least a security chip serial number;
[0396] The security chip serial numbers of the various Bluetooth devices are dispersed based on the preset service root keys to obtain application keys of the multiple Bluetooth devices.
[0397] A Bluetooth communication method, applied to a source Bluetooth device, comprising:
[0398] Obtaining a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained by the Bluetooth communication method applied to the cryptographic resource management system;
[0399] Verifying the first signature using a preset master station certificate, and if the verification of the first signature is successful, decrypting the first cryptographic resource ciphertext using a preset application key of the source Bluetooth device to obtain a cryptographic resource;
[0400] Based on the password resource, Bluetooth communication is performed with the target Bluetooth device.
[0401] In one embodiment, performing Bluetooth communication with a destination Bluetooth device based on the password resource includes:
[0402] Constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource;
[0403] Based on the private address, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
[0404] In one embodiment, the temporary key includes: a temporary key K1 and a temporary key K2; the Z algorithm instance includes: a Z algorithm instance Z1 and a Z algorithm instance Z2;
[0405] The constructing of a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes:
[0406] Obtaining the current local time and region code, and generating a timestamp based on the current local time;
[0407] Based on the temporary key K1 and the Z algorithm instance Z1, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address;
[0408] Based on the temporary key K2 and the Z algorithm instance Z2, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the destination Bluetooth device address;
[0409] Constructing a private address of the source Bluetooth device based on the encrypted ciphertext of the source Bluetooth device address, the timestamp and the region code;
[0410] Based on the encrypted ciphertext of the destination Bluetooth device address, the timestamp and the regional code, a private address of the destination Bluetooth device is constructed.
[0411] In one embodiment, performing Bluetooth communication with a destination Bluetooth device based on the private address and using a session key in the cryptographic resource includes:
[0412] Sending a connection establishment request to the destination Bluetooth device based on the source Bluetooth device private address and the destination Bluetooth device private address;
[0413] When the connection establishment request is sent successfully, obtain the private address to be verified sent by the target Bluetooth device;
[0414] The legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification passes, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
[0415] In one embodiment, the using the session key in the cryptographic resource to perform Bluetooth communication with the destination Bluetooth device includes:
[0416] Performing dynamic session key negotiation with a destination Bluetooth device using the session key in the cryptographic resource to obtain a temporary session key;
[0417] A secure communication channel is established based on the temporary session key to perform Bluetooth communication.
[0418] In one embodiment, after establishing the secure communication channel, the method further includes:
[0419] Acquiring a local channel state, and constructing a channel map and a channel priority table based on the local channel state;
[0420] Obtain your own business information and establish a business priority table based on the level and priority of your own business.
[0421] In one embodiment, it further includes:
[0422] The channel map and channel priority table are sent to all Bluetooth devices in the network in a broadcasting manner.
[0423] In one embodiment, it further includes:
[0424] Switching data channels according to a channel selection algorithm;
[0425] Using the switched data channel to obtain current channel status information and current service information;
[0426] Comparing the current channel state information with the channel priority table to obtain the priority of the current channel;
[0427] According to the priority of the current channel and the service priority table, the service priority table and the current service information, the service channel is switched to obtain the most suitable channel.
[0428] In one embodiment, switching the service channel to obtain the most suitable channel according to the priority of the current channel, the service priority table, and the current service information includes:
[0429] According to the service priority table and current service information, query and obtain the current service priority;
[0430] Determining whether the current service priority matches the priority of the current channel;
[0431] Determining that the current service priority matches the priority of the current channel, and using the current channel for communication;
[0432] It is determined that the current service priority does not match the priority of the current channel, a channel that matches the current service priority is selected from the channel priority table, and the channel is used for communication.
[0433] In one embodiment, it further includes:
[0434] Periodically acquiring a channel status, and updating the channel priority table based on the channel status to obtain a new channel priority table;
[0435] The new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
[0436] In one embodiment, it further includes:
[0437] During the communication process, the size of the interactive data packet determines whether to dynamically adjust the time slot of the current communication;
[0438] When the interactive data packet is large, the proportion of the time slot used for current communication is adjusted according to the current business priority to achieve dynamic adjustment of the time slot.
[0439] In one embodiment, adjusting the proportion of time slots used for current communication according to the current service priority to achieve dynamic adjustment of time slots includes:
[0440] generating a plurality of service weights according to the current service priority and the service priority table;
[0441] Based on the proportion of each service weight, the proportion of the time slot used for current communication is adjusted to achieve dynamic adjustment of the time slot.
[0442] In one embodiment, adjusting the proportion of time slots used for current communication based on the proportion of each service weight includes:
[0443] Initialize the total time slot length;
[0444] Calculate the adjusted time slot length of each connection based on the proportion of each service weight and the total time slot length;
[0445] Based on the adjusted time slot length of each connection, a time slot update is performed on each connection in the current communication to adjust the proportion of time slots used for the current communication.
[0446] A Bluetooth communication method, applied to a target Bluetooth device, comprising:
[0447] Obtaining a second cryptographic resource ciphertext and a second signature, wherein the second cryptographic resource ciphertext and the second signature are obtained by the Bluetooth communication method applied to the cryptographic resource management system;
[0448] Verifying the second signature using a preset master station certificate, and if the verification of the second signature is successful, decrypting the second cryptographic resource ciphertext using a preset application key of the destination Bluetooth device to obtain the cryptographic resource;
[0449] Based on the cryptographic resource, Bluetooth communication is performed with the source Bluetooth device.
[0450] In one embodiment, performing Bluetooth communication with a source Bluetooth device based on the cryptographic resource includes:
[0451] Constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource;
[0452] Based on the private address, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device.
[0453] In one embodiment, the temporary key includes: a temporary key K1 and a temporary key K2; the Z algorithm instance includes: a Z algorithm instance Z1 and a Z algorithm instance Z2;
[0454] The constructing of a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes:
[0455] Obtaining the current local time and region code, and generating a timestamp based on the current local time;
[0456] Based on the temporary key K1 and the Z algorithm instance Z1, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address;
[0457] Based on the temporary key K2 and the Z algorithm instance Z2, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the destination Bluetooth device address;
[0458] Constructing a private address of the source Bluetooth device based on the encrypted ciphertext of the source Bluetooth device address, the timestamp and the region code;
[0459] Based on the encrypted ciphertext of the destination Bluetooth device address, the timestamp and the regional code, a private address of the destination Bluetooth device is constructed.
[0460] In one embodiment, performing Bluetooth communication with a source Bluetooth device based on the private address and using a session key in the cryptographic resource includes:
[0461] In response to a connection establishment request sent by a source Bluetooth device, obtaining a private address to be verified sent by the source Bluetooth device;
[0462] The legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification passes, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device.
[0463] In one embodiment, the using the session key in the cryptographic resource to perform Bluetooth communication with the source Bluetooth device includes:
[0464] Performing dynamic session key negotiation with a source Bluetooth device using the session key in the cryptographic resource to obtain a temporary session key;
[0465] A secure communication channel is established based on the temporary session key to perform Bluetooth communication.
[0466] In one embodiment, after establishing the secure communication channel, the method further includes:
[0467] Acquiring a local channel state, and constructing a channel map and a channel priority table based on the local channel state;
[0468] Obtain your own business information and establish a business priority table based on the level and priority of your own business.
[0469] In one embodiment, it further includes:
[0470] The channel map information and the channel priority table are sent to all Bluetooth devices in the network in a broadcast manner.
[0471] In one embodiment, it further includes:
[0472] Periodically acquiring a channel status, and updating the channel priority table based on the channel status to obtain a new channel priority table;
[0473] The new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
[0474] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0475] The present application is described with reference to the flow chart and / or block diagram of the method, device (system), and computer program product according to the embodiment of the present application. It should be understood that each flow process and / or box in the flow chart and / or block diagram and the combination of the flow process and / or box in the flow chart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processing machine or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one flow chart flow or multiple flows and / or one box or multiple boxes of the block diagram.
[0476] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0477] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0478] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0479] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0480] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0481] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0482] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A Bluetooth communication method, characterized in that: Applied to a password resource management system, the Bluetooth communication method includes: Obtaining a cryptographic resource application sent by a source Bluetooth device; the cryptographic resource application includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers; Based on the source Bluetooth device information and the destination Bluetooth device information, matching the application key of the source Bluetooth device and the application key of the destination Bluetooth device from a plurality of preset Bluetooth device application keys; Generate a cryptographic resource based on an application key of the source Bluetooth device, an application key of the destination Bluetooth device and a plurality of random numbers; Encrypting the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; Sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on the preset master station private key to generate a first signature and a second signature; Sending the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and sending the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the cryptographic resources; The cryptographic resource is used to generate a private address.
2. The Bluetooth communication method according to claim 1, characterized in that: The cryptographic resource management system is pre-set with security chip serial numbers of multiple Bluetooth devices, the multiple random numbers include a first random number, a second random number and a third random number, and the cryptographic resources include a Z algorithm instance, a temporary key and a session key; The generating of cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and a plurality of random numbers comprises: Based on the first random number, the application key of the source Bluetooth device is dispersed to obtain a temporary key K1; Distribute the application key of the destination Bluetooth device based on the second random number to obtain a temporary key K2; Generate a Z algorithm instance Z1 using the Z cryptographic algorithm based on the temporary key K1, and generate a Z algorithm instance Z2 using the Z cryptographic algorithm based on the temporary key K2; Distribute the application key of the source Bluetooth device based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key; The cryptographic resource is obtained according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key.
3. The Bluetooth communication method according to claim 1, characterized in that: The process of obtaining the preset multiple Bluetooth device application keys includes: Register multiple Bluetooth devices and obtain security chip information of each Bluetooth device respectively, wherein the security chip information at least includes a security chip serial number; The security chip serial numbers of the various Bluetooth devices are dispersed based on the preset service root keys to obtain application keys of the multiple Bluetooth devices.
4. A Bluetooth communication method, characterized in that: Applicable to source Bluetooth devices, including: Obtaining a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained by the Bluetooth communication method according to any one of claims 1 to 3; Verify the first signature using a preset master station certificate, and if the verification of the first signature is successful, decrypt the first cryptographic resource ciphertext using a preset application key of the source Bluetooth device to obtain the cryptographic resource; Based on the password resource, Bluetooth communication is performed with the target Bluetooth device.
5. The Bluetooth communication method according to claim 4, characterized in that: The cryptographic resources include a Z algorithm instance, a temporary key and a session key; The performing Bluetooth communication with the target Bluetooth device based on the password resource includes: Constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource; Based on the private address, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device.
6. The Bluetooth communication method according to claim 5, characterized in that: The temporary key includes: temporary key K1 and temporary key K2; the Z algorithm instance includes: Z algorithm instance Z1 and Z algorithm instance Z2; The constructing of a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes: Obtaining the current local time and region code, and generating a timestamp based on the current local time; Based on the temporary key K1 and the Z algorithm instance Z1, the random code composed of the timestamp and the regional code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address; Based on the temporary key K2 and the Z algorithm instance Z2, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the destination Bluetooth device address; Constructing a source Bluetooth device private address based on the encrypted ciphertext of the source Bluetooth device address, the timestamp and the regional code; Based on the encrypted ciphertext, timestamp and region code of the target Bluetooth device address, a private address of the target Bluetooth device is constructed.
7. The Bluetooth communication method according to claim 6, characterized in that: The method of performing Bluetooth communication with a destination Bluetooth device based on the private address and using a session key in the cryptographic resource includes: Sending a connection establishment request to the destination Bluetooth device based on the source Bluetooth device private address and the destination Bluetooth device private address; When the connection establishment request is sent successfully, obtain the private address to be verified sent by the target Bluetooth device; The legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification is passed, the session key in the cryptographic resource is used to perform Bluetooth communication with the target Bluetooth device.
8. The Bluetooth communication method according to claim 7, characterized in that: When the verification is successful, the session key in the cryptographic resource is used to perform Bluetooth communication with the destination Bluetooth device, including: Using the session key in the cryptographic resource to negotiate a dynamic session key with the destination Bluetooth device to obtain a temporary session key; A secure communication channel is established based on the temporary session key to perform Bluetooth communication.
9. The Bluetooth communication method according to claim 8, characterized in that: After establishing a secure communication channel, it also includes: Acquire the local channel state, and construct a channel map and a channel priority table based on the local channel state; Obtain your own business information and establish a business priority table based on the level and priority of your own business.
10. The Bluetooth communication method according to claim 9, characterized in that: Also includes: The channel map and channel priority table are sent to all Bluetooth devices in the network in a broadcasting manner.
11. The Bluetooth communication method according to claim 9, characterized in that: Also includes: switching data channels according to a channel selection algorithm; Using the switched data channel to obtain current channel status information and current service information; Comparing the current channel state information with the channel priority table to obtain the priority of the current channel; According to the priority of the current channel, the service priority table and the current service information, the service channel is switched to obtain the most suitable channel.
12. The Bluetooth communication method according to claim 11, characterized in that: The switching of the service channel according to the priority of the current channel, the service priority table and the current service information to obtain the most suitable channel includes: According to the service priority table and current service information, query and obtain the current service priority; Determining whether the current service priority matches the current channel priority; If it is determined that the current service priority matches the priority of the current channel, the current channel is used for communication; If it is determined that the current service priority does not match the priority of the current channel, a channel matching the current service priority is selected from the channel priority table and the channel is used for communication.
13. The Bluetooth communication method according to claim 9, characterized in that: Also includes: Periodically acquiring a channel status, and updating the channel priority table based on the channel status to obtain a new channel priority table; The new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
14. The Bluetooth communication method according to claim 9, characterized in that: Also includes: During the communication process, determine whether to dynamically adjust the time slot of the current communication according to the size of the interactive data packet; When the size of the interactive data packet is greater than a preset threshold, the proportion of the time slot used for the current communication is adjusted according to the current service priority to achieve dynamic adjustment of the time slot.
15. The Bluetooth communication method according to claim 14, characterized in that: The adjusting the proportion of the time slots used for the current communication according to the current service priority to achieve dynamic adjustment of the time slots includes: Generate multiple business weights according to the current business priority and the business priority table; Based on the proportion of each service weight, the proportion of the time slot used for the current communication is adjusted to achieve dynamic adjustment of the time slot.
16. The Bluetooth communication method according to claim 15, characterized in that: The adjusting the proportion of time slots used for current communication based on the proportion of each service weight includes: Initialize the total time slot length; Calculate the adjusted time slot length of each connection according to the proportion of each service weight and the total time slot length; Based on the adjusted time slot length of each connection, a time slot is updated for each connection in the current communication to adjust the proportion of time slots used for the current communication.
17. A Bluetooth communication method, characterized in that: Applicable to target Bluetooth devices, including: Obtaining a second cryptographic resource ciphertext and a second signature, wherein the second cryptographic resource ciphertext and the second signature are obtained by the Bluetooth communication method according to any one of claims 1 to 3; Verify the second signature using a preset master station certificate, and if the second signature verification succeeds, decrypt the second cryptographic resource ciphertext using a preset application key of the destination Bluetooth device to obtain the cryptographic resource; Based on the cryptographic resource, Bluetooth communication is performed with a source Bluetooth device.
18. The Bluetooth communication method according to claim 17, characterized in that: The cryptographic resources include a Z algorithm instance, a temporary key and a session key; The performing Bluetooth communication with the source Bluetooth device based on the password resource includes: Constructing a private address based on the Z algorithm instance and the temporary key in the cryptographic resource; Based on the private address, a session key in the cryptographic resource is used to perform Bluetooth communication with a source Bluetooth device.
19. The Bluetooth communication method according to claim 18, characterized in that: The temporary key includes: temporary key K1 and temporary key K2; the Z algorithm instance includes: Z algorithm instance Z1 and Z algorithm instance Z2; The constructing of a private address based on the Z algorithm instance and the temporary key in the cryptographic resource includes: Obtaining the current local time and region code, and generating a timestamp based on the current local time; Based on the temporary key K1 and the Z algorithm instance Z1, the random code composed of the timestamp and the regional code is encrypted to obtain the encrypted ciphertext of the source Bluetooth device address; Based on the temporary key K2 and the Z algorithm instance Z2, the random code composed of the timestamp and the region code is encrypted to obtain the encrypted ciphertext of the destination Bluetooth device address; Constructing a source Bluetooth device private address based on the encrypted ciphertext of the source Bluetooth device address, the timestamp and the regional code; Based on the encrypted ciphertext, timestamp and region code of the target Bluetooth device address, a private address of the target Bluetooth device is constructed.
20. The Bluetooth communication method according to claim 18, characterized in that: The method of performing Bluetooth communication with a source Bluetooth device based on the private address and using a session key in the cryptographic resource includes: In response to a connection establishment request sent by a source Bluetooth device, obtaining a private address to be verified sent by the source Bluetooth device; The legitimacy of the private address to be verified is verified based on the cryptographic resource, and if the verification is passed, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device.
21. The Bluetooth communication method according to claim 20, characterized in that: When the verification is successful, the session key in the cryptographic resource is used to perform Bluetooth communication with the source Bluetooth device, including: Using the session key in the cryptographic resource to negotiate a dynamic session key with the source Bluetooth device to obtain a temporary session key; A secure communication channel is established based on the temporary session key to perform Bluetooth communication.
22. The Bluetooth communication method according to claim 21, characterized in that: After establishing a secure communication channel, it also includes: Acquire the local channel state, and construct a channel map and a channel priority table based on the local channel state; Obtain your own business information and establish a business priority table based on the level and priority of your own business.
23. The Bluetooth communication method according to claim 22, characterized in that: Also includes: The channel map information and the channel priority table are sent to all Bluetooth devices in the network in a broadcasting manner.
24. The Bluetooth communication method according to claim 22, characterized in that: Also includes: Periodically acquiring a channel status, and updating the channel priority table based on the channel status to obtain a new channel priority table; The new channel priority table is broadcasted so that the connected Bluetooth devices can dynamically adjust the frequency hopping channels according to the new channel priority table.
25. A Bluetooth communication system, characterized in that: It includes a password resource management system, a source Bluetooth device and a destination Bluetooth device; The source Bluetooth device is used to send a cryptographic resource application to the cryptographic resource management system; the cryptographic resource application includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers; The cryptographic resource management system is used to match the application key of the source Bluetooth device and the application key of the destination Bluetooth device from the application keys of the preset multiple Bluetooth devices based on the source Bluetooth device information and the destination Bluetooth device information; generate cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and multiple random numbers; The cryptographic resources are encrypted using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; the first cryptographic resource ciphertext and the second cryptographic resource ciphertext are signed respectively based on a preset master station private key to generate a first signature and a second signature; the first signature and the first cryptographic resource ciphertext are sent to the source Bluetooth device, and the second signature and the second cryptographic resource ciphertext are sent to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device perform Bluetooth communication based on the cryptographic resources; wherein the cryptographic resources are used to generate a private address.
26. A Bluetooth communication device, characterized in that: Applied to a password resource management system, the Bluetooth communication device comprises: An acquisition module, used to acquire a cryptographic resource application sent by a source Bluetooth device; the cryptographic resource application includes source Bluetooth device information, destination Bluetooth device information and multiple random numbers; An application key matching module, used for matching the application key of the source Bluetooth device and the application key of the destination Bluetooth device from a plurality of preset Bluetooth device application keys based on the source Bluetooth device information and the destination Bluetooth device information; A cryptographic resource generation module, used to generate cryptographic resources based on the application key of the source Bluetooth device, the application key of the destination Bluetooth device and a plurality of random numbers; A first encryption module, used to encrypt the cryptographic resource using the application key of the source Bluetooth device and the application key of the destination Bluetooth device respectively, to obtain a first cryptographic resource ciphertext and a second cryptographic resource ciphertext; wherein the cryptographic resource is used to generate a private address; A first signature module, used to sign the first cryptographic resource ciphertext and the second cryptographic resource ciphertext respectively based on a preset master station private key to generate a first signature and a second signature; The sending module is used to send the first signature and the first cryptographic resource ciphertext to the source Bluetooth device, and send the second signature and the second cryptographic resource ciphertext to the destination Bluetooth device, so that the source Bluetooth device and the destination Bluetooth device can perform Bluetooth communication based on the cryptographic resources.
27. The Bluetooth communication device according to claim 26, characterized in that: The cryptographic resource management system is pre-set with security chip serial numbers of multiple Bluetooth devices, the multiple random numbers include a first random number, a second random number and a third random number, and the cryptographic resources include a Z algorithm instance, a temporary key and a session key; The password resource generation module includes: A first distributed processing unit, configured to perform distributed processing on the application key of the source Bluetooth device based on the first random number to obtain a temporary key K1; A second distributed processing unit, configured to perform distributed processing on the application key of the destination Bluetooth device based on the second random number to obtain a temporary key K2; An algorithm instance unit, configured to generate a Z algorithm instance Z1 by using a Z cryptographic algorithm based on the temporary key K1, and to generate a Z algorithm instance Z2 by using a Z cryptographic algorithm based on the temporary key K2; A third distributed processing unit, configured to perform distributed processing on the application key of the source Bluetooth device based on the security chip serial number of the destination Bluetooth device and the third random number to obtain a session key; A resource generation unit is used to obtain a key according to the temporary key K1, the temporary key K2, the Z algorithm instance Z1, the Z algorithm instance Z2 and the session key. Code resources.
28. A Bluetooth communication device, characterized in that: Applicable to source Bluetooth devices, including: A first cryptographic resource acquisition module, used to acquire a first cryptographic resource ciphertext and a first signature, wherein the first cryptographic resource ciphertext and the first signature are obtained by the Bluetooth communication device described in any one of claims 26-27; A first signature verification module, configured to verify the first signature using a preset master station certificate, and if the first signature verification is successful, decrypt the first cryptographic resource ciphertext using a preset application key of the source Bluetooth device to obtain the cryptographic resource; The first Bluetooth communication module is used to perform Bluetooth communication with a target Bluetooth device based on the password resource.
29. A Bluetooth communication device, characterized in that: Applicable to target Bluetooth devices, including: A second cryptographic resource acquisition module, used to obtain a second cryptographic resource ciphertext and a second signature, wherein the second cryptographic resource ciphertext and the second signature are obtained by the Bluetooth communication device described in any one of claims 26-27; A second signature verification module is used to verify the second signature using a preset master station certificate, and if the second signature verification is successful, decrypt the second cryptographic resource ciphertext using a preset application key of the target Bluetooth device to obtain the cryptographic resource; The second Bluetooth communication module is used to perform Bluetooth communication with the source Bluetooth device based on the password resource.
30. An electronic device, characterized in that: The electronic device includes: at least one processor; a memory connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the at least one processor implements the Bluetooth communication method according to any one of claims 1 to 24 by executing the instructions stored in the memory.
31. A machine-readable storage medium having instructions stored thereon, characterized in that: When the instruction is executed by a processor, the processor is configured to execute the Bluetooth communication method according to any one of claims 1 to 24.
Citation Information
Patent Citations
Method, device and system for allocating communication time slots in time division multiple access system
CN103533655A
Multi-factor verifiable low-power-consumption Bluetooth device IPv6 address automatic configuration method and system
CN117014887A
Bluetooth communication method, device and system, storage medium and electronic equipment
CN117255340A
Systems and Methods for Deployment, Management and Use of Dynamic Cipher Key Systems
US20200112430A1
Safe distribution method, device and system of vehicle bluetooth key and storage medium
WO2022027957A1