Communication method and related apparatus
By introducing a digital certificate authentication mechanism for third nodes, the problem of fake AP attacks in enterprise networks is solved, and trusted authentication of node identities and network security are improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2026-04-02
AI Technical Summary
In existing technologies, enterprise network authentication methods are insufficient to prevent fake AP attacks, leading to the leakage of access user data. Relying solely on authentication servers to authenticate the identity of terminals is insufficient to ensure network security.
A third node is introduced to implement a two-way authentication mechanism based on digital certificates. Identity authentication is performed through certificates and signatures between the first, second, and third nodes to ensure the trustworthiness of the node's identity. A three-element peer-to-peer authentication mechanism is adopted, using digital certificates and signatures for authentication.
It significantly improves the security performance of nodes, reduces the possibility of attackers accessing the network, ensures the credibility of node identities in the network, and enhances the security and stability of the network.
Smart Images

Figure CN2025124156_02042026_PF_FP_ABST
Abstract
Description
Communication method and related apparatus
[0001] This application claims priority to the Chinese Patent Application No. 202411398169.7, filed on September 30, 2024, and entitled "A communication method and related apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, and in particular to a communication method and related apparatus. BACKGROUND
[0003] In the era of rapid development of mobile Internet, our tools are more convenient to use than traditional computers, especially desktop workstations and servers. However, they also face greater risks. Communication security has gradually become a key issue in the field of communication. Especially for wireless transmission, nodes and access points (APs) need to perceive each other in a complex space first, and then perform an access process to realize data transmission between them.
[0004] For enterprise networks, considering internal network security, enterprise networks often need to perform security authentication on access users to ensure that the identity of the terminal entering the network is trusted. The authentication method of the enterprise network usually introduces an authentication server to authenticate the identity of the terminal after the terminal accesses the AP. However, since the access process involves multiple nodes such as terminals, APs, and authentication servers, relying solely on the authentication server to authenticate the identity of the terminal cannot ensure network security. For example, the authentication method of authenticating the identity of the terminal by the authentication server cannot prevent fake AP attacks. A fake AP is an AP disguised by an attacker. When a terminal accesses a fake AP, it is easy to cause data leakage of the access user. SUMMARY
[0005] The present application provides a communication method and related apparatus. In the present application, a third node can authenticate a second node and a first node, and the authentication is based on a digital certificate, which has high reliability and can significantly improve the security performance of the node and protect the security of the network. Further, the present application supports a bidirectional authentication mechanism of a ternary peer-to-peer architecture of the first node, the second node and the third node. The first node, the second node and the third node all use certificates for bidirectional authentication, which can further improve the security performance of the node.
[0006] In a first aspect, the present application provides a communication method, comprising: receiving first information and a first signature from a second node, and sending second information and a second signature to a third node, wherein the first information comprises a certificate of the second node, the first signature is a signature of the first information, the second information comprises the first information, the first signature and a certificate of the first node, the second signature is a signature of the second information, and the certificate of the first node, the certificate of the second node, the first signature and the second signature are used for authentication.
[0007] The method can be applied to a first node, which is a device with communication capability. In specific implementation processes, the method can be executed by a software module, a hardware module or a function module combined with software and hardware in the first node, such as a chip or a processor in the first node. For ease of description, the following description takes the first node as an example.
[0008] In the present application, the first information (comprising the certificate of the second node) and the first signature can be used to authenticate the identity of the second node, and the second information (comprising the certificate of the first node) and the second signature can be used to authenticate the identity of the second node. The first node obtains the first information and the first signature, and sends the first information, the first signature, the second information and the second signature to the third node, and the third node can authenticate the identities of the first node and the second node based on the first information, the first signature, the second information and the second signature. In this way, the third node authenticates the identities of the first node and the second node based on digital certificates, which can ensure that the identities of the first node and the second node are both reliable, thereby reducing the possibility of an attacker accessing the network and the possibility of a node being associated with a fake access point, and ensuring that the identities of the second node and the first node in the network are both reliable. Moreover, the authentication process is based on digital certificates and a signature mechanism, which is highly reliable. In summary, the present application can significantly improve the security performance of the node and ensure the security of the network.
[0009] In a possible implementation of the first aspect, the first node is a node requesting association with the second node, that is, the first node is an associated node (which can be regarded as an access point), and the second node is a node requesting association with the first node. Exemplarily, the second node can send an association request (or an access request) to the first node, thereby requesting association with the first node. The present application can significantly improve the security performance of the node in the process of accessing the network, and can avoid an attacker accessing the network and a node being associated with a fake access point.
[0010] In a further possible implementation form of the first aspect, the third node is an authentication capable node capable of authenticating the first node and the second node, in some scenarios referred to as authentication node, authentication server, authentication service, etc. By authenticating the nodes of the access network and the access points of the network via the third node, it can be ensured that only trusted, authorized nodes can access the network and access a secure network, thus ensuring the security of the network. Optionally, the third node is communicatively connected to the second node, or the third node and the first node belong to the same device. The communicative connection can be embodied in that the third node and the first node can exchange messages.
[0011] In a further possible implementation form of the first aspect, the communication method further comprises receiving third information and a third signature from the third node, the third information comprising a certificate of the third node, and the third signature being a signature of the third information.
[0012] The third information (comprising the certificate of the third node) and the third signature can be used to authenticate the identity of the third node. In this way, the first node can authenticate the third node or provide the above information to other nodes to authenticate the third node, ensuring the information of the third node, ensuring that the identities of the nodes communicated by the first node are trusted, further improving the security performance of the nodes, and ensuring the security of the network.
[0013] In a further possible implementation form of the first aspect, after receiving the first information and the first signature from the second node, the method further comprises authenticating the second node based on the certificate of the second node and the first signature.
[0014] Exemplarily, the certificate of the second node can be issued by a certificate authority, and the second node can generate a pair of public and private keys, provide the public key to the certificate authority, and the certificate authority signs the signed information using its own private key, and includes the signed information and the signature in the digital certificate. The signed information includes the public key, and optionally one or more of the identity of the second node, the information of the certificate authority, the validity period of the certificate, etc. The first node can verify the signature in the digital certificate based on the public key of the certificate authority, thereby checking the correctness of the certificate.
[0015] Exemplarily, the certificate includes the public key, and the first signature is generated based on the private key and the first information. The first node can verify the first signature based on the public key in the certificate and the first information. If the first signature is verified, it indicates that the identity of the source (i.e. the second node) of the first information is trusted and the first information has not been tampered with.
[0016] Exemplarily, if the verification of the certificate of the second node passes and the verification of the first signature passes, it indicates that the identity of the second node is trusted, and the first node can continue to perform subsequent operations. Otherwise, the identity of the second node is not trusted, and at this time, the first node can discard the received message from the first node, or disconnect the connection with the second node, or add the second node to a blacklist, or no longer perform subsequent steps, etc., to ensure the security of the node.
[0017] In the above embodiment, the first node can authenticate the second node through the certificate and the signature, which can improve the security performance of the first node, avoid attackers from accessing the network, and improve the security of the network.
[0018] In a further possible implementation of the first aspect, after receiving the third information and the third signature from the third node, the method further includes authenticating the third node based on a certificate of the third node and the third signature.
[0019] Exemplarily, the first node can verify the certificate of the third node to determine whether the certificate of the third node is trusted. For example, the certificate of the third node includes information signed by a certificate authority, and the first node can verify the certificate based on the public key of the certificate authority of the certificate of the third node.
[0020] Exemplarily, the first node can verify the third signature. Exemplarily, the certificate of the third node includes a public key, and the first node can verify the third signature based on the public key in the certificate of the third node and the third information. If the verification of the third signature passes, it indicates that the identity of the source (i.e., the third node) of the third information is trusted and the third information is not tampered.
[0021] In the above embodiment, while the first node provides its own certificate and signature to other nodes for authentication of the other nodes, the first node itself can also authenticate the third node through the certificate and the signature, which can achieve the peer-to-peer mutual authentication of the first node and the third node, improve the security performance of the first node, avoid the first node from communicating with the third node disguised by an attacker, and improve the security of the network.
[0022] In a further possible implementation of the first aspect, the communication method further includes sending fourth information and a fourth signature to the second node. The fourth information includes the third information, the third signature, a certificate of the third node, and a certificate of the first node, the fourth signature is a signature of the fourth information, and the certificate of the first node, the certificate of the third node, the third signature, and the fourth signature are used for authentication.
[0023] In the above embodiments, the first node can provide the second node with the certificate of the first node, the third signature, the certificate of the third node and the fourth signature, so as to authenticate the first node and the third node by the second node, which helps to implement a peer-to-peer mutual authentication mechanism, improves the security performance of the second node, avoids the second node from communicating with an untrusted node, and improves the security of the network.
[0024] In a further possible implementation of the first aspect, the third information further includes an authentication result of the first node by the third node and / or an authentication result of the second node by the third node.
[0025] As a possible implementation, the authentication result of the first node by the third node includes one or more of a verification result of the second signature, or a verification result of the certificate of the first node. For example, the verification result of the second signature can include a verification pass or a verification fail. For another example, the verification result of the certificate of the first node includes whether the certificate verification passes, and when the verification fails, the verification result of the certificate of the first node can optionally further include a failure cause, which for example indicates one or more of that the certificate is expired, the certificate is revoked, or the certificate is illegal.
[0026] As a further possible implementation, the authentication result of the second node by the third node includes one or more of a verification result of the first signature, or a verification result of the certificate of the second node. For example, the verification result of the first signature can include a verification pass or a verification fail. For another example, the verification result of the certificate of the second node includes whether the certificate verification passes, and when the verification fails, the verification result of the certificate of the second node can optionally further include a failure cause, which for example indicates one or more of that the certificate is expired, the certificate is revoked, or the certificate is illegal.
[0027] In the above embodiments, by carrying the authentication result in the third information, the success or failure (optionally further including a failure cause) of the identity verification can be fed back, which facilitates the first node to trigger a corresponding security operation based on the authentication result, forms an authentication closed-loop management, and improves the network security. Exemplarily, if the identity of the second node is authenticated to pass, it indicates that the first node and the second node can perform a subsequent communication process, otherwise the first node can disconnect the connection with the second node or no longer continue the subsequent communication process, so as to ensure the communication security of the first node. For another example, if the identity of the first node is authenticated to fail, the first node can feed back or prompt, so as to trigger an administrator or a management device to update the certificate of the first node, avoids network access problems, and improves the network stability.
[0028] In a further possible implementation of the first aspect, the communication method further includes: sending an authentication mode indication, the authentication mode indication being used to indicate that the authentication mode is the certificate authentication mode.
[0029] Optionally, the authentication manner indication is carried in a unicast message, a groupcast message or a broadcast message. For example, the first node can periodically or aperiodically send a broadcast message, and the authentication manner indication is carried in the broadcast message. For another example, the first node can send the authentication manner indication to the second node in a message sent to the second node.
[0030] Taking the star flash communication system as an example, the first node can be a management node, and the second node can be a terminal node. The management node sends a communication domain system message in a broadcast manner, and the authentication manner indication is carried in the communication domain system message. The terminal node receives the communication domain system message, requests association with the management node, and performs an authentication procedure with the management node and the authentication node in the authentication manner indicated by the authentication manner indication.
[0031] In some scenarios, the above authentication procedure is performed in an enterprise version network. For example, the authentication manner indication is used to indicate that the authentication manner is an enterprise version-certificate authentication manner.
[0032] In the above embodiments, before the authentication procedure, the first node can send the authentication manner indication to indicate the manner of authenticating the second node, so that the second node can perform a corresponding authentication procedure in the authentication manner indicated by the first node.
[0033] In a further possible implementation form of the first aspect, the first information further comprises a public key of the second node, and the public key of the second node is used to determine a first key, and the first key is used to verify information negotiated in the security context negotiation procedure.
[0034] In the above embodiments, the second node can carry the first public key in the first information, and the first public key can be used to obtain a negotiation key with another node or further derive other keys based on the negotiation key. The first key can be the negotiation key or a key derived based on the negotiation key, and is used to verify information transmitted between the first node and the second node in the security context negotiation procedure.
[0035] The security context negotiation procedure is a procedure performed between the first node and the second node. The security context negotiation procedure between the first node and the second node is verified by the first key, which can ensure the information security of the first node and the second node and help improve the communication security of the first node.
[0036] In some embodiments, the security context negotiation procedure is used to negotiate the security context of the first node and the second node. The security context includes, but is not limited to, one or more of a security key, a security algorithm, or a security parameter. The security key includes, but is not limited to, one or more of a shared key, a master key, an encryption key, an integrity protection key, an authenticated encryption key, an identity authentication key, an identification (ID) encryption key, etc. The security algorithm includes, but is not limited to, one or more of a key negotiation algorithm, a key derivation function (KDF), an authenticated encryption algorithm, an encryption algorithm, an integrity protection algorithm, an information digest algorithm, etc. The security parameter includes, but is not limited to, one or more of a freshness parameter, an ID of the node, information used for encryption, timestamp information, a key validity period, etc.
[0037] In some embodiments, the security context negotiation procedure is performed before the authentication procedure, i.e., the first node and the second node perform the security context negotiation procedure before receiving the first information and the first signature from the second node. At this time, the identity of the second node has not been authenticated, and thus, a first key can be determined in the second node authentication process. The first key is determined based on the identity authentication, and information transmitted in the security context negotiation procedure is verified based on the first key, which ensures the forward information security of the first node and helps to improve the communication security of the first node.
[0038] In a further possible implementation form of the first aspect, the first information further includes a first freshness parameter, and the first freshness parameter is used to determine the first key.
[0039] The above implementation form introduces the first freshness parameter provided by the second node into the generation process of the first key, and defines a new way of generating the first key, thereby improving the security. The first freshness parameter is used as a freshness value in the determination process of the first key, which can improve the privacy and uniqueness of the first key and help to improve the security performance of the node.
[0040] In a further possible implementation form of the first aspect, the second information further includes a second freshness parameter, and the third information further includes the second freshness parameter. The second freshness parameter is used to determine the first key.
[0041] The above implementation form introduces the second freshness parameter provided by the first node into the generation process of the first key, and defines a new way of generating the first key, thereby improving the security. The second freshness parameter is used as a freshness value in the determination process of the first key, which can improve the privacy and uniqueness of the first key and help to improve the security performance of the node.
[0042] It should be appreciated that the above-mentioned embodiments can be combined. For example, the first fresh parameter and the second fresh parameter can be used in the process of determining the first key. In this way, the fresh parameter provided by the first node and the fresh parameter provided by the second node are involved in the process of determining the first key as fresh values, which can improve the privacy and uniqueness of the first key and help improve the security performance of the nodes.
[0043] In a further possible implementation form of the first aspect, before receiving the first information and the first signature from the second node, the method further comprises: sending a third fresh parameter to the second node, and the first information further comprises the third fresh parameter.
[0044] The above-mentioned embodiments provide a challenge-response based anti-replay mechanism. A replay attack refers to an attack technique in which an attacker steals data sent by another device to a destination device and re-sends the data to the destination device, so as to deceive the destination device and obtain the trust of the destination device. In order to avoid the replay attack by the attacker, the first node can send a third fresh parameter to the second node, and the second node includes the third fresh parameter in the first information provided to the first node, the third fresh parameter being a fresh parameter specified to be sent to the second node and used only by the second node, and the third fresh parameter can indicate the uniqueness of the first information this time and / or mark the second node. If the attacker steals the first information and the first signature and re-sends them to the first node, since the third fresh parameter in the first information sent by the attacker has been used, the first node can detect that the first information is information that has been received, so as to reduce the possibility of success of the replay attack and improve the security performance of the first node and the second node.
[0045] Optionally, the third fresh parameter is the same as the second fresh parameter, that is, the second fresh parameter used to participate in the generation of the first key is also applied to the anti-replay mechanism, so as to avoid repeated calculation of the fresh parameter and reduce the calculation amount of the first node.
[0046] In a further possible implementation form of the first aspect, the first information further comprises a first timestamp determined by the second node. The first timestamp has uniqueness and can be used to indicate a time point related to the first information, for example, a time point at which the first information is generated or a time point at which the first information is sent, which can be accurate to seconds, microseconds or milliseconds.
[0047] The above-mentioned embodiments provide a timestamp-based anti-replay mechanism. The timestamp is used to prevent replay and avoid the attacker from copying the information sent by the second node to the first node and re-sending it to the first node. Since the timestamp can uniquely identify a time point and has uniqueness, and the timestamp is carried in the signed first information to avoid tampering, the above-mentioned embodiments can reduce the possibility of success of the replay attack and improve the security performance of the first node and the second node.
[0048] Optionally, the first timestamp is included in the second information. Further, the first timestamp is involved in generating the first key.
[0049] In a further possible implementation form of the first aspect, the second information further comprises information of a first KDF and / or information of a first key agreement algorithm, the first KDF being agreed upon by the first node and the second node, the first key agreement algorithm being agreed upon by the first node and the second node. The first key agreement algorithm is configured to agree on a key, and the first KDF is configured to derive the key.
[0050] In the above implementation form, the first KDF and the first key agreement algorithm are determined by negotiation, and for the second node with different security capabilities, the first KDF and the first key agreement algorithm determined by negotiation with the first node can be different, so that the authentication process among the first node, the second node and the third node can adapt to the first node and the second node with different security capabilities, and the compatibility of the network is improved, and the user experience is improved.
[0051] Exemplarily, the first key agreement algorithm is configured to determine a negotiated master key, and the first KDF is configured to determine the first key based on the negotiated master key.
[0052] In a further possible implementation form of the first aspect, the first node communicates with the second node using a first communication protocol, and the first node and the third node communicate using a second communication protocol, the first communication protocol being different from the second communication protocol.
[0053] The above implementation form provides an application scenario of the present application. The present application can be applied to a complex network supporting multiple communication protocols, and supports authenticating a node, an access point of a network and an authentication node in the complex communication network, and has strong compatibility. Exemplarily, the first communication protocol is a starlink communication protocol, and the second communication protocol is an Ethernet communication protocol.
[0054] In a further possible implementation form of the first aspect, the first communication protocol is different from the second communication protocol, information transmitted between the first node and the third node is encapsulated in a data packet, a format of the data packet is defined by the first communication protocol, and the data packet is carried in a payload part of a protocol data unit (PDU) transmitted between the first node and the third node, a format of the PDU being defined by the second communication protocol.
[0055] In the above embodiments, the first node communicates with the third node in the second communication protocol. Since the first node also supports the first communication protocol, the message encapsulated in the first communication protocol transmitted between the first node and the authentication node can be transmitted in the payload part of the message in the second communication protocol. That is, the format of the PDU transmitted between the first node and the third node is defined by the second communication protocol, but the payload part of the PDU carries the message in the first communication protocol.
[0056] For example, the second communication protocol is the Ethernet communication protocol, and the first communication protocol is the StarFlash communication protocol. The information transmitted between the first node and the third node is encapsulated in the message format of StarFlash, and the StarFlash message is carried in the payload part of the Ethernet message, and the message transmitted between the first node and the third node is the Ethernet message. That is, the message in the second communication protocol covers the message in the first communication protocol, so that the information transmitted in the first communication protocol can be transmitted in the second communication protocol, and the compatibility between different communication protocols is improved.
[0057] In a further possible implementation form of the first aspect, the payload part of the PDU further comprises a message type field, a value of the message type field being used to indicate a type of the data message carried by the payload part of the PDU.
[0058] For example, the message type field is used to indicate one of the following message types: certificate authentication request, certificate authentication response, certificate authentication complete, or key distribution. It should be understood that the names of the above messages are only examples, and in specific implementations, the names of the messages can be replaced. Moreover, the terms of message, message, packet, etc. are different calls for data units in different scenarios, and can be replaced without conflict.
[0059] In a further possible implementation form of the first aspect, the first node communicates with the second node in the first communication protocol, and the first node and the third node communicate in the second communication protocol, and the first communication protocol is the same as the second communication protocol. The above embodiment provides another application scenario, and the present application is also applicable to a network supporting a single communication protocol. For example, the first communication protocol and the second communication protocol are both StarFlash communication protocols.
[0060] In a further possible implementation form of the first aspect, receiving the first information and the first signature from the second node comprises: receiving an access authentication request from the second node, the access authentication request comprising the first information and the first signature. That is, the first information and the first signature can be carried in the access authentication request and transmitted. Optionally, the first information can be regarded as all data fields in the access authentication request except the first signature.
[0061] In a further possible implementation form of the first aspect, the sending of the second information and the second signature to the third node comprises sending a certificate authentication request to the third node, the certificate authentication request comprising the second information and the second signature. That is, the second information and the second signature can be carried in the certificate authentication request and transmitted. Optionally, the second information can be regarded as all data fields in the certificate authentication request except the second signature.
[0062] In a further possible implementation form of the first aspect, the receiving of the third information and the third signature from the third node comprises receiving a certificate authentication response from the third node, the certificate authentication response comprising the third information and the third signature. That is, the third information and the third signature can be carried in the certificate authentication response and transmitted. Optionally, the third information can be regarded as all data fields in the certificate authentication response except the third signature.
[0063] In a further possible implementation form of the first aspect, the sending of the fourth information and the fourth signature to the second node comprises sending an access authentication response to the second node, the access authentication response comprising the fourth information and the fourth signature. That is, the fourth information and the fourth signature can be carried in the access authentication response and transmitted. Optionally, the fourth information can be regarded as all data fields in the access authentication response except the fourth signature.
[0064] In a further possible implementation form of the first aspect, after the sending of the fourth information and the fourth signature to the second node, the communication method further comprises receiving a first message from the second node. The first message is used to indicate that the access authentication is completed, for example, an access authentication completion message.
[0065] In the above implementation form, the second node can feed back to the first node that the access authentication is completed, so as to facilitate the first node to perform corresponding operations after the access authentication is completed, to realize closed-loop management of the access authentication procedure at the first node side, and to improve stability of the network.
[0066] In a further possible implementation form of the first aspect, after the sending of the fourth information and the fourth signature to the second node (for example, after the receiving of the first message from the second node), the communication method further comprises sending a second message to the third node, the second message being used to indicate that the certificate authentication is completed, for example, a certificate authentication completion message.
[0067] In the above implementation form, the first node can feed back to the third node that the certificate authentication is completed, so as to facilitate the third node to perform corresponding operations after the certificate authentication is completed, to facilitate the third node to realize closed-loop management of the certificate authentication procedure, and to improve stability of the network.
[0068] In a second aspect, the present application provides a communication method, comprising: sending first information and a first signature to a first node; receiving fourth information and a fourth signature from the first node; authenticating the first node based on a certificate of the second node and the fourth signature; and authenticating a third node based on a certificate of the third node and a third signature. The first information comprises the certificate of the second node, the first signature is a signature of the first information, and the certificate of the second node and the first signature are used for authentication. The fourth information comprises third information, the third signature and the certificate of the first node, the fourth signature is a signature of the fourth information, the third signature is a signature of the third information, the third information comprises the certificate of the third node, the third node is in communication connection with the first node, and the third node is used for authentication.
[0069] The third node is used for authentication, which means that the third node is used for authenticating the identity of other nodes, for example, using a certificate, a signature or other authentication methods to authenticate nodes in the network.
[0070] The method can be applied to a second node, which is a device with communication capability. In a specific implementation process, the method can be executed by a software module, a hardware module or a function module combined with software and hardware in the second node, for example, a chip or a processor in the second node. In order to facilitate description, the following will take the second node as an example for description.
[0071] In the present application, the first information (comprising the certificate of the second node) and the first signature can be used to authenticate the identity of the second node, and the fourth information (comprising the certificate of the third node, the certificate of the second node and the third signature) and the fourth signature can be used to authenticate the identity of the third node and the identity of the second node. The second node can authenticate the identity of the first node based on the certificate of the first node and the fourth signature, and authenticate the identity of the first node based on the certificate of the third node and the third signature, which can ensure that the first node communicated by the second node and the third node used for authentication are both correct, and can reduce the possibility of the second node accessing an unreliable network. Moreover, the above authentication process is based on a digital certificate and a signature mechanism, which has high reliability. In summary, the present application can significantly improve the security performance of the node and protect the security of the network.
[0072] In addition, the second node also provides the certificate of the second node and the first signature to the first node, so that the identity of the second node can also be authenticated by other nodes, realizing a bidirectional authentication mechanism of a three-node peer-to-peer architecture, and significantly improving the communication security performance of the node.
[0073] In a possible implementation of the second aspect, the first node is a node associated with the second node, that is, the first node is an associated node (which can be regarded as an access point), and the second node is a node requesting association with the first node.
[0074] In a further possible implementation form of the second aspect, the third node is an authentication capable node, capable of authenticating the first node and the second node, in some scenarios referred to as authentication node, authentication server, authentication service, etc.
[0075] In a further possible implementation form of the second aspect, the third node is communicatively connected to the second node, where the communicative connection can be embodied in that the third node can transmit and receive messages from the first node. In some scenarios, the third node and the second node can be integrated in the same device, and can communicate with each other via a software, hardware or programmatic interface, etc.
[0076] In a further possible implementation form of the second aspect, the third information comprises the second information and a second signature, the second information comprising the first information, the first signature and a certificate of the first node, and the second signature being a signature of the second information. In the above implementation form, the certificate of the first node can be carried in the second information, which is included in the third information, which is included in the fourth information, so that the fourth information comprises the certificate of the first node. The nesting of information makes it easier for the nodes to check the integrity of the information via the signature, and improves the security performance of the communication.
[0077] In a further possible implementation form of the second aspect, the third information further comprises an authentication result of the first node by the third node and / or an authentication result of the second node by the third node.
[0078] In a further possible implementation form of the second aspect, before transmitting the first information and the first signature to the first node, the method further comprises receiving an authentication mode indication from the first node, the authentication mode indication being used to indicate that the authentication mode is the certificate authentication mode.
[0079] In some scenarios, the above authentication procedure is performed in an enterprise version network, for example, the authentication mode indication is used to indicate that the authentication mode is an enterprise version-certificate authentication mode.
[0080] In a further possible implementation form of the second aspect, the third information further comprises a public key of the third node, and the method further comprises determining the first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm.
[0081] Further, the first key is used to verify information negotiated in a security context negotiation procedure.
[0082] The security context negotiation procedure is a procedure performed between the first node and the second node. The first key determined by the negotiation between the first node and the third node (optionally, the first key is obtained through a key derivation procedure, etc.), which is used to verify the security context negotiation procedure between the first node and the second node, can ensure the security of the information of the first node and the second node, and helps to improve the security of the communication of the first node.
[0083] In some embodiments, the security context negotiation procedure is used to negotiate the security context of the first node and the second node. In some embodiments, the security context negotiation procedure is performed before the authentication procedure, i.e. before the first information and the first signature are sent to the first node, the second node and the first node perform the security context negotiation procedure.
[0084] In a further possible implementation form of the second aspect, the first key agreement algorithm is a determined key agreement algorithm negotiated for the first node and the second node. For example, the first key agreement algorithm is determined in the security context negotiation procedure.
[0085] In a further possible implementation form of the second aspect, the first information further comprises a public key of the second node, the public key of the second node being related to a private key of the second node. By carrying the public key of the second node in the first information, the third node can obtain the negotiated key consistent with the second node based on the public key of the second node and the private key of the third node.
[0086] In a further possible implementation form of the second aspect, the first information further comprises a first freshness parameter. Determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a negotiated key based on the public key of the third node and the private key of the second node using the first key agreement algorithm, and determining the first key based on at least the negotiated key and the first freshness parameter.
[0087] The above implementation form introduces the first freshness parameter provided by the second node into the generation process of the first key, defines a new way of generating the first key, and improves the security. The first freshness parameter is used as a freshness value in the determination process of the first key, which can improve the privacy and uniqueness of the first key, and helps to improve the security performance of the node.
[0088] In a further possible implementation form of the second aspect, the fourth information further comprises a second freshness parameter, the second freshness parameter being generated by the first node. Determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a negotiated key based on the public key of the third node and the private key of the second node using the first key agreement algorithm, and determining the first key based on at least the negotiated key and the second freshness parameter.
[0089] The above implementation form introduces the second freshness parameter provided by the first node into the generation process of the first key, defines a new way of generating the first key, and improves the security. The second freshness parameter is used as a freshness value in the determination process of the first key, which can improve the privacy and uniqueness of the first key, and helps to improve the security performance of the node.
[0090] In a further possible implementation form of the second aspect, the first information comprises a first freshness parameter, and the third information further comprises a second freshness parameter. Determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a negotiated key based on the public key of the third node and the private key of the second node using the first key agreement algorithm, and determining the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter.
[0091] The above implementation form introduces the first freshness parameter and the second freshness parameter into the generation process of the first key, defines a new way of generating the first key, and improves security. The first freshness parameter and the second freshness parameter are used as freshness values in the determination process of the first key, which can improve the privacy and uniqueness of the first key and help improve the security performance of the node.
[0092] In a further possible implementation form of the second aspect, determining the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter comprises: determining an intermediate key based on a first key derivation function KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determining the first key based on at least the first KDF and the intermediate key.
[0093] The above implementation form introduces the first freshness parameter and the second freshness parameter into the generation process of the first key, defines a new way of generating the first key, and improves security. The first freshness parameter and the second freshness parameter are used as freshness values in the determination process of the first key, which can improve the privacy and uniqueness of the first key and help improve the security performance of the node.
[0094] In a further possible implementation form of the second aspect, determining the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter comprises: determining an intermediate key based on a first key derivation function KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determining the first key based on the first KDF, the intermediate key, an identity of the first node and an identity of the second node.
[0095] The above implementation form introduces the first freshness parameter, the second freshness parameter, the identity of the first node and the identity of the second node into the generation process of the first key, defines a new way of generating the first key, and improves security. The first freshness parameter and the second freshness parameter are used as freshness values in the determination process of the first key, which can improve the privacy and uniqueness of the first key and help improve the security performance of the node.
[0096] In a further possible implementation form of the second aspect, before sending the first information and the first signature to the first node, the method further comprises determining a first timestamp, and the first information further comprises the first timestamp. The first timestamp is unique and can be used to indicate a time point related to the first information, such as a time point when the first information is generated or a time point when the first information is sent, which can be accurate to seconds, microseconds or milliseconds.
[0097] The above implementation form provides a timestamp-based anti-replay mechanism. Since the timestamp is unique and can be used to indicate a time point, and the timestamp is carried in the signed first information to avoid tampering, the above implementation form can reduce the possibility of a successful replay attack and improve the security performance of the first node and the second node.
[0098] Optionally, the first timestamp can be used in the derivation of the first key, such as being used as an input in the process of deriving an intermediate key based on a negotiated key. Alternatively, the first timestamp can be used in the derivation of the first key based on the intermediate key, as an input.
[0099] In a further possible implementation form of the second aspect, before sending the first information and the first signature to the first node, the method further comprises receiving a third freshness parameter from the first node, and the first information further comprises the third freshness parameter.
[0100] The above implementation form provides a challenge-response-based anti-replay mechanism. The third freshness parameter can indicate the uniqueness of the first information and / or mark the second node. If an attacker steals the first information and the first signature and sends them to the first node again, the first node can detect that the first information has been received before, since the third freshness parameter in the first information sent by the attacker has already been used. This can reduce the possibility of a successful replay attack and improve the security performance of the first node and the second node.
[0101] Optionally, the third freshness parameter is the same as the second freshness parameter, i.e., the second freshness parameter used in the derivation of the first key is also used in the anti-replay mechanism. This can avoid repeated calculation of the freshness parameter and reduce the computational load of the first node.
[0102] In a further possible implementation form of the second aspect, sending the first information and the first signature to the first node comprises sending an access authentication request to the first node, and the access authentication request comprises the first information and the first signature. That is, the first information and the first signature can be carried in the access authentication request and transmitted. Optionally, the first information can be regarded as all data fields in the access authentication request except the first signature.
[0103] In a further possible implementation form of the second aspect, the receiving the fourth information and the fourth signature from the first node comprises receiving an access authentication response from the first node, the access authentication response comprising the fourth information and the fourth signature. That is, the fourth information and the fourth signature can be carried in the access authentication response. Optionally, the fourth information can be regarded as all data fields in the access authentication response except the fourth signature.
[0104] In a third aspect, the present application provides a communication method, comprising: receiving second information and a second signature from a first node, authenticating the first node based on a certificate of the first node and the second signature, authenticating a second node based on a certificate of the second node and a first signature, and sending third information and a third signature to the first node. The second information comprises the first information, the first signature and the certificate of the first node, the first information comprises the certificate of the second node, the first signature is a signature of the first information, and the second signature is a signature of the second information. The third information comprises a certificate of a third node, and the third signature is a signature of the third information. The certificate of the third node and the third signature are used for authentication.
[0105] The method can be applied to a third node, which is a device with communication capability and authentication capability, and can authenticate the first node and the second node. In some scenarios, the third node is referred to as an authentication node, an authentication server, an authentication service, etc. In a specific implementation process, the method can be executed by a software module, a hardware module or a function module combined with software and hardware in the first node, such as a chip or a processor in the third node. For ease of description, the following description takes the third node as an example.
[0106] In the present application, the second information (comprising the certificate of the second node, the first signature and the certificate of the second node) and the first signature can be used to authenticate the identity of the second node and the identity of the third node, and the third information (comprising the certificate of the third node) and the third signature can be used to authenticate the identity of the third node. The third node can authenticate the identity of the first node based on the certificate of the first node and the second signature, and authenticate the identity of the second node based on the certificate of the second node and the first signature, so as to ensure that the first node communicated by the third node and the second node connected by the first node are both authentic, and the possibility of the second node accessing an unreliable network can be reduced. Moreover, the above authentication process is based on a digital certificate and a signature mechanism, and has high reliability. In summary, the present application can significantly improve the security performance of the node and protect the security of the network.
[0107] In addition, the third node also provides the certificate of the third node and the third signature to the first node, so that the identity of the third node can also be authenticated by other nodes, and a bidirectional authentication mechanism of a three-node peer-to-peer architecture is realized, which significantly improves the communication security performance of the node.
[0108] In a further possible implementation form of the third aspect, the third information further comprises an authentication result for the first node and / or an authentication result for the second node.
[0109] In a further possible implementation form of the third aspect, the first information further comprises a public key of the second node, and the method further comprises determining the first key based on the public key of the second node and a private key of the third node using the first key agreement algorithm. Further, the first key is used to verify information agreed in the security context negotiation procedure.
[0110] In a further possible implementation form of the third aspect, the first information comprises a first freshness parameter. Determining the first key based on the public key of the second node and the private key of the third node using the first key agreement algorithm comprises determining a negotiated key based on the public key of the second node and the private key of the third node using the first key agreement algorithm, and determining the first key based on at least the negotiated key and the first freshness parameter.
[0111] In a further possible implementation form of the third aspect, the third information further comprises a second freshness parameter. Determining the first key based on the public key of the second node and the private key of the third node using the first key agreement algorithm comprises determining a negotiated key based on the public key of the second node and the private key of the third node using the first key agreement algorithm, and determining the first key based on at least the negotiated key and the second freshness parameter.
[0112] In a further possible implementation form of the third aspect, the first information comprises a first freshness parameter, and the third information further comprises a second freshness parameter. Determining the first key based on the public key of the second node and the private key of the third node using the first key agreement algorithm comprises determining a negotiated key based on the public key of the second node and the private key of the third node using the first key agreement algorithm, and determining the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter.
[0113] In a further possible implementation form of the third aspect, determining the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter comprises determining an intermediate key based on a first KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determining the first key based on at least the first KDF and the intermediate key.
[0114] In a further possible implementation form of the third aspect, determining the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter comprises determining an intermediate key based on a first KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determining the first key based on the first KDF, the intermediate key, an identity of the first node and an identity of the second node.
[0115] In a further possible implementation form of the third aspect, the second information further comprises information of a first KDF and / or information of a first key agreement algorithm, the first KDF being agreed upon by the first node and the second node, the first key agreement algorithm being agreed upon by the first node and the second node.
[0116] In a further possible implementation form of the third aspect, the first node communicates with the second node using a first communication protocol, the first node and the third node communicate using a second communication protocol, the first communication protocol being different from the second communication protocol.
[0117] In a further possible implementation form of the third aspect, the information transmitted between the first node and the third node is encapsulated in a data packet, the data packet being in a format defined by the first communication protocol, the data packet being carried in a payload portion of a PDU, the PDU being in a format defined by the second communication protocol.
[0118] In a further possible implementation form of the third aspect, the payload portion of the PDU further comprises a packet type field, a value of the packet type field being used to indicate a type of the data packet carried in the payload portion of the PDU.
[0119] In a further possible implementation form of the third aspect, the receiving the second information and the second signature from the first node comprises receiving a certificate authentication request from the first node, the certificate authentication request comprising the second information and the second signature.
[0120] In a further possible implementation form of the third aspect, the sending the third information and the third signature to the first node comprises sending a certificate authentication response to the first node, the certificate authentication response comprising the third information and the third signature.
[0121] In a fourth aspect, the present application provides a communication apparatus, comprising units or modules for performing the method described in the first aspect or any possible implementation form of the first aspect.
[0122] And / or, the communication apparatus comprises units or modules for performing the method described in the second aspect or any possible implementation form of the second aspect.
[0123] And / or, the communication apparatus comprises units or modules for performing the method described in the third aspect or any possible implementation form of the third aspect.
[0124] Exemplarily, the communication apparatus comprises a processing unit and a communication unit. The processing unit is configured to implement one or more of the operations of negotiating, processing, determining, generating, calculating, encrypting, decrypting, etc. The communication unit is configured to implement one or more of the operations of sending, receiving, etc.
[0125] In a fifth aspect, the present application provides a node, comprising a processor and a memory, the memory being configured to store computer instructions, and the processor being configured to invoke the computer instructions stored in the memory to implement the method described in the first aspect or any possible implementation of the first aspect, and / or implement the method described in the second aspect or any possible implementation of the second aspect, and / or implement the method described in the third aspect or any possible implementation of the third aspect.
[0126] In a sixth aspect, the present application provides a chip, comprising a processor and an interface circuit, the interface circuit being configured to receive signals from other communication devices (including nodes) and transmit the signals to the processor or send signals from the processor to other communication devices (including nodes), and the processor being configured to implement the aforementioned communication method through a logic circuit or by executing code instructions.
[0127] Exemplarily, the processor is configured to implement the method described in the first aspect or any possible implementation of the first aspect, and / or implement the method described in the second aspect or any possible implementation of the second aspect, and / or implement the method described in the third aspect or any possible implementation of the third aspect.
[0128] In a seventh aspect, the present application provides a communication system, comprising a first node configured to implement the method described in the first aspect or any possible implementation of the first aspect, and a second node configured to implement the method described in the second aspect or any possible implementation of the second aspect.
[0129] In a possible implementation of the seventh aspect, the communication system further comprises a third node configured to implement the method described in the third aspect or any possible implementation of the third aspect. Optionally, the first node and the third node can be integrated in the same device.
[0130] In an eighth aspect, the present application provides a terminal, comprising the communication device described in the fourth aspect, or comprising the node described in the fifth aspect, or comprising the chip described in the sixth aspect, or comprising the communication system described in the seventh aspect. Optionally, the terminal can be a handheld terminal, a wearable device, a vehicle, a robot, a drone, or the like intelligent device or carrier.
[0131] In a ninth aspect, the present application provides a readable storage medium configured to store a computer program, when the computer program is executed by a processor, causing a communication device comprising the processor to implement the method described in the first aspect or any possible implementation of the first aspect, or implement the method described in the second aspect or any possible implementation of the second aspect, or implement the method described in the third aspect or any possible implementation of the third aspect.
[0132] In a tenth aspect, the present application provides a computer program product, which, when executed by a processor, causes a communication apparatus comprising the processor to implement the method described in the first aspect or any possible implementation of the first aspect, or implement the method described in the second aspect or any possible implementation of the second aspect, or implement the method described in the third aspect or any possible implementation of the third aspect.
[0133] The beneficial effects of the technical solutions in the second aspect to the tenth aspect of the present application can be referred to the beneficial effects of the technical solutions in the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0134] The drawings needed to be used in the following embodiment description will be briefly introduced.
[0135] FIG. 1 is a schematic diagram of an architecture of a communication system;
[0136] FIG. 2 is a schematic diagram of an architecture of another communication system;
[0137] FIG. 3 is a schematic diagram of an architecture of a network provided by an embodiment of the present application;
[0138] FIG. 4 is a schematic diagram of a flow of a communication method provided by an embodiment of the present application;
[0139] FIG. 5 is a schematic diagram of a flow of a security context negotiation;
[0140] FIG. 6 is a schematic diagram of a flow of another communication method provided by an embodiment of the present application;
[0141] FIG. 7 is a schematic diagram of a transmission unit of a second communication protocol compatible with a message of a first communication protocol provided by an embodiment of the present application;
[0142] FIG. 8 is a schematic diagram of a flow of another communication method provided by an embodiment of the present application;
[0143] FIG. 9 is a schematic diagram of a flow of another communication method provided by an embodiment of the present application;
[0144] FIG. 10 is a schematic diagram of a structure of a communication apparatus provided by an embodiment of the present application;
[0145] FIG. 11 is a schematic diagram of a structure of a communication device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0146] The following will introduce some technical terms.
[0147] 1. Node
[0148] A node is a device with communication capability, including but not limited to one or more of a user device, a network device, an industrial device, etc. Among them, the user device includes one or more of a handheld terminal, a wearable terminal, a vehicle, a vehicle-mounted device, a sensing device, a smart home device, or a leisure and entertainment device, etc., the handheld terminal includes but is not limited to a mobile phone, a tablet, or a notebook computer, etc., the wearable device includes but is not limited to a headset, a smart bracelet, a smart watch, or smart glasses, etc., the vehicle includes but is not limited to a vehicle, a ship, an aircraft, rail transit (such as a subway, a high-speed rail, etc.), or a logistics robot (such as an automated guided vehicle (AGV)), etc., the vehicle-mounted device includes but is not limited to a domain controller (DC), a screen, a microphone, a sound, an electronic key, a keyless entry, a start system controller, a battery management system (BMS), a battery pack, or a battery cell, etc., the sensing device includes but is not limited to a camera, a radar, a laser radar, an illumination sensor, a temperature sensor, or a humidity sensor, etc., the smart home device includes but is not limited to a projector, a smart TV, a smart refrigerator, a smart home gateway, or a security device, etc. The leisure and entertainment device includes but is not limited to a virtual reality (VR) device, a mixed reality (MR) device, a massage chair, a home theater, a game control device, or a 4D cinema cabin, etc. The network device includes but is not limited to a router, a switch, or a base station, etc. The industrial device includes but is not limited to an industrial robot, or a mechanical arm, etc.
[0149] The present application is applicable to various networks, and nodes will be used instead of devices in these networks in this document.
[0150] Exemplarily, the present application can be applied to a network formed by a wired communication network, a wireless communication network, or a combination of wired communication and wireless communication, etc. For example, the wireless communication network includes a network connected by a communication technology such as SparkLink (or NearLink), 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB) technology, or a wireless short-range communication system, etc. And / or, the wireless communication network includes a long-distance connection technology such as a wireless communication technology based on long term evolution (LTE), a 5th generation mobile network or 5th generation wireless system (5th-Generation, 5G or 5G technology), a global system for mobile communications (GSM), general packet radio service (GPRS), universal mobile telecommunications system (UMTS), etc. For another example, the wired communication network includes a network connected by one or more of a communication technology such as fiber connection technology, vehicle-mounted wired communication technology, controller area network (CAN), local interconnect network bus (LIN), CAN flexible data-rate (CAN FD), or vehicle-mounted Ethernet, etc.
[0151] The node in the embodiments of the present application can be applied to various scenarios such as intelligent vehicles, smart homes, intelligent terminals, intelligent manufacturing, intelligent showrooms, mobile internet (MI), industrial control, self-driving, transportation safety, or internet of things (IoT), etc.
[0152] It should be understood that in certain application scenarios or certain network types, similar communication-capable devices can not be referred to as nodes, but for the convenience of description, communication-capable devices are collectively referred to as nodes in embodiments of the present application.
[0153] 2. Certificate and signature mechanism
[0154] Certificate, also known as digital certificate, refers to digital authentication for identifying and authenticating the identity of each party in Internet communication. Certificates are usually issued by a certificate authority (CA) center. An applicant can generate a public-private key pair (including a private key and a public key), and provide the identity of the applicant and the public key in the public-private key pair to the CA center. The CA center issues a certificate to the applicant corresponding to the public key, and the certificate proves that the applicant listed in the certificate legally owns the public key listed in the certificate. The digital signature of the CA center makes it impossible for an attacker to forge and tamper with the certificate.
[0155] When the applicant sends information to a destination device, the private key is used to sign the sent information and provide the certificate issued by the CA center. The destination device can verify the signature of the certificate based on the public key of the CA center, and verify the signature of the information sent by the applicant using the public key in the certificate, thereby ensuring that the source of the information is indeed the applicant, and the identity of the applicant is trusted.
[0156] 3. Key agreement algorithm
[0157] Key agreement is a process in which both parties of communication agree on a key by interacting with a part of the parameter. The algorithm used for key agreement is also called a key agreement algorithm. Key agreement algorithms include Diffie-Hellman key exchange (DH) algorithm, DH based on Elliptic Curve Cryptosystems (ECC) (ECDH) algorithm, Two-Basis Password Exponential Key Exchange (TBPEKE) algorithm, national secret algorithm (such as SM2, etc.), Oakley algorithm, etc.
[0158] It should be noted that the key agreement algorithm can also be regarded as a kind of key agreement protocol, that is, for both parties of communication, the key agreement algorithm defines the rules of key generation.
[0159] 4. Key derivation function (KDF)
[0160] KDF, also known as key derivation algorithm, key derivation function and key derivation function, is used to derive (or called derive, derive) one or more secret values from a secret value. For example, the new secret value DK derived by the secret value Key can be expressed as: DK = KDF(Key). Of course, Key here is only an example, and other parameters can also be involved in the key derivation process in specific implementation.
[0161] The key derivation algorithm involved in the embodiments of the present application can include hash algorithm, password-based key derivation function (PBKDF), scrypt algorithm, etc. Illustratively, the hash algorithm includes hash-based message authentication code (HMAC) algorithm, cipher-based message authentication code algorithm (CMAC), etc. Among them, the specific hash algorithm used in HMAC can be one of the national cryptographic algorithm (such as SM3, etc.), SHA-256, SHA-1, etc. These different HMACs are usually marked as: HMAC-SM3, HMAC-SHA256, HMAC-SHA1, etc. CMAC can be combined with other cryptographic algorithms, for example, combined with advanced encryption standard (AES) to form AES-CMAC algorithm. And the PBKDF algorithm includes the first generation PBKDF1 and the second generation PBKDF2.
[0162] It should be understood that some KDF algorithms can perform hash changes on the input secret value through hash algorithms, so the KDF function can also receive an algorithm identifier as input to indicate which hash algorithm to use. It should be noted that KDF is not only applied to deriving secret values, but also applied to generating authentication information, identity information, etc.
[0163] 5. Security protection
[0164] Security protection includes one or more of confidentiality protection, integrity protection, authentication encryption, etc., wherein the confidentiality protection needs to use an encryption key, or an authentication encryption key. The integrity protection needs to use an integrity protection key or an authentication encryption key.
[0165] 6. Fresh parameter
[0166] The fresh parameter is applied in encryption, integrity protection, key derivation, key agreement and the like, and can also be referred to as a freshness parameter or freshness parameter. Generally, the specific value of the fresh parameter changes after being generated once, so that the fresh parameter determined this time is different from the value of the fresh parameter determined last time, thereby improving security.
[0167] Exemplarily, the fresh parameter can include a random number (such as NONCE), a counter value and the like.
[0168] The foregoing explanations of technical terms can be optionally used in the embodiments below.
[0169] The architecture of a communication system to which embodiments of the present application can be applied and service scenarios will be introduced below. It should be noted that the system architecture and service scenarios described herein are for the purpose of more clearly illustrating the technical solutions of the present application, and do not constitute a limitation on the technical solutions provided by the present application. It should be understood that as the system architecture evolves and new service scenarios appear, the technical solutions provided by the present application are equally applicable to similar technical problems.
[0170] The present application can be applied to a communication system, which is a system for transmitting information by using electrical signals (or optical signals). The communication system usually includes multiple nodes, and communication connections can be established between the nodes to transmit information. The nodes in the communication system can have different identities and / or different capabilities. The communication system can include wired communication systems and wireless communication systems. The wireless communication system includes short-range wireless communication systems, long-range wireless communication systems, and the like. The short-range communication system is, for example, a Bluetooth system, an 802.11b / g system, a Bluetooth system, and the like. The long-range wireless communication system is, for example, an LTE system, a 5G system, and the like.
[0171] The architecture of a communication system will be introduced below by taking a Bluetooth communication system as an example. The communication system shown in FIG. 1 includes a management node and a terminal node. Among them:
[0172] The management node has communication capability and management capability, and is also referred to as a G node, an access point, or an authorized node in some scenarios. The management capability includes communication management capability, such as connection management, resource scheduling, or information security management. Exemplarily, the management node can send resource management information or data scheduling information, such as access layer resource management information.
[0173] A terminal node, also referred to as a T-node in some scenarios, has communication capability and can perform traffic transmission with a management node. In some solutions, a terminal node is a node that receives resource management information (or data scheduling information) and transmits data according to the resource management information (or data scheduling information). Exemplarily, a terminal node can include a user equipment (UE), such as a device including a barcode, a radio frequency identification (RFID), a sensor, a global positioning system (GPS), a laser radar, a battery, and the like.
[0174] It should be understood that the identities of the management node and the terminal node are not absolute, and the identities shown herein are only exemplary naming made for the purpose of distinguishing the operations of the nodes in communication in one possible connection scenario. In some scenarios, a node belongs to two or more communication domains at the same time, and functions as a terminal node in some communication domains and as a management node in another communication domain. For the purpose of understanding, such a node is denoted as a G(T)-node in some embodiments.
[0175] In combination with FIG. 1, a terminal node and a management node can establish an association. The establishment of the association requires performing an association procedure. Before performing the association procedure, the management node can send a broadcast message, and the terminal node can perceive the management node based on the broadcast message. Further, the terminal node can request the association management node. After the terminal node and the management node complete the association procedure, an association relationship can be established.
[0176] It should be noted that in FIG. 1, an association relationship between the management node and the terminal node is represented by a dashed line, and in some solutions, a connection link includes two links, a management node direction communication link and a terminal node direction communication link. The management node direction communication link is a communication link in the direction from the management node to the terminal node, and can carry one or more of a data channel, control information, a broadcast channel, and a synchronization signal from the management node to the terminal node, and can be referred to as a G-link. The terminal node direction communication link is a communication link in the direction from the terminal node to the management node, and can carry one or more of a data channel, an access channel, or a feedback signal from the terminal node to the management node, and can be referred to as a T-link.
[0177] Optionally, communication between the management node and the terminal node includes unicast communication, groupcast communication, and / or broadcast communication. In some solutions, as shown in FIG. 1, a management node can connect one or more terminal nodes. In a star flash communication system, a management node supports connection to multiple terminal nodes, and a terminal node also supports association with multiple management nodes.
[0178] The present application supports a spark link / nearlink protocol, or the present application supports an IEEE protocol, such as an IEEE 802.11be / WiFi7 / EHT (extremely high throughput) protocol, an IEEE 802.11bn / WiFi 8 / UHR (ultra high reliability) protocol, an IEEE IMMW (Integrated mmWave) protocol, an IEEE 802.15.4ab / UWB (ultra wideband) protocol, such as an IEEE 802.11bf / Sensing protocol.
[0179] The communication system to which the present application is applied can be used in scenarios such as smart parks, smart homes, smart showrooms, smart factories, and smart buildings.
[0180] In order to improve the management and control of the nodes accessed by the network, the communication system usually further sets a third node, which is used to authenticate the nodes accessing the network. Please refer to FIG. 2, which is a schematic diagram of the architecture of another communication system, including a first node 10 (which can be regarded as a management node), a second node 20 (which can be regarded as a terminal node), and a third node 30.
[0181] Among them, the first node 10 can be associated with other nodes, while the second node 20 can request to associate with the first node 10, and the third node 30 can authenticate the second node 20, and further can authenticate the first node 10. It should be understood that the third node 30 here is used to refer to a functional module that can complete identity authentication. In the implementation process, the third node 30 can be an entity device or a virtual device. Illustratively, the third node can include an authentication device (or an authentication node), an authentication service, etc., wherein the authentication device is, for example, a Radius server, a portal server, an access controller (AC), etc., and the authentication service is, for example, a third-party Radius, an SMS server, etc.
[0182] It should be noted that the devices shown in FIG. 2 are only examples. In some schemes, the third node 30 can be integrated with the first node 10 in the same device, and of course the present application is also applicable to the case where the two are separately arranged. Similarly, the first node 10 and the second node 20 can also be integrated in the same device, and for the same reason, the present application is also applicable to the case where the two are separately arranged.
[0183] In some scenarios (e.g. in enterprise network), the first node can act as a network side node to provide network resource access service to the terminal node. Please refer to FIG. 3, which is a schematic diagram of an architecture of a network provided by an embodiment of the present application, including user terminals, access devices, controlled resources and authentication services, and optionally network facilities. The devices in the access device level can be regarded as first nodes (e.g. G nodes), the devices in the user terminal level can be regarded as second nodes (e.g. T nodes), and the authentication services (which can be regarded as third nodes) can include authentication servers and / or third-party authentication servers. Exemplarily, the user terminal level includes one or more of a guest, a customer, a dumb terminal, an ordinary enterprise user, a high-security enterprise user or a police wireless local area network (PWL) terminal user, etc., the devices in the access device level include one or more of an access point (AP), a radio unit (RU), a FAT AP or a mobile AP, etc., the controlled resources include one or more of an enterprise intranet, a third-party service or the Internet, etc., the authentication devices include one or more of a Radius server, a portal server or an AC, etc., the third-party authentication services include one or more of a third-party Radius, a short message server or a third-party service (i.e. authentication service), etc., and the devices in the network facility level include one or more of a convergence switch, a gateway firewall, an access switch or a core switch, etc. The access devices, the authentication services, the network facilities (optional) and the controlled resources can be connected through wired and / or wireless communication links. The wired communication link is, for example, an Ethernet, and the wireless communication link is, for example, a fourth generation communication system (4G) and / or a fifth generation communication system (5G), etc. The access devices and the user terminals can be connected through a wireless communication link, for example, based on a star flash communication protocol.
[0184] In the network architecture shown in FIG. 3, the devices in the access device level can provide access points for the devices in the user terminal level to access the network, so that the devices in the user terminal level access the controlled resources through the devices in the access device level. After the user terminals access the access devices, before accessing the controlled resources, in consideration of internal network security, the authentication services need to be introduced to authenticate the identity of the user terminals accessing the network, so as to avoid attackers impersonating legitimate devices to access the controlled resources. However, at present, the authentication services have security vulnerabilities in authenticating the user terminals.
[0185] Therefore, the application provides a communication method and related device. In the application, the third node can authenticate the second node and the first node, and the authentication is based on a digital certificate, which has high reliability and can significantly improve the security performance of the nodes and protect the security of the network. Further, the application supports bidirectional authentication of the three-node peer-to-peer architecture of the first node, the second node and the third node, and the first node, the second node and the third node all use certificates for bidirectional authentication, which can further improve the security performance of the nodes.
[0186] The method provided by the embodiments of the application is described below.
[0187] Please refer to FIG. 4, which is a flowchart of a communication method provided by an embodiment of the application. In order to facilitate understanding, the communication method is described by taking the first node, the second node and the third node as exemplary execution subjects. Optionally, the method can be applied to a communication system, such as the communication system shown in FIG. 1, FIG. 2 or FIG. 3. The communication method shown in FIG. 4 can include some or all of steps S401 to S410. It should be understood that, in order to facilitate description, the steps S401 to S410 are described in this order, and it is not intended to limit the execution in the above order. The embodiments of the application do not limit the execution order, execution time, execution times, etc. of one or more steps. The steps S401 to S410 are as follows:
[0188] Step S401: The second node sends first information and a first signature to the first node. Correspondingly, the first node receives the first information and the first signature from the second node.
[0189] The first information includes a certificate of the second node, which is used to authenticate the second node. As shown in FIG. 4, the content included in the information corresponding to the signature is described below the information. In some schemes, the certificate of the second node includes a public key of the second node, which forms a pair of public-private key pair with a private key of the second node, and is used for certificate and signature mechanism. Optionally, the certificate of the second node is issued by a CA, and further, the CA can be authenticated or the CA can cooperate with an authentication service to issue the certificate, for example, the second node has corresponding authority (such as the authority to access a specific resource), and the certificate is issued for the second node.
[0190] The first signature is a signature of the first information. For example, the second node generates the first signature based on the private key (which forms a pair of public-private key pair with the public key in the certificate) and the first information. The second node can verify the first information based on the public key in the certificate and the first signature, check the correctness of the first signature, and determine whether the first information is tampered.
[0191] In some possible implementation manners, the first information further comprises one or more of a public key of the second node, a first timestamp, a first freshness parameter, or a third freshness parameter. The following are introduced respectively.
[0192] (1) The public key of the second node is an exchange parameter for key agreement, and is a public key of a key agreement algorithm provided by the second node. The public key of the second node can be determined based on a private key of the second node. For example, in the DH algorithm, the second node generates a private key of the first node, and calculates a public key of the first node based on the private key of the first node using a key agreement algorithm. Another party of the key agreement, for example, the third node, also generates a private key and calculates a public key based on the private key using the same key agreement algorithm. The second node and the third node can exchange the public keys, and calculate a consistent agreement key by using the public key provided by the other party and the private key of the self through the key agreement algorithm.
[0193] The second node sends the public key of the second node to the first node, which can facilitate the second node to obtain a consistent agreement key through negotiation with the authentication server. Based on the agreement key, the second node and the authentication server (or other nodes trusted by the authentication server) can perform security protection and / or security verification on information, thereby further improving the security performance of the node.
[0194] Since the first information is signed information, the source can be verified and the integrity can be guaranteed based on the signature. The public key exchanged in the key agreement process is protected by the certificate and the signature mechanism, which can prevent the problem of man-in-the-middle attack in the key agreement process, further improve the security of the key agreement process, and improve the security performance of the node.
[0195] (2) The first timestamp is a timestamp determined by the second node, which usually indicates a specific time. The first timestamp can uniquely identify a time, has uniqueness, and can reduce the possibility of successful replay attack. Further, the first timestamp can be carried in the signed first information to avoid tampering, further improving the security performance of the first node and the second node.
[0196] In some schemes, the first timestamp is used to indicate a time related to the first information, for example, to indicate a time of generating the first information or a time of sending the first information. The time can be accurate to seconds, microseconds or milliseconds, and can be predefined or designed according to the situation.
[0197] (3) The first freshness parameter belongs to a freshness parameter, for example, a random number, a counter value or other parameters that can have freshness.
[0198] Optionally, the first freshness parameter is used to determine a first key, the first key is a key shared between the second node and the third node, and can be used for security protection or security verification. In one possible implementation, the first key is used to verify information negotiated in a security context negotiation process (to be described below).
[0199] (4) The third freshness parameter is a freshness parameter, such as a random number, a counter value, or other parameter that can have freshness.
[0200] The third freshness parameter is provided by the first node to the second node. Before step S401, the first node sends the third freshness parameter to the second node, and the second node receives the third freshness parameter and sends the third freshness parameter to the first node. The third freshness parameter is a freshness parameter that is sent to the second node and is used only by the second node. The third freshness parameter can indicate the uniqueness of the information carrying the third information parameter and / or mark the second node. If an attacker steals information sent by the second node to the first node and re-sends it to the first node, the first node can detect a replay attack because the third freshness parameter stolen by the attacker has already been received by the first node, and the first node can avoid an attack by the attacker using a replay attack, thereby improving the security performance of the nodes and the network.
[0201] The third freshness parameter is sent in the first information. On the one hand, the third freshness parameter can be prevented from being tampered with, and on the other hand, the first information can be prevented from being stolen for a replay attack, thereby improving the security of the nodes.
[0202] The above information can be partially or entirely carried in the first information. For combined cases, this will not be described one by one, and will be described below in combination with specific embodiments.
[0203] In some possible implementations, the first information and the first signature can be carried in one or a group of messages, which are referred to as message M1. Exemplarily, the message M1 can include a plurality of data fields, the first signature is carried in a field corresponding to the first signature, and the first information can be regarded as all data fields of the message M1 except the first signature. In some schemes, the message M1 is referred to as an access authentication request.
[0204] In some possible implementations, before step S401, the first node can send an authentication mode indication, which is used to indicate a mode of authenticating a node accessing the first node, which can be understood as a mode of authenticating the second node. Further, the authentication mode indication can be used to indicate that the authentication mode of the first node includes a certificate authentication mode. In some scenarios, the above authentication process is performed in an enterprise version network, for example, the authentication mode indication is used to indicate that the authentication mode is an enterprise version-certificate authentication mode.
[0205] Optionally, the authentication manner indication is carried in a unicast message, a groupcast message or a broadcast message. For example, the first node can periodically or aperiodically send a broadcast message, and the authentication manner indication is carried in the broadcast message. For another example, the first node can send the authentication manner indication to the second node in a message sent to the second node (e.g., a message in a security context negotiation procedure).
[0206] Taking the star flash communication system as an example, the first node can be a management node, and the second node can be a terminal node. The management node sends a broadcast message (e.g., a communication domain system message) in a broadcast manner, and the authentication manner indication is carried in the broadcast message. The terminal node receives the broadcast message, requests association with the management node, and performs an authentication procedure with the management node and an authentication node in the authentication manner indicated by the authentication manner indication.
[0207] In step S402, the first node authenticates the second node based on the certificate of the second node and the first signature.
[0208] Specifically, the first node verifies the certificate of the second node and verifies the first signature, thereby authenticating the second node. If the certificate of the second node is verified (e.g., the certificate is valid, the certificate is legal, etc.), the certificate of the second node is trusted. Otherwise, the certificate of the second node can be untrusted, and the authentication of the second node fails. Similarly, if the first signature is verified, the identity of the second node is trusted, and the authentication of the second node succeeds. Otherwise, the authentication of the second node fails.
[0209] In some possible solutions, the authentication of the second node succeeds if the certificate of the second node is verified and the first signature is verified. Otherwise, the authentication of the second node fails.
[0210] Optionally, if the authentication of the second node fails, the first node can not perform a subsequent procedure (e.g., step S403 and subsequent procedures), or disconnect with the second node, or discard information received from the second node, or delete a security context of the second node, etc. Further, if the authentication of the second node fails N times, the first node can add the second node to a blacklist to avoid being attacked by the second node. N can be predefined, preconfigured or calculated.
[0211] As an implementation of the certificate verification, the certificate of the second node can be issued by a certificate authority and has a signature of the certificate authority (the signature is signed based on a private key of the certificate authority). The first node can verify the signature in the certificate of the first node based on a public key of the certificate authority, thereby verifying the certificate of the second node.
[0212] As an implementation of the certificate verification, the certificate of the second node includes a public key, and the first signature is generated based on the private key of the second node and the first information. The first node can verify the first signature based on the public key in the certificate and the first information. If the first signature is verified, it indicates that the identity of the source of the first information (i.e., the second node) is trusted and the first information is not tampered with. It should be understood that the public key and the private key here are a public-private key pair in the certificate and signature system, and the public key and the private key in the key negotiation process belong to different mechanisms.
[0213] In some schemes, step S402 is an optional step (indicated by a dashed box in FIG. 4). At this time, the first node does not authenticate the identity of the second node, but the third node authenticates the first node and the first node.
[0214] Step S403: The first node sends the second information and the second signature to the third node.
[0215] Correspondingly, the third node receives the second information and the second signature from the first node.
[0216] The second information includes the first information, the first signature, and the certificate of the first node, wherein the first information includes the certificate of the second node, and optionally one or more of the public key of the second node, the first timestamp, the first freshness parameter, or the third freshness parameter.
[0217] The second signature is a signature of the second information, and the certificate of the first node, the certificate of the second node, the first signature, and the second signature are used for authentication.
[0218] It should be understood that the first information and the first signature are carried in the second information, which is convenient for the third node to verify the first signature and the certificate of the second node. In some schemes, the second node can also carry information D0 and signature S0 (the parameters are only examples) for the third node to verify in the first information. At this time, the second information can not carry the first information and the first signature, but can carry the information D0 and the signature S0 instead, which is used for the third node to authenticate the second node. For example, the information D0 can include one or more of the certificate of the second node, the public key of the second node, the second freshness parameter, or the first timestamp, and the signature S0 is a signature of the information D0.
[0219] In some possible implementations, the second information further includes one or more of the second freshness parameter, the indication information of the first KDF, the indication information of the first key negotiation algorithm, or the identity of the node. The following will be introduced respectively:
[0220] (1) The second freshness parameter belongs to a freshness parameter, such as a random number, a counter value, or other parameters that can have freshness.
[0221] Optionally, the second freshness parameter is used to determine a first key, the first key being a key shared between the second node and the third node, and being used for security protection or security verification. In one possible implementation, the first key is used to verify information negotiated in a security context negotiation procedure (to be described below).
[0222] Optionally, the second freshness parameter is the same as a third freshness parameter. That is, the second freshness parameter used by the first node to participate in the generation of the first key is also applied to a replay protection mechanism, so that the repeated calculation of the freshness parameter can be avoided, and the calculation amount of the first node can be reduced.
[0223] (2) The indication information of the first KDF algorithm is used to indicate the first KDF algorithm. The first KDF algorithm is used by the third node to derive a key, for example, to derive a key consistent with the second node.
[0224] Further, the first KDF is negotiated by the first node and the second node, for example, in a security context negotiation procedure. In this way, for the second node and the first node with different security capabilities, the first KDF negotiated by the second node and the first node can be different, so that the authentication process between the first node, the second node and the third node can adapt to the first node and the second node with different security capabilities, improving the compatibility of the network and the user experience.
[0225] (3) The indication information of the first key negotiation algorithm is used to indicate the first key negotiation algorithm. The first key negotiation algorithm is used by the third node to negotiate a key, for example, to negotiate a negotiation key with the second node.
[0226] Further, the first key negotiation algorithm is negotiated by the first node and the second node, for example, in a security context negotiation procedure. In this way, for the second node and the first node with different security capabilities, the first key negotiation algorithm negotiated by the second node and the first node can be different, so that the authentication process between the first node, the second node and the third node can adapt to the first node and the second node with different security capabilities, improving the compatibility of the network and the user experience.
[0227] (4) The identity of the node includes the identity of the first node and / or the identity of the second node. The identity of the node is used to indicate the node, for example, the identity of the node in the communication network, the device identity of the node, and the like. The identity of the node in the communication network, for example, the ID of a certain communication protocol layer, the media access control (MAC) address of the node, the network access permit number of the node, and the like. The device identity of the node is used to uniquely identify the device of the node itself, for example, the production serial number of the node, the device model, and the like. Optionally, the identity of the node can be fixed, or random.
[0228] As a possible implementation, the node identity is used to distinguish the node in the network, such as the identity of the first node is the ID of the first communication protocol layer of the first node.
[0229] Exemplarily, the communication protocol stack between the first node and the second node includes a plurality of protocol layers, which can be referred to as layer 1, layer 2, layer 3, etc., and the identity of the first node can be the Layer 2 ID (L2ID) of the second node.
[0230] Exemplarily, taking the starlink communication protocol between the first node and the second node as an example, the protocol stack architecture of starlink is as follows from top to bottom: application layer, network and transport layer, data link layer (including link control layer and medium access layer) and physical layer. Among them, the physical layer is layer 1, the data link layer is layer 2 (i.e. L2), and the data link layer can include two sub-layers, and the rest of the layers are similar. The identity of the first node here can be the data link layer ID of the first node. Alternatively, the identity of the first node is the physical layer identity phy-ID of the first node.
[0231] Similar to the identity of the first node, the identity of the second node is used to indicate the second node, such as the L2ID of the second node, the phy-ID of the second node, etc., and the related design can refer to the possible design of the identity of the first node.
[0232] The above information can be partially or entirely carried in the second information, and for the combined case, it will not be described one by one here, and will be introduced in combination with the specific embodiments below.
[0233] In some possible embodiments, the second information and the second signature can be carried in a message or a group of messages for transmission, which is referred to as message M2. Exemplarily, the message M2 can include a plurality of data fields, the second signature is carried in the field corresponding to the second signature, and the second information can be regarded as all data fields of the message M2 except the second signature. In some schemes, the message M2 is referred to as a certificate authentication request.
[0234] Optionally, in the case where the first information and the first signature are carried in the message M1, the message M2 can carry the message M1, so that the message M2 includes the first information and the first signature.
[0235] Step S404: The third node authenticates the second node based on the certificate of the second node and the first signature.
[0236] Specifically, the third node verifies the certificate of the second node, verifies the signature of the information (such as the first signature) of the second node, and thereby authenticates the second node.
[0237] Exemplarily, if the certificate of the second node is verified, e.g. the certificate is valid, the certificate is legal, etc., the certificate of the second node is trusted. Otherwise, the certificate of the second node can be untrusted, and the authentication of the second node fails. Exemplarily, taking the verified signature as the first signature, if the first signature is verified, the identity of the second node is trusted, and the authentication of the second node passes. Otherwise, the authentication of the second node fails. Alternatively, the first signature can be replaced by a signature of the second node on other information, e.g. the signature S0 on the information D0.
[0238] In some possible solutions, the certificate of the second node is verified, and the first signature is verified, and the authentication of the second node passes. Otherwise, the authentication of the second node fails.
[0239] As an implementation of the certificate verification, the certificate of the second node can be issued by a certificate authority, and has a signature of the certificate authority (the signature is signed based on a private key of the certificate authority). The third node can verify the signature in the certificate of the first node based on a public key of the certificate authority, so as to verify the certificate of the second node.
[0240] As an implementation of the certificate verification, the certificate of the second node includes a public key, and the first signature is generated based on a private key of the second node and the first information. The third node can verify the first signature based on the public key in the certificate and the first information. If the first signature is verified, it indicates that the identity of the source (i.e. the second node) of the first information is trusted and the first information is not tampered. It should be understood that the public key and the private key herein are a public-private key pair in the certificate and signature system, and the public key and the private key in the key negotiation process belong to different mechanisms.
[0241] In some possible implementations, the third node authenticates the second node based on the certificate of the second node and the signature of the second node, and obtains an authentication result of the second node.
[0242] Exemplarily, the authentication result of the third node on the second node includes one or more of a verification result of the first signature, or a verification result of the certificate of the second node, etc. For example, the verification result of the first signature can include a verification pass or a verification fail. For another example, the verification result of the certificate of the second node includes whether the certificate is verified, and when the certificate is not verified, the verification result of the certificate of the second node can optionally further include a failure reason, e.g. one or more of indicating that the certificate is expired, the certificate is revoked, or the certificate is illegal. In the above implementations, by carrying the authentication result in the third information, the success or failure (optionally further including the failure reason) of the identity verification can be fed back, so as to facilitate the first node to trigger a corresponding security operation based on the authentication result, form an authentication closed-loop management, and improve network security.
[0243] Optionally, in case the second node is not authenticated, the third node can not perform the subsequent procedure (e.g., step S405 and the subsequent procedure), or instruct the first node to disconnect with the second node, or instruct the first node to discard the information received from the second node. Further, in case the M times of authentication are not passed, the third node can add the second node to a blacklist to avoid being attacked by the second node, where M can be predefined, preconfigured or calculated.
[0244] Step S405: The third node authenticates the first node based on the certificate of the first node and the second signature.
[0245] Specifically, the third node verifies the certificate of the first node, and verifies the second signature, thereby authenticating the first node. For example, if the certificate of the first node is verified, e.g., the certificate is valid, the certificate is legal, etc., the certificate of the first node is trusted. Otherwise, the certificate of the first node can not be trusted, and the first node is not authenticated. For another example, taking the verified signature as the second signature, if the second signature is verified, the identity of the first node is trusted, and the authentication is passed. Otherwise, the first node is not authenticated.
[0246] In some possible solutions, the certificate of the first node is verified, and the second signature is verified, and the first node is authenticated. Otherwise, the authentication of the first node is not passed.
[0247] As an implementation of the certificate verification, the certificate of the first node can be issued by a certificate authority, and has a signature of the certificate authority (the signature is signed based on a private key of the certificate authority). The third node can verify the signature in the certificate of the first node based on a public key of the certificate authority, thereby verifying the certificate of the first node.
[0248] As an implementation of the certificate verification, the certificate of the first node includes a public key, and the second signature is generated based on a private key of the first node and the second information. The third node can verify the second signature based on the public key in the certificate and the first information. If the second signature is verified, it indicates that the identity of the source (i.e., the first node) of the second information is trusted and the second information is not tampered.
[0249] In some possible implementations, the third node authenticates the first node based on the certificate of the first node and the signature of the first node, and obtains an authentication result of the first node.
[0250] Exemplarily, the authentication result of the first node by the third node comprises one or more of a verification result of the second signature, or a verification result of the certificate of the first node, etc. For example, the verification result of the second signature can comprise a verification pass or a verification fail. For another example, the verification result of the certificate of the first node comprises whether the certificate verification passes, and when the verification fails, the verification result of the certificate of the first node can optionally further comprise a failure cause, for example, indicating one or more of that the certificate is expired, the certificate is revoked, or the certificate is illegal, etc.
[0251] Optionally, when the authentication of the first node fails, the third node can not perform the subsequent process (such as step S405 and the subsequent process), or disconnect with the first node, or discard the information received from the first node. Further, when the authentication fails K times, the third node can add the first node to a blacklist to avoid being attacked by the first node, and K can be predefined, pre-set or calculated.
[0252] In some possible implementation, when the first information (or the second information) comprises the public key of the second node, the public key here refers to a public key used for key agreement, and the third node can determine the agreement key based on the public key of the second node. Specifically, the third node generates a private key of the third node, and determines the agreement key based on the private key of the third node and the public key of the second node by using a first key agreement algorithm. In this way, the third node and the second node can perform security protection and / or information verification based on the agreement key. Of course, the agreement key can directly participate in the security protection and / or the information verification, or the agreement key can derive a key, and the derived key can participate in the security protection and / or the information verification.
[0253] Exemplarily, the public key of the second node can be denoted as Pubt, and the private key of the third node can be denoted as PriAC. The third node can generate an agreement key based on PriAC and Pubt by using a first key agreement algorithm, and the agreement key is denoted as DH key for example.
[0254] In some possible implementation, the third node can derive a first key based on the agreement key, and the first key is used to exemplarily illustrate a derived key. In some scenarios, the first key is a shared key between the second node and the third node, which can be regarded as an authentication key. Some possible implementations of deriving the first key are introduced as follows:
[0255] Implementation one: the third node generates an intermediate key based on the agreement key, and generates the first key based on the intermediate key. Optionally, in the process of generating the intermediate key and the first key, a fresh parameter or other parameter participates.
[0256] As a possible design, the third node generates an intermediate key based on the negotiation key and the first input parameter, and generates the first key based on the intermediate key and the second input parameter. An exemplary calculation manner is as follows: MK=KDF(DH key, P1), RK=KDF(MK, P2). Wherein, KDF can be the KDF indicated by the indication information of the first KDF, MK is used to represent the intermediate key, P1 is used to represent the first input parameter, P2 is used to represent the second input parameter, and RK represents the first key.
[0257] Optionally, the first input parameter comprises one or more of a first freshness parameter, a second freshness parameter, a third freshness parameter, a first timestamp, or a freshness parameter determined by the third node, or can further comprise other parameters not listed. The second input parameter comprises one or more of an identity of the first node, an identity of the second node, a first timestamp, or the like, or can further comprise other parameters not listed. Optionally, if the first input parameter and the second input parameter comprise a parameter determined by the third node, the third node can provide the parameter determined by the third node to the second node, so as to facilitate the second node to generate a consistent first key. For example, if the first input parameter (or the second freshness parameter) comprises a parameter rand1 determined by the third node, the third node can send rand1 to the second node, of course, the sending process of rand1 can be forwarded through the first node.
[0258] As a possible design, the third node determines an intermediate key based on the negotiation key, the first freshness parameter, and the second freshness parameter, and determines the first key based on the intermediate key, the identity of the first node, and the identity of the second node.
[0259] Exemplarily, the calculation manner of the intermediate key MK is as follows: MK=KDF(DH key, Nt, Ng), wherein Nt is used to represent the first freshness parameter, and Ng is used to represent the second freshness parameter, and other representations are as described above. The calculation manner of the key RK is as follows: RK=KDF(MK, L2ID of the first node, L2ID of the second node), wherein the L2ID of the first node belongs to the identity of the first node, and the L2ID of the first node belongs to the identity of the second node.
[0260] It should be noted that the derivation process of the first key is expressed in the form of multiple steps above. However, in the specific implementation process, the multiple steps described above can not actually exist, for example, the first key is directly obtained through a corresponding calculation manner, and the multiple steps described above are only an intermediate process of calculation. For example, the calculation manner of the first key is as follows: RK=KDF{KDF[DH(PriAC, Pubt), Nt, Ng], L2ID of the first node, L2ID of the second node}, wherein DH(PriAC, Pubt) is used to obtain DHkey.
[0261] In a second implementation, the third node generates the first key based on the negotiated key and the first KDF. For example, the key RK (which can be regarded as the first key) is calculated as follows: RK = KDF (DH key, fresh parameter). The fresh parameter can be one or more of the first fresh parameter, the second fresh parameter, or a fresh parameter determined by the third node. Optionally, if the fresh parameter is a fresh parameter determined by the third node, the third node can provide the fresh parameter to the second node.
[0262] In some possible implementation, the first key is used to verify the information transmitted in the security context negotiation process (the specific verification process is described below). The security context negotiation process is a process between the first node and the second node. By verifying the security context negotiation process between the first node and the second node by the first key, the information security of the first node and the second node can be ensured, and the communication security of the first node can be improved.
[0263] Step S406: The third node sends the third information and the third signature to the first node.
[0264] Correspondingly, the first node receives the third information and the third signature from the third node.
[0265] The third information includes the certificate of the third node. The third signature is a signature of the third information.
[0266] In some possible implementation, the third information further includes one or more of the second information, the second signature, the authentication result, the second fresh parameter, the public key of the third node, etc. The second information and the second signature are described above. The authentication result includes the authentication result of the second node and / or the authentication result of the third node, which can be referred to the foregoing description. The public key of the third node is a parameter corresponding to the private key of the third node, which is the key agreement public key provided by the third node in the key agreement process, and is used by the first node to determine the negotiated key.
[0267] Optionally, when the parameter determined by the third node is input in the process of determining the first key, the parameter determined by the third node can be carried in the third information and sent to the second node.
[0268] In some possible implementation, the third information and the third signature can be carried in one message or one group of messages and sent, which is referred to as message M3. For example, the message M3 can include a plurality of data fields, the third signature is carried in the field corresponding to the third signature, and the third information can be regarded as all data fields of the message M3 except the third signature. In some schemes, the message M3 is referred to as a certificate authentication response.
[0269] Optionally, in case the second information and the second signature are carried in the message M2, the message M3 can carry the message M2, so that the second information and the second signature are included in the message M3.
[0270] In some solutions, the step S406 is an optional step (indicated by dashed line in FIG. 4). In this case, the third node can not send the certificate and the signature of the third node to the first node, for example, the third information only carries one or more of the second information, the second signature, the authentication result, the second fresh parameter, the public key of the third node, etc.
[0271] Step S407: The first node authenticates the third node based on the certificate and the third signature of the third node.
[0272] Specifically, the first node verifies the certificate of the third node, and verifies the signature (e.g., the third signature) of the third node on the information, so as to authenticate the third node.
[0273] For example, if the certificate of the third node is verified, e.g., the certificate is valid, the certificate is legal, etc., the certificate of the third node is trusted. Otherwise, the certificate of the third node can not be trusted, and the authentication of the third node fails. For another example, if the third signature is verified, the identity of the third node is trusted, and the authentication of the third node succeeds. Otherwise, the authentication of the third node fails.
[0274] In some possible solutions, the certificate of the third node is verified and the third signature is verified, and the authentication of the third node succeeds. Either the certificate or the signature fails to be verified, and the authentication of the third node fails.
[0275] As an implementation of the certificate verification, the certificate of the third node can be issued by a certificate authority, and has a signature of the certificate authority (the signature is signed based on a private key of the certificate authority). The first node can verify the signature in the certificate of the third node based on a public key of the certificate authority, so as to verify the certificate of the third node.
[0276] As an implementation of the certificate verification, the certificate of the third node includes a public key, and the third signature is generated based on a private key of the third node and the third information. The first node can verify the first signature based on the public key in the certificate and the third information. If the first signature is verified, it indicates that the identity of the source (i.e., the third node) of the third information is trusted and the third information is not tampered. It should be understood that the public key and the private key herein are a pair of public and private keys in the certificate and signature system, and the public key and the private key in the key agreement process belong to different mechanisms.
[0277] In some possible implementation, the first node authenticates the third node based on the certificate and the third signature of the third node, and obtains an authentication result of the third node. For example, the authentication result of the third node includes one or more of a verification result of the third signature, a verification result of the certificate of the third node, etc.
[0278] Optionally, when the third node fails to pass the authentication, the first node can not perform the subsequent process (e.g., step S409 and the subsequent process), or disconnect with the third node, or discard the information received from the third node. Further, when the third node fails to pass the authentication for L times, the first node can add the third node to a blacklist to avoid being attacked by the third node, where L can be predefined, preconfigured or calculated.
[0279] In some solutions, step S407 is an optional step (indicated by a dashed box in FIG. 4). In this case, the first node does not perform identity authentication on the third node.
[0280] Step S408: The first node sends fourth information and a fourth signature to the second node.
[0281] Correspondingly, the second node receives the fourth information and the fourth signature from the first node.
[0282] The fourth information includes the third information, the third signature and the certificate of the first node, and the fourth signature is a signature of the third information.
[0283] Optionally, the fourth information further includes a second freshness parameter, or the second freshness parameter can also be included in the third information, so that the fourth information carries the second freshness parameter.
[0284] In some possible implementation, the fourth information and the fourth signature can be carried in one or a group of messages, which are referred to as message M4. For example, the message M4 can include a plurality of data fields, the fourth signature is carried in a field corresponding to the fourth signature, and the fourth information can be regarded as all data fields of the message M4 except the third signature. In some solutions, the message M4 is referred to as an access authentication response.
[0285] Optionally, when the third information and the third signature are carried in the message M3, the message M4 can carry the message M3, so that the third information and the third signature are included in the message M4.
[0286] In some solutions, step S406 is an optional step (indicated by a dashed line in FIG. 4). In this case, the third node can not send the certificate and the signature of the third node to the first node, for example, the third information only carries one or more of the second information, the second signature, the authentication result, the second freshness parameter, the public key of the third node, etc.
[0287] In some solutions, step S408 is an optional step (indicated by a dashed line in FIG. 4). In this case, the first node can not send the certificate and the third signature of the third node to the second node, or can not send the certificate and the fourth signature of the second node. For example, the fourth information only carries one or more of the third information, the third signature, the authentication result, the second fresh parameter, the public key of the third node, etc.
[0288] Step S409: The second node authenticates the third node based on the certificate and the third signature of the third node.
[0289] Specifically, the second node verifies the certificate of the third node, verifies the signature (e.g., the third signature) of the information by the third node, and thus authenticates the third node.
[0290] For example, if the certificate of the third node is verified, e.g., the certificate is valid, the certificate is legal, etc., the certificate of the third node is trusted. Otherwise, the certificate of the third node can not be trusted, and the authentication of the third node fails. For another example, if the third signature is verified, the identity of the third node is trusted, and the authentication passes. Otherwise, the authentication of the third node fails.
[0291] In some possible solutions, the certificate of the third node is verified and the third signature is verified, and thus the authentication of the third node passes. If either the certificate or the signature fails to be verified, the authentication of the third node fails.
[0292] For details, refer to the related description of the authentication of the third node by the first node in step S407.
[0293] In some solutions, step S409 is an optional step (indicated by a dashed line in FIG. 4). In this case, the second node does not perform identity authentication on the third node.
[0294] Step S410: The second node authenticates the first node based on the certificate and the fourth signature of the first node.
[0295] Specifically, the second node verifies the certificate of the first node, verifies the second signature, and thus authenticates the first node. For example, if the certificate of the first node is verified, e.g., the certificate is valid, the certificate is legal, etc., the certificate of the first node is trusted. Otherwise, the certificate of the first node can not be trusted, and the authentication of the first node fails. For another example, taking the verified signature as the second signature, if the second signature is verified, the identity of the first node is trusted, and the authentication passes. Otherwise, the authentication of the first node fails.
[0296] In some possible solutions, the certificate of the first node is verified and the second signature is verified, and thus the authentication of the first node passes. If either the certificate or the signature fails to be verified, the authentication of the first node fails.
[0297] The detailed description can refer to the related description of the third node authenticating the first node in step S405.
[0298] In some schemes, step S410 is an optional step (indicated by a dashed box in FIG. 4). At this time, the second node does not authenticate the identity of the first node.
[0299] In some possible implementations, when the fourth information (or the third information) includes the public key of the third node, the public key here refers to a public key used for key agreement, and the second node can determine the agreement key based on the public key of the third node. Specifically, the second node determines the agreement key based on the private key of the second node and the public key of the third node using the first key agreement algorithm. In this way, the third node and the second node can perform security protection and / or information verification based on the agreement key. Of course, the agreement key can directly participate in security protection and / or information verification, or the agreement key can derive (or derive) a key, and the derived key can participate in security protection and / or information verification.
[0300] For example, the public key of the third node can be represented as PubAC, and the private key of the second node can be represented as Prit. The second node can generate an agreement key based on Prit and PubAC using the first key agreement algorithm, for example, represented as DH key.
[0301] In some possible implementations, the second node can derive a first key based on the agreement key, and the first key is used to exemplarily illustrate a derived key. Some possible implementations of deriving the first key are introduced as follows:
[0302] Implementation one: the second node generates an intermediate key based on the agreement key, and generates the first key based on the intermediate key. Optionally, a fresh parameter or other parameter participates in the generation of the intermediate key and the first key.
[0303] As a possible design, the second node generates an intermediate key based on the agreement key and a first input parameter, and generates the first key based on the intermediate key and a second input parameter. An exemplary calculation method is as follows: MK = KDF (DH key, P1), RK = KDF (MK, P2). Wherein, KDF can be the KDF indicated by the indication information of the first KDF, MK is used to represent the intermediate key, P1 is used to represent the first input parameter, P2 is used to identify the second input parameter, and RK represents the first key.
[0304] Optionally, the first input parameter comprises one or more of the first freshness parameter, the second freshness parameter, the third freshness parameter, the first timestamp, or a freshness parameter determined by the third node, or possibly other parameters not listed. The second input parameter comprises one or more of the identity of the first node, the identity of the second node, the first timestamp, or possibly other parameters not listed. Optionally, if the first input parameter and the second input parameter comprise a parameter determined by the third node, the third node can provide the parameter determined by the third node to the second node to facilitate the second node to generate a consistent first key. For example, if the first input parameter (or the second freshness parameter) comprises a parameter rand1 determined by the third node, the third node can send rand1 to the second node, of course, the sending of rand1 can be forwarded through the first node.
[0305] As one possible design, the third node determines an intermediate key based on the negotiated key, the first freshness parameter, and the second freshness parameter, and determines the first key based on the intermediate key, the identity of the first node, and the identity of the second node.
[0306] For example, the intermediate key MK is calculated as follows: MK = KDF(DH key, Nt, Ng), where Nt is used to represent the first freshness parameter, and Ng is used to represent the second freshness parameter, and other representations are as described above. The key RK is calculated as follows: RK = KDF(MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node belongs to the identity of the first node, and the L2ID of the second node belongs to the identity of the second node.
[0307] It should be noted that the derivation of the first key is expressed in the form of multiple steps above. However, in the actual implementation process, the multiple steps described above can not actually exist, for example, the first key is directly obtained through a corresponding calculation manner, and the multiple steps described above are only an intermediate process of calculation. For example, the first key RK is calculated as follows: RK = KDF{KDF[DH(PriAC, Pubt), Nt, Ng], L2ID of the first node, L2ID of the second node}, where DH(PriAC, Pubt) is used to obtain the DH key.
[0308] In the second implementation manner, the second node generates the first key based on the negotiated key and the first KDF. For example, the key RK (which can be regarded as the first key) is calculated as follows: RK = KDF(DH key, freshness parameter). The freshness parameter can be one or more of the first freshness parameter, the second freshness parameter, or a freshness parameter determined by the third node. Optionally, if the freshness parameter is a freshness parameter determined by the third node, the third node can provide the freshness parameter to the second node.
[0309] In some possible implementation, the first key is used to verify information transmitted in the security context negotiation process (the specific verification process will be described below). The security context negotiation process is a process between the first node and the second node. By verifying the security context negotiation process between the first node and the second node by the first key, the information security of the first node and the second node can be ensured, and the communication security of the first node can be improved.
[0310] In some possible implementation, after sending the fourth information and the fourth signature to the second node, the second node can send a first message, or message M8, to the first node. Accordingly, the first node receives the first message from the second node. The first message is used to indicate that the access authentication is completed, for example, access authentication completion or access authentication completion message.
[0311] In some possible implementation, after sending the fourth information and the fourth signature to the second node (for example, after receiving the first message from the second node), the first node further sends a second message, or message M9, to the third node. Accordingly, the third node receives the second message from the first node. The second message is used to indicate that the certificate authentication is completed, for example, certificate authentication completion (message).
[0312] In the embodiment shown in FIG. 4, the first node obtains the first information and the first signature, and sends the first information, the first signature, the second information and the second signature to the third node. The third node can authenticate the identities of the first node and the second node based on the first information, the first signature, the second information and the second signature. In this way, the third node authenticates the identities of the first node and the second node based on the digital certificate, which can ensure that the identities of the first node and the second node are both trusted, reduce the possibility of an attacker accessing the network, reduce the possibility of a node being associated with a fake access point, and ensure that the identities of the second node and the first node in the network are both trusted. Moreover, the authentication process is based on the digital certificate and the signature mechanism, and has high reliability. In summary, the application can significantly improve the security performance of the node and protect the security of the network.
[0313] Further, each of the first node, the second node and the third node authenticates the identities of the other two nodes using the certificates and the signatures of the other two nodes, implements a two-way authentication mechanism of a ternary peer-to-peer architecture, and significantly improves the communication security performance of the node.
[0314] The foregoing describes the flow of the method provided by the application, and some possible designs that can be combined with the foregoing embodiments are described below.
[0315] In the foregoing embodiments, the security context negotiation process is mentioned. The security context is described exemplarily in combination with FIG. 5.
[0316] The security context negotiation procedure is a procedure between the first node and the second node. In some solutions, the security context negotiation procedure is used to negotiate the security context of the first node and the second node. The security context includes, but is not limited to, one or more of a security key, such as one or more of a shared key, a master key, an encryption key, an integrity protection key, an authenticated encryption key, an identity authentication key, an identification (ID) encryption key, a security algorithm, including one or more of a key agreement algorithm, a key derivation function (KDF), an authenticated encryption algorithm, an encryption algorithm, an integrity protection algorithm, an information digest algorithm, and a security parameter, such as one or more of a freshness parameter, an ID of the node, information used for encryption, timestamp information, a validity period of a key, and the like.
[0317] In one possible design, as shown in FIG. 5, the security context negotiation procedure includes that the second node sends a message T1 (or a first message, the notations of the parameters shown herein are merely examples) to the first node, where the message T1 carries the security capability of the second node. Accordingly, the first node receives the message T1 from the second node, and determines the first KDF based on at least the security capability of the second node. For example, if the second node only supports one KDF, the first KDF is the KDF. If the second node supports one or more KDFs, the first node selects the first KDF with the highest priority based on an algorithm preference policy and / or a type of service, and the like.
[0318] Further, the first node can send a second message T2 (or a second message) to the second node, where the second message T2 carries indication information of the first KDF. Accordingly, the second node receives the second message T2, and obtains the indication information of the first KDF, i.e., determines the first KDF. In this way, the first node and the second node negotiate the first KDF through the security context negotiation.
[0319] It should be understood that the names of the messages and the notations of the messages herein are merely examples, and the names of the messages, the information, the nodes, and the algorithms can be replaced in implementation. For example, the message T1 can be referred to as an association request message, which is used to request association of the first node, e.g., including information of the second node, such as an ID, a security capability, and the like. The message T2 can be referred to as a security context request message.
[0320] In some possible implementation, the security context negotiation procedure further comprises one or more of the following messages, for example, message T3 (or referred to as third message, security context request message), message T4 (or referred to as fourth message, security context request message), message T5 (or referred to as association establishment message, association completion message), etc.
[0321] In some possible implementation, before the security context negotiation procedure, the first node can send the key negotiation algorithm capability of the first node (which can be optionally included in the security capability). The second node can receive the key negotiation algorithm capability of the first node, and select the first key negotiation algorithm, and optionally, the indication information of the first key negotiation algorithm can be included in the message T1. For example, the key negotiation algorithm capability of the first node can be sent in a broadcast message, a groupcast message or a unicast message.
[0322] Optionally, the authentication mode indication can be sent in a broadcast message, or sent in the message T2, the message T4, etc.
[0323] In some possible design, the first key is used to verify the information transmitted between the first node and the second node. For example, used to verify one or more information transmitted in the broadcast message, the security context negotiation procedure, etc.
[0324] In combination with FIG. 6, FIG. 6 is a flow diagram of another communication method provided in the present application. The security context negotiation procedure can refer to the method procedure shown in FIG. 4, and the authentication procedure can refer to the method procedure shown in FIG. 4. The method shown in FIG. 6 further comprises steps S61 to S67, which are as follows.
[0325] In step S61, the third node sends a message M5 to the first node. Accordingly, the first node receives the message M5 from the third node.
[0326] The message M5 comprises the first key, and the determination process of the first key can refer to the related description in the embodiment shown in FIG. 4. Optionally, the message M5 can be referred to as key distribution (message).
[0327] In step S62, the first node generates a first verification parameter based on the first to-be-verified information and the first key.
[0328] The first to-be-verified information includes the second key and information transmitted by the first node and the second node. For example, the first to-be-verified information includes one or more of the following information: the first key, the fourth freshness parameter, the content of the message T1, or the content of the message T3, and the like. Understandably, the first to-be-verified information used by the first node includes information received by the first node, or information exchanged between the first node and the second node. Alternatively, the fourth freshness parameter is determined by the first node, and the first node sends the fourth freshness parameter to the second node in the security context negotiation process, for example, in the message T2.
[0329] Further, the generation of the first check parameter also needs to use the KDF, which can be replaced by a hash algorithm. For example, the first check parameter can be represented as HASHg. An example of the calculation method of HASHg is as follows:
[0330] HASHg = KDF(RK, NONCEg, message T1 content, message T3 content), wherein KDF is used to indicate the KDF algorithm used, and the inputs of the KDF include RK, NONCEg, message T1 content, and message T3 content, which have the following meanings: RK is the first key, and NONCEg is the fourth freshness parameter. It should be understood that the order between the inputs of the KDF and the number of parameters here are only examples, and in the specific implementation process, the number of information items included in the first to-be-verified information can be more or less, and the order of the inputs can also be designed in other ways.
[0331] In step S63, the first node sends the message M6 to the second node. Correspondingly, the second node receives the message M6.
[0332] The message M6 includes the first check parameter. In some schemes, the message M5 can be referred to as a session key confirmation request.
[0333] In step S64, the second node verifies the first check parameter.
[0334] That is, the second node performs information verification based on the first check parameter and the first to-be-verified information. For example, the second node generates a first check code based on the first to-be-verified information (including the second key and information transmitted by the first node and the second node) obtained by itself, and compares the first check code with the first check parameter to determine whether the value of the first to-be-verified information on the first node side is the same as the value of the first to-be-verified information on the second node side, so as to verify whether the first to-be-verified information is tampered with.
[0335] In step S65, the second node generates a second check parameter based on the second to-be-verified information and the first key.
[0336] The second to-be-verified information includes the first key and information transmitted by the first node and the second node. For example, the second to-be-verified information includes one or more of the following: the first key, the key agreement algorithm capability of the first node, the authentication mode indication, the fifth freshness parameter, the content of the message T2, or the content of the message T4, and the like. Understandably, the second to-be-verified information used by the second node includes information received by the second node. Alternatively, the fifth freshness parameter is determined by the second node, and the second node sends the fifth freshness parameter to the first node in the security context negotiation process, for example, in the message T1.
[0337] Further, the generation of the second verification parameter also needs to use the KDF, which can be replaced by a hash algorithm. For example, the second verification parameter can be represented as HASHt. An example of the calculation of HASHt is as follows:
[0338] HASHt = KDF(RK, the key agreement algorithm capability of the first node, the authentication mode indication, NONCEt, the content of the message T2, and the content of the message T4), wherein KDF is used to indicate the KDF algorithm used, and the inputs of the KDF include RK, the key agreement algorithm capability of the first node, the authentication mode indication, NONCEt, the content of the message T2, and the content of the message T4. The specific information is as follows: RK is the first key, the key agreement algorithm capability of the first node can be optionally carried in the broadcast message, the authentication mode indication can be optionally carried in the broadcast message, and NONCEt is the fifth freshness parameter. It should be understood that the order between the inputs of the KDF and the number of parameters are only examples, and in the specific implementation process, the number of information items included in the second to-be-verified information can be more or less, and the order of the inputs can also be designed in other ways.
[0339] In step S66, the second node sends the message M7 to the first node. Correspondingly, the first node receives the message M7.
[0340] The message M7 includes the second verification parameter. In some schemes, the message M5 can be referred to as a session key confirmation response.
[0341] In step S67, the first node verifies the second verification parameter.
[0342] That is, the first node performs information verification based on the second verification parameter and the second to-be-verified information. For example, the second node generates a second check code based on the second to-be-verified information (including the second key and the information transmitted between the first node and the second node) obtained by itself, and compares the second check code with the second verification parameter to determine whether the value of the second to-be-verified information at the first node side is the same as the value of the second to-be-verified information at the second node side, so as to verify whether the second to-be-verified information is tampered with.
[0343] In a possible implementation, the second-node-side information verification process is performed before the second-node-side information verification process. When the first verification parameter is verified successfully, the second node generates a second verification parameter based on the second to-be-verified information. Optionally, if the information verification is not successful, the second node can end the association process, or no longer respond to subsequent processes, or discard the information currently transmitted with the first node, and the like.
[0344] In a possible implementation, the first node can verify whether the second verification parameter is correct, and if the verification is successful, the first node opens the controlled port and allows the second node to access the corresponding resource.
[0345] FIG. 6 exemplarily shows a process of verifying information transmitted between the first node and the second node based on the first key. Through verification of the first key, forward security of the information transmitted between the first node and the second node can be ensured, and the communication security performance of the node is improved.
[0346] In some solutions, the security context negotiation process shown in FIG. 6 is performed before the authentication process, that is, the first node and the second node perform the security context negotiation process before receiving the first information and the first signature from the second node. At this time, the identity of the second node has not been authenticated, and therefore, the first key can be determined in the second node authentication process. The first key is determined based on identity authentication, and the information transmitted in the security context negotiation process is verified based on the first key, which can ensure forward information security of the node and help improve the communication security performance of the node.
[0347] In some possible designs, the first node communicates with the second node using a first communication protocol, and the first node communicates with the third node using a second communication protocol. In some cases, the first communication protocol is different from the second communication protocol. In some other cases, the first communication protocol is the same as the second communication protocol.
[0348] Further, in the case where the first communication protocol is different from the second communication protocol, for the message transmitted between the first node and the third node, a transmission unit defined by the second communication protocol needs to be used to carry the information (such as a message) that needs to be transmitted by the first communication protocol. For example, the first communication protocol is a star flash communication protocol, and the second communication protocol is an Ethernet communication protocol. The second information, the third signature, the third information, the third signature, and the message M5 are information that needs to be transmitted by the star flash communication protocol, which are carried in a star flash data message for transmission. Since the first node and the third node communicate using the Ethernet communication protocol, the star flash data message needs to be carried in an Ethernet message.
[0349] As a possible implementation, the information transmitted between the first node and the third node is encapsulated in a data packet, the data packet is in a format defined by the first communication protocol, and the data packet is carried in a payload of a protocol data unit (PDU) transmitted between the first node and the third node, the PDU being in a format defined by the second communication protocol.
[0350] As shown in FIG. 7, the PDU in the second communication protocol includes a header, a payload, and an optional trailer, and the packet (data packet) in the first communication protocol includes a data portion and optionally a header and a trailer. At least a part (e.g., the data portion, or the data portion and the header, or the data portion, the header, and the trailer) of the packet (i.e., the data packet) in the first communication protocol can be carried in the payload of the PDU.
[0351] In combination with FIG. 7, the payload of the PDU in the second communication protocol further includes a packet type field, which is used to indicate a packet type of the data packet carried in the payload of the PDU. For example, in combination with Table 1, the packet type field is used to indicate one of the following packet types: certificate authentication request, certificate authentication response, certificate authentication completion, or key delivery.
[0352] Table 1: second packet type
[0353] In combination with FIG. 7, the payload of the PDU further includes a packet length field, a value of the packet length field being used to indicate a data length of the data packet in the first communication protocol carried by the PDU. Optionally, a data length of the packet type field and / or a data length of the packet length field can be designed according to requirements.
[0354] The above embodiment of FIG. 4 and possible designs thereof show various possible implementations, two of which are described below in combination with FIG. 8 and FIG. 9. It should be understood that some concepts and logics in FIG. 8 and FIG. 9 can be referred to the description of the embodiment of FIG. 4 and possible designs thereof.
[0355] Please refer to FIG. 8, which is a flowchart of another communication method according to an embodiment of the present application. Optionally, the method can be applied to a communication system, such as the communication system shown in FIG. 1, FIG. 2, or FIG. 3. The communication method shown in FIG. 8 can include one or more of steps S801 to S821. It should be understood that, for the convenience of description, the steps S801 to S821 are described in this order, and it is not intended to limit the execution of the steps in the above order. The present embodiment does not limit the order of execution, the time of execution, the number of execution, etc. of the one or more steps. The steps S801 to S821 are as follows:
[0356] Step 801: The first node sends a broadcast message.
[0357] Correspondingly, the second node can receive the broadcast message, for example, a communication domain system message. Optionally, the broadcast message carries an indication of the key agreement algorithm capability and the authentication mode of the first node. The authentication mode indication is used to indicate certificate authentication, for example, to indicate enterprise certificate authentication.
[0358] Optionally, the second node can request association with the first node.
[0359] Step 802: The first node and the second node perform a security context negotiation process.
[0360] In the security context negotiation process, the first node and the second node negotiate a cipher algorithm (including a KDF and a key agreement algorithm). Meanwhile, a session key for a signaling plane and a session key for a user plane are generated, and signaling plane encryption and integrity protection are started.
[0361] In one possible implementation, when the first node and the second node perform the security context negotiation process, the calculation and verification process of the authentication parameter in the security context negotiation process is omitted. Optionally, in the security context negotiation process, the first node and the second node negotiate to generate a session key. Further, the session key includes a session key for a signaling plane and a session key for a user plane.
[0362] After the first node and the second node complete the security context negotiation, a certificate authentication process is performed:
[0363] Step 803: The second node sends a message M1 to the first node. Correspondingly, the first node receives the message M1 from the second node.
[0364] The message M1 carries a first timestamp, a random number Nt, a public key Pubt of the second node, a certificate of the second node, and a first signature. The first signature is a signature of a specified data field in the message M1 except for the field corresponding to the first signature, which can be predefined or preconfigured. For example, the specified field is all data fields except for the field corresponding to the first signature, that is, the first signature is a signature of the message M1 (i.e., the first timestamp, the random number Nt, the public key Pubt of the second node, and the certificate of the second node) except for the first signature. In the embodiments in FIG. 4 and the like, the information covered by the first signature is referred to as first information for ease of description.
[0365] As one possible implementation, the second node generates a temporary private key Prit and generates a corresponding public key Pubt according to a key agreement algorithm. The second node generates a random number Nt. The first node also determines a first timestamp, which can indicate a generation time or a sending time of the message M1, for example. The above information is carried in the message M1.
[0366] In some schemes, when the second node is connected with the first node based on the StarFlash communication protocol, the second node can be referred to as a T node, the certificate of the second node can be referred to as a T certificate, and the first signature can be referred to as a T signature.
[0367] In some schemes, the message M1 is referred to as an access authentication request.
[0368] Step 804: The first node verifies the certificate of the second node and verifies the first signature.
[0369] Step 805: The first node sends a message M2 to a third node. Correspondingly, the third node receives the message M2 from the first node.
[0370] The message M2 carries the message M1, a random number Ng, the certificate of the first node, a second signature, and indication information of the KDF and indication information of the key agreement algorithm determined in the security context negotiation process, the identity (such as L2ID) of the first node, and the identity (such as L2ID) of the second node.
[0371] The second signature is a signature of a specified data field in the message M2 except for the field corresponding to the second signature, which can be predefined or pre-set. For example, the specified field is all data fields except for the field corresponding to the second signature, that is, the second signature is a signature of the message M2 except for the second signature. In order to facilitate description, the information covered by the second signature is referred to as second information in the embodiments of FIG. 4 and the like.
[0372] In some schemes, when the second node is connected with the first node based on the StarFlash communication protocol, the first node can be referred to as a G node, the certificate of the first node can be referred to as a G certificate, and the second signature can be referred to as a G signature.
[0373] In some schemes, the message M2 can be referred to as a certificate authentication request.
[0374] Step 806: The third node verifies the certificate of the first node and verifies the second signature.
[0375] Step 807: The third node verifies the certificate of the second node and verifies the first signature.
[0376] Step 808: The third node generates a negotiation key based on the Pubt and the PriAC using the key agreement algorithm.
[0377] Specifically, the third node can generate a temporary private key PriAC (that is, the private key of the third node) and generate a corresponding public key PubAC (that is, the public key of the third node) according to the key agreement algorithm. The third node generates a DH key based on the PriAC, the Pubt, and the key agreement algorithm.
[0378] It should be understood that the parameters related to the third node are exemplarily represented by the suffix AC, and the parameters related to the second node are exemplarily represented by the suffix t, and the parameters related to the first node are exemplarily represented by the suffix g, but the above representations are not limitations on the scheme. In fact, the representations of the parameters, information and messages in the present application are only for the convenience of description, and in some schemes, the parameters, information or messages can be represented as other names or mathematical representations, and the representations in the present application are only examples.
[0379] Step 809: The third node generates the MK and derives the RK.
[0380] The related description can be referred to the related introduction of the generation of the first key in the embodiment shown in FIG. 4.
[0381] The third node generates the intermediate key MK based on the negotiation key and the first input parameter, and generates the first key based on the intermediate key MK and the second input parameter.
[0382] Exemplarily, the calculation method of the intermediate key MK is as follows: MK = KDF(DH key, Nt, Ng), where Nt is used to represent the first fresh parameter (here, the random number determined by the second node), and Ng is used to represent the second fresh parameter (here, the random number determined by the first node). In some schemes, the MK can also be generated by adding the first timestamp.
[0383] The calculation method of the key RK is as follows: RK = KDF(MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node belongs to the identity of the first node, and the L2ID of the second node belongs to the identity of the second node, and the meanings of other mathematical identities are described above.
[0384] Step 810: The third node sends the message M3 to the first node. Correspondingly, the first node receives the message M3.
[0385] The message M3 carries the message M2, the authentication result, the public key PubAC of the third node, the certificate of the third node and the third signature. The third signature is a signature of the specified data field in the message M3 except the field corresponding to the third signature, which can be predefined or pre-set. For example, the specified field is all the data fields except the field corresponding to the third signature, that is, the third signature is a signature of the message M3 except the third signature. In order to facilitate the description, the information covered by the third signature is referred to as the third information in the embodiments such as FIG. 4.
[0386] Optionally, the authentication result includes one or more of the results of verifying the first signature, the result of verifying the certificate of the second node, the result of verifying the second signature, and the result of verifying the certificate of the first node. The related description can be referred to the foregoing description.
[0387] In some schemes, the third node comprises an AC, the certificate of the third node can be referred to as an AC certificate, and the third signature can be referred to as an AC signature.
[0388] In some schemes, the message M3 can be referred to as a certificate authentication response.
[0389] Step 811: The first node verifies the certificate of the third node and verifies the third signature.
[0390] Step 812: The first node sends a message M4 to the second node. Correspondingly, the second node receives the message M4 from the first node.
[0391] The message M4 carries the message M3, the certificate of the first node and a fourth signature. Exemplarily, the fourth signature is a signature on specified data fields in the message M4 except for the field corresponding to the fourth signature, which can be predefined or pre-set. For example, the specified fields are all data fields except for the field corresponding to the fourth signature, i.e., the fourth signature is a signature on the message M4 except for the fourth signature. In the embodiment of FIG. 4 and the like, for the convenience of description, the information covered by the fourth signature is referred to as fourth information.
[0392] In some schemes, the message M4 can be referred to as an access authentication response.
[0393] In some schemes, the first node is a G node, the certificate of the first node can be referred to as a G certificate, and the fourth signature can be referred to as a G signature.
[0394] Step 813: The second node verifies the certificate of the first node and verifies the fourth signature.
[0395] Step 814: The second node verifies the certificate of the third node and verifies the third signature.
[0396] Step 815: The second node generates a negotiated key based on the PubAC and the PriAC using a key agreement algorithm.
[0397] Specifically, the second node generates a DH key based on the PriAC and the Pubt using a key agreement algorithm. Optionally, the key agreement algorithm is the algorithm determined in the security context negotiation process with the first node, which can be referred to as a first key agreement algorithm for the convenience of distinguishing.
[0398] It should be understood that, in the case that the public key for key agreement in the interaction is not tampered with, the negotiated key DH key determined by the second node is consistent with the negotiated key DH key determined by the third node.
[0399] Step 816: The second node generates the MK and derives the RK.
[0400] The related description can refer to the related description of generating the first key in the embodiment shown in FIG. 4.
[0401] The second node generates an intermediate key MK based on the negotiated key and the first input parameter, and generates the first key based on the intermediate key MK and the second input parameter. Exemplarily, the intermediate key MK is calculated in the following manner: MK = KDF (DH key, Nt, Ng), where Nt is used to represent the first fresh parameter (here, the random number determined by the second node), and Ng is used to represent the second fresh parameter (here, the random number determined by the first node). In some schemes, the MK can also be generated by adding the first timestamp.
[0402] The key RK is calculated in the following manner: RK = KDF (MK, L2ID of the first node, L2ID of the second node), where the L2ID of the first node belongs to the identity of the first node, and the L2ID of the second node belongs to the identity of the second node. The meanings of other mathematical identities are described above.
[0403] Step 817: The second node sends a message M8 to the first node. Correspondingly, the first node receives the message M8 from the second node.
[0404] In some schemes, the message M8 can be referred to as an access authentication completion message, which is used to indicate that the access authentication is completed.
[0405] Step 818: The first node sends a message M9 to the third node. Correspondingly, the third node receives the message M9 from the first node.
[0406] In some schemes, the message M9 can be referred to as a certificate authentication completion message, which is used to indicate that the certificate authentication is completed.
[0407] In some schemes, the steps S816 and S817 are optional steps.
[0408] Step 819: The third node sends a message M5 to the first node. Correspondingly, the first node receives the message M5 from the third node.
[0409] The message M5 carries the first key RK, which is referred to as an authentication key in some scenarios. In some schemes, the first key is used to verify the information transmitted between the first node and the second node.
[0410] Exemplarily, the message M5 can be referred to as a key delivery message, or an authentication key delivery message.
[0411] In some schemes, the first node and the second node perform a session key confirmation process. Alternatively, the session key confirmation process is used to verify the security of the session key determined in the security context negotiation process. The session key confirmation process is as follows:
[0412] Step 820: The first node sends a message M6 to the second node. Accordingly, the second node receives the message M6 from the first node.
[0413] Optionally, the first verification parameter is included in the message M6, and the first verification parameter can be generated based on the first key and information transmitted between the first node and the second node. For related examples, refer to the embodiment shown in FIG. 6.
[0414] Step 821: The second node sends a message M7 to the first node. Accordingly, the first node receives the message M7 from the second node.
[0415] Optionally, the second verification parameter is included in the message M7, and the second verification parameter can be generated based on the second key and information transmitted between the first node and the second node. For related examples, refer to the embodiment shown in FIG. 6.
[0416] Optionally, the first node verifies the second verification parameter. In the case that the verification of the HASHg is passed, the first node opens a controlled port to allow the second node to access the allowed resources. Optionally, the controlled port is, for example, the first communication port, and the second node can access the resources based on the first communication port.
[0417] In the embodiment shown in FIG. 8, each node uses the certificate and signature of the other two nodes to authenticate the identity of the other two nodes between the first node, the second node and the third node, to implement a two-way authentication mechanism of a ternary peer-to-peer architecture, which significantly improves the communication security performance of the node and the security and stability of the network. Further, the time stamp is used to implement a replay protection mechanism, which further improves the stability of the network.
[0418] Please refer to FIG. 9, which is a flow diagram of another communication method provided by the embodiments of the present application. Optionally, the method can be applied to a communication system, such as the communication system shown in FIG. 1, FIG. 2 or FIG. 3. The communication method shown in FIG. 9 can include steps S801-S821 and multiple steps in step S901. It should be understood that the description order shown in FIG. 9 is only an example and is not intended to limit the execution through the order shown in FIG. 9. The embodiments of the present application do not limit the execution order, execution time, execution times, etc. of one or more steps described above. The communication method shown in FIG. 9 includes:
[0419] Step 801: The first node sends a broadcast message.
[0420] Accordingly, the second node can receive the broadcast message. Optionally, the second node can request to associate with the first node.
[0421] Step 802: The first node and the second node perform a security context negotiation process.
[0422] After the first node and the second node complete the security context negotiation, a certificate authentication process is performed:
[0423] Step 901: The first node sends a message M10 to the second node. Accordingly, the second node receives the message M10 from the first node.
[0424] The message M10 includes a random number Ng, which is a random number generated by the first node. The random number Ng can be subsequently used to determine a first key, and related descriptions can be referred to the descriptions of the foregoing embodiments of FIG. 4 and FIG. 8.
[0425] Specifically, the first node generates the random number Ng, and sends the message M10 to the second node, where the message M10 carries the random number Ng.
[0426] Step 803: The second node sends a message M1 to the first node. Accordingly, the first node receives the message M1 from the second node.
[0427] The message M1 carries the random number Ng, a random number Nt, a public key Pubt of the second node, a certificate of the second node, and a first signature. The first signature is a signature of specified data fields in the message M1 except for the field corresponding to the first signature. Related descriptions can be referred to the descriptions of the foregoing step S803.
[0428] The step S804 and the step S821 can be referred to the foregoing descriptions. In the embodiment shown in FIG. 9, the random number Ng determined by the first node is used to implement the replay protection mechanism. Since the message M1 carries the random number Ng, and the message M2 carries the message M1, the message M2 can no longer carry the random number Ng field, but can include the random number Ng by carrying the message M2.
[0429] In the embodiment shown in FIG. 9, each node uses the certificates and the signatures of the other two nodes to authenticate the identities of the other two nodes, so as to implement a two-way authentication mechanism of a three-node peer-to-peer architecture, significantly improve the communication security performance of the nodes, and improve the security and stability of the network. Further, the random number provided by the first node is used to implement the replay protection mechanism, and further improve the stability of the network.
[0430] The method of the embodiments of the present application is described in detail above, and the apparatus of the embodiments of the present application is provided below.
[0431] It should be understood that the division of units in the apparatus provided in the embodiments of the present application is only a logical functional division, and all or part of the units can be integrated into a physical entity or physically separated in actual implementation. In addition, the units in the apparatus can be implemented in the form of processor calling software. For example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any one of the above methods or to realize the functions of the units of the apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is an internal memory of the apparatus or an external memory of the apparatus.
[0432] Alternatively, the units in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units can be realized by the design of the hardware circuit, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units are realized by the design of the logical relationship of elements in the circuit. For another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and the functions of part or all of the units are realized by the configuration of the connection relationship between the logic gate circuits.
[0433] In the embodiments of the present application, each unit in the apparatus can be one or more processors (or processing circuits) configured to implement the above methods, such as CPU, (graphics processing unit, GPU), neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), microprocessor unit (MPU), digital signal processor (DSP), ASIC, FPGA, or a combination of at least two forms of processors.
[0434] In addition, all or some of the units in the above apparatus can be integrated or can be independent. In one implementation, the units are integrated together to form a system on a chip (SOC, also known as system-level chip). The SOC can include at least one processor for implementing the functions of the above methods or implementing the functions of the units of the apparatus. The at least one processor can be of different types, such as including a CPU and an FPGA, or including a CPU and an artificial intelligence processor, or including a CPU and a GPU, and the like. The following lists several possible apparatuses.
[0435] Referring to FIG. 10, FIG. 10 is a structural schematic diagram of a communication apparatus provided in an embodiment of the present application. Optionally, the communication apparatus 100 can be a standalone device, such as a node, etc. Alternatively, the communication apparatus 100 can also be a device, such as a chip or an integrated circuit, etc., in a standalone device (such as a node). The communication apparatus 100 is configured to implement the communication method described above, such as the communication method and possible implementation manners thereof shown in the embodiments of FIG. 4, FIG. 6, FIG. 8, FIG. 9, etc.
[0436] For example, the communication apparatus 100 includes a sending unit 1001 and a receiving unit 1002. Optionally, the communication apparatus 100 further includes a processing unit 1003. The sending unit 1001 is configured to send information, the receiving unit 1002 is configured to receive information, and the processing unit 1003 is configured to process the information to be sent or process the received information. For example, the processing unit 1003 is configured to implement one or more operations of authentication, negotiation, processing, determination, generation, calculation, encryption, decryption, etc. It should be understood that the division of the units here is only illustrative, and in specific implementation, some units can be combined together, or one unit can be split into multiple units. For example, the sending unit 1001 and the receiving unit 1002 can be combined to obtain a communication unit. For another example, the processing unit 1003 can include an obtaining unit and a calculation unit, the obtaining unit is configured to obtain data from the data, and the calculation unit is configured to perform a calculation process.
[0437] In one possible design, the communication apparatus 100 is configured to implement the method on the first node side in the foregoing communication method.
[0438] In one possible implementation, the receiving unit 1002 is configured to receive first information and a first signature from a second node, and the sending unit 1001 is configured to send second information and a second signature to a third node. The first information includes a certificate of the second node, the first signature is a signature of the first information, the second information includes the first information, the first signature and a certificate of the first node, and the second signature is a signature of the second information. The certificate of the first node, the certificate of the second node, the first signature and the second signature are used for authentication.
[0439] In an embodiment, the receiving unit 1002 is configured to receive, from the third node, third information and a third signature, the third information comprising a certificate of the third node, the third signature being a signature on the third information.
[0440] In an embodiment, the processing unit 1003 is configured to authenticate the second node based on the certificate of the second node and the first signature.
[0441] In an embodiment, the processing unit 1003 is configured to authenticate the third node based on the certificate of the third node and the third signature.
[0442] In an embodiment, the sending unit 1001 is configured to send, to the second node, fourth information and a fourth signature, the fourth information comprising the third information, the third signature, a certificate of the third node and a certificate of the first node, the fourth signature being a signature on the fourth information, the certificate of the first node, the certificate of the third node, the third signature and the fourth signature being used for authentication.
[0443] In an embodiment, the sending unit 1001 is configured to send an authentication mode indication, the authentication mode indication indicating that the authentication mode is the certificate authentication mode.
[0444] In some scenarios, the above authentication procedure is performed in an enterprise network, for example, the authentication mode indication indicates that the authentication mode is an enterprise-certificate authentication mode.
[0445] In an embodiment, the sending unit 1001, the receiving unit 1002 and the processing unit 1003 are configured to perform a security context negotiation procedure.
[0446] In an embodiment, the sending unit 1001 is configured to send, to the second node, a third fresh parameter, the first information further comprising the third fresh parameter.
[0447] In an embodiment, the sending unit 1001 is configured to send, to the third node, a certificate authentication request, the certificate authentication request comprising the second information and the second signature. That is, the second information and the second signature can be carried in the certificate authentication request and transmitted.
[0448] In an embodiment, the receiving unit 1002 is configured to receive, from the third node, a certificate authentication response, the certificate authentication response comprising the third information and the third signature. That is, the third information and the third signature can be carried in the certificate authentication response and transmitted.
[0449] In an embodiment, the sending unit 1001 is configured to send, to the second node, an access authentication response, the access authentication response comprising the fourth information and the fourth signature. That is, the fourth information and the fourth signature can be carried in the access authentication response and transmitted.
[0450] In yet another possible implementation, the receiving unit 1002 is configured to receive a first message, such as message M8, from the second node. The first message is configured to indicate that the access authentication is completed, for example, referred to as an access authentication completion message.
[0451] In yet another possible implementation, the sending unit 1001 is configured to send a second message, such as message M9, to the third node. The second message is configured to indicate that the credential authentication is completed, for example, referred to as a credential authentication completion message.
[0452] The detailed description can refer to the foregoing method embodiments.
[0453] In yet another possible design, the communication apparatus 100 is configured to implement the method on the second node side in the foregoing communication method.
[0454] In a possible implementation, the sending unit 1001 is configured to send first information and a first signature to the first node, and the receiving unit 1002 is configured to receive fourth information and a fourth signature from the first node, to authenticate the first node based on a credential of the second node and the fourth signature, and to authenticate the third node based on a credential of the third node and the third signature. The first information includes the credential of the second node, and the first signature is a signature of the first information, and the credential of the second node and the first signature are used for authentication. The fourth information includes the third information, the third signature and the credential of the first node, and the fourth signature is a signature of the fourth information, and the third signature is a signature of the third information, and the third information includes the credential of the third node, and the third node is in communication connection with the first node, and the third node is configured to be authenticated.
[0455] In yet another possible implementation, the receiving unit 1002 is further configured to receive an authentication mode indication from the first node, and the authentication mode indication is configured to indicate that the authentication mode is the credential authentication mode.
[0456] In some scenarios, the foregoing authentication procedure is performed in an enterprise version network, for example, the authentication mode indication is configured to indicate that the authentication mode is an enterprise version-credential authentication mode.
[0457] In yet another possible implementation, the third information further includes a public key of the third node. The processing unit 1003 is configured to determine a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm.
[0458] In yet another possible implementation, the sending unit 1001, the receiving unit 1002 and the processing unit 1003 are further configured to perform a security context negotiation procedure.
[0459] In yet another possible implementation, the first information comprises a first freshness parameter. The processing unit 1003 is further configured to determine a negotiated key based on the public key of the third node and the private key of the second node using the first key agreement algorithm, and determine the first key based on at least the negotiated key and the first freshness parameter.
[0460] In yet another possible implementation, the fourth information comprises a second freshness parameter, and the second freshness parameter is generated by the first node. The processing unit 1003 is further configured to determine a negotiated key based on the public key of the third node and the private key of the second node using the first key agreement algorithm, and determine the first key based on at least the negotiated key and the second freshness parameter.
[0461] In yet another possible implementation, the first information comprises a first freshness parameter, and the third information further comprises a second freshness parameter. The processing unit 1003 is further configured to determine a negotiated key based on the public key of the third node and the private key of the second node using the first key agreement algorithm, and determine the first key based on at least the negotiated key, the first freshness parameter and the second freshness parameter.
[0462] In yet another possible implementation, the processing unit 1003 is further configured to determine an intermediate key based on a first key derivation function KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determine the first key based on at least the first KDF and the intermediate key.
[0463] In yet another possible implementation, the processing unit 1003 is further configured to determine an intermediate key based on a first key derivation function KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determine the first key based on the first KDF, the intermediate key, an identity of the first node and an identity of the second node.
[0464] In yet another possible implementation, the processing unit 1003 is further configured to determine a first timestamp, and the first information further comprises the first timestamp.
[0465] In yet another possible implementation, the receiving unit 1002 is further configured to receive a third freshness parameter from the first node, and the first information further comprises the third freshness parameter. Optionally, the third freshness parameter is the same as the second freshness parameter.
[0466] In yet another possible implementation, the sending unit 1001 is configured to send an access authentication request to the first node, and the access authentication request comprises the first information and the first signature. That is, the first information and the first signature can be carried in the access authentication request and transmitted.
[0467] In yet another possible implementation, the receiving unit 1002 is configured to receive an access authentication response from the first node, and the access authentication response comprises the fourth information and the fourth signature. That is, the fourth information and the fourth signature can be carried in the access authentication response and transmitted.
[0468] In yet another possible implementation, the sending unit 1001 is further configured to send a first message, such as message M8, for indicating that the access authentication is completed.
[0469] The detailed description can refer to the foregoing method embodiments.
[0470] In yet another possible design, the communication apparatus 100 is configured to implement the method on the third node side in the foregoing communication method.
[0471] In a possible implementation, the receiving unit 1002 is configured to receive second information and a second signature from the first node. The processing unit 1003 is configured to authenticate the first node based on a certificate of the first node and the second signature, and authenticate the second node based on a certificate of the second node and a first signature. The sending unit 1001 is configured to send third information and a third signature to the first node. The second information includes the first information, the first signature and the certificate of the first node, the first information includes the certificate of the second node, the first signature is a signature of the first information, and the second signature is a signature of the second information. The third information includes a certificate of the third node, and the third signature is a signature of the third information, the certificate of the third node and the third signature being used for authentication.
[0472] In yet another possible implementation, the first information further includes a public key of the second node. The processing unit 1003 is further configured to determine the first key by using a first key agreement algorithm based on the public key of the second node and a private key of the third node.
[0473] In yet another possible implementation, the first information includes a first fresh parameter. The processing unit 1003 is further configured to determine a negotiated key by using the first key agreement algorithm based on the public key of the second node and the private key of the third node, and determine the first key based on at least the negotiated key and the first fresh parameter.
[0474] In yet another possible implementation, the third information further includes a second fresh parameter. The processing unit 1003 is further configured to determine a negotiated key by using the first key agreement algorithm based on the public key of the second node and the private key of the third node, and determine the first key based on at least the negotiated key and the second fresh parameter.
[0475] In yet another possible implementation, the first information includes a first fresh parameter, and the third information further includes a second fresh parameter. The processing unit 1003 is further configured to determine a negotiated key by using the first key agreement algorithm based on the public key of the second node and the private key of the third node, and determine the first key based on at least the negotiated key, the first fresh parameter and the second fresh parameter.
[0476] In yet another possible implementation, the processing unit 1003 is further configured to determine an intermediate key based on the first KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determine the first key based on at least the first KDF and the intermediate key.
[0477] In yet another possible implementation, the processing unit 1003 is further configured to determine an intermediate key based on the first KDF, the negotiated key, the first freshness parameter and the second freshness parameter, and determine the first key based on the first KDF, the intermediate key, the identity of the first node and the identity of the second node.
[0478] In yet another possible implementation, the receiving unit 1002 is further configured to receive a certificate authentication request from the first node, the certificate authentication request comprising the second information and a second signature.
[0479] In yet another possible implementation, the sending unit 1001 is further configured to send a certificate authentication response to the first node, the certificate authentication response comprising the third information and a third signature.
[0480] In yet another possible implementation, the receiving unit 1002 is further configured to receive a second message, such as message M9. The second message is used to indicate that the certificate authentication is completed.
[0481] The detailed description can refer to the foregoing method embodiments.
[0482] Please refer to FIG. 11, which is a structural schematic diagram of a communication device according to an embodiment of the present application. The communication device 110 can be a standalone device, such as a node, a server, etc., or a component included in a standalone device, such as a chip, a software module, or an integrated circuit, etc. In some schemes, the communication device 110 can also be referred to as a communication apparatus. The communication device 110 can include at least one processor 1101 and a memory 1103. Optionally, it can also include a communication interface 1102. Further optionally, it can also include a connection line 1104, wherein the processor 1101, the communication interface 1102 and / or the memory 1103 are connected through the connection line 1104, and / or communicate with each other through the connection line 1104 to transfer control signals and / or data signals.
[0483] Wherein:
[0484] The processor 1101 is a module for performing arithmetic operations and / or logical operations, and can specifically include one or more of the following modules: a filter, a modem, a power amplifier, a low noise amplifier (LNA), a baseband processor, a radio frequency processor, a radio frequency circuit, a central processing unit (CPU), an application processor (AP), a microcontroller unit (MCU), an electronic control unit (ECU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated Circuit (ASIC), an image signal processor (ISP), a digital signal processor (DSP), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), or a co-processor, etc.
[0485] The communication interface 1102 can be configured to provide information input or output for at least one processor, or to receive a signal transmitted from an external device and / or transmit a signal to an external device. For example, the communication interface 1102 can include an interface circuit. For example, the communication interface 1102 can include a wired link interface such as an Ethernet cable, and can also be a wireless link (Wi-Fi, Bluetooth, universal wireless transmission, vehicle-mounted short-range communication technology, and other short-range wireless communication technologies) interface. Optionally, the communication interface 1102 can also include a radio frequency transmitter, an antenna, etc. In the case where the communication interface 1102 includes an antenna, the number of antennas can be one or more.
[0486] As a possible design, if the communication device 110 is a standalone device, the communication interface 1102 can include a receiver and a transmitter. The receiver and the transmitter can be the same component or different components. When the receiver and the transmitter are the same component, the component can be referred to as a transceiver.
[0487] As yet another possible design, if the communication device 110 is a chip or a circuit, the communication interface 1102 can include an input interface and an output interface, which can be the same interface, or can be different interfaces.
[0488] Optionally, the functions of the communication interface 1102 can be implemented by a transceiver circuit or a dedicated chip of transceiver.
[0489] The memory 1103 is configured to provide a storage space in which data such as an operating system and a computer program can be stored. The memory 1103 can be one or a combination of a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM).
[0490] It should be noted that the functions and actions of the modules or units in the above-mentioned communication device 110 are only exemplary.
[0491] The functional units in the communication device 110 can be configured to implement the above-mentioned communication method, such as the communication method shown in the embodiments of FIG. 4, FIG. 6, FIG. 8, or FIG. 9, and possible implementation manners thereof. For example, the communication device 110 is configured to perform the method performed by the first node, the second node, or the authentication server.
[0492] Optionally, the processor 1101 can be a processor specially configured to perform the above-mentioned method (for the sake of distinction, referred to as a special-purpose processor), or can be a processor that performs the above-mentioned method by invoking a computer program (for the sake of distinction, referred to as a special-purpose processor). Optionally, the at least one processor can include both a special-purpose processor and a general-purpose processor.
[0493] Optionally, in the case where the communication device 110 includes at least one memory 1103, if the processor 1101 performs the above-mentioned communication method by invoking a computer program, the computer program can be stored in the memory 1103.
[0494] The embodiments of the present application also provide a chip, which includes a logic circuit and a communication interface. The communication interface is configured to receive a signal or send a signal; and the logic circuit is configured to receive a signal or send a signal through the communication interface. The chip is configured to implement the above-mentioned communication method, such as the communication method shown in the embodiments of FIG. 4, FIG. 6, FIG. 8, or FIG. 9, and possible implementation manners thereof.
[0495] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores instructions. When the instructions run on at least one processor (or a communication device), the communication method described above, for example, the communication method shown in the embodiments of FIG. 4, FIG. 6, FIG. 8, FIG. 9 and possible implementation manners thereof, is implemented.
[0496] The embodiment of the present application further provides a computer program product, and the computer program product includes computer instructions. The computer instructions are used to implement the communication method described above, for example, the communication method shown in the embodiments of FIG. 4, FIG. 6, FIG. 8, FIG. 9 and possible implementation manners thereof.
[0497] The embodiment of the present application further provides a terminal, and the terminal includes the communication device 100 and / or the communication equipment 110 described above.
[0498] It should be noted that in the embodiments of the present application, the words such as "exemplarily" or "for example" are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplarily" or "for example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. In fact, the words such as "exemplarily" or "for example" are intended to present the related concept in a specific manner.
[0499] In the embodiments of the present application, the names of information and devices are exemplarily named for the convenience of understanding the content of the present application, and in the specific implementation, the names can be designed in other manners. In addition, the names of the same thing can also be designed differently in different scenarios (for example, different communication layers).
[0500] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "At least one" or similar expressions refer to any combination of these items, including any combination of single item or multiple items.
[0501] For example, at least one of a, b or c can represent: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b and c can be single or multiple. "And / or" describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can represent: A alone, A and B together, and B alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it.
[0502] Also, unless otherwise stated, the ordinal numbers such as "first", "second", "T1", "T2" and the like used in the embodiments of the present application are used to distinguish the multiple objects, and are not used to limit the order, time sequence, priority or importance of the multiple objects. For example, the first node, the second node are only used to facilitate the description of the nodes in different embodiments, and do not mean that the nodes perform different operations, importance, structure, etc.
[0503] In the above embodiments, according to the context, the term "when" can be interpreted as meaning "if", "after" or "in response to determining" or "in response to detecting". The above is only an optional embodiment of the present application, and is not used to limit the present application. Any modification, equivalent replacement, improvement, etc. within the concept and principle of the present application should be included in the protection scope of the present application.
[0504] A person of ordinary skill in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by a program instructing related hardware to complete. The program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.
Claims
1. An access authentication method characterized by, The method is applied to a first node, and the access authentication method comprises: receiving first information and a first signature from a second node, the first information comprising a certificate of the second node, and the first signature being a signature of the first information; sending second information and a second signature to a third node, the second information comprising the first information, the first signature and a certificate of the first node, the second signature being a signature of the second information, and the certificate of the first node, the certificate of the second node, the first signature and the second signature being used for authentication; receiving third information and a third signature from the third node, the third information comprising a certificate of the third node, and the third signature being a signature of the third information.
2. The method of claim 1, wherein, After receiving the first information and the first signature from the second node, the method further comprises: authenticating the second node based on the certificate of the second node and the first signature.
3. The method according to claim 1 or 2, characterized in that, After receiving the third information and the third signature from the third node, the method further comprises: authenticating the third node based on the certificate of the third node and the third signature.
4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: sending fourth information and a fourth signature to the second node, the fourth information comprising the third information, the third signature, the certificate of the third node and the certificate of the first node, the fourth signature being a signature of the fourth information, and the certificate of the first node, the certificate of the third node, the third signature and the fourth signature being used for authentication.
5. The method of claim 4, wherein, The third information further comprises an authentication result of the first node by the third node and / or an authentication result of the second node by the third node.
6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: sending an authentication mode indication, the authentication mode indication being used to indicate that the authentication mode is a certificate authentication mode.
7. The method according to any one of claims 1 to 6, characterized in that, The first information further comprises a public key of the second node, the public key of the second node being used to determine a first key, and the first key being used to verify information transmitted in a security context negotiation process.
8. The method according to any one of claims 1 to 7, characterized in that, The third information further comprises a public key of the third node, the public key of the third node being used to determine the first key, and the first key being used to verify information negotiated in a security context negotiation process.
9. The method according to any one of claims 1 to 8, characterized in that, The first information further comprises a first freshness parameter, and the first freshness parameter is used to determine the first key.
10. The method according to any one of claims 1 to 9, characterized in that, The second information further comprises a second freshness parameter, and the third information further comprises the second freshness parameter. The second freshness parameter is used to determine the first key.
11. The method according to any one of claims 1 to 10, characterized in that, Before receiving the first information and the first signature from the second node, the method further comprises: sending a third freshness parameter to the second node, and the first information further comprises the third freshness parameter.
12. The method according to any one of claims 1 to 11, characterized in that, The first information further comprises a first timestamp determined by the second node.
13. The method according to any one of claims 1 to 12, characterized in that, The second information further comprises information of a first key derivation function (KDF) and / or information of a first key negotiation algorithm, the first KDF being negotiated by the first node and the second node, and the first key negotiation algorithm being negotiated by the first node and the second node, the first key negotiation algorithm being used to negotiate a key, and the first KDF being used to derive a key.
14. The method according to any one of claims 1 to 13, characterized in that, The first node communicates with the second node using a first communication protocol, and the first node and the third node communicate using a second communication protocol, the first communication protocol being different from the second communication protocol.
15. The method of claim 14, wherein, Information transmitted between the first node and the third node is encapsulated in a data packet, the data packet being in a format defined by the first communication protocol, The data packet is carried in a payload portion of a protocol data unit (PDU) transmitted between the first node and the third node, the PDU being in a format defined by the second communication protocol.
16. The method according to claim 14 or 15, characterized in that The payload portion of the PDU further includes a packet type field, a value of the packet type field being used to indicate a type of the data packet carried in the payload portion of the PDU.
17. The method of claim 4, wherein, The receiving the first information and the first signature from the second node includes: receiving an access authentication request from the second node, the access authentication request including the first information and the first signature; The sending the second information and the second signature to the third node includes: sending a certificate authentication request to the third node, the certificate authentication request including the second information and the second signature; The receiving the third information and the third signature from the third node includes: receiving a certificate authentication response from the third node, the certificate authentication response including the third information and the third signature; The sending the fourth information and the fourth signature to the second node includes: sending an access authentication response to the second node, the access authentication response including the fourth information and the fourth signature.
18. An access authentication method characterized by, The access authentication method is applied to a second node, and the access authentication method includes: sending first information and a first signature to a first node, the first information including a certificate of the second node, and the first signature being a signature of the first information, the certificate of the second node and the first signature being used for authentication; receiving fourth information and a fourth signature from the first node, the fourth information including third information, a third signature and a certificate of the first node, and the fourth signature being a signature of the fourth information, the third signature being a signature of the third information, the third information including a certificate of a third node, the third node being in communication connection with the first node and being used for authentication; authenticating the first node based on the certificate of the first node and the fourth signature; authenticating the third node based on the certificate of the third node and the third signature.
19. The method of claim 18, wherein, The third information includes second information and a second signature, The second information includes the first information, the first signature and the certificate of the first node, and the second signature being a signature of the second information.
20. The method of claim 18 or 19, wherein, The third information further includes an authentication result of the first node by the third node and / or an authentication result of the second node by the third node.
21. The method according to any one of claims 18-20, characterized by, Before sending the first information and the first signature to the first node, the method further includes: receiving an authentication mode indication from the first node, the authentication mode indication being used to indicate that the authentication mode is a certificate authentication mode.
22. The method according to any one of claims 18-21, characterized by, The third information further comprises a public key of the third node, and the method further comprises: determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure.
23. The method according to any one of claims 18-22, characterized by, The first information further comprises a public key of the second node, the public key of the second node being related to the private key of the second node.
24. The method of claim 22, wherein, The first information further comprises the first fresh parameter; and the determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure. The first information further comprises the first fresh parameter; and the determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises:
25. The method of claim 22, wherein, determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure. The first information further comprises the first fresh parameter; and the determining the first key based on the public key of the third node and the private key of the second node using the first key agreement algorithm comprises: determining a first key based on the public key of the third node and a private key of the second node using a first key agreement algorithm, the first key being used to verify information agreed in a security context agreement procedure.
26. The method of claim 25, wherein, The determining the first key based on the first key agreement algorithm, the public key of the third node and the private key of the second node comprises: determining an intermediate key based on a first key derivation function (KDF), the first key, the first fresh parameter and the second fresh parameter; determining the first key based on the first KDF, the intermediate key, an identity of the first node and an identity of the second node.
27. The method of any one of claims 18-26, wherein, Before sending the first information and the first signature to the first node, the method further comprises: determining a first timestamp, and the first information further comprises the first timestamp.
28. The method of any one of claims 18-27, wherein, Before sending the first information and the first signature to the first node, the method further comprises: receiving a third fresh parameter from the first node, and the first information further comprises the third fresh parameter.
29. An access authentication method characterized by, The access authentication method is applied to a third node, and the access authentication method comprises: receiving second information and a second signature from a first node, the second information comprising the first information, the first signature and a certificate of the first node, the first information comprising a certificate of the second node, the first signature being a signature of the first information, and the second signature being a signature of the second information; authenticating the first node based on the certificate of the first node and the second signature; authenticating the second node based on the certificate of the second node and the first signature; sending third information and a third signature to the first node, the third information comprising a certificate of the third node, and the third signature being a signature of the third information, the certificate of the third node and the third signature being used for authentication.
30. A communications device, characterized by The communication apparatus comprises units or modules for performing the method of any of claims 1-17, or units or modules for performing the method of any of claims 18-28, or units or modules for performing the method of claim 29.
31. A communications device, characterized by The communication apparatus comprises a processor and a memory, the memory is configured to store computer instructions, and the processor is configured to invoke the computer instructions stored in the memory, so that the communication apparatus implements the method of any of claims 1-17, or implements the method of any of claims 18-28, or implements the method of claim 29.
32. A communications device, characterized by The communication apparatus comprises a logic circuit and an interface, the interface is configured to input and / or output information, and the logic circuit is configured to make the communication apparatus implement the method of any of claims 1-17, or implement the method of any of claims 18-28, or implement the method of claim 29.
33. A communication system, characterized by The communication system comprises a first node, a second node and a third node, the first node is configured to implement the method of any of claims 1-17, the second node is configured to implement the method of any of claims 18-28, and the third node is configured to implement the method of claim 29.
34. A readable storage medium, characterized by The readable storage medium is configured to store a computer program, when the computer program is executed by a processor, the communication apparatus comprising the processor executes the method of any of claims 1-29.
35. A computer program product, characterised in that, When the computer program product is executed by a processor, the communication apparatus comprising the processor executes the method of any of claims 1-29.
Citation Information
Patent Citations
WAPI-based authentication method of wireless mesh network
CN101448262A
Access authentication method for wireless mesh network
CN102421095A
WAPI certificate authentication method and system
CN116249114A
Identity authentication method and system based on WAPI and data transmission method
CN118509847A
Method and apparatus for performing mutual authentication within a network
US20070162751A1