Secure Channel Wake-Up Key Renewal After Tunnel Sleep
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Tunnel communication security is compromised when a communication node sleeps for an extended period, making it susceptible to cracking, and subsequent attacks by illegitimate devices that mimic legitimate nodes are difficult to detect.
Innovation Solution
A secure channel sleep wake-up method that involves nodes exchanging key update messages upon waking up, using stored IP communication information and shared keys to renegotiate new encryption keys, and verifying IP address changes to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the tunnel enters sleep state to reduce resource consumption, then power and network bandwidth are saved, but communication security deteriorates due to high probability of cracking
Solution Approach 1:
The patent applies preliminary action by pre-generating and storing multiple communication parameters (IP addresses, port numbers, session identifiers) and cryptographic keys before entering sleep state. When waking up, the node can immediately use pre-prepared parameters without time-consuming renegotiation, thus maintaining security while saving energy during sleep.
Solution Approach 2:
The patent changes cryptographic parameters by updating encryption keys and communication parameters after waking from sleep state. The node receives parameter update messages from the peer node and switches to new cryptographic parameters, thereby preventing security compromises that would result from prolonged use of dormant credentials.
2Loss of energy
If the tunnel sleeps for extended period to conserve resources, then energy and bandwidth are reduced, but security vulnerability increases making dormant devices easy to crack
Solution Approach 1:
Multiple communication parameters and cryptographic keys are prepared in advance before sleep. This preliminary preparation allows the node to quickly switch to secure parameters upon waking without requiring time-consuming renegotiation, thus reducing energy loss while preventing security vulnerabilities.
Solution Approach 2:
The patent implements preliminary anti-action by pre-generating backup communication parameters and cryptographic keys before entering sleep state. These pre-prepared secure parameters act as a countermeasure against potential cracking attacks on dormant devices, enabling immediate secure reconnection without exposing the system to security risks.
3Reliability
If communication parameters are renegotiated after waking up, then security is maintained, but the process becomes complex and time-consuming
Solution Approach 1:
Communication parameters including IP addresses, port numbers, session identifiers, and cryptographic keys are generated and stored in advance before sleep. Upon waking, the node can immediately use these pre-prepared parameters or receive quick updates from the peer, avoiding complex and time-consuming renegotiation processes while maintaining security.
4Reliability
If communication parameters are renegotiated after waking up, then security is ensured, but the procedure becomes complex requiring multiple steps
Solution Approach 1:
All necessary communication parameters and cryptographic materials are prepared in advance before sleep state. This preliminary preparation simplifies the wake-up process significantly, as the node can either immediately use pre-configured parameters or receive a single parameter update message from the peer, eliminating complex multi-step renegotiation procedures while ensuring security.
Data Source
AI summary
Embodiments of the present disclosure provide a secure channel sleep wake-up method, apparatus and device. The method comprises: when a node 1 is awakened from a sleep state, obtaining stored IP communication information communicating with a node 2, performing message encapsulation by using the IP communication information to obtain a first message, and sending the first message to the node 2; the node 2 obtaining the IP communication information and a key updating request message from the first message, and generating a second key according to information comprising a basic key corresponding to a basic key identifier in the key updating request message and a first random number generated by the node 1 and in combination with a second random number self-generated by the node 2; the node 1 obtaining the IP communication information and a key updating response message, and generating the second key and the second random number.


