CN117081802A - Encrypted communication method, device, terminal equipment and storage medium - Google Patents

Encrypted communication method, device, terminal equipment and storage medium Download PDF

Info

Publication number
CN117081802A
CN117081802A CN202311030083.4A CN202311030083A CN117081802A CN 117081802 A CN117081802 A CN 117081802A CN 202311030083 A CN202311030083 A CN 202311030083A CN 117081802 A CN117081802 A CN 117081802A
Authority
CN
China
Prior art keywords
server
client
node
protocol
key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202311030083.4A
Other languages
Chinese (zh)
Inventor
叶可可
关志
方有轩
赖思为
赵思远
郑旭晓
陈钟
王珂
孙磊
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Peking University
China Mobile Communications Group Co Ltd
China Mobile Information Technology Co Ltd
Original Assignee
Peking University
China Mobile Communications Group Co Ltd
China Mobile Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Peking University, China Mobile Communications Group Co Ltd, China Mobile Information Technology Co Ltd filed Critical Peking University
Priority to CN202311030083.4A priority Critical patent/CN117081802A/en
Publication of CN117081802A publication Critical patent/CN117081802A/en
Pending legal-status Critical Current

Links

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/061—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key exchange, e.g. in peer-to-peer networks
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/08—Protocols for interworking; Protocol conversion

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer And Data Communications (AREA)

Abstract

本申请公开了加密通信方法、装置、终端设备以及存储介质,涉及通信技术领域,其方法包括:通过预设的跨协议节点接收到客户端发起的访问请求,得到转换后的客户端密钥交换参数;生成服务端密钥交换参数,将所述服务端密钥交换参数发送至所述跨协议节点,其中,所述跨协议节点用于根据所述服务端密钥交换参数生成服务端节点算法密钥;根据所述服务端密钥交换参数与所述转换后的客户端密钥交换参数,生成服务端算法密钥;通过所述跨协议节点,基于所述服务端算法密钥与所述服务端节点算法密钥,与客户端之间进行跨协议通信。本发明提高了不同密码协议间通信的自动化程度。

This application discloses an encrypted communication method, device, terminal equipment and storage medium, and relates to the field of communication technology. The method includes: receiving an access request initiated by a client through a preset cross-protocol node, and obtaining a converted client key exchange Parameters; generate server-side key exchange parameters, and send the server-side key exchange parameters to the cross-protocol node, wherein the cross-protocol node is used to generate a server-side node algorithm according to the server-side key exchange parameters. Key; generate a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter; through the cross-protocol node, generate a server algorithm key based on the server algorithm key and the converted client key exchange parameter. Server node algorithm key for cross-protocol communication with the client. The invention improves the automation degree of communication between different cryptographic protocols.

Description

Encryption communication method, device, terminal equipment and storage medium
Technical Field
The present application relates to the field of communications technologies, and in particular, to an encrypted communication method, an encrypted communication device, a terminal device, and a storage medium.
Background
The national secret protocol is one of key technologies in national secret application, and is widely used in the application fields of Web, VPN, blockchain and the like. The national cipher TLCP (Trusted Logical Connection Protocol ), while generally similar to the SSL (Secure Socket Layer, secure sockets layer)/TLS (Transport Layer Security ) international protocol standard, differs in the cryptographic algorithm employed and in some details of the protocol and the international standard. Some servers only support the national cryptographic protocol, and some clients only support the international protocol, so that cryptographic protocol substitution is required.
Currently, the common practice of replacing the international cryptographic protocol with the national cryptographic protocol is to analyze the source code of the application of the decryption code, find out the cryptographic protocol algorithm used therein, and replace it with the national cryptographic algorithm one by one. For example, if the cryptographic protocol TLS is found to be used in the source code, then the algorithm modification needs to be replaced with the national cryptographic protocol TLCP.
However, international cryptographic protocols are already built in many cryptographic application systems, such as browsers, web servers, blockchain nodes, VPN software, etc., and to replace the international cryptographic protocols in these general-purpose software requires reading and parsing source codes, while these software are not necessarily all open source software, and cryptographic replacement for cryptographic applications requires modification of source codes, finding modification locations, and performing replacement modifications on source codes. Therefore, the automation degree of the general alternative cryptographic protocol method is relatively low.
Disclosure of Invention
The application mainly aims to provide an encryption communication method, an encryption communication device, terminal equipment and a storage medium, aiming at improving the degree of automation of communication among different cryptographic protocols.
In order to achieve the above object, the present application provides an encrypted communication method applied to a server, the encrypted communication method comprising:
receiving an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
and performing cross-protocol communication with the client based on the server-side algorithm key and the server-side node algorithm key through the cross-protocol node.
Optionally, before the step of receiving the access request initiated by the client through the preset cross-protocol node to obtain the converted client key exchange parameter and generate the server key exchange parameter, the method further includes:
generating a server-side signature key and a communication key;
the server signing key is sent to the client, key exchange is carried out with the client, and key exchange information is generated;
re-signing the communication key according to the server signing key to generate a server signing certificate;
the key exchange information and the server signing certificate are sent to a preset intermediate node, wherein the intermediate node is used for re-signing the server signing certificate according to the key exchange information to obtain the server signing certificate signed by the intermediate node and sending the server signing certificate to the server;
sending the server signing certificate signed by the intermediate node to the client, wherein the client re-signs the server signing certificate signed by the intermediate node to obtain a three-party signing certificate and sends the three-party signing certificate to the server;
and deploying the intermediate node as the cross-protocol node according to the three-party signed certificate.
Optionally, the step of receiving, by a preset cross-protocol node, an access request initiated by a client, and obtaining a converted client key exchange parameter includes:
when a client-side initiated access request is received, acquiring converted client-side handshake information based on the cross protocol node, wherein the cross protocol node is used for converting the client-side handshake information to obtain the converted client-side handshake information and sending the converted client-side handshake information to the server-side;
generating server side handshake information and sending the server side handshake information to the cross-protocol node; the cross-protocol node is used for converting the server handshake information to obtain the converted server handshake information and sending the converted server handshake information to a client;
based on the cross-protocol node, obtaining a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter, obtaining the converted client key exchange parameter and sending the converted client key exchange parameter to a server;
and generating the server-side key exchange parameters according to the converted client-side key exchange parameters.
Optionally, the step of performing, by the cross-protocol node, cross-protocol communication between clients based on the server-side algorithm key and the server-side node algorithm key includes:
Acquiring original server communication information;
encrypting the original server communication information according to the server algorithm key to obtain encrypted server communication information;
and sending the encrypted server communication information to the cross-protocol node, wherein the cross-protocol node is used for decrypting the encrypted server communication information according to the server node algorithm key to obtain node encrypted server communication information, and sending the node encrypted server communication information to the client.
Optionally, the step of performing, by the cross-protocol node, cross-protocol communication between clients based on the server-side algorithm key and the server-side node algorithm key further includes:
and when the client communication information encrypted by the node is received, decrypting the client communication information encrypted by the node according to the server algorithm key to obtain the original client communication information.
The application also provides an encryption communication method which is applied to the client, and comprises the following steps:
when an access request is initiated, generating a client key exchange parameter and sending the client key exchange parameter to a preset cross-protocol node;
Acquiring a converted server key exchange parameter based on the cross-protocol node, wherein the cross-protocol node is used for converting the server key exchange parameter to obtain the converted server key exchange parameter and sending the converted server key exchange parameter to the client, and the cross-protocol node is used for generating a client node algorithm key according to the client key exchange parameter;
generating a client algorithm key according to the client key exchange parameter and the converted server key exchange parameter;
and performing cross-protocol communication with the server based on the client algorithm key and the client node algorithm key through the cross-protocol node.
Optionally, the step of performing cross-protocol communication with the server through the cross-protocol node based on the client algorithm key and the client node algorithm key includes:
acquiring original client communication information;
encrypting the original client communication information according to the client algorithm key to obtain encrypted client communication information;
and sending the encrypted client communication information to the cross-protocol node, wherein the cross-protocol node is used for decrypting the encrypted client communication information according to the client node algorithm key to obtain the node encrypted client communication information, and sending the node encrypted client communication information to the server.
Optionally, the step of performing cross-protocol communication with the server through the cross-protocol node based on the client algorithm key and the client node algorithm key further includes:
and when the service end communication information encrypted by the node is received, decrypting the service end communication information encrypted by the node according to the client algorithm key to obtain the original service end communication information.
The embodiment of the application also provides an encryption communication device, which comprises:
the key parameter generation module receives an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
the parameter exchange sending module is used for generating a server key exchange parameter and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
the algorithm key generation module is used for generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
And the cross-protocol communication module is used for performing cross-protocol communication with the client through the cross-protocol node based on the server-side algorithm key and the server-side node algorithm key.
The embodiment of the application also provides a terminal device, which comprises a memory, a processor and an encrypted communication program stored in the memory and capable of running on the processor, wherein the encrypted communication program realizes the steps of the encrypted communication method when being executed by the processor.
The embodiment of the application also proposes a computer-readable storage medium on which an encrypted communication program is stored, which when executed by a processor implements the steps of the encrypted communication method as described above.
The encryption communication method, the device, the terminal equipment and the storage medium provided by the embodiment of the application are used for obtaining the converted client key exchange parameters by receiving the access request initiated by the client through the preset cross-protocol node, wherein the cross-protocol node is used for converting the client key exchange parameters to obtain the converted client key exchange parameters and sending the converted client key exchange parameters to the server; generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter; generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter; and performing cross-protocol communication with the client based on the server-side algorithm key and the server-side node algorithm key through the cross-protocol node. When the equipment only supporting the international cryptographic protocol communicates with the equipment of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
Drawings
FIG. 1 is a schematic diagram of functional modules of a terminal device to which an encryption communication apparatus of the present application belongs;
FIG. 2 is a flow chart of a first exemplary embodiment of an encrypted communication method according to the present application;
FIG. 3 is a schematic diagram of a certificate re-signing flow involved in the encryption communication method of the present application;
FIG. 4 is a schematic diagram of a cross-protocol communication flow diagram 1 according to the encryption communication method of the present application;
fig. 5 is a schematic diagram of a cross-protocol communication flow related to the encryption communication method of the present application.
The achievement of the objects, functional features and advantages of the present application will be further described with reference to the accompanying drawings, in conjunction with the embodiments.
Detailed Description
It should be understood that the specific embodiments described herein are for purposes of illustration only and are not intended to limit the scope of the application.
The main solutions of the embodiments of the present application are: receiving an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server; generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter; generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter; and performing cross-protocol communication with the client based on the server-side algorithm key and the server-side node algorithm key through the cross-protocol node. When the equipment only supporting the international cryptographic protocol communicates with the equipment of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
The embodiment of the application considers that the current common practice of replacing the international cryptographic protocol with the national cryptographic protocol is to analyze the source code of the application of the deciphering password, find out the cryptographic protocol algorithm used therein and replace the cryptographic protocol algorithm with the national cryptographic algorithm one by one. For example, if the cryptographic protocol TLS is found to be used in the source code, then the algorithm modification needs to be replaced with the national cryptographic protocol TLCP.
However, international cryptographic protocols are already built in many cryptographic application systems, such as browsers, web servers, blockchain nodes, VPN software, etc., and to replace the international cryptographic protocols in these general-purpose software requires reading and parsing source codes, while these software are not necessarily all open source software, and cryptographic replacement for cryptographic applications requires modification of source codes, finding modification locations, and performing replacement modifications on source codes. Therefore, the automation degree of the general alternative cryptographic protocol method is relatively low.
Based on this, the embodiment of the application proposes a solution, when the device only supporting the international cryptographic protocol communicates with the device of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
Specifically, referring to fig. 1, fig. 1 is a schematic diagram of functional modules of a terminal device to which the encryption communication apparatus of the present application belongs. The encryption communication device may be a device independent of the terminal device and capable of performing data processing, or may be carried on the terminal device in a form of hardware or software.
In this embodiment, the terminal device to which the encryption communication apparatus belongs includes at least an output module 110, a processor 120, a memory 130, and a communication module 140.
The memory 130 stores an operating system and an encrypted communication program, and when a client initiates an access request to a server, a handshake connection between the client and the server is established based on a preset cross-protocol node to obtain a server key exchange parameter and a client key exchange parameter; based on the cross-protocol node, establishing key parameter exchange connection between the client and the server according to the server key exchange parameter and the client key exchange parameter, and generating a server algorithm key, a client algorithm key and a node algorithm key to be stored in the memory 130; the output module 110 may be a display screen, a speaker, etc. The communication module 140 may include a WIFI module, a mobile communication module, a bluetooth module, and the like, and communicates with an external device or a server through the communication module 140.
Wherein the encrypted communication program in the memory 130, when executed by the processor, performs the steps of:
when an access request initiated by a client is received, obtaining a server key exchange parameter and a client key exchange parameter based on a preset cross-protocol node;
based on the cross-protocol node, generating a server algorithm key, a client algorithm key and a node algorithm key according to the server key exchange parameter and the client key exchange parameter;
based on the cross-protocol node, cross-protocol communication is performed between the client and the server through the server algorithm key, the client algorithm key and the node algorithm key.
Further, the encrypted communication program in the memory 130, when executed by the processor, further performs the steps of:
receiving an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
Generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
and performing cross-protocol communication with the client based on the server-side algorithm key and the server-side node algorithm key through the cross-protocol node.
Further, the encrypted communication program in the memory 130, when executed by the processor, further performs the steps of:
generating a server-side signature key and a communication key;
the server signing key is sent to the client, key exchange is carried out with the client, and key exchange information is generated;
re-signing the communication key according to the server signing key to generate a server signing certificate;
the key exchange information and the server signing certificate are sent to a preset intermediate node, wherein the intermediate node is used for re-signing the server signing certificate according to the key exchange information to obtain the server signing certificate signed by the intermediate node and sending the server signing certificate to the server;
sending the server signing certificate signed by the intermediate node to the client, wherein the client re-signs the server signing certificate signed by the intermediate node to obtain a three-party signing certificate and sends the three-party signing certificate to the server;
And deploying the intermediate node as the cross-protocol node according to the three-party signed certificate.
Further, the encrypted communication program in the memory 130, when executed by the processor, further performs the steps of:
when a client-side initiated access request is received, acquiring converted client-side handshake information based on the cross protocol node, wherein the cross protocol node is used for converting the client-side handshake information to obtain the converted client-side handshake information and sending the converted client-side handshake information to the server-side;
generating server side handshake information and sending the server side handshake information to the cross-protocol node; the cross-protocol node is used for converting the server handshake information to obtain the converted server handshake information and sending the converted server handshake information to a client;
based on the cross-protocol node, obtaining a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter, obtaining the converted client key exchange parameter and sending the converted client key exchange parameter to a server;
and generating the server-side key exchange parameters according to the converted client-side key exchange parameters.
Further, the encrypted communication program in the memory 130, when executed by the processor, further performs the steps of:
acquiring original server communication information;
encrypting the original server communication information according to the server algorithm key to obtain encrypted server communication information;
and sending the encrypted server communication information to the cross-protocol node, wherein the cross-protocol node is used for decrypting the encrypted server communication information according to the server node algorithm key to obtain node encrypted server communication information, and sending the node encrypted server communication information to the client.
Further, the encrypted communication program in the memory 130, when executed by the processor, further performs the steps of:
and when the client communication information encrypted by the node is received, decrypting the client communication information encrypted by the node according to the server algorithm key to obtain the original client communication information.
According to the scheme, when an access request initiated by a client is received, the server key exchange parameter and the client key exchange parameter are obtained based on the preset cross-protocol node; based on the cross-protocol node, generating a server algorithm key, a client algorithm key and a node algorithm key according to the server key exchange parameter and the client key exchange parameter; based on the cross-protocol node, cross-protocol communication is performed between the client and the server through the server algorithm key, the client algorithm key and the node algorithm key. When the equipment only supporting the international cryptographic protocol communicates with the equipment of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
The method embodiment of the application is proposed based on the above-mentioned terminal equipment architecture but not limited to the above-mentioned architecture.
Referring to fig. 2, fig. 2 is a flowchart illustrating a first exemplary embodiment of an encryption communication method according to the present application.
An embodiment of the present application provides an encrypted communication method, including:
step S10, receiving an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
cryptographic protocols generally refer to communication formats, steps agreed upon for performing activities related to cryptographic communication, such as key transfer, data transmission, or status information, control information exchange, etc., between cryptographic devices, between cryptographic managers and managed persons, and between cryptographic systems and served users, and prescribed cryptographic operation methods, key data used, etc. The most commonly used cryptographic protocol is SSL/TLS.
The national security SSL protocol (namely the TLCP protocol of the national standard GB/T) is one of key technologies in national security application, and is widely used in the application fields of Web, VPN, blockchain and the like. The TLCP protocol of the national cipher, while generally similar to the SSL/TLS international protocol standard, differs from the international standard in some details of the cryptographic algorithm and protocol employed. Some servers only support the national cryptographic protocol, and some clients only support the international protocol, so that cryptographic protocol substitution is required.
Currently, the common practice of replacing the international cryptographic protocol with the national cryptographic protocol is to analyze the source code of the application of the decryption code, find out the cryptographic protocol algorithm used therein, and replace it with the national cryptographic algorithm one by one. For example, if the cryptographic protocol TLS is found to be used in the source code, then the algorithm modification needs to be replaced with the national cryptographic protocol TLCP.
However, international cryptographic protocols are already built in many cryptographic application systems, such as browsers, web servers, blockchain nodes, VPN software, etc., and to replace the international cryptographic protocols in these general-purpose software requires reading and parsing source codes, while these software are not necessarily all open source software, and cryptographic replacement for cryptographic applications requires modification of source codes, finding modification locations, and performing replacement modifications on source codes. Therefore, the automation degree of the general alternative cryptographic protocol method is relatively low.
Therefore, this embodiment proposes that when only the device supporting the international cryptographic protocol communicates with the device supporting the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, where all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
Specifically, the cross-protocol node automatically converts the national cryptographic protocol and the fields into the protocols and the fields which can be identified by the original international cryptographic protocol software, and similarly, the cross-protocol node automatically converts the international protocol and the fields into the protocols and the fields which can be identified by the national cryptographic protocol software.
Further, the cross-protocol node can automatically identify international cryptographic protocol communication and decide whether to perform a conversion work of the national cryptographic protocol according to the policy. And can replace fields such as execution identifier, symmetric cipher, certificate, signature value, etc. in the information, realize the communication exchange of cross-protocol.
Specifically, the cross-protocol node may be a proxy server or a gateway server. By taking the cross-protocol node as the middle part of the client and the server, the information of the corresponding cryptographic protocol is converted, so that the client and the server can establish handshake connection only by sending handshake information corresponding to the cryptographic protocol, and then corresponding server key exchange parameters and client key exchange parameters are generated.
Step S20, generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
Step S30, generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
in order to enhance the security and convenience of subsequent communications between the server and the client, a customized set of algorithm keys needs to be established for subsequent communications.
Specifically, the server key exchange parameter is intercepted across protocol nodes (gateways), the server key exchange parameter is recorded to conform to the international protocol standard, and the converted server key exchange parameter is regenerated.
The client generates a client algorithm key, i.e. an international algorithm key, according to the converted client key exchange parameters, and the server generates a server algorithm key, i.e. a national key, according to the converted client key exchange parameters. The gateway generates encryption keys with the client and the server, namely an international algorithm encryption key and a national algorithm encryption key respectively.
And finally, according to the international algorithm key, the national encryption algorithm key and the international algorithm encryption key, the communication between the server and the client is carried out with the national encryption algorithm encryption key.
And generating corresponding algorithm keys, namely an international algorithm key and a national secret algorithm key, according to the converted server key exchange parameters and the client key exchange parameters. This approach allows the client and the server to communicate between different cryptographic protocols, improving the feasibility of cross-protocol communications, and this means that the gateway plays an important role in the encrypted communication process, providing an independent key generation mechanism. This may enhance the security of the communication so that the encryption key between the client and the server is not directly revealed or exposed to the other party.
It can be understood that, based on the cross-protocol node, the server key exchange parameter and the client key exchange parameter are automatically converted into the converted server key exchange parameter and the converted client key exchange parameter corresponding to the opposite protocol, the server and the client establish a key parameter exchange connection after receiving the converted parameter key of the opposite party, and the server and the client exchange the key parameters. And generating a server side algorithm key and a client side algorithm key for subsequent communications while generating corresponding node algorithm keys based on the cross-protocol nodes.
And step S40, performing cross-protocol communication with the client through the cross-protocol node based on the server algorithm key and the server node algorithm key.
Specifically, when the subsequent server communicates with the client, the communication message is correspondingly processed through the algorithm key of the three parties, so that the encrypted communication connection between the client and the server is established.
Step S41, obtaining original server communication information;
step S42, encrypting the original server communication information according to the server algorithm key to obtain encrypted server communication information;
Step S43, the encrypted service side communication information is sent to the cross-protocol node, wherein the cross-protocol node is used for decrypting the encrypted service side communication information according to the service side node algorithm key to obtain node encrypted service side communication information, and the node encrypted service side communication information is sent to the client.
And step S44, when the client communication information encrypted by the node is received, decrypting the client communication information encrypted by the node according to the server algorithm key to obtain the original client communication information.
Specifically, the client can encrypt the corresponding original client communication information directly through the client algorithm key, obtain the encrypted client communication information and then send the encrypted client communication information to the cross-protocol node; decrypting the encrypted client communication information through the server node algorithm key by the cross-protocol node to obtain node intermediate information; then encrypting the node intermediate information through a server node algorithm key to obtain the client communication information encrypted by the node, and sending the client communication information to a server; and finally, the server decrypts the client communication information encrypted by the corresponding node through the server key to obtain the original client communication information conforming to the password protocol of the server.
Specifically, the server can encrypt the corresponding original server communication information directly through the server algorithm key, obtain the encrypted server communication information and then send the encrypted server communication information to the cross-protocol node; decrypting the encrypted server communication information through a server node algorithm key by the cross-protocol node to obtain node intermediate information; then encrypting the node intermediate information through a client node algorithm key to obtain node encrypted server communication information, and sending the node encrypted server communication information to a client; and finally, the client decrypts the corresponding encrypted server communication information of the node through the client key to obtain the original server communication information conforming to the cryptographic protocol of the client.
It can be understood that the communication message is correspondingly processed through the algorithm key of the three parties, so that effective communication between the client and the server is established.
It can be appreciated that, compared with the existing general technical scheme, the encryption communication method provided in this embodiment has two technical advantages, namely, the source code is not required to be modified, and the working efficiency is improved. The proposal improves the efficiency by the automatic replacement of the cryptographic protocol of the cross-protocol nodes (gateway devices or VPNs) deployed on the network boundary; secondly, the safety and reliability are improved. The proposal does not modify the source code, so the original password application is not influenced, the new security problem is not introduced, and the gateway equipment re-signs the original certificate and operates in a trusted execution environment, thereby being capable of providing trusted service.
According to the encryption communication method provided by the embodiment of the application, the access request initiated by the client is received through the preset cross-protocol node to obtain the converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server; generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter; generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter; and performing cross-protocol communication with the client based on the server-side algorithm key and the server-side node algorithm key through the cross-protocol node. When the equipment only supporting the international cryptographic protocol communicates with the equipment of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
Based on the first embodiment, a second embodiment of the present application is proposed, which differs from the first embodiment in that: the step of receiving an access request initiated by a client through a preset cross-protocol node, obtaining a converted client key exchange parameter and generating a server key exchange parameter is supplemented, wherein the step may include:
in this embodiment, step S10 further includes, before the steps of receiving, by a preset cross-protocol node, an access request initiated by a client to obtain a converted client key exchange parameter and generate a server key exchange parameter:
step S01, generating a server-side signature key and a communication key;
step S02, the server signing key is sent to the client, key exchange is carried out with the client, and key exchange information is generated;
step S03, re-signing the communication key according to the server signing key to generate a server signing certificate;
step S04, the key exchange information and the server signing certificate are sent to a preset intermediate node, wherein the intermediate node is used for re-signing the server signing certificate according to the key exchange information to obtain the server signing certificate signed by the intermediate node and sending the server signing certificate to the server;
Step S05, sending the server signing certificate signed by the intermediate node to the client, wherein the client re-signs the server signing certificate signed by the intermediate node to obtain a three-party signing certificate and sends the three-party signing certificate to the server;
step S06, according to the three-party signed certificate, deploying the intermediate node as the cross-protocol node.
In order to realize an automatic replacement cryptographic protocol, a corresponding cross-protocol node needs to be established, and before a server side and a client side communicate, the corresponding certificate can be re-signed through exchanging a signing key, so that the re-signed certificate is trusted by both sides, and the cross-protocol node is established according to the re-signed certificate.
Specifically, this stage is a stage in which the proxy re-signs the generation of a trusted certificate by which a new intermediate proxy, i.e. a cross-protocol node, is established.
More specifically, proxy re-signing is a trusted working model consisting of at least three parties, the server, the client and the intermediate node (proxy).
The following process based on EIGamal (diffie-hellman, elGamal encryption algorithm is an asymmetric encryption algorithm based on diffie-hellman key exchange, which was proposed by tahler-germor in 1985) algorithm re-signing is exemplified by the specific encryption algorithm process of firstly declaring that there is a group G with G as generator in order of large prime number q, taking random number sk=a as private key, then the public key is pk=g a . Taking the random number r, the encrypted data is then (pk r ,g r ·m)=((g a ) r ,g r M), proxy re-signing key is calculated as rk A→B =sk B /sk A mod q=b/a mod q, and the process of re-signing is ((g) ar ) b/a ,m·gr)=(gb r ,m·g r )。
Further, the cross-protocol node is deployed on the basis of a Web server supporting the national-private TLCP protocol and a client supporting only the SSL/TLS protocol. As shown in fig. 2, the specific flow is as follows:
first, a CA (certificate authority) server of a TLCP national encryption server generates a server side signing key (g a A), the CA server of the SSL browser client generates a client signing key (g) b ,b);
Then, the TLCP national encryption server generates a communication key m, re-signs the communication key m using the server-side signing key, and the CA server signs the generated corresponding server-side signing certificate ((g) a ) r ,g r M), where r is a random factor.
Then, the CA server of the TLCP national encryption server and the CA server of the SSL browser client exchange key information by using DH protocol to obtain key exchange information (a, b).
The TLCP national encryption server then generates a re-signing key b/a from the key information and forwards the secret to the intermediate node (gateway/proxy).
After the intermediate node (gateway/proxy) verifies the server-side signed certificate, the server-side signed certificate is signed using the re-signing key b/a ((g) a ) r ,g r M) re-signing to obtain the node server signed certificate ((g) ar ) b/a ,m·g r )。
After verifying the signing certificate of the node server, the SSL browser client signs the signing certificate of the node server again to obtain a three-party signing certificate, and the specific process is ((g) ar ) b/a ,m·g r )=(g br ,m·g r )。
And according to the certificate signed by the three parties, deploying the intermediate node as an intermediate agent which is trusted by the two parties, namely a cross-protocol node, so that subsequent cross-protocol communication is realized.
It will be appreciated that this stage is a stage of re-signing the generation of trusted certificates and deployment of cross-protocol nodes. The signing keys generated by the protocols of the client and the server are used for generating a re-signing to generate a trusted certificate, namely, a three-party signing certificate, and then a corresponding cross-protocol node is established according to the certificate, so that the cross-protocol node can automatically convert national secret protocols and fields into protocols and fields which can be identified by original international secret protocol software, and the cross-protocol node can also automatically convert the international protocols and fields into protocols and fields which can be identified by the national secret protocol software.
Further, the cross-protocol node can automatically identify international cryptographic protocol communication and decide whether to perform a conversion work of the national cryptographic protocol according to the policy. And can replace fields such as execution identifier, symmetric cipher, certificate, signature value, etc. in the information, realize the communication exchange of cross-protocol.
In addition, verification of the signing certificate of the server and the signing certificate of the node server is needed to ensure that the used certificate is legal and effective. If the verification is not passed, i.e. the certificate is problematic or unauthorized, the certificate signed by the server is not re-signed. This helps to reduce potential security risks and prevent malicious certificate usage.
In addition, the falsification can be prevented, and the integrity of the certificate can be ensured by particularly verifying the signing certificate of the server and the signing certificate of the node server. If the certificate is tampered or damaged in the transmission process, verification will fail, so that the tampered certificate is prevented from being re-signed, and the reliability of the certificate is ensured.
It can be appreciated that signing the certificate on the server side and signing the certificate on the node server side can be verified, which is helpful to improve the security and reliability of the system, prevent potential certificate problems and security threats, and protect the integrity and reliability of the certificate ecosystem
The encryption communication method provided by the embodiment of the application generates a server-side signature key and a communication key; the server signing key is sent to the client, key exchange is carried out with the client, and key exchange information is generated; re-signing the communication key according to the server signing key to generate a server signing certificate; the key exchange information and the server signing certificate are sent to a preset intermediate node, wherein the intermediate node is used for re-signing the server signing certificate according to the key exchange information to obtain the server signing certificate signed by the intermediate node and sending the server signing certificate to the server; sending the server signing certificate signed by the intermediate node to the client, wherein the client re-signs the server signing certificate signed by the intermediate node to obtain a three-party signing certificate and sends the three-party signing certificate to the server; according to the signing certificate of the three parties, the intermediate node is deployed as the cross-protocol node, and according to the signing certificate of the three parties, the intermediate node is deployed as a trusted intermediate agent of the two parties, namely the cross-protocol node, so that the cross-protocol node can automatically convert the national cryptographic protocol and the fields into the protocols and the fields which can be identified by the original international cryptographic protocol software, and the cross-protocol node can also automatically convert the international protocol and the fields into the protocols and the fields which can be identified by the national cryptographic protocol software, thereby realizing the subsequent cross-protocol communication.
Based on the first embodiment, a third embodiment of the present application is proposed, which differs from the first embodiment in that: step S10, the step of receiving an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter and a generated server key exchange parameter is refined, wherein the refining step can comprise the following steps:
in this embodiment, step S10, the step of receiving, by a preset cross-protocol node, an access request initiated by a client, and obtaining a converted client key exchange parameter includes:
step S11, when a client initiates an access request, acquiring converted client handshake information based on the cross protocol node, wherein the cross protocol node is used for converting the client handshake information to obtain the converted client handshake information and sending the converted client handshake information to the server;
step S12, generating server side handshake information and sending the server side handshake information to the cross-protocol node; the cross-protocol node is used for converting the server handshake information to obtain the converted server handshake information and sending the converted server handshake information to a client;
Step S13, obtaining a converted client key exchange parameter based on the cross-protocol node, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to a server;
step S14, generating the server key exchange parameters according to the converted client key exchange parameters.
Specifically, taking the client as an SSL browser client and the server as a TLCP cryptographic server as examples, the handshake process is described. When the SSL browser Client initiates an access request to the TLCP national encryption server, client handshake information, such as a Client hello data packet, is acquired. The data packet contains a typical international cryptographic algorithm identifier and a field.
The data packet is received by the cross protocol node (gateway), the Client handshake information is analyzed, the field information is intercepted and reserved, the fields such as TLS VERSION, client Random, cipher suite and the like in the data packet are modified by the cross protocol node (gateway), the converted Client handshake information is obtained, the converted Client handshake information can be understood to meet national standards, and the data packet is repackaged and then sent to the server.
After receiving the handshake information of the client after conversion from the cross-protocol node (gateway), the cryptographic server replies the handshake information of the server, including a ServerHello data packet, to the client, and attaches a cryptographic double certificate.
Intercepting the handshake information of the server side by a cross-protocol node (gateway), and recording a protocol field; and modifying fields such as TLS VERSION, client Random, cipher suite and the like in the server handshake information data packet to enable the fields to conform to the international algorithm standard, obtaining converted server handshake information, repackaging the converted server handshake information, sending the converted server handshake information to the Client, and attaching own international algorithm certificate.
And the client receives the converted server handshake information from the cross-protocol node, verifies the international algorithm certificate in the converted server handshake information, and stores the random number if the international algorithm certificate is valid.
The client then sends the client key exchange parameters required for the key exchange to the cryptographic server.
Intercepting the client key exchange parameter by a cross-protocol node (gateway), recording the client key exchange parameter to enable the client key exchange parameter to conform to a national secret protocol, regenerating the converted client key exchange parameter, packaging and sending the client key exchange parameter to a national secret server.
The national cipher server receives the converted client key exchange parameters from the cross-protocol node (gateway), records the converted client key exchange parameters, and then sends the server key exchange parameters to the client and signs the client key exchange parameters.
It can be appreciated that the handshake connection is automatically established based on the cross-protocol node, and the exchange of key parameters is completed, so that the degree of automation of communication between different cryptographic protocols is improved.
According to the encryption communication method provided by the embodiment of the application, when an access request initiated by a client is received, the converted client handshake information is obtained based on the cross protocol node, wherein the cross protocol node is used for converting the client handshake information, so that the converted client handshake information is obtained and sent to the server; generating server side handshake information and sending the server side handshake information to the cross-protocol node; the cross-protocol node is used for converting the server handshake information to obtain the converted server handshake information and sending the converted server handshake information to a client; based on the cross-protocol node, obtaining a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter, obtaining the converted client key exchange parameter and sending the converted client key exchange parameter to a server; and generating the server key exchange parameter according to the converted client key exchange parameter, automatically establishing handshake connection based on the cross-protocol node, and completing the exchange of the key parameter, thereby improving the degree of automation of communication among different cryptographic protocols.
An embodiment of the present invention provides an encrypted communication method, including:
step S50, when an access request is initiated, generating a client key exchange parameter and sending the client key exchange parameter to a preset cross-protocol node;
the embodiment proposes that when the equipment only supporting the international cryptographic protocol communicates with the equipment of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
Specifically, the cross-protocol node automatically converts the national cryptographic protocol and the fields into the protocols and the fields which can be identified by the original international cryptographic protocol software, and similarly, the cross-protocol node automatically converts the international protocol and the fields into the protocols and the fields which can be identified by the national cryptographic protocol software.
Further, the cross-protocol node can automatically identify international cryptographic protocol communication and decide whether to perform a conversion work of the national cryptographic protocol according to the policy. And can replace fields such as execution identifier, symmetric cipher, certificate, signature value, etc. in the information, realize the communication exchange of cross-protocol.
Specifically, the cross-protocol node may be a proxy server or a gateway server. By taking the cross-protocol node as the middle part of the client and the server, the information of the corresponding cryptographic protocol is converted, so that the client and the server can establish handshake connection only by sending handshake information corresponding to the cryptographic protocol, and then corresponding server key exchange parameters and client key exchange parameters are generated.
Step S60, obtaining a converted server key exchange parameter based on the cross-protocol node, wherein the cross-protocol node is used for converting the server key exchange parameter to obtain the converted server key exchange parameter and sending the converted server key exchange parameter to the client, and the cross-protocol node is used for generating a client node algorithm key according to the client key exchange parameter;
Step S70, generating a client algorithm key according to the client key exchange parameter and the converted server key exchange parameter;
in order to enhance the security and convenience of subsequent communications between the server and the client, a customized set of algorithm keys needs to be established for subsequent communications.
Specifically, the server key exchange parameter is intercepted across protocol nodes (gateways), the server key exchange parameter is recorded to conform to the international protocol standard, and the converted server key exchange parameter is regenerated.
The client generates a client algorithm key, i.e. an international algorithm key, according to the converted client key exchange parameters, and the server generates a server algorithm key, i.e. a national key, according to the converted client key exchange parameters. The gateway generates encryption keys with the client and the server, namely an international algorithm encryption key and a national algorithm encryption key respectively.
And finally, according to the international algorithm key, the national encryption algorithm key and the international algorithm encryption key, the communication between the server and the client is carried out with the national encryption algorithm encryption key.
And generating corresponding algorithm keys, namely an international algorithm key and a national secret algorithm key, according to the converted server key exchange parameters and the client key exchange parameters. This approach allows the client and the server to communicate between different cryptographic protocols, improving the feasibility of cross-protocol communications, and this means that the gateway plays an important role in the encrypted communication process, providing an independent key generation mechanism. This may enhance the security of the communication so that the encryption key between the client and the server is not directly revealed or exposed to the other party.
It can be understood that, based on the cross-protocol node, the server key exchange parameter and the client key exchange parameter are automatically converted into the converted server key exchange parameter and the converted client key exchange parameter corresponding to the opposite protocol, the server and the client establish a key parameter exchange connection after receiving the converted parameter key of the opposite party, and the server and the client exchange the key parameters. And generating a server side algorithm key and a client side algorithm key for subsequent communications while generating corresponding node algorithm keys based on the cross-protocol nodes.
And step S80, performing cross-protocol communication with the server side through the cross-protocol node based on the client algorithm key and the client node algorithm key.
Specifically, when the subsequent server communicates with the client, the communication message is correspondingly processed through the algorithm key of the three parties, so that the encrypted communication connection between the client and the server is established.
Step S81, obtaining original client communication information;
step S82, encrypting the original client communication information according to the client algorithm key to obtain encrypted client communication information;
Step S83, sending the encrypted client communication information to the cross protocol node, where the cross protocol node is configured to decrypt the encrypted client communication information according to the client node algorithm key, encrypt the encrypted client communication information to obtain node encrypted client communication information, and send the node encrypted client communication information to the server;
and step S84, when the service side communication information encrypted by the node is received, decrypting the service side communication information encrypted by the node according to the client algorithm key to obtain the original service side communication information.
Specifically, the client can encrypt the corresponding original client communication information directly through the client algorithm key, obtain the encrypted client communication information and then send the encrypted client communication information to the cross-protocol node; decrypting the encrypted client communication information through the server node algorithm key by the cross-protocol node to obtain node intermediate information; then encrypting the node intermediate information through a server node algorithm key to obtain the client communication information encrypted by the node, and sending the client communication information to a server; and finally, the server decrypts the client communication information encrypted by the corresponding node through the server key to obtain the original client communication information conforming to the password protocol of the server.
Specifically, the server can encrypt the corresponding original server communication information directly through the server algorithm key, obtain the encrypted server communication information and then send the encrypted server communication information to the cross-protocol node; decrypting the encrypted server communication information through a server node algorithm key by the cross-protocol node to obtain node intermediate information; then encrypting the node intermediate information through a client node algorithm key to obtain node encrypted server communication information, and sending the node encrypted server communication information to a client; and finally, the client decrypts the corresponding encrypted server communication information of the node through the client key to obtain the original server communication information conforming to the cryptographic protocol of the client.
It can be understood that the communication message is correspondingly processed through the algorithm key of the three parties, so that effective communication between the client and the server is established.
It can be appreciated that, compared with the existing general technical scheme, the encryption communication method provided in this embodiment has two technical advantages, namely, the source code is not required to be modified, and the working efficiency is improved. The proposal improves the efficiency by the automatic replacement of the cryptographic protocol of the cross-protocol nodes (gateway devices or VPNs) deployed on the network boundary; secondly, the safety and reliability are improved. The proposal does not modify the source code, so the original password application is not influenced, the new security problem is not introduced, and the gateway equipment re-signs the original certificate and operates in a trusted execution environment, thereby being capable of providing trusted service.
For other content, reference may be made to the above embodiments, and no further description is given here.
According to the method, when equipment only supporting the international cryptographic protocol communicates with equipment of the national cryptographic protocol (for example, a client only supports the international protocol, and a server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
FIG. 4 is a schematic diagram of a cross-protocol communication flow diagram 1 according to the encryption communication method of the present application;
Fig. 5 is a schematic diagram of a cross-protocol communication flow related to the encryption communication method of the present application.
In addition, an embodiment of the present application further provides an encryption communication apparatus, including:
the key parameter generation module receives an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
the parameter exchange sending module is used for generating a server key exchange parameter and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
the algorithm key generation module is used for generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
and the cross-protocol communication module is used for performing cross-protocol communication with the client through the cross-protocol node based on the server-side algorithm key and the server-side node algorithm key.
The principle and implementation process of the encryption communication are implemented in this embodiment, please refer to the above embodiments, and the description is omitted herein.
In addition, the embodiment of the application also provides a terminal device, which comprises a memory, a processor and an encryption communication program stored on the memory and capable of running on the processor, wherein the encryption communication program realizes the steps of the encryption communication method when being executed by the processor.
Because the encryption communication program is executed by the processor and adopts all the technical schemes of all the embodiments, the encryption communication program at least has all the beneficial effects brought by all the technical schemes of all the embodiments and is not described in detail herein.
Furthermore, an embodiment of the present application also proposes a computer-readable storage medium having stored thereon an encrypted communication program which, when executed by a processor, implements the steps of the encrypted communication method as described above.
Because the encryption communication program is executed by the processor and adopts all the technical schemes of all the embodiments, the encryption communication program at least has all the beneficial effects brought by all the technical schemes of all the embodiments and is not described in detail herein.
Compared with the prior art, the encryption communication method, the device, the terminal equipment and the storage medium provided by the embodiment of the application are used for establishing handshake connection between the client and the server based on a preset cross-protocol node when the client initiates an access request to the server, so as to obtain a server key exchange parameter and a client key exchange parameter; based on the cross-protocol node, establishing key parameter exchange connection between the client and the server according to the server key exchange parameter and the client key exchange parameter, and generating a server algorithm key, a client algorithm key and a node algorithm key; and establishing the encrypted communication connection between the client and the server through the server algorithm key, the client algorithm key and the node algorithm key based on the cross-protocol node. When the equipment only supporting the international cryptographic protocol communicates with the equipment of the national cryptographic protocol (for example, the client only supports the international protocol, and the server only supports the national cryptographic protocol), a cross-protocol node is set, wherein all the messages of the international cryptographic protocol are automatically converted into messages corresponding to the national cryptographic protocol when passing through the cross-protocol node, and the messages of all the national cryptographic protocols are automatically converted into messages corresponding to the international cryptographic protocol when passing through the cross-protocol node.
It should be noted that, in this document, the terms "comprises," "comprising," or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or system. Without further limitation, an element defined by the phrase "comprising one … …" does not exclude the presence of other like elements in a process, method, article, or system that comprises the element.
The foregoing embodiment numbers of the present application are merely for the purpose of description, and do not represent the advantages or disadvantages of the embodiments.
From the above description of the embodiments, it will be clear to those skilled in the art that the above-described embodiment method may be implemented by means of software plus a necessary general hardware platform, but of course may also be implemented by means of hardware, but in many cases the former is a preferred embodiment. Based on such understanding, the technical solution of the present application may be embodied essentially or in a part contributing to the prior art in the form of a software product stored in a storage medium (e.g. ROM/RAM, magnetic disk, optical disk) as above, comprising instructions for causing a terminal device (which may be a mobile phone, a computer, a server, a controlled terminal, or a network device, etc.) to perform the method of each embodiment of the present application.
The foregoing description is only of the preferred embodiments of the present application, and is not intended to limit the scope of the application, but rather is intended to cover any equivalents of the structures or equivalent processes disclosed herein or in the alternative, which may be employed directly or indirectly in other related arts.

Claims (11)

1. An encrypted communication method, applied to a server, comprising:
receiving an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
generating a server key exchange parameter, and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
and performing cross-protocol communication with the client based on the server-side algorithm key and the server-side node algorithm key through the cross-protocol node.
2. The method for encrypted communication according to claim 1, wherein the steps of receiving the access request initiated by the client through the preset cross-protocol node, obtaining the converted client key exchange parameter and generating the server key exchange parameter further comprise:
generating a server-side signature key and a communication key;
the server signing key is sent to the client, key exchange is carried out with the client, and key exchange information is generated;
re-signing the communication key according to the server signing key to generate a server signing certificate;
the key exchange information and the server signing certificate are sent to a preset intermediate node, wherein the intermediate node is used for re-signing the server signing certificate according to the key exchange information to obtain the server signing certificate signed by the intermediate node and sending the server signing certificate to the server;
sending the server signing certificate signed by the intermediate node to the client, wherein the client re-signs the server signing certificate signed by the intermediate node to obtain a three-party signing certificate and sends the three-party signing certificate to the server;
And deploying the intermediate node as the cross-protocol node according to the three-party signed certificate.
3. The method for encrypted communication according to claim 1, wherein the step of receiving the access request initiated by the client through the preset cross-protocol node, and obtaining the transformed client key exchange parameter comprises:
when a client-side initiated access request is received, acquiring converted client-side handshake information based on the cross protocol node, wherein the cross protocol node is used for converting the client-side handshake information to obtain the converted client-side handshake information and sending the converted client-side handshake information to the server-side;
generating server side handshake information and sending the server side handshake information to the cross-protocol node; the cross-protocol node is used for converting the server handshake information to obtain the converted server handshake information and sending the converted server handshake information to a client;
based on the cross-protocol node, obtaining a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter, obtaining the converted client key exchange parameter and sending the converted client key exchange parameter to a server;
And generating the server-side key exchange parameters according to the converted client-side key exchange parameters.
4. The method according to claim 1, wherein the step of performing cross-protocol communication between clients by the cross-protocol node based on the server-side algorithm key and the server-side node algorithm key includes:
acquiring original server communication information;
encrypting the original server communication information according to the server algorithm key to obtain encrypted server communication information;
and sending the encrypted server communication information to the cross-protocol node, wherein the cross-protocol node is used for decrypting the encrypted server communication information according to the server node algorithm key to obtain node encrypted server communication information, and sending the node encrypted server communication information to the client.
5. The method according to claim 4, wherein the step of performing cross-protocol communication between clients by the cross-protocol node based on the server-side algorithm key and the server-side node algorithm key further comprises:
And when the client communication information encrypted by the node is received, decrypting the client communication information encrypted by the node according to the server algorithm key to obtain the original client communication information.
6. An encrypted communication method, applied to a client, comprising:
when an access request is initiated, generating a client key exchange parameter and sending the client key exchange parameter to a preset cross-protocol node;
acquiring a converted server key exchange parameter based on the cross-protocol node, wherein the cross-protocol node is used for converting the server key exchange parameter to obtain the converted server key exchange parameter and sending the converted server key exchange parameter to the client, and the cross-protocol node is used for generating a client node algorithm key according to the client key exchange parameter;
generating a client algorithm key according to the client key exchange parameter and the converted server key exchange parameter;
and performing cross-protocol communication with the server based on the client algorithm key and the client node algorithm key through the cross-protocol node.
7. The method according to claim 6, wherein the step of performing cross-protocol communication with the server through the cross-protocol node based on the client algorithm key and the client node algorithm key includes:
acquiring original client communication information;
encrypting the original client communication information according to the client algorithm key to obtain encrypted client communication information;
and sending the encrypted client communication information to the cross-protocol node, wherein the cross-protocol node is used for decrypting the encrypted client communication information according to the client node algorithm key to obtain the node encrypted client communication information, and sending the node encrypted client communication information to the server.
8. The method according to claim 7, wherein the step of performing cross-protocol communication with the server through the cross-protocol node based on the client algorithm key and the client node algorithm key further comprises:
and when the service end communication information encrypted by the node is received, decrypting the service end communication information encrypted by the node according to the client algorithm key to obtain the original service end communication information.
9. An encrypted communication apparatus, characterized in that the encrypted communication apparatus comprises:
the key parameter generation module receives an access request initiated by a client through a preset cross-protocol node to obtain a converted client key exchange parameter, wherein the cross-protocol node is used for converting the client key exchange parameter to obtain the converted client key exchange parameter and sending the converted client key exchange parameter to the server;
the parameter exchange sending module is used for generating a server key exchange parameter and sending the server key exchange parameter to the cross-protocol node, wherein the cross-protocol node is used for generating a server node algorithm key according to the server key exchange parameter;
the algorithm key generation module is used for generating a server algorithm key according to the server key exchange parameter and the converted client key exchange parameter;
and the cross-protocol communication module is used for performing cross-protocol communication with the client through the cross-protocol node based on the server-side algorithm key and the server-side node algorithm key.
10. A terminal device comprising a memory, a processor and an encrypted communication program stored on the memory and executable on the processor, which when executed by the processor, implements the steps of the encrypted communication method according to any one of claims 1-5.
11. A computer-readable storage medium, characterized in that the computer-readable storage medium has stored thereon an encrypted communication program which, when executed by a processor, implements the steps of the encrypted communication method according to any one of claims 1-5.
CN202311030083.4A 2023-08-15 2023-08-15 Encrypted communication method, device, terminal equipment and storage medium Pending CN117081802A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202311030083.4A CN117081802A (en) 2023-08-15 2023-08-15 Encrypted communication method, device, terminal equipment and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202311030083.4A CN117081802A (en) 2023-08-15 2023-08-15 Encrypted communication method, device, terminal equipment and storage medium

Publications (1)

Publication Number Publication Date
CN117081802A true CN117081802A (en) 2023-11-17

Family

ID=88703577

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202311030083.4A Pending CN117081802A (en) 2023-08-15 2023-08-15 Encrypted communication method, device, terminal equipment and storage medium

Country Status (1)

Country Link
CN (1) CN117081802A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN120853779A (en) * 2025-07-04 2025-10-28 上海市长宁区精神卫生中心(上海市长宁区西郊绿地医院) A psychiatric electronic medical record system and device based on national secret algorithm

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN120853779A (en) * 2025-07-04 2025-10-28 上海市长宁区精神卫生中心(上海市长宁区西郊绿地医院) A psychiatric electronic medical record system and device based on national secret algorithm

Similar Documents

Publication Publication Date Title
US11968302B1 (en) Method and system for pre-shared key (PSK) based secure communications with domain name system (DNS) authenticator
US12015721B1 (en) System and method for dynamic retrieval of certificates with remote lifecycle management
US10630489B2 (en) Apparatus and method for managing digital certificates
US10270601B2 (en) Providing forward secrecy in a terminating SSL/TLS connection proxy using ephemeral Diffie-Hellman key exchange
EP2115931B1 (en) AUTOMATED METHOD FOR SECURELY ESTABLISHING SIMPLE NETWORK MANAGEMENT PROTOCOL VERSION 3 (SNMPv3) AUTHENTICATION AND PRIVACY KEYS
CN114338844B (en) Cross-protocol communication method and device between client servers
US20090119504A1 (en) Intercepting and split-terminating authenticated communication connections
CN109302369A (en) A kind of data transmission method and device based on key authentication
EP3633949A1 (en) Method and system for performing ssl handshake
CN1507720A (en) Secure Data Transfer Link
CN1507733A (en) Establishment of Symmetric Key Using Public Key Encryption
CN101459506A (en) Cipher key negotiation method, system, customer terminal and server for cipher key negotiation
CN102932350B (en) A kind of method and apparatus of TLS scanning
EP1714422A1 (en) Establishing a secure context for communicating messages between computer systems
CN101325519A (en) Content auditing method, system and content auditing device based on security protocol
CN118174967A (en) Information verification method and related equipment
CN119652507B (en) A quantum-resistant national cryptographic SSL communication system and method
CN115001705B (en) Network protocol security improving method based on encryption equipment
WO2008095382A1 (en) A method, system and apparatus for establishing transport layer security connection
CN105991622A (en) Message authentication method and device
CN101827106A (en) DHCP safety communication method, device and system
CN116366262A (en) Double SSL certificate web server setting method and web service system
CN112332986A (en) Private encryption communication method and system based on authority control
CN113676468B (en) Three-party enhanced authentication system design method based on message verification technology
CN117375824A (en) A method for generating and verifying multi-factor authentication credentials

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination