[go: up one dir, main page]

WO2023109468A1 - Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel - Google Patents

Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel Download PDF

Info

Publication number
WO2023109468A1
WO2023109468A1 PCT/CN2022/134182 CN2022134182W WO2023109468A1 WO 2023109468 A1 WO2023109468 A1 WO 2023109468A1 CN 2022134182 W CN2022134182 W CN 2022134182W WO 2023109468 A1 WO2023109468 A1 WO 2023109468A1
Authority
WO
WIPO (PCT)
Prior art keywords
multicast
key
key distribution
group
information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2022/134182
Other languages
English (en)
Chinese (zh)
Inventor
陈银桃
马纳
章维
张高达
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Zhejiang Supcon Technology Co Ltd
Original Assignee
Zhejiang Supcon Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhejiang Supcon Technology Co Ltd filed Critical Zhejiang Supcon Technology Co Ltd
Publication of WO2023109468A1 publication Critical patent/WO2023109468A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/088Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3297Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02PCLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
    • Y02P90/00Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
    • Y02P90/02Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]

Definitions

  • the invention relates to the technical field of industrial information security, in particular to a method and system for distributing multicast communication keys for industrial controllers.
  • the control system has high requirements for real-time communication and reliability. Furthermore, the controller itself has limited computing resources, and usually cannot support security encryption protocols that require large computing power, such as TLS/DTLS protocols. On the other hand, traditional devices mostly use digital certificate-based public key encryption technology for identity authentication, and digital certificates are cumbersome and inconvenient in daily system maintenance.
  • the key distribution server uses the group member device ID to query the stored multicast group address and multicast group communication key of the group member, and further based on the multicast key request
  • the message, multicast group address, and multicast group communication key generate a multicast communication key distribution message and send it to the group members;
  • the key distribution server uses the group member device identifier to query the multicast group address of the group member and the multicast group communication key pre-stored in the key distribution server;
  • the key distribution server signs the multicast communication key distribution information by using the private key of the root certificate, and obtains the second signature information;
  • the group member stores the multicast communication key and the multicast group address in the multicast communication key distribution information whose verification result is correct.
  • the multicast key request information includes: random numbers of group members, device identifiers of group members, and time stamps of group members;
  • the group members are also used to verify the multicast communication key distribution message, and store the corresponding multicast communication key and multicast group address in the multicast communication key distribution message whose verification result is correct.
  • the group member stores the multicast communication key and the multicast group address in the multicast communication key distribution information whose verification result is correct.
  • the multicast key request information includes: group member random numbers, group member device identifiers, and group member time stamps.
  • the group member generates multicast key request information
  • the multicast communication key distribution information includes: group member random number, group member multicast group address, multicast communication key and key distribution server timestamp information;
  • the group members are also used to verify the multicast communication key distribution message, and store the corresponding multicast communication key and multicast group address in the multicast communication key distribution message whose verification result is correct.
  • the key distribution server uses the group member device ID to query the stored multicast group address of the group member and the multicast group communication key, and further based on the multicast key request message , multicast group address, and multicast group communication key to generate a multicast communication key distribution message and send it to group members, including:
  • the key distribution server receives the multicast key request message, and uses the private key of the root certificate of the key distribution server to decrypt the multicast key request message, and obtains the multicast key request information and the first signature information.
  • the group member stores the multicast communication key and the multicast group address in the multicast communication key distribution information whose verification result is correct.
  • the key distribution server generates multicast communication key distribution information based on the group member random number, multicast group address and multicast group communication key in the multicast key request information.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

La présente invention concerne un procédé et un système de distribution de clé de communication de multidiffusion pour un dispositif de commande industriel. Le procédé est appliqué entre un élément de groupe et un serveur de distribution de clé. Le procédé comprend les étapes suivantes : un élément de groupe génère des informations de demande de clé de multidiffusion, signe les informations de demande de clé de multidiffusion pour acquérir des premières informations de signature, génère également un message de demande de clé de multidiffusion d'après les informations de demande de clé de multidiffusion et les premières informations de signature, puis envoie le message de demande de clé de multidiffusion à un serveur de distribution de clé ; selon le message de demande de clé de multidiffusion et à l'aide d'un identifiant de dispositif de l'élément de groupe, le serveur de distribution de clé interroge une adresse de groupe de multidiffusion, qui est stockée sur le serveur de distribution de clé et à laquelle se situe l'élément de groupe, ainsi qu'une clé de communication de groupe de multidiffusion, puis génère un message de distribution de clé de communication de multidiffusion d'après le message de demande de clé de multidiffusion, l'adresse du groupe de multidiffusion et la clé de communication du groupe de multidiffusion, et envoie le message de distribution de clé de communication de multidiffusion à l'élément de groupe ; et l'élément de groupe vérifie le message de distribution de clé de communication de multidiffusion, puis stocke la clé de communication de multidiffusion et l'adresse du groupe de multidiffusion correspondantes dans le message de distribution de clé de communication de multidiffusion, un résultat de vérification indiquant que le message de distribution de clé de communication de multidiffusion est correct.
PCT/CN2022/134182 2021-12-17 2022-11-24 Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel Ceased WO2023109468A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202111555495.0A CN114422118B (zh) 2021-12-17 2021-12-17 一种工业控制器多播通讯密钥分发方法及系统
CN202111555495.0 2021-12-17

Publications (1)

Publication Number Publication Date
WO2023109468A1 true WO2023109468A1 (fr) 2023-06-22

Family

ID=81266725

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/134182 Ceased WO2023109468A1 (fr) 2021-12-17 2022-11-24 Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel

Country Status (2)

Country Link
CN (1) CN114422118B (fr)
WO (1) WO2023109468A1 (fr)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114422118B (zh) * 2021-12-17 2024-11-29 中控技术股份有限公司 一种工业控制器多播通讯密钥分发方法及系统
CN115460134A (zh) * 2022-09-05 2022-12-09 国网智能电网研究院有限公司 一种针对电力5g业务的mec数据多播转发方法
CN115567192B (zh) * 2022-09-29 2025-07-01 中电信量子科技有限公司 采用量子密钥分发实现组播数据透明加解密方法及系统

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6295361B1 (en) * 1998-06-30 2001-09-25 Sun Microsystems, Inc. Method and apparatus for multicast indication of group key change
CN1780413A (zh) * 2004-11-25 2006-05-31 华为技术有限公司 一种组播广播业务密钥控制方法
CN101155027A (zh) * 2006-09-27 2008-04-02 华为技术有限公司 密钥共享方法和系统
US20110016307A1 (en) * 2009-07-14 2011-01-20 Killian Thomas J Authorization, authentication and accounting protocols in multicast content distribution networks
CN108737430A (zh) * 2018-05-25 2018-11-02 全链通有限公司 区块链节点的加密通信方法和系统
CN114422118A (zh) * 2021-12-17 2022-04-29 浙江中控技术股份有限公司 一种工业控制器多播通讯密钥分发方法及系统

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4554264B2 (ja) * 2004-04-19 2010-09-29 エヌ・ティ・ティ・ソフトウェア株式会社 デジタル署名処理方法及びそのためのプログラム
US11368325B2 (en) * 2020-02-11 2022-06-21 Honeywell International Inc. System for communication on a network
CN112653551A (zh) * 2020-10-11 2021-04-13 黑龙江头雁科技有限公司 一种基于密钥分发组播的集中密钥管理方法
CN112350826A (zh) * 2021-01-08 2021-02-09 浙江中控技术股份有限公司 一种工业控制系统数字证书签发管理方法和加密通信方法

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6295361B1 (en) * 1998-06-30 2001-09-25 Sun Microsystems, Inc. Method and apparatus for multicast indication of group key change
CN1780413A (zh) * 2004-11-25 2006-05-31 华为技术有限公司 一种组播广播业务密钥控制方法
CN101155027A (zh) * 2006-09-27 2008-04-02 华为技术有限公司 密钥共享方法和系统
US20110016307A1 (en) * 2009-07-14 2011-01-20 Killian Thomas J Authorization, authentication and accounting protocols in multicast content distribution networks
CN108737430A (zh) * 2018-05-25 2018-11-02 全链通有限公司 区块链节点的加密通信方法和系统
CN114422118A (zh) * 2021-12-17 2022-04-29 浙江中控技术股份有限公司 一种工业控制器多播通讯密钥分发方法及系统

Also Published As

Publication number Publication date
CN114422118A (zh) 2022-04-29
CN114422118B (zh) 2024-11-29

Similar Documents

Publication Publication Date Title
WO2023109468A1 (fr) Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel
JP5288210B2 (ja) ネットワークでのユニキャスト鍵の管理方法およびマルチキャスト鍵の管理方法
CN103763356B (zh) 一种安全套接层连接的建立方法、装置及系统
CN113079215B (zh) 一种基于区块链的配电物联网无线安全接入方法
WO2017185999A1 (fr) Procédé, appareil et système de distribution et d'authentification de clés de chiffrement
PT1362444E (pt) Método para armazenamento e distribuição de chaves de cifra
JP2011160210A (ja) 通信端末及び通信システム
CN101420686A (zh) 基于密钥的工业无线网络安全通信实现方法
CN102238000A (zh) 加密通信方法、装置及系统
CN104601571A (zh) 一种租户与云服务器存储交互的数据加密系统及方法
CN103237038A (zh) 一种基于数字证书的双向入网认证方法
CN111447283A (zh) 一种用于实现配电站房系统信息安全的方法
CN108259469A (zh) 一种基于区块链的集群安全认证方法、一种节点及集群
US20210067329A1 (en) High availability secure network including dual mode authentication
CN109474432A (zh) 数字证书管理方法及设备
CN112311537A (zh) 基于区块链的设备接入认证系统及方法
CN101282208B (zh) 安全连接关联主密钥的更新方法和服务器及网络系统
Lai et al. A secure blockchain-based group mobility management scheme in VANETs
JP2016051921A (ja) 通信システム
CN104901940A (zh) 一种基于cpk标识认证的802.1x网络接入方法
US12418406B2 (en) Authentication using a decentralized and/or hybrid decentralized secure cryptographic key storage method
US7751569B2 (en) Group admission control apparatus and methods
CN101345723B (zh) 客户网关的管理认证方法和认证系统
CN113992418A (zh) 一种基于区块链技术的IoT设备管理方法
CN103312495B (zh) 一种成组ca的形成方法和装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22906219

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22906219

Country of ref document: EP

Kind code of ref document: A1