WO2023109468A1 - Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel - Google Patents
Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel Download PDFInfo
- Publication number
- WO2023109468A1 WO2023109468A1 PCT/CN2022/134182 CN2022134182W WO2023109468A1 WO 2023109468 A1 WO2023109468 A1 WO 2023109468A1 CN 2022134182 W CN2022134182 W CN 2022134182W WO 2023109468 A1 WO2023109468 A1 WO 2023109468A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- multicast
- key
- key distribution
- group
- information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/088—Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3297—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02P—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
- Y02P90/00—Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
- Y02P90/02—Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]
Definitions
- the invention relates to the technical field of industrial information security, in particular to a method and system for distributing multicast communication keys for industrial controllers.
- the control system has high requirements for real-time communication and reliability. Furthermore, the controller itself has limited computing resources, and usually cannot support security encryption protocols that require large computing power, such as TLS/DTLS protocols. On the other hand, traditional devices mostly use digital certificate-based public key encryption technology for identity authentication, and digital certificates are cumbersome and inconvenient in daily system maintenance.
- the key distribution server uses the group member device ID to query the stored multicast group address and multicast group communication key of the group member, and further based on the multicast key request
- the message, multicast group address, and multicast group communication key generate a multicast communication key distribution message and send it to the group members;
- the key distribution server uses the group member device identifier to query the multicast group address of the group member and the multicast group communication key pre-stored in the key distribution server;
- the key distribution server signs the multicast communication key distribution information by using the private key of the root certificate, and obtains the second signature information;
- the group member stores the multicast communication key and the multicast group address in the multicast communication key distribution information whose verification result is correct.
- the multicast key request information includes: random numbers of group members, device identifiers of group members, and time stamps of group members;
- the group members are also used to verify the multicast communication key distribution message, and store the corresponding multicast communication key and multicast group address in the multicast communication key distribution message whose verification result is correct.
- the group member stores the multicast communication key and the multicast group address in the multicast communication key distribution information whose verification result is correct.
- the multicast key request information includes: group member random numbers, group member device identifiers, and group member time stamps.
- the group member generates multicast key request information
- the multicast communication key distribution information includes: group member random number, group member multicast group address, multicast communication key and key distribution server timestamp information;
- the group members are also used to verify the multicast communication key distribution message, and store the corresponding multicast communication key and multicast group address in the multicast communication key distribution message whose verification result is correct.
- the key distribution server uses the group member device ID to query the stored multicast group address of the group member and the multicast group communication key, and further based on the multicast key request message , multicast group address, and multicast group communication key to generate a multicast communication key distribution message and send it to group members, including:
- the key distribution server receives the multicast key request message, and uses the private key of the root certificate of the key distribution server to decrypt the multicast key request message, and obtains the multicast key request information and the first signature information.
- the group member stores the multicast communication key and the multicast group address in the multicast communication key distribution information whose verification result is correct.
- the key distribution server generates multicast communication key distribution information based on the group member random number, multicast group address and multicast group communication key in the multicast key request information.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
La présente invention concerne un procédé et un système de distribution de clé de communication de multidiffusion pour un dispositif de commande industriel. Le procédé est appliqué entre un élément de groupe et un serveur de distribution de clé. Le procédé comprend les étapes suivantes : un élément de groupe génère des informations de demande de clé de multidiffusion, signe les informations de demande de clé de multidiffusion pour acquérir des premières informations de signature, génère également un message de demande de clé de multidiffusion d'après les informations de demande de clé de multidiffusion et les premières informations de signature, puis envoie le message de demande de clé de multidiffusion à un serveur de distribution de clé ; selon le message de demande de clé de multidiffusion et à l'aide d'un identifiant de dispositif de l'élément de groupe, le serveur de distribution de clé interroge une adresse de groupe de multidiffusion, qui est stockée sur le serveur de distribution de clé et à laquelle se situe l'élément de groupe, ainsi qu'une clé de communication de groupe de multidiffusion, puis génère un message de distribution de clé de communication de multidiffusion d'après le message de demande de clé de multidiffusion, l'adresse du groupe de multidiffusion et la clé de communication du groupe de multidiffusion, et envoie le message de distribution de clé de communication de multidiffusion à l'élément de groupe ; et l'élément de groupe vérifie le message de distribution de clé de communication de multidiffusion, puis stocke la clé de communication de multidiffusion et l'adresse du groupe de multidiffusion correspondantes dans le message de distribution de clé de communication de multidiffusion, un résultat de vérification indiquant que le message de distribution de clé de communication de multidiffusion est correct.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202111555495.0A CN114422118B (zh) | 2021-12-17 | 2021-12-17 | 一种工业控制器多播通讯密钥分发方法及系统 |
| CN202111555495.0 | 2021-12-17 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023109468A1 true WO2023109468A1 (fr) | 2023-06-22 |
Family
ID=81266725
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/134182 Ceased WO2023109468A1 (fr) | 2021-12-17 | 2022-11-24 | Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN114422118B (fr) |
| WO (1) | WO2023109468A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114422118B (zh) * | 2021-12-17 | 2024-11-29 | 中控技术股份有限公司 | 一种工业控制器多播通讯密钥分发方法及系统 |
| CN115460134A (zh) * | 2022-09-05 | 2022-12-09 | 国网智能电网研究院有限公司 | 一种针对电力5g业务的mec数据多播转发方法 |
| CN115567192B (zh) * | 2022-09-29 | 2025-07-01 | 中电信量子科技有限公司 | 采用量子密钥分发实现组播数据透明加解密方法及系统 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6295361B1 (en) * | 1998-06-30 | 2001-09-25 | Sun Microsystems, Inc. | Method and apparatus for multicast indication of group key change |
| CN1780413A (zh) * | 2004-11-25 | 2006-05-31 | 华为技术有限公司 | 一种组播广播业务密钥控制方法 |
| CN101155027A (zh) * | 2006-09-27 | 2008-04-02 | 华为技术有限公司 | 密钥共享方法和系统 |
| US20110016307A1 (en) * | 2009-07-14 | 2011-01-20 | Killian Thomas J | Authorization, authentication and accounting protocols in multicast content distribution networks |
| CN108737430A (zh) * | 2018-05-25 | 2018-11-02 | 全链通有限公司 | 区块链节点的加密通信方法和系统 |
| CN114422118A (zh) * | 2021-12-17 | 2022-04-29 | 浙江中控技术股份有限公司 | 一种工业控制器多播通讯密钥分发方法及系统 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP4554264B2 (ja) * | 2004-04-19 | 2010-09-29 | エヌ・ティ・ティ・ソフトウェア株式会社 | デジタル署名処理方法及びそのためのプログラム |
| US11368325B2 (en) * | 2020-02-11 | 2022-06-21 | Honeywell International Inc. | System for communication on a network |
| CN112653551A (zh) * | 2020-10-11 | 2021-04-13 | 黑龙江头雁科技有限公司 | 一种基于密钥分发组播的集中密钥管理方法 |
| CN112350826A (zh) * | 2021-01-08 | 2021-02-09 | 浙江中控技术股份有限公司 | 一种工业控制系统数字证书签发管理方法和加密通信方法 |
-
2021
- 2021-12-17 CN CN202111555495.0A patent/CN114422118B/zh active Active
-
2022
- 2022-11-24 WO PCT/CN2022/134182 patent/WO2023109468A1/fr not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6295361B1 (en) * | 1998-06-30 | 2001-09-25 | Sun Microsystems, Inc. | Method and apparatus for multicast indication of group key change |
| CN1780413A (zh) * | 2004-11-25 | 2006-05-31 | 华为技术有限公司 | 一种组播广播业务密钥控制方法 |
| CN101155027A (zh) * | 2006-09-27 | 2008-04-02 | 华为技术有限公司 | 密钥共享方法和系统 |
| US20110016307A1 (en) * | 2009-07-14 | 2011-01-20 | Killian Thomas J | Authorization, authentication and accounting protocols in multicast content distribution networks |
| CN108737430A (zh) * | 2018-05-25 | 2018-11-02 | 全链通有限公司 | 区块链节点的加密通信方法和系统 |
| CN114422118A (zh) * | 2021-12-17 | 2022-04-29 | 浙江中控技术股份有限公司 | 一种工业控制器多播通讯密钥分发方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN114422118A (zh) | 2022-04-29 |
| CN114422118B (zh) | 2024-11-29 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2023109468A1 (fr) | Procédé et système de distribution de clé de communication de multidiffusion pour dispositif de commande industriel | |
| JP5288210B2 (ja) | ネットワークでのユニキャスト鍵の管理方法およびマルチキャスト鍵の管理方法 | |
| CN103763356B (zh) | 一种安全套接层连接的建立方法、装置及系统 | |
| CN113079215B (zh) | 一种基于区块链的配电物联网无线安全接入方法 | |
| WO2017185999A1 (fr) | Procédé, appareil et système de distribution et d'authentification de clés de chiffrement | |
| PT1362444E (pt) | Método para armazenamento e distribuição de chaves de cifra | |
| JP2011160210A (ja) | 通信端末及び通信システム | |
| CN101420686A (zh) | 基于密钥的工业无线网络安全通信实现方法 | |
| CN102238000A (zh) | 加密通信方法、装置及系统 | |
| CN104601571A (zh) | 一种租户与云服务器存储交互的数据加密系统及方法 | |
| CN103237038A (zh) | 一种基于数字证书的双向入网认证方法 | |
| CN111447283A (zh) | 一种用于实现配电站房系统信息安全的方法 | |
| CN108259469A (zh) | 一种基于区块链的集群安全认证方法、一种节点及集群 | |
| US20210067329A1 (en) | High availability secure network including dual mode authentication | |
| CN109474432A (zh) | 数字证书管理方法及设备 | |
| CN112311537A (zh) | 基于区块链的设备接入认证系统及方法 | |
| CN101282208B (zh) | 安全连接关联主密钥的更新方法和服务器及网络系统 | |
| Lai et al. | A secure blockchain-based group mobility management scheme in VANETs | |
| JP2016051921A (ja) | 通信システム | |
| CN104901940A (zh) | 一种基于cpk标识认证的802.1x网络接入方法 | |
| US12418406B2 (en) | Authentication using a decentralized and/or hybrid decentralized secure cryptographic key storage method | |
| US7751569B2 (en) | Group admission control apparatus and methods | |
| CN101345723B (zh) | 客户网关的管理认证方法和认证系统 | |
| CN113992418A (zh) | 一种基于区块链技术的IoT设备管理方法 | |
| CN103312495B (zh) | 一种成组ca的形成方法和装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22906219 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22906219 Country of ref document: EP Kind code of ref document: A1 |