CN103685323A - Method for realizing intelligent home security networking based on intelligent cloud television gateway - Google Patents

Method for realizing intelligent home security networking based on intelligent cloud television gateway Download PDF

Info

Publication number
CN103685323A
CN103685323A CN201410001601.4A CN201410001601A CN103685323A CN 103685323 A CN103685323 A CN 103685323A CN 201410001601 A CN201410001601 A CN 201410001601A CN 103685323 A CN103685323 A CN 103685323A
Authority
CN
China
Prior art keywords
ukey
smart
gateway
smart home
identification
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201410001601.4A
Other languages
Chinese (zh)
Other versions
CN103685323B (en
Inventor
王雅哲
王瑜
韩振
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Institute of Information Engineering of CAS
Original Assignee
Institute of Information Engineering of CAS
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Institute of Information Engineering of CAS filed Critical Institute of Information Engineering of CAS
Priority to CN201410001601.4A priority Critical patent/CN103685323B/en
Publication of CN103685323A publication Critical patent/CN103685323A/en
Application granted granted Critical
Publication of CN103685323B publication Critical patent/CN103685323B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Small-Scale Networks (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种基于智能云电视网关的智能家居安全组网实现方法,其中智能家居内部网络指智能云电视作为用户智能家居的网关,与处于家庭内部的设备交互,并能控制家庭内部设备所组成的网络环境,也称为智能家居内网。智能云电视指已获得基于PKI数字证书体系的设备证书及可提供安全读写的安全存储区及带有ZigBee无线通信挂件,作为智能家居对公网通信的统一出口,也称为智能云电视网关。便携式UKey指具有设备间互通信模块和安全计算模块的设备。智能家居设备是指集成ZigBee无线通信挂件,具有检测、控制、处理数据等功能的家居设备。其中ZigBee无线通信挂件是指提供ZigBee通信和安全计算的可插拔模块。本发明具有安全性高、机密性强的优点,且通用性和用户体验性好。

Figure 201410001601

A smart home security network implementation method based on a smart cloud TV gateway, wherein the smart home internal network refers to the smart cloud TV as the gateway of the user's smart home, interacting with devices inside the home, and being able to control the network formed by the devices inside the home environment, also known as the smart home intranet. Smart cloud TV refers to a device certificate based on the PKI digital certificate system, a safe storage area that can provide safe reading and writing, and a ZigBee wireless communication pendant. . Portable UKey refers to a device with an inter-device communication module and a secure computing module. Smart home devices refer to home devices that integrate ZigBee wireless communication pendants and have functions such as detection, control, and data processing. The ZigBee wireless communication pendant refers to a pluggable module that provides ZigBee communication and secure computing. The invention has the advantages of high security and strong confidentiality, and good versatility and user experience.

Figure 201410001601

Description

A kind of Smart Home safe network implementation method based on intelligent cloud TV gateway
Technical field
The invention belongs to Smart Home internal network security field, be specifically related to a kind of Smart Home safe network implementation method based on intelligent cloud TV gateway.
Background technology
Along with the deep development of Internet of Things, the integration of three networks, cloud computing generation information technology, the intellectuality of terminal equipment, networking become the main trend of electron trade development, are expected to drive the upgrading of conventional industries.Intelligence cloud TV is the fusion of traditional tv and emerging technology, as a kind of safe and reliable information carrier, not only on audio-visual quality, obtain vast improvement and raising, and can allow user live to become more intelligent, therefore, intelligent cloud TV will become the most important part of each family life.Intelligence cloud TV has the features such as intellectuality, platform immobilization and large scale display, can be used as home gateway and the perfect adaptation of Smart Home controllable device of Smart Home, carry out the secure interactive of information with public network, thoroughly realize the intelligent management and control of family, solve user simultaneously service provider is distrusted to problem (being that the intelligent cloud TV gateway that each user meets at oneself to the access control of home intelligent equipment is processed), for user brings high-quality home services, enjoy.Yet, in the face of this emerging intelligent equipment of intelligent cloud TV, relevant research institution and business organization also do not have clear and definite proposition comparatively rationally perfect scheme solve intelligent cloud TV and as wired home, control gateway and realize home equipment access control safely; In simultaneously traditional Smart Home internal network design, the simple Zigbee protocol of general employing carries out group-net communication between home equipment, only adopt this agreement to carry out networking and have safety issue, as user's intelligent home device can be controlled by the home gateway of other families, home gateway networking exists the data message of illegality equipment access, transmission can be obtained by intercepting and capturing etc.In recent years, some enterprises have started exploration and realized home equipment networking under human factor are controlled, and to meet the demand of user to Smart Home fail safe, and obtain certain achievement, but still there is no complete head it off.
Summary of the invention
The technology of the present invention is dealt with problems: overcome the deficiencies in the prior art, a kind of Smart Home safe network implementation method based on intelligent cloud TV gateway be provided, have advantages of safe, confidentiality is strong, and versatility and user experience good.
The technology of the present invention solution: a kind of Smart Home safe network implementation method based on intelligent cloud TV gateway, wherein Smart Home internal network refers to that intelligent cloud TV is as the gateway of user's Smart Home, mutual with the equipment in household internal, and can control the network environment that household internal equipment forms, also referred to as Smart Home Intranet.Intelligence cloud TV refers to the secure storage areas that obtains the device certificate based on PKI digital certificate system and safe read-write can be provided and with ZigBee radio communication suspension member, the uniform outlet as Smart Home to public network communication, also referred to as intelligent cloud TV gateway.Portable UKey refers to a kind of by USB(USB (universal serial bus)) be directly connected, have cryptographic authorization functions, reliable small memory device at a high speed with the Micro-USB mouth of intelligent movable equipment, there is the equipment of equipment room intercommunication module and safety caculation module (as safety chip).Intelligent home device refers to integrated ZigBee radio communication suspension member, has the home equipment of the functions such as detection, control, deal with data.Wherein ZigBee radio communication suspension member refers to the pluggable module that ZigBee communication and safety compute (as safety chip) are provided.
Briefly introduce the basic thought of this programme, the present invention has drawn the advantage of existing solution, and specifically, technical solution of the present invention comprises following several aspect:
Aspect one: in view of user wants oneself home equipment of Remote Visit and Control, be required to be user " key " of opening door is provided, by intelligent cloud TV gateway to UKey initialization, make UKey obtain the digital certificate of the demarcation UKey identity based on PKI certificate system, " key " (safety of signing and issuing of intelligent cloud TV gateway enter license voucher) of opening door and PKI and the sign of intelligent cloud TV gateway, thereby set up the safe and orderly mechanism of permitting the entrance that user accesses oneself Smart Home, become the important safe barrier of Smart Home secure access.
Aspect two: realize the initialization to intelligent home device by obtaining digital certificate UKey, intelligent home device the is obtained credible networking voucher be responsible for signing and issuing by UKey and the PKI that guarantees the intelligent cloud TV gateway of networking information confidentiality, for the fail safe, the reliability that strengthen based on the networking of traditional Z igBee protocol devices, establish solid foundation, guaranteed the legitimacy of networking home equipment.
Aspect three: for fear of the intelligent cloud TV gateway of illegal home equipment access user, steal subscriber household private information, the credible networking voucher that intelligent home device issues by UKey and intelligent cloud TV gateway PKI, realize the mutual trust checking networking with intelligent cloud TV gateway, and consult to obtain the secret key of symmetry of secure communication with intelligent cloud TV gateway, build safety permission mechanism and Intranet house security communication mechanism that intelligent cloud TV gateway is received intelligent home device.
Aspect four: the secret key of communicating by letter of consulting with intelligent home device by intelligent cloud TV gateway, realize both sides' secure communication, prevent that go-between from illegally obtaining family's private data, guarantee confidentiality, the integrality of family data information, further promote the fail safe of the total system of Smart Home.
The present invention compared with prior art, has following remarkable advantage:
User experience is good, versatility, safe, confidentiality is strong.Because the present invention has adopted the Implementation Modes of safe and portable UKey, there is fabulous user-operable, applicable to general intelligent home device; Adopt two-layer voucher technology and symmetrical secret key coded communication technology based on PKI public key cryptography system simultaneously, there is extremely strong confidentiality, the anti-property denied, so user experience is good, versatility, safe, confidentiality is strong.
Accompanying drawing explanation
Fig. 1 the invention process overall framework;
The flow chart of Fig. 2 intelligence cloud TV gateway initialization UKey;
The flow chart of Fig. 3 UKey initialization intelligent home device;
The flow chart of Fig. 4 intelligence cloud TV gateway and intelligent home device mutual trust checking networking;
The flow chart of Fig. 5 intelligence cloud TV gateway and intelligent home device secure communication.
Embodiment
The present invention, by intelligent cloud TV and portable safety UKey equipment, on traditional Z igBee protocol basis, adopts two-layer voucher and symmetrical secret key communication encryption based on PKI public key cryptography system, sets up Smart Home internal network security service mechanism.This programme is by the two-layer voucher technology based on PKI public key cryptography system, realize the secret key of communicating by letter between the identity map binding of user's intelligent home device and oneself intelligent cloud TV gateway and consulting device, the intelligent home device that guarantees user can only, by oneself intelligent cloud TV gateway institute management and control, improve the personal secrets of subscriber household equipment; By symmetrical secret key coded communication information, guarantee to transmit between household equipment confidentiality, the integrality of data simultaneously, promote the coefficient of safety of intelligent domestic system.Its core is to set up the security service mechanism of Smart Home internal network, forms the controlled Smart Home of secure and trusted, promotes the sound development of Smart Home industry.
For making object of the present invention, advantage and technical scheme clearer, by following concrete, implement, and by reference to the accompanying drawings 1, the present invention is described in more detail.
The General Implementing framework of this scheme has been described on the whole for Fig. 1, in short, the one, it is a kind of by USB(USB (universal serial bus) that user uses UKey(UKey of the present invention to refer to first) be directly connected, have the memory device of cryptographic authorization functions with the Micro-USB mouth of intelligent movable equipment) time, UKey need be inserted on the ZigBee radio communication suspension member interface of intelligent cloud TV gateway TV, by the curing Smart Home App client certificate Cert of UKey app, the legal credibility of the upper prepackage of checking TV App.After if App checking is credible, App starts PIN(full name Personal Identification Number, is called for short PIN, is exactly the individual recognition code of UKey) interface is set, user successfully arranges after the PIN code of UKey, and public private key pair, TV that UKey generates self sign and issue the security credence Ticket that enters uKey, TV generates the secret key K of outer Network Communication outNet, TV PKI K tV (pub)with sign ID tV, simultaneously intelligent cloud TV gateway obtains the PKI K of UKey uKey (pub)with sign ID uKeythereby, complete the initial work to UKey; The 2nd, user uses UKey to insert intelligent home device D, and intelligent home device D can obtain from UKey the PKI K of intelligent cloud TV gateway tV (pub)with sign ID tVand obtain the credible networking voucher Ticket signed and issued by UKey dthereby, complete the initial work to intelligent home device; The 3rd, user's intelligent home device D completes after initial work, according to credible networking voucher Ticket dwith intelligent cloud TV gateway PKI K tV (pub), independently complete with intelligent cloud TV gateway secure and trusted networking and consult both sides' the secret key of communication encryption
Figure BDA0000452557620000031
realize the identity map binding of user's intelligent home device and oneself intelligent cloud TV gateway; The 4th, user's intelligence cloud TV gateway is by the secret key of communication encryption
Figure BDA0000452557620000032
the confidentiality of realization to the security control of intelligent home device and assurance intelligent home device transmission information.Mainly comprise tetrameric content below.
One, the implementation method of intelligent cloud TV gateway initialization UKey
User wants oneself home equipment of Remote Visit and Control, is required to be user " key " of opening door is provided, and the UKey initialization of user being carried by intelligent cloud TV gateway, can make UKey acquisition enter and permit voucher Ticket uKeyand for the initialization of intelligent home device lays the foundation, below in conjunction with accompanying drawing 2, specifically describe its implementation:
(1) when user uses UKey first, UKey is inserted on the ZigBee radio communication suspension member interface of intelligent cloud TV gateway TV, by the curing Smart Home App client certificate Cert of UKey app, the legal credibility (this legitimate verification principle is) of the upper prepackage of checking TV App, after App checking is credible, UKey and intelligent cloud TV gateway TV set up safe trusting relationship by App;
(2) UKey and intelligent cloud TV gateway TV successfully set up safe trusting relationship, and the Smart Home App client on TV ejects PIN code interface is set, and user successfully arranges after PIN code, and UKey obtains PIN code by App, and then UKey generates public private key pair K uKey (pub)and K uKey (pri);
(3) UKey is by self identification ID uKeywith PKI K uKey (pub)send intelligent cloud TV gateway TV to;
(4) intelligent cloud TV gateway TV receives UKey sign ID uKeywith PKI K uKey (pub)after, rise time stamp TS tVwith the secret key K of outer Network Communication outNet, adopt hash algorithm (as SHA1, SHA256) to calculate ID tV, ID uKeyand TS tVcryptographic Hash H=Hash (ID tV|| ID uKey|| TS tV), use intelligent cloud TV gateway TV private key K tV (pri)private key is encrypted cryptographic Hash H, forms intelligent cloud TV gateway TV signature S TV = Sign [ Hash ( ID TV | | ID UKey | | TS TV ) ] K TV ( pri ) ;
(5) intelligent cloud TV gateway TV is used its PKI K tV (pub)to UKey sign ID uKeywith time stamp T S tVencrypt, form TV and use its K tV (pub)the identification information ciphertext of encrypting
Figure BDA0000452557620000042
(6) the intelligent cloud TV gateway TV S that will sign tVwith identification information ciphertext
Figure BDA0000452557620000043
as the license voucher of entering Ticket UKey = Sign [ Hash ( ID TV | | ID UKey | | TS TV ) ] K TV ( pri ) | | Enc [ ID UKey | | TS TV ] K TV ( pub ) , License voucher Ticket will enter uKey, TV PKI K tV (pub), the secret key K of outer Network Communication outNetbe handed down to UKey, simultaneously by the sign ID of UKey uKeywith PKI K tV (pub)as the important record of UKey, be stored in the secure storage areas of TV;
(7) UKey accepts TV and transmits information, uses and obtains PIN code to its private key K uKey (pri)with the secret key K of outer Network Communication outNetbe encrypted respectively protection, form private key ciphertext Enc[K uKey (pri)] pINwith the secret key ciphertext of outer Network Communication Enc[K outNet] pIN;
(8) UKey is by self identification ID uKeywith other hardware informations (as memory block capacity and computing chip sign etc.), generate PIN code and protect secret key K uKey (EncPin)(this secret key dynamic operation in UKey produces and does not preserve, and has strengthened the fail safe of UKey), and by this secret key K uKey (EncPin)encrypt PIN code, form PIN code ciphertext
Figure BDA0000452557620000045
(9) UKey will enter and permit voucher Ticket uKey, TV PKI K tV (pub), PIN code ciphertext
Figure BDA0000452557620000051
the secret key ciphertext of outer Network Communication Enc[K outNet] pIN, self PKI K uKey (pub)with private key ciphertext Enc[K uKey (pri)] pINas important record storage, the initial work of UKey completes.
The successful realization of this process, sets up the safe and orderly mechanism of permitting the entrance that user accesses oneself Smart Home, becomes the important safe barrier of Smart Home secure access.
Two, the implementation method of UKey initialization intelligent home device
In intelligent home device networking process, to guarantee that intelligent home device D can only be identified by oneself intelligent cloud TV gateway TV of user, to guarantee that this process is safe and reliable simultaneously, here adopt UKey to meet above-mentioned security requirement to the initialization of intelligent home device, UKey after user uses initially inserts intelligent home device D, and intelligent home device D can obtain from UKey the PKI K of intelligent cloud TV tV (pub)with the credible networking voucher Ticket being signed and issued by UKey d, below in conjunction with accompanying drawing 3, specifically describe its implementation:
(1) user is inserted in the UKey after initial on the ZigBee radio communication suspension member interface of intelligent home device D, after intelligent home device D identification UKey, by the sign ID of himself dsend UKey to;
(2) UKey receives the sign ID of home equipment D d, generate random number N uKey, adopt hash algorithm (as SHA1, SHA256) to calculate ID d, ID uKeyand N uKeycryptographic Hash H=Hash (ID uKey|| ID d|| N uKey);
(3) UKey is by self identification ID uKeywith other hardware informations (as memory block capacity and computing chip sign etc.), generate PIN code and protect secret key K uKey (EncPin), and by this secret key K uKey (EncPin)the PIN code ciphertext of deciphering UKey storage Enc [ PIN ] K UKey ( EncPin ) , Obtain PIN code;
(4) UKey is deciphered and is obtained the UKey private key K being protected by PIN code in memory block by PIN code uKey (pri), and with obtaining private key K uKey (pri)(2) step cryptographic Hash is encrypted, form UKey signature S UKey = Sign [ Hash ( ID UKey | | ID D | | N UKey ) ] K UKey ( pri ) ;
(5) UKey is used the PKI K of intelligent cloud TV gateway tV (pub)to device identification ID dand random number N uKeyencrypt, form UKey and use K tV (pub)the identification information ciphertext of encrypting
Figure BDA0000452557620000054
(6) the UKey S that will sign uKey, identification information ciphertext
Figure BDA0000452557620000055
with the license voucher Ticket that enters uKey, as networking voucher Ticket D = Sign [ Hash ( ID UKey | | ID D | | N UKey ) ] K UKey ( pri ) | | Enc [ ID D | | N UKey ] K TV ( pub ) | | Ticket UKey Be handed down to intelligent home device D, intelligent home device D is by this credible networking voucher Ticket dstorage, the initial work of intelligent home device D completes.
The successful realization of this process, has established solid foundation for the fail safe, the reliability that strengthen based on the networking of traditional Z igBee protocol devices, has guaranteed the legitimacy of networking home equipment.
Three, the implementation method of intelligent cloud TV gateway and intelligent home device mutual trust checking networking
After intelligent home device D initialization completes, mainly by obtaining believable networking voucher Ticket dwith intelligent cloud TV gateway PKI K tV (pub), independently carry out secure and trusted networking and consult both sides' the secret key of communication encryption with intelligent cloud TV gateway realize the identity map binding of user's intelligent home device and oneself intelligent cloud TV gateway, below in conjunction with accompanying drawing 4, specifically describe its implementation:
(1) after intelligent home device D initialization completes, generate random number N D, use this random number N dto device identification ID dwith equipment network voucher Ticket dencrypt, form networking voucher ciphertext
Figure BDA0000452557620000062
then use intelligent cloud TV gateway PKI K tV (pub)to N dencrypt, form random number ciphertext finally using the subsidiary networking voucher ciphertext of random number ciphertext as equipment network broadcast message
Figure BDA0000452557620000064
zigBee communication module by intelligent home device D is broadcasted;
(2) intelligent cloud TV gateway TV receives after the networking information of intelligent home device D broadcast, uses its private key K tV (pri)decrypted random is counted ciphertext, obtains random number N d, then use N ddeciphering networking voucher ciphertext, equipment sign ID dwith equipment network voucher Ticket d, finally verify networking voucher Ticket dlegitimacy, intelligent cloud TV gateway is used UKey PKI K uKey (pub)the signature of checking UKey obtain cryptographic Hash H=Hash (ID uKey|| ID d|| N uKey), and with intelligent cloud TV gateway private key K tV (pri)deciphering is used K by UKey tV (pub)the identification information ciphertext of encrypting
Figure BDA0000452557620000066
equipment sign ID drandom number N with UKey generation uKey, and from its safe storage, obtain UKey sign ID uKey, adopt identical hash algorithm (as SHA1, SHA256) the calculating ID that signs with UKey d, N uKeyand ID uKeycryptographic Hash H 1=Hash (ID uKey|| ID d|| N uKey), compare cryptographic Hash H and H 1whether equate, if both are not identical, show that UKey is undesired, networking voucher Ticket dillegal, TV stops next step work; If both are identical, show that UKey is normal, TV is used its PKI K tV (pub)certifying signature
Figure BDA0000452557620000067
obtain cryptographic Hash H=Hash (ID tV|| ID uKey|| TS tV), and with its private key K tV (pri)deciphering is by K tV (pub)the identification information ciphertext of encrypting
Figure BDA0000452557620000068
obtain UKey sign ID uKeytime stamp T S with TV generation tV, adopt identical hash algorithm (as SHA1, SHA256) the calculating ID that signs with TV tV, ID uKeyand TS tVcryptographic Hash H 1=Hash (ID tV|| ID uKey|| TS tV), compare cryptographic Hash H and H 1whether equate, if both are not identical, show that TV signature is forged, networking voucher Ticket dillegal, TV stops next step work; If both are identical, show that TV is normal, networking voucher Ticket dchecking legitimacy, is presented at equipment D information the networking equipment list of intelligent cloud TV gateway; If other legal intelligent home device D in subscriber household .receive after intelligent home device D broadcast message, will, based on Zigbee protocol as routing node, forward this information of broadcast; If illegal intelligent home device D in user's wired home *receive after intelligent home device D broadcast message, cannot obtain by N dthe particular content of enciphered data and initiate man-in-the-middle attack to TV; If intelligent cloud TV gateway requires networking to possess high security and ageing, can control checking networking voucher Ticket dnumber of times and the time stamp T S of this voucher tVrealize, i.e. equipment network voucher Ticket din N dhave uniqueness, the proving time of the voucher of networking simultaneously can not surpass the certain hour starting from timestamp;
(3) user selects a certain equipment D(in home equipment networking list in intelligent cloud TV gateway TV to operate as added), intelligent cloud TV gateway produces Traffic encryption key(TEK) at random for this equipment D
Figure BDA0000452557620000071
and by the sign ID of equipment d, networking voucher Ticket dand Traffic encryption key(TEK) as an equipment records, be stored in its secure storage areas;
(4) intelligent cloud TV gateway is used (2) step to obtain random number N d+ 1 couple of device identification ID dand Traffic encryption key(TEK)
Figure BDA0000452557620000073
encrypt, form the secret key ciphertext of communication
Figure BDA0000452557620000074
by this ciphertext attendant equipment sign ID dby its ZigBee communication module, broadcast;
(5) intelligent home device D receives after TV broadcast data, uses its (1) step to generate random number N dthe sign ID of the secret key ciphertext of+1 decrypt communication equipment dwith the secret key of communication encryption
Figure BDA0000452557620000075
checking receives the consistency of device identification and deciphering equipment sign, if both verify unanimously, by the secret key of communication encryption
Figure BDA0000452557620000076
networking voucher Ticket d, intelligent cloud TV gateway PKI K tV (pub)as a record, preserve; If both verify inconsistent, intelligent home device D repeats (1) step, if carry out M(M>=1) inferior, the sign ID of acquisition dobtain sign ID with deciphering dstill consistent, quit work.If legal intelligent home device D receives after TV broadcast message in subscriber household, by the wireless network protocol based on ZigBee(low speed short-distance transmission, the low-power consumption of an IEEE802.15.4 standard territory fidonetFido) agreement, as routing node, forwards this information of broadcast; If illegal intelligent home device D in subscriber household *receive after TV broadcast message, cannot obtain by N dthe particular content of enciphered data, initiates man-in-the-middle attack to intelligent home device D.
The successful execution of this process, intelligent home device and intelligent cloud TV gateway complete mutual trust checking networking and consult the secret key of symmetry of both sides' secure communication, build safety permission mechanism and Intranet house security communication mechanism that intelligent cloud TV gateway is received intelligent home device.
Four, the implementation method of intelligent cloud TV gateway and intelligent home device secure communication
Intelligence cloud TV gateway receives after the remote control commands of intelligent home device D, uses the secret key K of outer Network Communication of its storage outNet(this K outNetcorresponding one by one with UKey) this equipment control command of deciphering acquisition, then by the secret key of this equipment D communication encryption
Figure BDA0000452557620000077
complete and intelligent home device between the safe access control of information, below in conjunction with accompanying drawing 5, specifically describe its implementations:
(1) intelligent cloud TV gateway TV receive intelligent home device D remote control commands (this command format:
Figure BDA0000452557620000081
use UKey sign ID in intelligent cloud TV gateway secure storage areas uKeythe corresponding secret key K of outer Network Communication outNetto ciphertext instruction
Figure BDA0000452557620000082
be decrypted, obtain the sign ID of this equipment dwith control command cmd;
(2) Intelligent television terminal gateway TV is used Traffic encryption key(TEK) corresponding to home equipment D in its secure storage areas
Figure BDA0000452557620000083
to device identification ID dencrypt with control command cmd, forming device D Intranet is encrypted control command the Intranet generating is encrypted to control command attendant equipment sign ID d, the ZigBee-network module by intelligent cloud TV gateway is by this control information < < ID D | | Enc [ ID D | | cmd ] K D InNet > > Broadcast;
(3) intelligent home device D receives after the information of intelligent cloud TV gateway TV broadcast, with the secret key of communication encryption of its storage
Figure BDA0000452557620000086
to encrypting control command
Figure BDA0000452557620000087
be decrypted, obtain control command cmd and sign ID d, checking obtains sign ID dwhether consistent with self identification, if checking is consistent, home equipment D carries out these data of data data(data after the execution that this control command cmd obtains this order and comprises obtaining information after the exectorial state of home equipment or home equipment fill order, as the humiture value information of Intelligent electric lamp switch state, intelligent temperature and humidity equipment); If verify inconsistently, home equipment D does not do any operation.If legal intelligent home device D receives after TV broadcast message in subscriber household, will, based on Zigbee protocol as routing node, forward this information of broadcast; If illegal intelligent home device D in subscriber household *receive after TV broadcast message, cannot obtain the particular content of encrypted instruction and initiate man-in-the-middle attack to D;
(4) intelligent home device D obtains data Data and intelligent home device D sign ID by instruction successful execution d, with the secret key of intelligent home device D communication encryption
Figure BDA0000452557620000088
encrypt, form enciphered data d is by subsidiary its sign of enciphered data ID das return data zigBee communication module by D is broadcasted;
(5) intelligent cloud TV gateway TV receives the return data of D broadcast after, utilize equipment sign ID dsearch Traffic encryption key(TEK) corresponding to home equipment D in secure storage areas and use decrypt encrypted data
Figure BDA00004525576200000814
obtain the device identification ID encrypting dwith executing data data, the sign ID that checking directly obtains dobtain sign ID with deciphering dwhether consistent, if checking is consistent, use UKey sign ID in (1) step uKeythe corresponding secret key K of outer Network Communication outNetto sign ID dencrypt with data data, form outer net and encrypt execution result
Figure BDA00004525576200000815
and outer net is encrypted to the subsidiary UKey sign of execution result ID uKeyas partial data record
Figure BDA00004525576200000816
send to remote control terminal; If verify inconsistently, intelligent cloud TV gateway repeats (2) step, if carry out M(M>=1) inferior, the sign ID of acquisition dobtain sign ID with deciphering dstill consistent, return to execution unsuccessfully to remote control terminal.If other legal intelligent home device D in subscriber household .receive after intelligent home device D broadcast message, by the wireless network protocol based on ZigBee(low speed short-distance transmission, the low-power consumption of an IEEE802.15.4 standard territory fidonetFido) agreement is as routing node, and this information is broadcasted in forwarding; If illegal intelligent home device D in subscriber household *receive after intelligent home device D broadcast message, cannot obtain the particular content of encrypted data, to TV, initiate man-in-the-middle attack.
The successful execution of this process, realizes the secure communication of Smart Home Intranet, prevents that go-between from illegally obtaining family's private data and launching a offensive, and guarantees confidentiality, the integrality of family data information, further promotes the fail safe of the total system of Smart Home.
Non-elaborated part of the present invention belongs to techniques well known.
The above; be only part embodiment of the present invention, but protection scope of the present invention is not limited to this, in the technical scope that any those skilled in the art disclose in the present invention; the variation that can expect easily or replacement, within all should being encompassed in protection scope of the present invention.

Claims (6)

1.一种基于智能云电视网关的智能家居安全组网实现方法,其特征在于实现步骤如下:1. A method for implementing a smart home security network based on an intelligent cloud TV gateway, characterized in that the steps of implementation are as follows: (1)用户首次使用UKey时,需将UKey插在智能云电视网关TV的ZigBee无线通信挂件接口上,借助UKey固化的智能家居App客户端证书CertApp,验证TV上预装App的合法可信性;所述UKey指一种通过通用串行总线接口USB直接与移动智能设备的Micro-USB口相连、具有密码验证功能的存储设备;若App验证可信后,App启动UKey的个人识别密码PIN设置界面,用户成功设置UKey的PIN码后,UKey生成自身的公私钥对、TV签发进门安全凭证TicketUKey、TV生成外网通信秘钥KOutNet、TV的公钥KTV(pub)和TV的标识IDTV,同时智能云电视网关TV获得UKey的公钥KUKey(pub)和UKey的标识IDUKey,从而完成对UKey的初始化工作;(1) When the user uses UKey for the first time, the UKey needs to be inserted into the ZigBee wireless communication pendant interface of the smart cloud TV gateway TV, and the smart home App client certificate Cert App solidified by UKey is used to verify the legitimacy and credibility of the pre-installed App on the TV The UKey refers to a storage device that is directly connected to the Micro-USB port of the mobile smart device through the Universal Serial Bus interface USB and has a password verification function; if the App verification is credible, the App starts the personal identification password PIN of the UKey On the setting interface, after the user successfully sets the PIN code of UKey, UKey generates its own public-private key pair, TV issues the entry security certificate Ticket UKey , TV generates the external network communication secret key K OutNet , TV public key K TV(pub) and TV’s Identify the ID TV , and at the same time, the smart cloud TV gateway TV obtains the public key K UKey (pub) of UKey and the identification ID UKey of UKey, thereby completing the initialization of UKey; (2)用户使用UKey插入智能家居设备D,智能家居设备D从UKey获得智能云电视网关的公钥KTV(pub)和智能云电视网关的标识IDTV及获得由UKey签发的可信组网凭证TicketD,从而完成对智能家居设备的初始化工作;(2) The user uses the UKey to insert the smart home device D, and the smart home device D obtains the public key K TV (pub) of the smart cloud TV gateway and the ID TV of the smart cloud TV gateway from the UKey, and obtains the trusted networking issued by the UKey Voucher Ticket D to complete the initialization of smart home devices; (3)用户智能家居设备D完成初始化工作后,依据可信组网凭证TicketD和智能云电视网关公钥KTV(pub),自主地完成与智能云电视网关安全可信组网及协商双方的通信加密秘钥
Figure FDA0000452557610000011
实现用户智能家居设备D与自家智能云电视网关TV的身份映射绑定;
(3) After the user's smart home device D completes the initialization work, according to the trusted networking certificate Ticket D and the public key K TV (pub) of the smart cloud TV gateway, it independently completes the secure and trusted networking with the smart cloud TV gateway and negotiates with both parties communication encryption key
Figure FDA0000452557610000011
Realize the identity mapping and binding between the user's smart home device D and his own smart cloud TV gateway TV;
(4)用户智能云电视网关TV通过通信加密秘钥
Figure FDA0000452557610000012
实现对智能家居设备D的安全控制及保证智能家居设备传输信息的机密性。
(4) The user's smart cloud TV gateway TV encrypts the key through communication
Figure FDA0000452557610000012
Realize the security control of the smart home device D and ensure the confidentiality of the information transmitted by the smart home device.
2.根据权利要求1所述的基于智能云电视网关的智能家居安全组网实现方法,其特征在于:所述步骤(1)中的UKey的初始化工作具体实现如下:2. The smart home security networking implementation method based on the smart cloud TV gateway according to claim 1, characterized in that: the initialization of UKey in the step (1) is specifically implemented as follows: (1)用户首次使用UKey时,要将UKey插在智能云电视网关TV的ZigBee无线通信挂件接口上,借助UKey固化的智能家居App客户端证书CertApp,验证TV上预装App的合法可信性,App验证可信后,UKey与智能云电视网关TV借助App建立起安全信任关系;(1) When the user uses UKey for the first time, the UKey should be inserted into the ZigBee wireless communication pendant interface of the smart cloud TV gateway TV, and the smart home App client certificate Cert App solidified by UKey should be used to verify the legitimacy and credibility of the pre-installed App on the TV After the App is verified and trusted, UKey and the smart cloud TV gateway TV establish a secure trust relationship with the App; (2)UKey与智能云电视网关TV成功建立安全信任关系,TV上的智能家居App客户端弹出PIN码设置界面,用户成功设置PIN码后,UKey通过App获得PIN码,然后UKey生成公私钥对KUKey(pub)和KUKey(pri)(2) UKey has successfully established a secure trust relationship with the smart cloud TV gateway TV, and the smart home App client on the TV pops up the PIN code setting interface. After the user successfully sets the PIN code, UKey obtains the PIN code through the App, and then UKey generates a public-private key pair K UKey(pub) and K UKey(pri) ; (3)UKey将自身的标识IDUKey和公钥KUKey(pub)传送给智能云电视网关TV;(3) UKey transmits its own identification ID UKey and public key K UKey(pub) to the smart cloud TV gateway TV; (4)智能云电视网关TV接受到UKey标识IDUKey和公钥KUKey(pub)后,生成时间戳TSTV和外网通信秘钥KOutNet,采用哈希算法计算IDTV、IDUKey和TSTV的哈希值H=Hash(IDTV||IDUKey||TSTV),使用智能云电视网关TV私钥KTV(pri)私钥对哈希值H加密,形成智能云电视网关TV签名 S TV = Sign [ Hash ( ID TV | | ID UKey | | TS TV ) ] K TV ( pri ) ; (4) After the smart cloud TV gateway TV receives the UKey identification ID UKey and public key K UKey (pub) , it generates a time stamp TS TV and an external network communication key K OutNet , and uses a hash algorithm to calculate ID TV , ID UKey and TS Hash value H of TV = Hash(ID TV ||ID UKey ||TS TV ), use smart cloud TV gateway TV private key K TV(pri) private key to encrypt hash value H to form smart cloud TV gateway TV signature S TV = sign [ Hash ( ID TV | | ID UKey | | TS TV ) ] K TV ( the price ) ; (5)智能云电视网关TV使用其公钥KTV(pub)对UKey的标识IDUKey和时间戳TSTV加密,形成TV使用其KTV(pub)加密的标识信息密文
Figure FDA0000452557610000022
(5) Smart cloud TV gateway TV uses its public key K TV(pub) to encrypt UKey's identification ID UKey and time stamp TS TV to form a ciphertext of identification information encrypted by TV using its K TV(pub)
Figure FDA0000452557610000022
(6)智能云电视网关TV将签名STV和标识信息密文
Figure FDA0000452557610000023
作为进门许可凭证 Ticket UKey = Sign [ Hash ( ID TV | | ID UKey | | TS TV ) ] K TV ( pri ) | | Enc [ ID UKey | | TS TV ] K TV ( pub ) , 并将进门许可凭证TicketUKey、TV公钥KTV(pub)、外网通信秘钥KOutNet下发给UKey,同时TV将UKey的标识IDUKey和公钥KTV(pub)作为UKey重要记录存储于TV的安全存储区;
(6) Smart cloud TV gateway TV will sign S TV and identify information ciphertext
Figure FDA0000452557610000023
as entry permit Ticket UKey = sign [ Hash ( ID TV | | ID UKey | | TS TV ) ] K TV ( the price ) | | Enc [ ID UKey | | TS TV ] K TV ( pub ) , And send the entry license Ticket UKey , TV public key K TV(pub) , and external network communication key K OutNet to UKey, and at the same time, TV stores UKey's identification ID UKey and public key K TV(pub) as important records of UKey in the secure storage area of the TV;
(7)UKey接受TV传送信息,使用获得PIN码对其私钥KUKey(pri)和外网通信秘钥KOutNet分别进行加密保护,形成私钥密文Enc[KUKey(pri)]PIN和外网通信秘钥密文Enc[KOutNet]PIN(7) UKey accepts the information transmitted by TV, uses the obtained PIN code to encrypt and protect its private key K UKey(pri) and external network communication key K OutNet respectively, and forms the private key ciphertext Enc[K UKey(pri) ] PIN and External network communication key cipher text Enc[K OutNet ] PIN ; (8)UKey通过自身标识IDUKey及包括存储区容量和计算芯片标识在内的其他硬件信息,生成PIN码保护秘钥KUKey(EncPin),并通过该秘钥KUKey(EncPin)加密PIN码,形成PIN码密文 Enc [ PIN ] K UKey ( EncPin ) ; (8) UKey generates a PIN code protection key K UKey (EncPin) through its own identification ID UKey and other hardware information including storage area capacity and computing chip identification, and encrypts the PIN code through this key K UKey (EncPin) , forming the PIN code ciphertext Enc [ PIN ] K UKey ( EncPin ) ; (9)UKey将进门许可凭证TicketUKey、TV公钥KTV(pub)、PIN码密文
Figure FDA0000452557610000026
外网通信秘钥密文Enc[KOutNet]PIN、自身公钥KUKey(pub)和私钥密文Enc[KUKey(pri)]PIN作为重要记录存储,UKey的初始化工作完成。
(9) UKey will enter the door permit ticket Ticket UKey , TV public key K TV(pub) , PIN code ciphertext
Figure FDA0000452557610000026
The external network communication secret key ciphertext Enc[K OutNet ] PIN , its own public key K UKey(pub) and private key ciphertext Enc[K UKey(pri) ] PIN are stored as important records, and the initialization of UKey is completed.
3.根据权利要求1所述的基于智能云电视网关的智能家居安全组网实现方法,其特征在于:所述步骤(2)中智能家居设备的初始化工作具体实现如下:3. The method for implementing smart home security networking based on smart cloud TV gateway according to claim 1, characterized in that: the initialization of smart home devices in the step (2) is specifically implemented as follows: (1)用户将初始后的UKey插在智能家居设备D的ZigBee无线通信挂件接口上,智能家居设备D识别UKey后,将其自身的标识IDD传送给UKey;(1) The user inserts the initial UKey into the ZigBee wireless communication pendant interface of the smart home device D. After the smart home device D recognizes the UKey, it transmits its own identification ID D to the UKey; (2)UKey接受到家居设备D的标识IDD,生成随机数NUKey,采用哈希算法计算IDD、IDUKey和NUKey的哈希值H=Hash(IDUKey||IDD||NUKey);(2) UKey receives the ID D of the home device D, generates a random number N UKey , and uses a hash algorithm to calculate the hash value of ID D , ID UKey and N UKey H=Hash(ID UKey ||ID D ||N UKey ); (3)UKey通过自身的标识IDUKey及包括存储区容量和计算芯片标识在内的其他硬件信息,生成PIN码保护秘钥KUKey(EncPin),并通过该秘钥KUKey(EncPin)解密UKey存储的PIN码密文 Enc [ PIN ] K UKey ( EncPin ) , 获得PIN码;(3) UKey generates a PIN code protection key K UKey (EncPin) through its own identification ID UKey and other hardware information including storage area capacity and computing chip identification, and decrypts UKey through this key K UKey (EncPin) Stored PIN ciphertext Enc [ PIN ] K UKey ( EncPin ) , Obtain a PIN code; (4)UKey通过PIN码解密获取存储区中被PIN码保护的UKey私钥KUKey(pri),并用获得私钥KUKey(pri)对(2)步骤哈希值加密,形成UKey签名 S UKey = Sign [ Hash ( ID UKey | | ID D | | N UKey ) ] K UKey ( pri ) ; (4) UKey decrypts the PIN code to obtain the UKey private key K UKey(pri) protected by the PIN code in the storage area, and uses the obtained private key K UKey(pri) to encrypt the hash value of step (2) to form a UKey signature S UKey = sign [ Hash ( ID UKey | | ID D. | | N UKey ) ] K UKey ( the price ) ; (5)UKey使用智能云电视网关的公钥KTV(pub)对设备标识IDD和随机数NUKey加密,形成UKey使用KTV(pub)加密的标识信息密文
Figure FDA0000452557610000032
(5) UKey uses the public key K TV(pub) of the smart cloud TV gateway to encrypt the device identification ID D and the random number N UKey to form the ciphertext of the identification information encrypted by UKey using K TV(pub)
Figure FDA0000452557610000032
(6)UKey将签名SUKey、标识信息密文
Figure FDA0000452557610000033
和进门许可凭证TicketUKey,作为组网凭证 Ticket D = Sign [ Hash ( ID UKey | | ID D | | N UKey ) ] K UKey ( pri ) | | Enc [ ID D | | N UKey ] K TV ( pub ) | | Ticket UKey 下发给智能家居设备D,智能家居设备D将该可信组网凭证TicketD存储,智能家居设备D的初始化工作完成。
(6) UKey will sign S UKey and identify information ciphertext
Figure FDA0000452557610000033
And the entry permit Ticket UKey , as the networking certificate Ticket D. = sign [ Hash ( ID UKey | | ID D. | | N UKey ) ] K UKey ( the price ) | | Enc [ ID D. | | N UKey ] K TV ( pub ) | | Ticket UKey Send it to the smart home device D, and the smart home device D stores the trusted networking certificate Ticket D , and the initialization of the smart home device D is completed.
4.根据权利要求1所述的基于智能云电视网关的智能家居安全组网实现方法,其特征在于:所述步骤(3)中的用户智能家居设备与自家智能云电视网关的身份映射绑定具体实现如下:4. The smart home security networking implementation method based on the smart cloud TV gateway according to claim 1, characterized in that: the user smart home device in the step (3) is bound with the identity mapping of the home smart cloud TV gateway The specific implementation is as follows: (1)智能家居设备D初始化完成后,生成随机数ND,使用该随机数ND对设备标识IDD和设备组网凭证TicketD加密,形成组网凭证密文
Figure FDA0000452557610000035
然后使用智能云电视网关公钥KTV(pub)对ND加密,形成随机数密文
Figure FDA0000452557610000036
最后将随机数密文附带组网凭证密文作为设备组网广播信息通过智能家居设备D的ZigBee通信模块进行广播;
(1) After the initialization of the smart home device D is completed, a random number N D is generated, and the random number N D is used to encrypt the device identification ID D and the device network certificate Ticket D to form a network certificate ciphertext
Figure FDA0000452557610000035
Then use the smart cloud TV gateway public key K TV (pub) to encrypt N D to form random number ciphertext
Figure FDA0000452557610000036
Finally, the random number ciphertext with the network certificate ciphertext is used as the device network broadcast information Broadcast through the ZigBee communication module of the smart home device D;
(2)智能云电视网关TV接收到智能家居设备D广播的组网信息后,使用其私钥KTV(pri)解密随机数密文,获得随机数ND,然后使用ND解密组网凭证密文,获得设备标识IDD和设备组网凭证TicketD,最后验证组网凭证TicketD的合法性,智能云电视网关TV使用UKey公钥KUKey(pub)验证UKey的签名
Figure FDA0000452557610000038
获得哈希值H=Hash(IDUKey||IDD||NUKey),并用智能云电视网关私钥KTV(pri)解密被UKey使用KTV(pub)加密的标识信息密文
Figure FDA0000452557610000039
获得设备标识IDD和UKey生成的随机数NUKey,并从其安全存储中获得UKey标识IDUKey,采用与UKey签名相同的哈希算法计算IDD、NUKey和IDUKey的哈希值H1=Hash(IDUKey||IDD||NUKey),比较哈希值H和H1是否相等,若两者不相同,则表明UKey不正常,组网凭证TicketD不合法,TV停止下一步的工作;若两者相同,则表明UKey正常,智能云电视网关TV使用其公钥KTV(pub)验证签名
Figure FDA0000452557610000041
获得哈希值H=Hash(IDTV||IDUKey||TSTV),并用其私钥KTV(pri)解密被KTV(pub)加密的标识信息密文
Figure FDA0000452557610000042
获得UKey标识IDUKey和TV生成的时间戳TSTV,采用与TV签名相同的哈希算法计算IDTV、IDUKey和TSTV的哈希值H1=Hash(IDTV||IDUKey||TSTV),比较哈希值H和H1是否相等,若两者不相同,则表明TV签名被伪造,组网凭证TicketD不合法,TV停止下一步的工作;若两者相同,则表明TV正常,组网凭证TicketD验证合法性,则将智能家居设备D信息显示在智能云电视网关的组网设备列表;如果用户家庭内其他合法的智能家居设备D·接收到智能家居设备D广播信息后,将基于ZigBee协议作为路由节点,转发广播该信息;如果用户家庭内非法的智能家居设备D×接收到智能家居设备D广播信息后,则无法获取被ND加密数据的具体内容而向TV发起中间人攻击;如果智能云电视网关要求组网具备高安全性和时效性,则可控制验证组网凭证TicketD的次数和该凭证的时间戳TSTV来实现,即设备组网凭证TicketD中的ND具有唯一性,同时组网凭证的验证时间不能超过从时间戳开始的一定时间;
(2) After the smart cloud TV gateway TV receives the networking information broadcast by the smart home device D, it uses its private key K TV(pri) to decrypt the random number ciphertext, obtains the random number ND , and then uses ND to decrypt the networking certificate The ciphertext, obtain the device identification ID D and the device network certificate Ticket D , and finally verify the legitimacy of the network certificate Ticket D , the smart cloud TV gateway TV uses the UKey public key K UKey (pub) to verify the UKey signature
Figure FDA0000452557610000038
Obtain the hash value H=Hash(ID UKey ||ID D ||N UKey ), and use the smart cloud TV gateway private key K TV(pri) to decrypt the ciphertext of the identification information encrypted by UKey using K TV(pub)
Figure FDA0000452557610000039
Obtain the random number N UKey generated by the device identification ID D and UKey, and obtain the UKey identification ID UKey from its safe storage, and use the same hash algorithm as the UKey signature to calculate the hash value H 1 of ID D , N UKey and ID UKey =Hash(ID UKey ||ID D ||N UKey ), compare whether the hash value H and H 1 are equal, if the two are not the same, it indicates that the UKey is abnormal, the network certificate Ticket D is invalid, and the TV stops the next step If the two are the same, it means that the UKey is normal, and the smart cloud TV gateway TV uses its public key K TV (pub) to verify the signature
Figure FDA0000452557610000041
Obtain the hash value H=Hash(ID TV ||ID UKey ||TS TV ), and use its private key K TV(pri) to decrypt the ciphertext of the identification information encrypted by K TV(pub)
Figure FDA0000452557610000042
Obtain the UKey identification ID UKey and the timestamp TS TV generated by TV, and use the same hash algorithm as the TV signature to calculate the hash value H 1 of ID TV , ID UKey and TS TV H 1 =Hash(ID TV ||ID UKey ||TS TV ), compare whether the hash values H and H 1 are equal, if the two are not the same, it indicates that the TV signature is forged, the networking certificate Ticket D is invalid, and the TV stops the next work; if the two are the same, it indicates that the TV Normal, if the validity of the networking certificate Ticket D is verified, the information of the smart home device D will be displayed in the network device list of the smart cloud TV gateway; if other legal smart home devices D in the user's home receive the broadcast information of the smart home device D Afterwards, it will forward and broadcast the information based on the ZigBee protocol as a routing node; if the illegal smart home device D × in the user’s home receives the broadcast information of the smart home device D, it will not be able to obtain the specific content of the ND encrypted data and send the TV Initiate a man-in-the-middle attack; if the smart cloud TV gateway requires high security and timeliness in networking, you can control the number of times to verify the network certificate Ticket D and the time stamp TS TV of the certificate to achieve it, that is, the device network certificate Ticket D The ND is unique, and the verification time of the networking certificate cannot exceed a certain time from the timestamp;
(3)用户选择智能云电视网关TV中家居设备组网列表中的某一智能家居设备D,智能云电视网关为该智能家居设备D随机产生通信加密密钥
Figure FDA0000452557610000043
并将设备的标识IDD、组网凭证TicketD和通信加密密钥
Figure FDA0000452557610000044
作为一条设备记录保存于智能云电视网关TV安全存储区;
(3) The user selects a smart home device D in the home device networking list in the smart cloud TV gateway TV, and the smart cloud TV gateway randomly generates a communication encryption key for the smart home device D
Figure FDA0000452557610000043
And the identification ID D of the device, the network certificate Ticket D and the communication encryption key
Figure FDA0000452557610000044
Save as a device record in the TV security storage area of the smart cloud TV gateway;
(4)智能云电视网关使用(2)步骤获得随机数ND+1对设备标识IDD和通信加密密钥
Figure FDA0000452557610000045
加密,形成通信秘钥密文将该密文附带设备标识IDD通过其ZigBee通信模块进行广播;
(4) The smart cloud TV gateway uses the step (2) to obtain the random number N D + 1 pair of device identification ID D and communication encryption key
Figure FDA0000452557610000045
Encrypt to form communication key ciphertext Broadcast the ciphertext with the device identification ID D through its ZigBee communication module;
(5)智能家居设备D接收到TV广播数据后,使用(1)步骤生成随机数ND+1解密通信秘钥密文获得设备的标识IDD和通信加密秘钥
Figure FDA0000452557610000047
验证接受到设备标识和解密获得设备标识的一致性,若两者验证一致,则将通信加密秘钥
Figure FDA0000452557610000048
组网凭证TicketD、智能云电视网关公钥KTV(pub)作为一条记录保存;若两者验证不一致,则智能家居设备D重复执行(1)步骤,若执行M(M≥1)次,获得的标识IDD和解密获得标识IDD仍一致,则停止工作;如果用户家庭内合法的智能家居设备D接收到TV广播信息后,则将基于ZigBee协议作为路由节点,转发广播该信息;如果用户家庭内非法的智能家居设备D×接收到TV广播信息后,无法获取被ND加密数据的具体内容,则向智能家居设备D发起中间人攻击。
(5) After the smart home device D receives the TV broadcast data, use the step (1) to generate a random number ND + 1 to decrypt the communication key ciphertext to obtain the device's identification ID D and communication encryption key
Figure FDA0000452557610000047
Verify the consistency of the device ID received and decrypted to obtain the device ID. If the two verifications are consistent, the communication encryption key will be
Figure FDA0000452557610000048
The network certificate Ticket D and the smart cloud TV gateway public key K TV(pub) are saved as a record; if the two verifications are inconsistent, the smart home device D repeats the step (1). If it is executed M (M≥1) times, If the obtained identification ID D and the decrypted identification ID D are still consistent, stop working; if the legal smart home device D in the user's home receives the TV broadcast information, it will forward and broadcast the information based on the ZigBee protocol as a routing node; if After receiving the TV broadcast information, the illegal smart home device D × in the user's home cannot obtain the specific content of the encrypted data by ND , so it launches a man-in-the-middle attack on the smart home device D.
5.根据权利要求1所述的基于智能云电视网关的智能家居安全组网实现方法,其特征在于:所述步骤(4)中具体实现如下:5. The method for implementing smart home security networking based on smart cloud TV gateway according to claim 1, characterized in that: the specific implementation in the step (4) is as follows: (1)智能云电视网关TV接收到智能家居设备D的远程控制指令,该指令格式:
Figure FDA0000452557610000051
使用智能云电视网关安全存储区中UKey标识IDUKey对应的外网通信秘钥KOutNet对密文指令进行解密,获取该智能家居设备的标识IDD和控制指令cmd;
(1) The smart cloud TV gateway TV receives the remote control command from the smart home device D. The format of the command is:
Figure FDA0000452557610000051
Use the external network communication key K OutNet corresponding to the UKey ID UKey in the secure storage area of the smart cloud TV gateway to pair the ciphertext instructions Decrypt to obtain the ID D and control command cmd of the smart home device;
(2)智能电视终端网关TV使用其安全存储区中智能家居设备D对应的通信加密密钥
Figure FDA0000452557610000053
对设备标识IDD和控制指令cmd加密,形成智能家居设备D内网加密控制指令
Figure FDA0000452557610000054
将生成的内网加密控制指令附带设备标识IDD,通过智能云电视网关的ZigBee网络模块将该控制信息
Figure FDA0000452557610000055
进行广播;
(2) Smart TV terminal gateway TV uses the communication encryption key corresponding to smart home device D in its safe storage area
Figure FDA0000452557610000053
Encrypt the device identification ID D and the control command cmd to form a smart home device D intranet encrypted control command
Figure FDA0000452557610000054
The generated internal network encryption control command is attached with the device identification ID D , and the control information is transmitted through the ZigBee network module of the smart cloud TV gateway.
Figure FDA0000452557610000055
to broadcast;
(3)智能家居设备D接收到智能云电视网关TV广播的信息后,用其存储的通信加密秘钥对加密控制指令
Figure FDA0000452557610000057
进行解密,获得控制命令cmd和标识IDD,验证获得标识IDD与自身标识是否一致,若验证一致,则智能家居设备D执行该控制命令cmd获取该命令的执行后的数据data,该数据data包含家居设备执行命令的状态或家居设备执行命令后获取信息,包括智能电灯开关状态、智能温湿度设备的温湿度值信息;若验证不一致,则智能家居设备D不做任何操作;如果用户家庭内合法的智能家居设备D接收到TV广播信息后,则将基于ZigBee协议作为路由节点,转发广播该信息;如果用户家庭内非法的智能家居设备D×接收到TV广播信息后,无法获取被加密指令的具体内容,则向智能家居设备D发起中间人攻击;
(3) After the smart home device D receives the information broadcast by the smart cloud TV gateway TV, it uses its stored communication encryption key Encryption Control Instructions
Figure FDA0000452557610000057
Decrypt to obtain the control command cmd and identification ID D , and verify whether the obtained identification ID D is consistent with its own identification. If the verification is consistent, the smart home device D executes the control command cmd to obtain the data data after the execution of the command. The data data Contains the status of home devices executing commands or information obtained after home devices execute commands, including smart light switch status, temperature and humidity value information of smart temperature and humidity devices; if the verification is inconsistent, smart home device D will not do anything; if the user's home After the legitimate smart home device D receives the TV broadcast information, it will act as a routing node based on the ZigBee protocol to forward and broadcast the information; if the illegal smart home device D × in the user's home receives the TV broadcast information, it cannot obtain the encrypted command specific content, launch a man-in-the-middle attack on the smart home device D;
(4)智能家居设备D将指令成功执行获得数据Data和智能家居设备D标识IDD,用智能家居设备D通信加密秘钥加密,形成加密数据智能家居设备D将加密数据附带其标识IDD作为返回数据
Figure FDA00004525576100000510
通过D的ZigBee通信模块进行广播;
(4) The smart home device D successfully executes the command to obtain the data Data and the smart home device D identification ID D , and uses the smart home device D communication encryption key encryption, forming encrypted data Smart home device D returns encrypted data with its ID D as return data
Figure FDA00004525576100000510
Broadcast through the ZigBee communication module of D;
(5)智能云电视网关TV接收到智能家居设备D广播的返回数据
Figure FDA00004525576100000511
后,利用获得设备标识IDD查找安全存储区中智能家居设备D对应的通信加密密钥
Figure FDA00004525576100000512
并用
Figure FDA00004525576100000513
解密加密数据
Figure FDA00004525576100000514
获得加密的设备标识IDD和执行数据data,验证直接获得的标识IDD和解密获得标识IDD是否一致,若验证一致,则使用(1)步骤中UKey标识IDUKey对应的外网通信秘钥KOutNet对标识IDD和数据data加密,形成外网加密执行结果
Figure FDA00004525576100000515
并将外网加密执行结果附带UKey标识IDUKey作为完整数据记录发送给远程控制端;若验证不一致,则智能云电视网关重复执行(2)步骤,若执行M(M≥1)次,获得的标识IDD和解密获得标识IDD仍一致,则返回执行失败给远程控制端;如果用户家庭内其他合法的智能家居设备D·接收到智能家居设备D广播信息后,则将基于ZigBee协议作为路由节点,转发广播该信息;如果用户家庭内非法的智能家居设备D×接收到智能家居设备D广播信息后,则无法获取被加密数据的具体内容向TV发起中间人攻击。
(5) The smart cloud TV gateway TV receives the return data broadcast by the smart home device D
Figure FDA00004525576100000511
After that, use the obtained device identification ID D to find the communication encryption key corresponding to the smart home device D in the secure storage area
Figure FDA00004525576100000512
and use
Figure FDA00004525576100000513
decrypt encrypted data
Figure FDA00004525576100000514
Obtain the encrypted device identification ID D and execution data data, and verify whether the directly obtained identification ID D and the decrypted identification ID D are consistent. If the verification is consistent, use the external network communication key corresponding to the UKey identification ID UKey in step (1) K OutNet encrypts the identification ID D and data data to form the execution result of external network encryption
Figure FDA00004525576100000515
And the execution result of external network encryption is attached with UKey ID UKey as a complete data record Send it to the remote control terminal; if the verification is inconsistent, the smart cloud TV gateway repeats the step (2). If it is executed M (M≥1) times, the obtained ID D and the decrypted ID D are still consistent, and the execution failure will be returned to the remote control terminal; if other legitimate smart home devices D in the user’s home receive the broadcast information of the smart home device D, they will be based on the ZigBee protocol as a routing node and forward and broadcast the information; if illegal smart home devices in the user’s home After D × receives the broadcast information of the smart home device D, it cannot obtain the specific content of the encrypted data to launch a man-in-the-middle attack on the TV.
6.根据权利要求2所述的基于智能云电视网关的智能家居安全组网实现方法,其特征在于:所述步骤(2)中的生成的PIN码保护秘钥KUKey(EncPin)在UKey中动态运行产生而不保存,增强了UKey的安全性。6. The smart home security networking implementation method based on the smart cloud TV gateway according to claim 2, characterized in that: the generated PIN code protection key K UKey (EncPin) in the step (2) is in the UKey The dynamic operation is generated without saving, which enhances the security of UKey.
CN201410001601.4A 2014-01-02 2014-01-02 A kind of Smart Home safe network implementation method based on intelligent cloud television gateway Expired - Fee Related CN103685323B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410001601.4A CN103685323B (en) 2014-01-02 2014-01-02 A kind of Smart Home safe network implementation method based on intelligent cloud television gateway

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410001601.4A CN103685323B (en) 2014-01-02 2014-01-02 A kind of Smart Home safe network implementation method based on intelligent cloud television gateway

Publications (2)

Publication Number Publication Date
CN103685323A true CN103685323A (en) 2014-03-26
CN103685323B CN103685323B (en) 2016-08-17

Family

ID=50321637

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410001601.4A Expired - Fee Related CN103685323B (en) 2014-01-02 2014-01-02 A kind of Smart Home safe network implementation method based on intelligent cloud television gateway

Country Status (1)

Country Link
CN (1) CN103685323B (en)

Cited By (26)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104267681A (en) * 2014-09-15 2015-01-07 马国强 Intelligent device information interaction system and method
CN105007164A (en) * 2015-07-30 2015-10-28 青岛海尔智能家电科技有限公司 Centralized safety control method and device
CN105573134A (en) * 2015-12-30 2016-05-11 深圳众乐智府科技有限公司 Intelligent household equipment control method and intelligent household system
CN106130982A (en) * 2016-06-28 2016-11-16 北京万协通信息技术有限公司 Intelligent household appliance remote control method based on PKI system
CN106330465A (en) * 2016-11-21 2017-01-11 航天信息股份有限公司 Processing method, server and system for distributed timestamp
CN103873487B (en) * 2014-04-04 2017-04-05 中国科学院信息工程研究所 A kind of household based on the safe suspension member of intelligent home device trusts the implementation method of networking
CN107426218A (en) * 2017-07-28 2017-12-01 杭州聪普智能科技有限公司 A kind of smart home intranet and extranet method for handover control
CN108155996A (en) * 2018-03-12 2018-06-12 浙江大学 Smart home safe communication method based on family's channel
TWI627554B (en) * 2017-05-10 2018-06-21 威盛電子股份有限公司 Methods for blocking unauthorized applications and apparatuses using the same
CN108537925A (en) * 2018-04-04 2018-09-14 安恒世通(北京)网络科技有限公司 A kind of lockset terminal joint control method
WO2018209644A1 (en) * 2017-05-18 2018-11-22 深圳市得城网络科技有限公司 Data encryption method and system for smart household
CN109617867A (en) * 2018-12-04 2019-04-12 海南高信通科技有限公司 A kind of Intelligent gateway system for home equipment control
CN109639542A (en) * 2019-02-27 2019-04-16 深圳创维-Rgb电子有限公司 A kind of distribution method and system based on intelligent domestic gateway
CN110419193A (en) * 2017-10-26 2019-11-05 顺天乡大学校产学协力团 Certification and communication means and its system for safe and intelligent domestic environment based on KSI
CN110519267A (en) * 2019-08-27 2019-11-29 国网电子商务有限公司 A kind of article identity encryption method and device
CN110716441A (en) * 2019-11-08 2020-01-21 北京金茂绿建科技有限公司 Method for controlling intelligent equipment, intelligent home system, equipment and medium
CN110808991A (en) * 2019-11-08 2020-02-18 北京金茂绿建科技有限公司 Method, system, electronic device and storage medium for secure communication connection
CN111007814A (en) * 2019-11-21 2020-04-14 时拓(嘉兴)智能科技有限公司 LoRaWAN wireless intelligent home local area network system
CN112003868A (en) * 2020-08-28 2020-11-27 苏州中科安源信息技术有限公司 Intelligent household system secure communication method based on white-box encryption
CN112019524A (en) * 2020-08-10 2020-12-01 优联三维打印科技发展(上海)有限公司 Communication protocol structure of 3D printing cloud service, data packet processing method and system
CN114125823A (en) * 2020-08-25 2022-03-01 云米互联科技(广东)有限公司 Networking communication encryption method, server, household appliance, system and storage medium
CN115174302A (en) * 2022-09-06 2022-10-11 杭州涂鸦信息技术有限公司 Processing method, device, equipment and storage medium of pluggable accessory
CN115174145A (en) * 2022-05-30 2022-10-11 青岛海尔科技有限公司 Equipment control method and edge gateway equipment
CN116074144A (en) * 2022-12-20 2023-05-05 深圳市千岩科技有限公司 Home control system, method, electronic device and storage medium
CN116094825A (en) * 2023-02-01 2023-05-09 成都赛力斯科技有限公司 Communication security protection method, system, electronic equipment and storage medium
CN118041528A (en) * 2024-03-04 2024-05-14 安徽明生恒卓科技有限公司 Quantum encryption-based power gateway communication method and system

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1867066A (en) * 2005-05-20 2006-11-22 中国移动通信集团公司 Digital television program broadcasting system and method
CN101513044A (en) * 2006-09-04 2009-08-19 诺基亚西门子通信有限责任两合公司 Personalizing any TV gateway
CN102811385A (en) * 2012-08-24 2012-12-05 上海下一代广播电视网应用实验室有限公司 User interactive interface realization method for household intelligent television gateway
CN103024476A (en) * 2013-01-08 2013-04-03 北京视博数字电视科技有限公司 Digital television gateway device and content safeguard method

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1867066A (en) * 2005-05-20 2006-11-22 中国移动通信集团公司 Digital television program broadcasting system and method
CN101513044A (en) * 2006-09-04 2009-08-19 诺基亚西门子通信有限责任两合公司 Personalizing any TV gateway
CN102811385A (en) * 2012-08-24 2012-12-05 上海下一代广播电视网应用实验室有限公司 User interactive interface realization method for household intelligent television gateway
CN103024476A (en) * 2013-01-08 2013-04-03 北京视博数字电视科技有限公司 Digital television gateway device and content safeguard method

Cited By (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103873487B (en) * 2014-04-04 2017-04-05 中国科学院信息工程研究所 A kind of household based on the safe suspension member of intelligent home device trusts the implementation method of networking
CN104267681A (en) * 2014-09-15 2015-01-07 马国强 Intelligent device information interaction system and method
CN105007164A (en) * 2015-07-30 2015-10-28 青岛海尔智能家电科技有限公司 Centralized safety control method and device
CN105007164B (en) * 2015-07-30 2021-07-06 青岛海尔智能家电科技有限公司 A centralized security control method and device
CN105573134A (en) * 2015-12-30 2016-05-11 深圳众乐智府科技有限公司 Intelligent household equipment control method and intelligent household system
CN106130982B (en) * 2016-06-28 2019-07-12 北京万协通信息技术有限公司 Intelligent household appliance remote control method based on PKI system
CN106130982A (en) * 2016-06-28 2016-11-16 北京万协通信息技术有限公司 Intelligent household appliance remote control method based on PKI system
CN106330465A (en) * 2016-11-21 2017-01-11 航天信息股份有限公司 Processing method, server and system for distributed timestamp
CN106330465B (en) * 2016-11-21 2020-10-13 航天信息股份有限公司 Distributed timestamp processing method, server and system
TWI627554B (en) * 2017-05-10 2018-06-21 威盛電子股份有限公司 Methods for blocking unauthorized applications and apparatuses using the same
US10701061B2 (en) 2017-05-10 2020-06-30 Via Technologies, Inc. Methods for blocking unauthorized applications and apparatuses using the same
WO2018209644A1 (en) * 2017-05-18 2018-11-22 深圳市得城网络科技有限公司 Data encryption method and system for smart household
CN107426218B (en) * 2017-07-28 2021-04-20 杭州聪普智能科技有限公司 Intelligent household internal and external network switching control method
CN107426218A (en) * 2017-07-28 2017-12-01 杭州聪普智能科技有限公司 A kind of smart home intranet and extranet method for handover control
CN110419193A (en) * 2017-10-26 2019-11-05 顺天乡大学校产学协力团 Certification and communication means and its system for safe and intelligent domestic environment based on KSI
CN108155996A (en) * 2018-03-12 2018-06-12 浙江大学 Smart home safe communication method based on family's channel
CN108537925A (en) * 2018-04-04 2018-09-14 安恒世通(北京)网络科技有限公司 A kind of lockset terminal joint control method
CN108537925B (en) * 2018-04-04 2021-05-18 安恒世通(北京)网络科技有限公司 Lock terminal joint control method
CN109617867A (en) * 2018-12-04 2019-04-12 海南高信通科技有限公司 A kind of Intelligent gateway system for home equipment control
CN109639542A (en) * 2019-02-27 2019-04-16 深圳创维-Rgb电子有限公司 A kind of distribution method and system based on intelligent domestic gateway
CN110519267A (en) * 2019-08-27 2019-11-29 国网电子商务有限公司 A kind of article identity encryption method and device
CN110716441A (en) * 2019-11-08 2020-01-21 北京金茂绿建科技有限公司 Method for controlling intelligent equipment, intelligent home system, equipment and medium
CN110808991A (en) * 2019-11-08 2020-02-18 北京金茂绿建科技有限公司 Method, system, electronic device and storage medium for secure communication connection
CN111007814A (en) * 2019-11-21 2020-04-14 时拓(嘉兴)智能科技有限公司 LoRaWAN wireless intelligent home local area network system
CN112019524A (en) * 2020-08-10 2020-12-01 优联三维打印科技发展(上海)有限公司 Communication protocol structure of 3D printing cloud service, data packet processing method and system
CN114125823A (en) * 2020-08-25 2022-03-01 云米互联科技(广东)有限公司 Networking communication encryption method, server, household appliance, system and storage medium
CN112003868A (en) * 2020-08-28 2020-11-27 苏州中科安源信息技术有限公司 Intelligent household system secure communication method based on white-box encryption
CN112003868B (en) * 2020-08-28 2023-06-16 苏州中科安源信息技术有限公司 Intelligent home system safety communication method based on white box encryption
CN115174145A (en) * 2022-05-30 2022-10-11 青岛海尔科技有限公司 Equipment control method and edge gateway equipment
CN115174145B (en) * 2022-05-30 2023-12-19 青岛海尔科技有限公司 Equipment control method and edge gateway equipment
CN115174302A (en) * 2022-09-06 2022-10-11 杭州涂鸦信息技术有限公司 Processing method, device, equipment and storage medium of pluggable accessory
CN116074144A (en) * 2022-12-20 2023-05-05 深圳市千岩科技有限公司 Home control system, method, electronic device and storage medium
CN116074144B (en) * 2022-12-20 2025-01-14 深圳市千岩科技有限公司 Home control system, method, electronic equipment and storage medium
CN116094825A (en) * 2023-02-01 2023-05-09 成都赛力斯科技有限公司 Communication security protection method, system, electronic equipment and storage medium
CN118041528A (en) * 2024-03-04 2024-05-14 安徽明生恒卓科技有限公司 Quantum encryption-based power gateway communication method and system
CN118041528B (en) * 2024-03-04 2024-09-17 安徽明生恒卓科技有限公司 Quantum encryption-based power gateway communication method and system

Also Published As

Publication number Publication date
CN103685323B (en) 2016-08-17

Similar Documents

Publication Publication Date Title
CN103685323A (en) Method for realizing intelligent home security networking based on intelligent cloud television gateway
US9467430B2 (en) Device, method, and system for secure trust anchor provisioning and protection using tamper-resistant hardware
CN103731756B (en) A kind of Smart Home remote secure access control method based on intelligent cloud television gateway
CN105162772B (en) A method and device for authentication and key agreement of Internet of Things equipment
CN103229452B (en) The identification of mobile hand-held device and communication authentication
CN103873487B (en) A kind of household based on the safe suspension member of intelligent home device trusts the implementation method of networking
TWI642288B (en) Instant communication method and system
CN104094267B (en) Method, apparatus and system for secure sharing of media content from a source device
US9762567B2 (en) Wireless communication of a user identifier and encrypted time-sensitive data
CN103532713B (en) Sensor authentication and shared key production method and system and sensor
CN105282179B (en) A method of family&#39;s Internet of Things security control based on CPK
CN108924147B (en) Communication terminal digital certificate issuing method, server and communication terminal
JP5954609B1 (en) Method and system for backing up private key of electronic signature token
CN109923830A (en) System and method for configuring wireless network access device
US20180262352A1 (en) Secure Authentication of Remote Equipment
ES2665887T3 (en) Secure data system
EP3422630B1 (en) Access control to a network device from a user device
CN110198295A (en) Safety certifying method and device and storage medium
CN104202170B (en) A kind of identity authorization system and method based on mark
CN108964897A (en) Identity authorization system and method based on group communication
WO2017020530A1 (en) Enhanced wlan certificate authentication method, device and system
CN115102740A (en) Communication method, apparatus, device, storage medium and program product
KR100668446B1 (en) How to move secure authentication information
KR20130007097A (en) Security system of smart phone service and secruity method
Yoon et al. Security enhancement scheme for mobile device using H/W cryptographic module

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20160817

Termination date: 20180102

CF01 Termination of patent right due to non-payment of annual fee