Pairing method and apparatus
Embodiments of this application provide a pairing method and apparatus, applied to the field of communications technologies and the field of connected vehicles. The method includes: A first node sends a first message, where the first message includes indication information of at least one pairing method supported by the first node; and receives a second message from a second node, where the second message includes indication information of a first pairing method, and the first pairing method is included in a pairing method supported by both the first node and the second node. According to embodiments of this application, the two nodes may support a plurality of pairing methods, so that the first pairing method is agreed on from the plurality of pairing methods, thereby improving node pairing flexibility.
1 . A pairing method, comprising:
sending, by a first node, a first message, wherein the first message comprises indication information of at least one pairing method supported by the first node; and
receiving, by the first node, a second message from a second node, wherein the second message comprises indication information of a first pairing method, and the first pairing method is a pairing method supported by both the first node and the second node;
receiving, by the first node, a fourth message from the second node, wherein the fourth message comprises third authentication information, the third authentication information is obtained by the second node based on an inferring algorithm, a second shared key, and the at least one pairing method supported by the first node;
wherein the second shared key is obtained by the second node based on a first key agreement algorithm and a second key agreement parameter, the second key agreement parameter is generated by the first node based on the first key agreement algorithm;
generating, by the first node, fourth authentication information based on the inferring algorithm, a first shared key, and the at least one pairing method supported by the first node;
wherein the first shared key is obtained by the first node based on the first key agreement algorithm and a first key agreement parameter, the first key agreement parameter is generated by the second node based on the first key agreement algorithm;
determining, by the first node, that identity authentication on the second node succeeds by verifying that the third authentication information is consistent with fourth authentication information;
wherein the first key agreement algorithm is determined from a key agreement algorithm supported by both the first node and the second node.
2 . The method according to claim 1 , wherein the second message is for requesting to establish an association with the first node.
3 . The method according to claim 1 , wherein the first message further comprises priority information corresponding to the at least one pairing method supported by the first node, or a priority corresponding to the at least one pairing method is preconfigured.
4 . The method according to claim 3 , wherein the first pairing method is determined based on the priority information of the at least one pairing method supported by the first node.
5 . The method according to claim 1 , wherein the indication information of the at least one pairing method supported by the first node is an input/output capability of the first node.
6 . The method according to claim 1 , wherein the inferring algorithm is a key derivation algorithm.
7 . The method according to claim 1 , wherein the first key agreement algorithm a Diffie-Hellman key exchange (DH) algorithm, an elliptic curve cryptosystems-based DH (ECDH) algorithm, a Chinese cryptographic algorithm, or an Oakley algorithm.
8 . The method according to claim 1 , wherein the fourth message further comprises a second message integrity code (MIC), wherein the second MIC is a message integrity code generated based on an integrity protection algorithm, and the second MIC is for protecting integrity of the fourth message.
9 . A pairing method, comprising:
receiving, by a second node, a first message from a first node, wherein the first message comprises indication information of at least one pairing method supported by the first node;
determining, by the second node, a first pairing method, and the first pairing method is a pairing method supported by both the first node and the second node; and
sending, by the second node, a second message to the first node, wherein the second message comprises indication information of the first pairing method;
sending, by the second node, a fourth message to the first node, wherein the fourth message comprises third authentication information, the third authentication information is obtained by the second node based on an inferring algorithm, a second shared key, and the at least one pairing method supported by the first node;
wherein the second shared key is obtained by the second node based on a first key agreement algorithm and a second key agreement parameter, the second key agreement parameter is generated by the first node based on the first key agreement algorithm;
wherein the first key agreement algorithm is determined from a key agreement algorithm supported by both the first node and the second node.
10 . The method according to claim 9 , wherein the second message is for requesting to establish an association with the first node.
11 . The method according to claim 9 , wherein the first message further comprises priority information corresponding to the at least one pairing method supported by the first node, or a priority corresponding to the at least one pairing method is preconfigured.
12 . The method according to claim 11 , wherein the first pairing method is determined based on the priority information of the at least one pairing method supported by the first node.
13 . The method according to claim 9 , wherein the indication information of the at least one pairing method supported by the first node is an input/output capability of the first node.
14 . The method according to claim 9 , wherein the inferring algorithm is a key derivation algorithm.
15 . The method according to claim 9 , wherein the first key agreement algorithm a Diffie-Hellman key exchange (DH) algorithm, an elliptic curve cryptosystems-based DH (ECDH) algorithm, a Chinese cryptographic algorithm, or an Oakley algorithm.
16 . The method according to claim 9 , wherein the fourth message further comprises a second message integrity code (MIC), wherein the second MIC is a message integrity code generated based on an integrity protection algorithm, and the second MIC is for protecting integrity of the fourth message.
17 . An apparatus operating as part of a first node, comprising:
at least one processor; and
one or more memories coupled to the at least one processor and storing programming instructions for execution by the at least one processor to:
send a first message, wherein the first message comprises indication information of at least one pairing method supported by the first node; and
receive a second message from a second node, wherein the second message comprises indication information of a first pairing method, and the first pairing method is a pairing method supported by both the first node and the second node;
receiving a fourth message from the second node, wherein the fourth message comprises third authentication information, the third authentication information is obtained by the second node based on an inferring algorithm, a second shared key, and the at least one pairing method supported by the first node;
wherein the second shared key is obtained by the second node based on a first key agreement algorithm and a second key agreement parameter, the second key agreement parameter is generated by the first node based on the first key agreement algorithm;
generating fourth authentication information based on the inferring algorithm, a first shared key, and the at least one pairing method supported by the first node;
wherein the first shared key is obtained by the first node based on the first key agreement algorithm and a first key agreement parameter, the first key agreement parameter is generated by the second node based on the first key agreement algorithm;
determining that identity authentication on the second node succeeds by verifying that the third authentication information is consistent with fourth authentication information;
wherein the first key agreement algorithm is determined from a key agreement algorithm supported by both the first node and the second node.
18 . The apparatus according to claim 17 , wherein the second message is for requesting to establish an association with the first node.
19 . The apparatus according to claim 17 , wherein the first message further comprises priority information corresponding to the at least one pairing method supported by the first node, or a priority corresponding to the at least one pairing method is preconfigured.