IP Library Granted Patent US 12676745
Granted Patent B2
US 12676745 · App. 19/227,635 · Granted Jul 7, 2026

Key authentication method, electronic device, and storage medium

Inventors: Chengjie Lin (Fuzhou, CN); Zhifei Zang (Fuzhou, CN)
Assignee: RUIJIE NETWORKS CO., LTD.
H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12676745
App. No.
19/227,635
Granted
Jul 7, 2026
Kind
B2
Abstract

A key authentication method, an electronic device, and a storage medium. The key authentication method includes: determining user information based on a key authentication request sent by a user end, where the key authentication request includes the user information and an initial key; determining whether the user information has been bound to a pre-shared key; when the user information has not been bound to a pre-shared key, determining whether the initial key matches a first key, where the first key is used to determine whether the user end has a registration need for a pre-shared key; and when the initial key matches the first key, registering the first pre-shared key for the user end and binding the first pre-shared key to the user information.

Claims (59)

1 . A key authentication method, comprising:

determining, by a processor, user information based on a key authentication request sent by a user end, wherein the key authentication request comprises the user information and an initial key;

determining, by the processor, whether the initial key matches a first key based on encryption parameter values obtained by parsing the key authentication request, wherein the first key is used to determine whether the user end has a registration need for a pre-shared key; and

when the initial key matches the first key, registering, by the processor, a first pre-shared key for the user end and binding, by the processor, the first pre-shared key to the user information;

wherein before the determining, by the processor, whether the initial key matches the first key, the method further comprises:

determining, by the processor, whether the user information has been bound to a pre-shared key; and

the determining, by the processor, whether the initial key matches the first key comprises:

when the user information has not been bound to a pre-shared key, determining, by the processor, whether the initial key matches the first key.

2 . The method according to claim 1 , wherein after the determining, by the processor, whether the user information has been bound to the pre-shared key, the method further comprises:

when the user information has been bound to the pre-shared key, determining whether the initial key matches a second pre-shared key bound to the user information; and

when the initial key matches the second pre-shared key bound to the user information, sending, to the user end, an authentication message associated with the second pre-shared key.

3 . The method according to claim 2 , wherein the authentication message associated with the second pre-shared key comprises at least one of authorized virtual local area network information and service quality information.

4 . The method according to claim 2 , wherein after the determining, by the processor, whether the initial key matches the second pre-shared key bound to the user information, the method further comprises:

when the initial key does not match the second pre-shared key bound to the user information, sending, to the user end, a feedback message indicating an authentication error of the initial key.

5 . The method according to claim 4 , wherein the feedback message comprises an error type of the authentication error of the initial key.

6 . The method according to claim 2 , wherein the determining, by the processor, whether the initial key matches the second pre-shared key bound to the user information comprises:

determining an encryption parameter value based on the key authentication request;

encrypting the initial key based on the encryption parameter value to obtain a first encrypted key;

encrypting the second pre-shared key based on the encryption parameter value to obtain a second encrypted key; and

when the first encrypted key matches the second encrypted key, determining that the initial key matches the second pre-shared key.

7 . The method according to claim 1 , wherein after the determining, by the processor, whether the initial key matches the first key, the method further comprises:

when the initial key does not match the first key, determining whether the initial key matches a second key, wherein the second key is a pre-shared key in a pre-shared key set; and

when the initial key matches the second key, binding the second key to the user information and sending, to the user end, an authentication message associated with the second key.

8 . The method according to claim 7 , wherein the determining whether the initial key matches the second key comprises:

determining an encryption parameter value based on the key authentication request;

encrypting the initial key based on the encryption parameter value to obtain a third encrypted key;

obtaining the second key from the pre-shared key set;

encrypting the second key based on the encryption parameter value to obtain a fourth encrypted key; and

when the third encrypted key matches the fourth encrypted key, binding the second key to the user information and sending, to the user end, the authentication message associated with the second key.

9 . The method according to claim 8 , wherein the determining whether the initial key matches the second key further comprises:

when the third encrypted key does not match the fourth encrypted key, selecting a next candidate pre-shared key from the pre-shared key set as the second key.

10 . The method according to claim 1 , further comprising:

when the initial key does not match the first key, sending, to the user end, a second feedback message indicating an authentication failure of the initial key.

11 . The method according to claim 1 , wherein the registering, by the processor, the first pre-shared key for the user end and binding the first pre-shared key to the user information comprises:

determining registration information sent by the user end;

when determining that the registration information meets a preset registration rule, registering the first pre-shared key for the user end; and

sending the first pre-shared key to the user end and binding the first pre-shared key to the user information.

12 . The method according to claim 1 , wherein the registering, by the processor, the first pre-shared key for the user end comprises:

sending an accept packet to the user end, wherein the accept packet comprises at least one type of the following information: a registered role, a name of the registered role, a jump address, and a public key; and

receiving the registration information sent by the user end and determining the first pre-shared key based on the registration information and a set randomized generation algorithm.

13 . The method according to claim 1 , further comprising:

after the registering the first pre-shared key for the user end, sending an offline request to the user end, wherein the offline request is used to request the user end to discontinue a registration connection.

14 . An electronic device, comprising:

a memory, configured to store a computer program; and

a processor, configured to execute the computer program stored in the memory, to implement:

determining, by the processor, user information based on a key authentication request sent by a user end, wherein the key authentication request comprises the user information and an initial key;

determining, by the processor, whether the initial key matches a first key based on encryption parameter values obtained by parsing the key authentication request, wherein the first key is used to determine whether the user end has a registration need for a pre-shared key; and

when the initial key matches the first key, registering, by the processor, a first pre-shared key for the user end and binding, by the processor, the first pre-shared key to the user information;

wherein before the determining, by the processor, whether the initial key matches the first key, the method further comprises:

determining, by the processor, whether the user information has been bound to a pre-shared key; and

the determining, by the processor, whether the initial key matches the first key comprises:

when the user information has not been bound to a pre-shared key, determining, by the processor, whether the initial key matches the first key.

15 . A non-transitory computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor is configured to implement:

determining, by the processor, user information based on a key authentication request sent by a user end, wherein the key authentication request comprises the user information and an initial key;

determining, by the processor, whether the initial key matches a first key based on encryption parameter values obtained by parsing the key authentication request, wherein the first key is used to determine whether the user end has a registration need for a pre-shared key; and

when the initial key matches the first key, registering, by the processor, a first pre-shared key for the user end and binding, by the processor, the first pre-shared key to the user information; wherein before the determining, by the processor, whether the initial key matches the first key, the method further comprises:

determining, by the processor, whether the user information has been bound to a pre-shared key; and

the determining, by the processor, whether the initial key matches the first key comprises:

when the user information has not been bound to a pre-shared key, determining, by the processor, whether the initial key matches the first key.