1.1 ECDH_client_pubkey
Access
app reboot
RSA decode &generate share_key
0.2 certificate
choose ECDH or PSK
tcp reconnect
Web Server
2.1 access_psk
2.2 share_key
3.2 share_key
1.4 PSK(encrypt share_key)
3.1 ECDH+refresh_psk
Client
1.3 share_key
0.1 https request
1.2 RSA ( ECDH_server_pubkey )
app first startup
KeyCenter
cache access_pskstore refresh_psk
generate share_key