A security authentication method for an ad-hoc network system
By introducing asymmetric encryption channels and session IDs to generate authorization codes in the ad hoc network system, the problem of security authentication in the ad hoc network system relying on pre-burning authorization codes is solved, effective authentication and encrypted communication of the master node are realized, and the security of the system and communication protection capabilities are improved.
Patent Information
- Application Number
- CN202210384268.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-13
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-04-13
AI Technical Summary
In the existing ad hoc networking system, device security authentication relies on pre-burned authorization codes to cause low security and insufficient communication security between the master node and the management server.
The master node establishes an asymmetric encryption channel with the authentication server, generates and passes the first symmetric key, generates an authorization code using the session ID, and performs dual encryption communication between the master node and the slave node, and uses a pre-set public key to encrypt it to realize authentication of the master node.
The authentication security of the ad hoc network system is improved, the difficulty in identifying illegal devices and the risk of intercepting communications is avoided, and higher transmission security and simplified authentication process are achieved.
Smart Images

Figure CN115002755B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a security authentication method for an ad-hoc network system. Background Art
[0002] An ad-hoc network system is a communication system based on mobile communication and routing and switching technologies. In an ad-hoc network system, each device has both the functions of a routing device and an application host, and thus relays, exchanges, and forwards data in the ad-hoc network system while meeting service requirements, thereby achieving long-distance multi-hop transmission. In an ad-hoc network system, the node device used to manage the ad-hoc network devices is usually referred to as the master node, and the remaining nodes are called slave nodes.
[0003] In the prior art, there already exists an ad-hoc network system implemented based on ad-hoc network technology, which is used for data exchange and management of ad-hoc network devices in an application scenario. However, in the actual implementation process, the inventor found that in the ad-hoc network system in the prior art, the security authentication link for devices mainly relies on the authorization codes pre-burned in the devices. This results in that multiple devices in the ad-hoc network system in the prior art need to be mutually verified separately to ensure security, and the communication security between the master node and the management server in the prior art is relatively low. Summary of the Invention
[0004] In view of the above problems existing in the prior art, there is provided a security authentication method for an ad-hoc network system at present.
[0005] The specific technical solution is as follows:
[0006] A security authentication method for an ad-hoc network system, which is applicable to the ad-hoc network system formed by multiple ad-hoc network nodes. Before the security authentication method, there is a self-negotiation process in the ad-hoc network system to select the master node and slave nodes in the ad-hoc network system;
[0007] Then the security authentication method includes:
[0008] Step S1: The master node establishes an asymmetric encryption channel with a remote authentication server, the master node generates a first symmetric key, and transmits the first symmetric key through the asymmetric encryption channel;
[0009] Step S2: The master node generates a session ID according to the self-negotiation process, and sends the session ID to the authentication server through the asymmetric encryption channel;
[0010] Step S3: The authentication server generates an authorization code according to the session ID, encrypts the authorization code with the first symmetric key, and then sends it to the master node;
[0011] Step S4: The master node decrypts to obtain the authorization code, encrypts it using the second public key, and then sends it to the slave node.
[0012] Step S5: The slave node determines whether the authorization code is generated by the authentication server according to the authorization code and the session ID.
[0013] If so, it indicates that the master node has passed the security authentication, and then the communication process starts.
[0014] If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
[0015] Preferably, at least one pair of first public key and first private key are pre-generated by the authentication server before the security authentication method.
[0016] Then step S1 includes:
[0017] Step S11: The master node requests the first public key from the authentication server, and the authentication server sends the public key to the master node to establish the asymmetric encryption channel.
[0018] Step S12: The master node generates the first symmetric key, encrypts the first symmetric key using the first public key, and then sends the encrypted first symmetric key to the authentication server through the asymmetric encryption channel.
[0019] Step S13: The authentication server decrypts the encrypted first symmetric key using the first private key to obtain the first symmetric key.
[0020] Preferably, step S2 includes:
[0021] Step S21: The master node obtains the session ID corresponding to the auto-negotiation process.
[0022] Step S22: The master node encrypts the session ID using the first public key, and then sends the encrypted session ID to the authentication server through the asymmetric encryption channel.
[0023] Step S23: The authentication server decrypts the encrypted session ID using the first private key to obtain the session ID.
[0024] Preferably, step S3 includes:
[0025] Step S31: The authorization server generates the authorization code according to the session ID.
[0026] Step S32: The authorization server encrypts the authorization code with the first symmetric key, and then sends the encrypted authorization code to the master node.
[0027] Preferably, the step S4 includes:
[0028] Step S41: The master node decrypts the encrypted authorization code with the first symmetric key to obtain the authorization code;
[0029] Step S42: The master node encrypts the authorization code with the second public key and sends the encrypted authorization code to the slave nodes respectively.
[0030] Preferably, the step S5 includes:
[0031] Step S51: The slave node decrypts the encrypted authorization code with the second public key to obtain the authorization code;
[0032] Step S52: The slave node determines whether the authorization code is generated by the authentication server according to the session ID;
[0033] If so, it indicates that the master node has passed the security authentication, and then the communication process starts;
[0034] If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
[0035] Preferably, the step S52 includes:
[0036] Step S521: The slave node generates a comparison value according to the session ID;
[0037] Step S522: The slave node determines whether the authorization code is generated by the authentication server according to the comparison value;
[0038] If so, it indicates that the master node has passed the security authentication, and then the communication process starts;
[0039] If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
[0040] Preferably, after the step S5, there is further a communication process between the master node and the slave node;
[0041] During the communication process, the master node and / or the slave node uses the authorization code as a symmetric key to encrypt communication data.
[0042] The above technical solution has the following advantages or beneficial effects: By selecting the session ID as the generation variable of the authorization code in each authorization process, the problem that the pre-burned authorization code in the prior art cannot effectively identify illegal devices is avoided, thereby achieving a better authentication effect for the master node. Moreover, by presetting the second public key for the encrypted communication process between the master node and the slave node, the risk that the communication process within the ad hoc network system is intercepted by external devices is avoided. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Referring to the accompanying drawings, the embodiments of the present invention will be described more fully. However, the accompanying drawings are only for illustration and explanation, and do not constitute a limitation on the scope of the present invention.
[0044] Figure 1 It is a schematic diagram of the whole of an embodiment of the present invention;
[0045] Figure 2 It is a schematic diagram of the sub-steps of step S1 in an embodiment of the present invention;
[0046] Figure 3 It is a schematic diagram of the sub-steps of step S2 in an embodiment of the present invention;
[0047] Figure 4 It is a schematic diagram of the sub-steps of step S3 in an embodiment of the present invention;
[0048] Figure 5 It is a schematic diagram of the sub-steps of step S4 in an embodiment of the present invention;
[0049] Figure 6 It is a schematic diagram of the sub-steps of step S5 in an embodiment of the present invention;
[0050] Figure 7 It is a schematic diagram of the sub-steps of step S52 in an embodiment of the present invention DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0052] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0053] Next, the present invention will be further described in conjunction with the accompanying drawings and specific embodiments, but it is not a limitation of the present invention.
[0054] The present invention includes:
[0055] A security authentication method for an ad-hoc network system, applicable to an ad-hoc network system formed by multiple ad-hoc network nodes. Before the security authentication method, there is a self-negotiation process in the ad-hoc network system to select the master node and slave nodes in the ad-hoc network system;
[0056] Then as Figure 1 shown, the security authentication method includes:
[0057] Step S1: The master node establishes an asymmetric encryption channel with a remote authentication server. The master node generates a first symmetric key and transmits the first symmetric key through the asymmetric encryption channel;
[0058] Step S2: The master node generates a session ID according to the self-negotiation process and sends the session ID to the authentication server through the asymmetric encryption channel;
[0059] Step S3: The authentication server generates an authorization code according to the session ID, encrypts the authorization code with the first symmetric key, and then sends it to the master node;
[0060] Step S4: The master node decrypts to obtain the authorization code, encrypts it with the second public key, and then sends it to the slave node;
[0061] Step S5: The slave node determines whether the authorization code is generated by the authentication server according to the authorization code and the session ID;
[0062] If so, it indicates that the master node passes the security authentication, and then the communication process starts;
[0063] If not, it indicates that the master node fails the authentication, and the slave node stops communicating with the master node.
[0064] Specifically, aiming at the problem that the ad-hoc network system in the prior art cannot effectively authenticate the master node, in this embodiment, an authentication server is set to authenticate the master node, and by separately setting an asymmetric encryption channel to upload the session ID and a symmetric encryption channel to receive the session ID, a higher transmission security in the authentication process is achieved, thereby avoiding the risk that the authentication information transmitted based on a single encryption channel in the prior art may be intercepted and the data packet may be parsed, and achieving a higher security in the authentication process.
[0065] In the implementation process, the master node and the slave nodes are the same or different devices in a self-organizing network system. According to actual service requirements, the types and communication methods of the devices can be set arbitrarily, as long as they have the self-organizing network function. For example, in one embodiment, the master node is the egress gateway of a local area network, and the slave nodes are multiple self-organizing network devices set in the local area network. In another embodiment, the master node is an industrial control device, and the slave nodes are sensors, industrial equipment, etc. distributed in the application environment. In other embodiments, it can also be any combination of routing devices, application hosts, etc., which does not constitute a limitation to the present invention. The self-negotiation process is a self-organizing network process implemented based on the prior art, which is used to form a self-organizing network communication system among multiple self-organizing network devices and generate a master node for managing the slave nodes according to the corresponding networking rules. The authentication server is a server pre-built in a specific environment, which is configured to authenticate the master node for the authentication request of the master node and generate an authorization code according to the session ID uploaded by the master node. A comparison algorithm for comparing the session ID and the authorization code is pre-generated in each self-organizing network device, and then it is judged whether the authorization code is generated by the authentication server.
[0066] In a preferred embodiment, the authentication server pre-generates at least one pair of a first public key and a first private key before the security authentication method;
[0067] Then as Figure 2 shown, step S1 includes:
[0068] Step S11: The master node requests the first public key from the authentication server, and the authentication server sends the public key to the master node to establish an asymmetric encryption channel;
[0069] Step S12: The master node generates a first symmetric key, encrypts the first symmetric key with the first public key, and then sends the encrypted first symmetric key to the authentication server through the asymmetric encryption channel;
[0070] Step S13: The authentication server decrypts the encrypted first symmetric key with the first private key to obtain the first symmetric key.
[0071] Specifically, aiming at the problem that the self-organizing network system in the prior art cannot effectively prevent the access of unauthenticated nodes, in this embodiment, by setting the authentication server to first send the non-secret first public key to the master node to establish an asymmetric encryption channel, and then transmitting the first symmetric key and the session ID in the asymmetric encryption channel, better security is achieved.
[0072] As an alternative embodiment, the first symmetric key is generated by the master node as a random number with a specific number of digits according to a preset rule to serve as the first symmetric key. The first public key and the first private key can be a pair of asymmetric keys fixed in the authentication server, or one of a group of asymmetric keys, which are replaced according to each authentication process to achieve the effect of one-time password, thereby achieving better authentication security.
[0073] In a preferred embodiment, as Figure 3 shown, step S2 includes:
[0074] Step S21: The master node obtains the session ID corresponding to the auto-negotiation process;
[0075] Step S22: The master node encrypts the session ID using the first public key, and then sends the encrypted session ID to the authentication server through the asymmetric encryption channel;
[0076] Step S23: The authentication server decrypts the encrypted session ID using the first private key to obtain the session ID.
[0077] Specifically, for the problem that the ad-hoc network devices need to be repeatedly authenticated in the existing ad-hoc network system and the process is relatively cumbersome, in this embodiment, by selecting the session ID in each auto-negotiation process, better authentication security is achieved, and for the authentication of each auto-negotiation process, the security authentication process is simplified.
[0078] During the implementation process, the auto-negotiation process may occur once or multiple times in the ad-hoc network system, which depends on the adjustment rules set by the ad-hoc network system. For example, when the master node withdraws from the network, it is necessary to re-execute the auto-negotiation process to regenerate the master node, and the new master node needs to send the current session ID for authentication when performing authentication. In another embodiment, when a slave node in the ad-hoc network system withdraws from the network, or due to the long-distance movement of a mobile device, which changes the network topology structure, an auto-negotiation process will also be executed to generate a new session ID.
[0079] In a preferred embodiment, as Figure 4 shown, step S3 includes:
[0080] Step S31: The authorization server generates an authorization code according to the session ID;
[0081] Step S32: The authorization server encrypts the authorization code using the first symmetric key, and then sends the encrypted authorization code to the master node.
[0082] Specifically, in view of the problem that the self-organizing network system in the prior art uses a single encrypted channel for communication and is easily decrypted, which poses a security risk, this embodiment uses a first symmetric key that is pre-encrypted and transmitted to encrypt the generated authorization code, and then transmits the authorization code back through the symmetric encryption channel. The session ID is uploaded and the authorization code is downloaded twice in different encryption methods, which provides better security.
[0083] In a preferred embodiment, Figure 5 As shown, step S4 includes:
[0084] Step S41: The master node uses the first symmetric key to decrypt the encrypted authorization code to obtain the authorization code;
[0085] Step S42: The master node uses the second public key to encrypt the authorization code, and sends the encrypted authorization code to the slave nodes respectively.
[0086] Specifically, in order to address the problems in the prior art that the confidentiality of self-organizing network systems is poor and that broadcast communications within the network cannot prevent unauthenticated devices from eavesdropping, in this embodiment, a second public key is pre-set in each self-organizing network device, and then the second public key is used to encrypt the authorization code when the master node sends the authorization code to the slave node, thereby preventing external devices that do not have the second public key from obtaining the authorization code and improving security.
[0087] In a preferred embodiment, Figure 6 As shown, step S5 includes:
[0088] Step S51: The slave node uses the second public key to decrypt the encrypted authorization code to obtain the authorization code;
[0089] Step S52: The slave node determines whether the authorization code is generated by the authentication server according to the session ID;
[0090] If yes, it means the master node has passed the security authentication and then starts the communication process;
[0091] If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
[0092] Specifically, in order to address the problem in the prior art that the self-organizing network system cannot effectively determine whether the master node is authenticated by relying solely on the pre-burned authorization code, this embodiment compares the session ID generated during each self-negotiation process with the authorization code sent by the master node to determine whether the master node is authenticated, thereby improving the security of the self-organizing network system.
[0093] In a preferred embodiment, Figure 7 , step S52 comprises:
[0094] Step S521: The slave node generates a comparison value based on the session ID;
[0095] Step S522: The slave node determines whether the authorization code is generated by the authentication server according to the comparison value;
[0096] If so, it indicates that the master node has passed the security authentication, and then the communication process starts;
[0097] If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
[0098] Specifically, for the problem in the prior art that the ad-hoc network system relying only on the pre-burned authorization code cannot effectively determine whether the master node has passed the authentication, in this embodiment, a verification algorithm for calculating the comparison value based on the session ID is preset in each ad-hoc network device, and the comparison value generated by the verification algorithm is compared with the authorization code to determine whether the authorization code is generated by the authentication server. The verification algorithm and the algorithm used in the authentication server to generate the authorization code are the same algorithm or different algorithms.
[0099] In a preferred embodiment, after step S5, a communication process between the master node and the slave node is further included;
[0100] During the communication process, the master node and / or the slave node uses the authorization code as the symmetric key to encrypt the communication data.
[0101] Specifically, for the problem that the ad-hoc network system in the prior art cannot well meet the requirements of encrypted communication, in this embodiment, by using the authorization code in the authentication process as the key for symmetric encryption communication between the master node and the slave node, and between the slave nodes, better security is achieved.
[0102] The above are only the preferred embodiments of the present invention, and do not limit the implementation manners and protection scope of the present invention. For those skilled in the art, it should be able to realize that all the equivalent replacements and obvious changes made by using the description and illustrations of the present invention should be included in the protection scope of the present invention.
Claims
1. A security authentication method for an ad-hoc network system, characterized in that, Applicable to the ad-hoc network system formed by multiple ad-hoc network nodes. There is a self-negotiation process before the security authentication method in the ad-hoc network system to select the master node and slave nodes in the ad-hoc network system; Then the security authentication method includes: Step S1: The master node establishes an asymmetric encryption channel with a remote authentication server. The master node generates a first symmetric key and transmits the first symmetric key through the asymmetric encryption channel; The authentication server pre-generates at least one pair of a first public key and a first private key before the security authentication method; Then the step S1 includes: Step S11: The master node requests the first public key from the authentication server, and the authentication server sends the first public key to the master node to establish the asymmetric encryption channel; Step S12: The master node generates the first symmetric key, encrypts the first symmetric key with the first public key, and then sends the encrypted first symmetric key to the authentication server through the asymmetric encryption channel; Step S13: The authentication server decrypts the encrypted first symmetric key with the first private key to obtain the first symmetric key; Step S2: The master node generates a session ID according to the self-negotiation process and sends the session ID to the authentication server through the asymmetric encryption channel; Step S3: The authentication server generates an authorization code according to the session ID, encrypts the authorization code with the first symmetric key, and then sends it to the master node; Step S4: The master node decrypts to obtain the authorization code, encrypts it with the second public key, and then sends it to the slave node; Step S5: The slave node determines whether the authorization code is generated by the authentication server according to the authorization code and the session ID; If so, it indicates that the master node passes the security authentication, and then the communication process starts; If not, it indicates that the master node fails the authentication, and the slave node stops communicating with the master node; A verification algorithm is set in the slave node, and the verification algorithm is the same algorithm as the algorithm used by the authentication server to generate the authorization code.
2. The security authentication method according to claim 1, wherein The step S2 includes: Step S21: The master node obtains the session ID corresponding to the self-negotiation process; Step S22: The master node encrypts the session ID with the first public key, and then sends the encrypted session ID to the authentication server through the asymmetric encryption channel; Step S23: The authentication server decrypts the encrypted session ID with the first private key to obtain the session ID.
3. The security authentication method according to claim 1, wherein The step S3 includes: Step S31: The authentication server generates the authorization code according to the session ID; Step S32: The authentication server encrypts the authorization code with the first symmetric key, and then sends the encrypted authorization code to the master node.
4. The security authentication method according to claim 1, wherein The step S4 includes: Step S41: The master node decrypts the encrypted authorization code with the first symmetric key to obtain the authorization code; Step S42: The master node encrypts the authorization code using the second public key and sends the encrypted authorization code to the slave nodes respectively.
5. The security authentication method according to claim 3, wherein The step S5 includes: Step S51: The slave node decrypts the encrypted authorization code using the second public key to obtain the authorization code; Step S52: The slave node determines whether the authorization code is generated by the authentication server according to the session ID; If so, it indicates that the master node has passed the security authentication, and then the communication process starts; If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
6. The security authentication method according to claim 5, wherein The step S52 includes: Step S521: The slave node generates a comparison value according to the session ID; Step S522: The slave node determines whether the authorization code is generated by the authentication server according to the comparison value; If so, it indicates that the master node has passed the security authentication, and then the communication process starts; If not, it indicates that the master node has not passed the authentication, and the slave node stops communicating with the master node.
7. The security authentication method according to claim 1, wherein After the step S5, it further includes the communication process between the master node and the slave node; During the communication process, the master node and / or the slave node uses the authorization code as a symmetric key to encrypt the communication data.
Citation Information
Patent Citations
Method and network node device for controlling the run of technology specific push-button configuration sessions within a heterogeneous or homogeneous wireless network and heterogeneous or homogeneous wireless network
CN104380775A
IoT equipment authentication and key agreement method and device
CN105162772A