A Cross-Domain Collaborative Authentication Method for the Internet of Things Based on Blockchain

By adopting a blockchain-based cross-domain collaborative authentication method in the Internet of Things system, the problems of certificate information silos and CA single point failure in traditional solutions are solved, and efficient and secure cross-domain Internet of Things device authentication is achieved.

CN116015669BActive Publication Date: 2025-06-10HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211552851.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-02
Publication Date
2025-06-10
Estimated Expiration
2042-12-02

AI Technical Summary

Technical Problem

Traditional IoT cross-domain authentication schemes have data silos for certificate information and single point of failure problems that CA is susceptible to attack, resulting in low efficiency and insufficient security of cross-domain authentication.

Method used

The cross-domain collaborative authentication method based on blockchain is adopted, and the system parameters are initialized on the blockchain through the domain management machine. The device generates a certificate when joining the domain and publishes it to the blockchain. Authentication and key negotiation are carried out through the blockchain during cross-domain access.

Benefits of technology

It realizes security authentication of cross-domain IoT devices, avoids the island problem of certificate information, improves authentication efficiency, and reduces the risk of single point of CA failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015669B_ABST
    Figure CN116015669B_ABST
Patent Text Reader

Abstract

The present invention discloses an Internet of Things cross-domain collaborative authentication method based on blockchain, which includes the following steps: Step 1, initialization of the system, where the domain management machines of each domain execute the initialization algorithm; Step 2, joining of devices: Before a device performs cross-domain authentication, it needs to join a specific management domain; Step 3, cross-domain authentication: Authentication is performed before a device accesses across domains; Step 4, key negotiation: After the devices authenticate each other successfully, a key is negotiated, and then encrypted communication is carried out through the shared key; Step 5, device exit: The device actively exits a certain domain. In view of the problems of the above-mentioned traditional cross-domain solutions and the applicability of blockchain in the Internet of Things, the present invention proposes a new blockchain-based Internet of Things cross-domain authentication method. Through this method, devices from different domains can be authenticated while ensuring security, and at the same time, its authentication efficiency can also be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of security for cross-domain collaborative authentication among different domains in a multi-domain physical network, and particularly relates to an Internet of Things cross-domain collaborative authentication method based on blockchain. Background Art

[0002] The Internet of Things (IoT) consists of some intelligent devices and shares information with each other through the Internet. These intelligent devices (such as sensors) are deployed in different environments to collect some information or trigger some events. Based on these characteristics, the IoT is widely applied in many fields such as smart cities, intelligent transportation, smart homes, smart agriculture, smart healthcare, and smart industries, bringing great convenience to people's lives and becoming an indispensable part of people's lives.

[0003] With the continuous deepening of IoT applications, the IoT has gradually become large-scale, dynamic, heterogeneous, and shows a distributed development trend. Moreover, the scale of its network is getting larger and larger, the types and quantities of intelligent sensing devices are also increasing, so the sensing information is also increasing. However, since most intelligent devices have insufficient computing power and storage capacity and limited network bandwidth, they are easily attacked, resulting in the leakage of user privacy. Therefore, people's demand for the security of the IoT system is becoming stronger and stronger.

[0004] With the continuous development of network technology and the continuous progress of human society, in order to improve production efficiency, it may be necessary for IoT devices from different domains to communicate and cooperate with each other to complete something. For example, industrial IoT devices from different factories cooperate with each other to complete the production of a certain commodity, which can greatly improve production efficiency. However, for security reasons, each domain will not allow unauthenticated external devices or users to access the internal devices or information of the domain.

[0005] Traditional IoT identity authentication schemes are usually based on the public key infrastructure PKI, and each PKI system will have a certificate authority (CA). This method is based on asymmetric encryption and uses certificates to verify users, devices, or other entities. However, this scheme is not applicable to the scenario of cross-domain IoT authentication, and the reasons for its inapplicability are mainly two aspects. On the one hand, the CA certificates of each domain are not open to the outside, which leads to data islands of certificate information, thus increasing the complexity of cross-domain authentication and making the efficiency of cross-domain authentication very low. On the other hand, authentication can only be completed if the CA is trusted, but the CA is easily attacked or forged, resulting in a threat of single point of failure.

[0006] Blockchain is essentially a decentralized, distributed, and immutable data sharing and transmission mode. Its main implementation mode is to store asset and transaction information on a peer-to-peer network. Since blockchain can achieve immutable data sharing, it can play a certain role in the secure communication and secure sharing across regions in the Internet of Things. Summary of the Invention

[0007] To solve the above technical problems existing in the prior art, the object of the present invention is to propose a cross-domain collaborative authentication method based on blockchain in different Internet of Things domains. The specific technical solution is as follows:

[0008] An Internet of Things cross-domain collaborative authentication method based on blockchain, comprising the following steps:

[0009] Step 1, initialization of the system, where the domain management machine of each domain executes the initialization algorithm;

[0010] Step 2, joining of devices: The device needs to join a specific management domain before performing cross-domain authentication;

[0011] Step 3, cross-domain authentication: Authentication is performed before the device accesses across domains;

[0012] Step 4, key negotiation: After the devices authenticate each other successfully, negotiate a key, and then perform encrypted communication through the shared key;

[0013] Step 5, device exit: The device actively exits a certain domain.

[0014] Further, the initialization work of domain A in step 1 is as follows:

[0015] Step 1.1: The domain management machine of domain A is M A , M A First, select an additive group of order q with a generator p on the elliptic curve E(F p ), where p and q are two large prime numbers; and define a hash function: h 0 :

[0016] Step 1.2: M A Select a random number as the master private key of the system, and then calculate the public key as PK A = p * r A ;

[0017] Step 1.3: M A Sign the system parameters {p, q, h 0 , G, PK A} and write them into the blockchain.

[0018] Further, for the device in step 2 to join domain A, the specific steps are as follows:

[0019] Step 2.1: The device selects a random number as its private key, and then calculates the public key as

[0020] Step 2.2: The device sends the public key, identity identifier, and timestamp to the management machine of domain A, that is, sends to M A ;

[0021] Step 2.3: M A checks the legitimacy of the identity identifier . If it is legitimate, the subsequent steps are executed; if it is not legitimate, the joining fails and exits directly;

[0022] Step 2.4: M A encrypts the identity with its private key public key and the timestamp of the submitted joining request to calculate the certificate of the device

[0023] Step 2.5: M A generates an expiration time for the certificate

[0024] Step 2.6: M A stores the certificate and the expiration time in the local database;

[0025] Step 2.7: M A calculates the hash value of the certificate and sets the status of the certificate state = 1;

[0026] Step 2.8: M A posts the hash value, status, and expiration time to the consortium blockchain and synchronizes the certificate information through the consensus algorithm;

[0027] Step 2.9: M A sends the certificate to the device

[0028] Further, for the device in domain A in step 3 to access the device in domain B it needs to authenticate the device before access. The specific process is as follows:

[0029] Step 3.1: Before initiating an access request, check whether its own certificate has expired. If it has expired, perform the update operation of device information to obtain a new certificate. If it has not expired, execute the following steps;

[0030] Step 3.2: The device in Domain A Sends a connection request to The device in Domain B;

[0031] Step 3.3: The device Forwards the connection request to M after receiving it B ;

[0032] Step 3.4: M B Checks whether there is Authentication information. If there is, execute the next step. If not, jump to Step 3.8;

[0033] Step 3.5: M B Queries the hash value of the certificate from the blockchain;

[0034] Step 3.6: M B Judges whether the hash value is equal to the hash value in the stored authentication information. If they are equal, execute the next step. If not, jump to Step 3.8;

[0035] Step 3.7: M B Judges whether the authentication information has expired. If it has expired, execute the next step. If not, jump to Step 3.17;

[0036] Step 3.8: M B Generates a random string RS and sends it to the device

[0037] Step 3.9: After receiving it, signs RS to obtain

[0038] Step 3.10: Performs a hash operation on the certificate to obtain Then Sends it to M B ;

[0039] Step 3.11: M B Obtains The public key and identity from the certificate, and verifies the signature with the public key to obtain

[0040] Step 3.12: M B Judges whether RS′ and RS are equal. If they are equal, execute the next step. If not, the authentication fails and jumps to Step 3.18;

[0041] Step 3.13: MB Query from the blockchain The relevant information of the certificate;

[0042] Step 3.14: M B Judge whether the certificate has expired, is legal, and whether the hash value of the certificate is equal to If satisfied, execute the next step; if not, it means the authentication fails and jump to step 3.18;

[0043] Step 3.15: M B Store And use The public key to encrypt the certificate of the device And send it to

[0044] Step 3.16: After decryption, obtain the certificate of device B and send it to M A ;

[0045] Step 3.17: Authentication successful;

[0046] Step 3.18: End.

[0047] Furthermore, the specific steps of step 4 are as follows:

[0048] Step 4.1: The device First select a random number As its private key Then calculate its public key as

[0049] Step 4.2: The device Send the public key to the device

[0050] Step 4.3: The device Select a random number As its private key Then calculate its public key as

[0051] Step 4.4: The device Send the public key To the device At this time, the device And the device Calculate the public key as After that, the communication parties can use the public key SK for encrypted communication.

[0052] Furthermore, the specific steps of step 5 are as follows:

[0053] Step 5.1: The device Sign the certificate with one's own private key and send it to M A ;

[0054] Step 5.2: M A Check whether the signature is legal. If it is legal, execute the next step. If it is illegal, the device exits with failure and jumps to Step 5.7;

[0055] Step 5.3: M A Delete the certificate information about the device in the local database ;

[0056] Step 5.4: M A Send a device exit transaction, set the state of the certificate in the blockchain to 0, and synchronize node information through the consensus algorithm;

[0057] Step 5.5: M A Return the exit result to the device

[0058] Step 5.6: The device exits successfully;

[0059] Step 5.7: End.

[0060] In view of the problems of the above-mentioned traditional cross-domain scheme and the applicability of the blockchain in the Internet of Things, the present invention proposes a new blockchain-based cross-domain authentication method for the Internet of Things. Through this method, devices from different domains can be authenticated while ensuring security, and at the same time, its authentication efficiency can also be guaranteed. Brief Description of the Drawings

[0061] Figure 1 is a structural diagram of an application system of a blockchain-based cross-domain collaborative authentication method of the present invention;

[0062] Figure 2 is a flowchart of device joining;

[0063] Figure 3 is a flowchart of device update;

[0064] Figure 4 is a flowchart of device exit;

[0065] Figure 5 is a flowchart of cross-domain authentication;

[0066] Figure 6 is a schematic diagram of key negotiation. Detailed Embodiment

[0067] To better understand the content of the present invention, the present invention will be described in more detail below with reference to the accompanying drawings.

[0068] As Figure 1As shown in the figure, the application system of the blockchain-based Internet of Things cross-domain collaborative authentication method of the present invention consists of multiple domains, and each domain consists of a domain management machine and Internet of Things devices. Among them, the domain management machine is the core manager of this domain, and it can be composed of multiple machines. Its main functions are as follows: 1. Perform the initialization work of the system. This function mainly generates some public parameters required by the system and then publishes them to the blockchain for sharing by the domain management machines of other domains; 2. Be responsible for managing the devices in this domain, such as the joining of devices, the update of device information, and the withdrawal of devices; 3. The domain management machine of the local domain is a node in the consortium chain, and the domain management machines in all domains jointly form the consortium chain and participate in its consensus process. The Internet of Things devices are mainly composed of some intelligent sensors, mobile phones and other devices, and some of the Internet of Things devices may have relatively weak storage and processing capabilities by themselves.

[0069] In the cross-domain collaborative authentication scheme based on blockchain, assume that there are two domains, namely Domain A and Domain B. The devices in Domain A Before performing cross-domain access, the device joining operation needs to be carried out first. After the joining is successful, the domain management machine of Domain A will generate a certificate for the device Then publish the hash value of its certificate to the blockchain, which can not only save memory space but also ensure its security. After that, the device Initiate a cross-domain access request to the devices in Domain B And will forward this request to the domain management machine M of Domain B B It is completed by M for cross-domain authentication operations. After authentication, And Will negotiate a common key and then conduct secure communication. The specific steps are as follows:

[0070] Step 1: Initialization of the system

[0071] For the initialization of the system, the domain management machines of each domain execute the initialization algorithm. The initialization work of each domain is basically the same. Taking Domain A as an example, the initialization work of Domain A is as follows:

[0072] Step 1.1: The domain management machine of Domain A is M A ,M A First, select a q-order additive group with a generator p on the elliptic curve E(F p )), where p and q are two large prime numbers. And define a hash function:

[0073] h 0 :

[0074] Step 1.2: M A Select a random number As the main private key of the system, then calculate the public key as PK A = p * r A .

[0075] Step 1.3: M A Sign the system parameters {p, q, h 0 , G, PK A} and write them into the blockchain. The initialization of the system is completed.

[0076] Step 2: Joining of the device

[0077] Before a device performs cross-domain authentication, it needs to join a specific management domain. Assume the device wants to join domain A. Its joining algorithm is as Figure 2 shown, and its specific joining process is as follows:

[0078] Step 2.1: The device selects a random number as its private key, and then calculates the public key as

[0079] Step 2.2: The device sends the public key, identity identifier, and timestamp to the management machine of domain A, that is, sends to M A

[0080] Step 2.3: M A checks the legality of the identity identifier . If it is legal, the following steps are executed; otherwise, the joining fails and it exits directly.

[0081] Step 2.4: M A encrypts its identity public key and the timestamp of the submitted joining request to calculate the certificate of the device

[0082] Step 2.5: M A generates an expiration time for the certificate

[0083] Step 2.6: M A stores the certificate and the expiration time in the local database.

[0084] Step 2.7: M A calculates the hash value of the certificate and sets the status of the certificate state = 1.

[0085] Step 2.8: M APublish the hash value, status, and expiration time to the consortium blockchain and synchronize the certificate information through the consensus algorithm.

[0086] Step 2.9: M A Send the certificate to the device At this time, the device Successfully joins domain A.

[0087] Step 3: Cross-domain authentication

[0088] Now assume that a device in domain A wants to access a device in domain B Before accessing, the device needs to be authenticated. The cross-domain authentication process is as Figure 5 shown, and the specific authentication process is as follows.

[0089] Step 3.1: Before initiating an access request, first check whether its own certificate has expired. If it has expired, perform the update operation of the device information to obtain a new certificate. The update algorithm is as Figure 3 shown. If it has not expired, perform the following steps.

[0090] Step 3.2: The device in domain A sends a connection request to the device in domain B

[0091] Step 3.3: The device forwards the connection request to M after receiving it B .

[0092] Step 3.4: M B Check whether there is authentication information. If there is, perform the next step; if not, jump to Step 3.8

[0093] Step 3.5: M B Query the hash value of the certificate from the blockchain.

[0094] Step 3.6: M B Judge whether the hash value is equal to the hash value in the stored authentication information. If it is equal, perform the next step; if not, jump to 3.8.

[0095] Step 3.7: M B Judge whether the authentication information has expired. If it has expired, perform the next step; if not, jump to 3.17

[0096] Step 3.8: M B Generate a random string RS and send it to the device

[0097] Step 3.9:​ After receiving, perform an RS signature to obtain

[0098] Step 3.10: Perform a hash operation on the certificate to obtain Then Send it to M B .

[0099] Step 3.11: M B After obtaining the public key and identity of from the certificate, verify the signature with the public key to obtain

[0100] Step 3.12: M B Judge whether RS' and RS are equal. If they are equal, execute the next step. If they are not equal, the authentication fails and jump to 3.18

[0101] Step 3.13: M B Query the relevant information of the certificate from the blockchain.

[0102] Step 3.14: M B Judge whether the certificate has expired, is legal, and whether the hash value of the certificate is equal to If it is satisfied, execute the next step. If it is not satisfied, it means the authentication fails and jump to 3.18

[0103] Step 3.15: M B Store And use the public key to encrypt the certificate of the device and send it to

[0104] Step 3.16: After decryption, obtain the certificate of device B and send it to M A .

[0105] Step 3.17: Authentication successful.

[0106] Step 3.18: End.

[0107] Step 4: Key negotiation

[0108] When devices and authenticate each other successfully, they can negotiate a key, and then perform encrypted communication through this shared key. The key negotiation process is as Figure 6 shown. The specific steps are as follows:

[0109] Step 4.1: Device First select a random number As its private key Then calculate its public key as

[0110] Step 4.2: Device Send the public key to the device

[0111] Step 4.3: Device Select a random number As its private key Then calculate its public key as

[0112] Step 4.4: Device Send the public key To the device At this time, device And device Can calculate their common key as After that, the two communicating parties can use the common key SK for encrypted communication.

[0113] Step 5: Device exits

[0114] The device can actively exit a certain domain, and its specific exit process is as Figure 4 Shown, and its specific steps are as follows:

[0115] Step 5.1: Device Sign the certificate with its own private key and send it to M A .

[0116] Step 5.2: M A Check whether the signature is legal. If it is legal, execute the next step. If it is not legal, the device exit fails and jumps to Step 5.7.

[0117] Step 5.3: M A Delete the certificate information about the device In the local database.

[0118] Step 5.4: M A Send a device exit transaction, set the state of the certificate in the blockchain to 0, and synchronize node information through the consensus algorithm.

[0119] Step 5.5: M A Return the exit result to the device

[0120] Step 5.6: The device exits successfully.

[0121] Step 5.7: End.

Claims

1. A cross - domain collaborative authentication method for the Internet of Things based on blockchain, characterized in that it includes the following steps: Step 1, system initialization, where the domain management machines of each domain execute the initialization algorithm; Step 2, device joining: Before cross - domain authentication, the device needs to join a specific management domain; Step 3, cross - domain authentication: Authentication is performed before the device accesses across domains; Step 4, key negotiation: After the devices authenticate each other successfully, negotiate keys, and then perform encrypted communication through the shared keys; Step 5, device exit: The device actively exits a certain domain; The initialization work of domain A in the said Step 1 is as follows: Step 1.1: The domain management machine of domain A is M A ,M A First, select an additive group of order q with a generator p on the elliptic curve E(F p ), where p and q are two large prime numbers; and define a hash function: Step 1.2: M A Select a random number as the system's master private key, and then calculate the public key as PK A = p * r A ; Step 1.3: M A Sign the system parameters {p, q, h 0 , G, PK A} and write them into the blockchain; The device in step 2 Adding to domain A is as follows: Step 2.1: Device Select a random number as its private key, and then calculate the public key as Step 2.2: Device Send the public key, identity identifier, and timestamp to the management machine in Domain A, that is, send to M A ; Step 2.3: M A Verify the legality of the identity identifier If it is legal, execute the subsequent steps; if it is illegal, add it to the failure and directly exit; Step 2.4: M A Encrypt with the private key Identity Public key Timestamp for submitting the join request To calculate and obtain the device Certificate Step 2.5: M A Generate an expiration time for the certificate Step 2.6: M A Store the certificate and expiration time in the local database; Step 2.7: M A Calculate the hash value of the certificate and set the status of the certificate state = 1; Step 2.8: M A Publish the hash value, status, and expiration time to the consortium blockchain and synchronize the certificate information through the consensus algorithm; Step 2.9: M A Send the certificate to the device The device in domain A in step 3 Access the device in domain B Before access, the device Needs to be authenticated. The specific process is as follows: Step 3.1: Before initiating an access request, check whether one's own certificate has expired. If it has expired, perform an update operation on the device information to obtain a new certificate. If it has not expired, perform the following steps; Step 3.2: The device in domain A sends a connection request to the device in domain B; Step 3.3: Device Forward the connection request to M after receiving it B ; Step 3.4: M B Check whether there is certification information. If there is, execute the next step; if not, jump to Step 3.8; Step 3.5: M B Query the hash value of the certificate from the blockchain; Step 3.6: M B Determine whether the hash value is equal to the hash value in the stored authentication information. If they are equal, proceed to the next step; otherwise, jump to Step 3.

8. Step 3.7: M B Determine whether the authentication information has expired. If it has expired, proceed to the next step. If not, jump to Step 3.17; Step 3.8: M B Generate a random string RS and send it to the device Step 3.9: After receiving, perform RS signature to obtain Step 3.10: Perform a hash operation on the certificate to obtain Then Send it to M B ; Step 3.11: M B After obtaining the public key and identity from the certificate verify the signature with the public key to obtain Step 3.12: M B Determine whether RS′ and RS are equal. If they are equal, proceed to the next step; if not, the authentication fails and jump to Step 3.18; Step 3.13: M B Query from the blockchain for relevant information of the certificate; Step 3.14: M B Determine whether the certificate has expired, is legal, and whether the hash value of the certificate is equal to If satisfied, execute the next step; if not, it means the authentication fails and jump to Step 3.18; Step 3.15: M B Store And use The public key to encrypt the device Certificate and send it to Step 3.16: After decryption, obtain the certificate of device B and send it to M A ; Step 3.17: Authentication successful; Step 3.18: End.

2. The cross - domain collaborative authentication method for the Internet of Things based on blockchain according to claim 1, characterized in that: The specific steps of Step 4 are as follows: Step 4.1: Device First, select a random number as its private key Then calculate its public key as Step 4.2: Device Send the public key to the device Step 4.3: Device Select a random number as its private key Then calculate its public key as Step 4.4: Device Send the public key to the device At this time, the device and the device calculate the public key as After that, both communication parties use the public key SK for encrypted communication.

3. The cross - domain collaborative authentication method for the Internet of Things based on blockchain according to claim 2, characterized in that: The specific steps of the said Step 5 are as follows: Step 5.1: Device Sign the certificate with its own private key and send it to M A ; Step 5.2: M A Check whether the signature is legal. If it is legal, execute the next step. If it is illegal, the device exits with failure and jumps to Step 5.7; Step 5.3: M A Delete the certificate information of the device from the local database; Step 5.4: M A The sending device exits the transaction, sets the state of the certificate in the blockchain to 0, and synchronizes node information through the consensus algorithm; Step 5.5: M A Return the exit result to the device Step 5.6: Device exit successful; Step 5.7: End.

Citation Information

Patent Citations

  • Decentralized Internet-of-Things cross-domain access authorization method and system

    CN111835528A

  • Cross-domain anonymous authentication method and system based on block chain

    CN112039872A