A lightweight distributed security communication authentication method and system based on blockchain

Through the lightweight distributed authentication method combined with blockchain and edge computing, the problems of cumbersome identity authentication and low security in industrial control systems are solved, distributed authentication and key negotiation between devices are realized, and the security and traceability of the system are enhanced.

CN116232732BActive Publication Date: 2025-07-22HARBIN INST OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310229760.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-10
Publication Date
2025-07-22
Estimated Expiration
2043-03-10

AI Technical Summary

Technical Problem

The existing industrial control system identity authentication technology mainly relies on centralized certificate authentication. The authentication process is cumbersome and has low security. The increase in the number of equipment leads to limited computing capabilities, and the centralized management model faces challenges.

Method used

The lightweight distributed secure communication authentication method based on blockchain is adopted, and public parameters and private keys are generated through the security management center, and local data processing and operation are used by edge nodes. Device identity authentication is realized in combination with the elliptic curve digital signature algorithm, and authentication information is stored on the blockchain to complete distributed authentication and key negotiation between devices.

Benefits of technology

It realizes distributed authentication between devices, enhances the security and traceability of the authentication process, reduces the complexity of public key certificate management, and provides safe and reliable data transmission guarantees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232732B_ABST
    Figure CN116232732B_ABST
Patent Text Reader

Abstract

The present invention discloses a lightweight distributed security communication authentication method and system based on blockchain. The method completes the preliminary configuration and preprocessing through a security management center, generates the public parameters of the system and the information used in the signature authentication process by using the elliptic curve digital signature algorithm, and publishes the authentication information to the blockchain; the edge nodes perform the processing and operation of data locally to complete the authentication process of multiple subjects between the edge nodes and devices and between devices; after the multi-subject authentication process is completed, the negotiation of the shared key is realized through the transmission of three pieces of information. The present invention uses blockchain to realize the storage of key information, ensures the publicity and traceability of data, and reduces the centralization function of the security management center. In the multi-subject authentication process, the data is stored distributively, the distributed authentication between devices is realized, and the negotiation of the shared key is completed, providing security guarantee for the subsequent data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security of industrial control systems, and relates to a secure communication authentication method and system, specifically to a lightweight distributed secure communication authentication method and system based on blockchain applied to industrial control systems. Background Art

[0002] With the development of modern Internet technology, information technology is constantly penetrating into industrial control systems, making the connection between industrial control systems and the Internet closer. While Internet technology improves industrial productivity, it also brings many malicious network attacks to industrial control systems themselves, and their security is greatly threatened. However, during the initial construction of industrial control systems, insufficient consideration was given to the security risks brought by the connection to the network, resulting in weak resistance to malicious attacks. The information security issues of industrial control systems should be given sufficient attention.

[0003] From the composition structure of industrial control systems, the terminal devices of industrial control systems are at the bottom layer, used to control field devices, communicate directly with the main control center, and need to store relatively important data. However, their application scenarios are very closed, in unattended fields, with almost no security protection measures, and are easily attacked maliciously by the network. If the industrial control system is invaded by illegal personnel and important data stored in the terminal device is stolen, the consequences will be disastrous. Therefore, it is urgent to strengthen the security protection of industrial control systems. As the first line of defense for information security protection, identity authentication plays a particularly important role and should provide a secure and reliable authentication solution for industrial control systems.

[0004] However, existing research related to identity authentication in industrial control systems still mainly focuses on centralized certificate authentication, with a cumbersome authentication process and low security. At the same time, with the increase in industrial demand, the number of devices is increasing. The cost control of industrial control systems has limited the computing power of industrial control devices to a certain extent, and problems such as a large number of devices, small storage capacity, and limited processor computing power have emerged in industrial control systems, posing many new challenges to the centralized management mode. Summary of the Invention

[0005] Aiming at problems such as imperfect identity authentication technology and low security of the centralized management mode in industrial control systems, the present invention provides a lightweight distributed secure communication authentication method and system based on blockchain, which realizes distributed authentication between devices, ensures the openness, integrity, and traceability of information during the authentication process, can prevent terminal devices from being invaded by illegal external personnel, and protect sensitive data of the system.

[0006] The object of the present invention is achieved through the following technical solutions:

[0007] A lightweight distributed security communication authentication method based on blockchain, comprising the following steps:

[0008] Step 1. Initialization phase:

[0009] The security management center generates the public parameters pp, identifier hid, signature master private key K M-pri , signature master public key K M-pub of the system, as well as the private key K EP-pri of the edge computing node and the private key K ED-pri of the terminal device. The public keys of the edge computing node and the terminal device are their unique identity identifiers, denoted as K x-pub ;

[0010] Step 2. Registration phase:

[0011] Assume that the security management center is trusted. The terminal device registration is carried out according to the following steps:

[0012] Step 2-1. The security management center first selects the message M to be encrypted, and sends the message M to the edge node through a secure channel, and at the same time sends it to the terminal device;

[0013] Step 2-2. After receiving the message M, the edge node encrypts the message M according to the public key encryption algorithm using its own public key K EP-pub to generate the ciphertext E n (M). Then the edge node sends the ciphertext E n (M) to the terminal device it manages through a secure channel;

[0014] Step 2-3. After receiving the ciphertext E n (M), the terminal device saves it, and then generates the digest h of the message M using its own public key K ED-pub and the hash function H1() in the elliptic encryption algorithm. Then it generates the digital signature S using its own private key K ED-pri Finally, the signature (h, S) is obtained;

[0015] Step 2-4. The terminal device sends the ciphertext E n (M) and the digital signature (h, S) to the security management center. The security management center creates a transaction through a smart contract, and publishes the public parameters pp, signature master public key K M-pub , ciphertext E n (M), signature (h, S), identifier hid and the public key K ED-pub of the terminal device to the blockchain ledger. At this time, it indicates that the device has been legally registered in the blockchain network;

[0016] Step 3. Device identity authentication phase:

[0017] Step Three One: The terminal device sends an authentication request to join the system to the edge node. After receiving the authentication request, the edge node queries the device-related information on the blockchain, obtains the relevant information published by the blockchain in the previous stage, and records the public parameters of the system as pp', the signature master public key as K', M-pub the ciphertext as E' n (M), the signature as (h', S'), the identifier as hid', and the public key of the terminal device as K' ED-pub ;

[0018] Step Three Two: After obtaining the relevant information, the edge node first uses its own private key K EP-pri to decrypt the ciphertext E' n (M) to obtain the message M';

[0019] Step Three Three: After the edge node obtains the message M', it then uses the message M', the public parameters pp' of the system, the signature master public key K' M-pub , the ciphertext E' n (M), the signature (h', S'), the identifier hid', and the public key K' of the terminal device ED-pub to calculate the signature (h', S') according to the identity-based digital signature algorithm to obtain the message digest h2 of the message M';

[0020] Step Three Four: Judge whether h2 = h' holds. If it holds, the identity of the terminal device is legal, and the terminal device is allowed to join the system, and the event is broadcast to the whole network; otherwise, the identity of the terminal device is incorrect, and it is not allowed to join the industrial control system and does not enter the mutual authentication stage between devices;

[0021] Step Four: Mutual authentication stage between devices:

[0022] Assume that terminal device 1 and terminal device 2 have respectively passed the authentication of edge node 1 and edge node 2, and the mutual authentication between devices is carried out according to the following steps:

[0023] Step Four One: After edge node 1 completes the authentication of terminal device 1, edge node 1 will automatically pair the corresponding Ethereum mapping address for terminal device 1 and set the access validity period t for terminal device 1 through the timestamp t0 E ;

[0024] Step Four Two: Terminal device 1 queries the authentication information of terminal device 2 and edge node 2 in the blockchain network through the smart contract and sends an identity authentication request for terminal device 2;

[0025] Step 43: After the terminal device 1 sends an identity authentication request, the smart contract creates a message token Token with the Ethereum addresses of the edge node 2, the terminal device 1, and the terminal device 2, as well as the current timestamp t0, and sends this Token to the terminal device 1 and the edge node 2;

[0026] Step 44: After the terminal device 1 receives this Token, it first verifies whether the timestamp t0 ≤ t E holds. If it holds, the next step of authentication is carried out. If it does not hold, this Token is discarded and the authentication process ends;

[0027] Step 45: The terminal device 1 uses its own private key K ED-pri (1) Signs the message token Token according to the identity-based digital signature algorithm and sends it to the edge node 2;

[0028] Step 46: After the edge node 2 receives the signature, it uses the public key K of the terminal device 1 ED-pub (1) to verify this signature. If the verification passes, the edge node 2 generates a random number R1. The edge node 2 uses its own private key K EP-pri (2) to sign the message token Token according to the identity-based digital signature algorithm, and returns the random number R1, the signature, and the verification result to the terminal device 1;

[0029] Step 47: After the terminal device 1 receives the random number R1, the signature, and the verification result sent by the edge node 2, it uses the public key K of the edge node 2 EP-pub (2) to verify this signature. If the verification passes, the terminal device 1 generates a random number R2, and returns the random number R2 and the verification result to the edge node 2. At this time, the identity authentication process between devices is completed. If the verification fails, all information is discarded, the identity authentication process between devices ends, and it does not enter the key negotiation phase;

[0030] Step 5. Key negotiation phase:

[0031] After successfully sending the random numbers R1 and R2 to each other during the mutual authentication phase between devices, the key negotiation is carried out according to the following steps:

[0032] Step 51: The terminal device 1 generates a random number R3, and uses the public key K of the terminal device 2 ED-pub (2) to encrypt the random number R3 according to the elliptic curve encryption algorithm, generating the ciphertext E n (R3). Then, the generated E n (R3) and an encryption suite are sent to the terminal device 2;

[0033] Step 52: The terminal device 2 receives the ciphertext En (After R3), use its own private key K ED-pri (2) Decrypt E n (R3) to obtain the random number R3 generated by the terminal device 1. At this time, both the terminal device 1 and the terminal device 2 have three random numbers R1, R2, and R3. Then, both sides generate a symmetric encryption key K according to the same algorithm in the encryption suite sym ;

[0034] Step Five Three: The terminal device 2 uses the negotiated key K sym to encrypt the third random number R3 and send it to the terminal device 1. After receiving the ciphertext, the terminal device 1 uses the symmetric key K sym to decrypt it;

[0035] Step Five Four: The terminal device 1 compares whether the decrypted data is correct. If it is correct, it notifies the terminal device 2 that the key negotiation is successful, and subsequent data communication uses this symmetric key for encrypted communication; if it is incorrect, it restarts from Step Five One.

[0036] A blockchain-based lightweight distributed secure communication authentication system for implementing the above method, including a security management center, distributed edge nodes, and terminal devices, where:

[0037] The security management center is responsible for setting and publishing the public parameters of the system, generating the private keys of all edge nodes and terminal devices, and performing identity management on the terminal devices, implementing the registration of each device, and writing the identity information of the newly added device into the blockchain;

[0038] The distributed edge nodes are responsible for maintaining the basic operation of the blockchain, managing the terminal devices in the area, and verifying the legality of the terminal device identities;

[0039] The terminal devices interact with the smart contract through the Ethereum client with the help of the distributed edge nodes. For the terminal devices that have successfully joined the industrial control system, both parties will perform identity authentication and key negotiation before communication.

[0040] Compared with the prior art, the present invention has the following advantages:

[0041] 1. The present invention proposes a blockchain-based lightweight distributed secure communication authentication scheme, which combines blockchain technology with edge computing technology and applies it to the identity authentication of industrial control systems. In the authentication process, edge nodes are used to perform local data preprocessing and operations, and the data is distributedly stored, realizing distributed authentication between devices. At the same time, a timestamp is added to impose relevant constraints on the access time, enhancing the security of the authentication system.

[0042] 2. The present invention performs the pre - registration work for terminal devices through the security management center, and writes information such as system parameters, digital signatures, and authentication results into the blockchain by creating smart contracts. Utilizing the immutable feature of the blockchain, it realizes the storage of key information of the authentication system, ensures the publicity, integrity, and traceability of information during the authentication process. At the same time, it weakens the central role of the security management center and enhances the security of the authentication system.

[0043] 3. The present invention uses an identity - based digital signature algorithm to implement the authentication process of the system. Taking its own identity identifier as its public key, the existence of public key certificates is no longer required, greatly reducing the complexity of public key certificate management and maintenance. At the same time, after the two devices confirm the correctness of each other's identities, the generation of symmetric keys is completed, providing security guarantees for subsequent data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is the entity information interaction flow chart of the present invention;

[0045] Figure 2 is the timing diagram of the registration stage of the present invention;

[0046] Figure 3 is the timing diagram of the device identity authentication stage of the present invention;

[0047] Figure 4 is the timing diagram of the mutual authentication stage between devices of the present invention;

[0048] Figure 5 is the timing diagram of the key negotiation stage of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] The technical solutions of the present invention will be further described below in conjunction with the accompanying drawings, but are not limited thereto. Any modification or equivalent replacement of the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention shall be covered by the protection scope of the present invention.

[0050] The present invention provides a lightweight distributed security communication authentication system based on blockchain for industrial control systems, as Figure 1 shown. The system includes a security management center, distributed edge nodes, and terminal devices, where:

[0051] Security management center: mainly responsible for setting and publishing the public parameters of the system, generating the private keys of all edge nodes and terminal devices, performing identity management on terminal devices, realizing the registration of each device, and writing the identity information of newly added devices into the blockchain. The security management center interacts with the smart contract through a front - end application program;

[0052] Distributed Edge Node: The distributed edge node is located near the edge device and locally executes the preprocessing and operation of data, thereby reducing the latency of communication between the cloud server and the device; each distributed edge node has a pair of public / private keys, and each edge node generates a unique Ethereum address through its public key; the distributed edge node is mainly responsible for maintaining the basic operation of the blockchain, managing the terminal devices within the area, and verifying the legality of the identities of the terminal devices.

[0053] Terminal Device: Each terminal has a pair of public / private keys, and each terminal device generates an Ethereum address based on this pair of public / private keys; each terminal device is mapped to a distributed edge node, and the terminal device interacts with the smart contract through the distributed edge node via an Ethereum client. For the terminal devices that have successfully joined the industrial control system, the two parties will perform identity authentication and key negotiation before communication.

[0054] The present invention also provides a lightweight distributed security communication authentication method based on blockchain. First, the security management center completes the preliminary configuration and preprocessing, generates the public parameters of the system and the information used in the signature authentication process by using the elliptic curve digital signature algorithm, and publishes the authentication information to the blockchain. Then, the edge node locally executes the processing and operation of the data to complete the authentication process of multiple subjects between the edge node and the device and between the devices. Finally, after the multi-subject authentication process is completed, the negotiation of the shared key is realized through the transmission of three pieces of information. The method includes an initialization stage, a registration stage, a device identity verification stage, an inter-device mutual authentication stage, and a key negotiation stage. The specific steps are as follows:

[0055] Step 1. Initialization stage:

[0056] In this stage, the security management center mainly generates the public parameters pp of the system, the identifier hid, the signature master private key K M-pri and the signature master public key K M-pub , as well as the private key of the edge computing node and the private keys K x-pri (when x = EP, K EP-pri is the key of the edge computing node, and when x = ED, K ED-pri is the key of the terminal device, and the same situation will be handled in the same way below). The public keys of the edge computing node and the terminal device are their unique identity identifiers, denoted as K x-pub . The private keys of the edge computing node and the terminal device are generated by the security management center according to their public keys K x-pub through the elliptic curve encryption algorithm. The specific steps include the following:

[0057] Step 1.1: The security management center generates K M-pri∈[1,N - 1] is used as the signature master private key, where N is the order of the cyclic groups G1, G2, and G T ; G T is a multiplicative cyclic group of order N, and G1 and G2 are additive cyclic groups of order N. Then calculate the element K M-pub = [K M-pri P2 in the elliptic curve encryption algorithm G2, where P2 is the generator of the group G2; Use K M-pub as the signature master public key, then the signature master key pair is (K M-pri , K M-pub ); The security management center will secretly store K M-pri , and publicly disclose K M-pub , and at the same time use one byte to represent the function identifier hid of the signature private key generation;

[0058] Steps one and two: The public keys of the edge node and the terminal device are their respective unique identity identifiers, denoted as K x-pub , To generate the signature private key K x-pri of the edge node and the terminal device, the security management center first calculates t1 = H1(K N ||hid, N)+K x-pub on the finite field F M-pri of the elliptic encryption algorithm, where H1 is a cryptographic function derived from a cryptographic hash function. If t1 = 0, return to step one. Otherwise, calculate t2 and K x-pri through the elliptic encryption algorithm. The calculation formula is as follows: K x-pri = [t2]P1, where P1 is the generator of the group G1.

[0059] Define the public key K EP-pub (1) of edge node 1 to have the value "byjd01", the public key K EP-pub (2) of edge node 2 to have the value "byjd02", the public key K ED-pub (1) of terminal device 1 to have the value "zdsb01", and the public key K ED-pub (2) of terminal device 2 to have the value "zdsb02".

[0060] According to the above calculation formula, the calculated private key K EP-pri (1) of edge node 1 has the value "4a07cc7bb01ae6cb81c97d3e647f9f07c6362c39cf40f6d67b5418767c4a9f84492d6413ebe1f5846ed8460c3386c2590a94ddd819815a76b9fc2cfd8d5388bf", and the private key K EP-pri(2) The value is "2aea8aff692d8aa54647b9ed8fede4d7a79e730119ba6e683cb29874255c603b73ff5198a5c8beafc602cdf96408191d17e98b94d574802b093617fe30cadc4e", the private key K of the terminal device 1 ED-pri (1) The value is "1f060b621c69f56aa44b1070f3d2c2a1d8d8a1b86a0bc10f8ed0ee04c8b7fe8d260cb46b9e5f6296b43a824639e22c5aafa c7ac07905290b930cd3bddad8c87a", the private key K of the terminal device 2 ED-pri (2) The value is "013d6db37bcb812a6a5c4d6eef5b426b399653a0e3be2299b6708f37f9495cf7902bf7c387e32268cea3bba1c25e3db7f6e4351091b2f7a199e7f4acb67e9875".

[0061] Step 2. Registration phase:

[0062] In this phase, the security management center mainly completes the registration work before the authentication of the terminal device. It should be noted that both the terminal device 1 and the terminal device 2 need to perform the registration work before authentication, and the steps are the same. Here, only the registration work of the terminal device 1 is taken as an example for detailed description.

[0063] Assume that the security management center is trustworthy, as Figure 2 shown, the registration of the terminal device 1 is carried out according to the following steps:

[0064] Step 2-1. The security management center first selects the message M to be encrypted, and the specific value is "4368696e65736520494245207374616e64617264", and sends the message M to the edge node 1 through the secure channel, and at the same time sends it to the terminal device 1.

[0065] Step 2-2. After receiving the message M, the edge node 1 encrypts the message M according to the public key encryption algorithm using its own public key "byjd01" to generate the ciphertext E n(M), with the specific value being "52ebabff56224965f542b199afa32b39f40216b9929c503df2349eecb3f08c7d15315125a4f115e8eda15a7c7d261bd354a364a524e0c3d8df03e3ea225cf9feadba14f85d1db3a64cda289576bbea4d4fdf6b98bfaff960fcd02b45cccd14ad60a3a9e85ce21c32fb774a1afd4a4ee4befa04b1f3f09239a7d750f19656340ae2cad29d705729d5aa1a529d3d96e089". Then, the edge node 1 sends the ciphertext E n (M) to the terminal device 1 through a secure channel.

[0066] Step 2.3: After receiving the ciphertext E n (M), the terminal device 1 saves it. Then, it uses its own public key ED1 and the hash function H1() in the elliptic encryption algorithm to generate the digest h of the message M, with the specific value being "430ad7cb71d3b184a39d4e47a13446123cae8fed5012609db24ccdbfbfbf1780". Then, it uses its own private key K ED-pri to generate the digital signature S, with the specific value being "92f8e49a2df9fe56eae37582bcef51297283cb8fb054a18fd0f54eece19bf7663a81f64f91f4790c7c4af93c90c516954836c649923c77e052f9ff6c37a8583d". Finally, the signature (h, S) is obtained.

[0067] Step 2.4: The terminal device 1 sends the ciphertext E n (M) and the digital signature (h, S) to the security management center. The security management center creates a transaction through a smart contract and publishes the public parameters pp of the system, the signature master public key K M-pub , the ciphertext E n (M), the signature (h, S), the identifier hid, and the public key K ED-pub information of the terminal device 1 to the blockchain ledger. At this time, it indicates that the device has been legally registered in the blockchain network.

[0068] Step 3: Device identity authentication phase:

[0069] In this stage, the edge nodes mainly verify the legitimacy of the identity of the terminal devices to be added to the system by querying the information in the blockchain. Here, a detailed example is given to illustrate the identity authentication process between edge node 1 and terminal device 1 to be added to the system. As Figure 3 shown, the specific steps are as follows:

[0070] Step 3-1: Terminal device 1 sends an authentication request to join the system to edge node 1. After receiving the authentication request, edge node 1 queries the relevant information of terminal device 1 on the blockchain, obtains the relevant information published by the blockchain in the previous stage, and records the public parameters of the system as pp', the signature master public key as K' M-pub , the ciphertext as E' n (M), the signature as (h', S'), the identifier as hid' and the public key of the terminal device as K' ED-pub .

[0071] Step 3-2: After obtaining the relevant information, edge node 1 first uses its own private key K EP-pri to decrypt the ciphertext E' n (M) to obtain the message M'. The normal value of M' is "4368696e65736520494245207374616e64617264".

[0072] Step 3-3: After obtaining the message M', edge node 1 then uses the message M', the public parameters pp' of the system, the signature master public key K' M-pub , the ciphertext E' n (M), the signature (h', S'), the identifier hid' and the public key K' of terminal device 1 ED-pub to calculate the signature (h', S') according to the identity-based digital signature algorithm to obtain the message digest h2 of the message M'.

[0073] Step 3-4: When h2 = h' = 430ad7cb71d3b184a39d4e47a13446123cae8fed5012609db24ccdbfbfbf1780, the identity of terminal device 1 is legal, and it is agreed to add terminal device 1 to the system and broadcast this event to the whole network; otherwise, the identity of terminal device 1 is incorrect and it is not allowed to join the industrial control system, and it does not enter the device-to-device mutual authentication stage.

[0074] Step 4: Device-to-device mutual authentication stage:

[0075] This stage mainly realizes the identity authentication between terminal devices through edge nodes and smart contracts. After the terminal devices join the industrial control system network, they still need to complete the identity authentication between devices and the exchange of symmetric keys to conduct secure communication. Assume that terminal device 1 and terminal device 2 have respectively passed the authentication of edge node 1 and edge node 2. As Figure 4 shown, the mutual authentication between devices is carried out according to the following steps:

[0076] Step 4-1: After edge node 1 completes the authentication of terminal device 1, edge node 1 pairs the corresponding Ethereum mapping address for terminal device 1 and sets the access validity period t for terminal device 1 through the timestamp t0 E .

[0077] Step 4-2: Terminal device 1 queries the authentication information of terminal device 2 and edge node 2 in the blockchain network through the smart contract and sends an identity authentication request for terminal device 2.

[0078] Step 4-3: After terminal device 1 sends the identity authentication request, the smart contract creates a message token Token with the Ethereum addresses of edge node 2, terminal device 1, and terminal device 2 and the current timestamp t0, and sends this Token to terminal device 1 and edge node 2.

[0079] Step 4-4: After receiving this Token, terminal device 1 first verifies whether the timestamp t0 ≤ t E holds. If it holds, the next step of authentication is carried out. If it does not hold, this Token is discarded and the authentication process ends.

[0080] Step 4-5: Terminal device 1 uses its own private key K ED-pri (1) Sign the message token Token according to the identity-based digital signature algorithm and send it to edge node 2.

[0081] Step 4-6: After receiving the signature, edge node 2 uses the public key K of terminal device 1 ED-pub (1) Verify the signature. If the verification passes, edge node 2 generates a random number R1. Edge node 2 uses its own private key K EP-pri (2) Sign the message token Token according to the identity-based digital signature algorithm and return the random number R1, the signature, and the verification result to terminal device 1.

[0082] Step 4-7: After receiving the random number R1, the signature, and the verification result sent by edge node 2, terminal device 1 uses the public key K of edge node 2 EP-pub(2) Verify the signature. If the verification is successful, the terminal device 1 will generate a random number R2 and return the random number R2 and the verification result to the edge node 2. At this time, the identity authentication process between the devices is completed; if the verification fails, discard all information, and the identity authentication process between the devices ends without entering the key negotiation phase.

[0083] Step Five: Key Negotiation Phase:

[0084] This phase mainly completes the negotiation of the symmetric key between the devices. After the mutual authentication of the two devices in the previous phase, the terminal device 1 and the terminal device 2 each generate a random number R1 and R2 and send them to each other. At this time, both sides have two random numbers. After successfully sending the random numbers R1 and R2 to each other during the mutual authentication phase between the devices, as Figure 5 shown, the key negotiation is carried out according to the following steps:

[0085] Step 5-1: The terminal device 1 generates a random number R3 and uses the public key K of the terminal device 2 ED-pub (2) Encrypt the random number R3 according to the elliptic curve encryption algorithm to generate the ciphertext E n (R3). Then send the generated E n (R3) and an encryption suite to the terminal device 2. This encryption suite determines the algorithm used for generating the symmetric key later.

[0086] Step 5-2: After receiving the ciphertext E n (R3), the terminal device 2 uses its own private key K ED-pri (2) to decrypt E n (R3) to obtain the random number R3 generated by the terminal device 1. At this time, both the terminal device 1 and the terminal device 2 have three random numbers R1, R2, and R3. Then both sides generate a symmetric encryption key K sym according to the same algorithm in the encryption suite. After that, the data transmitted later can be symmetrically encrypted using this key.

[0087] Step 5-3: The terminal device 2 encrypts the third random number R3 using the negotiated key K sym and sends it to the terminal device 1. After receiving the ciphertext, the terminal device 1 decrypts it using the symmetric key K sym .

[0088] Step 5-4: The terminal device 1 compares whether the decrypted data is correct. If it is correct, it notifies the terminal device 2 that the key negotiation is consistent, and the subsequent data communication uses this symmetric key for encrypted communication; if it is incorrect, restart from Step 5-1.

[0089] The present invention utilizes blockchain to achieve the storage of key information, ensuring the publicity and traceability of data and reducing the centralization of the security management center. During the authentication process of multiple entities, the data is stored distributively, achieving distributed authentication between devices and completing the negotiation of shared keys, providing security guarantee for subsequent data transmission.

Claims

1. A lightweight distributed secure communication authentication method based on blockchain, characterized in that The method includes the following steps: Step 1, Initialization phase: The public parameters pp, identifier hid, and signature master private key K of the security management center generation system M-pri , signature master public key K M-pub , and the private key K of the edge computing node EP-pri and the private key K of the terminal device ED-pri . The public keys of the edge computing node and the terminal device are their unique identity identifiers, denoted as K x-pub ; Step 2, Registration phase: Assume that the security management center is trusted. The terminal device registration is carried out according to the following steps: Step 2-1, The security management center first selects the message M to be encrypted, and sends the message M to the edge node through the secure channel, and at the same time sends it to the terminal device; Step 22: After the edge node receives the message M, it uses its own public key K EP-pub to encrypt the message M according to the public key encryption algorithm to generate the ciphertext E n (M). Then, the edge node sends the ciphertext E n (M) to the terminal device managed by its subordinate through the secure channel; Step 2-3: The terminal device saves the received ciphertext E n (M), and then uses its own public key K ED-pub and the hash function H1() in the elliptic encryption algorithm to generate the digest h of the message M. Then, it uses its own private key K ED-pri to generate the digital signature S, and finally obtains the signature (h, S); Step 24. The terminal device sends the ciphertext E n (M), digital signature (h, S) to the security management center. The security management center creates a transaction through the smart contract, and publishes the public parameters pp of the system, signature public key K M-pub , ciphertext E n (M), signature (h, S), identifier hid and the public key K ED-pub of the terminal device to the blockchain ledger. At this time, it indicates that the device has been legally registered in the blockchain network; Step 3, Device identity authentication phase: Step 3-1: The terminal device sends an authentication request to join the system to the edge node. After receiving the authentication request, the edge node queries the device-related information on the blockchain, obtains the relevant information published by the blockchain in the previous stage, and records the public parameters of the system as pp', the signature master public key as K', M-pub the ciphertext as E' n (M), the signature as (h', S'), the identifier as hid', and the public key of the terminal device as K' ED-pub ; Step 3-2: After obtaining the relevant information, the edge node first uses its own private key K EP-pri to decrypt the ciphertext E' n (M) to obtain the message M'; Step 33: After the edge node obtains the message M', it further uses the message M', the public parameters pp' of the system, the signature master public key K' M-pub , the ciphertext E' n (M), the signature (h', S'), the identifier hid', and the public key K' of the terminal device ED-pub Calculate the message digest h2 of the message M' according to the identity-based digital signature algorithm for the signature (h', S'); Step 3-4: Judge whether h2 = h' holds. If it holds, the identity of the terminal device is legal, and the terminal device is allowed to be added to the system, and the event is broadcast throughout the network; otherwise, the identity of the terminal device is incorrect, and it is not allowed to be added to the industrial control system, and it does not enter the mutual authentication phase between devices; Step 4, Mutual authentication phase between devices: Assume that terminal device 1 and terminal device 2 have respectively passed the authentication of edge node 1 and edge node 2. The mutual authentication between devices is carried out according to the following steps: Step 4-1: After the edge node 1 completes the authentication of the terminal device 1, the edge node 1 will automatically pair the corresponding Ethereum mapping address for the terminal device 1 and set the access validity period t for the terminal device 1 through the timestamp t0 E ; Step 4-2: Terminal device 1 queries the authentication information of terminal device 2 and edge node 2 in the blockchain network through the smart contract, and sends an identity authentication request for terminal device 2; Step 4-3: After terminal device 1 sends the identity authentication request, the smart contract will create a message token Token with the Ethereum addresses of edge node 2, terminal device 1 and terminal device 2 and the current timestamp t0, and send this Token to terminal device 1 and edge node 2; Step Four Four: After receiving this Token, the terminal device 1 first verifies whether the timestamp t0 ≤ t E holds. If it holds, the next authentication step is carried out. If not, this Token is discarded and the authentication process ends; Step 4 and 5: The terminal device 1 uses its own private key K ED-pri (1) Sign the message token Token according to the identity-based digital signature algorithm and send it to the edge node 2; Step 46: After receiving the signature, Edge Node 2 uses the public key K of Terminal Device 1 ED-pub (1) Verify the signature. If the verification passes, Edge Node 2 generates a random number R1. Edge Node 2 uses its own private key K EP-pri (2) Sign the message token Token according to the identity-based digital signature algorithm, and return the random number R1, the signature, and the verification result to Terminal Device 1; Step 47: After the terminal device 1 receives the random number R1, signature, and verification result sent by the edge node 2, it uses the public key K of the edge node 2 EP-pub (2) Verify the signature. If the verification passes, the terminal device 1 will generate a random number R2 and return the random number R2 and the verification result to the edge node 2. At this time, the identity authentication process between the devices is completed; if the verification fails, discard all information, the identity authentication process between the devices ends, and does not enter the key negotiation stage; Step 5, Key negotiation phase: After successfully sending the random numbers R1 and R2 to each other in the mutual authentication phase between devices, the key negotiation is carried out according to the following steps: Step 5-1. The terminal device 1 generates a random number R3 and uses the public key K of the terminal device 2 ED-pub (2) Encrypt the random number R3 according to the elliptic curve encryption algorithm to generate a ciphertext E n (R3), and then send the generated E n (R3) and an encryption suite to the terminal device 2; Step Five Two: After the terminal device 2 receives the ciphertext E n (R3), it uses its own private key K ED-pri (2) to decrypt E n (R3), obtaining the random number R3 generated by the terminal device 1. At this time, both the terminal device 1 and the terminal device 2 have three random numbers R1, R2, and R3. Then, both sides generate a symmetric encryption key K sym ; Step Five Three. The terminal device 2 uses the negotiated key K sym to encrypt the third random number R3 and send it to the terminal device 1. After receiving the ciphertext, the terminal device 1 uses the symmetric key K sym to decrypt it; Step 5-4: Terminal device 1 compares whether the decrypted data is correct. If it is correct, it notifies terminal device 2 that the key negotiation is successful, and the subsequent data communication uses this symmetric key for encrypted communication; if it is incorrect, it restarts from step 5-1.

2. The lightweight distributed security communication authentication method based on blockchain according to claim 1, wherein The specific steps of step 1 include the following steps: Step 1: The security management center generates K M-pri ∈ [1, N - 1] as the signature master private key, where N is the order of the cyclic groups G1, G2, and G T , G T is a multiplicative cyclic group of order N, and G1 and G2 are additive cyclic groups of order N. Then calculate the element K M-pub = [K M-pri P2, where P2 is the generator of the group G2; Take K M-pub as the signature master public key. Then the signature master key pair is (K M-pri , K M-pub ); The security management center will secretly store K M-pri , and publicly disclose K M-pub , and at the same time use one byte to represent the function identifier hid generated by the signature private key; Step 1-2: The public keys of the edge node and the terminal device are their respective unique identity identifiers, denoted as K x-pub , to generate the signature private keys K x-pri of the edge node and the terminal device, the security management center first calculates t1 in the finite field F N of the elliptic encryption algorithm. If t1 = 0, it returns to Step 1-1. Otherwise, it calculates t2 and K x-pri .

3. The lightweight distributed security communication authentication method based on blockchain according to claim 2, characterized in that The calculation formula of the said t1 is as follows: t1 = H1(K x-pub ||hid,N) + K M-pri , where H1 is a cryptographic function derived from a cryptographic hash function.

4. The lightweight distributed security communication authentication method based on blockchain according to claim 2, wherein The calculation formula for the said t2 is as follows: K x-pri = [t2]P1, where P1 is a generator of the group G1.

5. A lightweight distributed secure communication authentication system based on blockchain for implementing the method according to any one of claims 1-4, characterized in that The system includes a security management center, distributed edge nodes, and terminal devices, where: The security management center is responsible for setting and publishing the public parameters of the system, generating the private keys of all edge nodes and terminal devices, managing the identities of terminal devices, realizing the registration of each device, and writing the identity information of the newly added device into the blockchain; The distributed edge nodes are responsible for maintaining the basic operation of the blockchain, managing the terminal devices in the area, and verifying the legality of the identities of the terminal devices; The terminal devices interact with the smart contract through the Ethereum client with the help of the distributed edge nodes. For the terminal devices that have successfully joined the industrial control system, the two parties will perform identity authentication and key negotiation before communication.

6. The lightweight distributed secure communication authentication system based on blockchain according to claim 5, characterized in that The distributed edge nodes are located close to the edge devices and locally execute the preprocessing and operation of the data.

Citation Information

Patent Citations

  • Lightweight end-to-end secure communication authentication method based on identification password

    CN112118106A

  • Internet of Things equipment identity security authentication method based on block chain and fog computing

    CN113301022A