Lightweight data security transmission method and system for wireless sensor networks

The session key is updated through pre-shared keys and non-interactive methods, combined with the ChaCha20_Poly1305 authentication encryption algorithm, the problem of key cracking and communication failure in wireless sensor networks is solved, realizing lightweight data secure transmission.

CN116963053BActive Publication Date: 2025-09-02ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310356785.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-06
Publication Date
2025-09-02
Estimated Expiration
2043-04-06

AI Technical Summary

Technical Problem

There are problems in wireless sensor networks where keys are cracked, insufficient availability caused by the key update strategy relying on time synchronization, and frequent communication failures in traditional interactive transmission solutions under unstable channels.

Method used

A non-interactive secure transmission method with pre-shared keys, initial vectors and packet sequence numbers is used to calculate the session key through key update intervals and save time, and a transmission ciphertext and authentication tag are generated using the ChaCha20_Poly1305 authentication encryption algorithm, and the defects of the traditional solution are overcome in combination with the key sequence generation algorithm.

Benefits of technology

While ensuring security, reducing the number of interactions, reducing network communication overhead, and improving packet reception success rate, it is suitable for the lightweight needs of all kinds of low-power nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116963053B_ABST
    Figure CN116963053B_ABST
Patent Text Reader

Abstract

The present invention proposes a lightweight data security transmission method and system for wireless sensor networks. The method includes the following steps: upon network access, a central node distributes a pre-shared key, initialization vector, node sequence number, and packet sequence number to wireless sensor network nodes, and sets a corresponding key update interval and key retention time based on network scale and node performance; after network node deployment, the network nodes directly synchronize with the central node to calculate the initialization seed required for the key sequence generation algorithm; the sender and receiver implement full-duplex secure encrypted communication based on the synchronized session key; and the sender or receiver updates the session key after a preset key update interval to ensure key freshness. While ensuring secure data transmission, the present invention effectively reduces network overhead by reducing the number of interactions. It also requires low computing power and storage space on network nodes, achieving the advantages of both security and lightweightness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of wireless sensor network security communication and relates to a lightweight data security transmission method and system for wireless sensor networks. Background Art

[0002] In wireless sensor network research, nodes with sensing capabilities can collect information about the current environment and transmit this information to authorized, legitimate users. Depending on the network scenario, wireless sensor networks can be divided into terrestrial wireless sensor network scenarios, such as the Internet of Things, and underwater wireless sensor networks, such as underwater acoustic sensor networks.

[0003] Due to the openness of wireless channels, wireless sensor networks are more vulnerable to attacks such as eavesdropping, counterfeiting, and tampering. At the same time, the node's information sending function is also easily exploited by attackers. Attackers can intercept information or pretend to be legitimate users to obtain information collected by nodes. Therefore, establishing an effective and secure data transmission mechanism is an effective guarantee for the further application and development of wireless sensor networks.

[0004] In the wireless sensor network environment, the ever-increasing number of terminal node devices will bring greater pressure to the wireless sensor network. When a large number of network nodes access the network at the same time in a short period of time, if the traditional one-to-one authentication mechanism is adopted, it will not only cause the system network to be busy, but also occupy a large amount of network and communication resources, bringing severe tests to the network's carrying capacity; at the same time, the massive terminal devices in the wireless sensor network are of various types and models, and their computing and storage resources and energy supply capabilities are also uneven. Therefore, the deployment of security mechanisms in the nodes needs to consider factors such as their storage space, energy consumption and running time to meet the requirements of wireless sensor network scenarios for lightweight and high availability.

[0005] In the process of implementing the present invention, the inventors discovered that existing secure data solutions for wireless sensor networks have at least the following problems:

[0006] (1) Some schemes do not consider the key update strategy and use the same key to encrypt the transmitted data for a long time, thereby increasing the risk of the key being cracked and having insufficient security. (2) The key update strategy of some schemes adopts a time segment method, allowing the communicating parties to automatically iterate and update to generate new keys after a period of time, which creates a dependence and requirement for time synchronization and has insufficient availability. (3) Traditional schemes mostly rely on the active interaction between the sender and the receiver in the negotiation and update of session keys and require at least two handshakes. The communication overhead is large and it has insufficient lightness. At the same time, traditional interactive transmission schemes usually directly assume that the transmission channel between the sender and the receiver is stable and reliable when designed. However, in some actual scenarios of wireless sensor networks, such as underwater wireless sensor networks, the network connectivity is poor and the link is unstable, with intermittent phenomena, and it is impossible to ensure continuous connectivity between the sender and the receiver. Therefore, traditional schemes based on interactive methods are likely to frequently encounter communication failures in such scenarios and are difficult to implement. To overcome the above problems, the present invention proposes a non-interactive secure transmission method and system based on pre-shared key information, which does not require frequent interaction between nodes while ensuring security. Summary of the Invention

[0007] The purpose of the present invention is to provide a lightweight data security transmission method and system for wireless sensor networks, which reduces the number of interactions required for the overall solution while ensuring lightweightness, and solves the problems of identity authentication, data security transmission, and high computing overhead between sensor nodes and central nodes in a wireless sensor network environment.

[0008] According to a first aspect of an embodiment of the present invention, a lightweight data security transmission method for a wireless sensor network is provided, which is applied to a wireless sensor network node and includes:

[0009] S11: The wireless sensor network node obtains the pre-shared key, initialization vector, node sequence number and packet sequence number assigned by the central node, and caches the key update interval and key retention time set by the central node based on the network scale and node performance;

[0010] S12: The wireless sensor network node calculates an initialization seed according to the key update interval and the key retention time, and inputs the initialization seed into a key sequence generation algorithm to obtain a session key;

[0011] S13: When the wireless sensor network node acts as a data sender, it increments the initialization vector and the packet sequence number, generates a transmission ciphertext and an authentication tag through an authentication encryption algorithm, and sends the data packet to the central node. The data packet includes the node sequence number of the wireless sensor network node, the currently encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext, and the authentication tag.

[0012] When a wireless sensor network node acts as a data receiver, after receiving a data packet sent by a central node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is successful, the session key is used to decrypt the data packet to obtain the plaintext;

[0013] S14: The wireless sensor network node updates a new session key after the preset key update interval arrives, and uses the new session key to encrypt and transmit current and subsequent data packets within a certain range.

[0014] Furthermore, determining whether the session key needs to be updated based on the packet sequence number carried in the data packet includes:

[0015] The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of transmitted packets is greater than or equal to the pre-assigned key update interval, the wireless sensor network node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

[0016] According to a second aspect of an embodiment of the present invention, a lightweight data security transmission system for a wireless sensor network is provided, which is applied to a wireless sensor network node and includes:

[0017] The device registration module is used for wireless sensor network nodes to obtain the pre-shared key, initialization vector, node sequence number and packet sequence number assigned to them by the central node, and cache the key update interval and key retention time set by the central node based on the network scale and node performance;

[0018] A key generation module is used for the wireless sensor network node to calculate an initialization seed according to the key update interval and the key retention time, and to input the initialization seed into the key sequence generation algorithm to obtain a session key;

[0019] The encryption transmission module is used to, when the wireless sensor network node acts as the data sender, increment the initialization vector and the packet sequence number respectively, then generate a transmission ciphertext and an authentication tag through the authentication encryption algorithm, and send the data packet to the central node. The data packet contains the node sequence number of the wireless sensor network node, the current encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext and the authentication tag;

[0020] When a wireless sensor network node acts as a data receiver, after receiving a data packet sent by a central node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is successful, the session key is used to decrypt the data packet to obtain the plaintext;

[0021] The key update module is used for the wireless sensor network node to update a new session key after the preset key update interval arrives, and use the new session key to encrypt and transmit the current and subsequent data packets within a certain range.

[0022] According to a third aspect of an embodiment of the present invention, a lightweight data security transmission method for a wireless sensor network is provided, which is applied to a central node and includes:

[0023] S21: The central node distributes a pre-shared key, an initialization vector, a node sequence number, and a packet sequence number to the wireless sensor network node when joining the network, and sets a corresponding key update interval and key retention time according to the network scale and node performance. The distributed shared information is cached locally and in the wireless sensor network node, respectively, so that the central node and the wireless sensor network node can directly and synchronously calculate the initialization seed after deployment is completed, and feed the initialization seed into the key sequence generation algorithm to obtain the session key;

[0024] S22: When the central node acts as the data sender, it increments the initialization vector and the packet sequence number, generates a transmission ciphertext and an authentication tag through an authentication encryption algorithm, and sends the data packet to the wireless sensor network node. The data packet includes the node sequence number of the central node, the currently encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext, and the authentication tag.

[0025] When the central node acts as the data receiver, after receiving a data packet sent by a wireless sensor network node, it determines that the communication object is the corresponding wireless sensor network node according to the node sequence number in the data packet, and determines whether the session key needs to be updated according to the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified according to the session key and the initialization vector carried in the data packet. After the verification passes, the session key is used to decrypt the data packet to obtain the plaintext;

[0026] S23: The central node updates a new session key after the preset key update interval arrives, and caches the session key before the update according to the set key retention time.

[0027] Furthermore, determining whether the session key needs to be updated based on the packet sequence number carried in the data packet includes:

[0028] The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of packets transmitted is greater than or equal to the pre-assigned key update interval, the central node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

[0029] Furthermore, the central node updates a new session key after a preset key update interval arrives, and caches the session key before the update according to the set key retention time, including:

[0030] After receiving the data packet encrypted by the wireless sensor network node using the updated session key, the central node determines the communication object according to step S22 and calculates the number of data packets currently transmitted. Since the number of data packets transmitted at this time is greater than or equal to the pre-assigned key update interval, the central node needs to iteratively update the new session key to correctly decrypt the data packet. At the same time, due to the multi-path delayed arrival problem in the wireless sensor network, the historical key before the update cannot be discarded immediately, but needs to be cached in the central node and wait for the key storage time set in step S21 before being overwritten.

[0031] According to a fourth aspect of an embodiment of the present invention, a lightweight data security transmission system for a wireless sensor network is provided, which is applied to a central node and includes:

[0032] The device deployment module is used for the central node to distribute pre-shared keys, initialization vectors, node sequence numbers, and packet sequence numbers to wireless sensor network nodes when joining the network, and set corresponding key update intervals and key retention times according to the network scale and node performance, and cache them in the wireless sensor network nodes, so that the wireless sensor network nodes calculate the initialization seeds based on the key update intervals and key retention times, and feed the initialization seeds into the key sequence generation algorithm to obtain the session key;

[0033] The encryption transmission module is used to, when the central node acts as the data sender, increment the initialization vector and the packet sequence number respectively, and then generate a transmission ciphertext and an authentication tag through the authentication encryption algorithm, and send the data packet to the wireless sensor network node. The data packet contains the node sequence number of the wireless sensor network node, the current encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext and the authentication tag;

[0034] When the central node acts as the data receiver, after receiving a data packet sent by a wireless sensor network node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is passed, the session key is used to decrypt the data packet to obtain the plaintext;

[0035] The key update module is used for the central node to update a new session key after the preset key update interval arrives, and use the new session key to encrypt and transmit the current and subsequent data packets within a certain range.

[0036] According to a fifth aspect of an embodiment of the present invention, there is provided an electronic device, characterized by comprising:

[0037] one or more processors;

[0038] a memory for storing one or more programs;

[0039] When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in the first aspect or the third aspect.

[0040] According to a sixth aspect of an embodiment of the present invention, a computer-readable storage medium is provided, on which computer instructions are stored, characterized in that when the instructions are executed by a processor, the steps of the method described in the first aspect or the third aspect are implemented.

[0041] The present invention may include the following beneficial effects: (1) Since the present invention sets a key update interval, the session key is periodically and actively updated during the encrypted transmission process, and the receiver is synchronously informed through the packet sequence number carried in the data packet, thereby ensuring the freshness of the key in the protocol; at the same time, the update of the session key is generated by a lightweight key sequence generation algorithm. Since the iterative process of the algorithm is unidirectional, even if the session key is cracked by an attacker at a certain moment, the attacker cannot restore the historical session key from the current cracked session key, thereby ensuring the confidentiality of the data packet previously encrypted by the historical session key; in addition, the session key update process overcomes the defect of using a negotiated interactive method to update the key in the traditional scheme, and further reduces the overall network communication overhead of the scheme.

[0042] (2) The present invention takes into account the multi-path delayed arrival problem in wireless sensor networks and proposes a key preservation time mechanism. This problem can be specifically described as follows: assuming that the data packet currently being sent needs to update the session key before it can be correctly decrypted, and the data packet first reaches the receiver through a path that is closer in the network, while the data packet sent by the sender earlier that requires the session key before the update to be correctly decrypted arrives at the receiver later through a path that is farther away in the network. If the receiver directly updates and overwrites the original session key at this time, since the update of the session key is unidirectional, the later-arriving data packet encrypted with the key before the update will not be correctly decrypted. Since the present invention requires the receiver to cache the historical key until the key preservation time after updating the session key and then discard it, the correct reception success rate of the data packet is guaranteed.

[0043] (3) Since the key sequence generation algorithm of the present invention is based on the technical means of a random number generator, it overcomes the technical defect that the traditional key negotiation algorithm requires a complex interactive negotiation process, and has the advantages of long cycle, good randomness, low computational overhead, and low memory usage, and is therefore suitable for the lightweight requirements of various low-power nodes in wireless sensor networks. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] The accompanying drawings are used to provide an understanding of the technical solution of the present application and constitute a part of the specification, wherein:

[0045] Figure 1 This is a flowchart of a lightweight data security transmission method for a wireless sensor network according to an embodiment of the present application (applied to wireless sensor network nodes).

[0046] Figure 2 This is a block diagram of a lightweight data security transmission system for a wireless sensor network according to an embodiment of the present application (applied to wireless sensor network nodes).

[0047] Figure 3 This is a flowchart of a lightweight data security transmission method for a wireless sensor network according to an embodiment of the present application (applied to a central node).

[0048] Figure 4 This is a schematic diagram of the lightweight key sequence generation algorithm structure of an embodiment of the present application.

[0049] Figure 5 This is a block diagram of a lightweight data security transmission system for a wireless sensor network according to an embodiment of the present application (applied to a central node).

[0050] Figure 6 This is a schematic diagram of the system logic structure of an embodiment of the present application. DETAILED DESCRIPTION

[0051] The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of schemes and systems consistent with some aspects of the present application as detailed in the appended claims.

[0052] When describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not rely on the specific order of the steps described herein, the method or process should not be limited to the steps in the specific order described. As will be understood by those skilled in the art, other orders of steps are also possible. Therefore, the specific order of the steps set forth in the specification should not be interpreted as a limitation to the claims. In addition, the claims for the method and / or process should not be limited to the steps performed in the order written, and those skilled in the art can readily understand that these orders can be changed and still remain within the spirit and scope of the embodiments of the present application.

[0053] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0054] Example 1:

[0055] refer to Figure 1 This embodiment provides a lightweight data security transmission method for a wireless sensor network, which is applied to a wireless sensor network node and includes:

[0056] S11: The wireless sensor network node obtains the pre-shared key, initialization vector, node sequence number and packet sequence number assigned by the central node, and caches the key update interval and key retention time set by the central node based on the network scale and node performance;

[0057] Specifically, the wireless sensor network node N i Register at the central node before deploying into the network and obtain the pre-shared key PSK assigned by the central node i , initial vector IV i 0 Node serial number UUID i and random packet sequence number PID i 0 , and caches the key update interval τ and key retention time Timeout set by the central node according to the network scale and node performance; the key retention time mechanism can allow the present invention to better deal with the possible multipath delay problem in resource-constrained communication environments such as underwater wireless sensor networks, and improve the success rate of correct reception of data packets.

[0058] S12: The wireless sensor network node calculates an initialization seed according to the key update interval and the key retention time, and inputs the initialization seed into a key sequence generation algorithm to obtain a session key;

[0059] Specifically, the method for calculating the initialization seed is seed i =H(PID i 0 ||PSK i ), since the parameters required for calculation are distributed to the wireless sensor network nodes by the central node during the registration phase, there is no need for the interactive negotiation process in the traditional scheme, which reduces the overall network communication overhead of the scheme. The initialization seed generated by the calculation is then sent to the key sequence generation algorithm in this method to obtain the session key, which is calculated as SK i =PXLKA_INIT(seed i ).

[0060] S13: When the wireless sensor network node acts as a data sender, it increments the initialization vector and the packet sequence number, generates a transmission ciphertext and an authentication tag through an authentication encryption algorithm, and sends the data packet to the central node. The data packet includes the node sequence number of the wireless sensor network node, the currently encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext, and the authentication tag.

[0061] When a wireless sensor network node acts as a data receiver, after receiving a data packet sent by a central node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is successful, the session key is used to decrypt the data packet to obtain the plaintext;

[0062] Specifically, when the wireless sensor network node N i When acting as a data sender, the initialization vector and the packet sequence number IV need to be combined before transmitting data. i j with PID i j Increment respectively, calculated as IV i j+1 =IV i j +1 and PID i j+1 =PID i j +1, N i Then call the ChaCha20_Poly1305 authentication encryption algorithm to encrypt the data PID i j+1, DATA and associated data UUID i Generate ciphertext and authentication tag, calculated as After the processing is completed, N i Send encrypted data packets to the central node

[0063] When a wireless sensor network node acts as a data receiver, after receiving a data packet from a central node, it first identifies the UUID in the data packet. CN Determine that the communication partner is the central node, and then determine whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, verify the authentication tag based on the session key and the initial vector carried in the data packet, specifically by calling the Poly1305 message authentication algorithm to recalculate the authentication tag Tag. CN ′, judge the Tag CN 'Whether it matches the received authentication tag Tag CN If they are equal, it means that the data packet has not been tampered with by the adversary and the identity authentication of the central node has been achieved. Then the ciphertext is decrypted to obtain the plaintext data sent by the central node.

[0064] Because this invention utilizes the ChaCha20_Poly1305 authentication and encryption algorithm during the encrypted transmission phase, it overcomes the technical issue of traditional solutions requiring both the sender and receiver to perform encryption and authentication separately when sending and receiving data, thereby avoiding additional computational and communication overhead. Furthermore, ChaCha20_Poly1305 is an authentication and encryption algorithm with excellent software performance and does not require any hardware acceleration modules on the device, making it more versatile.

[0065] The determination of whether the session key needs to be updated is based on the packet sequence number carried in the data packet, including:

[0066] The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of transmitted packets is greater than or equal to the pre-assigned key update interval, the wireless sensor network node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

[0067] Specifically, the wireless sensor network node calculates the number of data packets currently transmitted by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. The calculation method is: If n is greater than or equal to the pre-assigned key update interval τ, the wireless sensor network node needs to iteratively update the new session key, which is calculated as The freshness of the session key during encrypted transmission is guaranteed; if it is less than, there is no need to update the session key.

[0068] S14: The wireless sensor network node updates a new session key after the preset key update interval arrives, and uses the new session key to encrypt and transmit current and subsequent data packets within a certain range.

[0069] Specifically, the wireless sensor network node N i After the number of iterations of the packet sequence number reaches the key update interval τ, the current session key is actively updated. The calculation method is: Then, the initial vector and the packet sequence number are incremented respectively, and the authentication encryption algorithm is called in the same way as in step S13 to generate the ciphertext and the authentication tag. The calculation method is: After the processing is completed, N i Send encrypted data packets to the central node

[0070] Corresponding to the aforementioned embodiment of a lightweight data security transmission method for a wireless sensor network, the present application also provides an embodiment of a lightweight data security transmission system for a wireless sensor network.

[0071] Figure 2 FIG1 is a block diagram of a lightweight data security transmission system for a wireless sensor network according to an exemplary embodiment. Figure 2 ,The system is applied to wireless sensor network nodes, including:

[0072] The device registration module 11 is used for the wireless sensor network node to obtain the pre-shared key, initialization vector, node sequence number and packet sequence number assigned to it by the central node, and cache the key update interval and key retention time set by the central node according to the network scale and node performance;

[0073] The key generation module 12 is used for the wireless sensor network node to calculate the initialization seed according to the key update interval and the key retention time, and input the initialization seed into the key sequence generation algorithm to obtain the session key;

[0074] The encryption transmission module 13 is used to, when the wireless sensor network node acts as the data sender, increment the initialization vector and the packet sequence number, then generate a transmission ciphertext and an authentication tag using an authentication encryption algorithm, and send the data packet to the central node. The data packet contains the node sequence number of the wireless sensor network node, the currently encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext, and the authentication tag;

[0075] When a wireless sensor network node acts as a data receiver, after receiving a data packet sent by a central node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is successful, the session key is used to decrypt the data packet to obtain the plaintext;

[0076] The key updating module 14 is used for the wireless sensor network node to update a new session key after a preset key updating interval arrives, and use the new session key to encrypt and transmit current and subsequent data packets within a certain range.

[0077] Example 2:

[0078] refer to Figure 3 This embodiment provides a lightweight data security transmission method for a wireless sensor network, which is applied to a central node and includes:

[0079] S21: The central node distributes a pre-shared key, an initialization vector, a node sequence number, and a packet sequence number to the wireless sensor network node when joining the network, and sets a corresponding key update interval and key retention time according to the network scale and node performance. The distributed shared information is cached locally and in the wireless sensor network node, respectively, so that the central node and the wireless sensor network node can directly and synchronously calculate the initialization seed after deployment is completed, and feed the initialization seed into the key sequence generation algorithm to obtain the session key;

[0080] Specifically, the central node locally stores the pre-shared keys, initialization vectors, node serial numbers, and packet serial numbers of all devices within its jurisdiction. The corresponding key update interval τ and key storage time Timeout are set according to the network scale and node performance. The node serial numbers of all entities in the network are made public to each other. After the network node deployment is completed, the central node calculates the initialization seed synchronously based on the pre-allocated information shared with the node. The calculation method is Then the calculated initialization seed is sent to the key sequence generation algorithm in this method to obtain the session key, which is calculated as SK i =PXLKA_INIT(seed i ).

[0081] S22: When the central node acts as the data sender, it increments the initialization vector and the packet sequence number, generates a transmission ciphertext and an authentication tag through an authentication encryption algorithm, and sends the data packet to the wireless sensor network node. The data packet includes the node sequence number of the central node, the currently encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext, and the authentication tag.

[0082] When the central node acts as the data receiver, after receiving a data packet sent by a wireless sensor network node, it determines that the communication object is the corresponding wireless sensor network node according to the node sequence number in the data packet, and determines whether the session key needs to be updated according to the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified according to the session key and the initialization vector carried in the data packet. After the verification passes, the session key is used to decrypt the data packet to obtain the plaintext;

[0083] Specifically, when the central node acts as the data sender, it needs to combine the initialization vector and the packet sequence number IV before transmitting the data. i j and Incrementally respectively, the calculation method is The central node then calls the authentication encryption algorithm to encrypt the data DATA and associated data UUID CN Generate ciphertext and authentication tag, calculated as After the processing is completed, N i Send encrypted data packets to the central node

[0084] When the central node acts as the data receiver, after receiving the data packet sent by the wireless sensor network node, it first determines that the communication object is the network node N according to the identity identifier UUIDNi in the data packet. i , then determine whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initial vector carried in the data packet, specifically by calling the Poly1305 message authentication algorithm to recalculate the authentication tag judge Is it consistent with the received authentication tag? If they are equal, it means that the data packet has not been tampered by the adversary and the network node N has been tampered with. i The identity authentication is then performed on the ciphertext to obtain the plaintext data sent by the network node.

[0085] The determination of whether the session key needs to be updated is based on the packet sequence number carried in the data packet, including:

[0086] The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of packets transmitted is greater than or equal to the pre-assigned key update interval, the central node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

[0087] Specifically, the central node subtracts the packet sequence number carried in the data packet from the locally stored packet sequence number to calculate the number of data packets currently transmitted. The calculation method is: If n is greater than or equal to the pre-assigned key update interval τ, the wireless sensor network node needs to iteratively update the new session key, which is calculated as The freshness of the session key during encrypted transmission is guaranteed; if it is less than, there is no need to update the session key.

[0088] S23: The central node updates a new session key after the preset key update interval arrives, and uses the new session key to encrypt and transmit the current and subsequent data packets within a certain range.

[0089] Specifically, the central node actively updates the current session key after the number of iterations of the packet sequence number reaches the key update interval τ, which is calculated as follows: Then, the initial vector and the packet sequence number are incremented respectively, and the authentication encryption algorithm is called in the same way as in step S22 to generate the ciphertext and the authentication tag. The calculation method is: After the processing is completed, N i Send encrypted data packets to the central node

[0090] The central node updates a new session key after the preset key update interval arrives, and caches the session key before the update according to the set key retention time.

[0091] Specifically, after receiving the data packet encrypted by the wireless sensor network node using the updated session key, the central node determines the communication object according to step S22 and calculates the number of data packets currently transmitted. Since the number of data packets transmitted at this time is greater than or equal to the pre-assigned key update interval, the central node needs to iteratively update the new session key to correctly decrypt the data packet. At the same time, due to the multi-path delayed arrival problem in the wireless sensor network, the historical key before the update cannot be discarded immediately, but needs to be cached in the central node and wait for the key storage time Timeout set in step S21 before being overwritten.

[0092] The schematic diagram of the key sequence generation algorithm used in the above two embodiments is as follows: Figure 4 As shown in the figure, the algorithm is composed of two lightweight random number generators, PCG-32 and Xoshiro128++, and is named PXLKA algorithm. It mainly includes the following steps:

[0093] Step 1: Assume that PCG-32 and Xoshiro128++ have been initialized by their respective random number seeds seed1 and seed2, and according to the current internal state and Generate a random number X i With Y i .

[0094] Step 2: Use PCG-32 and Xoshiro128++ to generate two 32-bit random numbers X i With Y i Combine, that is, add 2 w Modulo, w depends on the word length of the processor.

[0095] Step 3: Send the 32-bit result of step 2 to the mixing function and output the result of the one-to-one mapping. The mixing function uses multiplication and XOR shift operations to mix and disturb the input parameters.

[0096] Step 4: Repeat steps 1 to 3, concatenating the 32-bit results in sequence until the 256-bit key required by the ChaCha20-Poly1305 authentication encryption algorithm is obtained.

[0097] Since the key sequence generation algorithm adopts a technical means based on a random number generator, it overcomes the technical defects of the traditional key negotiation algorithm that requires a complex interactive negotiation process. It has the advantages of long cycle, good randomness, low computational overhead, and low memory usage.

[0098] Corresponding to the aforementioned embodiment of a lightweight data security transmission method for a wireless sensor network, the present application also provides an embodiment of a lightweight data security transmission system for a wireless sensor network.

[0099] Figure 5 FIG1 is a block diagram of a lightweight data security transmission system for a wireless sensor network according to an exemplary embodiment. Figure 5 ,The system is applied to the central node and includes:

[0100] The device deployment module 21 is configured to allocate a pre-shared key, an initialization vector, a node sequence number, and a packet sequence number to wireless sensor network nodes when the central node joins the network, and to set a corresponding key update interval and key retention time based on the network scale and node performance. The pre-shared key and the key retention time are cached in the wireless sensor network nodes, so that the wireless sensor network nodes calculate an initialization seed based on the key update interval and key retention time, and feed the initialization seed into a key sequence generation algorithm to obtain a session key.

[0101] The encryption transmission module 22 is used to, when the central node acts as the data sender, increment the initialization vector and the packet sequence number, generate a transmission ciphertext and an authentication tag using an authentication encryption algorithm, and send the data packet to the wireless sensor network node. The data packet contains the node sequence number of the wireless sensor network node, the currently encrypted initialization vector, the packet sequence number of the data packet, the transmission ciphertext, and the authentication tag.

[0102] When the central node acts as the data receiver, after receiving a data packet sent by a wireless sensor network node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is passed, the session key is used to decrypt the data packet to obtain the plaintext;

[0103] The key updating module 23 is used for the central node to update a new session key after a preset key updating interval has arrived, and use the new session key to encrypt and transmit current and subsequent data packets within a certain range.

[0104] Regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0105] Figure 6 This is a topology diagram of a central node and multiple wireless sensor network nodes shown in the embodiment. The modules deployed in the central node and the wireless sensor network nodes have been described in detail in the embodiment and will not be elaborated here.

[0106] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0107] Accordingly, the present application also provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement a lightweight data security transmission method for a wireless sensor network as described above.

[0108] Accordingly, the present application also provides a computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, implements the above-mentioned lightweight data security transmission method for a wireless sensor network.

[0109] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the contents disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered merely as exemplary, and the true scope and spirit of the present application are indicated by the claims.

[0110] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A lightweight data security transmission method for wireless sensor networks, characterized in that: Applied to wireless sensor network nodes, including: S11: The wireless sensor network node obtains the pre-shared key, initialization vector, node sequence number and packet sequence number assigned by the central node, and caches the key update interval and key retention time set by the central node based on the network scale and node performance; S12: The wireless sensor network node calculates the initialization seed according to the key update interval and the key storage time, and sends the initialization seed to the key sequence generation algorithm to obtain the session key. The initialization seed is as follows: , the session key is calculated as , To initialize the seed, is the random package number, is the pre-shared key, is the session key; S13: When the wireless sensor network node acts as the data sender, the initial vector and the packet sequence number are incremented and then the transmission ciphertext and the authentication tag are generated by the authentication encryption algorithm. The calculation method is: , To transmit ciphertext, For certification labels, , is the initial vector, is the node number, , is the package number, i is a positive integer, For data, a data packet is sent to the central node, wherein the data packet includes the node serial number of the wireless sensor network node, the current encrypted initial vector, the packet serial number of the data packet, the transmission ciphertext and the authentication tag; When a wireless sensor network node acts as a data receiver, after receiving a data packet sent by a central node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is successful, the session key is used to decrypt the data packet to obtain the plaintext; S14: The wireless sensor network node updates a new session key after the preset key update interval arrives, and uses the new session key to encrypt and transmit the current and subsequent data packets within a certain range; The process of determining whether a session key needs to be updated based on the packet sequence number carried in the data packet includes: The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of transmitted packets is greater than or equal to the pre-assigned key update interval, the wireless sensor network node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

2. A lightweight data security transmission system for wireless sensor networks, characterized in that: Applied to wireless sensor network nodes, including: The device registration module is used for wireless sensor network nodes to obtain the pre-shared key, initialization vector, node sequence number and packet sequence number assigned to them by the central node, and cache the key update interval and key retention time set by the central node based on the network scale and node performance; The key generation module is used for the wireless sensor network node to calculate the initialization seed according to the key update interval and key retention time, and send the initialization seed into the key sequence generation algorithm to obtain the session key; the method of initializing the seed is as follows: , the session key is calculated as , To initialize the seed, is the random package number, is the pre-shared key, is the session key; The encryption transmission module is used when the wireless sensor network node acts as the data sender. It increments the initial vector and the packet sequence number and then generates the transmission ciphertext and the authentication tag through the authentication encryption algorithm. The calculation method is: , To transmit ciphertext, For certification labels, , is the initial vector, is the node number, , is the package number, i is a positive integer, For data, a data packet is sent to the central node, wherein the data packet includes the node serial number of the wireless sensor network node, the current encrypted initial vector, the packet serial number of the data packet, the transmission ciphertext and the authentication tag; When a wireless sensor network node acts as a data receiver, after receiving a data packet sent by a central node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is successful, the session key is used to decrypt the data packet to obtain the plaintext; The key update module is used for the wireless sensor network node to update a new session key after the preset key update interval arrives, and use the new session key to encrypt and transmit the current and subsequent data packets within a certain range; The process of determining whether a session key needs to be updated based on the packet sequence number carried in the data packet includes: The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of transmitted packets is greater than or equal to the pre-assigned key update interval, the wireless sensor network node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

3. A lightweight data security transmission method for wireless sensor networks, characterized in that: Applied to the central node, including: S21: The central node distributes pre-shared keys, initialization vectors, node numbers, and packet numbers to the wireless sensor network nodes when joining the network, and sets the corresponding key update interval and key retention time according to the network scale and node performance, and caches the distributed shared information to the local and wireless sensor network nodes respectively, so that the central node and the wireless sensor network nodes can directly synchronize and calculate the initialization seed after the deployment is completed, and send the initialization seed to the key sequence generation algorithm to obtain the session key; the method of initializing the seed is , the session key is calculated as , To initialize the seed, is the random package number, is the pre-shared key, is the session key; S22: When the central node acts as the data sender, the initial vector and packet sequence number are incremented and then the transmission ciphertext and authentication tag are generated through the authentication encryption algorithm. The calculation method is: , To transmit ciphertext, For certification labels, , is the initial vector, is the node number, , is the package number, i is a positive integer, For data, a data packet is sent to the wireless sensor network node, wherein the data packet includes the node serial number of the central node, the current encrypted initial vector, the packet serial number of the data packet, the transmission ciphertext and the authentication tag; When the central node acts as the data receiver, after receiving a data packet sent by a wireless sensor network node, it determines that the communication object is the corresponding wireless sensor network node according to the node sequence number in the data packet, and determines whether the session key needs to be updated according to the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified according to the session key and the initialization vector carried in the data packet. After the verification passes, the session key is used to decrypt the data packet to obtain the plaintext; S23: The central node updates a new session key after the preset key update interval arrives, and caches the session key before the update according to the set key retention time; The process of determining whether a session key needs to be updated based on the packet sequence number carried in the data packet includes: The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of transmitted packets is greater than or equal to the pre-assigned key update interval, the wireless sensor network node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

4. The method according to claim 3, characterized in that The central node updates the new session key after the preset key update interval arrives, and caches the session key before the update according to the set key retention time, including: After receiving the data packet encrypted by the wireless sensor network node using the updated session key, the central node determines the communication object according to step S22 and calculates the number of data packets currently transmitted. Since the number of data packets transmitted at this time is greater than or equal to the pre-assigned key update interval, the central node needs to iteratively update the new session key to correctly decrypt the data packet. At the same time, due to the multi-path delayed arrival problem in the wireless sensor network, the historical key before the update cannot be discarded immediately, but needs to be cached in the central node and wait for the key storage time set in step S21 before being overwritten.

5. A lightweight data security transmission system for wireless sensor networks, characterized in that: Applied to the central node, including: The device deployment module is used for the central node to distribute pre-shared keys, initialization vectors, node serial numbers and packet serial numbers to wireless sensor network nodes when joining the network, and set corresponding key update intervals and key retention times according to the network scale and node performance, and cache them in the wireless sensor network nodes, so that the wireless sensor network nodes can calculate the initialization seeds according to the key update intervals and key retention times, and send the initialization seeds to the key sequence generation algorithm to obtain the session key; the method of initializing the seeds is as follows: , the session key is calculated as , To initialize the seed, is the random package number, is the pre-shared key, is the session key; The encryption transmission module is used when the central node acts as the data sender to increment the initial vector and packet sequence number and then generate the transmission ciphertext and authentication tag through the authentication encryption algorithm. The calculation method is: , To transmit ciphertext, For certification labels, , is the initial vector, is the node number, , is the package number, i is a positive integer, For data, a data packet is sent to the wireless sensor network node, wherein the data packet includes the node serial number of the wireless sensor network node, the current encrypted initial vector, the packet serial number of the data packet, the transmission ciphertext and the authentication tag; When the central node acts as the data receiver, after receiving a data packet sent by a wireless sensor network node, it determines that the communication partner is the central node based on the node sequence number in the data packet, and determines whether the session key needs to be updated based on the packet sequence number carried in the data packet. Then, before the decryption operation, the authentication tag is verified based on the session key and the initialization vector carried in the data packet. If the verification is passed, the session key is used to decrypt the data packet to obtain the plaintext; The key update module is used for the central node to update the new session key after the preset key update interval arrives, and use the new session key to encrypt and transmit the current and subsequent data packets within a certain range; The process of determining whether a session key needs to be updated based on the packet sequence number carried in the data packet includes: The number of packets currently transmitted is calculated by subtracting the packet sequence number carried in the data packet from the locally stored packet sequence number. If the number of transmitted packets is greater than or equal to the pre-assigned key update interval, the wireless sensor network node needs to iteratively update a new session key to correctly decrypt the data packet; if it is less than the session key, there is no need to update the session key.

6. An electronic device, characterized in that: include: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.

7. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the instruction is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Anonymous authentication and key agreement protocol in WSN

    CN112887978A

  • Entity authentication method and device based on pre-shared key

    WO2016058404A1