Wireless Sensor Network Communication Method and System Based on Hierarchical Symmetric Key Pool

By adopting a layered symmetric key pool and replacement key method in wireless sensor network, the security and update efficiency of group symmetric key pools are solved, and higher security and faster key pool updates are achieved in group communication.

CN114531663BActive Publication Date: 2025-07-01RUBAN QUANTUM TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011204484.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-02
Publication Date
2025-07-01
Estimated Expiration
2040-11-02

AI Technical Summary

Technical Problem

In the prior art, the group symmetric key pool cannot be stored in a highly secure security chip due to its large capacity, and there is a possibility that it will be captured and dismantled and then cracked. At the same time, the existing key pool update method requires passing a large number of keys, resulting in a long update time and all members in the existing system have the same status. Capturing any member will cause the entire group communication system to fail.

Method used

The wireless sensor network communication method based on a hierarchical symmetric key pool is adopted to enhance the security of the key pool by dividing multiple subgroups within the group and generating a unique key pool using a replacement key in each subgroup. At the same time, a new key pool update method is adopted, and the key pool can be updated only by passing a small number of keys, and the protection measures are divided by rank among group members to prevent the entire system from being invalidated due to the capture of a single member.

Benefits of technology

In group communication, the security of the use of symmetric key pools is enhanced to ensure that even if a subgroup key pool is cracked, the security of other subgroups is not affected. At the same time, the key pool update process is simplified, the key transmission volume is reduced, the update efficiency is improved, and the entire group communication system is prevented from being captured by a single member through hierarchical division.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114531663B_ABST
    Figure CN114531663B_ABST
Patent Text Reader

Abstract

The present invention discloses a wireless sensor network communication method and system based on a hierarchical symmetric key pool. The method includes the following steps: S1, realizing upper-layer group communication between a layer-0 communication base station and a layer-1 cluster head node; S2, realizing lower-layer group communication between the layer-1 cluster head node and the layer-2 sensor nodes under normal circumstances; S3, realizing lower-layer group communication between the layer-1 cluster head node and the layer-2 sensor nodes when the cluster head node fails; S4, updating the key pool corresponding to the layer-1 cluster head node according to the key pool update method. Beneficial effects: The present invention combines a symmetric key pool and replacement keys, and in the scenario of group communication, further enhances the security of using the symmetric key pool, so that in the extreme case where a sub-group symmetric key pool is cracked, the security of group communication based on the symmetric key pool can still be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of group communication, and in particular to a wireless sensor network communication method and system based on a hierarchical symmetric key pool. Background Art

[0002] A wireless sensor network (WSN) is a distributed sensing network, and its terminals are sensors that can sense and inspect the external world. The sensors in the WSN communicate wirelessly, so the network setup is flexible, the device positions can be changed at any time, and it can also be connected to the Internet in a wired or wireless manner. It forms a multi-hop self-organizing network through wireless communication.

[0003] The sensor network realizes three functions of data collection, processing, and transmission. It, together with communication technology and computer technology, constitutes the three major pillars of information technology. A wireless sensor network (WSN) is a wireless network composed of a large number of stationary or mobile sensors in a self-organizing and multi-hop manner, which collaboratively senses, collects, processes, and transmits information about the sensed objects within the network coverage geographical area, and finally sends this information to the owner of the network.

[0004] With the continuous development of wireless communication technology, device-to-device (D2D) communication has become one of the hotspots of 3GPP Rel-12 standardized technologies. D2D allows two user equipments (UEs) to directly transmit data through a specific channel (Sidelink Channel) without passing through an evolved Node B (eNB). Of course, D2D is not limited to data transmission between two user equipments, and it can also support group communication from a single point to multiple points. Most of the existing network authentication systems are one-to-one authentication methods based on a single object. However, for data transmission from a single point to multiple points, groups are formed according to certain principles. In these application scenarios, when a new terminal joins the group, if the existing one-to-one authentication method is used, it will not only increase network signaling, leading to network congestion, but also consume a large amount of network resources. Therefore, the existing one-to-one network authentication system is no longer applicable. In this case, in order to reduce the consumption of authentication resources and reduce network congestion, a corresponding group authentication mechanism is needed. The existing group communication system uses a group key pool and realizes group communication by using the symmetric keys stored in the group-type symmetric key pool. If a certain member is attacked, the secure communication of the entire group is threatened in terms of security.

[0005] In the prior art, updating the key pool often requires the participation of the issuing center. Due to the large amount of data transmitted, there is a certain threat to security.

[0006] Based on the above analysis, the prior art has the following defects:

[0007] 1. In the prior art, due to its large capacity, the group symmetric key pool cannot be stored in a highly secure security chip, and there is a possibility of being captured, disassembled, and cracked. The group symmetric key pool is shared by all members within the group. Once the group symmetric key pool is cracked, the security of group communication based on the group symmetric key pool is threatened;

[0008] 2. The existing method for retrieving keys based on the symmetric key pool is as follows: First, select a key position, and then retrieve the entire segment of the key from that position. When the symmetric key pool is shared by group members, this key retrieval method is easily known by group members, and the privacy is not high;

[0009] 3. The existing method for updating the key pool is that one party generates a key and sends it to the other party. Due to the huge amount of keys in the key pool, it will take a long time to update the key pool; for group communication, the same key needs to be transmitted to each member of the group, and the amount of keys is even more huge, which is often difficult to achieve;

[0010] 4. In the existing group communication system based on the key pool, the status of all members with the group key pool is the same, and the capture of any one member will cause the entire group communication system to fail. Summary of the Invention

[0011] In view of the problems in the related art, the present invention provides a wireless sensor network communication method and system based on a hierarchical symmetric key pool to overcome the above-mentioned technical problems existing in the prior related art.

[0012] For this purpose, the specific technical solutions adopted by the present invention are as follows:

[0013] According to one aspect of the present invention, there is provided a wireless sensor network communication method based on a hierarchical symmetric key pool, and the method includes the following steps:

[0014] S1. Implement the upper-layer group communication between the layer 0 communication base station and the layer 1 cluster head node using the group communication method;

[0015] S2. Implement the lower-layer group communication between the layer 1 cluster head node and the layer 2 sensor nodes under normal circumstances using the group communication method;

[0016] S3. Implement the lower-layer group communication between the layer 1 cluster head node and the layer 2 sensor nodes in the case of the failure of the cluster head node using the group communication method;

[0017] S4. Update the key pool corresponding to the layer-1 cluster head nodes according to the key pool update method;

[0018] When the cluster head node issues the system public and private keys to the sensor node, it obtains the current issuance time, obtains a random number of corresponding size from the key pool through this issuance time, then uses this random number as the system private key corresponding to the sensor node, and calculates the system public key based on this system private key. At the same time, the private key of the sensor node can also be calculated based on this system private key, and the public and private keys, system public and private keys, and algorithm parameters are all stored in the memory of the sensor node and are lost when the power is off. Similarly, the public key of the cluster head node and the private key corresponding to the sensor node are calculated.

[0019] Further, the upper-layer group communication between the layer-0 communication base station and the layer-1 cluster head nodes implemented by S1 using the group communication method includes the following steps:

[0020] S11. The layer-0 communication base station initiates communication with the layer-1 cluster head nodes using the group communication method;

[0021] S12. The layer-1 cluster head nodes initiate communication with the layer-0 communication base station using the group communication method.

[0022] Further, the layer-0 communication base station in S11 initiating communication with the layer-1 cluster head nodes using the group communication method specifically includes the following steps:

[0023] S111. Generate a first timestamp according to the message sent by the layer-0 communication base station, and calculate the key pool of the layer-1 cluster head nodes through the layer-0 communication base station;

[0024] S112. The layer-0 communication base station retrieves a key from the key pool of the layer-1 cluster head nodes;

[0025] After the layer-0 communication base station retrieves the key, it uses this key to encrypt the message sent by the layer-0 communication base station to obtain a first encrypted message, and uses this key to calculate the first message authentication code for the identity number of the layer-0 communication base station, the first timestamp, and the message sent by the layer-0 communication base station. At the same time, it sends the information of the first encrypted message, the first message authentication code, the identity number of the layer-0 communication base station, and the first timestamp to the layer-1 cluster head nodes together;

[0026] S114. After receiving the information, the first-layer cluster head node retrieves a key from its own key pool for decryption. Meanwhile, it uses this key to calculate the message authentication code for the identity number of the zero-layer communication base station, the first timestamp, and the message sent by the zero-layer communication base station, and compares and verifies it with the received first message authentication code.

[0027] Further, the key retrieval in S112 includes the following steps:

[0028] S1121. Calculate the initial position pointer of the key and calculate the step size in sequence.

[0029] S1122. Then calculate the pointers for extracting random codes in sequence and obtain several pointers for extracting random codes.

[0030] S1123. According to several pointers for extracting random codes, sequentially retrieve key data of several bits at the corresponding positions from the key pool.

[0031] S1124. If it exceeds the size of the key pool, use the modulo operation with respect to the key pool length to return to the head of the key pool.

[0032] Further, the S2 uses the group communication method to implement the lower-layer group communication between the first-layer cluster head node and the second-layer sensor nodes under normal circumstances, including the following steps:

[0033] S21. The first-layer cluster head node initiates a private communication to the second-layer sensor nodes using the group communication method.

[0034] S22. The second-layer sensor nodes initiate a private communication to the first-layer cluster head node using the group communication method.

[0035] Further, the step in S21 where the first-layer cluster head node initiates a private communication to the second-layer sensor nodes using the group communication method includes the following steps:

[0036] S211. Use the first-layer cluster head node to calculate a first key.

[0037] S212. The first-layer cluster head node sends the identity information to be authenticated to the second-layer sensor nodes.

[0038] S213. The second-layer sensor nodes receive the identity information to be authenticated and verify it. After successful verification, the second-layer sensor nodes trust the identity of the first-layer cluster head node and the messages sent by the first-layer cluster head node.

[0039] Further, the lower-layer group communication between the first-layer cluster head node and the second-layer sensor nodes in the case of the failure of the cluster head node is implemented through a group communication method in S3, including the following steps:

[0040] S31. The communication base station of the 0th layer announces that the parent node of the ID of the second-layer sensor node ij is modified to ID I , and calculates the replacement key and key pool of the new first-layer cluster head node. Similarly, the replacement key and key pool of the original first-layer cluster head node are calculated;

[0041] S32. The communication base station of the 0th layer retrieves the new system private key and new system public key corresponding to the original ID of the second-layer sensor node ij , and calculates the private key corresponding to the new ID of the second-layer sensor node IJ . The communication base station of the 0th layer packs the above information to obtain the first packed information, and restores the public and private keys for communication between the original ID of the first-layer cluster head node i and the original ID of the second-layer sensor node ij . At the same time, the communication base station of the 0th layer calculates the second key;

[0042] S33. The communication base station of the 0th layer performs a symmetric encryption algorithm calculation on the message with the first packed information and the signature of the first packed information by using the second key, and packs the calculated result message to obtain the second packed information;

[0043] S34. The communication base station of the 0th layer retrieves the key from the key pool of the new ID of the first-layer cluster head node I , and calculates the message authentication code by using the key. At the same time, the communication base station of the 0th layer packs the above message again to obtain the third packed information and sends it to the new ID of the first-layer cluster head node I ;

[0044] S35. The new ID of the first-layer cluster head node I receives the third packed information and performs decryption authentication. At the same time, the new ID of the first-layer cluster head node I sends the second packed information to the original ID of the second-layer sensor node ij ;

[0045] S36. The original ID of the second-layer sensor node ij receives the second packed information, and calculates the third key. At the same time, the original ID of the second-layer sensor node ij uses the third key to decrypt the second packed message and perform message verification. After the verification passes, the original ID of the second-layer sensor node ijUpdate its own identity number to ID IJ , with the parent node being ID I , and update the public-private key and the system public key, and then send the message after the update is successful to the new first-layer cluster head node ID I , the new first-layer cluster head node ID I After receiving, confirm the new second-layer sensor node ID IJ as its child node, and send the message after the update is successful to the 0-layer communication base station. After the 0-layer communication base station confirms the message, store the issuing time corresponding to the new second-layer sensor node ID IJ .

[0046] Furthermore, the update of the key pool corresponding to the first-layer cluster head node by the S4 according to the key pool update method includes the following steps:

[0047] S41. The original first-layer cluster head node ID i generates the request content for updating the key pool, obtains the corresponding timestamp, and sends a key pool update request to the 0-layer communication base station;

[0048] S42. After decrypting and authenticating the message, the 0-layer communication base station generates a new identity number ID i for the first-layer cluster head node ID I and calculates a new replacement key, adds the new first-layer cluster head node ID I and the new replacement key to the message content, and encrypts and sends it to the original first-layer cluster head node ID i , and the original first-layer cluster head node ID i decrypts and authenticates the message;

[0049] S43. The original first-layer cluster head node ID i obtains the new identity number as ID I and the new replacement key, and uses the original replacement key and the symmetric cryptography algorithm in the security chip to restore the key pool in the node in segments and encrypt it with the new replacement key, and outputs the re-encrypted key segments to the corresponding positions in the key pool storage area of the original first-layer cluster head node ID i for overwriting storage;

[0050] S44. The original first-layer cluster head node ID i updates the replacement key and updates the identity number to ID I , and at the same time updates the identity and public-private key pair of its child nodes.

[0051] Furthermore, the output of the re-encrypted key segments to the corresponding positions in the key pool storage area of the original first-layer cluster head node ID i for overwriting storage in S43 includes the following steps:

[0052] S431. Original ID of the cluster head node in the first layer i Extract a section of the key from the key pool and input it into the security chip;

[0053] S432. Use the original replacement key to decrypt the key to obtain a key equal to the corresponding position in the key pool of the communication base station;

[0054] S433. Use the new replacement key to encrypt the key equal to the corresponding position in the key pool of the communication base station;

[0055] S434. Output the encrypted key to the security chip to become a section of the key in the key pool.

[0056] According to another aspect of the present invention, there is provided a wireless sensor network communication system based on a hierarchical symmetric key pool. The system includes multiple layers of nodes such as layer 0 nodes, layer 1 nodes, and layer 2 nodes. Among them, the layer 0 nodes are the communication base stations of the wireless sensor network, the layer 1 nodes are cluster head nodes, and the layer 2 nodes are sensor nodes;

[0057] Among them, the layer 0 nodes have a layer 0 key pool and corresponding replacement keys. The layer 1 nodes are provided with multiple cluster head nodes. Each cluster head node has its own unique key pool and corresponding replacement keys. And the key pool of each cluster head node is calculated from the layer 0 key pool through the replacement keys owned by each node. The replacement key of the cluster head node is calculated from the replacement key of the layer 0 node for the identity number of its own node. The replacement keys of the layer 0 nodes and the layer 1 nodes are stored in the local security storage chip. The layer 2 nodes are provided with multiple sensor nodes.

[0058] The beneficial effects of the present invention are as follows:

[0059] 1). The present invention combines a symmetric key pool and a replacement key, and in the scenario of group communication, further enhances the security of using the symmetric key pool, so that in the extreme case where a sub-group symmetric key pool is cracked, the security of group communication based on the symmetric key pool can still be guaranteed. Because multiple sub-groups are divided within the group. In the case where the key pool of one sub-group is cracked, the security of other sub-groups will not be affected because their key pools are different; in addition, in the case where the key pool of one sub-group is cracked, the key pool of the group administrator cannot be deduced due to the protection of the replacement key, and the security is not affected.

[0060] 2) The method for obtaining keys based on the symmetric key pool in the present invention is as follows: First, use the replacement key to generate the replaced key pool, and then take out multiple key bits one by one from the key pool with different step sizes, and each step size is different. In the case where the symmetric key pool is shared by group members, this key-taking method will not be known to group members either, and it has high privacy.

[0061] 3) The method for updating the key pool in the present invention only needs to transmit a small amount of keys to update the key pool. The key transmission amount of the key update scheme is very small and it is easy to implement.

[0062] 4) In the group communication system based on the key pool in the present invention, the status of all members with the group key pool is divided according to levels, and the protection measures and key pools for different levels are different. The protection measures for important-level members are good and they are not easily captured; the protection measures for unimportant-level members are relatively poor, but since their key pools are obtained by encrypting the key pools of important-level members, even if they are captured, it has little impact and will not cause the failure of the entire group communication system. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0064] Figure 1 is a schematic flowchart of a wireless sensor network communication method based on a hierarchical symmetric key pool according to an embodiment of the present invention;

[0065] Figure 2 is a schematic diagram of a random number acquisition method in a wireless sensor network communication method based on a hierarchical symmetric key pool according to an embodiment of the present invention;

[0066] Figure 3 is a structural block diagram of a wireless sensor network communication system based on a hierarchical symmetric key pool according to an embodiment of the present invention;

[0067] Figure 4 is a distribution schematic diagram of a hierarchical structure symmetric key pool in a wireless sensor network communication system based on a hierarchical symmetric key pool according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0068] To further illustrate each embodiment, the present invention provides accompanying drawings, which are part of the disclosure of the present invention. These drawings are mainly used to illustrate the embodiments and can be combined with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention. The components in the drawings are not drawn to scale, and similar component symbols are usually used to represent similar components.

[0069] According to an embodiment of the present invention, a wireless sensor network communication method and system based on a hierarchical symmetric key pool are provided. In a communication group, the present invention assumes that all member IDs carry the layer number of the ID. The smaller the layer number, the better the security protection measures and the lower the possibility of being captured by the enemy.

[0070] Now, the present invention will be further described in combination with the accompanying drawings and specific implementation manners. According to an embodiment of the present invention, as Figure 1-2 shown, a wireless sensor network communication method based on a hierarchical symmetric key pool is provided, and the method includes the following steps:

[0071] S1. Upper-layer group communication (implementing upper-layer group communication between the communication base station of layer 0 and the cluster head node of layer 1 using the group communication method);

[0072] In this embodiment, the communication base station of layer 0 is called A, the replacement key of A is KR0, and the identity number of A is ID0; a certain cluster head node of layer 1 is called B, the replacement key of B is KR B , and the identity number of B is ID B .

[0073] Among them, the S1 includes the following steps:

[0074] S11. Communication between A of layer 0 and B of layer 1 (the communication base station of layer 0 initiates communication with the cluster head node of layer 1 using the group communication method);

[0075] Suppose the message content to be sent by group member A is NTFA, and a timestamp TNTFA is generated for this message. A first calculates the key pool of B: A calculates the replacement key KR B of B according to its own replacement key KR0 and the identity number ID B of B, and then the key pool of B can be comprehensively calculated from KR B and the key pool of A, and the length of the key pool is KPL.

[0076] A extracts the key KTA from the key pool of B. This key is N bits in total. The specific calculation of obtaining KTA can refer to the system private key generation method described above, and the specific description process is as follows:

[0077] Calculate the initial position pointer PK of the key KTA: PK = FPK(TNTFA) mod KPL, where mod represents the modulo operation. Calculate the step lengths in sequence: LK1 = FLK(PK||TNTFA), LK2 = FLK(LK1||TNTFA), LK3 = FLK(LK2||TNTFA), …, LK N = FLK(LK N-1 ||TNTFA). The functions FPK(*) and FLK(*) are arbitrarily specified functions. Then calculate the pointers for extracting random codes in sequence: PK1 = PK + LK1 mod KPL, PK2 = PK1 + LK2 mod KPL, …, PK N = PK N-1 + LK N mod KPL. PK1 points to the start position of the key KTA, that is, the position of the first bit, PK2 points to the second bit position of the key KTA, and so on. According to PK1, PK2, …, PK N Take out a total of N bits of key data at the corresponding positions from the key pool in sequence. If it exceeds the key pool size KPL, use the modulo operation with respect to KPL to return to the head of the key pool.

[0078] After A retrieves the symmetric key KTA of group member B, use KTA to encrypt NTFA to obtain {NTFA}KTA. Use KTA to calculate the message authentication code for ID0, TNTFA, and NTFA to obtain MAC(ID0||TNTFA||NTFA, KTA). Send the encrypted information, message authentication code together with ID A and TNTF to group member B. The information sent can be expressed as ID0||TNTFA||{NTFA}KTA||MAC(ID0||TNTFA||NTFA, KTA).

[0079] After B receives it, use the same method to retrieve the symmetric key KTA from its own key pool, use KTA to decrypt {NTFA}KTA to obtain the message content NTFA, use KTA to calculate the message authentication code for ID0, TNTFA, and NTFA and compare it with the received message authentication code. If the two are consistent, it means the verification passes. After the verification passes, trust the message content NTFA; if the verification fails, do not trust the message content NTFA.

[0080] S12. The Layer 1 B communicates with the Layer 0 A (the Layer 1 cluster head node initiates communication with the Layer 0 communication base station using the group communication method);

[0081] Suppose the message content to be sent by group member B is NTFB, and a timestamp TNTFB is generated for this message. B retrieves the key KTB from its own key pool according to the method in S11. This key is N bits in total. Then, NTFB is encrypted using KTB to obtain {NTFB}KTB. Using KTB, calculate the message authentication code for ID B 、TNTFB and NTFB to get MAC(ID B ||TNTFB||NTFB,KTB). Send the encrypted information, the message authentication code together with ID B 、TNTFB to group member A. The information sent can be expressed as ID B ||TNTFB||{NTFB}KTB||MAC(ID B ||TNTFB||NTFB,KTB).

[0082] After A receives it, calculate to obtain B's key pool according to the method in S11 and retrieve KTB from it. Use KTB to decrypt {NTFB}KTB to obtain the message content NTFB. Use KTB to calculate the message authentication code for ID B 、TNTFB and NTFB and compare it with the received message authentication code. If the two are consistent, it means the verification passes. After the verification passes, trust the message NTFB; if the verification fails, do not trust the message NTFB.

[0083] S2. Downlink group communication under normal circumstances (realize the downlink group communication between the first-layer cluster head node and the second-layer sensor node under normal circumstances by using the group communication method);

[0084] Among them, S2 includes the following steps:

[0085] S21. Private communication between the first layer A and the second layer B;

[0086] The cluster head node A calculates the public key PKB of node B according to the identity number ID B of node B to get PKB = H(ID B ). A calculates using its own private key and the public key of node B to obtain Node A obtains a timestamp T1, and uses K AB to perform the message authentication algorithm on the timestamp to get K1 = MAC(T1,K AB ), where MAC(m,k) is the expression for calculating the message authentication algorithm for the message content m with the key k.

[0087] Let INFOA be the service information of the wireless sensor network of node A. Node A uses the private key SKA_B to perform the ID-based cryptography signature algorithm calculation on T1||INFOA to obtain SIGA = SIG(T1||INFOA, SKA_B), where SIG(m,k) is the expression for performing the ID-based cryptography signature algorithm calculation on the message content m with the key k. Node A uses K1 to encrypt INFOA||SIGA to obtain {INFOA||SIGA}K1, and uses the key K1 to perform the message authentication algorithm calculation on ID B ||ID A ||T1||{INFOA||SIGA}K1 to obtain MAC(ID B ||ID A ||T1||{INFOA||SIGA}K1, K1). Node A sends the encrypted information, the message authentication code, together with ID A 、ID B 、T1 to node B. The information sent can be expressed as ID A ||ID B ||T1||{INFOA||SIGA}K1||MAC(ID B ||ID A ||T1||{INFOA||SIGA}K1, K1).

[0088] After receiving it, node B calculates the public key PKA of node A according to the identity number ID A of node A as PKA = H(ID A ). B uses its own private key and the public key of node A to calculate Node B uses K BA to perform the message authentication algorithm on the timestamp T1 in the message to obtain K1’ = MAC(T1, K BA ). According to ID-based cryptography, it can be obtained that: Therefore, K1’ = K1. So node B can use the key K1’ to decrypt {INFOA||SIGA}K1 to obtain the correct INFOA||SIGA, and verify the message authentication code MAC(ID B ||ID A ||T1||{INFOA||SIGA}K1, K1). Finally, node B uses the calculated public key PKA of node A to verify the signature SIGA. After the verification passes, B trusts the identity of A and the message sent by A.

[0089] S22. Layer 2 B communicates privately with Layer 1 A.

[0090] The communication method in this case is basically the same as that of S21.

[0091] Node B calculates the public key PKA_B = H(ID) of cluster head node A according to the identity number ID of cluster head node A A ). B calculates using its own private key and the public key of node A to obtain A ). B obtains a timestamp T2 and uses K to perform a message authentication algorithm on the timestamp to obtain K2 = MAC(T2, K BA ). BA

[0092] Let INFOB be the service information of the wireless sensor network of node B. Node B uses its private key SKB to perform an ID-based cryptography signature algorithm calculation on T2||INFOB to obtain SIGB = SIG(T2||INFOB, SKB). Node B encrypts INFOB||SIGB using K2 to obtain {INFOB||SIGB}K2, and uses the key K2 to perform a message authentication algorithm on ID A ||ID B ||T2||{INFOB||SIGB}K2 to obtain MAC(ID A ||ID B ||T2||{INFOB||SIGB}K2, K2). Node B sends the encrypted information, message authentication code together with ID B 、ID A 、T2 to node A. The information sent can be expressed as ID B ||ID A ||T2||{INFOB||SIGB}K2||MAC(ID A ||ID B ||T2||{INFOB||SIGB}K2, K2).

[0093] After node A receives it, it calculates the public key PKB = H(ID) of node B according to the identity number ID of node B B ). A calculates using its own private key and the public key of node B to obtain B ). Node A uses K AB to perform a message authentication algorithm on the timestamp T2 in the message to obtain K2' = MAC(T2, K AB ), and K2' = K2. Node A decrypts {INFOB||SIGB}K2 using the key K2' to obtain the correct INFOB||SIGB, and verifies the message authentication code MAC(ID A ||ID B ​||T2||Verify it with {INFOB||SIGB}K2,K2). Finally, node A uses the calculated public key PKB of node B to verify the signature SIGB. After successful verification, A trusts B's identity and the message sent by B.

[0094] S3. Lower-layer group communication in the case of cluster head node failure (realize the lower-layer group communication between the first-layer cluster head node and the second-layer sensor node in the case of cluster head node failure through the group communication method);

[0095] Among them, the S3 includes the following steps:

[0096] The reasons for the failure of the cluster head node may be being destroyed, stolen, powered off, etc. After failure, the cluster head node is no longer trustworthy, and the base station sends a new cluster head node ID I to replace the original cluster head node ID i . Suppose ID i was originally connected to multiple sensor nodes, and the jth node is ID ij . After the cluster head node is replaced, it is necessary to connect the multiple sensor nodes originally connected to ID i to ID I .

[0097] The communication base station announces that the parent node of ID ij is changed to ID I , and the message content of changing ID ij to ID IJ is NTF, and the time is TNTF. The communication base station calculates the replacement key KR I of the new cluster head node = FKRID(ID I , KR0). Use the replacement key to calculate the key pool of the new cluster head node. Similarly, calculate the replacement key KR i of the old cluster head node i = FKRID(ID i , KR0), and use the replacement key KR i to calculate the key pool of the old cluster head node.

[0098] The communication base station obtains the new system private key sIJ and the new system public key PIJ ij of the sensor node corresponding to ID pub from the key pool of the new cluster head node using TNTF = sIJ·P, and calculates the private key SK IJ corresponding to the identity number ID IJ = sIJ*H(ID IJ ). The communication base station packs the above information to obtain NTF-I-J = NTF||ID i ||ID I ||IDIJ ||SK IJ ||PIJ pub 。The communication base station retrieves from the time backup of node ID i the time regarding node ID ij and restores the public and private keys PKH i / SKH i for communicating with node ID ij through the key pool of node ID ij / SKH ij 。The communication base station uses SKH ij to perform an ID-cryptography-based signature on NTF-I-J: SIG-I-J = SIG(NTF-I-J, SKH ij ). The communication base station takes NTF-I-J||SIG-I-J as the message content NTF sensor 。The communication base station calculates the public key PK ij of the node according to the identity number ID ij of the node: PK ij = H(ID ij ). Using the private key of node ID i and the public key of node ID ij to calculate The communication base station obtains a timestamp T1 and performs a message authentication algorithm on the timestamp with K HS to get K1 = MAC(T1, K HS ).

[0099] The communication base station uses the key K1 to perform a symmetric encryption algorithm on NTF sensor to calculate {NTF sensor}K1. The communication base station packs the message to get NTF-i-j = ID ij ||ID i ||T1||{NTF sensor}K1||MAC(ID ij ||ID i ||T1||{NTF sensor}K1, K1).

[0100] The communication node uses the timestamp T1 to retrieve from ID IThe key KBI is taken out from the key pool of the node, and the specific generation process can refer to the above step S11. The communication base station encrypts NTF-i-j||TNTF with the key KBI to obtain {NTF-i-j||TNTF}KBI and calculates the message authentication code for ID0, T1, and NTF-i-j||TNTF to get MAC(ID0||T1||NTF-i-j||TNTF, KBI). The communication base station packs the message to obtain ID0||T1||{NTF-i-j||TNTF}KBI||MAC(ID0||T1||NTF-i-j||TNTF, KBI). The communication base station sends the message to the new cluster head node ID I .

[0101] New cluster head node ID I After receiving, according to the timestamp T1 in the message, KBI is taken out from the local key pool in the same way, and the message is decrypted and authenticated with KBI to obtain NTF-i-j and TNTF. Here, refer to step S11. Cluster head node ID I Calculates the system public and private keys and communication public and private keys for node ID IJ using the time TNTF. At the same time, cluster head node ID I sends NTF-i-j to the sensor node ID ij .

[0102] Sensor node ID ij After receiving NTF-i-j, calculates the public key PKH i of node ID i according to the identity number of the old cluster head node ID ij =H(ID i ), and takes out its own private key SK ij to calculate K HS =K SH . Node ID ij Calculates K1’ = MAC(T1, K SH ) using K SH . Node ID ij Decrypts and verifies the message NTF-i-j with the key K1’, and the specific process can refer to step S21. Node ID ij updates its own identity number to ID IJ , changes the parent node to ID I , updates the public and private keys to PK IJ / SK IJ , and updates the system public key to PIJ pub . And sends the message after successful update to the cluster head node ID I in the way of step S22. Cluster head node IDI Confirm the sensor node ID after receipt IJ As its child node, and use the method in step S12 to update the ID IJ Send the message after successful update to the communication base station. After the communication base station confirms the message, store the ID IJ The corresponding issuance time

[0103] S4. Update the lower-layer node key pool (update the key pool corresponding to the first-layer cluster head node according to the key pool update method);

[0104] Among them, S4 includes the following steps:

[0105] This embodiment is the process for the cluster head node to implement key pool update. To enhance security, the cluster head node actively updates its own identity and the corresponding key pool. Assume that the identity number of the cluster head node for key pool update in this embodiment is ID i , assume ID ij Is the identity number of a child node of this cluster head node

[0106] Cluster head node ID i Generate the request content NTFH for updating the key pool, and obtain the time stamp as THTFH. Send the key pool update request to the communication base station in the method of step S12

[0107] After the communication base station decrypts and authenticates the message, generate a new first-layer identity number ID I And through ID I Calculate to obtain the new replacement key KR I . Add the new identity number ID I And the new replacement key KR I To the message content, and encrypt and send it to the cluster head node ID in the manner of step S11 i Cluster head node ID i Decrypt and authenticate the message

[0108] Cluster head node ID i Get the new identity number ID I And the new replacement key KR I Cluster head node ID i Use the original replacement key KR in the security chip i And the symmetric cryptography algorithm to restore the key pool in the node in segments and encrypt it with the new replacement key KR I The re-encrypted key segment is output to the corresponding position of the key pool storage area of the cluster head node ID i For overwriting storage. The specific process is as follows:

[0109] 1) ID iTake a segment of the key K-i from the key pool and input it into the secure chip;

[0110] 2) Use KR i to decrypt K-i to obtain the key KA that is equal to the corresponding position in the key pool of the communication base station;

[0111] 3) Use KR I to encrypt KA to obtain K-I;

[0112] 4) Output K-I from the secure chip to become a segment of the key in the key pool.

[0113] Cluster head node ID i Update and replace the key with KR I , and update the identity number to ID I . The cluster head node needs to update the identities and public-private key pairs of its child nodes, and the update method is the same as that in step S3.

[0114] According to another aspect of the present invention, as Figure 3-4 shown, a wireless sensor network communication system based on a hierarchical symmetric key pool is provided. The system includes multiple layers of nodes such as layer 0 nodes, layer 1 nodes, and layer 2 nodes. Among them, layer 0 is the communication base station of the wireless sensor network, layer 1 nodes are cluster head nodes, and layer 2 nodes are sensor nodes.

[0115] In the symmetric key pool based on the hierarchical structure of the present invention, it is assumed that the layer 0 node has the layer 0 key pool and the replacement key KR0. The implementation scenario of the present invention is wireless sensor network communication under the communication base station. There is exactly one layer 0 node, i.e., the communication base station, which also serves as the group administrator of the wireless sensor network. The base station has an original key pool and a replacement key, and the original key pool is generated by true random numbers; there are several cluster head nodes in layer 1, and each cluster head node has its own unique key pool and replacement key, and the key pool of each node is calculated from the original key pool through the replacement key owned by each node; there are several sensor nodes in layer 2. The replacement key of the nodes in layer 1, i.e., the cluster head nodes, is calculated by the replacement key of the communication base station in layer 0 for the identity numbers of each node. Let the identity number of the i-th node in layer 1, i.e., ID, be ID i , and the replacement key of the communication base station be KR0. Using the replacement key KR0 to calculate IDi can obtain the replacement key KR of this node i = FKRID(ID i, (KR0), where FKRID is an irreversible function, preferably a message authentication code, i.e., a MAC function, or a hash function. Among them, the replacement keys of the nodes in the 0th layer and the 1st layer are stored in a local secure storage chip such as a TPM / TCM, which has anti-disassembly functions and cannot be obtained. Moreover, since the FKRID function is located inside the secure chip and has no output interface, the calculation result, i.e., the subordinate replacement key obtained from the replacement key, cannot be obtained either (except for the nodes in the 0th layer, because the administrator of the nodes in the 0th layer holds the PIN codes of all secure storage chips and can perform key import and export operations); the sensor nodes in the 2nd layer are limited by power consumption, storage capacity, and cost and do not have secure chips.

[0116] The key replacement formula is KRS = FKR(K, KR). Among them, FKR is a reversible function, preferably a symmetric encryption function, and the length of KRS is equal to the length of K.

[0117] The process of generating the replacement key pool for the nodes in the 1st layer is as follows. The key pool in the 0th layer is evenly divided into multiple segments of keys. Let the nth segment be K n , for the ID of the ith node in the 1st layer i , use the key replacement formula to calculate KRS ni = FKR(K n , KR i ), and use KRS ni to replace K n . After the replacement is completed, a key pool for the ID of the ith node in the 1st layer i equal to the length of the key pool in the 0th layer is obtained. To sum up, the key pool of a certain node in the 1st layer is obtained by comprehensively calculating the replacement key of this node and the key pool of its parent node, i.e., the 0th layer. By analogy, using the replacement keys of each node in the 1st layer for calculation, the key pools of each node in the 1st layer can be obtained.

[0118] In the present invention, an algorithm system based on ID cryptography is adopted. The algorithm parameters are where q is a large prime number, G1 and G2 are respectively an additive cyclic group and a multiplicative cyclic group of order q, and the mapping G1×G1→G2 becomes a bilinear mapping, P is a generator randomly selected from G1, H is a hash function defined as {0, 1} * →G1 * , and ad_paras are other system parameters in the algorithm. The communication base station distributes the algorithm parameters to each cluster head node and sensor node.

[0119] The cluster head node will generate a pair of system public and private keys for each of its subordinate child nodes. When the cluster head node issues the public and private keys to a certain sensor node, it will obtain the current issuance time T. A random number of corresponding size is obtained from the key pool through the time T. Let the obtained random number be s, and the size s ∈ Z q* The calculation method of the random number s is as follows:

[0120] Calculate the initial position pointer Ps of the random number s = FPK(T) mod KPL, where mod represents the modulo operation. Calculate the step lengths in sequence: Ls1 = FLK(Ps||T), Ls2 = FLK(Ls1||T), Ls3 = FLK(Ls2||T), …, Ls N = FLK(Ls N-1 ||T). The functions FPK(*) and FLK(*) are arbitrarily specified functions. Then calculate the pointers for extracting the random code in sequence: Ps1 = Ps + Ls1 mod KPL, Ps2 = Ps1 + Ls2 mod KPL, …, Ps N = Ps N-1 + Ls N mod KPL. Ps1 points to the start position of the random number s, that is, the position of the first bit, Ps2 points to the second bit position of the random number s, and so on. According to Ps1, Ps2, …, Ps N Take out a total of N-bit random number data at the corresponding positions from the key pool in sequence. If it exceeds the key pool size KPL, use the modulo operation with respect to KPL to return to the head of the key pool.

[0121] Take the random number s as the system private key of the corresponding sensor node, that is, the system master key, and calculate the system public key P pub = s·P. From this, the public and private keys of the sensor node can be calculated as PK sensor = H(ID sensor ) / SK sensor = s * PK sensor , where PK sensor is the public key of this sensor node, and SK sensor is the private key of this sensor node. This sensor node stores this public and private key pair, the system public key, and the algorithm parameters in the memory of this sensor node, and they are lost when the power is off. The cluster head node will also calculate the public key PK head = H(ID head ) and the private key SK head = s * PK head .

[0122] In the wireless sensor network communication system based on a hierarchical symmetric key pool of the present invention, if there are several child nodes, i.e., several sensor nodes, under a cluster head node, the cluster head node will execute the above key issuance process multiple times. At the same time, the cluster head node will save the issuance time and algorithm parameters used to generate the system public and private keys in the secure chip and back up them to the communication base station. After the cluster head node or the sensor node is captured, the enemy can obtain the key pool of the node, but cannot obtain the relevant issuance time, algorithm parameters, and public and private keys. Since the system master keys corresponding to each sensor node are different, even if one of the system master keys is cracked, it will not affect the security of the algorithm system, the cluster head node, and its child nodes.

[0123] In summary, by means of the above technical solutions of the present invention, the present invention combines a symmetric key pool and a replacement key, and further enhances the security of using the symmetric key pool in the scenario of group communication, so that in the extreme case where the symmetric key pool of a sub-group is cracked, the security of group communication based on the symmetric key pool can still be guaranteed. Because multiple sub-groups are divided within the group, in the case where the key pool of a sub-group is cracked, the security of other sub-groups will not be affected because their key pools are different; in addition, in the case where the key pool of a sub-group is cracked, the key pool of the group administrator cannot be deduced because it is protected by the replacement key, and the security is not affected. In addition, the method for obtaining keys based on the symmetric key pool of the present invention is as follows: first, use the replacement key to generate a replaced key pool, and then sequentially extract multiple key bits from the key pool with different step lengths, and each step length is different. In the case where the symmetric key pool is shared by group members, this key extraction method is also unknown to group members, and the privacy is high. In addition, the method for updating the key pool of the present invention only needs to transfer a small amount of keys to update the key pool, and the key transmission amount of the key update scheme is very small and is easy to implement. In addition, in the group communication system based on the key pool of the present invention, the status of all members having the group key pool is divided according to levels, and the protection measures and key pools of different levels are different. The protection measures for members of important levels are good and they are not easily captured; the protection measures for members of unimportant levels are relatively poor, but since their key pools are encrypted from the key pools of members of important levels, even if they are captured, it will not have much impact and will not cause the failure of the entire group communication system.

[0124] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0125] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.

Claims

1. A communication method for a wireless sensor network based on a hierarchical symmetric key pool, characterized in that, The method includes the following steps: S1. Implement upper-layer group communication between the communication base station of layer 0 and the cluster head nodes of layer 1 using the group communication method; S2. Implement lower-layer group communication between the cluster head nodes of layer 1 and the sensor nodes of layer 2 under normal circumstances using the group communication method; S3. Implement lower-layer group communication between the cluster head nodes of layer 1 and the sensor nodes of layer 2 in the case of cluster head node failure using the group communication method; The step that S3 implements lower-layer group communication between the cluster head nodes of layer 1 and the sensor nodes of layer 2 in the case of cluster head node failure using the group communication method includes the following steps: S31. The communication base station of layer 0 announces that the parent node of the sensor node ID of layer 2 ij is modified to ID I , and calculates the replacement key and key pool of the new cluster head node of layer 1. Similarly, calculates the replacement key and key pool of the original cluster head node of layer 1; S32. Use the communication base station of layer 0 to retrieve the original sensor node ID of layer 2, ij the new system private key and the new system public key, and calculate the new sensor node ID of layer 2 IJ the corresponding private key. The communication base station of layer 0 packs the information to obtain the first packed information and restores the original cluster head node ID of layer 1 i and the original sensor node ID of layer 2 ij the public and private keys for communication. Meanwhile, use the communication base station of layer 0 to calculate the second key; S33. The communication base station of layer 0 performs a symmetric encryption algorithm calculation on the message with the first packaging information and the signature of the first packaging information using the second key, and packages the message of the calculation result to obtain the second packaging information; S34. Use the communication base station of the 0th layer to retrieve a key from the key pool of the new 1st layer cluster head node ID I and use this key to calculate the message authentication code. At the same time, the communication base station of the 0th layer repackages the message to obtain the third packaged information and sends it to the new 1st layer cluster head node ID I ; S35, New Layer 1 Cluster Head Node ID I Receive the third packaged information and perform decryption authentication. Meanwhile, the new Layer 1 cluster head node ID I Send the second packaged information to the original Layer 2 sensor node ID ij ; S36. Original ID of the sensor nodes in the second layer ij Receive the second packaged information and calculate to obtain the third key. Meanwhile, the original ID of the sensor nodes in the second layer ij Use the third key to decrypt and verify the second packaged message. After successful verification, the original ID of the sensor nodes in the second layer ij Update its own identity number to ID IJ , with the parent node being ID I , and update the public and private keys and the system public key. Subsequently, send the successfully updated message to the new ID of the first-layer cluster head node I , the new ID of the first-layer cluster head node I After receiving it, confirm that the new ID of the second-layer sensor node IJ is its child node, and send the successfully updated message to the 0-layer communication base station. After the 0-layer communication base station confirms the message, store the issuance time corresponding to the new ID of the second-layer sensor node IJ ; S4. Update the key pool corresponding to the cluster head nodes of layer 1 according to the key pool update method; The step that S4 updates the key pool corresponding to the cluster head nodes of layer 1 according to the key pool update method includes the following steps: S41. Original ID of the cluster head node in the first layer i Generate the request content for updating the key pool, obtain the corresponding timestamp, and send a key pool update request to the communication base station of layer 0; After the 0-layer communication base station decrypts and authenticates the message, it generates the ID of the first-layer cluster head node i New identity number ID I And calculates the new replacement key, and adds the new first-layer cluster head node ID I And the new replacement key to the message content, and encrypts and sends it to the original first-layer cluster head node ID i , the original first-layer cluster head node ID i Decrypts and authenticates the message; S43. Original ID of the cluster head node in the first layer i Obtain a new identity number as ID I And a new replacement key, and use the original replacement key and symmetric cryptography algorithm in the security chip to segmentally restore the key pool in the node and encrypt it with the new replacement key, and output the re-encrypted key segment to the corresponding position in the key pool storage area of the original ID of the cluster head node in the first layer i for overwriting storage; S44. Original cluster head node ID of the first layer i Update and replace the key and update the identity number to ID I , and at the same time update the identity and public-private key pairs of its child nodes; Wherein, when the cluster head node issues the system public and private keys to the sensor node, the current issuing moment is obtained, and a random number of corresponding size is obtained from the key pool of the cluster head nodes of layer 1 through this issuing moment. Then, this random number is used as the system private key corresponding to the sensor node, and the system public key is calculated based on this system private key. At the same time, the private key of the sensor node can also be calculated based on this system private key, and the public and private keys, system public and private keys, and algorithm parameters are all stored in the memory of the sensor node and are lost when the power is off. Similarly, the public key of the cluster head node and the private key corresponding to the sensor node are calculated.

2. The wireless sensor network communication method based on a hierarchical symmetric key pool according to claim 1, wherein The step that S1 implements upper-layer group communication between the communication base station of layer 0 and the cluster head nodes of layer 1 using the group communication method includes the following steps: S11. The communication base station of layer 0 initiates communication with the cluster head nodes of layer 1 using the group communication method; S12. The cluster head nodes of layer 1 initiate communication with the communication base station of layer 0 using the group communication method.

3. The wireless sensor network communication method based on a hierarchical symmetric key pool according to claim 2, wherein, The step that the communication base station of layer 0 in S11 initiates communication with the cluster head nodes of layer 1 using the group communication method specifically includes the following steps: S111. Generate a first timestamp according to the message sent by the communication base station of layer 0, and calculate the key pool of the cluster head nodes of layer 1 through the communication base station of layer 0; S112. The communication base station of layer 0 retrieves the key from the key pool of the cluster head nodes of layer 1; After the communication base station of layer 0 retrieves the key, it encrypts the message sent by the communication base station of layer 0 using this key to obtain the first encrypted message, and calculates the first message authentication code for the identity number of the communication base station of layer 0, the first timestamp, and the message sent by the communication base station of layer 0 using this key. At the same time, the information of the first encrypted message, the first message authentication code, the identity number of the communication base station of layer 0, and the first timestamp is sent to the cluster head nodes of layer 1 together; S114. After receiving the information, the cluster head node of the first layer retrieves the key from its own key pool for decryption. At the same time, it uses this key to calculate the message authentication code for the identity number of the communication base station of the zeroeth layer, the first timestamp, and the message sent by the communication base station of the zeroeth layer, and compares and verifies it with the received first message authentication code.

4. The wireless sensor network communication method based on a hierarchical symmetric key pool according to claim 3, characterized in that The steps for retrieving the key in S112 are as follows: S1121. Calculate the initial position pointer of the key, and then calculate the step size in sequence. S1122. Then calculate the pointers for extracting random codes in sequence, and obtain several pointers for extracting random codes. S1123. According to several of the pointers for extracting random codes, sequentially retrieve the key data of several bits at the corresponding positions from the key pool. S1124. If it exceeds the size of the key pool, use the modulo operation with respect to the length of the key pool to return to the head of the key pool.

5. The wireless sensor network communication method based on a hierarchical symmetric key pool according to claim 1, wherein S2. Using the group communication method to implement the lower-layer group communication between the cluster head node of the first layer and the sensor nodes of the second layer under normal circumstances includes the following steps: S21. The cluster head node of the first layer uses the group communication method to initiate a private communication to the sensor nodes of the second layer. S22. The sensor nodes of the second layer use the group communication method to initiate a private communication to the cluster head node of the first layer.

6. The wireless sensor network communication method based on a hierarchical symmetric key pool according to claim 5, wherein The steps for the cluster head node of the first layer in S21 to use the group communication method to initiate a private communication to the sensor nodes of the second layer are as follows: S211. Use the cluster head node of the first layer to calculate the first key. S212. The cluster head node of the first layer sends the identity information to be authenticated to the sensor nodes of the second layer. S213. The sensor nodes of the second layer receive the identity information to be authenticated and perform verification. After the verification passes, the sensor nodes of the second layer trust the identity of the cluster head node of the first layer and the message sent by the cluster head node of the first layer.

7. The wireless sensor network communication method based on a hierarchical symmetric key pool according to claim 1, wherein The re-encrypted key segment in S43 is output to the corresponding position in the key pool storage area of the original first-layer cluster head node ID i for overwriting storage, which includes the following steps: S431. Original ID of the cluster head node in the first layer i Extract a segment of the key from the key pool and input it into the security chip; S432. Decrypt the key using the original replacement key to obtain a key equal to the corresponding position in the communication base station key pool. S433. Encrypt the key equal to the corresponding position in the communication base station key pool using the new replacement key. S434. Output the encrypted key to the secure chip to become a segment of the key in the key pool.

8. A wireless sensor network communication system based on a hierarchical symmetric key pool, which is used to implement the steps of the wireless sensor network communication method based on a hierarchical symmetric key pool according to any one of claims 1-7, characterized in that, The system includes multiple layers of nodes, namely the zeroeth layer nodes, the first layer nodes, and the second layer nodes. Among them, the zeroeth layer nodes are the communication base stations of the wireless sensor network, the first layer nodes are the cluster head nodes, and the second layer nodes are the sensor nodes. Among them, the zeroeth layer nodes have a zeroeth layer key pool and corresponding replacement keys. The first layer nodes are provided with multiple cluster head nodes. Each of the cluster head nodes has its own unique key pool and corresponding replacement keys. Moreover, the key pool of each cluster head node is calculated from the zeroeth layer key pool through the replacement keys owned by the nodes. The replacement key of the cluster head node is calculated from the replacement key of the zeroeth layer node with respect to the identity number of its own node. The replacement keys of the zeroeth layer nodes and the first layer nodes are stored in the local secure storage chip. The second layer nodes are provided with multiple sensor nodes.

Citation Information

Patent Citations

  • Secret key management method and system

    CN102013975A

  • Dynamic clustering wireless sensor network cipher key management method

    CN108880814A