Hierarchical Wireless Sensor Network Communication Method and System Based on Asymmetric Key Pool

By using a hierarchical structure of asymmetric key pool and elliptic curve algorithm to calculate subkeys in wireless sensor networks, the problems of insufficient security of group communication and time-consuming and energy-consuming key updates are solved, and secure communication and efficient key management in extreme cases are realized.

CN115037448BActive Publication Date: 2025-07-04NANJING RUPAN QUANTUM TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110194047.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-20
Publication Date
2025-07-04
Estimated Expiration
2041-02-20

AI Technical Summary

Technical Problem

In the existing wireless sensor network communication system, group communication is insufficient security, and any member being captured will cause the entire group communication system to fail, and the update transmission of the symmetric key pool is time-consuming and energy-consuming.

Method used

The hierarchical structure of an asymmetric key pool is adopted. The nodes are divided into multiple levels, including communication base stations, cluster head nodes and sensing nodes. Each layer of nodes has identity information and security chips. The key pool calculates sub-keys through an elliptic curve algorithm. The cluster head node contains a key management server to realize key issuance based on ID cryptography. Session key encryption and identity authentication are used during communication.

Benefits of technology

Security can still be ensured when the group communication node is cracked, reducing the time and energy consumption of key updates, and improving the security and performance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115037448B_ABST
    Figure CN115037448B_ABST
Patent Text Reader

Abstract

Hierarchical Wireless Sensor Network Communication Method and System Based on Asymmetric Key Pool. This patent combines a hierarchical structure, an asymmetric key pool, and a chip key, divides the status of members of the group key pool by level, and the protection measures and keys of members at different levels are different, so that the security of communication can still be guaranteed in the extreme case where the group communication node is cracked. The chip key, key pointer function, and key coefficient function of the cluster head node are all located in the secure chip, so the enemy cannot obtain them; more types of key values are retrieved from the key pool through the key pointer function and the key coefficient function, so it is more difficult for the enemy to crack this system. The system private keys of each sensing node are different, and the cracking of the key of a certain node will not affect the security of the system and other nodes. In addition, the key management scheme in this patent is acceptable for wireless sensor networks in terms of performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless sensor network communication, and particularly to a hierarchical wireless sensor network communication method and system based on an asymmetric key pool. Background Art

[0002] A wireless sensor network is a network formed by organizing and combining a large number of sensor nodes in a clustered form through wireless communication technology. The units constituting the sensor nodes are respectively: a data acquisition unit, a data transmission unit, a data processing unit, and an energy supply unit. Among them, the data acquisition unit usually collects and converts information in the monitoring area, such as light intensity, atmospheric pressure, and humidity, etc.; the data transmission unit mainly focuses on wireless communication and exchanging information, as well as sending and receiving the collected data information; the data processing unit usually processes the routing protocols, management tasks, and positioning devices of all nodes, etc.; the energy supply unit will choose the form of a micro battery to reduce the area occupied by the sensor nodes. The nodes in the wireless sensor network are divided into two types, one is a sink node, and the other is a sensor node. The sink node mainly refers to the gateway, which can eliminate the wrong reported data among the sensor nodes, combine it with the relevant reports to fuse the data, and judge the occurrence time. The sink node can communicate directly with the user node through a wide area network or a satellite, and process the collected data. In addition to the sink node and the user node, a global base station or service center can also be deployed to summarize the information of all sink nodes.

[0003] The existing quantum-resistant wireless sensor network communication can use a group key pool, and group communication is realized by using the symmetric keys stored in the group-type symmetric key pool. If a certain member is attacked, the secure communication of the entire group is threatened by security.

[0004] In the prior art, the update of the key pool often requires the participation of an issuing center. Due to the large amount of data transmitted, there is a certain threat to security.

[0005] Based on the above analysis, the prior art has the following defects:

[0006] 1. In the prior art, there is a possibility that a wireless sensor is captured and disassembled, resulting in the possibility that the stored group communication key is cracked. The security of group communication is insufficient, and the capture of any one member will cause the failure of the entire group communication system.

[0007] 2. In the existing communication system based on a symmetric key pool, the amount of key data transmitted for updating the key pool is large (such as the patent with the application number "201711204731.8"), and the transmission is time-consuming and energy-consuming, which is unacceptable for a wireless sensor network. Summary of the Invention

[0008] In view of the problems in the related art, the present invention proposes a hierarchical wireless sensor network communication method and system based on an asymmetric key pool to overcome the above-mentioned technical problems existing in the existing related art.

[0009] For this purpose, the specific technical solutions adopted by the present invention are as follows:

[0010] A hierarchical wireless sensor network communication system based on an asymmetric key pool, in which the nodes in the system are divided into multiple levels according to their permissions. The communication base station is the highest level, the next level is the cluster head node, and the next lower level is the sensing node; each node has an identity information, and each identity information contains the layer number to which the identity information belongs; both the communication base station and the cluster head node have a security chip and a key pool. The key pool of the communication base station is a private key pool composed of true random numbers and its corresponding public key pool set. The key pool of the cluster head node includes its own unique public key pool. The public key pool set of the communication base station is the public key pool set of the cluster head node; the security chip has an anti-disassembly function and the internal information cannot be obtained. The security chip stores the corresponding chip key, key pointer function and key coefficient function. The chip key of the communication base station can be calculated from the chip key of the cluster head node through the elliptic curve algorithm; each layer of the key pool is evenly divided into multiple sub-key pools, and the sub-key pool contains a sub-public key and a sub-private key; the sub-public key can be calculated from the sub-private key, and the sub-private key can be obtained based on the layer identity information through the elliptic curve algorithm; the cluster head node includes a key management server, and the key management server builds a key issuance service based on ID cryptography. The key management server stores different private keys corresponding to different sensing nodes, and the sensing node stores the public key of the key management server and its own private key.

[0011] A hierarchical wireless sensor network communication method based on an asymmetric key pool, implemented in the above system, includes the following steps: The sender sends a first message and generates verification information, encrypts the second message containing the first message with a session key to obtain a first ciphertext, and sends the first ciphertext and the verification message to the receiver together; the receiver receives the first ciphertext and the verification message, and decrypts the first ciphertext and authenticates the identity through the session key.

[0012] Wireless sensor network communication occurs between the communication base station and the cluster head node. The sender and the receiver are respectively a communication node or a cluster head node. The communication base station calculates the pointer position according to the key pointer function, extracts the sub-private key of the communication base station from the private key pool according to the pointer position, obtains the private key of the communication base station according to the key coefficient function and the sub-private key of the communication base station, uses the chip key of this layer as the public key of the lower layer, calculates the communication key through the private key of this layer and the public key of the cluster head node, and calculates the session key through the communication key;

[0013] The cluster head node calculates the pointer position according to the key pointer function, then extracts the sub-public key of the cluster head node from the public key pool according to the pointer position, calculates the public key of the communication base station based on the key coefficient function and the sub-public key of the cluster head node, uses the x coordinate on the chip key elliptic curve of this layer as the private key of this layer, calculates the communication key through the public key of the communication base station and the private key of this layer, and calculates the session key identical to that of the communication base station through the communication key.

[0014] Preferably, the verification message is the current timestamp.

[0015] It occurs when the cluster head node and the sensing node communicate in the wireless sensor network. The generation method of the session key is to obtain the corresponding first private key of the key server docking the sensing node according to the bilinear pair operation, and calculate the session key according to the first private key and the timestamp;

[0016] The verification message is the timestamp. The steps for the sender to send the first message and generate the verification information, encrypt the second message containing the first message with the session key to obtain the first ciphertext, and send the first ciphertext and the verification message to the receiver are as follows:

[0017] The sender signs the combination of the first message and the current timestamp with the first private key to obtain the first signature, encrypts the combination of the first signature and the first message with the session key to obtain the second message, and calculates the first message authentication code for the key management server identity information, sensing node identity information, timestamp and the second message with the session key. The first ciphertext also includes the key management server identity information, sensing node identity information and the first message authentication code;

[0018] The steps for the receiver to decrypt the first ciphertext and perform identity authentication through the session key after receiving the first ciphertext and the verification message are as follows:

[0019] After receiving the first ciphertext, the receiver signs the combination of the key management server identity information, sensing node identity information, the second message and the current timestamp with the session key to obtain the second message authentication code, compares the second message authentication code with the first message authentication code from the first ciphertext. After they are consistent, decrypt the second message with the session key, and verify the first signature using its own public key and the public key of the key management server. After the verification passes, it is confirmed that the message has been received.

[0020] Optionally, the verification message is the current timestamp. In the case of the failure of the cluster head node, the communication base station first finds a new cluster head node public key pool from the public key pool, calculates the private key based on ID cryptography and the system public key issued by the new cluster head node for the sensor node, calculates the second private key of the cluster head node relative to the corresponding sensor node, and uses the second private key to perform ID-cryptography-based signature on the first message, the current timestamp, and the identity information of the new cluster head node, the private key of the sensor node, and the system public key of the key management server to obtain the second signature. Encrypt the second message obtained by combining the first message and the second signature according to the above method to obtain the first ciphertext and transmit it to the new cluster head node;

[0021] After receiving the first ciphertext, the new cluster head node performs verification. After passing the verification, it obtains the first ciphertext, sends the first ciphertext to the sensor node. The sensor node calculates the session key according to the above method, decrypts the second message through the session key, and then verifies the second signature using the public key and the public key of the key management server. After passing the verification, it confirms the receipt of the first message, and completes the update of its own identity information, private key, and the public key of the key manager, and sends the replacement success message to the new cluster head node.

[0022] The step of the communication base station sending the replacement success message to the new cluster head node is the same as the method described above.

[0023] The beneficial effects of the invention are as follows:

[0024] 1. In the scenario of wireless sensor network communication, this patent ensures the security of communication even in the extreme case where the group communication nodes are cracked. For the communication between the cluster head node and the base station, since the keys of both parties are also protected by the chip key, and the chip key, key pointer function, and key coefficient function are all located in the secure chip, the enemy cannot obtain them. For the communication between the sensor node and the cluster head node, although the enemy can use a quantum computer to calculate the private key of the ID cryptography system used by the cluster head node after the sensor node is captured, the system private keys of each sensor node are different. Therefore, the security of the system and other sensor nodes will not be affected after the key is cracked. In short, the status of all members in this patent is divided by level, and the protection measures and keys at different levels are different, enabling users to implement different levels and costs of protection measures according to the importance of the nodes.

[0025] 2. In this patent, the cluster head node realizes extracting more types of key values from the key pool through the key pointer function and the key coefficient function, so that the key pool does not need to be updated, thus avoiding the problem of large transmission time and energy consumption caused by a large amount of key data when the key pool is updated; the keys of the sensing nodes generally do not need to be updated either. In the abnormal situation where the cluster head node fails, since the communication volume and calculation volume for updating the keys are small, the cost for updating is low and it is easy to implement. In short, the key management scheme in this patent is acceptable for wireless sensor networks in terms of performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0027] Figure 1 It is the system structure diagram involved in the embodiments of the present invention; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To further illustrate the embodiments, the present invention provides drawings. These drawings are part of the disclosure of the present invention. They are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operation principle of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention. The components in the drawings are not drawn to scale, and similar component symbols are usually used to represent similar components.

[0029] It should be understood that, when technically feasible, the technical features listed for different embodiments above can be combined with each other to form other embodiments within the scope of the present invention. In addition, the specific examples and embodiments described in the present invention are non-limiting, and corresponding modifications can be made to the structures, steps, and sequences described above without departing from the protection scope of the present invention.

[0030] As Figure 1 shown, the wireless sensor network communication system based on a hierarchical structure asymmetric key pool according to the present invention includes a total of three layers of nodes: layer 0 nodes, layer 1 nodes, and layer 2 nodes. Among them, the layer 0 nodes are communication base stations, the layer 1 nodes are cluster head nodes, and the layer 2 nodes are sensing nodes. All member nodes have IDs, and the layer number of the ID is included in the ID. The smaller the layer number, the better the security protection measures and the smaller the possibility of being captured by the enemy. Let the i-th node in layer 1 be ID i , and let the leaf node under ID i , that is, the j-th node in layer 2, be IDij , and the IDs of other nodes are similar.

[0031] In the present invention, both the 0th and 1st layers have key pools. The 0th layer key pool is a private key pool composed of true random numbers and its corresponding public key pool set. The 1st layer key pool is a unique public key pool for each layer, where the 0th layer public key pool set is the set of public key pools of all 1st layer members. Both the 0th and 1st layers store security chips such as TPM / TCM, which have anti-disassembly functions and internal information cannot be obtained. The corresponding chip keys are KR stored in the security chip, namely KR0 of the 0th layer and KR1 of the 1st layer, and there is a formula KR0=KR 1x *P, where parameter KR 1x represents the x-coordinate of the elliptic curve point KR1, and P is the elliptic curve algorithm parameter.

[0032] Divide the key pools of each layer into multiple key segments evenly. Let the public key of the 0th layer public key pool at position Pos be K0, and its corresponding private key be SK0, and K0 = SK0*P. i The key corresponding to the key pool is K i and SK i , among which SK i =SK0+MAC(ID i ||Pos,KR 0x ) and K i =SK i *P. Since the enemy cannot obtain the chip keys of each layer, there are: Even if the enemy obtains SK i SK0 cannot be derived either.

[0033] The implementation principle of the present invention is described in detail below through specific implementation methods.

[0034] Example 1: Upper layer group communication

[0035] Case 1.1: Layer 0 A communicates with Layer 1 B.

[0036] Assume that the message to be sent by communication base station A is NTF, and a timestamp TNTF is generated for the message. A calculates pointer RK = H (TNTF), and according to KN key pointer functions {FP i , i∈[1,KN]} calculates the pointer position {P i =FP i (RK), i∈[1, KN]}, and then take out KN keys {SK 0i , i∈[1,KN]}, according to SK 0i Calculate SK Ai , the key coefficient {μ i =FUi (RK), where i ∈ [1, KN]}, the private key is calculated The key pointer function and the key coefficient function are both located inside the secure chip, so the enemy cannot obtain them. By means of the key pointer function and the key coefficient function, more kinds of key values are retrieved from the key pool, so it is more difficult for the enemy to crack this system. Let SK A be the private key of A, and let KR0 be the public key of B. According to KTG = SK A * KR0, the communication key KTG is calculated. Then, according to KSG = MAC(TNTF, KTG), the session key KSG is calculated. The message NTF is encrypted with KSG to obtain {NTF}KSG, and the ciphertext {NTF}KSG and the timestamp TNTF are sent to B together. MAC is the session key generation function, such as the message authentication code function.

[0037] The cluster head node B receives the ciphertext {NTF}KSG and the timestamp TNTF. Calculate the pointer RK = H(TNTF). According to the KN key pointer functions FP i calculate the pointer position P i , and then according to the pointer position, KN keys {K Ai , where i ∈ [1, KN]} are retrieved from the public key pool. According to the key coefficient function, the key coefficients {μ i = FU i (RK), where i ∈ [1, KN]}, the public key is calculated The key pointer function and the key coefficient function are both located inside the secure chip, so the enemy cannot obtain them. Let K A be the public key of A, and let KR 1x be the private key of B. According to KTGB = KR 1小 * K A calculate the communication key KTGB. Also, so KTGB = KTG can be obtained. According to the formula KSG = MAC(TNTF, KTG) = MAC(TNTF, KTGB), KSG can be calculated. Decrypting {NTF}KSG with KSG can obtain the message NTF.

[0038] Case 1.2: Layer 1 B communicates with Layer 0 A.

[0039] Suppose the message to be sent by group member B is NTF, and a timestamp TNTF is generated for this message. B calculates the session key KSG according to the method in Case 1.1 and encrypts NTF with KSG to obtain {NTF}KSG. The ciphertext {NTF}KSG and TNTF are sent to A together.

[0040] After A receives {NTF}KSG and TNTF, it calculates the key KSG according to the method in situation 1.1 and uses KSG to decrypt {NTF}KSG to obtain the message NTF.

[0041] Example 2: Lower layer group communication under normal circumstances

[0042] The first layer of cluster head nodes includes the key management server KMS, which has an ID cryptographic key issuance service. The second layer of sensor nodes are A, B, C, etc.

[0043] Taking sensor node A as an example, KMS uses the method in 1.1 to A Replace TNTF and take out the public key PKMS from the key pool. The system private key of KMS to A is SKMS A =(PKMS x *KR1) x , KMS to A's system public key is PKMS A =SKMS A *P, where PKMS x Indicates the x-coordinate of the elliptic curve point PKMS. A's ID / public key / private key are ID A / PK A =H1(ID A ) / SK A =SKMS A *PK A , S.K. A and PKMS A Stored in A. If node A is captured, the enemy can use the quantum computer to calculate the A or PKMS A Calculate SKMS A However, because the system private key of each sensor node is different, the security of the system and other sensor nodes will not be affected after the system private key of a node is cracked; and because SKMS A It is the value calculated based on the key pool and chip key, not the original key value in the key pool, so the enemy cannot use SKMS A Get the original key value in the key pool. KMS is used to connect to A's ID / public key / private key. S / PK S =H1(ID S ) / SK S_A =SKMS A *PK S , ID S / PK S / SK S_A Stored in the KMS memory and lost if power is off.

[0044] Scenario 2.1: A cluster head node in the first layer communicates privately with A in the second layer.

[0045] In this scenario, A is a leaf node of the cluster head node. Assume the wireless sensor network service information to be sent by the cluster head node is INFO. The cluster head node calculates K according to the bilinear pair S-A = e(SK S_A , PK A ) to obtain K S-A . Take the timestamp T1. According to K1 = MAC(T1, K S-A ), obtain the key K1. Use SK S_A to sign T1||INFO using ID-based cryptography to obtain SIG S , that is, SIG S = SIGN(T1||INFO, SK S_A ). Then encrypt INFO||SIG S using K1 to obtain {INFO||SIG S}K1, and use K1 to perform a MAC calculation on the combined ID S ||ID A ||T1||{INFO||SIG S}K1 to obtain MAC(ID S ||ID A ||T1||{INFO||SIG S}K1, K1). Send the combined ID S ||ID A ||T1||{INFO||SIG S}K1||MAC(ID S ||ID A ||T1||{INFO||SIG S}K1, K1) to A.

[0046] After A receives the message ID S ||ID A ||T1||{INFO||SIG S}K1||MAC(ID S ||ID A ||T1||{INFO||SIG S}K1, K1), it obtains each part. A calculates K A-S = e(SK A , PK S ) to obtain K A-S . According to the principle of the bilinear pair, e(SK A , PK S ) = e(SKMS A *PKA , PK S ) = e(SKMS A * PK S , PK A ) = e(SK S_A , PK A ), that is, K A-S = K S-A . So, according to K1 = MAC(T1, K S-A ) = MAC(T1, K A-S ), K1 can be obtained, and then K1 is used to perform MAC calculation on the obtained ID S || ID A || T1 || {INFO || SIG S}K1, and the obtained result is compared with MAC(ID S || ID A || T1 || {INFO || SIG S}K1, K1). If they are equal, it means that the received message is complete and unchanged. Then, {INFO || SIG S}K1 is decrypted with K1 to obtain INFO || SIG S , and the signature SIG S is verified with PK A and PKMS S . If it is correct, it means that the identity of the message sender can be trusted, and the received INFO is valid.

[0047] Case 2.2: The second-layer A communicates privately with a certain cluster head node in the first layer.

[0048] In this case, A is a leaf node of the cluster head node. Assume that the wireless sensor network service information to be sent by A is INFO. A calculates the key K2 according to the method in 2.1, uses the private key SK A to perform ID-based cryptography signature on T2 || INFO to obtain SIG A , uses K2 to encrypt INFO || SIG A to obtain {INFO || SIG A}K2, and uses K2 to perform MAC calculation on the combined ID A || ID S || T2 || {INFO || SIG A}K2 to obtain MAC(ID A || ID S || T2 || {INFO || SIG A}K2, K2), and combines the ID A || ID S || T2 || {INFO || SIGA}K2||MAC(ID A ||ID S ||T2||{INFO||SIG A}K2, K2) is sent to the corresponding cluster head node.

[0049] The cluster head node receives the message

[0050] ID A ||ID S ||T2||{INFO||SIG A}K2||MAC(ID A ||ID S ||T2||{INFO||SIG A}K2, K2) and obtains each part of it. Calculate the key K2 according to the method in 2.1, verify the MAC and then decrypt to obtain INFO||SIG A , verify the signature SIG A After success, valid INFO can be obtained.

[0051] Embodiment 3: Lower-layer group communication in the case of cluster head node failure

[0052] The reasons for the failure of the cluster head node may be being destroyed, stolen, powered off, etc. After failure, the cluster head node is no longer trustworthy or unusable. Therefore, the communication base station sends a new cluster head node ID I to replace the original cluster head node ID i , so that the sensor nodes originally managed by the latter can continue to communicate.

[0053] The communication base station announces that the parent node of the sensor node ID ij is changed to ID I , and the message of changing ID ij to ID IJ is used as NTF, and the time is TNTF. The communication base station first finds the public key pool of the new cluster head node ID I from the public key pool set, and then calculates SK IJ and PKMS IJ according to the method described above, that is, the ID cryptographic private key and system public key issued by the new cluster head node for the sensor node, and combines TNTF||NTF||ID IJ ||SK IJ ||PKMS IJ and calls it NTF IJ . Also, the communication base station calculates the private key SK i of ID ij relative to ID i_ij , and uses SK i_ij to encrypt NTFIJ Perform a signature based on ID cryptography to obtain SIG IJ , and then combine NTF IJ ||SIG IJ as the message NTF sensor , with the timestamp being TNTF sensor . According to the method in 2.1, calculate the key K3, encrypt NTF sensor and then form the message NTF ij . Take NTF ij as the message NTF head , take the timestamp TNTF head , and the base station generates the message NTF I and sends it to ID I .

[0054] ID I After receiving the message NTF I and successfully verifying it according to the method in 1.1, obtain the message NTF head which is NTF ij . Send NTF ij to ID ij . ID ij After receiving the message NTF ij , calculate the key K3 according to the method in 2.1, decrypt it to obtain NTF sensor . Then calculate the ID cryptography public key PK i of ID i , and use PK i and PKMS ij to verify the signature SIG IJ . After successful verification, confirm the validity of NTF IJ which is TNTF||NTF||ID IJ ||SK IJ ||PKMS IJ . ID ij Replaces its own ID with ID IJ , replaces SK ij with SK IJ , replaces PKMS ij with PKMS IJ , and takes ID I as its new superior node. After successful replacement, send the message of successful replacement to ID I according to the method in 2.2. ID I After receiving the message, confirm that ID IJ is its new subordinate node.

[0055] In summary, by means of the above technical solutions of the present invention, the present invention realizes a hierarchical wireless sensor network communication method and system based on an asymmetric key pool. In the scenario of wireless sensor network communication, the security of communication can still be guaranteed even in the extreme case where group communication nodes are cracked. For the communication between the cluster head node and the base station, since the keys of both parties are also protected by the chip key, and the chip key, key pointer function, and key coefficient function are all located in the secure chip, the enemy cannot obtain them. For the communication between the sensing node and the cluster head node, although the enemy can use a quantum computer to calculate the private key of the ID cryptosystem used by the cluster head node after the sensing node is captured, the system private keys of each sensing node are different. Therefore, the security of the system and other sensing nodes will not be affected after the key is cracked.

[0056] In addition, the cluster head node realizes obtaining more types of key values from the key pool through the key pointer function and the key coefficient function, so that the key pool does not need to be updated. Therefore, the problem of time-consuming and energy-consuming transmission caused by a large amount of key data during the update of the key pool is avoided; the keys of the sensing nodes generally do not need to be updated either. In the abnormal situation where the cluster head node fails, since the communication volume and calculation volume for updating the keys are small, the cost for updating is low and it is easy to implement. In short, the key management scheme in this patent is acceptable for the wireless sensor network in terms of performance.

[0057] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0058] The above-described embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent should be subject to the appended claims.

Claims

1. A hierarchical wireless sensor network communication system based on an asymmetric key pool, characterized in that The nodes within the system are divided into multiple levels according to their permissions. The communication base station is at the highest level, the next level is the cluster head node, and the level below that is the sensor node; each node has an identity information, and each identity information contains the layer number to which the identity information belongs; both the communication base station and the cluster head node have security chips and key pools. The key pool of the communication base station is a set of private key pools composed of true random numbers and their corresponding public key pools. The key pool of the cluster head node includes its own unique public key pool. The public key pool set of the communication base station is the public key pool set of the cluster head node; the security chip has an anti-disassembly function and stores the corresponding chip key, key pointer function, and key coefficient function internally; the chip key of the communication base station is calculated from the chip key of the cluster head node through the elliptic curve algorithm; the key pools of each layer are evenly divided into multiple sub-key pools. The sub-key pool contains a sub-public key and a sub-private key. The sub-public key is calculated from the sub-private key, and the sub-private key is obtained based on the layer identity information through the elliptic curve algorithm; the cluster head node includes a key management server. The key management server builds a key issuance service based on ID cryptography and stores different private keys corresponding to different sensor nodes. The sensor node stores the public key of the key management server and its own private key; The system includes: a total of 3 layers of nodes, namely layer 0 nodes, layer 1 nodes, and layer 2 nodes; among them, the layer 0 nodes are communication base stations, the layer 1 nodes are cluster head nodes, and the layer 2 nodes are sensor nodes; all member nodes have IDs, and the layer number of the ID is included in the ID; Layers 0 and 1 contain key pools. The key pool of layer 0 is a private key pool composed of true random numbers and its corresponding public key pool set. The key pool of layer 1 is a unique public key pool for each. The public key pool set of layer 0 is the set of public key pools of all members of layer 1. Both layer 0 and layer 1 store security chips such as TPM / TCM; the corresponding chip keys are KR stored in the security chips, namely KR0 of layer 0 and KR1 of layer 1, and KR0 = KR 1x *P, where KR 1x represents the x coordinate of the elliptic curve point KR1, and P is the elliptic curve algorithm parameter; Divide each layer of key pool into multiple segments of keys. Suppose a segment of public key K0 at position Pos in the public key pool of layer 0, its corresponding private key is SK0, and there is K0 = SK0 * P; the key corresponding to the key pool at the same position of ID i is K i and SK i , where there is SK i = SK0 + MAC(ID i ||Pos, KR 0x ) and K i = SK i * P; Since the enemy cannot obtain the chip keys of each layer, that is: even if the enemy obtains SK i it is impossible to deduce SK0; among them, the i-th node in the first layer is ID i , and suppose the leaf node under ID i , that is, the j-th node in the second layer is ID ij .

2. A hierarchical wireless sensor network communication method based on an asymmetric key pool, characterized in that, Implementing in the system described in claim 1 includes the following steps. The sender sends a first message and generates a verification message, encrypts the second message containing the first message with the session key to obtain a first ciphertext, and sends the first ciphertext and the verification message to the receiver together; the receiver receives the first ciphertext and the verification message, decrypts the first ciphertext and performs identity authentication through the session key.

3. The hierarchical wireless sensor network communication method based on an asymmetric key pool according to claim 2, characterized in that When wireless sensor network communication occurs between the communication base station and the cluster head node, the sender and the receiver are respectively the communication node or the cluster head node. The communication base station calculates the pointer position according to the key pointer function, retrieves the sub-private key of the communication base station from the private key pool according to the pointer position, obtains the private key of the communication base station according to the key coefficient function and the sub-private key of the communication base station, uses the chip key of this layer as the public key of the lower layer, calculates the communication key through the private key of this layer and the public key of the cluster head node, and calculates the session key through the communication key; The cluster head node calculates the pointer position according to the key pointer function, then retrieves the sub-public key of the cluster head node from the public key pool according to the pointer position, calculates the public key of the communication base station according to the key coefficient function and the sub-public key of the cluster head node, uses the x coordinate on the elliptic curve of the chip key of this layer as the private key of this layer, calculates the communication key through the public key of the communication base station and the private key of this layer, and calculates the same session key as the communication base station through the communication key.

4. The hierarchical wireless sensor network communication method based on an asymmetric key pool according to claim 3, wherein, The verification message is the current timestamp.

5. The hierarchical wireless sensor network communication method based on an asymmetric key pool according to claim 4, characterized in that, In the case of the failure of the cluster head node, the communication base station first finds a new cluster head node public key pool from the public key pool, calculates the new cluster head node, and uses it as the private key based on ID cryptography and the system public key issued to the sensing node. Calculate the second private key of the cluster head node relative to the corresponding sensing node, and use the second private key to perform ID-cryptography signature on the first message, the current timestamp, and the identity information of the new cluster head node, the private key of the sensing node, and the public key of the key management server system to obtain the second signature; Generate a session key, encrypt the second message obtained by combining the first message and the second signature to obtain the first ciphertext and transmit it to the new cluster head node; After receiving the first ciphertext, the new cluster head node verifies it. After passing the verification, it obtains the first ciphertext, sends the first ciphertext to the sensing node. The sensing node calculates the session key, decrypts the second message through the session key, and then uses the public key and the public key of the key management server to verify the second signature. After passing the verification, it confirms the receipt of the first message, and completes the update of its own identity information, private key, and the public key of the key manager, and sends a message indicating successful replacement to the new cluster head node.

6. The hierarchical wireless sensor network communication method based on an asymmetric key pool according to claim 2, wherein When wireless sensor network communication is carried out between the cluster head node and the sensing node, the session key is generated by obtaining the corresponding first private key of the key server docking the sensing node according to the bilinear pairing operation, and calculating the session key according to the first private key and the timestamp.

7. A hierarchical wireless sensor network communication method based on an asymmetric key pool according to claim 6, characterized in that The verification message is a timestamp. The steps for the sender to send the first message, generate the verification message, encrypt the second message containing the first message with the session key to obtain the first ciphertext, and send the first ciphertext and the verification message to the receiver are as follows: The sender signs the combination of the first message and the current timestamp with the first private key to obtain the first signature, encrypts the combination of the first signature and the first message with the session key to obtain the second message, and calculates the first message authentication code for the identity information of the key management server, the identity information of the sensing node, the timestamp, and the second message with the session key. The first ciphertext also includes the identity information of the key management server, the identity information of the sensing node, and the first message authentication code.

8. A hierarchical wireless sensor network communication method based on an asymmetric key pool according to claim 7, characterized in that, The steps for the receiver to receive the first ciphertext and the verification message, and decrypt and authenticate the first ciphertext through the session key are as follows: After receiving the first ciphertext, the receiver signs the combination of the identity information of the key management server, the identity information of the sensing node, the second message, and the current timestamp with the session key to obtain the second message authentication code, compares the second message authentication code with the first message authentication code from the first ciphertext, and after confirming that the two are consistent, decrypts the second message with the session key, and uses its own public key and the public key of the key management server to verify the first signature. After passing the verification, it confirms the receipt of the message.

Citation Information

Patent Citations

  • Secret key supplementary method, secret key supplementary device and secret key supplementary system based on symmetric secret key pool

    CN107959569A

  • Grouping cluster and master key based key management method

    CN103813320A

  • Dynamic clustering wireless sensor network cipher key management method

    CN108880814A