A continuous identity authentication method for numerical control systems under zero trust architecture
By using blockchain and the National Secret SM9 protocol in the CNC system, the generation of public parameters and keys, and combining XOR operation or lightweight hash functions, the continuous identity authentication of the device is achieved, solving the shortcomings of the existing solutions under the zero-trust architecture and improving security and efficiency.
Patent Information
- Application Number
- CN202210635588.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-06-06
AI Technical Summary
The existing continuous authentication scheme cannot effectively handle the identity authentication of the device in the CNC system, and it depends on a trusted authoritative organization or an absolutely secure channel, making it difficult to implement under a zero-trust architecture.
Using blockchain technology, nodes are selected through practical Byzantine fault-tolerant consensus algorithms, common parameters and keys are generated for devices in the CNC system, and initial authentication is used to use the authentication protocol based on the National Secretariat SM9, and continuous authentication is achieved in combination with XOR operation or lightweight hash functions.
Continuous identity authentication of CNC system devices is realized under the zero-trust architecture, improving security and efficiency, and able to resist man-in-the-middle attacks, simulated attacks, replay attacks and forward security threats.
Smart Images

Figure CN115189880B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication of numerical control systems, and in particular to a continuous identity authentication method applied to numerical control systems under a zero-trust architecture. Background Art
[0002] With the in-depth development of the integration of industrialization and information technology, the networking of CNC systems has become imperative, and the original closed production environment has gradually shifted to an open environment. If the security issues faced by CNC networks are not resolved, the development of the CNC industry will be seriously restricted.
[0003] Compared with traditional information systems, CNC systems and their networks have the characteristics of high reliability, high time sensitivity, high precision, and high risk prevention. In addition, the application scenarios of CNC technology vary greatly, which makes the security of CNC systems face many new challenges. Traditional identity authentication schemes only authenticate users / devices at the security boundary of the system. Once the authentication is successful, resources can be accessed at will, which will cause one of the devices to be damaged and the entire defense system may be paralyzed.
[0004] In order to deal with the above problems, Zero-trust Architecture (ZTA) was proposed. In ZTA, the default network is insecure, and trust relies on the results of evaluation and authentication, rather than any person, device, or location. According to a report released by the National Institute of Standards and Technology, authentication is one of the most important roles in ZTA implementation. Continuous authentication means that it continuously authenticates entities throughout the process, rather than authenticating all entities at once. It complies with the principles of ZTA. Therefore, continuous authentication has become one of the most popular branches in the field of ZTA.
[0005] Most of the existing continuous authentication protocols focus on human authentication. Continuous authentication based on biometric information or posture is suitable for human authentication. In addition to people, CNC systems also involve device authentication, so these existing continuous identity authentications are not competent. In order to overcome this bottleneck, it is necessary to study continuous authentication solutions for devices. Summary of the invention
[0006] In view of the problem that the existing continuous authentication schemes of CNC systems all rely on a trusted authority or node to generate keys or secret values for devices, or rely on an absolutely secure channel to transmit initial information, the present invention provides a continuous identity authentication method for CNC systems under a zero-trust architecture, which uses blockchain to select a node, generates public parameters and keys for two entities participating in the identity authentication, adopts security parameters and time intervals of different lengths according to the trust levels of different entities, and divides the system's time period into three time periods instead of two time periods, thereby achieving a better trade-off between security and efficiency.
[0007] To solve the above technical problems, the embodiments of the present invention provide the following solutions:
[0008] On the one hand, a continuous identity authentication method for a numerical control system under a zero-trust architecture is provided, comprising the following steps:
[0009] Initialize the CNC system, use blockchain to select a node through the practical Byzantine fault-tolerant consensus algorithm, and generate public parameters and keys for the two entities involved in identity authentication in the CNC system;
[0010] The initial authentication of the two entities is achieved using the national secret SM9-based authentication protocol;
[0011] Use XOR operations or lightweight hash functions to achieve continuous authentication between two entities;
[0012] Analyze and verify the security of the continuous certification stage.
[0013] Preferably, during the process of initializing the numerical control system, security parameters and time intervals of different lengths are used according to the trust levels of different entities.
[0014] Preferably, the initializing the numerical control system includes:
[0015] The Trust Assessment Center TAC initializes the CNC system, assuming that D A and D G Represents the IoT devices and gateways participating in the authentication; if one of them is an untrusted device, it is terminated; otherwise, the generated public parameters and keys are as follows:
[0016] Step A1: TAC initializes the blockchain and generates source modules; defines TAC as the master node of the blockchain because it does not participate in the device authentication; TAC selects two security parameters and five time intervals: k1, k2, and t c , where k1<k2, If both entities are trusted devices, then k<k1, Otherwise, k<k2,
[0017] Step A2: D A The intent is broadcast to all devices in the same CNC system; after receiving it, TAC will randomly select a trusted device D other than the two p , generate public parameters for it;
[0018] Step A3: D p Select k based on the trust level of the two devices, and then generate a k-bit prime number q; D p In E / F P Generate a q-order cyclic group on One of its producers is G;
[0019] Step A4: Select N-order additive cyclic groups G1 and G2, and multiplicative cyclic group G respectively. T , P1 and P2 are the generators of additive cyclic groups G1 and G2 respectively; TAC selects the bilinear pairing e: G1×G2→G T ; In addition, four hash functions are defined H3: {0, 1} * →{0, 1} * and H4: {0, 1} * →{0, 1}*; randomly select s∈[1, N-1] as the system parameter master key, calculate P pub =sP2 as the master key;
[0020] Step A5: D p Forming public parameters: As a new transaction, it is broadcast to all devices with the same domain; all devices have voting rights, except untrusted devices; if the result of the PBFT consensus algorithm is positive, TAC writes a new block to the blockchain; otherwise, TAC records and selects another device, and then jumps to step A3.
[0021] Preferably, generating a key comprises:
[0022] Step B1: For device D A , TAC selects and publishes a private key generation function identifier hid, in the elliptic curve finite field F N Calculate t1 = H1 (ID A ||hid, N)+s, if t1=0, then the master private key 0 needs to be regenerated, otherwise calculate Private Key and public key Q A =H1(ID A ||hid,N)P1+P pub ;
[0023] Step B2: For Gateway D G , TAC selects and publishes a private key generation function identifier hid, in the elliptic curve finite field F N Calculate t3 = H1 (ID G ||hid, N)+s, if t3=0, then the master private key 0 needs to be regenerated, otherwise calculate Private Key and public key Q G =H1(ID G ||hid,N)P1+P pub ;
[0024] At this point, both entities have their own keys and will authenticate each other.
[0025] Preferably, the initial authentication includes:
[0026] Step C1: For the message M to be signed, device A performs the following steps to sign:
[0027] C101: Calculating g A =e(P1,P pub );
[0028] C102: Let r A ∈[1, N-1], calculate ω A =h′ A ,h A =H2(M||ω A , N);
[0029] C103: Calculation of L A =(r A -h A )mod N, if L A =0, then return to C102;
[0030] C104: Calculate S A =L A d A , then the signature of message M is (h A , S A );
[0031] Device A will M, (h A , S A ) is sent to gateway G;
[0032] Step C2: The gateway receives the message M′ and (h′ A , S′ A );
[0033] C201: Test h′ A∈[1, N-1], and S′ A ∈G1 is true, if true, the verification fails;
[0034] C202: Let g′ A =e(P1,P pub ),calculate h1=H1(ID A ||hid,N),P A =h1P2+P pub ;
[0035] C203: Calculate μ = e(S′ A , P A ), ω′ A =μ·t, h2=H2(M′||ω′ A , N), check h2 = h′ A Is it true? If so, the verification is successful. Otherwise, the verification fails.
[0036] C204: Calculation of g G =e(P1,P pub );
[0037] C205: Let r G ∈[1, N-1], calculate ω G =g′ G ,h G =H2(M||ω G , N);
[0038] C206: Calculation of L G =(r G -h G )mod N, if L G =0, then return to C205;
[0039] C207: Calculate S G =L G d G , then the signature of message M is (h G , S G );
[0040] Gateway G will M, (h G , S G ) is sent to device A;
[0041] Step C3: Device A receives M′, (h′ G , S′ G );
[0042] C301: Test h′ G ∈[1, N-1], and S′ G∈G1 is true, if true, the verification fails;
[0043] C302: Let g′ G =e(P1,P pub ),calculate h3=H1(ID G ||hid,N),P G =h3P2+P pub ;
[0044] C303: Calculate μ2 = e(S′ G , P G ), ω′ G =μ2·t2, h2=H2(M′||ω′ A , N), check h4 = h′ G Is it true? If so, the verification is successful. Otherwise, the verification fails.
[0045] C304: Select
[0046] C305: Computation
[0047] Device A will C A Send to gateway G;
[0048] Step C4: Gateway G receives C′ A ;
[0049] C401: Select
[0050] C402: Calculation C403: Inspection C A =C G Is it true? If true, calculate Generate Token
[0051] C404: Calculation And send it to device A;
[0052] Step C5: Device A receives
[0053] C501: Computation Generate Token
[0054] C502: Calculation verify If so, then D A and D G The authentication will be completed and have the same token.
[0055] Preferably, the continuous authentication includes:
[0056] After the initial authentication, both entities have two identical tokens and random seeds, and during the ongoing authentication phase, the two entities rely on these results to authenticate each other;
[0057] Step D1: D A Take two random numbers respectively and Then calculate and Finally, D A CM A and CA A To Gateway D G ;
[0058] Step D2: D G Produced in the same way and D G After receiving the message, calculate Then calculate If CA A ′≠CA A , then report to TAC and jump to the initial authentication stage; otherwise D G calculate Finally, put CM G and CA G Send to D A ;
[0059] Step D3: D A After receiving the message, calculate Then calculate If CA G ′≠CA G , then report to TAC and jump to initial authentication; otherwise D A Assume ACK = 1, as well as Finally, send ACK to D G ;
[0060] Step D4: If the received ACK=1, it means that the authentication has been completed. G set up as well as
[0061] Preferably, the analysis and verification of the security of the continuous authentication phase includes:
[0062] Mutual Authentication:
[0063] During the initial authentication phase, only two entities can compute the same token and random seed; therefore, both get the same CM i and CA j ; Pass the certification CA i =CA j , legal entities can authenticate each other;
[0064] Man-in-the-middle attack:
[0065] A man-in-the-middle attack is when an attacker establishes two sessions with two entities respectively, and the two entities believe that they are communicating directly, resulting in the two entities' sessions being under the attacker's control. During the continuous authentication phase, although the attacker can intercept the information of the two entities, the attacker does not know and tk i , so it is impossible to forge a legitimate CA i ,In this way, the attacker cannot control the session between the two entities,,that is, the continuous authentication phase can resist man-in-the-middle attacks;
[0066] Simulated Attack:
[0067] An impersonation attack means that an entity A can impersonate another entity B to communicate with an entity C. If the attacker wants to pass the authentication, he must forge a CA. f =CA c CA f ,The hash algorithm has anti-collision performance, and the probability of forgery by attackers is negligible, so the continuous authentication phase can resist counterfeit attacks;
[0068] Replay Attack:
[0069] A replay attack is when an attacker intercepts communication information and then sends it to the victim to deceive them. In the continuous authentication phase, after each round of authentication, the two entities will update the token and random seed because Therefore, the attacker replayed the CA r With CA v The difference indicates that the continuous authentication phase can resist replay attacks;
[0070] Forward Security:
[0071] Forward security means that the leakage of the token will only damage the security of the current authentication and will not affect the security of future authentication; if the token is leaked, the attacker can deceive the peer entity and calculate the and update the token; however, during the ongoing authentication phase, the attacker cannot update the random seed, so he cannot find the correct CA to pass the authentication and cannot deceive the entity again.
[0072] On the one hand, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to perform the continuous identity authentication method.
[0073] On the one hand, a storage medium is provided, on which instructions are stored, and when the instructions are executed by a processor, the continuous identity authentication method is executed.
[0074] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0075] In the embodiment of the present invention, a blockchain is used to replace a trusted authority, and a node is selected through a practical Byzantine fault-tolerant consensus algorithm to generate public parameters and keys for two entities in the numerical control system so as to authenticate each other. In addition, the present invention uses an authentication protocol based on the national secret SM9 to implement initial authentication, and uses lightweight operations such as XOR and hash to implement continuous authentication. At the same time, security parameters and time intervals of different lengths are used to distinguish the trust level of the entity, and the trust evaluation center performs the evaluation, achieving a better balance between security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0076] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0077] Figure 1 is a schematic diagram of a numerical control system model provided by an embodiment of the present invention;
[0078] Figure 2 This is a flowchart of a continuous identity authentication method applied to a numerical control system under a zero-trust architecture provided by an embodiment of the present invention.
[0079] As shown in the figure, in order to clearly implement the structure of the embodiment of the present invention, specific structures and devices are marked in the figure, but this is only for illustrative purposes and is not intended to limit the present invention to the specific structure, device and environment. According to specific needs, ordinary technicians in this field can adjust or modify these devices and environments, and the adjustments or modifications made are still included in the scope of protection of the present invention. DETAILED DESCRIPTION
[0080] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0081] The embodiment of the present invention provides a continuous identity authentication method applied to a numerical control system under a zero-trust architecture. Figure 1 It is a model diagram of the CNC system. Figure 2 is a flow chart of the continuous identity authentication method, the method comprising the following steps:
[0082] Initialize the CNC system, use blockchain to select a node through the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm, and generate public parameters and keys for the two entities involved in identity authentication in the CNC system;
[0083] The initial authentication of the two entities is achieved using the national secret SM9-based authentication protocol;
[0084] Use XOR operations or lightweight hash functions to achieve continuous authentication between two entities;
[0085] Analyze and verify the security of the continuous certification stage.
[0086] Among them, during the initialization of the numerical control system, security parameters and time intervals of different lengths are used according to the trust levels of different entities.
[0087] Specifically, the initializing the numerical control system includes:
[0088] The Trust Assessment Center (TAC) initializes the CNC system and generates corresponding public parameters and hash functions. A and D G Represents the IoT devices and gateways participating in the authentication; if one of them is an untrusted device, it is terminated; otherwise, the generated public parameters and keys are as follows:
[0089] Step A1: TAC initializes the blockchain and generates source modules; defines TAC as the master node of the blockchain because it does not participate in the device authentication; TAC selects two security parameters and five time intervals: k1, k2, and t c , where k1<k2, If both entities are trusted devices, then k<k1, Otherwise, k<k2,
[0090] Step A2: D A The intent is broadcast to all devices in the same CNC system; after receiving it, TAC will randomly select a trusted device D other than the two p , generate public parameters for it;
[0091] Step A3: D p Select k based on the trust level of the two devices, and then generate a k-bit prime number q; D p In E / F P Generate a q-order cyclic group on One of its producers is G;
[0092] Step A4: Select N-order additive cyclic groups G1 and G2, and multiplicative cyclic group G respectively. T , P1 and P2 are the generators of additive cyclic groups G1 and G2 respectively; TAC selects the bilinear pairing e: G1×G2→G T ; In addition, four hash functions are defined H3: {0, 1} * →{0, 1} * and H4: {0, 1} * →{0, 1} * ; Randomly select s∈[1, N-1] as the system parameter master key and calculate P pub =sP2 as the master key;
[0093] Step A5: D p Forming public parameters: As a new transaction, it is broadcast to all devices with the same domain; all devices have voting rights, except untrusted devices; if the result of the PBFT consensus algorithm is positive, TAC writes a new block to the blockchain; otherwise, TAC records and selects another device, and then jumps to step A3.
[0094] Further, generating a key includes:
[0095] Step B1: For device D A , TAC selects and publishes a private key generation function identifier hid, in the elliptic curve finite field F N Calculate t1 = H1 (ID A ||hid, N)+s, if t1=0, then the master private key 0 needs to be regenerated, otherwise calculate Private Key and public key Q A =H1(ID A ||hid,N)P1+Ppub ;
[0096] Step B2: For Gateway D G , TAC selects and publishes a private key generation function identifier hid, in the elliptic curve finite field F N Calculate t3 = H1 (ID G ||hid, N)+s, if t3=0, then the master private key 0 needs to be regenerated, otherwise calculate Private Key and public key Q G =H1(ID G ||hid,N)P1+P pub ;
[0097] At this point, both entities have their own keys and will authenticate each other.
[0098] Furthermore, the initial authentication includes:
[0099] Step C1: For the message M to be signed, device A performs the following steps to sign:
[0100] C101: Calculating g A =e(P1,P pub );
[0101] C102: Let r A ∈[1, N-1], calculate ω A =g′ A ,h A =H2(M||ω A , N);
[0102] C103: Calculation of L A =(r A -h A )mod N, if L A =0, then return to C102;
[0103] C104: Calculate S A =L A d A , then the signature of message M is (h A , S A );
[0104] Device A will M, (h A , S A ) is sent to gateway G;
[0105] Step C2: The gateway receives the message M′ and (h′ A , S′ A );
[0106] C201: Test h′ A ∈[1, N-1], and S′ A ∈G1 is true, if true, the verification fails;
[0107] C202: Let g′ A =e(P1,P pub ),calculate h1=H1(ID A ||hid,N),P A =h1P2+P pub ;
[0108] C203: Calculate μ = e(S′ A , P A ), ω′ A =μ·t, h2=H2(M′||ω′ A , N), check h2 = h′ A Is it true? If so, the verification is successful. Otherwise, the verification fails.
[0109] C204: Calculation of g G =e(P1,P pub );
[0110] C205: Let r G ∈[1, N-1], calculate ω G =g′ G ,h G =H2(M||ω G , N);
[0111] C206: Calculation of L G =(r G -h G )mod N, if L G =0, then return to C205;
[0112] C207: Calculate S G =L G d G , then the signature of message M is (h G , S G );
[0113] Gateway G will M, (h G , S G ) is sent to device A;
[0114] Step C3: Device A receives M′, (h′ G , S′ G );
[0115] C301: Test h′ G∈[1, N-1], and S′ G ∈G1 is true, if true, the verification fails;
[0116] C302: Let g′ G =e(P1,P pub ),calculate h3=H1(ID G ||hid,N),P G =h3P2+P pub ;
[0117] C303: Calculate μ2 = e(S′ G , P G ), ω′ G =μ2·t2, h2=H2(M′||ω′ A , N), check h4 = h′ G Is it true? If so, the verification is successful. Otherwise, the verification fails.
[0118] C304: Select
[0119] C305: Computation
[0120] Device A will C A Send to gateway G;
[0121] Step C4: Gateway G receives C′ A ;
[0122] C401: Select
[0123] C402: Calculation C403: Inspection C A =C G Is it true? If true, calculate Generate Token
[0124] C404: Calculation And send it to device A;
[0125] Step C5: Device A receives
[0126] C501: Computation Generate Token
[0127] C502: Calculation verify If so, then D A and DG The authentication will be completed and have the same token.
[0128] Furthermore, the continuous authentication includes:
[0129] After the initial authentication, both entities have two identical tokens and random seeds, and during the ongoing authentication phase, the two entities rely on these results to authenticate each other;
[0130] Step D1: D A Take two random numbers respectively and Then calculate and Finally, D A CM A and CA A To Gateway D G ;
[0131] Step D2: D G Produced in the same way and D G After receiving the message, calculate Then calculate If CA A ′≠CA A , then report to TAC and jump to the initial authentication stage; otherwise D G calculate Finally, put CM G and CA G Send to D A ;
[0132] Step D3: D A After receiving the message, calculate Then calculate If CA G ′≠CA G , then report to TAC and jump to initial authentication; otherwise D A Assume ACK = 1, as well as Finally, send ACK to D G ;
[0133] Step D4: If the received ACK=1, it means that the authentication has been completed. G set up as well as
[0134] Next, the security of the continuous identity authentication method applied to the CNC system under the zero-trust architecture proposed in the present invention will be analyzed and verified, including mutual authentication, man-in-the-middle attacks, simulation attacks, replay attacks and forward security.
[0135] (1) Mutual Authentication:
[0136] During the initial authentication phase, only two entities can compute the same token and random seed. Therefore, both entities get the same CM i and CA j ; Pass the certification CA i =CA j , legitimate entities can authenticate each other.
[0137] (2) Man-in-the-middle attack:
[0138] A man-in-the-middle attack is when an attacker establishes two sessions with two entities, and the two entities believe that they are communicating directly, resulting in the two entities' sessions being under the attacker's control. During the continuous authentication phase, although the attacker can intercept the information of the two entities, the attacker does not know and tk i , so it is impossible to forge a legitimate CA i ,In this way, the attacker cannot control the session between the two entities, that is, the continuous authentication phase can resist man-in-the-middle attacks.
[0139] (3) Simulated attack:
[0140] An impersonation attack means that an entity A can pretend to be another entity B and communicate with an entity C, but entity C is unaware of this. If the attacker wants to pass the authentication, he must forge a CA. f =CA c CA f ,The hash algorithm has good anti-collision performance, and the probability of forgery by an attacker is negligible, so the continuous authentication phase can resist counterfeit attacks.
[0141] (4) Replay attack:
[0142] A replay attack is when an attacker intercepts communication information and then sends it to the victim to deceive them. In the continuous authentication phase, after each round of authentication, the two entities will update the token and random seed because Therefore, the attacker replayed the CA r With CA v The difference indicates that the continuous authentication phase can resist replay attacks.
[0143] (5) Forward security:
[0144] Forward security means that the leakage of the token will only damage the security of the current authentication and will not affect the security of future authentication. If the token is leaked, the attacker can deceive the peer entity and calculate the and update the token; however, during the ongoing authentication phase, the attacker cannot update the random seed, so he cannot find the correct CA to pass the authentication and cannot deceive the entity again.
[0145] The continuous identity authentication method applied to the numerical control system under the zero-trust architecture provided by the present invention uses blockchain to replace the trusted authorization agency, selects a node through the practical Byzantine fault-tolerant consensus algorithm, and generates public parameters and keys for two entities in the numerical control system to authenticate each other. In addition, the present invention uses the authentication protocol based on the national secret SM9 to implement initial authentication, and uses lightweight operations such as XOR and hash to implement continuous authentication. At the same time, security parameters and time intervals of different lengths are used to distinguish the trust level of the entity, and the trust evaluation center performs the evaluation, achieving a better balance between security and efficiency.
[0146] Correspondingly, an embodiment of the present invention also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to execute the continuous identity authentication method.
[0147] An embodiment of the present invention further provides a storage medium, on which instructions are stored, and when the instructions are executed by a processor, the continuous identity authentication method is executed.
[0148] It should be noted that the references to "one embodiment", "embodiment", "exemplary embodiment", "some embodiments" and the like in the specification indicate that the embodiments described may include specific features, structures or characteristics, but not every embodiment may include the specific features, structures or characteristics. In addition, when a specific feature, structure or characteristic is described in conjunction with an embodiment, it should be within the knowledge of a person skilled in the art to implement such feature, structure or characteristic in conjunction with other embodiments (whether or not explicitly described).
[0149] In general, a term can be understood, at least in part, from its use in context. For example, depending, at least in part, on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in the singular sense, or can be used to describe a combination of features, structures, or characteristics in the plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey an exclusive set of factors, but can instead, depending, at least in part, on the context, allow for the presence of other factors that are not necessarily explicitly described.
[0150] As used herein, the term "nominal / nominal" refers to an expected or target value for a characteristic or parameter of a component or process operation set during the design phase of a production or manufacturing process, as well as a range of values above and / or below the expected value. The range of values may be due to slight variations in the manufacturing process or tolerances. As used herein, the term "approximately" indicates a value of a given quantity that may vary based on a particular technology node associated with the subject semiconductor device. Based on a particular technology node, the term "approximately" may indicate a value of a given quantity that varies, for example, within 5%-15% of the value (e.g., ±5%, ±10%, or ±15% of the value).
[0151] It will be understood that the meaning of “on,” “over,” and “above” in this disclosure should be interpreted in the broadest manner, so that “on” means not only “directly on” something, but also includes the meaning of being “on” something with intervening features or layers therebetween, and “on” or “over” means not only “on” or “above” something, but also includes the meaning of being “on” or “above” something with no intervening features or layers therebetween.
[0152] Additionally, spatially relative terms such as "under," "beneath," "lower," "above," "upper," and the like may be used herein for descriptive convenience to describe the relationship of one element or feature to another element or features, as shown in the accompanying drawings. Spatially relative terms are intended to encompass different orientations of the device in use or operation in addition to the orientation depicted in the accompanying drawings. The device may be oriented in other ways, and the spatially relative descriptors used herein may be similarly interpreted accordingly.
[0153] The present invention covers any substitution, modification, equivalent method and scheme made on the essence and scope of the present invention. In order to make the public have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention, but those skilled in the art can fully understand the present invention without the description of these details. In addition, in order to avoid unnecessary confusion about the essence of the present invention, well-known methods, processes, procedures, components and circuits are not described in detail.
[0154] A person skilled in the art will appreciate that all or part of the steps in the above-mentioned embodiment method can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc.
[0155] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A continuous identity authentication method applied to a numerical control system under a zero-trust architecture, characterized in that: The following steps are involved: Initialize the CNC system, use blockchain to select a node through the practical Byzantine fault-tolerant consensus algorithm, and generate public parameters and keys for the two entities involved in identity authentication in the CNC system; The initialization of the numerical control system includes: The Trust Assessment Center TAC initializes the CNC system, assuming that D A and D G Represents the IoT devices and gateways participating in the authentication; if one of them is an untrusted device, it is terminated; otherwise, the generated public parameters and keys are as follows: Step A1: TAC initializes the blockchain; defines TAC as the master node of the blockchain because it does not participate in the device identity authentication; TAC selects two security parameters and five time intervals: k1, k2, and t c , where k1 <k2, If both entities are trusted devices, then k <k1, Otherwise, k <k2, Step A2: D A The intent is broadcast to all devices in the same CNC system; after receiving it, TAC will randomly select a trusted device D other than the two p , generate public parameters for it; Step A3: D p According to two devices D A and D G The trust level is k, and then a k-bit prime number q is generated; D p In E / F P Generate a q-order cyclic group on One of its generators is Gateway D G ; Step A4: Select N-order additive cyclic groups G1 and G2, and multiplicative cyclic group G respectively. T , P1 and P2 are the generators of additive cyclic groups G1 and G2 respectively; TAC selects the bilinear pairing e:G1×G2→G T ; In addition, five hash functions H0 are defined: H1: H2: H3:{0,1} * →{0,1} * and H4:{0,1} * →{0,1} * ; Randomly select s∈[1,N-1] as the system parameter master key and calculate P pub =sP2 as the master key; Step A5: D p Forming public parameters: As a new transaction, broadcast to all devices with the same domain; all devices have voting rights, except untrusted devices; if the result of the practical Byzantine fault tolerance consensus algorithm is positive, TAC writes a new block to the blockchain; otherwise, TAC records and selects another device, and then jumps to step A3; The initial authentication of the two entities is achieved using the national secret SM9-based authentication protocol; Use XOR operations or lightweight hash functions to achieve continuous authentication between two entities; Analyze and verify the security of the continuous certification stage.
2. The continuous identity authentication method applied to a numerical control system under a zero-trust architecture according to claim 1 is characterized in that: During the process of initializing the numerical control system, security parameters and time intervals of different lengths are used according to the trust levels of different entities.
3. The continuous identity authentication method applied to a numerical control system under a zero-trust architecture according to claim 1 is characterized in that: Generating a key involves: Step B1: For device D A , TAC selects and publishes a private key generation function identifier hid, in the elliptic curve finite field F N Calculate t1 = H1 (ID A ||hid,N)+s, if t1=0, then the master private key 0 needs to be regenerated, otherwise calculate Private Key and public key Q A =H1(ID A ||hid,N)P1+P pub ; Step B2: For Gateway D G , TAC selects and publishes a private key generation function identifier hid, in the elliptic curve finite field F N Calculate t3 = H1 (ID G ||hid,N)+s, if t3=0, the master private key 0 needs to be regenerated, otherwise calculate Private Key and public key Q G =H1(ID G ||hid,N)P1+P pub ; At this point, both entities have their own keys and will authenticate each other.
4. The continuous identity authentication method applied to a numerical control system under a zero-trust architecture according to claim 3 is characterized in that: The initial certification includes: Step C1: Treat the signed message M, device D A Follow the steps below to implement the signature: C101: Calculating g A =e(P1,P pub ); C102: Let r A ∈[1,N-1], calculate ω A =g′ A ,h A =H2(M||ω A , N); C103: Calculation of L A =(r A -h A )mod N, if L A =0, then return to C102; C104: Calculate S A =L A d A , then the signature of message M is (h A ,S A ); Equipment D A M, (h A ,S A ) is sent to gateway D G ; Step C2: The gateway receives the message M′ and (h′ A ,S′ A ); C201: Test h′ A ∈[1,N-1], and S′ A ∈G1 is true, if true, the verification fails; C202: Let g′ A =e(P1,P pub ),calculate h1=H1(ID A ||hid,N),P A =h1P2+P pub ; C203: Calculate μ = e(S′ A ,P A ), ω′ A =μ·t, h2=H2(M′||ω′ A ,N), check h2=h′ A Is it true? If so, the verification is successful. Otherwise, the verification fails. C204: Calculation of g G =e(P1,P pub ); C205: Let r G ∈[1,N-1], calculate ω G =g′ G ,h G =H2(M||ω G ,N); C206: Calculation of L G =(r G -h G )mod N, if L G =0, then return to C205; C207: Calculate S G =L G d G , then the signature of message M is (h G ,S G ); Gateway D G M, (h G ,S G ) is sent to device D A ; Step C3: Device D A Receive M′, (h′ G ,S′ G ); C301: Test h′ G ∈[1,N-1], and S′ G ∈G1 is true, if true, the verification fails; C302: Let g′ G =e(P1,P pub ),calculate h3=H1(ID G ||hid,N),P G =h3P2+P pub ; C303: Calculate μ2 = e(S′ G ,P G ), ω′ G =μ2·t2, h2=H2(M′||ω′ A ,N), check h4=h′ G Is it true? If so, the verification is successful. Otherwise, the verification fails. C304: Select C305: Computation Equipment D A C A Send to Gateway D G ; Step C4: Gateway D G Receive C' A ; C401: Select C402: Calculation C403: Inspection C A =C G Is it true? If true, calculate Generate Token C404: Calculation And send it to device D A ; Step C5: Device D A Received C501: Computation Generate Token C502: Calculation verify If so, then D A and D G The authentication will be completed and have the same token.
5. The continuous identity authentication method applied to a numerical control system under a zero-trust architecture according to claim 4 is characterized in that: The ongoing certification includes: After the initial authentication, both entities have two identical tokens and random seeds, and during the ongoing authentication phase, the two entities rely on these results to authenticate each other; Step D1: D A Take two random numbers respectively and Then calculate and Finally, D A CM A and CA A Send to Gateway D G ; Step D2: D G Produced in the same way and D G After receiving the message, calculate Then calculate If CA A ′≠CA A , then report to TAC and jump to the initial authentication stage; otherwise D G calculate Finally, put CM G and CA G Send to D A ; Step D3: D A After receiving the message, calculate Then calculate If CA G ′≠CA G , then report to TAC and jump to initial authentication; otherwise D A Assume ACK = 1, as well as Finally, send ACK to D G ; Step D4: If the received ACK=1, it means that the authentication has been completed. G set up as well as 6. The continuous identity authentication method applied to a numerical control system under a zero-trust architecture according to claim 5 is characterized in that: The analysis and verification of the security of the continuous authentication phase includes: Mutual Authentication: During the initial authentication phase, only two entities can compute the same token and random seed; therefore, both get the same CM i and CA j ; Pass the certification CA i =CA j , legal entities can authenticate each other; Man-in-the-middle attack: A man-in-the-middle attack is when an attacker establishes two sessions with two entities respectively, and the two entities believe that they are communicating directly, resulting in the two entities' sessions being under the attacker's control. During the continuous authentication phase, although the attacker can intercept the information of the two entities, the attacker does not know and tk i , so it is impossible to forge a legitimate CA i ,In this way, the attacker cannot control the session between the two entities,,that is, the continuous authentication phase can resist man-in-the-middle attacks; Simulated Attack: An impersonation attack means that an entity A can impersonate another entity B to communicate with an entity C. If the attacker wants to pass the authentication, he must forge a CA. f =CA c CA f ,The hash algorithm has anti-collision performance, and the probability of forgery by attackers is negligible, so the continuous authentication phase can resist counterfeit attacks; Replay Attack: A replay attack is when an attacker intercepts communication information and then sends it to the victim to deceive them. In the continuous authentication phase, after each round of authentication, the two entities will update the token and random seed because Therefore, the attacker replayed the CA r With CA v The difference indicates that the continuous authentication phase can resist replay attacks; Forward Security: Forward security means that the leakage of the token will only damage the security of the current authentication and will not affect the security of future authentication; if the token is leaked, the attacker can deceive the peer entity and calculate the and update the token; however, during the ongoing authentication phase, the attacker cannot update the random seed, so he cannot find the correct CA to pass the authentication and cannot deceive the entity again.
7. An electronic device, characterized in that: include: at least one processor; And a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to perform the continuous identity authentication method as described in any one of claims 1-6.
8. A storage medium, characterized in that: The storage medium stores instructions, and when the instructions are executed by the processor, the continuous identity authentication method according to any one of claims 1 to 6 is executed.
Citation Information
Patent Citations
Improved practical Byzantine fault tolerant system based on alliance block chain
CN110796547A