Dual-Factor Single and Two-Way Authentication Method and Electronic Device Based on Sensing and Communication Integration

By adopting a two-factor single- and two-way authentication method in the synesthesia integrated network, using communication-aware integrated signals to verify user legitimacy and data consistency, the problem of difficulty in preventing attacks in scenarios with limited resources and high real-time performance in the prior art is solved, and an efficient and secure authentication process is achieved.

CN115514513BActive Publication Date: 2025-06-24BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210903881.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-28
Publication Date
2025-06-24
Estimated Expiration
2042-07-28

AI Technical Summary

Technical Problem

In scenarios such as intelligent transportation systems, drone self-organized networks, air surveillance systems and fleets, the existing technology is difficult to effectively prevent identity disguise attacks, man-in-the-middle attacks, playback attacks and data injection attacks, and lacks effective means of confirming from the perspective of data legitimacy.

Method used

A two-factor single- and two-way authentication method based on synesthesia integration is proposed. By sending communication-perceptual integrated signals and extracting perceived information and user identity sequences for verification, the judgment of user legitimacy and data consistency is realized without the participation of third-party equipment.

Benefits of technology

This method effectively reduces the complexity of equipment and resource consumption, reduces the impact of data injection attacks and spoofing attacks on traffic safety, and improves the security and efficiency of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115514513B_ABST
    Figure CN115514513B_ABST
Patent Text Reader

Abstract

The present application provides a dual-factor single and two-way authentication method and an electronic device based on integrated communication and sensing. The method includes: sending a first integrated communication and sensing signal to a second user terminal to obtain a second echo signal; extracting second sensing information from the second echo signal; verifying whether the second sensing information is correct; in response to the second sensing information being correct, receiving a second integrated communication and sensing signal sent by the second user terminal; extracting a second user identity sequence from the second integrated communication and sensing signal; verifying whether the second user identity sequence is correct; in response to the second user identity sequence being correct, storing second identification information of the second user terminal; the second identification information includes the second sensing information and the second user identity sequence. In the embodiments of the present application, the identity of the user terminal is authenticated by verifying the sensing information and the identity sequence, effectively saving spectrum resources, computing resources, and signal interaction resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of device-device identity authentication and data consistency verification in integrated communication and sensing networks, and particularly relates to a two-factor single and two-way authentication method and an electronic device based on integrated communication and sensing. Background Art

[0002] Integrated communication and sensing means realizing two services of communication and sensing on a set of devices or a network, which greatly improves the spectral efficiency and is one of the important technological innovation directions in the 5G-A and 6G phases. Especially in scenarios where space and power are extremely limited, such as intelligent transportation systems, drone ad-hoc networks, air monitoring systems, and fleets, there is a strong demand for the integration of communication and sensing technologies. In these scenarios, there may be threats of attacks such as identity spoofing attacks, man-in-the-middle attacks, replay attacks, and message tampering. Identity authentication schemes and data consistency verification schemes are required.

[0003] In actual scenarios, existing identity authentication schemes mainly use third-party devices such as roadside units or ground control stations with functions such as high-precision positioning, data management, and displacement monitoring for identity authentication and data consistency verification.

[0004] For data injection attacks, such as in vehicle-to-vehicle networks, drone ad-hoc networks, and ship networks, if the data containing the vehicle's own speed and position exchanged between vehicle-vehicle, drone-drone, and ship-ship is false data or maliciously replicated data, then these data injection attacks are likely to cause traffic jams and even accidents, endangering personal and property safety.

[0005] In actual scenarios, existing security schemes for preventing data injection attacks mainly rely on message digest and data signature methods. These schemes all require a large amount of computation and are not suitable for scenarios with limited resources and high real-time requirements, such as intelligent transportation systems, drone ad-hoc networks, air monitoring systems, and fleets. At the same time, existing security methods lack effective means to confirm from the perspective of data legality and cannot resist replay attacks. Summary of the Invention

[0006] In view of this, the purpose of the present application is to propose a two-factor single and two-way authentication method and an electronic device based on integrated communication and sensing.

[0007] Based on the above purpose, the present application provides a two-factor two-way authentication method based on integrated communication and sensing, which is applied to a first user terminal and is characterized by including:

[0008] Sending a first communication and sensing integrated signal to a second user terminal to obtain a second echo signal;

[0009] Extract the second sensing information from the second echo signal;

[0010] Verify whether the second sensing information is correct;

[0011] In response to the second sensing information being correct, receive the second communication and sensing integrated signal sent by the second client;

[0012] Extract the second user identity sequence from the second communication and sensing integrated signal;

[0013] Verify whether the second user identity sequence is correct;

[0014] In response to the second user identity sequence being correct, store the second identification information of the second client; the second identification information includes the second sensing information and the second user identity sequence.

[0015] In a possible implementation, the second sensing information includes speed and the distance between the second client and the first client;

[0016] Among them, verifying whether the second sensing information is correct includes:

[0017] Obtain the latest speed and latest distance of the stored second client;

[0018] Verify whether the first similarity between the speed and the latest speed reaches a preset first threshold;

[0019] Verify whether the second similarity between the distance and the latest distance reaches a preset second threshold;

[0020] In response to the first similarity not reaching the preset first threshold and the second similarity not reaching the preset second threshold, determine that the second sensing information is correct.

[0021] In a possible implementation, verifying whether the second user identity sequence is correct includes:

[0022] Obtain the latest user identity sequence of the stored second client;

[0023] Verify whether the second user identity sequence is the same as the latest user identity sequence;

[0024] In response to the second user identity sequence being the same as the latest user identity sequence, determine that the second user identity sequence is correct.

[0025] In a possible implementation, it further includes:

[0026] In response to the error of the second sensing information, increment the second error count and record the second error count;

[0027] In response to the second error count not reaching the preset third threshold, resend the first communication and sensing integrated signal to the second client;

[0028] In response to the error count reaching the preset third threshold, send information about the abnormality of the second client to a third-party device.

[0029] In a possible implementation, it further includes:

[0030] In response to the error of the second user identity sequence, send information about the abnormality of the second client to a third-party device.

[0031] Based on the same inventive concept, the present application further provides a dual-factor two-way authentication method based on communication and sensing integration, which is applied to the second client and characterized by including:

[0032] Receive the first communication and sensing integrated signal sent by the first client;

[0033] Extract the first user identity sequence in the first communication and sensing integrated signal;

[0034] Verify whether the first user identity sequence is correct;

[0035] In response to the correct first user identity sequence, send a second communication and sensing integrated signal to obtain a first echo signal;

[0036] Extract the first sensing information in the first echo signal;

[0037] Verify whether the first sensing information is correct;

[0038] In response to the correct first sensing information, store the first identification information of the first client; the first identification information includes the first sensing information and the first user identity sequence.

[0039] In a possible implementation, it further includes:

[0040] In response to the error of the first user identity sequence, send information about the abnormality of the first client to a third-party device.

[0041] In a possible implementation, it further includes:

[0042] In response to the error of the first sensing information, increment the first error count and record the first error count;

[0043] In response to the fact that the first error count does not reach the preset fourth threshold, resend the second communication-sensing integrated signal to the first client;

[0044] In response to the error count reaching the preset fourth threshold, send information about the abnormality of the first client to a third-party device.

[0045] Based on the same inventive concept, the present application also provides a dual-factor one-way authentication method based on communication-sensing integration, which is characterized by including:

[0046] Send a verification communication-sensing integrated signal to the client to be verified, and obtain a to-be-verified echo signal;

[0047] Extract the to-be-verified sensing information from the to-be-verified echo signal;

[0048] In response to determining that the to-be-verified sensing information is correct, receive the to-be-verified communication signal sent by the to-be-verified client;

[0049] Extract the to-be-verified user identity sequence from the to-be-verified communication signal;

[0050] In response to determining that the to-be-verified user identity sequence is correct, store the third identification information of the to-be-verified client; the third identification information includes the to-be-verified sensing information and the to-be-verified user identity sequence.

[0051] Based on the same inventive concept, one or more embodiments of the present specification also provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements the dual-factor single-way and two-way authentication method based on communication-sensing integration as described in any one of the above.

[0052] As can be seen from the above, the dual-factor single-way and two-way authentication method and the electronic device based on communication-sensing integration provided by the present application combine the radar sensing signal and the data packet transmitted by communication to judge the legitimacy of the user and the consistency of the data. The two parties only need to send a signal to each other once to achieve one-way authentication and / or two-way authentication between the clients. In addition, since the sensing signal is directly extracted from the echo signal of the integrated waveform, it is credible, without the need to design additional keys and trust mechanisms, without additional hardware resources for encryption, and without the assistance of other road test third-party devices / ground control stations, effectively reducing the complexity of the device and reducing the impact of data injection attacks and spoofing attacks on traffic safety. Description of the Drawings

[0053] To more clearly illustrate the technical solutions in the present application or related technologies, the following will briefly introduce the accompanying drawings required for use in the embodiments or related technology descriptions. Obviously, the accompanying drawings in the following descriptions are only embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0054] Figure 1 Schematic diagram of the dual-factor two-way authentication method based on integrated communication and sensing for the embodiments of the present application;

[0055] Figure 2 Flowchart of the dual-factor two-way authentication method based on integrated communication and sensing for the embodiments of the present application applied to the first client;

[0056] Figure 3 Flowchart of the dual-factor two-way authentication method based on integrated communication and sensing for the embodiments of the present application applied to the second client;

[0057] Figure 4 Flowchart of the dual-factor one-way authentication method based on integrated communication and sensing for the embodiments of the present application;

[0058] Figure 5 Schematic diagram of the structure of the electronic device for the embodiments of the present application. Detailed implementation manners

[0059] To make the objectives, technical solutions, and advantages of the present application more clear and understandable, the following further elaborates on the present application in detail in combination with specific embodiments and with reference to the accompanying drawings.

[0060] It should be noted that unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the ordinary meaning understood by those of ordinary skill in the art to which the present application belongs. The "first", "second", and similar terms used in the embodiments of the present application do not indicate any order, quantity, or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or items appearing before this word cover the elements or items listed after this word and their equivalents, without excluding other elements or items. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left", "right", etc. are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0061] As described in the background art section, when exchanging road-related information, identity authentication sequences, and information such as its own location and speed in the related art, it is necessary to rely on third-party auxiliary authentication devices such as roadside units or ground control stations with functions such as high-precision positioning, data management, and displacement monitoring for identity authentication and data consistency verification.

[0062] In actual scenarios, an authentication and data consistency protection solution without relying on third-party devices is required. Taking the vehicle-to-everything (V2X) network as an example, 3GPP TS33.536 proposes that confidentiality, integrity, and replay protection need to be provided for the vehicle-to-vehicle direct communication (PC5) link in the V2X network. However, if third-party devices are not used in the above process and traditional certificate-based methods are used for identity authentication, the information inflow and outflow during the authentication process consume a lot of time, high computing resources, and a long key length. At the same time, once the information exchange is modified, simulated, replayed, data injected, or attacked by malicious nodes during the information exchange process, the information exchange in the authentication process will become false information, which is likely to cause traffic jams and even traffic accidents, endangering personal and property safety.

[0063] In the existing related technologies, the security solutions for preventing data illegal injection attacks are mainly based on methods such as distributing group keys to users, authorizing users, configuring database storage models, and distributed blockchains. However, these solutions all require pre-assigning valid identity information and authentication methods to users, and also need to combine data integrity protection methods. Due to the extremely large number of users in the actual application scenario and the randomness and rapid change of users in the network, the workload in the actual operation process is huge and difficult to implement.

[0064] In addition, taking the V2X network as an example, data reporting is required for data intercommunication between users in different V2X service scenarios in 3GPP TS 22.186. In the existing authentication methods, there is a lack of effective means to confirm from the perspective of data legality or authenticity.

[0065] In view of the above considerations, the embodiment of the present application proposes a dual-factor single and two-way authentication method based on integrated communication and sensing. The first user terminal sends a first communication and sensing integrated signal to the second user terminal to obtain a second echo signal; extracts the second sensing information in the second echo signal; verifies whether the second sensing information is correct; in response to the second sensing information being correct, receives the second communication and sensing integrated signal sent by the second user terminal; extracts the second user identity sequence in the second communication and sensing integrated signal; verifies whether the second user identity sequence is correct; in response to the second user identity sequence being correct, stores the second identification information of the second user terminal; the second identification information includes the second sensing information and the second user identity sequence. By combining the radar sensing signal and the communication transmission data packet to judge the legitimacy of the user and the consistency of the data, the two parties only need to send a signal to each other once to achieve one-way authentication and / or two-way authentication between user terminals. First, the authentication process of the present application uses the communication and sensing integrated signal to transmit information. During the transmission process, the communication signal and the sensing signal are transmitted on the same channel, effectively saving spectrum resources. Second, the present application uses the physical sensing attribute as the key, effectively reducing the computational complexity of the key and saving computational resources. Finally, without the participation of a third-party device in the entire authentication process while ensuring that the security of the authentication system is at least comparable to that of the prior art, and the signal transmission process and signal interaction process required during the entire authentication process are significantly reduced compared to the prior art, effectively saving signal resources and signal interaction resources.

[0066] In summary, the present application realizes dual-factor authentication of data consistency verification and identity legitimacy without relying on a third-party device, effectively improving the security during the authentication process, and reducing the device resources, signal resources, spectrum resources, etc. required for authentication, effectively ensuring personal and property safety.

[0067] Reference Figure 1 , is a schematic diagram of the dual-factor two-way authentication method based on integrated communication and sensing according to the embodiment of the present application.

[0068] Specifically, when the authentication process starts, User 1 (the first user terminal) and User 2 (the second user terminal) will access the roadside unit (RSU) / base station (BS) / ground control station (GCS) (third-party device) to synchronize each other's data, such as sensing information and user identity authentication sequences, and then report the data.

[0069] Specifically, the ways of reporting data mainly include: periodic reporting, that is, automatically triggering a data reporting instruction at regular intervals; immediate reading, that is, when a third-party device or network platform has a need to query data, it actively queries the data and directly issues a data reporting instruction; feedback reporting, that is, the third-party device or network platform issues a control instruction and uses the data reporting instruction to make the device feedback the execution result of the instruction; trigger reporting, that is, when the status data of a certain user terminal changes, the user terminal reports its data by itself, triggering a data reporting instruction. Figure 1Taking the status change of User 2 as an example, after the status of User 2 changes, a data reporting instruction is triggered. After User 1 receives the data reporting instruction sent by the third-party device, User 1 sends an integrated signal X (the first communication and sensing integrated signal) to User 2, extracts the sensing attribute (the second sensing information) from the echo signal, and then compares whether the extracted sensing attribute is approximately the same as the stored sensing attribute. In the embodiment of the present application, the method of calculating the similarity is used to show whether they are approximately the same. When they are not approximately the same, it is judged whether the number of errors (the second number of errors) reaches the error threshold (the third threshold). If the error threshold is not reached, User 1 resends the integrated signal X to User 2. If the error threshold is reached, User 1 sends user exception information (information on the second user terminal exception) to the third-party device. At the same time, after User 2 receives the integrated signal X sent by User 1, it extracts the ID data (the first user identity sequence) from it and compares whether the extracted ID data is the same as the stored ID data, that is, whether the identity of User 1 is legal. If the comparison result of the foregoing ID data is the same, User 2 then sends an integrated signal Y (the second communication and sensing integrated signal) to User 1. If the result is different, it directly sends user exception information (information on the first user terminal exception) to the third-party device. When User 1 receives the integrated signal Y sent by User 2, it extracts the ID data (the second user identity sequence) of User 2 from it and compares it with the stored ID data of User 1, that is, verifies whether the identity of User 1 is legal. If it is legal, it stores the identification information (the first identification information) of User 1. If it is not legal, it directly sends user exception information to the third-party device. At the same time, after User 2 receives the echo signal, it analyzes the echo signal and extracts the sensing attribute (the first sensing information) from it, and compares whether the extracted sensing attribute is approximately the same as the stored sensing attribute. Similarly, in the embodiment of the present application, the degree of approximation is used to measure. If the result is not approximately the same, it is judged whether the number of errors reaches the error threshold (the fourth threshold). If the error threshold is not reached, User 2 resends the integrated signal Y to User 1. If the error threshold is reached, User 2 sends user exception information (information on the first user terminal exception) to the third-party device; when the result is approximately the same, User 2 stores the identification information (the first identification information) of User 1. There may be multiple two-way authentication processes between User 1 and User 2 subsequently. In the subsequent authentication processes, the identification information stored this time will be used as the stored sensing attribute and the stored ID data to perform a new round of comparison with the newly obtained sensing attribute and ID data. This process will continue to cycle until the authentication process ends.

[0070] The following describes the two-factor two-way authentication method based on communication and sensing integration in the embodiment of the present application through specific steps.

[0071] An embodiment of the present application provides a dual-factor two-way authentication method based on integrated communication and sensing, and this dual-factor two-way authentication method based on integrated communication and sensing is applied to a first user terminal.

[0072] Referring to Figure 2 , the dual-factor two-way authentication method based on integrated communication and sensing in this embodiment may include the following steps:

[0073] Step S201: Send a first communication and sensing integrated signal to a second user terminal to obtain a second echo signal;

[0074] Step S202: Extract second sensing information from the second echo signal;

[0075] Step S203: Verify whether the second sensing information is correct;

[0076] Step S204: In response to the second sensing information being correct, receive a second communication and sensing integrated signal sent by the second user terminal;

[0077] Step S205: Extract a second user identity sequence from the second communication and sensing integrated signal;

[0078] Step S206: Verify whether the second user identity sequence is correct;

[0079] Step S207: In response to the second user identity sequence being correct, store second identification information of the second user terminal; the second identification information includes the second sensing information and the second user identity sequence.

[0080] Regarding step S201, in this embodiment, before the authentication process starts, the first user terminal and the second user terminal will upload their own sensing information and user identity sequences, and obtain the sensing information and corresponding user identity sequences of the other party through a third-party device and store them in their own memories. Among them, the user identity sequence can not only be the user's serial number, the key sequence generated by the upper layer, the sequence processed by a one-way mapping function such as a hash function for the device ID, but also other types of identity data, such as generating an identity authentication sequence through radio frequency fingerprint information for authentication based on physical layer characteristics.

[0081] At a certain moment, when the data reporting instruction is triggered, the first client sends a first communication and sensing integrated signal to the second client. Among them, the data reporting instruction can be periodic reporting, trigger reporting, immediate reading or feedback reporting. Taking the trigger reporting of the change of the second client state as an example, in response to the change of the second client state, the second client sends a data reporting instruction to the third-party device; in response to the third-party device receiving the data reporting instruction, it sends a data reporting instruction to the first client; further, when the first client receives the data reporting instruction, the first client sends a first communication and sensing integrated signal to the second client.

[0082] The generation of the first communication and sensing integrated signal can adopt time division, frequency division or signal multiplexing methods. The specific generation process of the first communication and sensing integrated signal can be expressed as:

[0083]

[0084] Among them, X1 represents the first communication and sensing integrated signal, and F() represents the generation method of the first communication and sensing integrated signal. represents the communication signal, and X radar1 represents the radar signal.

[0085] Among them, the first communication and sensing integrated signal can be single-carrier or multi-carrier. The time-domain expression of the single-carrier first communication and sensing integrated signal is:

[0086]

[0087] Among them, X(t) represents the single-carrier first communication and sensing integrated signal, N represents the number of modulation symbols constituting the signal frame, T represents the symbol duration, g() represents the baseband pulse shape; a(n) represents the discrete amplitude and phase after modulation, and n represents a certain modulation symbol number.

[0088] The time-domain expression of the first communication and sensing integrated signal of the multi-carrier orthogonal frequency division multiplexing (OFDM) technology is:

[0089]

[0090] Among them, X(t)′ represents the multi-carrier first communication and sensing integrated signal, M represents the total number of OFDM symbols, Q represents the total number of subcarriers, a() represents the modulation symbol in the complex domain, f q represents the frequency of the qth subcarrier, T′ represents the total duration of OFDM, rect() represents the rectangular pulse shape, m represents a certain OFDM symbol number, and j represents the imaginary unit.

[0091] In addition, the first client can send the first communication and sensing integrated signal to the second client at any time for the subsequent authentication process, that is, the first client can send the first communication and sensing integrated signal to the second client at any time when it has not received the data reporting instruction to initiate the authentication process.

[0092] Furthermore, after the first client sends the first communication and sensing integrated signal to the second client, the first client can receive the second echo signal, and the first client can realize the sensing function through the second echo signal.

[0093] Regarding step S202, the second sensing information can be extracted from the second echo signal, and the second sensing information can include the distance from the second client to the first client, the speed, arrival angle, shape, size, structure, etc. of the second client.

[0094] Among them, the second echo signal is calculated by the following formula:

[0095] X reflect2 =H radar X1+N iose

[0096] Among them, X reflect2 represents the second echo signal, H radar represents the sensing channel, X1 represents the first communication and sensing integrated signal, and N iose represents additive noise.

[0097] When the first communication and sensing integrated signal is a single carrier, the single carrier second echo signal is calculated by the following formula:

[0098]

[0099] Among them, X reflect (t) represents the single carrier second echo signal, A represents the attenuation and phase shift caused by propagation and scattering, X1(t - τ) represents the single carrier first communication and sensing integrated signal after a delay of τ, N represents the number of modulation symbols that make up the signal frame, g() represents the baseband pulse shape, n represents a certain modulation symbol number, c(n) represents the amplitude and phase of the nth pulse after passing through the sensing channel, f d represents the Doppler frequency shift, τ = 2R / c, R represents the distance between the first client and the second client, c represents the speed of light, and T represents the symbol duration.

[0100] When the first communication and sensing integrated signal is a multi - carrier, the multi - carrier second echo signal is calculated by the following formula:

[0101]

[0102] Among them, Xreflect (t)' represents the multi - carrier second echo signal, M represents the total number of OFDM symbols, Q represents the total number of sub - carriers, d Tx (mQ + q) represents the user data transmitted by the transmitter, f q represents the frequency of the q - th sub - carrier, T' represents the total duration of OFDM, rect() represents the rectangular pulse shape, m represents a certain OFDM symbol number, and j represents the imaginary unit.

[0103] Common methods for extracting the second sensing information include the Fourier transform method and the Multiple Signal Classification (MUSIC) algorithm. For the specific process of extracting the second sensing information, for example, the distance from the second user terminal to the first user terminal can be calculated based on the transmission time of the first communication - sensing integrated signal and the reception time of the echo signal, and the speed of the second user terminal can be calculated based on the Doppler frequency shift of the second echo signal, etc. Those skilled in the art should know that the above - mentioned extraction process can be realized, and the specific extraction processes of the remaining second sensing information will not be elaborated here.

[0104] Furthermore, after the first user terminal sends the first communication - sensing integrated signal to the second user terminal, the second user terminal demodulates and decodes the received first communication - sensing integrated signal to obtain the first identification information containing the first user identity sequence of the first user terminal, and then extracts the first user identity sequence of the first user terminal from the first identification information. The specific demodulation and decoding process should be known to those skilled in the art and will not be elaborated here.

[0105] Among them, the first communication - sensing integrated signal received by the second user terminal is calculated by the following formula:

[0106] X'1 = H comm1 X1 + N iose

[0107] X'1 represents the first communication - sensing integrated signal received by the second user terminal, H comm1 represents the channel from the first user terminal to the second user terminal, X1 represents the first communication - sensing integrated signal, and N iose represents additive noise.

[0108] Regarding step S203, after the second sensing information is extracted at the first user terminal, the second sensing information needs to be verified. During the verification process, at least the distance between the first user terminal and the second user terminal and the speed of the second user terminal need to be verified.

[0109] Specifically, obtain the latest speed and latest distance of the second client previously stored in the first client. Verify them with the speed and distance extracted from the second perception information. For example, calculate the second similarity between the distance and the latest distance, verify whether the second similarity reaches a preset second threshold, calculate the first similarity between the speed and the latest speed, verify whether the first similarity reaches a preset first threshold. When the first similarity does not reach the preset first threshold and the second similarity does not reach the preset second threshold, determine that the second perception information is correct. In response to the first similarity reaching the preset first threshold and / or the second similarity reaching the preset second threshold, the second perception information is incorrect. When the second perception information is incorrect, increment the second error count by one, and record the second error count at this time. The second error count is initially set to zero, and each time the second perception information is incorrect, the second error count is incremented by one. The settings of the above first threshold and second threshold depend on the scenario where the client is located. For example, the threshold when an automobile in a vehicle-to-everything (V2X) scenario is used as a client is correspondingly reduced compared to the threshold when a drone in a drone ad-hoc network scenario is used as a client. That is, the V2X scenario has a lower tolerance rate compared to the drone ad-hoc network scenario. It should be noted that those skilled in the art can set the above thresholds according to experience by themselves.

[0110] Further, verify whether the second error count at this time reaches a preset third threshold. When the second error count does not reach the preset third threshold, the first client resends the first communication and perception integration signal to the second client. When the second error count reaches the preset third threshold, send information about the abnormality of the second client to a third-party device.

[0111] Further, after the second client extracts the first user identity sequence from the received first communication and perception integration signal, verify whether the first user identity sequence is correct. Specifically, the second client obtains the latest user identity sequence of the first client stored, and verify whether the first user identity sequence is the same as the latest user identity sequence of the first client. When they are the same, determine that the first user identity sequence is correct and continue with the subsequent authentication steps. When they are different, directly send information about the abnormality of the first client to a third-party device.

[0112] After the second client verifies that the first user identity sequence is correct, the second client sends a second communication and perception integration signal to the first client.

[0113] It should be noted that in the embodiments of the present application, the process of verifying the second sensing information takes distance and speed as examples. However, in actual situations, the second sensing information not only includes distance and speed, and corresponding verification processes can be added according to actual needs. The correctness of the second sensing information can be verified by calculating the similarity. Those skilled in the art can obtain the verification processes of other second sensing information based on speed and distance, so it will not be elaborated here.

[0114] For step S204, after the first client verifies that the second sensing information is correct, it receives the second communication and sensing integrated signal sent by the second client.

[0115] Meanwhile, the second client receives the first echo signal and extracts the first sensing information from the first echo signal. The first sensing information can be extracted from the first echo signal, and the first sensing information can include the distance from the first client to the second client, the speed, arrival angle, shape, size, structure, etc. of the first client.

[0116] Common methods for extracting the first sensing information include the Fourier transform method and the Multiple Signal Classification (MUSIC) algorithm. For the specific process of extracting the first sensing information, for example, the distance from the first client to the second client can be calculated based on the transmission time of the second communication and sensing integrated signal and the reception time of the echo signal, and the speed of the first client can be calculated based on the Doppler frequency shift of the first echo signal, etc. Those skilled in the art should know that the above extraction process can be realized, and the specific extraction processes of the remaining first sensing information will not be elaborated here.

[0117] Among them, the first echo signal is calculated by the following formula:

[0118] X reflect1 =H radar X2+N iose

[0119] Among them, X reflect1 represents the first echo signal, H radar represents the sensing channel, X2 represents the second communication and sensing integrated signal, and N iose represents additive noise.

[0120] After the second client extracts the first sensing information, it is necessary to verify the first sensing information. During the verification process, at least the distance between the second client and the first client and the speed of the first client need to be verified.

[0121] Specifically, obtain the latest speed and the latest distance of the first client that are pre-stored in the second client. Verify them against the speed and distance extracted from the first perception information. For example, calculate the fourth similarity between the distance extracted from the first perception information and the latest distance stored in the second client, and verify whether the fourth similarity reaches a preset sixth threshold. Calculate the third similarity between the speed extracted from the first perception information and the latest speed stored in the second client, and verify whether the third similarity reaches a preset fifth threshold. When the fourth similarity does not reach the preset sixth threshold and the third similarity does not reach the preset fifth threshold, determine that the first perception information is correct. In response to the fourth similarity reaching the preset sixth threshold and / or the third similarity reaching the preset fifth threshold, determine that the first perception information is incorrect. When the first perception information is incorrect, increment the first error count by one, and record the first error count at this time. The first error count is initially set to zero, and each time the first perception information is incorrect, the first error count is incremented by one. The settings of the above sixth threshold and fifth threshold depend on the scenario where the client is located. For example, the thresholds when an automobile in a vehicle networking scenario serves as a client are correspondingly reduced compared to when a drone in a drone ad-hoc network scenario serves as a client. That is, the vehicle networking scenario has a lower error tolerance compared to the drone ad-hoc network scenario. Those skilled in the art can set the above thresholds according to experience by themselves.

[0122] Furthermore, verify whether the first error count at this time reaches a preset fourth threshold. When the first error count does not reach the preset fourth threshold, the second client resends the second communication and perception integrated signal to the first client. When the first error count reaches the preset fourth threshold, send information about the abnormality of the first client to a third-party device.

[0123] Regarding step S205, after the first client receives the second communication and perception integrated signal sent by the second client, the first client demodulates and decodes the received second communication and perception integrated signal to obtain second identification information including the second user identity sequence of the second client, and then extracts the second user identity sequence of the second client from the second identification information. The specific demodulation and decoding process should be known to those skilled in the art and will not be elaborated here.

[0124] Among them, the second communication and perception integrated signal received by the first client is calculated by the following formula:

[0125] X′2 = H comm2 X2 + N iose

[0126] X′2 represents the second communication and perception integrated signal received by the first client, H commdenotes the channel from the second client to the first client, X2 denotes the first communication and sensing integrated signal, and N iose denotes additive noise.

[0127] Regarding step S206, after the first client extracts the second user identity sequence of the second client, it verifies whether the second user identity sequence is correct. Specifically, the first client obtains the latest user identity sequence of the second client stored, and verifies whether the second user identity sequence is the same as the latest user identity sequence of the second client. When they are the same, it determines that the second user identity sequence is correct and continues with the subsequent authentication steps. When they are different, it directly sends information about the abnormality of the second client to the third-party device.

[0128] Regarding step S207, after the first client determines that the second user identity sequence is correct, it stores the second identification information of the second client, and the second identification information includes the second sensing information and the second user identity sequence. The above-mentioned second sensing information and second user identity sequence are used as comparison information in the next authentication process. At the same time, when the second client determines that the first sensing information is correct, it stores the first identification information of the first client, and the first identification information includes the first sensing information and the first user identity sequence. The above-mentioned first sensing information and first user identity sequence are used as comparison information in the next authentication process.

[0129] It can be seen that the two-factor two-way authentication method based on communication and sensing integration in the embodiments of the present application combines radar sensing signals and communication transmission data packets to judge the legitimacy of users and the consistency of data. The two parties only need to send a communication and sensing integrated signal to each other once to achieve one-way authentication and / or two-way authentication between the clients, effectively saving spectrum resources and signal resources. Secondly, in the authentication process, there is no need for the participation of a third-party device, effectively reducing the complexity of information transmission, effectively improving the efficiency of the authentication process, and reducing the impact of data injection attacks and spoofing attacks on personal and property safety. In addition, in the authentication process, physical sensing attributes are used as keys, effectively reducing the computational complexity of the keys and saving computational resources.

[0130] Based on the same inventive concept, the embodiments of the present application also provide a two-factor two-way authentication method based on communication and sensing integration, and this two-factor two-way authentication method based on communication and sensing integration is applied to the second client.

[0131] Refer to Figure 3 , the two-factor two-way authentication method based on communication and sensing integration in the embodiments of the present application may include the following steps:

[0132] Step S301, receive the first communication and sensing integrated signal sent by the first client;

[0133] Step S302: Extract the first user identity sequence from the first communication and sensing integrated signal;

[0134] Step S303: Verify whether the first user identity sequence is correct;

[0135] Step S304: In response to the first user identity sequence being correct, send a second communication and sensing integrated signal to obtain a first echo signal;

[0136] Step S305: Extract the first sensing information from the first echo signal;

[0137] Step S306: Verify whether the first sensing information is correct;

[0138] Step S307: In response to the first sensing information being correct, store the first identification information of the first user terminal; the first identification information includes the first sensing information and the first user identity sequence.

[0139] In some alternative embodiments, it further includes:

[0140] In response to the first user identity sequence being incorrect, send information about the abnormality of the first user terminal to a third-party device.

[0141] In some alternative embodiments, it further includes:

[0142] In response to the first sensing information being incorrect, increment the first error count by one and record the first error count;

[0143] In response to the first error count not reaching a preset fourth threshold, resend the second communication and sensing integrated signal to the first user terminal;

[0144] In response to the error count reaching the preset fourth threshold, send information about the abnormality of the first user terminal to a third-party device.

[0145] In some alternative embodiments, it further includes:

[0146] In response to the first user identity sequence being incorrect, send information about the abnormality of the first user terminal to a third-party device.

[0147] In the above embodiments of the dual-factor two-way authentication method based on integrated communication and sensing applied to the second client, the second client receives the first communication and sensing integrated signal sent by the first client; extracts the first user identity sequence in the first communication and sensing integrated signal; verifies whether the first user identity sequence is correct; in response to the first user identity sequence being correct, sends a second communication and sensing integrated signal to obtain a first echo signal; extracts the first sensing information in the first echo signal; verifies whether the first sensing information is correct; in response to the first sensing information being correct, stores the first identification information of the first client; the first identification information includes the first sensing information and the first user identity sequence. The specific implementation details of the above methods have been described in detail in the foregoing embodiments of the dual-factor two-way authentication method based on integrated communication and sensing applied to the first client, and can specifically refer to any of the foregoing method embodiments applied to the first client, which will not be elaborated here.

[0148] Based on the same inventive concept, an embodiment of the present application also provides a dual-factor one-way authentication method based on integrated communication and sensing.

[0149] Reference Figure 4 , the dual-factor one-way authentication method based on integrated communication and sensing in the embodiment of the present application may include the following steps:

[0150] Step S401, send a verification communication and sensing integrated signal to the client to be verified to obtain a to-be-verified echo signal;

[0151] Step S402, extract the to-be-verified sensing information in the to-be-verified echo signal;

[0152] Step S403, verify whether the to-be-verified sensing information is correct;

[0153] Step S404, in response to determining that the to-be-verified sensing information is correct, receive the to-be-verified communication signal sent by the to-be-verified client;

[0154] Step S405, extract the to-be-verified user identity sequence in the to-be-verified communication signal;

[0155] Step S406, verify whether the to-be-verified user identity sequence is correct;

[0156] Step S407, in response to determining that the to-be-verified user identity sequence is correct, store the third identification information of the to-be-verified client; the third identification information includes the to-be-verified sensing information and the to-be-verified user identity sequence.

[0157] For step S401, in this embodiment, the verification client sends a verification communication perception integrated signal to the client to be verified. Before the authentication process starts, the client to be verified uploads its own perception information and user identity sequence, and the verification client stores the above perception information and user identity sequence in its own memory through a third-party device. Among them, the user identity sequence can not only be the user's serial number, the key sequence generated by the upper layer, the sequence obtained by processing the device ID using a one-way mapping function such as a hash function, but also other types of identity data, such as generating an identity authentication sequence through radio frequency fingerprint information for authentication based on physical layer characteristics.

[0158] At a certain moment, a data reporting instruction is triggered, and the verification client sends a first communication perception integrated signal to the client to be verified. Among them, the data reporting instruction can be a periodic reporting instruction, a trigger reporting instruction triggered by a change in the state of the client to be verified, or an immediate call read or feedback reporting. Taking the trigger reporting caused by the change of the state of the second client as an example, in response to the change of the state of the client to be verified, the client to be verified sends a data reporting instruction to the third-party device; in response to the third-party device receiving the data reporting instruction, it sends a data reporting instruction to the verification client; further, when the verification client receives the data reporting instruction, the verification client sends a verification communication perception integrated signal to the client to be verified.

[0159] The generation of the verification communication perception integrated signal can adopt time division, frequency division or signal multiplexing methods, and the verification communication perception integrated signal can be a single carrier or a multi-carrier.

[0160] In addition, the verification client can send a first communication perception integrated signal to the client to be verified at any time for the subsequent authentication process, that is, the verification client can send a verification communication perception integrated signal to the client to be verified at any time when it has not received the data reporting instruction to start the authentication process.

[0161] Further, after the verification client sends a verification communication perception integrated signal to the client to be verified, the verification client can receive the echo signal to be verified, and the verification client can realize the perception function through the echo signal to be verified.

[0162] For step S402, the perception information to be verified can be extracted from the echo signal to be verified, and the perception information to be verified can include the distance from the client to be verified to the verification client, the speed, arrival angle, shape, size, structure, etc. of the client to be verified.

[0163] Common methods for extracting the perception information to be verified include the Fourier transform method and the Multiple Signal Classification (MUSIC) algorithm. For the specific process of extracting the perception information to be verified, for example, the distance from the user terminal to be verified to the verification user terminal can be calculated based on the transmission time of the verification communication perception integrated signal and the reception time of the echo signal, and the speed of the user terminal to be verified can be calculated based on the Doppler frequency shift of the echo signal to be verified, etc. Those skilled in the art should know that the above extraction process can be achieved, and the specific extraction process of the remaining second perception information will not be elaborated here.

[0164] Regarding step S403, after the verification user terminal extracts the perception information to be verified, it is necessary to verify the perception information to be verified. During the verification process, at least the distance between the verification user terminal and the user terminal to be verified and the speed of the user terminal to be verified need to be verified.

[0165] Specifically, obtain the latest speed and latest distance of the user terminal to be verified that are stored in the verification user terminal in advance. Verify them with the speed and distance extracted from the perception information to be verified. The specific verification process can refer to the corresponding verification process in the above-mentioned dual-factor two-way authentication method based on communication and sensing integration, which will not be elaborated here.

[0166] Regarding step S404, when the perception information to be verified is correct, receive the communication signal to be verified sent by the user terminal to be verified, and this communication signal includes the sequence of the user identity to be verified.

[0167] Furthermore, extract the sequence of the user identity to be verified from the communication signal to be verified. The specific extraction process can refer to the extraction process of extracting the second user identity sequence from the second communication perception integrated signal in the above-mentioned dual-factor two-way authentication method based on communication and sensing integration, which will not be elaborated here.

[0168] Regarding step S406, verify whether the sequence of the user identity to be verified extracted in the above steps is correct. The specific verification process can refer to the verification process of verifying the second user identity sequence in the above-mentioned dual-factor two-way authentication method based on communication and sensing integration, which will not be elaborated here.

[0169] Regarding step S407, when it is determined that the sequence of the user identity to be verified is correct, the round of authentication process for the user terminal to be verified ends. At this time, store the third identification information of the user terminal to be verified into the verification user terminal as the corresponding comparison data in the next round of authentication process.

[0170] It should be noted that the method of the embodiments of the present application can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In such a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present application, and these multiple devices will interact with each other to complete the described method.

[0171] It should be noted that some embodiments of the present application have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0172] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method of dual-factor single and two-way authentication based on integrated communication and sensing of any one of the above embodiments.

[0173] Figure 5 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.

[0174] The processor 1010 can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0175] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and called and executed by the processor 1010.

[0176] The input / output interface 1030 is used to connect to an input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0177] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module can achieve communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).

[0178] The bus 1050 includes a path for transmitting information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0179] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solutions of the embodiments of this specification and do not necessarily include all the components shown in the figure.

[0180] The electronic device in the above embodiment is used to implement the corresponding dual-factor single and two-way authentication method based on integrated communication and sensing in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0181] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present application (including the claims) is limited to these examples; within the concept of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and for the sake of brevity, they are not provided in detail.

[0182] In addition, for simplicity of explanation and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present application, it will be apparent to those skilled in the art that the embodiments of the present application may be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0183] Although the present application has been described in connection with specific embodiments of the present application, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0184] The embodiments of the present application are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application shall be included within the protection scope of the present application.

Claims

1. A dual-factor two-way authentication method based on integrated sensing and communication, applied to the first client, characterized in that, Including: Sending a first communication and sensing integrated signal to a second client to obtain a second echo signal; Extracting second sensing information from the second echo signal; Verifying whether the second sensing information is correct; In response to the second sensing information being correct, receiving the second communication and sensing integrated signal sent by the second client; Extracting a second user identity sequence from the second communication and sensing integrated signal; Verifying whether the second user identity sequence is correct, including: obtaining the latest user identity sequence of the second client stored; verifying whether the second user identity sequence is the same as the latest user identity sequence; in response to the second user identity sequence being the same as the latest user identity sequence, determining that the second user identity sequence is correct; In response to the second user identity sequence being correct, storing the second identification information of the second client; the second identification information includes the second sensing information and the second user identity sequence.

2. The method according to claim 1, wherein The second sensing information includes speed and the distance between the second client and the first client; Wherein, verifying whether the second sensing information is correct includes: Obtaining the latest speed and latest distance of the second client stored; Verifying whether the first similarity between the speed and the latest speed reaches a preset first threshold; Verifying whether the second similarity between the distance and the latest distance reaches a preset second threshold; In response to the first similarity not reaching the preset first threshold and the second similarity not reaching the preset second threshold, determining that the second sensing information is correct.

3. The method according to claim 1, wherein Also including: In response to the second sensing information being incorrect, incrementing the second error count and recording the second error count; In response to the second error count not reaching a preset third threshold, resending the first communication and sensing integrated signal to the second client; In response to the error count reaching the preset third threshold, sending information about the abnormality of the second client to a third-party device.

4. The method according to claim 1, characterized in that, Also including: In response to the second user identity sequence being incorrect, sending information about the abnormality of the second client to a third-party device.

5. A dual-factor two-way authentication method based on integrated communication and sensing, applied to a second client, characterized in that, Including: Receiving a first communication and sensing integrated signal sent by a first client; Extracting a first user identity sequence from the first communication and sensing integrated signal; Verifying whether the first user identity sequence is correct, including: obtaining the latest user identity sequence of the first client stored, verifying whether the first user identity sequence is the same as the latest user identity sequence of the first client, and when they are the same, determining that the first user identity sequence is correct; In response to the first user identity sequence being correct, sending a second communication and sensing integrated signal to obtain a first echo signal; Extracting first sensing information from the first echo signal; Verifying whether the first sensing information is correct; In response to the first sensing information being correct, storing the first identification information of the first client; the first identification information includes the first sensing information and the first user identity sequence.

6. The method according to claim 5, characterized in that, Also including: In response to the first user identity sequence being incorrect, sending information about the abnormality of the first client to a third-party device.

7. The method according to claim 5, characterized in that Also including: In response to the error of the first sensing information, increment the first error count by one and record the first error count; In response to the first error count not reaching the preset fourth threshold, resend the second communication and sensing integrated signal to the first client; In response to the error count reaching the preset fourth threshold, send information about the abnormality of the first client to a third-party device.

8. A dual-factor one-way authentication method based on integrated sensing and communication, characterized in that, Comprising: When the verification client receives a data reporting instruction, the verification client sends a verification communication and sensing integrated signal to the client to be verified, and obtains a verified echo signal; Extract the verified sensing information from the verified echo signal; Verify whether the verified sensing information is correct; In response to determining that the verified sensing information is correct, receive the verified communication signal sent by the client to be verified; Extract the verified user identity sequence from the verified communication signal; Verify whether the verified user identity sequence is correct; In response to determining that the verified user identity sequence is correct, store the third identification information of the client to be verified; the third identification information includes the verified sensing information and the verified user identity sequence.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Intelligence control system based on mobile terminal identity verification and position perception and method

    CN104599354A

  • Communication perception integration method, device, base station and system

    CN114599086A