A Smart Home Authentication Method Based on Edge Computing

By embedding PUF modules in smart home environments and utilizing edge computing authentication methods, the problem of insufficient security of information transmission in smart home environments is solved, real-time secure communication and efficient data processing are realized, and the security of the protocol and the utilization of equipment resources are enhanced.

CN115567222BActive Publication Date: 2025-07-08SHANDONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211198132.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-29
Publication Date
2025-07-08
Estimated Expiration
2042-09-29

AI Technical Summary

Technical Problem

In a smart home environment, existing edge computing authentication solutions cannot effectively resist various attacks, resulting in insufficient security of information transmission between users and smart devices. In addition, the data transmission performance in traditional cloud computing mode is low, which cannot meet real-time needs.

Method used

Adopting an authentication method based on edge computing, by embedding PUF modules in smart devices and using edge gateways for data processing and storage, combining one-way hashing functions and physical non-clone functions, secure authentication and key negotiation between users and smart devices are realized.

Benefits of technology

Real-time secure communication between users and smart devices is realized, the security of information transmission and protocol security is enhanced, data outflow is reduced, and resource utilization efficiency of smart devices is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567222B_ABST
    Figure CN115567222B_ABST
Patent Text Reader

Abstract

The present invention discloses a smart home authentication method based on edge computing, belonging to the technical fields of cryptography and network security, which includes four entities: a registration center, an edge gateway, a user, and a smart device; among them, the registration center is responsible for the registration of users and smart devices; the edge gateway is deployed inside the home and serves as a bridge for communication between smart devices and users; with the help of the edge gateway, users can enjoy the services provided by smart devices and remotely control them anytime and anywhere through mobile devices; smart devices include various smart devices in the home, and each smart device is embedded with a PUF module; this smart home authentication method includes three stages, namely the initialization stage, the user registration and smart device registration stage, and the user remote access and control smart device stage. The smart home environment authentication scheme proposed by the present invention has real-time controllability and can also ensure the secure transmission of information between users and smart devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of cryptography and network security, and particularly relates to a smart home authentication method based on edge computing. Background Art

[0002] The Internet of Things (IoT) is generally a network in which all things are connected, capable of collecting various types of information in real time and communicating with other devices. The development of the IoT has brought significant achievements in different fields, such as smart cities, smart healthcare, smart transportation, smart homes, etc. Smart home is an embodiment of the IoT. It is an environment where smart devices are deployed in the home, and various devices provide services for users by connecting to the Internet. People can obtain smart home services anytime and anywhere through voice assistants or applications and easily control smart devices. In the smart home environment, people's lives become more comfortable, their lifestyles become more intelligent, and the quality of people's lives is constantly improving.

[0003] Traditional smart home architectures rely on centralized cloud computing for data collection and processing. In this mode, many problems have emerged. If a large number of edge devices are added, a large amount of terminal data will still be transmitted to the cloud for processing, greatly increasing the amount of intermediate data transmission, reducing data transmission performance, imposing a large load on the network transmission bandwidth, and resulting in data transmission delays. In some scenarios where users require real-time feedback, such as monitoring. In such scenarios, cloud computing will not be able to meet the real-time needs of users, and the processing of large-capacity data leads to low real-time access. A large amount of sensitive data will also be generated in the smart home environment. Edge computing is closer to the data source than cloud computing and can better locally process this data and perform real-time analysis, reducing the data outflow of smart devices. Therefore, how to ensure the secure transmission of data is an important issue in the edge computing environment. How to apply edge computing to the smart home environment is an issue worthy of attention. Although many scholars have proposed numerous authentication and key agreement (AKA) schemes in the edge computing environment. However, currently, no scholar has proposed a scheme for applying edge computing to the smart home environment.

[0004] Although smart home brings convenience to people's lives, users and smart devices communicate through a public channel. Due to the openness of the public channel, the data transmitted in the public channel may be intercepted and eavesdropped by attackers, resulting in the leakage of user privacy. Therefore, it is crucial to establish secure communication between users and smart devices in the smart home environment. In recent years, many scholars have proposed many authentication and key agreement schemes to solve the above problems. In 2019, Shuai et al. proposed an efficient authentication and key agreement scheme, and used the elliptic curve cryptography mechanism in this scheme. The author showed that the proposed scheme can resist known existing attacks. However, Kaur and Kumar found that the scheme of Shuai et al. cannot resist insider attacks, replay attacks and offline password guessing attacks. Subsequently, Kaur and Kumar proposed a two-factor authentication and key agreement protocol. Unfortunately, Yu et al. pointed out that the protocol of Kaur and Kumar is vulnerable to impersonation attacks and session key leakage attacks, and proposed a secure three-factor authentication and key agreement protocol in the smart home environment. However, Alzahrani et al. found that the protocol of Yu et al. cannot achieve mutual authentication. Although many scholars have proposed many different schemes in the smart home environment, most of the protocols have been attacked and cannot guarantee the secure transmission of information between users and smart devices. Summary of the Invention

[0005] To solve the above problems, the present invention proposes a smart home authentication method based on edge computing, embeds a PUF module in the smart device, and applies edge computing to the authentication scheme of the smart home environment, effectively ensuring the secure transmission of information between users and smart devices.

[0006] The technical solution of the present invention is as follows:

[0007] A smart home authentication method based on edge computing includes four entities: a registration center, an edge gateway, a user, and a smart device; among them,

[0008] The registration center is responsible for the registration of users and smart devices, and stores the registered parameters of users and smart devices in the secure database of the edge gateway;

[0009] The edge gateway is deployed inside the home, collects data from various smart devices, processes the data, and sends the processed data to the users who need the data, serving as a bridge for communication between smart devices and users;

[0010] The user includes the home users who have successfully registered through the registration center. With the help of the edge gateway, they can enjoy the services provided by smart devices and remotely control them anytime and anywhere through mobile devices;

[0011] Intelligent devices, including various intelligent devices in the home, each intelligent device is embedded with a PUF module, in a smart home environment, connected to the edge gateway wirelessly, execute instructions transmitted by the user through the edge gateway, and collect real-time data;

[0012] The smart home authentication method includes three stages, namely the initialization stage, the user registration and intelligent device registration stage, and the user remote access and control intelligent device stage.

[0013] Furthermore, the specific process of the initialization stage is as follows: The registration authority generates a master key x, and each intelligent device is equipped with a unique identity identifier SMID j .

[0014] Furthermore, the user registration and intelligent device registration stage is further divided into two sub-stages, namely the user registration stage and the intelligent device registration stage; among them,

[0015] The user registration stage includes the following steps:

[0016] Step 2.1.1: The user first selects his / her user identity UID i and user password UPW i , then selects a random number a i , and then calculates the temporary identity PID i =h(UID i ||a i ), and sends {PID i ,UPW i ,a i} to the registration authority TTP in an indexed manner; where h(·) represents a one-way hash function, and || represents concatenation;

[0017] Step 2.1.2: After receiving the user's request message, TTP first retrieves PID i from its own database; if PID i can be retrieved, then TTP will reject the user's request; otherwise, TTP calculates the hash value X UT and the exclusive OR value R1, and the calculation formulas are as follows,

[0018] X UT =h(PID i ||a i ||x) (1)

[0019]

[0020] where, represents the exclusive OR operation;

[0021] Then, PID iStored in its own database, and store {PID i ,X UT} in the security database of the edge gateway in an indexed manner;

[0022] Finally, send R1 to the user;

[0023] Step 2.1.3: The user calculates the XOR value A1 and the verification value V i , and the calculation formula is as follows,

[0024]

[0025] V i = h(PID i ||UPW i ||a i ) (4)

[0026] And store {A1, R1, V i} in its own mobile device;

[0027] The intelligent device registration phase includes the following steps:

[0028] Step 2.2.1: The intelligent device selects its own intelligent device identity SMID j , generates a challenge and sets it as C j , calculates the response value R j and corrects the error, and sends {SMID j , C j , δ j} to the registration authority TTP in an indexed manner; The response value R j and the error correction calculation formula are as follows,

[0029] R j = PUF(C j ) (5)

[0030] Gen(R j ) = (σ j , δ j ) (6)

[0031] Among them, PUF(·) represents the physically unclonable function; Gen(·) represents the probabilistically generated fuzzy extractor, Gen(R j ) represents using the fuzzy extractor to correct the error of the response of the PUF, R j represents the response value corresponding to the challenge of the PUF function, σ j represents the key, and δ j represents the auxiliary data;

[0032] Step 2.2.2: TTP retrieves SMID from the databasej ; If not retrieved in the database, the TTP calculates the hash value X ST , and the calculation formula is as follows,

[0033] X ST = h(SMID j ||x||δ j ) (7)

[0034] Then, store SMID j in the database, and store {SMID j , C j , δ j , X ST} in the security database of the edge gateway in an indexed manner;

[0035] Finally, send X ST to the intelligent device;

[0036] Step 2.2.3. The intelligent device generates a random number b j , calculates the XOR value A2 and the XOR value A3, and the calculation formulas are as follows,

[0037]

[0038]

[0039] Finally, store {A2, A3, b j} in its own memory in an indexed manner.

[0040] Furthermore, the remote access and control phase includes the following steps:

[0041] Step 3.1. The user inputs UID i and UPW i to log in. At this time, calculate the random number a i , the temporary identity PID i and the verification value , and the calculation formulas are as follows,

[0042]

[0043] PID i = h(UID i ||a i ) (11)

[0044]

[0045] Then, verify whether it is equal to V i ; if the verification passes, it proves that the user is a legitimate user and the session continues; otherwise, the session terminates;

[0046] Then the user calculates the XOR value X UT and the pseudo-identity RID i , and the calculation formula is as follows

[0047]

[0048] RID i = h(PID i || a i || X UT ) (14)

[0049] where h(·) represents a one-way hash function

[0050] Then a random number r i , the timestamp T1, and the identity SMID of the intelligent device to be used j are selected, and the XOR value W1, the XOR value W2, and the verification value V UE are calculated. The calculation formula is as follows

[0051]

[0052]

[0053] V UE = h(RID i || X UT || r i || T1) (17)

[0054] Finally, the message M1 = {W1, W2, PID i , V UE , T1} is sent to the edge gateway through the common channel

[0055] Step 3.2: After receiving the user's message, the edge gateway first checks whether the absolute value of the difference between the current timestamp T S and the timestamp T1 is less than the allowed maximum transmission delay ΔT, that is, |T1 - T S | ≤ ΔT, and then matches X i according to PID UT ;

[0056] The edge gateway calculates the XOR value (SMID j || r i ), the user's pseudo-identity RID i and the verification value and verifies whether it is equal to V UE ; The calculation formula is as follows

[0057]

[0058]

[0059]

[0060] If the verification is passed, the edge gateway selects the timestamp T2, and according to SMID j matches {C j , δ j , X ST}, calculates the XOR value W3 and the verification value V ED , and sends the message M2 = {W3, V ED , T2} to the intelligent device; the calculation formula is as follows,

[0061]

[0062] V ED = h(RID i || δ j || X ST || T2) (22)

[0063] Step 3.3: After receiving the message M2, the intelligent device first verifies whether the absolute value of the difference between the current timestamp T S and the timestamp T2 is less than the maximum allowable transmission delay ΔT, that is, |T2 - T S | ≤ ΔT, and then calculates the XOR value X ST , the XOR value δ j , the XOR value (C j || RID i || r i ) and the verification value and verifies whether it is equal to V ED ; the calculation formula is as follows,

[0064]

[0065]

[0066]

[0067]

[0068] If the verification is successful, the intelligent device calculates the key σ j and the pseudo identity PSMID of the intelligent device j , and the calculation formula is as follows,

[0069] σ j = Rep(PUF(C j ), δ j ) (27)

[0070] PSMID j = h(SMID j || σ j || X ST ) (28)

[0071] where Rep(·) is the restoration function, which is used here to restore the key σ that is a private value j ;

[0072] Then, select a random number r j and a timestamp T3, and calculate the session key SK between the intelligent device and the user j , the XOR value W4, and the verification value V DE , and send the message M3 = {W4, V DE , T3} to the edge gateway through the public channel; the calculation formula is as follows

[0073]

[0074]

[0075] V DE = h(PSMID j || r j || δ j || T3) (31)

[0076] Step 3.4. After receiving the message M3, the edge gateway verifies whether the absolute value of the difference between the current timestamp T S and the timestamp T3 is less than the maximum allowed transmission delay ΔT, that is, |T3 - T S | ≤ ΔT, calculates the XOR value (PSMID j || r j ) and the verification value and verifies whether it is equal to V DE ; the calculation formula is as follows

[0077]

[0078]

[0079] If the verification is successful, it proves that the intelligent device SD j is a legal device;

[0080] Then, select a timestamp T4, calculate the XOR value W5 and the verification value V EU , and then send M4 = {W5, V EU , T4} to the user; the calculation formula is as follows

[0081]

[0082] V EU = h(PSMID j ||r j ||RID i ||T3) (35)

[0083] Step 3.5: After receiving message M4, the user verifies whether the absolute value of the difference between the current timestamp T S and timestamp T4 is less than the maximum allowed transmission delay ΔT, i.e., |T4 - T S | ≤ ΔT, calculates the exclusive-or value (PSMID j ||r j ) and the verification value and verifies whether it is equal to V EU ; the calculation formula is as follows,

[0084]

[0085]

[0086] If the verification is successful, calculate the session key SK between the user and the smart device i , the calculation formula is as follows,

[0087]

[0088] The user will use the session key to communicate with the smart device and securely obtain the services provided by the smart device.

[0089] The beneficial technical effects brought by the present invention:

[0090] For the first time, an authentication scheme applying edge computing to the smart home environment is proposed to provide users with real-time access; the edge gateway is a node of edge computing. Applying the edge gateway in the smart home environment can provide real-time computing and storage; data collected between the user's mobile device and the smart device can be locally processed;

[0091] The smart home environment authentication scheme proposed by the present invention has real-time controllability and can also ensure the secure transmission of information between the user and the smart device;

[0092] At the same time, applying the hardware of PUF to resource-constrained smart devices in the smart home environment improves the security of the protocol. BRIEF DESCRIPTION OF THE DRAWINGS

[0093] Figure 1 It is an architecture model diagram of the smart home based on edge computing of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0094] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments:

[0095] PUF (Physical Unclonable Functions) is a function embedded in an integrated circuit. The integrated circuit (IC) takes a bit string as an input called a challenge and generates an output of a random string called a response. For various PUF modules fabricated on the same integrated circuit, no two PUF modules will produce the same response if faced with the same challenge. When someone attempts to change or damage the PUF, the corresponding internal circuit and logic gate delays will be altered. Even if the same challenge is input, the response will be different. This feature indicates that it cannot be eliminated after PUF tampering. Since the digital circuits of intelligent devices will be affected as the external environment changes, the PUF cannot ensure a stable output. To ensure a stable output of the PUF response, a fuzzy extractor is used in the proposed protocol to correct the response of the PUF. Through research and investigation, it is found that many schemes have suffered from intelligent device theft attacks. The PUF technology can identify intelligent devices. Therefore, in the present invention, to increase the security of the scheme, a PUF is configured in the intelligent device of the protocol, which can avoid the problem of user privacy leakage due to intelligent device theft attacks.

[0096] A smart home authentication method based on edge computing constructs an architecture model as shown in Figure 1 Figure. This architecture includes four entities, namely a registration center, an edge gateway, a user, and an intelligent device. The registration center serves as the registration center for home users and intelligent devices. The user and the intelligent device complete authentication with the assistance of the edge gateway and establish a session key to achieve secure communication. The specific descriptions of each entity in the model are as follows:

[0097] 1. Registration center: The registration center is a trusted entity, mainly responsible for the registration of home users and intelligent devices. It also stores some parameters registered by the user and the intelligent device in the secure database of the edge gateway.

[0098] 2. Edge gateway: The edge gateway is a trusted entity deployed inside the home. The edge gateway has strong computing and storage capabilities. It can collect data from various intelligent devices, process the data, and send the processed data to the users who need the data. It also serves as a bridge for communication between intelligent devices and users.

[0099] 3. User: The user refers to a home user who has successfully registered through the registration center. With the help of the edge gateway, the user can enjoy the services provided by intelligent devices and remotely control them at any time through a mobile device.

[0100] 4. Intelligent Devices: Intelligent devices refer to various intelligent devices in the home, such as cameras, smart refrigerators, smart table lamps, smart locks, etc. Each intelligent device is embedded with a PUF module. In a smart home environment, it is wirelessly connected to the edge gateway, executes instructions transmitted by the user through the edge gateway, and can also collect data in real time.

[0101] A smart home authentication method based on edge computing includes three stages: an initialization stage, a user registration and intelligent device registration stage, and a user remote access and control of intelligent devices stage.

[0102] Stage 1: Initialization Stage.

[0103] The registration authority generates a master key x, and each intelligent device is equipped with a unique identity identifier SMID j , and each intelligent device contains a PUF module.

[0104] Stage 2: User registration and intelligent device registration stage, which is essentially divided into two sub-stages: the user registration stage and the intelligent device registration stage.

[0105] Among them, as shown in Table 1, the user registration stage includes the following steps:

[0106] Step 2.1.1: The user first selects their user identity UID i and user password UPW i , then selects a random number a i , and then calculates the temporary identity PID i = h(UID i ||a i ), and sends {PID i ,UPW i ,a i} to the registration authority TTP in an indexed manner; where, h(·) represents a one-way hash function, and || represents concatenation;

[0107] Step 2.1.2: After receiving the user's request message, TTP first retrieves PID i from its own database. If PID i can be retrieved, then TTP will reject the user's request. Otherwise, TTP calculates the hash value X UT and the XOR value R1, and the calculation formulas are as follows,

[0108] X UT = h(PID i ||a i ||x) (1)

[0109]

[0110] Among them, represents the exclusive OR operation; X UT is used as an intermediate variable to calculate R1; R1 is an exclusive OR value that is passed to the user and used to calculate X UT ;

[0111] Then, store the PID i in its own database, and store {PID i , X UT} in the security database of the edge gateway in an indexed manner.

[0112] Finally, send R1 to the user;

[0113] Step 2.1.3. The user calculates the exclusive OR value A1 and the verification value V i , and the calculation formula is as follows,

[0114]

[0115] V i = h(PID i || UPW i || a i ) (4)

[0116] And store {A1, R1, V i} in its own mobile device. Among them, A1 is an exclusive OR value used by the user to calculate the random number a i during the remote control stage, and V i is the verification value for verifying the user's identity.

[0117] Table 1 User registration process

[0118]

[0119] As shown in Table 2, the intelligent device registration stage includes the following steps:

[0120] Step 2.2.1. The intelligent device selects its own intelligent device identity SMID j , generates a challenge and sets it as C j , calculates the response value R j and corrects errors, and sends {SMID j , C j , δ j} to the registration authority TTP in an indexed manner; the response value R j and the error correction calculation formula are as follows,

[0121] R j = PUF(C j ) (5)

[0122] Gen(R j ) = (σ j , δ j ) (6)

[0123] Where PUF(·) represents the Physical Unclonable Function; Gen(·) represents the probabilistically generated fuzzy extractor. Gen(R j ) represents using the fuzzy extractor to correct the response of the PUF, and R j represents the response value corresponding to the PUF function challenge. σ j represents the key, and δ j represents the auxiliary data;

[0124] Step 2.2.2, The TTP retrieves the SMID j from the database. If it is not retrieved from the database, the TTP calculates the hash value X ST , and the calculation formula is as follows,

[0125] X ST = h(SMID j ||x||δ j ) (7)

[0126] Then, store the SMID j in the database, and store {SMID j , C j , δ j , X ST} in the secure database of the edge gateway in an indexed manner.

[0127] Finally, send the X ST to the intelligent device;

[0128] Step 2.2.3, The intelligent device generates a random number b j , and calculates the XOR value A2 and the XOR value A3. The calculation formulas are as follows,

[0129]

[0130]

[0131] Where A2 is used as the XOR value for the intelligent device to calculate the hash value X ST in the remote access and control phase; A3 is used as the XOR value for the intelligent device to calculate the auxiliary data δ j in the remote access and control phase;

[0132] Finally, store {A2, A3, b j} in its own memory in an indexed manner.

[0133] Table 2 Intelligent device registration process

[0134]

[0135] Phase Three: Remote Access and Control Phase. As shown in Table 3, it specifically includes the following steps:

[0136] Step 3.1: The user inputs UID i and UPW i to log in. Since the random number a i is not saved in the user's mobile device as a private value, when the user logs in and uses this value, the private value needs to be recalculated. Therefore, the random number a i , the temporary identity PID i and the verification value are calculated. The calculation formulas are as follows

[0137]

[0138] PID i = h(UID i || a i ) (11)

[0139]

[0140] Then, verify whether it is equal to V i . If the verification passes, it proves that the user is a legitimate user and the session continues; otherwise, the session terminates.

[0141] Then the user calculates the XOR value X UT and the pseudo-identity RID i , and the calculation formulas are as follows

[0142]

[0143] RID i = h(PID i || a i || X UT ) (14)

[0144] where h(·) represents a one-way hash function, and X UT is an XOR value calculated using the XOR value R1 saved in the mobile device;

[0145] Then, a random number r i , a timestamp T1, and the identity SMID of the smart device to be used j are selected to calculate the XOR value W1, the XOR value W2, and the verification value V UE , and the calculation formulas are as follows

[0146]

[0147]

[0148] V UE = h(RID i ||X UT ||r i ||T1) (17)

[0149] Wherein, W1 is an exclusive - OR value used to transmit (SMID j ||r i ); W2 is also an exclusive - OR value used to transmit the user's pseudo - identity RID i ; V UE is the verification value for the edge gateway to verify the authenticity of the user's transmitted message.

[0150] Finally, the message M1 = {W1, W2, PID i , V UE , T1} is sent to the edge gateway through the common channel.

[0151] Step 3.2. After receiving the user's message, the edge gateway first checks whether the absolute value of the difference between the current timestamp T S and the timestamp T1 is less than the maximum allowed transmission delay ΔT, that is, |T1 - T S | ≤ ΔT, and then matches X i according to PID UT .

[0152] The edge gateway calculates the exclusive - OR value (SMID j ||r i ), the user's pseudo - identity RID i and the verification value and verifies whether it is equal to V UE . The calculation formula is as follows,

[0153]

[0154]

[0155]

[0156] If the verification passes, the edge gateway selects the timestamp T2 (a timestamp selected by the intelligent device after the edge gateway verifies the user's transmitted message), matches {C j , δ j , X j} according to SMID ST and calculates the exclusive - OR value W3 and the verification value VED , and send message M2 = {W3, V ED , T2} to the intelligent device. The calculation formula is as follows,

[0157]

[0158] V ED = h(RID i ||δ j ||X ST ||T2) (22)

[0159] Among them, W3 is an exclusive-or value used to transmit (C j ||RID i ||r i ); V ED is the verification value for the intelligent device to verify the authenticity of the message transmitted by the edge gateway.

[0160] Step 3.3. After receiving message M2, the intelligent device first verifies whether the absolute value of the difference between the current timestamp T S and timestamp T2 is less than the maximum allowed transmission delay ΔT, that is, |T2 - T S | ≤ ΔT, and then calculates the exclusive-or value X ST , the exclusive-or value δ j , the exclusive-or value (C j ||RID i ||r i ) and the verification value and verifies whether it is equal to V ED . The calculation formula is as follows,

[0161]

[0162]

[0163]

[0164]

[0165] Among them, is the verification value for the intelligent device to verify the authenticity of the message transmitted by the edge gateway,

[0166] If the verification is successful, the intelligent device calculates the key σ j and the pseudo identity PSMID of the intelligent device j , and the calculation formula is as follows,

[0167] σ j = Rep(PUF(C j ), δ j ) (27)

[0168] PSMID j = h(SMID j || σ j || X ST ) (28)

[0169] where Rep(·) is the reduction function, which is used here to recover the key σ that is a private value j ;

[0170] Then, a random number r j and a timestamp T3 are selected to calculate the session key SK j , the XOR value W4, and the verification value V DE , and the message M3 = {W4, V DE , T3} is sent to the edge gateway through the public channel. The calculation formulas are as follows

[0171]

[0172]

[0173] V DE = h(PSMID j || r j || δ j || T3) (31)

[0174] where W4, as an XOR value, is used to transfer (PSMID j || r j ), and V DE is a verification value used by the edge gateway to verify the authenticity of the message transmitted by the intelligent device

[0175] Step 3.4: After receiving the message M3, the edge gateway verifies whether the absolute value of the difference between the current timestamp T S and the timestamp T3 is less than the maximum allowed transmission delay ΔT, i.e., |T3 - T S | ≤ ΔT, calculates the XOR value (PSMID j || r j ) and the verification value and verifies whether it is equal to V DE . The calculation formulas are as follows

[0176]

[0177]

[0178] where is the verification value used by the edge gateway to verify the authenticity of the message transmitted by the intelligent device;

[0179] If the verification is successful, it proves that the smart device SD j is a legal device.

[0180] Then select the timestamp T4 (the timestamp T4 is a timestamp selected for the message passed to the user after the edge gateway verifies the smart device), calculate the XOR value W5 and the verification value V EU , and then send M4 = {W5, V EU , T4} to the user. The calculation formula is as follows,

[0181]

[0182] V EU = h(PSMID j ||r j ||RID i ||T3) (35)

[0183] Among them, W5, as an XOR value, is used to transmit (PSMID j ||r j ); V EU is a verification value used for the user to verify the authenticity of the message passed by the edge gateway.

[0184] Step 3.5: After receiving the message M4, the user verifies whether the absolute value of the difference between the current timestamp T S and the timestamp T4 is less than the maximum allowable transmission delay ΔT, that is, |T4 - T S | ≤ ΔT, calculate the XOR value (PSMID j ||r j ) and the verification value and verify whether it is equal to V EU . The calculation formula is as follows,

[0185]

[0186]

[0187] Among them, is the verification value for the user to verify the authenticity of the message transmitted by the edge gateway.

[0188] If the verification is successful, calculate the session key SK i between the user and the smart device. The calculation formula is as follows,

[0189]

[0190] The user will use the session key to communicate with the smart device and securely obtain the services provided by the smart device.

[0191] Table 3 Remote Access and Control Phase

[0192]

[0193]

[0194] Of course, the above description is not a limitation of the present invention, and the present invention is not limited to the above examples. Changes, modifications, additions or substitutions made by those skilled in the art within the scope of the essence of the present invention shall also fall within the protection scope of the present invention.

Claims

1. A smart home authentication method based on edge computing, characterized in that, It includes four entities: a registration center, an edge gateway, users, and smart devices; among them, The registration center is responsible for the registration of users and smart devices, and stores the registration parameters of users and smart devices in the security database of the edge gateway; The edge gateway is deployed inside the home, collects data from various smart devices, processes the data, and sends the processed data to users who need the data, serving as a bridge for communication between smart devices and users; Users include home users who have successfully registered through the registration center. With the help of the edge gateway, they can enjoy the services provided by smart devices and remotely control them at any time through mobile devices; Smart devices include various smart devices in the home. Each smart device is embedded with a physically unclonable function (PUF) module. In the smart home environment, it is wirelessly connected to the edge gateway, executes the instructions transmitted by users through the edge gateway, and collects real-time data; This smart home authentication method includes three stages, namely the initialization stage, the user registration and smart device registration stage, and the user remote access and control smart device stage; The specific process of the initialization phase is as follows: The registration authority generates a master key x, and each smart device is equipped with a unique identity SMID j ; The user registration and smart device registration stage is further divided into two sub-stages: the user registration stage and the smart device registration stage; The smart device registration stage includes the following steps: Step 2.2.1, the intelligent device selects its own intelligent device identity SMID j , generates a challenge and sets it as C j , calculates the response value R j and corrects errors, and sends {SMID j , C j , δ j} to the registration authority TTP in an indexed manner; the response value R j and the error correction calculation formula are as follows, R j = PUF(C j ) (5) Gen(R j ) = (σ j , δ j ) (6) Among them, PUF(·) represents a physical unclonable function; Gen(·) represents a probabilistically generated fuzzy extractor, and Gen(R j ) represents using the fuzzy extractor to correct the response of the PUF, where R j represents the response value corresponding to the PUF function challenge, σ j represents the key, and δ j represents the auxiliary data; Step 2.2.2, the TTP retrieves the SMID from the database j ; if it is not retrieved from the database, the TTP calculates the hash value X ST , and the calculation formula is as follows X ST = h(SMID j ||x||δ j ) (7) Among them, h(·) represents a one-way hash function, and || represents concatenation; Then, store the SMID j in the database, and store {SMID j , C j , δ j , X ST} in the security database of the edge gateway in an indexed manner; Finally, send X ST to the smart device; Step 2.2.3, the intelligent device generates a random number b j , calculates the XOR value A2 and the XOR value A3, and the calculation formulas are as follows Finally, store {A2, A3, b j} in its own memory in an indexed manner.

2. The smart home authentication method based on edge computing according to claim 1, wherein The user registration stage includes the following steps: Step 2.1.1: The user first selects their user identity UID i and the user password UPW i , then selects a random number a i , and then calculates the temporary identity PID i = h(UID i || a i ), and sends {PID i , UPW i , a i} to the registration authority TTP in an indexed manner; Step 2.1.2: After receiving the user's request message, TTP first retrieves the PID from its own database i ; if the PID i can be retrieved, then TTP will reject the user's request; otherwise, TTP calculates the hash value X UT and the exclusive-or value R1, and the calculation formulas are as follows X UT = h(PID i || a i || x) (1) Among them, represents an exclusive OR operation; Then, store the PID i in its own database, and store {PID i , X UT} in the security database of the edge gateway in an indexed manner; Finally, send R1 to the user; Step 2.1.3, the user calculates the exclusive OR value A1 and the verification value V i , and the calculation formula is as follows V i = h(PID i ||UPW i ||a i ) (4) and store {A1, R1, V i} in its own mobile device.

3. The smart home authentication method based on edge computing according to claim 2, wherein The remote access and control stage includes the following steps: Step 3.

1. The user inputs UID i and UPW i to log in. At this time, a random number a i , a temporary identity PID i and a verification value V i * are calculated. The calculation formulas are as follows PID i = h(UID i || a i ) (11) Then, verify is equal to V i ; if the verification passes, it proves that the user is a legitimate user and the session continues; otherwise, the session terminates. Then the user calculates the XOR value X UT and the pseudo-identity RID i , and the calculation formula is as follows RID i = h(PID i ||a i ||X UT ) (14) Among them, h(·) represents a one-way hash function; Then select a random number r i , timestamp T1, and the identity SMID of the smart device to be used j , calculate the XOR value W1, the XOR value W2, and the verification value V UE , and the calculation formulas are as follows V UE = h(RID i ||X UT ||r i ||T1) (17) Finally, the message M1 = {W1, W2, PID i , V UE , T1} is sent to the edge gateway; Step 3.2: After receiving the user's message, the edge gateway first checks the current timestamp T S to see if the absolute value of the difference between it and the timestamp t1 is less than the maximum allowed transmission delay ΔT, that is, |T1 - T S | ≤ ΔT, and then matches X according to PID i ; UT ; The edge gateway calculates the exclusive OR value (SMID j ||r i ), the user's pseudo-identity RID i and the verification value and verifies whether it is equal to V UE ; The calculation formula is as follows, If the verification is passed, the edge gateway selects the timestamp T2 and, according to SMID j matches {C j , δ j , X ST}, calculates the exclusive-or value W3 and the verification value V ED , and sends the message M2 = {W3, V ED , T2} to the intelligent device; the calculation formula is as follows V ED = h(RID i ||δ j ||X ST ||T2) (22) Step 3.3: After receiving the message M2, the smart device first verifies the current timestamp T s to check if the absolute value of the difference between the timestamp T2 and the timestamp T is less than the maximum allowed transmission delay ΔT, i.e., |T2 - T S | ≤ ΔT. Then it calculates the XOR values X ST , the XOR value δ j , the XOR value (C j || RID i || r i ) and the verification value and verifies if it is equal to V ED ; the calculation formula is as follows If the verification is successful, the smart device calculates the key σ j and the smart device pseudo-identity PSMID j , and the calculation formula is as follows, σ j = Rep(PUF(C j ), δ j ) (27) PSMID j = h(SMID j ||σ j ||X ST ) (28) Among them, Rep(·) is the restoration function, which is used here to restore the key σ that is the private value j ; Then select a random number r j and timestamp T3, and calculate the session key SK between the intelligent device and the user j , the XOR value W4, and the verification value V DE , and send the message M3 = {W4, V DE , T3} to the edge gateway through the public channel; the calculation formula is as follows V DE = h(PSMID j || r j || δ j || T3) (31) Step 3.

4. After receiving message M3, the edge gateway verifies the current timestamp T S to check if the absolute value of the difference between the timestamp T3 and the timestamp T is less than the maximum allowed transmission delay ΔT, i.e., |T3 - T S | ≤ ΔT, calculates the XOR value (PSMID j ||r j ) and the verification value and verifies whether it is equal to V DE ; the calculation formula is as follows If the verification is successful, it proves that the smart device SD j is a legal device; Then select the timestamp T4, calculate the XOR value W5 and the verification value V EU , and then set M4 = {W5, V EU , T4} and send it to the user; the calculation formula is as follows V EU = h(PSMID j ||r j ||RID i ||T3) (35) Step 3.

5. After receiving message M4, the user verifies the current timestamp T S to see if the absolute value of the difference between it and timestamp T4 is less than the maximum allowed transmission delay ΔT, i.e., |T4 - T S | ≤ ΔT. Calculate the XOR value (PSMID j ||r j ) and the verification value and verify whether it is equal to V EU ; the calculation formula is as follows If the verification is successful, calculate the session key SK between the user and the intelligent device i , and the calculation formula is as follows: Users will communicate with smart devices using the session key to securely obtain the services provided by smart devices.

Citation Information

Patent Citations

  • Data processing method and electronic equipment

    CN111565218A

  • Smart home equipment batch authentication method, computing equipment and storable medium

    CN113872761A