Communication authentication method and apparatus, electronic device, and storage medium

By using wavelet analysis and classification models to extract hardware features for authentication in communication systems, the problems of unauthorized access and quantum computing threats are solved, achieving highly secure and compatible communication authentication.

CN115834117BActive Publication Date: 2026-04-21BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING UNIV OF POSTS & TELECOMM
Filing Date
2022-10-11
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing communication systems, unauthorized access to devices and spoofing attacks threaten communication security, and authentication methods based on mathematical complexity are vulnerable to quantum computing cracking, while designing specialized chips is costly.

Method used

By utilizing the authentication terminal in the communication system to extract hardware features of the sending and receiving ends through wavelet analysis, a pre-trained classification model is used for classification authentication, and authentication messages are generated for random number comparison to ensure identity verification at the communication end.

Benefits of technology

It improves the authentication security and applicability of communication systems, reduces additional equipment requirements, is compatible with existing systems, and ensures authentication accuracy by leveraging the uniqueness of hardware features.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834117B_ABST
    Figure CN115834117B_ABST
Patent Text Reader

Abstract

The application provides a communication authentication method and device, electronic equipment and storage medium. In the authentication end of a communication system, a wavelet analysis is used to extract the hardware features of the physical layer in the sending end and the receiving end, the hardware features in the time domain and the frequency domain can be obtained at the same time, and the accuracy of the hardware feature extraction is ensured. According to the hardware features, the sending end and the receiving end are classified and authenticated, and the inherent and unique characteristics of the hardware features ensure the authentication security of the communication system. The authentication of the sending end and the receiving end is completed by the authentication end, the pressure of other communication nodes is reduced, the authentication process is basically completed in the digital domain, no new equipment needs to be additionally added, the existing communication system is compatible, and the applicability of the communication authentication method is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication security technology, and in particular to a communication authentication method, apparatus, electronic device and storage medium. Background Technology

[0002] In certain communication scenarios with high security requirements, unauthorized access to devices, injection attacks, and spoofing can seriously threaten the security performance of the entire communication system. Therefore, appropriate authentication mechanisms are necessary. To ensure the security of a communication system, it is essential to authenticate both the sender and receiver. Furthermore, secure authentication is a crucial prerequisite for security methods such as key distribution and data encryption.

[0003] Typically, authentication methods used in communication systems are mainly classical cryptographic methods. However, with the development of quantum computing, authentication methods based on mathematical complexity are at risk of being cracked. Therefore, in order to authenticate communication systems at the hardware level, PUF (Physical Unclonable Function) utilizes differences in hardware manufacturing to design chips in communication systems. However, designing dedicated chips is very expensive, so it is not suitable for use in practical communication systems. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a communication authentication method, apparatus, electronic device and storage medium to solve or partially solve the above-mentioned technical problems.

[0005] To achieve the above objectives, a first aspect of this application provides a communication authentication method, the method being applied to a communication system, the communication system including an authentication end, a sending end, and a receiving end, the method comprising:

[0006] The sending end uses the acquired authentication request to send to the authentication end and the receiving end;

[0007] The receiving end generates a confirmation request based on the authentication request and sends the confirmation request to the authentication end.

[0008] The authentication terminal performs wavelet analysis on the authentication request and the confirmation request to obtain the hardware characteristics of the sending end and the receiving end.

[0009] The hardware features are classified using a pre-trained classification model at the authentication terminal to obtain the classification result;

[0010] The authentication terminal is used to obtain the first delay information of the authentication request and the second delay information of the confirmation request;

[0011] The authentication terminal generates an authentication message based on the first delay information, the second delay information, and the classification result, and sends the authentication message to the sending terminal and the receiving terminal.

[0012] The sending end and the receiving end compare the authentication message with a random number based on the authentication request. In response to determining that the comparison result is that the random numbers match, the sending end and the receiving end communicate.

[0013] A second aspect of this application provides a communication authentication device, the device being applied to a communication system, the communication system including an authentication end, a transmitting end, and a receiving end, the device comprising:

[0014] The sending module is configured to use the sending end to send the acquired authentication request to the authentication end and the receiving end;

[0015] The generation module is configured to generate a confirmation request based on the authentication request through the receiving end, and send the confirmation request to the authentication end.

[0016] The wavelet module is configured to perform wavelet analysis on the authentication request and the confirmation request through the authentication terminal to obtain the hardware characteristics of the sending terminal and the receiving terminal.

[0017] The classification module is configured to use the authentication terminal to classify the hardware features using a pre-trained classification model, and obtain a classification result;

[0018] The latency module is configured to use the authentication terminal to obtain first latency information of the authentication request and second latency information of the confirmation request;

[0019] The authentication module is configured to use the authentication end to generate an authentication message based on the first delay information, the second delay information, and the classification result, and send the authentication message to the sending end and the receiving end;

[0020] The comparison module is configured to compare the authentication message with a random number based on the authentication request by the sending end and the receiving end, and to communicate with the sending end in response to determining that the comparison result is that the random numbers are consistent.

[0021] A third aspect of this application provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method described in the first aspect.

[0022] A fourth aspect of this application provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method described in the first aspect.

[0023] As can be seen from the above, the communication authentication method, apparatus, electronic device, and storage medium provided in this application utilize wavelet analysis at the authentication end of the communication system to extract the hardware features of the physical layer in both the transmitting and receiving ends. This allows for the simultaneous acquisition of hardware features in both the time and frequency domains, ensuring the accuracy of hardware feature extraction. Furthermore, the transmitting and receiving ends are classified and authenticated based on these hardware features, leveraging the inherent and unique characteristics of these features to guarantee the authentication security of the communication system. By completing the authentication of both the transmitting and receiving ends at the authentication end, the burden on other communication nodes is reduced. Moreover, the authentication process is primarily completed in the digital domain, eliminating the need for additional equipment and ensuring compatibility with existing communication systems, thus improving the applicability of the communication authentication method. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1a This is a flowchart illustrating the communication authentication method according to an embodiment of this application;

[0026] Figure 1b This is a flowchart illustrating another communication authentication method according to an embodiment of this application;

[0027] Figure 2 This is a schematic diagram of the communication authentication device according to an embodiment of this application;

[0028] Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.

[0030] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0031] As described in the background section, in communication systems, communication equipment (e.g., transmitters, optical fibers, optical receivers) inevitably exhibits manufacturing variability during the production process. In optical transmitters or receivers, this variability primarily stems from components such as chips and lasers fabricated using CMOS (Complementary Metal Oxide Semiconductor) technology. The reasons for this variability include variations in oxide thickness, dopant concentration, edge roughness, and layout. These factors can cause minute variations in the threshold voltage of semiconductor components such as field-effect transistors. Hardware characteristics refer to the differences in the manufacturing of hardware facilities.

[0032] Hardware features can include three characteristics:

[0033] (1) Hardware features uniquely identify a device, and different hardware devices have different hardware features.

[0034] (2) It is impossible to simulate hardware features through mathematical modeling or other means.

[0035] (3) It is impossible to generate the same hardware features by copying the device.

[0036] Because the hardware characteristics of a device are as unique as a person's fingerprint, they are also called "hardware fingerprints".

[0037] like Figure 1a As shown, the method of this embodiment is applied to a communication system, which includes an authentication terminal, a sending terminal, and a receiving terminal. The method of this embodiment includes:

[0038] Step 101: Use the sending end to send the obtained authentication request to the authentication end and the receiving end.

[0039] Before step 101, both the sending and receiving ends need to register with the authentication terminal. During registration, both ends provide their identity information to the authentication terminal, which will be used in subsequent authentication processes. Registration is achieved by sending authentication requests to the authentication terminal, each request carrying its own identifier (such as IP (Internet Protocol) address, MAC (Media Access Control) address, etc.). These authentication requests need to be sent repeatedly. Upon receiving the authentication requests, the authentication terminal not only learns the identity information of the sending and receiving ends but also obtains their hardware characteristic sets.

[0040] In this step, the sender refers to the device that intends to establish a connection with another device, the authentication request refers to the request that can be used to establish a connection, the authenticator refers to the device that can authenticate the device that intends to establish a connection, and the receiver refers to the device that establishes a connection with the sender.

[0041] Specifically, in this embodiment, the preferred authentication request may be an identity identifier ID. A Identity ID of the communication object B Temporary interaction number N used for authentication A and timestamp T A , where N A It is a random number used during authentication and will be discarded afterward. N A Finally, the message returns to the sender to verify its reliability. The timestamp is the system time when the authentication request was sent, ensuring the timeliness of the message at the sender.

[0042] This provides a data foundation for the subsequent authentication end to use wavelet analysis to extract the hardware features of the transmitting end.

[0043] Step 102: The receiving end generates a confirmation request based on the authentication request and sends the confirmation request to the authentication end.

[0044] In this step, the confirmation request refers to a request that can be used to confirm the identity of the sender. In this embodiment, the preferred confirmation request can be the identity identifier ID of the receiver. B Temporary Interaction Number N B and timestamp T B .

[0045] Step 103: Perform wavelet analysis on the authentication request and the confirmation request through the authentication terminal to obtain the hardware characteristics of the sending terminal and the receiving terminal.

[0046] In this step, hardware features refer to the differences in the manufacturing of hardware facilities. In this embodiment, the preferred hardware feature can be the difference data extracted by the authentication end based on the requests sent by both parties to the authentication.

[0047] As the manufacturing processes of chips and other components used in communication equipment in communication systems become increasingly complex and their hardware characteristics become more and more obvious, these hardware characteristics can be extracted as identity information for the sending and receiving ends.

[0048] Furthermore, the computing power of the authentication end in the communication system is constantly improving, enabling it to quickly perform complex mathematical calculations such as convolutional neural networks and wavelet analysis, thereby enhancing the hardware feature extraction capabilities of the authentication end.

[0049] This allows for the simultaneous acquisition of hardware features in both the time and frequency domains, ensuring the accuracy of hardware feature extraction.

[0050] Step 104: Use the pre-trained classification model obtained by the authentication terminal to classify the hardware features and obtain the classification result.

[0051] In this step, the training process of the classification model can be completed when the sender and receiver register at the authentication terminal, and the classification result refers to the sender and receiver that are pre-registered in the authentication terminal.

[0052] Specifically, the classification model maps the input hardware features to the sender and receiver that are pre-registered at the authentication end. For example, the input hardware feature vector can be mapped one-to-one with the identity numbers of the sender and receiver to complete the confirmation of the sender and receiver at the authentication end.

[0053] In this way, the sending and receiving ends are classified and authenticated based on their hardware characteristics, and the inherent and unique characteristics of the hardware features ensure the authentication security of the communication system.

[0054] Step 105: Use the authentication terminal to obtain the first delay information of the authentication request and the second delay information of the confirmation request.

[0055] In this step, the first delay information refers to the time obtained by subtracting the timestamp of the authentication request sent by the sending end from the timestamp of the authentication request received by the authentication end, and the second delay information refers to the time obtained by subtracting the timestamp of the confirmation request sent by the receiving end from the timestamp of the confirmation request received by the authentication end.

[0056] This provides a data foundation for the subsequent generation of authentication messages by the authentication end.

[0057] Step 106: The authentication terminal generates an authentication message based on the first delay information, the second delay information, and the classification result, and sends the authentication message to the sending terminal and the receiving terminal.

[0058] In this step, the authentication message refers to a message that can be used by the sender and receiver to compare random numbers. In this embodiment, the preferred authentication message can be a temporary interaction number f encrypted by the sender and receiver using each other's keys. A (N A ), f B (N B ) and timestamp.

[0059] In this way, authentication of the sender and receiver is completed through the authentication terminal, reducing the pressure on other communication nodes. Moreover, the authentication process is basically completed in the digital domain, without the need to add new equipment, making it compatible with existing communication systems and improving the applicability of the communication authentication method.

[0060] Step 107: The sending end and the receiving end compare the authentication message with a random number according to the authentication request. In response to determining that the comparison result is that the random numbers are consistent, the sending end and the receiving end communicate.

[0061] In this step, the sending and receiving ends forward encrypted temporary interaction numbers to each other. After receiving the encrypted interaction number, the sending and receiving ends decrypt it using a key. They confirm the authentication reliability by comparing their own generated temporary interaction number with the temporary interaction number returned by the authentication center. If they match, the authentication is successful, and the two parties can proceed with subsequent communication.

[0062] The above scheme utilizes wavelet analysis at the authentication end of the communication system to extract the physical layer hardware features of the transmitter and receiver. This allows for the simultaneous acquisition of hardware features in both the time and frequency domains, ensuring the accuracy of feature extraction. Classification and authentication of the transmitter and receiver are then performed based on these hardware features, leveraging their inherent and unique characteristics to guarantee the authentication security of the communication system. Authentication of the transmitter and receiver is completed at the authentication end, reducing the burden on other communication nodes. Furthermore, the authentication process is primarily conducted in the digital domain, requiring no additional equipment and ensuring compatibility with existing communication systems, thus improving the applicability of the communication authentication method.

[0063] In some embodiments, step 103 specifically includes:

[0064] Step 1031: Obtain the first interaction data in the authentication request and the second interaction data in the confirmation request.

[0065] Step 1032: Subtract the second interaction data from the first interaction data to obtain the signal to be analyzed.

[0066] Step 1033: Perform discrete wavelet transform on the signal to be analyzed to obtain the transform result.

[0067] In some embodiments, the discrete wavelet transform is performed according to the following formula:

[0068] {W H1 [n],W L1 [n]}=DWT{f[n]}

[0069] [W Hi [n],W Li [n]]=DWT{W H(i-1) [n]}2≤i≤n

[0070] Where f[n] is the signal to be analyzed, n is the length of the identity identifier in the authentication request, DWT is the discrete wavelet transform symbol, and W H1 [n] represents the first detail component in the transformation result, W L1 [n] is the first approximate component in the transformation result, W Hi [n] represents the second detail component in the transformation result, W Li [n] represents the second approximate component in the transformation result, where i is a positive integer.

[0071] Specifically, the formulas for using DWT (Discrete Wavelet Transformation) and IDWT (Inverse Discrete Wavelet Transformation) are as follows:

[0072] DWT:

[0073] IDWT:

[0074] f(n) is the input discrete signal; W(i,j) represents the wavelet factor of f(n) after DWT; Ψ i,j (n) denotes the wavelet basis, and i and j denote the scaling and time-shifting factors, respectively; For Ψ i,j The dual function of (n); For Ψ i,j The conjugate function of (n). f'(n) represents the reconstructed signal after IDWT. Where W(i,j) can be expressed as:

[0075] W(i,j)=[W L W H ]

[0076] W H Representing detail components or high-frequency components, it can reflect the local details of the signal; W L Representing approximate or low-frequency components, it can reflect the contour of the signal. Further analysis of W is possible. H and WL Perform wavelet transform to achieve multi-level wavelet transform analysis.

[0077] Step 1034: Perform discrete wavelet inverse transform on the transformation result to obtain the reconstructed signal.

[0078] In some embodiments, the inverse discrete wavelet transform is performed according to the following formula:

[0079] f Li =IDWT{W Li [n]}

[0080] f Hi =IDWT{W Hi [n]}

[0081] Among them, f Li f is the third approximate component in the reconstructed signal. Hi The third detail component in the reconstructed signal is IDWT, which is the inverse discrete wavelet transform symbol.

[0082] Step 1035: The reconstructed signals are merged as the hardware feature.

[0083] In some embodiments, the reconstructed signals are merged according to the following formula:

[0084]

[0085] Among them, F j Let j be the hardware feature vector corresponding to the hardware feature, where j is a positive integer and M is the number of hardware feature vectors. The nth third detail component in the reconstructed signal. This refers to the nth third approximation component in the reconstructed signal. The first third detail component in the reconstructed signal, It is the first third approximation component in the reconstructed signal.

[0086] The above scheme utilizes wavelet analysis at the authentication end of the communication system to extract the hardware features of the physical layer in both the transmitting and receiving ends. This allows for the simultaneous acquisition of hardware features in both the time and frequency domains, ensuring the accuracy of hardware feature extraction.

[0087] In some embodiments, the training process of the classification model in step 104 includes:

[0088] Step 1041: Obtain the training set based on the hardware feature vector;

[0089] Step 1042: Construct an initial classification model using a neural network, wherein the output of the initial classification model is the identity identifier of the sending end;

[0090] Step 1043: Train the initial classification model based on the training set to obtain the classification model.

[0091] In the above scheme, during the registration phase of the sending and receiving ends, the authentication end generates multiple feature matrices, each containing M hardware feature vectors. These feature matrices are used as the training set for the classification algorithm. During training, the training samples composed of the feature matrices are used as input to the classification algorithm, and the identification numbers of the sending and receiving ends (which can also be redefined by the authentication center) are used as the output of the classification algorithm. After training, the authentication end can identify the hardware characteristics of the sending and receiving ends.

[0092] Understandably, the initial classification model can also include support vector machines and convolutional neural networks.

[0093] The above scheme classifies and authenticates the sending and receiving ends based on hardware characteristics, and ensures the authentication security of the communication system by utilizing the inherent and unique characteristics of hardware features.

[0094] In some embodiments, step 106 specifically includes:

[0095] Step 1061: Use the authentication terminal to obtain the line latency and processing latency;

[0096] Step 1062: In response to determining that the first delay information is less than the sum of the line delay and the processing delay, and the second delay information is less than the sum of the line delay and the processing delay, the authentication terminal generates the authentication message based on the classification result.

[0097] In the above scheme, the timeliness of the first and second delay information can be verified using the following formula:

[0098] |t A -T A |<Δt1+Δt2

[0099] |t B -T A |<Δt1+Δt2,

[0100] Where Δt1 represents the line delay, Δt2 represents the processing delay, and t A ,t B These represent the times when the authentication end receives the authentication request from the sending end and the receiving end, respectively.

[0101] The above scheme can provide a basis for identifying replay attacks at the authentication end.

[0102] It should be noted that the method in this embodiment can be executed by a single device, such as a computer or server. The method can also be applied in a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method in this embodiment, and the multiple devices will interact with each other to complete the method described.

[0103] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0104] Based on the same inventive concept, and on the basis of the corresponding implementation schemes of the above-mentioned embodiments, the following specific implementations are possible.

[0105] The communication authentication method in this embodiment mainly consists of two stages:

[0106] Phase 1: Registration Phase

[0107] Before a user's (corresponding to the sender or receiver in this embodiment) device is put into use, it needs to provide its identity information to the authentication center (corresponding to the authentication terminal in this embodiment). This identity information will be used in the subsequent authentication process. Registration is done by the user sending an authentication request to the authentication center, which carries its own identity identifier (such as IP address, MAC address, etc.). The authentication request needs to be sent repeatedly. Upon receiving the authentication request, the authentication center, while knowing the user's identity information, also obtains the user's hardware feature set {F}. i The hardware feature set consists of M feature matrices, where feature matrix F i It is an m×2n matrix, where m represents the length of the column vectors and n represents the length of the multi-level wavelet transform, where F j It is F i One of the vectors (corresponding to the hardware feature vector in the embodiments of this application). F i The construction method is as follows:

[0108] (1) The party requesting authentication sends a sequence known to both parties, such as IP address, MAC address, etc. T [n] (corresponding to the second interactive data in the embodiments of this application). The authentication center will receive the signal S R[n] (corresponding to the first interactive data in this application embodiment) minus the sent signal S T [n] is obtained by removing the influence of carried information on feature extraction.

[0109] f[n]=S R [n]-S T [n]

[0110] (2) Perform n-level discrete wavelet transform on f[n].

[0111] [W H1 W L1 ]=DWT{f[n]}

[0112] [W Hi [n],W Li [n]]=DWT{W H(i-1) [n]}2≤i≤n

[0113] (3) Perform discrete wavelet inverse transform on the above results to obtain 2n reconstructed signals.

[0114] f Li =IDWT{W Li [n]}

[0115] f Hi =IDWT{W Hi [n]}

[0116] (4) The reconstructed signal is used to form a feature vector F representing the hardware features. j .

[0117]

[0118] After generating M feature matrices, the authentication center uses them as training samples for the classification algorithm. During training, the training samples composed of the feature matrices are used as input to the classification algorithm, and the sender's identification number (which can also be redefined by the authentication center) is used as the output. After training, the authentication center can identify the hardware characteristics of the user device, completing the registration phase. Common classification algorithms include support vector machines and convolutional neural networks.

[0119] Phase Two: Certification Phase

[0120] After completing the registration phase, the user equipment can be used in the actual communication system. Assuming that all devices in the communication system remain synchronized, this embodiment provides an authentication method, the flowchart of which is as follows. Figure 1b As shown. The authentication method mainly consists of four steps:

[0121] (1) User Alice (corresponding to the sender in this embodiment) wants to establish communication with Bob (corresponding to the receiver in this embodiment) and broadcasts an authentication request message to the authentication center AS (corresponding to the authentication end in this embodiment) and Bob. The authentication request includes Alice's identity ID. A Identity ID of the communication object B Temporary interaction number N used for authentication A and timestamp T A In this embodiment, the temporary interaction number is a random number that is only used during authentication and is discarded after use. The temporary interaction number N... A Finally, the message returns to Alice, confirming its reliability. The timestamp is the system time at the time the message was sent, ensuring its timeliness.

[0122] (2) When user Bob receives Alice's authentication request, Bob learns Alice's identity identifier from the request. Bob sends a confirmation request message (corresponding to the confirmation request in this embodiment) to the authentication center, that is, requests the authentication center to confirm Alice's identity. The message includes Bob's identity identifier ID. B Temporary Interaction Number N B and timestamp T B .

[0123] (3) At this point, the authentication center receives messages from Alice and Bob, and can process the received messages (N) A N B We performed wavelet analysis to extract the hardware feature information of Alice and Bob, used a pre-trained classification algorithm for verification, and simultaneously used the following formula to verify the timeliness of the timestamps:

[0124] |t A -T A |<Δt1+Δt2

[0125] |t B -T A |<Δt1+Δt2

[0126] Δt1 represents the line delay, Δt2 represents the processing delay, and t A ,t B These represent the times when the authentication center received the authentication requests from Alice and Bob, respectively. Timeliness verification is required in subsequent processes. If both verifications pass simultaneously, an authentication success message is sent to both Alice and Bob. This message includes a temporary interaction number f encrypted using the other party's key. A (N A ) or f B (N BThe key is agreed upon by the user and the authentication center, along with a timestamp; if authentication fails, an authentication failure message is sent.

[0127] (4) If Alice and Bob receive the authentication success message, they will forward the encrypted temporary interaction number to each other. After receiving the encrypted interaction number, Alice and Bob will decrypt it using the key. They will confirm the authentication reliability by comparing the temporary interaction number they generated with the temporary interaction number returned by the authentication center. If they match, the authentication is successful and the two parties can communicate subsequently.

[0128] Specifically, three different attack methods can be used to illustrate the security of the communication authentication method in this embodiment. First, it is assumed that Alice and Bob have completed the registration phase. The number of samples collected by the authentication center, the order of wavelet analysis, the convolutional neural network structure, and the number of iterations can be selected according to the actual situation.

[0129] (1) The authentication initiator was attacked

[0130] An unauthorized party, Eve, attacks Alice, impersonating her to communicate with Bob. Eve sends an authentication request to Bob, and simultaneously, Eve must also send an authentication request to the authentication center. The authentication center, upon receiving authentication requests from both parties, begins authentication and returns a result. Bob will only communicate with Alice after receiving a successful authentication message from the authentication center. When the authentication center receives the spoofed information from Eve, although it can forge an identity, the hardware characteristics of Eve and Alice are different, so the authentication center will detect it, determine that Alice has been subjected to an impersonation attack, and return an authentication failure message.

[0131] (2) The authentication object was attacked

[0132] When Bob is attacked by Eve, Eve will impersonate Bob and accept Alice's authentication request. When Eve sends a confirmation request message to the authentication center, it will also be detected by the authentication center due to the different hardware characteristics, and an authentication failure message will be returned.

[0133] (3) The certification center was subjected to a replay attack.

[0134] In real-world systems, authentication centers are typically large servers with robust maintenance measures. Therefore, we will not consider Eve's spoofing attacks on the authentication center, but only replay attacks. This means Eve intercepts messages sent from the authentication center to Alice, extracts their content, and then forwards them to Alice. When the authentication center completes the authentication of Alice and Bob and returns a success message to Alice, this message is intercepted by Eve, analyzed, and then sent back to Alice. When Alice receives the duplicate message, she compares the received temporary interaction number with the timestamp. If the temporary interaction number is inconsistent or exceeds the time range, she believes the authentication center has been subjected to a replay attack.

[0135] The communication authentication method described above has the same beneficial effects as the communication authentication method embodiments described in any of the foregoing embodiments, and will not be repeated here.

[0136] Based on the same inventive concept, corresponding to any of the above embodiments, this application also provides a communication authentication device.

[0137] refer to Figure 2 The communication authentication device is applied to a communication system, which includes an authentication terminal, a transmitting terminal, and a receiving terminal. The device includes:

[0138] The sending module 201 is configured to use the sending end to send the acquired authentication request to the authentication end and the receiving end;

[0139] The generation module 202 is configured to generate a confirmation request based on the authentication request through the receiving end, and send the confirmation request to the authentication end;

[0140] Wavelet module 203 is configured to perform wavelet analysis on the authentication request and the confirmation request through the authentication terminal to obtain the hardware characteristics of the sending terminal and the receiving terminal.

[0141] The classification module 204 is configured to use the authentication terminal to classify the hardware features using a pre-trained classification model to obtain a classification result;

[0142] The delay module 205 is configured to use the authentication terminal to obtain first delay information of the authentication request and second delay information of the confirmation request;

[0143] The authentication module 206 is configured to use the authentication end to generate an authentication message based on the first delay information, the second delay information and the classification result, and send the authentication message to the sending end and the receiving end;

[0144] The comparison module 207 is configured to compare the authentication message with a random number based on the authentication request by the sending end and the receiving end, and to communicate with the sending end in response to determining that the comparison result is that the random numbers are consistent.

[0145] In some embodiments, the wavelet module 203 specifically includes:

[0146] The acquisition unit is configured to acquire the first interaction data in the authentication request and the second interaction data in the confirmation request;

[0147] The signal unit is configured to subtract the second interaction data from the first interaction data to obtain the signal to be analyzed.

[0148] The transformation unit is configured to perform discrete wavelet transform on the signal to be analyzed to obtain the transformation result;

[0149] The reconstruction unit is configured to perform a discrete wavelet inverse transform on the transformation result to obtain a reconstructed signal;

[0150] The merging unit is configured to merge the reconstructed signals as the hardware feature.

[0151] In some embodiments, the transformation unit is specifically configured as follows:

[0152] Perform the discrete wavelet transform according to the following formula:

[0153] {W H1 [n],W L1 [n]}=DWT{f[n]}

[0154] [W Hi [n],W Li [n]]=DWT{W H(i-1) [n]}2≤i≤n

[0155] Where f[n] is the signal to be analyzed, n is the length of the identity identifier in the authentication request, DWT is the discrete wavelet transform symbol, and W H1 [n] represents the first detail component in the transformation result, W L1 [n] is the first approximate component in the transformation result, W Hi [n] represents the second detail component in the transformation result, W Li [n] represents the second approximate component in the transformation result, where i is a positive integer.

[0156] In some embodiments, the reconfiguration unit is specifically configured as follows:

[0157] Perform the inverse discrete wavelet transform according to the following formula:

[0158] f Li =IDWT{W Li [n]}

[0159] f Hi =IDWT{W Hi [n]}

[0160] Among them, f Li f is the third approximate component in the reconstructed signal. Hi The third detail component in the reconstructed signal is IDWT, which is the inverse discrete wavelet transform symbol.

[0161] In some embodiments, the merging unit is specifically configured as follows:

[0162]

[0163] Among them, F j Let j be the hardware feature vector corresponding to the hardware feature, where j is a positive integer and M is the number of hardware feature vectors. The nth third detail component in the reconstructed signal. This refers to the nth third approximation component in the reconstructed signal. The first third detail component in the reconstructed signal, It is the first third approximation component in the reconstructed signal.

[0164] In some embodiments, the training process of the classification model in classification module 204 includes:

[0165] The training set is obtained based on the hardware feature vectors;

[0166] An initial classification model is constructed using a neural network, wherein the output of the initial classification model is the identity identifier of the sending end;

[0167] The initial classification model is trained using the training set to obtain the classification model.

[0168] In some embodiments, the authentication module 206 is specifically configured as follows:

[0169] The authentication terminal is used to obtain the line latency and processing latency;

[0170] In response to determining that the first delay information is less than the sum of the line delay and the processing delay, and the second delay information is less than the sum of the line delay and the processing delay, the authentication terminal generates the authentication message based on the classification result.

[0171] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, in implementing this application, the functions of each module can be implemented in one or more software and / or hardware.

[0172] The apparatus of the above embodiments is used to implement the corresponding communication authentication method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0173] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the communication authentication method described in any of the above embodiments.

[0174] Figure 3 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.

[0175] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0176] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0177] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0178] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0179] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.

[0180] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0181] The electronic devices described above are used to implement the corresponding communication authentication methods in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0182] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium that stores computer instructions for causing the computer to execute the communication authentication method as described in any of the above embodiments.

[0183] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0184] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the communication authentication method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0185] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in the details for the sake of brevity.

[0186] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0187] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0188] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.

Claims

1. A communication authentication method characterized by, The method is applied to a communication system, which includes an authentication terminal, a sending terminal, and a receiving terminal. The method includes: The sending end uses the acquired authentication request to send to the authentication end and the receiving end; The receiving end generates a confirmation request based on the authentication request and sends the confirmation request to the authentication end. The authentication terminal performs wavelet analysis on the authentication request and the confirmation request to obtain the hardware characteristics of the sending end and the receiving end. The hardware features are classified using a pre-trained classification model at the authentication terminal to obtain the classification result; The authentication terminal is used to obtain the first delay information of the authentication request and the second delay information of the confirmation request; The authentication terminal generates an authentication message based on the first delay information, the second delay information, and the classification result, and sends the authentication message to the sending terminal and the receiving terminal. The sending end and the receiving end compare the authentication message with random numbers according to the authentication request. In response to determining that the comparison result is that the random numbers match, the sending end and the receiving end communicate. The step of performing wavelet analysis on the authentication request and the confirmation request through the authentication terminal to obtain the hardware characteristics of the sending end and the receiving end includes: Obtain the first interaction data from the authentication request and the second interaction data from the confirmation request; Subtract the second interaction data from the first interaction data to obtain the signal to be analyzed; Perform a discrete wavelet transform on the signal to be analyzed to obtain the transform result; perform an inverse discrete wavelet transform on the transform result to obtain the reconstructed signal; The reconstructed signals are combined as the hardware feature.

2. The method of claim 1, wherein, The step of performing discrete wavelet transform on the signal to be analyzed to obtain the transform result includes: Perform the discrete wavelet transform according to the following formula: wherein is the signal to be analyzed, is the length of the identity identification in the authentication request, is the discrete wavelet transform sign, is the first detail component in the transform result, is the first approximation component in the transform result, is the second detail component in the transform result, is the second approximation component in the transform result, is a positive integer.

3. The method of claim 1, wherein, The step of performing an inverse discrete wavelet transform on the transformed result to obtain the reconstructed signal includes: performing an inverse discrete wavelet transform according to the following formula: wherein is a third approximation component in the reconstructed signal, is a third detail component in the reconstructed signal, IDWT is a discrete wavelet inverse transform symbol.

4. The method of claim 1, wherein, The step of merging the reconstructed signals as the hardware feature includes: The reconstructed signals are merged according to the following formula: in, The hardware feature vector corresponding to the aforementioned hardware feature. It is a positive integer. The number of the hardware feature vectors. The first in the reconstructed signal A third detail component, The first in the reconstructed signal The third approximate component, The first third detail component in the reconstructed signal, It is the first third approximation component in the reconstructed signal.

5. The method of claim 4, wherein, The training process of the classification model includes: The training set is obtained based on the hardware feature vectors; An initial classification model is constructed using a neural network, wherein the output of the initial classification model is the identity identifier of the sending end; The initial classification model is trained using the training set to obtain the classification model.

6. The method of claim 1, wherein, The authentication terminal generates an authentication message based on the first delay information, the second delay information, and the classification result, including: The authentication terminal is used to obtain the line latency and processing latency; In response to determining that the first delay information is less than the sum of the line delay and the processing delay, and the second delay information is less than the sum of the line delay and the processing delay, the authentication terminal generates the authentication message based on the classification result.

7. A communication authentication apparatus characterized by comprising: The device is used in a communication system, which includes an authentication terminal, a transmitting terminal, and a receiving terminal. The device includes: The sending module is configured to use the sending end to send the acquired authentication request to the authentication end and the receiving end; The generation module is configured to generate a confirmation request based on the authentication request through the receiving end, and send the confirmation request to the authentication end. The wavelet module is configured to perform wavelet analysis on the authentication request and the confirmation request through the authentication terminal to obtain the hardware characteristics of the sending terminal and the receiving terminal. The step of performing wavelet analysis on the authentication request and the confirmation request through the authentication terminal to obtain the hardware characteristics of the sending end and the receiving end includes: Obtain the first interaction data from the authentication request and the second interaction data from the confirmation request; Subtract the second interaction data from the first interaction data to obtain the signal to be analyzed; Perform a discrete wavelet transform on the signal to be analyzed to obtain the transform result; perform an inverse discrete wavelet transform on the transform result to obtain the reconstructed signal; The reconstructed signals are combined as the hardware feature; The classification module is configured to use the authentication terminal to classify the hardware features using a pre-trained classification model, and obtain a classification result; The latency module is configured to use the authentication terminal to obtain first latency information of the authentication request and second latency information of the confirmation request; The authentication module is configured to use the authentication end to generate an authentication message based on the first delay information, the second delay information, and the classification result, and send the authentication message to the sending end and the receiving end; The comparison module is configured to compare the authentication message with a random number based on the authentication request by the sending end and the receiving end, and to communicate with the sending end in response to determining that the comparison result is that the random numbers are consistent.

8. An electronic device, comprising: It includes a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor, when executing the computer program, implements the method as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium, comprising: The non-transitory computer-readable storage medium stores computer instructions for causing the computer to perform the method of any one of claims 1 to 6.