A Financial System Identity Authentication Method Based on Elliptic Curves

Through Diffie-Hellman key exchange and elliptic curve password protection, combined with the three-party mutual authentication method, the problems of man-in-the-middle attacks and session key leakage of wireless sensor networks in the financial system are solved, which improves authentication security and reduces resource overhead.

CN116015699BActive Publication Date: 2025-07-18HANGZHOU NORMAL UNIVERSITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111231595.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-22
Publication Date
2025-07-18
Estimated Expiration
2041-10-22

AI Technical Summary

Technical Problem

The existing wireless sensor network authentication methods are difficult to effectively resist man-in-the-middle attacks, offline password guessing attacks, and session key leakage attacks in financial systems, and the overhead of computing and communication resources is relatively large.

Method used

The Diffie-Hellman key exchange and the introduction of elliptic curve cipher are used to encrypt and protect the key parameters in the authentication process, and the session key is encrypted through the mutual authentication of three parties and independently generated parameters to reduce the operating pressure of the device.

Benefits of technology

Improves the security of the financial system authentication process, resists offline password guessing attacks and session key leakage attacks, and reduces the overhead of the device's computing and communication resource.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015699B_ABST
    Figure CN116015699B_ABST
Patent Text Reader

Abstract

The present invention discloses an identity authentication method for a financial system based on elliptic curves. The identity authentication method is applied in a financial system. This method provides an authentication method for mutual authentication and key verification among a user device, a gateway, and a wireless device carrying the financial system. By introducing elliptic curves to perform encryption operations on key parameters in the authentication process, the security of the entire authentication process is improved, and at the same time, the computing pressure on the wireless device is reduced. Through this identity authentication method, the present invention can effectively resist offline password guessing attacks, session key leakage attacks, and man-in-the-middle attacks, making the entire authentication process safe and efficient, and having high application value especially in the financial management scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an identity authentication method for a financial system based on elliptic curves. Background Art

[0002] In recent years, with the rapid development of the Internet of Things, wireless sensor networks have been widely used in medical, military, agricultural and other fields. In a complex environment, each device transmits information through a distributed wireless sensor device network. Therefore, the authentication method based on wireless sensor networks plays an important role in secure transmission.

[0003] Compared with some common encryption algorithms, the elliptic curve cryptosystem has the advantages of short key, high strength, few parameters, fast digital signature, and small amount of calculated data, and is especially suitable for devices with limited computing resources and storage resources. Therefore, the elliptic curve cryptosystem is gradually applied to wireless communication security protocols.

[0004] Patent document CN111130758A discloses a lightweight anonymous authentication method suitable for resource-constrained devices. The method is implemented by using an information system model, and the information system model includes three entities: a network management center, a constrained device, and an information center. The identity is verified through a two-way authentication method. At the same time, only one elliptic curve point multiplication operation needs to be performed at the authentication end. Compared with traditional algorithms, the overhead of computing resources and communication resources is further reduced while ensuring security. However, this authentication method cannot well solve the man-in-the-middle attack problem.

[0005] Academic literature "A novel user authentication and key agreement scheme for heterogeneous ad hoc wireless sensor networks, based on the Internet of Things notion[J]. Ad Hoc Networks, 2014, 20: 96-112" discloses a two-factor authentication scheme based on a hash function, which is applicable to the financial system under wireless sensor networks. However, this method is vulnerable to simulation attacks and session key leakage attacks. Summary of the Invention

[0006] In order to solve the above problems, the present invention proposes an identity authentication method for a financial system based on elliptic curves. This method is applicable to the financial system and uses Diffie-Hellman key exchange and introduces elliptic curve cryptography to encrypt and protect the key parameters in the authentication process, which can resist the problems of offline password guessing attacks and session key leakage attacks, thereby improving the security of the entire authentication process.

[0007] An identity authentication method for a financial system based on elliptic curves, which is applied to the financial system and includes:

[0008] S1 Gateway initialization;

[0009] S2 The user submits a registration request to the gateway through the user device. After the gateway verifies and processes it, it feeds back the registration information to the user device and stores it in the smart card;

[0010] S3 The user submits a login request to the gateway through the user device;

[0011] S4 When the user device, the gateway, and the wireless device complete authentication with each other, a session key SK for the user device and the wireless device is negotiated u .

[0012] Preferably, the gateway initialization is as follows: The gateway selects an elliptic curve E(GF q ) function and selects a base point P on the elliptic curve; then a gateway key K GWN is selected and secretly stored in the gateway. The gateway calculates the public key PK q =K G ·P through the elliptic curve E(GF GWN ), and finally publishes the parameters {E(GF q ), P, PK G}.

[0013] Preferably, the specific steps of S2 are as follows:

[0014] S2.1 After the user inserts the smart card into the card reader, the user sends the identity ID i to the gateway through the user device;

[0015] S2.2 After the gateway receives and verifies the legitimacy of the received identity ID i , it calculates the secret value a i between the user device and the gateway and sends it to the user device. Then the user inputs the personal password PW i . The user device calculates the login verification parameter MPW i based on the user's identity ID i and the password PW i , and finally stores the registration information {MPW i , F i} in the smart card, where F i is used to hide the secret value a i ;

[0016] S2.3 The gateway selects an identity SID for the wireless device carrying the financial systemj , and calculate the secret value b between the wireless device and the gateway j , and store it in the node of the wireless device; meanwhile, the gateway discloses the identity SID of the wireless device j .

[0017] Preferably, the authentication in S4 is a three-way mutual authentication and key negotiation among the user device, the gateway, and the wireless device.

[0018] Preferably, the specific steps of the three-way mutual authentication and key negotiation are as follows:

[0019] S4.1 The user inserts the smart card into the card reader. After passing the identity authentication, the user device generates a random number m i and the current timestamp T1, and calculates E1 through the elliptic curve E(GF q ) function. At the same time, calculates E2 and verification parameter E3 for hiding ID i and SID j , and sends the message MES1{E1, E2, E3, T1} to the gateway;

[0020] S4.2 After receiving the message MES1, the gateway verifies the legitimacy of the timestamp T1 and the verification parameter E3 in the message MES1. If it is not legitimate, the authentication process is terminated; if it is legitimate, the gateway authentication is successful;

[0021] S4.3 After the gateway authentication is successful, generate the current timestamp T2, calculate the gateway identifier K i , and calculate the verification parameter N2, and send the message MES2{E1, N1, N2, T2} to the wireless device, where N1 is used to hide the gateway identifier K i ;

[0022] S4.4 After the wireless device receives the message MES2, it verifies the legitimacy of the timestamp T2 and the verification parameter N2 in the message MES2. If it is not legitimate, the authentication process is terminated; if it is legitimate, the wireless device authentication is successful;

[0023] S4.5 After the wireless device authentication is successful, generate a random number c j and the current timestamp T3, calculate N3 through the elliptic curve E(GF q ) function, negotiate the session key SK u , and calculate the verification parameter N4, and send the message MES3{N3, N4, T3} to the gateway;

[0024] After the S4.6 gateway receives the message MES3, it verifies the legality of the timestamp T3 and the verification parameter N4 in the message MES3. If it is illegal, the authentication process is terminated; if it is legal, the gateway verification is successful;

[0025] After the S4.7 gateway verification is successful, it generates the current timestamp T4, calculates the verification parameter N6, and sends the message MES4{N3, N5, N6, T3, T4} to the user device, where N5 is used to hide the gateway identifier K i ;

[0026] After the S4.8 user device receives the message MES4, it verifies the legality of the timestamp T4 and the verification parameter N6 in the message MES4. If it is illegal, the authentication process is terminated; if it is legal, a session key SK is successfully established among the user device, the gateway, and the wireless device u 。

[0027] Preferably, the verification parameter and the session key SK u are both encrypted and calculated through the elliptic curve E(GF q ) function selected by the gateway, reducing the computing pressure among devices.

[0028] Preferably, the session key SK u is encrypted by mixing the random number m i , the random number c j , the gateway identifier K i and the timestamp T3. The random number m i is only generated in the user device, the random number c j and the timestamp T3 are only generated in the wireless device, and the gateway identifier K i is only generated in the gateway. The generation time of all parameters is different from the device, thus enhancing the security of the session key SK u .

[0029] Preferably, the method for verifying the timestamp is specifically |T′ n -T n |≤ΔT, where T n is the timestamp included in the message sent in the previous stage, T′ n is the current timestamp obtained by the device when receiving the message, and ΔT is the threshold time allowed in the preset communication process. When the time difference is greater than the threshold time, the authentication is terminated; when the time difference is less than the threshold time, the next step is performed.

[0030] Preferably, the messages MES1, MES2, MES3, and MES4 are all transmitted in the common channel. During the transmission process, the identity ID i of the user device and the gateway identifier K iHidden encryption is performed through a one-way hash function and the XOR logical algorithm, so that the key parameters cannot be directly obtained in the public channel.

[0031] Compared with the prior art, the beneficial effects of the present invention are as follows: The Diffie-Hellman key exchange and the introduction of elliptic curve cryptography are used to encrypt and protect the key parameters in the authentication process. At the same time, a three-party mutual authentication method is adopted, and the session key SK u is encrypted by an independently generated parameter to resist the problems of offline password guessing attacks and session key leakage attacks, thereby improving the security of the entire authentication process. Brief Description of the Drawings

[0032] Figure 1 It is a relationship diagram among the user equipment, the gateway and the wireless device;

[0033] Figure 2 It is a flowchart of the identity authentication method for the financial system based on elliptic curves designed by the present invention;

[0034] Figure 3 It is a schematic diagram of three-party mutual authentication and key verification among the user equipment, the gateway and the wireless device. Detailed Embodiment

[0035] As Figure 1 shown, the present invention is an identity authentication method for a financial system based on elliptic curves, including three entities: a user equipment, a gateway, and a wireless device carrying a financial system. Among them, the nodes of the wireless sensor can collect and store information, and the wireless device can be connected to the Internet through a trusted gateway. Therefore, the user can access the information stored in the wireless sensor node through the Internet. During the access process, the user equipment, the gateway, and the wireless device perform three-party mutual authentication to generate a session key for communication.

[0036] As Figure 2 shown, an identity authentication method for a financial system based on elliptic curves, which is applied to the financial system, includes:

[0037] S1 Gateway initialization: The gateway selects an elliptic curve E(GF q ) function, and selects a base point P on the elliptic curve; then selects a gateway key K GWN and secretly stores it in the gateway. The gateway calculates the public key PK q through the elliptic curve E(GF G =K GWN ·P, and finally publishes the parameters {E(GF q ), P, PK G};

[0038] In S2, the user submits a registration request to the gateway through the user device. After the gateway performs verification processing, it feeds back the registration information to the user device and stores it in the smart card.

[0039] In S3, the user submits a login request to the gateway through the user device.

[0040] In S4, after the user device, the gateway, and the wireless device complete mutual authentication, a session key SK for the user device and the wireless device is negotiated. u 。

[0041] Among them, the specific steps in S2 are as follows:

[0042] In S2.1, after the user inserts the smart card into the card reader, the user sends the identity ID through the user device i to the gateway.

[0043] In S2.2, after the gateway receives and verifies the legitimacy of the received identity ID i , it obtains the secret value a between the user device and the gateway through calculation i = h(ID i ||K GWN ) and sends it to the user device. Then the user inputs the personal password PW i . The user device calculates the login verification parameter MPW i according to the user's identity ID i and the password PW i = h(ID i ||PW i ) to hide the secret value a i 's F i = a i h(PW i ||ID i ). Finally, the registration information {MPW i , F i} is stored in the smart card.

[0044] In S2.3, the gateway selects an identity SID for the wireless device equipped with the financial system j , and calculates the secret value b between the wireless device and the gateway j = h(SID j ||K GWN ), which is stored in the node of the wireless device; at the same time, the gateway sends the identity SID j to the user device and stores it in the smart card.

[0045] As Figure 3 shown, the specific steps for mutual authentication and key verification among the user device, the gateway, and the wireless device are as follows:

[0046] S4.1 The user inserts the smart card into the card reader and enters the identity and the password PW i * , and calculates the comparison login verification parameter When MPW i * is not equal to the MPW stored in the smart card i , the login fails; if they are equal, the login is successful;

[0047] After the user logs in successfully, the user device generates a random number m i and the current timestamp T1, and calculates E1 = m q ·P through the elliptic curve E(GF i ), and restores the secret value between the gateway and the user device from the registration information At the same time, calculates the i for hiding the ID j and the SID and the verification parameter Finally, sends the message MES1{E1, E2, E3, T1} to the gateway;

[0048] S4.2 After the gateway receives the message MES1, it generates the current timestamp T′1, and makes a determination based on |T′1 - T1| ≤ ΔT. If it does not hold, the authentication process is terminated; if it holds, it restores from M2, and then calculates and the comparison verification information If is not equal to E3 in the message MES1, the authentication process is terminated; if they are equal, the authentication is successful;

[0049] S4.3 After the gateway authentication is successful, it generates the current timestamp T2, and calculates the gateway identifier using the timeliness feature of the timestamp T, so that the gateway identifier K i also has the characteristics of timeliness and cannot be guessed. The secret value between the gateway and the wireless device Finally, calculates the i for hiding the gateway identifier K and the verification parameter Sends the message MES2{E1, N1, N2, T2} to the wireless device;

[0050] S4.4 After the wireless device receives the message MES2, it generates the current timestamp T′2, and makes a determination based on |T′2 - T2| ≤ ΔT. If it does not hold, the authentication process is terminated; if it holds, it restores the gateway identifier from N1 And calculate the comparison and verification parameters If is not equal to N2 in the information MES2, the authentication process is terminated; if they are equal, the wireless device authentication is successful;

[0051] After the wireless device authentication in S4.5 is successful, generate a random number c j and the current timestamp T3, and calculate N3 = c q ·P through the elliptic curve E(GF j ) function to negotiate the session key And calculate the verification parameters Send the information MES3{N3, N4, T3} to the gateway;

[0052] After the gateway receives the information MES3 in S4.6, generate the current timestamp T′3, and make a determination according to |T′3 - T3| ≤ ΔT. If it does not hold, the authentication process is terminated; if it holds, calculate the comparison and verification parameters If is not equal to N4 in the information MES3, the authentication process is terminated; if they are equal, the authentication is successful.

[0053] After the wireless device authentication in S4.7 is successful, generate the current timestamp T4, and calculate the K used to hide the gateway identifier i of and the verification parameters And send the information MES4{N3, N5, N6, T3, T4} to the user device;

[0054] After the user device receives the information MES4 in S4.8, generate the current timestamp T′4, and make a determination according to |T′4 - T4| ≤ ΔT. If it does not hold, the authentication process is terminated; if it holds, recover the gateway identifier from N5 and calculate the comparison and verification parameters If is not equal to N6 in the information MES4, the authentication process is terminated; if they are equal, the session key is negotiated

[0055] In the above steps, the parameters with * are all information contents that may be stolen or imitated by the outside world during the authentication process.

Claims

1. A financial system identity authentication method based on elliptic curves, comprising: S1 Gateway initialization; The user of S2 submits a registration request to the gateway through the user device. After the gateway performs verification processing, it feeds back the registration information to the user device and stores it in the smart card. The gateway is initialized as follows: The gateway selects an elliptic curve E(GF q ) function and selects a base point P on the elliptic curve; then it selects a gateway key K GWN and secretly stores it in the gateway. The gateway calculates the public key PK G through the elliptic curve E(GFx) function. Finally, it publishes the parameters {E(GF q ), P, PK G}; S3 The user submits a login request to the gateway through the user device; S4 After the user device, the gateway, and the wireless device complete authentication with each other, a session key SK for the user device and the wireless device is negotiated. u , The authentication is based on mutual authentication and key verification among the user device, the gateway, and the wireless device. The specific steps are as follows: S4.1 The user inserts the smart card into the card reader. After passing the identity authentication, the user device generates the current timestamp T1 and calculates the verification parameter based on the registration information in the smart card, and sends the information MES1 to the gateway; S4.2 After receiving the information MES1, the gateway verifies the legitimacy of the timestamp T1 and the verification parameter in the information MES1. If it is not legitimate, the authentication process is terminated; If it is legitimate, the gateway authentication is successful; S4.3 After the gateway authentication is successful, it generates the current timestamp T2 and calculates the verification parameter, and sends the information MES2 to the wireless device; S4.4 The wireless device receives the information MES2 and verifies the legitimacy of the timestamp T2 and the verification parameter in the information MES2. If it is not legitimate, the authentication process is terminated; If it is legitimate, the wireless device authentication is successful; After the S4.5 wireless device authentication is successful, generate the current timestamp T3 and the session key SK u , and calculate the verification parameter, and send the message MES3 to the gateway; S4.6 After the gateway receives the information MES3, it verifies the legitimacy of the timestamp T3 and the verification parameter in the information MES3. If it is not legitimate, the authentication process is terminated; If it is legitimate, the gateway verification is successful; S4.7 After the gateway verification is successful, it generates the current timestamp T4 and calculates the verification parameter, and sends the information MES4 to the user device; After the user equipment receives the message MES4, it verifies the legitimacy of the timestamp T4 and the verification parameters in the message MES4. If it is illegal, the authentication process is terminated; if it is legal, a session key SK is successfully established among the user equipment, the gateway, and the wireless device u , the session key SK u is encrypted by mixing with the random number m i , the random number c j , the gateway identifier K i and the timestamp T3. The random number m i is only generated in the user equipment, and the random number c j and the timestamp T3 are only generated in the wireless device. The gateway identifier K i is only generated in the gateway; The information MES1, information MES2, information MES3, and information MES4 are all transmitted in a common channel. During the transmission process, the identity ID of the user equipment i and the gateway identifier K i are hidden through a one-way hash function and an XOR logical algorithm.

2. The identity authentication method for a financial system based on an elliptic curve according to claim 1, wherein The specific steps of the said S2: S2.1 After the user inserts the smart card into the card reader, the user sends the identity ID i to the gateway through the user device; S2.2 The gateway receives and verifies the legitimacy of the authentication identity ID i After that, the secret value a between the user device and the gateway is obtained through calculation i , and the registration information is sent to the user device and stored in the smart card; S2.3 The gateway selects an identity SID for the wireless device equipped with the financial system j , and calculates the secret value b between the wireless device and the gateway j , which is stored in the node of the wireless device; meanwhile, the gateway sends the identity SID j to the user device and stores it in the smart card.

3. The identity authentication method of the financial system based on elliptic curve according to claim 1, wherein The method for verifying the timestamp is specifically |T' n -T n | ≤ ΔT, where T n is the timestamp included in the information sent in the previous stage, and T' n is the current timestamp obtained by the device when the information is received. ΔT is the threshold time allowed in the preset communication process. When the time difference is greater than the threshold time, the authentication is terminated; When the time difference is less than the threshold time, the next step is carried out.

4. The identity authentication method for a financial system based on an elliptic curve according to claim 1, characterized in that The verification parameter and the session key SK u are both encrypted and calculated through the elliptic curve E(GF q ) function selected by the gateway.

Citation Information

Patent Citations

  • Lightweight anonymous authentication method suitable for resource-limited equipment

    CN111130758A