A method for group key agreement in a digital twin network

By employing elliptic curve cryptography and a group key negotiation method based on the family of sibling intractable functions, the problems of synchronization, authentication, and confidentiality in digital twin network communication are solved, achieving secure and efficient communication.

CN116192381BActive Publication Date: 2026-05-19CHANGAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHANGAN UNIV
Filing Date
2023-02-28
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing technologies cannot simultaneously guarantee the synchronization, authentication, and confidentiality of digital twin network communications, resulting in security and privacy issues.

Method used

By employing elliptic curve cryptography, self-certified keys, and a family of sibling intractable functions, system parameters and keys are generated through a control center to achieve group key negotiation and synchronization among multiple digital twins, ensuring the security and privacy of communication.

Benefits of technology

It enables secure communication between multiple digital twins, satisfies the indistinguishability under chosen-plaintext attacks, ensures synchronization, confidentiality, and authentication, and provides a secure and efficient communication solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192381B_ABST
    Figure CN116192381B_ABST
Patent Text Reader

Abstract

The application discloses a kind of group key agreement methods of synchronization in digital twin network, based on elliptic curve cryptography, self-authentication key, sibling intractable function family, it is proposed that group key agreement scheme of synchronization in digital twin network, first, control center completes the initialization of system, generates system parameter, and deploys digital twin generation key;Then multiple digital twins carry out synchronous group key agreement and group key generation, finally, multiple digital twins utilize group key and carry out safe data transmission.In addition, digital twin can choose to dynamically leave or join group key agreement.The application guarantees the synchronism, confidentiality, authentication of multiple digital twin communication, satisfies the indistinguishability of chosen plaintext attack under the random oracle model, achieves higher security while having higher efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of key negotiation technology in digital twin networks, and relates to a synchronous group key negotiation method in digital twin networks. Background Technology

[0002] In 2003, Grieves and other scholars first proposed a preliminary framework for digital twins, including physical targets, virtual targets, and the connections between them. In 2014, Grieves and other scholars proposed a formal definition of digital twin networks, including physical entities, virtual representatives, and bidirectional links. Since 2014, digital twins have been widely applied in various fields, such as intelligent transportation systems, the Internet of Things, and smart factories.

[0003] With the increasing prevalence of digital twin networks, potential security and privacy issues have received extensive research. Gehrmann et al. proposed a security architecture based on digital twin networks and emphasized the importance of state synchronization security. Karaarslan et al. focused on studying security threats to digital twin networks, including data modification threats, data communication threats, and data storage threats. Furthermore, Karaarslan et al. considered confidentiality to be the most important security factor in digital twin networks. Holmes et al. discussed the network security issues brought about by digital twin applications, specifically including availability, integrity, and confidentiality. Luan et al. proposed a communication paradigm for digital twin networks, allowing multiple digital twins to collaboratively process data through internal communication. They also argued that state information should be synchronized among multiple digital twins. Li et al. combined RSA-based synchronized aggregation signatures and provable data ownership techniques to achieve secure digital twin network communication; however, their scheme only considered data integrity issues.

[0004] Although the security and privacy issues of digital twin network communication have been extensively studied, there is currently no solution that can simultaneously guarantee the synchronization, authentication, and confidentiality of digital twin network communication. Summary of the Invention

[0005] This invention addresses the security and privacy issues in digital twin network communication by providing a method for synchronous group key negotiation in digital twin networks.

[0006] A method for synchronizing group key negotiation in a digital twin network includes the following steps:

[0007] S1: Input safety parameters, control center Complete system initialization, generate and output system parameters;

[0008] S2: Digital Twin identifier and Send to control center Control Center Computational digital twin The proof information and signature are sent to the digital twin. Digital twin Calculate the private key;

[0009] S3: Digital Twin Send proof information to the control center Control Center Receive and verify; once verification is successful, the current status information is processed. Control Center calculate Solving the problem of obtaining linear sets Control Center calculate Send to digital twin Digital twin After receiving the proof information, verification is performed; once verification is successful, the digital twin is generated. Get The system calculates the proof information and broadcasts it to multiple digital twins. After receiving the proof information, verification is performed; if the verification is successful, a digital twin is generated. Public computing cluster encryption key, digital twin Calculate an independent decryption key; if verification is successful, a digital twin is created. Accepts independent decryption keys.

[0010] The following methods enable secure data transmission between multiple digital twins:

[0011] The first step, digital twin Random selection ,in Indicates order as integer group ,calculate ,send Give ;

[0012] The second step, digital twins calculate Data recovery .

[0013] Multiple digital twins can be dynamically separated, as follows:

[0014] The first step, digital twin send and leave request to control center ;

[0015] The second step is to examine the current state information. Control Center Random selection ,calculate Control Center Solving the set of linear equations , obtain ;

[0016] Step 3, Control Center Using the elliptic curve digital signature algorithm to calculate ,in Control Center broadcast ;

[0017] Fourth step, for Digital twin receive Then, the elliptic curve digital verification algorithm was used for verification. If the verification passes, proceed to step five; otherwise, abandon the process.

[0018] Step 5, Digital Twin calculate , , Get ;

[0019] Step 6, Digital Twin Publicly compute the general group encryption key ,in ;

[0020] Step 7, for Digital twin calculate and independent decryption key .

[0021] Multiple digital twins can be dynamically added, as follows:

[0022] The first step, digital twin send and join the request to the control center ;

[0023] The second step is to examine the current state information. Control Center Random selection ,calculate ;

[0024] The third step is for digital twins. Control Center Random selection ,calculate , Solving the set of linear equations , obtain ;

[0025] Step 4, Control Center Using the elliptic curve digital signature algorithm to calculate ,in ;

[0026] Step 5, Control Center broadcast ;

[0027] Step 6, Digital Twin receive Then, the elliptic curve digital verification algorithm was used for verification. If the verification passes, proceed to step seven; otherwise, abandon the process.

[0028] Step 7, Digital Twin calculate , , Get ;

[0029] Step 8, for Digital twin broadcast ;

[0030] Step 9, for Digital twin broadcast ;

[0031] Step 10, Digital Twin Publicly compute the general group encryption key ,in ;

[0032] Step 11, for Digital twin calculate and independent decryption key ;

[0033] Step 12, for Digital twin Calculate an independent decryption key .

[0034] In S1, the control center completes system initialization and generates system parameters. The specific method is as follows:

[0035] Step 1: Enter security parameters ;

[0036] Step 2, Control Center Based on nonsingular elliptic curves Generation order is group , yes The generator is randomly selected. As the master key, calculate the public key. ;

[0037] Step 3, Control Center Choose a hash function pseudo-random function and general one-way hash function ;

[0038] Step 4, Control Center Choose a secure elliptic curve digital signature algorithm ,in, Represents the signature algorithm. Representative verification algorithm;

[0039] Step 5, Control Center Output system parameters .

[0040] In S2, the control center deploys a digital twin to generate keys, using the following method:

[0041] The first step, digital twin Random selection ,calculate ,send To the control center ,in, It is a digital twin The identifier;

[0042] Step 2, Control Center Random selection ,calculate proof information and signature and send Give ;

[0043] The third step, digital twin Calculate its private key .

[0044] Multiple digital twins perform synchronized group key negotiation and group key generation, as follows:

[0045] The first step, for Digital twin Random selection ,calculate ,send To the control center ;

[0046] Step 2, Control Center receive Then, calculate ,verify Whether it meets the requirements, after successful verification, for the current status information Control Center Random selection ,calculate , Solving the set of linear equations Get ;

[0047] Step 3, Control Center calculate ,in , It's the group identifier, then, the control center. broadcast ;

[0048] Fourth step, for Digital twin receive Afterwards, verification If the verification is successful, then a digital twin is generated. calculate , , Get ;

[0049] Step 5, Digital Twin Random selection ,calculate ,broadcast Give ;

[0050] Step 6, Digital Twin receive Then, calculate ,verify and If the verification is successful, then a digital twin is generated. Publicly compute the general group encryption key ,in ;

[0051] Step 7, for Digital twin Calculate an independent decryption key ,verify If the verification is successful, then a digital twin is generated. Accept independent decryption keys .

[0052] The beneficial effects of this invention are as follows: Compared with existing technologies, this invention addresses the security and privacy issues in communication within digital twin networks. Based on elliptic curve cryptography, self-authenticating keys, and the sibling intractable function family, it proposes a synchronous group key negotiation scheme for digital twin networks, achieving secure communication between multiple digital twins. This invention guarantees the synchronization, confidentiality, and authentication of communication between multiple digital twins, and satisfies the indistinguishability under a chosen-plaintext attack under a random oracle model. Furthermore, this invention provides a solution for achieving secure and efficient communication in digital twin-driven applications. Attached Figure Description

[0053] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the specific implementation will be briefly described below:

[0054] Figure 1 This is a system flowchart of the present invention;

[0055] Figure 2 This is a flowchart of the synchronous group key negotiation and group key generation process of this invention. Detailed Implementation

[0056] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments.

[0057] First, the basic cryptographic knowledge used in this invention is briefly explained; second, a detailed implementation process is given; and finally, proof of the security of this invention is provided.

[0058] I. Fundamentals of Cryptography

[0059] 1. Self-authentication key: The self-authentication key implicitly performs public key authentication and includes two algorithms:

[0060] Private key generation algorithm Given a random number selected by the user and identity As input, the probabilistic algorithm outputs the corresponding proof. and user private key ;

[0061] Public key extraction algorithm Given user identity and proof The deterministic algorithm outputs the user's public key. .

[0062] 2. The Sibling Intractable Function Family: The sibling intractable function family is used to safely distribute synchronization information, as detailed below:

[0063] make It is a mapping Different strings To the same string A family of functions. In order to construct... It is necessary to Solve the following set of linear equations:

[0064]

[0065] but It can be completely made by As described. And, The output is The sibling intractable function family has additional properties. The details are as follows:

[0066] make for polynomial, It has collision accessibility, that is .make For any A collection of strings, If for any function... Each polynomial and sufficiently large ,satisfy ,but It is -sibling the intractable function family.

[0067] II. Specific Implementation Process

[0068] See Figure 1 The present invention includes the following steps:

[0069] The first step is for the control center to complete system initialization and generate system parameters. The specific method is as follows:

[0070] 1) Input security parameters ;

[0071] 2) Control Center Based on nonsingular elliptic curves Generation order is group , yes The generator is randomly selected. As the master key Let {1, ..., q} represent the integer group of order q. It means that s is from The value of s is randomly selected from the group, where s is a random number and its value ranges from 1 to 2. In the process of calculating the public key ;

[0072] 3) Control Center Choose a hash function pseudo-random function and general one-way hash function ;

[0073] 4) Control Center Choose a secure elliptic curve digital signature algorithm ,in, Represents the signature algorithm. Representative verification algorithm;

[0074] 5) Control Center Output system parameters .

[0075] The second step involves deploying a digital twin at the control center and generating a key, as follows:

[0076] 1) Digital Twin Random selection ,calculate ,send To the control center ,in, It is a digital twin The identifier;

[0077] 2) Control Center Random selection ,calculate proof information and signature and send Give ;

[0078] 3) Digital Twin Calculate its private key .

[0079] The third step involves multiple digital twins synchronously negotiating and generating a group key (see [link]). Figure 2 The specific method is as follows:

[0080] 1) For Digital twin Random selection ,calculate ,send To the control center ;

[0081] 2) Control Center receive Then, calculate ,verify Does it satisfy the condition? If so, what is the current state information? Control Center Random selection ,calculate , Solving the set of linear equations Get ;

[0082] 3) Control Center calculate ,in , It's a group identifier. Then, the control center... broadcast ;

[0083] 4) For Digital twin receive Afterwards, verification Does it meet the requirements? If so, digital twin calculate , , Get Then, digital twins Random selection ,calculate ,broadcast Give ;

[0084] 5) Digital Twin receive Then, calculate ,verify and Does it meet the requirements? If so, digital twin Publicly compute the general group encryption key ,in ;

[0085] 6) For Digital twin Calculate an independent decryption key ,verify Does it meet the requirements? If it does, accept .

[0086] The fourth step involves secure data transmission between multiple digital twins, using the following method:

[0087] 1) Digital Twin Random selection ,calculate ,send Give digital twins ;

[0088] 2) Digital Twin calculate Data recovery .

[0089] Step 5: Dynamically separate multiple digital twins. The specific method is as follows:

[0090] 1) Digital Twin send and leave request to control center ;

[0091] 2) Regarding the current status information Control Center Random selection ,calculate ;

[0092] 3) Control Center Solving the set of linear equations , obtain ;

[0093] 4) Control Center Using the elliptic curve digital signature algorithm to calculate ,in ;

[0094] 5) Control Center broadcast ;

[0095] 6) For Digital twin receive Afterwards, verification If the verification passes, proceed to step 7; otherwise, abandon the process.

[0096] 7) For Digital twin calculate , , Get ;

[0097] 8) For Digital twin Publicly compute the general group encryption key ,in ;

[0098] 9) For Digital twin calculate and independent decryption key .

[0099] Step 6: Dynamically add multiple digital twins, as follows:

[0100] 1) Digital Twin send and join the request to the control center ;

[0101] 2) Regarding the current status information Control Center Random selection ,calculate ;

[0102] 3) For digital twins Control Center Execute the third step to generate ;

[0103] 4) Control Center Solving the set of linear equations , obtain ;

[0104] 5) Control Center Using the elliptic curve digital signature algorithm to calculate ,in ;

[0105] 6) Control Center broadcast ;

[0106] 7) Digital Twin receive Then, the elliptic curve digital verification algorithm was used for verification. If the verification passes, proceed to step 8; otherwise, abandon the process.

[0107] 8) Digital Twin calculate , , Get ;

[0108] 9) For Digital twin broadcast ;

[0109] 10) For Digital twin broadcast ;

[0110] 11) Digital Twin Publicly compute the general group encryption key ,in ;

[0111] 12) For Digital twin calculate and independent decryption key ;

[0112] for Digital twin Calculate an independent decryption key .

[0113] III. Security Proof

[0114] 1. Security Model

[0115] make Writing participants The Examples. The security model of this invention is challenged by the following... and rivals Game definition between:

[0116] Initialization: Given security parameters , Generate system parameters Send it to .

[0117] ask: The following inquiries can be made as appropriate:

[0118] :when When performing a hash query, Returns a random value.

[0119] :when conduct When asked, Return to participants Temporary key information.

[0120] :when conduct When asked, Return to participants The long-term private key.

[0121] :when conduct When asked, Return to participants The independent decryption key.

[0122] :when conduct When asked, Returns the common group encryption key.

[0123] : Select two messages Send to .Then, Random selection Encryption using a common group encryption key And return the ciphertext to This query can only be made once.

[0124] guess: Output a guess .if , Win the game. The advantage of winning the game is defined as .

[0125] Definition: If for any probability polynomial time adversary In other words, If the value is negligible, then the proposed scheme satisfies the indistinguishability of chosen-plaintext attacks.

[0126] 2. Specific proof

[0127] Theorem: Assume If the security of the proposed scheme can be compromised through non-negligible advantages, then there exists an algorithm. It can solve the elliptic curve decisional Diffie-Hellman problem with significant advantages.

[0128] Proof: Given an elliptic curve decision Diffie-Hellman tuple ,algorithm The goal is to determine Therefore, the algorithm choose As a challenge identity. Furthermore, to maintain a fast response time, the algorithm... The following list, initially empty, was maintained:

[0129] This list consists of tuples constitute.

[0130] This list consists of tuples constitute.

[0131] This list consists of tuples constitute.

[0132] This list consists of tuples constitute.

[0133] This list consists of tuples constitute.

[0134] This list consists of tuples constitute.

[0135] Initialization: Given security parameters ,algorithm Generate system parameters And send to .

[0136] ask: Perform the following queries adaptively:

[0137] :when Submit hash ask, examine Does it exist in If it exists, return Give If it does not exist, Random selection ,insert arrive and return Give .

[0138] :when Submit hash ask, examine Does it exist in If it exists, return Give If it does not exist, Random selection ,insert arrive and return Give .

[0139] :when Submit hash ask, examine Does it exist in If it exists, return Give If it does not exist, Random selection ,insert arrive and return Give .

[0140] :when submit ask, examine Does it exist in If it exists, return Give If it does not exist, Random selection ,insert arrive and return Give .

[0141] :when submit ask, Check if Existence or , return .Then, examine Does it exist in If it exists, return Give If it does not exist, Random selection ,calculate ,insert arrive and arrive and return Give .

[0142] :when submit ask, examine Is it equal to If they are equal, return .Then, examine Does it exist in If it exists, return Give .otherwise, from Get from Random selection ,calculate .Then, Random selection ,calculate ,insert arrive .at last, calculate ,insert arrive and return Give .

[0143] :when Submitted ask, from Get from and return to .

[0144] :when use submit ask, examine Is it equal to If they are equal, from Get from ,from Get from ,from Get from .Then, Random selection and ,set up and return Give If they are not equal, return .

[0145] guess: Output a guess .if , Output 1 indicates .otherwise Output 0.

[0146] Probability analysis: Assumptions The maximum number of times can be performed Secondary hash ask, Second-rate ask, Second-rate ask, Second-rate For inquiries, the following events can be defined:

[0147] : Never give up during any inquiry.

[0148] : Correct output .

[0149] The above game simulation can yield the following: .therefore, The probability of successfully outputting 1 is: .

[0150] Based on the above analysis, It was determined with undeniable advantages. However, this contradicts the Diffie-Hellman assumption of elliptic curve determination. Therefore, the proposed scheme is safe.

[0151] The above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art can still make modifications or equivalent substitutions to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention are within the protection scope of the claims of the present invention pending approval.

Claims

1. A method for synchronous group key negotiation in a digital twin network, characterized in that, Includes the following steps: S1: Input safety parameters, control center Complete system initialization, generate and output system parameters; S2: Digital Twin identifier and Send to control center Control Center Computational digital twin The proof information and signature are sent to the digital twin. Digital twin Calculate the private key; S3: Digital Twin Send proof information to the control center Control Center Receive and verify; once verification is successful, the current status information is processed. Control Center calculate Solving the problem of obtaining linear sets Control Center calculate Send to digital twin Digital twin After receiving the proof information, verification is performed; once verification is successful, the digital twin is generated. Get The system calculates the proof information and broadcasts it to multiple digital twins. After receiving the proof information, verification is performed; if the verification is successful, a digital twin is generated. Public computing cluster encryption key, digital twin Calculate an independent decryption key; if verification is successful, a digital twin is created. Accepts independent decryption keys; In S1, the control center completes system initialization and generates system parameters, using the following method: Step 1: Enter security parameters ; Step 2, Control Center Based on nonsingular elliptic curves Generation order is group , yes The generator is randomly selected. As the master key, calculate the public key. ; Step 3, Control Center Choose a hash function pseudo-random function and general one-way hash function ; Step 4, Control Center Choose a secure elliptic curve digital signature algorithm ,in, Represents the signature algorithm. Representative verification algorithm; Step 5, Control Center Output system parameters ; In S2, the control center deploys a digital twin to generate keys, using the following method: The first step, digital twin Random selection ,calculate ,send To the control center ,in, It is a digital twin The identifier; Step 2, Control Center Random selection ,calculate proof information and signature and send Give ; The third step, digital twin Calculate its private key ; In S3, multiple digital twins perform synchronized group key negotiation and group key generation, as follows: The first step, for Digital twin Random selection ,calculate ,send To the control center ; Step 2, Control Center receive Then, calculate ,verify Whether it meets the requirements, after successful verification, for the current status information Control Center Random selection ,calculate , Solving the set of linear equations Get ; Step 3, Control Center calculate ,in , It's the group identifier, then, the control center. broadcast ; Fourth step, for Digital twin receive Afterwards, verification If the verification is successful, then a digital twin is generated. calculate , , Get ; Step 5, Digital Twin Random selection ,calculate ,broadcast Give ; Step 6, Digital Twin receive Then, calculate ,verify and If the verification is successful, then a digital twin is generated. Publicly compute the general group encryption key ,in ; Step 7, for Digital twin Calculate an independent decryption key ,verify If the verification is successful, then a digital twin is generated. Accept independent decryption keys .

2. The method for synchronous group key negotiation in a digital twin network according to claim 1, characterized in that, The following methods enable secure data transmission between multiple digital twins: The first step, digital twin Random selection ,in Indicates order as integer group ,calculate ,send Give ; The second step, digital twins calculate Data recovery .

3. The method for synchronous group key negotiation in a digital twin network according to claim 1, characterized in that, Multiple digital twins can be dynamically separated, as follows: The first step, digital twin send and leave request to control center ; The second step is to examine the current state information. Control Center Random selection ,calculate Control Center Solving the set of linear equations , obtain ; Step 3, Control Center Using the elliptic curve digital signature algorithm to calculate ,in Control Center broadcast ; Fourth step, for Digital twin receive Then, the elliptic curve digital verification algorithm was used for verification. If the verification passes, proceed to step five; otherwise, abandon the process. Step 5, Digital Twin calculate , , Get ; Step 6, Digital Twin Publicly compute the general group encryption key ,in ; Step 7, for Digital twin calculate and independent decryption key .

4. The method for synchronous group key negotiation in a digital twin network according to claim 1, characterized in that, Multiple digital twins can be dynamically added, as follows: The first step, digital twin send and join the request to the control center ; The second step is to examine the current state information. Control Center Random selection ,calculate ; The third step is for digital twins. Control Center Random selection ,calculate , Solving the set of linear equations , obtain ; Step 4, Control Center Using the elliptic curve digital signature algorithm to calculate ,in ; Step 5, Control Center broadcast ; Step 6, Digital Twin receive Then, the elliptic curve digital verification algorithm was used for verification. If the verification passes, proceed to step seven; otherwise, abandon the process. Step 7, Digital Twin calculate , , Get ; Step 8, for Digital twin broadcast ; Step 9, for Digital twin broadcast ; Step 10, Digital Twin Publicly compute the general group encryption key ,in ; Step 11, for Digital twin calculate and independent decryption key ; Step 12, for Digital twin Calculate an independent decryption key .