Node authentication method, node, system, medium and device of sensor network

By using challenge random numbers and physically unclonable functions (PUFs) to authenticate cluster head nodes and nodes within clusters in wireless sensor networks, the security problem caused by the participation of base stations is solved, and highly secure and scalable node authentication is achieved.

CN116208329BActive Publication Date: 2025-10-21GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +4
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310193646.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-23
Publication Date
2025-10-21
Estimated Expiration
2043-02-23

AI Technical Summary

Technical Problem

The existing node authentication method of wireless sensor networks requires the participation of base stations, resulting in insufficient security and difficulty in resisting privileged attacks by attackers as internal members of the base station.

Method used

The protection value is generated by encrypting a challenge random number, combined with the physical unclonable function (PUF) and lightweight encryption and decryption algorithm to authenticate between the cluster head node and the nodes in the cluster, generate session keys for information exchange, and avoid the participation of the base station.

Benefits of technology

The security of the authentication process is improved, the computational workload of the base station is reduced, the scalability of the sensor network is enhanced, and privileged attacks are resisted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208329B_ABST
    Figure CN116208329B_ABST
Patent Text Reader

Abstract

The application discloses a kind of node authentication method, node, system, medium and equipment of sensing network, the method includes generating challenge random number, and challenge random number is encrypted into first protection value;Integrity verification encryption value and second protection value generated by the encryption of first protection value and pre-stored secret information and physical unclonable function feature data are received according to the node in cluster;Second protection value is decrypted to obtain the recovery value of feature data;Second response output value is obtained based on the recovery value of feature data and challenge random number and executes physical unclonable function;Second session key is generated, and first preset information is encrypted using second session key to obtain verification information, and verification information is sent to the node in cluster for node authentication.The application embodiment when cluster head node and the node in cluster are authenticated, does not need base station to participate, reduces the calculation amount of base station, and avoids the privileged attack of attacker as base station internal member, improves the security of authentication process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of identity authentication technology in the field of information security, and in particular to a node authentication method, node, system, medium and equipment for a sensor network. Background Art

[0002] IoT power transmission and transformation equipment represents a representative form of low-power wireless sensor networks. Constrained by cost and power consumption, IoT sensor terminals have limited computing power, storage capacity, power supply, and transmission capabilities. This makes it difficult to adopt high-cost, high-performance security protection technologies. Most existing equipment, especially environmental monitoring equipment, uses little or no security technologies like encryption and authentication. However, the real-time data collected by sensor nodes is highly sensitive, often impacting user privacy and even national security. Therefore, authorized access to sensor nodes and secure transmission of collected data have long been important research topics within the power IoT.

[0003] In the IoT scenario of power transmission and transformation equipment, wireless sensor networks need to provide communication connectivity for massive numbers of sensors. Due to the limited resource constraints of sensor nodes within the network, achieving ultra-low power consumption is a fundamental requirement. Currently, most wireless sensor networks exist in a clustered format, consisting of three roles: cluster nodes, cluster head nodes, and base stations. Within a cluster are numerous sensor nodes, which exchange data through the cluster head node. Therefore, authentication between the cluster head node and the cluster nodes is essential to ensure subsequent data transmission. The traditional authentication process involves a cluster node sending registration information to a registration center to become a legitimate node. The registration center then determines the cluster to which the node will join and completes mutual authentication and key negotiation between the cluster head node and the cluster nodes.

[0004] After registration is completed, the existing authentication method still requires the base station to participate in the authentication process during the re-authentication stage, which may cause attackers to launch privileged attacks as internal members of the base station, resulting in insufficient security. Summary of the Invention

[0005] In view of this, the embodiments of the present invention provide a sensor network node authentication method, node, system, medium and device to solve the technical problem in the prior art that the node authentication stage requires the participation of base stations in authentication, resulting in insufficient security.

[0006] The technical solutions proposed by the present invention are as follows:

[0007] A first aspect of an embodiment of the present invention provides a node authentication method for a sensor network, which is applied to a cluster head node, including: generating a challenge random number, and encrypting the challenge random number into a first protection value and then sending the first protection value to a node in the cluster; receiving an integrity verification encryption value and a second protection value generated by the node in the cluster based on the first protection value and pre-stored secret information and characteristic data of a physical unclonable function; decrypting the second protection value to obtain a recovery value of the characteristic data; executing a physical unclonable function based on the recovery value of the characteristic data and the challenge random number to obtain a second response output value; generating a second session key based on the second response output value, the integrity verification encryption value and the challenge random number, using the second session key to encrypt first preset information to obtain verification information, and sending the verification information to the node in the cluster for node authentication.

[0008] Optionally, sending the first protection value to the node in the cluster includes: performing a hash operation on the second preset information to obtain a first integrity verification value; and sending the first integrity verification value and the first protection value to the node in the cluster.

[0009] Optionally, a second session key is generated based on the second response output value, the integrity verification encryption value and the challenge random number, including: using a lightweight decryption function with the second response output value as the key to decrypt the integrity verification encryption value to obtain an intra-cluster random number recovery value and a second integrity verification value; performing a hash operation on the second response output value, the intra-cluster random number recovery value, the challenge random number and the pre-acquired identity information of the authentication node to obtain a second session key; verifying the second integrity verification value based on the second session key, and determining whether to proceed to the next authentication step based on the verification result.

[0010] Optionally, decrypting the second protection value to obtain the recovery value of the characteristic data includes: decrypting the second protection value to obtain the recovery value of the secret information; decrypting the pre-stored characteristic data encryption value according to the recovery value of the secret information to obtain the recovery value of the characteristic data.

[0011] Optionally, the first preset information is encrypted using the second session key to obtain verification information, including: performing a hash operation on the fourth preset information to obtain a third integrity verification value; and encrypting the first preset information using a lightweight encryption function with the second session key as the key to obtain verification information, wherein the first preset information is obtained by performing a bit connection operation on the third integrity verification value and a randomly generated cluster head random number.

[0012] Optionally, after using the second session key to encrypt the first preset information to obtain verification information, it also includes: encrypting the recovery value of the feature data according to the cluster head random number to obtain a feature data encryption update value; and updating the pre-stored feature data encryption value based on the feature data encryption update value.

[0013] A second aspect of an embodiment of the present invention provides a node authentication method for a sensor network, which is applied to nodes within a cluster, including: receiving a first protection value sent by a cluster head node, where the first protection value is encrypted by the cluster head node based on a randomly generated challenge random number; encrypting an integrity verification encryption value and a second protection value based on the first protection value and pre-stored secret information and characteristic data of a physical unclonable function, and sending the integrity verification encryption value and the second protection value to the cluster head node; receiving verification information sent by the cluster head node, where the verification information is that the cluster head node decrypts the second protection value to obtain a recovery value of the characteristic data, executes a physical unclonable function based on the recovery value of the characteristic data and the challenge random number to obtain a second response output value, generates a second session key according to the second response output value, the integrity verification encryption value and the challenge random number, and uses the second session key to encrypt the first preset information; decrypts the verification information and verifies whether the decrypted data is correct, and determines whether the authentication is completed based on the verification result.

[0014] Optionally, an integrity verification encryption value and a second protection value are generated based on the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function, including: decrypting the first protection value to obtain a recovery value of the challenge random number, and generating a first challenge value based on the recovery value of the challenge random number; executing a physical unclonable function based on the first challenge value and the characteristic data of the physical unclonable function to obtain a first response output value; generating a first session key based on the first response output value, the recovery value of the challenge random number, and a randomly selected intra-cluster random number; encrypting the first session key, the first challenge value, the intra-cluster random number, the recovery value of the challenge random number, and the characteristic data based on the first response output value to generate an integrity verification encryption value; and encrypting the pre-stored secret information to obtain a second protection value.

[0015] Optionally, the first session key, the first challenge value, the intra-cluster random number, the recovery value of the challenge random number and the characteristic data are encrypted according to the first response output value to generate an integrity verification encryption value, including: performing a hash operation on third preset information to obtain a second integrity verification value, wherein the third preset information includes the first session key, the first challenge value, the intra-cluster random number, the recovery value of the challenge random number and the characteristic data; and encrypting the intra-cluster random number and the second integrity verification value using a lightweight encryption function with the first response output value as the key to obtain the integrity verification encryption value.

[0016] Optionally, after decrypting the verification information and verifying whether the decrypted data is correct, the method further includes: if the verification is correct, updating the pre-stored secret information to the recovery value of the cluster head random number, wherein the recovery value of the cluster head random number is obtained by decrypting the verification information.

[0017] A third aspect of an embodiment of the present invention provides a cluster head node of a sensor network, comprising: a challenge module, configured to generate a challenge random number, and after encrypting the challenge random number into a first protection value, send the first protection value to a node within the cluster; a first receiving module, configured to receive an integrity verification encryption value and a second protection value generated by the node within the cluster based on the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function; a first decryption module, configured to decrypt the second protection value to obtain a recovery value of the characteristic data; an execution module, configured to execute a physical unclonable function based on the recovery value of the characteristic data and the challenge random number to obtain a second response output value; a first encryption module, configured to generate a second session key based on the second response output value, the integrity verification encryption value, and the challenge random number, encrypt first preset information using the second session key to obtain verification information, and send the verification information to the node within the cluster for node authentication.

[0018] According to a fourth aspect of an embodiment of the present invention, there is provided a cluster node in a sensor network, comprising: a second receiving module for receiving a first protection value sent by a cluster head node, wherein the first protection value is generated by the cluster head node based on encryption of a randomly generated challenge random number; a second encryption module for encrypting an integrity verification encryption value and a second protection value based on the first protection value and pre-stored secret information and characteristic data of a physical unclonable function, and sending the integrity verification encryption value and the second protection value to the cluster head node; a third receiving module for receiving verification information sent by the cluster head node, wherein the verification information is the cluster head node decrypting the second protection value to obtain a recovery value of the characteristic data, executing a physical unclonable function based on the recovery value of the characteristic data and the challenge random number to obtain a second response output value, generating a second session key according to the second response output value, the integrity verification encryption value and the challenge random number, and encrypting the first preset information using the second session key; and a verification module for decrypting the verification information and verifying whether the decrypted data is correct, and determining whether the authentication is completed based on the verification result.

[0019] A fifth aspect of an embodiment of the present invention provides a node authentication system for a sensor network, including a cluster head node and a node within a cluster; the cluster head node generates a challenge random number, encrypts the challenge random number into a first protection value, and then sends the first protection value to the node within the cluster; the node within the cluster receives the first protection value sent by the cluster head node, encrypts the first protection value and pre-stored secret information and characteristic data of a physical unclonable function to generate an integrity verification encryption value and a second protection value, and sends the integrity verification encryption value and the second protection value to the cluster head node; the cluster head node receives the challenge random number sent by the node within the cluster based on the first protection value and pre-stored secret information and characteristic data of a physical unclonable function Data encryption generates an integrity verification encryption value and a second protection value; the second protection value is decrypted to obtain the recovery value of the feature data; a physical unclonable function is executed based on the recovery value of the feature data and the challenge random number to obtain a second response output value; a second session key is generated according to the second response output value, the integrity verification encryption value and the challenge random number, the second session key is used to encrypt the first preset information to obtain verification information, and the verification information is sent to the nodes in the cluster for node authentication; the nodes in the cluster receive the verification information sent by the cluster head node, decrypt the verification information and verify whether the decrypted data is correct, and determine whether the authentication is completed based on the verification result.

[0020] A sixth aspect of an embodiment of the present invention provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the node authentication method of the sensor network as described in any one of the first and second aspects of the embodiments of the present invention.

[0021] A seventh aspect of an embodiment of the present invention provides a node authentication device for a sensor network, characterized in that it includes: a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the node authentication method for the sensor network as described in any one of the first and second aspects of the embodiments of the present invention by executing the computer instructions.

[0022] It can be seen from the above technical solutions that the embodiments of the present invention have the following advantages:

[0023] Embodiments of the present invention provide a sensor network node authentication method, node, system, medium, and device. The method comprises generating a challenge random number, encrypting the challenge random number into a first protection value, and then sending the first protection value to a node within a cluster. The method receives an integrity verification encryption value and a second protection value generated by the node within the cluster based on the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function. The method decrypts the second protection value to obtain a recovery value of the characteristic data. The method executes a physical unclonable function based on the recovery value of the characteristic data and the challenge random number to obtain a second response output value. The method generates a second session key based on the second response output value, the integrity verification encryption value, and the challenge random number. The method uses the second session key to encrypt first preset information to obtain verification information, and then sends the verification information to the node within the cluster for node authentication. In this embodiment of the present invention, when the cluster head node and the nodes within the cluster perform authentication, the base station does not need to participate, which reduces the computational workload of the base station, avoids privileged attacks by attackers as internal members of the base station, improves the security of the authentication process, and enhances the scalability of the sensor network. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly express the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0025] Figure 1 Schematic diagram of the structure of the sensor network in an embodiment of the present invention;

[0026] Figure 2 Flowchart of a sensor network node authentication method according to an embodiment of the present invention;

[0027] Figure 3 is a flow chart of another sensor network node authentication method according to an embodiment of the present invention;

[0028] Figure 4is a flow chart of another sensor network node authentication method according to an embodiment of the present invention;

[0029] Figure 5 is a registration flow chart of a sensor network in an embodiment of the present invention;

[0030] Figure 6 1 is a flow chart of authentication of a sensor network according to an embodiment of the present invention;

[0031] Figure 7 Schematic diagram of the structure of a cluster head node in a sensor network according to an embodiment of the present invention;

[0032] Figure 8 Schematic diagram of the structure of a node in a cluster of a sensor network according to an embodiment of the present invention;

[0033] Figure 9 Schematic diagram of the structure of a node authentication system for a sensor network according to an embodiment of the present invention;

[0034] Figure 10 A schematic diagram of the structure of a node authentication device according to an embodiment of the present invention;

[0035] Figure 11 Schematic diagram of the structure of a computer-readable storage medium in an embodiment of the present invention. DETAILED DESCRIPTION

[0036] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0037] In a clustered wireless sensor network, information is collected by sensor nodes within the cluster and transmitted to the cluster head node, which is responsible for the management and maintenance of the cluster nodes. Since the transmitted information is private and user-related, and wireless sensor networks operate over public channels, it is difficult to prevent unauthorized access and control by attackers. This necessitates security assurance at the protocol level. Furthermore, some existing authentication schemes are vulnerable to node capture and temporary secret disclosure attacks and cannot guarantee forward confidentiality (or require high costs to achieve forward security). Furthermore, considering the need for narrowband terminals, new schemes should be designed that can be applied to sensor nodes with low computational complexity and narrow communication channels. Therefore, current wireless sensor networks urgently need a new authentication method that can achieve forward security with low communication and computational costs and resist node capture and temporary key attacks. Based on this, embodiments of the present invention propose an authentication method for sensor networks.

[0038] The symbols and their meanings used in the embodiments of the present invention are shown in Table 1.

[0039] Table 1 Symbol definitions

[0040]

[0041] like Figure 1 As shown, the sensor network of the embodiment of the present invention is composed of three roles: cluster nodes, cluster head nodes and base stations. There are multiple cluster nodes and one cluster head node in a cluster. The cluster nodes need to exchange data through the cluster head node, so authentication of the cluster head node and the cluster nodes is required to ensure subsequent data transmission.

[0042] Before authentication, the cluster head node and the nodes within the cluster need to be registered, the corresponding identity information is generated, and the cluster head node and the nodes within the cluster are connected to the sensor network according to the identity information.

[0043] Specifically, if Figure 5 As shown, the base station BS generates secret data sec and sends the secret data to the cluster head node CH via a secure channel. j Storage, base station BS is the cluster node CM to be connected to the sensor network i Randomly generate node identity IDs within the cluster i , and equip it with a physical unclonable function PUF, the nodes in the cluster CM i Generate secret information x i And according to the characteristic data puf of the physical unclonable function PUF i and secret information x i Obpuf, the encrypted value of the characteristic data generated after the XOR operation i Send to base station BS, base station BS receives cluster head node CH j The ID value of the cluster head node sent j , and the cluster head node identity value ID j Perform hash operation with secret data sec to obtain the disguised identity value PID j , the calculation formula is: PID j =h(ID j ||sec)mod n, the base station BS will disguise the identity value PID j Sent to the CM nodes in the cluster i , the identity value ID of the node in the cluster i And the encrypted value of characteristic data obpuf i Sent to cluster head node CH j After registration is completed, the cluster node CM i Stores the identity value ID of the node in the cluster i , disguised identity value PIDj , characteristic data puf of physical unclonable function PUF i and secret information x i , cluster head node CH j Stores the cluster nodes CM to be connected i The node identity value ID in the cluster i And the encrypted value of characteristic data obpuf i .

[0044] The embodiment of the present invention provides a sensor network node authentication method, which is applied to a cluster head node, such as Figure 2 As shown, the method includes the following steps:

[0045] Step S101: Generate a challenge random number r j , and challenge the random number r j After being encrypted into the first protection value, the first protection value R j Sent to the CM nodes in the cluster i .

[0046] Specifically, the cluster head node CHj 生 Challenge random number r j and the first timestamp T1, and encrypt the value obpuf according to the first timestamp T1 and the stored characteristic data i The hash value of the challenge random number t j Encrypt to get the first protection value R j , the calculation formula is:

[0047]

[0048] Then the first protection value R j and the first timestamp T1 are sent to the cluster node CM via the common channel i The function of the first timestamp T1 is to record the time when the current information is sent.

[0049] Step S102: Receive the CM of the cluster node i According to the first protection value R j and pre-stored secret information x i And the characteristic data puf of the physical unclonable function i The integrity verification encryption value Epos and the second protection value R generated by encryption i .

[0050] Specifically, the cluster head node CH j CM node in the receiving cluster iAfter the data is sent, it will first determine whether the information is expired based on the time difference between the second timestamp T2 in the data and the current time. If it is expired, no processing is required. If it is not expired, authentication will continue. The second timestamp T2 is the time difference between the CM nodes in the cluster. i The data carried in the message sent indicates the CM node in the cluster i The moment the message was sent.

[0051] Step S103: The second protection value R i Decrypt to obtain the recovery value puf of the feature data i * Specifically, the second protection value R is obtained by using an XOR operation and a hash operation. i Decrypt and get the recovery value puf of the feature data i * ,The computational cost of XOR and hash operations is much lower than that of asymmetric encryption, but it can also achieve the security requirements that asymmetric encryption can achieve.

[0052] Step S104: Recovering the value puf based on the feature data i * and challenge random number r j Execute the physical unclonable function to obtain the second response output value K j Specifically, by challenging the random number r j , ID of the node in the cluster i and masquerade identity value PID j Perform hash operation to obtain the first challenge value pos j , that is, pos j =h(r j ||ID i ||PID j ), and then the restored value puf of the feature data i * and the first challenge value pos j Execute the physical unclonable function to obtain the second response output value K j , that is, K j =PUF(puf i * ,pos j ).

[0053] Step S105: Output value K according to the second response j , integrity verification encryption value Epos and challenge random number r j Generate the second session key SK ji , using the second session key SK ji Encrypt the first preset information to obtain the verification information DB, and send the verification information DB to the node CM in the cluster. iPerform node authentication.

[0054] Specifically, based on the second response output value K j Decrypt the integrity verification encrypted value Epos to obtain the cluster random number recovery value and the second integrity verification value, and use the obtained cluster random number recovery value to calculate the second session key SK ji , then generates a third timestamp T3, using the second session key SK ji Encrypt the first preset information to obtain verification information DB, and send the verification information DB and the third timestamp T3 to the node CM in the cluster. i The purpose of sending the third timestamp T3 is to record the sending time. The first preset information includes the information that needs to be verified, including the challenge random number r j , second session key SK ji , ID of the node in the cluster i and masquerade identity value PID j Etc. Send verification information DB to the node CM in the cluster i After that, the nodes in the cluster CM i Determine whether the authentication is completed based on the verification information DB.

[0055] A node authentication method for a sensor network according to an embodiment of the present invention generates a challenge random number r j , and challenge the random number r j After being encrypted into the first protection value, the first protection value R j Sent to the CM nodes in the cluster i ; Receive the CM node in the cluster i According to the first protection value R j and pre-stored secret information x i And the characteristic data puf of the physical unclonable function i The integrity verification encryption value Epos and the second protection value R generated by encryption i ; For the second protection value R i Decrypt to obtain the recovery value puf of the feature data i * ; Recovery value puf based on feature data i * and challenge random number r j Execute the physical unclonable function to obtain the second response output value K j ; According to the second response output value K j , integrity verification encryption value Epos and challenge random number r j Generate the second session key SK ji , using the second session key SK jiThe first preset information is encrypted to obtain verification information DB, and the verification information DB is sent to the nodes in the cluster for node authentication. In the node authentication method of the embodiment of the present invention, the cluster head node CH j Based on the CM of the nodes in the cluster i Pre-stored secret information x i And the characteristic data puf of the physical unclonable function i For nodes in the cluster CM i To authenticate, only the cluster head node CH is needed during the authentication process. j Through the CM nodes in the cluster i Information exchange and verification of each other's information are carried out to authenticate each other. The base station does not need to participate in the authentication process, which reduces the computational complexity of the base station and avoids privileged attacks by attackers as internal members of the base station. This improves the security of the authentication process and enhances the scalability of the sensor network.

[0056] This embodiment of the present invention also incorporates a physical unclonable function (PUF) into the authentication process. The PUF uniquely identifies the device and does not store keys within the IoT device. Instead, it reads the device's fingerprint for each application, making it inherently resistant to such attacks. Because PUF authentication does not transmit sensitive data over the network, it can resist security attacks similar to those targeting Wi-Fi, achieving security similar to certificate authentication protocols.

[0057] In one embodiment, step S101, the first protection value R j Sent to the CM nodes in the cluster i , including: performing a hash operation on the second preset information to obtain a first integrity verification value V j ; The first integrity verification value V j and the first protection value R j Sent to the CM nodes in the cluster i .

[0058] Specifically, the cluster head node CH is calculated j The PID of the disguised identity value j , the calculation formula is:

[0059] PID j =h(ID j ||sec)mod n

[0060] The second preset information includes the node identity value ID within the cluster i , disguised identity value PID j , challenge random number r j , the first timestamp T1 and the encrypted value of the characteristic data obpuf i , the identity value ID of the node in the cluster i , disguised identity value PIDj , challenge random number r j , the first timestamp T1 and the encrypted value of the characteristic data obpuf i Perform hash operation encryption to obtain the first integrity verification value V j , the calculation formula is:

[0061] V j =h(ID i ||PID j ||r j ||T1||obpuf j )

[0062] Obtain the first integrity verification value V through hash operation j It is convenient to verify whether the second preset information is accurate.

[0063] In one embodiment, step S105, according to the second response output value K j , integrity verification encryption value Epos and challenge random number t j Generate the second session key SK ji ,include:

[0064] Step S151: Use the second response output value K j The lightweight decryption function of the key decrypts the integrity verification encrypted value Epos to obtain the random number recovery value r within the cluster i * and the second integrity verification value V i Specifically, the calculation formula is: Among them, LDAlg K (·) represents a lightweight decryption function with K as the key.

[0065] Step S152: Output value K for the second response j , random number recovery value r within the cluster i * , challenge random number r j The second session key SK is obtained by performing a hash operation on the identity information of the pre-acquired authentication node ji Specifically, the pre-acquired authentication node identity information is the node identity value ID in the cluster. i and masquerade identity value PID j , the node identity value ID in the cluster i Assigned by the base station before authentication, disguised identity value PID j According to its own cluster head node identity value ID j The hash operation is performed on the secret data sec, and the operation formula is: PID j =h(ID j||sec)mod n. Second session key SK ji The calculation formula is:

[0066] SK ji =h(ID i ||PID j ||K j ||r i * ||r j )

[0067] Step S153: According to the second session key SK ji The second integrity verification value V i Perform verification and determine whether to proceed to the next authentication step based on the verification result.

[0068] Specifically, the second integrity verification value V is determined i Is it equal to h(SK ji ||pos j ||r i * ||r j ||puf i || T2), if yes, proceed to the next authentication step.

[0069] In this embodiment of the present application, a second session key SK is generated by a hash operation. ji , and pass the second session key SK ji Determine the second integrity verification value V i Is it correct to be able to recover the value r of the random number in the cluster? i * Verify whether it is correct and proceed to the next authentication step.

[0070] In one embodiment, step S105, using the second session key SK ji Encrypting the first preset information to obtain the verification information DB includes:

[0071] Step S154: Perform a hash operation on the fourth preset information to obtain a third integrity verification value V. Specifically, the fourth preset information includes the second session key SK ji , the third timestamp T3, the random number recovery value r within the cluster i * , challenge random number r j , ID of the node in the cluster i and masquerade identity value PID j , that is, the third integrity verification value V=h(SK ji ||T3||r i * ||r j ||IDi ||ID j ).

[0072] Step S155: Use the second session key SK ji The first preset information is encrypted by a lightweight encryption function using a key as the key to obtain verification information DB, wherein the first preset information is obtained by combining the third integrity verification value V and the randomly generated cluster head random number x j Specifically, when verifying the second integrity verification value V i Equal to h(SK ji ||pos j ||r i * ||r j ||puf i ||T2) after which the cluster head random number x is generated. j and the third timestamp T3, using a lightweight encryption function to encrypt the third integrity verification value V and the randomly generated cluster head random number x j To encrypt, the encryption formula is:

[0073] The embodiment of the present invention uses a hash operation and a lightweight encryption and decryption algorithm to perform the second session key SK ji , cluster head random number x j and challenge random number r j The computational cost of these operations is much lower than that of asymmetric encryption, but it can also achieve the security requirements that asymmetric encryption can achieve, so the computational cost of the authentication process can be reduced.

[0074] In one embodiment, step S103, the second protection value R i Decrypt to obtain the recovery value puf of the feature data i * ,include:

[0075] Step S131: The second protection value R i Decrypt to obtain the recovery value of the secret information Specifically, the second protection value R i , the second timestamp T2 and the encrypted value of the characteristic data obpuf i The hash value is XORed to recover the recovery value of the secret information Right now

[0076] Step S132: Recover the value based on the secret information Encrypt the pre-stored feature data value obpuf i Decrypt to obtain the recovery value puf of the feature datai * Specifically, the recovered value of the secret information And the encrypted value of characteristic data obpuf i Perform an XOR operation, that is Restore the recovery value puf of the feature data i * . The recovered value puf of the feature data is obtained by XOR decryption i * , compared with asymmetric encryption, it can reduce the computational cost.

[0077] In one embodiment, in step S105, using the second session key SK ji After encrypting the first preset information to obtain the verification information DB, the method further includes: j The restored value puf of the feature data i * Encrypt to obtain the encrypted update value of the feature data Update value based on feature data encryption Encrypt the pre-stored feature data value obpuf j to update.

[0078] Specifically, the cluster head random number x j The restored value puf of the feature data i * Perform XOR operation to obtain the encrypted update value of the feature data Right now Encrypt the pre-stored feature data to obpuf j Update encrypted update value for feature data After each verification, the characteristic data encryption value obpuf is replaced j Even if the attacker breaks into the cluster head node and obtains its internal long-term key, due to the encrypted value of the characteristic data obpuf j The value is different in different authentication processes, and the attacker cannot recover the previous session key. The encrypted value obpuf of the feature data is updated through each authentication. j In this way, the forward security of the session key between the nodes in the cluster and the cluster head node is achieved.

[0079] The embodiment of the present invention also provides a node authentication method for a sensor network, which is applied to nodes in a cluster, such as Figure 3 As shown, the method includes the following steps:

[0080] Step S201: Receive the cluster head node CH j The first protection value R sent j , the first protection value R j Cluster head node CHj Based on the randomly generated challenge random number r j Specifically, the first protection value R j is the cluster head node CH j According to the formula Calculated.

[0081] Step S202: Based on the first protection value R j and pre-stored secret information x i And the characteristic data puf of the physical unclonable function i Encryption generates integrity verification encryption value Epos and second protection value R i , and the integrity verification encrypted value Epos and the second protection value R i Sent to cluster head node CH j Specifically, when generating the integrity verification encryption value Epos and the second protection value R i Before, according to the cluster head node CH j Send the first protection value R j The first timestamp T1 carried by the message is used to determine whether the message has timed out. If not, the calculation continues. If it has timed out, the authentication ends.

[0082] Step S203: Receive the cluster head node CH j The verification information DB sent by the cluster head node CH j For the second protection value R i Decrypt to obtain the recovery value puf of the feature data i * , based on the recovery value puf of feature data i * and challenge random number r j Execute the physical unclonable function to obtain the second response output value K j , according to the second response output value K j , integrity verification encryption value Epos and challenge random number r j Generate the second session key SK ji and use the second session key SK ji The first preset information is encrypted.

[0083] Step S204: decrypt the verification information DB and verify whether the decrypted data is correct, and determine whether the authentication is completed based on the verification result. Specifically, before decrypting the verification information DB, the cluster head node CH jThe third timestamp T3 carried when sending the verification information DB is used to determine whether the message has timed out, that is, whether the difference between the third timestamp T3 and the current time is greater than the set value. If it is, it has timed out, otherwise it has not timed out. If it has not timed out, the verification information DB is decrypted and the decrypted data is verified to be correct. The lightweight decryption function is used to decrypt the verification information DB. The decrypted data includes the recovery value of the cluster head random number. And the third integrity verification value V, the third integrity verification value V is the second session key SK ji , the third timestamp T3, the random number recovery value within the cluster Challenge random number r j , ID of the node in the cluster i and masquerade identity value PID j Verify whether the third integrity verification value V is correct, that is, determine whether the third integrity verification value V is equal to h(SK ij ||T3||r i ||r j * ||ID i ||PID j ), if they are equal, the authentication is completed and the session key is generated; if they are not equal, the authentication fails.

[0084] A node authentication method of a sensor network according to an embodiment of the present invention is provided by receiving a cluster head node CH j The first protection value R sent j , the first protection value R j Cluster head node CH j Based on the randomly generated challenge random number r j Encrypted and generated based on the first protection value R j and pre-stored secret information x i And the characteristic data puf of the physical unclonable function i Encryption generates integrity verification encryption value Epos and second protection value R i , and the integrity verification encrypted value Epos and the second protection value R i Sent to cluster head node CH j , receiving cluster head node CH j The verification information DB sent is decrypted and the decrypted data is verified to be correct. Based on the verification result, the authentication is determined to be complete. When the cluster head node and the nodes within the cluster perform authentication, the base station does not need to participate, which reduces the computational workload of the base station and avoids attacks by attackers with privileges as internal members of the base station. This improves the security of the authentication process and enhances the scalability of the sensor network.

[0085] In one embodiment, step S202, based on the first protection value R jand pre-stored secret information x i And the characteristic data puf of the physical unclonable function i Encryption generates integrity verification encryption value Epos and second protection value R i ,include:

[0086] Step S221: First protection value R j Decrypt to get the recovery value r of the challenge random number j * , according to the recovery value r of the challenge random number j * Generate the first challenge value pos i Specifically, according to the formula: Recover the recovery value r of the challenge random number j * , then verify the cluster head node CH j The first integrity verification value V sent j Is it equal to Thus, it is determined whether to continue verification. The first integrity verification value V j Cluster head node CH j The identity value ID of the node in the cluster i , disguised identity value PID j , challenge random number r j , the first timestamp T1 and the encrypted value of the characteristic data obpuf i The hash operation is performed to encrypt the result. Then the recovery value r of the challenge random number is j * Calculate the first challenge value pos i =h(r j * ||ID i ||PID j ).

[0087] Step S222: According to the first challenge value pos i and the characteristic data puf of the physical unclonable function i Execute the physical unclonable function to get the first response output value K i , that is, K i =PUF(puf i ,pos i ).

[0088] Step S223: Output value K according to the first response i , challenge the recovery value r of the random number j * and a randomly selected random number r within the cluster i , generate the first session key SKij Specifically, the first session key SK ij The calculation formula is: SKi j =h(ID i ||PID j ||K i ||r i ||r j * ), through the hash function to identify the node ID in the cluster i , disguised identity value PID j , first response output value K i , random number r within the cluster i and the recovery value r of the challenge random number j * Perform calculation to obtain the first session key SK ij . Generate random numbers r in the cluster i When , a second timestamp T2 is also generated.

[0089] Step S224: Output value K according to the first response i The first session key SK ij , first challenge value pos i , random number r within the cluster i , challenge the recovery value r of the random number j * and feature data puf i Encryption is performed to generate an integrity verification encryption value Epos. Specifically, a hash operation is performed on the third preset information to obtain a second integrity verification value V i , wherein the third preset information includes the first session key SK ij , first challenge value pos i , random number r within the cluster i , challenge the recovery value r of the random number j * and feature data puf i , the second integrity verification value V i The calculation formula is: V i =h(SK ij ||pos i ||r i ||r j * ||puf i ||T2), using the first response output value K i Encrypt the random number r in the cluster for the lightweight encryption function of the key i and the second integrity verification value V i Get the integrity verification encryption value Epos, that is

[0090] Step S225: The pre-stored secret information x i Encrypted to obtain the second protection value R i Specifically, calculate the characteristic data puf i With secret information x i The hash value of the secret information x i Perform an XOR operation with the hash value to obtain the second protection value R i , that is, through the formula Encrypt and hide secret informationx i , get the second protection value R i .

[0091] The embodiment of the present invention performs the authentication process through hash functions, PUF and lightweight encryption and decryption algorithms. Compared with asymmetric encryption, it can reduce the computational cost of the authentication process, and the security performance can also achieve the security requirements that can be achieved by asymmetric encryption.

[0092] In one embodiment, after decrypting the verification information and verifying whether the decrypted data is correct in step S204, the following steps are further included:

[0093] Step S205: If the verification is correct, the pre-stored secret information x i Update to the recovery value of the cluster head random number The recovery value of the cluster head random number is obtained by decrypting the verification information DB. Specifically, the verification information DB is decrypted using a lightweight decryption function, and the decrypted data obtained includes the recovery value of the cluster head random number. And the third integrity verification value V, namely After verifying that the third integrity verification value V is correct, the cluster node CM i The secret information x stored in i Replaced with the recovery value of the cluster head random number By updating the CM of the cluster nodes during each authentication process i The secret information x stored in i Even if the attacker breaks into the cluster head node and obtains its internal long-term key, due to the cluster node CM i The secret value of the authentication process is different in different values, and the attacker cannot recover the previous session key, thus achieving the forward security of the session key between the cluster node and the cluster head node.

[0094] In one embodiment, the cluster head node CH j and the nodes CM in the cluster i The certification process is as follows Figure 4 and Figure 6 shown.

[0095] Cluster head node CH jGenerate a challenge random number r j and the first timestamp T1, then calculate the node CM in the cluster i The aliased identity value PID j =h(ID j ||sec) mod n, encrypt the value obpuf based on the first timestamp T1 and the stored feature data i The hash value of the challenge random number t j Encrypt to get the first protection value R j , the identity value ID of the node in the cluster i , disguised identity value PID j , challenge random number r j , the first timestamp T1 and the encrypted value of the characteristic data obpuf i Perform hash operation encryption to obtain the first integrity verification value V j , then set the first protection value R j , first integrity verification value V j and the first timestamp T1 are sent to the cluster node CM via the common channel i Denoted as MSG1={R j , V j , T1}.

[0096] Cluster node CM i Received from cluster head node CH j Sent MSG1 = {R j , V j , T1}, determine whether it has timed out according to the first timestamp T1. If it has timed out, the authentication is terminated. If it has not timed out, the authentication is continued according to the formula: Recover the recovery value r of the challenge random number j * , then verify the cluster head node CH j The first integrity verification value V sent j Is it equal to So as to determine whether to continue verification. If yes, randomly generate a random number r in the cluster i and the second timestamp T2, according to the recovery value r of the challenge random number j * Calculate the first challenge value pos i =h(r j * ||ID i ||PID j ), the pre-stored secret information x i Encrypted to obtain the second protection value R i ,Right now According to the first challenge value pos iand the characteristic data puf of the physical unclonable function i Execute the physical unclonable function to get the first response output value K i , that is, K i =PUF(puf i ,pos i ), then generate the first session key SK ij SK ij =h(ID i ||PID j ||K i ||r i ||r j * ), calculate the second integrity verification value V i , V i =h(SK ij ||pos i ||r i ||r j * ||puf i ||T2), and then use the first response output value K i Encrypt the random number r in the cluster for the lightweight encryption function of the key i and the second integrity verification value V i Get the integrity verification encryption value Epos, that is Then the integrity verification encryption value Epos and the second protection value R i And the second timestamp T2, namely MSG2 = {Epos, R i , T2} is sent to the cluster head node CH j .

[0097] Cluster head node CH j Receive MSG2 = {Epos, R i , T2}, judge whether it is timed out according to the second timestamp T2, if it is timed out, the authentication is terminated, if not, the authentication is continued, and the challenge random number r j , ID of the node in the cluster i and masquerade identity value PID j Perform hash operation to obtain the first challenge value pos j , that is, pos j =h(r j ||ID i ||PID j ), and then the restored value puf of the feature data i * and the first challenge value pos j Execute the physical unclonable function to obtain the second response output value K j , that is, K j=PUF(puf i * ,pos j ), the second protection value R i , the second timestamp T2 and the encrypted value of the characteristic data obpuf i The hash value is XORed to recover the recovery value of the secret information Right now The recovered value of the secret information And the encrypted value of characteristic data obpuf i Perform an XOR operation, that is Restore the recovery value puf of the feature data i * , use the second response output value K j The lightweight decryption function of the key decrypts the integrity verification encrypted value Epos to obtain the random number recovery value r within the cluster i * and the second integrity verification value V i Right now Use the obtained data to calculate the second session key SK ji =h(ID i ||PID j ||K j ||r i * ||r j ), determine the second integrity verification value V i Is it equal to h(SK ji ||pos j ||r i * ||r j ||puf i ||T2), if they are equal, randomly generate a cluster head random number x j and the third timestamp T3, using a lightweight encryption function to encrypt the third integrity verification value V and the randomly generated cluster head random number x j Encrypt to obtain verification information DB, the encryption formula is: The cluster head random number x k The restored value puf of the feature data i * Perform XOR operation to obtain the encrypted update value of the feature data obpuf j new ,Right now Encrypt the pre-stored feature data to obpuf j Update to the encrypted update value obpuf of the feature data j newThen the verification information DB and the third timestamp T3, ie MSG3 = {DB, T3}, are sent to the node CM in the cluster. i .

[0098] Cluster node CM i According to the cluster head node CH j The third timestamp T3 carried when sending the verification information DB is used to determine whether the message has timed out. If not, the lightweight decryption function is used to decrypt the verification information DB to obtain The decrypted data includes the recovery value of the cluster head random number And the third integrity verification value V, the third integrity verification value V is the second session key SK ji , the third timestamp T3, the random number recovery value r within the cluster i * , challenge random number r j , ID of the node in the cluster i and masquerade identity value PID j Verify whether the third integrity verification value V is equal to h(SK ij ||T3||r i ||r j * ||ID i ||PID j ), if it is equal, then the pre-stored secret information x i Update to the recovery value of the cluster head random number Then the authentication is completed and a session key is generated. If they are not equal, the authentication fails.

[0099] The embodiment of the present invention resists node capture attacks and temporary key attacks by introducing a physical unclonable function (PUF). The physical unclonable function (PUF) outputs a unique and unpredictable output based on the stimulus value. At the same time, due to its non-volatility, the physical unclonable function (PUF) does not store any keys. Each time a key is needed, it must be obtained through the physical unclonable function (PUF). This prevents attackers from obtaining the keys stored in the device through hardware attacks such as side channel attacks. After the key is generated, the secret information x stored in the nodes within the cluster is updated. i and the encrypted value of characteristic data in the cluster head node obpuf j The anonymity of the authentication node is guaranteed in the form of.

[0100] Furthermore, to accommodate the widespread adoption of applications with large numbers of sensor nodes within the Internet of Things (IoT), the authentication process in this embodiment of the present invention does not require the participation of a base station. Each node joining a cluster stores its own secret information, which is generated by the registration center during the registration phase and packaged and transmitted to the cluster head node. This ensures that attackers cannot obtain the secret value from the registration center or cluster head node, thus preventing node capture attacks. After generating the key, the cluster head node generates a new pseudo-random identity for each node in the cluster. This ensures that each authentication uses a different identity, ensuring both anonymity and forward security.

[0101] Furthermore, many existing protocols use asymmetric algorithms similar to ECC to protect against more attacks. However, in the embodiments of the present invention, the introduction of a physically unclonable function (PUF) and a lightweight symmetric algorithm can achieve the same goal. Asymmetric algorithms are based on the difficulty of the problem and are computationally intensive. PUFs are hardware-based and very fast, while lightweight algorithms reduce the number of computational steps. Both algorithms have significantly lower computational costs than asymmetric algorithms.

[0102] The embodiment of the present invention also provides a cluster head node of a sensor network, such as Figure 7 Shown, including:

[0103] The challenge module 701 is used to generate a challenge random number, encrypt the challenge random number into a first protection value, and send the first protection value to the nodes in the cluster. For details, please refer to the corresponding part of the above method embodiment and will not be repeated here.

[0104] The first receiving module 702 is used to receive the integrity verification encryption value and the second protection value generated by the node in the cluster based on the first protection value and the pre-stored secret information and the characteristic data of the physical unclonable function; the specific content can be found in the corresponding part of the above method embodiment, which will not be repeated here.

[0105] The first decryption module 703 is used to decrypt the second protection value to obtain the restored value of the characteristic data; for details, please refer to the corresponding part of the above method embodiment, which will not be repeated here.

[0106] The execution module 704 is used to execute a physical unclonable function based on the recovered value of the feature data and the challenge random number to obtain a second response output value; the specific content can be found in the corresponding part of the above method embodiment, which will not be repeated here.

[0107] The first encryption module 705 is configured to generate a second session key based on the second response output value, the integrity verification encrypted value, and the random challenge number, encrypt the first preset information using the second session key to obtain verification information, and send the verification information to the nodes in the cluster for node authentication. For details, refer to the corresponding section of the above method embodiment and will not be repeated here.

[0108] The node authentication device of the sensor network of the embodiment of the present invention authenticates the nodes in the cluster based on the secret information pre-stored by the nodes in the cluster and the characteristic data of the physically unclonable function. During the authentication process, the cluster head node only needs to perform information exchange with the nodes in the cluster and verify whether the information of each other is correct to perform authentication. The base station does not need to participate in the authentication process, which reduces the calculation amount of the base station and avoids privileged attacks by attackers as internal members of the base station, improves the security of the authentication process, and also enhances the scalability of the sensor network.

[0109] The embodiment of the present invention also provides a cluster node of a sensor network, such as Figure 8 Shown, including:

[0110] The second receiving module 801 is used to receive a first protection value sent by the cluster head node, where the first protection value is generated by the cluster head node based on a randomly generated challenge random number. For details, please refer to the corresponding part of the above method embodiment and will not be repeated here.

[0111] The second encryption module 802 is used to encrypt and generate an integrity verification encryption value and a second protection value based on the first protection value and pre-stored secret information and characteristic data of the physical unclonable function, and send the integrity verification encryption value and the second protection value to the cluster head node; for specific content, please refer to the corresponding part of the above method embodiment, which will not be repeated here.

[0112] The third receiving module 803 is used to receive verification information sent by the cluster head node, where the verification information is obtained by the cluster head node decrypting the second protection value to obtain the recovery value of the feature data, executing a physical unclonable function based on the recovery value of the feature data and the challenge random number to obtain a second response output value, generating a second session key according to the second response output value, the integrity verification encryption value and the challenge random number, and encrypting the first preset information using the second session key; for specific content, please refer to the corresponding part of the above method embodiment, which will not be repeated here.

[0113] The verification module 804 is used to decrypt the verification information and verify whether the decrypted data is correct, and determine whether the authentication is completed based on the verification result. For details, please refer to the corresponding part of the above method embodiment, which will not be repeated here.

[0114] The node authentication device of the sensor network of the embodiment of the present invention does not require the participation of the base station when authenticating the cluster head node and the nodes within the cluster, which reduces the calculation amount of the base station and avoids the privileged attack of the attacker as an internal member of the base station, improves the security of the authentication process, and also enhances the scalability of the sensor network.

[0115] The embodiment of the present invention also provides a sensor network node authentication system, such as Figure 9 As shown, it includes a cluster head node and a node in the cluster; the cluster head node generates a challenge random number, and encrypts the challenge random number into a first protection value and then sends the first protection value to the node in the cluster; the node in the cluster receives the first protection value sent by the cluster head node, encrypts the integrity verification encryption value and the second protection value based on the first protection value and pre-stored secret information and characteristic data of the physical unclonable function, and sends the integrity verification encryption value and the second protection value to the cluster head node; the cluster head node receives the integrity verification encryption value generated by the node in the cluster based on the first protection value and the pre-stored secret information and characteristic data of the physical unclonable function. The system comprises a first authentication method and a second authentication method, wherein the first authentication method comprises a first authentication method and a second protection value; a second authentication method and a second protection value are used to authenticate the encrypted value and the second protection value; the second protection value is decrypted to obtain the recovered value of the characteristic data; a physical unclonable function is executed based on the recovered value of the characteristic data and the challenge random number to obtain a second response output value; a second session key is generated based on the second response output value, the integrity verification encrypted value, and the challenge random number; the first preset information is encrypted using the second session key to obtain verification information; the verification information is sent to a node within the cluster for node authentication; the node within the cluster receives the verification information sent by the cluster head node, decrypts the verification information, verifies whether the decrypted data is correct, and determines whether authentication is complete based on the verification result. The specific working principle of the system is described in the corresponding part of the above-mentioned method embodiment and is not further described here. The node authentication system for a sensor network of the embodiment of the present invention authenticates nodes within the cluster based on secret information pre-stored by the nodes within the cluster and characteristic data of the physical unclonable function. During the authentication process, the cluster head node only needs to exchange information with the nodes within the cluster and verify whether the information between them is correct to perform authentication. The base station does not need to participate in the authentication process, which reduces the computational workload of the base station and avoids privileged attacks by attackers as internal members of the base station, improves the security of the authentication process, and enhances the scalability of the sensor network.

[0116] The embodiment of the present invention also provides a node authentication device, such as Figure 10As shown, it includes: a memory 420 and a processor 410, the memory 420 and the processor 410 are communicatively connected to each other, the memory 420 stores computer instructions, and the processor 410 executes the computer instructions to execute the node authentication method of the sensor network in the above embodiment of the present invention. The processor 410 and the memory 420 can be connected via a bus or other means. The processor 410 can be a central processing unit (CPU). The processor 410 can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components and other chips, or a combination of the above types of chips. The memory 420, as a non-transitory computer storage medium, can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as the corresponding program instructions / modules in the embodiments of the present invention. The processor 410 executes various functional applications and data processing of the processor 410 by running the non-transitory software programs, instructions, and modules stored in the memory 420, that is, implementing the node authentication method of the sensor network in the above-mentioned method embodiment. The memory 420 may include a program storage area and a data storage area, wherein the program storage area may store operating devices, applications required for at least one function; the data storage area may store data created by the processor 410, etc. In addition, the memory 420 may include a high-speed random access memory 420, and may also include a non-transitory memory 420, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory 420 may optionally include a memory 420 remotely located relative to the processor 410, and these remote memories 420 may be connected to the processor 410 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. One or more modules are stored in the memory 420, and when executed by the processor 410, the node authentication method of the sensor network in the above-mentioned method embodiment is executed. The specific details of the above electronic device can be understood by referring to the corresponding descriptions and effects in the above method embodiments, and will not be repeated here.

[0117] The embodiment of the present invention also provides a computer readable storage medium, such as Figure 11As shown, a computer program 510 is stored thereon. When the instructions are executed by the processor, the steps of the node authentication method of the sensor network in the above embodiment are implemented. The storage medium also stores audio and video stream data, feature frame data, interaction request signaling, encrypted data, and preset data size. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk drive (HDD) or a solid-state drive (SSD); the storage medium can also include a combination of the above types of memory. Those skilled in the art will understand that all or part of the processes in the above embodiment method can be implemented by instructing the relevant hardware through a computer program. The computer program 13 can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the storage medium may also include a combination of the above types of memory.

[0118] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A sensor network node authentication method, characterized in that: Applied to cluster head nodes, including: Generate a challenge random number, encrypt the challenge random number into a first protection value, and then send the first protection value to the nodes in the cluster; Receiving an integrity verification encryption value and a second protection value generated by the node in the cluster based on the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function; decrypting the second protection value to obtain a restored value of the characteristic data; executing a physical unclonable function based on the recovered value of the feature data and the challenge random number to obtain a second response output value; A second session key is generated according to the second response output value, the integrity verification encryption value and the challenge random number, the first preset information is encrypted using the second session key to obtain verification information, and the verification information is sent to the node in the cluster for node authentication.

2. The sensor network node authentication method according to claim 1, characterized in that: Sending the first protection value to nodes in the cluster includes: Performing a hash operation on the second preset information to obtain a first integrity verification value; The first integrity verification value and the first protection value are sent to nodes within the cluster.

3. The sensor network node authentication method according to claim 1, characterized in that: Generating a second session key according to the second response output value, the integrity verification encrypted value, and the challenge random number includes: Decrypt the integrity verification encrypted value using a lightweight decryption function with the second response output value as a key to obtain an intra-cluster random number recovery value and a second integrity verification value; Performing a hash operation on the second response output value, the intra-cluster random number recovery value, the challenge random number, and the pre-acquired identity information of the authentication node to obtain a second session key; The second integrity verification value is verified according to the second session key, and whether to proceed to the next authentication step is determined according to the verification result.

4. The sensor network node authentication method according to claim 1, characterized in that: Decrypting the second protection value to obtain a restored value of the characteristic data includes: decrypting the second protection value to obtain a recovery value of the secret information; The pre-stored encrypted value of the characteristic data is decrypted according to the restored value of the secret information to obtain the restored value of the characteristic data.

5. The sensor network node authentication method according to claim 1, characterized in that: Encrypting the first preset information using the second session key to obtain verification information includes: Performing a hash operation on the fourth preset information to obtain a third integrity verification value; The first preset information is encrypted using a lightweight encryption function using the second session key as a key to obtain verification information, wherein the first preset information is obtained by performing a bit connection operation on the third integrity verification value and a randomly generated cluster head random number.

6. The sensor network node authentication method according to claim 5, characterized in that: After encrypting the first preset information using the second session key to obtain verification information, the method further includes: Encrypting the restored value of the characteristic data according to the cluster head random number to obtain an encrypted updated value of the characteristic data; The pre-stored encrypted value of the characteristic data is updated based on the encrypted update value of the characteristic data.

7. A sensor network node authentication method, characterized in that: Applicable to nodes within the cluster, including: Receiving a first protection value sent by a cluster head node, where the first protection value is encrypted and generated by the cluster head node based on a randomly generated challenge random number; Encrypting the integrity verification encryption value and the second protection value based on the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function, and sending the integrity verification encryption value and the second protection value to the cluster head node; Receiving verification information sent by a cluster head node, the verification information is obtained by the cluster head node decrypting the second protection value to obtain a recovery value of the feature data, executing a physical unclonable function based on the recovery value of the feature data and the challenge random number to obtain a second response output value, generating a second session key according to the second response output value, the integrity verification encrypted value, and the challenge random number, and encrypting the first preset information using the second session key; The verification information is decrypted and the decrypted data is verified to be correct, and whether the authentication is completed is determined based on the verification result.

8. The sensor network node authentication method according to claim 7, characterized in that: Encrypting the integrity verification encryption value and the second protection value based on the first protection value, pre-stored secret information, and characteristic data of the physical unclonable function includes: Decrypting the first protection value to obtain a recovery value of the challenge random number, and generating a first challenge value according to the recovery value of the challenge random number; executing the physical unclonable function according to the first challenge value and characteristic data of the physical unclonable function to obtain a first response output value; generating a first session key based on the first response output value, the recovery value of the challenge random number, and a randomly selected intra-cluster random number; Encrypting the first session key, the first challenge value, the intra-cluster random number, the recovery value of the challenge random number, and the characteristic data according to the first response output value to generate the integrity verification encrypted value; The pre-stored secret information is encrypted to obtain the second protection value.

9. The sensor network node authentication method according to claim 8, characterized in that: Encrypting the first session key, the first challenge value, the intra-cluster random number, the recovery value of the challenge random number, and the characteristic data according to the first response output value to generate the integrity verification encrypted value includes: Performing a hash operation on third preset information to obtain a second integrity verification value, wherein the third preset information includes the first session key, the first challenge value, the intra-cluster random number, a recovery value of the challenge random number, and the characteristic data; The in-cluster random number and the second integrity verification value are encrypted using a lightweight encryption function with the first response output value as a key to obtain the integrity verification encrypted value.

10. The sensor network node authentication method according to claim 9, characterized in that: After decrypting the verification information and verifying whether the decrypted data is correct, the method further includes: If the verification is correct, the pre-stored secret information is updated to the recovery value of the cluster head random number, wherein the recovery value of the cluster head random number is obtained by decrypting the verification information.

11. A cluster head node of a sensor network, characterized in that: include: A challenge module, configured to generate a challenge random number, encrypt the challenge random number into a first protection value, and then send the first protection value to nodes in the cluster; A first receiving module is configured to receive an integrity verification encryption value and a second protection value generated by the node in the cluster according to the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function; a first decryption module, configured to decrypt the second protection value to obtain a restored value of the characteristic data; an execution module, configured to execute a physical unclonable function based on the recovered value of the feature data and the challenge random number to obtain a second response output value; The first encryption module is used to generate a second session key based on the second response output value, the integrity verification encryption value and the challenge random number, use the second session key to encrypt the first preset information to obtain verification information, and send the verification information to the node in the cluster for node authentication.

12. A node in a cluster of a sensor network, characterized in that: include: A second receiving module is configured to receive a first protection value sent by a cluster head node, where the first protection value is encrypted and generated by the cluster head node based on a randomly generated challenge random number; A second encryption module is configured to generate an integrity verification encryption value and a second protection value based on the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function, and send the integrity verification encryption value and the second protection value to the cluster head node; a third receiving module, configured to receive verification information sent by a cluster head node, the verification information being obtained by the cluster head node decrypting the second protection value to obtain a recovery value of the feature data, executing a physical unclonable function based on the recovery value of the feature data and the challenge random number to obtain a second response output value, generating a second session key according to the second response output value, the integrity verification encrypted value, and the challenge random number, and encrypting the first preset information using the second session key; The verification module is used to decrypt the verification information and verify whether the decrypted data is correct, and determine whether the authentication is completed based on the verification result.

13. A sensor network node authentication system, characterized in that: Including cluster head nodes and nodes within the cluster; The cluster head node generates a challenge random number, encrypts the challenge random number into a first protection value, and then sends the first protection value to the nodes in the cluster; The cluster node receives a first protection value sent by the cluster head node, generates an integrity verification encryption value and a second protection value based on the first protection value and pre-stored secret information and characteristic data of a physical unclonable function, and sends the integrity verification encryption value and the second protection value to the cluster head node; The cluster head node receives an integrity verification encryption value and a second protection value generated by the node in the cluster according to the first protection value, pre-stored secret information, and characteristic data of a physical unclonable function; decrypting the second protection value to obtain a restored value of the feature data; executing a physical unclonable function based on the restored value of the feature data and the challenge random number to obtain a second response output value; generating a second session key based on the second response output value, the integrity verification encrypted value, and the challenge random number, encrypting the first preset information using the second session key to obtain verification information, and sending the verification information to a node in the cluster for node authentication; The nodes in the cluster receive the verification information sent by the cluster head node, decrypt the verification information and verify whether the decrypted data is correct, and determine whether the authentication is completed based on the verification result.

14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the node authentication method for a sensor network according to any one of claims 1 to 10.

15. A node authentication device for a sensor network, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the node authentication method for a sensor network according to any one of claims 1 to 10 by executing the computer instructions.

Citation Information

Patent Citations

  • Embedded system encryption protection device and method based on AES algorithm and PUF technology

    CN111082925A

  • Key distribution method based on physical unclonable function in wireless sensor network

    CN111278009A