Multi-attribute terminal identity authentication method and system based on zero trust

Through the multi-attribute terminal identity authentication method based on the zero-trust architecture, the trust evaluation and identity authentication problems of drones in the 6G vehicle network are solved, and fast, secure and lightweight identity authentication between vehicle terminals and drones is realized, and emergency services and flexible edge computing services are supported.

CN116321147BActive Publication Date: 2025-08-15XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310081032.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-01
Publication Date
2025-08-15
Estimated Expiration
2043-02-01

AI Technical Summary

Technical Problem

The existing technology cannot provide 3D ubiquitous network coverage for 6G vehicle networking, cannot effectively manage trust evaluation and identity authentication of drone groups, lacks response solutions for scenarios where vehicle terminals are hijacked, and the authentication process has a large calculation overhead and is not real-time, which cannot meet the needs of emergency services.

Method used

Using a multi-attribute terminal identity authentication method based on a zero-trust architecture, through the collaborative work of edge computing servers and cloud servers, fast identity authentication and key negotiation between vehicle terminals and drones are realized, and calculation overhead is reduced using Chebischev chaotic mapping algorithm and hashing algorithm, and dynamically evaluate trust values to select suitable drones to provide emergency services.

Benefits of technology

It realizes fast, secure and lightweight identity authentication between vehicle terminals and drones in emergencies, reduces signaling and computing overhead, ensures the security of data transmission and user privacy, and supports flexible edge computing services and emergency response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116321147B_ABST
    Figure CN116321147B_ABST
Patent Text Reader

Abstract

The present invention provides a multi-attribute terminal identity authentication method and system based on zero trust. During the registration phase, the cloud server registers each edge computing server and vehicle terminal. During the edge authentication phase, the vehicle terminal generates a session key for the session through authentication with the edge computing server. During the drone initialization phase, each edge server sends initialization information to the drones it manages. During the emergency task scheduling phase, each edge computing server initiates an application service response based on the urgency of the task and selects a target drone. During the terminal and drone identity authentication phase, the drone and vehicle terminal verify and generate a temporary session key, thereby utilizing the temporary session key for the session. This invention can ensure efficient, timely, and secure network communication between vehicle terminals in emergency situations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of Internet of Vehicles, and specifically relates to a multi-attribute terminal identity authentication method and system based on zero trust. Background Art

[0002] With the advancement of communication technology and the increasing demand for information, sixth-generation mobile communication systems have attracted widespread attention and research from both academia and industry. Compared to 5G networks, 6G networks will further enhance performance in terms of transmission rate, reliability, connection density, and spectrum efficiency to meet diverse and complex business needs. For vehicular ad hoc networks (V2Ns), the mobile edge computing services of the 6G V2N require multi-dimensional and ubiquitous network coverage to facilitate intensive computing tasks and data distribution. Traditional cellular networks, designed to serve two-dimensional networking environments, struggle to meet the interconnectivity and integrated ground-to-space connectivity required by 6G networks. Drones, with their high flexibility, powerful functionality, and low cost, can effectively promote the development of multi-dimensional wireless communication networks, providing efficient wireless coverage solutions for V2Ns and helping to foster the formation of multi-source, heterogeneous, and cross-domain converged V2N networks. For example, drones can act as aerial base stations to provide network coverage for ground-based vehicles, or as relays for vehicle-to-vehicle or vehicle-to-server data transmission. Furthermore, drones, working together to form swarms, can perform dangerous tasks in remote areas, such as target detection, disaster management, and reconnaissance and surveillance. UAV networks typically rely on missions for communication. When executing complex tasks, drones must autonomously learn about their surroundings, data transmission, and mission execution strategies. With the increasing complexity of 6G connected vehicle services and mission environments, fixed-location edge servers may be unable to accurately and timely grasp global information. Drones must make task-driven resource decisions. Even without real-time control from ground stations, UAV networks must ensure secure and effective communications.

[0003] Existing drone communication network architectures can be categorized into four types: pre-configured, base station-assisted, fully distributed, and clustered networks. Fully distributed networks have high performance requirements, are difficult to manage, and hinder mission deployment. Clustered networks are suitable for scenarios with relatively fixed missions and environments, but struggle to cope with the constant entry and exit of drones. Base station-assisted communication networks enable drones to maintain a constant connection with ground-based edge computing servers (MEC servers), enabling real-time, multi-dimensional auxiliary services such as hotspot coverage and aerial monitoring. Pre-configured communication networks allow drones to pre-load instructions into their systems, which then execute their missions according to pre-configured instructions. Therefore, researchers, using deep learning and game theory, have developed strategies for handling high and low traffic flow periods and common traffic emergencies. This approach enables drones to provide multi-dimensional, intensive edge computing services to connected vehicles in the air under normal circumstances. In emergencies, the MEC server issues tasks to drones and derives implementation strategies based on pre-configured instructions, enabling timely response to emergencies. For example, to prevent vehicle terminals from being illegally hijacked, under normal circumstances, if an unmanned aerial vehicle (UAV) detects a vehicle terminal deviating from its route or remaining in a remote or unsafe location for an extended period, it can request access to the vehicle terminal's surveillance video. The data can then be analyzed and processed locally to determine whether the terminal has been maliciously hijacked. If an abnormality is detected within the vehicle, the video can be immediately sent to relevant authorities for an alert or emergency response, ensuring the safety of the terminal user. If the vehicle leaves the MEC Server's monitoring range (enters a network blind spot) or is maliciously equipped with a signal jammer, the MEC Server may be unable to detect the vehicle terminal's signal or location. If the signal suddenly disappears and cannot be reconnected during normal driving, the vehicle may be considered abnormal. Therefore, drones can be dispatched to search centered on the location where the signal was last seen. Once the vehicle terminal is located, the in-vehicle video is captured to determine whether it is safe and requires emergency services. In this case, a dynamic drone swarm can be dispatched to search within the area where the vehicle signal was last detected, relying on its field of view to capture in-vehicle video information for analysis and processing. After a drone equipped with a MEC Server finds a vehicle, it can request access to the vehicle's internal monitoring resources. To ensure communication security, identity authentication and authorization must be implemented between the vehicle terminal and the UAV before data transmission.

[0004] Based on the Chinese remainder theorem, LEI et al. proposed a lightweight authentication protocol for UAV networks to authenticate user equipment (UE) and UAVs. This protocol has low computational overhead, but the authentication process requires server assistance, resulting in high signaling overhead. The authentication messages are not integrity-protected, and the key confirmation step is missing. Furthermore, this scheme uses the round i key and identity ID to perform round i+1 authentication, updating the key after authentication. If an attacker intercepts and tampers with messages, synchronization between the UAV and UE session keys will fail, making it impossible to support emergency services in connected vehicles. The UAV authentication scheme proposed by Mohammad et al., based on hashing and XOR, has low computational overhead and offers higher security than the scheme proposed by LEI et al. However, it shares the same issues as the scheme proposed by LEI et al.: the authentication process requires server assistance, making it impossible for a UAV to remotely assist a UE in the authentication process. Furthermore, this scheme lacks a key confirmation step, and authentication fails if the UE fails to receive key parameters for an extended period.

[0005] Through the above analysis, the existing technology has the following problems and defects:

[0006] (1) Existing cellular networks mainly rely on fixed deployment of ground base stations and cannot provide 3D and ubiquitous network coverage for next-generation (6G) Internet of Vehicles applications to achieve intensive computing tasks and data distribution.

[0007] (2) For drone swarms managed by edge computing servers, there is a possibility of physical capture during auxiliary scheduling, which often stores private information of vehicle terminals. How to dynamically evaluate the trust indicators of drones based on the relevant processes of their auxiliary services and use them to perform dynamic drone identity authentication management? Existing technologies lack corresponding solutions.

[0008] (3) Existing technologies lack the ability to analyze and process the connection status of vehicle terminals (e.g., long periods of disconnection). It is unclear how to autonomously define the urgency and security level of the services required by vehicle terminals.

[0009] (4) The existing technology lacks a solution to the scenario where the vehicle terminal is illegally hijacked. Relying solely on a server deployed at a fixed location to manage the vehicle terminal can only identify the security of the vehicle terminal under normal connectivity. In special circumstances (such as when the vehicle terminal enters a network coverage blind spot or is maliciously equipped with a signal blocker), there is no solution to detect the safety of the vehicle.

[0010] (5) For drones with weaker computing and storage capabilities, the authentication process of existing Internet of Vehicles involves many entities and a large amount of signaling, and it may be difficult to guarantee real-time performance when directly applied between vehicle terminals and drones.

[0011] To address emergencies such as vehicle hijacking and loss of connectivity in connected vehicle scenarios, a dynamic drone-assisted V2X scenario is necessary to provide 3D and ubiquitous network coverage for next-generation V2X edge computing services, enabling intensive computing tasks and data delivery. Given the low computing power, low storage capacity, high power consumption, and susceptibility to physical capture of drones, the vehicle-to-drone authentication protocol must not only meet real-time requirements, reliability, and efficiency, but also utilize lightweight cryptographic algorithms to reduce computational overhead while ensuring protocol security. This allows for bidirectional drone-vehicle authentication and key agreement in edge computing, and in-vehicle data transmission based on this key for vehicle security analysis. Furthermore, the security risks inherent in drone dispatching and the trustworthiness of vehicle terminals after disconnection must be considered. Therefore, a mechanism is needed to dynamically assess the trustworthiness of both the vehicle terminal and the drone throughout the service process, and to dynamically implement drone dispatch selection and mutual authentication based on this trustworthiness. Summary of the Invention

[0012] In order to solve the above problems existing in the prior art, the present invention provides a multi-attribute terminal identity authentication method and system based on zero trust. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0013] The present invention provides a zero-trust-based multi-attribute terminal identity authentication method, which is applied to a zero-trust-based multi-attribute terminal identity authentication system. The zero-trust-based multi-attribute terminal identity authentication system comprises an edge computing server and a cloud server. The edge computing server can communicate with multiple drones and multiple vehicle terminals respectively. The zero-trust-based multi-attribute terminal identity authentication method includes:

[0014] During the registration phase, each edge computing server and vehicle terminal sends a registration request to the cloud server, and the cloud server returns the first registration information of each edge computing server and the second registration information of the vehicle terminal;

[0015] In the edge authentication phase, the vehicle terminal sends an access authentication request to the edge computing server. The edge computing server authenticates the vehicle terminal using the information carried in the access authentication request and its own information, and negotiates a session key with the vehicle terminal.

[0016] During the drone initialization phase, each edge server sends the drone initialization information for the drone it controls;

[0017] During the emergency task scheduling phase, each edge computing server determines the task urgency based on the vehicle terminal's connection status. When the task urgency reaches the required level, it selects a target drone with sufficient resources and the highest trust value from the drone list it maintains, and issues a service scheduling request to the target drone, thereby initiating an application service response. The target drone verifies whether the service scheduling request is legal, obtains the authentication parameters of the auxiliary vehicle terminal, and generates a safety detection identification for the response.

[0018] During the identity authentication stage between the terminal and the drone, the drone completes the authentication of the vehicle terminal through the session key negotiated with the vehicle terminal in the edge authentication stage and the corresponding security detection identifier, and uses the Chebyshev chaos map algorithm to negotiate a temporary session key, thereby establishing communication with the vehicle terminal using the temporary session key.

[0019] The present invention provides a multi-attribute terminal identity authentication system based on zero trust, which is used to implement a multi-attribute terminal identity authentication method based on zero trust.

[0020] Beneficial effects of the present invention:

[0021] 1. Aiming at vehicle emergency scenarios in intelligent transportation, this paper designs a fast authentication scheme for drone-vehicle terminals in a zero-trust architecture, avoiding the use of MEC S-assisted authentication before loss of connection, effectively reducing signaling overhead. Based on the hash algorithm, it avoids the use of algorithms with high computational overhead such as point multiplication and bilinear pairing mapping, effectively reducing computational overhead to ensure timeliness and efficiency in emergency network services.

[0022] 2. The present invention proposes a multi-attribute mutual identity authentication mechanism based on a zero-trust architecture. The mechanism is based on security level management application services and is based on static identification (session key SK and attribute set generated before disconnection) and dynamic identification (security detection identification C generated after disconnection and disconnection time T). Δ ) Realize fast identity authentication and key negotiation between drone-vehicle terminals in emergency situations.

[0023] 3. This paper proposes a continuous trust assessment mechanism based on a zero-trust architecture. This mechanism dynamically assesses the trust value of vehicle terminals by analyzing their historical service requests, connection status, and the terminal's attribute set {V}. It also dynamically assesses the trust value of drones by comparing the data access list maintained by drones and historical auxiliary service response times and resource consumption with expected values. Through a trust value feedback mechanism and analysis of the security level and urgency of application services, this mechanism matches emergency services to vehicle terminals and selects drones to dispatch tasks, effectively addressing intelligent transportation emergencies.

[0024] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is a flow chart of a vehicle terminal identity authentication method in a UAV-assisted edge computing scenario provided by an embodiment of the present invention;

[0026] Figure 2 This is a model diagram of a vehicle terminal identity authentication system in a UAV-assisted edge computing scenario provided by an embodiment of the present invention;

[0027] Figure 3 This is a diagram of a multi-attribute mutual identity authentication model based on a zero-trust architecture provided by an embodiment of the present invention;

[0028] Figure 4 This is a diagram of a dynamic authentication mechanism model based on trust evaluation values provided by an embodiment of the present invention;

[0029] Figure 5 Schematic diagram of the registration process of a vehicle terminal and an edge computing server provided by an embodiment of the present invention;

[0030] Figure 6 This is a schematic diagram of the UAV initialization and task scheduling process provided by an embodiment of the present invention;

[0031] Figure 7 This is a schematic diagram of the vehicle terminal-UAV identity authentication process provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0032] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.

[0033] The technical solutions adopted by the present invention are as follows: a multi-attribute terminal identity authentication method and system based on zero trust, wherein the terminal identity authentication and key negotiation implementation method are modeled after the 5G AKA mechanism; a terminal offline registration mechanism is adopted; based on the idea of zero trust architecture and continuous trust evaluation; rapid identity authentication between the terminal and the drone is achieved based on the session key negotiated during the access authentication phase; derivation of the session key between the terminal and the drone is achieved based on the Chebyshev chaos mapping algorithm; and key updates are achieved during drone assistance based on a one-way hash algorithm to ensure the anonymity and privacy of the terminal and the drone. While realizing vehicle terminal identity authentication in drone-assisted edge computing scenarios, the present invention reduces bandwidth overhead and computing overhead, avoids the problem of achieving two-way authentication between the terminal and the drone through server assistance during the emergency dispatch phase, and makes up for the defect of inflexible service network caused by deploying servers in fixed locations; at the same time, it can ensure the security of data transmission and the confidentiality of user privacy.

[0034] The significance of solving the existing technical problems lies in: Based on the key negotiated during the access authentication process between the vehicle terminal and the edge computing server, a lightweight Chebyshev chaos mapping algorithm is used to construct an authentication protocol for drones and vehicle terminals in emergency situations. Through the concept of zero trust and multi-attribute, based on the security principle of "never trust, always verify", identity is used as the basis for access control, and access control policies are calculated in real time. By completing key technologies such as vehicle terminal registration, MEC server registration, vehicle terminal access authentication, drone initialization, static authentication, service scheduling, and dynamic drone-vehicle terminal identity authentication, the deployment of UAVs in intelligent transportation systems to implement auxiliary edge computing services, thereby achieving rapid data processing and decision-making, flexible on-demand and timely emergency services, flexible monitoring of road blind spots, and reducing road monitoring costs, promoting the construction and development of safe, efficient, and stable road traffic.

[0035] The following is a detailed introduction to the meaning of the technical terms involved in the solution of the present invention:

[0036] UAV: Unmanned Aerial Vehicle; V: Vehicle Terminal; MEC Server: Edge Computing Server; RC: Registration Center. The technical solution of the present invention is described in detail below with reference to the accompanying drawings.

[0037] The present invention provides a multi-attribute terminal identity authentication method based on zero trust, which is applied to a multi-attribute terminal identity authentication system based on zero trust, the multi-attribute terminal identity authentication system based on zero trust includes an edge computing server and a cloud server, and the edge computing server can communicate with multiple drones and multiple vehicle terminals respectively.

[0038] like Figure 1 As shown, the multi-attribute terminal identity authentication method based on zero trust of the present invention includes:

[0039] During the registration phase, each edge computing server and vehicle terminal sends a registration request to the cloud server, and the cloud server returns the first registration information of each edge computing server and the second registration information of the vehicle terminal;

[0040] In the edge authentication phase, the vehicle terminal sends an access authentication request to the edge computing server. The edge computing server authenticates the vehicle terminal using the information carried in the access authentication request and its own information, and negotiates a session key with the vehicle terminal.

[0041] During the drone initialization phase, each edge server sends the drone initialization information for the drone it controls;

[0042] During the emergency task scheduling phase, each edge computing server determines the task urgency based on the vehicle terminal's connection status. When the task urgency reaches the required level, it selects a target drone with sufficient resources and the highest trust value from the drone list it maintains, and issues a service scheduling request to the target drone, thereby initiating an application service response. The target drone verifies whether the service scheduling request is legal, obtains the authentication parameters of the auxiliary vehicle terminal, and generates a safety detection identification for the response.

[0043] During the identity authentication stage between the terminal and the drone, the drone completes the authentication of the vehicle terminal through the session key negotiated with the vehicle terminal in the edge authentication stage and the corresponding security detection identifier, and uses the Chebyshev chaos map algorithm to negotiate a temporary session key, thereby establishing communication with the vehicle terminal using the temporary session key.

[0044] The vehicle terminal identity authentication system model in the drone-assisted edge computing scenario is as follows: Figure 2 As shown, MECServer maintains a UAV list, which includes the initialization process (such as Figure 6 The system parameters generated by UAV are used for data exchange and task delivery between MEC Server and UAV. Figure 5 The session key generated by (as shown) provides edge computing services under the V2X network. An abnormal disconnection table will be maintained in V for subsequent connection restoration or subsequent security verification of V. The MEC Server should maintain multiple UAVs, including static UAVs and dynamic UAVs. All UAVs within the flight domain are responsible for direct or indirect edge computing auxiliary services for vehicle terminals in the area to ensure the safety and order of daily traffic. In an emergency, the MEC Server will assign application service tasks to the UAV based on the vehicle monitoring situation, and provide the security level, urgency, route planning and estimated auxiliary service time of the task to ensure that the UAV can complete the service away from the MEC Server within a safe time. Since the object of the auxiliary service is the vehicle terminal, both parties should be authenticated before the service, whether it is signaling interaction or data transmission.

[0045] Multi-attribute mutual identity authentication model based on zero trust architecture Figure 3As shown, a vehicle terminal V should construct its attribute set {V}, which includes at least its identity ID, appearance features, personalized identification points, and real-time connection status. To ensure the anonymity of the vehicle terminal, a pseudo-identity identifier should be used to construct the attribute set. Appearance features should be fixed features such as the vehicle model and color. Personalized identification points include long-term wear and tear and personalized exterior decorations. These can be photographed and uploaded to the edge computing server, where they are converted into fixed, personalized identifiers using deep learning. The real-time connection status is defined as whether the current connection between V and the MEC server or UAV is normal, including normal connection, normal disconnection, and abnormal disconnection. The services provided by the MEC server are categorized by application security level. For example, level 1 services are normal services, including basic intelligent transportation services such as route planning and real-time traffic notifications, and are available after V completes access authentication. Level 2 services are privacy-sensitive services, such as in-vehicle video analysis and vehicle positioning, and require user consent for activation. Level 3 services are emergency services, including emergency assisted driving and video data analysis in the event of abnormal disconnection. Because these services require extremely low-latency decision-making and response in emergency situations, the MEC Server can directly provide emergency services to users based on these decisions. When deployed for emergency assistance, the UAV should not maintain constant trust with the vehicle V. Instead, it should implement identity authentication and security assistance based on the zero-trust principle of never trusting, always verifying, and a continuous dynamic trust assessment strategy. The dynamic identity authentication process between the UAV and the vehicle V, based on zero-trust assessment, consists of two parts. The first part is used to authenticate the terminal vehicle V, using two authentication factors: one based on existing static authentication parameters: the session key between the vehicle V and the MEC Server and the security detection identifier; the second part is used to construct {V} based on V's attribute set and the connection status to continuously update dynamic parameters. The more factors that generate the personalized parameters of the attribute set {V}, the higher its security level. The longer the disconnection time or duration recorded when the connection status is abnormally disconnected, the lower the security level. The second part is used to authenticate the UAV. In emergency services, the authentication of the UAV by the vehicle V should be based on the static authentication parameters included in the assigned task by the MEC Server to ensure the effectiveness and timeliness of the service. After the service is completed, the MEC Server should dynamically perform continuous trust evaluation for the UAV based on the data access list and request response time maintained by the UAV. The results of the continuous trust evaluation will be fed back into the UAV's authentication of V's identity and security status, as well as the MEC Server's assessment of the UAV's security trust level.

[0046] The dynamic authentication mechanism model based on trust evaluation value provided by the embodiment of the present invention is as follows Figure 4As shown, the inputs for continuous trust evaluation primarily consist of two components: For V, changes in the terminal's connection status are the primary factor in assessing its trust value, along with analysis of the terminal's service requests and their attribute values. For UAVs, the data access list they maintain, request-response time, and resource consumption are the primary factors in assessing their trust value. The more abnormal disconnections a terminal experiences, the lower its trust index. Requests for unauthorized services or requests to access other people's data also reduce its trust index. Since updates to the terminal's attribute values {V} increase its security level, the richer the personalized identification of the attribute values, the higher its trust index should be. When V's trust index falls below the minimum threshold, the MEC-S or UAV can directly obtain emergency permissions to provide emergency measures and responses in an emergency. Furthermore, the trust index of all UAVs maintained by the MEC-S should be determined based on the data access list. For dynamic UAVs, the legitimacy and effectiveness of the outbound service should be analyzed based on the estimated duration, response time, and resource consumption of the outbound service, and the UAV's trust index should be dynamically updated.

[0047] MEC S is based on the trust index values of V and UAV, and matches services and security indicators according to application service management strategies. In emergency situations, it can quickly assign tasks and issue security parameters to handle emergencies at vehicle terminals.

[0048] The registration process of the present invention is described below.

[0049] During the registration phase, the registration process for each edge computing server is as follows:

[0050] (1) The jth edge computing server MEC Server j Send a registration request message to the registration center RC deployed on the cloud server. The registration request message contains the MEC Server j Unique ID Vj ;

[0051] (2) After receiving the registration request message, the registration center checks the unique identity ID Vj Does it already exist? If so, request MEC Server j Send a new identity; otherwise, it is the MEC Server j Select a random number S j and the master key K Vj , and calculate the initial Chebyshev chaotic map value And send the registration response message to MEC Server j ;

[0052] The registration response message includes: the master key K Vj, initial Chebyshev chaotic map value and parameters (ID Vj ||S j ); MEC Server j The public parameters of

[0053] (3) MEC Server j Store the registration response message and As public parameters, RC stores {ID Vj ,K Vj}.

[0054] During the registration phase, the registration process for each vehicle terminal is as follows:

[0055] (1) The i-th vehicle terminal V i Send a registration request message to the registration center RC deployed on the cloud server, including its unique identity ID Oi ;

[0056] (2) After receiving the registration request message, RC checks the legal identity list and the malicious identity list to determine whether the identity already exists. If it does, it requests V i Send a new identity, otherwise RC is V i Choose a random number O i , and the master key K Oi , calculate the initial Byshev chaotic map value and pseudo-identifier SID i =H(ID Oi ||O i ), and register the response message Send to V i ;

[0057] (3)V i storage RC stores each V i The corresponding {ID Oi ,O i ,SID i ,T KOi (ID Oi ||O i )mod p}.

[0058] refer to Figure 6 During the initialization phase, the process of sending the initialization information of the drone controlled by the edge computing server is as follows:

[0059] (1) The jth edge computing server MEC Server j is the kth UAV kGenerate a random number U i As a UAV k Identity identification; according to the random number U i Calculate the secret value r k =H(S j ,U i ) and the initial Chebyshev chaotic map value And initialize the information Sent to UAV via secure channel k ;

[0060] (2) UAV k Initialize information Stored in local memory; where r k For UAV k and MEC Server j A shared key used for information exchange between Authentication parameters used for identity authentication with vehicle terminals during dynamic drone dispatch.

[0061] refer to Figure 6 ,In the emergency task scheduling phase, each edge computing server determines the task urgency according to the ,connection status of the vehicle terminal. When the task urgency reaches the ,requirement, it selects the target drone with sufficient resources and the ,highest trust value from the drone list it maintains, and issues a service ,scheduling request to the target drone to initiate the application service response ,process as follows:

[0062] (1) The jth edge computing server MEC Server j Evaluate the security level and urgency of the edge computing server's application services based on the vehicle terminal's connection status, and proactively initiate an application service response to the vehicle terminal in the event of a level 3 emergency.

[0063] The application service response process is as follows: based on deep learning, the estimated service response time and resource consumption value of the dispatched task are evaluated; based on the task response time and resource consumption value, the target UAV with sufficient resources and the highest trust value is selected from the UAV list maintained by the edge computing server; and a service scheduling request is issued to the target UAV. <T s1 ,M,MAC1>;

[0064] Among them, T s1 MEC Server j The timestamp when the abnormality of the vehicle terminal is identified; To schedule ciphertext, it is generated by symmetric encryption algorithm and symmetric key; MAC1 = H(T s1 ,M).

[0065] During the emergency task dispatch phase, the target UAV verifies whether the service dispatch request is legal, obtains the authentication parameters of the auxiliary vehicle terminal if it is legal, and generates a response safety detection identification in the following process:

[0066] (2) After receiving the service scheduling request, the UAV verifies the validity of the timestamp and the validity of the service scheduling request, thereby generating a service confirmation message and the corresponding security detection identifier, and sends the service confirmation message to the edge computing server. The service confirmation message is used to confirm the key of the edge computing server. The specific process is as follows:

[0067] ①UAV k After receiving the service scheduling request, first verify the validity of the timestamp, if and only if T cur1 -T s1 The service scheduling request is valid when ≤ΔT; where ΔT is the maximum time interval allowed by the system, T cur1 For UAV k The timestamp generated when the service scheduling request is received;

[0068] ②UAV k Use the symmetric encryption and decryption algorithm and the symmetric key to decrypt the ciphertext M and obtain <T s1 ,{V},SK ij >

[0069] ③UAV k Calculate MAC1'=H(T s1 ,M), the integrity of the service scheduling request is verified if and only if MAC1'=MAC1;

[0070] ④UAV k Computing safety detection identification

[0071] ⑤UAV k Generate current timestamp T s2 ;

[0072] ⑥UAV k Calculate MAC2 = H(T s2 ,C jk ) and send it to the MEC Server j Send service confirmation response message <T s2 ,MAC2>, used for MEC Server j Key confirmation.

[0073] (3) After receiving the service confirmation information, the j-th edge computing server MEC Serverj verifies the validity of the timestamp and generates a corresponding security detection identifier to verify the validity of the service confirmation message.

[0074] ① The jth edge computing server MEC Server j After receiving the service confirmation information, verify the validity of the timestamp if and only if T cur2 -T s2 The service confirmation information is valid when ≤ΔT;

[0075] ②MEC Server j Computing safety detection mark C jk =H(SID i ,ID Vj );

[0076] ③MEC Server j Calculate MAC2'=H(T s2 ,C jk ), MEC Server j Confirm UAV k Receives the dispatch service request and generates a response security detection identifier C jk .

[0077] like Figure 7 As shown in the figure, during the identity authentication phase between the terminal and the drone, the drone completes the authentication of the vehicle terminal through the session key negotiated with the vehicle terminal in the edge authentication phase and the corresponding security detection identifier, and negotiates a new session key using the Chebyshev chaos map algorithm. The process of establishing communication with the vehicle terminal using the new session key is as follows:

[0078] (1) When UAV k Found vehicle terminal V i Then perform the following process:

[0079] ①Generate timestamp T s3 ;

[0080] ②Use symmetric encryption algorithm and session key SK ij Generate ciphertext

[0081] ③Calculation Among them, T Δ =T s3 -T s1 ;

[0082] ④UAV k Towards V i Send an authentication request message <T s3 ,M1,MAC3>;

[0083] (2) When V i Receive UAV kAfter receiving the identity authentication request message, the following process is performed:

[0084] ① Verify the validity of the timestamp if and only if T cur3 -T s3 The message is valid when ≤ΔT;

[0085] ② Retrieve the abnormal disconnection table, obtain the session key SK between the vehicle terminal and MEC Server, and decrypt M1;

[0086] ③Calculation safety detection mark C jk =H(SID i ,ID Vj ), and judge

[0087] ④If and only if C jk '=C jk When calculating and judge

[0088] ⑤ If and only if MAC3'=MAC3, the UAV is completed k Authentication and generating random numbers

[0089] ⑥Calculate the temporary session key between UAV-V

[0090] ⑦Calculate the temporary key parameter T i-k =T a (ID Vj ||S j )mod p;

[0091] ⑧Calculate the ciphertext based on the symmetric encryption algorithm and the temporary session key

[0092] ⑨Generate timestamp T s4 ;

[0093] ⑩Calculation

[0094] V i Towards UAV k Sending an authentication response message <T i-k ,T s4 ,M2,MAC4>.

[0095] (3) When UAV k Receive V i The following process is performed for the identity authentication response message:

[0096] ① Verify the validity of the timestamp if and only if T cur4 -Ts4 The message is valid when ≤ΔT;

[0097] ②Calculation

[0098] ③Based on symmetric encryption and decryption algorithm and SK ik 'Decrypt ciphertext M2;

[0099] ④Calculation and judge

[0100] ⑤ If and only if MAC4'=MAC4, complete the UAV's identity authentication of V and generate the timestamp T s5 ;

[0101] ⑥Calculate MAC5=H(T s5 ,SK ik );

[0102] ⑦UAV k Towards V i Send key confirmation message <T s5 ,MAC5>;

[0103] (4) When V i Receive UAV k After receiving the key confirmation message, the following process is performed:

[0104] ① Verify the validity of the timestamp if and only if T cur5 -T s5 The message is valid when ≤ΔT;

[0105] ②Calculate MAC5'=H(T s5 ,SK ik ); if and only if MAC5'=MAC5, the key negotiation process is completed;

[0106] ③ UAV and vehicle terminals use temporary session keys SK ik Data or video transmission.

[0107] The following is an analysis of the identity authentication of the vehicle terminal of the present invention:

[0108] (1) Mutual identity authentication: The vehicle terminal will verify the legitimacy of the UAV through the MAC3 in the identity authentication request message. Uk By SK ij Encryption, SK ij This is the session key negotiated during the access authentication process between the vehicle terminal and the MEC Server before the disconnection, which is known only to the vehicle terminal and the MEC Server. In addition, the disconnection duration T Δ By disconnection timestamp T s1The secret parameters are calculated and are also known only to the vehicle terminal and MEC Server. Therefore, only legitimate UAVs can obtain the secret parameters from the MEC Server before disconnection through the security service scheduling request message for authentication. The transmission of the secret parameters is controlled by the symmetric key r k Encryption, the key is only owned by MECServer and the UAV it maintains. UAV verifies the legitimacy of the vehicle terminal through MAC4, because only the legal vehicle terminal has its own attribute value {V}, and only the legal vehicle terminal can pass SK ij Decrypt M1 and obtain To calculate the temporary session key SK ik And the corresponding key parameter T a (ID Vj ||S j )mod p.

[0109] (2) Session key negotiation: The vehicle terminal and the UAV will use the secret value in the mutual authentication process to negotiate the session key. To calculate SK ik The calculation of the secret value is based on the CMDH or CMDL problem. k The attacker cannot calculate SK ik .

[0110] (3) Key confirmation: The vehicle terminal verifies H(T s5 ,SK ik ) to confirm whether the UAV has successfully negotiated the session key SK ik ; The UAV confirms whether the vehicle terminal has successfully obtained the session key by decrypting the ciphertext M2.

[0111] (4) Identity anonymity: During the identity authentication process, the real identity ID of the vehicle terminal is i No transmission is performed, and the pseudo identity SID i By C jk =H(SID i ,ID Vj ) for protection. The real identification of the drone is U i No transmission is performed, and the identity ID of the MEC Server before the disconnection is used during the authentication process Vj Complete the certification, and the logo is also issued by C jk Therefore, any attacker cannot obtain the SID of the vehicle terminal. i And the U of UAV i Therefore, the protocol proposed in this paper can achieve the anonymity of the identities of vehicle terminals and drones.

[0112] (5) Unlinkability: In this protocol, since the vehicle terminal and UAV generate a timestamp Ts in each session, the same timestamp generated by both parties in different sessions is different. There is no connection between the messages sent in the same session. All messages are associated with the timestamp. The attacker cannot obtain any useful information about the vehicle terminal or UAV based on the public data, so the attacker cannot distinguish whether two messages come from the same vehicle terminal or UAV.

[0113] (6) PFS / PBS: In this protocol, the vehicle terminal and the UAV will To calculate SK ik , where a is the temporary secret value of the vehicle terminal, is the initial Chebyshev value of UAV. Even if the attacker obtains the long-term key K Oi 、r k , nor can we obtain the previous or future session keys. According to the CMDH and CMDL problems, it is difficult to calculate T a (ID Vj ||S j )mod p.

[0114] (7) Protocol attack resistance: In the protocol proposed in this invention, the use of timestamp Ts can resist replay attacks. Since mutual authentication and key agreement between the vehicle terminal and the UAV have been achieved, and the interactive messages are based on the symmetric key SK ij and SK ik Encryption is performed, and only the recipient of the desired interaction can obtain the temporary key SK ij And negotiate to obtain SK ik Therefore, the attacker cannot pretend to be a legitimate vehicle terminal or UAV to deceive the server or vehicle terminal to launch a man-in-the-middle attack. In addition, since these important information are all encrypted with the symmetric key SK ij and SK ik Encrypted with symmetric key SK ij and SK ik Both are based on the CMDH difficulty problem, and the attacker cannot calculate SK ij and SK ik , so the present invention can resist eavesdropping attacks.

[0115] The innovative features of the solution proposed in the present invention are summarized below.

[0116] 1. The present invention proposes a multi-dimensional, intensive edge computing scenario implemented by drone-assisted Internet of Vehicles, so as to realize identity authentication and key negotiation between vehicle terminals and drones in emergency situations. The present invention is based on a zero-trust architecture. After the vehicle terminal successfully accesses the edge computing server, the edge computing server can realize continuous trust evaluation of the vehicle terminal and the drone. Only a small amount of hash operations and Chebyshev chaos mapping algorithms are required to complete the mutual authentication of the drone and the vehicle terminal. There is no need for the disconnected edge computing server to perform auxiliary authentication, which effectively reduces the signaling overhead and computing overhead of both parties during the authentication period, and can support low-latency emergency auxiliary services. The security of the proposed scheme is fully demonstrated by the use of formal verification tools, and the performance analysis comparison results show that the scheme is superior to other existing schemes. Therefore, this lightweight scheme is generally more suitable for resource-constrained drone-assisted Internet of Vehicles to realize intensive edge computing scenarios.

[0117] 2. The present invention creatively proposes that drones assist the Internet of Vehicles to realize multi-dimensional, intensive edge computing scenarios and auxiliary service scheduling in emergency situations, and designs an application service management strategy for this purpose. By having the edge computing server simultaneously maintain a dynamic drone swarm and a static drone swarm, it is possible to realize the function of the drone swarm monitoring road traffic conditions in the air and acting as an aerial base station under normal circumstances, thereby assisting the Internet of Vehicles to realize multi-dimensional, intensive edge computing. Through deep learning and other methods, it is also possible to pre-schedule a dynamic drone swarm in an idle state to provide auxiliary services at locations where intensive traffic conditions will occur, so as to realize resource sharing and avoid waste of resources. In addition, dynamic drones can also be dispatched to realize long-distance emergency services without the assistance of edge computing servers to deal with emergencies outside the coverage of the edge computing server network.

[0118] 3. This invention innovatively proposes a continuous trust assessment strategy for drones and vehicle terminals. The vehicle terminal's trust value is dynamically assessed based on its historical service requests, connection status, and its attribute set {V}. The drone's trust value is also dynamically assessed based on the drone's maintained data access list and a comparison of historical auxiliary service response times and resource consumption with expected values. Trust feedback, along with the security level and urgency of the application service, is then used to match the vehicle terminal's emergency services and select the drone to dispatch the task to.

[0119] 4. In the process of identity authentication, the present invention implements the security principle of never trusting and always verifying between vehicle terminals and drones based on the zero-trust framework, without the need for MEC S-assisted authentication before disconnection. In addition, the construction of the attribute set {V} is added to the authentication factor of the vehicle terminal, and the security level definition of the personalized identification is used to stimulate the security needs of the terminal user. And through the disconnection time T Δ Dynamic authentication of both parties is achieved.

[0120] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature identified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0121] Although the present application is described herein with reference to various embodiments, those skilled in the art will be able to understand and implement other variations of the disclosed embodiments in practicing the claimed application by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality.

[0122] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A multi-attribute terminal identity authentication method based on zero trust, characterized in that: Applied to a zero-trust-based multi-attribute terminal identity authentication system, the zero-trust-based multi-attribute terminal identity authentication system edge computing server and cloud server, the edge computing server can communicate with multiple drones and multiple vehicle terminals respectively, the zero-trust-based multi-attribute terminal identity authentication method includes: During the registration phase, each edge computing server and vehicle terminal sends a registration request to the cloud server, and the cloud server returns the first registration information of each edge computing server and the second registration information of the vehicle terminal; In the edge authentication phase, the vehicle terminal sends an access authentication request to the edge computing server. The edge computing server authenticates the vehicle terminal using the information carried in the access authentication request and its own information, and negotiates a session key with the vehicle terminal. During the drone initialization phase, each edge server sends the drone initialization information to the drone it controls; the initialization information is U i is the jth edge computing server MEC Server j is the kth UAV k Generate a random number, r k For UAV k and the jth edge computing server MEC Server j A shared key used for information exchange between It is the authentication parameter used for identity authentication with the vehicle terminal during the dynamic UAV dispatch process; During the emergency task scheduling phase, each edge computing server determines the task urgency based on the vehicle terminal's connection status. When the task urgency reaches the required level, it selects a target drone with sufficient resources and the highest trust value from the drone list it maintains, and issues a service scheduling request to the target drone, thereby initiating an application service response. The target drone verifies whether the service scheduling request is legal and generates a response security detection mark if it is legal. During the identity authentication phase between the terminal and the drone, the drone completes the authentication of the vehicle terminal using the session key negotiated with the vehicle terminal in the edge authentication phase and the corresponding security detection identifier. The drone then uses the Chebyshev chaos map algorithm to negotiate a temporary session key, thereby establishing communication with the vehicle terminal using the temporary session key. During the emergency task dispatch phase, the target drone verifies whether the service dispatch request is legal and generates a safety detection mark in response if it is legal. The process is as follows: (1) After receiving the service scheduling request, the UAV verifies the validity of the timestamp and the validity of the service scheduling request, thereby generating a service confirmation message and a corresponding security detection identifier; and sends the service confirmation message to the edge computing server, where the service confirmation message is used to confirm the key of the edge computing server; (2) The jth edge computing server MEC Server j After receiving the service confirmation information, verify the validity of the timestamp and generate the corresponding security detection mark C jk , used to verify the validity of the service confirmation message; During the identity authentication phase between the terminal and the drone, the drone completes the authentication of the vehicle terminal using the session key negotiated with the vehicle terminal in the edge authentication phase and the corresponding security detection identifier, and negotiates a new session key using the Chebyshev chaos map algorithm. The process of establishing communication with the vehicle terminal using the new session key is as follows: (1) When UAV k Found vehicle terminal V i Then perform the following process: ①Generate timestamp T s3 ; ②Use symmetric encryption algorithm and session key SK ij Generate ciphertext C jk Indicates UAV k Calculated safety detection identification; ③Calculation Among them, T Δ =T s3 -T s1 ;T s1 Indicates MEC Server j The timestamp when the abnormality of the vehicle terminal is identified; ④UAV k Towards V i Send an authentication request message <T s3 ,M1,MAC3>; (2) When V i Receive UAV k After receiving the identity authentication request message, the following process is performed: ① Verify the validity of the timestamp if and only if T cur3 -T s3 The message is valid when ≤ΔT; ② Retrieve the abnormal disconnection table, obtain the session key SK between the vehicle terminal and MEC Server, and decrypt M1; ③Calculation safety detection mark C jk =H(SID i ,ID Vj ), and judge SID i represents the pseudo identity identifier of the i-th vehicle terminal, ID Vj Indicates the jth MEC Server j unique identifier; ④If and only if C jk '=C jk When calculating and judge ⑤ If and only if MAC3'=MAC3, the UAV is completed k Authentication and generating random numbers ⑥Calculate the temporary session key between UAV-V ⑦Calculate the temporary key parameter T i-k =T a (ID Vj ||S j )mod p;S j Indicates that the registration center is MEC Server j The random number selected; ⑧Calculate the ciphertext based on the symmetric encryption algorithm and the temporary session key {V} represents the terminal device attribute value; ⑨Generate timestamp T s4 ; ⑩Calculation V i Towards UAV k Sending an authentication response message <T i-k ,T s4 ,M2,MAC4>; (3) When UAV k Receive V i The following process is performed for the identity authentication response message: ① Verify the validity of the timestamp if and only if T cur4 -T s4 The message is valid when ≤ΔT; ②Calculate SK ik '=T rk (T a (ID Vj ||S j )mod p)mod p; ③Based on symmetric encryption and decryption algorithm and SK ik 'Decrypt ciphertext M2; ④Calculation and judge ⑤ If and only if MAC4'=MAC4, complete the UAV's identity authentication of V and generate the timestamp T s5 ; ⑥Calculate MAC5=H(T s5 ,SK ik ); ⑦UAV k Towards V i Send key confirmation message <T s5 ,MAC5>; (4) When V i Receive UAV k After receiving the key confirmation message, the following process is performed: ① Verify the validity of the timestamp if and only if T cur5 -T s5 The message is valid when ≤ΔT; ②Calculate MAC5'=H(T s5 ,SK ik ); if and only if MAC5'=MAC5, the key negotiation process is completed; ③ UAV and vehicle terminals use temporary session keys SK ik Data or video transmission.

2. The multi-attribute terminal identity authentication method based on zero trust according to claim 1 is characterized in that: During the registration phase, the registration process for each edge computing server is as follows: (1) The jth edge computing server MEC Server j Send a registration request message to the registration center RC deployed on the cloud server. The registration request message contains the MEC Server j Unique ID Vj ; (2) After receiving the registration request message, the registration center checks the unique identity ID Vj Does it already exist? If so, request MEC Server j Send a new identity; otherwise, it is the MEC Server j Select a random number S j and the master key K Vj , and calculate the master key K Vj The initial Chebyshev chaotic map value And send the registration response message to MECServer j ; The registration response message includes: the master key K Vj , initial Chebyshev chaotic map value and parameters (ID Vj ||S j ); MEC Server j The public parameters of (3) MEC Server j Store the registration response message and As public parameters, RC stores {ID Vj ,K Vj }.

3. The multi-attribute terminal identity authentication method based on zero trust according to claim 1, characterized in that: During the registration phase, the registration process for each vehicle terminal is as follows: (1) The i-th vehicle terminal V i Send a registration request message to the registration center RC deployed on the cloud server, including its unique identity ID Oi ; (2) After receiving the registration request message, RC checks the legal identity list and the malicious identity list to determine whether the identity already exists. If so, it requests V i Send a new identity, otherwise RC is V i Choose a random number O i , and the master key K Oi , calculate the master key K Oi The initial Byshev chaotic map value and pseudo-identifier SID i =H(ID Oi ||O i ), and register the response message Send to V i ; (3)V i storage RC stores each V i Corresponding 4. The multi-attribute terminal identity authentication method based on zero trust according to claim 2, characterized in that: During the initialization phase, each edge server sends the initialization information of the drones it controls as follows: (1) The jth edge computing server MEC Server j is the kth UAV k Generate a random number U i As a UAV k Identity identification; according to the random number U i Calculate the secret value r k =H(S j ,U i ) and for the secret value r k The initial Chebyshev chaotic map value And initialize the information Sent to UAV via secure channel k ; (2) UAV k Initialize information Stored in local memory.

5. The multi-attribute terminal identity authentication method based on zero trust according to claim 4 is characterized in that: In the emergency task scheduling phase, each edge computing server determines the task urgency based on the connection status of the vehicle terminal. When the task urgency reaches the required level, it selects a target drone with sufficient resources and the highest trust value from the drone list it maintains, and issues a service scheduling request to the target drone to initiate the application service response process. The jth edge computing server MEC Server j Evaluate the security level and urgency of the edge computing server's application services based on the vehicle terminal's connection status, and proactively initiate an application service response to the vehicle terminal in the event of a level 3 emergency. The application service response process is as follows: based on deep learning, the estimated service response time and resource consumption value of the dispatched task are evaluated; based on the task response time and resource consumption value, the target UAV with sufficient resources and the highest trust value is selected from the UAV list maintained by the edge computing server; and a service scheduling request is issued to the target UAV. <T s1 ,M,MAC1>; Among them, T s1 MEC Server j The timestamp when the abnormality of the vehicle terminal is identified; To schedule ciphertext, it is generated by symmetric encryption algorithm and symmetric key; MAC1 = H(T s1 ,M).

6. The multi-attribute terminal identity authentication method based on zero trust according to claim 1, characterized in that: In the emergency task scheduling phase (1) the process is: ①UAV k After receiving the service scheduling request, first verify the validity of the timestamp, if and only if T cur1 -T s1 The service scheduling request is valid when ≤ΔT; where ΔT is the maximum time interval allowed by the system, T cur1 For UAV k The timestamp generated when the service scheduling request is received; ②UAV k Use the symmetric encryption and decryption algorithm and the symmetric key to decrypt the ciphertext M and obtain <T s1 ,{V},SK ij > ③UAV k Calculate MAC1'=H(T s1 ,M), the integrity of the service scheduling request is verified if and only if MAC1'=MAC1; ④UAV k Computing safety detection identification ⑤UAV k Generate current timestamp T s2 ; ⑥UAV k Calculate MAC2 = H(T s2 ,C jk ) and send it to the MEC Server j Send service confirmation response message <T s2 ,MAC2>, used for MEC Server j Key confirmation.

7. The multi-attribute terminal identity authentication method based on zero trust according to claim 1, characterized in that: In the emergency task scheduling phase (2), the process is: ① The jth edge computing server MEC Server j After receiving the service confirmation information, verify the validity of the timestamp if and only if T cur2 -T s2 The service confirmation information is valid when ≤ΔT; ②MEC Server j Computing safety detection mark C jk =H(SID i ,ID Vj ); ③MEC Server j Calculate MAC2'=H(T s2 ,C jk ), MEC Server j Confirm UAV k Receives the dispatch service request and generates a response security detection identifier C jk .

8. A multi-attribute terminal identity authentication system based on zero trust, characterized in that: Implement the zero-trust-based multi-attribute terminal identity authentication method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Reliable vehicle-mounted edge calculation unloading method based on reinforcement learning

    CN112929849A

  • Unmanned aerial vehicle relay Internet of Vehicles secure transmission method based on non-orthogonal multiple access

    CN113194443A