Unmanned system double-factor authentication and security control method based on cloud network end architecture
Patent Information
- Application Number
- CN202311125538.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-01
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-09-01
AI Technical Summary
该方法由于在登录认证阶段需要服务器用数据库中存储的带有口令的秘密值与认证消息进行比对来验证用户的合法性,故特权用户能够利用数据库中存储的敏感信息猜测用户的口令,造成双因子认证的安全隐患
[0023]1.避免离线口令猜测攻击。
Smart Images

Figure CN117201105B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically relating to a two-factor authentication and security control method for unmanned systems, which can be used to continuously provide highly reliable identity authentication and forward security for unmanned system communication. Background Technology
[0002] The cloud-network-edge-based two-factor authentication and security control method for unmanned systems provides highly reliable identity authentication, offering stronger security guarantees through a two-factor authentication approach using both passwords and long-term keys. The implementation scheme primarily involves: mutual authentication and negotiation of shared session keys between the user and the cloud server, and between the cloud server and the unmanned device, to determine the legitimacy of the user, cloud server, and unmanned device; after authentication, the user and the unmanned device negotiate and share the session key, using this key to encrypt and transmit commands; subsequently, the user and the unmanned device update the session key based on a timestamp to encrypt and transmit commands, continuously providing forward security.
[0003] Wang et al. proposed a two-factor authentication method in their paper "Two birds with one stone: Two-factor authentication with security beyond conventional bound" (IEEE transactions ondependable and secure computing, 2016, 15(4):708-722.). This method employs a computational Diffie-Hellman-based key exchange mechanism to provide mutual authentication services between users and servers. It resists offline password guessing attacks by combining fuzzy verification factors with honeywords. The hash of the password is modulo a mid-term integer for local verification to obscure the correctness of the guessed password, and a threshold for the number of failed user authentication attempts is set to further limit the number of online guesses. However, due to the computational Diffie-Hellman-based key exchange mechanism used in the authentication and key negotiation phases, this method incurs significant computational, communication, and storage overhead, making it unsuitable for resource-constrained unmanned systems.
[0004] Shenyang Normal University proposed a "cloud-based two-factor authentication method based on PTPM and certificateless public key signature" in its patent application (CN201710996495.1). This method utilizes PTPM to provide mutual authentication services between any terminal device and the cloud, and employs a certificateless public key signature algorithm to ensure the non-repudiation of the signature pair. However, because the login authentication phase requires the server to compare the authentication message with a secret value containing the password stored in the database to verify the user's legitimacy, privileged users can use sensitive information stored in the database to guess the user's password, creating a security vulnerability in two-factor authentication. Summary of the Invention
[0005] The purpose of this invention is to address the shortcomings of the existing technologies by proposing a two-factor authentication and security control method for unmanned systems based on a cloud-network-device architecture. This method aims to avoid offline password guessing attacks and identity ID privacy leaks during interactive authentication, thereby improving access control and communication security of unmanned systems under a cloud-network-device architecture.
[0006] The idea behind this invention is to use a fuzzy verification factor for local verification and employ a nonlinear key evolution method to update the data and pseudonyms stored in the smart card. This avoids offline password guessing attacks and user ID privacy leaks caused by the failure to update sensitive data and pseudonyms in a timely manner when authentication is completed or when unexpected network interruptions occur. By using a linear key evolution method to update the negotiated session key based on a timestamp, non-interactive identity authentication services and forward security of session keys are provided for unmanned systems in extreme environments.
[0007] Based on the above ideas, the implementation steps of this invention include the following:
[0008] (1) Cloud servers select four hash functions H i : λ i For safety parameters, i∈{0,1,2,3}, and expose system parameters {H0,H1,H2,H3};
[0009] (2) User enters identity ID Ui and password PW Ui Select a random number r and calculate the blind password BPW. Ui =
[0010] H0(r||PW Ui Send a registration request m to the cloud server. reg ={ID Ui BPW Ui};
[0011] (3) After receiving the registration request, the cloud server selects an integer 2. 4≤v≤2 8 Calculate and store parameters (CID) Ui ,akm Ui ,cred Ui CTR CUi ), calculate registration information {B0,B1,V Ui ,v,CTR Ui} and send it to the user;
[0012] (4) The user writes the received registration information and random number r into their smart card SC. Ui ;
[0013] (5) Select a random identifier ID for the cloud server Dj Generate authentication key material akm Dj Storage parameters (ID) Dj ,akm Dj CTR CDj ), and send it to unmanned equipment;
[0014] (6) User enters identity ID Ui and password PW Ui Smart Card SC Ui Calculate Blind Password BPW Ui and fuzzy verification factor Validating fuzzy validation factors The correctness of the kana, and the calculation of the kana. The ciphertext X and the authentication message A1 are accumulated and stored, and the user state counter is also stored. Send message to cloud server
[0015]
[0016] (7) The cloud server verifies the correctness of message m1, calculates the ciphertext X′ and authentication message A2, and accumulates and stores the cloud-based unmanned device status counter. Send message m2 = {X′, A2, CTR to unmanned equipment CDj};
[0017] (8) After receiving the message, the unmanned device calculates the authentication message. And verify its correctness, obtain the current timestamp T. ij Calculate the master key k ij sk, a session key shared with the cloud server CDj sk, a session key shared with the user ij ciphertext Y, authentication message A3, authentication key material Accumulate unmanned equipment status counter Storage parameters And send the message m3 = {Y, A3, T} to the cloud server. ij};
[0018] (9) After receiving the message, the cloud server calculates the authentication message. And verify its correctness, calculate the session key sk shared with the unmanned device. CDj Authentication key materials Cipher text Y′, kana Authentication message A4, incrementing the cloud user status counter. Storage parameters Send message m4={Y′,A4,T to the user ij};
[0019] (10) User Authentication Message And verify its correctness, initialize the local state counter CTR. ij =0, choose a new integer 2 4 ≤v new ≤2 8 The session key sk shared between the computer and the cloud server. CUi Master key k ij and the session key sk shared with unmanned equipment ij Fuzzy verification factor Long-term key storage value storage Using session key sk ij Encrypt the transmission of instructions to unmanned equipment;
[0020] (11) The user and the unmanned device obtain the current timestamp T and calculate the master key. and session key sk ij , will the parameter {k ij CTR ij} Replace with parameters And use the session key sk ij Encrypt the transmission of instructions;
[0021] (12) User enters identity ID Ui and password PW Ui Calculate the blind password BPW Ui and fuzzy verification factor And verify its correctness, then enter the new password again. Calculate the updated blind password Voucher storage value Long-term key storage value and fuzzy verification factor And store parameters
[0022] Compared with the prior art, the present invention has the following advantages:
[0023] 1. Avoid offline password guessing attacks.
[0024] This invention increments a state counter when the first authentication message is sent, and after successful authentication, updates the sensitive information stored in the smart card using PPRF in a non-linear key evolution manner. Even if an adversary launches a side-channel attack to extract sensitive information, they will not be able to calculate the authentication message corresponding to the guessed value and guess the correct password, thus avoiding offline password guessing attacks.
[0025] 2. Prevent the leakage of user identity ID privacy.
[0026] This invention designs a dynamic pseudonym based on PPRF. Regardless of whether the authentication is successful or not, the pseudonym will be updated to a non-linkable value as the state counter accumulates. Furthermore, the long-term key material necessary for calculating the pseudonym is updated at the end of the authentication process. This prevents adversaries from guessing the user's identity ID or tracking the user's activities through previous sessions, thus avoiding the leakage of the user's identity ID privacy.
[0027] 3. Provide highly reliable non-interactive authentication services and continuously provide forward security.
[0028] This invention performs periodic key updates for users and unmanned devices based on timestamps, enabling authorized users to securely control designated unmanned devices without performing interactive authentication. This not only provides highly reliable non-interactive authentication services for unmanned systems, but also continuously provides forward security for the sessions established between users and unmanned devices. Attached Figure Description
[0029] Figure 1 This is a flowchart illustrating the overall implementation of the present invention;
[0030] Figure 2 This is a flowchart illustrating the implementation of interactive authentication and security control in this invention.
[0031] Figure 3 This is a flowchart illustrating the implementation of non-interactive authentication and security control in this invention.
[0032] Figure 4 This is a flowchart illustrating the implementation of user password modification in this invention. Detailed Implementation
[0033] The embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0034] This example implements an unmanned system based on a cloud-network-edge architecture. The system comprises three entities: a user, a cloud server, and unmanned devices. Its implementation process includes six phases. In the system initialization phase, the cloud server selects and publishes system parameters. In the user registration phase, the cloud server generates user registration information and stores it with the user. In the unmanned device registration phase, the cloud server generates unmanned device registration information and stores it with the unmanned device. In the interactive authentication phase, the cloud server mutually authenticates with both the user and the unmanned device and negotiates a shared session key. The user and the unmanned device negotiate the shared session key under the relay of the cloud server. In the non-interactive authentication phase, the user and the unmanned device update the shared session key based on timestamps. In the user password modification phase, the user sequentially enters their identity ID, original password, and new password to modify their current password.
[0035] Reference Figure 1 The specific implementation steps of the above-mentioned unmanned system in this example include the following:
[0036] Step 1: System initialization.
[0037] Cloud servers select four hash functions H i : The system parameters {H0,H1,H2,H3} are disclosed, where λ i For safety parameters, i∈{0,1,2,3},
[0038] Step 2, User Registration.
[0039] 2.1) User enters identity ID Ui and password PW Ui Choose a random one-time value r and calculate the blind password BPW. Ui =H0(r||PW Ui Then, a registration request m is sent to the cloud server. reg ={ID Ui BPW Ui};
[0040] 2.2) Cloud server computing registration information {B0,B1,V Ui ,v,CTR Ui}, and send it to the user:
[0041] 2.2.1) After receiving the registration request, the cloud server will update the user status counter (CTR). Ui Cloud User Status Counter (CTR) CUi All values are set to 0. The authentication key is generated using the Setup initialization algorithm in the PPRF puncturable pseudo-random function. Material: akm Ui =PPRF.Setup(1 λ);
[0042] 2.2.2) Select a random one-time value r′ and an integer 2. 4 ≤v≤2 8 Get the current timestamp T reg And calculate the pseudonym CID Ui Registration certificate cred Ui The credential storage value B0, the long-term key storage value B1, and the fuzzy verification factor V Ui :
[0043] The calculation of pseudonym CID Ui First, the user state counter (CTR) is set. Ui Set to 0, and use the Eval evaluation algorithm in the PPRF puncturable pseudo-random function to calculate the authentication key: ak Ui =PPRF.Eval(akm Ui CTR Ui Then, based on the authentication key ak Ui Calculate the CID of the pseudonym Ui :
[0044] The calculation registration certificate cred Ui It involves selecting a random number r′ and obtaining the current timestamp T. reg Calculate the registration certificate: cred Ui =H0(ID) Ui ||r′||T reg );
[0045] The calculated credential storage value B0 is based on the registration credential. Ui and blind password BPW Ui Calculation, that is:
[0046]
[0047] The calculation of the long-term key storage value B1 is based on the authentication key material akm. Ui and blind password BPW Ui Calculate the long-term key storage value:
[0048] The calculation of fuzzy verification factor V Ui It is based on the blind password BPW Ui Calculate with integer v, that is:
[0049]
[0050] 2.2.3) Storage Parameters (CID) Ui ,akm Ui ,credUi CTR CUi ) and register information {B0,B1,V Ui ,v,CTR Ui Send to the user;
[0051] 2.3) The user writes the received registration information and one-time value r into the smart card SC. Ui .
[0052] The puncturable pseudo-random function described in the PPRF originates from the paper "How to Use Indistinguishability Obfuscation: Deniable Encryption" published by Sahai et al. at the 46th ACM Symposium on Theory of Computation in 2014. It supports nonlinear key evolution and features high computational efficiency and forward security.
[0053] The fuzzy authentication factor is derived from the paper "Two birds with one stone: Two-factor authentication with security beyond conventionalbound" published by Wang et al. in IEEE TDSC in 2016. It resists offline password guessing attacks to a certain extent and has the characteristic of increasing the inaccuracy of guessed passwords.
[0054] Step 3: Register the unmanned equipment.
[0055] The cloud server selects a random identifier ID. Dj The unmanned equipment status counter (CTR) Dj Cloud-based unmanned equipment status counter (CTR) CDj Set all to 0;
[0056] The authentication key material is generated using the Setup initialization algorithm in the PPRF puncturable pseudo-random function. And store registration information (ID) Dj ,akm Dj CTR CDj Then, the storage registration information is sent to the unmanned device for storage.
[0057] Step 4, Interactive Authentication and Security Control.
[0058] Reference Figure 2 The specific implementation of this step includes the following:
[0059] 4.1) The user calculates the user authentication cloud server message m1 and sends it to the cloud server:
[0060] 4.1.1) User enters identity IDUi and password PW Ui The smart card calculates the blind password BPW based on the random number r and the integer v. Ui =H0(r||PW Ui ) and fuzzy verification factor And the fuzzy verification factor With stored fuzzy verification factor V Ui Comparison:
[0061] if Then the process will be terminated;
[0062] Otherwise, proceed with 4.1.2);
[0063] 4.1.2) The user selects a random number x and uses the blind password BPW. Ui Calculate kana Ciphertext X and Authentication Message A1:
[0064] The calculation of pseudonyms First, calculate the authentication key material. and authentication key Then based on the authentication key material akm Ui and authentication key ak Ui Calculate the kana
[0065] The ciphertext X is calculated by first selecting a random number x, and then using the authentication key ak. Ui The calculation yielded:
[0066] The calculation of authentication message A1 first involves calculating the registration credential. Then based on the registration credential Ui Calculated
[0067] 4.1.3) Accumulate and store user status counters. Send user authentication message to cloud server
[0068] 4.2) The cloud server calculates the cloud server authentication message m2 for the unmanned device and sends it to the unmanned device:
[0069] 4.2.1) After receiving the user authentication cloud server message m1, the cloud server retrieves the pseudonym from the database.
[0070] If kana If the entry is found in the cloud server's database, then the corresponding entry is extracted and step 4.2.2) is executed.
[0071] Otherwise, proceed to step 4.2.3);
[0072] 4.2.2) Determine the user status counter (CTR) Ui With cloud user state counter CTR CUi Size relationship:
[0073] If the user state counter CTR Ui With cloud user state counter CTR CUi If they are not equal, the process will be terminated.
[0074] Otherwise, based on the user authentication key material akm Ui and stored credentials Ui Kana CID Ui , Ciphertext X calculates the user authentication key ak Ui and authentication messages
[0075] ak Ui =PPRF.Eval(akm Ui CTR Ui ),
[0076] and the authentication message Compare with the received authentication message A1:
[0077] like Then the process will be terminated;
[0078] Otherwise, return to the entry and proceed to step 4.2.3);
[0079] 4.2.3) Retrieve database entry ∈ db and determine the user status counter CTR. Ui With cloud user state counter CTR CUi Size relationship:
[0080] If the user state counter CTR Ui Less than or equal to the cloud user state counter CTR CUi If so, proceed to step 4.2.4);
[0081] Otherwise, proceed to step 4.2.5);
[0082] 4.2.4) Determine whether all entries in the database have been retrieved:
[0083] If all entries in the database have been retrieved, then return
[0084] Otherwise, retrieve the next entry;
[0085] 4.2.5) Based on the user authentication key material akm Ui Cloud-based user status counter (CTR) CUi and user state counter CTR Ui Calculate the local authentication key: User authentication key: ak Ui =PPRF.Eval(akm Ui CTR Ui ),pseudonym: Then use the pseudonym CID Ui With the received kana Comparison:
[0086] if Then retrieve the next entry;
[0087] Otherwise, proceed to step 4.2.6);
[0088] 4.2.6) Based on the stored credentials Ui Kana CID Ui ciphertext X and the calculated authentication key ak Ui Calculate the authentication message: and the authentication message Compare with the received authentication message A1:
[0089] if Then retrieve the next entry;
[0090] Otherwise, the Punct algorithm in the PPRF puncturable pseudo-random function is used to update the user authentication key material: akm Ui =PPRF.Punct(akm Ui CTR CUi ), and return the currently retrieved entry;
[0091] 4.2.7) Calculate the authentication key ak for the unmanned equipment. Dj Ciphertext X′ and authentication message A2:
[0092] The unmanned equipment authentication key ak Dj It is based on the AKM authentication key material for unmanned equipment. Dj Cloudless unmanned equipment status counter (CTR) CDj The calculation yielded:
[0093] ak Dj =PPRF.Eval(akm Dj CTR CDj )
[0094] The calculated ciphertext X′ is based on the user authentication key ak.Ui and unmanned equipment authentication key ak Dj The calculation yielded:
[0095]
[0096] The computational authentication message A2 is based on the unmanned device authentication key ak. Dj Cloud-based unmanned equipment status counter (CTR) CDj The following can be calculated from the ciphertext X′:
[0097] A2 = H1(ID) Dj ||ak Dj ||CTR CDj ||X′);
[0098] 4.2.8) Accumulate and store the status counters of unmanned devices in the cloud. And send a cloud server authentication message for the unmanned device m2={X′,A2,CTR} to the unmanned device. CDj};
[0099] 4.3) The unmanned device calculates the unmanned device authentication cloud server message m3 and sends it to the cloud server:
[0100] 4.3.1) After receiving the message, the unmanned device calculates the authentication key ak. Dj and authentication messages
[0101] The calculated authentication key ak Dj It is based on the stored authentication key material akm Dj Unmanned equipment status counter (CTR) Dj The calculation yielded:
[0102] ak Dj =PPRF.Eval(akm Dj CTR Dj )
[0103] The computational authentication message It is based on the authentication key ak Dj The calculation yielded:
[0104]
[0105] 4.3.2) This authentication message Compare with the received authentication message A2:
[0106] if Then the process will be terminated;
[0107] Otherwise, based on the calculated unmanned equipment authentication key ak Djand the received unmanned equipment status counter (CTR) Dj The session key shared between the computing server and the cloud server: sk CDj =H3(ak) Dj ||CTR Dj ) and random numbers:
[0108] 4.3.3) Select a random number y and obtain the current timestamp T. ij Set the local state counter CTR ij Set to 0, calculate ciphertext Y and master key k ij The session key sk shared between unmanned equipment and users ij And authentication message A3:
[0109] The calculated ciphertext Y is based on the authentication key ak. Dj The calculation yielded:
[0110] The calculation master key k ij It is based on the user's random number x, the unmanned device's random number y, and the timestamp T. ij The calculation yielded:
[0111] k ij =H3(x||y||T) ij );
[0112] The session key sk shared between the unmanned computing device and the user ij It is based on the master key k ij The calculation yielded:
[0113] sk ij =PRF(k ij "sessionkey")
[0114] The computational authentication message A3 is based on the cloud-based unmanned device status counter CTR. CDj User ciphertext X′, unmanned device ciphertext Y, and timestamp T ij The calculation yielded:
[0115] A3=H2(ak Dj ||CTR CDj ||X′||Y||T ij );
[0116] 4.3.4) Determine the status counter (CTR) of unmanned equipment in the cloud. CDj and unmanned equipment status counter (CTR) Dj Size relationship:
[0117] If CTR CDj >CTRDj Then, based on the stored unmanned equipment authentication key material akm Dj Update:
[0118] akm Dj =PPRF.Punct(akm Dj CTR Dj );
[0119] Otherwise, the stored unmanned device authentication key material akm Dj Remain unchanged;
[0120] 4.3.5) Based on the stored unmanned equipment authentication key material akm Dj Cloud-based unmanned equipment status counter (CTR) CDj Update unmanned equipment authentication key materials: Accumulate the cloud-based unmanned device status counter Storage parameters And send an unmanned device authentication cloud server message m3={Y,A3,T to the cloud server. ij};
[0121] 4.4) The cloud server calculates the cloud server authentication user message m4 and sends it to the user:
[0122] 4.4.1) The cloud server calculates the authentication key ak for the unmanned device. Dj User encrypted message X′, unmanned device encrypted message Y, timestamp T ij and cloud-based unmanned device status counters Calculate authentication message
[0123] Then the authentication message Compare with received authentication message A3:
[0124] if Then the process will be terminated;
[0125] Otherwise, based on the calculated unmanned equipment authentication key ak Dj and cloud-based unmanned device status counters Session keys shared between the cloud computing server and unmanned devices: And proceed with step 4.4.2);
[0126] 4.4.2) Calculate the ciphertext Y′, authentication message A4, and session key sk shared between the cloud server and the user. CDj New user authentication key materials New kana
[0127] The computation of the unmanned device's ciphertext Y′ is based on the unmanned device's authentication key ak. Dj and user authentication key ak Ui The calculation yielded:
[0128] The calculated authentication message A4 is based on the user authentication key ak. Ui User status counter User ciphertext X, unmanned device ciphertext Y′, and timestamp T ij The calculation yielded:
[0129] The session key sk shared between the computing and the unmanned device CDj It is based on the unmanned equipment authentication key ak Dj Cloud-based unmanned equipment status counter Calculation, i.e.
[0130] The updated authentication key material It is based on the user state counter (CTR) Ui The calculation yielded:
[0131]
[0132] The calculation of pseudonyms First, calculate the new authentication key. Then based on the new authentication key The calculation yielded:
[0133] 4.4.3) Accumulate the cloud user status counter Storage parameters Send cloud server authenticated user message m4={Y′,A4,T ij};
[0134] 4.4) The user calculates and uses the session key sk ij Encrypt the transmission of instructions to unmanned equipment:
[0135] 4.4.1) The user uses the calculated authentication key ak Ui User ciphertext X, stored user state counter Received unmanned equipment ciphertext Y′ and timestamp T ij Calculate the authentication message: and the authentication message Compare with the received authentication message A4:
[0136] if Then the process will be terminated;
[0137] Otherwise, set the local state counter CTR. ij Set to 0 and execute step 4.4.2);
[0138] 4.4.2) Select a new integer 2 4 ≤v new ≤2 8 Calculate the session key sk shared between the user and the cloud server. CUi Master key k ij sk, a session key shared between the user and the unmanned device ij New fuzzy verification factor and long-term key storage value
[0139] The session key sk shared between the computing user and the cloud server CUi It is based on the user authentication key ak Ui and user state counter The calculation yielded:
[0140] The calculation master key k ij It is based on the timestamp T ij The calculation yields: k ij =H3(x||y||T) ij );
[0141] The session key sk shared between the computing and the unmanned device ij It is based on the master key k ij Calculated from the string "sessionkey":
[0142] sk ij =PRF(k ij "sessionkey";
[0143] The calculation of fuzzy verification factor It is based on the blind password BPW Ui and integer v new The calculation yielded:
[0144]
[0145] The calculation of the long-term key storage value First, based on the user state counter Calculate new authentication key material Based on the new authentication key materials Update long-term key storage value
[0146] 4.4.3) Storage parameters Using session key skij The instructions are transmitted to the unmanned equipment in encrypted form.
[0147] Step 5, Non-interactive authentication and security control.
[0148] Reference Figure 3 The specific implementation of this step includes the following:
[0149] 5.1) Obtain the current timestamp T, and calculate the period CTR = |TT| ij | / n0、Parameter n=CTR ij ;
[0150] 5.2) Determine the relationship between parameter n and period CTR:
[0151] 5.2.1) When n < CTR, enter the loop and calculate the master key: k ij =PRF(k ij "update"), determines the relationship between parameter n and the period CTR:
[0152] If CTR = n+1, then calculate the new master key: And accumulate the parameter n;
[0153] Otherwise, use the master key k ij Assigned to the new master key And execute step 5.2.2);
[0154] 5.2.2) The loop ends when n≥CTR, and a new session key is calculated: The parameter {k ij CTR ij} Replace with parameters
[0155] 5.3) Using session key sk ij The instructions are encrypted before transmission.
[0156] Step 6: The user changes their password.
[0157] Reference Figure 4 The specific implementation of this step includes the following:
[0158] 6.1) User enters initial identity ID Ui and password PW Ui The smart card calculates the blind password BPW based on a random number r and an integer v. Ui =H0(r||PW Ui ) and fuzzy verification factor And the fuzzy verification factor With stored fuzzy verification factor V Ui Comparison:
[0159] if Then the process will be terminated;
[0160] Otherwise, the user enters a new password. And proceed with step 6.2);
[0161] 6.2) Smart card calculates new blind password Voucher storage value Long-term key storage value and fuzzy verification factor
[0162] The calculation updates the blind password It is calculated based on the random number r:
[0163]
[0164] The calculation voucher storage value It is based on the new blind password The calculation yielded:
[0165]
[0166] The calculation of the long-term key storage value It is based on the new blind password The calculation yielded:
[0167]
[0168] The calculation of fuzzy verification factor That is, according to the new blind password Calculated with integer v, we get:
[0169]
[0170] 6.3) Set the parameters {B0, B1, V} Ui} Replace with parameters After completing the user's password modification, return to step 4.
[0171] The markings in the above steps are only for clearer illustration of the implementation scheme of the present invention, and their sequence order is not limited. Furthermore, the above description is merely a specific example of the present invention and does not constitute any limitation on the present invention. Obviously, those skilled in the art, after understanding the content and principles of the present invention, may make various modifications and changes in form and detail without departing from the principles and structure of the present invention. However, these modifications and changes based on the concept of the present invention are still within the scope of protection of the claims of the present invention.
Claims
1. A two-factor authentication and security control method for unmanned systems based on a cloud-network-edge architecture, characterized in that, Includes the following steps: (1) Cloud servers select four hash functions , For safety parameters, and publicly disclose system parameters ; (2) User inputs identity and password Select random number Calculate blind password Send a registration request to the cloud server ; (3) After receiving the registration request, the cloud server selects an integer. Calculate and store parameters ,in This represents user authentication key material. Represents registration credentials; calculates registration information. And send it to the user; (4) The user will receive the registration information and random number. Write your own smart card ; (5) Select random identifier for cloud server Generate authentication key materials for unmanned equipment Storage parameters And send it to unmanned equipment; (6) User enters identity and password smart card Calculate blind password and fuzzy verification factor Validate fuzzy validation factors The correctness of the kana, and the calculation of the kana. ciphertext and authentication messages Accumulate and store the user state counter Send a message to the cloud server ; (7) Cloud server verification message The correctness of the calculation of the ciphertext and authentication messages Accumulate and store the status counters of unmanned devices in the cloud. Send messages to unmanned devices ; (8) After receiving the message, the unmanned device calculates the authentication message. And verify its correctness, obtain the current timestamp. Calculate the master key Session keys shared with cloud servers Session keys shared with users ciphertext Authentication message And unmanned equipment authentication key materials Accumulate the unmanned equipment status counter Initialize the local state counter Storage parameters and send messages to the cloud server. ; (9) After receiving the message, the cloud server calculates the authentication message. And verify its correctness, calculate the session key shared with the unmanned device. Unmanned equipment authentication key materials ciphertext ,pseudonym and authentication messages Accumulate the cloud user status counter Storage parameters and send messages to users ; (10) User calculates authentication message And verify its correctness, initialize the local state counter. Choose a new integer Calculate the session key shared with the cloud server. Master key Session keys shared with unmanned devices Fuzzy verification factor and long-term key storage value ,storage and using session keys Encrypt the transmission of instructions to unmanned equipment; (11) Users and unmanned equipment obtain the current timestamp Calculate the master key and session key , parameters Replace with parameters ,in Use it as a loop counter variable; and use the session key. Encrypt the transmission of instructions; (12) User inputs identity and password Calculate blind password and fuzzy verification factor And verify its correctness, then enter the new password again. Calculate and update the blind password Voucher storage value Long-term key storage value and fuzzy verification factor and store parameters .
2. The method according to claim 1, characterized in that: In step (3), the parameters are calculated and stored. And calculate registration information Its implementation includes the following: Calculate user authentication key materials It is an initialization algorithm using the PPRF puncturable pseudo-random function. Generate user authentication key materials ; Calculate kana First, the user state counter is set. Set to 0, and use the evaluation algorithm in the PPRF puncturable pseudo-random function. Calculate the authentication key: Then based on the authentication key Calculate kana : ; Calculate registration certificate It is to select a random number. Get the current timestamp Calculate the registration certificate: ; Computing Cloud User State Counter It is a user status counter in the cloud. Set to 0; Calculate the stored value of the voucher It is based on the registration certificate. and blind password Calculation, that is: ; Calculate the long-term key storage value It is based on user authentication key materials and blind password Calculate the long-term key storage value: ; Calculate integers It is Choose any integer within the interval; Calculate fuzzy verification factor It is based on the blind password and integers Calculation, that is: ; Calculate the user state counter It is the user state counter Set to 0.
3. The method according to claim 1, characterized in that: In step (5), the unmanned equipment authentication key material is generated. It is a status counter for unmanned equipment. Cloud-based unmanned equipment status counter Set to 0, and calculate the unmanned equipment authentication key material: 。 4. The method according to claim 1, characterized in that: In step (6), the blind password is calculated. Fuzzy verification factor ,pseudonym ciphertext and authentication messages And verify the fuzzy verification factor. The correctness of this is achieved through the following means: The calculation of the blind password It is based on random numbers Calculation, i.e. ; The calculation of fuzzy verification factor It is based on the blind password Calculation, that is: ; The calculation of pseudonyms First, calculate the user authentication key material. and authentication key Then, based on the user authentication key materials... and user authentication key Calculate the kana ; The computation ciphertext First, select a random number. Then based on the user authentication key The calculation yielded: ; The computational authentication message The registration certificate is calculated first. Then, based on the registration certificate Calculated ; The verification fuzzy verification factor The correctness is determined by the calculated fuzzy verification factor. Fuzzy verification factor compared to local storage Comparison: like Then the fuzzy verification factor Validation error; Otherwise, fuzzy verification factor Verification successful.
5. The method according to claim 1, characterized in that, The cloud server verification message mentioned in step (7) The correctness of the calculation of the ciphertext. and authentication messages Its implementation includes the following: (7a) Cloud server verification message Correctness: (7a1) Retrieve kana from the cloud server's database. : (7a2) Determine the kana Was it found? If kana If found, the corresponding entry will be retrieved. , execute (7a3); Otherwise, execute (7a5); (7a3) Determine the message Correctness: If the user state counter With cloud user status counter If they are not equal, then the message mistake; Otherwise, execute (7a4); (7a4) Calculate the user authentication key: Based on the user authentication key Calculate the authentication message: Then the authentication message With the received authentication message Comparison: if Then the message mistake, Otherwise, message correct; (7a5) Retrieve database entries , judge message Correctness: If the user state counter Less than or equal to the cloud user state counter If so, then execute (7a6); Otherwise, execute (7a7); (7a6) Determine whether all entries in the database have been retrieved: If all entries in the database have been retrieved, then the message Error, return ; Otherwise, retrieve the next entry; (7a7) Calculate the local authentication key: User authentication key: Based on the local authentication key and user authentication key Calculate kana : Then change the pseudonym With the received kana Comparison: if If so, then retrieve the next entry; Otherwise, execute (7a8); (7a8) Calculate the authentication message: and the authentication message With the received authentication message Comparison: if If so, then retrieve the next entry; Otherwise, message Correct, and update user authentication key materials: Returns the currently retrieved item. ; (7b) Calculate the ciphertext and authentication messages : The computation ciphertext It is based on the user authentication key. and unmanned equipment authentication keys The calculation yielded: ; The computational authentication message It is based on the unmanned equipment authentication key. Cloud-based unmanned equipment status counter and ciphertext The calculation yielded: 。 6. The method according to claim 1, characterized in that: In step (8), the authentication message is calculated. And verify its correctness; Computation and unmanned devices share session keys Unmanned equipment authentication key materials ciphertext ,pseudonym Authentication message Its implementation includes the following: (8a) Calculate authentication message And verify its correctness: (8a1) Based on the unmanned equipment authentication key material Cloud-based unmanned equipment status counter Calculate the authentication key for unmanned equipment : ; (8a2) Based on the unmanned equipment authentication key Calculate the authentication message: ; (8a3) Calculate the authentication message With the received authentication message Comparison: if Then the authentication message Validation error; Otherwise, authentication message Verification successful; (8b) Calculate the session key shared with unmanned equipment Unmanned equipment authentication key materials ciphertext ,pseudonym Authentication message : The session key shared between the computing and the unmanned device It is based on the unmanned equipment authentication key. Cloud-based unmanned equipment status counter The session key shared between the computer and the unmanned device: ; The authentication key material for the computing unmanned equipment It employs the puncture algorithm in the puncture-capable pseudo-random function of PPRF. Update unmanned equipment authentication key materials: ; The computation ciphertext It is based on the unmanned equipment authentication key. and user authentication key The calculation yielded: ; The computational authentication message It is based on the status counter of unmanned equipment in the cloud. User encrypted text Unmanned equipment encrypted messages and timestamp The calculation yielded: .
7. The method according to claim 1, characterized in that: In step (9), the authentication message is calculated. And verify its correctness, and calculate the session key shared with the unmanned equipment. Unmanned equipment authentication key materials Unmanned equipment encrypted messages ,pseudonym Authentication message Its implementation includes the following: (9a) Calculate authentication message And verify its correctness: (9a1) Based on the unmanned equipment authentication key Calculate authentication message ; (9a2) Calculate the authentication message With the received authentication message Comparison: like Then the authentication message Verification failed; Otherwise, authentication message Verification successful; (9b) Compute the session key shared with unmanned devices Unmanned equipment authentication key materials Unmanned equipment encrypted messages ,pseudonym and authentication messages : The session key shared between the computing and the unmanned device It is based on the unmanned equipment authentication key. Cloud-based unmanned equipment status counter Calculation, i.e. ; The authentication key material for the computing unmanned equipment It is based on the user state counter. The calculation yielded: ; The encrypted message of the unmanned computing device It is based on the unmanned equipment authentication key. and user authentication key The calculation yielded: ; The computational authentication message It is based on the user authentication key. User status counter User encrypted text Unmanned equipment encrypted messages and timestamp The calculation yielded: ; The calculation of pseudonyms First, calculate the new user authentication key. Then based on the new user authentication key The calculation yielded: .
8. The method according to claim 1, characterized in that: In step (10), the authentication message is calculated. And verify its correctness, and calculate the session key shared with the cloud server. Master key Session keys shared with unmanned devices Fuzzy verification factor and long-term key storage value Its implementation includes the following: (10a) Based on the user authentication key Calculate the authentication message: ; (10b) Calculate the authentication message With the received authentication message Comparison: like Then the authentication message Verification failed; Otherwise, authentication message Verification successful; (10c) Calculate the session key shared with the cloud server Master key and session keys shared with unmanned devices Fuzzy verification factor Long-term key storage value : The session key shared between the computing and the cloud server It is based on the user authentication key. and user state counter The calculation yielded: ; The calculated master key It is based on timestamps The calculation yielded: ; The session key shared between the computing and the unmanned device It is based on the master key and strings The calculation yielded: ; The calculation of fuzzy verification factor It is based on the blind password and integers The calculation yielded: ; The calculation of the long-term key storage value It is first based on the user state counter. Calculate new user authentication key material Then, based on the new user authentication key materials Update long-term key storage value .
9. The method according to claim 1, characterized in that: In step (11), the master key is calculated. and session key It is a periodic setting Set the local state counter The value of is assigned to the loop counter variable. Complete the loop counting variable Initialization; based on the period and parameters Perform calculations; when At that time, enter the loop to calculate the master key. Determine the cycle and parameters Numerical relationships: if Then calculate the new master key. Accumulated parameters ; Otherwise, the master key Assigned to the new master key Accumulated parameters ; when When the loop ends, it is based on the new master key. Calculate the updated session key , where parameters This refers to the session key lifecycle, which is preset by the system.
10. The method according to claim 1, characterized in that: In step (12), the blind password is calculated. and fuzzy verification factor And verify its correctness, its implementation includes the following: (12a) Based on random numbers Calculate blind password ; (12b) According to the blind password Calculate fuzzy verification factor ; (12c) The calculated fuzzy verification factor Fuzzy verification factor compared to local storage Comparison: like Then the fuzzy verification factor Verification failed; Otherwise, fuzzy verification factor Verification successful.
11. The method according to claim 1, characterized in that: In step (12), the updated blind password is calculated. Voucher storage value Long-term key storage value and fuzzy verification factor Its implementation includes the following: The calculation updates the blind password It is based on random numbers The calculation yielded: ; The calculation voucher storage value It is based on the new blind password The calculation yielded: ; The calculation of the long-term key storage value It is based on the new blind password The calculation yielded: ; The calculation of fuzzy verification factor That is, according to the new blind password and integers The calculation yielded: 。
Citation Information
Patent Citations
Two-factor authentication method based on portable TPM (PTPM) and certificateless public key signature for cloud
CN107733657A