A blockchain-based anonymous identity authentication method for certificateless iot devices

CN117749388BActive Publication Date: 2026-09-25CHONGQING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311753577.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2026-09-25
Estimated Expiration
2043-12-18

AI Technical Summary

Technical Problem

认证效率方面,现有身份认证方案在实际应用中,随着用户和终端的增加,证书开销不断扩大,导致证书撤销列表过大,发证方批量维护列表周期较长,验证者下载更新列表不及时

Benefits of technology

[0051]本发明方法通过无证书机制和区块链解决了身份认证过程中的单点故障问题,使用加密了技术保证了身份认证信息不会被恶意获取篡改,使用变色龙哈希为物联网终端提供了兼顾安全性与高效性的匿名跨域身份认证过程。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117749388B_ABST
    Figure CN117749388B_ABST
Patent Text Reader

Abstract

This invention relates to the fields of identity recognition and blockchain technology, specifically to a certificateless IoT device anonymous identity authentication method based on blockchain, comprising: constructing a certificateless blockchain identity authentication system based on a blockchain authentication server (BAS), a terminal edge node (TE), and a terminal device (TD), and performing system initialization; TE and TD executing a third-party smart contract to complete identity registration; and TD connecting to TE. i When serving the domain, the fourth smart contract is executed to complete two-way identity authentication; TD from TE i Service domain switch to TE j When serving a domain, the fourth smart contract is executed to complete cross-domain identity authentication for TD; TE i If the TD identity expires, BAS executes a second smart contract to cancel the terminal's identity information. The method of this invention solves the single point of failure problem in the identity authentication process through a certificateless mechanism and blockchain, and uses Chameleon Hash to provide an anonymous cross-domain identity authentication process for IoT terminals that balances security and efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of identity recognition and blockchain technology, specifically to a blockchain-based method for anonymous identity authentication of certificateless IoT devices. Background Technology

[0002] In recent years, with the rapid development of IoT technology, the number of devices connected to the network has exploded. According to IoT Analytics, by the end of 2021, the number of global IoT connections reached 12.2 billion, a year-on-year growth rate of nearly 8%. Meanwhile, IoT Analytics predicts that by 2025, the number of global IoT gateway connections will reach approximately 27 billion. With the rapid expansion of the IoT, the issue of device authentication is receiving increasing attention. However, in practical applications, IoT devices need to interact across domains, requiring cross-domain authentication. Currently, most mainstream authentication methods are centralized; server attacks can lead to server paralysis, data leaks, or malicious tampering of authentication results. Blockchain, on the other hand, is a decentralized end-to-end network that uses a distributed database to identify, disseminate, and record information. Through a combination of cryptography, time-series mechanisms, and consensus mechanisms, blockchain can maintain the consistency of data in a distributed network system while ensuring that data is instantly verifiable, traceable, and difficult to tamper with or shield. Because of these characteristics, blockchain is widely used in payment settlement, bills, credit authentication, and regulatory fields. The execution of smart contracts on the blockchain has the advantages of being open and transparent, with processes that cannot be tampered with, and results that cannot be destroyed or forged. Therefore, it has attracted widespread attention from academia and industry.

[0003] Existing solutions still have issues regarding system security, privacy protection, and authentication efficiency. In terms of system security, some existing identity authentication models and solutions often employ centralized management of end-user credentials and identities, leading to single points of failure and significant risks of privacy leaks. For example, end-user identity credentials, such as passwords and biometric factors, are typically stored on the server side. If the server is attacked, the system may become unusable, and all end-user credentials may be at risk of being leaked. Regarding privacy protection, confidential information about the terminal, such as its identity, transaction data, and location, may be misused by identity service providers or application service providers. In terms of authentication efficiency, in practical applications, existing identity authentication schemes experience increasing certificate overhead as the number of users and terminals grows, resulting in excessively large certificate revocation lists. Issuing parties face long maintenance cycles for these lists, and verifiers are slow to download and update them. Furthermore, due to the append-only nature of blockchain, frequent data interactions and revocations cause continuously increasing data storage, placing a huge storage and computational burden on the identity authentication system and impacting its availability, applicability, and performance.

[0004] Therefore, the above-mentioned existing technologies pose a significant risk of privacy breaches or may cause enormous storage and computing burdens, affecting the availability, applicability, and performance of the system. Summary of the Invention

[0005] To address the aforementioned problems, this invention employs a blockchain-based certificateless IoT device anonymous identity authentication method, comprising:

[0006] S1. Construct an identity authentication system based on a certificateless blockchain using the blockchain authentication server BAS, the terminal edge node TE, and the terminal device TD. Deploy four smart contracts on the system, namely the first smart contract, the second smart contract, the third smart contract, and the fourth smart contract; initialize the system.

[0007] S2, the terminal edge node TE and the terminal device TD execute the third smart contract to complete identity registration;

[0008] S3. When the registered terminal device TD accesses the service domain of the registered terminal edge node TE, the fourth smart contract is executed to complete two-way identity authentication.

[0009] S4, the terminal device TD after two-way authentication receives data from the terminal edge node TE. i Service domain switched to terminal edge node TE j When serving the domain, the fourth smart contract is executed to complete the identity switching authentication of the terminal device TD;

[0010] S5. After the identity of the terminal edge node TE or the terminal device TD becomes invalid, BAS executes the second smart contract to cancel the terminal identity information.

[0011] The functions of smart contracts include:

[0012] The first smart contract is used to disclose public system parameters; the second smart contract is used for device identity management; the third smart contract is used for terminal identity registration; and the fourth smart contract is used for terminal identity authentication.

[0013] System initialization includes:

[0014] S11. Select a secure hash function H = (H0, H1, H2) and an elliptic curve E(F). p F and generator G; where F p For a finite field;

[0015] S12, Randomly generate the system master private key S admin The computing system master public key P admin =S admin G;

[0016] S13. Execute the first smart contract and expose the system's public parameter M. P =(E(F) p ),G,H,P admin ).

[0017] 11. A blockchain-based anonymous identity authentication method for certificateless IoT devices according to claim 1, characterized in that the first to fourth smart contracts include:

[0018] The first smart contract is a public system public parameter contract; the second smart contract is a device identity management contract; the third smart contract is a terminal identity registration contract; and the fourth smart contract is a terminal identity authentication contract.

[0019] The identity registration process for terminal edge nodes (TE) or terminal devices (TD) includes:

[0020] S21. The terminal edge node TE or the terminal device TD randomly selects a portion of the private key x according to the elliptic curve. T Calculate part of the public key U T and trapdoor key k T Generate blockchain account address ID T And Chameleon Hash CH T ;

[0021] S22, Terminal Edge Node (TE) or Terminal Device (TD) uses public key P admin Encryption x T U T ID T and CH T The ciphertext C1 is obtained, and the third smart contract is executed to send an identity registration request to BAS based on the ciphertext C1.

[0022] S23, BAS uses the system master private key s admin Decrypting ciphertext C1 yields x T U T ID T and CH T And execute the second smart contract to check the ID. T If the user is already registered, the registration request will be rejected; otherwise, BAS will proceed according to the publicly available system parameter M. p Partial private key x T Partial public key U T and blockchain account address ID T Generate a portion of the public key W for BAS T and part of the private key d T ;

[0023] S24, BAS uses U T Encryption part of the public key W T and part of the private key dT The ciphertext C2 is obtained, and the third smart contract is executed based on the ciphertext C2 to return an identity registration response;

[0024] S25, Terminal Edge Node TE or Terminal Equipment TD uses x T Decrypting C2 yields part of BAS's public key W. T and part of the private key d T And according to W T and d T Generate complete private key S T and the complete public key P T ;

[0025] S26. The terminal edge node TE or the terminal device TD executes the third-party smart contract to transfer the complete public key P. T Send to BAS;

[0026] S27. BAS obtains the registration time, expiration time, and identity verification of the terminal edge node TE or terminal device TD, and executes the second smart contract to transfer part of the public key U. T Complete public key P T Account Address ID T Chameleon Hash CH T Registration time, expiration time, and identity legitimacy are stored on the blockchain.

[0027] Terminal edge node TE or terminal device TD calculates trapdoor key k T Generate Chameleon Hash CH T include:

[0028] The terminal edge node TE or terminal device TD obtains the timestamp t, selects a random number m, and calculates r = H1(ID). T ||t), generate the chameleon hash CH T (m,r)=mG+rU T Calculate the trapdoor key k T =m+rx T ;

[0029] Where G is the generator, H1 is the system's secure hash function, and m and r are the two parameters of the Chameleon Hash.

[0030] Terminal equipment TD and terminal edge node TE i Two-way authentication includes:

[0031] S31, Terminal equipment TD access to terminal edge node TE i When serving a domain, a random number α is selected based on the elliptic curve. TD And TD pseudo-identity identifier PID TD Get timestamp TS TDUse Chameleon Hash to calculate the encrypted random number A TD The parameter r of the Chameleon Hash of the terminal device TD * TD and m * TD The terminal device TD will use PID TD A TD m * TD r * TD and timestamps (TS) TD Assemble the identity access authentication information and execute the fourth smart contract based on the identity access authentication information to send the identity access authentication request;

[0032] S32, BAS executes the second smart contract to check the identity validity of the terminal device TD and verify the chameleon hash based on the identity access authentication request. If the identity is valid and the chameleon hash verification is successful, the terminal edge node TE is notified. i The terminal device TD will request authentication; otherwise, authentication will fail.

[0033] S33, When the terminal edge node TE i When the terminal device TD requests authentication, the terminal edge node TE i Check timestamp TS TD Is it valid? If TS TD If valid, a random number is selected based on the elliptic curve. and TE i PID (Pseudo-identity identifier) TEi Use Chameleon Hash to calculate the encrypted random number Terminal edge node TE i Parameters of the chameleon hash and Get timestamp Terminal edge node TE i Will and timestamp The information is assembled into an authentication response, and the fourth smart contract is executed based on the authentication response to send the identity access authentication response.

[0034] S34, BAS executes the second smart contract and checks the terminal edge node TE based on the identity access authentication response. i The system verifies the identity's legitimacy and chameleon hash. If the identity is legitimate and the chameleon hash verification is successful, the terminal device TD is notified to communicate via the terminal edge node TE. i The authentication response will be received; otherwise, authentication will fail.

[0035] S35, When the terminal device TD passes through the terminal edge node TE iDuring the authentication response, the terminal device TD and the terminal edge node TE i Swap random numbers α TD and By exchanging random number α TD and Generate session key SK i Complete identity access authentication.

[0036] Calculate A TD , and include:

[0037] Calculate A TD =α TD U TD According to A TD Calculate v TD =H2(PID) TD ||A TD ||TS TD According to v TD Calculate r * TD =α TD v TD According to r * TD Calculate m * TD =k TD -r * TD x TD ;

[0038] Among them, U TD H2 is a portion of the public key of the terminal device TD, H2 is the system's secure hash function, and k TD For the trapdoor key of the terminal device TD, x TD For the TD private key of the terminal device, α TD The random number selected for the TD terminal device.

[0039] Verifying the chameleon hash includes: BAS calculation v TD =H2(PID) TD ||A TD ||TS TD And verify Check if the condition is met; if met, the verification passes; otherwise, the verification fails.

[0040] Where G is the generator of the system, H2 is the secure hash function of the system, and k TD For the trapdoor key of the terminal device TD, x TD This is a partial private key for the TD terminal device.

[0041] Identity switching authentication includes:

[0042] S41, Terminal device TD from terminal edge node TE i Service domain switched to terminal edge node TE j When accessing the service domain, the fourth smart contract is executed to send an identity switching authentication request;

[0043] S42, BAS executes the second smart contract to check the identity of the terminal device TD based on the identity switching authentication request. If the identity is valid, it notifies the terminal edge node TE. j The authentication request for identity switching is made through the terminal device TD; otherwise, the identity switching authentication fails.

[0044] S43, When the terminal edge node TE j When the terminal device TD requests identity switching authentication, the terminal edge node TE j Random numbers are selected based on the elliptic curve. Equipment TE j fake identity and timestamp The encrypted random number A is calculated using the Chameleon hash algorithm. TEj Terminal edge node TE i Parameters of the chameleon hash and TE j Will and timestamp Assemble the context exchange request information and execute the fourth smart contract to send a context exchange request to BAS based on the context exchange request information;

[0045] S44, BAS executes the second smart contract and checks the terminal edge node TE according to the context exchange request. j The system verifies the identity's legitimacy and chameleon hash. If the identity is legitimate and the chameleon hash verification is successful, the terminal edge node (TE) is notified. i via terminal edge node TE j A context exchange request must be submitted; otherwise, identity switching authentication will fail.

[0046] S45, When the terminal edge node TE i via terminal edge node TE j When the terminal edge node TE requests a context exchange, i The encrypted terminal device TD obtains the identity access authentication information, receives ciphertext C3, and executes the fourth smart contract based on ciphertext C3 to send a context exchange response;

[0047] S46, Terminal Edge Node TE jBased on the context exchange response, the encrypted text C3 is decrypted to obtain the identity and access authentication information of the terminal device TD. This information is then exchanged between the terminal device TD and the terminal edge node TE. j Based on the identity authentication information exchanged by the terminal device TD, a random number α is generated. TD , And based on the random number α TD , Generate session key SK j Complete the identity switching authentication.

[0048] Identity cancellation includes:

[0049] If BAS detects that the identities of terminal edge node TE and terminal device TD have expired, or if terminal edge node TE and terminal device TD actively execute the third smart contract to send an identity cancellation request, BAS executes the second smart contract to mark the identities of terminal edge node TE and terminal device TD as expired.

[0050] Beneficial effects:

[0051] The method of this invention solves the single point of failure problem in the identity authentication process through a certificateless mechanism and blockchain, uses encryption technology to ensure that identity authentication information cannot be maliciously obtained and tampered with, and uses chameleon hash to provide an anonymous cross-domain identity authentication process for IoT terminals that balances security and efficiency. Attached Figure Description

[0052] Figure 1 A system model diagram of an anonymous identity authentication scheme for IoT devices based on certificateless blockchain provided in an embodiment of the present invention;

[0053] Figure 2 A flowchart of an anonymous identity authentication method for IoT devices based on certificateless blockchain is provided for an embodiment of the present invention;

[0054] Figure 3 This is a data interaction diagram for terminal identity registration provided in an embodiment of the present invention;

[0055] Figure 4 This is a data interaction diagram for terminal identity access authentication provided in an embodiment of the present invention;

[0056] Figure 5 This is a data interaction diagram for terminal identity switching authentication provided in an embodiment of the present invention. Detailed Implementation

[0057] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0058] like Figure 1 As shown, this invention proposes an anonymous identity authentication scheme system for IoT devices based on certificate-free blockchain. The scheme includes: a system administrator, a blockchain authentication server, terminal devices, and terminal edge nodes. The system administrator is responsible for system initialization, selecting a group of trusted devices in the IoT as the blockchain authentication server and public system parameters. The blockchain authentication server is responsible for managing the terminal's identity information and verifying the legitimacy of the terminal's identity and chameleon hash. The terminal edge nodes, as service providers, provide application services within their wireless domain, while the terminal devices are service requesters.

[0059] like Figure 2 As shown, an anonymous identity authentication method for IoT devices based on certificateless blockchain includes: a system initialization phase, a terminal identity registration phase, a terminal identity access authentication phase, a terminal identity switching authentication phase, and a terminal identity deregistration phase, specifically including the following steps:

[0060] S1. Construct an identity authentication system based on a certificateless blockchain using the blockchain authentication server BAS, the terminal edge node TE, and the terminal device TD. Deploy the first to fourth smart contracts on the system and initialize the system. The blockchain authentication server BAS is responsible for maintaining the blockchain distributed ledger and providing decentralized services to store data.

[0061] S2, the terminal edge node TE and the terminal device TD execute the third smart contract to complete identity registration;

[0062] S3, Terminal equipment TD access to terminal edge node TE i When accessing the service domain, execute the fourth smart contract to complete two-way identity authentication;

[0063] S4, Terminal device TD from terminal edge node TE i Service domain switched to terminal edge node TE j When serving a domain, the fourth smart contract is executed to complete the continuous cross-domain identity authentication of the terminal device TD;

[0064] S5, Terminal Edge Node TE i If the TD identity of the terminal device becomes invalid, BAS executes the second smart contract to cancel the terminal identity information.

[0065] Furthermore, the specific steps of the system initialization phase are as follows:

[0066] S11: Select a secure hash function Elliptic curve E(F) p ) and generator G; where, Let be a character of arbitrary length randomly selected from a group of integers of order q-1;

[0067] S12: Randomly generate the system master and private keys S admin and the computing system master public key P admin =S admin G;

[0068] S13: Execute the first smart contract, and expose parameter M in the on-chain storage system. P =(E(F) p ),G,H,P admin ).like Figure 3 As shown, the specific steps for IoT terminals to register their device identity during the identity registration phase are as follows:

[0069] S21: Terminal T randomly selects a portion of the private key x T Calculate part of the public key U T Generate blockchain account address ID T Generate Chameleon Hash CH T And calculate the trapdoor key k T ;

[0070] Terminal edge node TE and terminal device TD are represented as T;

[0071] Furthermore, step S21 specifically includes the following steps:

[0072] S211: Terminal T randomly selects a portion of the private key x T ;

[0073] S212: Terminal T computes the public key U T =x T G;

[0074] S213: Terminal T generates blockchain account address ID T =H0(U T );

[0075] S214: Terminal T generates Chameleon hash CH T (m,r)=mG+rU T ;

[0076] S215: Terminal T calculates the trapdoor key k T =m+rx T .

[0077] S22: Terminal T will x T U T ID T and CH T Encrypt and execute a third-party smart contract to send an identity registration request to BAS;

[0078] Step S22 specifically includes the following steps:

[0079] S221: Terminal T uses public key P admin Encryption x T U T ID T and CH T The ciphertext C1 = Encr(P) is obtained. admin ,x T ||U T ||ID T ||CH T Encr() indicates encryption;

[0080] S221: Terminal T executes the third smart contract to send an identity registration request to BAS;

[0081] S23: BAS executes the second smart contract method to check the ID. T If the system is already registered, the registration request will be rejected; otherwise, BAS will proceed according to the publicly available system parameter M. p Terminal T part of public key U T and blockchain account address ID T Generate BAS partial public key W T and part of the private key d T ;

[0082] Furthermore, step S23 specifically includes the following steps:

[0083] S231: BAS executes the second smart contract to check the ID. T If the user is already registered, the registration request will be rejected.

[0084] S232: BAS uses the system master private key. admin Decrypting ciphertext C1 yields the original information x. T ||U T ||ID T ||CH T =Decr(s admin C1), Decr() is for decryption;

[0085] S233: BAS uses the system master public key P admin Terminal T part of public key U T and blockchain account address ID TGenerate d T W T =ExtractPartialKey(x T U T M P ExtractPartialKey() is a function that extracts a portion of the public key.

[0086] S24: BAS uses U T Encryption C2 = Encr(U T ,d T ||W T And execute the third smart contract to return an identity registration response;

[0087] S25: Terminal T uses x T Decrypting C2 yields d T W T And generate the complete private key S T and the complete public key P T ;

[0088] Furthermore, step S25 specifically includes the following steps:

[0089] S251: Terminal T uses x T Decrypting C2 yields d T ||W T =Decr(x T ,C2);

[0090] S252: Terminal T generates the complete private key S T =SetPriKey(x T ,d T SetPriKey() represents the function to generate a complete private key;

[0091] S253: Terminal T generates the complete public key P T =SetPubKey(W T M p SetPubKey() is the function to generate a complete public key.

[0092] S26: Terminal T executes the third smart contract and transfers the full public key P. T Send to BAS; RegFin completes the terminal identity registration process.

[0093] S27: BAS executes the second smart contract, transferring part of the public key U of device T. T Full public key P T Account address ID T Chameleon Hash CH T Registration information, such as registration time, expiration time, and identity verification, is stored on the blockchain.

[0094] like Figure 4 As shown, the specific steps of device identity access authentication in step S3, the identity authentication stage, are as follows:

[0095] S31: When the terminal device TD accesses the service domain of the terminal edge node TE1, a random number α is randomly selected. TD TD's pseudo-identity identifier PID TD And use chameleon hash to calculate r * TD and m * TD ;TD will PID TD m * TD r * TD and timestamps (TS) TD The information is assembled into identity authentication information and the fourth smart contract is executed to send an identity access authentication request to access the service domain of the terminal edge node TE1.

[0096] Furthermore, step S31 specifically includes the following steps:

[0097] S311: The terminal device TD randomly selects a random number. and TD pseudo-identity PID TD ∈ R {0,1} * {0,1} * A binary message of arbitrary length;

[0098] S312: Terminal Equipment TD Computing A TD =α TD U TD v TD =H2(PID) TD ||A TD ||TS TD ) Then calculate r * TD =α TD v TD and m * TD =k TD -r * TD x TD ;

[0099] S313: Terminal device TD selects the current timestamp TS TD ;

[0100] S314: Terminal device TD will use PID TD m *TD r * TD and timestamps (TS) TD The information is assembled into identity authentication information and the fourth smart contract is executed to send an identity access authentication request to access the service domain of the terminal edge node TE1.

[0101] S32: BAS executes the second smart contract, checking the identity of the terminal device TD and verifying the Chameleon hash CH. TD If the identity is valid and the Chameleon hash verification is successful, the terminal edge node TE1 will be notified through a contract event to request identity authentication through the terminal device TD.

[0102] Furthermore, step S32 specifically includes the following steps:

[0103] S321: BAS executes the second smart contract to check the identity and legitimacy of the terminal device TD;

[0104] S322: BAS calculates v TD =H2(PID) TD ||A TD ||TS TD And verify m TD G+v TD A TD =CH TD Are they equal?

[0105] S323: If the identity is valid and the Chameleon hash verification is successful, BAS notifies the terminal edge node TE1 that there is an identity authentication request from the terminal device TD.

[0106] S33: Terminal edge node TE1 checks timestamp TS TD Is it within its validity period? If TS TD If valid, a random number α is randomly selected. TE1 And TE1's pseudo-identity Using Chameleon Hash Calculation and TE1 will and timestamp The information is assembled into authentication response information and the fourth smart contract is executed to send the identity access authentication response;

[0107] S34: BAS executes the second smart contract, checking the identity of the terminal edge node TE1 and verifying the Chameleon hash. If the identity is valid and the Chameleon hash verification is successful, the terminal device TD is notified that there is an identity authentication response from the terminal edge node TE1.

[0108] S35: Terminal device TD acknowledges the response. Terminal device TD and terminal edge node TE1 exchange random numbers α. TD , Generate session key The identity access authentication process has ended.

[0109] like Figure 5 As shown, the specific steps for device identity switching authentication in step S4 are as follows:

[0110] S41: The mobile terminal device TD moves to the boundary between the service domains of terminal edge node TE1 and terminal edge node TE2. The terminal device TD detects the need for inter-domain handover authentication through signal threshold detection, executes the fourth smart contract to send an identity handover authentication request, and requests access to the service domain of terminal edge node TE2.

[0111] S42: BAS executes the second smart contract to check the identity of terminal device TD. If it is valid, it notifies the terminal edge node TE2 that there is an identity switching authentication request for terminal device TD.

[0112] S43: Terminal edge node TE2 randomly selects a random number. And the pseudo-identity of device TE2 And calculate using the chameleon hash algorithm and TE2 will and timestamp The information is assembled into a context exchange request message and the fourth smart contract is executed to send the context exchange request.

[0113] S44: BAS executes the second smart contract, checking the identity of the terminal edge node TE2 and verifying the Chameleon hash. If the identity is valid and the Chameleon hash verification is successful, notify terminal edge node TE1 that there is a context exchange request from terminal edge node TE2.

[0114] S45: Terminal edge node TE1 encrypts the identity access authentication context information of the terminal device TD and executes the fourth smart contract to send a context exchange response;

[0115] S46: Terminal edge node TE2 obtains and decrypts the identity access authentication context information of the terminal device TD. The mobile terminal device TD and terminal edge node TE2 then use a random number α... TD and Generate session key Complete the identity switching authentication process;

[0116] Furthermore, the specific steps for device identity deregistration in step S5 are as follows:

[0117] S51: BAS detects that the identity of terminal T in the identity information table has expired, or terminal T actively executes the third smart contract to send an identity cancellation request;

[0118] S52: BAS executes the second smart contract to mark the identity of terminal T as expired;

[0119] Furthermore, the four types of smart contracts are:

[0120] The first smart contract is used to disclose the system's public parameter M. P =(E(F) p ),G,H,P admin );

[0121] The second smart contract is a device identity management contract, used by BAS to maintain a list of terminal device identity information. This list includes information such as the validity period of the terminal device and terminal edge node's identity, identity legitimacy, terminal status, and terminal public key. When the terminal's identity information expires, BAS executes the second smart contract to set its identity information to an expired state.

[0122] The third smart contract is the terminal identity registration contract. When a new terminal device or terminal edge node is deployed to the Internet of Things, it needs to be registered, generating registration information and executing the terminal registration method of the third smart contract; when the terminal malfunctions and cannot be used normally, the terminal deregistration method of the third smart contract is executed to request BAS to set its identity information to an abnormal state;

[0123] The fourth smart contract is the terminal identity authentication contract, which is used for terminal identity access authentication, authentication switching, and session key negotiation.

[0124] The above-described embodiments further illustrate the purpose, technical solution, and advantages of the present invention. It should be understood that the above-described embodiments are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made to the present invention within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A blockchain-based method for anonymous identity authentication of certificateless IoT devices, characterized in that, include: S1, based on blockchain authentication server Terminal edge nodes and terminal equipment Construct an identity authentication system based on a certificateless blockchain, and deploy four smart contracts on the system, namely the first smart contract, the second smart contract, the third smart contract, and the fourth smart contract; Initialize the system; S2, Terminal Edge Node and terminal equipment Execute the third-party smart contract to complete identity registration; Terminal edge node or terminal equipment Identity registration includes: S21, Terminal Edge Node or terminal equipment Randomly select a portion of the private key based on the elliptic curve. Calculate part of the public key and trapdoor key Generate blockchain account address And Chameleon Hash ; S22, Terminal Edge Node or terminal equipment Use public key encryption , , and Received the ciphertext And according to the ciphertext Execute the third smart contract to Send an identity registration request; S23, Use the system master private key Decrypting the ciphertext ,get , , and And perform a second smart contract check. If you are already registered, please indicate whether you have already registered. If so, please reject this registration request; otherwise, please indicate whether you have already registered. According to publicly available system parameters Partial private key Partial public key and blockchain account address Partial public key and part of the private key ; S24, use Encryption part of the public key and part of the private key Received the ciphertext And according to the ciphertext The third-party smart contract was executed and returned an identity registration response; S25, Terminal Edge Node or terminal equipment use Decryption get Partial public key and part of the private key and according to and Generate complete private key and the complete public key ; S26, Terminal Edge Node or terminal equipment Executing the third-party smart contract will give the full public key. Send to ; S27 Obtain terminal edge nodes or terminal equipment The registration time, expiration time, and identity verification are used to execute the second smart contract and transfer a portion of the public key. Complete public key Account address Chameleon Hash Registration time, expiration time, and identity legitimacy are stored on the blockchain; S3, Registered terminal equipment Connect to the registered terminal edge node When accessing the service domain, execute the fourth smart contract to complete two-way identity authentication; terminal equipment and terminal edge nodes Two-way authentication includes: S31, Terminal Equipment Access to terminal edge node When serving a domain, a random number is selected based on an elliptic curve. and fake identity Get timestamp Use Chameleon Hash to calculate the encrypted random number Terminal equipment Parameters of the chameleon hash and Terminal equipment Will , , , and timestamp Assemble the identity access authentication information and execute the fourth smart contract based on the identity access authentication information to send the identity access authentication request; S32, The second smart contract is executed to check the terminal device based on the identity access authentication request. The system verifies the identity and chameleon hash. If the identity is valid and the chameleon hash verification is successful, the terminal edge node is notified. via terminal device The authentication request will be executed; otherwise, authentication will fail. S33, When the terminal edge node via terminal device When making an identity authentication request, the terminal edge node Check timestamp Is it effective? If valid, a random number is selected based on the elliptic curve. and fake identity Use Chameleon Hash to calculate the encrypted random number Terminal edge nodes Parameters of the chameleon hash and Get timestamp Terminal edge node Will , , , and timestamp The information is assembled into an authentication response, and the fourth smart contract is executed based on the authentication response to send the identity access authentication response. S34, The second smart contract is executed to check the terminal edge node based on the identity access authentication response. The system verifies the identity and chameleon hash. If the identity is valid and the chameleon hash verification is successful, the terminal device is notified. via terminal edge node The authentication response will be received; otherwise, authentication will fail. S35, When the terminal device via terminal edge node When the terminal device responds to the identity authentication, and terminal edge nodes Swap random numbers and By exchanging random numbers and Generate session key Complete identity access authentication; S4, Terminal devices after two-way authentication From the terminal edge node Service domain switch to terminal edge node When serving the terminal device, the fourth smart contract is executed to complete the service domain. Identity switching authentication; Identity switching authentication includes: S41, Terminal Equipment From the terminal edge node Service domain switch to terminal edge node When accessing the service domain, execute the fourth smart contract to send an identity switching authentication request; S42, The second smart contract is executed to check the terminal device based on the identity switching authentication request. Verify the legitimacy of the identity; if legitimate, notify the terminal edge node. via terminal device The identity switching authentication request will be executed; otherwise, the identity switching authentication will fail. S43, When the terminal edge node via terminal device When an identity switching authentication request is made, the terminal edge node Random numbers are selected based on the elliptic curve. ,equipment fake identity markers and timestamp The encrypted random number is calculated using the Chameleon hash algorithm. Terminal edge nodes Parameters of the chameleon hash and ; Will , , , and timestamp Assemble the context exchange request information and execute the fourth smart contract based on the context exchange request information. Send a context exchange request; S44 The second smart contract is executed to check the terminal edge node based on the context exchange request. The system verifies the identity's legitimacy and chameleon hash. If the identity is legitimate and the chameleon hash verification is successful, the terminal edge node is notified. via terminal edge node A context exchange request must be submitted; otherwise, identity switching authentication will fail. S45, When the terminal edge node via terminal edge node When the terminal edge node requests a context exchange, Encrypted terminal devices The identity access authentication information is used to obtain the encrypted data. And according to the ciphertext The fourth smart contract is executed to send a context exchange response; S46, Terminal Edge Node Decrypt the ciphertext based on the context exchange response. Obtain terminal equipment Identity access authentication information, terminal device and terminal edge nodes According to terminal equipment Identity access authentication information exchange random number , And based on random numbers , Generate session key Complete the identity switching authentication; S5, terminal edge node or terminal equipment After the identity expires, Execute the second smart contract to cancel the terminal's identity information.

2. The method for anonymous identity authentication of certificateless IoT devices based on blockchain according to claim 1, characterized in that, The functions of smart contracts include: The first smart contract is used to disclose public system parameters; the second smart contract is used for device identity management; the third smart contract is used for terminal identity registration; and the fourth smart contract is used for terminal identity authentication.

3. The method for anonymous identity authentication of certificateless IoT devices based on blockchain according to claim 1, characterized in that, System initialization includes: S11. Select a secure hash function , , ), Elliptic curve and generator ;in For a finite field; S12. Randomly generate the system master private key. Computing system master public key ; S13. Execute the first smart contract and expose the system's public parameters. .

4. The method for anonymous identity authentication of certificateless IoT devices based on blockchain according to claim 1, characterized in that, Terminal edge node or terminal equipment Calculate the trapdoor key Generate chameleon hash include: Terminal edge node or terminal equipment Get the timestamp t, and select a random number. ,calculate Generate chameleon hash Calculate the trapdoor key ; in, For generators, For the system's secure hash function, , These are the two parameters of the Chameleon Hash.

5. The method for anonymous identity authentication of certificateless IoT devices based on blockchain according to claim 1, characterized in that, calculate , and include: calculate ,according to calculate ,according to calculate ,according to calculate ; in, For terminal devices Part of the public key, For the system's secure hash function, For terminal devices The trapdoor key, For terminal devices Part of the private key, For terminal devices The selected random number.

6. The method for anonymous identity authentication of certificateless IoT devices based on blockchain according to claim 1, characterized in that, Verifying the chameleon hash includes: calculate And verify Check if the condition is met; if met, the verification passes; otherwise, the verification fails. in, For the generators of the system, For the system's secure hash function, For terminal devices The trapdoor key, For terminal devices Part of the private key.

7. The method for anonymous identity authentication of certificateless IoT devices based on blockchain according to claim 1, characterized in that, Identity cancellation includes: when Terminal edge node detected and terminal equipment Identity expired or terminal edge node and terminal equipment Actively execute a third-party smart contract to send an identity cancellation request. Executing the second smart contract will connect the terminal edge node. or terminal equipment The identity is marked as expired.

Citation Information

Patent Citations

  • Distributed credible identity authentication method and system in edge computing environment

    CN114866248A

  • Internet of vehicles cross-domain switching authentication method and system based on block chain

    CN116566581A