Security authentication method, device, system, electronic device and storage device
By generating target attribute certificates that adapt to different security authentication mechanisms through the certificate issuing end, the problem of trusted communication between nodes with different security authentication mechanisms is solved, and secure authentication and communication between nodes are realized.
Patent Information
- Application Number
- CN202311865300.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2043-12-29
AI Technical Summary
Existing technologies cannot meet the requirements for trusted communication between nodes with different security authentication mechanisms.
The target attribute certificate is generated by the certificate issuing end using different security authentication mechanisms. The certificate issuing end generates a certificate according to the security authentication mechanism of the receiving node and sends it to the peer node to verify whether it has the target attribute.
It implements security authentication between nodes that support different security authentication mechanisms, ensuring trusted communication between nodes.
Smart Images

Figure CN117896126B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the field of security authentication, and in particular to a security authentication method, device, system, electronic device and storage device. BACKGROUND
[0002] In some scenarios, when a node needs to perform trusted communication with another node, the node receiving the communication request needs to perform security authentication on the node sending the communication request. If the two nodes perform security authentication through the way of interacting messages, both of the two nodes need to use the same security authentication mechanism.
[0003] The inventor finds that the prior art can only meet the requirement of security authentication between nodes supporting the same security authentication mechanism, but in actual application, there is often a requirement of trusted communication between nodes supporting different security authentication mechanisms, and the prior art cannot meet such requirement. Therefore, how to perform security authentication between nodes supporting different security authentication mechanisms is a technical problem to be solved. SUMMARY
[0004] Embodiments of the present application provide a security authentication method, device, system, electronic device and storage device, to perform security authentication between nodes supporting different security authentication mechanisms.
[0005] An embodiment of the present application provides a security authentication method, comprising: a certificate issuing end obtaining a second target attribute proof request message sent by a first node, the second target attribute proof request message being used to request to prove that the first node has a target attribute, the second target attribute proof request message including identification information of a second node, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, the second node being a node that the first node needs to perform communication with; the second target attribute proof request message being sent after the first node obtains a first target attribute proof request message sent by the second node, the first target attribute proof request message being used to request to prove that the first node has a target attribute; the certificate issuing end generating a target attribute certificate for the target attribute using the second security authentication mechanism, as a second security authentication mechanism target attribute certificate; and the certificate issuing end sending the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, the second security authentication mechanism target attribute certificate being used for the second node to verify whether the first node has the target attribute.
[0006] In the second target attribute proof request message, the following information is further included: information of the target attribute; identification information of the first node; and a first hash value obtained by performing a hash operation on any one of the information of the target attribute, the identification information of the first node and the identification information of the second node.
[0007] The method further comprises: the certificate issuing end obtaining a first encrypted data group from the second target attribute certification request message, the first encrypted data group being a data group obtained by the first node encrypting a first data group using a public key of the certificate issuing end, the first data group comprising information of the target attribute, identification information of the first node, identification information of the second node, and the first hash value; and the certificate issuing end decrypting the first encrypted data group using a private key of the certificate issuing end to obtain the first data group.
[0008] The method further comprises: the certificate issuing end obtaining a description document of the first node from a block chain node according to the identification information of the first node; the certificate issuing end obtaining a public key of the first node from the description document of the first node; the certificate issuing end encrypting a first random number using the public key of the first node to obtain an encrypted first random number; the certificate issuing end sending the encrypted first random number to the first node; the certificate issuing end obtaining a first string sent by the first node, the first string being a string obtained by the first node performing a hash operation on the first random number, wherein the first node decrypts the encrypted first random number using a private key of the first node to obtain the first random number; the certificate issuing end performing a hash operation on the first random number to obtain a string as a first reference string; and the certificate issuing end generating a target attribute certificate for the target attribute using a second security authentication mechanism, comprising: if the first string is the same as the first reference string, generating a target attribute certificate for the target attribute using a second security authentication mechanism.
[0009] The method further comprises: the certificate issuing end obtaining information of a first encryption and decryption algorithm used by the first node for encrypting and decrypting a random number from the description document of the first node; the certificate issuing end encrypting a first random number using the public key of the first node to obtain an encrypted first random number, comprising: the certificate issuing end encrypting the first random number using the public key of the first node and the first encryption and decryption algorithm to obtain the encrypted first random number; and the first node decrypting the encrypted first random number using the private key of the first node to obtain the first random number, comprising: the first node decrypting the encrypted first random number using the private key of the first node and the first encryption and decryption algorithm to obtain the first random number.
[0010] The certificate issuing end uses the public key of the first node to encrypt the first random number to obtain an encrypted first random number, including: the certificate issuing end uses the public key of the first node and a third encryption and decryption algorithm used by the certificate issuing end for encrypting and decrypting random numbers to encrypt the first random number to obtain the encrypted first random number; wherein the first node obtains information of the third encryption and decryption algorithm used by the certificate issuing end for encrypting and decrypting random numbers from a description document of the certificate issuing end, and the first node obtains the description document of the certificate issuing end from a block chain node according to identification information of the certificate issuing end; the first node uses the private key of the first node to decrypt the encrypted first random number to obtain the first random number, including: the first node uses the private key of the first node and the third encryption and decryption algorithm to decrypt the encrypted first random number to obtain the first random number.
[0011] The method further includes: the certificate issuing end obtaining a description document of the second node from a block chain node according to identification information of the second node; and the certificate issuing end obtaining a security authentication mechanism identifier corresponding to the second node from the description document of the second node, the security authentication mechanism identifier corresponding to the second node indicating that the second node supports a second security authentication mechanism.
[0012] The second target attribute proof request message further includes a security authentication mechanism identifier indicating that the second node supports a second security authentication mechanism; the method further includes: the certificate issuing end obtaining the security authentication mechanism identifier indicating that the second node supports a second security authentication mechanism from the second target attribute proof request message; and the certificate issuing end determining that the second node supports a second security authentication mechanism according to the security authentication mechanism identifier indicating that the second node supports a second security authentication mechanism; wherein the first node obtains the security authentication mechanism identifier indicating that the second node supports a second security authentication mechanism from a description document of the second node, and the first node obtains the description document of the second node from a block chain node according to identification information of the second node.
[0013] The method further comprises: the certificate issuing end generating a target attribute certificate for the target attribute using another security authentication mechanism supported by the certificate issuing end in addition to the second security authentication mechanism, as an other security authentication mechanism target attribute certificate; and the certificate issuing end sending the other security authentication mechanism target attribute certificate to the second node according to the identification information of the second node; wherein the second node selects the second security authentication mechanism target attribute certificate corresponding to the second security authentication mechanism from the second security authentication mechanism target attribute certificate and the other security authentication mechanism target attribute certificate, and uses the second security authentication mechanism target attribute certificate to verify whether the first node has the target attribute.
[0014] The method further comprises: the certificate issuing end obtaining a description document of the second node from a block chain node according to the identification information of the second node; the certificate issuing end obtaining a public key of the second node from the description document of the second node; the certificate issuing end encrypting a second data group using the public key of the second node to obtain a second encrypted data group, the second data group comprising the second security authentication mechanism target attribute certificate, the identification information of the certificate issuing end and a second hash value, the second hash value being a hash value obtained by performing a hash operation on the second security authentication mechanism target attribute certificate or the identification information of the certificate issuing end; and the certificate issuing end sending the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, comprising: the certificate issuing end sending the second encrypted data group to the second node according to the identification information of the second node.
[0015] The first security authentication mechanism is one of an X.509 security authentication mechanism, an SM2 security authentication mechanism and an SM9 security authentication mechanism; and the second security authentication mechanism is one of an X.509 security authentication mechanism, an SM2 security authentication mechanism and an SM9 security authentication mechanism.
[0016] The first node is one of a vehicle-mounted unit, a roadside unit and a service providing unit in a vehicle-road cooperation scenario; and the second node is one of a vehicle-mounted unit, a roadside unit and a service providing unit in a vehicle-road cooperation scenario.
[0017] The embodiment of the present application provides a security authentication method, comprising: a second node obtaining a second security authentication mechanism target attribute certificate sent by a certificate issuing end, wherein the second security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuing end for a target attribute by using a second security authentication mechanism, the target attribute is a target attribute possessed by a first node, the first node supports a first security authentication mechanism, the second node supports the second security authentication mechanism, and the second node is a node required to communicate with the first node; the second node obtaining signature data of the target attribute from the second security authentication mechanism target attribute certificate by the certificate issuing end; and the second node verifying the signature data of the target attribute by using the second security authentication mechanism, and determining that the first node possesses the target attribute if the verification is passed.
[0018] The second node obtains the second security authentication mechanism target attribute certificate sent by the certificate issuing end, comprising: the second node obtaining a second encrypted data group sent by the certificate issuing end, wherein the second encrypted data group is obtained by the certificate issuing end by encrypting a second data group by using a public key of the second node, the second data group comprises the second security authentication mechanism target attribute certificate, identification information of the certificate issuing end and a second hash value, and the second hash value is a hash value obtained by performing a hash operation on the second security authentication mechanism target attribute certificate or the identification information of the certificate issuing end; and the second node decrypting the second encrypted data group by using a private key of the second node to obtain the second data group.
[0019] The method further comprises: the second node obtaining a description document of the certificate issuing end from a block chain node according to the identification information of the certificate issuing end; the second node obtaining a public key of the certificate issuing end from the description document of the certificate issuing end; the second node performing encryption processing on a second random number by using the public key of the certificate issuing end to obtain an encrypted second random number; the second node sending the encrypted second random number to the certificate issuing end; the second node obtaining a second string sent by the certificate issuing end, wherein the second string is a string obtained by performing a hash operation on the second random number by the certificate issuing end, the certificate issuing end decrypts the encrypted second random number by using a private key of the certificate issuing end to obtain the second random number; the second node performs a hash operation on the second random number to obtain a string as a second reference string; and the second node obtains signature data of the target attribute from the second security authentication mechanism target attribute certificate by the certificate issuing end, comprising: if the second string is the same as the second reference string, the second node obtains the signature data of the target attribute from the second security authentication mechanism target attribute certificate by the certificate issuing end.
[0020] The method further comprises: the second node obtaining, from the description document of the certificate issuer, information of a third encryption and decryption algorithm used by the certificate issuer for encryption and decryption of the random number; and the second node encrypting the second random number using the public key of the certificate issuer to obtain an encrypted second random number, including: the second node encrypting the second random number using the public key of the certificate issuer and the third encryption and decryption algorithm to obtain the encrypted second random number; and the certificate issuer decrypting the encrypted second random number using the private key of the certificate issuer to obtain the second random number, including: the certificate issuer decrypting the encrypted second random number using the private key of the certificate issuer and the third encryption and decryption algorithm to obtain the second random number.
[0021] The second node encrypts the second random number using the public key of the certificate issuer to obtain an encrypted second random number, including: the second node encrypting the second random number using the public key of the certificate issuer and a second encryption and decryption algorithm used by the second node for encryption and decryption of the random number to obtain the encrypted second random number; the certificate issuer obtains, from the description document of the second node, information of the second encryption and decryption algorithm used by the second node for encryption and decryption of the random number, and obtains the description document of the second node from the blockchain nodes according to the identification information of the second node; and the certificate issuer decrypts the encrypted second random number using the private key of the certificate issuer to obtain the second random number, including: the certificate issuer decrypting the encrypted second random number using the private key of the certificate issuer and the second encryption and decryption algorithm to obtain the second random number.
[0022] The method further comprises: the second node obtaining, from the second security authentication mechanism target attribute certificate, a verification parameter for verifying signature data of the target attribute; and the second node verifying the signature data of the target attribute using the second security authentication mechanism, including: the second node verifying the signature data of the target attribute using the second security authentication mechanism and the verification parameter.
[0023] The method further comprises: the second node obtaining a target attribute certificate of another security authentication mechanism sent by a certificate issuing end, the target attribute certificate of another security authentication mechanism being a target attribute certificate generated by the certificate issuing end for the target attribute by using another security authentication mechanism supported by the certificate issuing end and different from the second security authentication mechanism; and the second node selecting the second security authentication mechanism target attribute certificate corresponding to the second security authentication mechanism from the second security authentication mechanism target attribute certificate and the target attribute certificate of another security authentication mechanism, and using the second security authentication mechanism target attribute certificate to verify whether the first node has the target attribute.
[0024] The method further comprises: the second node obtaining a service providing request message sent by the first node for requesting the second node to provide a service for the first node; the second node sending a first target attribute proof request message for requesting to prove that the first node has a target attribute to the first node; the second node obtaining a second security authentication mechanism target attribute certificate sent by a certificate issuing end, comprising: after the second node sends the first target attribute proof request message to the first node, obtaining the second security authentication mechanism target attribute certificate sent by the certificate issuing end; and the method further comprises: after the second node verifies the signature data of the target attribute by using the second security authentication mechanism, the second node sends an instruction for indicating to allow the first node to perform trusted communication with the second node to the first node, or the second node sends service content of the service to the first node.
[0025] The service providing request message includes a third encrypted data group, the third encrypted data group is a data group obtained by encrypting a third data group by the first node using the public key of the second node, the third data group includes identification information of the first node, service information for indicating a service requested to be provided by the first node, and a third hash value obtained by performing a hash operation on the identification information of the first node or the service information; the method further includes: the second node obtains the third encrypted data group from the service providing request message; the second node decrypts the third encrypted data group using the private key of the second node to obtain the third data group; the second node obtains the description document of the first node from the block chain node according to the identification information of the first node included in the third data group; the second node obtains the public key of the first node from the description document of the first node; the second node encrypts a third random number using the public key of the first node to obtain an encrypted third random number; the second node sends the encrypted third random number to the first node; the second node obtains a third string sent by the first node, the third string is a string obtained by performing a hash operation on the third random number by the first node, wherein the first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number; the second node performs a hash operation on the third random number to obtain a string as a third reference string; the second node sends a first target attribute proof request message for requesting to prove that the first node has a target attribute to the first node, including: if the third string is the same as the third reference string, the second node sends the first target attribute proof request message for requesting to prove that the first node has a target attribute to the first node.
[0026] The method further includes: the second node obtains information of a first encryption and decryption algorithm used by the first node for encrypting and decrypting a random number from the description document of the first node; the second node encrypts a third random number using the public key of the first node to obtain an encrypted third random number, including: the second node encrypts the third random number using the public key of the first node and the first encryption and decryption algorithm to obtain the encrypted third random number; the first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number, including: the first node decrypts the encrypted third random number using the private key of the first node and the first encryption and decryption algorithm to obtain the third random number.
[0027] The second node encrypts the third random number using the public key of the first node to obtain an encrypted third random number, including: the second node encrypts the third random number using the public key of the first node and a second encryption and decryption algorithm used by the second node for random number encryption and decryption, to obtain the encrypted third random number; wherein the first node obtains information of the second encryption and decryption algorithm used by the second node for random number encryption and decryption from a description document of the second node, and the first node obtains the description document of the second node from the block chain nodes according to the identification information of the second node; the first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number, including: the first node decrypts the encrypted third random number using the private key of the first node and the second encryption and decryption algorithm to obtain the third random number.
[0028] The method further includes: the second node obtains information of the target attribute; and the second node sends a first target attribute proof request message for requesting the first node to prove that the first node has the target attribute to the first node, including: the second node encrypts a fourth data group using the public key of the first node to obtain a fourth encrypted data group, the fourth data group including the information of the target attribute, the identification information of the second node, and a fourth hash value obtained by performing a hash operation on the information of the target attribute or the identification information of the second node; and the second node sends the first target attribute proof request message including the fourth encrypted data group to the first node.
[0029] The method further comprises: the second node obtaining the encrypted fourth random number sent by the first node; the second node decrypting the encrypted fourth random number using the private key of the second node to obtain the fourth random number; the second node performing a hash operation on the fourth random number to obtain a fourth string; and the second node sending the fourth string to the first node; wherein the first node performs a hash operation on the fourth random number to obtain a fourth reference string, and if the fourth string is the same as the fourth reference string, the first node obtains identification information of the certificate issuing end capable of providing a target attribute certificate from the blockchain nodes, obtains a description document of the certificate issuing end from the blockchain nodes according to the identification information of the certificate issuing end, obtains the public key of the certificate issuing end from the description document of the certificate issuing end, encrypts a fifth data group using the public key of the certificate issuing end to obtain a fifth encrypted data group, and sends a second target attribute proof request message for requesting to prove that the first node has the target attribute to the certificate issuing end, wherein the second target attribute proof request message comprises the fifth encrypted data group, and the fifth data group comprises information of the target attribute, identification information of the first node, identification information of the second node, and a fifth hash value obtained by performing a hash operation on the information of the target attribute, the identification information of the first node and the identification information of the second node.
[0030] The encrypted fourth random number is obtained in the following manner: the first node obtains the fourth encrypted data group from the first target attribute proof request message; the first node decrypts the fourth encrypted data group using the private key of the first node to obtain the fourth data group; the first node obtains a description document of the second node from the blockchain nodes according to the identification information of the second node included in the fourth data group; the first node obtains the public key of the second node from the description document of the second node; and the first node encrypts the fourth random number using the public key of the second node to obtain the encrypted fourth random number.
[0031] The second node obtains the information of the target attribute in the following manner: the second node obtains service characteristic data of a service requested to be provided by the first node according to the service information; and the second node obtains the information of the target attribute required to be possessed by a node enjoying the service according to the service characteristic data.
[0032] The first security authentication mechanism is one of an X.509 security authentication mechanism, an SM2 security authentication mechanism and an SM9 security authentication mechanism; and the second security authentication mechanism is one of an X.509 security authentication mechanism, an SM2 security authentication mechanism and an SM9 security authentication mechanism.
[0033] The first node is one of a vehicle unit, a roadside unit and a service providing unit in a vehicle-road cooperation scenario, and the second node is one of a vehicle unit, a roadside unit and a service providing unit in the vehicle-road cooperation scenario.
[0034] The application provides a security authentication method, including: a first node sends a service providing request message to a second node, the service providing request message being used for requesting the second node to provide a service for the first node, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, and the second node being a node that needs to communicate with the first node; the first node obtains a first target attribute proof request message sent by the second node, the first target attribute proof request message being used for proving that the first node has a target attribute; the first node sends a second target attribute proof request message to a certificate issuing end, the second target attribute proof message being used for requesting to prove that the first node has the target attribute; and the first node obtains an instruction sent by the second node, the instruction being used for indicating that the first node is allowed to perform trusted communication with the second node or service content of the service.
[0035] The method further includes: the first node sends a second node searching request message to a blockchain node, the second node searching request message being used for searching for a second node that can provide the service for the first node; the first node obtains identification information of the second node sent by the blockchain node; the first node obtains a description document of the second node from the blockchain node according to the identification information of the second node; the first node obtains a public key of the second node from the description document of the second node; the first node obtains third encrypted data by encrypting a third data group using the public key of the second node, the third data group including identification information of the first node, service information used for indicating a service requested to be provided by the first node and a third hash value obtained by performing a hash operation on the identification information of the first node or the service information; and the first node sends a service providing request message to the second node, the service providing request message being used for requesting the second node to provide the service for the first node, and the first node sends the service providing request message including the third encrypted data to the second node.
[0036] The second node is a second node closest to the first node among all second nodes.
[0037] The method further includes: the first node obtaining the encrypted third random number sent by the second node, the encrypted third random number being obtained by the second node encrypting a third random number using the public key of the first node; the first node decrypting the encrypted third random number using the private key of the first node to obtain the third random number; the first node performing a hash operation on the third random number to obtain a third string; the first node sending the third string to the second node; and the first node obtaining the first target attribute proof request message sent by the second node for requesting to prove that the first node has a target attribute.
[0038] The first node decrypting the encrypted third random number using the private key of the first node to obtain the third random number includes: the first node decrypting the encrypted third random number using the private key of the first node and a first encryption and decryption algorithm to obtain the third random number, the first encryption and decryption algorithm being an encryption and decryption algorithm used by the first node for encrypting and decrypting random numbers.
[0039] Alternatively, the method further includes: the first node obtaining a description document of the second node from a block chain node according to the identification information of the second node; the first node obtaining information of a second encryption and decryption algorithm used by the second node for encrypting and decrypting random numbers from the description document of the second node; and the first node decrypting the encrypted third random number using the private key of the first node to obtain the third random number includes: the first node decrypting the encrypted third random number using the private key of the first node and the second encryption and decryption algorithm to obtain the third random number.
[0040] The first target attribute proof request message includes fourth encrypted data groups, the fourth encrypted data groups are obtained by encrypting a fourth data group using a public key of the first node, the fourth data group includes information of the target attribute, identification information of the second node, and a fourth hash value obtained by performing a hash operation on the information of the target attribute or the identification information of the second node; the method further includes: the first node obtains the fourth encrypted data groups from the first target attribute proof request message; the first node decrypts the fourth encrypted data groups using a private key of the first node to obtain the fourth data group; the first node obtains a description document of the second node from the second node according to the identification information of the second node included in the fourth data group; the first node obtains a public key of the second node from the description document of the second node; the first node encrypts a fourth random number using the public key of the second node to obtain an encrypted fourth random number; the first node sends the encrypted fourth random number to the second node; the first node obtains a fourth string sent by the second node, the fourth string is a string obtained by performing a hash operation on the fourth random number by the second node, wherein the second node decrypts the encrypted fourth random number using a private key of the second node to obtain the fourth random number; the first node performs a hash operation on the fourth random number to obtain a fourth reference string; and the first node sends a second target attribute proof request message for requesting to prove that the first node has the target attribute to a certificate issuing end, including: if the fourth random number is the same as the fourth reference string, the first node sends the second target attribute proof request message for requesting to prove that the first node has the target attribute to the certificate issuing end.
[0041] If the fourth random number is the same as the fourth reference string, the first node sends a second target attribute proof request message for requesting a proof that the first node has the target attribute to a certificate issuer, including: if the fourth string is the same as the fourth reference string, the first node obtains identification information of the certificate issuer capable of providing a target attribute certificate from a block chain node; the first node obtains a description document of the certificate issuer from the block chain node according to the identification information of the certificate issuer; the first node obtains a public key of the certificate issuer from the description document of the certificate issuer; the first node encrypts a fifth data group using the public key of the certificate issuer to obtain a fifth encrypted data group, the fifth data group including information of the target attribute, identification information of the first node, identification information of the second node, and a fifth hash value obtained by performing a hash operation on the information of the target attribute, the identification information of the first node and the identification information of the second node; and the first node sends the second target attribute proof request message including the fifth encrypted data group to the certificate issuer.
[0042] The method further includes: the first node obtaining an encrypted first random number sent by the certificate issuer, the encrypted first random number being obtained by the certificate issuer encrypting the first random number using a public key of the first node; the first node decrypting the encrypted first random number using a private key of the first node to obtain the first random number; the first node performing a hash operation on the first random number to obtain a first string; the first node sending the first string to the certificate issuer; and the first node obtaining an instruction sent by the second node for indicating that the first node is allowed to perform trusted communication with the second node or service content of the service, including: after the first node sends the first string to the certificate issuer, the first node obtains the instruction sent by the second node for indicating that the first node is allowed to perform trusted communication with the second node or the service content of the service.
[0043] The first security authentication mechanism is one of an X.509 security authentication mechanism, an SM2 security authentication mechanism and an SM9 security authentication mechanism; and the second security authentication mechanism is one of the X.509 security authentication mechanism, the SM2 security authentication mechanism and the SM9 security authentication mechanism.
[0044] The first node is one of a vehicle-mounted unit, a roadside unit and a service providing unit in a vehicle-road cooperation scenario; and the second node is one of the vehicle-mounted unit, the roadside unit and the service providing unit in the vehicle-road cooperation scenario.
[0045] The embodiment of the present application provides a security authentication device, which is applied to an authentication issuing end, and the device comprises: a request message obtaining unit, which is used for obtaining a second target attribute proof request message sent by a first node and used for requesting to prove that the first node has a target attribute, wherein the second target attribute proof request message comprises identification information of a second node, the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node required to be communicated by the first node; the second target attribute proof request message is sent after the first node obtains a first target attribute proof request message sent by the second node and used for requesting to prove that the first node has a target attribute; a target attribute certificate generating unit, which is used for generating a target attribute certificate for the target attribute by using the second security authentication mechanism, so as to serve as a second security authentication mechanism target attribute certificate; and a sending unit, which is used for sending the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, and the second security authentication mechanism target attribute certificate is used for verifying whether the first node has the target attribute by the second node.
[0046] The embodiment of the present application provides a security authentication device, which is applied to a second node, and the device comprises: a target attribute certificate obtaining unit, which is used for obtaining a second security authentication mechanism target attribute certificate sent by a certificate issuing end, wherein the second security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuing end for a target attribute by using a second security authentication mechanism, the target attribute is a target attribute of a first node, the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node required to be communicated by the first node; a signature data obtaining unit, which is used for obtaining signature data of the certificate issuing end for the target attribute from the second security authentication mechanism target attribute certificate; and a verifying unit, which is used for verifying the signature data of the target attribute by using the second security authentication mechanism, and if the verification is passed, it is determined that the first node has the target attribute.
[0047] The embodiment of the present application provides a security authentication device, which is applied to a first node, and the device comprises: a service request unit, configured to send a service providing request message for requesting the second node to provide a service for the first node to a second node, the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node which needs to communicate with the first node; a request message obtaining unit, configured to obtain a first target attribute proof request message sent by the second node and used for requesting to prove that the first node has a target attribute; a request message sending unit, configured to send a second target attribute proof request message for requesting to prove that the first node has the target attribute to a certificate issuing end; and a service obtaining unit, configured to obtain an instruction or service content of the service sent by the second node and used for indicating that the first node is allowed to perform trusted communication with the second node.
[0048] The embodiment of the present application provides a security authentication system, which comprises a first node, an authentication service end and a second node; the first node is configured to send a service providing request message for requesting the second node to provide a service for the first node to the second node, obtain a first target attribute proof request message sent by the second node and used for requesting to prove that the first node has a target attribute, send a second target attribute proof request message for requesting to prove that the first node has the target attribute to a certificate issuing end, obtain an instruction or service content of the service sent by the second node and used for indicating that the first node is allowed to perform trusted communication with the second node, and the first node supports a first security authentication mechanism; the authentication service end is configured to obtain a second target attribute proof request message sent by the first node and used for requesting to prove that the first node has a target attribute, generate a target attribute certificate for the target attribute by using a second security authentication mechanism, take the second security authentication mechanism target attribute certificate as a second security authentication mechanism target attribute certificate, and send the second security authentication mechanism target attribute certificate to the second node; and the second node is configured to obtain signature data of the certificate issuing end for the target attribute from the second security authentication mechanism target attribute certificate, verify the signature data of the target attribute by using the second security authentication mechanism, and if the verification is passed, send the instruction or the service content of the service to the first node, the instruction being used for indicating that the first node is allowed to perform trusted communication with the second node.
[0049] The embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program, and the computer program is executed by the processor to perform the above method.
[0050] The embodiment of the present application provides a storage device, which stores a computer program. The computer program is executed to perform the above method.
[0051] In the embodiment of the present application, after obtaining the target attribute proof request sent by the first node supporting the first security authentication mechanism, the certificate issuing end generates the target attribute certificate using the second security authentication mechanism supported by the second node, and sends the target attribute certificate to the second node to prove that the first node has the target attribute to the second node. In other words, when facing the demand of trusted communication between nodes supporting different security authentication mechanisms, the certificate issuing end can generate a certificate according to the security authentication mechanism supported by the node receiving the proof, and the security authentication between the nodes supporting different security authentication mechanisms is realized.
[0052] In the embodiment of the present application, the node needing to obtain the certificate can obtain the certificate generated by using the security authentication mechanism that the node can support from the certificate issuing end. The certificate can prove that the authenticated node supporting other security authentication mechanisms has a certain attribute to the node needing to obtain the certificate. In other words, even if the node needing to obtain the certificate and the authenticated node use different security authentication mechanisms, the node needing to obtain the certificate can also obtain the certificate used to prove that the authenticated node has a certain attribute. Therefore, the embodiment of the present application realizes the security authentication between the nodes supporting different security authentication mechanisms.
[0053] In the embodiment of the present application, when the authenticated node faces the requirement of the authentication node that the authenticated node provides the certificate used to prove that the authenticated node has a certain attribute, the authenticated node can request the certificate issuing end to provide the certificate to the authentication node. In this case, even if the authenticated node and the authentication node support different security authentication mechanisms, the trusted communication between the authenticated node and the authentication node can be realized because the certificate issuing end provides the certificate to the authentication node. Therefore, the embodiment of the present application realizes the security authentication between the nodes supporting different security authentication mechanisms. BRIEF DESCRIPTION OF DRAWINGS
[0054] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained according to these drawings without creative labor.
[0055] Figure 1 is a logical architecture schematic diagram provided by the embodiment of the present application;
[0056] Figure 2 is a security authentication total flowchart provided by the embodiment of the present application;
[0057] Figure 3is a data structure schematic diagram of a description document provided by an embodiment of the present application;
[0058] Figure 4 is a data structure schematic diagram of a first attribute certificate provided by an embodiment of the present application;
[0059] Figure 5 is a data structure schematic diagram of a second attribute certificate provided by an embodiment of the present application;
[0060] Figure 6 is a data structure schematic diagram of a third attribute certificate provided by an embodiment of the present application;
[0061] Figure 7 is a flowchart of a secure authentication method provided by an embodiment of the present application from the perspective of an authentication service end;
[0062] Figure 8 is a flowchart of a secure authentication method provided by an embodiment of the present application from the perspective of an authentication node;
[0063] Figure 9 is a flowchart of a secure authentication method provided by an embodiment of the present application from the perspective of an authenticated node;
[0064] Figure 10 is a logic structure diagram of a first device provided by an embodiment of the present application;
[0065] Figure 11 is a logic structure diagram of a second device provided by an embodiment of the present application;
[0066] Figure 12 is a logic structure diagram of a third device provided by an embodiment of the present application;
[0067] Figure 13 is a logic structure diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0068] The terms used in the embodiment part of the present application are only used for explaining the specific embodiments of the present application, and are not intended to limit the present application.
[0069] First, the scene to which the technical solution provided by the embodiments of the present application is applied is introduced. The technical solution provided by the embodiments of the present application can be applied in the scene of V2X (vehicle to everything, vehicle to external information interaction) and vehicle-road cooperation. Of course, the technical solution provided by the embodiments of the present application can also be applied in other reasonable scenes. The vehicle-road cooperation scene is taken as an example for description below.
[0070] As Figure 1As shown, in the vehicle-road cooperation scenario, the vehicle end, the road end and the service end can communicate with each other. The device of the vehicle end is, for example, an OBU (On board Unit, vehicle-mounted unit), the device of the road end is, for example, an RSU (Road Side Unit, road side unit), and the service end is, for example, an SP (Service Provider, service provider or service providing unit). The OBU is a microwave device that communicates with the RSU by using the DSRC (Dedicated Short Range Communication, dedicated microwave communication) technology. The OBU can communicate with the RSU and the SP as a client. The OBU is issued with a certificate identity by a trusted authority center when it is manufactured. The RSU is installed on the roadside and is a device that implements functions such as vehicle identity recognition and electronic demerit. The RSU can serve as a relay device for the OBU to communicate with the SP. The RSU is issued with a certificate identity by a trusted authority center when it is manufactured. The SP is a direct provider of Internet of Vehicles service contents and application services. The SP is issued with a certificate identity by a trusted authority center when it is initialized. The OBU, the RSU and the SP can be referred to as entities or units in the embodiments of the present application. Before trusted communication, the OBU, the RSU and the SP need to authenticate the identity of each other. For example, if the OBU requests the SP to provide services for the OBU, the SP needs to perform security authentication on the OBU.
[0071] In the embodiments of the present application, the OBU, the RSU and the SP can all generate their own public keys and private keys. For example, the public key of the OBU is PK OBU , the private key of the OBU is SK OBU , the public key of the RSU is PK RSU , the private key of the RSU is SK RSU , the public key of the SP is PK SP , and the private key of the SP is SK SP . The public keys and the private keys can be generated according to the ECC (Elliptic Curves Cryptography, elliptic curve cryptography) mechanism. After obtaining the public key of the OBU, the public key of the RSU and the public key of the SP, a hash algorithm can be used to take hash values of the public key of the OBU, the public key of the RSU and the public key of the SP, respectively, and then the first 25 bits of each hash value are taken as the identity of the corresponding entity. For example, the first 25 bits of the hash value of the OBU are taken as the identity (ID OBU ) of the OBU, the first 25 bits of the hash value of the RSU are taken as the identity (ID RSU ) of the RSU, and the first 25 bits of the hash value of the SP are taken as the identity (ID SP). Of course, other number or position of bits of the hash value can be taken as the identifier of the corresponding entity. The hash algorithm used is, for example, SHA256 (Secure Hash Algorithm-256). After obtaining the identifier of the OBU, the identifier of the RSU and the identifier of the SP, the identifiers can be stored in an identifier set table, which can be maintained by the blockchain node as shown in Figure 1 , and can be circulated among the blockchain nodes. Each entity has only one identifier, and each entity can obtain the identifier of other entities from the blockchain node. To prevent impersonation, the CRAM (Challenge-Response Authentication Mechanism) mechanism is used in the embodiments of the present application. The challenge-response mechanism used in the embodiments of the present application will be introduced in the following embodiments.
[0072] In addition, the embodiments of the present application can create a DD (Description Document) for each entity. The data structure of the description document is as shown in Figure 3 . Among them, Idex represents the identifier of the entity, which can be used as the index of the description document in the blockchain; Public key represents the public key of the entity; Authentication method represents the algorithm used for encryption and decryption of random numbers when the challenge-response mechanism is used between entities; Creation time represents the creation time of the description document; Recreation time represents the modification time of the description document; Attribute proof mechanism identifier represents the security authentication mechanism used for attribute proof, such as Figure 3 . If it is X.509, it means that the X.509 authentication mechanism is used, if it is SM2, it means that the SM2 certificateless authentication mechanism is used, and if it is SM9, it means that the SM9 authentication mechanism is used. The description document can be stored in the blockchain node and can be circulated among the blockchain nodes.
[0073] As shown in Figure 1As shown, the OBU, RSU, SP and the like entities can obtain the description document of any entity from the blockchain node. In actual application, any entity can obtain the description document of any entity from the blockchain node closest to it. Of course, any entity can also obtain the description document of any entity from other blockchain nodes except the blockchain node closest to it. In addition, if other information is also stored in the blockchain node, and if a certain entity has the right to query other information, the entity can also obtain other information from the blockchain node in addition to the description document. In addition, the description document and the like information can be transmitted among the blockchain nodes to keep the information stored in each blockchain node consistent.
[0074] The following will be described in combination with Figure 2 The security authentication total process provided by the embodiment of the present application will be described taking the case that the OBU needs to communicate with the SP as an example. Figure 2 The process shown is as follows:
[0075] S201: The OBU obtains the identity of the SP from the blockchain node.
[0076] In this step, if the OBU needs to communicate with the SP, or in other words, if the OBU needs the SP to provide a certain service, the OBU obtains the identity of the SP closest to the OUB from the blockchain node which can provide the service and is closest to the OUB relative to other SPs.
[0077] Specifically, the OBU can send an SP search request message for requesting to search for the SP to the blockchain node, and the SP search request message can include the service information of the service required by the OBU to obtain, and of course, can also include other requirement information of the OBU to the SP. After receiving the SP search request message, the blockchain node can find the SP which can provide the service required by the OBU through the blockchain related algorithm. If there are multiple SPs which can provide the service required by the OBU, the SP closest to the OBU can be selected. The identity of the selected SP is sent to the OBU.
[0078] S202: The OBU requests the blockchain node to provide the description document of the SP.
[0079] Specifically, the OBU can send the identity of the SP to the blockchain node to request the blockchain node to provide the description document of the SP to the OBU.
[0080] S203: The blockchain node sends the description document of the SP to the OBU.
[0081] In this step, the blockchain node can find the description document of the SP required by the OBU according to the identity of the SP.
[0082] S204: The OBU requests the SP to provide a certain service.
[0083] Specifically, the OBU can obtain the public key of the SP from the description document of the SP, encrypt the data group using the public key of the SP, and send the encrypted data group to the SP. The encrypted data group is, for example, {EPK SP [ID OBU , requested service, h(ID OBU || requested service)]}, where ID OBU is the identity of the OBU, "requested service" is used to represent the service information of the requested service, and h(ID OBU || requested service) represents a hash value obtained by performing a hash operation on ID OBU or "requested service".
[0084] It should be noted that the OBU sends the hash value obtained by performing a hash operation on ID OBU or "requested service" to the SP, which can further improve the security of the data.
[0085] The requested service is, for example, a request to provide a navigation service, etc.
[0086] S205: The challenge-response mechanism between the SP and the OBU determines the ownership of the identity of the OBU and that the identity of the OBU is not impersonated.
[0087] Specifically, the SP can use the private key of the SP to decrypt the encrypted data group mentioned in S204. Further, the SP can verify whether {SK SP , EPK SP [ID OBU , requested service, h(ID OBU || requested service)]} = 1 holds, where SK SP is the private key of SK, ID OBU is the identity of the OBU, and h(ID OBU || requested service) is a hash value obtained by performing a hash operation on the identity of the OBU or "requested service". If it holds, it means that the request information sent by the OBU is not tampered with.
[0088] After the SP decrypts the encrypted data group, the identity of the OBU and the requested service can be obtained. The SP can use the identity of the OBU to obtain the description document of the OBU from the block chain node, and obtain the public key of the OBU from the description document of the OBU.
[0089] Afterwards, the SP and the OBU adopt challenge-response mechanism to verify the OBU. Specifically, the SP can use its own algorithm for encrypting and decrypting the random number, or the algorithm used by the OBU for encrypting and decrypting the random number, to encrypt the random number and obtain the encrypted random number. The SP can obtain the algorithm used by the OBU for encrypting and decrypting the random number from the description document of the OBU. In the process of encrypting the random number, the public key used can be the public key of the OBU. After receiving the encrypted random number, the OBU uses the private key of the OBU and the encryption and decryption algorithm used by the SP to decrypt the encrypted random number and obtain the random number. Afterwards, the random number is subjected to hash operation to obtain a string, and the string is sent to the SP. The SP also performs hash operation on the random number and obtains a string, which is referred to as a benchmark string herein. The SP compares the string provided by the OBU with the benchmark string calculated by the SP. If the string provided by the OBU is the same as the benchmark string calculated by the SP, the SP can determine the ownership of the identifier of the OBU and that the identifier of the OBU is not impersonated.
[0090] S206: The SP requests the OBU to provide certain attribute proof.
[0091] After determining the ownership of the OBU and that the OBU is not impersonated, the SP can determine which attribute proof the OBU needs to provide. Specifically, the SP can obtain the service characteristics of the service required by the OBU according to the requested service, and then determine which attribute proof the OBU needs to provide according to the service characteristics, or in other words, determine which attribute the OBU needs to prove according to the service characteristics. For example, if the OBU requests the SP to provide navigation service, the SP can first determine that the navigation service has the characteristics of location information service and voice playing, and the SP can require the OBU to provide proof of having voice module or having specified voice module according to the voice playing characteristic. Of course, the SP can also determine which attribute proof the OBU needs to provide through other ways.
[0092] After determining the attribute that the OBU needs to prove, the SP can use the public key of the OBU to encrypt the data group and obtain the encrypted data group, and send the encrypted data group to the OBU. The encrypted data group is, for example, {EPK OBU [required attribute proof, ID SP , h(required attribute proof || ID SP )]}, where "required attribute proof" indicates that the OBU needs to prove having certain attribute, ID SP is the identifier of the SP, and h(required attribute proof || ID SP ) is the hash value obtained by performing hash operation on "required attribute proof" or the identifier of the SP.
[0093] S207: The challenge-response mechanism between the OBU and the SP is used to determine the ownership of the SP's identity and that the SP's identity is not impersonated.
[0094] The OBU can verify whether the following equation holds: {SKOBU, EPK OBU [proof of some required attribute || ID SP , h(proof of some required attribute || ID SP )]} = 1, and if it does, it means that the request information sent by the SP is not tampered with. Here, SKOBU is the private key of the OBU. In other words, if the OBU can decrypt the encrypted data group sent by the SP using its own private key, it can obtain information such as "proof of some required attribute".
[0095] Similar to the challenge-response mechanism mentioned in S205, the OBU can use its own encryption and decryption algorithm for the random number, or use the SP's encryption and decryption algorithm for the random number, to encrypt the random number and obtain the encrypted random number. The OBU can obtain the SP's description document from the blockchain node through the SP's identity. The OBU can obtain the encryption and decryption algorithm for the random number from the SP's description document. In the process of encrypting the random number, the public key used can be the public key of the SP. After receiving the encrypted random number, the SP uses the SP's private key and the encryption and decryption algorithm used by the OBU to decrypt the encrypted random number and obtain the random number. Then, the random number is hashed to obtain a string, which is sent to the OBU. The OBU will also hash the random number and obtain a string, which is referred to as the reference string. The OBU compares the string provided by the SP with the reference string calculated by the OBU. If the string provided by the SP is the same as the reference string calculated by the OBU, the OBU can determine the ownership of the SP's identity and that the SP's identity is not impersonated.
[0096] S208: The OBU requests the blockchain node to obtain the identity of the issuer that can provide the proof of some required attribute.
[0097] In this step, the OBU can send the "required attribute proof" to the blockchain node, so that the blockchain node knows which attribute proof the OBU needs to find the issuer to provide, or so that the blockchain node sends the "required attribute proof" to the issuer, so that the issuer knows which attribute proof needs to be provided. The issuer can refer to the issuer, also known as the certificate issuer, and also known as the CA (Certificate Authority). Of course, the OBU can also send the identifier of the SP to the blockchain node, and the blockchain node can find the description document of the SP according to the identifier of the SP, and then determine the security authentication mechanism supported by the SP from the description document of the SP, so as to find the issuer that can support the security authentication mechanism supported by the SP. Alternatively, the blockchain node can also send the identifier of the SP to the issuer, and the issuer can find the description document of the SP according to the identifier of the SP, and then determine the security authentication mechanism supported by the SP from the description document of the SP, so as to generate the attribute certificate using the security authentication mechanism supported by the SP.
[0098] It should be noted that the issuer can also be regarded as an entity similar to the OBU, the RSU, and the SP. The identifier and the description document of the issuer can also be stored in the blockchain node and circulated among the blockchain nodes. The generation method of the identifier of the issuer can refer to the generation method of the identifier of the OBU, the identifier of the RSU, and the identifier of the SP. The data structure of the description document of the issuer can also refer to the data structure of the description document of the OBU, the data structure of the description document of the RSU, and the data structure of the description document of the SP. Figure 3
[0099] S209: The blockchain node provides the identifier of the issuer of the required attribute proof to the OBU.
[0100] Specifically, the blockchain node can determine the issuer that provides the attribute proof required by the OBU according to the "required attribute proof", so as to find the issuer that can provide the "required attribute proof". After the blockchain node finds the issuer that can provide the "required attribute proof", the blockchain node can send the identifier of the found issuer to the OBU.
[0101] S210: The OBU requests the description document of the issuer from the blockchain node.
[0102] Specifically, the OBU can send the identifier of the issuer to the blockchain node to request the description document of the issuer.
[0103] S211: The blockchain node sends the description document of the issuer to the OBU.
[0104] Specifically, the blockchain node looks up the description document of the issuer according to the identifier of the issuer, and sends the found description document of the issuer to the OBU.
[0105] S212: The OBU requests the issuer to prove that the OBU has a certain attribute.
[0106] Specifically, the OBU obtains the public key of the issuer from the description document of the issuer. The data group is encrypted using the public key of the issuer to obtain an encrypted data group, and the encrypted data group is sent to the issuer to request the issuer to prove that the OBU has a certain attribute. The data group can include "proof of a certain attribute required", the identifier of the OBU and the identifier of the SP. The encrypted data group can be represented as: {EPK issuer [proof of a certain attribute required, ID OBU , ID SP , h(proof of a certain attribute required||ID OBU ||ID SP )]}, where h(proof of a certain attribute required||ID OBU ||ID SP ) represents a hash value obtained by performing a hash operation on any one of "proof of a certain attribute required", ID OBU , ID SP .
[0107] S213: The challenge-response mechanism between the issuer and the OBU determines the ownership of the identifier of the OBU and that the identifier of the OBU is not impersonated.
[0108] Specifically, the issuer can use the private key of the issuer to decrypt the encrypted data group mentioned in S212. Further, the issuer can verify whether {SK issuer , EPK issuer [proof of a certain attribute required, ID OBU , ID SP , h(proof of a certain attribute required||ID OBU ||ID SP )]} = 1 holds, where SK issuer is the private key of the issuer. If it holds, it means that the request information sent by the OBU is not tampered.
[0109] After the issuer decrypts the encrypted data group, the identifier of the OBU can be obtained. The issuer can use the identifier of the OBU to obtain the description document of the OBU from the blockchain node, and obtain the public key of the OBU from the description document of the OBU.
[0110] Afterwards, the issuer and the OBU adopt challenge-response mechanism to verify the OBU. Specifically, the issuer can use the algorithm for encrypting and decrypting the random number by itself or the algorithm for encrypting and decrypting the random number by the OBU to encrypt the random number and obtain the encrypted random number. The issuer can obtain the algorithm for encrypting and decrypting the random number by the OBU from the description document of the OBU. In the process of encrypting the random number, the public key used can be the public key of the OBU. After receiving the encrypted random number, the OBU uses the private key of the OBU and the encryption and decryption algorithm used by the issuer to decrypt the encrypted random number and obtain the random number. Afterwards, the random number is subjected to hash operation to obtain a string, and the string is sent to the issuer. The issuer also performs hash operation on the random number and also obtains a string, which is referred to as a reference string herein. The issuer compares the string provided by the OBU with the reference string calculated by the issuer. If the string provided by the OBU is the same as the reference string calculated by the issuer, the issuer can determine the ownership of the identifier of the OBU and that the identifier of the OBU is not impersonated.
[0111] S214: The issuer sends the certificate for proving that the OBU has certain attributes to the SP.
[0112] Specifically, the issuer can use the security authentication mechanism supported by the SP to generate the certificate (Certificate) for proving that the OBU has certain attributes, and the certificate can also be referred to as a voucher or a proof. Further, the issuer can obtain the description document of the SP from the block chain node according to the identifier of the SP, and obtain the attribute proof mechanism identifier from the description document of the SP, that is, determine which security authentication mechanism is supported by the SP, so that the security authentication mechanism supported by the SP generates the certificate.
[0113] In addition, when the OBU requests the issuer to prove that the OBU has certain attributes, the OBU can also send the attribute proof mechanism identifier of the SP to the issuer, in which case the issuer can determine which security authentication mechanism is supported by the SP without querying the description document of the SP.
[0114] Further, the issuer can generate a plurality of certificates for proving that the OBU has a certain attribute using a plurality of security authentication mechanisms, including the security authentication mechanism supported by the SP. In other words, the issuer can not need to determine which security authentication mechanism is supported by the SP, and in this case, the issuer generates a plurality of certificates using a plurality of security authentication mechanisms, and the plurality of certificates actually include a certificate corresponding to the security authentication mechanism supported by the SP. After receiving the plurality of certificates, the SP can select the certificate corresponding to the security authentication mechanism supported by the SP for verification.
[0115] Regardless of the way, after the issuer generates the certificate for proving that the OBU has a certain attribute, the issuer sends the certificate to the SP. Specifically, the issuer can obtain the description document of the SP from the blockchain node according to the identifier of the SP, and obtain the public key of the SP from the description document of the SP. The issuer encrypts the data group using the public key of the SP to obtain an encrypted data group, and sends the encrypted data group to the SP. The encrypted data group can be represented as: {EPK SP [C Attr , ID issuer , h(C Attr || ID issuer )]}, where C Attr represents the certificate for proving that the OBU has the attribute Attr, ID issuer represents the ID of the issuer, and h(C Attr || ID issuer ) is used to represent the hash value obtained by performing a hash operation on the certificate or the ID of the issuer.
[0116] S215: The challenge-response mechanism is used between the SP and the issuer to determine the ownership of the identifier of the issuer and that the identifier of the issuer is not impersonated.
[0117] Specifically, the SP can use the private key of the SP to decrypt the encrypted data group mentioned in S214. Further, the SP can verify whether {SK SP , EPK SP [C Attr , ID issuer , h(C Attr || ID issuer )]} = 1 holds, where SK SP is the private key of the SP. If it holds, it means that the request information sent by the issuer is not tampered.
[0118] The SP can obtain the description document of the issuer from the blockchain node using the identifier of the issuer, and obtain the public key of the issuer from the description document of the issuer.
[0119] After that, the SP and the issuer adopt a challenge-response mechanism to verify the issuer. Specifically, the SP can encrypt the random number using an encryption and decryption algorithm used by the SP or an encryption and decryption algorithm used by the issuer, to obtain an encrypted random number. The SP can obtain the encryption and decryption algorithm used by the issuer from the description document of the issuer. In the process of encrypting the random number, the public key used can be the public key of the issuer. After receiving the encrypted random number, the issuer decrypts the encrypted random number using the private key of the issuer and the encryption and decryption algorithm used by the SP, to obtain the random number. Then, the issuer performs a hash operation on the random number to obtain a string, and sends the string to the SP. The SP also performs a hash operation on the random number to obtain a string, which is referred to as a reference string. The SP compares the string provided by the issuer with the reference string calculated by the SP. If the string provided by the issuer is the same as the reference string calculated by the SP, the SP can determine the ownership of the identifier of the issuer and that the identifier of the issuer is not impersonated.
[0120] S216: The SP communicates with the OBU.
[0121] Specifically, after the SP obtains the certificate provided by the issuer, the SP obtains the signature data of the issuer for a certain attribute and parameters required for verifying the signature data from the certificate, and then verifies the signature data using a security authentication mechanism supported by the SP and the parameters required for verifying the signature data. If the verification is successful, the SP determines that the SP can provide services for the OBU, or determines that the SP can communicate with the OBU.
[0122] In V2X (vehicle to everything, vehicle-to-external information interaction) and vehicle-road cooperation scenarios, in order to ensure lightweight identity security and communication security, domestic and foreign security agencies and vehicle manufacturers jointly establish and promote different identity authentication technologies based on cryptography, and establish SM9 (related standard: GM / T 0044-2016 SM9 identity cryptography algorithm) identity authentication, lightweight SM2 (elliptic curve public key cryptography algorithm) certificateless identity security authentication, X.509 (format standard of public key certificate in cryptography) certificate authentication, and other security authentication systems, which highlight the integration of end-to-end cloud and zero-trust security system, and provide security protection for intelligent networking and large-scale application.
[0123] The security authentication mechanism mentioned in the above embodiments can be one or more of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism.
[0124] The X.509 security authentication mechanism, the SM2 security authentication mechanism, and the SM9 security authentication mechanism used in the embodiments of the present application are described below.
[0125] The X.509 CA security authentication mechanism is described below.
[0126] 1) Generating a system public-private key
[0127] The issuer is an authoritative trusted center. The issuer randomly selects two unequal prime numbers j and k, and calculates jk=g; randomly selects an integer f, 1<f<∮(g) and f is coprime with ∮(g), calculates u, which satisfies uf=1(mod∮(g)); obtains the public key (g, u) and the private key (g, f) of the issuer; and the issuer creates a root certificate.
[0128] 2) OBU applies for a certificate
[0129] The OBU obtains the root certificate of the issuer, then connects with the security server, and submits identity information that can prove that the Attr is satisfied to the security server; and the security server transfers it to the certificate registration authority (RA) server.
[0130] 3) RA server audits and signs
[0131] After the RA server receives the application, the identity information submitted by the OBU is authenticated according to the Attr; if the OBU satisfies the Attr requirement, the following steps are executed:
[0132] ① The RA server generates a key:
[0133] The RA randomly selects two unequal prime numbers P and q, and calculates Pq=n; randomly selects an integer e, 1<e<∮(n) and e is coprime with ∮(n), calculates d, which satisfies ed=1(mod∮(n)), obtains the public key (n, e) and the private key (n, d) of the RA server.
[0134] ② The RA server signs:
[0135] The RA server signs the Attr S=(h(Attr)) d mod n.
[0136] 4) The issuer issues a certificate
[0137] ①The issuer verifies the RA server signature:
[0138] After receiving (Attr, S), the issuer verifies it with the RA server's public key (n, e) and obtains h(Attr) = S e modn; compare h'(Attr)=h(Attr). If so, the verification is successful.
[0139] ③Issuer issues certificate:
[0140] The issuer signs the attribute Attr with its own private key
[0141] Get Certificate C Attr like Figure 4 shown.
[0142] The following introduces the SM2 security authentication mechanism.
[0143] 1) Generate system parameters:
[0144] The parameters of the elliptic curve system include the size q of the finite field Fq; the two elements a and b of the equation defining the elliptic curve E(Fq), Fq, the base point G = (xG, yG) (G≠O) on E(Fq), and the order n of G. A ) has an ID of 25 bits in length issuer , remember that ENTLA is the two bytes converted from the integer 25.
[0145] 2) Master key generation mechanism
[0146] The Key Generation Center (KGC) uses a random number generator to generate a random number ms∈[1,n-1] as the system master private key. The system master public key Ppub=[ms]G is calculated.
[0147] 3)Issuer key pair generation mechanism
[0148] issuer A Collaborate with KGC to generate issuer A Key pair:issuer A Private key S IssA and the declared public key WA. Both should implement the following operation steps:
[0149] ①issuer A Generate a random number S' using a random number generator IssA ∈[1,n-1];
[0150] ②issuerA Computation I A =[S' IssA ]G, and set your own ID issuerA and I A Submit KGC;
[0151] ③KGC calculates H A =H256(ENTLA|ID issuerA ∥a∥b∥xG∥yG∥xPub∥yPub);
[0152] ④KGC uses a random number generator to generate a random number w∈[1,n-1];
[0153] ⑤KGC calculates W A =[w]G+I A ; Calculate θ = H256 (xW A ∥yW A ∥H A )mod n;
[0154] ⑥KGC calculation t A =(w+θ*ms)mod n, and t A and W A Safely returned to the issuer A ;
[0155] ⑦issuer A Calculate S IssA =(t A +S' IssA )mod n;
[0156] ⑧If 0 IssA <n-1,则输出(S IssA ,W A ); otherwise return ①.
[0157] In order to verify the generated key pair (S IssA , W A ) is correct, issuer A (issurer A ) should implement the following operation steps:
[0158] ①Calculate H A =H256(ENTLA|ID issuerA ‖a‖b‖xG‖yG‖xPub‖yPub);
[0159] Calculate θ = H256(xW A ‖yW A ‖H A )mod n,
[0160] ②Calculate PA=WA +[θ]Ppub;
[0161] 3. Calculate PA' = [S IssA ]G;
[0162] 4. Check if PA = PA' holds, if yes, the verification is passed; otherwise, the verification is failed.
[0163] Signature:
[0164] The issuer A wants to prove Attr, the issuer A should implement the following operation steps:
[0165] Execute SIGN(param, H A ‖xW A ‖yW A ‖Attr, S IssA ), e = H256(H A ‖xW A ‖yW A ‖Attr),
[0166] Generate a random number k∈[1,n-1] by using random number generator; [k]G = (x1,y1), r = e + x1 mod n;
[0167] s = (1 + S IssA )-1(k-r*S IssA ) mod n; and output the signature
[0168] Get the certificate C Attr as shown in Figure 5 .
[0169] Verification:
[0170] In order to check the received message Attr' and its digital signature , the SP as verifier should implement the following operation steps:
[0171] 1. Calculate H A = H256(ENTLA∥ID issuerA ∥a∥b∥xG∥yG∥xPub∥yPub);
[0172] θ = H256(xW A ∥yW A ∥H A ) mod n,
[0173] 2. Calculate PA = W A +[θ]P pub ;
[0174] 3. Execute VERIFY(param, H A ‖xW issuerA ‖yW A ‖Attr, PA, r, s).A xW A yW A Attr', PA, (r', s') ) ;
[0175] e' = H256(H A xW A yW A Attr' ) ;
[0176] t = (r' + s') mod n; [s']G + [t]PA = (x1', y1') ; R = (e' + x1') mod n
[0177] If r' ∈ [1, n-1], R = r and s' ∈ [1, n-1], then the verification is passed.
[0178] The following introduces the SM9 security authentication mechanism.
[0179] 1) System parameter generation
[0180] Let N be a large prime number, G1 and G2 be two additive groups of order N (groups on elliptic curves), GT be a multiplicative group of order N, the mapping e: G1 x G2 → GT be a bilinear mapping (bilinear pair), P1 ∈ G1, P2 ∈ G2; hid be a private key generation function identifier; H() be a cryptographic hash function, H1() and H2() be cryptographic functions derived from the cryptographic hash function;
[0181] The key generation center (Key Generation Center, KGC) performs the following steps to generate system parameters and master private keys:
[0182] The KGC generates a random number s as the master private key, where 0 < s < N-1;
[0183] The KGC calculates the system public key P pub = s·P2;
[0184] The KGC saves the private key s and publishes the system public key.
[0185] 2) issuer public and private key generation
[0186] The generation process of the private key of the issuer A (issuer A) is as follows:
[0187] The KGC first calculates t1 = H1(ID issuerA || hid, N) + s mod N on the finite field FN, where ID issuerA is the identification of the issuer; if t1 = 0, the signature master private key needs to be generated again, the signature master public key is calculated and published, and the signature private keys of existing users are updated; the KGC calculates t2 = s·t1-1 mod N; then calculates dsA = [t2] P1.
[0188] 3) Generation of digital signature
[0189] The generation process is as follows:
[0190] 2) Calculate an element g = e(P1, Ppub) in the group GT; pub
[0191] 2) Generate a random number r e [1, N-1];
[0192] 3) Calculate an element ω = g r in the group GT, and convert the data type of ω into a bit string;
[0193] 4) Calculate an integer h = H2(Attr || ω, N);
[0194] 5) Calculate an integer l = (r - h) mod N, and if l = 0, return to 2;
[0195] 6) Calculate an element S = [l]d sA in the group G;
[0196] 7) Convert the data type of h into a byte string, convert the data type of S into a byte string, and the signature of the message Attr is o = (h, S).
[0197] 4) Authentication of signature
[0198] The authentication process is as follows:
[0199] 1) Convert the data type of h' into an integer, and check whether h' e [1, N-1] is true, and if not, the verification fails;
[0200] 2) Convert the data type of S' into a point on the elliptic curve, and check whether S' e G is true, and if not, the verification fails;
[0201] 3) Calculate an element g = e(P1, Ppub) in the group GT;
[0202] 4) Calculate an element t = gh' in the group GT;
[0203] 5) Calculate an integer h1 = H1(IDissuerA || hid, N);
[0204] 6) Calculate an element P = [h1] P2 + Ppub in the group G2;
[0205] 7) Calculate an element u = e(S', P) in the group GT;
[0206] 8) Calculate an element ω' = u · t in the group GT, and convert the data type of w' into a bit string;
[0207] ⑨ Calculate the integer h2=H2(Attr'||ω',N) and check whether h2=h'. If so, the verification passes; otherwise, the verification fails.
[0208] It is not difficult to see from the above embodiments that the embodiments of the present application integrate three security authentication mechanisms, namely the X.509 security authentication mechanism, the SM2 security authentication mechanism and the SM9 security authentication mechanism, and can adapt to the security authentication mechanisms supported by most entities in scenarios such as V2X and vehicle-road collaboration.
[0209] In addition, the embodiment of the present application introduces blockchain technology, which can realize the circulation and authentication of each entity information and certificate.
[0210] In addition, the embodiments of the present application propose a complete authentication data format and authentication process.
[0211] In addition, in the embodiments of the present application, if a certain attribute requires certificates corresponding to multiple security authentication mechanisms to prove it, the issuer can use multiple security authentication mechanisms to generate multiple certificates used to prove that a certain entity (such as the OBU in the above embodiment) has a certain attribute, and send the multiple certificates to the entity that needs to obtain proof (such as the SP in the above embodiment). In this case, it is equivalent to integrating multiple security authentication mechanisms to achieve specific security guarantees.
[0212] The above embodiment is the overall security authentication process of the embodiment of the present application. The embodiment of the present application is described below from the perspectives of the certificate issuing end, the authentication node, and the authenticated node.
[0213] First combine Figure 7 , the present application embodiment is described from the perspective of the certificate issuing end. Figure 7 As shown in the figure, the process of the security authentication method provided from the perspective of the authentication server is as follows:
[0214] S701: The certificate issuing end obtains a second target attribute certification request message sent by the first node for requesting proof that the first node has the target attribute. The second target attribute certification request message includes identification information of the second node. The first node supports a first security authentication mechanism, and the second node supports a second security authentication mechanism. The second node is the node with which the first node needs to communicate.
[0215] S702: The certificate issuing end uses the second security authentication mechanism to generate a target attribute certificate for the target attribute as the second security authentication mechanism target attribute certificate.
[0216] S703: The certificate issuing end sends the second node the second security authentication mechanism target attribute certificate according to the identification information of the second node, and the second security authentication mechanism target attribute certificate is used by the second node to verify whether the first node has the target attribute.
[0217] The first security authentication mechanism can be one of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism. The second security authentication mechanism can be one of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism. Of course, the first security authentication mechanism and the second security authentication mechanism can be different.
[0218] The first node can be one of a vehicle-mounted unit, a roadside unit, and a service providing unit in a vehicle-road cooperation scenario. The second node can be one of a vehicle-mounted unit, a roadside unit, and a service providing unit in a vehicle-road cooperation scenario. Of course, the first node and the second node can be different kinds of units. For example, the first node can refer to an OBU in Figure 2 , and the second node can refer to an SP in Figure 2 , and the certificate issuing end can refer to an issuer in Figure 2 . The first node can refer to an authenticated node. The second node can refer to an authentication node or a node that needs to obtain a certificate.
[0219] The second target attribute proof request message can further include the following information: information of the target attribute; identification information of the first node; and a first hash value obtained by performing a hash operation on any one of the information of the target attribute, the identification information of the first node, and the identification information of the second node.
[0220] The certificate issuing end can obtain a first encrypted data group from the second target attribute proof request message, the first encrypted data group being a data group obtained by the first node by encrypting a first data group using a public key of the certificate issuing end, the first data group including the information of the target attribute, the identification information of the first node, the identification information of the second node, and the first hash value. The certificate issuing end decrypts the first encrypted data group using a private key of the certificate issuing end to obtain the first data group.
[0221] The certificate issuing end can obtain the description document of the first node from the block chain node according to the identification information of the first node. The certificate issuing end obtains the public key of the first node from the description document of the first node. The certificate issuing end encrypts the first random number using the public key of the first node to obtain the encrypted first random number. The certificate issuing end sends the encrypted first random number to the first node. The certificate issuing end obtains the first string sent by the first node, which is a string obtained by the first node by performing a hash operation on the first random number, wherein the first node uses the private key of the first node to decrypt the encrypted first random number to obtain the first random number. The certificate issuing end performs a hash operation on the first random number to obtain a string as a first reference string. The certificate issuing end generates a target attribute certificate for the target attribute using a second security authentication mechanism, including: if the first string is the same as the first reference string, generating a target attribute certificate for the target attribute using a second security authentication mechanism.
[0222] The certificate issuing end obtains information of the first encryption and decryption algorithm used by the first node for encryption and decryption of the random number from the description document of the first node;
[0223] The certificate issuing end can use the public key of the first node to encrypt the first random number to obtain the encrypted first random number, including: the certificate issuing end uses the public key of the first node and the first encryption and decryption algorithm to encrypt the first random number to obtain the encrypted first random number. The first node uses the private key of the first node to decrypt the encrypted first random number to obtain the first random number, including: the first node uses the private key of the first node and the first encryption and decryption algorithm to decrypt the encrypted first random number to obtain the first random number.
[0224] The certificate issuing end uses the public key of the first node to encrypt the first random number to obtain an encrypted first random number, including: the certificate issuing end uses the public key of the first node and a third encryption and decryption algorithm used by the certificate issuing end for random number encryption and decryption to encrypt the first random number to obtain the encrypted first random number. Wherein the first node obtains the information of the third encryption and decryption algorithm used by the certificate issuing end for random number encryption and decryption from the description document of the certificate issuing end, and the first node obtains the description document of the certificate issuing end from the block chain node according to the identification information of the certificate issuing end. The first node uses the private key of the first node to decrypt the encrypted first random number to obtain the first random number, including: the first node uses the private key of the first node and the third encryption and decryption algorithm to decrypt the encrypted first random number to obtain the first random number.
[0225] The certificate issuing end can obtain the description document of the second node from the block chain node according to the identification information of the second node. The certificate issuing end obtains the security authentication mechanism identifier corresponding to the second node from the description document of the second node, and the security authentication mechanism identifier corresponding to the second node indicates that the second node supports the second security authentication mechanism.
[0226] The second target attribute proof request message can also include a security authentication mechanism identifier for indicating that the second node supports the second security authentication mechanism. The method can also include: the certificate issuing end obtains the security authentication mechanism identifier for indicating that the second node supports the second security authentication mechanism from the second target attribute proof request message; and the certificate issuing end determines that the second node supports the second security authentication mechanism according to the security authentication mechanism identifier for indicating that the second node supports the second security authentication mechanism. Wherein the first node obtains the security authentication mechanism identifier for indicating that the second node supports the second security authentication mechanism from the description document of the second node, and the first node obtains the description document of the second node from the block chain node according to the identification information of the second node.
[0227] The certificate issuing end can generate a target attribute certificate for the target attribute using a security authentication mechanism supported by the certificate issuing end other than the second security authentication mechanism, as an other security authentication mechanism target attribute certificate. The certificate issuing end sends the other security authentication mechanism target attribute certificate to the second node according to the identification information of the second node. The second node selects the second security authentication mechanism target attribute certificate corresponding to the second security authentication mechanism from the second security authentication mechanism target attribute certificate and the other security authentication mechanism target attribute certificate, and uses the second security authentication mechanism target attribute certificate to verify whether the first node has the target attribute.
[0228] The certificate issuing end can obtain a description document of the second node from a block chain node according to the identification information of the second node. The certificate issuing end obtains the public key of the second node from the description document of the second node. The certificate issuing end encrypts a second data set using the public key of the second node to obtain a second encrypted data set, the second data set including the second security authentication mechanism target attribute certificate, the identification information of the certificate issuing end, and a second hash value, the second hash value being a hash value obtained by performing a hash operation on the second security authentication mechanism target attribute certificate or the identification information of the certificate issuing end. The certificate issuing end sends the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, including: the certificate issuing end sends the second encrypted data set to the second node according to the identification information of the second node.
[0229] In the above embodiment, after the certificate issuing end obtains the target attribute proof request issued by the first node supporting the first security authentication mechanism, the certificate issuing end can generate a target attribute certificate using the second security authentication mechanism supported by the second node, and send the target attribute certificate to the second node to prove that the first node has the target attribute to the second node. In other words, when facing the demand of trusted communication between nodes supporting different security authentication mechanisms, the certificate issuing end can generate a certificate according to the security authentication mechanism supported by the node receiving the proof, and security authentication is realized between nodes supporting different security authentication mechanisms.
[0230] The following will be described in combination with Figure 8 The embodiments of the present application are described from the perspective of the authentication node (the second node). As shown in Figure 8 The flow of the security authentication method provided from the perspective of the authentication node is as follows:
[0231] S801: A second node obtains a second security authentication mechanism target attribute certificate sent by a certificate issuer, wherein the second security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuer for a target attribute using a second security authentication mechanism, the target attribute is a target attribute possessed by a first node, the first node supports a first security authentication mechanism, the second node supports the second security authentication mechanism, and the second node is a node that needs to communicate with the first node.
[0232] S802: The second node obtains signature data of the target attribute generated by the certificate issuer from the second security authentication mechanism target attribute certificate.
[0233] S803: The second node verifies the signature data of the target attribute using the second security authentication mechanism, and if the verification is passed, it is determined that the first node has the target attribute.
[0234] The first security authentication mechanism can be one of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism. The second security authentication mechanism can be one of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism. Of course, the first security authentication mechanism and the second security authentication mechanism can be different.
[0235] The first node can be one of an on-board unit, a road side unit, and a service providing unit in a car-road cooperative scenario. The second node can be one of an on-board unit, a road side unit, and a service providing unit in a car-road cooperative scenario. Of course, the first node and the second node can be different kinds of units. For example, the first node can refer to an OBU in Figure 2 , and the second node can refer to an SP in Figure 2 , the certificate issuer can refer to an issuer in Figure 2 . The first node can refer to an authenticated node. The second node can refer to an authentication node or a node that needs to obtain a certificate.
[0236] The second node obtains a second security authentication mechanism target attribute certificate sent by a certificate issuing end, including: the second node obtains a second encrypted data group sent by the certificate issuing end, the second encrypted data group being obtained by the certificate issuing end encrypting a second data group using a public key of the second node, the second data group including the second security authentication mechanism target attribute certificate, identification information of the certificate issuing end, and a second hash value, the second hash value being a hash value obtained by hashing the second security authentication mechanism target attribute certificate or the identification information of the certificate issuing end; and the second node decrypts the second encrypted data group using a private key of the second node to obtain the second data group.
[0237] The second node can obtain a description document of the certificate issuing end from a block chain node according to the identification information of the certificate issuing end. The second node obtains a public key of the certificate issuing end from the description document of the certificate issuing end. The second node encrypts a second random number using the public key of the certificate issuing end to obtain an encrypted second random number. The second node sends the encrypted second random number to the certificate issuing end. The second node obtains a second string sent by the certificate issuing end, the second string being a string obtained by the certificate issuing end hashing the second random number. The certificate issuing end decrypts the encrypted second random number using a private key of the certificate issuing end to obtain the second random number. The second node hashes the second random number to obtain a string as a second reference string. The second node obtains signature data of the certificate issuing end for the target attribute from the second security authentication mechanism target attribute certificate, including: if the second string is the same as the second reference string, the second node obtains the signature data of the certificate issuing end for the target attribute from the second security authentication mechanism target attribute certificate.
[0238] The second node can obtain information of a third encryption and decryption algorithm used by the certificate issuing end for encrypting and decrypting a random number from the description document of the certificate issuing end. The second node encrypts a second random number using a public key of the certificate issuing end to obtain an encrypted second random number, including: the second node encrypts the second random number using the public key of the certificate issuing end and the third encryption and decryption algorithm to obtain the encrypted second random number. The certificate issuing end decrypts the encrypted second random number using a private key of the certificate issuing end to obtain the second random number, including: the certificate issuing end decrypts the encrypted second random number using the private key of the certificate issuing end and the third encryption and decryption algorithm to obtain the second random number.
[0239] The second node can encrypt the second random number using the public key of the certificate issuing end to obtain an encrypted second random number, including: the second node encrypts the second random number using the public key of the certificate issuing end and a second encryption and decryption algorithm used by the second node for random number encryption and decryption to obtain the encrypted second random number. Wherein the certificate issuing end obtains information of the second encryption and decryption algorithm used by the second node for random number encryption and decryption from the description document of the second node, and the certificate issuing end obtains the description document of the second node from the block chain node according to the identification information of the second node. The certificate issuing end decrypts the encrypted second random number using the private key of the certificate issuing end to obtain the second random number, including: the certificate issuing end decrypts the encrypted second random number using the private key of the certificate issuing end and the second encryption and decryption algorithm to obtain the second random number.
[0240] The second node can obtain a verification parameter for verifying the signature data of the target attribute from the second security authentication mechanism target attribute certificate. The second node verifies the signature data of the target attribute using the second security authentication mechanism, including: the second node verifies the signature data of the target attribute using the second security authentication mechanism and the verification parameter.
[0241] The second node can obtain a certificate issuing end sent other security authentication mechanism target attribute certificate, and the other security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuing end using other security authentication mechanisms supported by the certificate issuing end except the second security authentication mechanism for the target attribute. The second node selects the second security authentication mechanism target attribute certificate corresponding to the second security authentication mechanism from the second security authentication mechanism target attribute certificate and the other security authentication mechanism target attribute certificate for verifying whether the first node has the target attribute.
[0242] The second node can obtain the service providing request message sent by the first node for requesting the second node to provide services for the first node. The second node sends a first target attribute proof request message to the first node for requesting to prove that the first node has a target attribute. The second node obtains a second security authentication mechanism target attribute certificate sent by a certificate issuer, including: after the second node sends the first target attribute proof request message to the first node, obtaining the second security authentication mechanism target attribute certificate sent by the certificate issuer. The method further comprises: after the second node verifies the signature data of the target attribute using the second security authentication mechanism, the second node sends an instruction to the first node indicating that the first node is allowed to perform trusted communication with the second node, or the second node sends the service content of the service to the first node.
[0243] The service providing request message includes a third encrypted data group, which is a data group obtained by encrypting a third data group using the public key of the second node, the third data group including the identification information of the first node, service information indicating the service requested by the first node to provide, and a third hash value obtained by performing a hash operation on the identification information of the first node or the service information. The method further comprises: the second node obtains the third encrypted data group from the service providing request message; the second node decrypts the third encrypted data group using the private key of the second node to obtain the third data group; the second node obtains the description document of the first node from the block chain node according to the identification information of the first node included in the third data group; the second node obtains the public key of the first node from the description document of the first node; the second node encrypts a third random number using the public key of the first node to obtain an encrypted third random number; the second node sends the encrypted third random number to the first node; the second node obtains a third string sent by the first node, the third string being a string obtained by performing a hash operation on the third random number by the first node, wherein the first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number; the second node performs a hash operation on the third random number to obtain a string as a third reference string; the second node sends a first target attribute proof request message to the first node for requesting to prove that the first node has a target attribute, including: if the third string is the same as the third reference string, the second node sends a first target attribute proof request message to the first node for requesting to prove that the first node has a target attribute.
[0244] The second node can obtain information of the first encryption and decryption algorithm used by the first node for encryption and decryption of random numbers from the description document of the first node. The second node encrypts a third random number using the public key of the first node to obtain an encrypted third random number, including: the second node encrypts the third random number using the public key of the first node and the first encryption and decryption algorithm to obtain the encrypted third random number. The first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number, including: the first node decrypts the encrypted third random number using the private key of the first node and the first encryption and decryption algorithm to obtain the third random number.
[0245] The second node can encrypt a third random number using the public key of the first node to obtain an encrypted third random number, including: the second node encrypts the third random number using the public key of the first node and the second encryption and decryption algorithm used by the second node for encryption and decryption of random numbers to obtain the encrypted third random number. Wherein, the first node obtains information of the second encryption and decryption algorithm used by the second node for encryption and decryption of random numbers from the description document of the second node, and the first node obtains the description document of the second node from the block chain nodes according to the identification information of the second node. The first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number, including: the first node decrypts the encrypted third random number using the private key of the first node and the second encryption and decryption algorithm to obtain the third random number.
[0246] The second node can obtain information of the target attribute. The second node sends a first target attribute proof request message for requesting the first node to prove that the first node has a target attribute to the first node, including: the second node encrypts a fourth data group using the public key of the first node to obtain a fourth encrypted data group, the fourth data group including information of the target attribute, identification information of the second node, and a fourth hash value obtained by performing a hash operation on the information of the target attribute or the identification information of the second node. The second node sends the first target attribute proof request message including the fourth encrypted data group to the first node.
[0247] The second node can obtain the encrypted fourth random number sent by the first node. The second node decrypts the encrypted fourth random number using a private key of the second node to obtain the fourth random number. The second node performs a hash operation on the fourth random number to obtain a fourth string. The second node sends the fourth string to the first node. The first node performs a hash operation on the fourth random number to obtain a fourth reference string. If the fourth string is the same as the fourth reference string, the first node obtains identification information of the certificate issuing end capable of providing a target attribute certificate from a blockchain node, obtains a description document of the certificate issuing end from the blockchain node according to the identification information of the certificate issuing end, obtains a public key of the certificate issuing end from the description document of the certificate issuing end, encrypts a fifth data group using the public key of the certificate issuing end to obtain a fifth encrypted data group, sends a second target attribute proof request message for requesting to prove that the first node has the target attribute to the certificate issuing end, and the second target attribute proof request message includes the fifth encrypted data group. The fifth data group includes information of the target attribute, identification information of the first node, identification information of the second node, and a fifth hash value obtained by performing a hash operation on the information of the target attribute, the identification information of the first node, and the identification information of the second node.
[0248] The encrypted fourth random number is obtained in the following manner: the first node obtains the fourth encrypted data group from the first target attribute proof request message; the first node decrypts the fourth encrypted data group using a private key of the first node to obtain the fourth data group; the first node obtains a description document of the second node from a blockchain node according to the identification information of the second node included in the fourth data group; the first node obtains a public key of the second node from the description document of the second node; and the first node encrypts a fourth random number using the public key of the second node to obtain the encrypted fourth random number.
[0249] The second node obtains the information of the target attribute, including: the second node obtains service characteristic data of a service requested to be provided by the first node according to the service information; and obtains information of the target attribute required to be possessed by a node enjoying the service according to the service characteristic data.
[0250] In the above embodiment, the node requiring the certificate can obtain the certificate generated by the security authentication mechanism that the node can support from the certificate issuing end, and the certificate can prove that the authenticated node supporting other security authentication mechanisms has certain attributes. In other words, even if the node requiring the certificate and the authenticated node use different security authentication mechanisms, the node requiring the certificate can obtain the certificate for proving that the authenticated node has certain attributes. Therefore, the embodiment of the present application implements security authentication between nodes supporting different security authentication mechanisms.
[0251] The embodiment of the present application will be described below from the perspective of the authenticated node (the first node). As shown in Figure 9 , the security authentication method provided from the perspective of the authenticated node has the following process: Figure 9
[0252] S901: The first node sends a service providing request message for requesting the second node to provide services for the first node to the second node, the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node that the first node needs to communicate with.
[0253] S902: The first node obtains the first target attribute proof request message sent by the second node for requesting to prove that the first node has a target attribute.
[0254] S903: The first node sends a second target attribute proof request message for requesting to prove that the first node has the target attribute to the certificate issuing end.
[0255] S904: The first node obtains the instruction for indicating that the first node is allowed to perform trusted communication with the second node or the service content of the service sent by the second node.
[0256] The first security authentication mechanism can be one of the X.509 security authentication mechanism, the SM2 security authentication mechanism, and the SM9 security authentication mechanism. The second security authentication mechanism can be one of the X.509 security authentication mechanism, the SM2 security authentication mechanism, and the SM9 security authentication mechanism. Of course, the first security authentication mechanism and the second security authentication mechanism can be different.
[0257] The first node can be one of the vehicle-mounted unit, the road side unit, and the service providing unit in the vehicle-road cooperation scenario. The second node can be one of the vehicle-mounted unit, the road side unit, and the service providing unit in the vehicle-road cooperation scenario. Of course, the first node and the second node can be different kinds of units. For example, the first node can refer to Figure 2 OBU in the first node, the second node can refer to Figure 2 SP in the first node, the certificate issuer can refer to Figure 2 issuer in the first node. The first node can refer to an authenticated node. The second node can refer to an authentication node or a node that needs to obtain a certificate.
[0258] The first node can send a second node search request message for searching for a second node capable of providing the service to the first node to a blockchain node. The first node obtains identification information of the second node sent by the blockchain node. The first node obtains a description document of the second node from the blockchain node according to the identification information of the second node. The first node obtains a public key of the second node from the description document of the second node. The first node encrypts a third data group using the public key of the second node to obtain a third encrypted data group, the third data group including identification information of the first node, service information for indicating a service requested to be provided by the first node, and a third hash value obtained by performing a hash operation on the identification information of the first node or the service information. The first node sends a service provision request message for requesting the second node to provide the service to the first node to the second node, including: the first node sends the service provision request message including the third encrypted data group to the second node.
[0259] The second node can be a second node closest to the first node among all second nodes.
[0260] The first node can obtain an encrypted third random number sent by the second node, the encrypted third random number being obtained by the second node by encrypting a third random number using a public key of the first node. The first node decrypts the encrypted third random number using a private key of the first node to obtain the third random number. The first node performs a hash operation on the third random number to obtain a third string. The first node sends the third string to the second node. The first node obtains a first target attribute proof request message for requesting to prove that the first node has a target attribute sent by the second node, including: after the first node sends the third string to the second node, the first node obtains the first target attribute proof request message for requesting to prove that the first node has a target attribute sent by the second node.
[0261] The first node decrypts the encrypted third random number using a private key of the first node to obtain the third random number, including: the first node decrypts the encrypted third random number using the private key of the first node and a first encryption and decryption algorithm to obtain the third random number, and the first encryption and decryption algorithm is an encryption and decryption algorithm used by the first node for encryption and decryption of random numbers.
[0262] Alternatively, the method further includes: the first node obtaining a description document of the second node from the block chain nodes according to the identification information of the second node. The first node obtains information of a second encryption and decryption algorithm used by the second node for encryption and decryption of random numbers from the description document of the second node. The first node decrypts the encrypted third random number using a private key of the first node to obtain the third random number, including: the first node decrypts the encrypted third random number using the private key of the first node and the second encryption and decryption algorithm to obtain the third random number.
[0263] The first target attribute proof request message includes a fourth encrypted data set, the fourth encrypted data set being obtained by the second node encrypting a fourth data set using the public key of the first node, the fourth data set including information of the target attribute, identification information of the second node, and a fourth hash value obtained by performing a hash operation on the information of the target attribute or the identification information of the second node. The method further includes: the first node obtaining the fourth encrypted data set from the first target attribute proof request message; the first node decrypting the fourth encrypted data set using the private key of the first node to obtain the fourth data set; the first node obtaining a description document of the second node from the blockchain nodes according to the identification information of the second node included in the fourth data set; the first node obtaining the public key of the second node from the description document of the second node; the first node encrypting a fourth random number using the public key of the second node to obtain an encrypted fourth random number; the first node sending the encrypted fourth random number to the second node; the first node obtaining a fourth string sent by the second node, the fourth string being a string obtained by the second node performing a hash operation on the fourth random number, wherein the second node decrypts the encrypted fourth random number using the private key of the second node to obtain the fourth random number; the first node performs a hash operation on the fourth random number to obtain a fourth reference string; and the first node sends a second target attribute proof request message for requesting to prove that the first node has the target attribute to a certificate issuing end, including: if the fourth random number is the same as the fourth reference string, the first node sends the second target attribute proof request message for requesting to prove that the first node has the target attribute to the certificate issuing end.
[0264] If the fourth random number is identical to the fourth reference string, the first node sends a second target attribute proof request message for requesting the first node to prove the target attribute to a certificate issuer, including: if the fourth string is identical to the fourth reference string, the first node obtains identification information of the certificate issuer capable of providing a target attribute certificate from a block chain node; the first node obtains a description document of the certificate issuer from a block chain node according to the identification information of the certificate issuer; the first node obtains a public key of the certificate issuer from the description document of the certificate issuer; the first node encrypts a fifth data group using the public key of the certificate issuer to obtain a fifth encrypted data group, the fifth data group including information of the target attribute, identification information of the first node, identification information of the second node and a fifth hash value obtained by performing a hash operation on the information of the target attribute, the identification information of the first node and the identification information of the second node; and the first node sends the second target attribute proof request message including the fifth encrypted data group to the certificate issuer.
[0265] The first node can obtain the encrypted first random number sent by the certificate issuer, the encrypted first random number being obtained by the certificate issuer encrypting the first random number using the public key of the first node; the first node decrypts the encrypted first random number using the private key of the first node to obtain the first random number; the first node performs a hash operation on the first random number to obtain a first string; the first node sends the first string to the certificate issuer; and the first node obtains the instruction sent by the second node for indicating that the first node is allowed to perform trusted communication with the second node or the service content of the service, including: after the first node sends the first string to the certificate issuer, the first node obtains the instruction sent by the second node for indicating that the first node is allowed to perform trusted communication with the second node or the service content of the service.
[0266] In the above embodiment, when the authenticated node faces the requirement of the authentication node that the authenticated node provides a certificate for proving that the authenticated node has a certain attribute, the authenticated node can request the certificate issuer to provide the certificate to the authentication node. In this case, even if the authenticated node and the authentication node support different security authentication mechanisms, since the certificate issuer provides the certificate to the authentication node, the trusted communication between the authenticated node and the authentication node can be realized. Therefore, the embodiment of the application realizes the security authentication between the nodes supporting different security authentication mechanisms.
[0267] Corresponding to Figure 7According to the flow shown, the embodiment of the present application further provides a security authentication device, which can be applied to an authentication issuing end. As shown in Figure 10 As shown, the security authentication device comprises: a request message obtaining unit 1001, configured to obtain a second target attribute proof request message sent by a first node, the second target attribute proof request message being used to request proof that the first node has a target attribute, the second target attribute proof request message comprising identification information of a second node, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, and the second node being a node with which the first node needs to communicate; a target attribute certificate generating unit 1002, configured to generate a target attribute certificate for the target attribute by using the second security authentication mechanism, as a second security authentication mechanism target attribute certificate; and a sending unit 1003, configured to send the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, the second security authentication mechanism target attribute certificate being used by the second node to verify whether the first node has the target attribute.
[0268] The related features of the security authentication device can refer to the related descriptions of the above method embodiments, and will not be described here again.
[0269] Corresponding to Figure 11 According to the flow shown, the embodiment of the present application further provides a security authentication device, which can be applied to an authentication issuing end. As shown in Figure 9 As shown, the security authentication device comprises: a target attribute certificate obtaining unit 1101, configured to obtain a second security authentication mechanism target attribute certificate sent by a certificate issuing end, the second security authentication mechanism target attribute certificate being a target attribute certificate generated by the certificate issuing end for a target attribute by using a second security authentication mechanism, the target attribute being a target attribute possessed by a first node, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, and the second node being a node with which the first node needs to communicate; a signature data obtaining unit 1102, configured to obtain signature data of the certificate issuing end for the target attribute from the second security authentication mechanism target attribute certificate; and a verifying unit 1103, configured to verify the signature data of the target attribute by using the second security authentication mechanism, and if the verification is passed, determine that the first node has the target attribute.
[0270] The related features of the security authentication device can refer to the related descriptions of the above method embodiments, and will not be described here again.
[0271] Corresponding to Figure 12 According to the flow shown, the embodiment of the present application further provides a security authentication device, which can be applied to an authentication issuing end. As shown in Figure 13As shown, the security authentication apparatus comprises: a service request unit 1201 configured to send, to a second node, a service provision request message for requesting the second node to provide a service for the first node, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, and the second node being a node with which the first node needs to communicate; a request message obtaining unit 1202 configured to obtain a first target attribute proof request message sent by the second node and used for requesting to prove that the first node has a target attribute; a request message sending unit 1203 configured to send, to a certificate issuing end, a second target attribute proof request message used for requesting to prove that the first node has the target attribute; and a service obtaining unit 1204 configured to obtain an instruction sent by the second node and used for indicating that the first node is allowed to perform trusted communication with the second node or service content of the service.
[0272] The above security authentication apparatus can refer to the related descriptions of the above method embodiments for related features, which will not be described herein again.
[0273] In addition to the above method embodiments and apparatus embodiments, the embodiments of the present application further provide a security authentication system, comprising a first node, an authentication service end, and a second node; the first node is configured to send, to a second node, a service provision request message for requesting the second node to provide a service for the first node, obtain a first target attribute proof request message sent by the second node and used for requesting to prove that the first node has a target attribute, send, to a certificate issuing end, a second target attribute proof request message used for requesting to prove that the first node has the target attribute, the first node supporting a first security authentication mechanism, obtain an instruction sent by the second node and used for indicating that the first node is allowed to perform trusted communication with the second node or service content of the service, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, and the second node being a node with which the first node needs to communicate; the authentication service end is configured to obtain a second target attribute proof request message sent by the first node and used for requesting to prove that the first node has a target attribute, generate a target attribute certificate for the target attribute by using a second security authentication mechanism, take the second security authentication mechanism target attribute certificate as a second security authentication mechanism target attribute certificate, and send the second security authentication mechanism target attribute certificate to the second node; and the second node is configured to obtain, from the second security authentication mechanism target attribute certificate, signature data of the certificate issuing end for the target attribute, verify the signature data of the target attribute by using the second security authentication mechanism, and if the verification is passed, send, to the first node, an instruction used for indicating that the first node is allowed to perform trusted communication with the second node or service content of the service.
[0274] The related features of the security authentication system described above can refer to the related descriptions of the above method embodiments, which will not be repeated here.
[0275] The embodiments of the present application also provide an electronic device. As shown in The electronic device includes a processor 1301, a communication interface 1302, a memory 1303, and a communication bus 1304. The processor 1301, the communication interface 1302, and the memory 1303 communicate through the communication bus 1304. The memory 1303 stores a computer program. The computer program is executed by the processor 1301 to perform any one of the method embodiments described above.
[0276] The embodiments of the present application also provide a storage device. The storage device stores a computer program. The computer program is executed to perform any one of the method embodiments described above.
[0277] The embodiments of the present application also provide a computer readable storage medium. The computer readable storage medium stores a computer program. When the computer program is executed on a computer, the computer performs the method provided by the embodiments of the present application.
[0278] The embodiments of the present application also provide a computer program product. The computer program product includes a computer program. When the computer program is executed on a computer, the computer performs the method provided by the embodiments of the present application.
[0279] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that A exists alone, A and B exist together, and B exists alone. Wherein A and B can be singular or plural. The character " / " generally represents an "or" relationship between the front and rear associated objects. "At least one of the following" and similar expressions mean any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, and c can mean a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0280] Those of ordinary skill in the art can realize that the units and algorithm steps described in the embodiments disclosed herein can be realized in electronic hardware, computer software, and a combination of electronic hardware and computer software. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0281] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the system, device and unit described above can refer to the corresponding processes in the foregoing method embodiments, and will not be described here.
[0282] In several embodiments provided in the present application, any function, if realized in the form of a software function unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts of the technical solutions that make contributions to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (Read-Only Memory; hereinafter referred to as: ROM), a random access memory (Random Access Memory; hereinafter referred to as: RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0283] The above is merely specific embodiments of the present application, and any changes or replacements that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application shall be covered within the protection scope of the present application. The protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A security authentication method, characterized in that: include: The certificate issuing end obtains a second target attribute certification request message sent by the first node for requesting certification that the first node has the target attribute, the second target attribute certification request message including identification information of the second node, the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node with which the first node needs to communicate; The second target attribute certification request message is sent after the first node obtains the first target attribute certification request message sent by the second node for requesting to prove that the first node has the target attribute; The certificate issuing end generates a target attribute certificate for the target attribute using the second security authentication mechanism as the second security authentication mechanism target attribute certificate; The certificate issuing end sends the second security authentication mechanism target attribute certificate to the second node based on the identification information of the second node. The second security authentication mechanism target attribute certificate is used by the second node to verify whether the first node has the target attribute.
2. The security authentication method according to claim 1, wherein: The second target attribute certification request message also includes the following information: Information about the target attributes; identification information of the first node; A first hash value obtained by performing a hash operation on any one of the target attribute information, the identification information of the first node, and the identification information of the second node.
3. The security authentication method according to claim 2, characterized in that: Also includes: The certificate issuer obtains a first encrypted data group from the second target attribute certification request message, where the first encrypted data group is a data group obtained by the first node encrypting the first data group using the public key of the certificate issuer, and the first data group includes information about the target attribute, identification information of the first node, identification information of the second node, and the first hash value; The certificate issuing end uses the private key of the certificate issuing end to decrypt the first encrypted data group to obtain the first data group.
4. The security authentication method according to claim 1, wherein: Also includes: The certificate issuing end obtains a description document of the first node from the blockchain node according to the identification information of the first node; The certificate issuing end obtains the public key of the first node from the description document of the first node; The certificate issuing end encrypts the first random number using the public key of the first node to obtain an encrypted first random number; The certificate issuing end sends the encrypted first random number to the first node; The certificate issuing end obtains a first character string sent by the first node, where the first character string is a character string obtained by the first node performing a hash operation on the first random number, wherein the first node decrypts the encrypted first random number using the first node's private key to obtain the first random number; The certificate issuing end performs a hash operation on the first random number to obtain a character string as a first reference character string; The certificate issuing end uses a second security authentication mechanism to generate a target attribute certificate for the target attribute, including: if the first character string is the same as the first reference character string, using the second security authentication mechanism to generate a target attribute certificate for the target attribute.
5. The security authentication method according to claim 4, characterized in that: Also includes: The certificate issuing end obtains information of a first encryption and decryption algorithm used by the first node to encrypt and decrypt random numbers from a description document of the first node; The certificate issuing end encrypts the first random number using the public key of the first node to obtain the encrypted first random number, including: the certificate issuing end encrypts the first random number using the public key of the first node and the first encryption / decryption algorithm to obtain the encrypted first random number; The first node uses the private key of the first node to decrypt the encrypted first random number to obtain the first random number, including: the first node uses the private key of the first node and the first encryption and decryption algorithm to decrypt the encrypted first random number to obtain the first random number.
6. The security authentication method according to claim 4, characterized in that: The step of encrypting, by the certificate issuing end, the first random number using the public key of the first node to obtain the encrypted first random number includes: encrypting, by the certificate issuing end, the first random number using the public key of the first node and a third encryption / decryption algorithm used by the certificate issuing end for encryption / decryption of random numbers to obtain the encrypted first random number; The first node obtains information about a third encryption and decryption algorithm used by the certificate issuing end to encrypt and decrypt random numbers from a description document of the certificate issuing end, and the first node obtains the description document of the certificate issuing end from a blockchain node based on the identification information of the certificate issuing end; The first node uses the private key of the first node to decrypt the encrypted first random number to obtain the first random number, including: the first node uses the private key of the first node and the third encryption and decryption algorithm to decrypt the encrypted first random number to obtain the first random number.
7. The security authentication method according to claim 1, wherein: Also includes: The certificate issuing end obtains a description document of the second node from the blockchain node according to the identification information of the second node; The certificate issuing end obtains the security authentication mechanism identifier corresponding to the second node from the description document of the second node, where the security authentication mechanism identifier corresponding to the second node indicates that the second node supports a second security authentication mechanism.
8. The security authentication method according to claim 1, wherein: The second target attribute certification request message further includes a security authentication mechanism identifier for indicating that the second node supports a second security authentication mechanism; The method further comprises: The certificate issuing end obtains the security authentication mechanism identifier used to indicate that the second node supports the second security authentication mechanism from the second target attribute certification request message; The certificate issuing end determines, based on the security authentication mechanism identifier indicating that the second node supports the second security authentication mechanism, that the second node supports the second security authentication mechanism; In which, the first node obtains the security authentication mechanism identifier used to indicate that the second node supports the second security authentication mechanism from the description document of the second node, and the first node obtains the description document of the second node from the blockchain node according to the identification information of the second node.
9. The security authentication method according to claim 1, wherein: Also includes: The certificate issuing end generates a target attribute certificate for the target attribute using another security authentication mechanism supported by the certificate issuing end except the second security authentication mechanism as the other security authentication mechanism target attribute certificate; The certificate issuing end sends the other security authentication mechanism target attribute certificate to the second node according to the identification information of the second node; Among them, the second node selects the second security authentication mechanism target attribute certificate corresponding to the second security authentication mechanism from the second security authentication mechanism target attribute certificate and the other security authentication mechanism target attribute certificates to verify whether the first node has the target attribute.
10. The security authentication method according to claim 1, wherein: Also includes: The certificate issuing end obtains a description document of the second node from the blockchain node according to the identification information of the second node; The certificate issuing end obtains the public key of the second node from the description document of the second node; The certificate issuing end encrypts the second data group using the public key of the second node to obtain a second encrypted data group, where the second data group includes the second security authentication mechanism target attribute certificate, the identification information of the certificate issuing end, and a second hash value, where the second hash value is a hash value obtained by performing a hash operation on the second security authentication mechanism target attribute certificate or the identification information of the certificate issuing end; The certificate issuing end sends the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, including: the certificate issuing end sends the second encrypted data group to the second node according to the identification information of the second node.
11. The security authentication method according to claim 1, wherein: The first security authentication mechanism is a security authentication mechanism selected from the group consisting of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism; The second security authentication mechanism is a security authentication mechanism selected from the group consisting of the X.509 security authentication mechanism, the SM2 security authentication mechanism, and the SM9 security authentication mechanism.
12. The security authentication method according to claim 1, wherein: The first node is one of the on-board unit, roadside unit, and service provider unit in the vehicle-road collaboration scenario; The second node is one of the on-board unit, roadside unit, and service provider unit in the vehicle-road collaboration scenario.
13. A security authentication method, characterized in that: include: The second node obtains a second security authentication mechanism target attribute certificate sent by the certificate issuing end, where the second security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuing end using the second security authentication mechanism for a target attribute, the target attribute being a target attribute possessed by the first node, the first node supporting the first security authentication mechanism, the second node supporting the second security authentication mechanism, and the second node being a node with which the first node needs to communicate; The second node obtains the signature data of the certificate issuing end for the target attribute from the second security authentication mechanism target attribute certificate; The second node verifies the signature data of the target attribute using the second security authentication mechanism, and if the verification succeeds, determines that the first node has the target attribute.
14. The security authentication method according to claim 13, wherein: The second node obtains the second security authentication mechanism target attribute certificate sent by the certificate issuing end, including: The second node obtains a second encrypted data group sent by the certificate issuer, where the second encrypted data group is obtained by the certificate issuer encrypting a second data group using the public key of the second node, where the second data group includes the second security authentication mechanism target attribute certificate, identification information of the certificate issuer, and a second hash value, where the second hash value is a hash value obtained by performing a hash operation on the second security authentication mechanism target attribute certificate or the identification information of the certificate issuer; The second node decrypts the second encrypted data group using the private key of the second node to obtain the second data group.
15. The security authentication method according to claim 14, characterized in that: Also includes: The second node obtains a description document of the certificate issuing end from a blockchain node according to the identification information of the certificate issuing end; The second node obtains the public key of the certificate issuing end from the description document of the certificate issuing end; The second node encrypts the second random number using the public key of the certificate issuing end to obtain an encrypted second random number; The second node sends the encrypted second random number to the certificate issuing end; The second node obtains, by the certificate issuing end, a second character string sent by the certificate issuing end, where the second character string is a character string obtained by the certificate issuing end performing a hash operation on the second random number, wherein the certificate issuing end decrypts the encrypted second random number using the private key of the certificate issuing end to obtain the second random number; The second node performs a hash operation on the second random number to obtain a character string as a second reference character string; The second node obtains the signature data of the certificate issuer for the target attribute from the second security authentication mechanism target attribute certificate, including: if the second character string is the same as the second reference character string, the second node obtains the signature data of the certificate issuer for the target attribute from the second security authentication mechanism target attribute certificate.
16. The security authentication method according to claim 15, characterized in that: Also includes: The second node obtains information of a third encryption and decryption algorithm used by the certificate issuing end to encrypt and decrypt the random number from a description document of the certificate issuing end; The second node encrypts the second random number using the public key of the certificate issuer to obtain the encrypted second random number, including: the second node encrypts the second random number using the public key of the certificate issuer and the third encryption / decryption algorithm to obtain the encrypted second random number; The certificate issuing end uses the private key of the certificate issuing end to decrypt the encrypted second random number to obtain the second random number, including: the certificate issuing end uses the private key of the certificate issuing end and the third encryption and decryption algorithm to decrypt the encrypted second random number to obtain the second random number.
17. The security authentication method according to claim 15, characterized in that: The second node encrypts the second random number using the public key of the certificate issuer to obtain the encrypted second random number, including: the second node encrypts the second random number using the public key of the certificate issuer and a second encryption and decryption algorithm used by the second node for encryption and decryption of random numbers to obtain the encrypted second random number; The certificate issuing end obtains information about the second encryption and decryption algorithm used by the second node to encrypt and decrypt the random number from the description document of the second node, and the certificate issuing end obtains the description document of the second node from the blockchain node based on the identification information of the second node; The certificate issuing end uses the private key of the certificate issuing end to decrypt the encrypted second random number to obtain the second random number, including: the certificate issuing end uses the private key of the certificate issuing end and the second encryption and decryption algorithm to decrypt the encrypted second random number to obtain the second random number.
18. The security authentication method according to claim 13, wherein: Also includes: The second node obtains, from the second security authentication mechanism target attribute certificate, a verification parameter for verifying the signature data of the target attribute; The second node verifies the signature data of the target attribute by using the second security authentication mechanism, including: the second node verifies the signature data of the target attribute by using the second security authentication mechanism and the verification parameter.
19. The security authentication method according to claim 13, wherein: Also includes: The second node obtains the other security authentication mechanism target attribute certificate sent by the certificate issuing end, where the other security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuing end for the target attribute using another security authentication mechanism supported by the certificate issuing end except the second security authentication mechanism; The second node selects the second security authentication mechanism target attribute certificate corresponding to the second security authentication mechanism from the second security authentication mechanism target attribute certificate and the other security authentication mechanism target attribute certificates to verify whether the first node has the target attribute.
20. The security authentication method according to claim 13, wherein: Also includes: The second node obtains a service provision request message sent by the first node for requesting the second node to provide a service for the first node; The second node sends a first target attribute certification request message to the first node for requesting certification that the first node has a target attribute; The second node obtains the second security authentication mechanism target attribute certificate sent by the certificate issuing end, including: after the second node sends the first target attribute certification request message to the first node, obtaining the second security authentication mechanism target attribute certificate sent by the certificate issuing end; The method also includes: after the second node verifies the signature data of the target attribute using the second security authentication mechanism, the second node sends an instruction to the first node to indicate that the first node is allowed to communicate with the second node in a trusted manner, or the second node sends the service content of the service to the first node.
21. The security authentication method according to claim 20, wherein: The service provision request message includes a third encrypted data group, where the third encrypted data group is a data group obtained by encrypting the third data group by the first node using the public key of the second node, and the third data group includes identification information of the first node, service information indicating the service requested by the first node, and a third hash value obtained by performing a hash operation on the identification information of the first node or the service information; The method further comprises: The second node obtains the third encrypted data group from the service provision request message; The second node decrypts the third encrypted data group using the private key of the second node to obtain the third data group; The second node obtains a description document of the first node from a blockchain node according to the identification information of the first node included in the third data group; The second node obtains the public key of the first node from the description document of the first node; The second node encrypts the third random number using the public key of the first node to obtain an encrypted third random number; The second node sends the encrypted third random number to the first node; The second node obtains, by the first node, a third character string sent by the first node, where the third character string is a character string obtained by the first node performing a hash operation on the third random number, wherein the first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number; The second node performs a hash operation on the third random number to obtain a character string as a third reference character string; The second node sends a first target attribute proof request message to the first node for requesting proof that the first node has the target attribute, including: if the third character string is the same as the third benchmark character string, the second node sends a first target attribute proof request message to the first node for requesting proof that the first node has the target attribute.
22. The security authentication method according to claim 21, characterized in that: Also includes: The second node obtains, from a description document of the first node, information about a first encryption and decryption algorithm used by the first node to encrypt and decrypt random numbers; The second node encrypts the third random number using the public key of the first node to obtain the encrypted third random number, including: the second node encrypts the third random number using the public key of the first node and the first encryption / decryption algorithm to obtain the encrypted third random number; The first node uses the private key of the first node to decrypt the encrypted third random number to obtain the third random number, including: the first node uses the private key of the first node and the first encryption and decryption algorithm to decrypt the encrypted third random number to obtain the third random number.
23. The security authentication method according to claim 21, wherein: The second node encrypting the third random number using the public key of the first node to obtain the encrypted third random number includes: the second node encrypting the third random number using the public key of the first node and a second encryption and decryption algorithm used by the second node for encryption and decryption of random numbers to obtain the encrypted third random number; The first node obtains information about a second encryption and decryption algorithm used by the second node to encrypt and decrypt random numbers from a description document of the second node, and the first node obtains the description document of the second node from a blockchain node based on the identification information of the second node; The first node uses the private key of the first node to decrypt the encrypted third random number to obtain the third random number, including: the first node uses the private key of the first node and the second encryption and decryption algorithm to decrypt the encrypted third random number to obtain the third random number.
24. The security authentication method according to claim 21, wherein: Also includes: The second node obtains information about the target attribute; The second node sends a first target attribute certification request message to the first node for requesting certification that the first node has a target attribute, including: The second node encrypts a fourth data group using the public key of the first node to obtain a fourth encrypted data group, where the fourth data group includes information about the target attribute, identification information of the second node, and a fourth hash value obtained by performing a hash operation on the information about the target attribute or the identification information of the second node; The second node sends a first target attribute certification request message including the fourth encrypted data group to the first node.
25. The security authentication method according to claim 24, characterized in that: Also includes: The second node obtains the encrypted fourth random number sent by the first node; The second node decrypts the encrypted fourth random number using the private key of the second node to obtain the fourth random number; The second node performs a hash operation on the fourth random number to obtain a fourth character string; The second node sends the fourth character string to the first node; Among them, the first node performs a hash operation on the fourth random number to obtain a fourth reference string. If the fourth string is the same as the fourth reference string, the identification information of the certificate issuing end that can provide the target attribute certificate is obtained from the blockchain node, the description document of the certificate issuing end is obtained from the blockchain node according to the identification information of the certificate issuing end, the public key of the certificate issuing end is obtained from the description document of the certificate issuing end, the fifth data group is encrypted using the public key of the certificate issuing end to obtain a fifth encrypted data group, and a second target attribute certification request message for requesting proof that the first node has the target attribute is sent to the certificate issuing end. The second target attribute certification request message includes the fifth encrypted data group. The fifth data group includes information about the target attribute, identification information of the first node, identification information of the second node, and a fifth hash value obtained by hashing the information about the target attribute, the identification information of the first node, and the identification information of the second node.
26. The security authentication method according to claim 25, characterized in that: The encrypted fourth random number is obtained in the following manner: The first node obtains the fourth encrypted data group from the first target attribute certification request message; The first node decrypts the fourth encrypted data group using the private key of the first node to obtain the fourth data group; The first node obtains a description document of the second node from a blockchain node according to the identification information of the second node included in the fourth data group; The first node obtains the public key of the second node from the description document of the second node; The first node encrypts the fourth random number using the public key of the second node to obtain the encrypted fourth random number.
27. The security authentication method according to claim 24, characterized in that: The second node obtains the target attribute information, including: The second node obtains, according to the service information, service characteristic data of the service requested by the first node; The target attribute information required for the node enjoying the service is obtained according to the service characteristic data.
28. The security authentication method according to claim 13, wherein: The first security authentication mechanism is a security authentication mechanism selected from the group consisting of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism; The second security authentication mechanism is a security authentication mechanism selected from the group consisting of the X.509 security authentication mechanism, the SM2 security authentication mechanism, and the SM9 security authentication mechanism.
29. The security authentication method according to claim 13, wherein: The first node is one of the on-board unit, roadside unit, and service provider unit in the vehicle-road collaboration scenario; The second node is one of the on-board unit, roadside unit, and service provider unit in the vehicle-road collaboration scenario.
30. A security authentication method, characterized in that: include: A first node sends a service provision request message to a second node, requesting the second node to provide a service for the first node, where the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node with which the first node needs to communicate; The first node obtains a first target attribute certification request message sent by the second node for requesting certification that the first node has a target attribute; The first node sends a second target attribute certification request message to the certificate issuing end for requesting certification that the first node has the target attribute; the second target attribute certification request message includes identification information of the second node, and the second target attribute certification request message is used to enable the certificate issuing end to use a second security authentication mechanism to generate a target attribute certificate for the target attribute as a second security authentication mechanism target attribute certificate, and send the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, and the second security authentication mechanism target attribute certificate is used by the second node to verify whether the first node has the target attribute; The first node obtains the instruction sent by the second node, which indicates that the first node is allowed to perform trusted communication with the second node, or the service content of the service.
31. The security authentication method according to claim 30, characterized in that: Also includes: The first node sends a second node search request message to the blockchain node for searching for a second node that can provide the service for the first node; The first node obtains the identification information of the second node sent by the blockchain node; The first node obtains a description document of the second node from the blockchain node according to the identification information of the second node; The first node obtains the public key of the second node from the description document of the second node; The first node encrypts a third data group using the public key of the second node to obtain a third encrypted data group, where the third data group includes identification information of the first node, service information indicating a service requested by the first node, and a third hash value obtained by performing a hash operation on the identification information of the first node or the service information. The first node sends a service provision request message to the second node for requesting the second node to provide a service for the first node, including: the first node sends a service provision request message including the third encrypted data group to the second node.
32. The security authentication method according to claim 31, characterized in that: The second node is the second node that is closest to the first node among all second nodes.
33. The security authentication method according to claim 30, characterized in that: Also includes: The first node obtains the encrypted third random number sent by the second node, where the encrypted third random number is obtained by the second node encrypting the third random number using the public key of the first node; The first node decrypts the encrypted third random number using the private key of the first node to obtain the third random number; The first node performs a hash operation on the third random number to obtain a third character string; The first node sends the third character string to the second node; The first node obtains a first target attribute proof request message sent by the second node for requesting proof that the first node has the target attribute, including: after the first node sends the third character string to the second node, the first node obtains the first target attribute proof request message sent by the second node for requesting proof that the first node has the target attribute.
34. The security authentication method according to claim 33, characterized in that: The first node decrypting the encrypted third random number using the private key of the first node to obtain the third random number includes: the first node decrypting the encrypted third random number using the private key of the first node and a first encryption / decryption algorithm to obtain the third random number, where the first encryption / decryption algorithm is an encryption / decryption algorithm used by the first node to encrypt and decrypt random numbers; Alternatively, the method further comprises: The first node obtains a description document of the second node from a blockchain node according to the identification information of the second node; The first node obtains information of a second encryption and decryption algorithm used by the second node to encrypt and decrypt random numbers from a description document of the second node; The first node uses the private key of the first node to decrypt the encrypted third random number to obtain the third random number, including: the first node uses the private key of the first node and the second encryption and decryption algorithm to decrypt the encrypted third random number to obtain the third random number.
35. The security authentication method according to claim 30, characterized in that: The first target attribute certification request message includes a fourth encrypted data group, where the fourth encrypted data group is obtained by the second node encrypting a fourth data group using the public key of the first node, the fourth data group including information about the target attribute, identification information of the second node, and a fourth hash value obtained by performing a hash operation on the information about the target attribute or the identification information of the second node; The method further comprises: The first node obtains the fourth encrypted data group from the first target attribute certification request message; The first node decrypts the fourth encrypted data group using the private key of the first node to obtain the fourth data group; The first node obtains a description document of the second node from a blockchain node according to the identification information of the second node included in the fourth data group; The first node obtains the public key of the second node from the description document of the second node; The first node encrypts the fourth random number using the public key of the second node to obtain the encrypted fourth random number; The first node sends the encrypted fourth random number to the second node; The first node obtains a fourth character string sent by the second node, where the fourth character string is a character string obtained by the second node performing a hash operation on the fourth random number, wherein the second node decrypts the encrypted fourth random number using the second node's private key to obtain the fourth random number; The first node performs a hash operation on the fourth random number to obtain a fourth reference character string; The first node sends a second target attribute certification request message to the certificate issuing end for requesting proof that the first node has the target attribute, including: if the fourth random number is the same as the fourth reference string, the first node sends a second target attribute certification request message to the certificate issuing end for requesting proof that the first node has the target attribute.
36. The security authentication method according to claim 35, characterized in that: If the fourth random number is identical to the fourth reference character string, the first node sending a second target attribute certification request message to the certificate issuing end for requesting certification that the first node has the target attribute, including: If the fourth character string is identical to the fourth reference character string, the first node obtains identification information of the certificate issuing end capable of providing the target attribute certificate from the blockchain node; The first node obtains a description document of the certificate issuing end from a blockchain node according to the identification information of the certificate issuing end; The first node obtains the public key of the certificate issuing end from the description document of the certificate issuing end; The first node encrypts a fifth data group using the public key of the certificate issuer to obtain a fifth encrypted data group, where the fifth data group includes the target attribute information, the identification information of the first node, the identification information of the second node, and a fifth hash value obtained by performing a hash operation on the target attribute information, the identification information of the first node, and the identification information of the second node; The first node sends a second target attribute certification request message including the fifth encrypted data group to the certificate issuing end.
37. The security authentication method according to claim 30, characterized in that: Also includes: The first node obtains the encrypted first random number sent by the certificate issuer, where the encrypted first random number is obtained by the certificate issuer encrypting the first random number using the public key of the first node; The first node decrypts the encrypted first random number using the private key of the first node to obtain the first random number; The first node performs a hash operation on the first random number to obtain a first character string; The first node sends the first character string to the certificate issuing end; The first node obtains the instruction sent by the second node for indicating that the first node and the second node are allowed to communicate with each other in a trusted manner or the service content of the service, including: after the first node sends the first character string to the certificate issuing end, the first node obtains the instruction sent by the second node for indicating that the first node and the second node are allowed to communicate with each other in a trusted manner or the service content of the service.
38. The security authentication method according to claim 30, characterized in that: The first security authentication mechanism is a security authentication mechanism selected from the group consisting of an X.509 security authentication mechanism, an SM2 security authentication mechanism, and an SM9 security authentication mechanism; The second security authentication mechanism is a security authentication mechanism selected from the group consisting of the X.509 security authentication mechanism, the SM2 security authentication mechanism, and the SM9 security authentication mechanism.
39. The security authentication method according to claim 30, characterized in that: The first node is one of the on-board unit, roadside unit, and service provider unit in the vehicle-road collaboration scenario; The second node is one of the on-board unit, roadside unit, and service provider unit in the vehicle-road collaboration scenario.
40. A security authentication device, characterized in that: Applied to the authentication issuing end, the device includes: a request message obtaining unit, configured to obtain a second target attribute certification request message sent by a first node for requesting certification that the first node has a target attribute, the second target attribute certification request message including identification information of a second node, the first node supporting a first security authentication mechanism, the second node supporting a second security authentication mechanism, and the second node being a node with which the first node needs to communicate; the second target attribute certification request message being sent by the first node after the first node obtains the first target attribute certification request message sent by the second node for requesting certification that the first node has a target attribute; a target attribute certificate generating unit, configured to generate a target attribute certificate for the target attribute using a second security authentication mechanism as a second security authentication mechanism target attribute certificate; A sending unit is used to send the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, and the second security authentication mechanism target attribute certificate is used by the second node to verify whether the first node has the target attribute.
41. A security authentication device, characterized in that: Applied to the second node, the apparatus includes: a target attribute certificate obtaining unit, configured to obtain a second security authentication mechanism target attribute certificate sent by a certificate issuing end, where the second security authentication mechanism target attribute certificate is a target attribute certificate generated by the certificate issuing end using the second security authentication mechanism for a target attribute, where the target attribute is a target attribute possessed by a first node, the first node supports the first security authentication mechanism, the second node supports the second security authentication mechanism, and the second node is a node with which the first node needs to communicate; A signature data obtaining unit, configured to obtain the signature data of the certificate issuing end for the target attribute from the target attribute certificate of the second security authentication mechanism; A verification unit is configured to verify the signature data of the target attribute using the second security authentication mechanism, and if the verification succeeds, determine that the first node has the target attribute.
42. A security authentication device, characterized in that: Applied to a first node, the apparatus includes: a service request unit, configured to send a service provision request message to a second node, requesting the second node to provide a service for the first node, where the first node supports a first security authentication mechanism, the second node supports a second security authentication mechanism, and the second node is a node with which the first node needs to communicate; a request message obtaining unit, configured to obtain a first target attribute certification request message sent by the second node for requesting certification that the first node has a target attribute; A request message sending unit is used to send a second target attribute certification request message to the certificate issuing end for requesting certification that the first node has the target attribute; the second target attribute certification request message includes identification information of the second node, and the second target attribute certification request message is used to enable the certificate issuing end to use a second security authentication mechanism to generate a target attribute certificate as a second security authentication mechanism target attribute certificate for the target attribute, and send the second security authentication mechanism target attribute certificate to the second node according to the identification information of the second node, and the second security authentication mechanism target attribute certificate is used by the second node to verify whether the first node has the target attribute; The service obtaining unit is configured to obtain an instruction sent by the second node indicating that the first node is allowed to perform trusted communication with the second node or the service content of the service.
43. A security authentication system, characterized in that: It includes a first node, an authentication server, and a second node; The first node is configured to send a service provision request message to a second node for requesting the second node to provide a service for the first node, obtain a first target attribute certification request message sent by the second node for requesting certification that the first node has a target attribute, and send a second target attribute certification request message to a certificate issuer for requesting certification that the first node has the target attribute, wherein the first node supports a first security authentication mechanism, obtain an instruction sent by the second node for indicating that the first node is allowed to perform trusted communication with the second node or the service content of the service, wherein the first node supports the first security authentication mechanism, the second node supports the second security authentication mechanism, and the second node is a node with which the first node needs to communicate; The authentication server is configured to obtain a second target attribute certification request message sent by the first node for requesting certification that the first node has the target attribute, generate a target attribute certificate for the target attribute using a second security authentication mechanism as the second security authentication mechanism target attribute certificate, and send the second security authentication mechanism target attribute certificate to the second node; The second node is used to obtain the signature data of the certificate issuer for the target attribute from the target attribute certificate of the second security authentication mechanism, and use the second security authentication mechanism to verify the signature data of the target attribute. If the verification passes, an instruction or the service content of the service is sent to the first node to indicate that the first node and the second node are allowed to communicate trustedly.
44. An electronic device, characterized in that The method comprises a processor and a memory, wherein the memory stores a computer program, and the computer program is executed by the processor to perform the method according to any one of claims 1 to 39.
45. A storage device, characterized in that The storage device stores a computer program, and the computer program executes the method according to any one of claims 1 to 39 after being run.
Citation Information
Patent Citations
Solution for identifying legitimate user equipment in communication networks
CN102273239A
Cross-domain authentication method of heterogeneous Internet of Things
CN111447187A