An efficient handover authentication method based on social relationship in mobile edge computing
By building social relationships between edge servers and using blockchain to store trust relationships, target edge servers are screened for authentication-free judgment, solving the problems of frequent authentication and security risks in mobile edge computing, and achieving efficient and secure service switching.
Patent Information
- Application Number
- CN202410765140.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-14
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-06-14
AI Technical Summary
In mobile edge computing, existing authentication switching methods result in frequent authentication, incompatibility with low-power mobile terminals, poor service continuity, and security risks.
By building social relationships between edge servers and using blockchain to store trust relationships, the system can filter and determine whether a target edge server can be accessed without authentication, reducing the authentication load on mobile devices. It also optimizes the authentication process using social trust and enables the switching of authentication-free access.
It improves switching efficiency, reduces the authentication load on mobile terminals, shortens authentication time, ensures service continuity and security, and is suitable for low-power mobile terminals.
Smart Images

Figure CN118764858B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security and identity verification, and particularly relates to an efficient switching authentication method based on social relationships in mobile edge computing. BACKGROUND
[0002] The rapid development of the Internet has led to a significant increase in data volume, which has driven the rapid development of cloud computing. Cloud computing aims to reduce the heavy burden on users with powerful computing and storage capabilities. However, in the mobile scenario, the cloud computing model has the problems of high long-distance network transmission delay and large network bandwidth pressure due to the concentration of computing resources in remote data centers. To solve these problems, mobile edge computing (MEC) is a solution. MEC is a computing architecture similar to cloud computing, which transfers computing and storage resources from traditional centralized cloud data centers to edge servers (ES) close to terminal devices. By distributing computing resources at the edge, MEC can better meet the needs of application scenarios with low latency and high real-time requirements.
[0003] In mobile edge computing, switching authentication refers to the process of re-authenticating to obtain new connection credentials when a terminal user moves from one ES to another. The purpose of the identity verification process is to ensure the security of the overall service. However, the current switching authentication method still has challenges in solving the problem of service continuity.
[0004] On the one hand, more service nodes bring more authentication needs. When a terminal user leaves the service range of the current ES and enters the service range of another ES, re-authentication is required to obtain new connection credentials. A large number of switching authentications limit service continuity and affect user experience during mobile device use.
[0005] On the other hand, with a large number of ESs accessing mobile edge computing, the probability of malicious nodes existing in the ES also increases, thereby bringing security risks. These malicious nodes may attempt to tamper with, steal, or destroy user data, endangering the security and stability of the entire system. Therefore, users urgently need a solution that can protect the security of the switching process while improving the efficiency of switching authentication.
[0006] Currently, the existing handover authentication methods at home and abroad are mainly divided into three types: pre-authentication, cache authentication and optimization algorithm and authentication framework. Pre-authentication is to authenticate the upcoming mobile terminal in advance on the premise of knowing the motion trajectory; cache authentication is to save historical authentication information to reduce the authentication steps of the terminal; optimization algorithm and authentication framework mainly reduce the authentication overhead by optimizing the encryption algorithm and authentication process, thereby improving the efficiency of authentication. However, these methods mostly need to store a large amount of authentication information in the mobile terminal, which cannot be deployed to low-power mobile terminals.
[0007] To solve the current handover authentication related problems, the application proposes an efficient handover authentication method based on social relationship, aiming to realize more efficient service handover in mobile edge computing. In view of the problem of high authentication load of mobile terminal in the handover process, the social relationship between ES is established based on bidirectional authentication, and the social circle belonging to each ES is constructed, and the social relationship is used to replace part of the authentication process, so as to reduce the authentication load of the mobile terminal. In view of the problem of frequent authentication of terminal user, a handover authentication-free mechanism is invented, including the selection of target edge server (ES B ) and authentication-free judgment, reasonably allocating the overall handover times of terminal user in the mobile process, and optimizing the authentication process from the perspective of social trust to improve the handover efficiency. The application has high practical significance and good application prospect in the field of future mobile edge computing. SUMMARY
[0008] The purpose of the application is to propose an efficient handover method in mobile edge computing, to solve the problems of frequent authentication, incompatibility with low-power mobile terminals, poor service continuity and other problems in the traditional handover process.
[0009] To achieve the above purpose, the technical solution adopted by the embodiments of the present application is:
[0010] An efficient handover authentication method based on social relationship in mobile edge computing is applied to a mobile edge computing scene containing a mobile terminal (MT), an edge server (ES) and a blockchain, which is composed of an edge server social relationship establishment mechanism and a handover authentication-free judgment mechanism, and specifically includes the following steps:
[0011] Step S1: The edge servers (ES) construct social relationship through bidirectional authentication, so as to establish their own social circle, and save the social relationship in the blockchain.
[0012] The social relationship is that the edge server (ES) uses redundant computing resources to build social relationship with other edge servers (ES S) between them, thereby obtaining a mutually trusted relationship; this trusted relationship can be partially transferred, i.e., A trusts B, B trusts X, and therefore A can partially trust X; multiple trust relationships can be fused, i.e., A can combine the trust degrees of B and C for X and his own understanding of X to obtain a more reliable trust degree for X; and the social trust relationship decays over time.
[0013] The two-way authentication specifically refers to a process in which two edge servers (ES) establish a social relationship with each other through identity authentication and integrity authentication; the social relationship can replace the real-time authentication process in the switching process to some extent.
[0014] The establishment of the social circle specifically refers to the fact that an edge server (ES) uniformly manages other edge servers (ES S with which it has a social relationship, thereby forming a social circle belonging to it; similarly, other edge servers (ES S ) can also construct their own social circles in this way.
[0015] Step S2: Screening and determining whether the edge server (ES) can be authenticated to access the mobile terminal (MT), screening the target edge server (ES B according to the existing social relationship, and determining whether the screened target edge server (ES B ) can be authenticated.
[0016] The screening of the target edge server (ES B ) specifically refers to the selection of a suitable target edge server (ES B ) through the proximity between the currently connected edge server (ES A ) and the target edge server (ES B ) to be selected, the matching degree of the social circle, and the moving direction of the terminal mobile user, thereby reasonably planning the overall number of handovers and achieving a balance between efficiency and security; the matching degree of the social circle specifically refers to the fact that the social circles of different edge servers (ES) can overlap, i.e., multiple edge servers (ES) can have a same "friend" relationship, and the number and activity level of the "friend" determine the matching degree of the social circle.
[0017] The authentication determination specifically refers to the calculation of the final trust degree between the screened target edge server (ES B ) and the currently connected edge server (ES A ), and the conversion of the calculation position from both the terminal user and the target edge server (ES B ) to the target edge server (ES B ) and the currently connected edge server (ES A) can achieve fast switching even if the terminal user is low-power.
[0018] The target edge server (ES B ) and the final trust between the currently connected edge server (ES A ) is specifically: using the social relationship, location information and service history and other data of the currently connected edge server (ES A ) and the target edge server (ES B ) recorded in the blockchain ledger, the final trust result is calculated by polynomial; When the final trust is higher than the trust threshold, the authentication-free service node change can be performed; The original identity authentication calculation is converted into trust calculation, the calculation position is changed and the calculation amount is reduced, the two-way authentication between the terminal mobile user and the target edge server (ES B ) is converted into the final trust between the target edge server (ES B ) and the currently connected edge server (ES A ), and the calculation position is changed from the terminal user and the target edge server (ES B ) to the target edge server (ES B ) and the currently connected edge server (ES A ), so as to meet the use scene of low-power mobile terminal.
[0019] The identity authentication calculation is converted into trust calculation, specifically: using the social relationship, location information and service history and other data of the currently connected edge server (ES A ) and the target edge server (ES B ) recorded in the blockchain ledger, the two-way authentication between the terminal mobile user and the target edge server (ES B ) is converted into the final trust between the target edge server (ES B ) and the currently connected edge server (ES A ); When the final trust is higher than the trust threshold, the authentication-free service node change can be performed.
[0020] Step S3: complete service switching, for the target edge server (ES B ) determined by the authentication-free judgment, the connection between the mobile terminal (MT) and the target edge server (ES A ) can be established, and the service is provided, while the connection between the mobile terminal (MT) and the currently connected edge server (ES A ) is interrupted.
[0021] The application further provides a high-efficiency switching authentication system based on social relations in mobile edge computing.
[0022] Compared with the prior art, the application has the beneficial effects as follows:
[0023] The application replaces part of the authentication mechanism with social relations, changes the original bidirectional authentication between the mobile terminal user and the ES into the final trust degree between the target edge server (ES B ) and the currently connected edge server (ES A ), and changes the calculation position from both the terminal user and the target edge server (ES B ) to the target edge server (ES B ) and the currently connected edge server (ES A ), so as to meet the demand of the low-power terminal user for fast switching. The application designs a switching authentication-free judgment mechanism, which includes selecting the target edge server (ES B ) and judging whether the ES B is authentication-free, fully considers the influence of different factors on the switching frequency and security, selects the appropriate target edge server (ES B ), and thus balances the efficiency and security during switching. The application reduces the real-time authentication process during switching, replaces the original complicated authentication process with the judgment of the social trust degree, and solves the service interruption problem caused by the long authentication time during switching. Based on this, the high-efficiency switching authentication method based on social relations in mobile edge computing provided by the application can effectively solve the deficiency of the current mobile user during switching. BRIEF DESCRIPTION OF DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description.
[0025] Figure 1 is a whole scheme model schematic diagram provided by the embodiments of the application, which describes the interaction steps of each entity and between the entities during switching.
[0026] Figure 2 is a flowchart of bidirectional authentication and social circle establishment provided by the embodiments of the application, which explains the specific flow steps of establishing the social circle in Figure 1 .
[0027] Figure 3 is a flowchart of the target edge server (ES B ) selection process according to the embodiments of the present application, which explains the specific process steps of selecting the next connected ES in Figure 1
[0028] Figure 4 is a flowchart of the authentication-free judgment process according to the embodiments of the present application, which explains the specific process steps of calculating the trust between the currently connected edge server (ES A ) and the target edge server (ES B ) in Figure 1
[0029] Figure 5 shows the comparison experimental results of the number of switching authentication times between the embodiments of the present application and other similar schemes as the number of mobile devices increases.
[0030] Figure 6 shows the comparison experimental results of the authentication time between the embodiments of the present application and other similar schemes as the number of mobile devices increases. DETAILED DESCRIPTION
[0031] The present application proposes an efficient switching authentication method based on social relationship in mobile edge computing, which is composed of edge server social relationship establishment mechanism and switching authentication-free judgment mechanism, and is applied to a mobile edge computing scenario containing mobile terminal (MT), edge server (ES) and blockchain; specifically including the following steps:
[0032] Step S1: The edge servers (ES) build social relationships through mutual authentication, thereby establishing their own social circles, and save the social relationships in the blockchain;
[0033] Step S2: Filter and judge whether the target edge server (ES B ) can access the mobile terminal (MT) without authentication, filter the target edge server (ES B ) according to the existing social relationship, and make authentication-free judgment on the filtered target edge server (ES B );
[0034] Step S3: Complete service switching, and for the target edge server (ES B ) that passes the authentication-free judgment, establish a connection with the mobile terminal (MT) and provide services for it, while interrupting the connection between the mobile terminal (MT) and the currently connected edge server (ES A ).
[0035] This embodiment focuses on two key elements: the initial establishment of social relationships and the ES authentication-free determination. Figure 1 As shown, the process can be summarized as follows: First, initialize the social relationships between ES servers to establish their own social circles; second, use the established social relationships to filter out target edge servers (ES servers). B Then, an authentication-free judgment mechanism is used to screen the target edge servers (ES). B The system determines whether an unauthenticated user can access the terminal user's service and then switches the service.
[0036] The model consists of three entities: edge server (ES), mobile terminal (MT), and distributed blockchain.
[0037] Step S1: Initialization Phase: ES A Obtain other ES from the blockchain S Location information ES A Execution and ES S Distance calculation using the formula And filter out ES within its own service scope S Randomly select several ES S Perform two-way identity authentication and integrity authentication and become its social node, ES A To ES S Send timestamp T1, itself And M1, hash value ES S Received from ES A After obtaining the information, check the timestamp T1 and And repeat the calculation and verification. Secondly, ES S ES in the verification blockchain A Inform ES of identity and location information. A Whether to perform two-way authentication; finally, after completing two-way authentication, each party uses their private key to sign a social transaction, submits it to the consensus node, and saves it to the blockchain, ultimately forming a social circle. The specific process is as follows: Figure 2 As shown.
[0038] Step S2: Target ES Selection Phase: First, the MT selects the target ES from the currently connected ES. A Send its subsequent movement direction; secondly, ES A Based on the movement direction information sent by the MT, select several candidate ESs in that direction. i and obtain ES from the blockchain i of and Information such as... Secondly, through polynomials... Calculate the weights of the candidate nodes. Where L is the ES value. A With ES i The distance is T3, where T3 is the current timestamp. Finally, the weighted node is selected as the ES. B The specific process is as follows: Figure 3 As shown.
[0039] Step S3: ES Authentication-Free Determination Phase: Based on the selected ES nodes to be accessed B Calculate its connection with the current ES A Mutual trust between them. Similar to the screening phase, firstly, it is necessary to go through a polynomial... Calculate the mutual weights of the two; then, calculate ES separately. B In ES A Reputation value and ES A In ES B Reputation value Finally, the judgment and If all thresholds are exceeded, then authentication exemption is granted. The specific process is as follows: Figure 4 As shown.
[0040] Step S4: Complete the service switchover phase: For ES that pass the judgment... B Establish a connection with MT and provide services to it, while interrupting the connection between MT and the original ES. A The connection between them.
[0041] Comparative experiment
[0042] This invention is compared in terms of computational cost with papers by Dwivedi et al., Son et al., and Maria et al. The paper by Dwivedi et al. was published in 2023 in the SCI Q2 international journal *IEEE Transactions on Network Science and Engineering*, the paper by Son et al. was published in 2022 in the SCI Q2 international journal *IEEE Transactions on Network Science and Engineering*, the paper by Maria et al. was published in 2021 in the SCI Q4 international journal *Security and Communication Networks*, and the paper by Guo et al. was published in 2021 in the SCI Q2 international journal *Computers & Security*.
[0043] As shown in Table 1, Dwivedi et al. implemented a mutual authentication and session key agreement protocol using elliptic curve scalar multiplication and one-way hash function, and the required computational cost for switching authentication is 12T ecm + 21T h ≈ 211.92 ms. Son et al. also used elliptic curve scalar multiplication and one-way hash function, and also used elliptic curve point addition, and the required computational cost for switching authentication is 9T ecm + 28T h + T eca ≈ 167.26 ms. Maria et al. used bilinear pairing and ECC cryptography system, and the required computational cost is high, 7T ex + 2T ecm + 2T bp + 3T h ≈ 253.78 ms. Guo et al. used lightweight cryptographic primitives (symmetric ternary polynomial) to reduce the switching authentication time, and eliminated redundant authentication messages with the cooperation of fog nodes, and the required computational cost is 9T se + 14T h ≈ 123.37 ms. The present application reduces the total switching authentication time by 46.63%, and increases the trust calculation when switching the device each time, and the time delay T tru ≈ 5.04 ms for one trust calculation, so the required computational cost for the overall switching authentication is 5T ecm + 14T h + 2T tru ≈ 100.06 ms.
[0044] Compared with other schemes, the present application is not limited to specific cryptographic algorithms, but allows the use of various cryptographic algorithms. In addition, the present application has an advantage in computational cost, and the computational cost is lower than that of other schemes.
[0045] Table 1: Comparison of computational cost
[0046]
[0047] In addition, the number of authentication times and time of the present application are compared with the schemes of Son et al., Wang et al. and Tradition. The paper of Son et al. is published in IEEE Transactions on Network Science and Engineering in 2022, which is an international journal in SCI 2 area. The paper of Wang et al. is published in Journal of Systems Architecture in 2021, which is a journal in SCI 3 area. Tradition is the scheme of traditional switching authentication. The comparison and analysis of the number of switching authentication times and authentication time of the four schemes with the increase of the number of mobile devices. All experiments are carried out in the same experimental conditions using python language. The experimental environment is 64-bit Windows 11 operating system Intel Core i7-11700 CPU 2.50GHZ and 16GB RAM memory. In order to make a more accurate comparison, the number of mobile devices is increased from 2 to 30 in units of 2. All results take the average of 10 experiments to make them more accurate.
[0048] The comparison of the number of switching authentication times and authentication time of the four schemes with the increase of the number of mobile devices is shown in FIGS. 1-4. Figure 5 Figure 6 Compared with the two schemes of Tradition and Wang et al., the present application obviously needs fewer switching authentication times and time in the switching process. Compared with the scheme of Son et al., although the present application is slightly higher in authentication time, it still performs well in the switching process. It should be noted that there is a certain defect in the scheme of Son et al., especially in the case that the user masters both malicious and honest terminals, the malicious terminal can use the identity information of the honest terminal to perform identity authentication free, which has greater security risk than efficiency benefit.
[0049] Therefore, the present application scheme has significantly less overhead in computing cost and switching time than other schemes, and will use less computing resources in the same case, and has a wider range of application scenarios.
[0050] In summary, the application applies the social relationship based on bidirectional authentication to the authentication-free, transfers the authentication originally performed by the terminal to the server side, and completes it in advance in the idle time; meanwhile, a switching authentication-free judgment mechanism is established, including selecting a target ES and judging the target ES for authentication-free. The switching times are reasonably planned to ensure the efficiency and security of the switching process, and to avoid the mobile terminal consuming a large amount of resources to maintain the authentication information, so as to realize the lightweight of the switching authentication process and meet the needs of the low-power mobile terminal. The application successfully solves the delay problem in the MEC switching authentication process with its unique social relationship foundation and authentication-free mechanism, and achieves remarkable results in security and performance.
[0051] The above is only an example and description of the concept of the application, and those skilled in the art can make various modifications or supplements to the described specific embodiments or replace them with similar ways, as long as they do not deviate from the concept of the application or exceed the scope defined by the claims.
Claims
1. A highly efficient handover authentication method based on social relationships in mobile edge computing, applied to mobile edge computing scenarios including mobile terminal (MT), edge server (ES), and blockchain, characterized in that, It consists of an edge server social relationship establishment mechanism and a handover authentication-free judgment mechanism. First, the social relationships between Elasticsearch servers are initialized, establishing their own social circles. Second, the established social relationships are used to filter out target edge servers. B Subsequently, an authentication-free judgment mechanism was used to screen the target edge servers ES. B The system determines whether an unauthenticated user can access the terminal user's account to provide services, and then completes the service switchover. This process includes the following steps: Step S1: Initialization Phase Obtain other things from the blockchain Location information , Execution and Distance calculation using the formula And filter out those within their own service scope. Randomly select a few from them Perform two-way identity authentication and integrity authentication, and become its social node. Towards Send timestamp ,itself as well as Hash value ; In receiving from After receiving the information, check the timestamp. and And repeat the calculation and verification. Secondly, Validating the blockchain Inform them of their identity and location information. Whether to perform two-way authentication; finally, after completing two-way authentication, each party uses their private key to sign a social transaction, submits it to the consensus node, and saves it to the blockchain, ultimately forming a social circle. ; Step S2: Target ES Selection Phase: First, the MT selects the target ES from the currently connected... Send its subsequent direction of movement; secondly, Based on the movement direction information sent by MT, select several candidates in that direction. and obtain from the blockchain of and Information; secondly, through polynomials Calculate the weights of the candidate nodes; where L is... and distance, Use the current timestamp; finally, select the weighted node as... ; Step S3: ES Authentication-Free Determination Phase: Based on the selected nodes to be connected... Calculate its connection with the current connection. Mutual trust between them; similar to the screening phase, firstly, it is necessary to go through a polynomial... Calculate the mutual weights of the two; then, calculate them separately. exist Reputation value as well as exist Reputation value Finally, make a judgment. and If all exceed the set threshold, then pass the authentication exemption judgment; Step S4: Complete the service switchover phase: For those that pass the judgment... Establish a connection with the MT and provide services to it, while interrupting the connection between the MT and the original... The connection between them.
2. The efficient switching authentication method as described in claim 1, characterized in that, The social relationships are specifically as follows: Edge servers (ES) utilize redundant computing resources to interact with other edge servers (ES). S A two-way authentication is established between them to obtain a relationship of mutual trust; This trust can be partially transferred and this social trust will diminish over time.
3. The efficient switching authentication method as described in claim 1, characterized in that, Two-way authentication is specifically the process by which two edge servers (ES) establish a social relationship through identity authentication and integrity authentication. This social relationship can, to some extent, replace the real-time authentication process during the switching process.
4. The efficient switching authentication method as described in claim 1, characterized in that, Building its own social circle specifically involves: an edge server (ES) connecting with other edge servers (ES) that have existing social relationships with it. S Implement unified management to create its own social circle.
5. The efficient switching authentication method as described in claim 1, characterized in that, Filter target edge servers ES B Specifically, this involves: connecting to the current edge server ES. A With the candidate target edge server ES B The appropriate target edge server (ES) is selected based on proximity, social circle matching, and the mobile user's movement direction. B This allows for the rational planning of the overall switching frequency, achieving a balance between efficiency and security. The matching degree of the social circle is specifically defined as follows: there will be overlap in the social circles between different edge servers ES, that is, multiple edge servers ES will have the same "friend" relationship. The number and activity level of this "friend" determines the matching degree of the social circle.
6. The efficient switching authentication method as described in claim 1, characterized in that, The authentication-free determination is specifically as follows: for the selected target edge servers (ES) B Compute and connect to the current edge server ES A The final trust level between them, and the computation location from the end user and the target edge server ES. B Both sides transformed into the target edge server ES B With the current connected edge server ES A This allows even low-power end users to switch quickly.
7. The efficient switching authentication method as described in claim 6, characterized in that, Compute target edge server ES B With the current connected edge server ES A The final level of trust between them is specifically achieved by utilizing the current connection to the edge server ES recorded in the blockchain ledger. A With the target edge server ES B The system uses multiple data points, including social relationships, location information, and service history, to calculate the final trust result through polynomial calculations. When the final trust level exceeds the trust threshold, the authentication-free service node can be changed; the original identity authentication calculation is converted into a trust level calculation, the calculation location is changed and the amount of computation is reduced, and the terminal mobile user and the target edge server ES are connected. B The two-way authentication between them is transformed into the computing target edge server ES. B With the current connected edge server ES A The final trust level between them, and the computation location from the end user and the target edge server ES. B Both sides transformed into the target edge server ES B With the current connected edge server ES A This makes it suitable for the use cases of low-power mobile terminals.
8. The efficient switching authentication method as described in claim 7, characterized in that, The transformation from identity authentication calculation to trust calculation specifically involves: utilizing the currently connected edge server ES recorded in the blockchain ledger. A With the target edge server ES B The system uses a combination of data, including social relationships, location information, and service history, to connect mobile users on the terminal with edge servers (ES) through polynomial computation. B The two-way authentication between them is transformed into the computing target edge server ES. B With the current connected edge server ES A The final trust level between them; when the final trust level is higher than the trust threshold, the service node can be changed without authentication.
9. A highly efficient handover authentication system based on social relationships in mobile edge computing, used to enable a mobile terminal to perform handover authentication between multiple edge servers in a mobile edge computing environment, characterized in that, When the instruction is executed by switching authentication, the steps of implementing the method described in any one of claims 1 to 8 are adopted.
Citation Information
Patent Citations
Data interaction method, system and device, terminal equipment and storage medium
CN115348651A