Identity authentication method, device, computer equipment and non-volatile storage medium
The unique identifier and key are generated by a physical unclonable function and combined with a timestamp for identity authentication, which solves the problem of high computing and storage resources of wireless sensor nodes and realizes secure identity authentication in low-power wireless sensor networks.
Patent Information
- Application Number
- CN202411123601.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-15
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-08-15
AI Technical Summary
Traditional methods have high requirements on the computing and storage resources of wireless sensor nodes, making it difficult to complete identity authentication. In addition, there is a risk of leakage in key generation, which cannot meet the security requirements of low-power wireless sensor networks with full coverage of cable channels.
A physical unclonable function is used to generate a unique identity and key, which is combined with a timestamp for identity authentication. Identity authentication is achieved by updating location data and verification data through interaction between the sensing node and the sink node.
It reduces computing and storage resource usage, lowers the risk of key leakage, and achieves low-cost and efficient node identity authentication, making it suitable for low-power wireless sensor networks.
Smart Images

Figure CN119109591B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless network identity authentication, and in particular to an identity authentication method, device, computer equipment and non-volatile storage medium. Background Art
[0002] With my country's economic development, electricity load in large cities continues to grow. To alleviate the conflict between load growth and limited transmission corridors, improve urban landscapes, ensure urban safety, and mitigate damage to urban power systems caused by natural disasters such as typhoons, cable tunnels have been widely promoted. Currently, 36 cities in China have launched demonstration projects for cable tunnel applications. However, cable tunnel construction in my country is still in its early stages. Inspection and troubleshooting of cable tunnels largely rely on manual labor, and there is a lack of mature, efficient, low-cost, and comprehensive cable tunnel operating environment and status monitoring and automatic early warning solutions. Low-cost, high-efficiency digital operations and maintenance solutions are urgently needed. Deploying wireless sensor networks is the lowest-cost common approach. With the development of low-power wireless sensor network technology, power requirements are becoming increasingly lower, making it the most cost-effective way to achieve comprehensive cable tunnel coverage. To address the power constraints of wireless power sensors, breakthroughs in key security technologies such as lightweight encryption, key generation, and authentication are urgently needed. The development of communication protocols for low-power wireless sensor networks is crucial to address the security challenges of these networks.
[0003] Common encryption technologies currently include asymmetric encryption algorithms and digital signature algorithms. However, these algorithms are not suitable for resource-constrained scenarios such as wireless sensor networks in underground cable channels. Key generation, for example, requires generating two large prime numbers before calculating the key. This is difficult for wireless sensors with limited computing and storage resources, and poses the risk of key leakage, compromising data security. Therefore, more efficient and secure key generation methods are urgently needed.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] The embodiments of the present invention provide an identity authentication method, apparatus, computer device and non-volatile storage medium to at least solve the technical problem that traditional methods have high requirements on node computing and storage resources, making it difficult to complete node identity authentication.
[0006] According to one aspect of an embodiment of the present invention, there is provided an identity authentication method, which is applied to a sensing node in a wireless sensor network, comprising: the sensing node obtains a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; the sensing node determines a first identity identifier and a first key based on the first physical unclonable function, and sends the first identity identifier and the first key to the sink node; the sensing node receives a second key sent by the sink node; the sensing node generates first position data, updates the first position data based on the first key, the first timestamp and the second key, and obtains second position data; the sensing node obtains first verification data based on the second position data, the first key and the first timestamp; the sensing node sends the first identity identifier, the second position data and the first verification data to the sink node, which In the embodiment, the aggregation node is used to obtain third position data based on the received second position data, the first key, the second key and the second timestamp obtained by the aggregation node, obtain second verification data based on the third position data, the first key and the second timestamp, and send a first identity authentication result to the perception node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the aggregation node and the perception node; the perception node receives the first identity authentication result sent by the aggregation node; the perception node obtains fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtains a second identity authentication result based on the first position data and the fourth position data, and sends the second identity authentication result to the aggregation node, and updates the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
[0007] Optionally, the sensing node determines the first identity and the first key based on the first physical unclonable function, including: the sensing node extracts first fixed-length data from the first physical unclonable function to obtain the first identity; the sensing node performs a first hash operation on second fixed-length data in the first physical unclonable function to obtain the first key.
[0008] Optionally, the perception node generates first position data, updates the first position data according to the first key, the first timestamp and the second key, and obtains second position data, including: the perception node randomly generates the first position data; the perception node splices the first key, the second key and the first timestamp to obtain first spliced data; the perception node performs a second hash operation on the first spliced data to obtain first hash data; the perception node updates the first position data according to the first hash data to obtain second position data.
[0009] According to another aspect of an embodiment of the present invention, an identity authentication method is also provided, which is applied to a sink node in a wireless sensor network, including: the sink node obtains a second physical unclonable function and a second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node; the sink node determines a second identity identifier and a second key based on the second physical unclonable function, and sends the second identity identifier and the second key to the sensing node; the sink node receives second position data and a first key sent by the sensing node, wherein the sensing node is used to generate first position data, and updates the first position data according to the first key, the first timestamp and the second key obtained by the sensing node to obtain second position data, and the first timestamp is used to generate second position data. The method is used to characterize the number of successful identity authentications between the perception node and the aggregation node; the aggregation node obtains third position data based on the second timestamp, the second key, the second position data, and the first key, obtains second verification data based on the third position data, the first key, and the second timestamp, and sends a first identity authentication result to the perception node based on the first verification data and the second verification data sent by the perception node; the aggregation node receives the second identity authentication result sent by the perception node, wherein the perception node obtains fourth position data based on the first identity authentication result, the first position data, the first key, and the second key, and obtains a second identity authentication result based on the first position data and the fourth position data; the aggregation node updates the second timestamp based on the received second identity authentication result.
[0010] Optionally, the aggregation node determines the second identity and the second key based on the second physical unclonable function, including: the aggregation node extracts the first fixed-length data in the second physical unclonable function to obtain the second identity; the aggregation node performs a first hash operation on the second fixed-length data in the second physical unclonable function to obtain the second key.
[0011] Optionally, the aggregation node obtains third position data based on the second timestamp, the second key, the received second position data, and the first key, and obtains second verification data based on the third position data, the first key and the second timestamp, including: the aggregation node splices the first key, the second key and the second timestamp to obtain second spliced data; the aggregation node performs a second hash operation on the second spliced data to obtain second hash data; the aggregation node updates the second position data based on the second hash data to obtain third position data; the aggregation node splices the first key, the second timestamp and the third position data to obtain third spliced data; the aggregation node performs a second hash operation on the third spliced data to obtain second verification data.
[0012] According to another aspect of an embodiment of the present invention, an identity authentication device is also provided, which is applied to a sensing node, including: a first acquisition module, used to obtain a first physical unclonable function and a first timestamp, wherein the first timestamp is used to characterize the number of successful identity authentications between the sensing node and the sink node; a first calculation module, used to determine a first identity identifier and a first key based on the first physical unclonable function, and send the first identity identifier and the first key to the sink node; a first receiving module, used to receive a second key sent by the sink node; a second calculation module, used to generate first position data, and update the first position data according to the first key, the first timestamp and the second key to obtain second position data; a third calculation module, used to obtain first verification data according to the second position data, the first key and the first timestamp; a fourth calculation module, used to send the first identity identifier, the second position data and the first verification data to the sink node. To the aggregation node, wherein the aggregation node is used to obtain third position data based on the received second position data, the first key, the second key and the second timestamp obtained by the aggregation node, obtain second verification data based on the third position data, the first key and the second timestamp, and send the first identity authentication result to the perception node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the aggregation node and the perception node; the second receiving module is used to receive the first identity authentication result sent by the aggregation node; the fifth calculation module is used to obtain fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtain the second identity authentication result based on the first position data and the fourth position data, and send the second identity authentication result to the aggregation node to update the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
[0013] According to another aspect of an embodiment of the present invention, an identity authentication device is also provided, which is applied to a convergence node, including: a second acquisition module, used to obtain a second physical unclonable function and a second timestamp, wherein the second timestamp is used to characterize the number of successful identity authentications between the convergence node and the perception node; a sixth calculation module, used to determine a second identity identifier and a second key based on the second physical unclonable function, and send the second identity identifier and the second key to the perception node; a third receiving module, used to receive second position data and a first key sent by the perception node, wherein the perception node is used to generate first position data, and update the first position data according to the first key, the first timestamp and the second key obtained by the perception node to obtain second position data, and the first timestamp is used to characterize the perception node. The number of successful identity authentications between the sensing node and the aggregation node; a seventh calculation module, for obtaining third position data based on the second timestamp, the second key, the second position data, and the first key, obtaining second verification data based on the third position data, the first key, and the second timestamp, and sending the first identity authentication result to the sensing node based on the first verification data and the second verification data sent by the sensing node; a fourth receiving module, for receiving the second identity authentication result sent by the sensing node, wherein the sensing node obtains fourth position data based on the first identity authentication result, the first position data, the first key, and the second key, and obtains the second identity authentication result based on the first position data and the fourth position data; an eighth calculation module, for updating the second timestamp based on the received second identity authentication result. According to another aspect of an embodiment of the present invention, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute any one of the above-mentioned identity authentication methods.
[0014] According to another aspect of an embodiment of the present invention, a computer device is provided. The computer device includes a processor, and the processor is used to run a program. When the program is run, any one of the above-mentioned identity authentication methods is executed.
[0015] According to yet another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program, which implements any one of the above-mentioned identity authentication methods when executed by a processor.
[0016] In an embodiment of the present invention, a first physical unclonable function and a first timestamp are obtained by a sensing node, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; the sensing node determines a first identity identifier and a first key according to the first physical unclonable function, and sends the first identity identifier and the first key to the sink node; the sensing node receives a second key sent by the sink node; the sensing node generates first position data, updates the first position data according to the first key, the first timestamp and the second key, and obtains second position data; the sensing node obtains first verification data according to the second position data, the first key and the first timestamp; the sensing node sends the first identity identifier, the second position data and the first verification data to the sink node, wherein the sink node is used to obtain third position data according to the received second position data, the first key, the second key and the second timestamp obtained by the sink node, and updates the first position data according to the third position data, the first timestamp and the second key. The first authentication result is generated by the physical unclonable function, thereby achieving the technical effect of reducing the computing and storage resource usage while reducing the risk of key leakage, thereby solving the technical problem that the traditional method has high requirements on node computing and storage resource, making it difficult to complete node authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0018] Figure 1 A hardware structure block diagram of a computer terminal for implementing an identity authentication method is shown;
[0019] Figure 2 1 is a flow chart of a method for authenticating a perception node according to an embodiment of the present invention;
[0020] Figure 3 1 is a flow chart of a method for authenticating a sink node according to an embodiment of the present invention;
[0021] Figure 4is a schematic diagram of a perception node identity authentication device provided according to an optional embodiment of the present invention;
[0022] Figure 5 2 is a schematic diagram of a sink node identity authentication device according to an optional embodiment of the present invention. DETAILED DESCRIPTION
[0023] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0024] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0025] According to an embodiment of the present invention, an embodiment of a method for identity authentication is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0026] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG1 shows a hardware structure block diagram of a computer terminal for implementing an identity authentication method. Figure 1As shown, the computer terminal 10 may include one or more (illustrated as 102a, 102b, ..., 102n in the figure) processors (the processor may include but is not limited to a microprocessor MCU or a programmable logic device FPGA and other processing devices), a memory 104 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0027] It should be noted that the one or more processors and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0028] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the identity authentication method in the embodiment of the present invention. The processor executes the software programs and modules stored in the memory 104 to execute various functional applications and data processing, that is, to implement the identity authentication method of the above-mentioned application. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include memory remotely located relative to the processor, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0029] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .
[0030] Figure 2 FIG. 1 is a flow chart of a method for authenticating a perception node according to an embodiment of the present invention. Figure 2 As shown, the method includes the following steps:
[0031] In step S202, the sensing node obtains a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node.
[0032] In this step, the sensing node is the basic unit in the wireless sensor network, capable of detecting and measuring various parameters of its surrounding environment, such as temperature, humidity, light, vibration, sound, etc., and transmitting these parameters to the sink node via the wireless network; the first physical unclonable function is a unique response generated by using the tiny, random physical differences produced by the integrated circuit during the manufacturing process, which can be used to generate a unique identifier or key for the sensing node; the first timestamp is used to record the number of successful identity authentications between the sensing node and the sink node. If the identity authentication is successful, the first timestamp is updated.
[0033] In step S204 , the sensing node determines a first identity and a first key according to the first physical unclonable function, and sends the first identity and the first key to the sink node.
[0034] In this step, the first identity identifier refers to a unique character string used to represent the perception node; the first key is a character string used to control the execution of the encryption or decryption algorithm during the perception node authentication process. It can be a symmetric key, an asymmetric key, a session key, etc., and is unique.
[0035] Step S206: The sensing node receives the second key sent by the sink node.
[0036] In this step, the second key is a string of characters used to control the execution of the encryption or decryption algorithm during the identity authentication process of the aggregation node. It can be a symmetric key, an asymmetric key, a session key, etc. and is unique.
[0037] In step S208 , the sensing node generates first location data, and updates the first location data according to the first key, the first timestamp, and the second key to obtain second location data.
[0038] In this step, the first location data is a string of characters randomly generated by the perception node during the identity authentication process, which can hide the actual physical address or network address of the perception node; the second location data is a string of characters generated by the perception node through specific calculations, which is related to the first key, the first timestamp, the second key and the first location data, and is used to hide the first location data during the identity authentication process.
[0039] In step S210 , the sensing node obtains first verification data according to the second location data, the first key, and the first timestamp.
[0040] In this step, the first verification data is a string of characters generated by the perception node through specific calculations, which is related to the second location data, the first key and the first timestamp, and is used to verify some data in the identity authentication process.
[0041] In step S212, the perception node sends the first identity identifier, the second location data, and the first verification data to the aggregation node, wherein the aggregation node is used to obtain the third location data based on the received second location data, the first key, the second key, and the second timestamp obtained by the aggregation node, obtain the second verification data based on the third location data, the first key, and the second timestamp, and send the first identity authentication result to the perception node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the aggregation node and the perception node.
[0042] In this step, the perception node sends the first identity identifier, the second location data and the first verification data to the aggregation node, which is equivalent to initiating an identity authentication request to the aggregation node; the aggregation node generates the third location data through specific calculations based on the received second location data, the first key, the second key and the second timestamp obtained by itself; the second verification data is a string generated by the aggregation node through specific calculations, which is related to the third location data, the first key and the second timestamp; if the first verification data and the second verification data are equal, it means that the aggregation node has successfully authenticated the perception node; otherwise, it means that the aggregation node has failed to authenticate the perception node.
[0043] Step S214: The sensing node receives the first identity authentication result sent by the sink node;
[0044] In this step, the sensing node receives the first identity authentication result from the sink node; the first identity authentication result may be a success or a failure, and the sensing node needs to further process it.
[0045] In step S216, the perception node obtains fourth position data based on the first identity authentication result, the first position data, the first key, and the second key, obtains a second identity authentication result based on the first position data and the fourth position data, and sends the second identity authentication result to the aggregation node to update the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
[0046] In this step, the fourth position data is a character string generated by the aggregation node through specific calculations, which is related to the first identity authentication result, the first position data, the first key and the second key; if the first position data and the fourth position data are equal, it means that the perception node has successfully authenticated the identity of the aggregation node and the first timestamp is updated; otherwise, it means that the perception node has failed to authenticate the identity of the aggregation node.
[0047] Through the above steps, the purpose of using a physically unclonable function to generate a key is achieved, thereby achieving the technical effect of reducing the computing and storage resource usage while reducing the risk of key leakage, and thus solving the technical problem that traditional methods have high requirements for node computing and storage resources, making it difficult to complete node identity authentication.
[0048] As an optional embodiment, the perception node determines the first identity and the first key based on the first physical unclonable function, including: the perception node extracts the first fixed-length data in the first physical unclonable function to obtain the first identity; the perception node performs a first hash operation on the second fixed-length data in the first physical unclonable function to obtain the first key.
[0049] Optionally, the first fixed length refers to the length of the first identity identifier corresponding to the predetermined perception node; the second fixed length refers to the length of the predetermined first physical unclonable function data used to generate the first key; the hash operation is a mathematical function processing process that converts data of any length into a string of fixed length; the first hash operation is used to generate the first key, the input is the second fixed length data in the first physical unclonable function, and the output is the first key.
[0050] Specifically, the sensing node extracts a 36-bit first physical unclonable function as the first identity identifier, namely ID c ; Extract another 511-bit long first physical unclonable function, namely PUF c PUF c Perform the first hash operation to obtain the 32-bit first key SID c , which can be expressed as SID c = hash1(PUF c ), where hash1(·) represents the first hash operation.
[0051] As an optional embodiment, the perception node generates first position data, updates the first position data according to the first key, the first timestamp and the second key, and obtains second position data, including: the perception node randomly generates the first position data; the perception node splices the first key, the second key and the first timestamp to obtain first spliced data; the perception node performs a second hash operation on the first spliced data to obtain first hash data; the perception node updates the first position data according to the first hash data to obtain second position data.
[0052] Optionally, the first position data is a string of characters randomly generated by the perception node; the first concatenated data is a new string of characters obtained by connecting the first key, the second key and the first timestamp end to end; the length of the first concatenated data is equal to the sum of the length of the first key, the length of the second key and the length of the first timestamp; the second hash operation can be used to generate the first hash data, the input is the first concatenated data, and the output is the first hash data; the second position data is related to the first position data and the first hash data.
[0053] Specifically, the sensing node randomly generates a 64-bit first position data Pos; the second position data can be expressed as MPos = (Pos||Pos)⊕hash2(SID c ||SID h ||N c ), wherein MPos represents the second position data, || represents the splicing symbol, hash2(·) represents the second hash operation, and ⊕ represents the exclusive OR operation.
[0054] Figure 3 FIG. 1 is a flow chart of a method for authenticating a sink node according to an embodiment of the present invention. Figure 3 As shown, the method includes the following steps:
[0055] In step S302, the sink node obtains a second physical unclonable function and a second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node.
[0056] In this step, the sink node is an important component of the wireless sensor network and is used to receive various parameters sent by the sensing network. The second physical unclonable function uses the tiny, random physical differences produced by the integrated circuit during the manufacturing process to generate a unique response, which can be used to generate a unique identifier or key for the sink node. The second timestamp is used to record the number of successful identity authentications between the sink node and the sensing node. If the identity authentication is successful, the second timestamp is updated.
[0057] In step S304, the sink node determines a second identity and a second key according to the second physical unclonable function, and sends the second identity and the second key to the sensing node.
[0058] In this step, the second identity identifier refers to a unique string used to represent the aggregation node; the second key is a string used to control the execution of the encryption or decryption algorithm during the aggregation node identity authentication process. It can be a symmetric key, an asymmetric key, a session key, etc., and is unique.
[0059] In step S306, the aggregation node receives the second location data and the first key sent by the perception node, wherein the perception node is used to generate the first location data, and updates the first location data according to the first key, the first timestamp and the second key obtained by the perception node to obtain the second location data, and the first timestamp is used to represent the number of successful identity authentications between the perception node and the aggregation node.
[0060] In this step, the first key is a string of characters used to control the execution of the encryption or decryption algorithm during the identity authentication process of the perception node. It can be a symmetric key, an asymmetric key, a session key, etc., and is unique; the first location data is a string of characters randomly generated by the perception node during the identity authentication process, which can hide the actual physical address or network address of the perception node; the second location data is a string of characters generated by the perception node through specific calculations, which is related to the first key, the first timestamp, the second key and the first location data, and is used to hide the first location data during the identity authentication process; the aggregation node authenticates the perception node based on the second location data and the first key sent by the perception node.
[0061] In step S308, the aggregation node obtains the third position data based on the second timestamp, the second key, the second position data, and the first key, obtains the second verification data based on the third position data, the first key, and the second timestamp, and sends the first identity authentication result to the perception node based on the first verification data and the second verification data sent by the perception node.
[0062] In this step, the aggregation node is used to obtain the third position data based on the received second position data, the first key, the second key and the second timestamp obtained by the aggregation node, obtain the second verification data based on the third position data, the first key and the second timestamp, and send the first identity authentication result to the perception node based on the first verification data and the second verification data sent by the perception node, wherein the second timestamp is used to represent the number of successful identity authentications between the aggregation node and the perception node.
[0063] In step S310, the aggregation node receives the second identity authentication result sent by the perception node, wherein the perception node obtains the fourth position data based on the first identity authentication result, the first position data, the first key and the second key, and obtains the second identity authentication result based on the first position data and the fourth position data.
[0064] In this step, the fourth position data is a character string generated by the aggregation node through specific calculations, which is related to the first identity authentication result, the first position data, the first key and the second key; if the first position data and the fourth position data are equal, it means that the perception node has successfully authenticated the identity of the aggregation node and the first timestamp is updated; otherwise, it means that the perception node has failed to authenticate the identity of the aggregation node.
[0065] Step S312: The sink node updates the second timestamp according to the received second identity authentication result.
[0066] In this step, the second identity authentication result may be successful or failed, and the aggregation node needs to further process it; if the first position data and the fourth position data are equal, it means that the identity authentication is successful and the second timestamp is updated; otherwise, it means that the identity authentication fails.
[0067] As an optional embodiment, the aggregation node determines the second identity and the second key based on the second physical unclonable function, including: the aggregation node extracts the first fixed-length data in the second physical unclonable function to obtain the second identity; the aggregation node performs a first hash operation on the second fixed-length data in the second physical unclonable function to obtain the second key.
[0068] Optionally, the first fixed length refers to the length of the second identity identifier corresponding to the predetermined aggregation node; the second fixed length refers to the length of the predetermined second physical unclonable function data used to generate the second key; the hash operation is a mathematical function processing process that converts data of any length into a string of fixed length; the first hash operation is used to generate the second key, the input is the second fixed-length data in the second physical unclonable function, and the output is the second key.
[0069] Specifically, the sink node extracts a 36-bit second physical unclonable function as the second identity identifier, namely ID h ; Extract another 511-bit second physical unclonable function, namely PUF h PUF h Perform the first hash operation to obtain the 32-bit second key SID h , which can be expressed as SID h = hash1(PUF h ), where hash1(·) represents the first hash operation.
[0070] As an optional embodiment, the aggregation node obtains third position data based on the second timestamp, the second key, the received second position data, and the first key, and obtains second verification data based on the third position data, the first key and the second timestamp, including: the aggregation node splices the first key, the second key and the second timestamp to obtain second spliced data; the aggregation node performs a second hash operation on the second spliced data to obtain second hash data; the aggregation node updates the second position data based on the second hash data to obtain third position data; the aggregation node splices the first key, the second timestamp and the third position data to obtain third spliced data; the aggregation node performs a second hash operation on the third spliced data to obtain second verification data.
[0071] Optionally, the second spliced data is a new string obtained by connecting the first key, the second key and the second timestamp end to end; the length of the second spliced data is equal to the sum of the length of the first key, the length of the second key and the length of the second timestamp; the second hash operation can be used to generate the second hash data, the input is the second spliced data, and the output is the second hash data; the third position data is related to the second position data and the second hash data; the third spliced data is a new string obtained by connecting the first key, the second timestamp and the third position data end to end; the second hash operation can be used to generate the second verification data, the input is the third spliced data, and the output is the second verification data.
[0072] Specifically, the third position data can be expressed as (Pos'||Pos')=MPos⊕hash2(SID c ||SID h ||N h ), where MPos represents the second position data, || represents the concatenation symbol, hash2(·) represents the second hash operation, ⊕ represents the XOR operation, and Pos' represents the third position data; the second verification data can be expressed as V'=hash2(SID c ||Pos'||N h ), wherein V' represents the second verification data.
[0073] As a specific embodiment, the sensing node and the sink node extract a 36-bit data from the first physical unclonable function and the second physical unclonable function as the identity authentication identifier, namely the first identity authentication identifier ID c and the second identity authentication ID h , extract another 511-bit data from the first physical unclonable function and the second physical unclonable function, namely PUF c and PUF h , generate the first key SID through the first hash operation c and the second key SIDh , which can be expressed as:
[0074] SID c = hash1(PUF c ) (1)
[0075] SID h = hash1(PUF h ) (2)
[0076] The sensing node and the sink node extract the first timestamp N c and the second timestamp N h ;
[0077] The sensing node and the sink node exchange identity authentication identifiers and keys, and store each other's identity authentication identifiers and keys;
[0078] The sensing node generates a 64-bit first position data Pos, calculates the second position data MPos and the first verification data V:
[0079] MPos = (Pos || Pos) ⊕ hash2(SID c ||SID h ||N c ) (3)
[0080] V = hash2(SID c ||Pos|| N c ) (4)
[0081] The perception node will first authenticate the ID c , the second position data MPos and the first verification data V are sent to the sink node;
[0082] After receiving the information, the sink node calculates the third position data Pos' and the second verification data V':
[0083] (Pos'||Pos')=MPos⊕hash2(SID c ||SID h ||N h ) (5)
[0084] V' = hash2(SID c || Pos' || N h ) (6)
[0085] The sink node verifies whether V'=V. If not, it calculates:
[0086] APS = ECC(ID c || Nh ⊕ SID h ) (7)
[0087] Among them, APS is elliptic curve encryption data, ECC is elliptic curve encryption operation, APS and ID h Send it to the sensing node as the first identity authentication result and request to restart the identity authentication process;
[0088] If V'=V, then calculate:
[0089] IDF = hash2(SID c || SID h || R) (8)
[0090] M = R ⊕ hash2(SID c || SID h || Pos') (9)
[0091] APS = ECC(IDF ⊕ Pos') (10)
[0092] R is the first random number of 128 bits generated by the sink node, IDF is the fourth splicing data, M is the identity authentication success mark data, and APS, ID h and M is sent to the sensing node as the first identity authentication result;
[0093] If the first authentication result received by the sensing node does not contain M, it means that the authentication has failed. In the case of failure, calculate:
[0094] (ID c ' || N c ') ⊕ SID h = EDC(APS) (11) EDC is the elliptic curve decryption operation, ID c ' is the third identity authentication identifier, N c ' is the third timestamp;
[0095] If ID c '≠ID c , the sensing node feeds back the authentication failure data ACK1 to the sink node through the second authentication data, and resends the authentication application. Otherwise, update N c =N c 'And feed back identity authentication success data ACK1 to the second identity authentication data aggregation node, and then resend the identity authentication application.
[0096] If the first identity authentication result received by the sensing node contains M, calculate the following formula:
[0097] R'=M⊕hash2(SID c || SID h || Pos) (12)
[0098] IDF' = hash2(SID c || SID h || R') (13)
[0099] Pos” = EDC(IDF' ⊕ APS) (14)
[0100] Wherein, R' is the second random number, IDF' is the fifth splicing data, and Pos" is the fourth position data;
[0101] If Pos" ≠ Pos, the identity authentication fails, and the second identity authentication data is fed back to the sink node via ACK1 and the identity authentication application is resent. Otherwise, N is updated. c =N c +1 and feeds back identity authentication success flag data ACK2 to the sink node through the second identity authentication data;
[0102] The sink node receives the second identity authentication data. If the second identity authentication data is ACK2, it indicates that the identity authentication is successful, and the N h =N h +1.
[0103] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present invention is not limited by the order of the actions described, because according to the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.
[0104] Through the description of the above implementation methods, those skilled in the art can clearly understand that the identity authentication method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0105] According to an embodiment of the present invention, there is also provided an identity authentication device for implementing the above-mentioned perception node identity authentication method. Figure 4 is a structural block diagram of a sensing node identity authentication device according to an embodiment of the present invention. Figure 4 As shown, the perception node identity authentication device includes: a first acquisition module 41, a first calculation module 42, a first receiving module 43, a second calculation module 44, a third calculation module 45, a fourth calculation module 46, a second receiving module 47, and a fifth calculation module 48. The perception node identity authentication device is described below.
[0106] A first acquisition module is configured to acquire a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node;
[0107] A first computing module, configured to determine a first identity and a first key according to a first physical unclonable function, and send the first identity and the first key to a sink node;
[0108] A first receiving module, configured to receive a second key sent by the sink node;
[0109] a second calculation module, configured to generate first position data, and update the first position data according to the first key, the first timestamp, and the second key to obtain second position data;
[0110] a third calculation module, configured to obtain first verification data according to the second position data, the first key, and the first timestamp;
[0111] a fourth computing module, configured to send the first identity identifier, the second location data, and the first verification data to the sink node, wherein the sink node is configured to obtain third location data based on the received second location data, the first key, the second key, and the second timestamp obtained by the sink node, obtain second verification data based on the third location data, the first key, and the second timestamp, and send a first identity authentication result to the sensing node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node;
[0112] A second receiving module is used to receive the first identity authentication result sent by the aggregation node;
[0113] The fifth computing module is used to obtain fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtain the second identity authentication result based on the first position data and the fourth position data, and send the second identity authentication result to the aggregation node to update the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
[0114] It should be noted that the first acquisition module 41, first calculation module 42, first receiving module 43, second calculation module 44, third calculation module 45, fourth calculation module 46, second receiving module 47, and fifth calculation module 48 correspond to steps S202 to S216 in the embodiment. The examples and application scenarios implemented by the various modules and the corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above modules, as part of the device, can be run in the computer terminal 10 provided in the embodiment.
[0115] According to an embodiment of the present invention, there is also provided an identity authentication device for implementing the above-mentioned sink node identity authentication method. Figure 5 : is a structural block diagram of a sink node identity authentication device according to an embodiment of the present invention. Figure 5 As shown, the sink node identity authentication device includes: a second acquisition module 51, a sixth calculation module 52, a third receiving module 53, a seventh calculation module 54, a fourth receiving module 55, and an eighth calculation module 56. The sink node identity authentication device is described below.
[0116] A second acquisition module is configured to acquire a second physical unclonable function and a second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node;
[0117] A sixth computing module, configured to determine a second identity identifier and a second key according to a second physical unclonable function, and send the second identity identifier and the second key to the sensing node;
[0118] a third receiving module, configured to receive second location data and a first key sent by the sensing node, wherein the sensing node is configured to generate the first location data, and update the first location data according to the first key, the first timestamp, and the second key obtained by the sensing node to obtain the second location data, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node;
[0119] a seventh computing module, configured to obtain third position data based on the second timestamp, the second key, the second position data, and the first key, obtain second verification data based on the third position data, the first key, and the second timestamp, and send a first identity authentication result to the sensing node based on the first verification data and the second verification data sent by the sensing node;
[0120] a fourth receiving module, configured to receive a second identity authentication result sent by the sensing node, wherein the sensing node obtains fourth position data based on the first identity authentication result, the first position data, the first key, and the second key, and obtains the second identity authentication result based on the first position data and the fourth position data;
[0121] An eighth calculation module is configured to update the second timestamp according to the received second identity authentication result.
[0122] It should be noted that the second acquisition module 51, the sixth calculation module 52, the third receiving module 53, the seventh calculation module 54, the fourth receiving module 55, and the eighth calculation module 56 correspond to steps S302 to S312 in the embodiment. The examples and application scenarios implemented by these modules and the corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above modules, as part of the device, can be run in the computer terminal 10 provided in the embodiment.
[0123] An embodiment of the present invention may provide a computer device. Optionally, in this embodiment, the computer device may be located in at least one of a plurality of network devices in a computer network. The computer device includes a memory and a processor.
[0124] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the identity authentication method and device in the embodiments of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the above-mentioned identity authentication method. The memory may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories may be connected to the computer terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0125] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: the sensing node obtains a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; the sensing node determines a first identity identifier and a first key according to the first physical unclonable function, and sends the first identity identifier and the first key to the sink node; the sensing node receives a second key sent by the sink node; the sensing node generates first location data, updates the first location data according to the first key, the first timestamp and the second key, and obtains second location data; the sensing node obtains first verification data according to the second location data, the first key and the first timestamp; the sensing node sends the first identity identifier, the second location data and the first verification data to the sink node, wherein the sink node The point is used to obtain third position data based on the received second position data, the first key, the second key and the second timestamp obtained by the aggregation node, obtain second verification data based on the third position data, the first key and the second timestamp, and send a first identity authentication result to the perception node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the aggregation node and the perception node; the perception node receives the first identity authentication result sent by the aggregation node; the perception node obtains fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtains a second identity authentication result based on the first position data and the fourth position data, and sends the second identity authentication result to the aggregation node, updating the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
[0126] Optionally, the sensing node determines the first identity and the first key based on the first physical unclonable function, including: the sensing node extracts first fixed-length data from the first physical unclonable function to obtain the first identity; the sensing node performs a first hash operation on second fixed-length data in the first physical unclonable function to obtain the first key.
[0127] Optionally, the perception node generates first position data, updates the first position data according to the first key, the first timestamp and the second key, and obtains second position data, including: the perception node randomly generates the first position data; the perception node splices the first key, the second key and the first timestamp to obtain first spliced data; the perception node performs a second hash operation on the first spliced data to obtain first hash data; the perception node updates the first position data according to the first hash data to obtain second position data.
[0128] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: the sink node obtains the second physical unclonable function and the second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the perception node; the sink node determines the second identity identifier and the second key according to the second physical unclonable function, and sends the second identity identifier and the second key to the perception node; the sink node receives the second position data and the first key sent by the perception node, wherein the perception node is used to generate the first position data, and updates the first position data according to the first key, the first timestamp and the second key obtained by the perception node to obtain the second position data, and the first timestamp is used to represent the second position data. The method comprises the following steps: collecting the number of successful identity authentications between the sensing node and the sink node; the sink node obtains the third position data according to the second timestamp, the second key, the second position data, and the first key, obtains the second verification data according to the third position data, the first key, and the second timestamp, and sends the first identity authentication result to the sensing node according to the first verification data and the second verification data; the sink node receives the second identity authentication result sent by the sensing node, wherein the sensing node obtains the fourth position data according to the first identity authentication result, the first position data, the first key, and the second key, and obtains the second identity authentication result according to the first position data and the fourth position data; the sink node updates the second timestamp according to the received second identity authentication result.
[0129] Optionally, the aggregation node determines the second identity and the second key based on the second physical unclonable function, including: the aggregation node extracts the first fixed-length data in the second physical unclonable function to obtain the second identity; the aggregation node performs a first hash operation on the second fixed-length data in the second physical unclonable function to obtain the second key.
[0130] Optionally, the aggregation node obtains third position data based on the second timestamp, the second key, the received second position data, and the first key, and obtains second verification data based on the third position data, the first key and the second timestamp, including: the aggregation node splices the first key, the second key and the second timestamp to obtain second spliced data; the aggregation node performs a second hash operation on the second spliced data to obtain second hash data; the aggregation node updates the second position data based on the second hash data to obtain third position data; the aggregation node splices the first key, the second timestamp and the third position data to obtain third spliced data; the aggregation node performs a second hash operation on the third spliced data to obtain second verification data.
[0131] By adopting the embodiment of the present invention, an identity authentication scheme is provided, which achieves the purpose of generating keys using physically unclonable functions, thereby achieving the technical effect of reducing the computing and storage resource usage while reducing the risk of key leakage, and further solves the technical problem that traditional methods have high requirements for node computing and storage resources, making it difficult to complete node identity authentication.
[0132] A person skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a non-volatile storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0133] The embodiment of the present invention further provides a non-volatile storage medium. Optionally, in this embodiment, the non-volatile storage medium can be used to store the program code executed by the identity authentication method provided in the embodiment.
[0134] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0135] Optionally, in this embodiment, the non-volatile storage medium is configured to store program codes for executing the following steps: the sensing node obtains a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; the sensing node determines a first identity identifier and a first key according to the first physical unclonable function, and sends the first identity identifier and the first key to the sink node; the sensing node receives a second key sent by the sink node; the sensing node generates first location data, updates the first location data according to the first key, the first timestamp, and the second key, and obtains second location data; the sensing node obtains first verification data according to the second location data, the first key, and the first timestamp; the sensing node sends the first identity identifier, the second location data, and the first verification data to the sink node, wherein the sink node The aggregation node is used to obtain third position data based on the received second position data, the first key, the second key and the second timestamp obtained by the aggregation node, obtain second verification data based on the third position data, the first key and the second timestamp, and send a first identity authentication result to the perception node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the aggregation node and the perception node; the perception node receives the first identity authentication result sent by the aggregation node; the perception node obtains fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtains a second identity authentication result based on the first position data and the fourth position data, and sends the second identity authentication result to the aggregation node, updating the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
[0136] Optionally, the sensing node determines the first identity and the first key based on the first physical unclonable function, including: the sensing node extracts first fixed-length data from the first physical unclonable function to obtain the first identity; the sensing node performs a first hash operation on second fixed-length data in the first physical unclonable function to obtain the first key.
[0137] Optionally, the perception node generates first position data, updates the first position data according to the first key, the first timestamp and the second key, and obtains second position data, including: the perception node randomly generates the first position data; the perception node splices the first key, the second key and the first timestamp to obtain first spliced data; the perception node performs a second hash operation on the first spliced data to obtain first hash data; the perception node updates the first position data according to the first hash data to obtain second position data.
[0138] In this embodiment, the non-volatile storage medium is configured to store program codes for executing the following steps: the sink node obtains a second physical unclonable function and a second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node; the sink node determines a second identity identifier and a second key based on the second physical unclonable function, and sends the second identity identifier and the second key to the sensing node; the sink node receives the second position data and the first key sent by the sensing node, wherein the sensing node is used to generate the first position data, and updates the first position data according to the first key, the first timestamp and the second key obtained by the sensing node to obtain the second position data, and the first timestamp is used to represent the second position data. The method comprises the following steps: collecting the number of successful identity authentications between the sensing node and the sink node; the sink node obtains the third position data according to the second timestamp, the second key, the second position data, and the first key, obtains the second verification data according to the third position data, the first key, and the second timestamp, and sends the first identity authentication result to the sensing node according to the first verification data and the second verification data; the sink node receives the second identity authentication result sent by the sensing node, wherein the sensing node obtains the fourth position data according to the first identity authentication result, the first position data, the first key, and the second key, and obtains the second identity authentication result according to the first position data and the fourth position data; the sink node updates the second timestamp according to the received second identity authentication result.
[0139] Optionally, the aggregation node determines the second identity and the second key based on the second physical unclonable function, including: the aggregation node extracts the first fixed-length data in the second physical unclonable function to obtain the second identity; the aggregation node performs a first hash operation on the second fixed-length data in the second physical unclonable function to obtain the second key.
[0140] Optionally, the aggregation node obtains third position data based on the second timestamp, the second key, the received second position data, and the first key, and obtains second verification data based on the third position data, the first key and the second timestamp, including: the aggregation node splices the first key, the second key and the second timestamp to obtain second spliced data; the aggregation node performs a second hash operation on the second spliced data to obtain second hash data; the aggregation node updates the second position data based on the second hash data to obtain third position data; the aggregation node splices the first key, the second timestamp and the third position data to obtain third spliced data; the aggregation node performs a second hash operation on the third spliced data to obtain second verification data.
[0141] An embodiment of the present invention further provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the identity authentication method in each embodiment of the present application.
[0142] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0143] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0144] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0145] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0146] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0147] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, and other media that can store program code.
[0148] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. An identity authentication method, characterized in that: Sensing nodes used in wireless sensor networks include: The sensing node obtains a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; The sensing node determines a first identity and a first key according to the first physical unclonable function, and sends the first identity and the first key to the sink node; The sensing node receives the second key sent by the sink node; The sensing node generates first location data, and updates the first location data according to the first key, the first timestamp, and the second key to obtain second location data; The sensing node obtains first verification data according to the second location data, the first key, and the first timestamp; The sensing node sends the first identity identifier, the second location data, and the first verification data to the sink node, wherein the sink node is configured to obtain third location data based on the received second location data, the first key, the second key, and the second timestamp obtained by the sink node, obtain second verification data based on the third location data, the first key, and the second timestamp, and send a first identity authentication result to the sensing node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node; The sensing node receives the first identity authentication result sent by the sink node; The perception node obtains fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtains a second identity authentication result based on the first position data and the fourth position data, and sends the second identity authentication result to the aggregation node to update the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
2. The method according to claim 1, characterized in that The sensing node determines a first identity and a first key according to the first physical unclonable function, including: The sensing node extracts data of a first fixed length from the first physical unclonable function to obtain the first identity identifier; The sensing node performs a first hash operation on the second fixed-length data in the first physical unclonable function to obtain the first key.
3. The method according to claim 1, characterized in that The sensing node generates first location data, and updates the first location data according to the first key, the first timestamp, and the second key to obtain second location data, including: The sensing node randomly generates the first position data; The sensing node concatenates the first key, the second key, and the first timestamp to obtain first concatenated data; The sensing node performs a second hash operation on the first spliced data to obtain first hash data; The sensing node updates the first location data according to the first hash data to obtain the second location data.
4. An identity authentication method, characterized in that: The sink nodes used in wireless sensor networks include: The sink node obtains a second physical unclonable function and a second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node; The sink node determines a second identity and a second key according to the second physical unclonable function, and sends the second identity and the second key to the sensing node; The sink node receives the second location data and the first key sent by the sensing node, wherein the sensing node is used to generate the first location data, and updates the first location data according to the first key, the first timestamp, and the second key obtained by the sensing node to obtain the second location data, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; The sink node obtains third location data based on the second timestamp, the second key, the second location data, and the first key, obtains second verification data based on the third location data, the first key, and the second timestamp, and sends a first identity authentication result to the sensing node based on the first verification data and the second verification data sent by the sensing node; The sink node receives the second identity authentication result sent by the sensing node, wherein the sensing node obtains fourth location data based on the first identity authentication result, the first location data, the first key, and the second key, and obtains the second identity authentication result based on the first location data and the fourth location data; The sink node updates the second timestamp according to the received second identity authentication result.
5. The method according to claim 4, characterized in that The sink node determines the second identity and the second key according to the second physical unclonable function, including: The sink node extracts the first fixed-length data in the second physical unclonable function to obtain the second identity identifier; The sink node performs a first hash operation on the second fixed-length data in the second physical unclonable function to obtain the second key.
6. The method according to claim 4, characterized in that The sink node obtains third location data according to the second timestamp, the second key, the received second location data, and the first key, and obtains second verification data according to the third location data, the first key, and the second timestamp, including: The sink node concatenates the first key, the second key, and the second timestamp to obtain second concatenated data; The sink node performs a second hash operation on the second spliced data to obtain second hash data; The sink node updates the second position data according to the second hash data to obtain the third position data; The sink node splices the first key, the second timestamp, and the third position data to obtain third spliced data; The sink node performs a second hash operation on the third concatenated data to obtain second verification data.
7. An identity authentication device, characterized in that: Applied to perception nodes, including: A first acquisition module is configured to acquire a first physical unclonable function and a first timestamp, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; a first computing module, configured to determine a first identity and a first key according to the first physical unclonable function, and send the first identity and the first key to the sink node; A first receiving module, configured to receive a second key sent by the sink node; a second calculation module, configured to generate first position data, and update the first position data according to the first key, the first timestamp, and the second key to obtain second position data; a third calculation module, configured to obtain first verification data according to the second position data, the first key, and the first timestamp; a fourth computing module, configured to send the first identity identifier, the second location data, and the first verification data to the sink node, wherein the sink node is configured to obtain third location data based on the received second location data, the first key, the second key, and a second timestamp obtained by the sink node, obtain second verification data based on the third location data, the first key, and the second timestamp, and send a first identity authentication result to the sensing node based on the first verification data and the second verification data, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node; A second receiving module, configured to receive the first identity authentication result sent by the sink node; A fifth computing module is used to obtain fourth position data based on the first identity authentication result, the first position data, the first key and the second key, obtain a second identity authentication result based on the first position data and the fourth position data, and send the second identity authentication result to the aggregation node to update the first timestamp, wherein the aggregation node is used to update the second timestamp based on the second identity authentication result.
8. An identity authentication device, characterized in that: Applied to aggregation nodes, including: A second acquisition module is configured to acquire a second physical unclonable function and a second timestamp, wherein the second timestamp is used to represent the number of successful identity authentications between the sink node and the sensing node; a sixth computing module, configured to determine a second identity and a second key according to the second physical unclonable function, and send the second identity and the second key to the sensing node; a third receiving module, configured to receive second location data and a first key sent by the sensing node, wherein the sensing node is configured to generate the first location data, and update the first location data according to the first key, the first timestamp, and the second key obtained by the sensing node to obtain the second location data, wherein the first timestamp is used to represent the number of successful identity authentications between the sensing node and the sink node; a seventh computing module, configured to obtain third position data based on the second timestamp, the second key, the second position data, and the first key, obtain second verification data based on the third position data, the first key, and the second timestamp, and send a first identity authentication result to the sensing node based on the first verification data and the second verification data sent by the sensing node; a fourth receiving module, configured to receive a second identity authentication result sent by the sensing node, wherein the sensing node obtains fourth position data based on the first identity authentication result, the first position data, the first key, and the second key, and obtains the second identity authentication result based on the first position data and the fourth position data; An eighth calculation module is used to update the second timestamp according to the received second identity authentication result.
9. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the identity authentication method according to any one of claims 1 to 6.
10. A computer device, characterized in that: include: memory and processor, The memory stores a computer program; The processor is configured to execute a computer program stored in the memory, and when the computer program is run, the processor is enabled to execute the identity authentication method according to any one of claims 1 to 6.
11. A computer program product comprising computer instructions, characterized in that The computer instructions are executed by a processor to execute the identity authentication method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Kerberos authentication system and based on physical unclonable function
CN111682936A
Authentication and key agreement method and device based on PUF
CN115442112A