A non-interactive instant identity verification and secure data transmission method
By employing non-interactive instant authentication and secure data transmission methods, utilizing global parameters and hash functions, and combining multi-authority center IBC and non-membership proofs, the inefficiency and insecurity of traditional authentication methods in edge computing environments are addressed, achieving efficient and secure identity authentication and data transmission.
Patent Information
- Application Number
- CN202411810224.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-12-10
AI Technical Summary
In edge computing environments, traditional authentication methods rely on user interaction, resulting in inefficient authentication processes and insufficient security. They are particularly vulnerable to security threats such as identity theft and data leakage in large-scale device access and complex network environments.
A non-interactive instant authentication method is adopted, which utilizes global parameters, key derivation and hash functions to achieve authentication without user interaction through collaboration between edge terminals, authentication centers and edge computing servers, and ensures the security of data transmission through encryption technology.
It improves the automation of identity verification, enhances the reliability of encrypted data transmission, reduces the complexity of the authentication process and communication delays, prevents forgery and replay attacks, and ensures the authenticity of edge terminal identities and the security of data transmission.
Smart Images

Figure CN119602955B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of data transmission, and specifically relates to a non-interactive instant identity verification and secure data transmission method. BACKGROUND
[0002] With the continuous development of information technology, especially in the application fields of edge computing and Internet of Things, the security problems of identity verification and data transmission are increasingly prominent. Traditional identity authentication methods, such as authentication based on username and password, two-factor authentication, etc., often have many shortcomings when facing large-scale device access and complex network environment. These traditional methods usually rely on user interaction, requiring users to provide identity information and authentication credentials at each authentication, resulting in inefficiency and security problems in the authentication process, especially in complex network environments and large numbers of terminal devices, which are prone to security threats such as identity theft and data leakage.
[0003] In the edge computing environment, edge terminal devices are usually located at the edge of the network and frequently exchange data with remote servers. In this process, how to achieve efficient and secure identity verification and data encryption transmission without relying on user interaction has become a technical problem to be solved. Traditional authentication methods often require frequent user input and complex communication processes, which not only increase the authentication time and cost, but also increase the possibility of security risks such as man-in-the-middle attacks and replay attacks.
[0004] In order to solve these problems, a non-interactive identity verification and secure data transmission method has emerged. Based on the principles of cryptography, this method uses global parameters, key derivation, hash functions, etc., through the cooperation between edge terminals and authentication centers, edge computing servers, to complete identity authentication without user interaction, and ensures the security of data transmission through encryption technology. This method can effectively reduce the complexity of the authentication process and improve the security and communication efficiency of devices in the edge computing environment.
[0005] Currently, many security protocols based on traditional authentication mechanisms have certain limitations when facing emerging application scenarios such as edge computing and Internet of Things. In order to meet the needs of large-scale device access and high-frequency data transmission, a scheme that can guarantee security and complete identity authentication and data encryption transmission with low latency and high efficiency is needed. Therefore, a non-interactive instant identity verification and secure data transmission method is proposed, which can effectively solve the problems in the existing technology, improve the automation of identity verification, and strengthen the reliability of data encryption transmission, and has important practical application value. SUMMARY
[0006] The present application aims at providing a mounting method and device for low-voltage converter commutation equipment
[0007] The present application aims at providing a mounting method and device for low-voltage converter commutation equipment
[0008] The present application provides a non-interactive instant identity verification and secure data transmission method, comprising the following steps:
[0009] Step S1: the trust authority generates a global parameter and sends the global parameter to the corresponding edge terminal, authentication center and edge computing server;
[0010] Step S2: the edge terminal sends an edge terminal identity identifier to the first authentication center and the second authentication center, and the first authentication center and the second authentication center jointly generate a pseudonym, a MAIBC key and a non-member certificate for the edge terminal, and send the pseudonym, the MAIBC key and the non-member certificate to the edge terminal;
[0011] Step S3: the edge terminal generates an edge terminal public key and private key, and publishes the edge terminal public key and the pseudonym;
[0012] Step S4: the edge terminal generates an instant authentication credential and sends the instant authentication credential to the edge computing server, and the edge computing server authenticates the edge terminal according to the instant authentication credential, if the authentication is successful, step S5 is executed, if the authentication fails, the verification is stopped;
[0013] Step S5: the edge terminal generates a public key information, generates a temporary symmetric key through a key derivation function according to the public key information, encrypts a message using the temporary symmetric key, and generates an encrypted message;
[0014] Step S6: the edge terminal sends the encrypted message and the instant authentication credential to the edge computing server, and the edge computing server decrypts the encrypted message to obtain the message transmitted by the edge terminal.
[0015] Further, the global parameter comprises a cyclic additive group G with a generator g and an order q, identity identifiers ID of the edge terminal, the authentication center and the edge computing server ID∈0,1 * , a public key pk1∈G and a private key a public key pk2∈G and a private key four hash functions H0:G×G→0,1 ★ 、
[0016] Further, the step S2 comprises the following steps:
[0017] Step S2.1: The edge terminal sends its identity identifier to the first authentication center and the second authentication center;
[0018] Step S2.2: The first certification center and the second certification center cooperate to generate pseudonyms for the edge terminal;
[0019] Step S2.3: The first authentication center and the second authentication center generate the MAIBC key for the edge terminal based on the pseudonym and the public and private keys of the first authentication center and the second authentication center and verify it. If the verification is successful, proceed to step S2.4. If the verification fails, the second authentication center exits the key distribution program and the edge terminal registration fails.
[0020] Step S2.4: The first and second authentication centers generate non-membership certificates for the edge terminal and send the pseudonym, MAIBC key, and non-membership certificate to the edge terminal.
[0021] Furthermore, step S2.2 includes the following steps:
[0022] The first certification center randomly selects a random number. in, The first random number, For the multiplicative group modulo q, calculate the first intermediate parameter. pk2 is the public key of the second authentication center, and the first authentication center sends the first intermediate parameter X to the second authentication center.
[0023] After receiving the first intermediate parameter X, the second authentication center generates the pseudonym PID of the edge terminal using the following formula. i :
[0024]
[0025] Where, pid i ID is the pseudonym for edge terminal i. i Let H0 be the identifier of edge terminal i, H0 be the first hash function in the global parameters, and sk2 be the private key of the second authentication center.
[0026] The second authentication center will use the pseudonym PID of the edge terminal. i Send it to the primary authentication center.
[0027] Furthermore, step S2.3 includes:
[0028] The first certification center based on the first random number The public key pk2 of the second authentication center and the pseudonym pid of the edge terminal i The first hash value is generated using the following formula.
[0029]
[0030] wherein H1 is a second hash function in the global parameters;
[0031] The first authentication center generates a first intermediate parameter X according to the first hash value The second intermediate parameter Y is generated by the following formula
[0032]
[0033] wherein sk1 is a private key of the first authentication center;
[0034] The first authentication center sends the second intermediate parameter Y to the second authentication center;
[0035] The second authentication center randomly selects a random number as a second random number r2 The second hash value is generated according to the following formula
[0036]
[0037] wherein, is the second hash value, and H2 is a third hash function in the global parameters;
[0038] The second authentication center verifies the intermediate parameter sent by the first authentication center according to the following equation:
[0039]
[0040] wherein X, are the first intermediate parameter and the second intermediate parameter generated by the first authentication center, respectively;
[0041] If the equation is established, the verification is successful, and step S2.4 is executed, and if the equation is not established, the verification fails, the second authentication center exits the key distribution procedure, and the edge terminal registration fails.
[0042] Further, the step S2.4 includes the following steps:
[0043] The second authentication center updates the second intermediate parameter Y according to the following formula The third intermediate parameter Y' is generated by the following formula
[0044]
[0045] According to the updated third intermediate parameter Y', the partial private key z of the edge terminal is generated i :
[0046]
[0047] in, For the updated second intermediate parameter, z i This is a portion of the private key for the edge terminal;
[0048] The first authentication center generates the first non-membership certificate for the edge terminal. Will Send to the edge terminal;
[0049] The second authentication center generates a second non-membership certificate for the edge terminal. Will Send to the edge terminal.
[0050] Furthermore, step S3 includes the following steps:
[0051] The edge terminal uses the received first intermediate parameter X and third intermediate parameter... Generate the first hash value of the edge terminal With the second hash value of the edge terminal
[0052]
[0053] Based on the first hash value of the edge terminal With the second hash value of the edge terminal Partial private key z for edge terminals i Verification is performed, and the equation is:
[0054]
[0055] If the equation does not hold, then the edge terminal ET i If generating the edge terminal's public and private keys fails, exit the registration process. If the equation is true, proceed with the following steps:
[0056] Edge Terminal ET i Generate the edge terminal public key pk according to the following formula. i Private key sk i Proof of non-membership ω i :
[0057]
[0058]
[0059] Where ω i Used to indicate the edge terminal ET i Public key PK i Not on the cancellation list;
[0060] Edge Terminal ET iThe edge terminal obtains the public key pk i with the pseudonym pid i .
[0061] Further, the step S4 comprises the following steps:
[0062] The edge terminal generates the instant authentication credential, comprising the following steps:
[0063] The edge terminal randomly selects a random number as a third random number According to the third random number, a first instant authentication value R i , a second instant authentication value R' i and an instant authentication intermediate value The formula is:
[0064] R i = r i · pk j
[0065]
[0066] Wherein, pk j is the public key of the edge computing server MEC j , the public key pk j of the edge computing server MEC j obtains the process, and the public key of the edge terminal ET i obtains the process, z j is a partial private key of the edge computing server MEC j , is the fourth random number, and d i is a hash function value calculated by R i , the public key information of the two parties involved and the current time timestamp as input;
[0067] The edge terminal takes the current system time stamp TS i , the time stamp TS i is embedded into the instant authentication credential IAC through d i , and the time stamp TS i is transmitted in plaintext. If the time stamp TS i is modified, the verification of IAC will not be passed;
[0068] According to the current system time stamp TS i , the non-member proof ω i , the first instant authentication value R i , the second instant authentication value R' i and the instant authentication intermediate value , the instant authentication credential is generated as IAC, wherein
[0069] The edge terminal sends the instant authentication credential (IAC) to the edge computing server (MEC). j ;
[0070] Edge Computing Server (MEC) j Get the current system timestamp (TS) j According to timestamp TS j TS can be verified using the following formula. i Is it still valid?
[0071] TS j -TS i >Δ
[0072] Where Δ is a pre-set system parameter, the value of which is related to the specific network environment;
[0073] If the value is greater than Δ, authentication fails; if the value is less than Δ, the edge computing server (MEC) fails. j verify Has it been verified within the Δ time period? If verified, authentication fails; if not verified, authentication succeeds. The edge computing server stores only the instant authentication credentials within a time period Δ.
[0074] Edge Computing Server (MEC) j According to ω i Check the ETi public key pk of the edge terminal i Check if the device is on the revocation list. If it is, authentication fails. If it is not on the revocation list, proceed with the following steps:
[0075] Edge Computing Server (MEC) j Through edge computing server MEC j Public key PK j The first instant authentication value R is determined according to the following equation. i Second instant authentication value R′ i Intermediate value with instant authentication Verification required:
[0076]
[0077] Among them, z j MEC (Multi-access Edge Computing) j Part of the private key, The fourth random number, z j and By edge computing server MEC j Public key PK j get;
[0078] If the equation is established, the authentication is successful, and step S5 is performed. If the equation is not established, the authentication fails.
[0079] Further, the step S5 includes the following steps:
[0080] Edge terminal ET i According to the public key pk i Generate public key information PS ij ,
[0081]
[0082] And use the key generation function KDF(PS ij ,R′ i ,pid j ) to derive the temporary symmetric key K ij ;
[0083] Edge terminal ET i Use the temporary symmetric key K ij Encrypt the message M ij , and the encryption formula is:
[0084]
[0085] Where C ij is the encrypted ciphertext;
[0086] Edge terminal ET i Generate encrypted message
[0087] Further, the step S6 includes the following steps:
[0088] Edge terminal ET i Send the encrypted message To the edge computing server MEC j , and the edge computing server MEC j Obtains the key raw material PS′ ij according to the encrypted message, and the formula is:
[0089]
[0090] Obtain the symmetric key K′ ij according to the key raw material PS′ ij , and the formula is:
[0091] K′ ij = KDF(P′ Sj ,R′ i ,pid i )
[0092] Edge computing server MEC j by a symmetric key K' ij decryption of the ciphertext C ij obtaining the message M ij .
[0093] Compared with the prior art, the present application has the following advantages:
[0094] (1) The present application uses a key management system combining multiple authorization centers IBC and non-member proof, taking into account the security of identity-based cryptography and the flexibility of certificateless cryptography, and a secure encryption method based on authentication preposition technology, which combines the flexibility of authenticated key agreement and the security of authenticated encryption, and realizes non-interactive instant secure data delivery.
[0095] (2) The present application uses a non-interactive identity authentication method, which uses a pre-shared global parameter and public key encryption method between the edge terminal and the edge computing server for identity authentication, avoiding the multiple message exchange in the traditional interactive authentication process, greatly improving the authentication efficiency and reducing the communication delay and system burden.
[0096] (3) The present application uses multiple hash functions and public key cryptography technology, generates temporary keys, instant authentication credentials and non-member proofs, ensures the authenticity of the edge terminal identity and the security of data transmission, effectively prevents security attacks such as forgery and replay, and improves the security and attack resistance of the system.
[0097] (4) The present application combines the mechanism of non-member proof and revocation list, ensures that only the legal and unrevoked edge terminal identity is allowed to communicate, thereby avoiding the access of revoked identity terminals to the system, and enhances the security and credibility of the system.
[0098] (5) The present application generates instant authentication credentials (IAC) and combines time stamp and hash verification to ensure the uniqueness and timeliness of each communication, avoiding the risk of authentication failure or data leakage due to key leakage or misuse. At the same time, through time validity verification and historical record verification, the reliability of the authentication mechanism is further strengthened.
[0099] (6) The present application uses public key information to generate a temporary symmetric key through a key derivation function (KDF), and uses the symmetric key to encrypt the message. This technology can effectively improve the efficiency of data transmission, reduce the computational burden caused by public key encryption, and at the same time ensure that the encrypted message is not tampered with or stolen during transmission.
[0100] (7) The application significantly reduces the network bandwidth and computing resource consumption in the authentication process, optimizes the overall performance of the system, and is particularly suitable for resource-constrained edge computing environments by using non-interactive authentication, generation and verification of instant authentication credentials, and application of symmetric encryption technology under the premise of ensuring security. BRIEF DESCRIPTION OF DRAWINGS
[0101] Figure 1 A flowchart of the method of the application;
[0102] Figure 2 A flowchart of the method of the application; DETAILED DESCRIPTION
[0103] The technical solutions in the embodiments of the application will be clearly and completely described below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are part of, rather than all of, the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by a person of ordinary skill in the art without creative work should fall within the protection scope of the application.
[0104] Embodiment 1
[0105] The embodiment provides a non-interactive instant identity authentication and secure data transmission method, comprising the following steps:
[0106] Step S1: The trust authority generates a global parameter and sends the global parameter to the corresponding edge terminal, authentication center and edge computing server;
[0107] Step S2: The edge terminal sends an edge terminal identity identifier to the first authentication center and the second authentication center, and the first authentication center and the second authentication center jointly generate a pseudonym, a MAIBC key and a non-member certificate for the edge terminal, and send the pseudonym, the MAIBC key and the non-member certificate to the edge terminal;
[0108] Step S3: The edge terminal generates an edge terminal public key and private key, and publishes the edge terminal public key and the pseudonym;
[0109] Step S4: The edge terminal generates an instant authentication credential and sends the instant authentication credential to the edge computing server, and the edge computing server authenticates the edge terminal according to the instant authentication credential, if the authentication is successful, step S5 is executed, if the authentication fails, the verification is stopped;
[0110] Step S5: The edge terminal generates public key information, generates a temporary symmetric key through a key derivation function according to the public key information, encrypts a message using the temporary symmetric key, and generates an encrypted message;
[0111] Step S6: The edge terminal sends the encrypted message and instant authentication credentials to the edge computing server. The edge computing server decrypts the encrypted message to obtain the message transmitted by the edge terminal.
[0112] The global parameters include a cyclic additive group G of order q with generator g, and the identity identifiers ID∈0,1 for the edge terminal, authentication center, and edge computing server. * The public key pk1∈G and the private key of the first authentication center The public key pk2∈G and the private key of the second authentication center Four hash functions H0: G×G→0,1 * ,
[0113] Step S2 includes the following steps:
[0114] Step S2.1: The edge terminal sends its identity identifier to the first authentication center and the second authentication center;
[0115] Step S2.2: The first certification center and the second certification center cooperate to generate pseudonyms for the edge terminal;
[0116] Step S2.3: The first authentication center and the second authentication center generate the MAIBC key for the edge terminal based on the pseudonym and the public and private keys of the first authentication center and the second authentication center and verify it. If the verification is successful, proceed to step S2.4. If the verification fails, the second authentication center exits the key distribution program and the edge terminal registration fails.
[0117] Step S2.4: The first and second authentication centers generate non-membership certificates for the edge terminal and send the pseudonym, MAIBC key, and non-membership certificate to the edge terminal.
[0118] Step S2.2 includes the following steps:
[0119] The first certification center randomly selects a random number. in, The first random number, For the multiplicative group modulo q, calculate the first intermediate parameter. pk2 is the public key of the second authentication center, and the first authentication center sends the first intermediate parameter X to the second authentication center.
[0120] After receiving the first intermediate parameter X, the second authentication center generates the pseudonym PID of the edge terminal using the following formula. i :
[0121]
[0122] Where, pid iID is the pseudonym for edge terminal i. i Let H0 be the identifier of edge terminal i, H0 be the first hash function in the global parameters, and sk2 be the private key of the second authentication center.
[0123] The second authentication center will use the pseudonym PID of the edge terminal. i Send it to the primary authentication center.
[0124] Step S2.3 includes:
[0125] The first certification center based on the first random number The public key pk2 of the second authentication center and the pseudonym pid of the edge terminal i The first hash value is generated using the following formula.
[0126]
[0127] Where H1 is the second hash function in the global parameters;
[0128] The first authentication center uses the first hash value. The second intermediate parameter is generated using the following formula.
[0129]
[0130] Among them, sk1 is the private key of the first authentication center;
[0131] The first certification center will use the second intermediate parameter. Send to the second certification center;
[0132] The second certification center randomly selects a random number as the second random number. The second hash value is generated according to the following formula.
[0133]
[0134] in, H2 is the second hash value, and H2 is the third hash function in the global parameters;
[0135] The second authentication center verifies the intermediate parameters sent by the first authentication center based on its private key according to the following equation:
[0136]
[0137] Among them, X, These are the first intermediate parameters and the second intermediate parameters generated by the first certification center, respectively.
[0138] If the equation is true, the verification is successful, and step S2.4 is executed. If the equation is false, the verification fails, the second authentication center exits the key distribution program, and the edge terminal registration fails.
[0139] Step S2.4 includes the following steps:
[0140] The second certification center updates the second intermediate parameter according to the following formula. Third intermediate parameter
[0141]
[0142] Based on the updated third intermediate parameter Generate a partial private key z for the edge terminal i :
[0143]
[0144] in, For the updated second intermediate parameter, z i This is a portion of the private key for the edge terminal;
[0145] The first authentication center generates the first non-membership certificate for the edge terminal. Will Send to the edge terminal;
[0146] The second authentication center generates a second non-membership certificate for the edge terminal. Will Send to the edge terminal.
[0147] Step S3 includes the following steps:
[0148] The edge terminal uses the received first intermediate parameter X and third intermediate parameter... Generate the first hash value of the edge terminal With the second hash value of the edge terminal
[0149]
[0150] Based on the first hash value of the edge terminal With the second hash value of the edge terminal Partial private key z for edge terminals i Verification is performed, and the equation is:
[0151]
[0152] If the equation does not hold, then the edge terminal ET i If generating the edge terminal's public and private keys fails, exit the registration process. If the equation is true, proceed with the following steps:
[0153] Edge terminal ET i The edge terminal public key pk is generated according to the following formula i Private key sk i Non-member proof ω i :
[0154]
[0155]
[0156] Where ω i is used to indicate that the edge terminal ET i The public key pk i is not in the revocation list;
[0157] Edge terminal ET i The edge terminal public key pk i is combined with the pseudonym pid i .
[0158] Wherein, step S4 comprises the following steps:
[0159] The edge terminal generates an instant authentication credential, comprising the following steps:
[0160] The edge terminal randomly selects a random number as a third random number According to the third random number, the first instant authentication value R i , the second instant authentication value R' i and the instant authentication intermediate value The formula is:
[0161] R i = r i ·pk j
[0162]
[0163] Wherein, pk j is the public key of the edge computing server MEC j , the public key pk j of the edge computing server MEC j is obtained in the same way as the edge terminal ET i The public key obtaining process, z j is a partial private key of the edge computing server MEC j , is a fourth random number, d i is a hash function value calculated by R i , the public key information of the two parties involved and the current time timestamp as input;
[0164] Edge terminal retrieves the current system timestamp TS i Timestamp TS i via d i Embedded in the Instant Authentication Certificate (IAC), timestamp TS i If transmitted in plaintext, such as with timestamp TS i Modification will cause the IAC verification to fail;
[0165] Based on the current system timestamp TS i Non-membership proof ω i First instant authentication value R i Second instant authentication value R′ i Intermediate value with instant authentication The instant authentication credential is generated as IAC, where
[0166] The edge terminal sends the instant authentication credential (IAC) to the edge computing server (MEC). j ;
[0167] Edge Computing Server (MEC) j Get the current system timestamp (TS) j According to timestamp TS j TS can be verified using the following formula. i Is it still valid?
[0168] TS j -TS i >Δ
[0169] Where Δ is a pre-set system parameter, the value of which is related to the specific network environment;
[0170] If the value is greater than Δ, authentication fails; if the value is less than Δ, the edge computing server (MEC) fails. j verify Has it been verified within the Δ time period? If verified, authentication fails; if not verified, authentication succeeds. For storage records, the edge computing server only stores real-time authentication credentials within a time period of Δ.
[0171] Edge Computing Server (MEC) j According to ω i Check the edge terminal ET i Public key PK i Check if the device is on the revocation list. If it is, authentication fails. If it is not on the revocation list, proceed with the following steps:
[0172] Edge Computing Server (MEC) j Through edge computing server MECj Public key PK j The first instant authentication value R is determined according to the following equation. i Second instant authentication value R′ i Intermediate value with instant authentication Verification required:
[0173]
[0174] Among them, z j MEC (Multi-access Edge Computing) j Part of the private key, The fourth random number, z j and By edge computing server MEC j Public key PK j get;
[0175] If the equation is true, authentication is successful, and step S5 is executed; if the equation is false, authentication fails.
[0176] Step S5 includes the following steps:
[0177] Edge Terminal ET i Based on public key pk i Generate public key information PS ij ,
[0178]
[0179] Using the key generation function KDF(PS) ij ,R′ i ,pid j Derive the temporary symmetric key K ij ;
[0180] Edge Terminal ET i Using a temporary symmetric key K ij For message M ij Encryption is performed using the following formula:
[0181]
[0182] Among them, C ij The encrypted ciphertext;
[0183] Edge Terminal ET i Generate encrypted messages
[0184] Step S6 includes the following steps:
[0185] Edge Terminal ET i Encrypted message Send to the edge computing server MEC j MEC (Multi-access Edge Computing) server j Obtain the key material PS′ based on the encrypted message. ij The formula is:
[0186]
[0187] Based on the key material PS′ ij Obtain the symmetric key K′ ij The formula is:
[0188] K′ ij =KDF(PS′) ij ,R′ i ,pid i )
[0189] Edge Computing Server (MEC) j Using the symmetric key K′ ij For ciphertext C ij Decrypt to obtain message M ij .
[0190] Example 2:
[0191] The parts not mentioned in this embodiment are the same as in Embodiment 1.
[0192] This embodiment provides a Non-Interactive Instant Authentication and Secure Data Transmission (NiIA-SDD) protocol designed to overcome the limitations of traditional Public Key Infrastructure (PKI) and interactive key exchange protocols, enabling mobile terminal devices to transmit data to the MEC network immediately after establishing a connection. NiIA-SDD allows authentication before data decryption, simplifying the data transmission process. This authentication is crucial in MEC environments because reducing network latency is a top priority, and this reduces the time required for secure authentication before data transmission. Once a network connection is established, the authenticated edge device can immediately upload data. The nearest MEC server temporarily stores this data and forwards it on behalf of the authenticated entity, eliminating the need for the edge device to create a separate connection with each data receiver. This approach not only reduces the number of connections but also ensures secure data transmission, making it ideal for multi-access edge networks with unstable network topologies. Figure 2 As shown, this embodiment includes the following steps:
[0193] (1) Setup phase: Generate the global parameters required for the protocol.
[0194] (2) Registration phase, including pseudonym generation, MAIBC key distribution and non-member certificate generation.
[0195] (3) Identity verification phase, ET i Generate instant identity verification credential, MEC j Verify the credential.
[0196] (4) Secure data delivery phase, encrypt and send necessary data.
[0197] The protocol includes three main phases: registration, authentication, and secure data distribution. In the registration phase, at least two ACs are involved to distribute keys and pseudonyms for edge terminals ET in the MEC environment. Assume that there are N ETs and M MEC servers (referred to as MECs) in the protocol. ET i denote some edge terminal that initiates authentication and data delivery, MEC j denote some edge server that verifies identity and receives data, 0≤i i ,ID j are their identity identifiers, pid i ,pid j are their pseudonyms. In addition, for convenience of description, all modulo symbols will be omitted in the following protocol description.
[0198] In the registration phase, the trust authority generates global parameters required by the protocol by inputting a security parameter λ into the Setup(λ) function, including a cyclic additive group G of order q with a generator g, identity identifiers ID∈0,1 * , master private and public key pairs of the two ACs and pk1,pk2∈G, four hash functions H0:G×G→0,1 ★ , and The registration phase includes pseudonym generation, MAIBC key distribution, and non-member certificate generation. At the beginning of the registration phase, edge terminal ET i first submits identity identifier ID i to the first authentication center AC1 and the second authentication center AC2, and AC1 and AC2 will generate a pseudonym pid i for ET i according to the following steps.
[0199] AC1 first randomly selects computes and sends X to AC2.
[0200] After receiving X, AC2 computes and sends the pseudonym pid i to AC1.
[0201] Subsequently, AC1 and AC2 distribute keys for ET iDistribute MAIBC keys:
[0202] AC1 calculation and And Sent to AC2; Received Then, AC2 randomly selects... calculate Subsequent verification If the equation is not true, AC2 exits the key distribution procedure, and ET... i Registration failed. If the equation is true, proceed to the next step.
[0203] Calculate AC2 respectively and
[0204] Subsequently, AC1 and AC2 are respectively ET i Generate non-membership proofs and To explain ET i The public key is not on the revocation list, and will be respectively... and Send to ET i .
[0205] Finally, ET i The following steps will be used to assemble the key and generate the complete public and private key sk. i ,pk i :
[0206] ET i Calculate separately and And verify the equation Does it hold true? If the equation does not hold true, then ET i If key assembly fails, exit the registration process; otherwise, proceed to the next step.
[0207] ET i Assembly key and non-membership proof ET i After registration, PK i and pid i public.
[0208] Authentication Phase: The authentication phase occurs at the edge terminal ET. i Preparing to move to the edge computing server MEC i When submitting data, ET i public and private keys MECi Public and private keys of ET The instant authentication credential will be generated according to the following steps:
[0209] ET i Randomly selected And calculate R i = r i · pk j ;
[0210] T i Get the current system timestamp TS i ← Time(·), calculate And Output the instant authentication credential as
[0211] Subsequently, the edge computing server MEC j Verify the credential according to the following steps:
[0212] MEC j First, get the current system timestamp TS j , and check whether TS i is within the valid period, through TS j - TS i > Δ. Where Δ is a system parameter set in advance, its value is related to the specific network environment.
[0213] MEC j Then verify whether has been used by ET i within the Δ time period. It is worth noting that MEC j will use a part of the storage space to record the credentials that have been used and passed the verification within the Δ time period, which can enhance the system's ability to resist replay attacks.
[0214] MEC j Check the non-member proof of ET i , verify whether the public key of ET i is in the revoked public key list.
[0215] MEC j Finally, verify the authentication credential by checking whether the equation is true. If ET i passes all the verifications, it will start the secure data delivery phase.
[0216] Secure data delivery phase, after ET i generates the authentication credential, it needs to send the data according to the following encryption, complete the secure data delivery:
[0217] ET i computing and using a key generation function KDF (PS ij ,R′ i ,pid i ) to derive a temporary symmetric key K ij .
[0218] ETi then encrypts the message (C ij ) using Kij to obtain ciphertext C ij . And sends together to MEC j .
[0219] The process of generating the instant authentication credential is actually a variant of Diffi-Hallman key exchange, so MEC j is able to generate the key material PS′ ij required for Diffi-Hallman key exchange according to the received authentication credential and derive the symmetric key, without the need to provide additional parameters. Specifically, MEC j decrypts the data according to the following steps:
[0220] Edge computing server MEC j obtains the key material PS′ ij from the encrypted message, and the formula is:
[0221]
[0222] The symmetric key K′ ij is obtained from the key material PS′ ij , and the formula is:
[0223] K′ ij = KDF (PS′ ij ,R′ i ,pid i )
[0224] Edge computing server MEC j decrypts the ciphertext C ij using the symmetric key K′ ij to obtain the message M ij .
[0225] If the above functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of software products. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0226] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A non-interactive instant identity verification and secure data transmission method, characterized in that, The method comprises the following steps: Step S1: The trust authority generates a global parameter, and sends the global parameter to a corresponding edge terminal, an authentication center and an edge computing server; Step S2: The edge terminal sends an edge terminal identity identifier in the received global parameter to the first authentication center and the second authentication center, and the first authentication center and the second authentication center generate a pseudonym, a MAIBC key and a non-member certificate for the edge terminal according to the received edge terminal identity identifier, and send the pseudonym, the MAIBC key and the non-member certificate to the edge terminal; Step S3: The edge terminal generates an edge terminal public key and a private key according to the received pseudonym, MAIBC key and non-member certificate; Step S4: The edge terminal generates an instant authentication credential according to the edge terminal public key and the private key, and sends the instant authentication credential to the edge computing server, and the edge computing server authenticates the edge terminal according to the instant authentication credential, and if the authentication is successful, step S5 is executed, and if the authentication fails, the authentication is stopped; Step S5: The edge terminal generates public key information, generates a temporary symmetric key through a key derivation function according to the public key information, encrypts a message using the temporary symmetric key, and generates an encrypted message; Step S6: The edge terminal sends the encrypted message and the instant authentication credential to the edge computing server, and the edge computing server decrypts the encrypted message to obtain the message transmitted by the edge terminal.
2. The method of claim 1, wherein, The global parameters include an edge terminal identity identifier, an authentication center identity identifier, an edge computing server identity identifier, a public key of the first authentication center and a private key , a public key of the second authentication center and a private key , four hash functions; wherein, is a cyclic additive group, a generator of the cyclic additive group is , and an order is ; the identity identifier ; the four hash functions include , , , .
3. The method of claim 1, wherein, The step S2 comprises the following steps: Step S2.1: The edge terminal sends the edge terminal identity identifier to the first authentication center and the second authentication center; Step S2.2: The first authentication center and the second authentication center generate a pseudonym for the edge terminal; Step S2.3: The first authentication center and the second authentication center generate a MAIBC key of the edge terminal according to the pseudonym, the public key and the private key of the first authentication center and the second authentication center, and verify the MAIBC key, if the verification is successful, step S2.4 is executed, and if the verification fails, the second authentication center exits the key distribution program, and the edge terminal fails to register; Step S2.4: The first authentication center and the second authentication center generate a non-member certificate for the edge terminal, and send the pseudonym, the MAIBC key and the non-member certificate to the edge terminal.
4. The method of claim 3, wherein the method further comprises: The step S2.2 comprises the following steps: The first authentication center randomly selects a random number wherein, is the first random number, is a multiplication group of modulo q , calculates a first intermediate parameter wherein is a public key of the second authentication center, and the first authentication center sends the first intermediate parameter to the second authentication center; The second authentication center receives the first intermediate parameter After that, a pseudonym of the edge terminal is generated by the following equation : wherein, is a pseudonym of the edge terminal , is an identity identifier of the edge terminal , is a first hash function in the global parameter, is a private key of the second authentication center; The second authentication center sends the pseudonym of the edge terminal to the first authentication center.
5. The method of claim 3, wherein the method further comprises: The step S2.3 comprises: The first authentication center generates a first hash value based on the first random number , the public key of the second authentication center , and the pseudonym of the edge terminal by the following equation : wherein, is a second hash function in the global parameters; The first authentication center generates a first intermediate parameter based on the first hash value The second intermediate parameter is generated by the following equation : wherein, is a private key of the first authentication center; The first authentication center sends the second intermediate parameter to the second authentication center; The second authentication center randomly selects a random number as a second random number , generates a second hash value according to the following formula : wherein, is a second hash value, is a third hash function in the global parameters; The second authentication center verifies the second intermediate parameter sent by the first authentication center according to the following equation according to the second authentication center private key: wherein, , are respectively a first intermediate parameter, a second intermediate parameter generated by the first certification center. If the equation is established, the verification is successful, and step S2.4 is executed, and if the equation is not established, the verification fails, the second authentication center exits the key distribution program, and the edge terminal fails to register.
6. The method of claim 3, wherein the method further comprises: The step S2.4 comprises the following steps: The second authentication center updates the second intermediate parameter according to the following equation , the third intermediate parameter : According to the updated third intermediate parameter Generating a partial private key of an edge terminal : wherein, is a third intermediate parameter, is a partial private key of the edge terminal; The first authentication center generates a first non-member certificate for the edge terminal , the first authentication center sends the first non-member certificate to the edge terminal The second authentication center generates a second non-member certificate for the edge terminal , the second authentication center sends the second non-member certificate to the edge terminal .
7. The method of claim 1, wherein the method further comprises: The step S3 comprises the following steps: The edge terminal generates a first hash value based on the received first intermediate parameters and the third intermediate parameters The edge terminal generates a first hash value based on the received first intermediate parameters and the third intermediate parameters : According to the edge terminal first hash value With the edge terminal second hash value Part of the private key of the edge terminal Verification, the equation is: If the equation is not true, the edge terminal If the equation is not true, the edge terminal If the equation is true, the following steps are performed: Edge terminal The edge terminal public key is generated according to the following formula and private key With non-member proof : wherein for indicating edge terminals public key not in the revocation list; Edge terminal The edge terminal public key with a pseudonym is disclosed.
8. The method of claim 1, wherein, The step S4 comprises the following steps: The edge terminal generates an instant authentication credential, comprising the following steps: The edge terminal randomly selects a random number as a third random number generates a first instant authentication value according to the third random number , a second instant authentication value and an instant authentication intermediate value , and the formula is: wherein, is a public key of the edge computing server is a public key of the edge computing server is a public key of the edge computing server is a public key of the edge computing server is a public key of the edge computing server , is a public key of the edge computing server is a public key of the edge computing server is a fourth random number, is a hash function value calculated by , public key information of the two parties involved, and a current timestamp as inputs; Edge terminal takes the current system's timestamp , the timestamp is passed through is embedded into the instant authentication credential , the timestamp is transmitted in clear, if the timestamp is modified it will result in the IAC's verification not being passed; According to the current system's timestamp , non-member attestation , first instant authentication value , second instant authentication value with instant authentication intermediate value generating instant authentication credentials wherein ; Edge terminal to authenticate instant credentials Transmitted to edge computing server ; Edge computing server Obtain the timestamp of the current system , according to the timestamp Check by the following formula Whether it is within the validity period: wherein, is a system parameter set in advance, the value of which is related to the specific network environment; If greater than authentication fails, if less than the edge computing server verifies whether it has been verified within a time period, if it has been verified, authentication fails, if it has not been verified, authentication succeeds, and stores a record, the edge computing server only stores the instant authentication credential within a time period; Edge computing server According to Checking edge terminal Public key whether in the revocation list, if in the revocation list, the authentication fails, if not in the revocation list, the following steps are performed: Edge computing server Through the edge computing server Public key The first instant authentication value , the second instant authentication value and the instant authentication intermediate value are verified according to the following equations: wherein, is a partial private key of the edge computing server , is a fourth random number, and is obtained by the edge computing server from the public key . If the equation is established, the authentication is successful, and step S5 is executed, and if the equation is not established, the authentication fails.
9. The method of claim 1, wherein, The step S5 comprises the following steps: Edge termination According to the public key Generating public key information : in, This is a portion of the private key for the edge terminal; It is by The hash function value is calculated using the public key information of both participating parties and the current timestamp as input. This is the first instant authentication value; The first random number; For edge computing servers The public key; and using a key generation function deriving a temporary symmetric key ; Edge terminal Using temporary symmetric key Encrypting a message Encrypting a message wherein, is the encrypted ciphertext; is a third intermediate parameter; are respectively the public keys of the first and second authentication centers; is the edge terminal public key; is an encryption function; Edge terminal Generating an encrypted message wherein, is an instant authentication intermediate value; is a second instant authentication value; is a non-member proof; is a timestamp.
10. The non-interactive instant identity verification and secure data transmission method of claim 9, wherein, Step S6 comprises the following steps: Edge terminal The encrypted message Is sent to an edge computing server , The edge computing server Obtains a key material according to the encrypted message , The formula is: According to the key material Obtaining a symmetric key , the formula is: Edge computing server By symmetric key To decrypt the ciphertext Obtain the message .
Citation Information
Patent Citations
A message authentication method between an unmanned vehicle and a multi-mobile edge computing server
CN109005538A
Industrial environment authentication method based on PUF and block chain
CN114422152A