Multi-Entity Cross-Domain Key Agreement and Authentication Method Based on Multi-Factor Authentication

Through the application of multi-factor authentication and hardware SGX, the problem of multi-entity cross-domain authentication in drone communication is solved, safe and efficient multi-entity cross-domain key negotiation and authentication is achieved, and communication security in a low-altitude economic environment is improved.

CN119767302BActive Publication Date: 2025-07-01NANJING UNIV OF INFORMATION SCI & TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510252791.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-07-01
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

The prior art fails to effectively solve the cross-domain authentication problem between multiple entities in drone communication, resulting in increased computing volume and reduced security, and vulnerability to attacks.

Method used

Multi-entity cross-domain key negotiation and authentication methods based on multi-factor authentication are adopted. Through the registration and authentication process of drones, roadside units, fog nodes and cloud servers, hardware SGX is used to improve protocol security, reduce duplicate authentication, and dynamically allocate fog node computing resources.

Benefits of technology

In a low-altitude economic environment, the security of frequent cross-domain communications of drones is ensured, the computing pressure of a single cloud node is reduced, and the security of multi-entity authentication and protocol security is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119767302B_ABST
    Figure CN119767302B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication, specifically as follows: Step 1: The unmanned aerial vehicle (UAV), roadside unit, and fog node register with the cloud server CS; Step 2: UAV login phase; Step 3: After the UAV logs in and first passes through the area responsible for a certain roadside unit, the UAV starts to conduct authentication communication with the roadside unit in a single-domain scenario; Step 4: When the UAV is about to move into the area where the next roadside unit is located, the current roadside unit where the UAV is located sends the pseudo-identity of the UAV to. If this UAV is communicating with for the first time, it enters the data request, requests the private data of the UAV from CS, and then proceeds to Step 5, otherwise directly proceeds to Step 5; Step 5: Conduct cross-region authentication for the UAV and.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of communication security, and particularly relates to a multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication. Background Art

[0002] With the rapid development of the low-altitude economy, the utilization of low-altitude airspace by all parties has become more and more sufficient. Communication needs exist not only between unmanned aerial vehicles (UAVs) and ground control systems, but also between UAVs, between users and UAVs, etc. Since the low-altitude economy is usually in an exposed and open environment and often needs to cross domains, both physical attacks and virtual network attacks are relatively easy, which can easily cause economic losses and security problems. Therefore, it is extremely necessary to establish an authentication and key negotiation mechanism during communication to protect privacy and property security.

[0003] Existing technical solutions only consider the communication between UAVs and edge servers. Usually, smart card information collection methods are used, and authentication methods based on PUF are used to authenticate single verifiers and multi-verifiers. Or, due to portability requirements, only after the node (cloud server) issues the materials required for session authentication to the UAV, these materials are continuously used during UAV sessions. These methods can meet some security requirements, but are relatively easy to be cracked, and do not consider the communication needs between UAVs, edge nodes, and users, as well as the cross-domain situations among them. When multiple entities authenticate each other, an attack on a single node will cause the entire system to be unable to correctly complete tasks, and repeated authentication of some entities during cross-domain will increase the computational complexity and bring secondary attacks. Summary of the Invention

[0004] Object of the Invention: In order to solve the problems existing in the above-mentioned prior art, the present invention provides a multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication.

[0005] Technical Solution: The present invention provides a multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication, and the specific method is as follows:

[0006] Step 1: Register the UAV , the roadside unit and the fog node with the cloud server CS;

[0007] Step 2: UAV login phase;

[0008] Step 3: After the UAV logs in and passes through the responsible area of a certain roadside unit for the first time, the UAV starts to conduct authentication communication with the roadside unit in a single-domain scenario; and mark this roadside unit as ;

[0009] Step 4: When the UAV is about to move to the next roadside unit When in the responsible area, send the pseudo-identity of the drone to , if the drone is communicating with for the first time, enter the data request, request the private data of the drone from the CS, and then go to step 5, otherwise directly go to step 5;

[0010] Step 5: Perform cross-region authentication on the drone and Beneficial effects: In the new scenario of the low-altitude economy, the present invention ensures the security of the cross-domain communication requirements frequently encountered by drones. By using cloudlet nodes, it reduces the computing pressure on a single cloud node, considers the dynamic allocation of fog node memory, and makes full use of computing resources. The present invention adopts multi-factor authentication, taking into account the communication requirements and cross-domain situations among drones, edge nodes, users, and between drones and users, increasing the security of authentication and avoiding repeated authentication among multiple entities; the present invention applies the hardware SGX to the spatial drone communication environment, improving the security of the protocol.

[0011] Brief description of the drawings Brief description of the drawings

[0012] Figure 1 is the system authentication scenario diagram of the present invention. Detailed implementation manners

[0013] The drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation of the present invention.

[0014] The multi-entity cross-domain authentication scenario diagram of the present invention is as shown in Figure 1 , including a system model of five entities: roadside unit, user, drone, cloud node, and fog node.

[0015] The multi-factor authentication-based multi-entity cross-domain key negotiation and authentication method of the present invention constructs a system model including five entities: roadside unit, user, drone, cloud node, and fog node; it generally includes a drone registration stage, a roadside unit (RSU) registration stage, a user registration stage, a fog node registration stage, a login and authentication stage, a notification stage, a data request stage, and a cross-domain authentication stage.

[0016] The drone registration stage includes the following steps:

[0017] Step 1.1: First, the drone selects an identity , a password , a biometric and a random number , use the generation function of the fuzzy extractor to extract a randomly distributed string from the biometric feature and the public auxiliary string ; finally, transmit the identity to the CS (Cloud Serve) cloud server through a secure channel.

[0018] Step 1.2: After receiving the message, CS selects a random number , calculates the pseudo-identity of the UAV and the private data of the UAV , stores in the database, and finally transmits it to the corresponding UAV through a secure channel. h(.) represents the hash function, is the long-term key of CS.

[0019] Step 1.3: After receiving the message, the UAV calculates , , , is the message digest, which is used to verify the integrity and correctness of the identity information during login. is the ciphertext after encrypting the password. is the data after encrypting the private data of the UAV. represents the exclusive OR operation; the UAV stores in the on-board unit OBU.

[0020] Roadside unit registration phase, including the following steps:

[0021] Step 2.1: The j-th roadside unit selects an identity and a random number ; and transmits to CS through a secure channel.

[0022] Step 2.2: After receiving the message, CS selects a random number , calculates the pseudo-identity of the roadside unit and the private data Stores { in the database. CS sends { } to the corresponding roadside unit, and at the same time sends { , , } to all fog nodes.

[0023] Step 2.3: The roadside unit stores the received message in the memory.

[0024] Step 2.4: After receiving the message, the fog node saves to the database, and at the same time stores { , } Save it to the software protection extension module SGX.

[0025] The fog node registration phase includes the following steps:

[0026] Step 3.1: Taking the m-th fog node as an example, the fog node selects an identity , a random number , and sends the identity and the random number to the CS through a secure channel.

[0027] Step 3.2: After receiving the message, the CS selects a random number , calculates the pseudo-identity of the fog node and the private data , saves in the database, and sends { , } to the fog node through a secure channel;

[0028] Step 3.3: The fog node stores the received message in the database.

[0029] The login and authentication phase includes the following steps:

[0030] Login phase: The user first inputs the identity, password, and scans the biometric features of the UAV. The UAV calculates a new string using the regeneration function of the fuzzy extractor based on the biometric features input by the user, substitutes the identity, password, biometric features of the UAV input by the user, and into the calculation formula of to obtain , and verifies whether and are equal. If they are equal, the login is successful; otherwise, the login fails.

[0031] In the single-domain scenario, the process of the UAV and a certain roadside unit to achieve authentication is as follows:

[0032] Step 4.1: After successful login, selects a random number and a timestamp . The UAV calculates its own private data using the following formula according to the random number, , and :

[0033] = h( || )

[0034] =( || )

[0035] =h( || )

[0036] =h( || || || )

[0037] Among them, is the value obtained by jointly encrypting the identity, pseudo-identity, and private data of the UAV using a random number, is the value obtained by encrypting the pseudo-identity and private data of the UAV, is the UAV and the roadside unit parameters used by the fog node to verify the UAV during the authentication process.

[0038] The UAV sends as data to the roadside unit .

[0039] Step 4.2: After receiving the message, verify the freshness of the timestamp in (in this embodiment, verifying the freshness of the timestamp specifically means: calculating the absolute value of the difference between the time when the data is received and the timestamp in the data. If the absolute value of this difference is greater than or equal to the preset time threshold, the verification fails), if the verification fails, terminate the authentication, otherwise continue the authentication, Pass Retrieve the private data stored in the SGX. If it is not retrieved, it means that this UAV and are communicating for the first time or the data in has been attacked and tampered with; if it is not retrieved, then Send a data request to the CS to request the private data of the UAV, and then go to Step 4.3; otherwise, it means that there has been communication before, and go to Step 4.3; is the value received from .

[0040] Step 4.3: Select a random number and a timestamp , calculate , and :

[0041]

[0042]

[0043] = h( || || || )

[0044] Among them, is the encrypted value of the private data and the pseudo - identity of the roadside unit, is the value obtained by encrypting the private data and pseudo - identity of the roadside unit with a random number; is the parameter used by the fog node to verify the roadside unit during the authentication process between the drone and the roadside unit ;

[0045] is sent to the corresponding fog node as data where is used as data ; among them, is the value received by the roadside unit; is the value received by the roadside unit, is the value received by the roadside unit.

[0046] Step 4.4: After receiving the data, the fog node verifies the freshness of the timestamp in . If the verification fails, the authentication is terminated. Otherwise, according to the received pseudo - identity of the drone, the private data of the drone is matched. If no match is found, the authentication is terminated. If a match is found, the identity of the drone and the random number selected by the drone are deduced:

[0047] ( ) =

[0048]

[0049] Among them, is for and Encrypted value indicating the value received by the fog node

[0050] Calculation parameter :

[0051]

[0052] wherein is the value received by the fog node. If and are equal, it indicates that the data in M1 and M2 has not been attacked, and the authentication continues; otherwise, the authentication is terminated is the value received by the fog node

[0053] The fog node matches the pseudo - identity of the received roadside unit with the identity and the private data of the roadside unit. If no match is found, the authentication is terminated; otherwise, the random number selected by the roadside unit and the parameter are deduced :

[0054]

[0055] =h( || || || )

[0056] wherein is the value received by the fog node, is the value obtained by substituting and into the formula for calculating , is the value received by the fog node

[0057] If is equal to , the authentication continues and proceeds to step 4.5; otherwise, the authentication is terminated is the value received by the fog node

[0058] Step 4.5: The fog node selects a timestamp , calculate the parameters used by the roadside unit to verify with the fog node during the authentication process of the UAV and the roadside unit :

[0059]

[0060]

[0061] Among them, is the value obtained by encrypting the UAV identity and the roadside unit identity combined with a random number; the fog node sends the data as the data to the roadside unit .

[0062] Step 4.6: Verify the freshness of the timestamp in after receiving the data. If the verification fails, terminate the authentication; otherwise derive the UAV's identity and the random number selected by the UAV using the following formula, and calculate the session key for the roadside unit to communicate with the UAV:

[0063]

[0064]

[0065] Among them, is the value received.

[0066] Calculate the parameter according to the following formula:

[0067]

[0068] If is equal to , continue the authentication; otherwise, terminate the authentication; is the value received by the roadside unit, is the value received by the roadside unit.

[0069] Select a timestamp , and calculate the parameters used by the UAV to verify with the roadside unit during the authentication process of the UAV and the roadside unit:

[0070]

[0071]

[0072] Among them, is and the value after encrypting the combination of the random number; Send the data as the data to the drone.

[0073] Step 4.7: After receiving the data, the drone verifies the freshness of the timestamp in , the random number selected by the roadside unit and the session key

[0074]

[0075]

[0076] Among them, is the value received by the drone.

[0077] Calculate the parameter :

[0078]

[0079] Among them, is the value received by the drone.

[0080] If is equal to , the drone and complete mutual authentication and establish a session key, otherwise terminate the authentication; is the value received by the drone.

[0081] In step 4.2 The stage of sending a data request to the CS to request private data about the drone involves three entities, namely the roadside unit , the CS, and the fog node; the specific details of this stage are as follows:

[0082] Step A: Generate the request data , select the random number and the timestamp , and calculate the value after encrypting the combination of the roadside unit identity and private data with the random number And the parameters used by the CS to verify with the roadside unit in step 3.4 :

[0083]

[0084]

[0085] Send as data to the CS.

[0086] Step B: After the CS receives the data, verify the freshness of the timestamp in it. If the verification fails, terminate the authentication. Otherwise, the CS matches the corresponding identity according to the received pseudo identity If no match is found, it indicates that the data has been attacked and the authentication is terminated. Otherwise, deduce the private data and random number of to obtain the deduced private data and random number : and random number :

[0087]

[0088] )

[0089] Calculate the parameter :

[0090]

[0091] If and are equal, go to step C. Otherwise, terminate the authentication; is the value of received by the CS; is the value of received by the CS.

[0092] Step C: The CS selects the timestamp and and uses to encrypt the private data of the drone through symmetric encryption to obtain the encrypted data and calculate the parameter used by the roadside unit to verify with the CS:

[0093]

[0094]

[0095] Among them, indicates the use of for encryption operations.

[0096] The CS matches the identity of the fog node according to the pseudo-identity of the received fog node and calculates the private data of the fog node , uses to encrypt through symmetric encryption technology to obtain the encrypted data , and calculates the verification parameter of the fog node to the CS: :

[0097]

[0098]

[0099] Among them, indicates the use of for encryption operations.

[0100] The CS takes as the data and sends it to the roadside unit , and takes as the data M7 and sends it to the fog node.

[0101] Step D: After receiving the data, verify the freshness of the timestamp in . If the verification fails, terminate the authentication. Otherwise, calculate the parameter :

[0102]

[0103] Among them, is the value received , and is the value received .

[0104] If and are not equal, terminate the authentication. If they are equal, it indicates that has not been attacked, that is, . Decrypt to obtain the decrypted private data of the UAV, and save in the SGX. is the value received . ​

[0105] After the fog node receives the data, it verifies the freshness of the timestamp in it. If the verification fails, the authentication is terminated. Otherwise, the parameters are calculated :

[0106]

[0107] Among them, is the value of received by the fog node, the value of received by the fog node.

[0108] If and are not equal, the authentication is terminated. If they are equal, then is decrypted to obtain the private data of the drone after decryption. The fog node stores in SGX; is the value of received by the fog node.

[0109] The data request phase is a cross-domain data request phase, including the following steps:

[0110] Step 5.1: First, generate a data request , select a random number and a timestamp , and calculate the parameter for the fog node to verify with

[0111]

[0112]

[0113] Among them, is the value obtained by encrypting the identity and the private data of using the random number and the timestamp, Take { } as the data and send it to the fog node.

[0114] Step 5.2: After the fog node receives the message, it verifies the freshness of the timestamp in it. If the verification fails, the authentication is terminated. Otherwise, the fog node matches the pseudo-identity it received to the identity of and finds the private data of in SGX of , and then derive a random number according to the following formula:

[0115]

[0116] where, is the derived random number, is the value of received by the fog node;

[0117] Calculate the parameter :

[0118]

[0119] where, is the value of received by the fog node.

[0120] If and are equal, continue the authentication; otherwise, terminate the authentication; is the value of received by the fog node.

[0121] The fog node selects a timestamp , and the fog node finds the private data of the drone corresponding to in SGX according to the pseudo-identity of the received drone, and encrypts to obtain the encrypted data , and calculates the parameter for verifying to the fog node in the data request phase :

[0122]

[0123]

[0124] where, represents the encryption operation using .

[0125] The fog node sends as the data to .

[0126] Step 5.3: Verify the freshness of the timestamp in after receiving the message. If the verification fails, terminate the verification; otherwise, decrypt , and calculate the parameter :

[0127]

[0128] Among them, is the received value, is the received value.

[0129] If and are equal, the authentication is successful. Then decrypt to obtain the private data of the drone. At this time, the successful authentication indicates that the data has not been tampered with. Then the private data of the drone obtained by decryption and the original private data of the drone are the same, otherwise terminate the authentication; is the received value.

[0130] The notification stage includes the following steps:

[0131] During the communication between the drone and it will inform that it will move to the area 2 where is located. At this time will be informed in advance will determine whether the drone has communicated with itself through the pseudo-identity of the drone sent by . If it is the first communication, enter the cross-domain data request stage and request the private data of the drone from the fog node. If there has been communication, when the drone enters this area and communicates with , skip the data request stage and directly enter the cross-domain authentication stage.

[0132] Step 6.1: First, generate the request data , select the timestamp , and calculate the verification parameter used for the fog node to verify with the roadside unit :

[0133]

[0134] Take as the data and send it to the fog node.

[0135] Step 6.2: After receiving the data, the fog node verifies the freshness of the timestamp in . If the verification fails, terminate the authentication. Otherwise, according to the roadside unit received by the fog node Pseudo-identity Match Identity , calculate parameters :

[0136] Among them, is the value of received by the fog node.

[0137] If and are equal, the fog node selects the timestamp and, according to the pseudo-identity of the received roadside unit matches the identity to calculate the parameters for the verification to the fog node in the notification phase , otherwise terminate the authentication; is the value of received by the fog node:

[0138]

[0139] The fog node takes as data and sends it to ; is the requested data received by the fog node , is the received by the fog node.

[0140] Step 6.3: After receiving the data check the freshness of the timestamp in . If the verification fails, terminate the authentication. Otherwise, calculate the parameter

[0141]

[0142] using the following formula: is the received timestamp value. If and are not equal, terminate the authentication. Otherwise, retrieve the private data of the drone according to the pseudo-identity of the received drone. If not retrieved, it is considered the first communication. is the value of received by the fog node.

[0143] The cross-domain authentication phase includes the following steps: ​

[0144] Step 7.1: The drone selects a random number and a timestamp and calculates the parameters for verifying the drone during the cross-domain authentication phase : :

[0145]

[0146]

[0147]

[0148] Among them, is the value after encrypting the drone's pseudo-identity, the drone's private data, and the pseudo-identity ; is the value after encrypting the drone using and the random number . The drone will send as the data to ;

[0149] Step 7.2: After receiving the data, verify the freshness of the timestamp in the data . If the verification fails, terminate the authentication; otherwise calculate the random number selected by the drone in Step 7.1 according to the following formula:

[0150]

[0151] Among them, is the random number selected by the drone in Step 7.1 calculated, is the identity of the received drone; is the value of received, is for the pseudo-identity of the received drone , the drone's private data, and the pseudo-identity after encryption; The expression of

[0152]

[0153] Calculate the parameter through the following formula:

[0154]

[0155] Among them, is the received timestamp;

[0156] Judge and whether they are equal. If not, terminate the authentication; otherwise, go to step 7.3; is the value received;

[0157] Step 7.3: Select a random number and a timestamp , and calculate the parameters for the cross-domain authentication stage used by the drone to authenticate, as well as the key for initiating a call to the drone :

[0158]

[0159]

[0160] Among them, , is the value obtained by encrypting the identity of using the random number and ; Take as the data and send it to the drone;

[0161] Step 7.4: After the drone receives the data, verify the freshness of the timestamp in . If the verification fails, terminate the authentication; otherwise, the drone calculates the selected random number through the following formula:

[0162]

[0163] Among them, is the calculated selected random number, is the identity of the received by the drone, is the value received by the drone;

[0164] Calculate the parameter and the key for the drone to initiate a call to

[0165]

[0166]

[0167] in, Timestamp received by the drone If and If they are equal, the certification is passed, and the drone and Complete mutual authentication and establish session keys, otherwise terminate authentication.

[0168] During the user registration phase, users only need to register with the cloud node once. After authentication with the cloud node, the cloud node authenticates the drone. The initial communication between the user and the drone is completed through the cloud and fog nodes. After that, the user participates in the entire system communication as part of the drone without the need for separate communication.

[0169] Considering that a single fog node has a large amount of computational complexity in processing all requests at once, this embodiment adopts a load balancing algorithm. The communication sender searches for the three nearest fog nodes and distributes the workload in real time according to the remaining memory and computing power to reduce the computational pressure of a single fog node.

[0170] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present invention will not further describe various possible combinations.

Claims

1. A multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication, characterized in that: The method is as follows: Step 1: Drone E i , Roadside Unit RSU j and fog node FS m Register with the cloud server CS; Step 2: Drone login stage; Step 3: After the drone logs in, when it passes through the responsible area of ​​a roadside unit for the first time, the drone begins to communicate with the roadside unit for authentication in a single-domain scenario; And the roadside unit is recorded as RSU1; Step 4: When the drone is about to move to the area under the responsibility of the next roadside unit RSU2, RSU1 sends the pseudo-identity of the drone to RSU2. If the drone is communicating with RSU2 for the first time, it enters the data request process. RSU2 requests the drone's private data from CS and then goes to step 5. Otherwise, it goes directly to step 5. Step 5: The drone and RSU2 perform cross-region authentication; The specific stages of drone registration are: Drone ID i Generate identity i , Password ID i , Biometrics i and random number PSW i , using the generating function of the fuzzy extractor to extract a randomly distributed string σ from the biometric i , and generate a public auxiliary string τ i , then the identity E i Transmit to CS via secure channel; CS receives the drone’s ID i Then, select a random number r c , calculate the drone’s pseudo identity PID i and private data TK EC ; and {PID i , TK EC }Save in the database and transmit to the drone through a secure channel; The drone receives {PID i , TK EC }, the summary information P is calculated according to the following formula i , and encrypt its own private data to obtain the encrypted data TR i : P i =h(ID i ||RPW i ||r i ); in, Indicates XOR operation, RPW i RPW is the ciphertext of the password. i =h(PSW i ||σ i ), h(·) represents the hash function, and then {PID i , r i , P i , TR i , τ i }Save in the onboard unit OBU; Roadside unit registration is specifically: Roadside unit RSU j Select ID j and a random number r j ; and {ID j , r j }Sent to CS via secure channel; CS receives TC RC Then select a random number {PID j , ID j }, calculate the pseudo identity RSU of the roadside unit j and private data {ID j , r j }; CS will {PID j , TK RC } is stored in the database and r s Send to PID j , {PID j , ID j , TK RC }Send to all fog nodes; RSU j {PID j , TK RC } is stored in memory, and the fog node stores {PID j , ID j } is saved in the database, and {PID j , TK RC }Save in the software protection extension module SGX; The specific registration of fog nodes is as follows: fog nodes select identity ID f and a random number r f , and replace {ID f , r f }Send it to CS through a secure channel; after receiving the message, CS selects a random number r CS , calculate the pseudo identity PID of the fog node f and private data TK FC ; Set {PID f , ID f } is saved in the database, and {PID f , TK FC }Transmitted to fog nodes through secure channels; The fog node saves the received data in the database; In step 4, it is determined whether the drone and RSU2 are communicating for the first time according to the following steps: Step 4.1: RSU1 first generates the request data Not j , select timestamp T A , calculate the parameter D1 used for the fog node to verify the roadside unit RSU1 in step 4: D1=h(PID j1 ||ID j1 ||T A ); RSU1 will {Not j , PID i , PID j1 , PID j2 , D1, T A } as data M a Sent to fog node; PID j2 is the pseudo identity of RSU2; PID j1 is the pseudo identity of RSU1, ID j1 is the identity of RSU1; Step 4.2: After receiving the data, the fog node verifies M a The freshness of the timestamp in the fog node. If the verification fails, the authentication is terminated. Otherwise, the pseudo identity PID of the roadside unit RSU1 received by the fog node is used. j1,f Match the identity ID of RSU1 received by the fog node j1,f The freshness of the verification timestamp is to calculate the absolute value of the difference between the time when the data is received and the timestamp in the data. If the absolute value of the difference is greater than or equal to the preset time threshold, the verification fails. j1,f , ID j1,f and T A,f Substitute into the formula for calculating D1 and get the parameter D1'; T A,f is the T received by the fog node A The value of If D1' and D 1,f If they are equal, the fog node selects timestamp T B , and based on the pseudo identity PID received from the roadside unit RSU2 j2,f Match the identity ID of RSU2 received by the fog node j2,f , calculate the parameters D2, D used for RSU2 to verify the fog node in step 4 1,f is the value of D1 received by the fog node; otherwise, the authentication is terminated; D2=h(PID j2,f ||ID j2,f ||T B ); The fog node will {Not j,f , PID i,f , D2, T B } as data M b , sent to RSU2; Not j,f Not the request data received by the fog node j , PID i,f PID received by the fog node i The value of Step 4.3: RSU2 receives the data and verifies M b If the verification fails, the authentication is terminated. Otherwise, the parameter D2' is calculated by the following formula: in, The timestamp T received by RSU2 B The value of ID j2 is the identity of RSU2, if D2′ and D 2,f If they are not equal, the authentication is terminated. Otherwise, RSU2 retrieves the drone’s private data based on the received drone’s pseudo-identity. If it is not retrieved, it is considered as the first communication. 2,f is the value of D2 received by the fog node.

2. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 1 is characterized in that: The expressions of the drone’s pseudo identity and private data are as follows: PID i =h(ID i ||r c ); TK EC =h(PID i ||K CS ); Among them, K CS It is the long-term key of CS; The expressions for the pseudo-identity and private data of the roadside unit are as follows: PID j =h(ID j ||r j ||r s ); TK RC =h(PID j ||K CS ); The expressions of the pseudo identity and private data of the fog node are as follows: PID f =h(ID f ||r f ||r cs ); TK FC =h(PID f ||K CS )。 3. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 1 is characterized in that: The drone login authentication is specifically as follows: the user logs in to the drone, enters the drone's identity, password, and biometrics, and the drone calculates a new string σ using the regeneration function of the fuzzy extractor based on the biometrics entered by the user i ', the user inputs the drone's identity, password, biometrics, and σ i Substitute into P i In the calculation formula, we get P i ′, verify P i ′ and P i Are they equal? ​​If they are equal, the login is successful, otherwise the login fails.

4. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 1, characterized in that: The step 3 is specifically as follows: Step 3.1: After the drone successfully logs in, a random number N is generated i and timestamp T1, the drone uses the following formula to calculate its own private data TK based on the random number EC : Step 3.2: Calculate the parameter E1 used by the fog node to verify the drone in step 3: E1= h (ID i ||N i ||THE EC ||T1); in, TN EC =h(TK EC ||PID i ), TE EC TN is the value obtained by encrypting the drone identity, pseudo identity and private data with random numbers. EC is the encrypted value of the drone’s pseudo identity and private data; the drone will {PID i ,TE EC , E1, T1} is sent as data M1 to the roadside single RSU1; Step 3.3: After receiving the data, RSU1 verifies the freshness of the timestamp in M1. If the verification fails, the authentication is terminated. Otherwise, go to step 3.

4. The freshness of the timestamp verification is: calculate the absolute value of the difference between the time when the data is received and the timestamp in the data. If the absolute value of the difference is greater than or equal to the preset time threshold, the verification fails. Step 3.4: RSU1 receives the pseudo-identity PID of the drone i ^ Retrieve PID in SGX i ^ If the corresponding private data is not retrieved, RSU1 sends a data request to CS to request the private data of the drone, and then goes to step 3.5 to continue authentication. If it can be retrieved, it goes directly to step 3.5 to continue authentication; Step 3.5: RSU1 selects a random number N j The parameter E2 used by the fog node to verify the roadside unit in step 3 is calculated using the timestamp T2: <h2 style=";text-align:left;direction:ltr">E2=<h2 style=";text-align:left;direction:ltr"> h <h2 style=";text-align:left;direction:ltr"> (ID<h2 style=";text-align:left;direction:ltr"> j1 <h2 style=";text-align:left;direction:ltr"> ||N<h2 style=";text-align:left;direction:ltr"> j <h2 style=";text-align:left;direction:ltr"> ||TE<h2 style=";text-align:left;direction:ltr"> RC <h2 style=";text-align:left;direction:ltr"> ||T2); in, TN RC =h(TK RC1 ||PID j1 ), TN RC is the private data TK of the roadside unit RSU1 RC1 and pseudo identity PID j1 The encrypted value, TE RC The value obtained by encrypting the private data and pseudo-identity of the roadside unit with a random number; ID j1 is the identity of RSU1, then RSU1 will {PID i ^,TE EC ^, E1^, T1^, PID j1 ,TE RC , E2, T2} is sent as data M2 to the corresponding fog node; where TE^ EC TE received by the roadside unit EC The value of; E1^ is the value of E1 received by the roadside unit, T1^ is the value of T1 received by the roadside unit; Step 3.6: After receiving the data, the fog node verifies the freshness of the timestamp in M2. If the verification fails, the authentication is terminated. Otherwise, according to the pseudo identity PID of the received drone i ^^Match the drone's private data TK EC ^^, if no match is found, the authentication is terminated. If a match is found, the drone's identity ID is derived based on the private data of the matched drone. i ′ and the random number N selected by the drone i ′: Among them, TN EC For PID i ^^ and TK EC ^^Encrypted value, TN EC =h(PID i ^^||TK EC ^^), Indicates the fog node receives The value of ID i ′,N i ′, Substitute T1^^ into the formula for calculating E1 to obtain the verification parameter E1′. If E1′ and E1^^ are equal, continue authentication and go to step 3.7, otherwise terminate authentication; E1^^ is the value of E1^ received by the fog node, and T1^^ is the value of T1^ received by the fog node; Step 3.7: The fog node receives the pseudo identity PID of the roadside unit RSU1. j1 ^, matching the ID of the roadside unit RSU1 j1 ^ and private data TK RC1 ^, if no match is found, the authentication is terminated, otherwise the random number N selected by the roadside unit RSU1 is derived j ′: Among them, TE RC ^TE received by the fog node RC The value of TN RC ^ is the PID j1 ^ and TK RC1 ^Substitute into the calculation of TN RC The value obtained after the formula; N j ′, ID j1 ^,TE RC ^ and T2^ are substituted into the formula for calculating E2 to obtain the verification parameter E2'. If E2' is equal to E2', the authentication continues and goes to step 3.8, otherwise the authentication is terminated; E2^ is the value of E2 received by the fog node, and T2^ is the value of T2 received by the fog node; Step 3.8: The fog node selects timestamp T3 and calculates the parameter E3 used by the roadside unit to verify the fog node in step 3: E3 = h(ID j1 ^||N j '||TE FR ||T3); Among them, TE FR The value is the encrypted value of the drone identity and the roadside unit identity combined with the random number. The fog node sends data {TE FR , E3, T3} is sent as data M3 to the roadside unit RSU1; Step 3.9: After receiving the data, RSU1 verifies the freshness of the timestamp in M3. If the verification fails, the authentication is terminated. Otherwise, TE FR ^, N j , ID j1 Substitute T3^ into the formula for calculating E3 to obtain parameter E3′; T3^ is the value of T3 received by the roadside unit; TE FR ^TE received by the roadside unit FR The value of If E3^ and E3′ are equal, authentication continues and RSU1 uses the following formula to derive the drone’s ID″ i and the random number N chosen by the drone i ″, and calculate the session key SK for the roadside unit to initiate a session with the drone i , otherwise the authentication is terminated: SK i =h(ID″ i ||ID j1 ||N i ″||N j ); Step 3.10: RSU1 selects timestamp T4 and calculates parameter E4 used for the drone to verify with the roadside unit in step 3: E4 = h(ID″) i ||N i ″||TE RE1 ||T4); Among them, TE RE1 ID i and ID j1 Combined with the encrypted value of the random number, The data {TE RE1 , E4, T4} is sent to the drone as data M4; Step 3.11: After receiving the data, the drone verifies the freshness of the timestamp in M4. If the verification fails, the authentication is terminated. Otherwise, the drone uses the following formula to derive the identity ID of the roadside unit ′ j1 , the random number N″ selected by the roadside unit j And the session key SK for the drone to initiate a session with the roadside unit i ′: (ID′ j1 ||N″ j )=TE RE1 ^h(ID i ||N i ); SK i ′=h(ID i ||ID′ j1 ||N i ||N″ j ); Among them, TE RE1 ^TE received by the drone RE1 The value of ID i , N i ,TE RE1 ^ and T4^ are substituted into the formula for calculating E4 to obtain the parameter E4′. If E4^ is equal to E4′, the UAV and RSU1 complete mutual authentication and establish a session key, otherwise the authentication is terminated; E4^ is the value of E4 received by the UAV, and T4^ is the value of T4 received by the UAV.

5. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 4 is characterized in that: The private data requested about the drone in step 3.4 is specifically: Step A: RSU1 generates request data Req j1 , choose a random number N R and timestamp T5, and calculate the roadside unit identity and private data combined with the random number encrypted value TE RC1 And the parameter E5 used for CS to verify the roadside unit in step 3.4: E5⼝h(ID j1 ||N R ||TE RC1 ||T5); {Req j1 , PID i ^, PID j1 , PID f ,TE RC1 , E5, T5} is sent to CS as data M5; Step B: After receiving the data, CS verifies the freshness of the timestamp in M5. If the verification fails, the authentication is terminated. Otherwise, CS receives the pseudo-identity PID of RSU1. j1,cs Match the corresponding identity ID j1,cs If no match is found, it indicates that data M5 is under attack and the authentication is terminated. If a match is found, the private data and random number N of RSU1 are R Perform derivation to obtain the derived private data TK RC1,cs and a random number N R ′: yourself RC1,CS =h(PID j1,cs ||K CS ); Among them, TE RC1,CS TE received for CS RC1 The value of K CS It is the long-term key of CS; N R ′, ID j1,cs , T 5,CS and TE RC1,CS Substitute it into the formula for calculating E5 to obtain the parameter E5′; if E5′ and E 5,CS If they are equal, go to step C, otherwise terminate the authentication; E 5,CS is the value of E5 received by CS; T 5,CS is the value of T5 received by CS; Step C: CS selects timestamps T6 and T7, using h(ID j1,cs ||TK RC1,cs ) Private data of drones TK EC Encrypted by symmetric encryption, the encrypted data CN is obtained m , calculate the parameter E6 for the roadside unit to verify with the CS in step 3.4: E6=h(ID j1,cs ||N R ′||CN m ||T6); CS receives the pseudo-identity PID of the fog node f,cs Match the identity ID of the fog node f,cs , calculate the private data TK of the fog node FC,cs , use h(ID f,cs ||TK FC,cs ) to TK EC Encrypted by symmetric encryption technology, the encrypted data CN is obtained n , calculate the E7 of the verification parameter of the fog node to the CS in step 3.4: <h2 style=";text-align:left;direction:ltr">E7 = h(ID<h2 style=";text-align:left;direction:ltr"> f,cs <h2 style=";text-align:left;direction:ltr"> ||TK<h2 style=";text-align:left;direction:ltr"> FC,cs <h2 style=";text-align:left;direction:ltr"> ||CN<h2 style=";text-align:left;direction:ltr"> n <h2 style=";text-align:left;direction:ltr"> ||T7); CS will {CN m ,E6,T6} as data M6 and sent to the roadside unit RSU1. n ,E7,T7} is sent to the fog node as data M7; Step D: After receiving the data, RSU1 verifies the freshness of the timestamp in M6. If the verification fails, the authentication is terminated. Otherwise, ID j1 , N R as well as Substitute into the formula for calculating E6 to obtain parameter E6'. If E6' and If they are not equal, the authentication is terminated. If they are equal, Decryption is performed to obtain the decrypted private data of the drone; wherein, is the value of E6 received by RSU1, CN received by RSU1 m The value of is the value of T6 received by RSU1; Step E: After receiving the data, the fog node verifies the freshness of the timestamp in M7. If the verification fails, the authentication is terminated. Otherwise, the ID f , TK FC , CN n,f and T 7,f Substitute it into the formula for calculating E7 to obtain the parameter E7′. If E7′ and E 7,f If they are not equal, the authentication is terminated. If they are equal, the CN n,f Decrypt and obtain the decrypted private data of the drone; F 7,f is the value of E7 received by the fog node, CN n,f CN received by the fog node n The value of T 7,f is the value of T7 received by the fog node.

6. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 1, characterized in that: The data request in step 4 is specifically: Step a: RSU2 first generates a data request Req j2 , choose a random number N s and timestamp T C , and then calculate the parameter D3 that the fog node verifies to RSU2 in step 4 data request phase: D3=h(ID j2 ||N s ||TE RF ||T C ): Among them, TE RF The ID of RSU2 is generated by using a random number and a timestamp. j2 and private data TK RC2 The encrypted value, RSU2 will {Req j2 , PID i , PID j2 ,TE RF , D3, T C } as data M c Send to fog node; Step b: After receiving the data, the fog node verifies M c The freshness of the timestamp in the time stamp. If the verification fails, the authentication is terminated. Otherwise, the fog node receives the pseudo-identity PID of RSU2 from itself. j2,f 'Matched to the identity ID of RSU2 j2,f ′, and find the private data TK of RSU2 in SGX RC2,f ', and then derive the random number N according to the following formula s , and get N s ', the freshness of the verification timestamp is to calculate the absolute value of the difference between the time when the data is received and the timestamp in the data. If the absolute value of the difference is greater than or equal to the preset time threshold, the verification fails: Among them, TE RF,f TE received by the fog node RF The value of N s ′, ID j2,f ′,TE RF,f and T c,f Substitute it into the formula for calculating D3 to obtain the parameter D3′. If D3′ is equal to D3, go to step c, otherwise terminate the authentication; T C,f is the T received by the fog node C The value of D 3,f is the value of D3 received by the fog node; Step c: The fog node selects the timestamp T D , the fog node receives the pseudo-identity PID of the drone i,f ′ Find the same PID in SGX i,f ′The corresponding drone’s private data TK EC,f ′, and for TK EC,f ′ is encrypted to obtain the encrypted data CN O , and calculate the parameter D4 that RSU2 verifies to the fog node in the data request phase of step 4: D4=h(ID j2,f ′||N s ′||CN O ||T D ); The fog node will O , D4, T D } as data M d Send to RSU2; Step d: RSU2 receives the data and verifies M d The freshness of the timestamp in the ID j2 , and N s Substitute it into the formula for calculating D4 to obtain the parameter D4′; if D4′ and If they are equal, the authentication is successful, and RSU2 Decryption is performed to obtain the drone's private data, otherwise the authentication is terminated; CN received by RSU2 O The value of T received by RSU2 D The value of is the value of D4 received by RSU2.

7. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 6 is characterized in that: In step c, use h(ID j2 ||TK RC2 ) to TK EC,f ′ for encryption.

8. The multi-entity cross-domain key negotiation and authentication method based on multi-factor authentication according to claim 1, characterized in that: The authentication phase of step 5 is specifically as follows: Step 5.1: Drone selects a random number N m and timestamp T a , calculate the verification parameter D5 used for step 5 when RSU2 verifies the drone: D5=h(ID i ||N m ||TE ER ||T a ); in, TN ER =h(TK EC ||PID i ||PID j2 ), TN ER To verify the drone’s pseudo-identity, drone’s private data, and RSU2’s pseudo-identity PID j2 The encrypted value, TE ER For TN ER and a random number N m Drone ID i After the encrypted value, the drone will i ,TE ER ,D5,T a } as data M e Send to RSU2; Step 5.2: RSU2 verifies data M after receiving it e The freshness of the timestamp in the data. If the verification fails, the authentication is terminated. Otherwise, RSU2 calculates the random number selected by the drone in step 5.1 according to the following formula. The freshness of the verification timestamp is to calculate the absolute value of the difference between the time when the data is received and the timestamp in the data. If the absolute value of the difference is greater than or equal to the preset time threshold, the verification fails. Among them, N m ' is the random number selected by the drone in step 5.1, The identity of the drone received by RSU2; TE received by RSU2 ER The value of The pseudo identity of the drone received by RSU2 Drone private data and RSU2 pseudo-identity PID j2 The encrypted value, The expression is: The parameter D5' is calculated by the following formula: in, T received by RSU2 a The value of Determine D5′ and Are they equal? ​​If not, terminate the authentication, otherwise go to step 5.3; is the value of D5 received by RSU2; Step 5.3: RSU2 selects a random number N n and timestamp T b , and calculate the parameter D6 used by the drone to authenticate to RSU2 in step 5 and the key SK used by RSU2 to initiate a call to the drone j : D6=h(ID j2 ‖N n ‖TE RE2 ‖T b ); in, TE RE2 To use a random number N n and N m ′Identity ID of RSU2 j2 After encryption, RSU2 will RE2 ,D6,T b } as data M f Send to drone; Step 5.4 After receiving the data, the drone verifies M f The freshness of the timestamp in the RSU2 is determined by the following formula: Among them, N n ′ is the random number selected by RSU2, ID j2,E The identity of RSU2 received by the drone, TE RE2,E TE received for the drone RE2 The value of Calculate the parameter D6′ and the key SK for the drone to initiate a session with RSU2 according to the following formula: j ′: D6′=h(ID j2,E ||N n ′||TE RE2,E ||T b,E ); SK j ′=h(ID i ||ID j2,E ||N m ||N n ′); Among them, T b,E The timestamp T received by the drone b If D6′ and D 6,E If they are equal, the authentication is successful and the session key is established; otherwise, the authentication is terminated. 6,E The value of D6 received by the drone.

Citation Information

Patent Citations

  • Cross-region-based authentication method for secure communication of Internet of Vehicles

    CN115714974A