Batch message verification method and system applied to industrial Internet of Things

By adopting certificate-free aggregation signature algorithm and identity-based encryption technology in the industrial Internet of Things, the problem of insufficient efficiency and security of existing systems is solved, and efficient batch message verification and enhanced security are achieved.

CN119922547APending Publication Date: 2025-05-02XIHUA UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510078043.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The existing industrial Internet of Things message verification system is insufficient in efficiency and security, which cannot meet the needs of large-scale data processing and analysis, and the system architecture is complex, which increases management difficulty.

Method used

Certificate-free aggregation signature algorithm is used to batch verify a large number of messages sent by smart devices, offload computing-intensive tasks to edge servers, encrypt messages using identity-based pseudonym information, simplifying key management and verification processes.

Benefits of technology

Significantly reduce the computing overhead of smart devices, improve the overall efficiency and stability of the system, enhance security functions, reduce the risks of data leakage and network attacks, and meet the real-time and security needs of the industrial Internet of Things.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922547A_ABST
    Figure CN119922547A_ABST
Patent Text Reader

Abstract

The invention discloses a batch message verification method and system applied to an industrial internet of things, and relates to the technical field of wireless network security communication. According to the message authentication method, the compute-intensive tasks are unloaded to the edge server, the certificateless aggregation signature algorithm is adopted for message batch verification, system server computing resources are fully utilized, and the message processing efficiency is remarkably improved. Identity-based pseudonym information is adopted to encrypt the message, the complexity of key management and the requirement for verifying a public key certificate are eliminated, the required identity information amount is reduced, compared with a certificate-based system, the key storage, distribution, generation and verification processes are simplified, the processing efficiency of the system is improved, meanwhile, the anonymity requirement is met, and the safety of the system is improved. And the safety of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless network security communication, and in particular to a batch message verification method and system applied to industrial Internet of Things. Background Art

[0002] In the existing industrial Internet of Things, the methods for handling message security can be roughly divided into two categories: (1) Relying on a trusted third party for verification. Let the trusted third party assume a completely reliable role and complete functions such as identity authentication of all entities and secure and reliable key distribution. (2) Introducing edge computing, let the edge server act as a semi-trusted third party, offloading some functions in the verification process to the server, thereby reducing the overhead of the device itself and improving the response rate.

[0003] However, with the rapid growth of the number of connected industrial devices and systems and the dramatic expansion of data volume, the traditional method of relying entirely on a reliable third party for verification has shown obvious deficiencies in scalability. First, limited device energy and computing power have become a major obstacle to effective operation in such an environment. In addition, once the third party is compromised by an attacker, the privacy information and communication content of all entities will be completely exposed, which may lead to immeasurable losses.

[0004] Edge computing now provides an opportunity to process data closer to the device, thereby ensuring the confidentiality and privacy of the data, while improving processing efficiency by processing data near the data source. In addition, local data encryption and processing can enhance security functions and reduce the risk of data leakage and cyber attacks. Therefore, applying edge computing to the industrial Internet of Things can significantly improve the efficiency and security of data processing. However, existing edge computing-based solutions have the following problems: (1) Single message verification: The existing solution can only verify a single message and cannot fully utilize the computing resources of the server, resulting in low resource utilization and unable to meet the needs of large-scale data processing and analysis. (2) Highly time-consuming operations: The current solution relies on resource-constrained smart devices to perform a large number of time-consuming operations, which significantly increases the system's latency and resource consumption, which is not conducive to industrial Internet of Things applications with high real-time requirements. (3) Unreasonable system architecture: The existing system architecture regards the edge server as a semi-trusted entity and ignores the insecure characteristics of the wireless channel. In the design of the solution, these channels are assumed to be highly reliable and adopt a publish / subscribe structure, that is, the publisher acts as the sender of the message and the subscriber acts as the receiver of the message. However, in a complex industrial Internet of Things environment, the production process requires the simultaneous collaboration of a large number of devices. Classifying devices based solely on publishers and subscribers cannot meet the needs of actual deployment, increasing the complexity of the system architecture and the difficulty of management. Summary of the invention

[0005] The present invention provides a batch message verification method and system applied to the industrial Internet of Things, so as to solve the problems of insufficient efficiency and security of the existing message verification system.

[0006] The present invention is achieved through the following technical solutions:

[0007] A first aspect of the present invention provides a batch message verification method applied to an industrial Internet of Things, which is applied to an edge server, and the method includes:

[0008] S1, receiving an access request sent by a smart device and completing mutual authentication with the smart device;

[0009] S2, sending the corresponding pseudonym and key information to the smart device;

[0010] S3, receiving multiple messages sent by the smart device, each of the messages including a ciphertext message and a digital signature, wherein the digital signature is generated based on the pseudonym and secret key information;

[0011] S4, aggregating the digital signatures included in the multiple messages to obtain an aggregate signature, and batch-verifying the multiple messages through the aggregate signature; if the verification passes, forwarding each message to the corresponding destination device; if the verification fails, executing step S5;

[0012] S5, divide the multiple messages into two segments, and determine whether the segment contains an invalid signature based on the digital signature contained in each segment; if not, forward each message in the segment to the corresponding destination device; if contained, repeat step S5 for the multiple messages in the segment until all invalid signatures are determined.

[0013] The present invention uses a certificateless aggregate signature algorithm to batch verify a large number of messages sent by smart devices, and offloads computationally intensive tasks to edge servers, thereby significantly reducing the workload of resource-limited smart devices. In addition, the use of identity-based pseudonymous information to encrypt messages eliminates the complexity of key management and the need to verify public key certificates, reduces the amount of identity information required, simplifies the key storage, distribution, generation and verification process compared to certificate-based systems, improves the system's processing efficiency, meets anonymity requirements, and improves the security of the system.

[0014] In some embodiments, a method of mutual authentication includes:

[0015] After receiving the access request sent by the smart device, sending a first authentication parameter to the smart device, and receiving a second authentication parameter sent by the smart device;

[0016] Verify the second authentication parameter, and if the verification is successful, send a third authentication parameter to the smart device, and receive a fourth authentication parameter sent by the smart device, wherein the fourth authentication parameter is sent by the smart device after the first authentication parameter is verified successfully;

[0017] Verify the fourth authentication parameter. If the verification is successful and the smart device verifies the third authentication parameter successfully, mutual authentication is completed. Otherwise, the authentication fails.

[0018] In some implementations, the method of sending corresponding pseudonym and key information to the smart device includes:

[0019] The public parameter T pub Sent to the smart device, where T pub =sk·P, sk is the secret value selected during the edge server registration phase, P is the system public parameter, and represents the generator of the cyclic addition group;

[0020] Receive the smart device according to the public parameter T pub The generated transmission key S1 = H4(x i ·T pub ), and request messages Among them, X i is the public key stored in the smart device itself, X i =x i ·P, x i is a random number, H4 and P are common parameters of the system. Represents a set of hash functions, H4 represents a hash function, ID i The identity information of the smart device. To transmit the secret key S1 to ID i and X i The ciphertext obtained after encryption is represents the encryption function using S1 for encryption, tt i Indicates the timestamp of when the request message was generated;

[0021] Calculate the decryption parameter S′1=H4(X i sk), decrypt the ciphertext using S′1 Get the identity information ID of the smart device i and public key X i , verify the X in the ciphertext i Is it consistent with the plain text X in the request message? i If they are equal, the corresponding pseudonym and key information are distributed to the smart device.

[0022] In some implementations, the batch verification of the plurality of messages by using the aggregate signature includes:

[0023] S4-1, according to each of the received messages {ACI i , δ i , V, M i ,tt i , j}, calculate the authentication parameters for each of the messages:

[0024] h′ i1 =H2(T pub , ACI i , R i , X i );

[0025] h′ i2 =H2(PID i , PK i , U i );

[0026] h′ i3 =H3(PID i , PK i , U i );

[0027] h′ i4 =H4(PID i , PK i , U i );

[0028] In each message i, ACI i Indicates the access control information of the smart device, which includes the pseudonym PID i and the validity period of the pseudonym;

[0029] δ i represents the digital signature of message i, δ i =(U i , σ i ),in:

[0030] U i =u i P,σ i =h i4 u i +h i3 d i +h i2 x i mod q;

[0031] h i2 =H2(PID i , PK i , U i),h i3 =H3(PID i , PK i , U i ),h i4 =H4(PID i , PK i , U i );

[0032] PK i is the public key of the smart device, PK i =(X i , R i ), where X i The public key stored in the smart device itself, d i , R i The private key and public key information provided by the edge server, X i =x i ·P,V=v·P,x i 、u i , v is a random number, P, H2, H3, H4, and q are common system parameters, provided by system initialization. represents a set of hash functions, P is the generator of the cyclic additive group, H2, H3, H4 are hash functions, q is the prime order of the cyclic additive group; M i is the ciphertext message, tt i Indicates the timestamp of when the message was generated;

[0033] S5-2, based on the received digital signature, verify the formula Is it true, where T pub =sk·P, sk is the secret value of the edge server, and P is the generator of the cyclic addition group; if the formula is established, the verification is successful.

[0034] In some implementations, the aggregate signature is represented as:

[0035]

[0036] Among them, σ represents the aggregate signature, σ i represents the digital signature contained in each message i, i represents the message identifier, and n represents the number of digital signatures to be aggregated.

[0037] In some implementations, determining whether the segment contains an invalid signature based on the digital signature contained in each segment includes:

[0038] In each of said segments, a subsegment s is determined j, the sub-segment includes j digital signatures, 1≤j≤d, d is the number of signatures contained in the segment;

[0039] Calculate the sum of signatures in a subsection:

[0040]

[0041] Among them, h i2 =H2(PID i ,PK i ,U i ),h i3 =H3(PID i ,PK i ,U i ),h i4 =H4(PID i ,PK i ,U i ), PID i Pseudonym for functional equipment, PK i is the public key of the smart device, PK i =(X i ,R i ), X i is the public key stored in the smart device itself, X i =x i ·P,d i , R i The private key and public key information provided by the edge server, U i =u i ·P, x i 、u i is a random number, P, H2, H3, H4 are system common parameters. represents a set of hash functions, P is a generator of the cyclic additive group, H2, H3, H4 are hash functions, and q is the prime order of the cyclic additive group;

[0042] If there is a subsegment s j If β1=0, the segment is identified as not containing an invalid signature, otherwise it is identified as containing an invalid signature.

[0043] In some implementations, before step S1, the method further includes: completing registration with the system to obtain system public parameters.

[0044] A second aspect of the present invention provides a batch message verification method applied to industrial Internet of Things, which is applied to smart devices. The method comprises:

[0045] Sending an access request to the edge server through a nearby access point and completing mutual authentication with the edge server;

[0046] Receiving the pseudonym and secret key information sent by the edge server;

[0047] A message including a ciphertext message and a digital signature is sent to the edge server so that the message is forwarded to a destination device through the edge server, wherein the digital signature is generated according to the pseudonym and the secret key information.

[0048] In some implementations, the message is generated by:

[0049] Select random number Calculation parameters V = v·P, S2 = H5 (v·X j ),in, P and H5 are system common parameters. represents a set of hash functions, P represents the generator of the cyclic addition group, H5 represents a hash function, X j Indicates the public key of the destination device;

[0050] Generate ciphertext message Among them, m i is the message to be sent, H2 is the system public parameter, which represents the hash function, and || represents cascading, that is, connecting different strings together. Represents the encryption function encrypted by S2;

[0051] Choose a random number u i , calculate the parameter U i =u i P,σ i =h i4 u i +h i3 d i +h i2 x i mod q, get the digital signature δ i =(U i , σ i ), where h i2 =H2(PID i , PK i , U i ),h i3 =H3(PID i , PK i , U i ),h i4 =H4(PID i , PK i , U i ), PID iPseudonymous information for smart devices, PK i is the public key of the smart device, PK i =(X i , R i ), where X i is the public key stored in the smart device itself, X i =x i ·P,d i , R i The private key and public key information provided by the edge server, x i 、u i is a random number, q is the prime order of the cyclic additive group;

[0052] Generate message {ACI i , δ i , V, M i ,tt i}, where ACI i Access control information for smart devices, including pseudonyms PID i and the validity period of the pseudonym, tt i Timestamp of when the message was generated.

[0053] A third aspect of the present invention provides a batch message verification system applied to industrial Internet of Things, comprising:

[0054] The key generation center is used to provide system public parameters;

[0055] An edge server, used to execute the batch message verification method applied to the industrial Internet of Things as described in any one of the implementation modes of the first aspect of the present invention;

[0056] An intelligent device is used to execute the batch message verification method applied to the industrial Internet of Things as described in any one of the implementation modes of the second aspect of the present invention.

[0057] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0058] A certificateless aggregate signature algorithm is used to batch verify a large number of messages sent by smart devices, which can batch process a large number of messages, forward batch messages, quickly identify invalid messages, and improve message processing efficiency.

[0059] Offloading computationally intensive tasks to edge servers can fully utilize the server's computing resources, significantly reduce the computing overhead of smart devices, and improve the overall efficiency and stability of the system.

[0060] The use of identity-based pseudonymous information to encrypt messages eliminates the complexity of key management and the need to verify public key certificates, reduces the amount of identity information required, simplifies the key storage, distribution, generation and verification process, and achieves perfect forward and backward secrecy. It can resist man-in-the-middle attacks and impersonation attacks, and improve system security.

[0061] The present invention adopts a lightweight encryption algorithm, which reduces the calculation delay compared to the use of exponential and logarithmic operations in general encryption methods, and combines message batch verification and identity-based encryption technology to ensure system efficiency and security.

[0062] Through two-way authentication, the authentication process of newly connected smart devices and edge servers is simplified, improving the efficiency of connection establishment.

[0063] During the message encryption and signing process, the generation of certain data does not depend on the message being sent in real time. These parameters can be preprocessed when the device is idle or in offline mode to improve the efficiency of message signing. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative work. In the drawings:

[0065] Figure 1 This is a schematic diagram of the architecture of a batch message verification system applied to the industrial Internet of Things according to an embodiment of the present invention;

[0066] Figure 2 is a schematic diagram of a mutual authentication method between an edge server and a smart device according to an embodiment of the present invention;

[0067] Figure 3 is a flow chart of a method for pseudonym distribution and key generation according to an embodiment of the present invention;

[0068] Figure 4 This is a flow chart of a method for batch verification of messages according to an embodiment of the present invention;

[0069] Figure 5 This is a comparison chart of server computing overhead between different protocols;

[0070] Figure 6 It is a comparison chart of device overhead between different protocols;

[0071] Figure 7 This is a comparison chart of authentication time between different protocols;

[0072] Figure 8 This is a comparison chart of energy consumption between the same protocols. DETAILED DESCRIPTION

[0073] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with embodiments and drawings. The exemplary embodiments of the present invention and their description are only used to explain the present invention and are not intended to limit the present invention.

[0074] It should be noted that the terms "including" and "having" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to or inherent to other steps or units of the device.

[0075] The terms used in the various embodiments of the application are only used to describe the purpose of specific embodiments and are not intended to limit the various embodiments of the application. As used herein, the singular form is intended to also include the plural form, unless the context clearly indicates otherwise. Unless otherwise limited, all terms used here (including technical terms and scientific terms) have the same meaning as the meanings commonly understood by ordinary technicians in the field of the various embodiments of the application. The terms (such as the terms defined in the dictionary generally used) will be interpreted as having the same meaning as the contextual meaning in the relevant technical field and will not be interpreted as having an idealized meaning or an overly formal meaning, unless clearly defined in the various embodiments of the application.

[0076] The embodiment of the present invention provides a batch message verification method applied to the industrial Internet of Things, which is suitable for the verification and forwarding of batch messages, is conducive to reducing the computing resource consumption of Internet of Things devices, reducing the overall system delay and resource consumption, and improving the real-time performance of message processing.

[0077] like Figure 1 As shown, Figure 1 This is a schematic diagram of the architecture of a batch message verification system applied to the industrial Internet of Things in an embodiment of the present invention, which is composed of a key generation center (KGC), an edge computing server (ES) and a smart device (SD). The message authentication method of the present invention reduces the number of interactions and offloads computationally intensive tasks to the edge server, thereby significantly reducing the workload of smart devices with limited resources.

[0078] The batch message verification method of this system is implemented through several main steps, including system initialization, edge server registration, smart device registration, pseudonym generation and key distribution of smart devices, message encryption and signature generation, batch verification and forwarding of messages, and identification of invalid signatures. The system initialization is performed by the key generation center to generate system public parameters for the edge servers and smart devices in the system to perform mutual authentication, message processing and forwarding. The edge server needs to complete registration with the key generation center to obtain management authority for the smart devices in the system and receive batch messages from smart devices for verification and forwarding. The smart device accesses the edge server nearby, and after completing mutual authentication with the edge server, it can anonymously forward messages to the destination device through the edge server. In the system architecture of this solution, wired communication is performed between the edge server and the key generation center, and wireless communication is performed between the smart device and the edge server. Considering the different communication modes between the devices at each layer of the system model, the key generation center sends down the key parameters through the wired channel to avoid the risk of data exposure. The batch message verification method of the present invention will be introduced in the following order according to the system execution sequence.

[0079] 1. System initialization.

[0080] Before IoT devices are connected to the system in batches, the system first performs initialization operations to generate the necessary system parameters.

[0081] Specifically, for a given security parameter 1 k The key generation center KGC selects a q-order cyclic additive group G1 and a cyclic multiplicative group G2, and then selects five secure one-way hash functions, which are represented as: H1: {0, 1} * →G1, H2: H3: H4: H5: Among them, {0, 1} * It represents a set of binary strings of arbitrary length, that is, the hash function H1 can accept binary data of arbitrary length as input. “→” is used to represent the mapping relationship between the input and output of the hash function. When H1 accepts a binary string of arbitrary length as input, it outputs an element in G1. The representation of other hash functions is similar. m Represents the bit length of the message. KGC from the hash set Select a master key from Generate system common parameters {G1, G2, l m , P, H2, H3, H4, H5}, the public parameters will be published to the edge server ES and smart device SD in the system, where P is the generator of the cyclic addition group G1 and H1 is retained in the key generation center.

[0082] 2. Edge server registration.

[0083] In this system, only the edge server ES needs to register with the key generation center KGC in the initial stage and obtain the system public parameters. Taking an edge server as an example, its registration process is as follows.

[0084] S1-1, edge server ES i By using your own identity information ID i Sent to the key generation center KGC. Each edge server has unique identity information, where i is used to represent the number of the edge server.

[0085] S1-2, the key generation center KGC calculates ES through the reserved hash function H1 i The public key is expressed as: Q U =H1(ID i ).

[0086] Since this public key is based on the edge server ES i Each edge server has unique identity information, so no authentication is required to obtain the public key.

[0087] S1-3, edge server ES i Receive the public key Q returned by the key generation center KGC U Afterwards, the private key S is calculated based on the public key U , calculation formula: S U =sk·Q U Where sk is the master key, which is provided by ES i From a hash set A parameter is randomly selected from

[0088] All edge servers in the system register with KGC according to the above method and obtain the public key Q based on their own identity information. U , here Q U It can be used to indicate the legal identity of ES, that is, it has been authenticated by KGC.

[0089] 3. Smart device registration and batch message processing.

[0090] After completing the above pre-processing, the edge server can be applied to process batch messages, including the following steps.

[0091] S2-1, receiving the access request sent by the smart device and completing mutual authentication with the smart device.

[0092] S2-2, sending the corresponding pseudonym and secret key information to the smart device.

[0093] S2-3, receiving multiple messages sent by the smart device, each message including a ciphertext message and a digital signature, wherein the digital signature is generated based on the pseudonym and secret key information.

[0094] S2-4, aggregate the digital signatures contained in the multiple messages to obtain an aggregate signature, and batch verify the multiple messages through the aggregate signature; if the verification passes, forward each message to the corresponding destination device; if the verification fails, execute step S2-5.

[0095] S2-5, divide the multiple messages into two segments, and determine whether the segment contains an invalid signature based on the digital signature contained in each segment; if not, forward each message in the segment to the corresponding destination device; if contained, repeat step S5 for the multiple messages in the segment until all invalid signatures are determined.

[0096] In S2-1, when the smart device connects to the edge server through the nearest access point for the first time, the smart device and the edge server perform mutual authentication to complete the smart device registration. The mutual authentication follows the security authentication protocol specified by the 802.11 standard, namely the WiFi Protected Access (WPA3) protocol. Once the authentication is successful, the edge server will generate a pseudonym and private key and send them to the smart device.

[0097] In some embodiments, Figure 2 is a schematic diagram of a mutual authentication method between an edge server and a smart device, and the two-way mutual authentication method includes the following steps.

[0098] S2-1-1, after receiving the access request sent by the smart device, the edge server sends a first authentication parameter to the smart device and receives a second authentication parameter sent by the smart device.

[0099] The smart device indirectly initiates an access request to the edge server through the nearest access point (AP). When the smart device is connected to the access point AP, the AP requests its identity information from the smart device, and the smart device replies with its identity information. After receiving the identity information, the AP initiates an access request to the edge server ES. After receiving the access request, the edge server ES sends the first authentication request to the AP, and the AP forwards the authentication request to the smart device SD.

[0100] Specifically, the edge server selects two random numbers n e and e ∈[2,q], such that N e =n e +y e mod q∈[2,q], and calculate F E =-ye ·P, where P and q are public parameters, P is the generator of the cyclic additive group G1, and q is the prime order of the cyclic additive group G1. The edge server will authenticate the first parameter {N e , F E}Sent to the smart device through AP.

[0101] At the same time, the smart device randomly selects two random numbers n s and s ∈[2,q], calculate N s =n s +y s mod q∈[2,q],F S =-y s ·P, the first authentication parameter {N s , F S}Sent to the edge server through AP.

[0102] S2-1-2, verify the second authentication parameter. If the verification is successful, send the third authentication parameter to the smart device and receive the fourth authentication parameter sent by the smart device. The fourth authentication parameter is sent by the smart device after the first authentication parameter is verified.

[0103] The edge server and the smart device receive the first authentication parameters {N s , F S}、{N e , F E}, both parties will verify the received N s 、N e No, within the range [2, q], if either party fails the verification, the handshake terminates, otherwise the edge server and the smart device perform a second mutual authentication.

[0104] The edge server calculates the second authentication parameter MVC E =HMAC(k, tr), where k = H2(K), K = n e ·(F S +N s ·P), tr=(N e , F E , N s , F S ). H2 and P are common parameters, n e 、N e 、F E is the first authentication parameter of the edge server, N s 、F S It is the first authentication parameter of the smart server received during the first authentication.

[0105] Similarly, the smart device calculates the second authentication parameter MVC S =HMAC(k, tr), where k = H2(K), K = n s ·(F E +N e ·P), tr=(N e , F E , N s , F S ), H2 and P are common parameters, n s 、N s 、F S N is the first authentication parameter of the smart device SD. e 、F E It is the first authentication parameter received from the edge server during the first authentication.

[0106] S2-1-3, verify the fourth authentication parameter. If the verification is successful and the smart device verifies the third authentication parameter successfully, mutual authentication is completed. Otherwise, the authentication fails.

[0107] Both parties will use the second authentication parameter MVC E 、MVC S Send and confirm to each other, compare the received parameters with the parameters calculated by themselves, if they are the same, the handshake is successful and the identity authentication of both parties is successful, otherwise, the confirmation frame will be ignored and the authentication fails.

[0108] In this scheme, two authentication messages are sent to each other and mutual verification is performed. After two handshakes, normal communication is established, which simplifies the authentication process. Figure 2 As shown, Figure 2 is a schematic diagram of a mutual authentication method between an edge server and a smart device, including the following steps.

[0109] In step S2-2, after the edge server completes the identity authentication with the smart device, the pseudonym and key information are distributed to the smart device. This stage occurs before the encryption and signing of the message. The information will be used as the encryption parameter of the message, thereby realizing anonymous message forwarding.

[0110] Since the wired connection between the access point and the edge server can be considered highly secure, subsequent operations can be simplified to communication between the smart device and the edge server. Figure 3 Shown is a flow chart of a method for pseudonym distribution and key generation according to an embodiment of the present invention, which includes the following steps.

[0111] S2-3-1, the edge server will publish the parameter T pub Published to registered smart devices.

[0112] Among them, the parameter T pubThe calculation formula is: pub =sk·P, sk is the secret value selected during the edge server registration phase, and P is a public parameter.

[0113] Each smart device receives T pub After that, first from the hash set Choose a secret value x from i As part of the private key value, Calculate X again i =x i P is part of the public key information.

[0114] Then calculate the transmission key S1 = H4 (x i ·T pub ), and sends a request message to the edge server Among them, IDi is the identity information of the smart device, To transmit the secret key S1 to ID i and X i After encryption, Indicates the encryption function using S1 for encryption. Select the appropriate encryption algorithm according to the scenario. For example, you can use the elliptic curve encryption algorithm ECC or RSA algorithm. i Indicates the timestamp when the request message is generated.

[0115] S2-3-2, after receiving the request message, the edge server first calculates S′1=H4(X i ·sk). Decrypt the ciphertext using S′1 Get {ID i , X i}, determine the X in the ciphertext i Is it consistent with the plaintext X in the request message? i If they are equal, the message is received; otherwise, it is discarded directly.

[0116] Among them, there is the following relationship: S1=H4(x i ·T pub )=H4(x i ·sk·P)=H4(X i ·sk)=S′1.

[0117] S2-3-3, after the verification is completed, the edge server distributes the corresponding pseudonym and private key information to each smart device.

[0118] Specifically, the edge server randomly selects a secret value And calculate R i =r i ·P,d i =(r i +sk·hi1 ) mod q, where h i1 =H2(T pub , ACI i , R i , X i ), ACI i It is the access control information of each smart device, which contains the pseudonym PID of the smart device i and the pseudonym validity period ExpireTime i .

[0119] Complex industrial IoT systems contain a large amount of personal privacy data or industry-sensitive data. In the process of information interaction between a large number of IoT devices, higher requirements are placed on the privacy protection of devices and information. In order to protect the privacy information of each smart device, the edge server generates a series of pseudonymous PIDs for each smart device. i The following describes the pseudonym generation process for each smart device.

[0120] Assuming that the edge server assigns C pseudonyms to each smart device and the validity period of each pseudonym is Δt, the pseudonym of smart device i in the jth time slot is represented by PID i,j , the edge server ES selects two random seeds SE i,1 and SE i,2 , and then calculate SD according to the following formula i Pseudonym:

[0121]

[0122] Finally, the edge server encrypts the pseudonym and part of the key information with S1 to obtain the ciphertext Send to each smart device.

[0123] After receiving the information, the smart device verifies the formula: d i P=R i +h i1 T pub If the verification is successful, the partial key will be accepted. Then, each smart device stores its private key SK i =(x i , d i ) and publish the public key PK i =(X i , R i ).

[0124] Based on message encryption and signature, the edge server can batch verify and forward a large number of received messages. When the edge server ES receives a large number of encrypted messages from multiple connected smart devices SD, it first performs a legitimacy check on the received messages. In the verification method of the present invention, a certificateless aggregate signature scheme is adopted to eliminate the reliance on traditional digital certificates and reduce the complexity and cost of system maintenance. Figure 4 The flowchart of the message batch verification method is shown in FIG.

[0125] First, multiple digital signatures are aggregated through the signature aggregator to calculate δ i Represents the digital signature of the encrypted message, and n represents the total number of digital signatures.

[0126] Use the received messages to calculate the verification parameter h′ i1 =H2(T pub ,ACI i ,R i ,X i ), h′ i2 =H2(PID i ,PK i ,U i ), h′ i3 =H3(PID i ,PK i ,U i ), h′ i4 =H4(PID i ,PK i ,U i ).

[0127] The received messages are encrypted and signed by each smart device. The message encryption and digital signature methods are as follows.

[0128] S3-3-1, Smart device selects random number Calculate V = v·P and S2 = H5 (v·X j ), where X j The public key information of the destination device is then encrypted to generate ciphertext m i For the message to be sent, P, H5, and H2 are all public parameters. represents a set of hash functions, P represents the generator of the cyclic addition group, H2 and H5 represent different hash functions, and || represents concatenation, that is, connecting different strings together. Indicates the encryption function encrypted by S2. You can select a suitable encryption algorithm based on the scenario.

[0129] S3-3-2, use its private key to calculate the digital signature δi =(U i ,σ i ).

[0130] First, choose a random number Calculation parameter U i =u i P,σ i =h i4 u i +h i3 d i +h i2 x i mod q.

[0131] Among them, h i2 =H2(PID i ,PK i ,U i ),h i3 =H3(PID i ,PK i ,U i ),h i4 =H4(PID i ,PK i ,U i ), PID i PK is the pseudonym of the smart device and the public key of the smart device. i =(X i ,R i ), H2, H3, and G4 are system common parameters.

[0132] S3-3-3, generate encrypted message {ACI i ,δ i ,V,M i ,tt i} and sent to the edge server, where ACI i It is the access control information of the smart device, which contains the pseudonym PID i and the pseudonym validity period ExpireTime i ,tt i Timestamp of when the message was generated.

[0133] After completing the above steps, the edge server needs to verify whether equation (2) holds:

[0134]

[0135] Among them, σ is the aggregate signature, P is the generator of the cyclic addition group, and U i To obtain the parameters from the digital signature, the edge server receives the digital signature δ i After the message is received, U can be obtained according to the data packet formati The specific value of R i is the public key distributed by the edge server to the smart device, T pub is the secret value of the edge server, X i It is the public key stored in the smart device itself.

[0136] The correctness of formula (2) is proved as follows.

[0137]

[0138]

[0139] This step involves signing δ i Perform batch verification to determine the correctness and validity of the message. If the equation holds, it proves that n messages have passed the verification. For the group that has passed the batch verification, forward the message according to the address of the destination device. The destination device receives the message and calculates the key S4=H5(V·x j ), and decrypt the ciphertext M i To obtain the plaintext information m i At the same time, the destination device calculates H2(m i ) to verify the integrity of the received message. If the timestamp is invalid, the destination device will reject the message.

[0140] Through the following calculation, it can be deduced that: S4 = H5 (V x j )=H5(v·P·x j )=H5(v·X j )=S3.

[0141] If formula (2) is not true, it proves that there is an invalid signature in the aggregated signature. At this time, the messages need to be grouped again and each group of messages needs to be re-authenticated using the above batch verification method within the validity period of the timestamp.

[0142] S5-1, divide n signatures into 2 segments, then each segment has The two segments are labeled {s1,s2}, and each segment has a set of signatures {σ1,...,σ j} belongs to subsection s j , where 1≤j≤d.

[0143] S5-2, find out the invalid segments in each segment.

[0144] The sum of each segment is calculated using the following formula to identify segments containing invalid signatures. Let inv sec Represents the number of invalid segments, set inv sec =1, then calculate:

[0145]

[0146] Among them, h i2 =H2(PID i ,PK i ,U i ),h i3 =H3(PID i ,PK i ,U i ), h i4 =H4(PID i ,PK i ,U i ), PID i Pseudonym for functional equipment, PK i is the public key of the smart device, PK i =(X i ,R i ), X i is the public key stored in the smart device itself, X i =x i ·P,d i , R i The private key and public key information provided by the edge server, U i =u i ·P, x i 、u i is a random number, P, H2, H3, H4 are system common parameters. represents the set of hash functions, P is the generator of the cyclic additive group, H2, H3, H4 are hash functions, and q is the prime order of the cyclic additive group.

[0147] Similar to the batch verification principle scheme proposed in the present invention, each segment is batch verified by equation (3). If a sub-segment s is found j (1≤j≤d) makes the value of β1 equal to 0, then the segment is identified as a segment that does not contain an invalid signature, and the edge server forwards the data of the segment to the target device. Otherwise, go to step S5-3.

[0148] S5-3, the aggregator continues to divide the d signatures of the segment that failed the verification into 2 segments, each segment has Signatures are obtained, and step S5-2 is then repeated.

[0149] After recursively executing step S5-2 and step S5-3, the server can accurately find the invalid signature and require the device to resubmit the data based on the location information contained in the data. If the process exceeds the specified time, all smart devices will be required to resubmit the data.

[0150] 4. Message encryption and signature generation.

[0151] After completing the pseudonym distribution and key generation of IoT devices, smart devices can send messages to the edge network, which forwards the messages to the corresponding destination devices. In order to ensure the confidentiality of the messages and prevent attackers from intercepting them, before sending the messages, smart devices need to encrypt the messages and generate corresponding signature information to send to the edge server.

[0152] Specifically, a batch message verification method applied to smart devices in a system includes the following steps.

[0153] S3-1, sending an access request to the edge server through the nearest access point and completing mutual authentication with the edge server;

[0154] S3-2, receiving the pseudonym and secret key information sent by the edge server;

[0155] S3-3, sending a message including a ciphertext message and a digital signature to the edge server so as to forward the message to the destination device through the edge server, wherein the digital signature is generated according to the pseudonym and secret key information distributed by the edge server.

[0156] This method mainly targets the generation process of batch messages. In order for the edge server to verify the batch messages, the encryption process of the message is processed with features. The above steps S3-1 and S3-2 can refer to the interaction process between the smart device and the edge server. This section will focus on the method of encrypting messages and signing by smart devices, as follows.

[0157] S3-3-1, Smart device selects random number Calculate V = v·P and S2 = H5 (v·X j ), where X j The public key information of the destination device is then encrypted to generate ciphertext m i For the message to be sent, P, H5, and H2 are all public parameters. represents a set of hash functions, P represents the generator of the cyclic addition group, H2 and H5 represent different hash functions, || represents ..., Indicates the encryption function encrypted by S2. You can select a suitable encryption algorithm based on the scenario.

[0158] S3-3-2, use its private key to calculate the digital signature δ i =(U i , σ i ).

[0159] First, choose a random number Calculation parameter U i =ux·P,σ i =h i4 u i +h i3 d i +h i2 x i mod q.

[0160] Among them, h i2 =H2(PID i , PK i , U i ),h i3 =H3(PID i , PK i , U i ),h i4 =H4(PID i , PK i , U i ), PID i PK is the pseudonym of the smart device and the public key of the smart device. i =(X i , R i ), H2, H3, and H4 are system common parameters.

[0161] S3-3-3, generate encrypted message {ACI i , δ i , V, M i ,tt i} and sent to the edge server, where ACI i It is the access control information of the smart device, which contains the pseudonym PID i and the pseudonym validity period ExpireTime i ,tt i Timestamp of when the message was generated.

[0162] During the message encryption and signing process, the generation of some data does not depend on the message m i For example, access control information ACI can be activated when the device is idle or in offline mode. i The transmission key S2 is preprocessed. Therefore, when the smart device is idle or the computing density is low, they can actively generate and store in advance for future online signatures. Effective use of preprocessing can improve signature efficiency.

[0163] Summary: The present invention overcomes the defects existing in the aforementioned prior art and provides a new batch message verification method in the Industrial Internet of Things. A batch message verification framework supported by an edge server is designed to effectively help smart devices process a large number of messages. The method offloads computationally intensive tasks to the edge server by reducing the number of interactions, thereby significantly reducing the workload of smart devices with limited resources. In addition, the present invention adopts identity-based encryption technology to eliminate the complexity of key management and the need to verify public key certificates. Compared with certificate-based systems, this method simplifies the key storage, distribution, revocation, generation and verification process, reduces the amount of identity information required, and is crucial for resource-limited Industrial Internet of Things (IIoT) environments.

[0164] Furthermore, the present invention adopts the certificateless aggregate signature (CLAS) algorithm and uses the Scyther tool for formal verification. The verification results show that the protocol can meet the security requirements of communication between industrial Internet of Things devices, ensure the integrity, confidentiality and anonymity of messages, and achieve perfect forward and backward secrecy, and can resist man-in-the-middle attacks (MitM) and impersonation attacks. These advantages make the present invention significantly practical and reliable in the industrial Internet of Things environment.

[0165] The present invention uses a 3.8GB memory, The computational cost of the batch authentication phase is evaluated on a platform running on a Ryzen 7 5800h processor and Ubuntu virtual machines. In the simulation of the scheme, the elements in the cryptographic library G are set to 97 bytes, the theoretical size of large integers is 48 bytes, and the plaintext message size is set to 56 bytes. In addition, the output sizes of the hash function and timestamp are fixed to 32 bytes and 16 bytes, respectively. For all operations based on elliptic curve encryption, secp256k1 is selected as the default elliptic curve. During the simulation, each encryption function is run 10,000 times to measure its average execution time.

[0166] In the comparison of different indicators, the abbreviation used in this scheme is BMAE; the compared schemes are ECBS (reference: secure and efficient certificateless batch verification scheme within valid signature identification for the internet of things), ASSE (reference: Anonymous message authentication scheme for semi-trusted edge-enabled IIoT), and MASE (reference: Efficient batch authentication scheme based on edge computing in IIoT).

[0167] like Figure 5 The figure shows the server computing overhead curve as the number of devices increases. Figure 6 The figure shows the computing overhead curve of the device as the number of devices increases. The measurement results are as follows: Dot product operation time T pm Take 0.067ms; click to add operation time T pa Take 0.004ms; hash operation time T H It takes 0.003ms; the multiplication time in G is T mul Take 0.168ms; single bilinear pair T b The execution time is 11.245ms; the single power T exp The time for the XOR operation is 1.608ms. Operations such as XOR and arithmetic can be ignored.

[0168] In the scheme, the robustness of this scheme is evaluated to estimate the robustness of the scheme in batch verification of n messages. The batch verification process may be forced to stop and restart when encountering unknown attacks. It is assumed that unknown attacks may occur in each step of the batch verification, and the probability of unknown attacks occurring is uniform. The average time for successful verification is calculated as follows:

[0169]

[0170] Among them, T, T success , T failed are the average time for successful authentication, the total time for successful authentication, and the total time for failed authentication, respectively. success is the number of successful authentications, p is the number of unknown percentage attacks, n is the number of steps in the protocol, and t failed represents the total time cost before the attack occurs in step i, t successIt indicates the time taken for a successful authentication before the attack occurs. Finally, the authentication time comparison between different protocols is as follows: Figure 7 shown.

[0171] The computational energy analysis and transmission energy analysis are performed with reference to a 133MHz SA-1110 Strong ARM microprocessor and a LA-4121WLAN card. Table 1 summarizes the energy consumption of several basic operations.

[0172] Table 1 Energy costs for basic operation

[0173] symbol definition Energy consumption <![CDATA[E exp ]]> The energy consumption of an exponential operation in G 9.1mJ <![CDATA[E MapToPoint ]]> Energy cost of a hash-to-point operation 18.4mJ <![CDATA[E ver ]]> Energy cost of ECDSA (160-bit) signature verification 10.9mJ <![CDATA[E pair ]]> Energy cost of a pairing operation 47.0mJ <![CDATA[E tran ]]> Energy consumption for transmitting a single bit 0.66μJ <![CDATA[E mul ]]> Energy consumption of a scalar multiplication 8.8mJ <![CDATA[E rec ]]> Energy consumption for receiving a single bit 0.31μJ

[0174] The energy consumption comparison finally obtained in this embodiment is shown in Table 2 and Figure 8 As shown:

[0175] Table 2 Energy consumption of different protocols

[0176]

[0177] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the batch message verification method applied to the industrial Internet of Things according to any embodiment of the present invention is implemented. The storage medium may be a ROM / RAM, a magnetic disk, an optical disk, etc.

[0178] An embodiment of the present invention provides a computer program product. When the computer program product is run on a computer, the computer executes the batch message verification method applied to the industrial Internet of Things according to any one of the above embodiments of the present invention.

[0179] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A batch message verification method applied to industrial Internet of Things, characterized in that: Applied to an edge server, the method comprises: S1, receiving an access request sent by a smart device and completing mutual authentication with the smart device; S2, sending the corresponding pseudonym and key information to the smart device; S3, receiving multiple messages sent by the smart device, each of the messages including a ciphertext message and a digital signature, wherein the digital signature is generated based on the pseudonym and secret key information; S4, aggregating the digital signatures included in the multiple messages to obtain an aggregate signature, and batch-verifying the multiple messages through the aggregate signature; if the verification passes, forwarding each message to the corresponding destination device; if the verification fails, executing step S5; S5, divide the multiple messages into two segments, and determine whether the segment contains an invalid signature based on the digital signature contained in each segment; if not, forward each message in the segment to the corresponding destination device; if contained, repeat step S5 for the multiple messages in the segment until all invalid signatures are determined.

2. The batch message verification method applied to the industrial Internet of Things according to claim 1 is characterized in that: Methods of mutual authentication include: After receiving the access request sent by the smart device, sending a first authentication parameter to the smart device, and receiving a second authentication parameter sent by the smart device; Verify the second authentication parameter, and if the verification is successful, send a third authentication parameter to the smart device, and receive a fourth authentication parameter sent by the smart device, wherein the fourth authentication parameter is sent by the smart device after the first authentication parameter is verified successfully; Verify the fourth authentication parameter. If the verification is successful and the smart device verifies the third authentication parameter successfully, mutual authentication is completed. Otherwise, the authentication fails.

3. The batch message verification method applied to the industrial Internet of Things according to claim 1 is characterized in that: The method of sending corresponding pseudonym and secret key information to the smart device comprises: The public parameter T pub Sent to the smart device, where T pub =sk·P, sk is the secret value selected during the edge server registration phase, P is the system public parameter, and represents the generator of the cyclic addition group; Receive the smart device according to the public parameter T pub The generated transmission key S1 = H4(x i ·T pub ), and request messages Among them, X i is the public key stored in the smart device itself, X i =x i ·P, x i is a random number, H4 and P are system common parameters. Represents a set of hash functions, H4 represents a hash function, ID i The identity information of the smart device. To transmit the secret key S1 to ID i and X i The ciphertext obtained after encryption is represents the encryption function using S1 for encryption, tt i Indicates the timestamp of when the request message was generated; Calculate the decryption parameter S′1=H4(X i sk), decrypt the ciphertext using S′1 Get the identity information ID of the smart device i and public key X i , verify the X in the ciphertext i Is it consistent with the plain text X in the request message? i If they are equal, the corresponding pseudonym and key information are distributed to the smart device.

4. The batch message verification method applied to the industrial Internet of Things according to claim 1 is characterized in that: The batch verification of the plurality of messages by using the aggregate signature includes: S4-1, according to each of the received messages {ACI i ,δ i ,V,M i ,tt i }, calculate the authentication parameters for each of the messages: h′ i1 =H2(T pub ,ACI i ,R i ,X i ); h′ i2 =H2(PID i ,PK i ,U i ); h′ i3 =H3(PID i ,PK i ,U i ); h′ i4 =H4(PID i ,PK i ,U i ); In each message i, ACI i Indicates the access control information of the smart device, which includes the pseudonym PID i and the validity period of the pseudonym; δ i represents the digital signature of message i, δ i =(U i ,σ i ),in: U i =u i ·P,σ i =h i4 you i +h i3 d i +h i2 x i q mode; h i2 =H2(PID i ,PK i ,U i )、h i3 =H3(PID i ,PK i ,U i )、h i4 =H4(PID i ,PK i ,U i ); PK i PK is the public key of the smart device. i =(X i ,R i ), where X i is the public key stored in the smart device itself, d i , R i The private key and public key information provided by the edge server, X i =x i ·P,V=v·P,x i 、u i , v is a random number, P, H2, H3, H4, and q are common system parameters, provided by system initialization. represents a set of hash functions, P is the generator of the cyclic additive group, H2, H3, H4 are hash functions, q is the prime order of the cyclic additive group; M i is the ciphertext message, tt i Indicates the timestamp of when the message was generated; S5-2, based on the received digital signature, verify the formula Is it true, where T pub =sk·P, sk is the secret value of the edge server, and P is the generator of the cyclic addition group; if the formula is established, the verification is successful.

5. The batch message verification method applied to the industrial Internet of Things according to claim 1 or 4, characterized in that: The aggregate signature is expressed as: Among them, σ represents the aggregate signature, σ i represents the digital signature contained in each message i, i represents the message identifier, and n represents the number of digital signatures to be aggregated.

6. The batch message verification method applied to the industrial Internet of Things according to claim 4 is characterized in that: The step of judging whether the segment contains an invalid signature according to the digital signature contained in each segment includes: In each of said segments, subsegments s are determined j , the sub-segment includes j digital signatures, 1≤j≤d, d is the number of signatures contained in the segment; Calculate the sum of signatures in a subsection: Among them, h i2 =H2(PID i ,PK i ,U i ),h i3 =H3(PID i ,PK i ,U i ),h i4 =H4(PID i ,PK i ,U i ), PID i Pseudonym for functional equipment, PK i PK is the public key of the smart device. i =(X i ,R i ), X i is the public key stored in the smart device itself, X i =x i ·P,d i , R i The private key and public key information provided by the edge server, U i =u i ·P, x i 、u i is a random number, P, H2, H3, H4 are system common parameters. represents a set of hash functions, P is a generator of the cyclic additive group, H2, H3, H4 are hash functions, and q is the prime order of the cyclic additive group; If there is a subsegment s j If β1=0, the segment is identified as not containing an invalid signature, otherwise it is identified as containing an invalid signature.

7. The batch message verification method applied to the industrial Internet of Things according to claim 6 is characterized in that: Before step S1, the method further includes: completing registration with the system to obtain system public parameters.

8. A batch message verification method applied to industrial Internet of Things, characterized in that: Applied to a smart device, the method comprises: Sending an access request to the edge server through a nearby access point and completing mutual authentication with the edge server; Receiving the pseudonym and secret key information sent by the edge server; A message including a ciphertext message and a digital signature is sent to the edge server so that the message is forwarded to a destination device through the edge server, wherein the digital signature is generated according to the pseudonym and the secret key information.

9. The batch message verification method applied to the industrial Internet of Things according to claim 8 is characterized in that: The message is generated by: Select random number Calculation parameters V = v·P, S2 = H5 (v·X j ),in, P and H5 are system common parameters. represents a set of hash functions, P represents the generator of the cyclic addition group, H5 represents a hash function, X j Indicates the public key of the destination device; Generate ciphertext message Among them, m i is the message to be sent, H2 is the system public parameter, which represents the hash function, and || represents cascading, that is, connecting different strings together. Represents the encryption function encrypted by S2; Choose a random number u i , calculate the parameter U i =u i P,σ i =h i4 u i +h i3 d i +h i2 x i mod q, get the digital signature δ i =(U i ,σ i ), where h i2 =H2(PID i ,PK i ,U i ),h i3 =H3(PID i ,PK i ,U i ),h i4 =H4(PID i ,PK i ,U i ), PID i Pseudonymous information for smart devices, PK i PK is the public key of the smart device. i =(X i ,R i ), where X i is the public key stored in the smart device itself, X i =x i ·P,d i , R i The private key and public key information provided by the edge server, x i 、u i is a random number, q is the prime order of the cyclic additive group; Generate message {ACI i ,δ u ,V,M i ,tt i }, where ACI i Access control information for smart devices, including pseudonyms PID i and the validity period of the pseudonym, tt i Timestamp of when the message was generated.

10. A batch message verification system applied to the industrial Internet of Things, characterized in that: include: The key generation center is used to provide system public parameters; An edge server, used to execute the batch message verification method applied to the industrial Internet of Things as described in any one of claims 1 to 7; An intelligent device, used to execute the batch message verification method applied to the industrial Internet of Things as described in any one of claims 8-9.

Citation Information

Cited By

  • Multi-agent-based efficient batch authentication method and system applied to industrial Internet of Things

    CN121967018A