Mobile Internet of Things equipment traceable authentication method and system under privacy protection scene

By adopting a blockchain-based identity authentication solution in the identity authentication of mobile IoT devices, using the chameleon hash function to achieve two-way verification, it solves the identity authentication challenges of mobile IoT devices in resource-constrained and complex network environments, and achieves efficient and secure identity authentication and privacy protection.

CN119945723AActive Publication Date: 2025-05-06INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411904014.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-06
Estimated Expiration
2044-12-23

AI Technical Summary

Technical Problem

Mobile IoT devices face security and efficiency challenges in the identity authentication process, especially when resource constraints and complex network environments, traditional authentication methods are inefficient and vulnerable to man-in-the-middle attacks.

Method used

The blockchain-based identity authentication scheme is adopted to record device identity and interactive data through a distributed ledger, strictly constrain the permissions of all parties using smart contracts, and realize two-way verification and key negotiation of mobile IoT devices and edge nodes through a chameleon hash function.

Benefits of technology

It realizes secure and efficient identity authentication under resource-constrained and complex network environments, reduces computing complexity, supports cross-domain authentication and batch authentication of mobile IoT devices, and enhances the scalability and privacy protection capabilities of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945723A_ABST
    Figure CN119945723A_ABST
Patent Text Reader

Abstract

The invention discloses a traceable authentication method and a traceable authentication system for mobile Internet of Things equipment in a privacy protection scene, which belong to the field of identity authentication and tracking and mainly comprise four stages of initialization, mobile Internet of Things equipment registration, authentication and tracking and revocation. The method is suitable for bidirectional identity authentication between facilities such as edge nodes and the mobile Internet of Things equipment, authentication, on-demand tracking and revocation of the mobile equipment are realized on the premise of ensuring the identity information security and the mobile path privacy of the mobile Internet of Things equipment, and the requirements of privacy protection authentication and traceability are well met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of identity authentication and tracking, and relates to a traceable authentication method and system for a mobile Internet of Things device in a privacy protection scenario. Background Art

[0002] With the development of IoT technology, the application scope of mobile IoT devices has also expanded. General IoT devices, such as smart home devices, are often fixed in position and only communicate with user terminal devices through home gateways. Generally speaking, security can be guaranteed by simply verifying the identity of the user terminal. Unlike general IoT devices, mobile IoT devices change their spatial position during operation, making it difficult to determine the identity of the device, and putting forward new requirements for privacy protection in identity authentication.

[0003] Typical mobile IoT devices include connected vehicles, connected ships, drones, etc. These mobile IoT devices are often unable to use complex authentication algorithms to ensure security due to limited computing resources and low network bandwidth. Identity authentication for such devices poses great challenges in terms of security and efficiency. Traditional identity authentication methods, such as those based on public key infrastructure (PKI), are inefficient in resource-constrained environments and are susceptible to man-in-the-middle attacks. In addition, some solutions require devices to remain connected to the Internet continuously, but mobile IoT devices may not be able to maintain a stable connection in complex network environments, further increasing the difficulty of the authentication process.

[0004] In this context, blockchain-based identity authentication schemes have begun to attract attention. The benefits of blockchain-based schemes are: blockchain records device identities and interaction data through distributed ledgers to ensure the integrity and traceability of information, and uses smart contracts to strictly constrain the permissions of all parties, thereby providing a safe and efficient identity authentication solution under resource-constrained and complex network environments. Such schemes usually involve the following implementation scenarios and participants: 1) Mobile IoT device D: responsible for generating device identification and interacting with authentication devices. Such devices have limited resources and cannot perform complex encryption operations. 2) Edge node N: a computing device deployed at the edge of the network with certain computing and storage capabilities and a large number. It is responsible for data aggregation, signature verification, and some authentication work, thereby reducing the burden on the device. 3) Domain management agency RSM: responsible for supervising devices and authentication operations within a specific network domain, but can only read the content on the blockchain and does not have write permissions. 4) Law enforcement agency LEA: has read and write permissions on the blockchain and is responsible for handling the revocation of authentication and identity updates of abnormal devices, as well as intervention and evidence collection in special events. 5) Blockchain BC: Blockchain is jointly maintained by law enforcement agencies and domain management agencies. Its role in the system is reflected in its decentralized, tamper-proof and transparent characteristics, providing a credible basis for the collaboration of multiple participants.

[0005] However, in the existing technical solutions, the private key of the mobile IoT device depends on the registration center for generation and distribution, which poses a security risk of key escrow. At the same time, the existing technical solutions do not support the unlinkability of mobile IoT device messages, that is, attackers may infer the path information of the mobile IoT device by linking (linking means that attackers can judge that two messages are sent by the same mobile IoT device based on certain fields in the message) two or more messages. In addition, in order to ensure the security and efficiency of communication after the authentication is completed, key negotiation is also required. Summary of the invention

[0006] The present invention provides a traceable authentication method and system for a mobile Internet of Things device in a privacy protection scenario, which can not only solve the deficiencies of existing Internet of Things privacy authentication schemes, but also enable law enforcement agencies to track specific mobile Internet of Things devices on demand.

[0007] To achieve the above object, the technical solution of the present invention includes the following contents.

[0008] A traceability authentication method for a mobile Internet of Things device in a privacy protection scenario is applied to a law enforcement agency, and the method includes:

[0009] Generate a system private key pair (x sys ,Y sys ), system chameleon hash value CH sys and system trapdoors (k sys ,x sys ) and broadcast the system chameleon hash value CH sys and system public key Y sys , the system trapdoor (k sys ,x sys ) is sent to the domain management agency and edge nodes; where k sys Represents the system hash private key, x sys Indicates the system private key;

[0010] Get the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D , and the signature σ, the device chameleon hash value CH D and the effective registration time T of mobile IoT device D EXP Submit to the blockchain and get the transaction address TX D , and the transaction address TX D 、System Chameleon Hash Value CH sys and system public key Y sys Return to the mobile IoT device D, so that the mobile IoT device D and the edge node can be based on the transaction address TX D 、System Chameleon Hash Value CH sys、System public key Y sys And the device chameleon hash value CH in the blockchain D Perform a challenge-response process to complete the two-way authentication of the mobile IoT device D and the edge node; wherein the signature σ is generated by the identity information ID D 、Device Chameleon Hash Value CH D and effective registration time T EXP To generate a signature, the law enforcement agency stores the identity information ID locally D And transaction address TX D The information is correct.

[0011] Furthermore, the generation system private key pair (x sys ,Y sys ), system chameleon hash value CH sys and system trapdoors (k sys ,x sys ),include:

[0012] Select an elliptic curve E and obtain the base point P of the elliptic curve E;

[0013] Select a random number to generate the system private key And pick a random number and random numbers in, is a finite field;

[0014] Based on the system private key x sys and the base point P, generate the system public key Y sys ;

[0015] Based on random numbers Base point P, random number and system public key Y sys , generate the system chameleon hash value CH sys ;

[0016] Based on random numbers Random Numbers and the system private key x sys , generate the system hash private key k sys .

[0017] Furthermore, the identity information ID of the mobile Internet of Things device D is obtained D And the device Chameleon hash value CH D ,include:

[0018] Select random number As the encryption and decryption private key of the law enforcement agency, and based on the encryption and decryption private key Calculate encryption and decryption public keys with base point P

[0019] Broadcast the encryption and decryption public key So that the mobile IoT device D can use the encryption and decryption public key Identity information ID D And the device Chameleon hash value CH D Encrypt and transmit the encrypted registration information to law enforcement agencies via edge nodes and domain management agencies;

[0020] Use encryption and decryption private key Decrypt the encrypted registration information to obtain the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D .

[0021] Furthermore, the signature σ is obtained by D 、Device Chameleon Hash Value CH D and effective registration time T EXP Generate a signature, including:

[0022] Select random number As the signature private key of the law enforcement agency, and based on the signature private key Calculate the signature public key with base point P Afterwards, broadcast the signature public key

[0023] Based on the elliptic curve signature algorithm and using the signature private key Identity information ID D 、Device Chameleon Hash Value CH D and effective registration time T EXP Sign and obtain signature σ.

[0024] Furthermore, the mobile IoT device D and the edge node are based on the transaction address TX D 、System Chameleon Hash Value CH sys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Before the challenge-response process, it also includes:

[0025] Mobile IoT device D uses transaction address TX D Get the signature σ in the blockchain and use the signature public key The signature σ is verified; if the verification is successful, it indicates that the mobile Internet of Things device D has been successfully registered.

[0026] Furthermore, the mobile IoT device D and the edge node are based on the transaction address TX D 、System Chameleon Hash Value CHsys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Perform a challenge-response process to complete the two-way authentication of the mobile IoT device D and the edge node, including:

[0027] Mobile IoT device D generates a system private key pair (x D ,Y D ) and device trapdoor (k D ,x D ), where x D Indicates the device private key, Y D Represents the device public key, k D Represents the device hash private key;

[0028] Mobile IoT device D selects a random number a, records the current time to generate a timestamp, and based on the random number a, timestamp and system public key Y sys , computing challenge r;

[0029] Mobile IoT device D is based on device trapdoor (k D ,x D ) and challenge value r, calculate the first response value m D , and based on the random number a and the base point P, calculate the second response value A;

[0030] The mobile Internet of Things device D sends a first message to the edge node N; wherein the first message includes: a second response value A, a timestamp, and a device public key Y D , first response value m D and a pseudonymous PID of the mobile IoT device, the pseudonymous PID being based on the transaction address TX D And challenge value r is generated;

[0031] The edge node checks the validity of the timestamp timestamp, and after the check passes, based on the second response value A and the system private key x sys And timestamp thmestamp restores the challenge value r;

[0032] The edge node obtains the transaction address TX based on the challenge value r and the pseudonym PID D , and based on the transaction address TX D Get the device Chameleon hash value CH of mobile IoT device D D ;

[0033] The edge node is based on the device public key Y D And the device Chameleon hash value CH DAuthenticate the mobile IoT device D, and if the identity of the mobile IoT device D is verified, record the current time to generate a timestamp timestamp2;

[0034] The edge node uses the challenge value r and the system trapdoor (k sys ,x sys ) Calculate the third response value m N , using the pseudonym PID, timestamp timestamp2, second response value A and system private key x sys Calculate the session key session key, use the pseudonym PID, timestamp timestamp2 and the session key session key to calculate the hash value HASH1, and then send the second message to the mobile Internet of Things device D; wherein the second message includes: the third response value m N , timestamp timestamp2 and hash value HASH1;

[0035] Mobile IoT device D checks the validity of timestamp2 and, if the check passes, generates a new value based on the system chameleon hash value CH sys and system public key Y sys Verify the identity of edge nodes;

[0036] When the identity of the edge node is verified, the pseudonym PID, timestamp timestamp2, random number a and system public key Y are used. sys Calculate the session key session key′, and use the pseudonym PID, timestamp timestamp2 and the session key session key′ to calculate the hash value HASH′1;

[0037] When the hash value HASH1 is equal to the hash value HASH′1, the mobile Internet of Things device D calculates the hash value HASH2 of the first message message1, the second message message2 and the current session key session key′, and sends the hash value HASH2 to the edge node;

[0038] The edge node calculates the hash value HASH′2 of the first message message1, the second message message2 and the current session key sessionkey;

[0039] When the hash value HASH2 and the hash value HASH′2 are equal, the two-way authentication between the mobile IoT device D and the edge node is completed, and the mobile IoT device and the edge node communicate using the session key.

[0040] Furthermore, when the mobile Internet of Things device D is in the initial stage or cross-domain mobile stage, based on the transaction address TX D Get the device Chameleon hash value CH of mobile IoT device D from the blockchain D ;

[0041] When the mobile IoT device D is in the domain fast switching authentication stage, based on the transaction address TX D Get the device chameleon hash value CH of mobile IoT device D from the neighboring edge node D .

[0042] Furthermore, when the domain management agency discovers malicious behavior of the mobile Internet of Things device D, the method further includes:

[0043] The device chameleon hash value CH of the mobile IoT device D D Report to law enforcement agencies;

[0044] Law enforcement agencies use Chameleon hashing devices D Query on the blockchain and get the transaction address TX D ;

[0045] Based on the locally stored information, the law enforcement agency finds the transaction address TX D The corresponding identity information ID of mobile IoT device D D .

[0046] Furthermore, when the domain management agency discovers malicious behavior of the mobile Internet of Things device D or the mobile Internet of Things device D actively requests to deregister the device, the method further includes:

[0047] The domain management agency sends a message containing the chameleon hash value CH of the device to its subordinate edge nodes within the domain. D The revocation message;

[0048] After receiving the revocation message, the edge node stores the (TX D ,CH D ) entry deletion involves the device Chameleon hash value CH D Items of;

[0049] Law enforcement agencies use smart contracts to store device Chameleon hash values ​​on the blockchain. D The transaction address involved is TX D Set to an invalid value.

[0050] A mobile Internet of Things device traceability authentication system in a privacy protection scenario, the system comprising: a law enforcement agency, a domain management agency, an edge node and a mobile Internet of Things device D; wherein the law enforcement agency is used to:

[0051] Generate a system private key pair (x sys ,Y sys ), system chameleon hash value CH sys and system trapdoors (k sys ,x sys ) and broadcast the system chameleon hash value CH sys and system public key Y sys , the system trapdoor (k sys ,x sys ) is sent to the domain management agency and edge nodes; where k sys Represents the system hash private key, x sys Indicates the system private key;

[0052] Get the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D , and the signature σ, the device chameleon hash value CH D and the effective registration time T of mobile IoT device D EXP Submit to the blockchain and get the transaction address TX D , and the transaction address TX D 、System Chameleon Hash Value CH sys and system public key Y sys Return to the mobile IoT device D, so that the mobile IoT device D and the edge node can be based on the transaction address TX D 、System Chameleon Hash Value CH sys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Perform a challenge-response process to complete the two-way authentication of the mobile IoT device D and the edge node; wherein the signature σ is generated by the identity information ID D 、Device Chameleon Hash Value CH D and effective registration time T EXP To generate a signature, the law enforcement agency stores the identity information ID locally D And transaction address TX D The information is correct.

[0053] Compared with the prior art, the present invention has at least the following beneficial effects.

[0054] (1) In the present invention, the pseudonym and chameleon hash value used by the mobile Internet of Things device in the authentication process are generated by itself, thereby achieving the unlinkability of the mobile Internet of Things device messages and avoiding the security risks that may be caused by hosting.

[0055] (2) In the present invention, the chameleon hash function is used to implement two-way verification and key negotiation between mobile Internet of Things devices and edge nodes, which reduces the complexity of calculation. For edge nodes, batch authentication of mobile Internet of Things devices can be achieved.

[0056] (3) In the present invention, blockchain is used to store and share the chameleon hash values ​​of all registered vehicles, thereby realizing cross-domain authentication of mobile IoT devices and enhancing scalability in large-scale practical application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 It is a schematic diagram of the architecture of an embodiment of the method of the present invention.

[0058] Figure 2 It is an implementation flow chart of the registration algorithm in the present invention.

[0059] Figure 3 It is an implementation flow chart of the authentication algorithm in the present invention.

[0060] Figure 4 It is an implementation flow chart of the tracking and revocation algorithm in the present invention. DETAILED DESCRIPTION

[0061] The present invention is further described in detail below in conjunction with the accompanying drawings. The examples given are only used to explain the present invention but not to limit the scope of the present invention.

[0062] The present invention uses a chameleon hash function of an elliptic curve variant, a finite field F q Elliptic curve y on 2 =x 3 Various operations on +ax+b(mod q) (where q is a prime number or a power of a prime number) can be defined as follows:

[0063] 1. Point addition: For two points P = (x1, y1) and Q = (x2, y2) on the curve, the result of point addition (R = P + Q) can be calculated by the following formula, where λ represents the slope of the line connecting P and Q:

[0064] When P≠Q:

[0065] When P=Q:

[0066] Calculate the coordinates of R: x R =λ 2 -x1-x2 mod q

[0067] y R =λ(x1-x R )-y1mod q

[0068] 2. Scalar multiplication: For a given scalar k and point p, the result of scalar multiplication kP is k point additions performed on point P.

[0069] The security of each cryptographic function in the present invention is implemented based on the elliptic curve discrete logarithm problem and can be defined as follows:

[0070] Let E be defined on a finite field E q The elliptic curve on q is P, which is the generating point of the elliptic curve and has an order of n (i.e., nP=O, O is a point at infinity). For any point G on an elliptic curve, if there exists an integer t that satisfies G=tP, then t is called the discrete logarithm of G with respect to P. When q and n are sufficiently large prime numbers and have similar scales, and the selected elliptic curve meets certain properties, it is difficult to calculate the value of t when G and P are known.

[0071] The chameleon hash function of the elliptic curve variant used in the present invention can be defined as follows:

[0072] set up is the initial input, and the trapdoor (k, x) satisfies Hash key (P, Y) satisfies P is F q A point on the elliptic curve with a prime order of p, Y = xP. The hash value is calculated as follows:

[0073] CH(m,r)=mP+rY

[0074] Among them, m=k-rx mod q.

[0075] For an entity that does not hold a trapdoor, it is difficult to find (m,r) = (m′,r′) such that CH(m,r) = CH(m′,r′), that is, the Chameleon hash function is collision-resistant.

[0076] like Figure 1 As shown, the present invention mainly includes four stages: initialization, mobile Internet of Things device registration, authentication, and tracking and revocation.

[0077] 1. Initialization phase.

[0078] During the initialization phase, the law enforcement agency initializes parameters, generates system public and private key pairs, system chameleon hash values, and trapdoors, broadcasts the public keys and chameleon hash values ​​through public channels, and sends the trapdoors to edge nodes and other authentication entities through secure channels.

[0079] Specifically, all edge nodes in the present invention use the shared system chameleon hash value and the corresponding trapdoor to achieve identity authentication. The specific implementation steps of hash value, trapdoor generation and sharing are:

[0080] (1) The law enforcement agency selects an elliptic curve E and a base point P, and selects a random number generation system private key And generate random numbers Calculate the system public key Y sys 、System hash private key k sys and the system Chameleon hash value CH sys , the formula is as follows:

[0081] Y sys =x sys P

[0082]

[0083] Law enforcement agencies select random numbers As the encryption and decryption private key and signature private key of the law enforcement agency, and calculate the corresponding encryption and decryption public key and the signature public key

[0084] Each domain management agency selects a random number As its encryption and decryption private key and signature private key, and calculate the encryption and decryption public key and the signature public key And the encryption and decryption public key and the signature public key sent to law enforcement agencies;

[0085] Each edge node selects a random number As its encryption and decryption private key, and calculate the encryption and decryption public key And the encryption and decryption public key Sent to the domain authority of the domain to which it belongs.

[0086] (2) Law enforcement agencies use the encryption and decryption public keys of subordinate domain management agencies Encryption trapdoor, the system trapdoor (k sys ,x sys ) is sent to the domain management agency, which uses the encryption and decryption public key of the edge node The system trapdoor is sent again until each edge node obtains the system trapdoor. sys and the law enforcement agency's system public key Y sys , encryption and decryption public key Signature public key It can be sent to each domain management agency and edge node by broadcasting, and the signature public key of the domain management agency It is sent to all edge nodes in the domain through intra-domain broadcast.

[0087] 2. Mobile IoT device registration phase.

[0088] The mobile IoT device registers, generates a chameleon hash value autonomously and sends it securely to the law enforcement agency, which records the identity information and chameleon hash value of the mobile IoT device and encrypts and submits the relevant data to the blockchain. The mobile IoT device obtains system parameters and related authentication information.

[0089] In one embodiment, the mobile IoT device chameleon hash value CH D Generated autonomously by the mobile IoT device, the mobile IoT device D selects a random number Computing device public key Y D , median Device Chameleon Hash Value CH D and the device hash private key k D , the formula is as follows:

[0090] Y D =x D P

[0091]

[0092] Among them, ID D represents the mobile IoT device D, and H() is the hash function.

[0093] like Figure 2 As shown, the specific implementation steps of the registration algorithm are:

[0094] (1) Mobile IoT device D generates device chameleon hash value CH D , and register with the domain management agency. Mobile IoT device D uses the public key of the law enforcement agency Encrypted identity information ID D Chameleon hash value CH with device D Get encrypted registration information and through a secure method (such as offline registration or using the domain administration authority's public key encryption) Submit it to the domain management agency, which then sends it to the law enforcement agency LEA;

[0095] (2) Law enforcement agencies use the decryption private key Decrypting encrypted registration information Get the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D , set the effective registration time T for mobile IoT device D according to actual needs EXP (i.e. T EXP After a certain period of time, the mobile IoT device cannot pass the authentication), and then based on the elliptic curve signature algorithm and using the signature private key of the law enforcement agency Identity information ID D、Device Chameleon Hash Value CH D and effective registration time T EXP After signing, get the signature

[0096] (3) Law enforcement agencies will {σ,CH D ,T EXP}Submit to the blockchain and obtain the transaction address TX D ;

[0097] (4) Law enforcement agencies store {TX D ,ID D};

[0098] (5) The law enforcement agency returns {TX D ,CH sys ,Y sys}, the mobile IoT device checks whether the corresponding information has been uploaded to the chain and uses the signature public key of the law enforcement agency Verify the signature of the law enforcement agency σ, that is, check Is the result of true?

[0099] 3. Certification stage.

[0100] The mobile IoT device performs identity authentication, the edge node extracts authentication information from the temporary identity information of the mobile IoT device, and obtains the hash value of the mobile IoT device from the blockchain. Both parties conduct a challenge-response process to complete two-way authentication and key negotiation.

[0101] In one embodiment, Figure 3 As shown in the figure, the specific implementation steps of the authentication algorithm are:

[0102] If the mobile IoT device is in the initial stage or cross-domain mobility stage, that is, when the first authentication occurs with an edge node in a domain:

[0103] (1) Mobile IoT device D selects a random number a, records the current time to generate a timestamp, and calculates r = H(aY sys , timestamp), and use trapdoor (k D ,x D ) Calculate the first response value m D =k D -rx D and the second response value A=aP;

[0104] (2) The mobile IoT device sends a message to the edge node N. r}( is an XOR operation), PID is a pseudonym for the mobile IoT device;

[0105] (3) The edge node checks the validity of the timestamp and then calculates the challenge value r′=H(Ax sys ,timestamp), where Ax sys =aPx sys =aY sys , so r′=r, get the transaction address Use transaction address TX D Get the Chameleon hash value CH of the mobile IoT device from the blockchain D , and verify the identity of the mobile IoT device, the formula is as follows:

[0106]

[0107] (4) The edge node generates timestamp2, using the challenge value r′ and the system trapdoor (k sys ,x sys ) Calculate the third response value m N =k sys -r′x sys , and calculate the session key and hash value HASH. The calculation method is as follows:

[0108] session key=H(PID,timestamp2,Ax sys )

[0109] HASH=H(PID,timestamp2,session key)

[0110] Then, message2 = {m N ,timestamp2,HASH} is sent to D.

[0111] (5) The mobile IoT device checks the validity of timestamp2 and uses the system CH if it passes. sys and Y sys Verify the identity of the edge node, calculate the session key and verify it. The formula is as follows:

[0112]

[0113] session key′=H(PID,timestamp2,aY sys )

[0114]

[0115] (6) The mobile IoT device calculates the hash value of message1, message2 and session key′ and sends it to the edge node. The edge node also calculates the hash value of message1, message2 and session key and compares it with the hash value sent by the mobile IoT device. If they are equal, the mobile IoT device and the edge node use the session key to communicate.

[0116] If the mobile IoT device is in the intra-domain fast handover authentication phase, then in step (3), the edge node uses the (TX D ,CH D ) relationship to obtain the Chameleon hash of the mobile IoT device instead of querying the blockchain; the other steps are the same as the authentication in the initial stage.

[0117] When there are many authentication messages of mobile IoT devices, in (3), batch authentication can be used to process the authentication messages of multiple mobile IoT devices at one time. The batch authentication formula is:

[0118]

[0119] 4. Tracking and cancellation stage.

[0120] When a mobile IoT device generates malicious behavior or actively requests to cancel the device, law enforcement agencies can use the hash value of the mobile IoT device to find the real identity information of the mobile IoT device to trace the mobile IoT device, or modify the status of the mobile IoT device on the blockchain to achieve revocation.

[0121] In one embodiment, Figure 4 As shown in the figure, the specific implementation steps of the tracking and revocation algorithm are:

[0122] (1) The domain management agency discovers the malicious behavior of the vehicle and sends the vehicle’s CH D Report to law enforcement agencies. At the same time, record the current time to generate a timestamp T revocation , sending a revocation message to subordinate edge nodes within the domain

[0123] (2) Law enforcement agencies use mobile IoT devices D Query on the blockchain and get the transaction address TX D ;

[0124] (3) After receiving the revocation message, the edge node first checks the timestamp T revocation The validity of the signature is verified by If the verification is successful, check whether the internal storage exists (TXD ,CH D ), if any, delete the entry;

[0125] (4) The law enforcement agency finds TX in its local storage D The corresponding mobile IoT device real identity ID D , achieving on-demand tracking;

[0126] (5) Law enforcement agencies use smart contracts to transfer mobile IoT devices on the blockchain EXP Fields are set to invalid values;

[0127] (6) When the mobile IoT device attempts to authenticate again, the edge node cannot obtain device information from neighboring nodes, and cannot obtain the hash value of the mobile IoT device from the blockchain, so the authentication process cannot be completed.

[0128] In summary, the present invention is suitable for two-way identity authentication between edge node-like facilities and mobile Internet of Things devices. It can realize authentication, on-demand tracking and revocation of mobile devices while ensuring the security of identity information of mobile Internet of Things devices and the privacy of mobile paths, thus meeting the needs of privacy protection authentication and traceability.

[0129] Although the specific embodiments of the present invention are disclosed for the purpose of illustration, the purpose is to help understand the content of the present invention and implement it accordingly, those skilled in the art will understand that various substitutions, changes and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the content disclosed in the best embodiment, and the scope of the present invention is subject to the scope defined in the claims.

Claims

1. A traceability authentication method for mobile Internet of Things devices in a privacy protection scenario, characterized in that: Applied to a law enforcement agency, the method comprises: Generate a system private key pair (x sys ,Y sys ), system chameleon hash value CH sys and system trapdoors (k sys ,x sys ) and broadcast the system chameleon hash value CH sys and system public key Y sys , the system trapdoor (k sys ,x sys ) is sent to the domain management agency and edge nodes; where k sys Represents the system hash private key, x sys Indicates the system private key; Get the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D , and the signature σ, the device chameleon hash value CH D and the effective registration time T of mobile IoT device D EXP Submit to the blockchain and get the transaction address TX D , and the transaction address TX D 、System Chameleon Hash Value CH sys and system public key Y sys Return to the mobile IoT device D, so that the mobile IoT device D and the edge node can be based on the transaction address TX D 、System Chameleon Hash Value CH sys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Perform a challenge-response process to complete the two-way authentication of the mobile IoT device D and the edge node; wherein the signature σ is generated by the identity information ID D 、Device Chameleon Hash Value CH D and effective registration time T EXP To generate a signature, the law enforcement agency stores the identity information ID locally D And transaction address TX D The information is correct.

2. The method according to claim 1, characterized in that: The generated system private key pair (x sys ,Y sys ), system chameleon hash value CH sys and system trapdoors (k sys ,x sys ),include: Select an elliptic curve E and obtain the base point P of the elliptic curve E; Select a random number to generate the system private key And pick a random number and random numbers in, is a finite field; Based on the system private key x sys and the base point P, generate the system public key Y sys ; Based on random numbers Base point P, random number and system public key Y sys , generate the system chameleon hash value CH sys ; Based on random numbers Random Numbers and the system private key x sys , generate the system hash private key k sys .

3. The method according to claim 2, characterized in that The identity information ID of the mobile IoT device D is obtained D And the device Chameleon hash value CH D ,include: Select random number As the encryption and decryption private key of the law enforcement agency, and based on the encryption and decryption private key Calculate encryption and decryption public keys with base point P Broadcast the encryption and decryption public key So that the mobile IoT device D can use the encryption and decryption public key Identity information ID D And the device Chameleon hash value CH D Encrypt and transmit the encrypted registration information to law enforcement agencies via edge nodes and domain management agencies; Use encryption and decryption private key Decrypt the encrypted registration information to obtain the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D .

4. The method according to claim 2, characterized in that: The signature σ is obtained by D 、Device Chameleon Hash Value CH D and effective registration time T EXP Generate a signature, including: Select random number As the signature private key of the law enforcement agency, and based on the signature private key Calculate the signature public key with base point P Afterwards, broadcast the signature public key Based on the elliptic curve signature algorithm and using the signature private key Identity information ID D 、Device Chameleon Hash Value CH D and effective registration time T EXP Sign and obtain signature σ.

5. The method according to claim 4, characterized in that Mobile IoT device D and edge node based on transaction address TX D 、System Chameleon Hash Value CH sys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Before the challenge-response process, it also includes: Mobile IoT device D uses transaction address TX D Get the signature σ in the blockchain and use the signature public key The signature σ is verified; if the verification is successful, it indicates that the mobile Internet of Things device D has been successfully registered.

6. The method according to claim 2, characterized in that The mobile IoT device D and the edge node are based on the transaction address TX D 、System Chameleon Hash Value CH sys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Perform a challenge-response process to complete the two-way authentication of the mobile IoT device D and the edge node, including: Mobile IoT device D generates a system private key pair (x D ,Y D ) and device trapdoor (k D ,x D ), where x D Indicates the device private key, Y D Represents the device public key, k D Represents the device hash private key; Mobile IoT device D selects a random number a, records the current time to generate a timestamp, and based on the random number a, timestamp and system public key Y sys , computing challenge r; Mobile IoT device D is based on device trapdoor (k D ,x D ) and challenge value r, calculate the first response value m D , and based on the random number a and the base point P, calculate the second response value A; The mobile Internet of Things device D sends a first message to the edge node N; wherein the first message includes: a second response value A, a timestamp, and a device public key Y D , first response value m D and a pseudonymous PID of the mobile IoT device, the pseudonymous PID being based on the transaction address TX D And challenge value r is generated; The edge node checks the validity of the timestamp timestamp, and after the check passes, based on the second response value A and the system private key x sys And timestamp timestamp recovery challenge value r; The edge node obtains the transaction address TX based on the challenge value r and the pseudonym PID D , and based on the transaction address TX D Get the device Chameleon hash value CH of mobile IoT device D D ; The edge node is based on the device public key Y D And the device Chameleon hash value CH D Authenticate the mobile IoT device D, and if the identity of the mobile IoT device D is verified, record the current time to generate a timestamp timestamp2; The edge node uses the challenge value r and the system trapdoor (k sys ,x sys ) Calculate the third response value m N , using the pseudonym PID, timestamp timestamp2, second response value A and system private key x sys Calculate the session key session key, use the pseudonym PID, timestamp timestamp2 and the session key session key to calculate the hash value HASH1, and then send the second message to the mobile Internet of Things device D; wherein the second message includes: the third response value m N , timestamp timestamp2 and hash value HASH1; Mobile IoT device D checks the validity of timestamp2 and, if the check passes, generates a new value based on the system chameleon hash value CH sys and system public key Y sys Verify the identity of edge nodes; When the identity of the edge node is verified, the pseudonym PID, timestamp timestamp2, random number a and system public key Y are used. sys Calculate the session key session key′, and use the pseudonym PID, timestamp timestamp2 and the session key session key′ to calculate the hash value HASH′1; When the hash value HASH1 is equal to the hash value HASH′1, the mobile Internet of Things device D calculates the hash value HASH2 of the first message message1, the second message message2 and the current session key session key′, and sends the hash value HASH2 to the edge node; The edge node calculates the hash value HASH′2 of the first message message1, the second message message2 and the current session key session key; When the hash value HASH2 and the hash value HASH′2 are equal, the two-way authentication between the mobile IoT device D and the edge node is completed, and the mobile IoT device and the edge node communicate using the session key.

7. The method according to claim 6, characterized in that When the mobile IoT device D is in the initial stage or cross-domain mobile stage, based on the transaction address TX D Get the device Chameleon hash value CH of mobile IoT device D from the blockchain D ; When the mobile IoT device D is in the domain fast switching authentication stage, based on the transaction address TX D Get the device chameleon hash value CH of mobile IoT device D from the neighboring edge node D .

8. The method according to any one of claims 1 to 7, characterized in that: When the domain management agency discovers malicious behavior of the mobile Internet of Things device D, the method further includes: The device chameleon hash value CH of the mobile IoT device D D Report to law enforcement agencies; Law enforcement agencies use Chameleon hashing devices D Query on the blockchain and get the transaction address TX D ; Based on the locally stored information, the law enforcement agency finds the transaction address TX D The corresponding identity information ID of mobile IoT device D D .

9. The method according to any one of claims 1 to 7, characterized in that: When the domain management agency discovers malicious behavior of the mobile Internet of Things device D or the mobile Internet of Things device D actively requests to deregister the device, the method further includes: The domain management agency sends a message containing the chameleon hash value CH of the device to its subordinate edge nodes within the domain. D The revocation message; After receiving the revocation message, the edge node stores the (TX D ,CH D ) entry deletion involves the device Chameleon hash value CH D Items of Law enforcement agencies use smart contracts to store device chameleon hashes on the blockchain D The transaction address involved is TX D Set to an invalid value.

10. A mobile Internet of Things device traceability authentication system in a privacy protection scenario, characterized in that: The system includes: a law enforcement agency, a domain management agency, an edge node and a mobile Internet of Things device D; wherein the law enforcement agency is used to: Generate a system private key pair (x sys ,Y sys ), system chameleon hash value CH sys and system trapdoors (k sys ,x sys ) and broadcast the system chameleon hash value CH sys and system public key Y sys , the system trapdoor (k sys ,x sys ) is sent to the domain management agency and edge nodes; where k sys Represents the system hash private key, x sys Indicates the system private key; Get the identity information ID of mobile IoT device D D And the device Chameleon hash value CH D , and the signature σ, the device chameleon hash value CH D and the effective registration time T of mobile IoT device D EXP Submit to the blockchain and get the transaction address TX D , and the transaction address TX D 、System Chameleon Hash Value CH sys and system public key Y sys Return to the mobile IoT device D, so that the mobile IoT device D and the edge node can be based on the transaction address TX D 、System Chameleon Hash Value CH sys 、System public key Y sys And the device chameleon hash value CH in the blockchain D Perform a challenge-response process to complete the two-way authentication of the mobile IoT device D and the edge node; wherein the signature σ is generated by the identity information ID D 、Device Chameleon Hash Value CH D and effective registration time T EXP To generate a signature, the law enforcement agency stores the identity information ID locally D And transaction address TX D The information is correct.

Citation Information

Patent Citations

  • Lightweight authentication method and system based on Ethereum IoT entity, and intelligent terminal

    CN111147228A

  • Internet of vehicles crowd sensing reputation management system and method based on blockchain

    CN113452681A

  • Internet of vehicles cross-domain switching authentication method and system based on block chain

    CN116566581A

  • Certificateless Internet of Things equipment anonymous identity authentication method based on block chain

    CN117749388A

  • Cross-domain Internet of Things equipment identity authentication method and system based on block chain

    CN118214563A