Distributed certificate generation and switching authentication method suitable for 6G heterogeneous network
By introducing distributed certificate generation and switching authentication methods in 6G heterogeneous networks, and using a small dynamic committee to generate cross-domain certificates, the single point of failure problem of traditional centralized switching authentication solutions is solved, achieving higher security and robustness.
Patent Information
- Application Number
- CN202510036874.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-06
AI Technical Summary
In 6G heterogeneous networks, traditional centralized handover authentication schemes may have single point of failure problems, lack of robustness, resulting in critical services interruptions for user equipment.
Using distributed certificate generation and switching authentication methods, a small, dynamic, anonymous, silent committee is introduced to generate cross-domain certificates for cross-domain users through threshold methods, thereby conducting identity authentication and key negotiation.
This method supports decentralized handover authentication, which reduces the burden on the certification center and user equipment, improves the security and robustness of authentication, and reduces time delay and network load.
Smart Images

Figure CN119946633A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a distributed certificate generation and switching authentication method applicable to 6G heterogeneous networks, belonging to the technical field of network security. Background Art
[0002] With the exponential growth of data and devices in wireless networks, managing the growing traffic load is becoming increasingly challenging. In order to solve the reliability, efficiency, security and privacy issues of the fifth generation (5G) wireless network, the research and development of the sixth generation mobile communication technology (6G) is in full swing. The goal is to achieve full coverage, full spectrum, full application and strong security. 6G will be backward compatible, ensuring the continued functionality of existing infrastructure and equipment, thereby facilitating a smoother transition to 6G.
[0003] Heterogeneous Network (HetNet) refers to a network composed of different types of communication technologies, devices or systems. These networks usually integrate multiple access technologies, such as macro cells, small cells, Wi-Fi, Bluetooth, etc., with the aim of improving network capacity, coverage and communication quality. In a heterogeneous network, various nodes (such as high-power base stations and low-power hotspots) work together to cope with the growing user demand and data traffic. The advantage of HetNet is that it can make full use of the characteristics of different networks through intelligent scheduling and resource allocation to achieve efficient and flexible communication, which is particularly suitable for 5G and future network environments.
[0004] While HetNets offer many advantages, they also present new challenges. Among them, handover authentication between HetNets is key to ensuring efficient network performance and improving service quality. The handover authentication service ensures the secure roaming of user equipment (UE) between different networks. It ensures that when a terminal moves from one access point (AP) to another, its authentication information is securely transmitted and verified. The traditional centralized handover authentication process involves three entities: User Equipment (UE), Access Point (AP), and Authentication Center (AuC). When the UE moves, the source AP sends a handover request to the target AP, and the target AP requests authentication data from the AuC. After the AuC verifies the UE identity, it sends the result to the target AP. The target AP establishes a session key with the UE. Finally, the target AP notifies the source AP that the handover is successful.
[0005] Many handover authentication schemes have been proposed for 5G and future network environments to fill certain security gaps or improve handover performance. However, these schemes rely on a single AuC to register all network entities and are therefore not applicable to HetNets.
[0006] For the switching of HetNets, a general switching authentication scheme has been proposed using blockchain technology, elliptic curve Diffie-Hellman key exchange, and chameleon hash function. In this scheme, user equipment (UE) independently generates their private keys to ensure key escrow freedom. Although the scheme improves privacy and security or considers multiple switching scenarios, it relies on centralized switching authentication, which may have single point failure problems and lack robustness.
[0007] In order to achieve decentralized switching, the prior art uses a (t, n) threshold scheme to calculate the switching key. This scheme allows users to move anonymously in the mobile network and can also track the real identity of malicious users. There is also a group key negotiation protocol based on (t, n) secret sharing to reduce the overhead of switching authentication. With the assistance of decentralized edges, a decentralized switching authentication scheme is proposed, which reduces time delay and network load by transferring security from the network center to the edge. Although the above schemes enhance security by collaborating with multiple entities, these schemes are insecure if the collaborating entities become untrustworthy.
[0008] Related knowledge:
[0009] ElGamal encryption scheme: ElGamal encryption scheme is a public key encryption algorithm based on discrete logarithm problem, proposed by Taher ElGamal in 1985. It is widely used in modern cryptography, especially in the field of digital signature and data encryption. The scheme sets g as the generator of the cyclic group G of order q. The public parameters params of ElGamal encryption scheme EG are (G, g, q), which are implicit in the input of the following algorithm. EG is defined by the following three algorithms.
[0010] 1)EG.KeyGen: From the finite field Z q Select an element as the private key sk, and then calculate the public key pk = g sk ;
[0011] 2)EG.Enc pk (m): Select a random value r∈Z q After that, the algorithm outputs the ciphertext c = (c1, c2) = (g r ,m·pk r );
[0012] 3)EG.Dec sk(c): The algorithm outputs the plaintext m = c2 (c1 -sk ).
[0013] Cryptographic Sorting: Cryptographic Sorting is a random selection mechanism for participants based on cryptography, commonly used in distributed systems or consensus protocols, such as blockchain networks. The scheme can uniformly select C participants from N candidates. Let N and C be contained in the public parameter cpp. The process is non-interactive and consists of the following three algorithms.
[0014] 1)Π.KeyGen(cpp): The algorithm outputs a key pair consisting of a public key pk and a private key sk.
[0015] 2) Π.Select(cpp,sk,i): Given an input i and a private key sk, the algorithm outputs a verifiable random bit b and its proof π, where Pr[b=1]=C / N.
[0016] 3)Π.Verify(cpp,pk,b,π,i): This algorithm verifies the validity of b and π with respect to i and pk. Summary of the invention
[0017] Purpose of the invention: To address the problems and deficiencies in the prior art: With the increase in the density of user equipment (UE) in 6G heterogeneous networks, it becomes critical to ensure the reliability of frequent handovers in 6G wireless roaming environments. Traditional centralized handover authentication schemes may have single point failure problems and lack robustness, which may lead to interruption of key services for UEs.
[0018] The present invention provides a distributed certificate generation and handover authentication method suitable for 6G heterogeneous networks, which can simultaneously support the initial authentication, intra-domain handover authentication and cross-domain handover authentication of UE. In cross-domain handover, a trusted committee is introduced. When the UE enters the control range of the destination AP in a different domain, the destination AP first interacts with the committee to obtain the cross-domain certificate of the UE. After completion, the UE obtains a temporary cross-domain certificate and negotiates a session key with the destination AP.
[0019] The main challenge of the present invention is how to set up a trusted committee to complete the generation of cross-domain certificates in cross-domain handover. One of the important characteristics of blockchain is decentralization. Therefore, we introduce a small, dynamic, anonymous, silent committee in the blockchain and use a threshold method to generate cross-domain certificates for cross-domain users, thereby performing identity authentication and key negotiation. This method supports decentralized handover authentication, reduces the burden on AuC and UE, and improves the security and robustness of authentication.
[0020] Protecting user privacy is a basic security requirement for handover authentication, ensuring that the user's true identity is never transmitted in plain text. However, encryption alone is not enough to fully protect user privacy, because semi-honest network entities can still infer the user's identity. In order to solve this problem, the present invention allows the UE to obtain a pseudo-identity when registering its true identity. During the UE registration phase, the AuC will generate corresponding legal certificates for the true identity and pseudo-identity of the legitimate user, and only the corresponding AuC knows the true identity of the UE. Although anonymity can protect user privacy, malicious UEs can use it to cause damage to the system without worrying about retaliation. Therefore, the traceability mechanism of the present invention can identify such malicious UEs when necessary.
[0021] Technical solution: A distributed certificate generation and handover authentication method for 6G heterogeneous networks, including: an initial setup phase, a committee setup phase, and a handover authentication phase;
[0022] The committee setting stage includes the committee election and the succession of the confidentiality committee; the committee election includes the election of the nomination committee, the election of the confidentiality committee and the establishment of an anonymous transmission channel;
[0023] The handover authentication phase includes: UE registration, AuC distributing the secret share of the certificate generation key held by it to committee members, and UE handover authentication; the UE handover authentication includes intra-domain authentication and cross-domain authentication.
[0024] In the initial setup phase, let λ be a security parameter, used as input to determine the size of q, and select three cyclic groups G1, G2 and G T , which are all prime order q, and an asymmetric bilinear map e:G1×G2→G T ; Let g1∈G1 and g2∈G2 be generators; each AuC calculates its public and private key pair as The private key Ask is randomly selected by AuC itself; the hash function is represented by H.
[0025] In addition, each user in the blockchain generates a long-term key pair (lpk, lsk) and a temporary key pair (tpk, tsk) through the key generation algorithm of the ElGamal encryption scheme EG; all stakeholders in the blockchain generate a key pair (cpk, csk) through the key generation algorithm of the encryption sorting algorithm CS to participate in the encryption sorting; for each blockchain user, assume that other blockchain users know their public keys lpk, tpk and cpk.
[0026] During the committee setting phase, an encryption sorting algorithm is used to select a nomination committee, and the nomination committee selects a confidentiality committee.
[0027] 1) Election of the Nomination Committee: Let all stakeholders be represented by S T =S1,S2,…,S |sT| , the size of the nomination committee is C, which is specified by the public parameters of the cryptographic selection scheme CS; then each participant S i Call the selection function in the lottery scheme, or the lottery result b i And the proof of this result π i , i is the index of the current epoch; if S i b i is equal to 1, then S i is a certifier in epoch i+1, π i is their proof; if the number of nominators exceeds C, then the authenticators whose order in the secret committee exceeds C will be ignored. If the number of nominators is less than C, the missing members will be considered inaccessible in this case.
[0028] 2) Election of the Confidentiality Committee: After the election of the Nominating Committee is completed, each nominator nominates a candidate, who will be the certifier in the next Confidentiality Committee.
[0029] 3) Establish an anonymous communication channel: In order to ensure the anonymity of the confidentiality committee, the nominator needs to establish an anonymous communication channel with his candidate.
[0030] The election of the Secret Committee is delayed. The Nominating Committee of the previous era nominates the Secret Committee of the current era. Therefore, if the certification authority AuC t Share its private key Ask in the i-th epoch t , then the secret-keeping committee of the i+1th epoch can process cross-domain requests destined for domain t.
[0031] Succession of the Secret Committee: After the end of the current era, the Secret Committee enters the succession phase.
[0032] In the process of AuC distributing the secret share of the certificate generation key it holds to the committee members, AuC distributes its private key Ask to the secret committee. As a decentralized AuC, the committee can replace the AuC of the target domain to issue cross-domain certificates to legitimate UEs.
[0033] In the UE intra-domain handover authentication, it is assumed that the UE knows the target access point AP t The public key When the UE with the pseudonymous pID is located in the same domain but roams to another access point AP in the same domain t When the UE is in the area managed by the UE, it performs intra-domain handover authentication.
[0034] During UE cross-domain handover authentication, when the authentication center AuC sThe user UE moves to another authentication center AuC t Access Point AP t When the covered areas are different, the UE performs cross-domain handover authentication.
[0035] The beneficial effects of the present invention are:
[0036] First, in the intra-domain handover authentication phase of the present invention, the AP quickly performs identity authentication and key negotiation by verifying the UE certificate.
[0037] Second, the present invention introduces a small, dynamic, anonymous, silent committee from the blockchain in the cross-domain authentication stage, and uses a threshold method to generate a cross-domain certificate for the cross-domain UE. Each cross-domain UE can obtain a cross-domain certificate from the committee without the direct participation of the source domain AuC and the target domain AuC, thereby completing mutual authentication and key negotiation with the target domain AP, which reduces the burden on AuC and UE and improves the robustness of authentication.
[0038] Third, the security analysis of the present invention shows that this method can provide robust security properties in distributed handover authentication.
[0039] Fourth, theoretical and experimental analysis of the performance of the present invention show that the handover authentication method has low computational overhead on the AuC side and the UE side.
[0040] Fifth, the present invention can simultaneously realize the authentication of the following three situations:
[0041] 1) UE initial authentication: The UE sends its own information (including the UE's real identity and pseudo identity) to the AuC through a secure channel. The AuC detects whether the UE meets the network access requirements. If so, the AuC generates certificates for the UE's real identity and pseudo identity to protect the UE's real identity.
[0042] 2) Same domain cross-region authentication (cross-AP management area authentication under the same AuC): Determine whether the UE is a legitimate user by directly verifying whether the UE's certificate is valid. If it is legitimate, the destination AP negotiates the session key with the UE;
[0043] 3) Cross-domain authentication in different domains (cross-AP management area authentication under different AuCs): If the UE's certificate in the source domain is valid and meets the cross-domain access conditions of the destination domain, the destination AP applies for a cross-domain certificate from the committee. After receiving partial cross-domain certificates issued by enough committees, the destination AP generates a complete cross-domain certificate, sends it to the UE, and negotiates a session key with the UE. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is an architectural diagram of the entities involved in the method of the embodiment of the present invention;
[0045] Figure 2 is an overall flow chart of the method of the embodiment of the present invention;
[0046] Figure 3 It is a line graph of the communication overhead of the system in intra-domain handover authentication and inter-domain handover authentication in the experimental environment;
[0047] Figure 4 It is a line graph of the time cost required for the entity to perform the operation in the experimental environment;
[0048] Figure 5 The time overhead of each entity in the method of the embodiment of the present invention at different stages is as follows: (a) AuC calculation overhead in the preparation stage, (b) AP calculation overhead in the cross-domain switching stage, (c) calculation overhead of the current era authenticator in the inheritance stage, and (d) calculation overhead of the next era authenticator in the inheritance stage. DETAILED DESCRIPTION
[0049] The present invention is further explained below in conjunction with specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention. After reading the present invention, various equivalent forms of modifications to the present invention by those skilled in the art all fall within the scope defined by the claims attached to this application.
[0050] A distributed certificate generation and handover authentication method suitable for 6G heterogeneous networks includes: an initial setting phase, a committee setting phase, and a handover authentication phase.
[0051] The committee setting stage includes the committee election and the succession of the confidentiality committee; the committee election includes the election of the nomination committee, the election of the confidentiality committee and the establishment of an anonymous transmission channel.
[0052] The handover authentication phase includes: UE registration, AuC distributing the secret share of the certificate generation key it holds to committee members, and UE handover authentication; UE handover authentication includes intra-domain authentication and cross-domain authentication.
[0053] In the initial setup phase, let λ be the security parameter, which is used as input to determine the size of q, and select three cyclic groups G1, G2 and G T , which are all prime order q, and an asymmetric bilinear map e:G1×G2→G T ; Let g1∈W1 and g2∈G2 be generators; each AuC calculates its public and private key pair as The private key Ask is randomly selected by AuC itself; the hash function is represented by H.
[0054] In addition, each user in the blockchain generates a long-term key pair (lpk, lsk) and a temporary key pair (tpk, tsk) through the key generation algorithm of the ElGamal encryption scheme EG; all stakeholders in the blockchain generate a key pair (cpk, csk) through the key generation algorithm of the encryption sorting algorithm CS to participate in the encryption sorting; for each blockchain user, assume that other blockchain users know their public keys lpk, tpk and cpk.
[0055] During the committee setting stage, an encrypted sorting algorithm is used to select the nomination committee, and the nomination committee selects the confidentiality committee.
[0056] 1) Election of the Nomination Committee: Let all stakeholders be represented by S T =S1,S2,…,S |ST| , the size of the nomination committee is C, which is specified by the public parameters of the cryptographic selection scheme CS; then each participant S i Call the selection function in the lottery scheme, or the lottery result b i And the proof of this result π i , i is the index of the current epoch; if S i b i is equal to 1, then S i is a certifier in epoch i+1, π i is their proof; if the number of nominators exceeds C, then the authenticators whose order in the secret committee exceeds C will be ignored. If the number of nominators is less than C, the missing members will be considered inaccessible in this case.
[0057] 2) Election of the Confidentiality Committee: After the election of the Nominating Committee is completed, each nominator nominates a candidate, who will be the certifier in the next Confidentiality Committee.
[0058] 3) Establishing an anonymous communication channel: In order to ensure the anonymity of the confidentiality committee, the nominator needs to establish an anonymous communication channel with his candidate. The specific steps include:
[0059] Step 101: Each nominator nominates a candidate from the participants and obtains its long-term public key lpk. An honest nominator will nominate randomly, and a dishonest nominator nominates a dishonest candidate.
[0060] Step 102: Each nominator generates a new temporary key pair (tpk, tpk) for its candidate by calling the key generation algorithm of Elgamal, where tsk is the temporary private key and tpk is the temporary public key. The nominator then calls the encryption algorithm to encrypt the temporary private key tsk with the candidate's long-term public key lpk, and ek is the resulting ciphertext.
[0061] Step 103: Each nominator deletes its candidate’s private key tsk and then broadcasts (tpk,ek).
[0062] Step 104: Each stakeholder monitors the broadcast channel. Assume that in the i-th round of broadcast, the nominator sends several two-tuples (tpk1,ek1), (tpk2,ek2)….
[0063] Step 105: The stakeholders are sorted according to the dictionary of the temporary public key field of the two-tuple in step 104.
[0064] Step 106: For each two-tuple (tpk j ,ek j ), each stakeholder attempts to use their temporary private key lsk to try to ek j Decryption, if the result is the same as the temporary public key tpk j Correspondingly, he will realize that he is the jth authenticator in the next epoch and store the temporary private key tsk locally j .
[0065] The election of the Secret Committee is delayed. The Nominating Committee of the previous era nominates the Secret Committee of the current era. Therefore, if the certification authority AuC t Share its private key Ask in the i-th epoch t , then the secret-keeping committee of the i+1th epoch can process cross-domain requests destined for domain t.
[0066] Inheritance of the Secret Committee: After the current epoch ends, the Secret Committee enters the inheritance phase. Let Ask be a secret held by the current Secret Committee, represented by a secret polynomial F with degree t. i Definition, where F i (0) = Ask. The jth authenticator C i,j Shares held Then C i,j The inheritance process proceeds as follows:
[0067] Step 201: Randomly select a random polynomial g of degree t j ,in
[0068] Step 202: Retrieve the temporary public keys of all authenticators of the secret committee in the i+1th epoch from the broadcast channel and sort them in lexicographic order. Define Sh j,k =g j (k), and use the kth temporary public key tpk k , using the Elgamal algorithm to encrypt the re-shared share Sh j,k , the ciphertext obtained is em j,k .
[0069] Step 203: Generate a new long-term key pair (Lsk j ′,lpk j ′), lsk j ′ is the new long-term private key, lpk j ′ is the new long-term public key, and the previous long-term private key and all shared keys and temporary private keys related to the long-term private key are deleted.
[0070] Step 204: Broadcast a message including lpk j ′、C tuple (em j,1 ,…,em j,C ) and a partial cross-domain certificate for all legitimate requests during the committee’s term, the C tuple can be written as
[0071] set up is the set of j-tuples broadcast by all authenticators in step 204 in round i, arranged in lexicographic order. Let λ1,…,λ t+1 is the Lagrangian difference of the first t+1 points 1,…,t+1. Then, the jth authenticator C in the i+1th epoch i+1,j Execute steps 301 to 303.
[0072] Step 301: Select the first t+1 C-tuples in the set And extract the jth ciphertext em of each C tuple 1,j ,…,em t+1,j .
[0073] Step 302: Authenticator C i+1,j Use temporary private key tsk j Decrypt all the ciphertexts obtained in step 301 and obtain Sh 1,j ,…,Sh t+1,j .
[0074] Step 303: Calculate the global secret share is the effective share of the global key Ask.
[0075] In the UE registration, it is assumed that during the UE registration process, the transmission channel between the UE and the AuC is secure. λ When a UE registers with the network, the UE first randomly selects Select s as its long-term private key usk, then select the generator g2 of G2, and calculate the long-term public key through exponential operation UE sends a registration request Req UE ={rID,upk,T pID} sent to AuC, where TpID Is a timestamp.
[0076] Receive Req UE Afterwards, AuC processes the user's registration request through steps 401 to 405.
[0077] Step 401: Check timestamp T pID freshness to prevent replay attacks;
[0078] Step 402: Generate the UE's pseudo private key usk through the hash function H p =H(upk Ask ,T pID ), and obtain the pseudo public key through exponential operation
[0079] Step 403: By formula Generate a pseudo identity pID, where It is an XOR operation;
[0080] Step 404: Generate a certificate corresponding to rID and pID: Cert rID =H(rID,upk) Ask , Cert pID =H(pID,upk p ,T pID ) Ask ;
[0081] Step 405: Send a response message Res to the UE UE ={pID,usk p ,upk p ,Cert pID ,Cert rID}.
[0082] In the process of AuC distributing the secret share of the certificate generation key it holds to the committee members, AuC distributes its private key Ask to the secret committee. As a decentralized AuC, the committee can replace the AuC in the target domain to issue cross-domain certificates to legitimate UEs. Assuming that AuC shares its private key Ask in the i-th round, the specific process is divided into the following three steps.
[0083] Step 501: AuC randomly selects a polynomial F of degree t i+1 , where F i+1 (0) = Ask.
[0084] Step 502: AuC monitors the broadcast channel to obtain the secret committee C in the next era i+1 Temporary public keys tpk1,…,tpk C For C i+1For the jth authenticator in the authenticator, AuC assigns an evaluation point j and calculates the authenticator’s secret share After being encrypted with the authenticator’s public key, the ciphertext is broadcast.
[0085] Step 503: AuC broadcasts the ciphertext of all evaluation points and the secret share at the evaluation point. Every participant in the blockchain can try to decrypt the ciphertext in step 503, but only C i+1 The authenticator in is able to successfully decrypt and obtain the correct share.
[0086] In the UE intra-domain handover authentication, it is assumed that the UE knows the target access point AP t The public key When the UE with the pseudonymous pID is located in the same domain but roams to another access point AP in the same domain t When the UE is in the area managed by the UE, the UE performs intra-domain handover authentication, and the steps are as follows:
[0087] Step 601: UE sends an access request Req acc ={Cert pID ,pID,upk p ,T pID ,T acc ,Apk s}Send to AP t , T acc Is the timestamp.
[0088] Step 602: AP t Receive Req acc After that, first verify T acc to prevent replay attacks. Then, AP t Check the UE's certificate Cett by the following formula pID Validity: e(Cert pID ,g2)=e(H(pID,upk p ,T pID ),Apk s ), e is an asymmetric bilinear mapping function. If the equation holds, AP t Calculate the session key by exponential operation and h acc =H(SK,T SK ), and Res acc ={h acc ,T SK} is returned to the UE, where It is AP t The private key, T SK is the current timestamp, upk p It is the anonymous public key of the user UE.
[0089] Step 603: UE receives Res acc When T SK The timeliness of the access point is to prevent replay attacks, and then the public key of the access point is And your own private key usk p Recalculate the session key After the calculation is completed, the hash function H is used to verify the formula H(SK′,T SK )=h acc Is it true? If so, the UE completes the intra-domain handover authentication and the session key SK negotiation is completed.
[0090] During UE cross-domain handover authentication, when the authentication center AuC s The user UE moves to another authentication center AuC t Access Point AP t When the covered areas are different, the UE performs cross-domain handover authentication, and the steps are as follows:
[0091] Step 701: UE first checks whether there is an AuC t If the corresponding valid certificate exists, the UE can access the target domain, exit the cross-domain handover process and perform key negotiation according to the intra-domain handover authentication process; otherwise, the UE will request Req acc ={Cert pID ,pID,upk p ,T pID ,T acc ,Apk s}Send to AP t , Apk s It is the UE source authentication center AuC t The public key of acc Is the timestamp.
[0092] Step 702: AP t Receive Req from UE acc After that, we will check T acc To prevent replay attacks, through the asymmetric bilinear mapping e, according to the formula e(Cert pID ,g2)=e(H(pID,upk p ,T pID ),Apk s )Verify the certificate Cert pID If the verification is successful, AP t Broadcast a cross-origin request to the blockchain Where T req is the timestamp of the request, Is the validity period of the certificate.
[0093] Step 703: Upon receiving Req CD After that, the current secret committee C i All authenticators in check the request timestamp T req To prevent replay attacks, some cross-domain certificates are generated locally for the UE. In the secret committee C i term of office After the end, C i The secret committee succession process (steps 201 to 204) of the execution committee setup phase, each member of the secret committee sends its partial certificate to the AP t .
[0094] Step 704: When AP t After receiving more than t replies from step 703, AP t First, randomly select a subset of size t+1 from the received messages And through the formula Combine them to generate a complete cross-domain certificate Cert CD ,in is the Lagrangian interpolation at j. Then, AP t By formula Verify Cert CD Finally, AP t Calculate the session's private key and the user's anonymous public key upk p Calculate the key and h acc =H(SK,Cert CD ,T exp ,T SK ), and Res acc ={Cert CD ,T exp ,T SK ,h acc} is returned to the UE, where Is Cert CD The expiration time, T SK Is the timestamp.
[0095] Step 705: UE receives Res acc When T SK The UE then uses its own private key usk p and AP t The public key Calculate the session key If H(SK′,Cert CD ,T exp ,T SK )=h acc , the UE completes the intra-domain handover authentication and the session key SK negotiation ends.
[0096] We provide an instantiation method for the present invention based on Crypto++ and PBC. 2 =x 3 +b, where the lengths of the elements in groups G1, G2 and finite field Zr are 40B, 80B and 20B respectively, i.e., the security parameter λ = 160. The hash function H is implemented based on SHA-1 (20B). In addition, the lengths of pID and rID are also 20B. In the experiment, we set Ensuring an honest majority.
[0097] Experimental Results
[0098] The number of basic encryption primitives in the preparation phase and the handover authentication phase is counted, and the specific information is shown in Table 1. Among them, system is a general term for access points and authentication centers.
[0099] Table 1 Statistics of computational overhead at different stages
[0100]
[0101] The communication overhead of the present invention is as follows Figure 3 As shown in the figure, it can be seen that the intra-domain authentication overhead of the present invention has nothing to do with the size of the secret committee and is a constant level. However, the cross-domain authentication overhead is linearly related to the size of the secret committee.
[0102] Figure 4 The constant level overhead of each entity in the whole process of the present invention is counted. Figure 5 The remaining computational cost of each entity is shown.
[0103] Specifically, during the registration phase, AuC needs to generate a certificate for the UE based on its needs. The computational cost is as follows: Figure 4 As shown. Then, AuC distributes its private key Ask to the current secret committee. Figure 5 As shown in (a), this part of the computational cost is approximately linearly related to the committee size C. The AP in the target area is responsible for processing the authentication request within the domain, and its computational cost is independent of the committee size, such as Figure 4 The calculation cost of APs in the target area participating in cross-domain authentication is shown in Figure 4 . Figure 5 (c) Figure 5 (d) are the computational overhead of the authenticator in the current epoch and the next epoch, respectively.
[0104] We also simulated the succession process of the secret committee, such as Figure 5 As shown in Figure 2. The computational cost of the authenticator is approximately linear in the size of the committee C, but remains at the millisecond level. In the succession phase, the authenticators of the current epoch need to re-share their secrets. The authenticators of the next epoch will decrypt more than t key shares from the secret-keeping committee of the previous epoch and combine them to reconstruct their global key.
Claims
1. A distributed certificate generation and handover authentication method suitable for 6G heterogeneous networks, characterized in that: include: Initial setup phase, committee setup phase, and switch certification phase; The committee setting phase includes committee elections and succession to the secret committee; The committee election includes electing a nomination committee, electing a confidentiality committee and establishing an anonymous transmission channel; The handover authentication phase includes: UE registration, AuC distributing the secret share of the certificate generation key held by it to committee members, and UE handover authentication; The UE handover authentication includes intra-domain authentication and cross-domain authentication.
2. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 1 is characterized in that: In the initial setup phase, let λ be a security parameter, used as input to determine the size of q, and select three cyclic groups G1, G2 and G T , which are all prime order q, and an asymmetric bilinear map e: G1×G2→G T ;set up g1 ∈G1 and g2 ∈G2 is the generator; each AuC calculates its public and private key pair as The private key Ask is randomly selected by AuC itself; the hash function is represented by H; Each user in the blockchain generates a long-term key pair (lpk, lsk) and a temporary key pair (tpk, tsk) through the key generation algorithm of the E1Gamal encryption scheme EG; all stakeholders in the blockchain generate a key pair (cpk, csk) through the key generation algorithm of the encryption sorting algorithm CS to participate in the encryption sorting; for each blockchain user, assume that other blockchain users know their public keys lpk, tpk and cpk.
3. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 1 is characterized in that: In the committee setting stage, an encryption sorting algorithm is used to select a nomination committee, and the nomination committee selects a confidentiality committee; 1) Election of the Nomination Committee: Let all stakeholders be represented by S T =S1,S2,...,S |ST| , the size of the nomination committee is C, which is specified by the public parameters of the cryptographic selection scheme CS; then each participant S i Call the selection function in the lottery scheme, or the lottery result b i And the proof of this result π i , i is the index of the current epoch; if S i b i is equal to 1, then S i is a certifier in epoch i+1, π i is their proof; if the number of nominators exceeds C, then the authenticators whose order exceeds C in the secret committee will be ignored. If the number of nominators is less than C, the missing members will be considered inaccessible in this case; 2) Election of the Confidentiality Committee: After the Nomination Committee is elected, each nominator nominates a candidate, who will be the certifier of the next Confidentiality Committee; 3) Establish an anonymous communication channel: In order to ensure the anonymity of the confidentiality committee, the nominator needs to establish an anonymous communication channel with his candidate.
4. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 3 is characterized in that: The nominator needs to establish an anonymous communication channel with his / her candidate, which includes the following steps: Step 101: Each nominator nominates a candidate from the participants and obtains its long-term public key lpk; an honest nominator will nominate randomly, and a dishonest nominator nominates a dishonest candidate; Step 102: Each nominator generates a new temporary key pair (tsk, tpk) for its candidate by calling the key generation algorithm of Elgamal, where tsk is a temporary private key and tpk is a temporary public key; the nominator then calls the encryption algorithm to encrypt the temporary private key tsk with the candidate's long-term public key lpk, and ek is the resulting ciphertext; Step 103: Each nominator deletes the private key tsk of its candidate and then broadcasts (tpk, ek); Step 104: Each stakeholder monitors the broadcast channel; suppose that in the i-th round of broadcast, the nominator sends several two-tuples (tpk1, ek1), (tpk2, ek2)...; Step 105: The equity holders are sorted according to the dictionary of the temporary public key fields of the two-tuples in step 104; Step 106: For each two-tuple (tpk j ,ek j ), each stakeholder attempts to use their temporary private key lsk to try to ek j Decryption, if the result is the same as the temporary public key tpk j Correspondingly, he will realize that he is the jth authenticator in the next epoch and store the temporary private key tsk locally j .
5. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 3 is characterized in that: The election of the Secret Committee is delayed; the Nominating Committee of the previous epoch nominates the Secret Committee of the current epoch, so if the Certificate Authority AuC t Share its private key Ask in the i-th epoch t , then the secret-keeping committee of the i+1th epoch can process cross-domain requests destined for domain t.
6. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 3 is characterized in that: Inheritance of the Secret Committee: After the current epoch ends, the Secret Committee enters the inheritance phase; let Ask be a secret held by the current Secret Committee, represented by a secret polynomial F of degree t i Definition, where F i (0) = Ask; jth authenticator C i,j Shares held Then C i,j The inheritance process proceeds as follows: Step 201: Randomly select a random polynomial g of degree t j ,in Step 202: retrieve the temporary public keys of all authenticators of the secret committee in the i+1th epoch from the broadcast channel and sort them in lexicographic order; define Sh j,k =g j (k), and use the kth temporary public key tpk k , using the Elgamal algorithm to encrypt the re-shared share Sh j,k , the ciphertext obtained is em j,k ; Step 203: Generate a new long-term key pair (lsk′ j , lpk′ j ), lsk′ j is the new long-term private key, lpk′ j It is a new long-term public key, and the previous long-term private key and all shared keys and temporary private keys related to the long-term private key are deleted; Step 204: Broadcast a message including lpk′ j 、C tuple (em j,1 ,...,em j,C ) and a partial cross-domain certificate for all legitimate requests during the committee’s term, the C tuple can be written as set up is the set of j-tuples broadcasted by all authenticators in step 204 in round i, arranged in lexicographic order; let λ1, ..., λ t+1 is the Lagrangian difference of the first t+1 points 1, ..., t+1; then, the jth authenticator C in the i+1th epoch i+1,j Execute step 301 to step 303; Step 301: Select the first t+1 C-tuples in the set And extract the jth ciphertext em of each C tuple 1,j ,...,em t+1,j ; Step 302: Authenticator C i+1,j Use temporary private key tsk j Decrypt all the ciphertexts obtained in step 301 and obtain Sh 1,j , ..., Sh t+1,j ; Step 303: Calculate the global secret share is the effective share of the global key Ask.
7. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 1 is characterized in that: In the UE registration, it is assumed that during the UE registration process, the transmission channel between the UE and the AuC is secure; when the real identity is rID∈{0,1} λ When a UE registers with the network, the UE first randomly selects Select s as its long-term private key usk, and calculate the long-term public key through exponential operation UE sends a registration request Req UE ={rID, upk, T pID } sent to AuC, where T pID is a timestamp; Receive Req UE After that, AuC processes the user's registration request through steps 401 to 405; Step 401: Check timestamp T pID freshness to prevent replay attacks; Step 402: Generate the UE's pseudo private key usk through the hash function H p =H(upk Ask , T pID ), and obtain the pseudo public key through exponential operation Step 403: By formula Generate a pseudo identity pID, where It is an XOR operation; Step 404: Generate a certificate corresponding to rID and pID: Cert rID =H(rID, upk) Ask , Cert pID =H(pID,upk p , T pID ) Ask ; Step 405: Respond to the UE with a response message ReS UE ={pID,usk p , upk p , Cert pID , Cert rID }.
8. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 1, characterized in that: In the process of AuC distributing the secret share of the certificate generation key it holds to the committee members, AuC distributes its private key Ask to the secret committee. As a decentralized AuC, the committee can replace the AuC in the target domain to issue cross-domain certificates to legitimate UEs. Assuming that AuC shares its private key Ask in the i-th round, the specific process is divided into the following three steps: Step 501: AuC randomly selects a polynomial F of degree t i+1 , where F i+1 (0) = Ask; Step 502: AuC monitors the broadcast channel to obtain the secret committee C in the next era i+1 The temporary public key tpk1, ..., tpk c ; For C i+1 For the jth authenticator in the authenticator, AuC assigns an evaluation point j and calculates the authenticator’s secret share After being encrypted with the authenticator’s public key, the ciphertext is broadcast; Step 503: AuC broadcasts the ciphertext of all evaluation points and the secret share at the evaluation point. Every participant in the blockchain can try to decrypt the ciphertext in step 503, but only C i+1 The authenticator in is able to successfully decrypt and obtain the correct share.
9. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 1, characterized in that: In the UE intra-domain handover authentication, it is assumed that the UE knows the target access point AP t The public key When the UE with the pseudonymous pID is located in the same domain but roams to another access point AP in the same domain t When the UE is in the area managed by the UE, the UE performs intra-domain handover authentication, and the steps are as follows: Step 601: UE sends an access request Req acc ={Cert pID ,pID,upk p , T pID , T acc , Apk s }Send to AP t , T acc is the timestamp; Step 602: AP t Receive Req acc After that, first verify T acc to prevent replay attacks; then, AP t Check the UE certificate Cert using the following formula pID Validity: e(Cert pID , g2) = e(H(pID, upk p , T pID ), Apk s ), e is an asymmetric bilinear mapping function; If the equation holds, AP t Calculate the session key by exponential operation and h acc =H(SK,T SK ), and Res acc ={h acc , T SK } is returned to the UE, where It is AP t The private key, T SK is the current timestamp, upk p The anonymous public key of the user UE; Step 603: UE receives Res acc When T SK The timeliness of the access point is to prevent replay attacks, and then the public key of the access point is And your own private key usk p Recalculate the session key After the calculation is completed, the hash function H is used to verify the formula H(SK′, T SK )=h acc Is it true? If so, the UE completes the intra-domain handover authentication and the session key SK negotiation is completed.
10. The distributed certificate generation and handover authentication method applicable to 6G heterogeneous networks according to claim 1, characterized in that: During UE cross-domain handover authentication, when the authentication center AuC s The user UE moves to another authentication center AuC t Access Point AP t When the covered areas are different, the UE performs cross-domain handover authentication, and the steps are as follows: Step 701: UE first checks whether there is an AuC t The corresponding valid certificate that has not expired; if it exists, the UE can access the target domain, exit the inter-domain handover process and perform key negotiation according to the intra-domain handover authentication process; Otherwise, the UE will access the request Req acc ={Cert pID ,pID,upk p , T pID , T acc , Apk s }Send to AP t , Apk s It is the UE source authentication center AuC t The public key of acc is the timestamp; Step 702: AP t Receive Req from UE acc After that, we will check T acc To prevent replay attacks, through the asymmetric bilinear mapping e, according to the formula e(Cert pID , g2) = e(H(pID, upk p , T pID ), Apk s )Verify the certificate Cert pID ; If the verification is successful, AP t Broadcast a cross-origin request to the blockchain Where T req is the timestamp of the request, is the validity period of the certificate; Step 703: Upon receiving Req CD After that, the current secret committee C i All authenticators in check the request timestamp T req To prevent replay attacks, some cross-domain certificates are generated locally for the UE. In the secret committee C i term of office After the end, C i The secret committee succession process during the Executive Committee Setup phase, where each member of the secret committee sends their partial credentials to the AP t ; Step 704: When AP t After receiving more than t replies from step 703, AP t First, randomly select a subset of size t+1 from the received messages And through the formula Combine them to generate a complete cross-domain certificate Cert CD ,in is the Lagrangian interpolation at j; subsequently, AP t By formula Verify Cert CD effectiveness; finally, AP t Calculate the session's private key and the user's anonymous public key upk p Calculate the key and h acc =H(SK,Cert CD , T exp , T SK ), and Res acc ={Cert CD , T exp , T SK ,h acc } is returned to the UE, where Is Cert CD The expiration time, T SK is the timestamp; Step 705: UE receives Res acc When T SK timeliness to prevent replay attacks; then UE uses its own private key usk p and AP t The public key Calculate the session key If H(SK′, Cert CD , T exp , T SK )=h acc , the UE completes the intra-domain handover authentication and the session key SK negotiation ends.