Electronic signature and identity authentication strengthening system and method applied to industrial internet

By implementing equipment registration, data transmission encapsulation and multiple identity authentication mechanisms in the industrial Internet, the problems of complex equipment registration, insufficient data transmission security and incomplete identity authentication are solved, and the security and credibility of the industrial Internet are significantly improved.

CN119995897APending Publication Date: 2025-05-13SUZHOU HENGLI SMART TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510188028.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the industrial Internet, the equipment registration process is complicated, the data transmission security is insufficient, and the identity authentication mechanism is incomplete, resulting in insufficient security and credibility.

Method used

Improve the security and credibility of the industrial Internet through device registration, data transmission encapsulation and multi-factor identity authentication mechanisms, including digital certificate authentication, public key encryption verification and token verification.

Benefits of technology

It significantly improves the security and credibility of the industrial Internet, prevents illegal equipment access and data leakage, and ensures the integrity and confidentiality of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995897A_ABST
    Figure CN119995897A_ABST
Patent Text Reader

Abstract

The invention discloses an electronic signature and identity authentication strengthening system and method applied to the industrial internet, and relates to the field of digital signal transmission, and the system comprises equipment registration, data transmission packaging, primary identity authentication and advanced identity authentication mechanisms. The method comprises the following steps: firstly, generating a unique identifier, a digital certificate, a public key and a token of equipment; performing encryption processing on the transmission data by using an RSA electronic signature algorithm and an AES algorithm; the primary authentication realizes comprehensive identity auditing of the sending end equipment through three mechanisms of digital certificate authentication, public key encryption verification and token verification; the advanced authentication further ensures the authenticity and data integrity of the electronic signature through multiple steps of separation, decryption, public key information extraction, RSA verification, Hash calculation, comparison and the like; according to the method, the equipment registration process is simplified, the authority and access control of the equipment in the communication process are ensured, the identity authentication strength is enhanced, and the safety and credibility of the industrial internet are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of digital signal transmission, and more specifically, particularly relates to an electronic signature and identity authentication enhancement system and method applied to the industrial Internet. Background Art

[0002] With the rapid development of the industrial Internet, data transmission and identity authentication between devices have become important links in ensuring industrial production safety.

[0003] Chinese patent CN114448729B discloses a method and device for authenticating a client in the industrial Internet; the client generates a first signature and attaches it to the verification information. If the signature passes the verification, it proceeds to the next step; the collaborative signing end receives the first identity resolution request of the client that passes the initial verification, performs signature processing on it, and generates a second identity resolution request; the client performs signature processing on the received second identity resolution request again to generate a third identity resolution request; the identity authentication end uses the first digital certificate and the second digital certificate to verify the second signature of the client and the signature of the collaborative signing end respectively; only when the signature of the collaborative signing end and the second signature of the client are both verified, the identity authentication end confirms that the identity authentication of the client is successful; the present invention enhances the authentication strength of the client identity through a multi-level signature and verification mechanism, and improves the security of the entire identity resolution system.

[0004] At present, when devices in the Industrial Internet perform identity authentication, there are problems such as complex device registration process, insufficient data transmission security, and imperfect identity authentication mechanism. A more efficient, secure, and reliable electronic signature and identity authentication system and method is still needed. Summary of the invention

[0005] 1. Technical issues to be resolved In response to the problems in the related technology, the present invention provides an electronic signature and identity authentication enhancement system and method applied to the Industrial Internet, which effectively improves the security and credibility of the Industrial Internet through device registration, data transmission encapsulation and multiple identity authentication mechanisms.

[0006] (II) Technical solution In order to solve the above technical problems, the present invention is achieved through the following technical solutions: S1. Register the device using the Industrial Internet platform, connect the device to the server of the Industrial Internet, and generate a digital certificate, public key and token for the device; S2. Access the private key of the sending device, read the transmission data and perform hash value processing to obtain the hash value of the transmission data, apply the RSA electronic signature algorithm to the hash value of the transmission data to obtain the electronic signature, encrypt the transmission data to obtain encrypted transmission data, encapsulate the encrypted transmission data and the electronic signature to obtain an encapsulated data packet, and the sending device uses the industrial Internet platform to send the encapsulated data packet to the receiving device; S3, the receiving device parses the encapsulated data packet to obtain a parsed data packet, extracts the identity information of the sending device from the parsed data packet, and performs primary authentication on the sending device using an integrated authentication mechanism that combines multiple authentication methods such as digital certificate authentication, public key encryption authentication, and token authentication; S4. The receiving device performs advanced authentication on the sending device that has passed the primary authentication.

[0007] Preferably, the S1 comprises the following steps: S11. Generate an identifier of the device; S12, the device sends an identifier c The device and other registration information are sent to the Industrial Internet Platform. After verifying that the information is correct, the Industrial Internet Platform creates an account for the device and generates an initial configuration file. Other registration information includes device information, user information, security information, and network information. S13, connecting the device to the industrial Internet, using DNS resolution to obtain the address of the industrial Internet platform server, and establishing a TCP / IP connection with the server; S14, generating a digital certificate, a public key and a token of the device; The above steps ensure the legal identity of the device and the secure storage of basic information by generating a unique identifier for the device and submitting the necessary registration information. Through verification and account creation on the Industrial Internet platform, a reliable online identity is established for the device, and personalized configuration services are provided. Through DNS resolution and the establishment of TCP / IP connections, stable and efficient data communication between the device and the Industrial Internet platform is guaranteed. Finally, by generating digital certificates, public keys and tokens, a powerful identity authentication and access control mechanism is provided for the device, greatly improving the security and credibility of the Industrial Internet.

[0008] Preferably, the S11 comprises the following steps: S111. Get the IMEI number of the registered device: 、MAC address information is b 1; S112, the IMEI number of the registered device , MAC address information b 1 are converted into strings to obtain the IMEI number string of the registered device 、MAC address string b 2; S113: Register the IMEI number string of the device 、MAC address string b 2 Connect and get the device identifier c ; The above steps ensure the uniqueness and unforgeability of the device identification by obtaining the device's unique hardware information such as the IMEI number and MAC address and converting it into a string format; connecting these two strings to generate a device identifier further enhances the unique identification capability of the device identity, providing a reliable and secure identity foundation for the registration, authentication and communication of the device in the Industrial Internet.

[0009] Preferably, the S14 comprises the following steps: S141. Select two prime numbers G 1 and G 2. Get the modulus by calculation I , modulus I The length of is the length of the key; the calculation formula is as follows, ; S142. Calculate Euler function , set an integer J , the integer must satisfy and J and mutually prime; J As a public key index; S143, according to the public key index J and Euler function ,calculate J about Mutual modular inversion to obtain the private key index L ; then the public key is ( J , I ), the private key is ( L , I ); S144, the device submits the public key and identity information to a certificate authority (CA) to apply for a digital certificate; after the CA verifies the identity of the applicant, it signs the public key and identity information using the CA's private key to generate a digital certificate; after the device receives the digital certificate, it installs it on the device; S145. After the device passes the authentication of the industrial Internet platform, the server of the industrial Internet platform will generate a token, which contains information such as user identity and authority. The server of the industrial Internet platform sends the token to the device, and the device stores the token. The above steps establish a strong encryption mechanism based on the RSA algorithm for the device by selecting prime numbers and calculating the modulus, Euler function, and public and private keys, ensuring the security and confidentiality of data transmission; the device applies for and installs a digital certificate from the certificate authority (CA), realizing the authoritative authentication and tamper-proof nature of the device identity, and improving the credibility of the system; the token generated by the Industrial Internet platform for the device contains user identity and permission information, which not only simplifies the subsequent authentication process, but also realizes fine-grained access control, further enhancing the security and management efficiency of the Industrial Internet.

[0010] Preferably, S2 comprises the following steps: S21. Set the data to be transmitted by the transmitting device as transmission data, and represent the transmission data as a bit sequence. A , save the transferred data to a local file to obtain the transferred data file B ; Set the file path for the transferred data to C B , set the private key storage location for the transmitted data to C K ; S22, according to the private key storage location C K , access the user's private key ( L , I ), verify user permissions and ensure legal access; S23, read the transmission data file B , for the file B Perform hash processing to obtain the hash value of the transmitted data B H ; S24. Hash value for transmitted data B H Apply the RSA electronic signature algorithm to obtain an electronic signature E , record signature timestamp F ;The RSA electronic signature algorithm is as follows, ; S25. Transmission of data files B The transmission data in the encrypted transmission data file is encrypted N ; S26. Encrypt the transmitted file N Encrypted transmission data and electronic signature in E Connect to get the transmission data signature file Q ; S27, selecting an encapsulation format, adding metadata such as a timestamp, a data type, sender information, etc. to the encrypted transmission data and the electronic signature data, and obtaining the data to be encapsulated; Serialize the electronic signature data and metadata in the data to be encapsulated into the selected encapsulation string format; use the encapsulation function to encapsulate the data to be encapsulated to obtain an encapsulated data packet R; S28, the sending end device uses the industrial Internet platform to encapsulate the data packet R Send to the receiving device; The above steps ensure the integrity and traceability of the data by converting the transmitted data into a bit sequence and saving it as a file; access to the user's private key through multi-factor authentication strengthens the security of data transmission and prevents illegal access; hashing the transmitted data file and applying the RSA electronic signature algorithm ensures the data's immutability and the verifiability of the signature time; encrypting the transmitted data further protects the confidentiality of the data during transmission; connecting the encrypted data and the electronic signature and adding metadata achieves self-description and formatted encapsulation of the data, which is convenient for parsing and processing by the receiving device; finally, the encapsulated data packet is sent using the Industrial Internet platform to ensure efficient and reliable transmission of data.

[0011] Preferably, the S25 comprises the following steps: S251, set the key of AES encryption algorithm to O , set the initialization vector P ; S252, using AES algorithm combined with key O , Initialization vector P Encrypt the transmission data in the transmission data file to obtain an encrypted transmission file N ; The above steps provide strong encryption protection for transmitted data by setting the key and initialization vector of the AES encryption algorithm, ensuring the confidentiality and integrity of the data during transmission.

[0012] Preferably, S3 comprises the following steps: S31. The receiving device receives the encapsulated data packet through the Industrial Internet platform R , and encapsulate the data packet R Parse the data packet to obtain the parsed data packet and extract the identity information of the sending device; S32, the receiving device initiates an identity authentication request to the sending device through the identity authentication interface. After the request is passed, the sending device is authenticated by using an integrated authentication mechanism that combines digital certificate authentication, public key encryption authentication, and token authentication. S33, when all authentications in the integrated authentication mechanism are passed, the primary authentication is passed, and S4 is continued to be executed; otherwise, the primary authentication is not passed, and the communication connection with the sending end device is interrupted; The above steps receive and parse the encapsulated data packets, and the receiving device can effectively extract the identity information of the sending device, laying the foundation for subsequent identity verification; the integrated authentication mechanism that combines multiple authentication methods, including digital certificate authentication, public key encryption authentication, and token authentication, greatly enhances the reliability and security of identity authentication, and effectively prevents the access of illegal devices and data leakage. This multi-level authentication process ensures that only strictly verified devices can exchange data, thereby maintaining the stable operation of the industrial Internet and the confidentiality of data.

[0013] Preferably, the digital certificate authentication in S32 comprises the following steps: the sending end device sends a digital certificate to the receiving end device, and the receiving end device verifies the validity of the digital certificate of the sending end device, including the issuing authority, validity period and revocation status of the certificate; Public key encryption verification includes the following steps: The receiving device generates a challenge data T 1, and use the public key of the sending device to challenge the data T 1 Encrypt and get the encrypted challenge data T 2, Encrypt the challenge data T 2 is transmitted to the sending device; the sending device uses its private key to encrypt the challenge data T 2 Decrypt and get the decrypted data T 3, and the decrypted data T 3 Return to the receiving device, the receiving device verifies the returned decrypted data T 3. Whether to challenge data T 1 consistent, T 3 and T 1, the public key encryption verification passes, otherwise it fails; Token verification includes the following steps: the sending device sends an access token to the receiving device, and the receiving device verifies the validity and legitimacy of the token, including the issuer, validity period, and permissions of the token; The digital certificate authentication in the above steps ensures the legitimacy of the identity of the sending device and the current validity of the certificate, thereby establishing a basis for trust; public key encryption verification verifies the validity of the public and private key pairs held by the sending device through a challenge mechanism, ensuring the security of the encryption and decryption process of data transmission, and enhancing the confidentiality and integrity of communications; token verification further confirms the access rights of the sending device and the legitimacy of the token; these three authentication mechanisms complement each other to form a multi-level, comprehensive security authentication system, which greatly improves the security and credibility of communications between devices in the Industrial Internet, effectively prevents various security threats, and ensures the stable operation of the Industrial Internet and the confidentiality and integrity of data.

[0014] Preferably, S4 comprises the following steps: S41. After the sending device passes the primary authentication, the receiving device uses a separation function to separate the encrypted transmission data and the electronic signature in the parsed data packet to obtain the separated electronic signature. U and separated encrypted transmission data V 1; S42, decrypt the separated encrypted transmission data to obtain decrypted transmission data V 2; S43: Extracting the public key index from the public key of the sending device J and modulus I ; According to the public key index J and modulus I , use the RSA algorithm to verify the separated electronic signature and obtain the verification value W 1; S44, decrypting the transmitted data V 2 Calculate the hash value to obtain the decrypted transmission data hash value W 2. Compare the verification value with the decrypted transmission data hash value; S45, if the verification value W 1 = decrypt the transmitted data hash value W 2, if the advanced authentication succeeds, the communication connection with the sending device is maintained; otherwise, the advanced authentication fails, and the communication connection with the sending device is terminated; The above steps effectively separate the encrypted transmission data and the electronic signature through the separation function, ensuring the efficiency and accuracy of subsequent processing; decrypting the encrypted transmission data to restore the original data, providing a basis for data verification; using the public key information of the sending device, the electronic signature is verified and calculated through the RSA algorithm to ensure the authenticity and integrity of the signature; the hash value of the decrypted transmission data is calculated and compared with the verification value to verify the data integrity; finally, based on the verification result, it is decided whether to maintain the communication connection with the sending device, ensuring that only legal data that has been strictly verified can be received and processed, thereby greatly improving the security and credibility of data transmission in the Industrial Internet.

[0015] An electronic signature and identity authentication enhancement system applied to the industrial Internet, which is used to implement the above-mentioned electronic signature and identity authentication enhancement method applied to the industrial Internet, including a device registration module, an electronic signature generation module, a data encryption and packaging module, a primary authentication module, and an advanced authentication module; The device registration module is used to generate a unique identifier when registering a device, send it to the industrial Internet platform for verification, create an account, establish a connection, and generate a digital certificate, public key and token; The electronic signature generation module accesses the private key of the sending device, reads and hashes the transmitted data, applies the RSA electronic signature algorithm to generate an electronic signature and records a timestamp; The data encryption and packaging module is used to encrypt the transmission data, obtain the encrypted transmission data, encapsulate the electronic signature and the encrypted transmission data into a data packet, and finally securely send it to the receiving end device through the industrial Internet platform; The primary authentication module is used to parse the data packet through the receiving end, extract the identity information, and complete the primary authentication through the triple authentication of digital certificate, public key encryption and token verification; The advanced authentication module is used to strictly authenticate data transmission in the Industrial Internet through a multi-step process including separation, decryption, extraction of public key information, RSA verification, hash calculation and comparison, to ensure the authenticity of the electronic signature and data integrity, and complete advanced authentication.

[0016] (III) Beneficial effects The present invention has the following beneficial effects: The present invention significantly improves the security and credibility of the Industrial Internet through device registration, data transmission encapsulation and multiple identity authentication mechanisms; the digital certificate, public key and token generated during the device registration process establish a unique and unforgeable identity for the device, effectively preventing the access of illegal devices; at the same time, the hash value processing, RSA electronic signature algorithm application and AES encryption processing during data transmission ensure the integrity and confidentiality of the data during transmission, greatly reducing the risk of data tampering or leakage.

[0017] The multiple identity authentication mechanism of the present invention, including digital certificate authentication, public key encryption verification and token verification, realizes a comprehensive and strict identity review of the sending device; this integrated authentication mechanism not only verifies the legal identity of the device, but also ensures the device's authority and access control during the communication process, thereby building a more secure and reliable industrial Internet environment; in addition, through the primary authentication and electronic signature verification of the receiving device, the strength of identity authentication is further enhanced, effectively preventing malicious attacks and illegal access.

[0018] The present invention simplifies the device registration process and improves the operating efficiency of the industrial Internet; by automatically generating device identifiers, digital certificates and tokens, it reduces the possibility of manual intervention and configuration errors; at the same time, the formatting and standardized processing of encapsulated data packets reduces the complexity of data transmission and improves the efficiency of data transmission.

[0019] In summary, the present invention not only improves the security and credibility of the Industrial Internet, but also optimizes the device registration and data transmission processes, providing a strong guarantee for the rapid development of the Industrial Internet.

[0020] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions of the embodiments of the invention, the drawings required for describing the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the invention. For ordinary technicians in this field, they can also obtain drawings based on these drawings without paying creative work.

[0022] Figure 1 It is a flow chart of the electronic signature and identity authentication strengthening method applied to the industrial Internet according to the present invention; Figure 2 It is a flow chart of the primary authentication module in the electronic signature and identity authentication enhancement system applied to the industrial Internet according to the present invention; Figure 3 It is a flow chart of the advanced authentication module in the electronic signature and identity authentication enhancement system applied to the industrial Internet of the present invention. DETAILED DESCRIPTION

[0023] The following will be combined with the drawings in the embodiments of the invention to clearly and completely describe the technical solutions in the embodiments of the invention. Obviously, the described embodiments are only part of the embodiments of the invention, not all of the embodiments. Based on the embodiments in the invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the invention.

[0024] In the description of the present invention, it is necessary to understand that the terms "opening", "upper", "lower", "top", "middle", "inside" and the like indicating orientation or positional relationship are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the components or elements referred to must have a specific orientation, be constructed and operate in a specific orientation, and therefore cannot be understood as limiting the invention. Example

[0025] See also Figure 1 , Figure 2 , Figure 3 The present invention discloses an electronic signature and identity authentication strengthening method applied to the industrial Internet, comprising the following steps: S1. Register the device using the Industrial Internet platform, connect the device to the server of the Industrial Internet, and generate a digital certificate, public key and token for the device; S11. Generate an identifier of the device; The S11 comprises the following steps: S111. Get the IMEI number of the registered device: 、MAC address information is b 1; S112, the IMEI number of the registered device , MAC address information b 1 are converted into strings to obtain the IMEI number string of the registered device 、MAC address string b 2; S113: Register the IMEI number string of the device 、MAC address string b 2 Connect and get the device identifier c ; S12, the device sends an identifier c The device and other registration information are sent to the Industrial Internet Platform. After verifying that the information is correct, the Industrial Internet Platform creates an account for the device and generates an initial configuration file. Other registration information includes device information, user information, security information, and network information. S13, connecting the device to the industrial Internet, using DNS resolution to obtain the address of the industrial Internet platform server, and establishing a TCP / IP connection with the server; S14, generating a digital certificate, a public key and a token of the device; The S14 comprises the following steps: S141. Select two prime numbers G 1 and G 2. Get the modulus by calculation I , modulus I The length of is the length of the key; the calculation formula is as follows, ; S142. Calculate Euler function , set an integer J , the integer must satisfy and J and mutually prime; J As a public key index; S143, according to the public key index J and Euler function ,calculate J about Mutual modular inversion to obtain the private key index L ; then the public key is ( J , I ), the private key is ( L , I ); S144, the device submits the public key and identity information to a certificate authority (CA) to apply for a digital certificate; after the CA verifies the identity of the applicant, it signs the public key and identity information using the CA's private key to generate a digital certificate; after the device receives the digital certificate, it installs it on the device; S145. After the device passes the authentication of the industrial Internet platform, the server of the industrial Internet platform will generate a token, which contains information such as user identity and authority. The server of the industrial Internet platform sends the token to the device, and the device stores the token. S2. Access the private key of the sending device, read the transmission data and perform hash value processing to obtain the hash value of the transmission data, apply the RSA electronic signature algorithm to the hash value of the transmission data to obtain the electronic signature, encrypt the transmission data to obtain encrypted transmission data, encapsulate the encrypted transmission data and the electronic signature to obtain an encapsulated data packet, and the sending device uses the industrial Internet platform to send the encapsulated data packet to the receiving device; The S2 comprises the following steps: S21. Set the data to be transmitted by the transmitting device as transmission data, and represent the transmission data as a bit sequence. A , save the transferred data to a local file to obtain the transferred data file B ; Set the file path for the transferred data to C B , set the private key storage location for the transmitted data to C K ; S22, according to the private key storage location C K , access the user's private key ( L , I ), verify user permissions and ensure legitimate access, such as through multi-factor authentication such as passwords and biometrics; S23, read the transmission data file B , use SHA-256 to encrypt the file B Perform hash processing to obtain the hash value of the transmitted data B H ; S24. Hash value for transmitted data B H Apply the RSA electronic signature algorithm to obtain an electronic signature E , record signature timestamp F ;The RSA electronic signature algorithm is as follows, ; S25. Transmission of data files B The transmission data in the encrypted transmission data file is encrypted N ; The S25 comprises the following steps: S251, set the key of AES encryption algorithm to O , set the initialization vector P ; S252, using AES algorithm combined with key O , Initialization vector P Encrypt the transmission data in the transmission data file to obtain an encrypted transmission file N ; S26. Encrypt the transmitted file N Encrypted transmission data and electronic signature in E Connect to get the transmission data signature file Q ; S27. Select the encapsulation format as JSON, add metadata such as timestamp, data type, sender information, etc. to the encrypted transmission data and electronic signature data, and obtain the data to be encapsulated; Serialize the electronic signature data and its metadata in the data to be encapsulated into the selected encapsulation JSON string format; use the encapsulation function to encapsulate the data to be encapsulated to obtain an encapsulated data packet R ; S28, the sending end device uses the industrial Internet platform to encapsulate the data packet R Send to the receiving device; S3, the receiving device parses the encapsulated data packet to obtain a parsed data packet, extracts the identity information of the sending device from the parsed data packet, and performs primary authentication on the sending device using an integrated authentication mechanism that combines multiple authentication methods such as digital certificate authentication, public key encryption authentication, and token authentication; The S3 comprises the following steps: S31. The receiving device receives the encapsulated data packet through the Industrial Internet platform R , use JSON to encapsulate the data packet R Parse the data packet to obtain the parsed data packet and extract the identity information of the sending device; S32, the receiving device initiates an identity authentication request to the sending device through the identity authentication interface. After the request is passed, the sending device is authenticated by using an integrated authentication mechanism that combines digital certificate authentication, public key encryption authentication, and token authentication. The digital certificate authentication in S32 includes the following steps: the sending end device sends a digital certificate to the receiving end device, and the receiving end device verifies the validity of the digital certificate of the sending end device, including the issuing authority, validity period and revocation status of the certificate; Public key encryption verification includes the following steps: The receiving device generates a challenge data T 1, and use the public key of the sending device to challenge the dataT 1 Encrypt and get the encrypted challenge data T 2, Encrypt the challenge data T 2 is transmitted to the sending device; the sending device uses its private key to encrypt the challenge data T 2 Decrypt and get the decrypted data T 3, and the decrypted data T 3 Return to the receiving device, the receiving device verifies the returned decrypted data T 3. Whether to challenge data T 1 consistent, T 3 and T 1, the public key encryption verification passes, otherwise it fails; Token verification includes the following steps: the sending device sends an access token to the receiving device, and the receiving device verifies the validity and legitimacy of the token, including the issuer, validity period, and permissions of the token; S33, when all authentications in the integrated authentication mechanism are passed, the primary authentication is passed, and S4 is continued to be executed; otherwise, the primary authentication is not passed, and the communication connection with the sending end device is interrupted; S4, the receiving device performs advanced authentication on the sending device that has passed the primary authentication; The S4 comprises the following steps: S41. After the sending device passes the primary authentication, the receiving device uses a separation function to separate the encrypted transmission data and the electronic signature in the parsed data packet to obtain the separated electronic signature. U and separated encrypted transmission data V 1; S42, decrypt the separated encrypted transmission data to obtain decrypted transmission data V 2; S43: Extracting the public key index from the public key of the sending device J and modulus I ; According to the public key index J and modulus I , use the RSA algorithm to verify the separated electronic signature and obtain the verification value W 1; S44, use SHA-256 to decrypt the transmitted data V 2 Calculate the hash value to obtain the decrypted transmission data hash value W 2. Compare the verification value with the decrypted transmission data hash value; S45, if the verification value W 1 = decrypt the transmitted data hash value W2, the advanced authentication succeeds and the communication connection with the sending device is maintained; otherwise, the advanced authentication fails and the communication connection with the sending device is interrupted.

[0026] Embodiment 2: An electronic signature and identity authentication enhancement system applied to the industrial Internet, which is used to implement the above-mentioned electronic signature and identity authentication enhancement method applied to the industrial Internet, including a device registration module, an electronic signature generation module, a data encryption and packaging module, a primary authentication module, and an advanced authentication module; The device registration module is used to generate a unique identifier when registering a device, send it to the industrial Internet platform for verification, create an account, establish a connection, and generate a digital certificate, public key and token; The electronic signature generation module accesses the private key of the sending device, reads and hashes the transmitted data, applies the RSA electronic signature algorithm to generate an electronic signature and records a timestamp; The data encryption and packaging module is used to encrypt the transmission data, obtain the encrypted transmission data, encapsulate the electronic signature and the encrypted transmission data into a data packet, and finally securely send it to the receiving end device through the industrial Internet platform; The primary authentication module is used to parse the data packet through the receiving end, extract the identity information, and complete the primary authentication through the triple authentication of digital certificate, public key encryption and token verification; The advanced authentication module is used to strictly authenticate data transmission in the Industrial Internet through a multi-step process including separation, decryption, extraction of public key information, RSA verification, hash calculation and comparison, to ensure the authenticity of the electronic signature and data integrity, and complete advanced authentication.

[0027] In the description of this specification, the description with reference to the terms "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0028] The preferred embodiments of the invention disclosed above are only used to help explain the invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific implementation methods described. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the invention, so that those skilled in the art can understand and use the invention well.

Claims

1. An electronic signature and identity authentication enhancement method applied to the industrial Internet, characterized in that: The following steps are involved: S1. Register the device using the Industrial Internet platform, connect the device to the server of the Industrial Internet, and generate a digital certificate, public key and token for the device; S2. Access the private key of the sending device, read the transmission data and perform hash value processing to obtain the hash value of the transmission data, apply the RSA electronic signature algorithm to the hash value of the transmission data to obtain the electronic signature, encrypt the transmission data to obtain encrypted transmission data, encapsulate the encrypted transmission data and the electronic signature to obtain an encapsulated data packet, and the sending device uses the industrial Internet platform to send the encapsulated data packet to the receiving device; S3, the receiving device parses the encapsulated data packet to obtain a parsed data packet, extracts the identity information of the sending device from the parsed data packet, and performs primary authentication on the sending device using an integrated authentication mechanism that combines multiple authentication methods such as digital certificate authentication, public key encryption authentication, and token authentication; The S3 comprises the following steps: S31. The receiving device receives the encapsulated data packet through the Industrial Internet platform R , and encapsulate the data packet R Parse the data packet to obtain the parsed data packet and extract the identity information of the sending device; S32, the receiving device initiates an identity authentication request to the sending device through the identity authentication interface. After the request is passed, the sending device is authenticated by using an integrated authentication mechanism that combines digital certificate authentication, public key encryption authentication, and token authentication. S33, when all authentications in the integrated authentication mechanism are passed, the primary authentication is passed, and S4 is continued to be executed; otherwise, the primary authentication is not passed, and the communication connection with the sending end device is interrupted; S4, the receiving device performs advanced authentication on the sending device that has passed the primary authentication; The S4 comprises the following steps: S41. After the sending device passes the primary authentication, the receiving device uses a separation function to separate the encrypted transmission data and the electronic signature in the parsed data packet to obtain the separated electronic signature. U and separated encrypted transmission data V 1; S42, decrypt the separated encrypted transmission data to obtain decrypted transmission data V 2; S43: Extracting the public key index from the public key of the sending device J and modulus I ; According to the public key index J and modulus I , use the RSA algorithm to verify the separated electronic signature and obtain the verification value W 1; S44, decrypting the transmitted data V 2 Calculate the hash value to obtain the decrypted transmission data hash value W 2. Compare the verification value with the decrypted transmission data hash value; S45, if the verification value W 1 = decrypt the transmitted data hash value W 2, the advanced authentication succeeds and the communication connection with the sending device is maintained; otherwise, the advanced authentication fails and the communication connection with the sending device is interrupted.

2. The electronic signature and identity authentication strengthening method applied to the industrial Internet according to claim 1 is characterized in that: The S1 comprises the following steps: S11. Generate an identifier of the device; S12, the device sends an identifier c The device and other registration information are sent to the Industrial Internet Platform. After verifying that the information is correct, the Industrial Internet Platform creates an account for the device and generates an initial configuration file. S13, connecting the device to the industrial Internet, using DNS resolution to obtain the address of the industrial Internet platform server, and establishing a TCP / IP connection with the server; S14, generating a digital certificate, a public key and a token for the device.

3. The electronic signature and identity authentication strengthening method applied to the industrial Internet according to claim 2 is characterized in that: The S11 comprises the following steps: S111. Get the IMEI number of the registered device: 、MAC address information is b 1; S112, the IMEI number of the registered device , MAC address information b 1 are converted into strings to obtain the IMEI number string of the registered device 、MAC address string b 2; S113: Register the IMEI number string of the device 、MAC address string b 2 Connect and get the device identifier c .

4. The electronic signature and identity authentication strengthening method applied to the industrial Internet according to claim 2 is characterized in that: The S14 comprises the following steps: S141. Select two prime numbers G 1 and G 2. Get the modulus by calculation I , modulus I The length of is the length of the key; the calculation formula is as follows, ; S142. Calculate Euler function , set an integer J , the integer must satisfy and J and mutually prime; J As a public key index; S143, according to the public key index J and Euler function ,calculate J about Mutual modular inversion to obtain the private key index L ; then the public key is ( J , I ), the private key is ( L , I ); S144, the device submits the public key and identity information to the CA to apply for a digital certificate; After the CA verifies the identity of the applicant, it uses the CA's private key to sign the public key and identity information to generate a digital certificate. After the device receives the digital certificate, it installs it on the device. S145. After the device passes the industrial Internet platform authentication, the server of the industrial Internet platform will generate a token, the server of the industrial Internet platform will send the token to the device, and the device will store the token.

5. The electronic signature and identity authentication strengthening method applied to the industrial Internet according to claim 1 is characterized in that: The S2 comprises the following steps: S21. Set the data to be transmitted by the transmitting device as transmission data, and represent the transmission data as a bit sequence. A , save the transferred data to a local file to obtain the transferred data file B ; Set the file path for the transferred data to C B , set the private key storage location for the transmitted data to C K ; S22, according to the private key storage location C K , access the user's private key ( L , I ), verify user permissions and ensure legal access; S23, read the transmission data file B , for the file B Perform hash processing to obtain the hash value of the transmitted data B H ; S24. Hash value for transmitted data B H Apply the RSA electronic signature algorithm to obtain an electronic signature E , record signature timestamp F ;The RSA electronic signature algorithm is as follows, ; S25. Transmission of data files B The transmission data in the encrypted transmission data file is encrypted N ; S26. Encrypt the transmitted file N Encrypted transmission data and electronic signature in E Connect to get the transmission data signature file Q ; S27, selecting an encapsulation format, adding metadata to the encrypted transmission data and the electronic signature data, and obtaining data to be encapsulated; Serialize the electronic signature data and its metadata in the data to be encapsulated into the selected encapsulation string format; use the encapsulation function to encapsulate the data to be encapsulated to obtain an encapsulated data packet R ; S28, the sending end device uses the industrial Internet platform to encapsulate the data packet R Send to the receiving device.

6. The electronic signature and identity authentication strengthening method applied to the industrial Internet according to claim 5 is characterized in that: The S25 comprises the following steps: S251, set the key of AES encryption algorithm to O , set the initialization vector P ; S252, using AES algorithm combined with key O , Initialization vector P Encrypt the transmission data in the transmission data file to obtain an encrypted transmission file N .

7. The electronic signature and identity authentication strengthening method applied to the industrial Internet according to claim 1 is characterized in that: The digital certificate authentication in S32 includes the following steps: the sending end device sends a digital certificate to the receiving end device, and the receiving end device verifies the validity of the digital certificate of the sending end device; Public key encryption verification includes the following steps: The receiving device generates a challenge data T 1, and use the public key of the sending device to challenge the data T 1 Encrypt and get the encrypted challenge data T 2. Encrypt the challenge data T 2 is transmitted to the sending device; the sending device uses its private key to encrypt the challenge data T 2 Decrypt and get the decrypted data T 3, and the decrypted data T 3 Return to the receiving device, the receiving device verifies the returned decrypted data T 3. Whether to challenge data T 1 consistent, T 3 and T 1, the public key encryption verification passes, otherwise it fails; Token verification includes the following steps: the sending device sends an access token to the receiving device, and the receiving device verifies the validity and legality of the token.

8. An electronic signature and identity authentication enhancement system applied to the industrial Internet, used to implement the electronic signature and identity authentication enhancement method applied to the industrial Internet as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Client authentication methods and devices in the Industrial Internet

    CN114448729B

  • Secure certification and transaction method with combination of digital certificate and one-time password

    CN102075522A

  • Identity authentication method and identity authentication device

    CN106161032A

  • RSA multiple blind signature method and system based on identity verification

    CN118337392A

  • Integrated data security transmission system

    CN118764252A