Access authorization method of industrial internet data authorization sharing system based on key negotiation
By adopting a data authorization sharing system based on key negotiation in the industrial Internet, the problem of slow data access login speed and inability to trace malicious data visitors is solved, and fast login and data security is improved.
Patent Information
- Application Number
- CN202510410345.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-02
AI Technical Summary
The existing technology has problems in the industrial Internet that data access login speed is slow and malicious data visitors cannot be traced, which affects data access efficiency and security.
A method of access authorization for industrial Internet data authorization sharing system based on key negotiation is proposed. Through enterprise managers and functional departments and servers, fast login is achieved, and malicious data visitors are traced through specific tags and tokens.
It realizes rapid login of functional departments, improves data access efficiency, and enhances data security through traceability mechanisms to prevent malicious data access.
Smart Images

Figure CN119996066A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method suitable for industrial Internet data access security authorization, and specifically to an industrial Internet data authorization sharing system access authorization method based on key negotiation, which belongs to the field of information security technology and industrial Internet security. Background Art
[0002] As a representative of the new generation of information technology, the Industrial Internet integrates elements such as artificial intelligence, big data, and edge computing to form a new industrial ecosystem and application model. It is also the core infrastructure for the digitalization, networking, and intelligent transformation of the industry. For industrial Internet companies, industrial data is a valuable asset of the enterprise, covering key content such as core technologies, business secrets, and customer information. Once these data are leaked, tampered with, or destroyed, the development and interests of the enterprise will face direct threats. Therefore, ensuring the security of industrial data is closely linked to the security of the Industrial Internet. Cryptography technology is a key tool for data management and information protection. Its proper application in the Industrial Internet can ensure the secure transmission and use of data, and constitute the cornerstone of the entire Industrial Internet trust system.
[0003] In this context, authenticated key negotiation technology plays a vital role as the core technology for achieving secure data access. It allows data owners to open data access rights only to authorized users and establish a secure communication link, thereby achieving strict control over data access. Key negotiation technology ensures the confidentiality, integrity and availability of data transmission, improves the robustness and security of the system, and ensures the efficient, safe and stable operation of the system. Since the actual situation faced by industrial Internet companies is more complicated, such as many departments, huge amounts of data, and data outsourcing, it is particularly important to develop a key negotiation technology that is both lightweight and fully functional.
[0004] Although there have been many studies on the key negotiation technology for the industrial Internet, there are still problems such as slow data access login speed and inability to trace malicious data accessors. Specifically, each functional department of an enterprise in the industrial Internet will upload a large amount of data related to production and life to the server side in order to use the server's more powerful storage and computing capabilities to process these industrial data. For all the data stored on the server, the company's senior management department will authorize data access to each functional department as needed. The authorized department can negotiate the authentication key with the server and use the negotiated key to access the data. However, if a key negotiation is required every time data is accessed, it will greatly affect the access efficiency and increase the overhead. Therefore, it is very important to design a mechanism for authorizing functional departments to quickly log in to access data. In addition, data security issues are also crucial. Functional departments may intentionally or unintentionally perform malicious data access, such as incorrectly processing data or leaking data to external personnel without authorization, which will pose a serious threat to data security. Therefore, how to integrate the manager's authorization information in the key negotiation process between the functional department and the server and add a tracking mechanism for malicious behavior is an important issue that needs to be studied in depth. Summary of the invention
[0005] The present invention aims to overcome the shortcomings of the prior art and solve the problems of lightweight authentication, authorized access, secure transmission, and identification of data abusers in the field of industrial Internet. To this end, a method for access authorization of industrial Internet data authorization sharing system based on key negotiation is proposed, which solves the inefficiency problem of repeated negotiation authorization and realizes the rapid login of functional departments; at the same time, specific tags are redesigned for functional departments, breaking through the limitation that the prior art cannot trace malicious data accessors.
[0006] An industrial Internet data authorization sharing system access authorization method based on key negotiation includes the following steps:
[0007] Step 1: Initialize the Industrial Internet Data Authorization Sharing System
[0008] Before the Industrial Internet Data Authorization Sharing System is activated, each functional department has its own unique identity information, as well as the password and password index to be used in this data access authorization, that is, department D i With {ID i ,(ind i ,pw i}}; The enterprise management bureau has its own secret initial key value k OPRF And know that each department D i Identifier ID i The server has the password index and password, but does not know the identity identifiers (ind, pwind ), the relationship between password and identity information is unclear;
[0009] n is the security parameter of the industrial Internet data authorization sharing system, τ(n) is a function value related to n, and H, H1, H2, and H3 are four hash functions;
[0010] Step 2: Enterprise managers authorize functional departments
[0011] The manager and the functional department have a secret exchange, prompting the functional department to generate a token and a tag containing the manager's information; after the server completes the exchange with the manager, it verifies whether the functional department has communicated effectively with the manager, and then conducts a password-based authentication key negotiation process with the functional department.
[0012] Step 3: Authorize departments to quickly access server-side data
[0013] Functional departments that have completed key negotiation and authentication with the server can send information to quickly log in and access data when accessing the industrial Internet enterprise data on the server again;
[0014] Step 4: Malicious data access tracing
[0015] When a functional department in the enterprise is found to have maliciously used or improperly operated the data on the server, the manager will generate auxiliary information related to the identity information of this department and send it to the server to assist the server in tracing the identity of the malicious department and restricting its data access rights.
[0016] Furthermore, the specific steps for the enterprise manager to authorize the functional department are:
[0017] Step 1: The enterprise manager uses his own unique secret initial key value k OPRF With password pw i Department D i Execute the oblivious pseudo-random function protocol so that the functional department D i Get a hash value associated with the manager information
[0018] Step 2: Department D i Replace e with your ID i Concatenate to form a new element l=l1l2…l with a length of τ(n) τ(n) ; According to element l, department D i Generate token td i With the tag tag i ;
[0019] Step 3: Server S receives a message from department D iThe short-term session public key pk e , tag i , and the password index ind, find the corresponding password pw ind , and use pw i Execute the OPFR protocol with manager M to get the hash value Then, the server S sets the message m=ID s ||pw i ||r i , calculate and analyze H1(m) = σ||K; using pk e Encrypt the message m and the hash value e to obtain the ciphertext c←CEnc(pk e ,(m,e)); calculate the hash value a←H2(pw i ||tag i ||pk e ||c||m); Finally, the server sends (a,c) to department D i ;
[0020] Step 4: Department D i First, use the instantaneous key sk e Decrypt the ciphertext c' from the server to obtain (m',e')←Dec(sk e ,c'); if e'≠e, the protocol terminates; if they are equal, resolve m'=ID' s ||pw' i ||r' i ; If a≠H2(pw i ||tag i ||pk e ||c'||m'), the protocol is terminated; then, D i Calculate and parse H1(m') = σ'||K', and send σ' to server S; finally, D i Calculate the key sKey negotiated with the server i =H3(K'||e||pw i ||c||tag i )||tag i .
[0021] Step 5: Server S compares the received σ' with the σ obtained in 2.3. If σ'≠σ, the protocol is terminated; if σ'=σ, the result is the same as (ind, pw ind ) corresponding key sKey ind , which is sKey i =H1(k||e||pw i ||c||tag i )||tag i.
[0022] Furthermore, the specific execution process of step 2 in which the enterprise manager authorizes the functional department is as follows: first, generate τ(n) pairs Composition token td i ,Right now
[0023]
[0024] Generate a tag based on element l i :If l j =0, then pk j according to Generate; if l j =1, then pk j according to Generate, i.e. pk j From Get tag tag i =(pk1,…,pk τ(n) ), td i With tag i With respect to l, a specific equality relationship is satisfied, denoted as (td i ,tag i )∈R(l) EQ ; Finally, Department D i Run a key generation algorithm of a conventional encryption scheme to generate a short-term session key pair CKeyGen(1 n )→(sk e ,pk e ).
[0025] Furthermore, the specific steps for the authorization department to quickly access the server-side data are as follows:
[0026] Step 1: Department D i Choose a random number α and calculate your own password pw i The hash value p = H(pw i ), using the key sKey agreed with the server in the previous step i For message tuples Encrypted Department D i Finally, send your password index and ciphertext (ind, C) to the server;
[0027] Step 2: After receiving (ind, C), server S finds the corresponding negotiated key sKey according to ind ind And decrypt the ciphertext to get (i',p',α')=Dec(sKey i ,C); if i'=i and H(pw i)=p', the server recognizes department D i Login successful; otherwise D i Login failed.
[0028] Furthermore, the specific execution process of the malicious data access department tracing is:
[0029] Step 1: The administrator uses the malicious department’s ID i Find the corresponding token td i And use all To generate an auxiliary information And send it to the server;
[0030] Step 2: Server S receives After that, find sKey i , parse sKey i =H1(k||e||pw i ||c||tag i )||tag i , restore the tag i =(pk1,…,pk τ(n) ); Then, the server initializes an element b of length τ(n) to set tag i and Compare each component of , if for each 1≤j≤τ(n), Then set the jth element b of element b j = 0, otherwise b j =1, and then we get b=b1b2…b τ(n) =e||ID i ; Finally, server S recovers the identity information of the malicious department, and then can take related measures such as restricting its data access rights.
[0031] The beneficial effects of the present invention are: (1) the entire system is initialized by using system parameters, identity information, passwords, password indexes held by each department, department identities held by managers, and passwords and password indexes held by servers; (2) enterprise managers interact with each department and server respectively, and each department sends a personal token to the manager and negotiates a password-based key with the server to obtain data access authorization; (3) functional departments that want to access all enterprise data send messages to the server, and the server can quickly verify and implement functional login; (4) when a functional department maliciously uses or improperly operates enterprise data, the manager will generate auxiliary information related to the identity information of this department and send it to the server, so that the identity information of the malicious department can be restored and its data access rights can be restricted. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1This is a schematic diagram of a framework of an access authorization method for an industrial Internet data authorization sharing system based on key negotiation; DETAILED DESCRIPTION
[0033] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technical personnel in this field without creative work are within the scope of protection of the present invention.
[0034] In the technical solution described in the present invention, the upper-level managers of the enterprise use an inadvertent pseudo-random function to authenticate with the functional department and the server respectively; the functional department embeds its own identity information into personal tokens and tags that satisfy a specific relationship, and uses the tags and passwords to negotiate keys with the server; the functional department uses the negotiated keys and passwords carrying identity information to achieve rapid login on the server side; once the enterprise manager finds that a functional department has maliciously accessed the server data, the manager will generate auxiliary information related to the token of the maliciously accessed functional department, and send it to the server to help the server restore the identity of the functional department to limit its access rights.
[0035] An industrial Internet data authorization sharing system access authorization method based on key negotiation includes the following steps:
[0036] Step 1: Initialize the Industrial Internet Data Authorization Sharing System
[0037] Before the Industrial Internet Data Authorization Sharing System is activated, each functional department has its own unique identity information, as well as the password and password index to be used in this data access authorization, that is, department D i With {ID i ,(ind i ,pw i )}; The enterprise management bureau has its own secret initial key value k OPRF And know that each department D i Identifier ID i The server has the password index and password, but does not know the identity identifiers (ind, pw ind ), the relationship between password and identity information is unclear;
[0038] n is the security parameter of the industrial Internet data authorization sharing system, τ(n) is a function value related to n, and H, H1, H2, and H3 are four hash functions;
[0039] Step 2: Enterprise managers authorize functional departments
[0040] The manager and the functional department have a secret exchange, prompting the functional department to generate a token and a tag containing the manager's information; after the server completes the exchange with the manager, it verifies whether the functional department has communicated effectively with the manager, and then conducts a password-based authentication key negotiation process with the functional department.
[0041] Step 3: Authorize departments to quickly access server-side data
[0042] Functional departments that have completed key negotiation and authentication with the server can send information to quickly log in and access data when accessing the industrial Internet enterprise data on the server again;
[0043] Step 4: Malicious data access tracing
[0044] When a functional department in the enterprise is found to have maliciously used or improperly operated the data on the server, the manager will generate auxiliary information related to the identity information of this department and send it to the server to assist the server in tracing the identity of the malicious department and restricting its data access rights.
[0045] Furthermore, the specific steps for the enterprise manager to authorize the functional department are:
[0046] Step 1: The enterprise manager uses his own unique secret initial key value k OPRF With password pw i Department D i Execute the oblivious pseudo-random function protocol so that the functional department D i Get a hash value associated with the manager information
[0047] Step 2: Department D i Replace e with your ID i Concatenate to form a new element l=l1l2…l with a length of τ(n) τ(n) ; According to element l, department D i Generate token td i With the tag tag i ;
[0048] Step 3: Server S receives a message from department D i The short-term session public key pk e , tag i , and the password index ind, find the corresponding password pw ind (Essentially Department D i The password is pw i ), and use pw i Execute the OPFR protocol with manager M to get the hash value Then, the server S sets the message m=ID s ||pw i ||r i , calculate and analyze H1(m) = σ||K; using pk e Encrypt the message m and the hash value e to obtain the ciphertext c←CEnc(pk e ,(m,e)); calculate the hash value a←H2(pw i ||tag i ||pk e ||c||m); Finally, the server sends (a,c) to department D i ;
[0049] Step 4: Department D i First, use the instantaneous key sk e Decrypt the ciphertext c' from the server to obtain (m',e')←Dec(sk e ,c'); if e'≠e, the protocol terminates; if they are equal, resolve m'=ID' s ||pw' i ||r' i ; If a≠H2(pw i ||tag i ||pk e ||c'||m'), the protocol is terminated; then, D i Calculate and parse H1(m') = σ'||K', and send σ' to server S; finally, D i Calculate the key sKey negotiated with the server i =H3(K'||e||pw i ||c||tag i )||tag i .
[0050] Step 5: Server S compares the received σ' with the σ obtained in 2.3. If σ'≠σ, the protocol is terminated; if σ'=σ, the result is the same as (ind, pw ind ) corresponding key sKey ind , which is sKey i =H1(k||e||pw i ||c||tag i )||tag i .
[0051] Furthermore, the specific execution process of step 2 in which the enterprise manager authorizes the functional department is as follows: first, generate τ(n) pairs Composition token td i ,Right now
[0052]
[0053] Generate tag tag based on element l i :If l j =0, then pk j according to Generate; if l j =1, then pk j according to Generate, i.e. pk j From Get tag tag i =(pk1,…,pk τ(n) ), td i With tag i With respect to l, a specific equality relationship is satisfied, denoted as (td i ,tag i )∈R(l) EQ ; Finally, Department D i Run a key generation algorithm of a conventional encryption scheme to generate a short-term session key pair CKeyGen(1 n )→(sk e ,pk e ).
[0054] Furthermore, the specific steps for the authorization department to quickly access the server-side data are as follows:
[0055] Step 1: Department D i Choose a random number α and calculate your own password pw i The hash value p = H(pw i ), using the key sKey agreed with the server in the previous step i For message tuples Encrypted Department D i Finally, send your password index and ciphertext (ind, C) to the server;
[0056] Step 2: After receiving (ind, C), server S finds the corresponding negotiated key sKey according to ind ind (essentially sKey i ) and decrypt the ciphertext to obtain (i',p',α')=Dec(sKey i ,C); if i'=i and H(pw i )=p', the server recognizes department D i Login successful; otherwise D i Login failed.
[0057] Furthermore, the specific execution process of the malicious data access department tracing is:
[0058] Step 1: The administrator uses the malicious department’s ID i Find the corresponding token td i And use all To generate an auxiliary information And send it to the server; roughly speaking, it uses td i The first private key component in the whole generates the corresponding "public key value" to help the server trace the identity of the source department;
[0059] Step 2: Server S receives After that, find sKey i , parse sKey i =H1(k||e||pw i ||c||tag i )||tag i , restore the tag i =(pk1,…,pk τ(n) ); Then, the server initializes an element b of length τ(n) to set tag i and Compare each component of , if for each 1≤j≤τ(n), Then set the jth element b of element b j = 0, otherwise b j =1, and then we get b=b1b2…b τ(n) =e||ID i ; Finally, server S recovers the identity information of the malicious department, and then can take related measures such as restricting its data access rights.
[0060] The innovation of the present invention is that the upper management department of the industrial Internet enterprise uses an inadvertent pseudo-random function to authorize each department and server. Secondly, inspired by the key structure of the lossy public key encryption scheme, tokens and labels with identity characteristics are generated for each department of the enterprise, where the tokens are shared with managers. Under normal circumstances, the identity information of each department will not be exposed; however, once malicious behavior is discovered, combined with the auxiliary information provided by the upper management, the identity of the malicious department can be traced through tokens and labels, and its data access rights on the server side can be revoked.
[0061] The above shows and describes the basic principles, main features and advantages of the present invention. Technical personnel in this industry should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.
Claims
1. An industrial Internet data authorization sharing system access authorization method based on key negotiation, characterized by: The access authorization method comprises the following steps: Step 1: Initialize the Industrial Internet Data Authorization Sharing System Before the Industrial Internet Data Authorization Sharing System is activated, each functional department has its own unique identity information, as well as the password and password index to be used in this data access authorization, that is, department D i With {ID i ,(ind i ,pw i )}; The enterprise management bureau has its own secret initial key value k OPRF And know that each department D i Identifier ID i The server has the password index and password, but does not know the identity identifiers (ind, pw ind ), the relationship between password and identity information is unclear; n is the security parameter of the industrial Internet data authorization sharing system, τ(n) is a function value related to n, and H, H1, H2, and H3 are four hash functions; Step 2: Enterprise managers authorize functional departments Managers interact closely with functional departments, prompting them to generate tokens and tags containing manager information; After the server completes the exchange with the manager, it checks whether the functional department has communicated effectively with the manager, and then conducts a password-based authentication key negotiation process with the functional department; Step 3: Authorize departments to quickly access server-side data Functional departments that have completed key negotiation and authentication with the server can send information to quickly log in and access data when accessing the industrial Internet enterprise data on the server again; Step 4: Malicious data access tracing When a functional department in the enterprise is found to have maliciously used or improperly operated the data on the server, the manager will generate auxiliary information related to the identity information of this department and send it to the server to assist the server in tracing the identity of the malicious department and restricting its data access rights.
2. The method for access authorization of an industrial Internet data authorization sharing system based on key negotiation according to claim 1, characterized in that: The specific steps for the enterprise manager to authorize the functional department are: Step 1: The enterprise manager uses his own unique secret initial key value k OPRF With password pw i Department D i Execute the oblivious pseudo-random function protocol so that the functional department D i Get a hash value associated with the manager information Step 2: Department D i Replace e with your ID i Concatenate to form a new element l=l1l2…l with a length of τ(n) τ(n) ; According to element l, department D i Generate token td i With the tag tag i ; Step 3: Server S receives a message from department D i The short-term session public key pk e , tag i , and the password index ind, find the corresponding password pw ind , and use pw i Execute the OPFR protocol with manager M to get the hash value Then, the server S sets the message m=ID s ||pw i ||r i , calculate and analyze H1(m) = σ||K; using pk e Encrypt the message m and the hash value e to obtain the ciphertext c←CEnc(pk e ,(m,e)); calculate the hash value a←H2(pw i ||tag i ||pk e ||c||m); Finally, the server sends (a,c) to department D i ; Step 4: Department D i First, use the instantaneous key sk e Decrypt the ciphertext c' from the server to obtain (m',e')←Dec(sk e ,c'); if e'≠e, the protocol terminates; if they are equal, resolve m'=ID' s ||pw' i ||r' i ; If a≠H2(pw i ||tag i ||pk e ||c'||m'), the protocol is terminated; then, D i Calculate and parse H1(m') = σ'||K', and send σ' to server S; finally, D i Calculate the key sKey negotiated with the server i =H3(K'||e||pw i ||c||tag i )||tag i ; Step 5: Server S compares the received σ' with the σ obtained in 2.
3. If σ'≠σ, the protocol is terminated; if σ'=σ, the result is the same as (ind, pw ind ) corresponding key sKey ind , which is sKey i =H1(k||e||pw i ||c||tag i )||tag i .
3. The method for access authorization of an industrial Internet data authorization sharing system based on key negotiation according to claim 2, characterized in that: The specific execution process of step 2 in which the enterprise manager authorizes the functional department is as follows: first, generate τ(n) pairs Composition token td i ,Right now Generate tag tag based on element l i :If l j =0, then pk j according to Generate; if l j =1, then pk j according to Generate, i.e. pk j From Get tag tag i =(pk1,…,pk τ(n) ), td i With tag i With respect to l, a specific equality relationship is satisfied, denoted as (td i ,tag i )∈R(l) EQ ; Finally, Department D i Run a key generation algorithm of a conventional encryption scheme to generate a short-term session key pair CKeyGen(1 n )→(sk e ,pk e ).
4. The method for access authorization of an industrial Internet data authorization sharing system based on key negotiation according to claim 1, characterized in that: The specific steps for the authorization department to quickly access the server-side data are as follows: Step 1: Department D i Choose a random number α and calculate your own password pw i The hash value p = H(pw i ), using the key sKey agreed with the server in the previous step i For message tuples Encrypted Department D i Finally, send your password index and ciphertext (ind, C) to the server; Step 2: After receiving (ind, C), server S finds the corresponding negotiated key sKey according to ind ind And decrypt the ciphertext to get (i',p',α')=Dec(sKey i ,C); If i'=i and H(pw i )=p', the server recognizes department D i Login successful; otherwise D i Login failed.
5. The method for access authorization of an industrial Internet data authorization sharing system based on key negotiation according to claim 1, characterized in that: The specific execution process of the malicious data access department tracing is as follows: Step 1: The administrator uses the malicious department’s ID i Find the corresponding token td i And use all To generate an auxiliary information And send it to the server; Step 2: Server S receives After that, find sKey i , parse sKey i =H1(k||e||pw i ||c||tag i )||tag i , restore the tag i =(pk1,…,pk τ(n) ); Then, the server initializes an element b of length τ(n) to set tag i and Compare each component of , if for each 1≤j≤τ(n), Then set the jth element b of element b j = 0, otherwise b j =1, and then we get b=b1b2…b τ(n) =e||ID i ; Finally, server S recovers the identity information of the malicious department, and then can take related measures such as restricting its data access rights.
Citation Information
Patent Citations
Lightweight NFC identity authentication method in Internet of Things scene, and Internet of Things communication platform
CN110147666A
Block chain assisted Internet of Vehicles security authentication method
CN114362993A
Multi-factor identity authentication method based on edge computing and SDN (Software Defined Network) under internet of things
CN114726604A
Threshold password authentication single sign-on method capable of resisting voucher leakage on lattice
CN116582292A
Distributed digital identity credibility authentication method based on hierarchical storage
CN116938521A