WAPI bidirectional access authentication system and method in electric power Internet of Things scene

By adopting the WAPI two-way access authentication system in the power Internet of Things scenario, and using distributed terminal access bidirectional authentication and multi-hop aggregation authentication technology, the problems of wireless network security and reliability in the power Internet of Things scenario are solved, the legitimacy of terminal equipment and the security of network connections are realized, and network experience and service quality are improved.

CN120018132APending Publication Date: 2025-05-16STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510153516.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art is difficult to effectively ensure the security and reliability of wireless networks in the power Internet of Things scenario, especially in complex and changeable network environments.

Method used

The WAPI bidirectional access authentication system is adopted, and the distributed terminal access bidirectional authentication method is used with the access terminal as the core, and the multi-hop aggregation authentication and BLS signature algorithm are used to realize the legitimacy of terminal devices and the security of network connections.

Benefits of technology

Effectively protect the security and reliability of the network, ensure the legality of terminal equipment and the security of network connections, and provide more flexible and efficient terminal access methods to improve users' network experience and service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FDA0005268831990000021
    Figure FDA0005268831990000021
  • Figure FDA0005268831990000034
    Figure FDA0005268831990000034
  • Figure FDA0005268831990000044
    Figure FDA0005268831990000044
Patent Text Reader

Abstract

The invention belongs to the technical field of Internet of Things, and particularly relates to a WAPI bidirectional access authentication system and method in an electric power Internet of Things scene, and the method comprises the following steps: S1, a to-be-networked electric power service terminal sends an access request, and the access request of the to-be-networked electric power service terminal is agreed only after verification succeeds; otherwise, refusing to access; s2, the access terminal carries out distributed terminal access bidirectional security authentication on the power service terminal and the newly added terminal node which are accessed to the WAPI; authorization is carried out on the legal service terminal, trusted access of the service terminal is realized, and trusted access verification is carried out on the newly added terminal node; equipment management and identity authentication functions are issued to the edge side access terminal from the remote centralized authentication center, and distributed terminal access bidirectional authentication is completed. Through the terminal authentication system and method taking the access terminal as the core, the security and reliability of the network can be effectively protected, and the legality of the terminal equipment and the security of network connection are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of Internet of Things, and specifically relates to a WAPI two-way access authentication system and method in a power Internet of Things scenario. Background Art

[0002] With the popularization of wireless networks and the rapid development of Internet of Things technology, the security and transmission efficiency of wireless local area networks (WLANs) have become urgent issues to be addressed. Traditional WiFi standards (such as WiFi5) have gradually failed to meet the needs of modern applications in terms of data transmission rate, network latency, device access density, and security. As a new generation of wireless technology, WiFi6 has significantly improved data transmission rate and network efficiency by introducing more advanced modulation technology and channel management strategies. However, relying solely on the technical improvements of WiFi6 is not enough to ensure the comprehensive security of wireless networks, especially in the face of complex and changing network environments.

[0003] WAPI is a WLAN security solution proposed by China's national wireless LAN standard GB15629.11. The standard includes a brand-new WAPI (WLAN authentication and privacy infrastructure) security mechanism. The WAPI security mechanism consists of two parts: WLAN authentication infrastructure (WAI) and WLAN privacy infrastructure (WPI). WAI and WPI respectively. Realize the authentication of user identities and the encryption of transmitted data. WAPI can provide comprehensive security protection for users' WLAN systems. In terms of security processing, WAPI has the same starting point as WEP, but the security of WAPI's identity authentication and data encryption far exceeds that of WEP.

[0004] As my country's first secure access technology standard with independent innovative intellectual property rights in the field of computer broadband wireless network communications, WAPI (Wireless LAN Authentication and Privacy Infrastructure) provides highly reliable security for wireless networks through its unique ternary peer-to-peer architecture and two-way authentication mechanism. Therefore, combining the technical advantages of WAPI and WiFi6, studying the WiFi6 trusted access enhancement technology based on WAPI has important practical significance and application value. Summary of the invention

[0005] The purpose of the present invention is to provide a WAPI two-way access authentication system and method in the electric power Internet of Things scenario to address the problems existing in the prior art. Through this terminal authentication system and method with the access terminal as the core, the security and reliability of the network can be effectively protected, the legitimacy of the terminal equipment and the security of the network connection can be ensured, and a more flexible and efficient terminal access method can be provided, providing users with a better network experience and service quality.

[0006] The technical solution of the present invention is:

[0007] A WAPI two-way access authentication method in a power Internet of Things scenario includes the following steps:

[0008] S1. The power service terminal to be connected to the network sends an access request. The WAPI authentication center that receives the authentication request generates a random number based on the request through its WAPI node, and sends a multi-hop aggregation authentication request to the remaining neighboring WAPI nodes for aggregation verification. The node that receives the aggregation authentication request will return the aggregation information obtained by the BLS algorithm signature hop by hop, and verify at the nodes along the way whether the node's own random number is aggregated in the signature information. If all verifications are successful, the access request of the power service terminal to be connected to the network will be approved; otherwise, the access will be rejected.

[0009] S2. The access terminal performs bidirectional security authentication for distributed terminal access to the power business terminals and newly added terminal nodes connected to WAPI; authorizes legitimate business terminals to achieve trusted access for business terminals, and performs trusted access verification for newly added terminal nodes; the equipment management and identity authentication functions are decentralized from the remote centralized authentication center to the edge-side access terminal to complete bidirectional authentication for distributed terminal access.

[0010] Specifically, the aggregation verification is as follows:

[0011] For multiple BLS signatures S1, S2, S3..., the aggregated signature is:

[0012] S ALL =a1*S1+a2*S2+a3*S3+…

[0013] The corresponding aggregated key is:

[0014] PALL=a1*PK A +a2*PK B +a3*PK C +……

[0015] For the coefficient a i have:

[0016] a i = hash(P i ,{P1,P2,P3...})

[0017] Among them, S is the symmetric key shared between the access network node and the authorized terminal. As the necessary prior information for terminal access, it is the first line of defense for authentication access. PK is the public key, SK is the private key, BLS_Sign is based on the BLS signature algorithm. The BLS signature information will be transmitted and verified between the nodes in the authentication stage. x (Y) means using SKx to sign information Y, BLS_Sign ALL Represents a signature aggregation operation.

[0018] Specifically, the distributed terminal access two-way authentication specifically includes the following steps:

[0019] 1) A→B: Terminal A (legal service terminal or newly added terminal) sends an authentication request to WAPI node B, carrying A's identity. Access node B queries the public key corresponding to id (A) through the remote database;

[0020] 2) B→A:

[0021] WAPI node B encrypts its own ID (B) with the network shared key S and sends it to terminal A;

[0022] 3) A→B:

[0023] After receiving EDS{id(B)}, terminal A first uses the network shared key S to decrypt ID(B); then uses ID(B) to query B's public key in the remote database, and then uses B's public key PKB to encrypt its own ID(A) and random number X1, and pass them to node B;

[0024] 4) B→C→D→…: Multi-hop aggregation authentication

[0025] When access node B receives the ID encrypted information sent by the power business terminal After that, it decrypts and obtains ID(A), and sends a multi-hop aggregation authentication request to neighbor node C, with ID(A) encrypted by C's public key. After receiving the information, neighbor node C generates X3, encrypts ID(A) with D's public key, and sends it to node D. Node D decrypts it with its private key and generates a random number X4 locally.

[0026] 5)…→D→C: ED s {id(D),X4},BLs_sign D (id(A),X1)}

[0027] When neighbor node D receives the message, it will use the BLS algorithm to generate BLs_sign signed by D's private key. D(id(A), X1), neighbor node C receives the returned information, first uses the shared key to decrypt to check whether the neighbor node C's identity is correct, then uses D's public key to decrypt the signature, and then uses the BLS algorithm to generate id(A) signed by C's private key, together with C's identity and X4, X3 encrypted with the shared key, and returns it to node B;

[0028] 6) C → B: ED s {id(C),X3,X4,BLs_sign C (id(A),X1)}

[0029] B receives the information sent by C, uses the shared key to decrypt the identifier and the random numbers of other nodes, and uses C's public key to decrypt the signature. At this point, each access network node has completed mutual verification, proving that the access network nodes are all normal;

[0030] 7) B → A:

[0031] Node B receives BLs_sign C After (id(A), X1), first use the public key of node C to decrypt and get ID(A). At this point, terminal A and node B have exchanged their respective identity information; then use PK A Encrypt X2, sign ID(A) and random number X1 with B's private key, and send to access network terminal A;

[0032] 8) A→B:

[0033] Terminal A receives After that, first use SK A Decryption is performed to obtain X1. At the same time, terminal A calculates the value of (X1) locally and compares it with the decrypted value of (X1). If the two are the same, it indicates that terminal A has successfully verified the identity of node B. If the results are different, the identity authentication fails and the authentication process ends. Next, terminal A uses the BLS multi-signature technology to aggregate all private key encryption information, and then encrypts it with B's public key and sends it to B.

[0034] 9) B→C:

[0035] Node B receives After that, use SK B Decrypt and get BLs_sign ALL (id(A), X1 and X2); after terminal B confirms that this access authentication is successful; then continue to encrypt BLs_sign with C's public key ALL (id(A),X1),X3,X4) is sent to C. If it is not satisfied, the access of terminal A fails, the authentication process ends, and the result is notified to other participating nodes.

[0036] 10) C→D:

[0037] Node C receives After that, use SK C Solve

[0038] Password, get BLS_Sign ALL (id(A)),X1,X3,X4,At the same time, node C verifies whether the locally stored random number is the same as the parsed result. If the two are the same, it means that node C successfully verifies the identity of terminal A; if the results are different, it means that the identity authentication failed and the authentication process ends. If successful, continue to encrypt BLS_Sign with D public key ALL (id(A),X1), X4 is sent to D, who decrypts it with the private key and restores BLS_Sign in the same way as the aggregate signature ALL Information to verify the legitimacy of each signatory.

[0039] Specifically, the terminal B authentication process in step 9) is divided into two parts:

[0040] 1. Node B verifies whether the random number X2 generated by itself is consistent with the decrypted value;

[0041] 2. According to the public key and signature key generation rules of each participating node in this authentication, PALL is calculated locally and the signature content is decrypted to verify whether legal information can be obtained.

[0042] Specifically, the WAPI authentication center adopts a WAPI access authentication method based on SM4.

[0043] A WAPI two-way access authentication system in a power Internet of Things scenario, including an access terminal, a WAPI authentication center, an IPK identification / key management center and a database;

[0044] The access terminal performs distributed bidirectional security authentication on the power business terminals and newly added terminal nodes accessing WAPI, authorizes the legitimate business terminals, realizes trusted access of the business terminals, and performs trusted access verification on the newly added terminal nodes;

[0045] The WAPI authentication center receives the authentication request, generates a random number based on the request, and sends a multi-hop aggregation authentication request to the remaining neighboring WAPI nodes for aggregation verification.

[0046] The IPK identification / key management center is responsible for generating and managing the globally unique identification and public-private key pairs of each terminal node and legal business terminal;

[0047] The database stores the globally unique identification of each terminal node and legal business terminal and the public-private key pair of the identification, and each terminal node can query the public-private key according to the identification.

[0048] The method provided by the present invention aims at the emergence of intelligent new power local communication services such as robot inspection, smart safety supervision, and mobile office in the power local wireless LAN environment such as power grid substations, forming a power local multi-service wireless trusted intelligent access enhancement technology system for these typical scenarios and services. Combined with the current status of domestic power grid construction and the level of development of related technologies, the application and transformation prospects of the results are broad. The present invention starts with the research on WIFI6 power local wireless access and WAPI authentication based on WAPI, supporting the key basic theoretical and technical achievements of the new power local wireless communication network.

[0049] The present invention adopts asymmetric security credential management to realize identity management and WAPI access authentication in the power Internet of Things scenario, shorten the authentication chain, realize fast and secure access, and reduce authentication overhead; at the same time, it relieves the pressure of the core network, avoids signaling storms and authentication, and the asymmetric key system has a natural decentralized feature. There is no need to save the keys of all terminal devices on the network side, and there is no need to deploy a permanently online centralized identity management node. By utilizing the advantages of wireless LAN based on WAPI technology in terms of large bandwidth capacity, low construction cost, and security and controllability, it realizes the enhancement of wireless trusted intelligent access of local power multi-services, and improves the intelligence and security and trustworthiness of local power service access. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 It is a schematic diagram of the WAPI distributed two-way authentication process structure of the present invention;

[0051] Figure 2 It is the WAPI access terminal security authentication process;

[0052] Figure 3 This is a schematic diagram of the WAPI wireless network access process based on SM4. DETAILED DESCRIPTION

[0053] The technical solution of the present invention is described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0054] Example 1

[0055] This embodiment provides a WAPI two-way access authentication method in a power Internet of Things scenario, including the following steps:

[0056] S1. The power service terminal to be connected to the network sends an access request. The WAPI authentication center that receives the authentication request generates a random number based on the request through its WAPI node, and sends a multi-hop aggregation authentication request to the remaining neighboring WAPI nodes for aggregation verification. The node that receives the aggregation authentication request returns the aggregation information obtained by the BLS algorithm signature hop by hop, and verifies at the nodes along the way whether the node's own random number is aggregated in the signature information. If all verifications are successful, the access request of the power service terminal to be connected to the network will be approved; otherwise, the access is denied. The WAPI authentication center adopts the WAPI access authentication method based on SM4.

[0057] S2. The access terminal performs bidirectional security authentication for distributed terminal access to the power business terminals and newly added terminal nodes connected to WAPI; authorizes legitimate business terminals to achieve trusted access for business terminals, and performs trusted access verification for newly added terminal nodes; the equipment management and identity authentication functions are decentralized from the remote centralized authentication center to the edge-side access terminal to complete bidirectional authentication for distributed terminal access.

[0058] The meanings of the symbols in the two-way security authentication process are shown in Table 1:

[0059] Table 5-1 Access terminal security certification compliance description

[0060] symbol illustrate ED Cryptographic Operations <![CDATA[X1,X2]]> Random Numbers PK,SK Public key, private key || Connectors Id Node ID S Network Shared Key BLS_Sign BLS Signature

[0061] The aggregation verification is specifically as follows:

[0062] For multiple BLS signatures S1, S2, S3..., the aggregated signature is:

[0063] S ALL =a1*S1+a2*S2+a3*S3+…

[0064] The corresponding aggregated key is:

[0065] PALL=a1*PKA+a2*PKB+a3*PKC+……

[0066] For the coefficient a i have:

[0067] a i = hash(P i ,{P1,P2,P3...})

[0068] Among them, S is the symmetric key shared between the access network node and the authorized terminal. As the necessary prior information for terminal access, it is the first line of defense for authentication access. The network shared key S is generated and maintained by the local mesh network, shared between legitimate network nodes, and disclosed to the authorized access terminal in a private form. PK is the public key and SK is the private key. BLS_Sign is based on the BLS signature algorithm. The BLS signature information will be transmitted and verified between the nodes in the authentication stage. BLS_Sign x (Y) means using SKx to sign information Y, BLS_Sign ALL Represents a signature aggregation operation.

[0069] Example 2

[0070] This embodiment provides a specific process of distributed terminal access bidirectional authentication as follows: Figure 2 As shown, the steps are as follows:

[0071] 1) A→B: Terminal A (legal service terminal or newly added terminal) sends an authentication request to WAPI node B, carrying A's identity. Access node B queries the public key corresponding to id (A) through the remote database;

[0072] 2) B→A:

[0073] WAPI node B encrypts its own ID (B) with the network shared key S and sends it to terminal A;

[0074] 3) A→B:

[0075] After receiving EDS{id(B)}, terminal A first uses the network shared key S to decrypt ID(B); then uses ID(B) to query B's public key in the remote database, and then uses B's public key PKB to encrypt its own ID(A) and random number X1, and pass them to node B;

[0076] 4) B→C→D→…: Multi-hop aggregation authentication

[0077] When access node B receives the ID encrypted information sent by the power business terminal After that, it decrypts and obtains ID(A), and sends a multi-hop aggregation authentication request to neighbor node C, with ID(A) encrypted by C's public key. After receiving the information, neighbor node C generates X3, encrypts ID(A) with D's public key, and sends it to node D. Node D decrypts it with its private key and generates a random number X4 locally.

[0078] 5)…→D→C: ED s {id(D),X4},BLs_sign D(id(A),X1)}

[0079] When neighbor node D receives the message, it will use the BLS algorithm to generate BLs_sign signed by D's private key. D (id(A), X1), neighbor node C receives the returned information, first uses the shared key to decrypt to check whether the neighbor node C's identity is correct, then uses D's public key to decrypt the signature, and then uses the BLS algorithm to generate id(A) signed by C's private key, together with C's identity and X4, X3 encrypted with the shared key, and returns it to node B;

[0080] 6) C → B: ED s {id(C),X3,X4,BLs_sign C (id(A),X1)}

[0081] B receives the information sent by C, uses the shared key to decrypt the identifier and the random numbers of other nodes, and uses C's public key to decrypt the signature. At this point, each access network node has completed mutual verification, proving that the access network nodes are all normal;

[0082] 7) B → A:

[0083] Node B receives BLs_sign C After (id(A), X1), first use the public key of node C to decrypt and get ID(A). At this point, terminal A and node B have exchanged their respective identity information; then use PK A Encrypt X2, sign ID(A) and random number X1 with B's private key, and send to access network terminal A;

[0084] 8) A→B:

[0085] Terminal A receives After that, first use SK A Decryption is performed to obtain X1. At the same time, terminal A calculates the value of (X1) locally and compares it with the decrypted value of (X1). If the two are the same, it indicates that terminal A has successfully verified the identity of node B. If the results are different, the identity authentication fails and the authentication process ends. Next, terminal A uses the BLS multi-signature technology to aggregate all private key encryption information, and then encrypts it with B's public key and sends it to B.

[0086] 10) B → C:

[0087] Node B receives After that, use SK B Decrypt and get BLs_sign ALL (id(A),X1) and X2; the verification process is divided into two parts:

[0088] 1. Node B verifies whether the random number X2 generated by itself is consistent with the decrypted value;

[0089] 2. According to the public key and signature key generation rules of each participating node in this authentication, PALL is calculated locally and the signature content is decrypted to verify whether legal information can be obtained.

[0090] Terminal B determines that this access authentication is successful; then continue to encrypt BLs_sign with C's public key ALL (id(A),X1),X3,X4) is sent to C. If it is not satisfied, the access of terminal A fails, the authentication process ends, and the result is notified to other participating nodes.

[0091] 10) C→D:

[0092] Node C receives After that, use SK C Solve

[0093] Password, get BLS_Sign ALL (id(A)),X1,X3,X4,At the same time, node C verifies whether the locally stored random number is the same as the parsed result. If the two are the same, it means that node C successfully verifies the identity of terminal A; if the results are different, it means that the identity authentication failed and the authentication process ends. If successful, continue to encrypt BLS_Sign with D public key ALL (id(A),X1), X4 is sent to D, who decrypts it with the private key and restores BLS_Sign in the same way as the aggregate signature ALL Information to verify the legitimacy of each signatory.

[0094] Specifically,.

[0095] Example 3

[0096] A WAPI two-way access authentication system in a power Internet of Things scenario, including an access terminal, a WAPI authentication center, an IPK identification / key management center and a database;

[0097] The access terminal performs distributed bidirectional security authentication on the power business terminals and newly added terminal nodes accessing WAPI, authorizes the legitimate business terminals, realizes trusted access of the business terminals, and performs trusted access verification on the newly added terminal nodes;

[0098] The WAPI authentication center receives the authentication request, generates a random number based on the request, and sends a multi-hop aggregation authentication request to the remaining neighboring WAPI nodes for aggregation verification.

[0099] The IPK identification / key management center is responsible for generating and managing the globally unique identification and public-private key pairs of each terminal node and legal business terminal;

[0100] The database stores the globally unique identification of each terminal node and legal business terminal and the public-private key pair of the identification, and each terminal node can query the public-private key according to the identification.

[0101] Example 4

[0102] This embodiment provides a WAPI access authentication method based on SM4. The SM4 block cipher algorithm is an iterative block cipher algorithm, which consists of an encryption and decryption algorithm and a key expansion algorithm. The SM4 block cipher algorithm adopts an unbalanced Feistel structure, with a block length of 128b and a key length of 128b. Both the encryption algorithm and the key expansion algorithm adopt a 32-round nonlinear iterative structure. The algorithm structure of the encryption operation and the decryption operation is the same, and the order of the round keys used in the decryption operation is opposite to that of the encryption operation.

[0103] The SM4 block cipher algorithm mainly includes three parts: encryption algorithm, decryption algorithm and key expansion algorithm. The encryption key and decryption key in the algorithm have the same length, generally set to 128b, and are represented in the algorithm as MK=(MK0,MK1,MK2,MK3), where MKi(i=0,1,2,3) is 32b. The round key in the algorithm is generated by the encryption algorithm key, mainly represented as (rk0,rk1,...,rk31), where rki(i=0,1,...,31) is 32b. FK=(FK1,FK2,FK3,FK4) is a system parameter, and CK=(CK0,CK1,...,CK31) is a fixed parameter. These two parameters are mainly used in the key expansion algorithm, where FKi(i=0,1,...,31) and CKi(i=0,1,...,31) are both 32b.

[0104] The complete process of WAPI terminal accessing WAPI wireless network based on SM4 is as follows Figure 3 As shown in the figure, it includes three processes: certificate authentication, unicast key negotiation, and multicast key notification. The WAPI management plane implements wireless access control to achieve access security, ensuring that only legitimate terminals can access the wireless network and that the terminals can access a trusted wireless network. After the wireless terminal STA establishes a wireless association with the AP, only the WAPI authentication protocol message (protocol number 0x88B4) can pass, and all other messages are discarded (communication port closed). Only after the authentication is passed and key negotiation is completed, data communication can be carried out (communication port opened).

[0105] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or some technical features can be replaced by equivalents without departing from the spirit of the technical solution of the present invention, which should be included in the scope of the technical solution for protection of the present invention.

Claims

1. A WAPI two-way access authentication method in a power Internet of Things scenario, characterized in that: The steps include: S1. The power service terminal to be connected to the network sends an access request. The WAPI authentication center that receives the authentication request generates a random number based on the request through its WAPI node, and sends a multi-hop aggregation authentication request to the remaining neighboring WAPI nodes for aggregation verification. The node that receives the aggregation authentication request will return the aggregation information obtained by the BLS algorithm signature hop by hop, and verify at the nodes along the way whether the node's own random number is aggregated in the signature information. If all verifications are successful, the access request of the power service terminal to be connected to the network will be approved; otherwise, the access will be rejected. S2. The access terminal performs bidirectional security authentication for distributed terminal access to the power business terminals and newly added terminal nodes connected to WAPI; authorizes legitimate business terminals to achieve trusted access for business terminals, and performs trusted access verification for newly added terminal nodes; the equipment management and identity authentication functions are decentralized from the remote centralized authentication center to the edge-side access terminal to complete bidirectional authentication for distributed terminal access.

2. According to claim 1, the WAPI two-way access authentication method in the electric power Internet of Things scenario is characterized in that: The aggregation verification is specifically as follows: For multiple BLS signatures S1, S2, S3..., the aggregated signature is: <h2 style=";text-align:left;direction:ltr">S<h2 style=";text-align:left;direction:ltr"> ALL <h2 style=";text-align:left;direction:ltr"> =a1*S1+a2*S2+a3*S3+… The corresponding aggregated key is: <h2 style=";text-align:left;direction:ltr">P<h2 style=";text-align:left;direction:ltr"> ALL <h2 style=";text-align:left;direction:ltr"> =a1*PK<h2 style=";text-align:left;direction:ltr"> A <h2 style=";text-align:left;direction:ltr"> +a2*PK<h2 style=";text-align:left;direction:ltr"> B <h2 style=";text-align:left;direction:ltr"> +a3*PK<h2 style=";text-align:left;direction:ltr"> C <h2 style=";text-align:left;direction:ltr"> +…… For the coefficient a i have: a i =hash(P i ,{P1,P2,P3...}) Among them, S is the symmetric key shared between the access network node and the authorized terminal. As the necessary prior information for terminal access, it is the first line of defense for authentication access. PK is the public key, SK is the private key, BLS_Sign is based on the BLS signature algorithm. The BLS signature information will be transmitted and verified between the nodes in the authentication stage. x (Y) means using SKx to sign information Y, BLS_Sign ALL Represents a signature aggregation operation.

3. According to claim 1, the WAPI two-way access authentication method in the electric power Internet of Things scenario is characterized in that: The distributed terminal access two-way authentication specifically includes the following steps: 1) A→B: Terminal A (legal service terminal or newly added terminal) sends an authentication request to WAPI node B, carrying A's identity. Access node B queries the public key corresponding to id (A) through the remote database; 2)B→A: WAPI node B encrypts its own ID (B) with the network shared key S and sends it to terminal A; 3)A→B: Terminal A receives ED S {id(B)}, first use the network shared key S to decrypt ID(B); query B's public key in the remote database through ID(B), and then use B's public key PKB to encrypt its own identification ID(A) and random number X1, and pass them to node B; 4) B→C→D→…: Multi-hop aggregation authentication When access node B receives the ID encrypted information sent by the power business terminal After that, it decrypts and obtains ID(A), and sends a multi-hop aggregation authentication request to neighbor node C, with ID(A) encrypted by C's public key. After receiving the information, neighbor node C generates X3, encrypts ID(A) with D's public key, and sends it to node D. Node D decrypts it with its private key and generates a random number X4 locally. 5)…→D→C:ED s {id(D),X4},BLs_signD(id(A),X1)} When neighbor node D receives the information, it will use the BLS algorithm to generate BLs_signD(id(A),X1) signed by D's private key. When neighbor node C receives the returned information, it will first use the shared key to decrypt to check whether the neighbor node C's identity is correct, then use D's public key to decrypt the signature, and then use the BLS algorithm to generate id(A) signed by C's private key, and return it to node B together with C's identity and X4,X3 encrypted with the shared key; 6)C→B:ED s {id(C),X3,X4,BLs_signC(id(A),X1)} B receives the information sent by C, uses the shared key to decrypt the identifier and the random numbers of other nodes, and uses C's public key to decrypt the signature. At this point, each access network node has completed mutual verification, proving that the access network nodes are all normal; 7)B→A: After receiving BLs_signC(id(A),X1), node B first decrypts it with the public key of node C to obtain ID(A). At this point, terminal A and node B have exchanged their respective identity information. A Encrypt X2, sign ID(A) and random number X1 with B's private key, and send to access network terminal A; 8)A→B: Terminal A receives After that, first use SK A Decryption is performed to obtain X1. At the same time, terminal A calculates the value of (X1) locally and compares it with the decrypted value of (X1). If the two are the same, it indicates that terminal A has successfully verified the identity of node B. If the results are different, the identity authentication fails and the authentication process ends. Next, terminal A uses the BLS multi-signature technology to aggregate all private key encryption information, and then encrypts it with B's public key and sends it to B. 9)B→C: Node B receives After that, use SK B Decrypt and get BLs_sign ALL (id(A), X1 and X2); after terminal B confirms that this access authentication is successful; then continue to encrypt BLs_sign with C's public key ALL (id(A),X1),X3,X4) is sent to C. If it is not satisfied, the access of terminal A fails, the authentication process ends, and the result is notified to other participating nodes. 10) Node C receives After that, use SK C Solve Password, get BLS_Sign ALL (id(A)),X1,X3,X4,At the same time, node C verifies whether the locally stored random number is the same as the parsed result. If the two are the same, it means that node C successfully verifies the identity of terminal A; if the results are different, it means that the identity authentication failed and the authentication process ends. If successful, continue to encrypt BLS_Sign with D public key ALL (id(A),X1), X4 is sent to D, who decrypts it with the private key and restores BLS_Sign in the same way as the aggregate signature ALL Information to verify the legitimacy of each signatory.

4. According to claim 3, the WAPI two-way access authentication method in the electric power Internet of Things scenario is characterized in that: The terminal B authentication process in step 9) is divided into two parts:

1. Node B verifies whether the random number X2 generated by itself is consistent with the decrypted value; 2. According to the public key and signature key generation rules of each participating node in this authentication, P is calculated locally. ALL Then decrypt the signed content to verify whether legal information can be obtained.

5. According to claim 1, the WAPI two-way access authentication method in the electric power Internet of Things scenario is characterized in that: The WAPI authentication center adopts a WAPI access authentication method based on SM4.

6. A WAPI two-way access authentication system in the power Internet of Things scenario, characterized in that: Includes access terminal, WAPI authentication center, IPK identification / key management center and database; The access terminal performs distributed bidirectional security authentication on the power business terminals and newly added terminal nodes accessing WAPI, authorizes the legitimate business terminals, realizes trusted access of the business terminals, and performs trusted access verification on the newly added terminal nodes; The WAPI authentication center receives the authentication request, generates a random number based on the request, and sends a multi-hop aggregation authentication request to the remaining neighboring WAPI nodes for aggregation verification. The IPK identification / key management center is responsible for generating and managing the globally unique identification and public-private key pairs of each terminal node and legal business terminal; The database stores the globally unique identification of each terminal node and legal business terminal and the public-private key pair of the identification, and each terminal node can query the public-private key according to the identification.

Citation Information

Cited By

  • Wireless access device and method based on reconfigurable intelligent surface combined WAPI (Wireless Local Area Network Authentication and Privacy Infrastructure)

    CN120751409A