Lightweight collaborative network access authentication method and system suitable for IP ad hoc network
By distributing identity resources in IP ad hoc network and using identification password algorithm for lightweight authentication, the complexity and security risks of traditional central authentication methods in ad hoc network are solved, and efficient and secure network access identity authentication is achieved.
Patent Information
- Application Number
- CN202510175668.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-23
AI Technical Summary
The traditional central network access identity authentication method has problems such as increasing complexity, exposure of security risks, and large network transmission burden in ad hoc networks, especially in narrowband ad hoc network environments.
The lightweight collaborative network access authentication method suitable for IP ad hoc networking is adopted, and the identity resources are distributed to all registered ad hoc network nodes through infrastructure, identity authentication is performed between the access node and the accessed node, and the identification password algorithm is used to realize the transmission and processing of lightweight authentication messages.
The uncentered self-organization characteristics of the ad hoc network are maintained, which reduces the consumption of communication resources by the authentication process, reduces security risks, and improves the efficiency and security of the access identity authentication in a narrowband ad hoc network environment.
Smart Images

Figure CN120034861A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a lightweight collaborative network access authentication method and system suitable for IP ad hoc networks. Background Art
[0002] In the current information system under the narrowband ad hoc network environment, the user access authentication method basically adopts a centralized authentication method, that is, when all nodes perform identity authentication, they need to apply to the pre-set authentication and authorization center (central node) for network access authentication. After the authentication and authorization center authenticates and authorizes the node's identity and sends the authorization control information to the relevant ad hoc network node (as a network / resource access control gateway), the node can access the ad hoc network for subsequent network and information system resource access operations, such as Figure 1 shown.
[0003] However, this authentication and authorization method has the following shortcomings:
[0004] 1. The centralized network access identity authentication method first requires that the authenticated user node knows the authentication authorization center and can send the authentication message to the authentication authorization center. For ad hoc networks, which are accessed at will, this requires the ad hoc network nodes to have the ability to identify authentication messages and automatically route authentication messages to the authentication authorization center, which increases the complexity of the ad hoc network nodes.
[0005] 2. Since the authentication message has been granted uncontrolled access by the network when it is sent to the authentication authority, the network access security risk of the ad hoc network is more exposed, posing a non-negligible risk to the security of the ad hoc network.
[0006] 3. The centralized network access identity authentication method requires that the authentication messages, etc., be converged to the authentication and authorization center in the ad hoc network. On the one hand, it increases the network transmission burden of the ad hoc network, and on the other hand, it also destroys the self-organizing and centerless characteristics of the ad hoc network, causing a significant negative impact on the performance of the ad hoc network. In addition, the authentication confirmation messages, authorization information, etc. need to be spread from the authentication and authorization center to different nodes in the network, which also greatly increases the network transmission burden of the ad hoc network and may further deteriorate the performance of the ad hoc network.
[0007] Therefore, the traditional centralized network access authentication method is not suitable for ad hoc networks, especially narrowband ad hoc network environments. A collaborative network access authentication method that is oriented to ad hoc networks and has lightweight transmission requirements is needed. Summary of the invention
[0008] In view of this, the present application provides a lightweight collaborative network access authentication method and system suitable for IP ad hoc networks, which is suitable for high-security network access identity authentication in a narrowband ad hoc network environment based on the IP protocol.
[0009] The present application discloses a lightweight collaborative network access authentication method applicable to an IP ad hoc network, which includes:
[0010] The infrastructure distributes and deposits identity resources to all registered ad hoc network nodes; the registered ad hoc network nodes include the ad hoc network nodes to be connected and the ad hoc network nodes that have been connected;
[0011] When the ad hoc network node to be accessed wants to access the ad hoc network, the first authentication message is sent to the node that has already accessed the ad hoc network. The node that has already accessed the ad hoc network performs identity authentication on the node to be accessed based on the received first authentication message. If the authentication is successful, the node sends a second authentication message to the node to be accessed.
[0012] The node to be connected to the ad hoc network performs identity authentication on the node to be connected to the ad hoc network based on the second authentication message. If the authentication is successful, the node to be connected to the ad hoc network accesses the ad hoc network through the node to be connected to the ad hoc network.
[0013] Furthermore, the identity resources include an identification password encryption algorithm, an identification password decryption algorithm, an identification password signing algorithm, an identification password signature verification algorithm, an identification password encryption and decryption public and private key pair, an identification password signature verification public and private key pair, an identification list and an identification revocation list.
[0014] Furthermore, the infrastructure distributes and deposits identity resources to all registered ad hoc network nodes, including:
[0015] The infrastructure selects relevant algorithms; the relevant algorithms include the identification password encryption algorithm, the identification password decryption algorithm, the identification password signature algorithm and the identification password signature verification algorithm;
[0016] The infrastructure is based on the public identity ID of the i-th self-organizing network node that has been registered. i , use the ID password encryption algorithm and the ID password decryption algorithm to generate the encryption and decryption public and private key pair (ID i ,EPK i ), use the identity password signature algorithm and the identity password verification algorithm to generate the signature verification public and private key pair (ID i , SPK i );
[0017] The infrastructure forms an identification list; the identification list includes the identities of all registered self-organizing network nodes and their corresponding communication IP addresses;
[0018] The infrastructure distributes and injects the selected relevant algorithms into all registered ad hoc network nodes;
[0019] The infrastructure encrypts and decrypts the public and private key pair (ID i ,EPKi ), identification password signature verification public and private key pair (ID i , SPK i ) distributes and injects the i-th self-organizing network node that has been registered; for the self-organizing network node i that has been registered, the infrastructure uses ID i As the encryption public key, after encrypting the identification list using the identification password encryption algorithm, it is distributed and injected into the self-organizing network node i that has been registered. The self-organizing network node i that has been registered is EPK i As the decryption private key, use the ID password decryption algorithm to decrypt the encrypted ID list for use; ID i is the identity of node i;
[0020] The infrastructure forms an identification revocation list; the identification revocation list includes the identities of all ad hoc network nodes that are not allowed to access the network;
[0021] For each registered ad hoc network node i, the infrastructure uses ID i As the encryption public key, the identification revocation list is encrypted using the identification password encryption algorithm, and then distributed and injected into the self-organizing network node i that has been registered. The self-organizing network node i that has been registered is EPK i As the decryption private key, the encrypted identity revocation list is decrypted using the identity password decryption algorithm and then used.
[0022] Further, the node that has accessed the self-organizing network performs identity authentication on the node to be accessed the self-organizing network according to the received first authentication message, including:
[0023] The node connected to the ad hoc network extracts the source IP address of the first authentication message and searches the ID corresponding to the source IP address in the identification list. x If the query is successful, continue with the subsequent operation; record the node to be connected to the ad hoc network as node x; ID x is the identity of node x;
[0024] Look up the ID corresponding to the source IP address in the ID revocation list x , if the query fails, continue with the subsequent operations;
[0025] Adopt the identification password verification algorithm, with ID x The signature information of the Sign field of the first authentication message is verified as the public key. If the verification is successful, it is considered that the network access identity authentication of node x has passed, and node x is confirmed to be a legal node. Node x is allowed to access the network and perform subsequent normal communication.
[0026] Furthermore, the first authentication message includes an IP protocol header, a UDP message header, an SN field, and a Sign field;
[0027] The IP protocol header and UDP message header are generated by the standard IP protocol stack; the SN field is randomly generated by node x using a random number algorithm; the Sign field is generated by node x using an identification cryptographic signature algorithm with SPK x To generate a signature private key, all information including the IP protocol header, UDP message header and SN field is signed.
[0028] Furthermore, it also includes searching the ID corresponding to the source IP address in the identification list. x If the query fails, the authentication process is terminated and the node to be connected to the ad hoc network is denied access to the network and subsequent communications;
[0029] Look up the ID corresponding to the source IP address in the ID revocation list x , if the query is successful, the authentication process is terminated and node x is denied access to the network and subsequent communications;
[0030] Use the ID password verification algorithm to x The signature information of the Sign field of the first authentication message is verified by the public key. If the verification fails, the authentication process is terminated immediately and node x is denied access to the network and subsequent communications.
[0031] Further, the node to be connected to the self-organizing network performs identity authentication on the node that has been connected to the self-organizing network based on the second authentication message, including:
[0032] The node to be connected to the ad hoc network extracts the source IP address of the second authentication message and searches the ID corresponding to the source IP address in the identification list. y If the query is successful, continue with the subsequent operation; record the node that has been connected to the ad hoc network as node y; ID y is the identity of node y;
[0033] Look up the ID corresponding to the source IP address in the ID revocation list y , if the query fails, continue with the subsequent operations;
[0034] Use the ID password verification algorithm to y The signature information of the Sign field of the first authentication message is verified by the public key. If the verification is successful, it is considered that the identity authentication of node y is passed, and node y is confirmed to be a legitimate node, allowing node x to perform subsequent normal communication.
[0035] Furthermore, the second authentication message includes an IP protocol header, a UDP message header, an SN field, and a Sign field;
[0036] The IP protocol header and UDP message header are generated by the standard IP protocol stack; the SN field is randomly generated by node y using a random number algorithm; the Sign field is generated by node y using an identification cryptographic signature algorithm with SPKy To generate a signature private key, all information including the IP protocol header, UDP message header and SN field is signed.
[0037] Furthermore, it also includes searching the ID corresponding to the source IP address in the identification list. y ,If the query fails, the authentication process is terminated and node x refuses to communicate with node y in the future;
[0038] Look up the ID corresponding to the source IP address in the ID revocation list y ,If the query is successful, the authentication process is terminated and node x refuses to communicate with node y in the future;
[0039] Use the ID password verification algorithm to y The signature information of the Sign field of the second authentication message is verified by the public key. If the verification fails, the authentication process is terminated immediately and node x refuses to communicate with node y in the future.
[0040] The present application also discloses a lightweight collaborative network access authentication system applicable to an IP self-organizing network, which implements the lightweight collaborative network access authentication method applicable to an IP self-organizing network as described above, and includes:
[0041] Infrastructure, used to distribute and deposit identity resources to all registered ad hoc network nodes; registered ad hoc network nodes include ad hoc network nodes to be connected and ad hoc network nodes that have been connected;
[0042] The self-organizing network node access authentication module is used to send a first authentication message to the connected self-organizing network node when the self-organizing network node to be accessed wants to access the self-organizing network, and the connected self-organizing network node performs identity authentication on the self-organizing network node to be accessed according to the received first authentication message. If the authentication is successful, the second authentication message is sent to the self-organizing network node to be accessed;
[0043] The ad hoc network node access module is used for the ad hoc network node to be accessed to perform identity authentication on the ad hoc network node that has been accessed based on the second authentication message. If the authentication is successful, the ad hoc network node to be accessed accesses the ad hoc network through the ad hoc network node that has been accessed.
[0044] This application is aimed at a narrowband ad hoc network environment and discloses a lightweight collaborative network access authentication method suitable for IP ad hoc networks based on an identification cryptographic algorithm. The main beneficial effects and advantages of this application are as follows:
[0045] (1) Compared with the traditional centralized network access identity authentication method, this application makes use of the identity self-identification characteristics of the identification password algorithm to distribute the network access authentication function to all self-organizing network nodes by pre-setting identification password resources. On the one hand, it ensures the decentralized self-organizing characteristics of the self-organizing network, and on the other hand, it reduces the consumption of self-organizing network communication resources during the authentication process.
[0046] (2) Compared with the traditional centralized network access identity authentication method, the present application can complete the network access authentication on any adjacent ad hoc network node that has been connected to the network, thereby avoiding the random spread of identity authentication messages in the ad hoc network and reducing the security risks of the ad hoc network.
[0047] (3) Compared with the traditional network access identity authentication method, the lightweight authentication message and its interaction and processing flow adopted in this application extracts the identity ID by converting the self-organizing network node IP address carried by the lightweight authentication message, thereby reducing the length of the lightweight authentication message and reducing the consumption of self-organizing network communication resources in the authentication process.
[0048] (4) This application binds the IP address of the self-organizing network node to its identity ID in the identification list ID-LIST, and transmits and stores it in an encrypted manner, thereby improving the anti-counterfeiting capability of the identity information. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0050] Figure 1 A schematic diagram of the existing self-organizing network with centralized identity authentication and authorization access process;
[0051] Figure 2 A schematic diagram of the lightweight collaborative authentication architecture and composition of an embodiment of the present application;
[0052] Figure 3 A schematic diagram of the lightweight authentication protocol message format of an embodiment of the present application;
[0053] Figure 4 This is a schematic diagram of the collaborative authentication interaction and processing flow of an embodiment of the present application. DETAILED DESCRIPTION
[0054] The present application is further described in conjunction with the accompanying drawings and embodiments, and the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by ordinary technicians in this field should fall within the scope of protection of the embodiments of the present application.
[0055] The present application embodiment provides a lightweight collaborative network access authentication method applicable to an IP ad hoc network. For example, see Figure 2, including several self-organizing network nodes and 1 infrastructure, wherein the self-organizing network node is the implementing body of the embodiment of the present application, the self-organizing network node implements the lightweight authentication message and collaborative authentication interaction and processing flow described in the embodiment of the present application, and collaborates with other self-organizing network nodes to complete the network access identity authentication; the infrastructure is responsible for providing the self-organizing network node with the relevant identity resources required to complete the collaborative identity authentication in an offline or online manner. The identity resources required by the self-organizing network node in the embodiment of the present application include an identification password encryption algorithm, an identification password decryption algorithm, an identification password signature algorithm, an identification password verification algorithm, an identification password encryption and decryption public and private key pair, an identification password signature verification public and private key pair, an identification list, and an identification revocation list.
[0056] The infrastructure uses the following methods to generate, manage, and provision identity resources for ad hoc nodes:
[0057] (1) The infrastructure selects relevant algorithms and their algorithm parameters, including the identity password encryption algorithm AlgEncrypt, the identity password decryption algorithm AlgDecrypt, the identity password signature algorithm AlgSign, and the identity password signature verification algorithm AlgValidate;
[0058] (2) For a certain self-organizing network node x (whose public identity is IDx) that has been registered, the infrastructure uses the selected identification cryptographic algorithm to generate an encryption and decryption public-private key pair (IDx, EPKx) and a signature verification public-private key pair (IDx, SPKx) based on the information of the self-organizing network node; (IDx, SPKx) represents the identification cryptographic signature verification public-private key pair of the self-organizing network node x; (IDx, EPKx) represents the identification cryptographic encryption and decryption public-private key pair of the self-organizing network node x; IDx is the identity of the node x;
[0059] (3) The infrastructure forms an identification list ID-LIST, which contains all registered self-organizing network node IDs and their corresponding communication IP addresses;
[0060] (4) For all registered ad hoc network nodes, the infrastructure pre-distributes the selected relevant algorithms and their algorithm parameters online or offline and injects them into all ad hoc network nodes;
[0061] (5) For the self-organizing network node x that has been registered, the infrastructure will pre-distribute its identification password encryption and decryption public and private key pair (IDx, EPKx) and identification password signature verification public and private key pair (IDx, SPKx) through a secure channel and inject them into the self-organizing network node x;
[0062] (6) For the self-organizing network node x that has been registered, the infrastructure uses IDx as the encryption public key and uses the AlgEncrypt algorithm to encrypt the identification list ID-LIST, and then distributes and injects it into the self-organizing network node x online or offline. The self-organizing network node x uses its own EPKx as the decryption private key and uses the AlgDecrypt algorithm to decrypt the encrypted identification list ID-LIST for use;
[0063] (7) Repeat steps (5) and (6) to complete the addition of the public and private key pairs and identification lists of all registered ad hoc network nodes;
[0064] (8) The infrastructure forms an identification revocation list EID-LIST, which contains all the IDs of the ad hoc network nodes that are not allowed to access the network due to special reasons such as loss of control and management constraints;
[0065] (9) For the self-organizing network node x that has been registered, the infrastructure uses IDx as the encryption public key and uses the AlgEncrypt algorithm to encrypt the identity revocation list EID-LIST, and then distributes and injects it into the self-organizing network node x online or offline. The self-organizing network node x uses its own EPKx as the decryption private key and uses the AlgDecrypt algorithm to decrypt the encrypted identity revocation list EID-LIST for use;
[0066] (10) Repeat step (9) to complete the addition of the identification revocation list of all self-organizing network nodes that have been registered.
[0067] In order to reduce the amount of information transmitted during the authentication process, the embodiment of the present application completes the network access authentication by constructing a lightweight authentication message based on the UDP transmission protocol. The lightweight authentication message structure is as follows: Figure 3 As shown, it includes the IP protocol header, UDP message header, and SN and Sign fields.
[0068] Among them, the IP protocol header and UDP protocol header are constructed using the protocol header of the standard IP protocol stack, and their lengths are 20 bytes and 8 bytes respectively; the SN field is a random number randomly generated by the message sender, and its length is not specifically restricted in the embodiment of the present application. During implementation, it is adjusted according to the security strength required for network access authentication; the Sign field is the signature information of the message sender for all information including the IP protocol header, UDP message header and random number SN. Its length is not specifically restricted in the embodiment of the present application. During implementation, it is determined according to the output length of the selected signature algorithm AlgSign.
[0069] The collaborative authentication interaction and processing flow includes:
[0070] The self-organizing network node needs to perform network access authentication for other self-organizing network nodes that are newly connected to the node.
[0071] The present application embodiment takes the node x to be connected to the self-organizing network (hereinafter referred to as node x) and the node y that has been connected to the self-organizing network (hereinafter referred to as node y) as examples to illustrate the process. After completing the above-mentioned identity resource management work, node x is turned on and runs. When node x finds a new neighbor node y at the physical layer, it initiates network access authentication. The specific authentication process flow is as follows Figure 4 As shown, the following steps are included:
[0072] (21) Before node x joins the network, all nodes in the ad hoc network (including but not limited to node x and node y) must obtain identity resources from the infrastructure and complete the injection in an offline or online manner;
[0073] (22) Node x discovers neighbor node y at the physical layer;
[0074] (23) Node x constructs and sends a lightweight authentication message to node y, in which the IP protocol header and UDP message header are generated by the standard IP protocol stack; the SN field is randomly generated by node x using a random number algorithm; the Sign field is signed by node x using the AlgSign algorithm with SPKx as the private key to generate all information including the IP protocol header, UDP message header and SN;
[0075] (24) After node y receives the lightweight authentication message sent by node x and verifies the legitimacy of the message, it performs the following identity authentication operations in sequence:
[0076] 1-1) Extract the source IP address IPs of the IP message, and query the IDx corresponding to the IPs address in the ID-LIST. If the query is successful, continue with the subsequent operations; if the query fails, terminate the authentication process and deny node x access to the network and subsequent communications;
[0077] 2-1) Query IDx in EID-LIST. If the query is successful, terminate the authentication process and deny node x access to the network and subsequent communications. If the query fails, continue with subsequent operations.
[0078] 3-1) Use the AlgValidate algorithm to verify the signature information of the Sign field with IDx as the public key. If the verification is successful, it is considered that the network access identity authentication of node x has passed, confirming that node x is a legitimate node, and allowing node x to access the network and conduct subsequent normal communications; if the verification fails, the authentication process is terminated immediately, and node x is denied access to the network and subsequent communications;
[0079] (25) Node y constructs and sends a lightweight authentication message to node x, in which the IP protocol header and UDP message header are generated by the standard IP protocol stack; the SN field is randomly generated by node y using a random number algorithm; the Sign field is signed by node y using the AlgSign algorithm with SPKy as the private key to generate a signature for all information including the IP protocol header, UDP message header and SN; (IDy, SPKy) represents the public-private key pair for the identification cryptographic signature verification of node y in the self-organizing network; IDy is the identity of node y, and SPKy is the signature private key of node y.
[0080] (26) After node x receives the lightweight authentication message sent by node y and verifies the legitimacy of the message, it performs the following identity authentication operations in sequence:
[0081] 1-2) Extract the source IP address IPs of the IP message, and query the IDy corresponding to the IPs address in the ID-LIST. If the query is successful, continue the subsequent operation; if the query fails, terminate the current authentication process, and node x refuses to communicate normally with node y in the future;
[0082] 2-2) Query IDy in EID-LIST. If the query is successful, the authentication process is terminated and node x refuses to communicate with node y in the future. If the query fails, the subsequent operation continues.
[0083] 3-2) Use the AlgValidate algorithm to verify the signature information of the Sign field with IDy as the public key. If the verification is successful, it is considered that the identity of node y has been authenticated and node y is confirmed to be a legitimate node, and node x can safely communicate normally in the future; if the verification fails, the authentication process is terminated immediately, and node x refuses to communicate normally with node y in the future;
[0084] (27) Node x selects a legitimate online node y to access the self-organizing network successfully and conducts subsequent normal communication.
[0085] The embodiments of the present application do not limit the specific identification password encryption algorithm, identification password decryption algorithm, identification password signature algorithm, and identification password verification algorithm. It only requires that the above cryptographic algorithm system is an identification cryptographic algorithm system.
[0086] The embodiment of the present application does not limit the length of the SN field and the length of the Sign field in the lightweight authentication message, but only limits the message structure and performs a lightweight application method according to the embodiment of the present application.
[0087] The embodiment of the present application further provides a lightweight collaborative network access authentication system applicable to an IP self-organizing network, which implements the lightweight collaborative network access authentication method applicable to an IP self-organizing network described in the above embodiment, and includes:
[0088] Infrastructure, used to distribute and deposit identity resources to all registered ad hoc network nodes; registered ad hoc network nodes include ad hoc network nodes to be connected and ad hoc network nodes that have been connected;
[0089] The self-organizing network node access authentication module is used to send a first authentication message to the connected self-organizing network node when the self-organizing network node to be accessed wants to access the self-organizing network, and the connected self-organizing network node performs identity authentication on the self-organizing network node to be accessed according to the received first authentication message. If the authentication is successful, the second authentication message is sent to the self-organizing network node to be accessed;
[0090] The ad hoc network node access module is used for the ad hoc network node to be accessed to perform identity authentication on the ad hoc network node that has been accessed based on the second authentication message. If the authentication is successful, the ad hoc network node to be accessed accesses the ad hoc network through the ad hoc network node that has been accessed.
[0091] This application is mainly aimed at narrowband self-organizing network environments that use the IP protocol. Based on the identification cryptographic algorithm, it adopts identity resource pre-setting, lightweight authentication messages, and end-to-end collaborative authentication to achieve highly secure collaborative identity authentication, and solve the problems of traditional self-organizing network center access authentication methods, such as large communication resource consumption affecting communication efficiency, and network access surface exposure leading to high security risks.
[0092] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present application rather than to limit it. Although the present application has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present application can still be modified or replaced by equivalents, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present application should be included in the scope of protection of the claims of the present application.
Claims
1. A lightweight collaborative network access authentication method suitable for IP ad hoc networks, characterized in that: include: The infrastructure distributes and deposits identity resources to all registered ad hoc nodes; The registered ad hoc network nodes include the ad hoc network nodes to be connected and the ad hoc network nodes that have been connected; When the ad hoc network node to be accessed wants to access the ad hoc network, the first authentication message is sent to the node that has already accessed the ad hoc network. The node that has already accessed the ad hoc network performs identity authentication on the node to be accessed based on the received first authentication message. If the authentication is successful, the node sends a second authentication message to the node to be accessed. The node to be connected to the ad hoc network performs identity authentication on the node to be connected to the ad hoc network based on the second authentication message. If the authentication is successful, the node to be connected to the ad hoc network accesses the ad hoc network through the node to be connected to the ad hoc network.
2. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 1 is characterized in that: The identity resources include an identification password encryption algorithm, an identification password decryption algorithm, an identification password signature algorithm, an identification password signature verification algorithm, an identification password encryption and decryption public and private key pair, an identification password signature verification public and private key pair, an identification list and an identification revocation list.
3. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 1 is characterized in that: The infrastructure distributes and deploys identity resources to all registered ad hoc nodes, including: The infrastructure selects relevant algorithms; the relevant algorithms include the identification password encryption algorithm, the identification password decryption algorithm, the identification password signature algorithm and the identification password signature verification algorithm; The infrastructure is based on the public identity ID of the i-th self-organizing network node that has been registered. i , use the ID password encryption algorithm and the ID password decryption algorithm to generate the encryption and decryption public and private key pair (ID i ,EPK i ), use the identity password signature algorithm and the identity password verification algorithm to generate the signature verification public and private key pair (ID i , SPK i ); The infrastructure forms an identification list; the identification list includes the identities of all registered self-organizing network nodes and their corresponding communication IP addresses; The infrastructure distributes and injects the selected relevant algorithms into all registered ad hoc network nodes; The infrastructure encrypts and decrypts the public and private key pair (ID i ,EPK i ), identification password signature verification public and private key pair (ID i , SPK i ) distributes and injects the i-th self-organizing network node that has been registered; for the self-organizing network node i that has been registered, the infrastructure uses ID i As the encryption public key, after encrypting the identification list using the identification password encryption algorithm, it is distributed and injected into the self-organizing network node i that has been registered. The self-organizing network node i that has been registered is EPK i As the decryption private key, use the ID password decryption algorithm to decrypt the encrypted ID list for use; ID i is the identity of node i; The infrastructure forms an identification revocation list; the identification revocation list includes the identities of all ad hoc network nodes that are not allowed to access the network; For each registered ad hoc network node i, the infrastructure uses ID i As the encryption public key, the identification revocation list is encrypted using the identification password encryption algorithm, and then distributed and injected into the self-organizing network node i that has been registered. The self-organizing network node i that has been registered is EPK i As the decryption private key, the encrypted identity revocation list is decrypted using the identity password decryption algorithm and then used.
4. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 1, characterized in that: The node that has accessed the self-organizing network performs identity authentication on the node to be accessed the self-organizing network according to the received first authentication message, including: The node connected to the ad hoc network extracts the source IP address of the first authentication message and searches the ID corresponding to the source IP address in the identification list. x If the query is successful, continue with the subsequent operation; record the node to be connected to the ad hoc network as node x; ID x is the identity of node x; Look up the ID corresponding to the source IP address in the ID revocation list x , if the query fails, continue with the subsequent operations; Adopt the identification password verification algorithm, with ID x The signature information of the Sign field of the first authentication message is verified as the public key. If the verification is successful, it is considered that the network access identity authentication of node x has passed, and node x is confirmed to be a legal node. Node x is allowed to access the network and perform subsequent normal communication.
5. The lightweight collaborative network access authentication method applicable to an IP ad hoc network according to any one of claims 1 to 4, characterized in that: The first authentication message includes an IP protocol header, a UDP message header, an SN field, and a Sign field; The IP protocol header and UDP message header are generated by the standard IP protocol stack; the SN field is randomly generated by node x using a random number algorithm; the Sign field is generated by node x using an identification cryptographic signature algorithm with SPK x To generate a signature private key, all information including the IP protocol header, UDP message header and SN field is signed.
6. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 4, characterized in that: It also includes querying the ID corresponding to the source IP address in the identification list x If the query fails, the authentication process is terminated and the node to be connected to the ad hoc network is denied access to the network and subsequent communications; Look up the ID corresponding to the source IP address in the ID revocation list x , if the query is successful, the authentication process is terminated and node x is denied access to the network and subsequent communications; Use the ID password verification algorithm to x The signature information of the Sign field of the first authentication message is verified by the public key. If the verification fails, the authentication process is terminated immediately and node x is denied access to the network and subsequent communications.
7. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 4, characterized in that: The node to be connected to the self-organizing network performs identity authentication on the node that has been connected to the self-organizing network based on the second authentication message, including: The node to be connected to the ad hoc network extracts the source IP address of the second authentication message and searches the ID corresponding to the source IP address in the identification list. y If the query is successful, continue with the subsequent operation; record the node that has been connected to the ad hoc network as node y; ID y is the identity of node y; Look up the ID corresponding to the source IP address in the ID revocation list y , if the query fails, continue with the subsequent operations; Use the ID password verification algorithm to y The signature information of the Sign field of the first authentication message is verified by the public key. If the verification is successful, it is considered that the identity authentication of node y is passed, and node y is confirmed to be a legitimate node, allowing node x to perform subsequent normal communication.
8. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 1 or 7, characterized in that: The second authentication message includes an IP protocol header, a UDP message header, an SN field, and a Sign field; The IP protocol header and UDP message header are generated by the standard IP protocol stack; the SN field is randomly generated by node y using a random number algorithm; the Sign field is generated by node y using an identification cryptographic signature algorithm with SPK y To generate a signature private key, all information including the IP protocol header, UDP message header and SN field is signed.
9. The lightweight collaborative network access authentication method applicable to IP ad hoc networks according to claim 7, characterized in that: It also includes querying the ID corresponding to the source IP address in the identification list y ,If the query fails, the authentication process is terminated and node x refuses to communicate with node y in the future; Look up the ID corresponding to the source IP address in the ID revocation list y ,If the query is successful, the authentication process is terminated and node x refuses to communicate with node y in the future; Use the ID password verification algorithm to y The signature information of the Sign field of the second authentication message is verified by the public key. If the verification fails, the authentication process is terminated immediately and node x refuses to communicate with node y in the future.
10. A lightweight collaborative network access authentication system applicable to an IP self-organizing network, implementing the lightweight collaborative network access authentication method applicable to an IP self-organizing network as described in any one of claims 1 to 9, characterized in that: include: Infrastructure for distributing and depositing identity resources to all registered ad hoc nodes; The registered ad hoc network nodes include the ad hoc network nodes to be connected and the ad hoc network nodes that have been connected; The self-organizing network node access authentication module is used to send a first authentication message to the connected self-organizing network node when the self-organizing network node to be accessed wants to access the self-organizing network, and the connected self-organizing network node performs identity authentication on the self-organizing network node to be accessed according to the received first authentication message. If the authentication is successful, the second authentication message is sent to the self-organizing network node to be accessed; The ad hoc network node access module is used for the ad hoc network node to be accessed to perform identity authentication on the ad hoc network node that has been accessed based on the second authentication message. If the authentication is successful, the ad hoc network node to be accessed accesses the ad hoc network through the ad hoc network node that has been accessed.