Off-line identity authentication and key agreement method containing biological characteristics

By adopting biometric offline identity authentication and key negotiation methods in the shared vehicle system, using the collaborative work of smart terminal devices, authentication servers and vehicles, the difficulty in managing car keys in shared vehicles and the problem of using the vehicle after the loss of smart terminals is solved, and a safe and efficient user vehicle use process is achieved.

CN120050077AActive Publication Date: 2025-05-27SHANDONG UNIV OF SCI & TECH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510175595.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-27
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

During the use of shared vehicles, due to the scattered and distributed in different geographical spaces, physical car key management is difficult, and the existing technology has failed to effectively solve the problem of users continuing to use cars after they are lost in smart cards or other smart terminals, and the problem of using cars when they cannot communicate directly with the server in harsh environments.

Method used

The offline identity authentication and key negotiation method containing biometrics is adopted, and the identity authentication and key exchange involving three parties of the user's smart terminal device, authentication server and vehicle are used to realize the entire process of user's car use, and a solution to reuse the car after the smart terminal is lost.

Benefits of technology

It realizes secure user identity authentication and vehicle unlocking without relying on network connections, avoids the risk of vehicle theft caused by the loss of smart terminals, improves user experience and security, and reduces the difficulty of vehicle physical key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050077A_ABST
    Figure CN120050077A_ABST
Patent Text Reader

Abstract

The invention discloses an offline identity authentication and key negotiation method containing biological characteristics, and belongs to the technical field of shared resource network security. The method is completed by three parties of user intelligent terminal equipment, an authentication server and vehicle-mounted equipment, and comprises a user registration / vehicle initialization stage, a user login / vehicle selection stage, a user off-line identity authentication vehicle using stage, a user vehicle returning stage and a stage of continuing to use the vehicle after the user intelligent terminal is lost. The main purpose of the invention is to solve the problem that physical vehicle keys are difficult to manage due to the fact that vehicles are scattered and distributed in different geographic spaces in the use process of shared vehicles. The key thought is that the intelligent terminal of the user is used as a key substitute of the shared vehicle, and biological characteristics, timestamps, random numbers and the like are introduced, so that the effects of preventing attacks of stealing the intelligent terminal, preventing replay attacks, resisting key manipulation and the like can be achieved, and the safety is improved while the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security for shared resources, and particularly to an offline identity authentication and key negotiation method including biometric features. Background Art

[0002] With the rapid development of the sharing economy, the sharing model provides a convenient and economical solution in travel by optimizing resource allocation - the shared car service, which has been rapidly popularized globally. However, during the use of shared vehicles, due to the scattered distribution of vehicles in a relatively wide geographical space, it is difficult to manage physical car keys.

[0003] Traditional car rental usually requires users to register and log in on the platform, select a vehicle and wait for the platform to confirm, then use the car key provided by the platform to start the vehicle and return it at the designated location. However, there are the following problems in the traditional car rental process: the way of user identity authentication depends on the account and password, which may lead to the theft of the account; there is a lack of sufficient encryption protection in multi-party communication, and there is a risk of leakage of user car usage information; it is difficult to communicate in an offline environment, etc.

[0004] Currently, existing solutions attempt to provide smart cards, vehicle networking technologies, etc. Although they are convenient to operate to a certain extent, they are not perfect in the problem of users continuing to use the car after the smart card or other smart terminals are lost, and at the same time, they do not consider the problem of using the car in the case of poor network signals and other problems that make it impossible to directly communicate with the server in a harsh environment. Summary of the Invention

[0005] Based on the above technical problems, the present invention proposes an offline identity authentication and key negotiation method including biometric features. This method mainly solves the problem that during the use of shared vehicles, the scattered distribution of vehicles in different geographical spaces makes it difficult to manage physical car keys.

[0006] The technical solution adopted by the present invention is:

[0007] An offline identity authentication and key negotiation method including biometric features, which is completed by the participation of a user intelligent terminal device, an authentication server, and a vehicle, and includes the following steps:

[0008] (1) User registration / vehicle initialization stage;

[0009] The user intelligent terminal device U provides its own real identity ID U and password PW U to apply for registration at the authentication server S, and imprint the user's biometric feature B at the fuzzy extractor of the user intelligent terminal device U ; the authentication server S uniquely verifies the user's identity by email or SMS and saves the user information, including the user's biometric feature B U, and generate a shared key K with the user's intelligent terminal device U U , the user's intelligent terminal device U and the authentication server S jointly save the key K U ; At the same time, the vehicle V also registers at the authentication server S to generate a vehicle number ID V , the key K shared with the authentication server S V , the vehicle V and the authentication server S jointly save the key K V ;

[0010] (2) User login / vehicle selection stage;

[0011] The user's intelligent terminal device U inputs the identity ID' U and the password PW' U , and imprints the user's biometric feature B U ' at the fuzzy extractor of the user's intelligent terminal device, encrypts the identity information with the shared key K U and sends a login request to the authentication server S. The authentication server S decrypts it with the shared key K U to verify the user's identity. If it is valid, it generates a session key K U,S and sends it to the user's intelligent terminal device U; If the user's intelligent terminal device U passes the authentication of the authentication server S, the user's intelligent terminal device U starts to select a vehicle and obtains the vehicle number ID V ; The authentication server S generates a session key K U,V and sends it to the vehicle V. The authentication server S first encrypts all the information required for the user to use the vehicle, i.e., the vehicle use ticket, with the shared key K V , and then encrypts this vehicle use ticket with the shared key K U and sends it to the user's intelligent terminal device U;

[0012] (3) User offline identity authentication vehicle use stage;

[0013] After the user's intelligent terminal device U receives the encrypted vehicle use ticket in step (2), it is set that the user's intelligent terminal device U can only decrypt it with the correct user biometric feature using the shared key K U , so as to obtain the vehicle use ticket encrypted with the shared key K V , and then the user's intelligent terminal device U presents this encrypted vehicle use ticket to the vehicle V. The vehicle V decrypts it with the shared key K V to obtain the information and verify it. If the verification is successful, the vehicle V is unlocked; In this process, the user's intelligent terminal device U and the vehicle V use near-field communication;

[0014] (4) User vehicle return stage;

[0015] The user's intelligent terminal device U submits a vehicle return request to the authentication server S. The authentication server S confirms the identity ID' of the user's intelligent terminal device UU and the password PW' U After that, it is required to imprint the user's biometric feature B at the fuzzy extractor of the user's intelligent terminal device U '. After successful verification, the authentication server S destroys the session key K U,S and K U,V .

[0016] Preferably, the above offline identity authentication and key negotiation method including biometric features further includes the following steps:

[0017] (5) The stage of continuing to use the vehicle after the user's intelligent terminal device is lost;

[0018] If the intelligent terminal device is lost during the user's vehicle use, the user needs to confirm the identity ID' on a new intelligent terminal device U and submit a verification request to the authentication server S. The authentication server S retrieves the previously registered ID' from the database U and then uniquely verifies the user's identity using an email or SMS, and uses the password PW generated when the user registered U to encrypt the key K previously shared with the user's intelligent terminal device U U , and sends the encrypted information to the new user intelligent terminal device. The new user intelligent terminal device then inputs the password PW' U to decrypt and obtain the shared key K U ; after the authentication server S successfully verifies the user's biometric feature, it encrypts the previously generated vehicle use ticket with the shared key K from the database U and resends it to the new user intelligent terminal device so that the new user intelligent terminal device can continue to use the vehicle based on this ticket again.

[0019] The principle and beneficial technical effects of the present invention are as follows:

[0020] The present invention proposes an offline identity authentication and key negotiation method including biometric features. This method can use an intelligent terminal device (such as a mobile phone, smart watch, etc.) as a vehicle key carrier to realize the entire process of user vehicle use. At the same time, considering the problem of reusing the vehicle after the intelligent terminal is lost, it uses the uniqueness and difficulty of forgery of the user's biometric feature to realize the user's identity authentication, and stipulates that only after the user inputs the correct biometric feature can the vehicle use ticket be obtained, preventing the theft of identity information and ensuring the security problem after replacing the intelligent terminal. At the same time, the near-field communication technology is used to realize the user vehicle use process to solve the offline authentication problem and avoid causing inconvenience to the user's travel. The key negotiation technology is used to encrypt each call and the user's basic information, improving the security while enhancing the user experience.

[0021] Specifically, the method of the present invention also has the following advantages:

[0022] The present invention realizes the identity authentication of user intelligent terminal devices, authentication servers, and vehicles (or in-vehicle devices); each message transmission is accompanied by a timestamp T n transmitted together. Whenever the recipient receives a message, it will first check the validity of the timestamp T n . Only when it is determined to be valid will the recipient continue to execute. Therefore, the present invention can prevent replay attacks. In the present invention, the user first applies to the server for vehicle use. After the server verifies the user's identity, it will return a vehicle use credential (vehicle use ticket) to the user. This credential is encrypted and protected by the shared key between the server and the vehicle. The user cannot see any specific information in the credential. The user only needs to present this encrypted credential to the selected vehicle after receiving it. The vehicle decrypts it using the shared key to obtain the specific information contained therein and verifies it to unlock and realize vehicle use. If the user's intelligent terminal device is lost and needs to be replaced, the user only needs to apply to the server. After the identity authentication is passed, the server will resend the credential saved in the database to the user to facilitate their continued vehicle use. Therefore, the present invention can prevent intelligent terminal theft attacks. Due to the existence of the identity authentication mechanism, this method can prevent impersonation attacks because the attacker must obtain all the secret information owned by the user to pass the authentication; at the same time, it can also prevent man-in-the-middle attacks. Each login authentication process requires multiple message transmissions and is under encrypted protection, ensuring secure transmission. By using random numbers and calculating in combination with other secret information, it will not affect communication security and can also resist attacks on temporarily leaked secrets; the session key components of this method come from different parties, and the identity authentication is accompanied during the transmission process. Therefore, no party can independently calculate the session key, thus effectively resisting key manipulation BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a general flow schematic diagram of an offline identity authentication and key negotiation method with biometrics according to the present invention DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] During the use of shared vehicles, due to the scattered distribution of vehicles in a relatively wide geographical space, it is difficult to manage physical car keys. At the same time, intelligent terminal devices such as mobile phones and smart watches of users are becoming increasingly popular. How to combine technologies such as cryptography, network security protocols, biometric extraction and authentication to use intelligent terminals as substitutes for shared vehicle keys, while ensuring security, can greatly reduce the difficulty of managing physical vehicle keys. This is the starting point of the research and proposal of the present invention

[0025] Based on this, the present invention proposes an offline identity authentication and key negotiation method including biometric features, which involves three parties: the user's intelligent terminal device, the authentication server, and the vehicle (in-vehicle device) for identity authentication and key exchange. The method includes stages such as user registration / vehicle initialization, user login / vehicle selection, user offline identity authentication for vehicle use, user vehicle return, and continued vehicle use after the user's intelligent terminal is lost. The user's intelligent terminal device and the in-vehicle device first register with the authentication server. The authentication server generates a shared key and exchanges and saves it respectively. It is required that the intelligent terminal device be equipped with a biometric fuzzy extractor (such as a fingerprint scanner, a facial recognition camera) and a near-field communication module (NFC), and the vehicle be equipped with an NFC receiver. Before using the vehicle, the user's intelligent terminal device needs to first log in to the authentication server, negotiate and generate a session key for this communication and complete the exchange with the authentication server, and then the communication between the intelligent terminal device and the authentication server uses the exchanged session key for encrypted transmission. The vehicle selected by the user negotiates and generates a session key for this communication and completes the exchange with the authentication server, and then the communication between the vehicle and the authentication server uses the exchanged session key for encrypted transmission. During the user's vehicle use, near-field communication is used with the vehicle. The user only needs to present the vehicle use ticket encrypted with the shared key, and then the vehicle will decrypt it, and vehicle use can be completed without the participation of the server. For the user to return the vehicle, only the session key needs to be destroyed and the vehicle use ticket becomes invalid. If the user's intelligent terminal device is lost, the password generated during user registration is required to re-obtain the shared key and its encrypted vehicle use ticket to ensure continued vehicle use.

[0026] Considering that the authentication server is the management entity but has weak performance, in the authentication key exchange process, generally only lightweight operations such as exclusive OR operation and hash operation are used for the registration and authentication of the user's intelligent terminal device and the in-vehicle device. The authentication server, as the central node for key negotiation and exchange, undertakes most of the key negotiation, generation, verification and other heavy computational tasks, and the intelligent terminal device and the in-vehicle device also undertake a small amount of computational tasks.

[0027] The following further illustrates the present invention in conjunction with the accompanying drawings and specific embodiments:

[0028] As Figure 1 shown, an offline identity authentication and key negotiation method including biometric features, which is completed by three main bodies: the user's intelligent terminal device, the authentication server, and the vehicle, includes the following steps:

[0029] Step 1, user registration / vehicle initialization stage;

[0030] The user provides their own identity ID U and password PW U to apply for registration at the authentication server S and imprint the biometric feature B at the fuzzy extractor of the terminal deviceU , after the authentication server S uniquely verifies the user's identity using an email or SMS, it saves the user's relevant information, including the user's biometric feature B U , and generates a shared key K shared with the user's intelligent terminal device U U , the user's intelligent terminal device U and the authentication server S jointly save the key K U to ensure the security of subsequent information transmission. At the same time, the vehicle V also registers at the authentication server S to generate an ID V , and a shared key K with the authentication server S V , the vehicle V and the authentication server S jointly save the shared key K V .

[0031] Specifically, the user registration / vehicle initialization phase includes the following steps:

[0032] Step 11: If a user wants to obtain services from the selected server S, they must first go through the registration process. In this process, the user selects their own identity ID U and password PW U , and then submits a registration request {ID U , PW U} to the server S through a secure channel

[0033] Step 12: After the server S receives the registration request {ID U , PW U} sent by the user's intelligent terminal device U, it uniquely verifies the user's identity through an email or SMS, and generates a shared key K between the user's intelligent terminal device U and the server S U , and stores {ID U , PW U , K U} in the database, and then sends {K U} to the user's intelligent terminal through a secure channel, and the intelligent terminal stores {K U}

[0034] Step 13: After the user's intelligent terminal device U receives {K U} sent by the server S, it imprints the biometric feature B at the fuzzy extractor of the intelligent terminal U , and calculates (R U , P U ) = Gen(B U ), and V = h(ID U || PW U ), and then sends {B U , P U , L, V} to the server S, and the server sends {B U , PU , store {N, Gen(·), R, L, V} in the database. Here, N is a random number, Gen(·) is the generation algorithm of the fuzzy extractor, R U is the string output by the generation algorithm, and P U is a publicly available helper string output by the generation algorithm.

[0035] Step 14: Vehicle V registers with the server to generate a unique identifier (vehicle number) ID V and establish a shared key K with the server S V . The server S stores the vehicle number ID V in the database, and both the server S and the vehicle V store K V .

[0036] Step 2: User login / vehicle selection phase;

[0037] The user's intelligent terminal device U inputs the identity ID' U and the password PW' U , imprints the biometric feature B U ' at the fuzzy extractor of the terminal device, encrypts the identity information with the shared key K U and sends a login request to the server S. The server S decrypts it with the shared key K U to verify the user's identity. If valid, it generates a session key K U,S and sends it to the user's intelligent terminal device U, and then both sides perform identity authentication and key exchange. If the user's intelligent terminal device U passes the authentication of the server S, the user's intelligent terminal device U starts to select a vehicle and obtains the vehicle number ID V . The server S generates a session key K U,V and sends it to the vehicle V. The server S first encrypts all the information required for the user to use the vehicle, i.e., the vehicle usage ticket, with the shared key K V , and then encrypts this ticket with the shared key K U and sends it to the user's intelligent device terminal U. This ticket can only be decrypted by the vehicle V with the shared key K V .

[0038] Specifically, the user login / vehicle selection phase includes the following steps:

[0039] Step 21: The user inputs the identity ID' U and the password PW' U on the intelligent terminal, and imprints the biometric feature B U ' at the fuzzy extractor of the intelligent terminal. Since the newly entered username and password during login may not be correct and need to be compared with the initial username and password stored in the server, the identity ID' U is distinguished from ID U . Distinguish ID' Uand use the shared key K U encrypted {PW' U ,B U '} is sent to the server S via a secure channel to request login. The server S uses the shared key K U to decrypt and save {PW' U ,B U '}, and verify R U ' = Rep(B U ',P U ). If the verification fails, the session is terminated; otherwise, the verification is valid. The server S generates a session key K U,S and stores it in the database and then sends it to the user intelligent terminal device U. The intelligent terminal saves K U,S . Among them, Rep(·) is the regeneration algorithm of the fuzzy extractor.

[0040] Step 22: The user intelligent terminal device U calculates selects a random number r U and X, and then calculates K U,S = h(ID U ||H||A 1 ||A 2 ||T 1 ) and C U = h(ID U ||H||K U,S ||T 1 ). The user intelligent terminal sends {ID U ,p,q,g,r U ,X,A 1 ,NID,T 1} to the server S. The server S stores {ID U ,p,q,g,r U ,X,A 1 ,NID,T 1} in the database. The user intelligent terminal device uses the shared key K U to encrypt {K U,S ,H,C U} and sends the encrypted result to the server S via a secure channel. Among them, T 1 is the current timestamp of the user intelligent terminal device U, p is a randomly generated large prime number, q is a prime factor of (p - 1), and g is a primitive element of order q in the finite field GF(p).

[0041] Step 23: When the server S receives the message at time T 2 , verify |T 2 -T 1| ≤ ΔT, where ΔT is the effective time delay in message transmission. If the verification fails, the server S terminates the session. Otherwise, the server S uses the shared key K U to decrypt and obtain {K U,S , H, C U}, and then calculates and obtains The server S saves {A 3 , ID U} and uses ID U to retrieve from the database and verify C U =? h(ID U || H || A 1 || A 3 || T 1 ). If the verification fails, the session terminates. Otherwise, the user intelligent terminal device U is authenticated by the server S, and the server S returns the authentication result to the user intelligent terminal device U.

[0042] Step 24: When the user intelligent terminal device U receives the message at time T 3 , it verifies |T 3 - T 2 | ≤ ΔT. If the time delay in message transmission is invalid, the session terminates. Otherwise, the user intelligent terminal device U sends the selected vehicle number ID V and {ID U , T 3} to the server S through a secure channel. The server S saves {ID V , T 3}. The server S generates a random number r S , calculates and generates the session key K U,V = h(ID U || ID V || H || A 4 || A 3 || T 3 || T 1 ) and C S = h(ID U || H || K U,V || T 3 ). Then the server S encrypts the ticket information {K V , C U,V , A S} with the shared key K 4 , and then encrypts the ticket with the shared key K U . Then it combines the encrypted information with {ID V , r S , T 3} are sent to the user's intelligent terminal together, that is, the ticket of the specified vehicle is sent to the user's intelligent terminal device U.

[0043] Step 3: User offline identity authentication for vehicle use stage;

[0044] After the user's intelligent terminal device U receives the information in Step 2, it is stipulated that the user's intelligent terminal device U can only use the shared key K by inputting the correct biometric feature U to decrypt and obtain the vehicle use ticket encrypted with the shared key K V Then the user's intelligent terminal device U presents this ticket to the vehicle V, and the vehicle V uses the shared key K V to decrypt and obtain the information for verification. If the verification is successful, the vehicle V is unlocked and the user can use the vehicle V. In this process, the user's intelligent terminal device U and the vehicle V use near-field communication without the participation of the server S to complete.

[0045] During the offline authentication process, biometric features are introduced to solve potential security risks such as vehicle theft caused by the loss of the intelligent terminal.

[0046] Specifically, the user offline identity authentication for vehicle use stage includes the following steps:

[0047] Step 31: At time T 4 After receiving the information in Step 24, the user's intelligent terminal verifies |T 4 -T 3 | ≤ ΔT. If the time delay in message transmission is invalid, the session is terminated. Otherwise, the following steps are carried out. Here, it is stipulated that the user's intelligent terminal device U can only use the shared key K after inputting the correct biometric feature U to decrypt the information and obtain the vehicle use ticket encrypted with the shared key K. Then the ticket is presented to the vehicle V, and at the same time, {ID V , H, X, r U , p, g, A S , T 2 , T 1 , T 3} is sent to the vehicle V, and the vehicle V saves {ID U , H, X, r S , p, g, A 2 , T 1 , T 3}, and uses the shared key K V to decrypt the ticket and calculate the session key K U,V = h(ID U ||ID V ||H||A 2 ||A 5 ||T 3 ||T1 ) to verify C S =?h(ID U ||ID V ||H||A 2 ||A 5 ||T 3 ||T 1 ). If the verification fails, the session is terminated; otherwise, the verification is successful and the vehicle is unlocked, i.e., the user can use the vehicle.

[0048] Step 4: User's vehicle return phase;

[0049] The user's intelligent terminal device U submits a vehicle return request to the server S, and the server S confirms the identity ID' U and password PW' U input by the user's intelligent terminal device U, and then requests the user to imprint the biometric feature B U ' at the fuzzy extractor of the intelligent terminal. After successful verification, the server S destroys the session keys K U,S and K U,V .

[0050] Specifically, the user's vehicle return phase includes the following steps:

[0051] Step 41: The user's intelligent terminal device U confirms its identity ID' U and password PW' U , and then sends {ID' U ,PW' U} to the server S through a secure channel to submit a vehicle return request.

[0052] Step 42: After receiving the vehicle return request from the user's intelligent terminal device U, the server S verifies {ID' U ,PW' U}. After successful verification, it requests the user to imprint their biometric feature B U ' at the fuzzy extractor of the intelligent terminal. After the server S receives B U ', it verifies R U ' = Rep(B U ',P U ) and calculates If the verification fails, the session is terminated; otherwise, the verification is successful and Step 43 is executed.

[0053] Step 43: The server S destroys K U,S and K U,V , and at the same time, the server S destroys the vehicle usage ticket presented by the user's intelligent terminal device U during the vehicle usage period.

[0054] Step 5: Continuing vehicle usage phase after the user's intelligent terminal is lost;

[0055] If the user's intelligent terminal device is lost during vehicle use, the user needs to confirm the identity ID on the new intelligent terminal device. U And submit a verification request to the server S. The server S retrieves the previously registered ID from the database. U Then, it uniquely verifies the user's identity using the email or mobile phone SMS, and uses the password PW generated when the user registered. U Encrypt the previously shared key K with the user's intelligent terminal U. U And send the encrypted information to the user's intelligent terminal device U. The user's intelligent terminal device U then inputs the password PW. U Decrypt to obtain the shared key K. U After the server S successfully verifies the biometric characteristics of the user's intelligent terminal device U, it encrypts the previously generated vehicle use ticket with the shared key K from the database. U And resends it to the user's intelligent terminal device U so that the user's intelligent terminal device U can continue to use the vehicle with this ticket. That is, the present invention allows the user to replace the intelligent terminal during the rental of the same vehicle.

[0056] Specifically, the stage of continuing to use the vehicle after the user's intelligent terminal device is lost includes the following steps:

[0057] Step 51: If the user's intelligent terminal is lost during vehicle use, the user needs to input their identity ID on the new intelligent terminal. U And submit the ID to the server S through a secure channel. U For a verification request. The server S retrieves the previously registered ID from the database. U Then, it authenticates the identity using the user's registered email or SMS, and uses the password PW generated when the user registered. U Encrypt the previously shared key K with the user's intelligent terminal device U. U At the same time, use the shared key K. U To encrypt the current timestamp {T 5}, and then send the encrypted information of PW U To the user's intelligent terminal device U.

[0058] Step 52: After the user's intelligent terminal device U receives the information from the server S at time T 6 , first input the password PW. U For decryption to obtain the shared key K U And {T 5}, verify |T 6 -T 5 |≤ΔT. If the time delay in message transmission is invalid, terminate the session. Otherwise, the user imprints the biometric feature B U ' at the fuzzy extractor of the intelligent terminal, and then use the shared key K UEncryption B U ' and ID U are sent to the server S together, and the server S saves B U ' and verifies R U ' = Rep(B U ', P U ), If the verification fails, the session is terminated. Otherwise, if the verification is successful, the server S encrypts the ticket stored in the database with the shared key K U and resends it to the user intelligent terminal device U, that is, the user intelligent terminal device U can present the ticket to the vehicle V again to continue using the vehicle V.

[0059] The symbols used in the above steps and their explanations are summarized as follows:

[0060] U represents the user intelligent terminal device; S represents the authentication server; V represents the vehicle; ID U represents the user's real identity; PW U represents the user's password; B U represents the user's biometric feature; ID V represents the real number of the vehicle; K U represents the shared key between U and S; K V represents the shared key between V and S; K U,S represents the session key between U and S, K U,V represents the session key between U and V; represents the exclusive OR operation; || represents the concatenation operator; mod represents the modulo operation; h(·) represents the one-way hash function; A 1 ~A 5 represents the intermediate parameter generated during the key negotiation process; Gen represents the generation process of fuzzy extraction; Rep represents the recovery process of fuzzy extraction; R U is the string output by the generation algorithm; P U is a public help string output by the generation algorithm; T n represents the nth timestamp; ΔT represents the time difference between T n and T n-1 ; p represents a large prime number; q represents the prime factor of (p - 1); g represents the primitive element of order q in the finite field GF(p).

[0061] The parts not described in the above method can be implemented by adopting or referring to the existing technologies.

[0062] The above-described embodiments are only descriptions of the preferred embodiments of the present invention and do not limit the scope of the present invention. Without departing from the design spirit of the present invention, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present invention, such as replacing shared vehicles with other shared resources with access control, etc., should also fall within the protection scope determined by the claims of the present invention.

Claims

1. A method for offline identity authentication and key agreement including biometrics, characterized in that: The method is completed by the user's intelligent terminal device, the authentication server and the vehicle, and includes the following steps: (1) User registration / vehicle initialization stage; The user's smart terminal device U provides its real identity ID U and password PW U Apply for registration at the authentication server S and imprint the user's biometric feature B at the fuzzy extractor of the user's smart terminal device U ; The authentication server S uniquely verifies the user's identity through email or mobile phone text message and saves the user information, including the user's biometric features B U , and generate a key K shared with the user's intelligent terminal device U U , the user's intelligent terminal device U and the authentication server S jointly store the key K U ; At the same time, vehicle V also registers at the authentication server S to generate a vehicle number ID V , the key K shared with the authentication server S V , vehicle V and authentication server S jointly store the key K V ; (2) User login / car selection stage; User smart terminal device U inputs identity ID' U and password PW' U , and imprint the user's biometric feature B at the fuzzy extractor of the user's smart terminal device U ', using the shared key K U After encrypting the identity information, the login request is sent to the authentication server S, and the authentication server S uses the shared key K U After decryption, the user's identity is verified. If valid, the session key K is generated. U,S Sent to the user's smart terminal device U; if the user's smart terminal device U passes the authentication of the authentication server S, the user's smart terminal device U starts to select a car and obtains the vehicle number ID V ; Authentication server S generates session key K U,V Sent to vehicle V, the authentication server S first uses the shared key K V Encrypt all the information needed by the user to use the car, that is, the car ticket, and then use the shared key K U The vehicle usage ticket is encrypted and sent to the user's smart terminal device U; (3) User offline identity authentication and vehicle use stage; After the user's smart terminal device U receives the encrypted vehicle ticket in step (2), it is set that the user's smart terminal device U can only use the shared key K after the correct user biometric feature is entered. U Decryption to obtain the shared key K V The encrypted vehicle ticket is then presented by the user's smart terminal device U to the vehicle V, which uses the shared key K V After decryption, the information is obtained and verified. If the verification is successful, the vehicle V is unlocked. During this process, the user's smart terminal device U and the vehicle V use near-field communication; (4) User returns the vehicle; The user's smart terminal device U submits a request to return the vehicle to the authentication server S, and the authentication server S confirms the identity ID of the user's smart terminal device U' U and password PW' U After that, the user's biometric feature B is required to be imprinted at the fuzzy extractor of the user's smart terminal device U ', after successful verification, the authentication server S destroys the session key K U,S and K U,V .

2. According to claim 1, a method for offline identity authentication and key agreement including biometric features is characterized in that: The following steps are also included: (5) The stage where the user continues to use the vehicle after losing the smart terminal device; If the smart terminal device is lost during the user's use of the car, the user needs to confirm the identity ID on the new smart terminal device. U And submit a verification request to the authentication server S, which retrieves the registered ID from the database' U Then use email or SMS to uniquely verify the user's identity and use the password PW generated when the user registered U Encrypt the key K previously shared with the user's smart terminal device U U , the encrypted information is sent to the new user's intelligent terminal device, and the new user's intelligent terminal device enters the password PW' U Decrypt to get the shared key K U After the authentication server S successfully verifies the user's biometrics, it uses the shared key K to generate the previously generated vehicle ticket from the database. U After encryption, the ticket is sent back to the new user's smart terminal device so that the new user's smart terminal device can continue to use the car with the ticket.

3. The method of offline identity authentication and key agreement including biometrics according to claim 1, characterized in that: Step (1) specifically includes the following steps: (11) User selects his / her own ID U and password PW U , and then submit a registration request {ID U ,PW U }; (12) The authentication server S receives the registration request {ID U ,PW U }, the user's identity is uniquely verified through email or mobile phone text message, and a shared key K between the user's smart terminal device U and the authentication server S is generated. U , and replace {ID U ,PW U ,K U } into the database, and then {K U } is sent to the user's intelligent terminal device, and the user's intelligent terminal device stores {K U }; (13) The user's intelligent terminal device receives {K U }, the user's biometric feature B is imprinted at the fuzzy extractor of the smart terminal device U , and calculate (R U ,P U )=Gen(B U ), and V = h(ID U ||PW U ), and then {B U ,P U ,L,V} is sent to the authentication server S, and the authentication server S sends {B U ,P U ,L,V} are stored in the database; Where N is a random number, Gen(·) is the generation algorithm of the fuzzy extractor, and R U is the string generated by the algorithm output, P U is a public help string that generates the algorithm output, represents XOR operation, || represents a connector; h(·) represents a hash function; (14) Vehicle V registers at the authentication server S to generate a vehicle ID V And establish a shared key K with the authentication server S V , the authentication server S will vehicle number ID V Stored in the database, and the authentication server S and the vehicle V both store the key K V .

4. The method of offline identity authentication and key agreement including biometrics according to claim 1, characterized in that: Step (2) specifically includes the following steps: (21) The user enters his / her ID on the smart terminal device. U and password PW' U , and imprint the biometric feature B at the fuzzy extractor of the smart terminal device U ', ID' U and use the shared key K U Encrypted {PW' U ,B U '}Send it to the authentication server S through a secure channel to request login. The authentication server S uses the shared key K U Decrypt and save {PW' U ,B U '}, verify R U '=Rep(B U ',P U ), If the verification fails, the session is terminated; otherwise, the verification is valid and the authentication server S generates a session key K U,S and stored in the database, and then sent to the user's intelligent terminal device U, which saves K U,S ; Where Rep(·) is the regeneration algorithm of the fuzzy extractor; (22) User Intelligent Terminal Device Computing Choose a random number r U and X, and calculate K U,S =h(ID U ||H||A1||A2||T1) and C U =h(ID U ||H||K U,S ||T1), the user's smart terminal device will {ID U ,p,q,g,r U ,X,A1,NID,T1} to the authentication server S, and the authentication server S will U ,p,q,g,r U ,X,A1,NID,T1} is stored in the database, and the intelligent terminal device uses the shared key K U For {K U,S ,H,C U }After encryption, the encryption result is sent to the authentication server S through a secure channel; Among them, T1 is the current timestamp of the user's intelligent terminal device U, p is a randomly generated large prime number, mod represents the modulo operation, q is the (p-1) prime factor, and g is the q-order primitive element of the finite field GF(p). (23) When the authentication server S receives the message at time T2, it verifies that |T2-T1|≤ΔT, where ΔT is the effective time delay in message transmission. If the verification fails, the authentication server S terminates the session. Otherwise, the authentication server S uses the shared key K U Decryption yields {K U,S ,H,C U }, then calculate and obtain The authentication server S saves {A3, ID U } and use the ID U Retrieve from database and verify C U =? h(ID U ||H||A1||A3||T1); if the verification fails, the session is terminated; otherwise, the user's smart terminal device U is authenticated by the authentication server S, and the authentication server S returns the authentication result to the user's smart terminal device U; (24) When the user's intelligent terminal device U receives the message at time T3, it verifies that |T3-T2|≤ΔT. If the time delay in the message transmission is invalid, the session is terminated; otherwise, the user's intelligent terminal device U will select the vehicle ID V and {ID U ,T3} is sent to the authentication server S through a secure channel, and the authentication server S saves {ID V ,T3}, and the authentication server S generates a random number r S ,calculate And generate the session key K U,V =h(ID U ||ID V ||H||A4||A3||T3||T1) and C S =h(ID U ||H||K U,V ||T3), then the authentication server S uses the shared key K V Encrypted ticket information {K U,V ,C S ,A4}, then use K U Encrypt the ticket and then add the encrypted information to {ID V ,r S ,T3} are sent together to the user's intelligent terminal device U.

5. The method of offline identity authentication and key agreement including biometrics according to claim 4, characterized in that: Step (3) specifically includes the following steps: (31) After receiving the information in step (24) at time T4, the user intelligent terminal device U verifies that |T4-T3|≤ΔT. If the time delay in the message transmission is invalid, the session is terminated; otherwise, the following steps are performed. It is stipulated here that the user intelligent terminal device U can only use the shared key K after entering the correct biometric feature. U Decrypt the information and obtain the shared key K V The encrypted vehicle ticket is then presented to the vehicle V, and {ID U ,H,X,r S ,p,g,A2,T1,T3} is sent to vehicle V, which saves {ID U ,H,X,r S ,p,g,A2,T1,T3}, and use the shared key K V Decrypt the bill and calculate Session key K U,V =h(ID U ||ID V ||H||A2||A5||T3||T1), verify C S =? h(ID U ||ID V ||H||A2||A5||T3||T1), if the verification fails, the session is terminated; otherwise, the verification succeeds, the vehicle is unlocked, and the user can use the vehicle.

6. The method of offline identity authentication and key agreement involving biometrics according to claim 5, characterized in that: Step (4) specifically includes the following steps: (41) The user confirms his / her identity ID U and password PW' U , and then sends {ID' U ,PW' U } to submit a request to return the vehicle; (42) After receiving the vehicle return request submitted by the user, the authentication server S verifies {ID' U ,PW' U }, after successful verification, the user is required to imprint his biometric feature B at the fuzzy extractor of the smart terminal device U U ', the authentication server S receives B U 'After verification R U '=Rep(B U ',P U ) and calculate If the verification fails, the session is terminated, otherwise the verification succeeds and step (43) is executed; (43) Authentication server S destroys K U,S , K U,V At the same time, the authentication server S destroys the vehicle usage ticket presented by the user's smart terminal device U to the vehicle V during the use of the vehicle.

7. The method of offline identity authentication and key agreement including biometrics according to claim 2, characterized in that: Step (5) specifically includes the following steps: (51) If the user's smart terminal device is lost during the use of the vehicle, the user needs to enter his / her identity ID on the new smart terminal device. U and submit ID' to the authentication server S through a secure channel U Make a verification request, and the authentication server S retrieves the registered ID from the database' U , and then use the email or SMS when the user registered to authenticate, and use the password PW generated when the user registered U Encrypt the key K previously shared with the user's smart terminal device U U , and use the shared key K U Encrypt the current timestamp {T5} and then U The encrypted information is sent to the user's intelligent terminal device U; (52) After receiving the information from the authentication server S at time T6, the user's intelligent terminal device U first enters the password PW' U Decrypt and get the shared key K U and {T5}, verify |T6-T5|≤ΔT, if the time delay in message transmission is invalid, terminate the session; otherwise, imprint the biometric feature B at the fuzzy extractor of the user's smart terminal device U ', then use K U Encryption B U 'After and ID U Send it to the authentication server S together, and the authentication server S saves the biometric feature B U ' and verify R U '=Rep(B U ',P U ), If the verification fails, the session is terminated. Otherwise, the verification succeeds and the authentication server S uses the shared key K to store the ticket in the database. U After encryption, it is resent to the user's smart terminal device U, and the user's smart terminal device U can present the vehicle usage ticket to the vehicle V again so that the vehicle V can continue to be used.

Citation Information

Patent Citations

  • Method and apparatus for automated rental key dispensal and return

    CN105608804A

  • Identity verification method for resisting password-guessing replay attack

    CN106534196A

  • Three-factor identity authentication and key negotiation method in multi-server environment

    CN108965338A

  • Equipment unlocking method and device, control system and computer readable medium

    CN112261632A

  • Distributed authentication key negotiation method in intelligent vehicle-mounted networking system

    CN116707791A