Industrial internet of things dynamic anonymous authentication method based on Cloud-Fog-Assisted technology

By adopting the dynamic anonymous authentication method of Cloud-Fog-Assisted technology in the industrial Internet of Things, using temporary identity identifiers and dynamic authentication keys, the problem of identity privacy leakage in the frequent authentication process of IoT devices is solved, and higher authentication security and efficiency are achieved.

CN120074913APending Publication Date: 2025-05-30YANCHENG INST OF IND TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510216460.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the industrial Internet of Things, frequent data transmission and sharing between terminal entities and cloud-fog infrastructure can easily lead to privacy leakage of terminals or fog nodes, especially when IoT devices dynamically join or leave groups. Frequent authentication may damage identity privacy.

Method used

The dynamic anonymous authentication method based on Cloud-Fog-Assisted technology is adopted, and through the synergy between fog nodes and cloud servers, temporary identity identifiers and dynamic authentication keys are used to ensure that the identity of IoT devices is not leaked during the communication process. The specific steps include the Internet of Things device launching a registration request to the cloud server through the fog node, generating and distributing temporary identity identifiers, using symmetric encryption algorithms to generate dynamic authentication keys, and encrypting the authentication requests through the dynamic authentication keys.

Benefits of technology

By reducing dependence on a single trust center, the risk of a single point of failure is reduced, the identity of the IoT device is not leaked, and the security and efficiency of authentication requests are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074913A_ABST
    Figure CN120074913A_ABST
Patent Text Reader

Abstract

The invention provides an industrial Internet of Things dynamic anonymous authentication method based on a Cloud-Fog-Assisted technology. The method comprises the following steps that S101, Internet of Things equipment initiates a registration request to a cloud server through a fog node; s102, the cloud server generates and distributes a temporary identity identifier to the Internet of Things device; s103, generating a dynamic authentication key by using a symmetric encryption algorithm; s104, the Internet of Things equipment initiates an authentication request to the fog node; s105, the fog node receives and decrypts the authentication request, and forwards the authentication request to a cloud server for final authentication; s106, the cloud server verifies the identity legality of the Internet of Things device, and generates and returns an authentication response; s107, the Internet of Things device and the fog node use the dynamic authentication key to carry out encryption communication after successful authentication of the cloud server; and S108, the Internet of Things equipment initiates the registration request to the cloud server again. According to the method, the dependence on a single trust center in a traditional authentication method is avoided, the single-point fault risk is reduced, and the identity of the Internet of Things equipment is ensured not to be leaked in the communication process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial Internet of Things, and in particular to a dynamic anonymous authentication method for industrial Internet of Things based on Cloud-Fog-Assisted technology. Background Art

[0002] With the continuous development of modern technology, Industry 5.0 has improved production efficiency and product personalization through human-machine collaboration and intelligent manufacturing, while also promoting green manufacturing and sustainable development. The Industrial Internet of Things (IIoT) provides a key technical foundation and rich real-time data for Industry 5.0. However, the storage and computing resources of various IIoT sensors and terminal devices are limited, so many computing and storage tasks need to be outsourced to fog nodes or clouds. Cloud-Fog computing infrastructure flexibly deploys resources in the Industrial Internet of Things (IIoT) and can adjust the computing and storage capabilities of cloud nodes and fog nodes according to specific needs, thereby optimizing cost and performance. However, frequent data transmission and sharing between terminal entities and cloud-fog infrastructure can easily lead to privacy leakage of terminals or fog nodes. Fog nodes are located at the edge of the data source and manage and process the needs of various local industrial sensors in real time. When sensors dynamically join or leave the group, frequent authentication with fog nodes may compromise identity privacy. Summary of the invention

[0003] In view of this, the object of the present invention is to provide an industrial Internet of Things dynamic anonymous authentication method based on Cloud-Fog-Assisted technology to solve or at least partially solve the above-mentioned problems existing in the prior art.

[0004] To achieve the above object, the present invention provides an industrial Internet of Things dynamic anonymous authentication method based on Cloud-Fog-Assisted technology, the method comprising the following steps:

[0005] S101, the IoT device initiates a registration request to the cloud server through a fog node, and the fog node performs preliminary verification on the IoT device, wherein the fog node includes a public key and a private key;

[0006] S102, after the cloud server receives the registration request of the IoT device, the cloud server generates and distributes a temporary identity identifier to the IoT device;

[0007] S103, the IoT device interacts with the fog node and generates a dynamic authentication key using a symmetric encryption algorithm;

[0008] S104, the IoT device initiates an authentication request to the fog node, and the authentication request message is encrypted by a dynamic authentication key;

[0009] S105. The fog node receives and decrypts the authentication request, verifies the decrypted authentication request, and forwards the verified authentication request to the cloud server for final authentication;

[0010] S106. The cloud server verifies the legitimacy of the identity of the Internet of Things device, generates and returns an authentication response, and the authentication response includes an authentication result and an updated temporary identity identifier;

[0011] S107. After the cloud server authenticates the Internet of Things device and the fog node successfully, they use the dynamic authentication key for encrypted communication;

[0012] S108. After a certain period of time, the temporary identity identifier becomes invalid, and the Internet of Things device needs to initiate a registration request to the cloud server again.

[0013] Further, the step S101 specifically includes the following steps:

[0014] S11. The Internet of Things device generates a random number R 1 ;

[0015] S12. The Internet of Things device uses its identity identifier ID device and the generated random number R 1 to construct a registration request message, which is expressed as follows:

[0016] Request = (ID device , R 1 )

[0017] where Request is the registration request message;

[0018] S13. The Internet of Things device encrypts the registration request message using the public key provided by the fog node, which is expressed as follows:

[0019]

[0020] where Encrypted_Request is the encrypted registration request message, is to encrypt the registration request information using the public key PK fog of the fog node;

[0021] S14. The fog node receives the encrypted registration request information from the Internet of Things device and decrypts the encrypted registration request information using the private key. After decryption, the identity identifier ID device of the Internet of Things device and the random number R 1 are obtained, which is expressed as follows:

[0022]

[0023] Among them, Decrypted_Data is the decrypted registration request message, using the private key SK of the fog node fog to decrypt the registration request information;

[0024] S15. The fog node queries the local database according to the identity identifier ID of the Internet of Things device device to verify whether the Internet of Things device has been registered. If it is verified that the Internet of Things device has not been registered, the fog node will generate a new identity identifier for the Internet of Things device or use the identity identifier provided by the Internet of Things device for subsequent registration.

[0025] Furthermore, the cloud server generates and distributes a temporary identity identifier, which specifically includes the following steps:

[0026] S21. The cloud server receives a registration request from the Internet of Things device, and the registration request contains the identity identifier ID of the Internet of Things device device ;

[0027] S22. The cloud server generates a random number R cloud ;

[0028] S23. The cloud server uses the identity identifier ID of the Internet of Things device device and the generated random number R cloud , and generates a temporary identity identifier for the Internet of Things device, which is expressed as follows:

[0029] TID device = H(ID device ||R cloud )

[0030] Among them, TID device is the temporary identity identifier of the Internet of Things device, and H is a hash function.

[0031] Furthermore, the generation of a dynamic authentication key using the symmetric encryption algorithm specifically includes the following steps:

[0032] S31. When the Internet of Things device and the fog node communicate initially, they share an initial symmetric key K through a secure channel initial ;

[0033] S32. The Internet of Things device generates a local timestamp T device and a random number R device ;

[0034] S33. The fog node generates a local timestamp T fog and a random number R fog ;

[0035] S34. Generate a dynamic authentication key based on the local timestamps and random numbers of the IoT device and the fog node, and the initial symmetric key K initial , which is expressed as follows:

[0036] K dynamic = H(K initial || ID device || ID fog || T device || T fog || R device

[0037] || R fog )

[0038] where K dynamic is the dynamic authentication key, H is the hash function, K initial is the initial symmetric key, ID device is the identity identifier of the IoT device, and ID fog is the identity identifier of the fog node.

[0039] Furthermore, the authentication request message is encrypted with the dynamic authentication key, which specifically includes:

[0040]

[0041] where Encrypted_Request is the encrypted authentication request, is the AES encryption using the dynamic authentication key, and TID device is the temporary identity identifier of the IoT device.

[0042] Furthermore, step S105 specifically includes the following steps:

[0043] S51. The IoT device sends the encrypted authentication request to the fog node;

[0044] S52. The fog node receives and decrypts the authentication request, which is expressed as follows:

[0045]

[0046] where Decrypted_Request is the decrypted authentication request, is the AES decryption using the dynamic authentication key;

[0047] S53. The fog node extracts the identity identifier TID device of the IoT device, the local timestamp T device of the IoT device, and the random number R device from the decrypted authentication request, and respectively for TID device and Tdevice and R device for verification.

[0048] Furthermore, the step S106 specifically includes the following steps:

[0049] S61. The cloud server receives the authentication request forwarded by the fog node, and the authentication request includes the temporary identity identifier TID of the Internet of Things device device , the local timestamp T of the Internet of Things device device , the random number R device , and the dynamic authentication key K dynamic ;

[0050] S62. The cloud server verifies whether the local timestamp of the Internet of Things device is within a reasonable time range, as shown below:

[0051] ΔT′ = |T′ current - T device |

[0052] where ΔT' is the difference between the current time of the cloud server and the local timestamp of the Internet of Things device, and T′ current is the current time of the cloud server;

[0053] S63. The cloud server queries the local database according to the temporary identity identifier TID of the Internet of Things device device to obtain the registration information of the Internet of Things device, and the registration information includes the identity identifier ID of the Internet of Things device device , and the initial symmetric key K initial ;

[0054] S64. The cloud server uses the initial symmetric key K initial and each dynamic parameter to recalculate the dynamic authentication key and compare and verify it with the received dynamic authentication key K dynamic , as shown below:

[0055]

[0056] where H is a hash function;

[0057] S65. The cloud server verifies whether the random number R device has been reused;

[0058] S66. The cloud server generates an authentication result according to the verification results of steps S61 - S65 and updates the temporary identity identifier , as shown below:

[0059]

[0060] Among them, R new is a new random number generated by the cloud server, and T new is a new timestamp generated by the cloud server;

[0061] S67. The cloud server constructs an authentication response, and the authentication response includes an authentication result, an updated temporary identity identifier the new random number R new and the new timestamp T new ;

[0062] S68. The cloud server uses the dynamic authentication key K dynamic to encrypt the authentication response and return the encrypted authentication response to the fog node.

[0063] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0064] By utilizing the synergistic effect of the fog node and the cloud server, the present invention avoids the dependence on a single trust center in traditional authentication methods, thereby reducing the risk of single point of failure. By using the temporary identity identifier and the dynamic authentication key, it ensures that the identity of the Internet of Things device is not leaked during the communication process. By encrypting the authentication request with the dynamic authentication key, it guarantees the security of the authentication request during the transmission process. By verifying the legitimacy of the identity of the Internet of Things device by the cloud server, generating and returning the authentication response, it improves the efficiency and accuracy of the authentication response. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only the preferred embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0066] Figure 1 FIG. is a schematic flowchart of a dynamic anonymous authentication method for industrial Internet of Things based on Cloud-Fog-Assisted technology provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0067] The following describes the principles and features of the present invention in conjunction with the drawings. The listed embodiments are only used to explain the present invention and are not intended to limit the scope of the present invention.

[0068] As Figure 1 shown, the present invention provides a schematic flowchart of a dynamic anonymous authentication method for industrial Internet of Things based on Cloud-Fog-Assisted technology.

[0069] This embodiment provides an industrial Internet of Things dynamic anonymous authentication method based on Cloud-Fog-Assisted technology, the method comprising the following steps:

[0070] S101, the IoT device initiates a registration request to the cloud server through the fog node, and the fog node performs preliminary verification on the IoT device. The fog node includes a public key and a private key, specifically including the following steps:

[0071] S11. IoT device generates random number R 1 ;

[0072] S12. IoT devices use their identity ID device and the generated random number R 1 To construct a registration request message, it is expressed as follows:

[0073] Request=(ID device ,R 1 )

[0074] Among them, Request is a registration request message;

[0075] S13. The IoT device uses the public key provided by the fog node to encrypt the registration request message, as shown below:

[0076]

[0077] Among them, Encrypted_Request is the encrypted registration request message.

[0078] To use the public key PK of the fog node fog Encrypt the registration request information;

[0079] S14, the fog node receives the encrypted registration request information from the IoT device, and uses the private key to decrypt the encrypted registration request information, and obtains the identity ID of the IoT device after decryption device and a random number R 1 , which is expressed as follows:

[0080]

[0081] Among them, Decrypted_Data is the decrypted registration request message. To use the private key SK of the fog node fog Decrypt the registration request information;

[0082] S15, fog node according to the identity ID of the IoT device deviceQuery the local database to verify whether the IoT device has been registered. If it is verified that the IoT device is not registered, the fog node will generate a new identity identifier for the IoT device or use the identity identifier provided by the IoT device for subsequent registration. For the subsequent registration of unregistered IoT devices, the specific content is as follows:

[0083] In the IoT device registration process, there is a confirmation message, which is used to confirm the registration status of the IoT device and request the authentication result from the fog node. The IoT device includes a public key and a private key.

[0084] Based on the unregistered IoT device, the fog node generates a temporary key K temp , for secure communication with the IoT device, which is expressed as follows:

[0085] K temp =RandomGenerator_secure()

[0086] Among them, K temp is the temporary key, and RandomGenerator_secure() represents the high-security random number generation function of the fog node;

[0087] The fog node uses the random number R 1 of the IoT device and the temporary key to construct a response message, which includes the random number R 2 generated by the fog node and the temporary key, which is expressed as follows:

[0088] Response=(R 2 ,K temp )

[0089] Among them, Response is the response message;

[0090] The fog node encrypts the response message using the public key or symmetric key provided by the IoT device. If a symmetric key has been shared between the IoT device and the fog node, it can be used to encrypt the response message, which is expressed as follows:

[0091]

[0092] Among them, Encrypted_Response is the encrypted response message,

[0093] is expressed as encrypted using the shared symmetric key K shared ;

[0094] The IoT device receives the encrypted response message from the fog node and decrypts the encrypted response message using the shared symmetric key. After decryption, the random number R generated by the fog node is obtained2 and the temporary key K temp , which is expressed as follows:

[0095]

[0096] Among them, Decrypted_Response represents the decrypted response message, which is expressed as using the shared symmetric key K shared to decrypt, and the Internet of Things device verifies whether the random number R of the fog node 2 is consistent with the previously calculated or other expected values to ensure the legitimacy of the fog node;

[0097] The Internet of Things device and the fog node use the random numbers R 1 and R 2 and the temporary key K temp to generate a session key K session , which is expressed as follows:

[0098] K session = Hash(R 1 ||R 2 ||K temp )

[0099] Among them, Hash is a hash function;

[0100] The Internet of Things device uses the generated session key K session to encrypt the confirmation message and send it to the fog node. The confirmation message contains a device status or a message indicating the completion of registration, which is expressed as follows:

[0101]

[0102] Among them, Encrypted_Confirmation is the encrypted confirmation message, which is expressed as using the session key K shared to encrypt, and Confirmation is the confirmation message;

[0103] The fog node receives the encrypted confirmation message from the Internet of Things device and uses the session key K session to decrypt the confirmation message. After decryption, the confirmation message of the Internet of Things device is obtained, which is expressed as follows:

[0104]

[0105] Among them, Decrypted_Confirmation is the decrypted confirmation message,

[0106] which is expressed as using the session key K sharedDecryption;

[0107] The fog node verifies the session key K session to check if it is the same as the previously generated one. If it is, it indicates that the session key negotiation between the IoT device and the fog node is successful. Finally, the fog node stores the identity identifier ID device of the IoT device, the session key K session and other relevant information in the local database and notifies the cloud server that the IoT device has been successfully registered.

[0108] S102. After receiving the registration request from the IoT device, the cloud server generates and distributes a temporary identity identifier to the IoT device, which specifically includes the following steps:

[0109] S21. The cloud server receives the registration request from the IoT device, and the registration request contains the identity identifier ID device ;

[0110] S22. The cloud server generates a random number R cloud , which is used to enhance the randomness and security of the temporary identity identifier, and is expressed as follows:

[0111] R cloud = RandomGenerator()

[0112] where RandomGenerator() represents the random number generation function of the cloud server;

[0113] S23. The cloud server uses the identity identifier ID device of the IoT device and the generated random number R cloud to generate the temporary identity identifier of the IoT device, which is expressed as follows:

[0114] TID device = H(ID device ||R cloud )

[0115] where TID device is the temporary identity identifier of the IoT device, and H is a hash function;

[0116] To ensure the security of the temporary identity identifier of the IoT device during transmission, the cloud server uses the public key PK device of the IoT device to encrypt TID device , and is expressed as follows:

[0117]

[0118] Among them, Encrypted_TID is the encrypted temporary identity identifier of the Internet of Things device, which is expressed as using the public key PK of the Internet of Things device device for asymmetric encryption;

[0119] The cloud server generates an authentication message M, and the authentication message M contains the encrypted temporary identity identifier of the Internet of Things device and other relevant information (such as the local timestamp T of the Internet of Things device device ), which is expressed as follows:

[0120] M = {Encrypted_TID, T device}

[0121] The cloud server sends the authentication message M to the Internet of Things device through a secure channel (such as a TLS-encrypted communication channel). The Internet of Things device receives the authentication message M sent by the cloud server and uses its private key SK device to decrypt the encrypted temporary identity identifier of the Internet of Things device in the authentication message, which is expressed as follows:

[0122]

[0123] Among them, Decrypted_TID is the decrypted temporary identity identifier of the Internet of Things device, which is expressed as using the private key SK of the Internet of Things device device for asymmetric decryption; the Internet of Things device verifies whether the local timestamp T of the Internet of Things device device is within the valid range to prevent replay attacks, such as |T current - T device | ≤ ΔT, receives the decrypted temporary identity identifier of the Internet of Things device, and stores it in the local database. In subsequent communication processes, the Internet of Things device uses the temporary identity identifier TID device to replace the real identity identifier ID device to protect the real identity of the Internet of Things device;

[0124] To further enhance security, the cloud server can regularly generate new temporary identity identifiers and distribute them to the Internet of Things devices according to the above steps.

[0125] S103. The Internet of Things device interacts with the fog node and generates a dynamic authentication key using a symmetric encryption algorithm, which specifically includes the following steps:

[0126] S31. When the Internet of Things device and the fog node initially communicate, they share an initial symmetric key K initial through a secure channel;

[0127] S32. The Internet of Things device generates a local timestamp Tdevice and random number R device ;

[0128] S33. The fog node generates a local timestamp T fog and random number R fog ;

[0129] S34. Based on the local timestamps and random numbers of the IoT device and the fog node, and the initial symmetric key K initial , generate a dynamic authentication key, expressed as follows:

[0130] K dynamic = H(K initial ||ID device ||ID fog ||T device ||T fog ||R device

[0131] ||R fog )

[0132] where K dynamic is the dynamic authentication key, H is a hash function, K initial is the initial symmetric key, ID device is the identity identifier of the IoT device, ID fog is the identity identifier of the fog node. The IoT device and the fog node use the generated dynamic authentication key K dynamic to encrypt and decrypt subsequent communication data to ensure secure data transmission. The dynamic authentication key K dynamic can be updated regularly as needed. Each time it is updated, new timestamps and random numbers are regenerated to enhance the security of the system; the IoT device uses a temporary identity identifier and the dynamic authentication key to ensure anonymity.

[0133] S104. The IoT device initiates an authentication request to the fog node. The authentication request message is encrypted with the dynamic authentication key, specifically including:

[0134] The authentication request message is encrypted with the dynamic authentication key, specifically including:

[0135]

[0136] where Encrypted_Request is the encrypted authentication request, is the AES encryption using the dynamic authentication key, and TID device is the identity identifier of the IoT device;

[0137] S105. The fog node receives and decrypts the authentication request, verifies the decrypted authentication request, and forwards the verified authentication request to the cloud server for final authentication, which specifically includes the following steps:

[0138] S51. The Internet of Things device sends the encrypted authentication request to the fog node;

[0139] S52. The fog node receives and decrypts the authentication request, which is expressed as follows:

[0140]

[0141] Among them, Decrypted_Request is the decrypted authentication request, and it is the AES decryption using the dynamic authentication key;

[0142] S53. The fog node extracts the identity identifier TID of the Internet of Things device, device the local timestamp T of the Internet of Things device, device the random number R device from the decrypted authentication request, and respectively verifies TID device T device and R device , which specifically includes:

[0143] Verifying TID device : The fog node looks up the corresponding Internet of Things device record in the local database according to the extracted identity identifier TID of the Internet of Things device device to obtain the registration information of the Internet of Things device, including the identity ID device , the initial symmetric key K initial and so on;

[0144] The fog node checks whether the identity ID device obtained from the local database is associated with the identity identifier TID of the Internet of Things device device . If there is an association, the fog node may need to update the registration information of the Internet of Things device, such as updating the timestamp, random number, etc., to ensure the security of subsequent communications.

[0145] Verifying T device :

[0146] ΔT = |T current - T device |

[0147] Among them, ΔT is the difference between the current time T of the fog node current and the timestamp T generated by the Internet of Things device device , T current is the current time of the fog node. If ΔT ≤ ΔTthreshold , the timestamp is valid; ΔT threshold is a preset value representing the allowable time difference range for determining whether the timestamp T device is within the valid time range. If ΔT > ΔT threshold , it indicates that the timestamp is invalid and the authentication request will be rejected.

[0148] Verify R device : On the premise that the local timestamp T of the Internet of Things device passes the verification, the fog node queries the identity identifier TID of the Internet of Things device from the local database device and the corresponding dynamic authentication key K device . Then, use K dynamic , R dynamic , and T device to calculate the proof value, which is expressed as follows: device Proof′ = H(K

[0149] || R dynamic || T device || T device )

[0150] where Proof′ is the proof value calculated by the fog node and H is a hash function;

[0151] The Internet of Things device also calculates the proof value using the same parameters in the authentication request, which is expressed as follows:

[0152] Proof = H(K dynamic || R device || T device )

[0153] where Proof is the proof value calculated by the Internet of Things device;

[0154] Compare Proof′ with Proof. If Proof′ = Proof, then R device is valid and the Internet of Things device is considered legal; otherwise, the verification fails.

[0155] S106. The cloud server verifies the legitimacy of the identity of the Internet of Things device, generates and returns an authentication response, and the authentication response includes an authentication result and an updated temporary identity identifier. The specific steps are as follows:

[0156] S61. The cloud server receives the authentication request forwarded by the fog node, and the authentication request includes the temporary identity identifier TID of the Internet of Things device device , the local timestamp T of the Internet of Things device device , the random number R device , and the dynamic authentication key K dynamic ;

[0157] S62. The cloud server verifies whether the local timestamp of the Internet of Things device is within a reasonable time range, as follows:

[0158] ΔT′ = |T′ current - T device |

[0159] Where ΔT' is the difference between the current time T′ of the cloud server current and the local timestamp T of the Internet of Things device device , T′ current is the current time of the cloud server. If ΔT ≤ ΔT threshold , the timestamp is valid;

[0160] S63. The cloud server queries the local database according to the temporary identity identifier TID of the Internet of Things device device to obtain the registration information of the Internet of Things device. The registration information includes the identity identifier ID of the Internet of Things device device , the initial symmetric key K initial , etc.;

[0161] S64. The cloud server uses the initial symmetric key K initial and each dynamic parameter to recalculate the dynamic authentication key and compares it with the received dynamic authentication key K dynamic for verification, as follows:

[0162]

[0163] Where H is a hash function;

[0164] S65. The cloud server verifies whether the random number R device is reused to ensure the uniqueness of the authentication request;

[0165] S66. The cloud server generates an authentication result according to the verification results of steps S61 - S65 and updates the temporary identity identifier as follows:

[0166]

[0167] Where R new is the new random number generated by the cloud server, and T new is the new timestamp generated by the cloud server. If all verifications pass, the authentication result is successful; if any verification fails, the authentication result is failed;

[0168] S67. The cloud server constructs an authentication response, and the authentication response includes the authentication result (success or failure) and the updated temporary identity identifier New random number R new and new timestamp T new ;

[0169] S68. The cloud server uses the dynamic authentication key K dynamic to encrypt the authentication response and return the encrypted authentication response to the fog node, as shown below:

[0170]

[0171] where Encrypted_Response is the encrypted authentication response, which is expressed as AES decryption using the dynamic authentication key, and Results is the authentication result;

[0172] After receiving the encrypted authentication response, the fog node uses the dynamic authentication key K dynamic to decrypt it to obtain the plaintext authentication response. The fog node forwards the plaintext authentication response to the Internet of Things device. After receiving the plaintext authentication response, the Internet of Things device verifies its authentication result. If the authentication result is successful, it updates the temporary identity identifier TID device stored in its local database to If the verification result is failed, the Internet of Things device will take corresponding measures, such as reinitiating an authentication request or raising an alarm.

[0173] S107. After the Internet of Things device and the fog node are successfully authenticated by the cloud server, they use the dynamic authentication key for encrypted communication, specifically including:

[0174] Before communicating with the fog node, the Internet of Things device uses the dynamic authentication key K dynamic to encrypt the communication data, as shown below:

[0175]

[0176] where Encrypted_Data is the encrypted communication data, and PlainTextData is the original data generated by the Internet of Things device (such as sensor data, control instructions, etc.);

[0177] The Internet of Things device sends the encrypted communication data to the fog node, and the fog node decrypts it using the same dynamic authentication key, as shown below:

[0178]

[0179] where Decrypted_PlainTextData is the original data generated by the Internet of Things device after decryption, and the fog node performs corresponding processing on it, such as storing, analyzing, or forwarding it to other nodes.

[0180] If it is reverse communication (from the fog node to the IoT device), the fog node can use the same dynamic authentication key K dynamic to encrypt the communication data and send it to the IoT device, which uses the same dynamic authentication key for decryption.

[0181] S108. After a certain period of time, the temporary identity identifier becomes invalid, and the IoT device needs to initiate a registration request to the cloud server again, specifically including:

[0182] To further enhance security, the IoT device and the fog node can periodically negotiate to update the dynamic authentication key K dynamic , and generate a new dynamic authentication key based on the new timestamp, random number, and device information.

[0183] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A dynamic anonymous authentication method for industrial Internet of Things based on Cloud-Fog-Assisted technology, characterized in that: The method comprises the following steps: S101, the IoT device initiates a registration request to the cloud server through a fog node, and the fog node performs preliminary verification on the IoT device, wherein the fog node includes a public key and a private key; S102, after the cloud server receives the registration request of the IoT device, the cloud server generates and distributes a temporary identity identifier to the IoT device; S103, the IoT device interacts with the fog node and generates a dynamic authentication key using a symmetric encryption algorithm; S104, the IoT device initiates an authentication request to the fog node, and the authentication request message is encrypted by a dynamic authentication key; S105, the fog node receives and decrypts the authentication request, verifies the decrypted authentication request, and forwards the verified authentication request to the cloud server for final authentication; S106, the cloud server verifies the legitimacy of the IoT device identity, generates and returns an authentication response, and the authentication response includes an authentication result and an updated temporary identity identifier; S107, after successful authentication with the cloud server, the IoT device and the fog node use a dynamic authentication key to perform encrypted communication; S108. After a certain period of time, the temporary identity identifier becomes invalid, and the IoT device needs to re-initiate a registration request to the cloud server.

2. According to claim 1, a dynamic anonymous authentication method for industrial Internet of Things based on Cloud-Fog-Assisted technology is characterized in that: The step S101 specifically includes the following steps: S11, IoT device generates a random number R1; S12. IoT devices use their identity ID device And the generated random number R1 is used to construct the registration request message, which is expressed as follows: Request=(ID device ,R1) Among them, Request is a registration request message; S13. The IoT device uses the public key provided by the fog node to encrypt the registration request message, as shown below: Among them, Encrypted_Request is the encrypted registration request message. To use the public key PK of the fog node fog Encrypt the registration request information; S14, the fog node receives the encrypted registration request information from the IoT device, and uses the private key to decrypt the encrypted registration request information, and obtains the identity ID of the IoT device after decryption device And the random number R1, expressed as follows: Among them, Decrypted_Data is the decrypted registration request message. To use the private key SK of the fog node fog Decrypt the registration request information; S15, fog node according to the identity ID of the IoT device device Query the local database to verify whether the IoT device is registered. If the IoT device is not registered, the fog node will generate a new IoT device identity or use the identity provided by the IoT device for subsequent registration.

3. According to claim 1, a method for dynamic anonymous authentication of industrial Internet of Things based on Cloud-Fog-Assisted technology is characterized in that: The cloud server generates and distributes a temporary identity identifier, specifically including the following steps: S21. The cloud server receives a registration request from the IoT device, wherein the registration request includes an ID of the IoT device. device ; S22. The cloud server generates a random number R cloud ; S23. Cloud server uses the identity ID of IoT device device and the generated random number R cloud , generate a temporary identity identifier for the IoT device, expressed as follows: TIME device =H(ID device ||R cloud ) Among them, TID device is the temporary identifier of the IoT device, and H is the hash function.

4. According to claim 1, a method for dynamic anonymous authentication of industrial Internet of Things based on Cloud-Fog-Assisted technology is characterized in that: The method of generating a dynamic authentication key by using a symmetric encryption algorithm specifically includes the following steps: S31, IoT devices and fog nodes share the initial symmetric key K through a secure channel during initial communication initial ; S32, IoT device generates local timestamp T device and a random number R device ; S33, fog node generates local timestamp T fog and a random number R fog ; S34, based on the local timestamp and random number of IoT devices and fog nodes, and the initial symmetric key K initial , generate a dynamic authentication key, expressed as follows: K dynamic =H(K initial ∥ID device ∥ID fog ∥T device ∥T fog ∥R device ∥R fog ) Among them, K dynamic is the dynamic authentication key, H is the hash function, K initial is the initial symmetric key, ID device It is the identity of IoT devices. fog It is the identity of the fog node.

5. According to claim 4, a method for dynamic anonymous authentication of industrial Internet of Things based on Cloud-Fog-Assisted technology is characterized in that: The authentication request message is encrypted by a dynamic authentication key, specifically including: Among them, Encrypted_Request is the encrypted authentication request. For AES encryption using dynamic authentication keys, TID device A temporary identifier for an IoT device.

6. According to claim 5, a method for dynamic anonymous authentication of industrial Internet of Things based on Cloud-Fog-Assisted technology is characterized in that: The step S105 specifically The following steps are involved: S51, the IoT device sends the encrypted authentication request to the fog node; S52, the fog node receives and decrypts the authentication request, which is shown as follows: Among them, Decrypted_Request is the decryption authentication request, AES decryption using dynamic authentication keys; S53, the fog node extracts the IoT device's identity identifier TID from the decrypted authentication request device , the local timestamp T of the IoT device device , random number R device , and respectively for TID device , T device and R device to verify.

7. According to claim 6, a method for dynamic anonymous authentication of industrial Internet of Things based on Cloud-Fog-Assisted technology is characterized in that: The step S106 specifically includes the following steps: S61: The cloud server receives the authentication request forwarded by the fog node, where the authentication request includes a temporary identity identifier TID of the IoT device. device , the local timestamp T of the IoT device device , random number R device , dynamic authentication key K dynamic ; S62. The cloud server verifies whether the local timestamp of the IoT device is within a reasonable time range, as shown below: ΔT′=|T′ current -T device | Where ΔT' is the difference between the current time of the cloud server and the local timestamp of the IoT device, T' current is the current time of the cloud server; S63, the cloud server uses the temporary identity identifier TID of the IoT device device Query the local database to obtain the registration information of the IoT device, which includes the identity ID of the IoT device device , initial symmetric key K initial ; S64, the cloud server uses the initial symmetric key K initial Recalculate the dynamic authentication key with the dynamic parameters and the received dynamic authentication key K dynamic The comparison and verification are as follows: Where H is a hash function; S65, cloud server verifies random number R device Whether it is reused; S66: The cloud server generates an authentication result based on the verification results of steps S61-S65 and updates the temporary identity identifier It is expressed as follows: Among them, R new A new random number generated by the cloud server, T new The new timestamp generated by the cloud server; S67: The cloud server constructs an authentication response, which includes the authentication result and the updated temporary identity identifier. New random number R new , new timestamp T new ; S68, cloud server uses dynamic authentication key K dynamic The authentication response is encrypted and returned to the fog node.

Citation Information

Cited By

  • Cloud and mist cooperative authentication key negotiation method and device based on elliptic curve

    CN120263386A