An identity authentication method based on Chebyshev mapping

Through the Chebishev mapping-based identity authentication method, the problem of insufficient security of IoT devices in low-resource devices is solved, and the security and efficiency of identity authentication are achieved, which is suitable for IoT systems and other low-computing situations.

CN120074963BActive Publication Date: 2025-07-11HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510544052.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-11
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The existing IoT device identity authentication methods are insufficient in low-resource devices, have low security, high complexity, poor compatibility and scalability, making it difficult to meet the needs of large-scale device access.

Method used

The identity authentication method based on Chebishev mapping is adopted, and the semi-group nature and additive nature of Chebishev mapping are used to realize the secure interaction of identity information and the generation of shared keys through matrix calculation, simplifying the calculation process and suitable for low-resource devices.

Benefits of technology

It improves the identity authentication security of low-resource devices, reduces communication overhead, and improves computing speed, which is suitable for device identity authentication and key negotiation in low-computing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074963B_ABST
    Figure CN120074963B_ABST
Patent Text Reader

Abstract

The present invention discloses an identity authentication method based on Chebyshev mapping. First, system parameters and key parameters required are generated according to hardware parameters and configuration information, and authentication parameters are obtained in a secure channel, including terminal device login verification parameters and authentication center verification parameters; the authentication parameters are calculated from the system parameters and key parameters for the identity parameters of the device. Secondly, the terminal device performs self-authentication check. Utilizing the semigroup property of Chebyshev mapping, the terminal device initiates an identity authentication to the authentication center. Finally, both parties verify the received session random numbers, and a negotiation key is generated after passing the verification. Finally, the terminal device and the authentication center perform secure data communication using the key, and symmetric encryption and decryption algorithms are used to encrypt and transmit the data. The present invention ensures the security of identity information, reduces the number of communications to optimize communication overhead, generates keys faster, and requires less computing resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of identity authentication technology in the field of information security, and particularly to an identity authentication method based on Chebyshev mapping. Background Art

[0002] With the rapid development of Internet of Things technology, more and more devices are connected to the Internet to achieve functions such as data collection, remote control, and intelligent management. However, the wide application of Internet of Things devices also brings many security challenges, especially the identity authentication problem of device access. Internet of Things devices are in different network environments and may be subject to different types of attacks. It is necessary to use an identity authentication mechanism to generate a reliable session key to ensure the secure transmission of data between devices. The existing identity authentication methods mainly have the following problems:

[0003] First, the identity authentication methods used in low-resource devices currently lack security. Generally, simple username and password authentication is used, which is easily cracked or stolen, resulting in illegal access to devices and security problems such as data leakage. Second, it is difficult to deploy traditional identity authentication methods in low-resource devices. These solutions usually require complex key management and certificate distribution, increasing the complexity and maintenance cost of the system. Moreover, in the case of a large number of device accesses, this drawback is infinitely magnified. Third, the existing identity authentication methods have poor compatibility and scalability. Devices from different manufacturers use different authentication protocols, making it difficult for devices to perform data interaction operations. And with the increase in the number of devices, the existing authentication methods are difficult to meet the needs of large-scale device access.

[0004] The existing device access authentication methods are mainly improved by the following several systems.

[0005] The RSA system is based on the problem of large number factorization. Its public key and private key are a pair of large prime numbers, and modular arithmetic of prime numbers is used to encrypt and decrypt information. The encryption and decryption operation speeds are relatively slow, and the key length is limited. If it is too short, it is vulnerable to large number factorization attacks; if it is too long, the encryption time will be extended. The ElGamal system is based on the intractability of the discrete logarithm problem. All keys are located in the exponential part, and exponential operations are used to encrypt parameters. The ciphertext will show exponential expansion as the plaintext increases. The ECC system depends on finding the order of elements in the point group over a finite field, which belongs to the elliptic curve discrete logarithm problem. Point multiplication operations are used to encrypt parameters. At the same security level, the key length required by ECC is shorter, which is convenient for hardware implementation. However, the implementation of point multiplication operations is difficult, and the parameters of the elliptic curve have an obvious impact on encryption and decryption. The bilinear pair system depends on the bilinear inverse DH problem, the decision bilinear inverse DH problem, the t-bilinear inverse DH, and the t-Gap-bilinear inverse DH problems. The public key is directly generated from the user identification, and key escrow is controllable. However, compared with traditional ECC operations, the computational overhead of its bilinear pair is relatively high.

[0006] Although the above several mechanisms have solved the security problem of terminal device access to a certain extent, their applications in low-resource devices are not yet perfect. As an emerging public key system, the Chebyshev chaotic map has received extensive attention from researchers due to its computational advantages of polynomials and special semigroup properties. Its security is built on the discrete logarithm problem of chaotic maps (CMBDLP) and the Diffie-Hellman problem of chaotic maps (CMBDHP). At the same time, it can achieve high security with a relatively short key length and has good application prospects in low-resource devices. Summary of the Invention

[0007] In view of the problem of insufficient lightweight in the above background technology, the present invention proposes an identity authentication method based on the Chebyshev map, which uses the semigroup property and the addition property theorem of the Chebyshev map to realize the secure interaction of identity information and the secure generation of shared keys. Matrix form is used for calculation to further improve the overall calculation speed, and the recurrence formula is , which is an extended Chebyshev map expression, retaining the semigroup property of the original map and improving the disadvantage of the original map having periodicity.

[0008] The calculation formula of the Chebyshev map is , it is a relatively simple trigonometric function expression; the SM2 algorithm uses point multiplication calculations in elliptic curves, which is relatively complex; the SM9 algorithm uses bilinear pair mappings and power operations of multiplicative groups, etc. Compared with algorithms such as SM2 and SM9, the Chebyshev mapping calculation is simpler and faster, providing a direction for solving the problem of identity authentication for low-resource devices. The main research content of this invention is the lightweight identity authentication protocol and key negotiation between the authentication center and the device, realizing the unique identification of the device identity, and being able to generate a secure session key to ensure the secure transmission of device data.

[0009] The authentication communication protocol mentioned in the above invention is applied to the Internet of Things system and other low-computing-power scenarios. The Internet of Things system includes terminal devices and an authentication center. The identity authentication method based on Chebyshev chaotic mapping includes the following steps:

[0010] Step S1, the authentication center performs initialization. Generate the required system parameters and key parameters according to the hardware parameters and configuration information, mainly including the registration private key , the registration public key , the hash function , and the Chebyshev input parameter and other parameters.

[0011] Step S2, the terminal device registers with the authentication center. Obtain the required authentication parameters for both parties in the secure channel, including the terminal device login verification parameter and the authentication center verification parameter . The authentication parameters are calculated from the system parameters and key parameters in Step S1 for the identity parameters of the device, that is , perform a Chebyshev operation on the parameter to obtain , and use the private key generated in S1 to perform another Chebyshev operation on to obtain the verification parameter . Send verification parameters such as the parameter to the terminal device for storage.

[0012] Step S3, complete the identity authentication and exchange the required authentication parameters. The terminal device first performs a self-authentication check. Calculate whether the login parameter calculated according to the user-entered identity parameters is the same as the pre-stored parameter . If they are the same, it means that the user-entered identity is consistent with the terminal device, and the self-authentication of the terminal is completed. If they are different, this authentication is terminated; secondly, the terminal device initiates an identity authentication to the authentication center. The authentication center calculates the parameter , and uses the semigroup property of the Chebyshev mapping, that is , to determine whether it is the same as the parameter pre-stored in the mapping table Verify the authenticity of the terminal device based on whether they are consistent; again, after three rounds of information interaction, both parties verify the session random numbers received to ensure that the received ones are the same as those generated by the other party. After passing the verification, generate a negotiation key that includes the session random numbers of both parties and the identity information of the terminal device i.e., where is a parameter and the key parameter of step S1 which is the result of the Chebyshev operation indicating character concatenation. Finally, complete the identity authentication and key negotiation

[0013] Step S4, the terminal device and the authentication center use the negotiation key to perform secure data communication, generally using a symmetric encryption and decryption algorithm to encrypt and transmit the data

[0014] The identity authentication and key negotiation method provided by the present invention uses the following properties: the semigroup property of the Chebyshev mapping, and the property formula is (i.e., the information of both parties and can be exchanged without being exposed), ensuring that both communication parties can complete information exchange under encryption, and applying this property to verify the identity of the terminal device in step S3; the addition property of Chebyshev, when there is a formula: where represents the Chebyshev operation on the parameter and represents taking the modulus with as the modulus. Use it in step S3 to verify whether the session random numbers received by both communication parties are consistent; the discrete logarithm property of the Chebyshev polynomial, which provides security for the identity authentication and key negotiation phases. Compared with the method based on classical cryptography, the identity authentication mechanism of the present invention has lower communication overhead; compared with the existing method of Chebyshev mapping, the present invention provides a key exchange mechanism

[0015] The beneficial effects of the present invention are as follows:

[0016] (1) The Chebyshev mapping generates public and private keys with a special relationship, and uses its semigroup property to encrypt and decrypt the multi-factor information of the authenticator, ensuring the security of the identity information

[0017] (2) The addition theorem of Chebyshev performs consistency authentication on the exchanged random numbers during the shared key generation phase, reducing the number of communications compared with the traditional EKE key exchange mechanism, that is, optimizing the communication overhead

[0018] ​(3) The computational complexity of Chebyshev polynomials is relatively low. Compared with traditional identity authentication mechanisms, it can generate keys faster and requires less computational resources, making it more suitable for deployment to IoT terminal devices with different architectures.

[0019] (4) The discrete logarithm property of Chebyshev polynomials is comparable to the cracking difficulty of traditional identity mechanisms, ensuring good security.

[0020] (5) Commonly used dual-identity, dual-password, and multi-factor identity authentication technologies are all supported in the algorithm implementation and protocol design of the present invention, meeting the diverse needs of users. Description of the Drawings

[0021] Figure 1 is the overall authentication protocol flowchart;

[0022] Figure 2 is the system parameter initialization stage

[0023] Figure 3 is the registration stage;

[0024] Figure 4 is the authentication stage between the terminal device and the registration center. Detailed Embodiment

[0025] The present invention will be further described below in conjunction with the drawings and embodiments.

[0026] The overall process of identity authentication is shown in Figure 1 , the method of the embodiment of the present invention is mainly applied to the IoT system, and also includes but is not limited to other scenarios such as lightweight and low-node computing power "cloud-edge-terminal" to complete identity authentication and key negotiation. The identity authentication method based on Chebyshev mapping includes the following steps:

[0027] S1. Parameter Initialization Stage

[0028] In the parameter initialization stage, see Figure 2 . The authentication center generates system parameters and key parameters, including the input parameters and extension coefficients of the Chebyshev mapping, the identity encryption private key required for the authentication center to encrypt the identity parameters of the terminal device, the digest algorithm for message integrity verification, etc. The steps are as follows:

[0029] S11. Parameter initialization is performed at the authentication center to generate the system parameters required by the authentication center. Use the discrimination mechanism based on the miller-rabin algorithm to generate large prime numbers and , and thus obtain the Chebyshev expansion parameter , the relationship parameter of the identity encryption public and private keys , where , 。

[0030] S12. Generate the key parameters required for the registration of the terminal device. The authentication center generates a random number and , XOR it with the device information to obtain the registration private key of the authentication center ,that is ; Use it as the input parameter of the Chebyshev mapping, and perform the Chebyshev mapping on the registration private key to calculate the registration public key of the authentication center , , denotes taking the modulus.

[0031] S13. Generate the key parameters required for the encryption and decryption of the terminal device identity. The authentication center generates a random number ,which serves as the identity decryption private key for the authentication center to decrypt the terminal device identity information. Utilize the relationship parameter of the identity encryption public and private keys to calculate the public key of the terminal device, that is 。

[0032] Use the national cryptography SM3 algorithm as the hash function for multiple subsequent information 。This algorithm outputs a digest value of a fixed length, facilitating the extraction of subsequent information, and publish the parameter ,and use it as the parameter used in the encryption process.

[0033] S2. Terminal device registration

[0034] The registration phase is shown in Figure 3 ,mainly that the terminal device sends a registration request to the authentication center. The authentication center generates a corresponding identity mapping table and returns some registration parameters, providing a verification basis for the subsequent authentication of the terminal device. The entire process is in a secure channel, and the steps are as follows:

[0035] S21. The terminal device sends a registration request to the authentication center ,and provides its multi-factor identity information, including the identity identifier ,password ,biological information ,that is 。

[0036] S22. The authentication center receives the registration request ,generates an identity encryption random number ,encrypts the identity information and ,and uses the hash function and the registered private key of the certification center , calculate the pseudo-identity of the user and the pseudo-password , , ; generate identity authentication information , ; to prevent the login verification parameters from being cracked, calculate the parameters , , denotes the exclusive OR operation, use the registered private key to encrypt the parameter , that is .

[0037] S23. Establish an identity mapping table according to the above information, that is , where denotes the association relationship of the data, store it in the certification center; send the generated partial identity information to the terminal device for storage.

[0038] S3. Identity authentication phase

[0039] In the terminal device identity authentication phase, it mainly includes the authentication of the terminal device identity and the generation of the session key, see Figure 4 .

[0040] S31. The terminal device extracts the parameters and the parameter stored in the registration phase. The terminal device inputs the identity information , the password information and the biometric information , and uses the parameter to calculate the pseudo-identity of the user in the terminal device and the login verification parameter ; if is the same as and and respectively, the terminal device completes the login authentication.

[0041] S32. The terminal device encrypts the parameters , and using the identity encryption public key to obtain the parameters , and , , , . Send an authentication request message to the certification center , the last item is the digest value of the transmitted data.

[0042] S33. The certification center verifies the integrity of the received message using the identity decryption private key to decrypt the parameter and to obtain the corresponding values of the parameters and , that is and , namely . Perform a Chebyshev operation on the parameter , that is . Check whether the parameter exists in the identity mapping table of the certification center to determine whether the device has been registered. Unregistered terminal devices need to be registered before identity authentication. In this authentication stage, they are temporarily marked as untrusted devices.

[0043] S34. The certification center reads out the parameter corresponding to the terminal device in the identity mapping table and compares it with the previously calculated parameter , that is . If it holds, it means that the identity information of the terminal device is consistent with the pre-stored information in the certification center, and the authentication is successful; otherwise, the authentication fails.

[0044] S35. The certification center uses the identity decryption private key to decrypt the parameter to obtain the password parameter , that is . Then, use the registration private key to perform a masking calculation on the parameter to obtain the pseudo password , that is ; at the same time, use the parameter and the parameter to calculate the terminal device identity authentication information , that is , and compare it with the value stored in the identity mapping table. If they are the same, the trusted authentication is completed.

[0045] S36. In the session key generation stage, the certification center generates a session random number , and uses the identity information of the terminal device to encrypt and send the session random number generated by the certification center, the pseudo identity of the terminal device , and to generate the information and send it to the terminal device, ,

[0046] S37. The terminal device performs integrity verification on the received message. After the verification passes, it uses the identity information of the terminal device to decrypt the parameter and obtains the session random number of the authentication center . The terminal device generates its own session random number , encrypts to obtain the parameter , . Calculate the sum of the session random numbers , , encrypts it to obtain , and sends the message to the authentication center. .

[0047] S38. The terminal device performs integrity verification on the received message. After the verification passes, the authentication center uses the identity information of the terminal device to decrypt the parameter and obtains the session random number of the terminal device . Using the received sum-of-session-random-numbers parameter and the session random number generated by the authentication center previously , based on the addition property theorem of Chebyshev, verifies the previously received random number , that is . After the verification passes, calculate the sum of the two session random numbers , and then use the Chebyshev mapping to encrypt it, and then send the reply message to the terminal device. . .

[0048] S39. The terminal device performs integrity verification on the received message. After the verification passes, based on the addition property theorem of Chebyshev, uses the received parameter and the parameter to verify whether the previously received authentication center random number is consistent with the session random number originally generated by the authentication center, that is . If the equation holds, the interaction of the random numbers is completed. .

[0049] S310. Both parties calculate the session key according to the interaction information in the previous authentication stage , that is , and complete the key negotiation.

[0050] S4. Business data encryption and decryption stage. Both parties use As the key, use the symmetric encryption algorithm to encrypt and decrypt the transmitted service data, thus realizing the secure communication of data.

[0051] Under the same test environment, the comparison results of the algorithm performance and the protocol performance are shown in Table 1 and Table 2 respectively. The space and time used for a single Chebyshev operation are less, while the core operation time and space of SM2 and SM9 are not dominant. By comparing the complete key negotiation process, it can be seen that the authentication method proposed by the present invention has obvious advantages in space but is relatively slow in time; the key negotiation method of SM2 has certain advantages in time, but it occupies a large amount of space and is not suitable for low-resource and low-computing-power platforms; the key negotiation method of SM9 has no advantages in both time and space and is difficult to be deployed on low-resource and low-computing-power platforms. Therefore, compared with the traditional SM2 and SM9 key negotiation methods, the identity authentication and key negotiation methods mentioned in the present invention are more balanced in space and time and are applicable to low-resource terminal devices.

[0052] Table 1

[0053]

[0054] Table 2

[0055]

[0056] Although the specific implementation manners of the present invention are described above in conjunction with the drawings, it is not a limitation on the protection scope of the present invention. The related modifications based on the Chebyshev mapping identity authentication algorithm and protocol proposed by the present invention are still within the protection scope of the present invention.

[0057] Two devices in the same local area network realize real-time communication through TCP connection. One device serves as the authentication center, and the other serves as the terminal device. Use the identity authentication method of the present invention to perform identity information interaction, and finally generate the same negotiated key according to the interaction information.

[0058] Table 3 Parameter Examples of the Authentication Center

[0059]

[0060] Table 4 Parameter Examples of the Terminal Device

[0061]

[0062] Tables 3 and 4 are the instance data of the authentication center and the terminal device respectively. The authentication center generates a series of system parameters and key parameters, including two large prime numbers, registration public and private keys, and identity encryption public and private keys, etc. The authentication center registers the terminal device and generates a series of identity parameters, including pseudo-identity, pseudo-password, and authentication parameters, etc. In the authentication phase, both sides exchange their respective random numbers. It can be seen from the table that the random numbers are consistent, and finally the same shared key is generated. This shows that the identity authentication method based on Chebyshev mapping proposed in the present invention is practical and feasible.

Claims

1. An identity authentication method based on Chebyshev mapping, characterized in that, Including the following steps: Step S1: Generate the required system parameters and key parameters according to the hardware parameters and configuration information, including the registration private key SK, the registration public key PK, the hash function h(·), and the Chebyshev input parameter x; Step S2, obtain authentication parameters in the secure channel, including the terminal device login verification parameter A and the authentication center verification parameter T SK (T A (x)); The authentication parameters are calculated from the system parameters and the key parameters for the identity parameters of the device, and the verification parameters are sent to the terminal device for storage; Step S3: The terminal device performs self-authentication check, and then, using the semigroup property of the Chebyshev mapping, the terminal device initiates an identity authentication to the authentication center. Finally, both parties verify the received session random number, and after passing, generate a negotiation key. The specific implementation process is as follows: S31: The authentication center receives the registration request M0, generates the identity encryption random parameter L. The terminal device extracts the parameter A and the parameter L. The terminal device inputs the identity information ID, the password information PW, and the biometric information Bio, and calculates the pseudo-identity PID1 of the user in the terminal device and the login verification parameter A1 using the parameter L. If A and PID are respectively the same as A1 and PID1, the terminal device completes the login authentication; S32. The terminal device uses K to encrypt PID, PW, and A Dev to obtain the parameters QID, QPW, and QA; and sends an authentication message M1 = {QID, QPW, QA, h(QID||QPW||QA)} to the authentication center. S33. The certification center verifies the integrity of the received message M1, and uses the identity decryption private key K Auth Decrypt the parameters QID and QA to obtain the corresponding values PID2 and A2 of the parameters PID and A, and perform a Chebyshev operation on the parameter A2, that is, T A2 (T SK (x)); Check whether the parameter PID2 exists in the identity mapping table of the certification center to determine whether the device has been registered. Unregistered terminal devices need to be registered before they can be authenticated. In this authentication stage, they are temporarily marked as untrusted devices; S34. The authentication center compares the T corresponding to the terminal device SK (T A (x)) with the parameter T A2 (T SK (x)). If the two are the same, the identity information of the terminal device is consistent with the pre-stored information in the authentication center, and the authentication is successful; otherwise, the authentication fails. S35. The certification center uses the identity decryption private key K Auth to decrypt the decryption parameter QPW to obtain the password parameter PW, perform a masking calculation on the parameter PW using the registration private key SK to obtain the pseudo password RPW', calculate the terminal device identity authentication information Auth1 = h(SK||RPW'||PID) using the parameter PID and the parameter RPW', compare it with the Auth value stored in the identity mapping table, and if they are the same, the trusted authentication is completed; S36. The authentication center generates a session random number r Auth , and uses the identity information T of the terminal device A (PK) to encrypt r Auth and QID generated by the authentication center: and Generate information M2 and send it to the terminal device. M2 = {QID', N1, h(QID'||N1)}; S37. Conduct three rounds of information interaction based on M2. Both parties verify the session random numbers received to ensure that the received ones are the same as those generated by the other party. Both parties calculate the session key K based on the interaction information s , that is, K s = T A (T SK (x)) || r Auth || r Dev , thus completing the key negotiation Step S4, the terminal device and the authentication center use the negotiated key K s to perform secure data communication and use a symmetric encryption and decryption algorithm to encrypt and transmit the data.

2. The identity authentication method based on Chebyshev mapping according to claim 1, wherein The specific implementation process of the said step S1 is as follows: S11. Parameter initialization is performed at the authentication center. The Miller-Rabin algorithm-based discrimination mechanism is used to generate large prime numbers p and q, obtain the Chebyshev expansion parameter N, and the relationship parameter of the identity encryption public and private keys S12. The certification center generates a random number r s and x, r s are XORed with the device information P Dev to obtain the registration private key SK of the certification center; x is used as the input parameter of the Chebyshev mapping, and the Chebyshev mapping T SK (x) is calculated to obtain the registration public key PK of the certification center, PK = T SK (x) mod N, where mod represents taking the modulus; S13. The certification center generates a random number K Auth , which serves as the identity decryption private key for the certification center to decrypt the identity information of the terminal device. Using the relationship parameter , calculate the public key K of the terminal device Dev .

3. The identity authentication method based on Chebyshev mapping according to claim 2, characterized in that, The specific implementation process of the said step S2 is as follows: S21: The terminal device sends a registration request M0 to the authentication center and provides its multi-factor identity information. The request M0 includes the identity identifier ID, the password PW, and the biometric information Bio; S22. The certification center receives the registration request M0, generates an identity encryption random number L, encrypts the identity information ID and PW, calculates the user's pseudo-identity PID and pseudo-password RPW, where RPW = h(PW||SK), PID = h(ID||L||Bio), and || represents character concatenation; generates the identity authentication information Auth = h(SK||RPW||PID); calculates the parameter denotes the exclusive OR operation, and performs a Chebyshev operation on the parameter A to obtain T A (x), and performs another Chebyshev operation on T A (x) using the private key SK to obtain the verification parameter T SK (T A (x)); S23. Establish an identity mapping table {PID → T SK (T A (x)) → Auth}, where → represents the association relationship of data, store the identity mapping table in the authentication center; send the generated identity information {PID, A, d, L, K Dev} to the terminal device for storage.

4. The identity authentication method based on Chebyshev mapping according to claim 3, characterized in that, The specific implementation process of the said three information interactions is as follows: The terminal device performs integrity verification on the received message M2. After the verification passes, it uses the identity information T of the terminal device A (PK) decrypts the parameter N1 to obtain the session random number r' of the authentication center Auth , the terminal device generates its own session random number r Dev , encrypts to obtain the parameter Calculates the sum of the session random numbers r DevSum , encrypts it to obtain Sends the message M3 to the authentication center The terminal device performs integrity verification on the received message M3. After the verification passes, the authentication center uses the identity information T of the terminal device A (PK) to decrypt the parameter N2 to obtain the session random number r' of the terminal device Dev , uses the received sum of session random numbers parameter T DevSum (PK) and the session random number r generated by the authentication center before Auth , based on the addition property theorem of Chebyshev, verifies the random number r' Dev . After the verification passes, calculates the sum r of the two session random numbers AuthSum , then encrypts r AuthSum using the Chebyshev mapping, and then sends the reply message M4 to the terminal device The terminal device performs integrity verification on the received message M4. After the verification passes, based on the addition property theorem of Chebyshev, it uses the received parameter and the parameter r Dev to verify whether the previously received random number r' from the authentication center Auth is consistent with the session random number originally generated by the authentication center. After the verification passes, the random number interaction is completed.

Citation Information

Patent Citations

  • Chebyshev polynomial multi-registration center anonymous authentication key agreement protocol

    CN114362932A

  • Lightweight identity authentication method for power internet of things based on PUF (Physical Unclonable Function) and Chebyshev chaotic mapping

    CN119070970A