Heterogeneous communication access distributed identity authentication method and system
By combining dynamically expanding the CRP library, PUF response processing and lightweight ZKP protocol, the problems of cumbersome identity authentication process, data redundancy and CRP library management in the existing technology are solved, and efficient and secure distributed identity authentication is achieved, reducing resource consumption and data disclosure.
Patent Information
- Application Number
- CN202510365239.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-13
AI Technical Summary
The existing blockchain-based identity authentication solution has problems such as cumbersome authentication process, on-chain data redundancy, CRP library management problems, PUF response stability problems, poor data disclosure, and delay and storage pressure when facing massive devices.
The method of combining dynamically extended CRP library with hash chain is adopted, and PUF is used to generate an irreversible chain structure, combining error correction encoding, security sketches and fuzzy extractor to process response noise, and a lightweight ZKP protocol and PUF-ZKP nested security design is adopted to deploy authentication logic contracts and trust scoring contracts through blockchain technology to build a network trust evaluation system.
It effectively reduces resource consumption, eliminates the pressure of CRP library management, enhances the robustness and privacy of PUF response verification, realizes protection capabilities against physical cloning, modeling attacks, and side channel protection, improves the efficiency and security of identity authentication, and reduces the burden of data disclosure and on-chain computing.
Smart Images

Figure CN120150962A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a heterogeneous communication access distributed identity authentication method and system, belonging to the technical fields of blockchain and identity authentication. Background Art
[0002] With the rapid development of the Internet of Things technology, the problem of device identity authentication in heterogeneous communication networks has become increasingly prominent. Traditional centralized identity authentication methods have problems such as single-point failure risk and poor scalability when facing a large number of distributed devices. In recent years, distributed identity authentication solutions based on blockchain technology have become an important direction for solving the identity authentication problem in heterogeneous communication networks due to their decentralized and tamper-proof characteristics.
[0003] In the prior art, CN119363318A discloses a distributed device identity authentication and access control method based on blockchain. This method uses the physical unclonable function (PUF) of the device to generate a device fingerprint, binds the device fingerprint with the public key to generate identity information, and performs blockchain storage through a smart contract [CN119363318A]. Although this solution realizes the trusted authentication of device identities, when facing a large number of devices, the problem of data redundancy on the chain is obvious, and there is a lack of an effective management mechanism for the CRP (challenge-response pair) library.
[0004] CN112637189A proposes a multi-layer blockchain cross-domain authentication method in the Internet of Things application scenario, using a blockchain identity registration protocol, a cross-domain identity authentication protocol, and a node trustworthiness evaluation method based on delegated proof of stake to perform distributed node management and security protection for the blockchain in the Internet of Things application scenario [CN112637189A]. This method improves the identity authentication efficiency in a heterogeneous network environment, but does not fully consider the stability problem of PUF responses, and the authentication process is relatively cumbersome.
[0005] CN112637189A further improves the multi-layer blockchain cross-domain authentication method, using a public blockchain to perform cross-chain trusted identity authentication to ensure user privacy and data security [CN112637189B]. However, this solution still has deficiencies in dealing with the data disclosure problem of distributed identity authentication, lacking refined settings for the information disclosure content of different identities.
[0006] CN115333757A discloses a blockchain authentication access implementation method based on a terminal encryption transmission gateway, combining blockchain and the Internet of Things, and using the distributed characteristics of blockchain to meet the network access requirements of Internet of Things devices in a moving scenario [CN115333757A]. Although this method has the characteristics of decentralization, trustlessness, and tamper-proof, when facing the identity authentication of a large number of Internet of Things devices, it still faces problems of delay and storage pressure.
[0007] CN113708935A proposes a unified authentication method for Internet of Things devices based on blockchain and PUF, which generates device PUF challenge values using the current block hash value on the blockchain, and each node in the blockchain network calculates partial response values to complete the authentication process [CN113708935A]. This method combines blockchain and PUF technologies to ensure the credibility of Internet of Things devices, but there are limitations in dynamically expanding the CRP library and establishing trust anchors.
[0008] In summary, the existing blockchain-based identity authentication solutions have the following technical problems: First, the authentication process is cumbersome and there is redundant data on the chain, affecting system efficiency; second, the management problem of the CRP library is prominent, and there is a lack of an effective dynamic expansion mechanism; third, the stability problem of PUF responses has not been well solved, affecting authentication reliability; in addition, the data disclosure problem, real-time performance, network efficiency, and flexibility problems of distributed identity authentication also need to be solved urgently. Especially in the heterogeneous communication network environment, there is a lack of a unified management solution for multiple self-sovereign identity authentications, and an information selective disclosure mechanism for users of different natures. Summary of the Invention
[0009] In order to solve the problems existing in the above-mentioned prior art, the present invention proposes a heterogeneous communication access distributed identity authentication method and system, which uses the physical unclonable function (PUF) combined with zero-knowledge proof and blockchain technology to reasonably optimize the distributed identity authentication system, and under the principle of "minimized disclosure", solves the current privacy protection and data security problems, meets the performance and security requirements of heterogeneous access of distributed resources in the new power system, optimizes the blockchain consensus efficiency, processes the possible delays and storage pressures faced by the identity authentication of a large number of Internet of Things devices, and realizes better authentication, less data disclosure, and more secure communication for power distributed resource heterogeneous communication access devices.
[0010] The technical solution of the present invention is as follows:
[0011] On the one hand, the present invention provides a heterogeneous communication access distributed identity authentication method, including the following steps:
[0012] Construct a dynamically expandable CRP library, generate challenges using a hash chain in the dynamically expandable CRP library, randomly select any challenge in the dynamically expandable CRP library by a heterogeneous communication access node, generate a node root key pair bound by PUF using the physical unclonable function of PUF, and establish a trust anchor;
[0013] The distributed device initiates an identity registration to the heterogeneous communication access node, generates a registration certificate through the node root key pair bound by PUF and returns it to the corresponding device;
[0014] Based on the blockchain, through the processes of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification, and key update, the identity authentication of distributed devices and heterogeneous communication access nodes is carried out.
[0015] As a preferred embodiment, the steps of using the PUF physically unclonable function to generate a node root key pair bound to the PUF and establishing a trust anchor include:
[0016] The heterogeneous communication access node randomly selects any challenge in the dynamically extended CRP library, uses the PUF physically unclonable function to calculate and generate a random response, and generates check information using an error correction code;
[0017] Based on the generated check information, auxiliary data is generated through a secure sketch algorithm;
[0018] Based on the generated random response, auxiliary data, and the random salt value stored on the chain, a key is generated using a fuzzy extractor as the node root private key, and then the random response is destroyed;
[0019] Based on the node root private key, the corresponding node root public key is generated through an asymmetric key algorithm as the trust anchor for the corresponding heterogeneous communication access node.
[0020] As a preferred embodiment, the steps of the distributed device initiating an identity registration to the heterogeneous communication access node, generating a registration certificate through the root key pair bound to the PUF, and returning it to the corresponding device include:
[0021] The distributed device submits device identity information to the heterogeneous communication access node, and the heterogeneous communication access node receives and verifies the freshness of the timestamp;
[0022] The heterogeneous communication access node randomly selects any challenge in the dynamically extended CRP library and uses the PUF physically unclonable function to generate a device root key pair bound to the PUF;
[0023] The heterogeneous communication access node constructs a Token including device identity information, the hash value of the device private key, and the current timestamp, and digitally signs the constructed Token with the node root private key to generate a registration certificate and return it to the corresponding device.
[0024] As a preferred embodiment, the steps of carrying out the identity authentication of distributed devices and heterogeneous communication access nodes based on the blockchain, through the processes of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification, and key update include:
[0025] The blockchain network generates a proof key and a verification key through multi-party computation and stores them on the chain;
[0026] When the heterogeneous communication access node receives an identity authentication request, it obtains the content of the registration certificate from the chain and generates a proof using the Groth16 protocol;
[0027] Input the verification key, the selected challenge, and the generated proof for zero-knowledge ZKP verification, and upload the verification result to the chain;
[0028] Construct an authentication request message, which includes device identity information, the selected challenge, the current timestamp, the proof, and a random number, and sign the authentication request message using the corresponding device root private key;
[0029] Perform multi-node consensus and upload the authentication result to the chain. If the authentication is passed, the smart contract generates a short-term access token and returns it to the corresponding device.
[0030] As a preferred implementation, before performing the identity authentication between the distributed device and the heterogeneous communication access node, it also includes performing a trustworthiness pre-check, specifically including:
[0031] After the heterogeneous communication access node receives the authentication request initiated by the distributed device, it calls the smart contract to query the current trust value, historical authentication records, and the last active time of the corresponding device according to the device identity information;
[0032] Among them, the current comprehensive trustworthiness is calculated through the trust decay value, the last active timestamp, the current timestamp, and the preset trust decay rate;
[0033] Evaluate the authentication behavior through the historical authentication records to obtain an authentication behavior score;
[0034] Calculate the current comprehensive trustworthiness according to the authentication behavior score and the current trust value;
[0035] According to the set global trust threshold and the current comprehensive trustworthiness, make a device authentication risk decision.
[0036] As a preferred implementation, the steps of making the device authentication risk decision include:
[0037] Compare whether the current comprehensive trustworthiness is with the set global trust threshold;
[0038] If the current comprehensive trustworthiness is less than the set global trust threshold, immediately reject the identity authentication and trigger an alarm, and record it in the blockchain audit log;
[0039] If the current comprehensive trustworthiness is greater than or equal to the set global trust threshold, request the corresponding device and the heterogeneous communication access node to provide identity certificates.
[0040] As a preferred implementation, it also includes an authentication behavior feedback mechanism, specifically including:
[0041] When the identity authentication of the corresponding device is successful, the current comprehensive trust level is increased according to a preset ratio and used as the historical trust value for the next identity authentication of the corresponding device.
[0042] When the identity authentication of the corresponding device fails, the current comprehensive trust level is decreased according to a preset ratio and used as the historical trust value for the next identity authentication of the corresponding device.
[0043] On the other hand, the present invention also provides a heterogeneous communication access distributed identity authentication system, including:
[0044] A trust anchor distribution module, configured to construct a dynamically extensible CRP library, generate challenges using a hash chain in the dynamically extensible CRP library, randomly select any challenge in the dynamically extensible CRP library by a heterogeneous communication access node, generate a node root key pair bound by a PUF (Physical Unclonable Function), and establish a trust anchor.
[0045] A registration certificate generation module, configured to generate a registration certificate through the node root key pair bound by a PUF and return it to the corresponding device when a distributed device initiates identity registration to a heterogeneous communication access node.
[0046] A distributed identity authentication module, based on a blockchain, performs identity authentication between a distributed device and a heterogeneous communication access node through a process of dynamic challenge generation, PUF response reading, zero-knowledge (ZKP) proof generation, on-chain verification, and key update.
[0047] On yet another aspect, the present invention also proposes an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the heterogeneous communication access distributed identity authentication method according to any embodiment of the present invention.
[0048] On yet another aspect, the present invention also proposes a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the heterogeneous communication access distributed identity authentication method according to any embodiment of the present invention.
[0049] The beneficial effects of the present invention are as follows: By adopting the method of dynamically expanding the CRP library and deriving new challenges through hash chains to form an irreversible chain structure, only a small amount of core CRP needs to be pre-stored for initialization, effectively reducing resource consumption, eliminating the management pressure of the CRP library, and obtaining the ability to resist replay attacks, balancing security and sustainability; By integrating error-correcting codes, secure sketches, and fuzzy extractors to process response noise, allowing correct comparison under certain errors, ensuring that the PUF response can be used as a key seed to generate a stable encryption key, enhancing the robustness and privacy of response verification; Adopting a lightweight ZKP protocol with high computational efficiency and small proof volume and a nested security design of PUF-ZKP, deeply combining the physical unclonability of PUF and the zero-knowledge property of ZKP to form three-layer protection at the physical layer, cryptographic layer, and protocol layer. Using the PUF function to block physical cloning, ZKP proof to hide sensitive data, and dynamic challenge chains to resist replay attacks, the nested security mechanism has the protection capabilities of anti-physical cloning, anti-modeling attacks, and side-channel protection; Using blockchain technology to deploy authentication logic contracts and trust scoring contracts, constructing a network trust evaluation system, adopting dynamic challenge chains and trust model updates, with efficient resource utilization, deep security guarantee, and flexible expansion, supporting batch proof and hybrid authentication modes to adapt to different scenario requirements; High-frequency devices can cache short-term credentials to reduce the on-chain query frequency. At the same time, PUF verification and hash comparison are executed off-chain, and only the digest and signature are uploaded to the chain, reducing on-chain calculations and alleviating the network burden; Supporting multiple device requests to be packaged into a single transaction to reduce consensus overhead; Achieving better authentication, less data disclosure, and more secure communication for power distributed resource heterogeneous communication access devices.
[0050] Additional aspects and advantages of the present invention will be set forth in the following description, and in part will be obvious from the description, or may be learned by practice of the present invention. Additionally, the various aspects and advantages of the present invention may be realized and obtained by the methods and combinations particularly pointed out in the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a schematic flowchart of the method according to the first embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0053] It should be understood that the step numbers used in the text are only for convenient description and do not limit the execution order of the steps.
[0054] It should be understood that the terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.
[0055] The terms "comprising" and "including" indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations.
[0056] The term "and / or" refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0057] Embodiment 1:
[0058] To solve the problems existing in the prior art, this embodiment proposes a heterogeneous communication access distributed identity authentication method that utilizes blockchain technology and physical unclonable functions (PUFs) and is applied to the distributed resource heterogeneous access scenario in the power system. First, considering the management problem of the challenge-response pair (CRP) library, a dynamic extension of the CRP library is adopted, and new challenges are derived using a hash chain to form an irreversible chain structure. Only a small amount of core CRPs need to be pre-stored for initialization, which can reduce resource consumption, eliminate the management pressure of the CRP library, and thus obtain the ability to resist replay attacks, generally balancing security and sustainability. And considering that the core of identity authentication is the stability of the PUF response, the response noise is processed by integrating error correction coding, SecureSketch, and Fuzzy Extractor, allowing correct comparison under a certain error, ensuring that the PUF response can be used as a key seed to generate a stable encryption key, and enhancing the robustness and privacy of response verification. Considering reducing the data disclosure of distributed identity authentication, in combination with zero-knowledge proof under the condition of resource-constrained devices, a lightweight ZKP protocol with high computational efficiency and small proof volume and a nested security design of PUF-ZKP are adopted, deeply combining the physical unclonability of PUF and the zero-knowledge property of ZKP to form a three-layer protection of the physical layer, cryptographic layer, and protocol layer. The PUF function is used to block physical cloning, the ZKP proof is used to hide sensitive data, and the dynamic challenge chain is used to resist replay attacks. The nested security mechanism has the protection capabilities of anti-physical cloning, anti-modeling attacks, and side-channel protection. It has high resource utilization efficiency, deeply guarantees security, and can be flexibly extended, supporting batch proof and hybrid authentication modes to adapt to different scenario requirements.
[0059] See Figure 1, this embodiment provides a heterogeneous communication access distributed identity authentication method, which specifically includes the following steps:
[0060] S100. Initialize. The heterogeneous communication access node generates a node root key pair bound to the PUF and establishes a trust anchor. This step specifically includes:
[0061] S101. Construct a dynamically extended CRP library. Generate a challenge in the dynamically extended CRP library using a hash chain. The heterogeneous communication access node randomly selects any challenge C in the dynamically extended CRP library i , and uses the PUF (Physical Unclonable Function) to calculate and generate a random response R i , and uses an error correction code to generate a check information E(R i ).
[0062] S102. Based on the generated check information E(R i ), generate auxiliary data S = SS.Gen(R i ) through the secure sketch algorithm.
[0063] S103. Based on the generated random response R i and the auxiliary data, use a fuzzy extractor to generate a key K i = HKDF(R i , Salt), and use K i as the stable node root private key Sk_root, where Salt is a random salt value stored on the chain (to prevent rainbow table attacks). After that, destroy the original random response R i , and do not store the original random response R i .
[0064] S103. Based on the node root private key SK_root, generate the corresponding node root public key PK_root through an asymmetric key algorithm. After confirming the correctness of the key generation, mark it as the trust anchor of the corresponding heterogeneous communication access node and prepare to distribute it to the verifier. The node device generates the current timestamp t req , and calculates the dynamic hash value H(t req || K i ).
[0065] S104. Construct a registration message:
[0066] Req = {C i , E(R i ), S, t req , H(t req || K i ), Nonce, Sign sk};
[0067] Apply to write the registration contract, use the random number Nonce (such as 16 bytes) + timestamp window hybrid scheme to prevent replay attacks, and enhance security by combining signatures. Use the node root private key SK_root to sign the message with ECDSA (Elliptic Curve Digital Signature Algorithm) to ensure the integrity and authenticity of the message.
[0068] S105. Update the CRP library after authentication, C i+1 = H(C i ||K i ), where H is a collision-resistant hash function, making the challenge sequence unpredictable and evolving unidirectionally, blocking the continuous acquisition of CRP.
[0069] S200. The distributed device initiates identity registration to the heterogeneous communication access node, generates a registration certificate through the node root key pair bound by PUF and returns it to the corresponding device; this step specifically includes:
[0070] S201. The distributed device submits device identity information (such as the unique serial number Device_ID) to the heterogeneous communication access node, and the heterogeneous communication access node verifies the freshness of the timestamp to prevent replay attacks.
[0071] S202. The heterogeneous communication access node randomly selects any challenge C j from the CRP library, calculates and generates a random response R j using PUF, generates check information E(R j ) using an error-correcting code, generates auxiliary data S = SS.Gen(R j ) through the secure sketch algorithm, generates a key K j = HKDF(R j , Salt) using a fuzzy extractor, takes K j as the stable device root private key SK j , where Salt is a randomly stored salt value on the chain (to prevent rainbow table attacks), and destroys the original random response R j , the original random response R j is not stored, and at the same time generates the corresponding device public key PK j .
[0072] S203. The heterogeneous communication access node constructs a Token including device identity information Device_ID, the hash value of the device private key H(SK j ), and the current timestamp t req , and digitally signs the constructed Token with the node root private key SK_root Sign sk to generate a registration certificate (Cert_Device):
[0073] Cert Dev i ce = Sign sk {Device_ID, H(SK j ), t req};
[0074] S204. Return the registration certificate to the device through a secure channel for subsequent interactions (such as data upload or service access). After authentication, update the CRP library, C j = H(C j ||R j ), where R j is the current response, and H is a collision-resistant hash function, making the challenge sequence unpredictable and evolving unidirectionally, blocking the continuous collection of CRP.
[0075] S300. Based on the blockchain, through a closed-loop process of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification, and key update, achieve the identity authentication of distributed devices and heterogeneous communication access nodes through the nested security of PUF and ZKP. This step specifically includes:
[0076] S301. In the initialization stage of the blockchain network, generate the proving key (ProvingKey, PK) and verification key (Verification Key, VK) through a multi-party computation (MPC) ceremony and store them on the chain.
[0077] S302. When the heterogeneous communication access node receives an identity authentication request, obtain the registration certificate content from the chain, define the circuit
[0078]
[0079] and generate a proof π i :
[0080] π i ←Prove(PK, (C i ), (K i ));
[0081] S303. Perform ZKP verification (off-chain execution): Input the verification key VK, challenge C i , proof π i , and call the verification function:
[0082] Verify(VK, C i , π i ) = 1
[0083] Perform off-chain verification to check if the calculation result is 1, and only upload the result hash and verification success flag to the chain.
[0084] S304. Construct an authentication request message:
[0085] R eq ={Device_ID, C j , t req , π i , Nonce};
[0086] Wherein, t req is the current timestamp, and a random number Nonce (such as 16 bytes) is added to prevent replay attacks. Sign the message using the device root private key.
[0087] S305. Conduct multi-node consensus and upload the authentication result, specifically including:
[0088] Proposal stage: The first authentication node broadcasts the verification result (passed / rejected) to other authentication nodes.
[0089] Preparation stage: Each authentication node independently verifies the request message, signature, timestamp, and proof calculation. The authentication node independently verifies the ZKP result and returns a signature confirmation.
[0090] Commit stage: After collecting 2f + 1 valid confirmations (f is the maximum number of Byzantine nodes), each authentication node writes to the local ledger, generates an authentication block, and writes it to the chain.
[0091] Result feedback: If the authentication is passed, the smart contract generates a short-term access token (Token), including:
[0092] Token = {Device_ID, H(SK j ), t req , Sign sk}
[0093] The Token is returned to the device through a secure channel for subsequent interactions (such as data upload or service access).
[0094] In one embodiment, considering improving the real-time performance, network efficiency, and flexibility of distributed authentication, the authentication logic contract and trust score contract are deployed using blockchain technology, a network trust evaluation system is constructed, dynamic challenge chains and trust model updates are adopted, the logs are regularly audited by regulatory nodes, and threshold signatures are used to limit the power of a single node to prevent node collusion and achieve forward security.
[0095] Specifically, before executing step S300, a trustworthiness pre-check is also performed, specifically including:
[0096] After the heterogeneous communication access node receives the authentication request initiated by the distributed device, it calls the smart contract to query the current comprehensive trust degree T of the corresponding device according to the device identity information. The smart contract queries according to the Device_ID. current The historical authentication records and the last active time t last ;
[0097] Among them, the current comprehensive trust degree is calculated through the trust attenuation value, the last active timestamp, the current timestamp and the preset trust attenuation rate; the calculation formula of the trust attenuation value is as follows:
[0098]
[0099] Among them, T time is the trust attenuation value, T last is the comprehensive trust degree of the last active time, β is the trust attenuation rate, and t now is the current timestamp.
[0100] The authentication behavior score is calculated by obtaining the number of successful / failed times in the most recent N times through the sliding window of the historical authentication records:
[0101]
[0102] The current comprehensive trust degree is calculated according to the authentication behavior score and the trust attenuation value. The comprehensive trust degree calculation formula is as follows:
[0103] T current =α·S history +(1-α)·T time ;
[0104] Among them, α is the preset weight ratio.
[0105] A200. According to the set global trust threshold T min and the current comprehensive trust degree T current , perform device authentication risk decision-making.
[0106] As a preferred implementation manner, the steps of performing device authentication risk decision-making include:
[0107] A201. Compare whether the current comprehensive trust degree is with the set global trust threshold;
[0108] If the current comprehensive trust degree T current is less than the set global trust threshold T min , immediately reject the identity authentication and trigger an alarm, and record it in the blockchain audit log;
[0109] If the current comprehensive trust degree T current is greater than or equal to the set global trust threshold Tmin , the corresponding device and heterogeneous communication access node are requested to provide identity proofs.
[0110] A202. When the identity authentication of the corresponding device is successful, the current comprehensive trust value is increased according to a preset ratio:
[0111] T new = T current + γ·(1 - T current );
[0112] γ is the preset increase ratio. Reasonably setting γ can avoid the trust value from saturating too quickly. T new is used as the historical trust value when the corresponding device conducts identity authentication next time.
[0113] When the identity authentication of the corresponding device fails, the current comprehensive trust value is decreased according to a preset ratio:
[0114] T new = T current - λ·(1 - T current );
[0115] λ is the preset decrease ratio. Reasonably setting λ can quickly reduce the permissions of suspicious devices. T new is used as the historical trust value when the corresponding device conducts identity authentication next time.
[0116] A203. Record abnormal events, and write the details of authentication failure (such as time, challenge value, deviation value) into the on-chain audit log for the regulatory node to analyze. If a private key leakage is detected (such as logging in from an abnormal geographical location), the regulatory node can initiate an emergency revocation proposal to freeze the device and reset the PUF-associated identity.
[0117] After each authentication, update the last active time t last of the device to the current time to ensure that subsequent trust value calculations are based on the latest status.
[0118] Based on the above embodiments, this solution takes into account reducing data disclosure in distributed identity authentication, avoiding exposing its responses or keys in an insecure environment when the PUF is applied across devices, and combines zero-knowledge proofs under resource-constrained device conditions. It adopts a lightweight ZKP protocol with high computational efficiency and small proof volume and a nested security design of PUF-ZKP, deeply combines the physical unclonability of the PUF with the zero-knowledge property of ZKP, forms a three-layer protection of the physical layer, cryptographic layer, and protocol layer, uses the PUF function to block physical cloning, ZKP proofs to hide sensitive data, and dynamic challenge chains to resist replay attacks. The nested security mechanism has the protection capabilities of anti-physical cloning, anti-modeling attacks, and side-channel protection. It has high resource utilization efficiency, deeply guarantees security, and can be flexibly extended to support batch proof and hybrid authentication modes to adapt to different scenario requirements.
[0119] Considering improving the real-time performance, network efficiency, and flexibility of distributed authentication, blockchain technology is used to deploy authentication logic contracts and trust scoring contracts, build a network trust evaluation system, adopt dynamic challenge chains and trust model updates, regularly audit logs through regulatory nodes, and use threshold signatures to limit the power of a single node to prevent node collusion and achieve forward security. High-frequency devices can cache short-term credentials to reduce the query frequency on the chain. At the same time, PUF verification and hash comparison are performed off-chain, and only the digest and signature are uploaded to the chain, reducing on-chain calculations and alleviating the network burden. In addition, multiple device requests are supported to be packaged into a single transaction to reduce consensus overhead.
[0120] Embodiment 2:
[0121] This embodiment provides a heterogeneous communication access distributed identity authentication system, including:
[0122] A trust anchor distribution module, used to build a dynamically extensible CRP library, generate challenges using a hash chain in the dynamically extensible CRP library. The heterogeneous communication access node randomly selects any challenge in the dynamically extensible CRP library, generates a node root key pair bound by PUF using the physically unclonable function of PUF, and establishes a trust anchor; this module is used to implement the function of step S100 in Embodiment 1 above and will not be elaborated here.
[0123] A registration certificate generation module, used to generate a registration certificate and return it to the corresponding device when a distributed device initiates identity registration to a heterogeneous communication access node through the node root key pair bound by PUF; this module is used to implement the function of step S100 in Embodiment 1 above and will not be elaborated here.
[0124] A distributed identity authentication module, based on blockchain, conducts identity authentication between a distributed device and a heterogeneous communication access node through a process of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification, and key update. This module is used to implement the function of step S100 in Embodiment 1 above and will not be elaborated here.
[0125] Embodiment 3:
[0126] This embodiment proposes an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the heterogeneous communication access distributed identity authentication method described in any embodiment of the present invention.
[0127] Embodiment 4:
[0128] This embodiment proposes a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the heterogeneous communication access distributed identity authentication method described in any embodiment of the present invention.
[0129] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent the cases of A existing alone, A and B existing simultaneously, and B existing alone. Where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0130] Those of ordinary skill in the art can realize that the various units and algorithm steps described in the embodiments disclosed herein can be implemented by a combination of electronic hardware, computer software, and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.
[0131] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0132] In several embodiments provided by the present application, if any function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (hereinafter referred to as ROMs), random access memories (hereinafter referred to as RAMs), magnetic disks, or optical discs that can store program codes.
[0133] The above are only embodiments of the present invention, and thus do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A distributed identity authentication method for heterogeneous communication access, characterized in that: The following steps are involved: Build a dynamically extended CRP library, use the hash chain to generate challenges in the dynamically extended CRP library, and the heterogeneous communication access node randomly selects any challenge in the dynamically extended CRP library, uses the PUF physical unclonable function to generate a PUF-bound node root key pair, and establishes a trust anchor; The distributed device initiates identity registration to the heterogeneous communication access node, generates a registration certificate through the node root key pair bound to the PUF and returns it to the corresponding device; Based on blockchain, identity authentication of distributed devices and heterogeneous communication access nodes is performed through the process of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification and key update.
2. A method for distributed identity authentication for heterogeneous communication access according to claim 1, characterized in that: The step of using the PUF physical unclonable function to generate a PUF-bound node root key pair and establishing a trust anchor includes: The heterogeneous communication access node randomly selects any challenge in the dynamically expanded CRP library, generates a random response using the PUF physical unclonable function calculation, and generates verification information using the error correction code; Based on the generated verification information, auxiliary data is generated through a secure sketch algorithm; Based on the generated random response and auxiliary data and the random salt value stored on the chain, a fuzzy extractor is used to generate a key as the node root private key, and the random response is subsequently destroyed; Based on the node root private key, the corresponding node root public key is generated through an asymmetric key algorithm as the trust anchor of the corresponding heterogeneous communication access node.
3. A method for distributed identity authentication for heterogeneous communication access according to claim 1, characterized in that: The steps of the distributed device initiating identity registration to the heterogeneous communication access node, generating a registration certificate through the root key pair bound to the PUF and returning the certificate to the corresponding device include: The distributed device submits the device identity information to the heterogeneous communication access node, and the heterogeneous communication access node receives and verifies the freshness of the timestamp; The heterogeneous communication access node randomly selects any challenge in the dynamically expanded CRP library and uses the PUF physical unclonable function to generate a PUF-bound device root key pair; The heterogeneous communication access node constructs a token including the device identity information, the device private key hash value, and the current timestamp, and digitally signs the constructed token with the node root private key, generates a registration certificate and returns it to the corresponding device.
4. A method for distributed identity authentication for heterogeneous communication access according to claim 1, characterized in that: The steps of performing identity authentication between distributed devices and heterogeneous communication access nodes based on blockchain through the process of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification and key update include: The blockchain network generates proof keys and verification keys through multi-party computing and stores them on the chain; When the heterogeneous communication access node receives the identity authentication request, it obtains the registration certificate content from the chain and generates a certificate using the Groth16 protocol; Enter the verification key, the selected challenge, and the generated proof to perform zero-knowledge ZKP verification and upload the verification result to the chain; Construct an authentication request message, which includes the device identity information, the selected challenge, the current timestamp, the certificate, and the random number, and sign the authentication request message using the corresponding device root private key; Multi-node consensus and authentication results are uploaded to the chain. If the authentication is successful, the smart contract generates a short-term access token and returns it to the corresponding device.
5. A method for distributed identity authentication for heterogeneous communication access according to claim 1, characterized in that: Before performing identity authentication between distributed devices and heterogeneous communication access nodes, a trust pre-check is also performed, including: After receiving the authentication request initiated by the distributed device, the heterogeneous communication access node calls the smart contract to query the current trust value, historical authentication records and last active time of the corresponding device according to the device identity information; Among them, the current comprehensive trust is calculated by the trust decay value, the last active timestamp, the current timestamp and the preset trust decay rate; Evaluate certification behavior through historical certification records and obtain certification behavior scores; Calculate the current comprehensive trust based on the authentication behavior score and the current trust value; Make device authentication risk decisions based on the set global trust threshold and the current comprehensive trust level.
6. A method for distributed identity authentication for heterogeneous communication access according to claim 5, characterized in that: The steps of making a device authentication risk decision include: Compare the current comprehensive trust with the set global trust threshold; If the current comprehensive trust is less than the set global trust threshold, the identity authentication will be rejected immediately and an alarm will be triggered, which will be recorded in the blockchain audit log; If the current comprehensive trust is greater than or equal to the set global trust threshold, the corresponding device and heterogeneous communication access node are requested to provide identity proof.
7. A method for distributed identity authentication for heterogeneous communication access according to claim 5, characterized in that: It also includes a certification behavior feedback mechanism, including: When the corresponding device successfully authenticates itself, the current comprehensive trust is increased according to a preset ratio and used as the historical trust value for the next authentication of the corresponding device; When the corresponding device fails to perform identity authentication, the current comprehensive trust level is reduced according to a preset ratio and used as the historical trust value for the next identity authentication of the corresponding device.
8. A distributed identity authentication system for heterogeneous communication access, characterized in that: include: The trust anchor distribution module is used to build a dynamically extended CRP library, generate challenges using a hash chain in the dynamically extended CRP library, and the heterogeneous communication access node randomly selects any challenge in the dynamically extended CRP library, generates a PUF-bound node root key pair using the PUF physical unclonable function, and establishes a trust anchor; The registration certificate generation module is used to initiate identity registration from a distributed device to a heterogeneous communication access node, generate a registration certificate through the node root key pair bound to the PUF, and return it to the corresponding device; The distributed identity authentication module, based on blockchain, performs identity authentication between distributed devices and heterogeneous communication access nodes through the process of dynamic challenge generation, PUF response reading, zero-knowledge ZKP proof generation, on-chain verification and key update.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the distributed identity authentication method for heterogeneous communication access is implemented as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the distributed identity authentication method for heterogeneous communication access as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Multi-layer blockchain cross-domain authentication method in Internet of Things application scene
CN112637189A
Multi-layer blockchain cross-domain authentication methods in IoT application scenarios
CN112637189B
Internet-of-Things equipment unified authentication method and system based on block chain and PUF (Physical Unclonable Function)
CN113708935A
Block chain authentication access implementation method based on terminal encryption transmission gateway
CN115333757A
Distributed device identity authentication and access control method and system based on block chain
CN119363318A