Lightweight Internet of Things identity authentication method based on bitter fish optimization algorithm and Hash chain

By introducing a dual-stage Kuyu optimization algorithm and dynamic hash chain nodes in the Internet of Things identity authentication, the problems of insufficient authentication parameter optimization capabilities and static hash chain updates in the existing technology are solved, and efficient and secure Internet of Things identity authentication is achieved.

CN120185892AActive Publication Date: 2025-06-20ANYANG NOBO ELECTRONIC TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510349088.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-20
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

The existing IoT identity authentication technology is difficult to achieve a dynamic balance between authentication efficiency and energy consumption under resource constraints, and the hash chain mechanism is updated statically, lacking dynamic perturbation strategies, making it difficult to effectively defend against replay attacks and forgery.

Method used

The lightweight IoT identity authentication method based on Kuyu optimization algorithm and hash chain is adopted, and the authentication parameters are dynamically optimized through the dual-stage Kuyu optimization algorithm, and dynamic hash chain nodes are generated in combination with the device status and network environment to enhance the security and efficiency of authentication.

Benefits of technology

It realizes lightweight, high efficiency and high reliability of the authentication process, improves the authentication success rate under low power state, improves the system's adaptability and authentication availability, and effectively defends against replay attacks and forgery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185892A_ABST
    Figure CN120185892A_ABST
Patent Text Reader

Abstract

The invention discloses a lightweight Internet of Things identity authentication method based on a bitter fish optimization algorithm and a Hash chain. The lightweight Internet of Things identity authentication method comprises the following steps: S1, generating an initial authentication parameter set; s2, generating an initial hash chain node by using the initial authentication parameter set; s3, performing dynamic optimization on the authentication parameters by adopting a two-stage bitter fish optimization algorithm; s4, optimized authentication parameters are obtained in the first stage; s5, updating the new Hash chain node into the authentication Hash chain; s6, sending to an Internet of Things authentication server through a wireless communication network; s7, after receiving the authentication request message, the Internet of Things authentication server verifies the authentication request message according to a preset authentication rule and generates a corresponding authentication response message; and S8, after receiving the authentication response message, the Internet of Things terminal equipment updates a local authentication state according to a verification result in the authentication response message, synchronously updates a local authentication hash chain node, and records an authentication record of the authentication process. According to the invention, light weight, high efficiency and high reliability of the authentication process are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a lightweight Internet of Things identity authentication method based on bitter fish optimization algorithm and hash chain. Background Art

[0002] With the wide deployment of Internet of Things technology, the number of terminal devices has increased exponentially, covering multiple application scenarios such as smart home, smart healthcare, industrial automation, and smart city. Internet of Things devices usually have the characteristics of being power consumption sensitive, having limited computing resources, and weak communication capabilities, resulting in the difficulty of directly applying traditional information security mechanisms to the field of Internet of Things identity authentication. In the existing technology system, mainstream identity authentication methods mostly rely on authentication protocols based on public key cryptography. Although they have high security, they have high computational complexity, high energy consumption, and high requirements for device processing capabilities, making it difficult to meet the actual application requirements of lightweight and low-power Internet of Things terminal devices.

[0003] On the other hand, in order to enhance authentication security, some studies have introduced hash chain mechanisms to prevent replay attacks and authentication information tampering. However, in most existing solutions, the construction method of the hash chain is relatively static and fails to dynamically adjust authentication parameters according to changes in device status and network environment, resulting in poor system adaptability and insufficient anti-attack capabilities. In addition, the existing technology does not fully consider the heterogeneity and resource constraints of devices during the generation and transmission of authentication parameters, and the authentication mechanism cannot be flexibly optimized according to actual computing resources, remaining power, network load factors, thus exacerbating resource consumption and affecting the authentication response efficiency.

[0004] At the same time, although some lightweight authentication mechanisms have made certain simplifications in computational complexity, they often sacrifice authentication security and fail to balance authentication efficiency and security. In addition, fixed or long update periods of authentication parameters also make the authentication process vulnerable to replay and forgery attacks, lacking a dynamic adjustment and optimization mechanism, and it is difficult to achieve continuous and reliable identity verification in a changing Internet of Things environment.

[0005] In summary, the existing Internet of Things identity authentication technologies generally have the following problems: First, they lack the ability to adaptively optimize authentication parameters under resource-constrained conditions and it is difficult to achieve a dynamic balance between authentication efficiency and energy consumption; second, the hash chain mechanism is updated statically and lacks a dynamic perturbation strategy that combines device status and environmental characteristics, making it difficult to effectively defend against replay attacks and forgery behaviors. Therefore, there is an urgent need to propose an identity authentication method that combines authentication security and computational efficiency, takes into account the characteristics of dynamics and lightweight, to meet the efficient, secure, and sustainable authentication requirements in a large-scale distributed Internet of Things environment. Summary of the Invention

[0006] An object of the present invention is to propose a lightweight Internet of Things identity authentication method based on the bitter fish optimization algorithm and the hash chain. The present invention realizes the lightweight, high efficiency and high reliability of the authentication process.

[0007] A lightweight Internet of Things identity authentication method based on the bitter fish optimization algorithm and the hash chain according to an embodiment of the present invention includes the following steps:

[0008] S1. Initialize the authentication environment of the Internet of Things system and generate an initial set of authentication parameters;

[0009] S2. Generate initial hash chain nodes using the initial set of authentication parameters according to a preset hash function;

[0010] S3. Take the initial set of authentication parameters, the current network environment and the resource status of the Internet of Things terminal device as inputs, and use the two-stage bitter fish optimization algorithm to dynamically optimize the authentication parameters. In the first stage, perform a global search to determine the optimization interval of the authentication parameters;

[0011] S4. In the second stage, perform a local fine-tuning within the optimization interval to obtain the optimized authentication parameters;

[0012] S5. Use the initial hash chain nodes, the optimized authentication parameters and the newly collected current timestamp to generate new hash chain nodes through a preset hash function, and update the new hash chain nodes to the authentication hash chain;

[0013] S6. Uniformly encapsulate the updated authentication hash chain and the current timestamp into an authentication request message, and send it to the Internet of Things authentication server through a wireless communication network;

[0014] S7. After receiving the authentication request message, the Internet of Things authentication server verifies the authentication request message according to a preset authentication rule and generates a corresponding authentication response message;

[0015] S8. After receiving the authentication response message, the Internet of Things terminal device updates the local authentication status according to the verification result in the authentication response message, synchronously updates the local authentication hash chain nodes, and records the authentication record of this authentication process.

[0016] Optionally, S1 includes the following steps:

[0017] S11. Collect the basic identification information of the Internet of Things terminal device and construct a device identity identification set ID dev ;

[0018] S12. Allocate a shared key corresponding to its unique identifier for each Internet of Things terminal device and construct a shared key set K shared ;

[0019] S13. Initialize and set the current system timestamp set T0 for IoT identity authentication, which is used to identify the initial authentication moment;

[0020] S14. Combine the device identity identifier set ID dev and the shared key set K shared with the system timestamp set T0 to construct the initial authentication parameter set P0:

[0021]

[0022] where, represents the initial authentication parameter vector of the i-th IoT terminal device, which includes the unique identifier of the IoT terminal device, the shared key, and the current timestamp. id i represents the unique identifier of the i-th IoT terminal device, and k i represents the shared key corresponding to the IoT terminal device id i , represents the current system timestamp of the IoT terminal device id i at the authentication initialization stage, and N is the number of IoT terminal devices participating in identity authentication in the system.

[0023] Optionally, the S2 includes the following steps:

[0024] S21. According to the initial authentication parameter set P0, use the lightweight optimized hash function LHash(.) to perform hash mapping on the initial authentication parameter vector of each IoT terminal device to generate the initial hash chain node set HC0:

[0025]

[0026] where, is the initial hash chain node of the i-th IoT terminal device, and γ i represents the exclusive perturbation factor of the IoT terminal device, which forms dynamic variation through circular left shift operation <<< combined with the current timestamp, enabling the initial hash chain node to have dynamic security under lightweight conditions and improving the resistance of the hash chain node to forgery attacks;

[0027] S22. Calculate the exclusive dynamic perturbation factor γ of the IoT terminal device i :

[0028]

[0029] where, E res,i is the current remaining power of the i-th IoT terminal device, and E max,i is the maximum battery capacity of this IoT terminal device, and C load,iLet \(L_i\) be the current network load status of the \(i\)-th Internet of Things (IoT) terminal device. The perturbation factor is adjusted in real time according to the network environment through an exponential function. \(\psi\) and \(\varphi\) are the weights used to adjust the energy state and network state in the perturbation factor respectively, \(\alpha\) is used to dynamically adjust the influence degree of the remaining battery power of the device on the perturbation factor, and \(\beta\) is used to control the sensitivity of the network load status to the perturbation factor, so as to optimize and balance the computational amount and communication overhead in the process of generating hash chain nodes in the scenario of limited IoT resources.

[0030] Optionally, step S3 includes the following steps:

[0031] S31. According to the exclusive dynamic perturbation factor \(\gamma\) of the IoT terminal device i , taking the initial authentication parameter set \(P_0\), the current network environment status and the resource status of the IoT terminal device as inputs, construct an exclusive dynamic perturbation factor optimization model \(F\) for the IoT terminal device γ :

[0032] \(F\) γ = w1·T γ,i + w2·E γ,i + w3·R γ,i ;

[0033] Where, \(T\) γ,i represents the computational delay caused by the perturbation factor \(\gamma\) i of the \(i\)-th IoT terminal device during the hash chain calculation and identity authentication process, \(E\) γ,i represents the additional energy consumption generated by the perturbation factor \(\gamma\) i of the \(i\)-th IoT terminal device, \(R\) γ,i represents the security risk index corresponding to the perturbation factor \(\gamma\) i of the \(i\)-th IoT terminal device, and w1, w2, w3 are the optimization weights set by the IoT authentication system according to the actual application scenario requirements;

[0034] S32. Based on the global search stage of the two-stage bitter fish optimization algorithm, taking the exclusive dynamic perturbation factor optimization model \(F\) γ of the IoT terminal device as the fitness function, perform a global search within the preset perturbation factor parameter space, and update the position of the bitter fish individual according to the search fitness value:

[0035]

[0036] Where, represents the perturbation factor of the \(i\)-th bitter fish individual at the \(t\)-th iteration, represents the perturbation factor of the \(i\)-th bitter fish individual at the \((t + 1)\)-th iteration, representing a candidate solution for the exclusive perturbation factor of the IoT terminal device, Denote the global optimal perturbation factor after the \(t\)-th iteration, representing the best perturbation factor that takes into account the computational delay, energy consumption, and security performance in the current global search process. \(\delta\) and \(\eta\) are adaptive adjustment coefficients, which dynamically adjust the search step size of bitter fish individuals according to the ratio of the current remaining power of the device to the maximum battery capacity, \(S\) γ is the global search step size reference value, is the bitter fish individual fitness gradient learning factor:

[0037]

[0038] where, is the optimization model of the exclusive dynamic perturbation factor for the Internet of Things terminal device at the \(t\)-th iteration, are the maximum and minimum fitness values of all bitter fish individual perturbation factors in the \(t\)-th iteration respectively, and \(\varepsilon\) is a very small positive number used to avoid the denominator in the formula being zero;

[0039] S33. Determine the perturbation factor \(\gamma\) based on the global search result in step S32 i The preliminary optimization interval of \([\gamma\) i,min , \(\gamma\) i,max .

[0040] Optionally, the S4 includes the following steps:

[0041] S41. Construct a local authentication parameter fine optimization function \(F\) i,min , \(\gamma\) i,max within the perturbation factor optimization interval to guide the fine adjustment of the perturbation factor in the local search stage: local where,

[0042]

[0043] where, represents the perturbation factor of the \(j\)-th local bitter fish individual in the \(t\)-th iteration, \(\theta\) i is the perturbation sensitivity coefficient of the Internet of Things terminal device, and \(\omega_4\), \(\omega_5\) are weight coefficients for balancing the degree of deviation and the gradient perturbation response, represents the perturbation factor of the local bitter fish individual after the \(t\)-th iteration;

[0044] S42. Initialize the local perturbation factor candidate set around the global optimal perturbation factor within the perturbation factor optimization interval

[0045]

[0046] where, is the candidate value of the \(j\)-th local perturbation factor of the \(i\)-th Internet of Things terminal device when representing the initialization of local search, \(\delta\) jis the perturbation offset coefficient, ρ is the offset range control parameter, γ i,max and γ i,min respectively represent the upper and lower bounds of the perturbation factor search interval of the i-th Internet of Things terminal device, which are determined by the global search stage;

[0047] S43. For each perturbation factor of each local bitter fish individual in the local perturbation factor candidate set perform local fine update: where,

[0048]

[0049] represents the perturbation factor of the j-th local bitter fish individual in the (t + 1)-th iteration, α1 is the local micro-step coefficient, is the local dynamic adjustment factor: where, κ is the network load adjustment factor, C

[0050]

[0051] is the current network load status of the i-th Internet of Things terminal device, which is used to dynamically adjust the perturbation sensitivity; load,i

[0052] S44. Repeat the steps of S42 - S43 until the iteration converges, and select the perturbation factor with the smallest local authentication parameter fine optimization function F from the local perturbation factor candidate setas the final optimization result: local where,

[0053]

[0054] represents the perturbation factor of the local bitter fish individual obtained after the T-th round of local optimization, is the optimal perturbation factor for the final authentication of the i-th Internet of Things terminal device;

[0055] S45. Substitute the optimal perturbation factor for the final authentication back into the lightweight hash function LHash(.), and combine the device authentication parameters id i i k i to generate the optimized authentication parameters

[0056]

[0057]

[0057] Optionally, the S5 includes the following steps:

[0058] S51. Collect the current system timestamp and combine it with the optimized authentication parameters and the optimized perturbation factor together constitute the input vector for the current authentication phase

[0059] S52. Based on the input vector for the current authentication phase use the lightweight hash chain constructor LHash(.) enhanced by dynamic perturbation to generate new optimized authentication parameters

[0060]

[0061] where is the new optimized authentication parameter, representing the new optimized hash chain node, represents the bitwise exclusive OR operation, is the dynamic perturbation mask generated in the current authentication round of the i-th device:

[0062]

[0063] where Hash(.) is the standard one-way hash function, <<< is the cyclic left shift operation, λ1 is the system-set perturbation displacement control constant, and mod is the modulo operator;

[0064] The dynamic perturbation mask enhances the unpredictability of the optimized authentication parameter through the coupling of the perturbation factor and the timestamp, ensuring that the generated optimized authentication parameter has dynamics and anti-replay capabilities, meeting the lightweight security computing requirements of IoT terminal devices;

[0065] S53. Add the new optimized authentication parameter generated in the current authentication phase to the authentication hash chain structure HC i maintained locally by the device to construct a complete authentication chain:

[0066]

[0067] where HC i represents the authentication hash chain currently maintained by the i-th IoT terminal device, is the initial new optimized authentication parameter, representing the initial hash chain node.

[0068] Optionally, the S7 includes the following steps:

[0069] S71. The IoT authentication server receives the authentication request message sent by the IoT terminal device, and extracts the device unique identifier id i in the authentication request message, the new optimized hash chain node the perturbation factor and the current timestamp Construct the authentication vector to be verified

[0070] S72. According to the authentication hash chain history record maintained by the authentication server Perform continuity verification on the new optimized hash chain node Calculate the expected hash chain node on the server side And make a consistency comparison with the received hash chain node:

[0071]

[0072] If satisfied Then the hash chain continuity is considered legal;

[0073] S73. Verify the legitimacy of the perturbation factor Based on the device resource status, historical perturbation behavior and authentication phase strategy, determine the legitimacy of the perturbation factor in combination with the following rules:

[0074] A legal perturbation factor is expressed as if the perturbation factor Meets any of the following all conditions:

[0075] The current remaining battery power ratio And the network load C load,i < 0.7;

[0076] The deviation from the previous perturbation factor recorded by the server does not exceed the threshold, that is

[0077] The perturbation factor Belongs to the accepted perturbation factor range [γ min , γ max ;

[0078] An illegal perturbation factor is expressed as if the perturbation factor Simultaneously has any of the following abnormal situations:

[0079] The current remaining battery power ratio And the network load C load,i > 0.9;

[0080] The deviation from the previous perturbation factor recorded by the server exceeds twice the threshold, that is

[0081] The perturbation factor Exceeds the tolerance interval of the perturbation factor dynamically maintained by the authentication server;

[0082] S74. If the authentication request simultaneously satisfies the verification of the hash chain continuity and the determination of the legality of the perturbation factor, the server generates a response message indicating successful authentication; otherwise, it generates a response message indicating failed authentication and indicates the specific reasons for the failed authentication, which include hash chain breakage and illegal perturbation factor.

[0083] The beneficial effects of the present invention are as follows:

[0084] (1) In the identity authentication process of the present invention, a two-stage bitter fish optimization algorithm is introduced, which is divided into two stages: global search and local fine adjustment. The global stage can quickly identify the optimization interval most suitable for the authentication perturbation parameters, while the local stage combines the current remaining power and network load status information of the device to finely adjust the perturbation parameters dynamically, enabling each device to obtain the optimal authentication parameters under its resource status, thereby ensuring that the authentication process is both secure and efficient. Tests conducted on low-power IoT terminals through actual deployment show that compared with traditional fixed-parameter authentication methods, the present invention can improve the authentication success rate in low-power states, enhancing the system's adaptability and authentication availability.

[0085] (2) The present invention makes a lightweight dynamic improvement to the traditional static hash chain structure, binds the device-specific authentication perturbation factor to the current time state, and through the introduction of a perturbation mask, makes each hash chain node generated during each authentication have time sensitivity and device individual differences. The authentication mechanism effectively improves the unpredictability and immutability of authentication data during transmission and storage. In the face of common security threats such as replay attacks and forgery attacks, the authentication mechanism demonstrates stronger resistance.

[0086] (3) The present invention designs a dual-verification mechanism based on the continuity of hash chain nodes and the legality of authentication perturbation factors on the authentication server side, which is different from the traditional method of only verifying node consistency. The server not only verifies whether the authentication node forms a continuous chain with historical nodes, but also comprehensively judges the device power level, the change range of historical perturbation parameters, and the current network load situation to further confirm whether the authentication request is within a reasonable behavior range. Through the dual-verification mechanism, the authentication server can effectively identify device abnormal behaviors and the risk of forged authentication parameters, improving the accuracy of authentication responses and the refinement of security defenses. Description of the Drawings

[0087] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings:

[0088] Figure 1 is a flowchart of a lightweight IoT identity authentication method based on the bitter fish optimization algorithm and hash chain proposed by the present invention. Detailed Embodiments

[0089] The present invention will now be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.

[0090] Reference Figure 1 , a lightweight Internet of Things identity authentication method based on the bitter fish optimization algorithm and hash chain, includes the following steps:

[0091] S1. Initialize the authentication environment of the Internet of Things system and generate an initial set of authentication parameters;

[0092] S2. Generate initial hash chain nodes according to a preset hash function using the initial set of authentication parameters;

[0093] S3. Take the initial set of authentication parameters, the current network environment, and the resource status of the Internet of Things terminal device as inputs, and use a two-stage bitter fish optimization algorithm to dynamically optimize the authentication parameters. In the first stage, perform a global search to determine the optimization interval of the authentication parameters;

[0094] S4. In the second stage, perform local fine-tuning within the optimization interval to obtain optimized authentication parameters;

[0095] S5. Use the initial hash chain nodes, the optimized authentication parameters, and the newly collected current timestamp to generate new hash chain nodes through a preset hash function, and update the new hash chain nodes to the authentication hash chain;

[0096] S6. Package the updated authentication hash chain and the current timestamp into an authentication request message and send it to the Internet of Things authentication server through a wireless communication network;

[0097] S7. After receiving the authentication request message, the Internet of Things authentication server verifies the authentication request message according to the preset authentication rules and generates a corresponding authentication response message;

[0098] S8. After receiving the authentication response message, the Internet of Things terminal device updates the local authentication status according to the verification result in the authentication response message, synchronously updates the local authentication hash chain nodes, and records the authentication record of this authentication process.

[0099] In this embodiment, S1 includes the following steps:

[0100] S11. Collect the basic identification information of the Internet of Things terminal device and construct a device identity identification set ID dev ;

[0101] S12. Allocate a shared key corresponding to the unique identifier for each Internet of Things terminal device and construct a shared key set K shared ;

[0102] S13. Initialize and set the current system timestamp set T0 for IoT identity authentication to identify the initial authentication moment;

[0103] S14. Combine the device identity identifier set ID dev , the shared key set K shared and the system timestamp set T0 to construct the initial authentication parameter set P0:

[0104]

[0105] Among them, represents the initial authentication parameter vector of the i-th IoT terminal device, including the unique identifier of the IoT terminal device, the shared key, and the current timestamp, id i represents the unique identifier of the i-th IoT terminal device, k i represents the shared key corresponding to the IoT terminal device id i , represents the current system timestamp of the IoT terminal device id i at the authentication initialization stage, and N is the number of IoT terminal devices participating in identity authentication in the system.

[0106] In this embodiment, S2 includes the following steps:

[0107] S21. According to the initial authentication parameter set P0, use the lightweight optimized hash function LHash(.) to perform hash mapping on the initial authentication parameter vector of each IoT terminal device to generate the initial hash chain node set HC0:

[0108]

[0109] Among them, is the initial hash chain node of the i-th IoT terminal device, γ i represents the device-specific perturbation factor of the IoT terminal device, which forms dynamic mutation through circular left shift operation <<< combined with the current timestamp, so that the initial hash chain node has dynamic security under lightweight conditions and improves the resistance of the hash chain node to forgery attacks;

[0110] S22. Calculate the device-specific dynamic perturbation factor γ of the IoT terminal device i :

[0111]

[0112] Among them, E res,i is the current remaining power of the i-th IoT terminal device, E max,i is the maximum battery capacity of this IoT terminal device, C load,iLet \(L_i\) be the current network load status of the \(i\)-th Internet of Things (IoT) terminal device. The perturbation factor is adjusted in real time according to the network environment through an exponential function. \(\psi\) and \(\varphi\) are the weights used to adjust the energy state and network state in the perturbation factor respectively, \(\alpha\) is used to dynamically adjust the influence degree of the remaining battery power of the device on the perturbation factor, and \(\beta\) is used to control the sensitivity of the network load status to the perturbation factor, so as to optimize and balance the computational amount and communication overhead in the process of generating hash chain nodes in the resource-constrained scenario of the Internet of Things.

[0113] In this embodiment, S3 includes the following steps:

[0114] S31. According to the exclusive dynamic perturbation factor \(\gamma\) of the IoT terminal device i , taking the initial authentication parameter set \(P_0\), the current network environment status and the resource status of the IoT terminal device as inputs, construct an exclusive dynamic perturbation factor optimization model \(F\) for the IoT terminal device γ :

[0115] \(F\) γ \(= w_1\cdot T\) γ,i \(+ w_2\cdot E\) γ,i \(+ w_3\cdot R\) γ,i ;

[0116] where, \(T\) γ,i represents the computational delay caused by the perturbation factor \(\gamma\) i in the process of hash chain calculation and identity authentication of the \(i\)-th IoT terminal device, \(E\) γ,i represents the additional energy consumption generated by the perturbation factor \(\gamma\) i of the \(i\)-th IoT terminal device, \(R\) γ,i represents the security risk index corresponding to the perturbation factor \(\gamma\) i of the \(i\)-th IoT terminal device, and \(w_1\), \(w_2\), \(w_3\) are optimization weights set by the IoT authentication system according to the actual application scenario requirements;

[0117] S32. Based on the global search stage of the two-stage bitter fish optimization algorithm, taking the exclusive dynamic perturbation factor optimization model \(F\) γ of the IoT terminal device as the fitness function, perform a global search in the preset perturbation factor parameter space, and update the position of the bitter fish individual according to the search fitness value:

[0118]

[0119] where, represents the perturbation factor of the \(i\)-th bitter fish individual at the \(t\)-th iteration, represents the perturbation factor of the \(i\)-th bitter fish individual at the \((t + 1)\)-th iteration, representing a candidate solution for the exclusive perturbation factor of the IoT terminal device, Denote the global optimal perturbation factor after the $t$-th iteration, representing the best perturbation factor that takes into account the computing delay, energy consumption, and security performance in the current global search process. $\delta$ and $\eta$ are adaptive adjustment coefficients, which dynamically adjust the search step size of bitter fish individuals according to the ratio of the current remaining power of the device to the maximum battery capacity, $S$ γ is the global search step size reference value, is the bitter fish individual fitness gradient learning factor:

[0120]

[0121] where, is the optimization model of the exclusive dynamic perturbation factor for the Internet of Things terminal device at the $t$-th iteration, are the maximum and minimum fitness values of all bitter fish individual perturbation factors in the $t$-th iteration respectively, and $\varepsilon$ is a very small positive number used to avoid the denominator in the formula being zero;

[0122] S33. Determine the perturbation factor $\gamma$ based on the global search result in step S32 i The preliminary optimization interval of $[\gamma$ i,min ,$\gamma$ i,max .

[0123] In this embodiment, S4 includes the following steps:

[0124] S41. Construct a local authentication parameter fine optimization function $F$ i,min ,$\gamma$ i,max within the perturbation factor optimization interval to guide the fine adjustment of the perturbation factor in the local search stage: local where,

[0125]

[0126] where, represents the perturbation factor of the $j$-th local bitter fish individual in the $t$-th iteration, and $\theta$ i is the perturbation sensitivity coefficient of the Internet of Things terminal device, and $\omega_4$, $\omega_5$ are weight coefficients that balance the degree of deviation and the gradient perturbation response, represents the perturbation factor of the local bitter fish individual after the $t$-th iteration;

[0127] S42. Initialize the local perturbation factor candidate set around the global optimal perturbation factor within the perturbation factor optimization interval

[0128]

[0129] where, is the $j$-th local perturbation factor candidate value of the $i$-th Internet of Things terminal device when representing the initialization of local search, and $\delta$ jis the perturbation offset coefficient, ρ is the offset range control parameter, γ i,max and γ i,min respectively represent the upper and lower bounds of the perturbation factor search interval of the i-th Internet of Things terminal device, which are determined in the global search stage;

[0130] S43. For each perturbation factor of each local bitter fish individual in the local perturbation factor candidate set perform local fine update:

[0131]

[0132] where represents the perturbation factor of the j-th local bitter fish individual in the (t + 1)-th iteration, α1 is the local micro-step coefficient, is the local dynamic adjustment factor:

[0133]

[0134] where κ is the network load adjustment factor, C load,i is the current network load status of the i-th Internet of Things terminal device, which is used to dynamically adjust the perturbation sensitivity;

[0135] S44. Repeat the steps of S42 - S43 until the iteration converges, and select the perturbation factor with the smallest local authentication parameter fine optimization function F from the local perturbation factor candidate set local as the final optimization result:

[0136]

[0137] where represents the perturbation factor of the local bitter fish individual obtained after the T-th round of local optimization, is the optimal perturbation factor for the final authentication of the i-th Internet of Things terminal device;

[0138] S45. Substitute the optimal perturbation factor for the final authentication back into the lightweight hash function LHash(.), and combine the device authentication parameters id i and k i and to generate the optimized authentication parameters

[0139]

[0140] In this embodiment, a two-stage bitter fish optimization algorithm is introduced in the identity authentication process, which is divided into two stages: global search and local fine-tuning. In the global stage, the optimization interval most suitable for the authentication perturbation parameters can be quickly identified, while in the local stage, the perturbation parameters are refined and dynamically adjusted in combination with the current remaining power and network load status information of the device, so that each device can obtain the optimal authentication parameters under its resource status, thereby ensuring that the authentication process is both safe and efficient. Tests conducted by actual deployment in low-power Internet of Things terminals show that compared with traditional fixed-parameter authentication methods, the present invention can improve the authentication success rate in low-power states and enhance the adaptive ability and authentication availability of the system.

[0141] In this embodiment, S5 includes the following steps:

[0142] S51. Collect the current system timestamp Combine it with the optimized authentication parameters and the optimized perturbation factor to jointly form the input vector of the current authentication stage

[0143] S52. Based on the input vector of the current authentication stage Use the lightweight hash chain constructor LHash(.) enhanced by dynamic perturbation to generate new optimized authentication parameters

[0144]

[0145] where, is the new optimized authentication parameter, representing the new optimized hash chain node, represents the bitwise exclusive OR operation, is the dynamic perturbation mask generated in the current authentication round of the i-th device:

[0146]

[0147] where, Hash(.) is the standard one-way hash function, <<< is the cyclic left shift operation, λ1 is the system-set perturbation displacement control constant, and mod is the modulo operator;

[0148] The dynamic perturbation mask enhances the unpredictability of the optimized authentication parameters through the coupling of the perturbation factor and the timestamp, ensuring that the generated optimized authentication parameters have dynamics and anti-replay capabilities, and meeting the lightweight security calculation requirements of Internet of Things terminal devices;

[0149] S53. Add the new optimized authentication parameters generated in the current authentication stage to the authentication hash chain structure HC i maintained locally by the device to construct a complete authentication chain:

[0150]

[0151] Among them, HC i represents the authentication hash chain currently maintained by the i-th Internet of Things terminal device, is the initial new optimized authentication parameter, representing the initial hash chain node.

[0152] In this embodiment, S7 includes the following steps:

[0153] S71. The Internet of Things authentication server receives the authentication request message sent by the Internet of Things terminal device, and extracts the device unique identifier id i , the new optimized hash chain node disturbance factor and the current timestamp to construct the authentication vector to be verified

[0154] S72. According to the authentication hash chain history record maintained by the authentication server perform continuity verification on the new optimized hash chain node calculate the expected hash chain node on the server side and compare it with the received hash chain node for consistency:

[0155]

[0156] If it satisfies then the hash chain continuity is considered legal;

[0157] S73. Verify the legitimacy of the disturbance factor . Based on the device resource status, historical disturbance behavior and authentication phase strategy, determine the legitimacy of the disturbance factor according to the following rules:

[0158] The legal disturbance factor is expressed as if the disturbance factor satisfies any of the following all conditions:

[0159] The current remaining battery power ratio and the network load C load,i < 0.7;

[0160] The deviation from the previous disturbance factor recorded by the server does not exceed the threshold, that is

[0161] the disturbance factor belongs to the accepted disturbance factor range [γ min , γ max recorded by the server;

[0162] The illegal perturbation factor is expressed as if the perturbation factor Simultaneously, any of the following abnormal situations exist:

[0163] The current remaining power ratio And the network load C load,i > 0.9;

[0164] The deviation from the previous perturbation factor recorded by the server exceeds twice the threshold, that is

[0165] The perturbation factor Exceeds the tolerance interval of the perturbation factor dynamically maintained by the authentication server;

[0166] S74. If the authentication request simultaneously satisfies the hash chain continuity verification and the perturbation factor legality determination, the server generates an authentication - passed response message; otherwise, it generates an authentication - failed response message and indicates the specific reason for the authentication failure. The specific reasons include hash chain breakage and illegal perturbation factor.

[0167] Embodiment 1:

[0168] In an intelligent agricultural Internet of Things monitoring system, a large number of low - power temperature and humidity sensor nodes are deployed to collect environmental data in the greenhouse in real - time. The sensor devices interact with the edge server through wireless communication. It is required that each sensor must complete identity authentication before reporting data to ensure the legality, integrity of the data source and prevent malicious device access. Since the computing power of the sensor devices is extremely limited (the main control chip is a low - power STM32L series, the operating frequency is only 32MHz, the SRAM is only 32KB, and the power supply is a lithium battery 3.7V / 1000mAh), traditional identity authentication methods based on RSA and ECC are difficult to apply in this scenario. Frequent hash operations and complex parameter matching lead to a significant increase in power consumption and severely limit the device life.

[0169] This embodiment adopts the lightweight Internet of Things identity authentication method based on the two - stage bitter fish optimization algorithm and hash chain proposed by the present invention. It is deployed in 32 intelligent greenhouses in an agricultural science and technology park in Province A. 10 nodes are deployed in each greenhouse, with a total of 320 Internet of Things sensing terminals, distributed within a range of 3 kilometers. The authentication period is once every 5 minutes, and 288 rounds of authentication are performed every day.

[0170] In the actual application process, the authentication system first collects the unique identifier of each terminal, such as the MAC address, the pre - allocated shared key, and the start timestamp in the initialization stage, and generates the initial authentication parameter set P0. The parameters of the first device in the embodiment are:

[0171] 1. The unique identifier id1: "AC:76:B1:22:00:18"

[0172] 2. Shared secret key k1: "7a3e9f56a8b21344"

[0173] 3. Initial timestamp "2025-03-20 08:00:00"

[0174] Generate the initial hash chain node by combining this set of parameters And calculate the perturbation mask through the initial value of the perturbation factor γ1

[0175] Subsequently, the system automatically monitors the current remaining power and communication load of each node. For example, the remaining power of a certain node is 78% and the network load is 42%. According to this state, the two-stage bitter fish optimization algorithm starts to execute:

[0176] 1. In the global stage, determine that the value range of the perturbation factor most suitable for this node is [7, 12];

[0177] 2. In the local stage, evaluate the authentication delay and security risk in the perturbation candidate set {7.5, 8.2, 9.0, 10.1, 11.3} by constructing an authentication parameter fine optimization function, and finally determine the optimal perturbation factor

[0178] This perturbation factor is used for the regeneration of the hash chain node:

[0179]

[0180] Final authentication node Is generated by the current timestamp And the perturbation mask, and appended to the authentication hash chain

[0181] The authentication request is sent to the server, and the server calls the same calculation process to verify the node continuity and verify Meet the following constraint conditions:

[0182]

[0183] C load,1 = 0.42 < 0.7;

[0184]

[0185] The authentication is judged to be legal, the server returns an authentication response, and the terminal starts to upload data after completing the authentication

[0186] After running continuously for 7 days, the experimenters compared the performance of the method of the present invention with the traditional authentication mechanism on the same device platform, and the results are shown in Table 1 below:

[0187] Table 1 Performance Comparison between the Method of the Present Invention and Traditional Identity Authentication Methods

[0188]

[0189] In addition, the experimenters counted the authentication success rates of the devices at different power levels and found that the method of the present invention can still maintain an authentication success rate of over 90% when the device power is below 20%, while the authentication interruption rate of the traditional method increases significantly at low power levels (the interruption rate of the RSA scheme is 38% and that of ECC is 21%), indicating that the authentication perturbation parameter optimization mechanism of the present invention has high self - adaptability in the scenario of dynamic resource changes.

[0190] In the anti - tampering test of the hash chain, the experimenters simulated the attack behavior of replaying the nodes of the previous authentication cycle. The anti - attack success rate of the traditional hash mechanism is about 87%. However, due to the addition of the dual dynamic mechanisms of the perturbation factor and the time mask in the present invention, the old nodes become invalid at the current time, and the attacker cannot forge valid authentication data, and the anti - replay attack success rate is as high as 98.7%.

[0191] In summary, this embodiment fully verifies the feasibility of the method of the present invention for identity authentication in resource - constrained and dynamic environments, and has significant advantages in terms of authentication speed, energy consumption control, dynamic adaptability, and security anti - attack ability, providing a practical and efficient security authentication solution for large - scale lightweight Internet of Things scenarios.

[0192] The present invention makes lightweight dynamic improvements to the traditional static hash chain structure, binds the unique authentication perturbation factor of the device to the current time state, and through the introduction of the perturbation mask, makes each hash chain node generated during authentication have time sensitivity and device individual differences. The authentication mechanism effectively improves the unpredictability and non - tamperability of authentication data during transmission and storage, and shows stronger resistance when facing common security threats such as replay attacks and forgery attacks.

[0193] The present invention designs a dual - verification mechanism based on the continuity of hash chain nodes and the legality of authentication perturbation factors on the authentication server side, which is different from the traditional method that only checks the node consistency. The server not only verifies whether the authentication node forms a continuous chain with the historical nodes, but also comprehensively judges the device power level, the change range of historical perturbation parameters, and the current network load situation to further confirm whether the authentication request is within the reasonable behavior range. Through the dual - verification mechanism, the authentication server can effectively identify device abnormal behaviors and the risk of forged authentication parameters, and improve the accuracy of authentication responses and the refinement of security defenses.

[0194] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, making equivalent substitutions or changes, shall be covered by the protection scope of the present invention.

Claims

1. A lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain, characterized in that: The steps include: S1. Initialize the IoT system authentication environment and generate an initial authentication parameter set; S2. Generate an initial hash chain node using the initial authentication parameter set according to a preset hash function; S3. Taking the initial authentication parameter set and the current network environment and IoT terminal device resource status as input, the two-stage bitter fish optimization algorithm is used to dynamically optimize the authentication parameters. In the first stage, a global search is performed to determine the optimization interval of the authentication parameters; S4. In the second stage, local fine adjustment is performed within the optimization range to obtain optimized authentication parameters; S5. Using the initial hash chain node, the optimized authentication parameters and the newly collected current timestamp, a new hash chain node is generated through a preset hash function, and the new hash chain node is updated to the authentication hash chain; S6. Encapsulate the updated authentication hash chain and the current timestamp into an authentication request message and send it to the IoT authentication server via the wireless communication network; S7. After receiving the authentication request message, the IoT authentication server verifies the authentication request message according to the preset authentication rules and generates a corresponding authentication response message; S8. After receiving the authentication response message, the IoT terminal device updates the local authentication status according to the verification result in the authentication response message, synchronously updates the local authentication hash chain node, and records the authentication record of this authentication process.

2. According to claim 1, a lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain is characterized in that: The S1 comprises the following steps: S11. Collect basic identification information of IoT terminal devices and build device identity set ID dev ; S12. Assign a shared key corresponding to its unique identifier to each IoT terminal device, and construct a shared key set K shared ; S13. Initialize the current system timestamp set T0 for IoT identity authentication, which is used to identify the initial moment of authentication; S14. Combined with the device identity set ID dev , shared key set K shared With the system timestamp set T0, construct the initial authentication parameter set P0: in, Represents the initial authentication parameter vector of the ith IoT terminal device, including the unique identifier of the IoT terminal device, the shared key and the current timestamp, id i represents the unique identifier of the i-th IoT terminal device, k i Indicates the IoT terminal device ID i The corresponding shared key, Indicates the IoT terminal device id i The current system timestamp during the authentication initialization phase, where N is the number of IoT terminal devices participating in identity authentication in the system.

3. According to claim 1, a lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain is characterized in that: The S2 comprises the following steps: S21. Based on the initial authentication parameter set P0, the lightweight optimized hash function LHash(.) is used to initialize the initial authentication parameter vector of each IoT terminal device. Perform hash mapping to generate the initial hash chain node set HC0: Tenth, is the initial hash chain node of the i-th IoT terminal device, γ i It represents the unique disturbance factor of IoT terminal devices, which is combined with the current timestamp through the cyclic left shift operation <<< to form a dynamic mutation, so that the initial hash chain node has dynamic security under lightweight conditions; S22. Calculate the dynamic disturbance factor γ specific to IoT terminal devices i : Among them, E res,i is the current remaining power of the i-th IoT terminal device, E max,i is the maximum battery capacity of the IoT terminal device, C load,i is the current network load state of the ith IoT terminal device. The perturbation factor is adjusted in real time as the network environment changes through an exponential function. ψ and φ are the weights used to adjust the energy state and network state in the perturbation factor, respectively. α is used to dynamically adjust the influence of the remaining power of the device on the perturbation factor. β is used to control the sensitivity of the network load state to the perturbation factor, so that the computational complexity and communication overhead in the hash chain node generation process can be optimized and balanced in the scenario of IoT resource constraints.

4. According to claim 1, a lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain is characterized in that: The S3 comprises the following steps: S31. According to the IoT terminal device exclusive dynamic disturbance factor γ i , taking the initial authentication parameter set P0, the current network environment status and the resource status of the IoT terminal device as input, constructing the dynamic disturbance factor optimization model F exclusive to the IoT terminal device γ : F γ =w1·T γ,i +w2·E γ,i +w3·R Y,i ; Among them, T γ,i Indicates the disturbance factor γ of the i-th IoT terminal device i The computational delay caused by the hash chain calculation and identity authentication process, E γ,i Indicates the disturbance factor γ of the i-th IoT terminal device i The additional energy consumption, R γ,i Represents the disturbance factor γ of the i-th IoT terminal device i The corresponding security risk indexes, w1, w2, and w3, are the optimization weights set by the IoT authentication system according to the actual application scenario requirements; S32. In the global search phase based on the two-stage bitter fish optimization algorithm, the dynamic disturbance factor optimization model F is used to optimize the IoT terminal device. γ As a fitness function, a global search is performed in the preset perturbation factor parameter space, and the individual positions of bitter fish are updated according to the search fitness value: in, represents the disturbance factor of the i-th bitter fish individual at the t-th iteration, represents the disturbance factor of the i-th bitter fish individual at the t+1th iteration, and represents the candidate solution of the exclusive disturbance factor of the IoT terminal device. It represents the global optimal perturbation factor after the tth iteration, which represents the best perturbation factor that takes into account the computational delay, energy consumption and safety performance in the current global search process. δ and η are adaptive adjustment coefficients, which dynamically adjust the individual search step of bitter fish according to the ratio of the current remaining power of the device to the maximum battery capacity. S γ is the global search step size benchmark value, is the individual fitness gradient learning factor of bitter fish: in, is the optimization model of the dynamic disturbance factor exclusive to IoT terminal devices at the tth iteration, are the maximum and minimum fitness values ​​of the disturbance factors of all bitter fish individuals in the tth iteration, respectively. ε is a very small positive number to avoid the denominator in the formula being zero; S33. Determine the disturbance factor γ based on the global search result of step S32 i The initial optimization interval [γ i,min , γ i,max ].

5. According to claim 1, a lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain is characterized in that: The S4 comprises the following steps: S41. In the disturbance factor optimization interval [γ i,min , γ i,max ] Construct a local authentication parameter fine optimization function F local , which is used to guide the fine adjustment of the perturbation factor in the local search phase: Tenth, represents the disturbance factor of the jth local bitterling individual in the tth iteration, θ i is the disturbance sensitivity coefficient of the IoT terminal device, ω4 and ω5 are the weight coefficients of the balance deviation degree and the gradient disturbance response, represents the disturbance factor of the local bitterling individual after the tth iteration; S42. Around the global optimal disturbance factor within the disturbance factor optimization interval Initialize the candidate set of local perturbation factors in, is the candidate value of the jth local perturbation factor of the i-th IoT terminal device when the local search is initialized, δ j is the disturbance offset coefficient, ρ is the offset range control parameter, γ i,max and γ i,min They represent the upper and lower bounds of the perturbation factor search interval of the i-th IoT terminal device, respectively, which are determined by the global search stage; S43. Candidate set of local perturbation factors The disturbance factor of each local bitterling individual in Perform a local fine-grained update: in, represents the disturbance factor of the jth local bitter fish individual in the t+1th iteration, α1 is the local micro-step coefficient, is the local dynamic adjustment factor: Among them, κ is the network load adjustment factor, C load,i is the current network load status of the i-th IoT terminal device, which is used to dynamically adjust the disturbance sensitivity; S44. Repeat steps S42-S43 until the iteration converges, and select the candidate set of local perturbation factors Select local authentication parameters to fine-tune the optimization function F local The minimum perturbation factor is taken as the final optimization result: in, represents the disturbance factor of the local bitter fish individual obtained after the Tth round of local optimization, is the optimal perturbation factor for the final authentication of the i-th IoT terminal device; S45. The optimal disturbance factor of the final certification Substitute it back into the lightweight hash function LHash(.) and combine it with the device authentication parameter id i , k i , Generate optimized authentication parameters 6. According to claim 1, a lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain is characterized in that: The S5 comprises the following steps: S51. Collect current system timestamp Combined with optimized authentication parameters And the optimized disturbance factor Together they form the input vector for the current authentication phase S52. Based on the input vector of the current authentication stage Generate new optimized authentication parameters using the lightweight hash chain constructor LHash(.) enhanced by dynamic perturbation in, is a new optimized authentication parameter, indicating a new optimized hash chain node, Represents a bitwise exclusive OR operation, The dynamic perturbation mask generated for the i-th device in the current authentication round: Tenth, Hash(.) is a standard one-way hash function, <<< is a circular left shift operation, λ1 is a perturbation displacement control constant set by the system, and mod is a modulus operator; S53. The new optimized authentication parameters generated in the current authentication phase Add to the authentication hash chain structure HC maintained locally on the device i , build a complete authentication chain: Among them, HC i Represents the authentication hash chain currently maintained by the i-th IoT terminal device, It is the initial new optimized authentication parameter, indicating the initial hash chain node.

7. According to claim 6, a lightweight Internet of Things identity authentication method based on bitterfish optimization algorithm and hash chain is characterized in that: The S7 comprises the following steps: S71. The IoT authentication server receives the authentication request message sent by the IoT terminal device and extracts the device unique identifier id in the authentication request message i , New optimized hash chain nodes Perturbation Factor With the current timestamp Construct the authentication vector to be verified; S72. Based on the authentication hash chain history maintained by the authentication server For new optimized hash chain nodes Perform continuity verification and calculate the server-side expected hash chain node And compare the consistency with the receiving hash chain node: If satisfied The hash chain continuity is considered legal; S73. Perturbation Factor The legitimacy of the disturbance factor is verified, and the legitimacy of the disturbance factor is determined based on the device resource status, historical disturbance behavior, and authentication phase strategy, combined with the following rules: The legal perturbation factor is expressed as All of the following conditions are met: Current remaining power ratio And the network load C load,i <0.7; The deviation from the last disturbance factor recorded by the server does not exceed the threshold, that is, Perturbation Factor The range of accepted perturbation factors recorded by the server [γ min , γ max ]; The illegal perturbation factor is expressed as Any of the following abnormal conditions exist at the same time: Current remaining power ratio And the network load C load,i >0.9; The deviation from the last disturbance factor recorded by the server exceeds the threshold by two times, i.e. Perturbation Factor Exceeding the disturbance factor tolerance interval dynamically maintained by the authentication server; S74. If the authentication request satisfies both the hash chain continuity verification and the perturbation factor legitimacy determination, the server generates a response message indicating authentication success; otherwise, it generates a response message indicating authentication failure and indicates the specific reasons for the authentication failure, which include hash chain breakage and illegal perturbation factor.

Citation Information

Patent Citations

  • A universal hand back image recognition method based on an S-CNN model

    CN109034016A

  • Lightweight authentication method and system based on Ethereum IoT entity, and intelligent terminal

    CN111147228A