Lightweight identity authentication and secret communication method based on Internet of Things security

By adopting lightweight identity authentication and confidential communication methods in the Internet of Things system, and using technologies such as symmetric encryption, message authentication code and hash function, the problem of full-link security of the Internet of Things system is solved, achieving high security and low communication costs.

CN120223435AActive Publication Date: 2025-06-27BEIJING SANSEC TECH DEV +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510669464.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-06-27
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

How to improve the security of the entire Internet of Things system and prevent information leakage, damage to items and affect personal life safety.

Method used

Lightweight identity authentication and confidential communication methods based on IoT security are adopted, and lightweight session process is realized through symmetric encryption, message authentication code, hash function and other technologies, and identity authentication and key negotiation are completed, and timestamps are added to prevent replay attacks.

Benefits of technology

While ensuring security performance, it reduces communication costs, improves user privacy data and access security, ensures the normal operation of equipment, improves the security of IoT systems, and reduces communication and computing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223435A_ABST
    Figure CN120223435A_ABST
Patent Text Reader

Abstract

The invention discloses a lightweight identity authentication and secret communication method based on Internet of Things security, which relates to the technical field of Internet of Things, and comprises the following steps: step 1, an intelligent device and a user register and distribute security parameters through a security service provider; 2, when the intelligent equipment or a user serves as a requester to request service, a request message is calculated according to the safety parameters and sent to the intelligent equipment of a receiver; 3, the receiver verifies the request message, generates an authentication response according to the security parameter and feeds back the authentication response to the requester; step 4, the requester generates session information after receiving the authentication response, and sends the session information to the receiver; and step 5, the receiver decrypts and verifies the session information to complete key negotiation. The method is used for ensuring the privacy data of the user, the access security of the user, the normal operation of equipment and the like, the security of the Internet of Things is improved, and the communication and calculation cost of the Internet of Things is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the Internet of Things, and more specifically, to a lightweight identity authentication and secure communication method based on the security of the Internet of Things. Background Art

[0002] With the emergence and development of the Internet of Things, the underlying Internet of Things technology, network communication technology, cloud computing technology, human-computer interaction technology, etc. are becoming increasingly powerful. Internet of Things devices and applications are now widely used in people's work and life. However, this is also accompanied by numerous security problems. These security problems involve all aspects of life, and not only will there be information leakage, item damage, etc., but in severe cases, it will even affect personal life safety.

[0003] Therefore, how to improve the security of the entire link of the Internet of Things system is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0004] In view of this, the present invention provides a lightweight identity authentication and secure communication method based on the security of the Internet of Things. Through symmetric encryption, message authentication code, hash function, etc., a lightweight session process is implemented to complete identity authentication and key negotiation. While ensuring security performance, the communication cost is reduced, and a timestamp is added to prevent replay attacks. The present invention is used to ensure aspects such as user's private data, user's access security, and normal operation of devices, improve the security of the Internet of Things, and reduce the communication and computing costs of the Internet of Things.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions:

[0006] A lightweight identity authentication and secure communication method based on the security of the Internet of Things, comprising the following steps:

[0007] Step 1: The smart device and the user register through a security service provider and allocate security parameters;

[0008] Step 2: When the smart device or the user requests a service as a requester, calculate the request message according to the security parameters and send it to the smart device of the receiver;

[0009] Step 3: The receiver verifies the request message and generates an authentication response according to the security parameters and feeds it back to the requester;

[0010] Step 4: After receiving the authentication response, the requester generates session information and sends it to the receiver;

[0011] Step 5: The receiver decrypts and verifies the session information to complete key negotiation.

[0012] Preferably, the specific implementation process of Step 1 is:

[0013] Step 11: The intelligent device D or the user U, as a communication node, after initialization, submits a registration request to the security service provider ISP through the gateway GW;

[0014] Step 12: The security service provider ISP assigns a node identity to the communication node according to the registration request (information such as the device serial number or user serial number, nature, etc.) , and sends the node identity and the gateway identity of the gateway GW where the communication node is located , private key back to the communication node as security parameters through a secure channel, and stores the security parameters in the node memory;

[0015] Step 13: The security service provider ISP stores the gateway identity of the gateway GW , private key and the node identity in the gateway memory.

[0016] Preferably, the implementation process of calculating the request message in Step 2 is as follows:

[0017] Step 21: The requestor selects a one-time random number , determines the receiving party node identity , and obtains the current sending timestamp ;

[0018] Step 22: Calculate the authentication message using the stored requestor node identity , private key and the receiving party node identity , h represents the hash function; represents the concatenation of strings;

[0019] Step 23: Calculate the request authentication code according to the authentication message and the gateway identity , MAC represents the message authentication code;

[0020]

[0020] Step 24: Generate the request message according to the request authentication code C, the requestor node identity , the receiving party node identity , the current sending timestamp and the random number .

[0021] Preferably, the specific process of Step 3 is as follows:

[0022] Step 31: The receiver calculates the time difference according to the current sending timestamp in the request message and the current receiving timestamp T , if , If it is an arbitrarily small positive number, it is determined that the current received timestamp T is within the credible range, and step 32 is entered; otherwise, the receiver ends the session;

[0023] Step 32: According to the stored private key and the identity of the requesting node in the request message , the identity of the receiving node calculate the verification message ;

[0024] Step 33: Calculate the verification authentication code according to the verification message ;

[0025] Step 34: Compare and verify the verification authentication code with the request authentication code C in the request message. If they are consistent, step 35 is entered; otherwise, the receiver ends the session;

[0026] Step 35: The receiver selects a secret random number b, obtains the current response timestamp , and encrypts it according to the stored private key to calculate the response message , represents the encryption function using the private key as the key;

[0027] Step 36: Calculate the response authentication code according to the secret random number b, the random number in the request message , and the request authentication code C , where HMAC represents the message authentication code based on the hash function;

[0028] Step 37: Generate the authentication response { } according to the response authentication code , the response message and the current response timestamp , and feedback it to the requester.

[0029] Preferably, the specific process of step 4 is as follows:

[0030] Step 41: The requester calculates the time difference according to the current response timestamp in the authentication response and the current received timestamp T. If holds, it is determined that the current received timestamp T is within the credible range, and step 42 is entered; otherwise, the requester terminates the session;

[0031] Step 42: The requester decrypts the response message in the authentication response according to the stored private key to obtain the identity of the receiving node of the response , the secret random number b, the response random number and the response timestamp , and the identity of the response recipient node , the response random number , the response timestamp are compared with the identity of the recipient node determined in step 21 , the random number , the current response timestamp in the authentication response . If they are consistent, go to step 43; otherwise, the requester terminates the session;

[0032] Step 43: The requester calculates the comparison authentication code based on the identity of the recipient node determined in step 21 , the selected random number , the stored identity of the requester node , the authentication message calculated in step 22 , the decrypted secret random number b and the current response timestamp . HMAC represents the message authentication code based on the hash function and is compared with the response authentication code in the authentication response. If they are consistent, go to step 44; otherwise, the requester terminates the session;

[0033] Step 44: Calculate the session key according to the current session timestamp , and encrypt the session key using the private key to obtain the encrypted session key ciphertext ;

[0034] Step 45: Generate the session information { } according to the current session timestamp and the encrypted session key ciphertext , and send it to the recipient.

[0035] Preferably, the specific process of step 5 is as follows:

[0036] Step 51: The recipient calculates the time difference according to the current session timestamp in the session information and the current reception timestamp T. If holds, it is determined that the current reception timestamp T is within the trusted range, and go to step 52; otherwise, the recipient terminates the session;

[0037] Step 52: The recipient decrypts the encrypted session key ciphertext in the session information using the stored private key to obtain the decrypted session key , the decrypted random number , and the decrypted session timestamp , and compare the decrypted random numbers respectively , decrypted session timestamp The secret random number b selected by the receiver in step 35 and the current session timestamp when the session information is received Are they consistent? If they are consistent, then go to step 53; otherwise, the receiving party terminates the session;

[0038] Step 53: The receiver responds based on the current timestamp , Step 32-Step 34 Verify the authentication message with the requester Consistent validation messages , the identity of the requesting node obtained according to the request message and the receiving node identity , the selected secret random number b, the current session timestamp Calculate the session key and decrypt the session key with A comparison is performed for authentication. If they are consistent, key negotiation succeeds; otherwise, key negotiation fails.

[0039] Compared with the prior art, the above-mentioned technical solution discloses a lightweight identity authentication and confidential communication method based on the security of the Internet of Things. By analyzing the authentication schemes and key negotiation protocols of systems such as smart homes and smart terminals, a lightweight authentication and key negotiation scheme based on the security of the Internet of Things is proposed to realize the communication process between devices or between users and devices without going through a gateway, thereby realizing high communication security and low communication calculation cost in the Internet of Things system. The method of the present invention includes three parties: smart devices, users, and security service providers. After the user and the smart device are registered with the security service provider, identity authentication and key negotiation are performed, which can ultimately realize information transmission and various instruction operation behaviors between devices and users and devices, and avoid the frequent use of gateways in the Internet of Things scenario, while realizing lightweight authentication and key negotiation adapted to the smart terminal devices of the Internet of Things. The present invention can be widely used in scenarios such as smart terminals, smart homes, smart industrial control, Internet of Vehicles, smart transportation, smart logistics, smart agriculture, etc. in the field of the Internet of Things. The beneficial effects of the present invention specifically include:

[0040] 1. High security:

[0041] (1) Anti-spoofing attack: Only legitimate devices in the gateway can obtain the private key , and it is well hidden so that an attacker cannot calculate , making it impossible to calculate ; In addition, the attacker cannot obtain the random number b, and thus cannot calculate the session key In summary, the attacker cannot achieve forgery attacks or impersonation. Similarly, the attacker cannot disguise as a gateway, thus realizing the security protection of the entire process.

[0042] (2)Replay attack resistance: The proposed solution introduces timestamps , and utilizes 's limiting conditions to effectively prevent replay attacks, avoiding the situation where an attacker sends duplicates after a user issues an instruction to a device or devices send tasks to each other, ensuring security.

[0043] (3)Forward secrecy: In an authentication session, both the user and the device each select random numbers , b, to negotiate the session key . On this basis, even if the long-term used master key is leaked, it will not cause the leakage of past session keys.

[0044] 2. High efficiency:

[0045] When communicating between a user and a device or between devices, information interaction does not frequently access the gateway, thus saving a large amount of communication costs. It can achieve mutual authentication between both parties with relatively low computational costs, only involving two symmetric encryptions, two MAC message authentication codes, two HMAC message authentication codes, and two hash operations, 2 . It does not use complex operations such as asymmetric encryption and bilinear mapping, achieving lightweight authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0047] Figure 1 is a schematic diagram of the lightweight identity authentication and secure communication structure based on Internet of Things security provided by the present invention;

[0048] Figure 2 is a schematic diagram of data transmission in the registration stage provided by the present invention;

[0049] Figure 3 is a schematic diagram of data transmission in the identity authentication and key negotiation stage provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0051] An embodiment of the present invention discloses a lightweight identity authentication and secure communication method based on Internet of Things security. As Figure 1 shown, it includes intelligent devices, users, and security service providers. The realization of lightweight identity authentication and secure communication among the three includes two stages: a registration stage, an identity authentication and key negotiation stage; and includes the following steps:

[0052] S1: The intelligent device and the user register through the security service provider and allocate security parameters;

[0053] S2: When the intelligent device or the user requests a service as a requester, it calculates a request message according to the security parameters and sends it to the intelligent device of the recipient;

[0054] S3: The recipient verifies the request message and generates an authentication response according to the security parameters and feeds it back to the requester;

[0055] S4: After receiving the authentication response, the requester generates session information and sends it to the recipient;

[0056] S5: The recipient decrypts and verifies the session information to complete key negotiation.

[0057] Furthermore, step 1 belongs to the registration stage. As Figure 2 shown, the specific implementation process is as follows:

[0058] S11: The intelligent device or the user as a communication node, after initialization, submits a registration request to the security service provider ISP through the gateway GW;

[0059] S12: The security service provider ISP assigns a node identity to the communication node according to the registration request (information such as the device serial number or user serial number, nature, etc. in the registration request) , and returns the node identity and the gateway identity of the gateway GW where the communication node is located , private key as security parameters to the communication node through a secure channel, and stores the security parameters in the node memory;

[0060] S13: The security service provider ISP will send the gateway identity of the gateway GW , private key and node identity Store it in the gateway memory.

[0061] The technical effect of the above technical solution is that the Internet service provider (ISP), the node memory, and the gateway memory all store { }; The intelligent device accesses the system and saves the corresponding information to the gateway where it is located. The Internet service provider (ISP) maintains the database of the entire system and records the devices that have accessed the system. In addition, to ensure security and prevent the entire system from being attacked, the ISP can set the key life cycle and update it regularly.

[0062] Furthermore, the implementation process of calculating the request message in S2 during the identity authentication and key negotiation phase is as follows:

[0063] S21: The requester selects a one-time random number , determines the identity of the recipient node , and obtains the current sending timestamp ;

[0064] S22: Use the stored identity of the requester node , private key , and the identity of the recipient node to calculate the authentication message , where h represents the hash function; represents the concatenation of strings. Concatenate , , and together;

[0065] S23: Calculate the request authentication code based on the authentication message and the gateway identity , where MAC represents the message authentication code;

[0066] S24: Generate the request message based on the request authentication code C, the identity of the requester node , the identity of the recipient node , the current sending timestamp, and the random number.

[0067] Furthermore, the specific process of S3 during the identity authentication and key negotiation phase is as follows:

[0068] S31: The recipient calculates the time difference based on the current sending timestamp in the request message and the current receiving timestamp T. If , is an arbitrarily small positive number, it is determined that the current receiving timestamp T is within the trusted range, and S32 is entered; otherwise, the recipient ends the session;

[0069] S32: According to the stored private key and the identity of the requesting party node in the request message , the identity of the receiving party node calculate the verification message ;

[0070] S33: Calculate the verification authentication code according to the verification message ;

[0071] S34: Compare and verify the verification authentication code with the request authentication code C in the request message. If they are the same, go to S35; otherwise, the receiving party ends the session;

[0072] S35: The receiving party selects a secret random number b, obtains the current response timestamp , and encrypts it according to the stored private key to calculate the response message , denotes the encryption function using the private key as the key;

[0073] S36: Calculate the response authentication code according to the secret random number b, the random number in the request message , and the request authentication code C. HMAC denotes the message authentication code based on the hash function;

[0074] S37: Generate the authentication response { } according to the response authentication code , the response message and the current response timestamp and feedback it to the requesting party.

[0075] Furthermore, the specific process of S4 in the identity authentication and key negotiation phase is as follows:

[0076] S41: The requesting party calculates the time difference according to the current response timestamp in the authentication response and the current reception timestamp T. If holds, it is determined that the current reception timestamp T is within the trusted range, and go to S42; otherwise, the requesting party terminates the session;

[0077] S42: The requesting party decrypts the response message in the authentication response according to the stored private key to obtain the identity of the response receiving party node , the secret random number b, the response random number and the response timestamp , and the identity of the response receiving party node​​ , response random number , response timestamp and the recipient node identity determined in step 21 , random number , the current response timestamp in the authentication response Compare them. If they are consistent, proceed to S43; otherwise, the requester terminates the session;

[0078] S43: The requester calculates a comparison authentication code based on the recipient node identity determined in step 21 , the selected random number , the stored requester node identity , the authentication message calculated in step 22 , the decrypted secret random number b and the current response timestamp , where HMAC represents the hash-based message authentication code, and compare it with the response authentication code in the authentication response. If they are consistent, proceed to S44; otherwise, the requester terminates the session;

[0079] S44: Calculate the session key based on the current session timestamp , and encrypt the session key using the private key to obtain the encrypted session key ciphertext ; ;

[0080] S45: Generate session information { } based on the current session timestamp and the encrypted session key ciphertext , and send it to the recipient.

[0081] Furthermore, the specific process of S5 in the authentication and key agreement phase is as follows:

[0082] S51: The recipient calculates the time difference based on the current session timestamp in the session information and the current reception timestamp T. If holds, it is determined that the current reception timestamp T is within the trusted range, and proceed to S52; otherwise, the recipient terminates the session;

[0083] S52: The recipient decrypts the encrypted session key ciphertext in the session information using the stored private key to obtain the decrypted session key , the decrypted random number , and the decrypted session timestamp , and respectively compare the decrypted random number , the decrypted session timestamp , the decrypted session timestamp With the secret random number b selected by the recipient in step 35 and the current session timestamp when receiving the session information Whether they are consistent. If they are consistent, proceed to S53; otherwise, the recipient terminates the session;

[0084] S53: The recipient calculates the session key according to the current response timestamp , the authentication message with the requester that passed verification in steps 32 - 34 The consistent verification message , the requester node identity obtained according to the request message and the recipient node identity , the selected secret random number b, and the current session timestamp Calculate the session key , and perform comparison authentication with the decrypted session key . If they are consistent, the key negotiation is successful; otherwise, the key negotiation fails.

[0085] In a specific embodiment, the Internet of Things system includes intelligent device D, user U, and security service provider ISP. Adopting a lightweight identity authentication method, any user and intelligent device To access the Internet of Things system, it must first submit a registration request to the security service provider ISP through the intelligent device for registration. After that, the ISP responds and allocates security parameters, and at the same time stores the security parameters in the legal device storage space for obtaining secret information for authentication during the later authentication process. Specifically, in the Internet of Things system, the information interaction parties are users and intelligent devices or devices and devices. Therefore, users and intelligent devices also act as communication nodes of the system, and the registration processes of the two types of roles are the same. Taking the intelligent device registration as an example:

[0086] S1: The intelligent device , as a communication node of the system, after initialization, submits a registration request to the security service provider ISP;

[0087] S2: After receiving the registration request from the intelligent device , the security service provider ISP assigns an identity to the device according to information such as the device serial number and nature , and at the same time returns the identity of the gateway where the device is located and the private key to the intelligent device through a secure channel and writes them into the device memory. The device memory stores { , , };

[0088] S3: The security service provider ISP will and and the identity of the intelligent device store it in the gateway In the gateway, the gateway memory stores { , , }.

[0089] The registration process of the intelligent device is completed. The intelligent device accesses the system and saves the corresponding information to the gateway where it is located. The security service provider ISP maintains the database of the entire system, recording the devices that have accessed the system. In addition, to ensure security and prevent the entire system from being attacked, the security service provider ISP can set the key life cycle and perform regular updates.

[0090] In a specific embodiment, when a user needs to log in to the system and request services from a specific intelligent device , the stored gateway key needs to be used, and an authentication message is calculated with the help of a random number, a time stamp, a message authentication code, etc. Then, a specific message is sent to the specific intelligent device ; the intelligent device verifies the user 's message, and at the same time selects its own parameters for authentication response and feedbacks it to the user ; the user calculates the session key after receiving the authentication response and encrypts and protects the session key and feeds it back to the intelligent device ; the intelligent device calculates the session key to complete the mutual authentication and session key negotiation with the user , ensuring security. The process of the authentication and key negotiation phase is as Figure 3 shown, including the following steps:

[0091] S1: The user selects a one-time random number , and obtains the current time stamp . All times in this system are synchronized with the time source to ensure compliance with the time accuracy standard of the National Time Service Center; use the stored information and the identity of the target intelligent device to calculate the authentication message . After completion, calculate the request authentication code ; send the calculated along with the identity information of both parties, the time stamp, and the random number to the target intelligent device . The user sends the request information: { }; }

[0092] S2: The intelligent device receives the user The sent request information is first calculated , is the current time, check whether it holds. Since is an arbitrarily small positive number, the timestamp is judged to be within the credible range by checking the time difference. When it is not within the credible range, the session ends. When it is within the credible range, the stored information and the identities of both parties are used to calculate the verification message , and further calculate the verification authentication code , and compare it with the received request authentication code . If they are the same, trust is achieved through verification, and the authentication process continues; the intelligent device selects a secret random number , and obtains the current timestamp , encrypts it using the private key , and calculates the response message ; uses the random numbers , to calculate the message authentication code for the challenge response between the user and the intelligent device for authentication, and obtains the response authentication code . After completing these, the device sends an authentication response: { };

[0093] S3: The user receives the authentication response, first checks the timestamp , calculates , judges whether it holds, then decrypts the message using the private key , and obtains , , , , compares , , with the known data to check if they are consistent. If they are consistent, calculate , otherwise end the session. After completion, compare with to judge whether . If the verification passes, identity authentication is achieved. If the verification fails, the user terminates the session; calculate the session key , and at the same time use to encrypt and protect this session key, and calculate the session key ciphertext ; obtain the current timestamp , and the user sends session information: { };

[0094] S4: Intelligent device Upon receiving the session information, first check the timestamp and calculate to determine whether it holds, and then use to perform encryption and decryption on to obtain , , , and compare , with the known data to check if they are equal. If they are equal, then calculate , otherwise end the session. After completion, compare whether is equal. If it is equal, the verification is completed, otherwise the session ends; if the verification is completed, mutual authentication between the user and the device is achieved, and the session key is successfully negotiated and confirmed.

[0095] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.

[0096] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A lightweight identity authentication and secure communication method based on Internet of Things security, characterized in that, It includes the following steps: Step 1: The smart device and the user register through the security service provider and are assigned security parameters; Step 2: When the smart device or the user requests a service as the requester, calculate the request message according to the security parameters and send it to the receiving smart device; Step 3: The receiver verifies the request message and generates an authentication response according to the security parameters and feeds it back to the requester; Step 4: After receiving the authentication response, the requester generates session information and sends it to the receiver; Step 5: The receiver decrypts and verifies the session information to complete the key negotiation.

2. The lightweight identity authentication and secure communication method based on Internet of Things security according to claim 1, characterized in that The specific implementation process of Step 1 is: Step 11: The smart device or the user acts as a communication node. After initialization, submit a registration request to the security service provider through the gateway; Step 12: The security service provider assigns a node identity to the communication node according to the registration request , and returns the node identity and the gateway identity of the gateway where the communication node is located , private key to the communication node as security parameters through a secure channel, and stores the security parameters in the node memory; Step 13: The security service provider stores the gateway identity of the gateway , the private key and the node identity in the gateway memory.

3. The lightweight identity authentication and secure communication method based on Internet of Things security according to claim 2, characterized in that, The implementation process of calculating the request message in Step 2 is: Step 21: The requester selects a one-time random number , determines the identity of the recipient node , and obtains the current sending timestamp ; Step 22: Use the stored identity of the requesting node , private key and the identity of the receiving node to calculate the authentication message , where h represents the hash function; represents the concatenation of strings; Step 23: Calculate the request authentication code according to the authentication message and the gateway identity Calculate the request authentication code , where MAC represents the message authentication code; Step 24: Generate a request message based on the request authentication code C, the identity of the requesting party node , the identity of the receiving party node , the current sending timestamp, and a random number .

4. The lightweight identity authentication and secure communication method based on Internet of Things security according to claim 3, characterized in that The specific process of Step 3 is: Step 31: The receiver calculates the time difference based on the current sending timestamp in the request message and the current receiving timestamp T . If , is an arbitrarily small positive number, it is determined that the current receiving timestamp T is within the credible range, and step 32 is entered. Otherwise, the receiver ends the session; Step 32: According to the stored private key and the identity of the requesting party node in the request message , the identity of the receiving party node calculate the verification message ; Step 33: Calculate the verification authentication code based on the verification message ; Step 34: Verify the authentication code Compare and verify it with the request authentication code C in the request message. If they are the same, proceed to Step 35; otherwise, the receiving party ends the session. Step 35: Select a secret random number b, obtain the current response timestamp , and encrypt it according to the stored private key to calculate the response message , represents the encryption function using the private key as the key; Step 36: Calculate the response authentication code according to the secret random number b and the random number in the request message, and the request authentication code C , where HMAC represents the hash-based message authentication code; Step 37: Generate an authentication response { } based on the response authentication code , the response message and the current response timestamp, and feedback it to the requester. ​ 5. The lightweight identity authentication and secure communication method based on Internet of Things security according to claim 4, wherein, The specific process of Step 4 is: Step 41: The requesting party calculates the time difference based on the current response timestamp and the current received timestamp T . If holds, it is determined that the current received timestamp T is within the trusted range, and step 42 is entered; otherwise, the requesting party terminates the session. Step 42: According to the stored private key Decrypt the response message in the authentication response to obtain the identity of the response recipient node , the secret random number b, the response random number and the response timestamp , and compare the identity of the response recipient node , the response random number , the response timestamp with the identity of the recipient node , the random number , and the current response timestamp in the authentication response . If they are consistent, proceed to Step 43; otherwise, the requester terminates the session; Step 43: Calculate the comparison authentication code , where HMAC represents the hash-based message authentication code and is compared with the response authentication code in the authentication response. If they are the same, proceed to Step 44; otherwise, the requester terminates the session; Step 44: According to the current session timestamp calculate the session key , and use the private key to encrypt the session key to obtain the encrypted session key ciphertext ; Step 45: According to the current session timestamp and the session key ciphertext generate session information { }, and send it to the recipient.

6. The lightweight identity authentication and secure communication method based on Internet of Things security according to claim 5, characterized in that, The specific process of Step 5 is: Step 51: The receiver calculates the time difference based on the current session timestamp in the session information and the current reception timestamp T . If holds, it is determined that the current reception timestamp T is within the trusted range, and step 52 is entered; Otherwise, the receiver terminates the session; Step 52: Use the stored private key to decrypt the session key ciphertext in the session information to obtain the decrypted session key , the decrypted random number and the decrypted session timestamp , and respectively compare the decrypted random number , the decrypted session timestamp with the selected secret random number b and the current session timestamp in the session information to check if they are consistent. If they are consistent, proceed to Step 53; otherwise, the receiver terminates the session; Step 53: Calculate the session key based on the current response timestamp and compare it with the decrypted session key for authentication. If they match, the key negotiation is successful; otherwise, the key negotiation fails. ​

Citation Information

Patent Citations

  • RFID tag anonymous authentication and key negotiation method based on smart city security system

    CN113747425A

  • Multi-factor authentication key negotiation method for intelligent equipment communication

    CN114125833A

  • Multi-factor Internet of Things terminal dynamic group access authentication method

    CN116318678A

  • Identity authentication system, method, apparatus, and device, and computer-readable storage medium

    US20230283475A1