A wireless authentication method and device against replay attacks
By establishing a device authentication and identity authentication system in a wireless communication network, using the secret key S encryption and consistency discrimination algorithm, combined with Gaussian function encoding, the problem of playback attacks in wireless communication is solved, and an efficient and reliable authentication process is achieved.
Patent Information
- Application Number
- CN202510722278.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-30
AI Technical Summary
In wireless communication networks, how to effectively resist the problem of replay attacks.
The authentication and system side are established to establish a two-fold verification system for device verification and identity verification, and the symbol sequence is encrypted using the secret key S, a consistency discrimination algorithm is designed, and information encoding is performed through the Gaussian function and the encoding matrix to improve verification accuracy and confidentiality.
It effectively improves the recognition accuracy and information transmission efficiency of playback attacks, reduces the misjudgment rate, and improves the reliability and confidentiality of the authentication process.
Smart Images

Figure CN120238871B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of communication and information security, and particularly to a wireless authentication method and device against replay attacks. Background Art
[0002] With the rapid development of wireless communication technologies, the security of wireless networks has been increasingly emphasized. As an effective attack pattern, replay attacks have been widely applied. Replay attacks are mainly used in the identity authentication process to undermine the correctness of authentication. Anti-replay attack refers to a security measure to prevent an attacker from resending previously captured data packets to deceive the system. In wireless communication networks, how to resist replay attacks has always been a research hotspot and difficulty in the field of network security. Summary of the Invention
[0003] The present invention mainly solves the problem of how to resist replay attacks in wireless communication networks, and discloses a wireless authentication method and device against replay attacks.
[0004] In the first aspect of the embodiments of the present application, a wireless authentication method against replay attacks is disclosed, which is implemented through an authentication end and a system end, and includes:
[0005] S1. The authentication end and the system end perform mutual device verification to obtain device verification information; the device verification information includes system device verification information and authentication device verification information; both the authentication end and the system end include a security information area; the security information area includes an anti-counterfeiting information packet and a key data packet; both the authentication end and the system end store a system device list and a device identifier;
[0006] S2. Based on the device verification information, the authentication end and the system end perform identity authentication processing;
[0007] S3. The authentication end sends the information to be sent to the system end;
[0008] S4. The authentication end and the system end end the communication process.
[0009] The authentication end and the system end perform mutual device verification to obtain device verification information, including:
[0010] S11. The authentication end sends a preset symbol sequence to the system end;
[0011] S12. The system end generates a secret key S, encrypts the received symbol sequence with the secret key S to obtain an encrypted sequence a, and sends the secret key S and the encrypted sequence a to the authentication end;
[0012] S13. The authentication end encrypts the stored device identifier with the received secret key S to obtain an encrypted device identifier idN;
[0013] S14. The authentication end uses the received secret key S to decrypt the received encrypted sequence a to obtain a decrypted sequence b, and performs a consistency discrimination process on the preset symbol sequence and the decrypted sequence b to obtain a consistency discrimination result.
[0014] If the consistency discrimination result is passed, the encryption device identifier idN is sent to the system end, and S15 is executed; if the consistency discrimination result is not passed, the communication process between the authentication end and the system end is stopped.
[0015] S15. The system end uses the stored authentication device list to determine whether the received encryption device identifier idN is legal to obtain authentication device verification information; if the authentication device verification information is legal, the system end sends the security system device identifier IDN to the authentication end; if the authentication device verification information is not legal, the communication process between the authentication end and the system end is stopped.
[0016] S16. The authentication end uses the stored system device list to determine whether the received security system device identifier IDN is legal to obtain system device verification information.
[0017] If the system device verification information is legal, device verification information is constructed using the system device verification information and the authentication device verification information, and S2 is executed.
[0018] If the system device verification information is not legal, the communication process between the authentication end and the system end is stopped, and in the security information area of the authentication end, the security system device identifier IDN is added to the anti-counterfeiting information package Q.
[0019] The consistency discrimination process between the preset symbol sequence and the decrypted sequence b includes:
[0020] Represent the preset symbol sequence as c.
[0021] Perform a consistency calculation process on sequence c and sequence b to obtain a consistency value.
[0022] The expression of the consistency calculation process is:
[0023]
[0024] where is the consistency value, N is the length of sequence b, and are the i-th elements of sequence b and sequence c respectively, is a preset deviation value.
[0025] Determine whether the consistency value is greater than a set consistency threshold. If it is greater, determine that the consistency discrimination result fails; if it is less than or equal to, determine that the consistency discrimination result passes.
[0026] Based on the device verification information, the authentication end and the system end perform identity verification processing, including:
[0027] Determine whether both the system device verification information and the authentication device verification information in the device verification information are legal, and obtain verification result information;
[0028] If the verification result information is all legal, the authentication end and the system end perform identity verification processing;
[0029] If the verification result information is not all legal, execute S1.
[0030] The authentication end and the system end perform identity verification processing, including:
[0031] S21, the authentication end sends the anti-counterfeiting information packet Q and the key data packet P stored in the security information area to the system end;
[0032] S22, the system end reads the key data packet P, determines whether the key data packet P is consistent with the key data packet stored in the security information area of the system end, and obtains a first verification result; if the first verification result is consistent, execute S23; if the first verification result is inconsistent, send an illegal identity warning message and stop the communication process between the authentication end and the system end;
[0033] S23, the system end reads the anti-counterfeiting information packet Q, determines whether the anti-counterfeiting information packet Q is an empty packet, and obtains a second verification result; if the second verification result is yes, the authentication end and the system end complete the identity verification processing and execute S3; if the second verification result is no, send an illegal identity warning message and stop the communication process between the authentication end and the system end.
[0034] The authentication end sends the information to be sent to the system end, including:
[0035] S31, perform statistical processing on the information to be sent to obtain a set of statistical feature values; the set of statistical feature values includes a median value, a mode value, a range value, and a variance value;
[0036] S32, use the coding dimension model to perform calculation processing on the length of the information to be sent and the set of statistical feature values to obtain a matrix row dimension value and a matrix column dimension value;
[0037] S33, based on the matrix row dimension value and the matrix column dimension value, use the information to be sent to construct an information matrix;
[0038] S34. Use a preset encoding matrix to perform encoding processing on the information matrix to obtain a matrix to be sent.
[0039] S35. Concatenate all row vectors of the matrix to be sent to obtain a transmission vector.
[0040] S36. Send the transmission vector to the system side.
[0041] The end of the communication process between the authentication side and the system side includes:
[0042] After the authentication side sends all the information to be sent to the system side, the system side generates a symbol sequence for executing the next wireless authentication method and sends the symbol sequence to the authentication side.
[0043] After receiving the symbol sequence, the authentication side stores it.
[0044] In the second aspect of the embodiments of the present application, a wireless authentication device against replay attacks is disclosed. The device includes:
[0045] A memory storing executable program code;
[0046] A processor coupled to the memory;
[0047] The processor calls the executable program code stored in the memory to execute the wireless authentication method against replay attacks.
[0048] In the third aspect of the embodiments of the present application, a computer-storable medium is disclosed. The computer-storable medium stores computer instructions, which are used to execute the wireless authentication method against replay attacks when called by a computer.
[0049] In the fourth aspect of the embodiments of the present application, an information data processing terminal is disclosed. The information data processing terminal is used to implement the wireless authentication method against replay attacks.
[0050] The beneficial effects of the present invention are:
[0051] Aiming at the problem of how to resist replay attacks in a wireless communication network, the present invention discloses a wireless authentication method against replay attacks. By establishing a two-layer verification system of device verification and identity verification, the problem of resisting replay attacks is effectively solved.
[0052] Traditional replay attacks are mainly achieved by forging device information. The present invention first generates a secret key S by the system side, encrypts the received symbol sequence using the secret key S, and the authentication side encrypts the stored device identifier using the received secret key S. By mutually verifying the two types of device information, the effectiveness of verification and the accuracy of identifying replay attacks are effectively improved.
[0053] For the discrimination process of the preset symbol sequence and the decryption sequence b, the present invention specifically designs a consistency discrimination processing algorithm, which improves the accuracy of the consistency discrimination result by effectively utilizing multi-source information. Brief Description of the Drawings
[0054] Figure 1 It is a flowchart of the implementation of the method of the present invention. Detailed Embodiment
[0055] To better understand the content of the present invention, an embodiment is given here.
[0056] Figure 1 It is a flowchart of the implementation of the method of the present invention.
[0057] In the first aspect of the embodiment of the present application, a wireless authentication method against replay attacks is disclosed, which is implemented through an authentication end and a system end, and includes:
[0058] S1, the authentication end and the system end perform device mutual verification to obtain device verification information; the device verification information includes system device verification information and authentication device verification information; both the authentication end and the system end include a security information area; the security information area includes an anti-counterfeiting information packet and a key data packet; both the authentication end and the system end store a system device list;
[0059] S2, based on the device verification information, the authentication end and the system end perform identity verification processing;
[0060] S3, the authentication end sends the information to be sent to the system end;
[0061] S4, the authentication end and the system end end the communication process.
[0062] The authentication end and the system end perform device mutual verification to obtain device verification information, including:
[0063] S11, the authentication end sends a preset symbol sequence to the system end; the preset symbol sequence can be a binary sequence corresponding to 32 / 64 / 128, or a symbol sequence stored in the authentication end;
[0064] S12, the system end generates a secret key S, uses the secret key S to encrypt the received symbol sequence to obtain an encrypted sequence a, and sends the secret key S and the encrypted sequence a to the authentication end;
[0065] S13, the authentication end uses the received secret key S to encrypt the stored device identifier to obtain an encrypted device identifier idN;
[0066] S14. The authentication end uses the received secret key S to decrypt the received encrypted sequence a to obtain a decrypted sequence b, and performs a consistency discrimination process on the preset symbol sequence and the decrypted sequence b to obtain a consistency discrimination result. If the consistency discrimination result is passed, the encrypted device identifier idN is sent to the system end to execute S15. If the consistency discrimination result is not passed, the communication process between the authentication end and the system end is stopped;
[0067] S15. The system end uses the stored authentication device list to determine whether the received encrypted device identifier idN is legal to obtain authentication device verification information. If the authentication device verification information is legal, the system end sends the security system device identifier IDN to the authentication end. If the authentication device verification information is not legal, the communication process between the authentication end and the system end is stopped;
[0068] S16. The authentication end uses the stored system device list to determine whether the received security system device identifier IDN is legal to obtain system device verification information;
[0069] If the system device verification information is legal, device verification information is constructed using the system device verification information and the authentication device verification information, and S2 is executed;
[0070] If the system device verification information is not legal, the communication process between the authentication end and the system end is stopped, and in the security information area of the authentication end, the security system device identifier IDN is added to the anti-counterfeiting information package Q;
[0071] The system end uses the stored authentication device list to determine whether the received encrypted device identifier idN is legal, which is to determine whether the received encrypted device identifier idN is in the stored authentication device list. If it is, it is legal; if not, it is not legal;
[0072] The authentication end uses the stored system device list to determine whether the received security system device identifier IDN is legal, which is to determine whether the security system device identifier IDN is in the stored system device list. If it is, it is legal; if not, it is not legal;
[0073] The consistency discrimination process between the preset symbol sequence and the decrypted sequence b includes:
[0074] The preset symbol sequence is represented as c;
[0075] A consistency calculation process is performed on sequence c and sequence b to obtain a consistency value;
[0076] The expression of the consistency calculation process is:
[0077] ,
[0078] Wherein, is the consistent value, N is the length of sequence b, and are the i-th elements of sequence b and sequence c respectively, is the preset deviation value;
[0079] Determine whether the consistent value is greater than the set consistency threshold. If it is greater, determine that the consistency discrimination result fails; if it is less than or equal to, determine that the consistency discrimination result passes.
[0080] The expression of the consistency calculation process comprehensively considers the differences between the corresponding elements of sequence b and sequence c. By calculating the differences of the elements at each corresponding position and combining the deviation situation of the exponential function, the consistency of the two sequences can be accurately measured. In wireless authentication, it can more accurately determine whether the received sequence is the correct decryption result of the original transmitted sequence, thereby improving the accuracy of authentication and reducing the misjudgment rate. In this expression, absolute value and division operations are used, which makes it more robust to noise and interference. In a wireless communication environment, signals are vulnerable to interference. This robustness can ensure that even if there is a certain degree of interference in the sequence, the consistency of the sequence can be accurately discriminated, ensuring the reliability of the authentication process.
[0081] In the above expression, the preset deviation value ε can be adjusted according to the actual communication environment and security requirements. In an environment with large interference, the value of ε can be appropriately increased to tolerate a certain degree of difference; while in a scenario with extremely high security requirements, the value of ε can be decreased to increase the strictness of consistency discrimination, so that the authentication system has better dynamic adaptability.
[0082] Based on the device verification information, the authentication end and the system end perform identity verification processing, including:
[0083] Judge whether both the system device verification information and the authentication device verification information in the device verification information are legal, and obtain the verification result information;
[0084] If the verification result information is all legal, the authentication end and the system end perform identity verification processing;
[0085] If the verification result information is not all legal, execute S1;
[0086] The authentication end and the system end perform identity verification processing, including:
[0087] S21, the authentication end sends the anti-counterfeiting information packet Q and the key data packet P stored in the security information area to the system end;
[0088] S22, the system end reads the key data packet P, determines whether the key data packet P is consistent with the key data packet stored in the security information area of the system end, and obtains a first verification result; if the first verification result is consistent, execute S23; if the first verification result is inconsistent, send an illegal identity warning message and stop the communication process between the authentication end and the system end;
[0089] S23, the system end reads the anti-counterfeiting information packet Q, determines whether the anti-counterfeiting information packet Q is an empty packet, and obtains a second verification result; if the second verification result is yes, the authentication end and the system end complete the identity verification process and execute S3; if the second verification result is no, send an illegal identity warning message and stop the communication process between the authentication end and the system end;
[0090] The authentication end sends the information to be sent to the system end, including:
[0091] Perform statistical processing on the information to be sent to obtain a set of statistical feature values; the set of statistical feature values includes median value, mode value, range value and variance value;
[0092] Use the coding dimension model to perform calculation processing on the length of the information to be sent and the set of statistical feature values to obtain the matrix row dimension value and the matrix column dimension value;
[0093] Based on the matrix row dimension value and the matrix column dimension value, use the information to be sent to construct an information matrix;
[0094] Use a preset coding matrix to perform coding processing on the information matrix to obtain a matrix to be sent;
[0095] Perform splicing processing on all row vectors of the matrix to be sent to obtain a sending vector;
[0096] Send the sending vector to the system end;
[0097] The authentication end and the system end end the communication process, including:
[0098] After the authentication end sends all the information to be sent to the system end, the system end generates a symbol sequence for the next wireless authentication method and sends the symbol sequence to the authentication end;
[0099] After the authentication end receives the symbol sequence, it stores the symbol sequence and uses the symbol sequence as the symbol sequence preset for the authentication end to send to the system end in subsequent wireless authentication;
[0100] The expression of the coding processing is:
[0101] ,
[0102] ,
[0103] Among them, is the Gaussian function, and are the time-domain transformation length and the frequency-domain transformation length respectively. A is the information matrix, P is the matrix to be transmitted, is the element in the k-th row and z-th column of the coding matrix, and G is the coding matrix.
[0104] The expression of the coding process, with the help of the Gaussian function and the information matrix A, realizes efficient information coding. The Gaussian function has good locality and attenuation characteristics, can effectively compress and code information within a limited bandwidth, reduce the amount of data transmitted, and improve the information transmission efficiency.
[0105] The expression of the coding process includes the time-domain transformation length and the frequency-domain transformation length, which enables the coding process to be flexibly adjusted in the time domain and the frequency domain; it can optimize the coding parameters according to different wireless communication channel characteristics and bandwidth limitations to adapt to different communication environments and improve the performance and adaptability of the system. The design of the coding matrix G combines the transformations in the time domain and the frequency domain and includes the operation of the exponential function, increasing the complexity of coding. This makes it difficult for attackers to crack the coding rules, improves the confidentiality of information during transmission, and effectively resists replay attacks and other forms of information theft.
[0106] The encoding of the information matrix using a preset coding matrix to obtain the matrix to be transmitted includes:
[0107] Performing cross-correlation calculations on all row vectors of the information matrix to obtain a cross-correlation matrix; the element in the i-th row and j-th column of the cross-correlation matrix is the cross-correlation value between the i-th row vector and the j-th row vector of the information matrix;
[0108] Performing singular value decomposition on the cross-correlation matrix to obtain an intermediate matrix;
[0109] Multiplying the preset coding matrix by the intermediate matrix to obtain an updated coding matrix;
[0110] Multiplying the updated coding matrix by the information matrix to obtain the matrix to be transmitted.
[0111] The expression of the singular value decomposition is Among them, is the intermediate matrix, and R is the cross-correlation matrix.
[0112] The expression of the coding dimension model is:
[0113] ,
[0114] ,
[0115] Among them, is the median value, is the mode value, is the variance value, is the range value, N is the length of the information to be sent, and are the matrix row dimension value and the matrix column dimension value respectively, represents rounding up, represents rounding down.
[0116] Based on the matrix row dimension value and the matrix column dimension value, using the information to be sent, an information matrix is constructed, including:
[0117] is to evenly divide the information to be sent into segmented vectors with a length of the matrix row dimension value;
[0118] Using all the segmented vectors as row vectors, an information matrix is constructed;
[0119] The authentication end is a terminal that needs to perform security authentication and communicate with the system end, and can be a mobile phone, a computer, an embedded system, etc.
[0120] The system end is a server that connects all the authentication ends and is installed with a security system;
[0121] In the second aspect of the embodiments of the present application, a wireless authentication device against replay attacks is disclosed. The device includes:
[0122] A memory storing executable program code;
[0123] A processor coupled to the memory;
[0124] The processor calls the executable program code stored in the memory and executes the wireless authentication method against replay attacks.
[0125] In the third aspect of the embodiments of the present application, a computer-readable storage medium is disclosed. The computer-readable storage medium stores computer instructions, and when the computer instructions are called by the computer, they are used to execute the wireless authentication method against replay attacks.
[0126] In the fourth aspect of the embodiments of the present application, an information data processing terminal is disclosed. The information data processing terminal is used to implement the wireless authentication method against replay attacks.
[0127] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A wireless authentication method against replay attacks, characterized in that It is implemented through an authentication terminal and a system terminal, including: S1. The authentication terminal and the system terminal perform mutual device verification to obtain device verification information; the device verification information includes system device verification information and authentication device verification information; both the authentication terminal and the system terminal include a security information area; the security information area includes an anti-counterfeiting information packet and a key data packet; both the authentication terminal and the system terminal store a system device list and a device identifier. S2. Based on the device verification information, the authentication terminal and the system terminal perform identity verification processing. S3. The authentication terminal sends the information to be sent to the system terminal. S4. The authentication terminal and the system terminal end the communication process. The authentication terminal and the system terminal perform mutual device verification to obtain device verification information, including: S11. The authentication terminal sends a preset symbol sequence to the system terminal. S12. The system terminal generates a secret key S, encrypts the received symbol sequence with the secret key S to obtain an encrypted sequence a, and sends the secret key S and the encrypted sequence a to the authentication terminal. S13. The authentication terminal encrypts the stored device identifier with the received secret key S to obtain an encrypted device identifier idN. S14. The authentication terminal decrypts the received encrypted sequence a with the received secret key S to obtain a decrypted sequence b, and performs a consistency discrimination process on the preset symbol sequence and the decrypted sequence b to obtain a consistency discrimination result. If the consistency discrimination result is passed, the encrypted device identifier idN is sent to the system terminal, and S15 is executed; if the consistency discrimination result is not passed, the communication process between the authentication terminal and the system terminal is stopped. S15. The system terminal uses the stored authentication device list to determine whether the received encrypted device identifier idN is legal to obtain authentication device verification information; if the authentication device verification information is legal, the system terminal sends a secure system device identifier IDN to the authentication terminal; if the authentication device verification information is not legal, the communication process between the authentication terminal and the system terminal is stopped. S16. The authentication terminal uses the stored system device list to determine whether the received secure system device identifier IDN is legal to obtain system device verification information. If the system device verification information is legal, the device verification information is constructed using the system device verification information and the authentication device verification information, and S2 is executed. If the system device verification information is not legal, the communication process between the authentication terminal and the system terminal is stopped, and in the security information area of the authentication terminal, the secure system device identifier IDN is added to the anti-counterfeiting information packet Q.
2. The wireless authentication method against replay attack according to claim 1, wherein The consistency discrimination process for the preset symbol sequence and the decrypted sequence b includes: Represent the preset symbol sequence as c. Perform a consistency calculation process on sequence c and sequence b to obtain a consistency value. The expression for the consistency calculation process is: , Among them, is a consistent value, N is the length of sequence b, and are the i-th elements of sequence b and sequence c respectively, is a preset deviation value; Determine whether the consistency value is greater than a set consistency threshold. If it is greater, determine that the consistency discrimination result is not passed; if it is less than or equal to, determine that the consistency discrimination result is passed.
3. The wireless authentication method against replay attack according to claim 1, wherein The identity verification processing performed by the authentication terminal and the system terminal based on the device verification information includes: Determine whether both the system device verification information and the authentication device verification information in the device verification information are legal to obtain verification result information; If the verification result information is all legal, the authentication end and the system end perform identity verification processing; If the verification result information is not all legal, execute S1.
4. The wireless authentication method against replay attack according to claim 3, wherein The authentication end and the system end perform identity verification processing, including: S21, the authentication end sends the anti-counterfeiting information packet Q and the key data packet P stored in the security information area to the system end; S22, the system end reads the key data packet P and determines whether the key data packet P is consistent with the key data packet stored in the security information area of the system end to obtain a first verification result; if the first verification result is consistent, execute S23; if the first verification result is inconsistent, an illegal identity warning message is issued, and the communication process between the authentication end and the system end is stopped; S23, the system end reads the anti-counterfeiting information packet Q and determines whether the anti-counterfeiting information packet Q is an empty packet to obtain a second verification result; if the second verification result is yes, the authentication end and the system end complete the identity verification processing and execute S3; if the second verification result is no, an illegal identity warning message is issued, and the communication process between the authentication end and the system end is stopped.
5. The wireless authentication method against replay attack according to claim 1, wherein The authentication end sends the information to be sent to the system end, including: S31, perform statistical processing on the information to be sent to obtain a set of statistical feature values; the set of statistical feature values includes a median value, a mode value, a range value, and a variance value; S32, use the coding dimension model to perform calculation processing on the length of the information to be sent and the set of statistical feature values to obtain a matrix row dimension value and a matrix column dimension value; The expression of the coding dimension model is: , , Among them, is the median value, is the mode value, is the variance value, is the range value, N is the length of the information to be sent, and are the matrix row dimension value and the matrix column dimension value respectively, represents rounding up, represents rounding down; S33, based on the matrix row dimension value and the matrix column dimension value, use the information to be sent to construct an information matrix; S34, use a preset coding matrix to perform coding processing on the information matrix to obtain a matrix to be sent; S35, splice all row vectors of the matrix to be sent to obtain a sending vector; S36, send the sending vector to the system end.
6. The wireless authentication method against replay attack according to claim 1, wherein, The authentication end and the system end end the communication process, including: After the authentication end sends all the information to be sent to the system end, the system end generates a symbol sequence for executing the next wireless authentication method and sends the symbol sequence to the authentication end; After receiving the symbol sequence, the authentication end stores it.
7. A wireless authentication device against replay attacks, characterized in that The device includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the wireless authentication method for anti-replay attack according to any one of claims 1 to 6.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, which are used to execute the wireless authentication method for anti-replay attack according to any one of claims 1 to 6 when called by a computer.
9. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the wireless authentication method for anti-replay attack according to any one of claims 1 to 6.
Citation Information
Patent Citations
Method for verifying legal terminal information extension sequence
CN111787014A
Privacy protection authentication method based on wireless body area network
US20230075612A1