Cloud and mist cooperative authentication key negotiation method and device based on elliptic curve

Through the combination of cloud and fog collaboration and elliptic curve cryptography, the problem of large computing burden and authentication delay is solved, safe and efficient authentication and key negotiation are achieved, and system performance is improved.

CN120263386AActive Publication Date: 2025-07-04ZHEJIANG SCI-TECH UNIV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510735769.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-04
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

The traditional security authentication and key negotiation protocols have high computing overhead for fog computing nodes with limited resources, resulting in computing burden and authentication delays, affecting system efficiency and response speed.

Method used

Through cloud-fog collaboration, the computing-intensive tasks of the fog node are handed over to the cloud platform, and the elliptic curve cryptography is used for encryption to ensure the security of the authentication and key negotiation process, and the user identity information is protected using pseudo-passwords, random numbers and biometrics.

Benefits of technology

It reduces the computing burden of fog nodes, reduces energy consumption and certification delays, improves the overall efficiency and response speed of the system, especially in large-scale IoT environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263386A_ABST
    Figure CN120263386A_ABST
Patent Text Reader

Abstract

The invention provides a cloud and fog cooperative authentication key negotiation method and device based on an elliptic curve. The method comprises the following steps: establishing an Internet of Things system including user equipment, a cloud server, a fog node and Internet of Things equipment; the user equipment and the cloud server send registration requests to the fog node, the Internet of Things equipment sends requests to the cloud server, and corresponding registration parameters are generated and stored; when a user calls the Internet of Things equipment, an authentication message is constructed by using elliptical encryption, the authentication message is verified by the fog node, the cloud server and the Internet of Things equipment in sequence, the Internet of Things equipment generates a message and returns the message to the user equipment after verification of each link is passed, and the user equipment extracts a key to call the Internet of Things equipment after verification. According to the scheme, part of calculation tasks of the fog node are transferred to the cloud platform in a cloud and fog cooperation mode, so that the burden of the fog node is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security, and particularly to a cloud and fog collaborative authentication key negotiation method and device based on elliptic curves. Background Art

[0002] With the rapid development of cloud computing and the Internet of Things, cloud computing and fog computing have become important computing architectures to address the growing data processing and storage requirements. However, with the sharp increase in the number of Internet of Things devices and fog computing nodes, the communication between these devices faces unprecedented security challenges. First, most traditional security authentication and key negotiation protocols rely on centralized cloud computing resources or local high-performance computing capabilities, which often bring relatively large computational overheads and communication burdens to fog computing nodes with limited resources. Especially in the Internet of Things environment where a large number of devices are involved, the security overheads of fog computing nodes (such as identity authentication, key negotiation, etc.) have become an important bottleneck affecting the overall system efficiency and response speed. Fog nodes are usually limited by computing power, storage space, and bandwidth. Directly undertaking excessive encryption computing tasks not only increases energy consumption but also leads to longer authentication delays, thus affecting the system performance and user experience.

[0003] Therefore, how to reduce the computational burden of fog nodes and improve the response speed of the system while ensuring security is an urgent problem to be solved in the prior art. Summary of the Invention

[0004] The embodiments of the present application provide a cloud and fog collaborative authentication key negotiation method and device based on elliptic curves, which transfer some of the computational tasks of fog nodes to the cloud platform through cloud and fog collaboration, thereby reducing the burden on fog nodes.

[0005] In a first aspect, the embodiments of the present application provide a cloud and fog collaborative authentication key negotiation method based on elliptic curves, and the method includes: Build an Internet of Things system, where the Internet of Things system includes user equipment, a cloud server, fog nodes, and Internet of Things devices. The user equipment and the cloud server respectively send user registration requests and cloud server registration requests to the fog nodes. The fog nodes respectively generate user registration parameters and cloud server registration parameters based on the user registration requests and the cloud server registration requests and store them in the fog node storage unit. The Internet of Things device sends a device registration request to the cloud server, and the cloud server generates device registration parameters based on the device registration request and stores them in the cloud server storage unit; When the user device invokes the Internet of Things device, an elliptic encryption method is used to construct a user authentication message and send it to the fog node. The fog node verifies the user authentication message based on the user registration parameters in the fog node storage unit. After successful verification, the fog node generates a fog node authentication message based on the cloud server registration parameters in the fog node storage unit and sends the fog node authentication message to the cloud server; The cloud server verifies the fog node authentication message based on its own cloud server registration parameters. After successful verification, the cloud server generates a cloud server authentication message based on the Internet of Things device registration parameters in the cloud server storage unit and sends the cloud server authentication message to the Internet of Things device; The Internet of Things device verifies the cloud server authentication message based on its own device registration parameters. After successful verification, the Internet of Things device generates a device authentication message and sends it to the user device. The user device verifies the device authentication message. After successful verification, the user device extracts the key from the device authentication message to invoke the Internet of Things device.

[0006] In a second aspect, an embodiment of the present application provides a cloud-fog collaborative authentication key negotiation device based on an elliptic curve, including: A registration module for building an Internet of Things system. The Internet of Things system includes a user device, a cloud server, a fog node, and an Internet of Things device. The user device and the cloud server respectively send a user registration request and a cloud server registration request to the fog node. The fog node respectively generates user registration parameters and cloud server registration parameters based on the user registration request and the cloud server registration request and stores them in the fog node storage unit. The Internet of Things device sends a device registration request to the cloud server. The cloud server generates device registration parameters based on the device registration request and stores them in the cloud server storage unit; A fog node authentication module. When the user device invokes the Internet of Things device, an elliptic encryption method is used to construct a user authentication message and send it to the fog node. The fog node verifies the user authentication message based on the user registration parameters in the fog node storage unit. After successful verification, the fog node generates a fog node authentication message based on the cloud server registration parameters in the fog node storage unit and sends the fog node authentication message to the cloud server; A cloud server authentication module. The cloud server verifies the fog node authentication message based on its own cloud server registration parameters. After successful verification, the cloud server generates a cloud server authentication message based on the Internet of Things device registration parameters in the cloud server storage unit and sends the cloud server authentication message to the Internet of Things device; The user device authentication module. The IoT device verifies the cloud server authentication message based on its own device registration parameters. After successful verification, the IoT device generates a device authentication message and sends it to the user device. The user device verifies the device authentication message and extracts the key from the device authentication message to call the IoT device after successful verification.

[0007] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute a cloud and fog collaborative authentication key negotiation method based on elliptic curves.

[0008] The main contributions and innovations of the present invention are as follows: In the registration process of the embodiment of the present application, the real identity information of the user is encrypted and hashed, avoiding direct exposure of the user's identity information. By using mechanisms such as pseudo passwords, random numbers, and biometric features, the user's identity information is ensured to be protected during transmission and storage. The embodiment of the present application adopts an encryption technology based on elliptic curve cryptography to ensure the security of the authentication and key negotiation process and can effectively resist various attacks. The fog node in the embodiment of the present application delegates computationally intensive authentication and key negotiation tasks to the cloud computing platform, thereby reducing the computational burden on the fog node, reducing energy consumption and authentication latency. And since the fog node no longer needs to bear overly heavy computational tasks alone, the overall efficiency and response speed of the system have been significantly improved, especially in a large-scale IoT environment. The user authentication message generated by the user device in the embodiment of the present application is generated through a combination of information such as user identifiers, timestamps, and random numbers, and through hash functions and encryption processing, so that the user's identity information is not directly exposed during the authentication process, realizing anonymous authentication.

[0009] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings: Figure 1 is a schematic diagram of a cloud and fog collaborative authentication key negotiation method based on elliptic curves according to an embodiment of the present application; Figure 2 is a block diagram of the structure of a cloud and fog collaborative authentication key negotiation device based on elliptic curves according to an embodiment of the present application; Figure 3Schematic diagram of the hardware structure of the electronic device according to an embodiment of the present application. Detailed implementation manners

[0011] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all the implementation manners consistent with one or more embodiments of this specification. On the contrary, they are merely examples of the devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.

[0012] It should be noted that: In other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.

[0013] Embodiment 1 The embodiment of the present application provides a cloud and fog collaborative authentication key negotiation method based on elliptic curves. By means of cloud and fog collaboration, part of the computing tasks of the fog node are transferred to the cloud platform, thereby reducing the burden on the fog node. Specifically, referring to Figure 1 , the method includes: Build an Internet of Things system, which includes user equipment, a cloud server, a fog node, and Internet of Things devices. The user equipment and the cloud server respectively send user registration requests and cloud server registration requests to the fog node. The fog node respectively generates user registration parameters and cloud server registration parameters based on the user registration request and the cloud server registration request and stores them in the fog node storage unit. The Internet of Things device sends a device registration request to the cloud server, and the cloud server generates device registration parameters based on the device registration request and stores them in the cloud server storage unit; When the user equipment calls the Internet of Things device, use the elliptic encryption method to construct a user authentication message and send it to the fog node. The fog node verifies the user authentication message based on the user registration parameters in the fog node storage unit. After passing the verification, the fog node generates a fog node authentication message based on the cloud server registration parameters in the fog node storage unit, and sends the fog node authentication message to the cloud server; The cloud server verifies the fog node authentication message based on its own cloud server registration parameters. After passing the verification, the cloud server generates a cloud server authentication message based on the Internet of Things device registration parameters in the cloud server storage unit and sends it to the Internet of Things device; The IoT device verifies the cloud server authentication message based on its own device registration parameters. After successful verification, the IoT device generates a device authentication message and sends it to the user device. The user device verifies the device authentication message and, upon successful verification, extracts the key from the device authentication message to invoke the IoT device.

[0014] In some embodiments, the user device selects a unique user identifier and password, performs a hash operation on the user identifier and password to generate a pseudo password, and uses the pseudo password and the user identifier as a user registration request.

[0015] Specifically, a unique user identifier is selected for the user device and password , where i represents the i-th user. The calculation formula for the pseudo password is:

[0016] where, represents a one-way hash function, represents concatenation, is the user identifier, is the password.

[0017] Furthermore, the user device generates a user random number and performs an exclusive OR operation on the user random number and the pseudo password in the user registration request.

[0018] Specifically, by introducing the user random number to perform the exclusive OR operation on the pseudo password, the user device can ensure that each user registration request transmitted has uniqueness, thereby guaranteeing the security of user identity information during transmission.

[0019] That is to say, the user registration request after introducing the random number is .

[0020] In some embodiments, when the fog node receives the user registration request, it generates a first fog node random number, calculates a user credential based on the first fog node random number and the user identifier, and uses the user credential, the user identifier, and the first fog node random number as user registration parameters.

[0021] Specifically, the formula for calculating the user credential is as follows:

[0022] where e is a preset parameter of the IoT system, is the user credential, represents a one-way hash function, represents concatenation, is the user identifier, b is the first fog node random number, is the user credential.

[0023] That is to say, the user registration parameters are represented as .

[0024] In some specific embodiments, the registration credential parameters are calculated based on the user credential, the user random number, and the pseudo password and returned to the user device. The user device calculates the login parameters based on the registration credential and saves them in the storage unit of the user device. When the user logs in on the user device using the password, the login is successful when the login parameters calculated based on the password are equal to the login parameters in the storage unit of the user device.

[0025] Specifically, the calculation formula of the registration credential is as follows:

[0026] Wherein, is the pseudo password, is the user credential, is the user random number, is the registration credential parameter.

[0027] Specifically, the user device calculates the identity credential parameters , and . When the above calculations are completed, the login parameters are saved in the storage unit of the user device.

[0028] Specifically, when the user logs in on the user device using the password, the pseudo password is calculated based on the password input by the user, and then the login parameters are restored based on the pseudo password. The login is successful when the login parameters restored by the pseudo password are equal to the login parameters in the storage unit of the user device.

[0029] Specifically, the formula for restoring the login parameters through the pseudo password is expressed as follows: , and

[0030] Specifically, the parameters in the above formula are explained in detail in the previous text and will not be repeated here.

[0031] That is to say, when the restored through the pseudo password is equal to the in the login parameters, the login is successful.

[0032] In some specific embodiments, when the user device receives the registration credential, a biometric feature is implanted in the user device and used as one of the login methods.

[0033] Specifically, the formula for implanting the biometric feature is expressed as follows:

[0034] Among them, is the generation function of the biometric fuzzy extractor, is the string corresponding to the user's biometric feature, is the auxiliary string for restoring the string, is the biometric feature.

[0035] Specifically, the formula for logging in using the biometric feature is as follows:

[0036] Among them, is the restoration function of the biometric extractor, is the biometric feature, is the auxiliary string for restoring the string, is the string corresponding to the user's biometric feature. That is to say, if can be obtained through the above formula, it indicates that the biometric feature is correct and the login is successful; otherwise, the login fails.

[0037] Specifically, in the registration process of this solution, the user's real identity information is processed through encryption and hashing, avoiding the direct exposure of the user's identity information, and through mechanisms such as using pseudo passwords, random numbers, and biometric features, ensuring the protection of the user's identity information during transmission and storage.

[0038] In some embodiments, the cloud server selects a unique cloud server identifier as the cloud server registration request and sends it to the fog node. When the fog node receives the cloud server registration request, it generates a second fog node random number, calculates the cloud server credential based on the cloud server registration request and the second fog node random number, and uses the cloud server identifier, the second fog node random number, and the cloud server credential as the cloud server registration parameters.

[0039] Specifically, the calculation formula for the cloud server credential is as follows:

[0040] Among them, is the cloud server credential, represents a one-way hash function, represents concatenation, is the cloud server identifier, e is a preset parameter of the Internet of Things system, is the second fog node random number.

[0041] That is to say, the cloud server registration parameters are represented as .

[0042] Specifically, when the fog node calculates the cloud server credential, it returns the cloud server credential to the cloud server through a secure channel. When the cloud server receives the cloud server credential, it stores its own identity parameters in the local database.

[0043] In some embodiments, the Internet of Things device selects a unique Internet of Things device identifier as a device registration request and sends it to the cloud server. The cloud server generates a device credential based on the device registration request and the cloud server credential, and uses the device identifier and the device credential as device registration parameters.

[0044] Specifically, the formula for the device credential is as follows:

[0045] where is the device credential, represents a one-way hash function, represents concatenation, is the cloud server credential, is the device identifier.

[0046] That is to say, the device registration parameters are represented as .

[0047] Specifically, when the cloud server calculates the device credential, it returns the device credential to the Internet of Things device through a secure channel. When the Internet of Things device receives the device credential, it saves it in the local memory of the Internet of Things device.

[0048] In some embodiments, the user device selects a first user random number m and sets a user sending timestamp . The user authentication message includes a first encryption parameter , an encrypted user identifier , a user authentication parameter , and a user sending timestamp . The formula for the first encryption parameter is expressed as , where P is the generator of the elliptic curve. The formula for the encrypted user identifier is expressed as , where is the user identifier, is the user sending timestamp, is the device identifier, represents a one-way hash function, represents concatenation, is the first encryption parameter, is the second encryption parameter, , , where e is a preset parameter of the IoT system, the user authentication parameter is represented by the formula , where is the user credential.

[0049] It is worth mentioning that there may be multiple IoT devices in the IoT system, and the device identifier in the user authentication message is the device identifier of the IoT device that the user device wants to call.

[0050] Furthermore, obtain the fog node reception timestamp when the fog node receives the user authentication message, and judge the absolute value of the difference between the fog node reception timestamp and the user sending timestamp. If the absolute value is less than or equal to the verification time threshold, then verify the user authentication message.

[0051] Exemplarily, taking as the fog node reception timestamp, as the verification time threshold, judge whether holds. If it holds, then verify the user authentication message. If it does not hold, then do not perform subsequent verification steps.

[0052] Specifically, when the fog node verifies the user authentication message, calculate the second encryption parameter based on the first encryption parameter . Through the first encryption parameter , the second encryption parameter and the user registration parameter in the fog node storage unit to recalculate the user authentication parameter. If the recalculated user authentication parameter is equal to the user authentication parameter in the received user authentication message, the verification passes; otherwise, the verification fails.

[0053] Specifically, in the verification stage, obtain by calculating as the recalculated user authentication parameter.

[0054] Specifically, this solution adopts an encryption technology based on elliptic curve cryptography, ensuring the security of the authentication and key negotiation process and being able to effectively resist various attacks.

[0055] Specifically, the user authentication message generated by the user device is generated through a combination of information such as the user identifier, timestamp, and random number, and through a hash function and encryption processing, so that the user's identity information will not be directly exposed during the authentication process, realizing anonymous authentication.

[0056] In some embodiments, after the fog node verifies the user authentication message, obtain the fog node sending timestamp And generate a fog node authentication message, where the fog node authentication message includes a cloud server credential , a fog node identifier , fog node authentication parameters , and a fog node sending timestamp , where the fog node identifier , fog node authentication parameters .

[0057] Specifically, the meanings of the same parameters have been described in detail above and will not be elaborated here.

[0058] Furthermore, obtain the cloud server receiving timestamp when the cloud server receives the fog node authentication message, and judge the absolute value of the difference between the cloud server receiving timestamp and the fog node sending timestamp. If the absolute value is less than or equal to the verification time threshold, then verify the fog node authentication message.

[0059] Exemplarily, take as the cloud server receiving timestamp, and judge whether holds. If it holds, then verify the fog node authentication message. If it does not hold, then do not perform subsequent verification steps.

[0060] Specifically, when the cloud server verifies the fog node authentication message, it recalculates the fog node authentication parameters through its own cloud server registration parameters of the cloud server. If the recalculated fog node authentication parameters are equal to the fog node authentication parameters in the received fog node authentication message, the verification passes; otherwise, the verification fails.

[0061] Specifically, the fog node delegates computationally intensive authentication and key negotiation tasks to the cloud computing platform, thereby reducing the computational burden of the fog node, reducing energy consumption and authentication latency, and since the fog node no longer needs to bear overly heavy computational tasks alone, the overall efficiency and response speed of the system have been significantly improved, especially in a large-scale Internet of Things environment.

[0062] In some embodiments, after the cloud server verifies the fog node authentication message, set the cloud server sending timestamp and generate a cloud server authentication message, where the cloud server authentication message includes the cloud server sending timestamp , a third encryption parameter , and a cloud server authentication parameter , where the third encryption parameter , and the cloud server authentication parameter .

[0063] Further, obtain the device reception timestamp when the Internet of Things device receives the cloud server authentication parameter, and judge the absolute value of the difference between the device reception timestamp and the cloud server sending timestamp. If the absolute value is less than or equal to the verification time threshold, then verify the cloud server authentication parameter.

[0064] Exemplarily, take as the device reception timestamp, and judge whether holds. If it holds, then verify the cloud server authentication message. If it does not hold, then do not perform subsequent verification steps.

[0065] Specifically, in the process of the Internet of Things device verifying the cloud server authentication message, calculate the first encryption parameter according to the third encryption parameter based on the device registration parameter of the Internet of Things device itself, that is , and then recalculate the cloud server authentication parameter according to the first encryption parameter and its own device registration parameter . If the recalculated cloud server authentication parameter is equal to the received cloud server authentication parameter, the verification passes; otherwise, the verification fails.

[0066] In some embodiments, after the Internet of Things device verifies the cloud server authentication message, generate a device random number n and a device sending timestamp , and use the device sending timestamp , the device encryption parameter and the device authentication parameter as the device authentication message. Among them, the device encryption parameter , P is the generator of the elliptic function, the device authentication parameter , where represents a one-way hash function, represents concatenation, SK is the key, , F is the encryption parameter, , m is the user random number, is the first encryption parameter.

[0067] Further, obtain the user reception timestamp when the user device receives the device authentication message, and judge the absolute value of the difference between the user reception timestamp and the device sending timestamp. If the absolute value is less than or equal to the verification time threshold, then verify the device authentication parameter.

[0068] Exemplarily, take as the user reception timestamp, and judge whether holds. If it holds, then verify the device verification message. If it does not hold, then do not perform subsequent verification steps.

[0069] Specifically, in the process of the user device verifying the device authentication message, the user device recalculates the encryption parameter using the user random number and the secret key as well as the device authentication parameter , if the recalculated device authentication parameter is equal to the device authentication parameter in the received device authentication message, then use as the secret key

[0070] Embodiment 2 Based on the same concept, referring to Figure 2 , the present application also proposes a cloud and fog collaborative authentication key negotiation device based on elliptic curves, including: A registration module, configured to build an Internet of Things system, the Internet of Things system includes user equipment, a cloud server, fog nodes, and Internet of Things devices, the user equipment and the cloud server respectively send user registration requests and cloud server registration requests to the fog nodes, the fog nodes respectively generate user registration parameters and cloud server registration parameters based on the user registration requests and cloud server registration requests and store them in the fog node storage unit, the Internet of Things device sends a device registration request to the cloud server, and the cloud server generates device registration parameters based on the device registration request and stores them in the cloud server storage unit; A fog node authentication module, when the user equipment invokes the Internet of Things device, uses the elliptic encryption method to construct a user authentication message and send it to the fog node, the fog node verifies the user authentication message based on the user registration parameters in the fog node storage unit, after verification, the fog node generates a fog node authentication message based on the cloud server registration parameters in the fog node storage unit, and sends the fog node authentication message to the cloud server; A cloud server authentication module, the cloud server verifies the fog node authentication message based on its own cloud server registration parameters, after verification, the cloud server generates a cloud server authentication message based on the Internet of Things device registration parameters in the cloud server storage unit and sends it to the Internet of Things device; A user equipment authentication module, the Internet of Things device verifies the cloud server authentication message based on its own device registration parameters, after verification, the Internet of Things device generates a device authentication message and sends it to the user equipment, and the user equipment verifies the device authentication message, after verification, extracts the secret key from the device authentication message and invokes the Internet of Things device.

[0071] Embodiment 3 This embodiment also provides an electronic device, referring to Figure 3 , including a memory 404 and a processor 402, the memory 404 stores a computer program, and the processor 402 is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0072] Specifically, the above-mentioned processor 402 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured as one or more integrated circuits for implementing the embodiments of the present application.

[0073] Among them, the memory 404 may include a mass storage 404 for data or instructions. By way of example and not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 404 may include removable or non-removable (or fixed) media. Where appropriate, the memory 404 may be internal or external to the data processing device. In a particular embodiment, the memory 404 is non-volatile memory. In a particular embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. Where appropriate, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.

[0074] The memory 404 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402.

[0075] The processor 402 reads and executes the computer program instructions stored in the memory 404 to implement any one of the elliptic curve-based cloud and fog collaborative authentication key agreement methods in the above embodiments.

[0076] Optionally, the above electronic device may further include a transmission device 406 and an input / output device 408. Among them, the transmission device 406 is connected to the above processor 402, and the input / output device 408 is connected to the above processor 402.

[0077] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above network may include wired or wireless networks provided by the communication provider of the electronic device. In one example, the transmission device includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one example, the transmission device 406 can be a radio frequency (Radio Frequency, abbreviated as RF) module, which is used to communicate with the Internet wirelessly.

[0078] The input / output device 408 is used to input or output information. In this embodiment, the input information can be a user registration request, a cloud server registration request, etc., and the output information can be a key, etc.

[0079] Optionally, in this embodiment, the above processor 402 can be set to execute the following steps through a computer program: Build an Internet of Things system, the Internet of Things system includes user equipment, a cloud server, fog nodes, and Internet of Things devices. The user equipment and the cloud server respectively send a user registration request and a cloud server registration request to the fog nodes. The fog nodes respectively generate user registration parameters and cloud server registration parameters based on the user registration request and the cloud server registration request and store them in the fog node storage unit. The Internet of Things device sends a device registration request to the cloud server, and the cloud server generates device registration parameters based on the device registration request and stores them in the cloud server storage unit; When the user equipment calls the Internet of Things device, use the elliptic encryption method to construct a user authentication message and send it to the fog node. The fog node verifies the user authentication message based on the user registration parameters in the fog node storage unit. After verification, the fog node generates a fog node authentication message based on the cloud server registration parameters in the fog node storage unit and sends the fog node authentication message to the cloud server; The cloud server verifies the fog node authentication message based on its own cloud server registration parameters. After successful verification, the cloud server generates a cloud server authentication message based on the Internet of Things device registration parameters in the cloud server storage unit and sends it to the Internet of Things device. The Internet of Things device verifies the cloud server authentication message based on its own device registration parameters. After successful verification, the Internet of Things device generates a device authentication message and sends it to the user device. The user device verifies the device authentication message and, after successful verification, extracts a key from the device authentication message to invoke the Internet of Things device.

[0080] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated herein.

[0081] Generally, various embodiments can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects of the present invention can be implemented in hardware, while other aspects can be implemented by firmware or software executed by a controller, microprocessor, or other computing device. However, the present invention is not limited thereto. Although various aspects of the present invention can be shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or a controller, or other computing devices, or some combination thereof.

[0082] Embodiments of the present invention can be implemented by computer software, which can be executed by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. A computer software or program (also referred to as a program product), including software routines, applets, and / or macros, can be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. The computer program product can include one or more computer-executable components configured to execute the embodiments when the program runs. The one or more computer-executable components can be at least one software code or a part thereof. Additionally, at this point, it should be noted that any block in the logical flow, as Figure 3 shown, can represent a program step, or an interconnected logical circuit, block, and function, or a combination of program steps and logical circuits, blocks, and functions. The software can be stored on physical media such as memory chips or storage blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs. The physical media are non-transitory media.

[0083] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity in description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0084] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A cloud and fog collaborative authentication key negotiation method based on elliptic curves, characterized in that Including the following steps: Build an Internet of Things (IoT) system, where the IoT system includes user devices, cloud servers, fog nodes, and IoT devices. Register the user devices and cloud servers in the fog nodes, and register the IoT devices in the cloud server; When a user device calls an IoT device, use the elliptic encryption method to construct a user authentication message and send it to the fog node. The fog node verifies the user authentication message. After successful verification, it generates a fog node authentication message and sends it to the cloud server; The cloud server verifies the fog node authentication message. After successful verification, the cloud server generates a cloud server authentication message and sends it to the IoT device; The IoT device verifies the cloud server authentication message. After successful verification, it generates a device authentication message and sends it to the user device. The user device verifies the device authentication message. After successful verification, it extracts the key from the device authentication message to call the IoT device.

2. The cloud and fog collaborative authentication key negotiation method based on elliptic curve according to claim 1, characterized in that, The user device sends a user registration request to the fog node. The fog node generates user registration parameters based on the user registration request and stores them in the fog node storage unit to complete the registration of the user device in the fog node. Among them, the user device selects a unique user identifier and password, performs a hash operation on the user identifier and password to generate a pseudo-password, and sends the pseudo-password and user identifier as a user registration request to the fog node. When the fog node receives the user registration request, it generates a first fog node random number, calculates the user credential based on the first fog node random number and the user identifier, and uses the user credential, user identifier, and first fog node random number as user registration parameters.

3. The method for cloud and fog collaborative authentication key negotiation based on elliptic curve according to claim 1, wherein Calculate the registration credential parameters based on the user credential, user random number, and pseudo-password and return them to the user device. The user device calculates the login parameters based on the registration credential and saves them in the storage unit of the user device. When the user logs in on the user device using the password, the login is successful when the login parameters calculated based on the password are equal to the login parameters in the user device storage unit.

4. A cloud and fog collaborative authentication key negotiation method based on elliptic curves according to claim 1, characterized in that The cloud server sends a cloud server registration request to the fog node. The fog node generates cloud server registration parameters based on the cloud server registration request and stores them in the fog node storage unit to complete the registration of the cloud server in the fog node. Among them, the cloud server selects a unique cloud server identifier as the cloud server registration request and sends it to the fog node. When the fog node receives the cloud server registration request, it generates a second fog node random number, calculates the cloud server credential based on the cloud server registration request and the second fog node random number, and uses the cloud server identifier, second fog node random number, and cloud server credential as cloud server registration parameters.

5. A cloud and fog collaborative authentication key negotiation method based on elliptic curves according to claim 1, characterized in that, The IoT device sends a device registration request to the cloud server. The cloud server generates device registration parameters based on the device registration request and stores them in the cloud server storage unit to complete the registration of the IoT device in the cloud server. Among them, the IoT device selects a unique IoT device identifier as the device registration request and sends it to the cloud server. The cloud server generates a device credential based on the device registration request and the cloud server credential, and uses the device identifier and device credential as device registration parameters.

6. The method for cloud and fog collaborative authentication key negotiation based on elliptic curve according to claim 1, wherein, Obtain the fog node reception timestamp when the fog node receives the user authentication message, and judge the absolute value of the difference between the fog node reception timestamp and the user sending timestamp. If the absolute value is less than or equal to the verification time threshold, verify the user authentication message; Obtain the cloud server reception timestamp when the cloud server receives the fog node authentication message, and judge the absolute value of the difference between the fog node sending timestamp and the cloud server reception timestamp. If the absolute value is less than the verification time threshold, verify the fog node authentication message; Obtain the device reception timestamp when the Internet of Things device receives the cloud server authentication parameter, and judge the absolute value of the difference between the device reception timestamp and the cloud server sending timestamp. If the absolute value is less than or equal to the verification time threshold, verify the cloud server authentication parameter; Obtain the user reception timestamp when the user device receives the device authentication message, and judge the absolute value of the difference between the user reception timestamp and the device sending timestamp. If the absolute value is less than or equal to the verification time threshold, verify the device authentication parameter.

7. A cloud and fog collaborative authentication key negotiation method based on elliptic curves according to claim 1, characterized in that, After the IoT device successfully verifies the authentication message from the cloud server, it generates a device random number n and a device sending timestamp , and uses the device sending timestamp , device encryption parameters , and device authentication parameters as the device authentication message. Among them, the device encryption parameter , where P is the generator of the elliptic function, and the device authentication parameter , where represents a one-way hash function represents concatenation, SK is the key , F is the encryption parameter , m is the user random number is the first encryption parameter 8. The method for cloud and fog collaborative authentication key negotiation based on elliptic curve according to claim 7, characterized in that During the process of the user equipment verifying the device authentication message, the user equipment recalculates the encryption parameters using the user random number , the key and the device authentication parameter . If the recalculated device authentication parameter is equal to the device authentication parameter in the received device authentication message, then use as the key 9. A cloud and fog collaborative authentication key negotiation device based on elliptic curves, characterized in that, Comprising: A registration module for building an Internet of Things system, the Internet of Things system including a user device, a cloud server, a fog node, and an Internet of Things device, registering the user device and the cloud server in the fog node, and registering the Internet of Things device in the cloud server; A fog node authentication module, when the user device invokes the Internet of Things device, constructs a user authentication message using elliptic encryption and sends it to the fog node. The fog node verifies the user authentication message, and after verification, generates a fog node authentication message and sends it to the cloud server; A cloud server authentication module, the cloud server verifies the fog node authentication message, and after verification, the cloud server generates a de-server authentication message and sends it to the Internet of Things device; A user device authentication module, the Internet of Things device verifies the cloud server authentication message, and after verification, generates a device authentication message and sends it to the user device. The user device verifies the device authentication message, and after verification, extracts a key from the device authentication message to invoke the Internet of Things device.

10. An electronic device, comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is set to run the computer program to execute a method for elliptic curve-based cloud and fog collaborative authentication key negotiation according to any one of claims 1-8.

Citation Information

Patent Citations

  • Internet of Things equipment authentication method based on block chain

    CN110691088A

  • Remote secure communication method, system, device and terminal of touch Internet of Things

    CN114978712A

  • Combination attack resistant block chain medical internet of things authentication system and method

    CN118869314A

  • Industrial internet of things dynamic anonymous authentication method based on Cloud-Fog-Assisted technology

    CN120074913A

  • Security and device control method for fog computer using blockchain technology

    KR1020180137251A