Internet of Things equipment authentication and access control method for zero trust
Through the zero-trust model and blockchain technology, combined with RF fingerprint and Chebishev chaos mapping, the authentication and access control of IoT devices are dynamically adjusted, and the problems of insufficient security and poor adaptability in traditional methods are solved, achieving efficient and secure authentication and access control.
Patent Information
- Application Number
- CN202510766402.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-10
AI Technical Summary
When traditional IoT device authentication and access control methods face heterogeneity, limited computing power and environmental changes, they have problems such as insufficient security, complex permission management, large computing overhead, and untraceability of data, making it difficult to meet efficient and secure authentication and access control needs.
The zero-trust model is used to combine the authentication mechanism of RF fingerprint and Chebishev chaos mapping to dynamically adjust the authentication strength, combine blockchain technology to store device authentication information, and adjust access permissions based on real-time environmental data to provide a secure and transparent authentication and access control solution.
It realizes high security and dynamic adaptability of IoT device authentication and access control, improves authentication efficiency and system security, and ensures traceability and immutability of device identity.
Smart Images

Figure CN120281585A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and specifically to an authentication and access control method for Internet of Things devices for zero trust. Background Art
[0002] As an important infrastructure of modern digital society, the Internet of Things has been widely applied in many fields such as smart home, smart city, industrial control, vehicle networking, medical health, etc. The popularization of Internet of Things devices has greatly improved the convenience of information interaction and the automation level of the system, but at the same time has also brought new security risks. Due to the heterogeneity, interoperability and limited computing power of Internet of Things devices, traditional device authentication and access control methods have exposed many problems when facing the Internet of Things environment. How to construct an efficient, secure and privacy-protected authentication and access control mechanism has become a key challenge in current Internet of Things security research.
[0003] Traditional identity authentication and access control methods mainly rely on pre-set access policies or trust-based models. For example, role-based access control, although widely used, has problems of permission abuse and complex management; attribute-based access control can provide more fine-grained permission management, but it is prone to policy conflicts when dealing with large-scale device access. In addition, traditional methods usually do not consider the changes in device environment and behavior characteristics, resulting in attackers being able to bypass security protection by stealing credentials or simulating legitimate devices, thus posing potential threats to the stability of the system and the confidentiality of data. Therefore, there is an urgent need for a more secure and dynamically adaptable authentication mechanism to ensure the credibility of device and user identities and strictly control access permissions. Specifically:
[0004] (1) Security and efficiency of the authentication process: Traditional identity authentication methods are vulnerable to threats such as credential leakage and man-in-the-middle attacks. The present invention adopts a mechanism combining strong authentication and weak authentication, dynamically adjusts the authentication strength according to the device status, effectively improves the authentication efficiency and system response speed while ensuring security. At the same time, by combining radio frequency fingerprint with Chebyshev chaotic mapping, the uniqueness and non-forgery of device authentication are ensured, further improving the security of the authentication process.
[0005] (2) Dynamic adaptability of the access control mechanism: Traditional access control policies based on roles and attributes lack real-time adaptation ability and cannot be dynamically adjusted according to the environmental status or behavior changes of devices. The present invention combines the zero trust model and dynamically adjusts access permissions based on environmental factors such as real-time interaction logs and location information of devices to avoid permission abuse and illegal access.
[0006] (3)Lightweight Design of Device Authentication: Internet of Things devices usually have limited computing resources and are difficult to carry complex authentication algorithms. Existing public key cryptography schemes have large computational overheads and are difficult to meet the requirements of low power consumption and efficient authentication. The present invention uses Chebyshev chaotic mapping to provide a secure and efficient key negotiation and authentication mechanism, making it suitable for resource-constrained Internet of Things environments.
[0007] (4)Traceability and Tamper Resistance of Data Storage: Traditional device authentication methods are difficult to ensure the integrity of the authentication process. Once an attack or data tampering occurs, it is difficult to trace and recover. The present invention stores device authentication information through blockchain technology, making the authentication data tamper-proof, ensuring the traceability of device identities, and improving the credibility and transparency of the system. Summary of the Invention
[0008] The present invention proposes an authentication and access control method for Internet of Things devices based on zero trust. The authentication mechanism is dynamically selected according to the historical interaction logs of the devices to improve the authentication efficiency. The anti-forgery ability of radio frequency fingerprints and Chebyshev chaotic mapping are used to implement the authentication and key negotiation mechanism for Internet of Things devices, so as to solve the security and privacy problems existing in current Internet of Things authentication. At the same time, blockchain technology is combined to provide a secure and transparent solution for device identity authentication and data storage, making the device authentication process more credible and difficult to be tampered with. In addition, the zero trust authentication and access control model is introduced to fundamentally improve the security of the system. The system no longer defaults to trusting any device or user, but each access needs to be verified, and the access permissions are dynamically adjusted based on real-time environmental data (such as device location information, device interaction logs) policies, realizing more secure access control of system resources. In short, this authentication and access control method for Internet of Things devices based on zero trust provides a new solution to achieve a high-security and high-dynamic adaptability Internet of Things device authentication and access control mechanism.
[0009] The present invention provides an authentication and access control method for Internet of Things devices based on zero trust, including the following steps: Step S1, device registration: The server sends a registration request to the registration center, and the trusted authority generates a private key, a public key, and authentication parameters for the registration request and sends them to the server for storage; The Internet of Things device generates a pseudo-identity and sends a registration request in combination with longitude and latitude information; The registration center extracts the radio frequency fingerprint, calculates the identity parameters and self-check parameters of the Internet of Things device, generates a symmetric encryption key, and encrypts the identity and location information of the Internet of Things device; The registration center constructs a storage tuple, uploads it to the blockchain, and sends a reply tuple to the Internet of Things device; The Internet of Things device stores the identity parameters and self-check parameters in the local memory; Step S2, Authentication: When the IoT device starts up, it performs a self-check, calculates the self-check parameters, and verifies the device status; Calculates the Chebyshev polynomial value, forms the authentication information, and sends it to the server; After obtaining the authentication information, the server verifies the time freshness and the RF fingerprint, decrypts the location information of the IoT device, and verifies the authentication information; If the verification passes, the server updates the strong authentication interaction log, calculates the distance between the server and the IoT device, determines the access resource level of the IoT device, and generates a session key, and sends the session key back to the IoT device; After receiving it, the IoT device verifies the time freshness and the authentication information again, calculates the session key and stores it, and accesses the resources through the session key and the access resource level.
[0010] Furthermore, during the process of forming the storage tuple in step S1, the value of the interaction log of the IoT device is set to empty.
[0011] Furthermore, during the process of verifying the authentication information in step S2, the interaction log of the IoT device is authenticated. Specifically: Determines whether the value of the interaction log of the IoT device is empty; If it is empty, then perform strong authentication; If it is not empty, then perform weak authentication.
[0012] Furthermore, step S1 is specifically as follows: Step S11: The server uses its own server identity to send a registration request to the registration center. After receiving the registration request from the server, the trusted authority generates a private key and a public key , and based on the public key obtains the first authentication parameter , expressed as: ; Among them, is the first random number, is the public key of the IoT device, represents that the parameter is of order Chebyshev polynomial, is the modulo operation, is a prime number, represents the index of the server; Based on the private key obtains the second authentication parameter and the third authentication parameter of the server identity , expressed as: ; ; Among them, represents a hash operation, is a string concatenation operator, is the server identity, is the first authentication parameter, is the first random number; The trusted authority combines the first authentication parameter , the second authentication parameter , the third authentication parameter and the first random number to form a reply tuple and sends it to the server. After receiving it, the server stores the reply tuple in the database; Step S12: The Internet of Things device uses the second random number to generate a pseudo-identity, expressed as: ; Among them, represents the pseudo-identity of the Internet of Things device , i represents the index of the Internet of Things device, is the identity of the server; Store the pseudo-identity of the Internet of Things device in the local memory, and then obtain the longitude and latitude information of the Internet of Things device , and form a first registration tuple with the pseudo-identity and the longitude and latitude information ; Among them, respectively represent the longitude information and latitude information of the Internet of Things device ; Send a registration request to the registration center through the first registration tuple. After receiving the registration tuple , extract the first radio frequency fingerprint of the Internet of Things device; Among them, ; Obtain the first identity parameter and the second identity parameter of the Internet of Things device based on the pseudo-identity, expressed as:
[0013] ;
[0014] ; Step S13: Obtain the first self-check parameter and the second self-check parameter generated by the Internet of Things device, expressed as: ; ; Among them, is the third random number; Calculate the symmetric encryption key , expressed as: ; Among them, represents the Chebyshev polynomial of order with parameter ; Then, symmetrically encrypt the first identity parameter, the second identity parameter, and the longitude and latitude information of the Internet of Things device respectively to obtain the encrypted third identity parameter and the encrypted location information , expressed as: ; ; Among them, is the symmetric encryption algorithm using the encryption key ; Combine the pseudo-identity, the third identity parameter, the encrypted location information, and the first radio frequency fingerprint of the Internet of Things device; and set the value of the interaction log to empty to form a storage tuple ; Combine the first identity parameter, the second identity parameter, the first self-check parameter, and the second self-check parameter of the Internet of Things device to form the first reply tuple , and send the first reply tuple to the Internet of Things device; Step S14: After receiving the first reply tuple, the Internet of Things device calculates the third self-check parameter for storage, expressed as: ; Among them, is the exclusive OR operation, represents the identity information of the Internet of Things device; The Internet of Things device stores the first identity parameter, the second identity parameter, the second self-check parameter, and the third self-check parameter in the local memory.
[0015] Furthermore, the authentication process in step S2 is specifically as follows: Step S21: Start the Internet of Things device; Step S211: Obtain the first self-check parameter and perform a self-check operation to check whether the device is running normally; Calculate the fourth self-check parameter , expressed as: ; Step S212: Verify whether the fourth self-check parameter is equal to the second self-check parameter to perform device self-check; After successful self-check, calculate the value of the first Chebyshev polynomial , expressed as: ; where is the fourth random number, is the Chebyshev polynomial of order with parameter , represents the identifier of the Internet of Things device; Step S213A: Form the first authentication information during the strong authentication process , expressed as: ; where is the first current time, represents the longitude information, represents the latitude information; Step S213B: Form the fifth authentication information during the weak authentication process , expressed as: ; where represents the first session key, is the fourth current time; Step S214A: During the strong authentication process, the Internet of Things device forms the first authentication request , expressed as: , and sends the first authentication request to the server; Step S214B: During the weak authentication process, the Internet of Things device forms the second authentication request , expressed as: ; Step S215: After receiving the first authentication request or the second authentication request sent by the Internet of Things device, the server verifies whether the time meets the freshness requirement, which is expressed as: ; ; where is the second current time, is the first current time, is the preset time difference threshold, represents the fifth current time, is the fourth current time; Step S216A: Extract the second RF fingerprint of the first authentication request , where For radio frequency fingerprint extraction operation; Step S217: Then use the pseudo-identity of the Internet of Things device as an index to obtain the storage tuple of the Internet of Things device on the blockchain .
[0016] Furthermore, the authentication process in step S2 also includes: Step S22A: Strong authentication process: If it is detected that the interaction log is empty, then check whether the first radio frequency fingerprint of the Internet of Things device is consistent with the second radio frequency fingerprint of the Internet of Things device; If they are consistent, the server calculates the symmetric encryption key; Step S22B: Weak authentication process: If it is detected that the interaction log is not empty, the server calculates the symmetric key.
[0017] Furthermore, the authentication process in step S2 also includes: Step S231: The server decrypts the third identity parameter to obtain the first identity parameter and the second identity parameter of the Internet of Things device, expressed as: ; Wherein is the symmetric decryption algorithm using the decryption key; Step S232: Decrypt the encrypted location information to obtain the longitude and latitude information of the Internet of Things device, expressed as: ; Step S233A: In the strong authentication process, form the second authentication information , expressed as: ; Check whether the second authentication information is consistent with the first authentication information; Step S233B: In the weak authentication process, form the sixth authentication information , expressed as: ; Check whether the sixth authentication information is consistent with the fifth authentication information.
[0018] Furthermore, the authentication process in step S2 also includes: Step S241: After determining consistency, the server completes the authentication of the Internet of Things device and updates the interaction log value of the Internet of Things device, expressed as: ; ; ; Wherein, is the authentication success weight, is the th authentication success value, is the authentication failure weight, is the th authentication failure value; is the current authentication value; is the current authentication value, is the th authentication success value, is th authentication failure value; If the current authentication is successful, then , if the authentication fails, then , if the current authentication is successful, then , if the authentication fails, then ; Step S242: Update the interaction log to the blockchain; then calculate the distance between the server and the IoT device; based on the updated interaction log and the distance between the server and the IoT device, determine the access resource level of the IoT device based on the access control list; Step S243: The server calculates the second Chebyshev polynomial value , expressed as: , where is the parameter of the th order Chebyshev polynomial; The server then calculates the fourth authentication parameter , expressed as: ; Step S244A: During the strong authentication process, calculate the third Chebyshev polynomial value , expressed as: ; where represents the parameter of the th order Chebyshev polynomial; Step S244B: During the weak authentication process, the server calculates the fourth Chebyshev polynomial value , expressed as: ; Then the server generates the second session key with the IoT device , expressed as: ; Step S245A: During the strong authentication process, the server forms the third authentication information , expressed as: ; Step S245B: During the weak authentication process, the server forms the seventh authentication information , expressed as: ; Step S246A: In the strong authentication process, obtain the first encrypted access resource level , expressed as: ; Among them, represents a symmetric encryption function using the value of the third Chebyshev polynomial as the key, represents the access resource level of the Internet of Things device; Step S246B: In the strong authentication process, obtain the second encrypted access resource level , expressed as: ; Among them, represents a symmetric encryption function using the value of the fourth Chebyshev polynomial as the key, represents the access resource level of the Internet of Things device.
[0019] Furthermore, the authentication process in step S2 also includes: Step S25A: Strong authentication process: The server calculates the value of the fourth Chebyshev polynomial , among which, represents the -th order Chebyshev polynomial with parameter Then the server generates the first session key with the Internet of Things device, expressed as: ; Obtain the first stored session key , expressed as: ; The server stores the first stored session key and the first encrypted access resource level in the database and forms the first reply tuple , among which, ; The server sends the second reply tuple to the Internet of Things device; After the Internet of Things device receives the second reply tuple M2, it first verifies whether the time meets the requirements; expressed as: ; among which, is the third current time; Calculate the fifth authentication parameter , expressed as: ; Calculate the value of the fifth Chebyshev polynomial , among which, represents the parameter as of order Chebyshev polynomial; receive the access resource level , , where represents the symmetric decryption function using the value of the fifth Chebyshev polynomial as the key; generate the fourth authentication information , expressed as: , check whether the fourth authentication information is equal to the third authentication information. If they are equal, it means the IoT device successfully authenticates the server; S25B: Weak authentication process: The server updates the first stored session key to the second stored session key and the first encrypted access resource level to the second encrypted access resource level; and form the third reply tuple : ; After receiving the third reply tuple, the IoT device first verifies whether the time meets the requirements; After verifying that it meets the requirements, the IoT device calculates the value of the sixth Chebyshev polynomial , expressed as: ; Then the networking device calculates the second session key with the server , expressed as: ; Then obtain the access resource level , expressed as: ; where represents the symmetric decryption function using the value of the sixth Chebyshev polynomial as the key, is the second encrypted access resource level; The IoT device generates the eighth authentication information , expressed as: ; Check whether the eighth authentication information is equal to the seventh authentication information. If they are equal, it means the IoT device successfully authenticates the server.
[0020] Furthermore, the authentication process in step S2 also includes: Step S26A: Strong authentication process: The IoT device calculates the value of the sixth Chebyshev polynomial , expressed as: ; where represents the parameter as of First-order Chebyshev polynomial Next, the IoT device calculates the first session key with the server , expressed as: ; Then obtain the first stored session key , expressed as: ; The IoT device stores the first stored session key and the first encrypted access resource level in the database, allowing the IoT device to perform system resource access behaviors using the first access resource level and the first session key; Step S26B: Weak authentication process: Obtain the second stored session key; The IoT device updates the first stored session key to the second stored session key and the first encrypted access resource level to the second encrypted access resource level, allowing the IoT device to perform system resource access behaviors using the first access resource level and the second session key.
[0021] Compared with the existing technologies, the present invention has the following beneficial effects:
[0022] (1) The present invention utilizes the real-time scenario factors of IoT devices to dynamically evaluate the access levels of devices, realizes real-time adjustment of permission allocation, ensures that risk devices can only access limited resources, while trusted devices can obtain higher permissions. This mechanism effectively solves the problem that the static access control method cannot flexibly respond to device state changes, and improves the security and adaptability of the system.
[0023] (2) The present invention designs a personalized authentication process based on the interaction logs of IoT devices, realizes a dynamic authentication strategy, and improves the authentication efficiency. This method can reduce the authentication complexity of legitimate devices, and at the same time impose a more stringent authentication process on abnormal devices, improving the security and user experience of the system.
[0024] (3) In the authentication process of the present invention, radio frequency fingerprints are used to uniquely identify devices, improving the non-forgeability of authentication. The Chebyshev chaotic mapping is used to implement the authentication and key negotiation protocol, ensuring the randomness and unpredictability of device authentication, and improving the robustness and security of authentication.
[0025] (4) The present invention uses blockchain to store device registration information and authentication records, ensuring the immutability and traceability of data. This mechanism improves the transparency and security of identity management in the IoT environment, preventing malicious devices from tampering with identities or accessing resources without authorization. Brief Description of the Drawings
[0026] Figure 1 is a flowchart of the method of the present invention. Detailed Embodiments
[0027] Refer to Figure 1 , the present invention provides an Internet of Things device authentication and access control method for zero trust, including the following steps: Step S1, device registration: The server sends a registration request to the registration center, and the trusted authority generates a private key, a public key, and authentication parameters for the registration request, and sends them to the server for storage; The Internet of Things device generates a pseudo-identity and sends a registration request in combination with longitude and latitude information; The registration center extracts the radio frequency fingerprint, calculates the identity parameters and self-check parameters of the Internet of Things device, generates a symmetric encryption key, and encrypts the identity and location information of the Internet of Things device; The registration center constructs a storage tuple, uploads it to the blockchain, and sends a reply tuple to the Internet of Things device; The Internet of Things device stores the identity parameters and self-check parameters in the local memory; Step S2, authentication: When the Internet of Things device starts, it performs a self-check, calculates the self-check parameters, and verifies the device status; Calculate the Chebyshev polynomial value, form authentication information, and send it to the server; After obtaining the authentication information, the server verifies the time freshness and radio frequency fingerprint, decrypts the location information of the Internet of Things device, and verifies the authentication information; If the verification passes, the server updates the strong authentication interaction log, calculates the distance between the server and the Internet of Things device, determines the access resource level of the Internet of Things device, and generates a session key, and sends the session key back to the Internet of Things device; After receiving it, the Internet of Things device verifies the time freshness and authentication information again, calculates the session key and stores it, and accesses resources through the session key and the access resource level.
[0028] Furthermore, during the process of forming the storage tuple in step S1, the value of the interaction log of the Internet of Things device is set to empty.
[0029] Furthermore, during the process of verifying the authentication information in step S2, the interaction log of the Internet of Things device is authenticated. Specifically: Judge whether the value of the interaction log of the Internet of Things device is empty; If it is empty, perform strong authentication; If it is not empty, perform weak authentication.
[0030] Furthermore, step S1 is specifically: Step S11: The server uses its own server identity to send a registration request to the registration center. After receiving the registration request from the server, the trusted authority generates a private key and a public key , based on the public key obtain the first authentication parameter , expressed as: ; Among them, is the first random number, is the public key of the Internet of Things device, indicates that the parameter is of Chebyshev polynomial of order is the modulo operation, is a prime number, represents the index of the server; Based on the private key obtain the second authentication parameter and the third authentication parameter of the server identity , expressed as: ; ; Among them, represents the hash operation, is the string concatenation operator, is the server identity, is the first authentication parameter, is the first random number; The trusted authority combines the first authentication parameter , the second authentication parameter , the third authentication parameter and the first random number to form a reply tuple and then sends it to the server. After receiving it, the server stores the reply tuple in the database; Step S12: The Internet of Things device uses the second random number to generate a pseudo-identity, expressed as: ; Among them, represents the pseudo-identity of the Internet of Things device , i represents the index of the Internet of Things device, is the identity of the server; Store the pseudo-identity of the Internet of Things device in the local memory, and then obtain the longitude and latitude information of the Internet of Things device , and form a first registration tuple with the pseudo-identity and the longitude and latitude information; Among them, respectively represent the Internet of Things device The longitude information and latitude information; Send a registration request to the registration center through the first registration tuple. The registration center receives the registration tuple and extracts the first radio frequency fingerprint of the Internet of Things device ; where ; Obtain the first identity parameter of the Internet of Things device based on the pseudo-identity and the second identity parameter , expressed as:
[0031] ;
[0032] ; Step S13: Obtain the first self-check parameter of the device generated by the Internet of Things device and the second self-check parameter , expressed as: ; ; where is the third random number; Calculate the symmetric encryption key , expressed as: ; where represents that the parameter is of order Chebyshev polynomial; Then, symmetrically encrypt the first identity parameter, the second identity parameter, and the longitude and latitude information of the Internet of Things device respectively to obtain the encrypted third identity parameter and the encrypted location information , expressed as: ; ; where is the symmetric encryption algorithm using the encryption key ; The pseudo-identity, the third identity parameter, the encrypted location information, and the first radio frequency fingerprint of the Internet of Things device; and set the value of the interaction log to empty to form a storage tuple ; Form the first reply tuple from the first identity parameter, the second identity parameter, the first self-check parameter, and the second self-check parameter of the Internet of Things device , and send the first reply tuple to the Internet of Things device; Step S14: After the IoT device receives the first response tuple, calculate the third self-check parameter for storage , which is expressed as: ; Among them, is the exclusive OR operation, represents the identity information of the IoT device; The IoT device stores the first identity parameter, the second identity parameter, the second self-check parameter, and the third self-check parameter in the local memory.
[0033] Furthermore, the specific process of authentication in step S2 is as follows: Step S21: Start the IoT device; Step S211: Obtain the first self-check parameter for self-checking operation to check whether the device is running normally; Calculate the fourth self-check parameter , which is expressed as: ; Step S212: Verify whether the fourth self-check parameter is equal to the second self-check parameter for device self-check; After successful self-check, calculate the first Chebyshev polynomial value , which is expressed as: ; Among them, is the fourth random number, is the parameter of the -order Chebyshev polynomial, represents the identifier of the IoT device; Step S213A: Form the first authentication information during the strong authentication process , which is expressed as: ; Among them, is the first current time, represents the longitude information, represents the latitude information; Step S213B: Form the fifth authentication information during the weak authentication process , which is expressed as: ; Among them, represents the first session key, is the fourth current time; Step S214A: During the strong authentication process, the IoT device forms the first authentication request , which is expressed as: , and sends the first authentication request to the server; Step S214B: During the weak authentication process, the IoT device forms a second authentication request , which is expressed as: ; Step S215: After receiving the first authentication request or the second authentication request sent by the IoT device, the server verifies whether the time meets the freshness requirement, which are respectively expressed as: ; ; Among them, is the second current time, is the first current time, is the preset time difference threshold, represents the fifth current time, is the fourth current time; Step S216A: Extract the second RF fingerprint of the first authentication request , among which, is the RF fingerprint extraction operation; Step S217: Then use the pseudo-identity of the IoT device as an index to obtain the storage tuple of the IoT device on the blockchain .
[0034] Furthermore, the authentication process in Step S2 also includes: Step S22A: Strong authentication process: If it is detected that the interaction log is empty, then check whether the first RF fingerprint of the IoT device is consistent with the second RF fingerprint of the IoT device; If they are consistent, the server calculates the symmetric encryption key; Step S22B: Weak authentication process: If it is detected that the interaction log is not empty, the server calculates the symmetric key.
[0035] Furthermore, the authentication process in Step S2 also includes: Step S231: The server decrypts the third identity parameter to obtain the first identity parameter and the second identity parameter of the IoT device, which is expressed as: ; Among them is the symmetric decryption algorithm using the decryption key; Step S232: Decrypt the encrypted location information to obtain the longitude and latitude information of the IoT device, which is expressed as: ; Step S233A: During the strong authentication process, form the second authentication information , which is expressed as: ; Check whether the second authentication information is consistent with the first authentication information; Step S233B: During the weak authentication process, form the sixth authentication information , expressed as: ; Check whether the sixth authentication information is consistent with the fifth authentication information.
[0036] Furthermore, the authentication process in step S2 further includes: Step S241: After determining consistency, the server completes the authentication of the IoT device and updates the interaction log value of the IoT device, expressed as: ; ; ; Among them, is the authentication success weight, is the th authentication success value, is the authentication failure weight, is the th authentication failure value; is the current authentication value; is the current authentication value, is the th authentication success value, is th authentication failure value; If the current authentication is successful, then , if the authentication fails, then , if the current authentication is successful, then , if the authentication fails, then ; Step S242: Update the interaction log to the blockchain; then calculate the distance between the server and the IoT device; based on the updated interaction log and the distance between the server and the IoT device, determine the access resource level of the IoT device based on the access control list; Step S243: The server calculates the second Chebyshev polynomial value , expressed as: , among which, is the -parameter th-order Chebyshev polynomial; The server then calculates the fourth authentication parameter , expressed as: ; Step S244A: During the strong authentication process, calculate the third Chebyshev polynomial value , denoted as: ; where denotes the -th Chebyshev polynomial; Step S244B: During the weak authentication process, the server calculates the fourth Chebyshev polynomial value , denoted as: ; Then the server generates a second session key with the Internet of Things device , denoted as: ; Step S245A: During the strong authentication process, the server forms the third authentication information , denoted as: ; Step S245B: During the weak authentication process, the server forms the seventh authentication information , denoted as: ; Step S246A: During the strong authentication process, obtain the first encrypted access resource level , denoted as: ; where represents a symmetric encryption function using the third Chebyshev polynomial value as the key, represents the access resource level of the Internet of Things device; Step S246B: During the strong authentication process, obtain the second encrypted access resource level , denoted as: ; where represents a symmetric encryption function using the fourth Chebyshev polynomial value as the key, represents the access resource level of the Internet of Things device.
[0037] Furthermore, the authentication process in Step S2 further includes: Step S25A: Strong authentication process: The server calculates the fourth Chebyshev polynomial value , where denotes the -th Chebyshev polynomial; Then the server generates a first session key with the Internet of Things device , denoted as: ; Obtain the first stored session key , expressed as: ; The server stores the first stored session key and the first encrypted access resource level in the database and forms the first reply tuple , where ; The server sends the second reply tuple to the Internet of Things device; After receiving the second reply tuple M2, the Internet of Things device first verifies whether the time meets the requirements; expressed as: ; where is the third current time; Calculate the fifth authentication parameter , expressed as: ; Calculate the fifth Chebyshev polynomial value , where represents the Chebyshev polynomial of degree with parameter ; Then obtain the access resource level , , where represents the symmetric decryption function using the fifth Chebyshev polynomial value as the key; Generate the fourth authentication information , expressed as: , check whether the fourth authentication information is equal to the third authentication information. If they are equal, it means that the Internet of Things device has successfully authenticated the server; S25B: Weak authentication process: The server updates the first stored session key to the second stored session key and the first encrypted access resource level to the second encrypted access resource level; And form the third reply tuple : ; After receiving the third reply tuple, the Internet of Things device first verifies whether the time meets the requirements; After verifying that it meets the requirements, the Internet of Things device calculates the sixth Chebyshev polynomial value , expressed as: ; Then the Internet of Things device calculates the second session key with the server , expressed as: ; Then obtain the access resource level , expressed as: ; Among them, represents using the value of the sixth Chebyshev polynomial as the symmetric decryption function of the key, is the second encryption access resource level; The Internet of Things device generates the eighth authentication information , which is expressed as: ; Check whether the eighth authentication information is equal to the seventh authentication information. If they are equal, it means that the Internet of Things device has successfully authenticated the server.
[0038] Furthermore, the authentication process in step S2 further includes: Step S26A: Strong authentication process: The Internet of Things device calculates the value of the sixth Chebyshev polynomial , which is expressed as: ; Among them, represents the -order Chebyshev polynomial with parameter ; Then the Internet of Things device calculates the first session key with the server, which is expressed as: ; Then obtain the first stored session key , which is expressed as: ; The Internet of Things device stores the first stored session key and the first encryption access resource level in the database, allowing the Internet of Things device to use the first access resource level and the first session key for system resource access behavior; Step S26B: Weak authentication process: Obtain the second stored session key; The Internet of Things device updates the first stored session key to the second stored session key and the first encryption access resource level to the second encryption access resource level, allowing the Internet of Things device to use the first access resource level and the second session key for system resource access behavior.
[0039] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An authentication and access control method for Internet of Things devices targeting zero trust, characterized in that, It includes the following steps: Step S1, device registration: The server sends a registration request to the registration center. The trusted authority generates a private key, a public key, and authentication parameters for the registration request and sends them to the server for storage; The Internet of Things device generates a pseudo-identity and sends a registration request in combination with longitude and latitude information; The registration center extracts the radio frequency fingerprint, calculates the identity parameters and self-check parameters of the Internet of Things device, generates a symmetric encryption key, and encrypts the identity and location information of the Internet of Things device; The registration center constructs a storage tuple, uploads it to the blockchain, and sends a reply tuple to the Internet of Things device; The Internet of Things device stores the identity parameters and self-check parameters in the local memory; Step S2, authentication: When the Internet of Things device starts up, it performs a self-check, calculates the self-check parameters, and verifies the device status; Calculate the Chebyshev polynomial value, form the authentication information, and send it to the server; After obtaining the authentication information, the server verifies the time freshness and the radio frequency fingerprint, decrypts the location information of the Internet of Things device, and verifies the authentication information; If the verification passes, the server updates the strong authentication interaction log, calculates the distance between the server and the Internet of Things device, determines the access resource level of the Internet of Things device, and generates a session key, and sends the session key back to the Internet of Things device; After receiving it, the Internet of Things device verifies the time freshness and the authentication information again, calculates the session key and stores it, and accesses resources through the session key and the access resource level.
2. The method for authenticating and accessing control of Internet of Things devices for zero trust according to claim 1, wherein During the process of forming the storage tuple in step S1, the value of the interaction log of the Internet of Things device is set to empty.
3. The method for authenticating and accessing control of Internet of Things devices for zero trust according to claim 2, wherein, During the process of verifying the authentication information in step S2, authenticate the interaction log of the Internet of Things device. Specifically: Judge whether the value of the interaction log of the Internet of Things device is empty; If it is empty, perform strong authentication; If it is not empty, perform weak authentication.
4. An authentication and access control method for Internet of Things devices targeting zero trust according to claim 1, characterized in that, Step S1 is specifically: Step S11: The server uses its own server identity to send a registration request to the registration center. After receiving the server's registration request, the trusted authority generates a private key and a public key , and based on the public key obtains the first authentication parameter , which is expressed as: ; Among them, is the first random number, is the public key of the Internet of Things device, represents that the parameter is of Chebyshev polynomial of order is modular arithmetic, is a prime number, represents the index of the server; Based on the private key Obtain the server identity of the second authentication parameter and the third authentication parameter , expressed as: ; ; Among them, represents a hash operation, is a string concatenation operator, is the server identity, is the first authentication parameter, is the first random number; The trusted authority combines the first authentication parameter , the second authentication parameter , the third authentication parameter and the first random number to form a reply tuple and sends it to the server. After receiving it, the server stores the reply tuple in the database; Step S12: The IoT device uses the second random number to generate a pseudo identity, expressed as: ; Among them, represents the pseudo - identity of the Internet of Things device where \(i\) represents the index of the Internet of Things device, and is the identity of the server; Store the pseudo-identity of the Internet of Things device in the local memory, and then obtain the Internet of Things device 's longitude and latitude information , and form a first registration tuple with the pseudo-identity and the longitude and latitude information ; where respectively represent the longitude information and latitude information of the Internet of Things device ; Send a registration request to the registration center through the first registration tuple, and the registration center receives the registration tuple After that, extract the first radio frequency fingerprint of the IoT device ; among which, ; Obtain the first identity parameter based on the pseudo-identity of the Internet of Things device and the second identity parameter , expressed as: ; ; Step S13: Obtain a first self-check parameter and a second self-check parameter generated by the IoT device, expressed as: and a second self-check parameter , expressed as: ; ; Among them, is the third random number; Calculating a symmetric encryption key , expressed as: ; Among them, represents the Chebyshev polynomial of -th order; Then, the first identity parameter, the second identity parameter, and the longitude and latitude information of the Internet of Things device are respectively symmetrically encrypted to obtain the encrypted third identity parameter and the encrypted location information , which is expressed as: ; ; Among them, is a symmetric encryption algorithm that uses an encryption key ; The pseudo-identity of the Internet of Things device, the third identity parameter, the encrypted location information, and the first radio frequency fingerprint; and the interaction log is set to null, and a storage tuple is formed ; Form a first reply tuple from the first identity parameter, the second identity parameter, the first self-check parameter, and the second self-check parameter of the Internet of Things device , and send the first reply tuple to the Internet of Things device; Step S14: After the Internet of Things device receives the first reply tuple, calculate the third self-check parameter for storage , expressed as: ; Among them, is an exclusive OR operation, represents the identity information of the Internet of Things device; The Internet of Things device stores the first identity parameter, the second identity parameter, the second self-check parameter, and the third self-check parameter in the local memory.
5. The method for authenticating and accessing control of Internet of Things devices for zero trust according to claim 4, wherein The process of authentication in step S2 is specifically: Step S21: Start the Internet of Things device; Step S211: Obtain the first self-check parameter and perform a self-check operation to check whether the device is running normally; Calculate the fourth self-check parameter , which is expressed as: ; Step S212: Verify whether the fourth self-check parameter is equal to the second self-check parameter to perform a device self-check; Calculate the value of the first Chebyshev polynomial after successful self-check , expressed as: ; wherein, is the fourth random number, is a -order Chebyshev polynomial with parameter ; represents the identifier of the IoT device; Step S213A: Generate the first authentication information during the strong authentication process , which is expressed as: ; Among them, is the first current time, represents longitude information, represents latitude information; Step S213B: Generate the fifth authentication information during the weak authentication process , expressed as: ; wherein, represents the first session key, is the fourth current time; Step S214A: During the strong authentication process, the IoT device forms a first authentication request , expressed as: , and sends the first authentication request to the server; Step S214B: During the weak authentication process, the IoT device forms a second authentication request , expressed as: ; Step S215: After the server receives the first authentication request or the second authentication request sent by the Internet of Things device, verify whether the time meets the freshness requirement, which is respectively expressed as: ; ; Wherein, is the second current time, is the first current time, is a preset time difference threshold value, represents the fifth current time, is the fourth current time; Step S216A: Extract the second RF fingerprint of the first authentication request , where is the RF fingerprint extraction operation Step S217: Then, use the pseudo-identity of the IoT device as an index to obtain the storage tuple of the IoT device on the blockchain .
6. The method for authenticating and accessing control of Internet of Things devices for zero trust according to claim 5, wherein The process of authentication in step S2 also includes: Step S22A: Strong authentication process: If it is checked that the interaction log is empty, then check whether the first radio frequency fingerprint of the Internet of Things device is consistent with the second radio frequency fingerprint of the Internet of Things device; If they are consistent, the server calculates the symmetric encryption key; Step S22B: Weak authentication process: If it is checked that the interaction log is not empty, the server calculates the symmetric key.
7. An authentication and access control method for Internet of Things devices for zero trust according to claim 6, characterized in that The process of authentication in step S2 also includes: Step S231: The server decrypts the third identity parameter to obtain the first identity parameter and the second identity parameter of the Internet of Things device, expressed as: ; wherein is a symmetric decryption algorithm using a decryption key; Step S232: Decrypt the encrypted location information to obtain the latitude and longitude information of the IoT device, expressed as: ; Step S233A: During the strong authentication process, form the second authentication information , expressed as: ; Check whether the second authentication information is consistent with the first authentication information; Step S233B: During the weak authentication process, generate the sixth authentication information , which is expressed as: ; Check whether the sixth authentication information is consistent with the fifth authentication information.
8. An authentication and access control method for Internet of Things devices for zero trust according to claim 7, characterized in that, The process of authentication in step S2 also includes: Step S241: After judging consistency, the server completes the authentication of the Internet of Things device and updates the value of the interaction log of the Internet of Things device, which is expressed as: ; ; ; Among them, is the authentication success weight, is the th authentication success value, is the authentication failure weight, is the th authentication failure value; is the current authentication value; is the current authentication value, is the th authentication success value, is th authentication failure value; If the current authentication is successful, then , if the authentication fails, then , if the current authentication is successful, then , if the authentication fails, then ; Step S242: Update the interaction log to the blockchain; then calculate the distance between the server and the IoT device; based on the updated interaction log and the distance between the server and the IoT device, determine the access resource level of the IoT device based on the access control list; Step S243: The server calculates the value of the second Chebyshev polynomial , which is expressed as: , where is the Chebyshev polynomial of th order; The server then calculates the fourth authentication parameter , which is expressed as: ; Step S244A: Calculate the value of the third Chebyshev polynomial during the strong authentication process , which is expressed as: ; wherein, represents the -th order Chebyshev polynomial; Step S244B: During the weak authentication process, the server calculates the value of the fourth Chebyshev polynomial , which is expressed as: ; Next, the server generates a second session key for the Internet of Things device , denoted as: ; Step S245A: During the strong authentication process, the server forms third authentication information , which is expressed as: ; Step S245B: During the weak authentication process, the server forms the seventh authentication information , which is expressed as: ; Step S246A: Obtain a first encrypted access resource level during the strong authentication process , expressed as: ; Among them, represents a symmetric encryption function using the value of the third Chebyshev polynomial as the key, represents the access resource level of the IoT device; Step S246B: Obtain the second encrypted access resource level during the strong authentication process , expressed as: ; Among them, represents a symmetric encryption function using the value of the fourth Chebyshev polynomial as the key, represents the access resource level of the IoT device.
9. A method for authenticating and accessing control of Internet of Things devices for zero trust according to claim 8, characterized in that, The authentication process in step S2 further includes: Step S25A: Strong authentication process: The server calculates the value of the fourth Chebyshev polynomial , where represents the Chebyshev polynomial of order with parameter ; Next, the server generates a first session key for the Internet of Things device , denoted as: ; Obtain the first storage session key , expressed as: ; The server stores the first storage session key and the first encrypted access resource level in the database and forms a first reply tuple , where ; The server sends the second reply tuple to the IoT device; After the IoT device receives the second reply tuple M2, it first verifies whether the time meets the requirements; expressed as: ; wherein, is the third current time; Calculate the fifth authentication parameter , expressed as: ; Calculate the value of the fifth Chebyshev polynomial , where represents the Chebyshev polynomial of order with parameter ; Received access resource level , , where represents a symmetric decryption function using the fifth Chebyshev polynomial value as the key; Generate the fourth authentication information , expressed as: , check whether the fourth authentication information is equal to the third authentication information. If they are equal, it means that the Internet of Things device has successfully authenticated the server; Step S25B: Weak authentication process: The server updates the first stored session key to the second stored session key and the first encrypted access resource level to the second encrypted access resource level; and form a third reply tuple : ; After the IoT device receives the third reply tuple, it first verifies whether the time meets the requirements; After verifying compliance with the requirements, the IoT device calculates the value of the sixth Chebyshev polynomial , which is expressed as: ; Next, the networking device calculates the second session key with the server , which is expressed as: ; Next, obtain the access resource level , which is expressed as: ; Among them, represents the use of the sixth Chebyshev polynomial value is the symmetric decryption function with the key, is the second encrypted access resource level; The IoT device generates the eighth authentication information , expressed as: ; Check whether the eighth authentication information is equal to the seventh authentication information. If they are equal, it means that the IoT device has successfully authenticated the server.
10. An authentication and access control method for Internet of Things devices targeting zero trust according to claim 9, characterized in that, The authentication process in step S2 further includes: Step S26A: Strong authentication process: The Internet of Things device calculates the value of the sixth Chebyshev polynomial , expressed as: ; Among them, represents the -th order Chebyshev polynomial; Next, the IoT device calculates the first session key with the server , denoted as: ; Then obtain the first stored session key , expressed as: ; The IoT device stores the first stored session key and the first encrypted access resource level in the database, allowing the IoT device to use the first access resource level and the first session key for system resource access behavior; Step S26B: Weak authentication process: Obtain the second stored session key; The IoT device updates the first stored session key to the second stored session key and the first encrypted access resource level to the second encrypted access resource level, allowing the IoT device to use the first access resource level and the second session key for system resource access behavior.
Citation Information
Patent Citations
Blockchain-based Internet of Things identity authentication system and method for digital twin world
CN110880105A
Lightweight authentication method for Internet of Things system in cloud computing environment
CN114785615A
Lightweight zero-knowledge identity authentication method for Internet of Things equipment
CN116248312A
Lightweight two-factor agricultural Internet of Things equipment continuous authentication method and system
CN117097489A
Big data hyper-fusion visual management method
CN117708223A