Internet of Things equipment cross-domain batch identity authentication method based on PWCBAP protocol
Through the PWCBAP protocol combined with PUF and WCC, the complexity of identity authentication and privacy leakage of cross-domain authentication in large-scale deployment of IoT devices is solved, and efficient and secure inter-device authentication and key negotiation are achieved, which enhances the security and reliability of IoT systems.
Patent Information
- Application Number
- CN202510437651.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-09
AI Technical Summary
The existing IoT device identity authentication scheme faces complex key management, vulnerability to attacks when deploying large-scale devices, and difficult for devices in different security domains to trust efficiently. There is a risk of privacy leakage during cross-domain authentication and a lack of defense mechanisms for active attacks.
Using a PWCBAP protocol-based method, combining physical non-cloneable function (PUF) and wireless channel characteristics (WCC), cross-domain batch identity authentication is realized through device registration, pseudo-identity generation and session key negotiation, and two-way authentication and key negotiation are used for CRPs and FPPs, reducing computing overhead and enhancing security.
It realizes strong mutual authentication, confidentiality, anonymity and unlinkability between devices, resists cloning, physical and replay attacks, resists man-in-the-middle attacks, reduces transmission overhead, and ensures the security and reliability of the Internet of Things system.
Smart Images

Figure CN120301600A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of identity authentication and data confidentiality security for Internet of Things (IoT) communication protocol devices, and specifically relates to the cross-domain batch identity authentication technology for IoT devices based on the PWCBAP (Physical Unclonable Function and Wireless Channel Characteristics) protocol. Background Art
[0002] With the rapid development of the Internet of Things (IoT), the demand for device interconnection across different manufacturers and management domains has increased sharply, such as in scenarios like smart home, industrial Internet of Things (IIoT), and vehicle-to-everything (V2X). However, traditional identity authentication schemes (such as digital certificates, pre-shared keys) face problems such as complex key management and vulnerability to attacks on static credentials when deployed on a large scale, and it is difficult for devices in different security domains to achieve efficient mutual trust, severely restricting the large-scale application of the IoT.
[0003] To ensure the availability and confidentiality of IoT services, the server needs to authenticate communication participants such as devices and gateways, and securely and effectively establish session keys on the public channel. Many scholars at home and abroad have proposed solutions for IoT identity authentication protocols, such as: hardware-based PUF (Physical Unclonable Function) solutions and authentication schemes based on wireless channel characteristics. Although there have been research attempts to combine PUF with channel fingerprints in recent years, there are still three key defects: (1) When performing batch authentication, it is necessary to verify each device one by one, with a time complexity of O(n), which cannot meet the rapid access requirements of a large number of devices; (2) When performing cross-domain authentication, it is necessary to share the CRP (Challenge-Response Pair) of the PUF or the channel characteristic database, posing a serious risk of privacy leakage; (3) There is a lack of effective defense mechanisms against active attacks (such as channel characteristic forgery, man-in-the-middle attack). These technical bottlenecks severely limit the practical application of existing solutions in the open IoT environment. The cross-domain batch identity authentication method for IoT devices based on the fusion of PUF and wireless channel characteristics proposed by the present invention can solve the above three problems. Summary of the Invention
[0004] Aiming at the defects existing in the prior art, to achieve the above technical objectives, the present invention provides a cross-domain batch identity authentication method for IoT devices based on the PWCBAP protocol.
[0005] To achieve the above object, the present invention adopts the following technical solutions:
[0006] The identity authentication method based on the PWCBAP protocol includes the following steps:
[0007] S1. Device D ii Registers with the domain server DS i Device D ii Registers with the domain server DS i Applies for registration. Device Dii Check whether it has PUF and WCC. If it only has PUF, generate PUF excitation C i and response R i . If it only has WCC, generate wireless channel fingerprint F i and location P i . If it has both PUF and WCC, generate corresponding C i 、R i 、F i and P i all information. Device D ii sends the information D ii 、C i 、R i 、F i and P i to the domain server DS i . The domain server DS i saves the information D ii 、C i 、R i 、F i and P i in the server. All devices D j wanting to perform key negotiation with devices inside the domain server DS ii will perform this step, and this step is transmitted over a secure channel;
[0008] S2. The domain server DS i registers with the authentication server AS: The domain server DS i applies to the authentication server AS for registration. The domain server DS i generates PUF excitation DC i and response DR i . The domain server DS i generates the pseudo-identity PD ii of all devices D ii . The domain server DS i sends the information DS i 、DC i 、DR i 、D ii and PD ii to the authentication server. The authentication server stores DS i 、DC i 、DR i 、D ii and PD ii in the server after receiving them, and the above steps are carried out in a secure channel;
[0009] S3. D ji registers with the domain server DS j : Device D jiApply for registration to the domain server DS j The device D ji Checks whether it has a PUF and a WCC. If it only has a PUF, it generates a PUF stimulus C j and a response R j . If it only has a WCC, it generates a wireless channel fingerprint F j and a location P j . If it has both a PUF and a WCC, it generates the corresponding C j , R j , F j and P j of all information. The device D ji sends the information D ji , C j , R j , F j and P j to the domain server DS j . The domain server DS j saves the information D ji , C j , R j , F j and P j in the server. All devices D i wanting to perform key negotiation with devices inside the domain server DS ji will perform this step, and this step is transmitted over a secure channel;
[0010] S4. The domain server DS j Registers with the authentication server AS: The domain server DS j applies for registration to the authentication server AS. The domain server DS j generates a PUF stimulus DC j and a response DR j . The domain server DS j generates the pseudo-identity PD ji of all devices D ji . The domain server DS j sends the information DS j , DC j , DR j , D ji and PD ji to the authentication server. The authentication server stores DS j , DC j , DR j , D ji and PD ji in the server after receiving them, and the above steps are carried out in a secure channel;
[0011] S5. The authentication server AS generates and distributes information: The authentication server AS generates its own pseudo-identity PA i , the domain server DS i 's pseudo-identity PDS i and the domain server DS j 's pseudo-identity PDS j . After that, the authentication server AS will put D ii , PD ii , DS i , PDS i , DC i , DR i , D ji , PD ji , DS j , PDS j , DC j , DR j and PA i in memory. The authentication server AS sends the information PA i , PDS i , PDS j , PD ji and D ji to the domain server DS i . The domain server DS i receives the information PA i , PDS i , PDS j , PD ji and D ji . After that, it saves the information PA i , PDS i , PDS j , PD ji and D ji in the server and sends the information PA i , PDS i , PDS j and PD ji to the device D ii . The device D ii saves the information PA i , PDS i , PDS j and PD ji in its own memory. The authentication server AS sends the information PA i , PDS i , PDS j , PD ii and D ii to the domain server DS j . The domain server DS j receives the information PA i , PDSi , PDS j , PD ii and D ii After that, save the information PA i , PDS i , PDS j , PD ii and D ii in the server and send the information PA i , PDS i , PDS j and PD ii to the device D ji . The device D ji will save the information PA i , PDS i , PDS j and PD ii in its own memory. Thus, the registration phase of all devices and the domain server with the authentication server has been completed.
[0012] S6. The device D ii initiates a session: After registration, the device D ii starts the key negotiation. The device D ii checks whether it has PUF and WCC. If it only has PUF, it generates the PUF excitation C i , response R i . If it only has WCC, it generates the wireless channel fingerprint F i , location P i . If it has both PUF and WCC, it generates the corresponding C i , R i , F i and P i all information. The device D ii generates a random number N1 and a timestamp T1, and calculates the verification information I1. Subsequently, the device D ii sends the message M1 through the public channel to its own domain server DS i ;
[0013] S7. The domain server DS i verifies and requests the inter-domain session key: After receiving the message M1 from the device D i , the domain server DS ii generates the message reception timestamp T1 Re , checks whether T1 Re - T1 < ΔT1 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of the device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps. Then, the domain server DSi Calculate the verification information And compare the result with I1 sent by M1 to verify Whether it holds. If the verification fails, the domain server DS i Will terminate the authentication key exchange process; otherwise, the domain server DS i Continue to execute the subsequent steps. The domain server DS i Calculate the identity D of the device according to the information in the memory ii , and verify whether this identity is in its own database. If it is not in the database, the domain server DS i Will terminate the authentication key exchange process; otherwise, the domain server DS i Continue to execute the subsequent steps. The domain server DS i Collect all the requested devices, and put the pseudo-identities of these n devices into the set A = {D i1 , D i2 , …, D in}, the domain server DS i Generate the response DR i of the incentive DC i 、random number N3 and timestamp T3, calculate the verification information I3, and then encrypt the set A = {D i1 , D i2 , …, D in} into Ciph A . After that, the domain server DS i Sends the message M3 to the authentication server AS through the public channel;
[0014] S8, device D ji Initiate a session: After registration is completed, device D ji Starts key negotiation. Device D ji Checks whether it has PUF and WCC. If it only has PUF, it generates the PUF incentive C j , response R j , if it only has WCC, it generates the wireless channel fingerprint F j , location P j , if it has both PUF and WCC, it generates the corresponding C j , R j , F j and P j All information. Device D ji Generates a random number N2 and a timestamp T2, and calculates the verification information I2. Subsequently, the device sends the message M2 to its own domain server DS through the public channel j ;
[0015] S9, domain server DS j Verify and request the inter-domain session group key: The domain server DSj After receiving the message M4 from device D ji , generate a message reception timestamp T2 Re , and check whether T2 Re -T2 < ΔT2 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of device D ji ; conversely, the domain server DS j continues to execute the subsequent steps. Then, the domain server DS j calculates the verification information and compares the result with I2 sent by M2 to verify whether holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process; conversely, the domain server DS j continues to execute the subsequent steps. The domain server DS j calculates the identity D of the device according to the information in the memory ji , and verifies whether this identity is in its own database. If it is not in the database, the domain server DS j will terminate the authentication key exchange process; conversely, the domain server DS j continues to execute the subsequent steps. The domain server DS j collects all the requested devices, puts the pseudo-identities of these n devices into the set B = {D j1 , D j2 , …, D jn}, the domain server DS j generates a response DR j to the incentive DC j , a random number N4 and a timestamp T4, calculates the verification information I4, and then encrypts the set B = {D j1 , D j2 , …, D jn} into Ciph B . After that, the domain server DS j sends the message M4 to the authentication server AS through the public channel;
[0016] S10. Generation of the inter-domain session group key by the authentication server AS: After the authentication server AS receives the messages M3 and M4 from device D ii and D ji , it generates message reception timestamps T3 Re and T4 Re respectively, checks whether T3 Re -T3 < ΔT3 and T4 Re- Whether -T4 < ΔT4 holds. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps. Then, the authentication server AS calculates the verification information and and compares the result with I3 and I4 sent by M3 and M4 to verify and Whether it holds. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps. The authentication server AS calculates the sets A = {D i1 , D i2 , …, D in} and B = {D j1 , D j2 , …, D jn}, generates the inter-domain session group key SK i1 , D i2 , …, D in} and B = {D j1 , D j2 , …, D jn}, and at the same time generates a random number N5 and a timestamp T5, calculates SK AB , SK A , SK B and the verification information I5, I6. After that, the authentication server AS sends the message M5 to the domain server DS i through the public channel, and sends the message M6 to the domain server DS j ;
[0017] S11, the domain server DS i Receives the inter-domain session group key: After the domain server DS i receives the message M5 from the authentication server AS, it generates the message reception timestamp T5 Re , checks whether T5 Re - T5 < ΔT5 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of the device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps. Then, the domain server DS i calculates the verification information and compares the result with I5 sent by M5 to verify Whether it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps. The domain server DS i calculates the inter-domain session group key SK according to the information in the memoryAB , then generate a random number N6 and a timestamp T6, and calculate SK' A and the verification information I7. After that, the domain server DS i sends the message M7 to the device D through the public channel ii ;
[0018] S12. The device D ii Receives the inter-domain session group key: After the device D ii receives the message M7 from the domain server DS i , it generates a message reception timestamp T6 Re , and checks whether T6 Re - T6 < ΔT6 holds. If the verification fails, the device D ii will terminate the authentication key exchange process; otherwise, the device D ii continues to execute the subsequent steps. Then, the device D ii calculates the verification information and compares the result with I7 sent by M7 to verify whether it holds. If the verification fails, the device D ii will terminate the authentication key exchange process; otherwise, the device D ii continues to execute the subsequent steps. The device D ii calculates the inter-domain session group key SK according to the information in the memory AB , and calculates the session key SK between the pseudo-identity PD of the device D AB in the domain server DS i and the pseudo-identity PD of the device D ii in the domain server DS ii and the pseudo-identity PD of the device D j in the domain server DS ji and the pseudo-identity PD of the device D ji . At this point, the device D i in the domain server DS ii has obtained the session key SK with the device D j in the domain server DS ji .
[0019] S13. The domain server DS j Receives the inter-domain session group key: After the domain server DS j receives the message M6 from the authentication server AS, it generates a message reception timestamp T6 Re , and checks whether T6 Re - T6 < ΔT6 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of the device D ji ; otherwise, the domain server DS j continues to execute the subsequent steps. Then, the domain server DS jCalculate verification information And compare the result with I6 sent by M6 for verification Whether it holds. If the verification fails, the domain server DS j Will terminate the authentication key exchange process; otherwise, the domain server DS j Continue to execute the subsequent steps. The domain server DS j Calculate the inter-domain session group key SK based on the information in the memory AB , then generate a random number N7 and a timestamp T7, and calculate SK' B And verification information I8. After that, the domain server DS j Sends the message M8 to the device D through the public channel ji ;
[0020] S14. The device D ji Receives the inter-domain session group key: After the device D ji Receives the message M8 from the domain server DS j , generates a message reception timestamp T7 Re , checks whether T7 Re - T7 < ΔT7 holds. If the verification fails, the device D ji Will terminate the authentication key exchange process; otherwise, the device D ji Continue to execute the subsequent steps. Then, the device D ji Calculates the verification information And compares the result with I8 sent by M8 for verification Whether it holds. If the verification fails, the device D ji Will terminate the authentication key exchange process; otherwise, the device D ji Continue to execute the subsequent steps. The device D ji Calculates the inter-domain session group key SK based on the information in the memory AB , calculates the pseudo-identity PD of the device D in the domain server DS AB According to the inter-domain session group key SK j And the session key SK between the pseudo-identity PD of the device D in the domain server DS ji And the pseudo-identity PD of the device D in the domain server DS ji And the domain server DS i The pseudo-identity PD of the device D in ii And the pseudo-identity PD of the device D in the domain server DS ii . At this point, the device D in the domain server DS j Has obtained the session key SK with the device D in the domain server DS ji ; i The device D in ii ;
[0021] Furthermore, the specific sub-steps of the step S1 are as follows:
[0022] S1-1. The device Dii Check whether it has PUF and WCC. If it only has PUF, device D ii Randomly generate excitation C i and use its PUF chip to generate response R i If it only has WCC, generate wireless channel fingerprint F i and use the wireless fingerprint to locate and calculate the device position P i If it has both PUF and WCC, generate the corresponding C i 、R i 、F i and P i All information. Send the device identity D ii ,excitation-response pair C i ,R i ,fingerprint-location pair F i ,P i to the domain server DS i ;
[0023] S1-2. Domain server DS i After receiving the above information, store this information in the server;
[0024] S1-3. All devices D j wanting to perform key negotiation with devices inside the domain server DS ii will perform step S1-2.
[0025] Furthermore, the specific sub-steps of step S2 are as follows:
[0026] S2-1. Domain server DS i Randomly generate PUF excitation DC i and use its PUF chip to generate response DR i ;
[0027] S2-2. Domain server DS i According to the information D ii 、R i and DS i generate the pseudo-identity PD ii of device D ii .
[0028] S2-3. Domain server DS i Send the identity identifier DS of the domain server i 、the PUF excitation response DC of the domain server i and DR i 、the identity identifier D of the device ii and pseudo-identity PD ii to the authentication server AS.
[0029] Furthermore, the specific sub-steps of step S3 are as follows:
[0030] S3-1. Device D ji Checks whether it has PUF and WCC. If it only has PUF, device D ji Randomly generates excitation C j , and uses its PUF chip to generate response R j . If it only has WCC, it generates wireless channel fingerprint F j 、Uses wireless fingerprint positioning to calculate the device location P j . If it has both PUF and WCC, it generates corresponding C j 、R j 、F j and P j All information. Sends the device identity D ji , excitation-response pair C j ,R j , fingerprint-location pair F j ,P j to the domain server DS j ;
[0031] S3-2. Domain server DS j After receiving the above information, stores this information in the memory;
[0032] S3-3. All devices D i wanting to perform key negotiation with devices inside the domain server DS ji will perform step S3-2.
[0033] Furthermore, the specific sub-steps of step S4 are as follows:
[0034] S4-1. Domain server DS j Randomly generates PUF excitation DC j , and uses its PUF chip to generate response DR j ;
[0035] S4-2. Domain server DS j Generates the pseudo-identity PD ji 、R j and DS j of device D ji according to the information D ji in the memory.
[0036] S4-3. Domain server DS j Sends the identity identifier DS j of the domain server, the PUF excitation response DC j and DRj The identity identifier D of the device ji and the pseudo-identity PD ji are sent to the authentication server AS.
[0037] Furthermore, the specific sub-steps of step S5 are as follows:
[0038] S5-1: After the authentication server AS receives the messages from the domain server DS i and DS j it generates its own pseudo-identity PA i , the pseudo-identity PDS of the domain server DS i and the pseudo-identity PDS of the domain server DS i . After that, the authentication server AS saves D j , PD j , DS ii , PDS ii , DC i , DR i , D i , PD i , DS ji , PDS ji , DS j , PDS j , DC j , DR j and PA i in the memory;
[0039] S5-2: The authentication server AS sends the information PA i , PDS i , PDS j , PD ji and D ji to the domain server DS i . After receiving the information PA i , PDS i , PDS i , PD j , PD ji and D ji , the domain server DS saves the information PA i , PDS i , PDS j , PD ji and D ji in the server and sends the information PA i , PDS i , PDS j and PD ji to the device D ii ;
[0040] S5-3: The device D ii sends the information PAi , PDS i , PDS j and PD ji are saved in its own memory;
[0041] S5-4. The authentication server AS sends the information PA i , PDS i , PDS j , PD ii and D ii to the domain server DS j . The domain server DS j receives the information PA i , PDS i , PDS j , PD ii and D ii . After that, it saves the information PA i , PDS i , PDS j , PD ii and D ii in the server and sends the information PA i , PDS i , PDS j , PD ii to the device D ji ;
[0042] S5-5. The device D ji saves the information PA i , PDS i , PDS j and PD ii in its own memory;
[0043] Furthermore, the specific sub-steps of step S6 are as follows:
[0044] S6-1. The device D ii checks whether it has PUF and WCC. If it only has PUF, it generates the PUF excitation C i , response R i . If it only has WCC, it generates the wireless channel fingerprint F i , location P i . If it has both PUF and WCC, it generates the corresponding C i , R i , F i and P i all the information;
[0045] S6-2. The device D ii generates a random number N1 and a timestamp T1, and calculates the verification information I1;
[0046] S6-3, Device D ii Send message M1 to its own domain server DS through the public channel i .
[0047] Furthermore, the specific sub-steps of step S7 are as follows:
[0048] S7-1, Domain server DS i After receiving the message M1 from Device D ii generate a message reception timestamp T1 Re , and check whether T1 Re - T1 < ΔT1 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of Device D ii ; conversely, the domain server DS i continues to execute the subsequent steps;
[0049] S7-2, Domain server DS i Calculate the verification information and compare the result with I1 sent by M1 to verify whether it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; conversely, the domain server DS i continues to execute the subsequent steps.;
[0050] S7-3, Domain server DS i Calculate the identity D of the device according to the information in the memory ii , and verify whether this identity is in its own database. If it is not in the database, the domain server DS i will terminate the authentication key exchange process; conversely, the domain server DS i continues to execute the subsequent steps;
[0051] S7-4, Domain server DS i Collect all the requested devices, and put the pseudo-identities of these n devices into the set A = {D i1 , D i2 , …, D in};
[0052] S7-5, Domain server DS i Generate a response DR i for the incentive DC i , a random number N3 and a timestamp T3, calculate the verification information I3, and then encrypt the set A = {D i1 , D i2 , …, D in} into Ciph A ;
[0053] S7-6, Domain Server DS i Send message M3 to the authentication server AS through the public channel.
[0054] Furthermore, the specific sub-steps of step S8 are as follows:
[0055] S8-1, Device D ji Check whether it has PUF and WCC. If it only has PUF, generate PUF excitation C j , Response R j , if it only has WCC, generate wireless channel fingerprint F j , Location P j , if it has both PUF and WCC, generate the corresponding C j , R j , F j and P j All information;
[0056] S8-2, Device D ji Generate random number N2 and timestamp T2, and calculate verification information I2;
[0057] S8-3, Device D ji Send message M2 to its own domain server DS through the public channel j .
[0058] Furthermore, the specific sub-steps of step S9 are as follows:
[0059] S9-1, Domain Server DS j After receiving message M4 from device D ji , generate message reception timestamp T2 Re , check T2 Re -T2 < ΔT2 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of device D ji ; otherwise, the domain server DS j continues to execute the subsequent steps;
[0060] S9-2, Domain Server DS j Calculate verification information and compare the result with I2 sent by M2 to verify whether it holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j continues to execute the subsequent steps;
[0061] S9-3, Domain Server DS j Calculate the identity D of the device according to the information in the memoryji , verify whether this identity exists in its own database. If it does not exist in the database, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j will continue to execute the subsequent steps;
[0062] S9-4. The domain server DS j collects all the requested devices and puts the pseudo-identities of these n devices into the set B = {D j1 , D j2 , …, D jn};
[0063] S9-5. The domain server DS j generates the response DR j to the incentive DC j , a random number N4, and a timestamp T4, calculates the verification information I4, and then encrypts the set B = {D j1 , D j2 , …, D jn} into Ciph B ;
[0064] S9-6. The domain server DS j sends the message M4 to the authentication server AS through the public channel.
[0065] Furthermore, the specific sub-steps of the step S10 are as follows:
[0066] S10-1. After receiving the messages M3 and M4 from the devices D ii and D ji , the authentication server AS generates the message reception timestamps T3 Re and T4 Re respectively, and checks whether T3 Re - T3 < ΔT3 and T4 Re - T4 < ΔT4 hold. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps;
[0067] S10-2. The authentication server AS calculates the verification information and and compares the results with I3 and I4 sent by M3 and M4 to verify whether and hold. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps;
[0068] S10-3. The authentication server AS calculates the sets A and B, where A = {D i1 , Di2 ,…,D in}, and B = {D j1 , D j2 ,…, D jn} generate the inter-domain session group key SK AB ;
[0069] S10-4. The authentication server AS generates a random number N5 and a timestamp T5, and calculates SK A , SK B and verification information I5, I6;
[0070] S10-5. The authentication server AS sends the message M5 to the domain server DS through the public channel i , and sends the message M6 to the domain server DS through the public channel j .
[0071] Furthermore, the specific sub-steps of the step S11 are as follows:
[0072] S11-1. After the domain server DS i receives the message M5 from the authentication server AS, it generates a message reception timestamp T5 Re , and checks whether T5 Re - T5 < ΔT5 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of the device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps;
[0073] S11-2. The domain server DS i calculates the verification information and compares the result with I5 sent by M5 to verify whether it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps.
[0074] S11-3. The domain server DS i calculates the inter-domain session group key SK AB according to the information in the memory;
[0075] S11-4. The domain server DS i generates a random number N6 and a timestamp T6, and calculates SK' A and verification information I7;
[0076] S11-5. The domain server DS i sends the message M7 to the device D through the public channel ii
[0077] Furthermore, the specific sub-steps of step S12 are as follows:
[0078] S12-1. Device D ii After receiving the message M7 from the domain server DS i generates a message reception timestamp T6 Re and checks whether T6 Re - T6 < ΔT6 holds. If the verification fails, device D ii will terminate the authentication key exchange process; otherwise, device D ii continues to execute the subsequent steps;
[0079] S12-2. Device D ii calculates the verification information and compares the result with I7 sent by M7 to verify whether it holds. If the verification fails, device D ii will terminate the authentication key exchange process; otherwise, device D ii continues to execute the subsequent steps;
[0080] S12-3. Device D ii calculates the inter-domain session group key SK based on the information in the memory AB ;
[0081] S12-4. Based on the inter-domain session group key SK AB calculate the pseudo-identity PD of device D in the domain server DS i and the session key SK between the pseudo-identity PD of device D in the domain server DS ii and the pseudo-identity PD of device D in the domain server DS ii and the pseudo-identity PD of device D in the domain server DS j and the pseudo-identity PD of device D in the domain server DS ji and the pseudo-identity PD of device D in the domain server DS ji . Thus, device D in the domain server DS i has obtained the session key SK with device D in the domain server DS ii ; j and the pseudo-identity PD of device D in the domain server DS ji ;
[0082] Furthermore, the specific sub-steps of step S13 are as follows:
[0083] S13-1. The domain server DS j After receiving the message M6 from the authentication server AS, generates a message reception timestamp T6 Re and checks whether T6 Re - T6 < ΔT6 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of device D ji ; otherwise, the domain server DS jContinue to execute the subsequent steps;
[0084] S13-2, Domain Server DS j Calculate the verification information And compare the result with I6 sent by M6 for verification Whether it holds. If the verification fails, the domain server DS j Will terminate the authentication key exchange process; otherwise, the domain server DS j Continue to execute the subsequent steps;
[0085] S13-3, Domain Server DS j Calculate the inter-domain session group key SK based on the information in the memory AB ;
[0086] S13-4, Domain Server DS j Generate a random number N7 and a timestamp T7, and calculate SK' B And the verification information I8;
[0087] S13-5, Domain Server DS j Send the message M8 to the device D through the public channel ji .
[0088] Furthermore, the specific sub-steps of the step S14 are as follows:
[0089] S14-1, Device D ji After receiving the message M8 from the domain server DS j , generate a message reception timestamp T7 Re , and check whether T7 Re -T7 < ΔT7 holds. If the verification fails, the device D ji Will terminate the authentication key exchange process; otherwise, the device D ji Continue to execute the subsequent steps;
[0090] S14-2, Device D ji Calculate the verification information And compare the result with I8 sent by M8 for verification Whether it holds. If the verification fails, the device D ji Will terminate the authentication key exchange process; otherwise, the device D ji Continue to execute the subsequent steps;
[0091] S14-3, Device D ji Calculate the inter-domain session group key SK based on the information in the memory AB ;
[0092] S14-4, Device D ji According to the inter-domain session group key SK ABCalculate the domain server DS j Device D in ji Pseudo-identity PD ji And the domain server DS i Device D in ii Pseudo-identity PD ii The session key SK between them.
[0093] Compared with the prior art, the present invention has the following beneficial effects:
[0094] 1. Strong mutual authentication: In this method, the mutual authentication of IoT devices, domain servers, and authentication servers depends on the validity of CRPs and FPPs. The domain server stores the pre-generated CRPs and FPPs of the devices, and the authentication server stores the CRPs pre-generated by the domain server. Since the attacker A cannot access the PUF chips of the devices and domain servers, it cannot obtain the response values in the "challenge-response pairs". The gateway has a pre-shared key with the server to ensure the communication security between the gateway and the devices. At the same time, the domain server, as an intermediate device for communication between the device and the authentication server, verifies the authenticity of both parties through the CRPs generated by the IoT device. The authentication server, as an intermediate device for communication between domain servers, verifies the authenticity of both parties through the CRPs generated by the domain server.
[0095] 2. Confidentiality: The parameters used each time this method runs are updated. Shannon's theorem proves that if at least one item in the XOR operation is random, then simple XOR encryption is secure. For the adversary A, the parameters of the intercepted messages change randomly in each round. Therefore, this protocol effectively guarantees the confidentiality of data transmitted through simple XOR encryption and reduces the transmission overhead.
[0096] 3. Device anonymity and unlinkability: This method does not use the real identities of the devices. In the registration phase, each device and the domain server know the pseudo-identities of other devices and servers. In the identity authentication phase, all devices and servers will use the pseudo-identities to authenticate the authenticity of the peer identities. Normally, all pseudo-identities and CRPs are changed in each round. The attacker A cannot connect to the devices or servers by intercepting the messages between each device and the domain server, and between the domain server and the authentication server. Therefore, our protocol provides strong anonymity and unlinkability.
[0097] 4. Perfect forward and backward secrecy: In this method, if an attacker obtains the current session key, it cannot obtain the previous session key and the next session key through the current session key. And it cannot obtain the session key between the gateway and the wireless sensor through the session key between the server and the gateway. In this protocol, the session key is generated by combining information such as random numbers, timestamps, CRPs, and FPPs. There is no association between session keys, which ensures the forward and reverse security of session keys.
[0098] 5. Anti-cloning and physical attacks: In this method, adversary A cannot obtain the data in the memory through side-channel attacks or tamper with the relevant data. Since any modification to the device will affect the output of the PUF, adversary A will not be able to obtain the complete PUF challenge-response pairs. At the same time, the physical unclonable function is non-replicable, so the protocol in this paper can resist cloning and physical attacks.
[0099] 6. Anti-replay attack: This method introduces a timestamp T n (n = 1, 2, 3...). At the initial stage of each session, both the device and the server will check the validity of the timestamp. Therefore, adversary A cannot obtain the target information or interfere with the secure operation of the protocol through replay attacks. Moreover, the verification code in the protocol of this paper contains the hashing and XOR operations of multiple key information such as pseudo-identities, CRPs, and FPPs, and even if replayed, it cannot pass the verification. Therefore, the protocol in this paper can resist replay attacks.
[0100] 7. Resistance to man-in-the-middle attacks: In this method, mutual authentication is carried out between the device and the server. The verification code in the protocol contains the hashing and XOR operations of multiple key information, and adversary A cannot obtain the authentication of the device or the server with only a few pieces of information. The timestamp can also ensure that adversary A cannot tamper with the messages through man-in-the-middle attacks. Therefore, this protocol can resist man-in-the-middle attacks.
[0101] 8. Anti-impersonation attacks: In this method, each IoT device is equipped with a unique PUF chip, and attackers or malicious devices cannot imitate them. At the same time, the device will also generate the location information of the device according to the wireless channel characteristics and bind the channel characteristics with the location. Even if adversary A simulates the channel characteristics of the device, it cannot always determine the real-time location of some mobile devices. Finally, adversary A cannot simulate the server either, because it does not have access to the CRPs and FPPs of the IoT device.
[0102] 9. Resistance to key leakage: In this method, it is assumed that adversary A obtains the wireless channel characteristics between the device and the domain server or the CRPs information between the device and the domain server, and between the domain server and the authentication server, and hopes to simulate either the device or the server to verify the other party. However, in this protocol, the interactive messages are transmitted through XOR-encrypted data or verification values encrypted by hash values. After obtaining the key, although the ciphertext can be decrypted, the obtained messages are not sufficient to calculate the verification value, nor can the device verification method be known. Therefore, the protocol can resist key leakage attacks.
[0103] 10. Resistance to DoS attacks: In this method, both communication parties will check the validity of the message timestamp T n (n = 1, 2, 3...) and the verification code at the initial stage of each session. If the verification fails, the negotiation will end immediately. Therefore, the protocol in this paper can resist DoS attacks. Brief Description of the Drawings
[0104] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0105] Figure 1 It is a flowchart of the registration phase of PWCBAP protocol devices and domain servers.
[0106] Figure 2 It is a flowchart of the identity authentication and key exchange phase of the PWCBAP protocol. Embodiment
[0108] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0109] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.
[0110] As Figure 1 and 2 The embodiment of the present invention provides an identity authentication method based on the PWCBAP protocol;
[0111] The identity authentication method based on the PWCBAP protocol includes:
[0112] S1. Device D ii Register with the domain server DS i : Device D ii Applies for registration with the domain server DS i . Device D ii Checks whether it has PUF and WCC. If it only has PUF, it generates a PUF excitation C i , response R i . If it only has WCC, it generates a wireless channel fingerprint F i , location P i . If it has both PUF and WCC, it generates the corresponding C i , R i , F i and P i All information. Device D iiSend information D ii , C i , R i , F i and P i to the domain server DS i , and the domain server DS i stores information D ii , C i , R i , F i and P i in the server. All devices D j wanting to perform key negotiation with devices inside the domain server DS ii will perform this step, and this step is transmitted over a secure channel.
[0113] Specifically, in the embodiment of the present invention, step S1 includes the following steps:
[0114] S1-1. Device D ii checks whether it has a PUF and a WCC. If it only has a PUF, device D ii randomly generates an excitation C i , and uses its PUF chip to generate a response R i = PUF(C i ). If it only has a WCC, it generates a wireless channel fingerprint F i and uses the wireless fingerprint to locate and calculate the device position P i . If it has both a PUF and a WCC, it generates the corresponding C i , R i , F i and P i for all information. Through the secure channel, the device identity D ii , the excitation-response pair C i , R i , the fingerprint-position pair F i , P i is sent to the domain server DS i ;
[0115] S1-2. After receiving the above information, the domain server DS i stores this information in the server;
[0116] S1-3. All devices D j wanting to perform key negotiation with devices inside the domain server DS ii will perform step S1-2.
[0117] S2. The domain server DS i registers with the authentication server AS: The domain server DS i applies to the authentication server AS for registration, and the domain server DSi Generate PUF excitation DC i and response DR i , domain server DS i generates the pseudo-identity PD of all devices D ii ii , domain server DS i sends the information DS i , DC i , DR i , D ii and PD ii to the authentication server. The authentication server AS receives DS i , DC i , DR i , D ii and PD ii and stores them in memory. The above steps are carried out in a secure channel.
[0118] Specifically, in the embodiment of the present invention, step S2 includes the following steps:
[0119] S2-1. The domain server DS i randomly generates the PUF excitation DC i , and uses its PUF chip to generate the response DR i = PUF(DC i );
[0120] S2-2. The domain server DS i generates the pseudo-identity of device D ii according to the information D i , R i and DS ii in the memory
[0121] S2-3. The domain server DS i sends the identity identifier DS of the domain server i , the PUF excitation response DC of the domain server i and DR i , the identity identifier D of the device ii and the pseudo-identity PD ii to the authentication server AS through a secure channel.
[0122] S3. D ji registers with the domain server DS j : The device D ji applies to the domain server DS j for registration. The device D ji checks whether it has a PUF and a WCC. If it only has a PUF, it generates the PUF excitation C j , response Rj , if there is only WCC, generate the wireless channel fingerprint F j , location P j , if both PUF and WCC are available, generate the corresponding C j , R j , F j and P j all information. Device D ji sends the information D ji , C j , R j , F j and P j to the domain server DS j , the domain server DS j saves the information D ji , C j , R j , F j and P j in the server. All devices D i that want to perform key negotiation with devices inside the domain server DS ji will perform this step, and this step is transmitted over a secure channel.
[0123] Specifically, in the embodiment of the present invention, step S3 includes the following steps:
[0124] S3-1. Device D ji checks whether it has PUF and WCC. If it only has PUF, device D ji randomly generates an excitation C j , and uses its PUF chip to generate a response R j = PUF(C j ), if there is only WCC, generate the wireless channel fingerprint F j , use the wireless fingerprint positioning to calculate the device location P j , if both PUF and WCC are available, generate the corresponding C j , R j , F j and P j all information. Through the secure channel, the device identity D ji , the excitation-response pair C j , R j , the fingerprint-location pair F j , P j are sent to the domain server DS j ;
[0125] S3-2. After receiving the above information, the domain server DS j stores this information in the memory;
[0126] S3-3. All devices D i that want to perform key negotiation with the domain server DS ji inside will perform step S3-2.
[0127] S4. The domain server DS j registers with the authentication server AS: The domain server DS j applies to the authentication server AS for registration. The domain server DS j generates the PUF excitation DC j and the response DR j . The domain server DS j generates the pseudo-identities PD ji of all devices D ji . The domain server DS j sends the information DS j , DC j , DR j , D ji and PD ji to the authentication server. After receiving DS j , DC j , DR j , D ji and PD ji , the authentication server stores them in the server. The above steps are performed in a secure channel.
[0128] Specifically, in the embodiment of the present invention, step S4 includes the following steps:
[0129] S4-1. The domain server DS j randomly generates the PUF excitation DC j , and uses its PUF chip to generate the response DR j = PUF(DC j );
[0130] S4-2. The domain server DS j generates the pseudo-identity ji of device D j according to the information D j , R ji and DS
[0131] S4-3. The domain server DS j sends the identity identifier DS j of the domain server, the PUF excitation response DC j and DR j , the identity identifier D ji of the device and the pseudo-identity PD ji to the authentication server AS through a secure channel.
[0132] S5. The authentication server AS generates and distributes information: The authentication server AS generates its own pseudo-identity PA i , the domain server DS i 's pseudo-identity PDS i and the domain server DS j 's pseudo-identity PDS j . After that, the authentication server AS stores D ii , PD ii , DS i , PDS i , DC i , DR i , D ji , PD ji , DS j , PDS j , DC j , DR j and PA i in memory. The authentication server AS sends the information PA i , PDS i , PDS j , PD ji and D ji to the domain server DS i . The domain server DS i receives the information PA i , PDS i , PDS j , PD ji and D ji and stores the information PA i , PDS i , PDS j , PD ji and D ji in the server and sends the information PA i , PDS i , PDS j and PD ji to the device D ii . The device D ii stores the information PA i , PDS i , PDS j and PD ji in its own memory. The authentication server AS sends the information PA i , PDS i , PDS j , PD ii and D ii to the domain server DS j . The domain server DS j receives the information PAi , PDS i , PDS j , PD ii and D ii After that, save the information PA i , PDS i , PDS j , PD ii and D ii in the server and send the information PA i , PDS i , PDS j and PD ii to the device D ji . The device D ji will save the information PA i , PDS i , PDS j and PD ii in its own memory. Thus, the registration phase of all devices and the domain server to the authentication server has been completed.
[0133] Specifically, in the embodiment of the present invention, step S5 includes the following steps:
[0134] S5-1. After the authentication server AS receives the messages from the domain servers DS i and DS j , generate its own pseudo-identity PA i , the pseudo-identity of the domain server DS i and the pseudo-identity of the domain server DS and the pseudo-identity of the domain server DS j . After that, the authentication server AS will save D ii , PD ii , DS i , PDS i , DC i , DR i , D ji , PD ji , DS j , PDS j , DC j , DR j and PA i in the memory;
[0135]
[0135] S5-2. The authentication server AS sends the information PA i , PDS i , PDS j , PD ji and D ji to the domain server DS i , and the domain server DS i receives the information PAi , PDS i , PDS j , PD ji and D ji After that, save the information PA i , PDS i , PDS j , PD ji and D ji in the server and send the information PA i , PDS i , PDS j and PD ji to the device D ii ;
[0136] S5-3. Device D ii Save the information PA i , PDS i , PDS j and PD ji in its own memory;
[0137] S5-4. The authentication server AS sends the information PA i , PDS i , PDS j , PD ii and D ii to the domain server DS j . The domain server DS j receives the information PA i , PDS i , PDS j , PD ii and D ii After that, save the information PA i , PDS i , PDS j , PD ii and D ii in the server and send the information PA i , PDS i , PDS j and PD ii to the device D ji ;
[0138] S5-5. Device D ji Save the information PA i , PDS i , PDS j and PD ii in its own memory;
[0139] S6. Device D ii Initiates a session: After registration is completed, device Dii Start key negotiation. Device D ii Check if it has both PUF and WCC. If it only has PUF, generate PUF challenge C i and response R i . If it only has WCC, generate wireless channel fingerprint F i and location P i . If it has both PUF and WCC, generate the corresponding C i , R i , F i and P i all information. Device D ii generates random number N1 and timestamp T1, and calculates verification information I1. Subsequently, device D ii sends message M1 to its domain server DS via the public channel i .
[0140] Specifically, in the embodiment of the present invention, step S6 includes the following steps:
[0141] S6-1. Device D ii Check if it has both PUF and WCC. If it only has PUF, generate PUF challenge C i and response R i =PUF(C i ), if it only has WCC, generate wireless channel fingerprint F i and location P i . If it has both PUF and WCC, generate the corresponding C i , R i , F i and P i all information;
[0142] S6-2. Device D ii generates random number N1 and timestamp T1, and calculates verification information I1 = h(D ii ||R i ||P i ||N1||T1);
[0143] S6-3. Device D ii sends message M1 = {PD ii , I1, N1, T1} to its domain server DS via the public channel i .
[0144] S7. Domain server DS i verifies and requests the inter-domain session key: The domain server DS i after receiving message M1 from device D ii , generates message reception timestamp T1 Re, check T1 Re - Whether -T1 < ΔT1 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps. Then, the domain server DS i calculates the verification information and compares the result with I1 sent by M1 to verify whether it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps. The domain server DS i calculates the identity of device D according to the information in the memory ii and verifies whether this identity is in its own database. If it is not in the database, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps. The domain server DS i collects all the requested devices, puts the pseudo - identities of these n devices into the set A = {D i1 , D i2 , …, D in}, the domain server DS i generates the response DR i for the incentive DC i , a random number N3, and a timestamp T3, calculates the verification information I3, and then encrypts the set A = {D i1 , D i2 , …, D in} into Ciph A . After that, the domain server DS i sends the message M3 to the authentication server AS through the public channel.
[0145] Specifically, in the embodiment of the present invention, step S7 includes the following steps:
[0146] S7 - 1. After receiving the message M1 from device D i , the domain server DS ii generates the message reception timestamp T1 Re , and checks T1 Re - Whether -T1 < ΔT1 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps;
[0147] S7 - 2. The domain server DSi Calculate the verification information And compare the result with I1 sent by M1 for verification to check if it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i will continue to execute the subsequent steps.;
[0148] S7-3. The domain server DS i Calculate the identity of the device based on the information in the memory and verify whether this identity is in its own database. If it is not in the database, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i will continue to execute the subsequent steps;
[0149] S7-4. The domain server DS i Collect all the requested devices and put the pseudo-identities of these n devices into the set A = {D i1 , D i2 , …, D in};
[0150] S7-5. The domain server DS i Generate the response DR i of the incentive DC i = PUF(DC i ), the random number N3, and the timestamp T3, calculate the verification information I3 = h(DS i ||PA i ||DR i ||N3||T3), and then encrypt the set A = {D i1 , D i2 , …, D in} into
[0151] S7-6. The domain server DS i Send the message M3 = {Ciph A , PDS i , I3, N3, T3} to the authentication server AS through the public channel.
[0152] S8. The device D ji Initiate a session: After registration is completed, the device D ji starts key negotiation. The device D ji Checks whether it has PUF and WCC. If it only has PUF, it generates the PUF incentive C j , the response R j , if it only has WCC, it generates the wireless channel fingerprint F j , the location Pj , if both the PUF and WCC are available, corresponding C is generated j , R j , F j and P j all information. Device D ji generates a random number N2 and a timestamp T2, and calculates the verification information I2. Subsequently, the device sends the message M2 to its domain server DS through the public channel j .
[0153] Specifically, in the embodiment of the present invention, step S8 includes the following steps:
[0154] S8-1. Device D ji checks whether it has the PUF and WCC. If only the PUF is available, it generates the PUF challenge C j , response R j = PUF(C j ), if only the WCC is available, it generates the wireless channel fingerprint F j , location P j , if both the PUF and WCC are available, it generates the corresponding C j , R j , F j and P j all information;
[0155] S8-2. Device D ji generates a random number N2 and a timestamp T2, and calculates the verification information I2 = h(D ji ||R j ||P j ||N2||T2);
[0156] S8-3. Device D ji sends the message M2 = {PD ji , I2, N2, T2} to its domain server DS through the public channel j .
[0157] S9. Domain server DS j verifies and requests the inter-domain session group key: After receiving the message M4 from device D j , the domain server DS ji generates a message reception timestamp checks whether it holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of device D ji ; otherwise, the domain server DS j continues to execute the subsequent steps. Then, the domain server DS j calculates the verification information Compare the result with I2 sent by M2 for verification whether it holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j will continue with the subsequent steps. The domain server DS j calculates the identity D of the device based on the information in the memory ji , and verifies whether this identity is in its own database. If it is not in the database, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j will continue with the subsequent steps. The domain server DS j collects all the requested devices, puts the pseudo-identities of these n devices into the set B = {D j1 , D j2 , …, D jn}, and the domain server DS j generates a response DR j for the incentive DC j , a random number N4, and a timestamp T4, calculates the verification information I4, and then encrypts the set B = {D j1 , D j2 , …, D jn} into Ciph B . After that, the domain server DS j sends the message M4 to the authentication server AS through the public channel.
[0158] Specifically, in the embodiment of the present invention, step S9 includes the following steps:
[0159] S9-1. After the domain server DS j receives the message M4 from the device D ji , it generates a message reception timestamp T2 Re , and checks whether T2 Re - T2 < ΔT2 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of the device D ji ; otherwise, the domain server DS j will continue with the subsequent steps;
[0160] S9-2. The domain server DS j calculates the verification information and compares the result with I2 sent by M2 to verify whether it holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j will continue with the subsequent steps;
[0161] S9-3, Domain Server DS j Calculate the identity of the device based on the information in the memory Verify whether the identity is in its own database. If it is not in the database, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j will continue to execute the subsequent steps;
[0162] S9-4, Domain Server DS j Collect all the requested devices and put the pseudo-identities of these n devices into the set B = {D j1 , D j2 , …, D jn};
[0163] S9-5, Domain Server DS j Generate the response DR j of the excitation DC j = PUF(DC j ), a random number N4, and a timestamp T4, calculate the verification information I4 = h(DS j ||PA i ||DR j ||N4||T4), and then encrypt the set B = {D j1 , D j2 , …, D jn} into
[0164] S9-6, Domain Server DS j Send the message M4 = {Ciph B , PDS j , I4, N4, T4} to the authentication server AS through the public channel.
[0165] S10, Generation of the inter-domain session group key by the authentication server AS: After receiving the messages M3 and M4 from the devices D ii and D ji , the authentication server AS generates the message reception timestamps T3 Re and T4 Re respectively, and checks whether T3 Re - T3 < ΔT3 and T4 Re - T4 < ΔT4 hold. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps. Then the authentication server AS calculates the verification information and and compares the results with I3 and I4 sent by M3 and M4 to verify and Whether it holds. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps. The authentication server AS calculates the sets A = {D i1 , D i2 , …, D in} and B = {D j1 , D j2 , …, D jn}, generates the inter-domain session group key SK AB for A = {D i1 , D i2 , …, D in} and B = {D j1 , D j2 , …, D jn}, and simultaneously generates a random number N5 and a timestamp T5, calculates SK A , SK B and verification information I5, I6. Then the authentication server AS sends the message M5 to the domain server DS i through the public channel, and sends the message M6 to the domain server DS j through the public channel.
[0166] Specifically, in the embodiment of the present invention, step S10 includes the following steps:
[0167] S10-1. After the authentication server AS receives the messages M3 and M4 from the devices D ii and D ji , it respectively generates message reception timestamps T3 Re and T4 Re , and checks whether T3 Re - T3 < ΔT3 and T4 Re - T4 < ΔT4 hold. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps;
[0168] S10-2. The authentication server AS calculates the verification information and and compares the results with I3 and I4 sent by M3 and M4 to verify whether and hold. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps;
[0169] S10-3. The authentication server AS calculates the sets and the set as A = {D i1 , D i2 , …, D in}, and B = {D j1 , D j2 , …, D jn} to generate the inter-domain session group key SK AB ;
[0170] S10-4. The authentication server AS generates a random number N5 and a timestamp T5, and calculates and the verification information I5 = h(DS i ||DR i ||SK A ||N5||T5), I6 = h(DS j ||DR j ||SK B ||N5||T5);
[0171] S10-5. The authentication server AS sends the message M5 = {SK A , I5, N5, T5} to the domain server DS through the public channel i , and sends the message M6 = {SK B , I6, N5, T5} to the domain server DS through the public channel j .
[0172] S11. The domain server DS i Receives the inter-domain session group key: After the domain server DS i receives the message M5 from the authentication server AS, it generates the message reception timestamp T5 Re , and checks whether T5 Re - T5 < ΔT5 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of the device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps. Then, the domain server DS i calculates the verification information and compares the result with I5 sent by M5 to verify whether it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps. The domain server DS i calculates the inter-domain session group key SK AB according to the information in the memory, then generates a random number N6 and a timestamp T6, and calculates SK' A and the verification information I7. After that, the domain server DS i sends the message M7 to the device D through the public channel ii .
[0173] Specifically, in the embodiments of the present invention, step S11 includes the following steps:
[0174] S11-1. Domain Server DS i After receiving the message M5 from the authentication server AS, generate a message reception timestamp T5 Re , and check T5 Re - Whether T5 < ΔT5 holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process of the device D ii ; otherwise, the domain server DS i continues to execute the subsequent steps;
[0175] S11-2. Domain Server DS i Calculate the verification information and compare the result with I5 sent by M5 to verify whether it holds. If the verification fails, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps.
[0176] S11-3. Domain Server DS i Calculate the inter-domain session group key according to the information in the memory
[0177] S11-4. Domain Server DS i Generate a random number N6 and a timestamp T6, and calculate and the verification information I7 = h(D ii ||R i ||F i ||SK A ||N6||T6);
[0178] S11-5. Domain Server DS i Send the message M7 = {SK' A , I7, N6, T6} to the device D through the public channel ii
[0179] S12. Device D ii Receive the inter-domain session group key: The device D ii After receiving the message M7 from the domain server DS i , generate a message reception timestamp T6 Re , and check T6 Re - Whether T6 < ΔT6 holds. If the verification fails, the device D ii will terminate the authentication key exchange process; otherwise, the device D ii continues to execute the subsequent steps. Then, the device Dii Calculate verification information And compare the result with I7 sent by M7 to verify Whether it holds. If the verification fails, device D ii Will terminate the authentication key exchange process; otherwise, device D ii Continue to execute the subsequent steps. Device D ii Calculate the inter-domain session group key SK according to the information in the memory AB According to the inter-domain session group key SK AB Calculate the pseudo-identity PD of device D in the domain server DS i Of device D ii Pseudo-identity PD ii And the domain server DS j Of device D in ji Pseudo-identity PD ji The session key SK between them. So far, the domain server DS i Of device D in ii Has obtained the session key SK with device D in the domain server DS j Of device D in ji Session key SK.
[0180] Specifically, in the embodiment of the present invention, step S12 includes the following steps:
[0181] S12-1. After device D ii Receives the message M7 from the domain server DS i Generates the message reception timestamp T6 Re , checks whether T6 Re -T6 < ΔT6 holds. If the verification fails, device D ii Will terminate the authentication key exchange process; otherwise, device D ii Continue to execute the subsequent steps;
[0182] S12-2. Device D ii Calculates the verification information And compares the result with I7 sent by M7 to verify Whether it holds. If the verification fails, device D ii Will terminate the authentication key exchange process; otherwise, device D ii Continue to execute the subsequent steps;
[0183] S12-3. Device D ii Calculates the inter-domain session group key according to the information in the memory
[0184] S12-4. According to the inter-domain session group key SK AB Calculates the domain server DS i Of device D in iiThe pseudo-identity PD ii and the domain server DS j in the device D ji The pseudo-identity PD ji The session key between So far, the domain server DS i in the device D ii has obtained the session key SK with the domain server DS j in the device D ji ;
[0185] S13. The domain server DS j Receives the inter-domain session group key: After the domain server DS j receives the message M6 from the authentication server AS, generates the message reception timestamp T6 Re , checks T6 Re -T6 < ΔT6 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of the device D ji ; otherwise, the domain server DS j continues to execute the subsequent steps. Then, the domain server DS j calculates the verification information and compares the result with I6 sent by M6 to verify whether it holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j continues to execute the subsequent steps. The domain server DS j calculates the inter-domain session group key SK according to the information in the memory AB , then generates a random number N7 and a timestamp T7, and calculates SK' B and the verification information I8. After that, the domain server DS j sends the message M8 to the device D through the public channel ji .
[0186] Specifically, in the embodiment of the present invention, step S13 includes the following steps:
[0187] S13-1. The domain server DS j After receiving the message M6 from the authentication server AS, generates the message reception timestamp T6 Re , checks T6 Re -T6 < ΔT6 holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process of the device D ji ; otherwise, the domain server DS j continues to execute the subsequent steps;
[0188] S13-2, Domain Server DS j Calculate the verification information and compare the result with I6 sent by M6 for verification to check if it holds. If the verification fails, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j will continue to execute the subsequent steps;
[0189] S13-3, Domain Server DS j Calculate the inter-domain session group key based on the information in the memory
[0190] S13-4, Domain Server DS j Generate a random number N7 and a timestamp T7, and calculate and the verification information I8 = h(D ji ||R j ||F j ||SK B ||N7||T7);
[0191] S13-5, Domain Server DS j Send the message M8 = {SK' B , I8, N7, T7} to the device D through the public channel ji .
[0192] S14, Device D ji Receive the inter-domain session group key: After the device D ji receives the message M8 from the domain server DS j , generate the message reception timestamp T7 Re , and check if T7 Re - T7 < ΔT7 holds. If the verification fails, the device D ji will terminate the authentication key exchange process; otherwise, the device D ji will continue to execute the subsequent steps. Then, the device D ji calculates the verification information and compares the result with I8 sent by M8 for verification to check if it holds. If the verification fails, the device D ji will terminate the authentication key exchange process; otherwise, the device D ji will continue to execute the subsequent steps. The device D ji calculates the inter-domain session group key SK according to the information in the memory AB , and calculates the pseudo-identity PD of the device D in the domain server DS AB based on the inter-domain session group key SK j where the device D is located in the domain server DS ji and the domain server DS ji and the domain server DSi Medium Equipment D ii Pseudo-identity PD ii The session key SK between them. At this point, the domain server DS j Medium Equipment D ji Has obtained the domain server DS i Medium Equipment D ii The session key SK.
[0193] Specifically, in the embodiment of the present invention, step S14 includes the following steps:
[0194] S14-1. Equipment D ji Received from domain server DS j After the message M8, the message receiving timestamp T7 is generated Re , check T7 Re -T7<ΔT7. If the verification fails, device D ji The authentication key exchange process will be terminated; otherwise, device D ji Continue with the next steps;
[0195] S14-2, Equipment D ji Calculation verification information And compare the result with I8 sent by M8 to verify If the verification fails, device D ji The authentication key exchange process will be terminated; otherwise, device D ji Continue with the next steps;
[0196] S14-3. Equipment D ji Calculate the inter-domain session group key based on the information in memory
[0197] S14-4, Equipment D ji According to the inter-domain session group key SK AB Calculate the domain server DS j Medium Equipment D ji Pseudo-identity PD ji and domain server DS i Medium Equipment D ii Pseudo-identity PD ii The session key between
[0198] Based on the PWCBAP protocol, the present invention uses CRPs and FPPs to implement a two-way authentication and key negotiation method between devices and between a device and a server. On the basis of meeting security requirements, the use of CRPs replaces the symmetric cryptosystem, reducing the computational overhead and shortening the authentication time. The use of FPPs increases the accuracy of protocol identity authentication. The PWCBAP protocol not only solves the problem that when performing batch authentication, it is necessary to verify each device one by one, with a time complexity of O(n), which cannot meet the fast access requirements of a large number of devices; but also solves the problem that when performing cross-domain authentication, sharing the CRP (challenge-response pair) of the PUF or the channel feature database has a serious risk of privacy leakage. At the same time, it enhances the effective defense mechanism against active attacks (such as side-channel attacks and man-in-the-middle attacks), ensuring the secure operation of the Internet of Things and having practical significance.
[0199] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same and similar parts between the various embodiments, reference can be made to each other. For the system disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for related parts.
[0200] The above are only the preferred embodiments of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be pointed out that for those of ordinary skill in the art, several improvements and refinements made without departing from the principle of the present invention should be regarded as within the protection scope of the present invention.
Claims
1. An Internet of Things device cross - domain batch identity authentication method based on the PWCBAP protocol, including a registration phase and an identity authentication and key exchange phase, characterized in that, The steps are as follows: S1. Device D ii Register with domain server DS i Registration: Device D ii Apply for registration with domain server DS i Device D ii Check whether it has PUF and WCC. If it only has PUF, generate PUF excitation C i and response R i If it only has WCC, generate wireless channel fingerprint F i and location P i If it has both PUF and WCC, generate corresponding C i 、R i 、F i and P i All information; Device D ii Send information D ii 、C i 、R i 、F i and P i To domain server DS i Domain server DS i Save information D ii 、C i 、R i 、F i and P i In the server; All devices D j wanting to perform key negotiation with devices inside domain server DS ii will perform this step, and the above steps are transmitted over a secure channel; S2, Domain Server DS i Register with the Authentication Server AS: Domain Server DS i Apply to the Authentication Server AS for registration, Domain Server DS i Generate PUF stimulus DC i and response DR i , Domain Server DS i Generate the pseudo-identities PD of all devices D ii ii , Domain Server DS i Send the information DS i , DC i , DR i , D ii and PD ii to the Authentication Server; After receiving DS i , DC i , DR i , D ii and PD ii , store them in the server. The above steps are carried out in a secure channel; S3, D ji Register with the domain server DS j : Device D ji Apply for registration with the domain server DS j : Device D ji Check if it has PUF and WCC. If it only has PUF, generate PUF excitation C j and response R j . If it only has WCC, generate wireless channel fingerprint F j and location P j . If it has both PUF and WCC, generate the corresponding C j 、R j 、F j and P j all information; Device D ji Send information D ji 、C j 、R j 、F j and P j to the domain server DS j : The domain server DS j Save information D ji 、C j 、R j 、F j and P j in the server; All devices D i wanting to perform key negotiation with devices inside the domain server DS ji will perform this step, and the above steps are transmitted over a secure channel; S4, Domain Server DS j Register with the Authentication Server AS: Domain Server DS j Apply to the Authentication Server AS for registration, Domain Server DS j Generate the PUF stimulus DC j and the response DR j , Domain Server DS j Generate the pseudo-identities PD ji for all devices D ji , Domain Server DS j Send the information DS j , DC j , DR j , D ji and PD ji to the Authentication Server; the Authentication Server stores DS j , DC j , DR j , D ji and PD ji in the server after receiving them; the above steps are carried out in a secure channel; S5. The authentication server AS generates and distributes information: The authentication server AS generates its own pseudo-identity PA i , the domain server DS i 's pseudo-identity PDS i and the domain server DS j 's pseudo-identity PDS j ; After that, the authentication server AS stores D ii , PD ii , DS i , PDS i , DC i , DR i , D ji , PD ji , DS j , PDS j , DC j , DR j and PA i in the memory; The authentication server AS sends the information PA i , PDS i , PDS j , PD ji and D ji to the domain server DS i . The domain server DS i receives the information PA i , PDS i , PDS j , PD ji and D ji and then saves the information PA i , PDS i , PDS j , PD ji and D ji in the server and sends the information PA i , PDS i , PDS j and PD ji to the device D ii . The device D ii saves the information PA i , PDS i , PDS j and PD ji in its own memory; The authentication server AS sends the information PA i , PDS i , PDS j , PD ii and D ii to the domain server DS j . The domain server DS j receives the information PA i , PDS i , PDS j , PD ii and D ii and then saves the information PA i , PDS i , PDS j , PD ii and D ii in the server and sends the information PA i , PDS i , PDS j and PD ii to the device D ji . The device D ji saves the information PA i , PDS i , PDS j and PD ii Save in its own memory; At this point, the registration phase of all devices and domain servers to the authentication server has been completed; S6, Device D ii Initiate session: After registration is completed, Device D ii starts key negotiation; Device D ii checks whether it has PUF and WCC. If it only has PUF, it generates a PUF stimulus C i and response R i ; if it only has WCC, it generates a wireless channel fingerprint F i and location P i ; if it has both PUF and WCC, it generates the corresponding C i , R i , F i and P i all information; Device D ii generates a random number N1 and a timestamp T1, and calculates the verification information I1; subsequently, Device D ii sends the message M1 = {PD ii , I1, N1, T1} to its domain server DS via the public channel i ; S7, Domain Server DS i Verify and request an inter-domain session key: Domain Server DS i After receiving message M1 from device D ii generate a message reception timestamp T1 Re , check T1 Re - whether T1 < ΔT1 holds; if the verification fails, Domain Server DS i will terminate the authentication key exchange process of device D ii ; conversely, Domain Server DS i continues with the subsequent steps; then, Domain Server DS i calculates the verification information and compares the result with I1 sent by M1 to verify whether it holds; if the verification fails, Domain Server DS i will terminate the authentication key exchange process; conversely, Domain Server DS i continues with the subsequent steps; Domain Server DS i calculates the identity of device D based on the information in the memory ii and verifies whether this identity is in its own database; If not in the database, the domain server DS i will terminate the authentication key exchange process; otherwise, the domain server DS i continues to execute the subsequent steps; the domain server DS i collects all the requested devices, puts the pseudo-identities of these n devices into the set A = {D i1 , D i2 , …, D in}, the domain server DS i generates a response DR i for the incentive DC i , a random number N3, and a timestamp T3, calculates the verification information I3, and then encrypts the set A = {D i1 , D i2 , …, D in} into Ciph A ; afterwards, the domain server DS i sends the message M3 = {Ciph A , PDS i , I3, N3, T3} to the authentication server AS through the public channel; S8, Device D ji Initiate a session: After registration, Device D ji starts key negotiation; Device D ji checks whether it has PUF and WCC. If it only has PUF, it generates PUF stimulus C j and response R j ; if it only has WCC, it generates wireless channel fingerprint F j and location P j ; if it has both PUF and WCC, it generates corresponding C j , R j , F j and P j all information; Device D ji generates a random number N2 and a timestamp T2, and calculates verification information I2; subsequently, the device sends the message M2 = {PD ji , I2, N2, T2} to its domain server DS through the public channel j ; S9, Domain Server DS j Verify and request the inter - domain session group key: Domain Server DS j After receiving the message M4 from device D ji generate the message reception timestamp T2 Re , check T2 Re - whether T2 < ΔT2 holds; if the verification fails, Domain Server DS j will terminate the authentication key exchange process of device D ji ; conversely, Domain Server DS j continues to execute the subsequent steps; then, Domain Server DS j calculates the verification information and compares the result with I2 sent by M2 to verify whether it holds; if the verification fails, Domain Server DS j will terminate the authentication key exchange process; conversely, Domain Server DS j continues to execute the subsequent steps; Domain Server DS j calculates the identity of the device D according to the information in the memory ji , and verifies whether this identity is in its own database; If not in the database, the domain server DS j will terminate the authentication key exchange process; otherwise, the domain server DS j continues with the subsequent steps; the domain server DS j collects all the requested devices, and puts the pseudo-identities of these n devices into the set B = {D j1 , D j2 , …, D jn}; the domain server DS j generates a response DR j for the incentive DC j , a random number N4, and a timestamp T4, calculates the verification information I4, and then encrypts the set B = {D j1 , D j2 , …, D jn} into Ciph B ; afterwards, the domain server DS j sends the message M4 = {Ciph B , PDS j , I4, N4, T4} to the authentication server AS through the public channel; S10. Generation of inter-domain session group key for the authentication server AS: After the authentication server AS receives messages M3 and M4 from devices D ii and D ji , it generates message reception timestamps T3 Re and T4 Re respectively, and checks whether T3 Re - T3 < ΔT3 and T4 Re - T4 < ΔT4 hold; if the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps; then the authentication server AS calculates the verification information and and compares the results with I3 and I4 sent by M3 and M4 to verify whether and hold; if the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS continues to execute the subsequent steps; the authentication server AS calculates the sets A = {D i1 , D i2 , …, D in} and set B = {D j1 , D j2 , …, D jn}, and generates the inter-domain session group key SK i1 for A = {D i2 , D in , …, D j1} and B = {D j2 , D jn} simultaneously generates random numbers N5 and timestamp T5, and calculates SK AB , SK A , SK B and verification information I5, I6; then the authentication server AS sends the message M5 = {SK A , I5, N5, T5} to the domain server DS i through the public channel, and sends the message M6 = {SK B , I6, N5, T5} to the domain server DS j through the public channel; S11. Domain Server DS i Receive the inter - domain session group key: Domain Server DS i After receiving the message M5 from the authentication server AS, generate the message reception timestamp T5 Re , check T5 Re - Whether T5 < ΔT5 holds; if the verification fails, Domain Server DS i will terminate the authentication key exchange process of Device D ii ; conversely, Domain Server DS i continues to execute the subsequent steps; then, Domain Server DS i calculates the verification information and compares the result with I5 sent by M5 to verify whether it holds; if the verification fails, Domain Server DS i will terminate the authentication key exchange process; conversely, Domain Server DS i continues to execute the subsequent steps; Domain Server DS i calculates the inter - domain session group key SK according to the information in the memory AB , then generates a random number N6 and a timestamp T6, and calculates SK' A and the verification information I7; afterwards, Domain Server DS i sends the message M7 = {SK' A , I7, N6, T6} to Device D through the public channel ii ; S12. Device D ii Receive the inter-domain session group key: Device D ii After receiving the message M7 from the domain server DS i generate the message reception timestamp T6 Re , and check T6 Re - whether -T6 < ΔT6 holds; if the verification fails, Device D ii will terminate the authentication key exchange process; otherwise, Device D ii continues to execute the subsequent steps; then, Device D ii calculates the verification information and compares the result with I7 sent by M7 to verify whether it holds; if the verification fails, Device D ii will terminate the authentication key exchange process; otherwise, Device D ii continues to execute the subsequent steps; Device D ii calculates the inter-domain session group key SK according to the information in the memory AB , and according to the inter-domain session group key SK AB calculates the pseudo-identity PD of Device D in the domain server DS i and the session key SK between the pseudo-identity PD of Device D in the domain server DS ii and the pseudo-identity PD of Device D in the domain server DS ii and the domain server DS j ; at this point, Device D in the domain server DS ji has obtained the session key SK with Device D in the domain server DS ji ; i ; ii ; j ; ji ; S13. Domain Server DS j Receive the inter - domain session group key: Domain Server DS j After receiving the message M6 from the authentication server AS, generate the message reception timestamp T6 Re , and check T6 Re - Whether - T6 < ΔT6 holds; if the verification fails, the domain server DS j will terminate the authentication key exchange process of the device D ji ; conversely, the domain server DS j continues to execute the subsequent steps; then, the domain server DS j calculates the verification information and compares the result with I6 sent by M6 to verify whether it holds; if the verification fails, the domain server DS j will terminate the authentication key exchange process; conversely, the domain server DS j continues to execute the subsequent steps; the domain server DS j calculates the inter - domain session group key SK according to the information in the memory AB , then generates a random number N7 and a timestamp T7, and calculates SK' B and the verification information I8; after that, the domain server DS j sends the message M8 = {SK' B , I8, N7, T7} to the device D through the public channel ji ; S14, Equipment D ji Receive the inter-domain session group key: Device D ji Received from domain server DS j After the message M8, the message receiving timestamp T7 is generated Re , check T7 Re -T7<ΔT7 is true; if the verification fails, device D ji The authentication key exchange process will be terminated; otherwise, device D ji Continue to the next steps; then, device D ji Calculation verification information And compare the result with I8 sent by M8 to verify Is it true? If the verification fails, device D ji The authentication key exchange process will be terminated; otherwise, device D ji Continue to the next step; Device D ji Calculate the inter-domain session group key SK based on the information in the memory AB , based on the inter-domain session group key SK AB Calculate the domain server DS j Medium Equipment D ji Pseudo-identity PD ji and domain server DS i Medium Equipment D ii Pseudo-identity PD ii The session key SK between them; at this point, the domain server DS j Medium Equipment D ji Has obtained the domain server DS i Medium Equipment D ii The session key SK.
2. The cross-domain batch identity authentication method for Internet of Things devices based on the PWCBAP protocol according to claim 1, wherein, In the registration phase and the identity authentication and key exchange phase, the device authentication conditions in different domains vary due to specific scenarios and are divided into four cases: (1) Devices in the domain only support PUF; (2) Devices in the domain only support WCC; (3) Devices in the domain support both PUF and WCC; (4) Some devices in the domain support PUF and some support WCC; The domain server has bound the authentication factors (PUF, WCC) supported by each device to its device identification code during the registration phase and saved them in its own memory; In the identity authentication and key exchange phase, the domain server will determine which authentication factor the device uses according to the device identification code.
3. The cross-domain batch identity authentication method for Internet of Things devices based on the PWCBAP protocol according to claim 1, wherein In the registration phase, the memory of the domain server contains a one-to-one mapping of all device identity identifications and their pseudo-identity identifications in the peer domain server. The devices in the domain server only know the pseudo-identities of the peer devices and do not know the real identities of the peer devices. In the initiation of the identity authentication and key exchange phase, the device sends the pseudo-identity of the peer device to the domain server, and the domain server finds the real identity of the peer device through the mapping and informs the authentication server of the real identity so that the authentication server can generate an inter-domain session group key.
4. The cross-domain batch identity authentication method for Internet of Things devices based on the PWCBAP protocol according to claim 1, characterized in that, In the identity authentication and key exchange phase, the domain server DS i will collect the devices D j within its own domain that want to communicate with the devices D ji in the domain server DS ii , and send their set A to the authentication server AS; similarly, the domain server DS j will collect the devices D i within its own domain that want to communicate with the devices D ii in the domain server DS ji , and send their set B to the authentication server AS; after receiving the messages, the authentication server AS will generate an inter-domain session group key SK AB that associates sets A and B.
5. The cross-domain batch identity authentication method for Internet of Things devices based on the PWCBAP protocol according to claim 1, wherein, In the identity authentication and key exchange phase, the in-domain device will receive the inter-domain session group key SK AB and perform an exclusive OR operation with h(PD ii ||PD ji ||SK AB ) to generate the device PD i in the domain server DS ii and the domain server DS j in the device PD ji The only session key SK between them, and only the device PD ii and the device PD ji will know.
Citation Information
Patent Citations
Lightweight security authentication method and device based on device fingerprint and PUF
CN113518083A
Internet of vehicles cross-domain authentication key negotiation method based on smart card
CN116015623A
Identity authentication method based on BACnet / IP protocol
CN116582277A
Identity authentication method based on PWKTAP protocol
CN119070996A