A method for cross-domain bulk authentication of IoT devices based on the PWCBAP protocol

By using the PWCBAP protocol and leveraging PUF and wireless channel characteristics to generate pseudo-identities and session keys, the problems of complex key management and cross-domain authentication privacy leakage in large-scale deployment of IoT devices are solved. This enables efficient and secure cross-domain batch identity authentication and key negotiation, improving the security and reliability of IoT systems.

CN120301600BActive Publication Date: 2025-10-28LANZHOU UNIVERSITY OF TECHNOLOGY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510437651.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-10-28
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

Existing IoT device authentication solutions suffer from complex key management, vulnerability of static credentials to attacks, privacy risks during cross-domain authentication, and a lack of effective defense mechanisms against proactive attacks when deployed on a large scale, thus failing to meet the needs for rapid access and efficient mutual trust.

Method used

The method adopts the PWCBAP protocol and generates pseudo-identities and session keys by registering devices and domain servers, registering authentication servers, and negotiating keys. It uses PUF and wireless channel characteristics to achieve cross-domain batch identity authentication. It uses secure channel transmission and public channel encryption, combined with timestamps and random numbers to verify information.

Benefits of technology

It achieves strong mutual authentication, confidentiality, anonymity, attack resistance, and forward and backward confidentiality of session keys for IoT devices, thereby improving the security and reliability of IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301600B_ABST
    Figure CN120301600B_ABST
Patent Text Reader

Abstract

A cross-domain batch authentication method for IoT devices based on the PWCBAP protocol includes a registration phase and an authentication and key exchange phase. This method uses the devices' wireless channel characteristics and location information (FPPs) and PUF incentives and responses (CRPs) to complete batch authentication of cross-domain devices. Adding timestamps prevents replay attacks and DoS attacks. The authenticity of the peer's identity is verified and a session key is generated through an XOR operation on the hash values ​​of multiple information sets. The update mechanism for CRPs and FPPs enhances the protocol's security. This invention effectively resists spoofing attacks, tampering attacks, man-in-the-middle attacks, key leakage, replay attacks, and DoS attacks. It provides two-way authentication between communicating parties while maintaining low computational overhead, ensuring the confidentiality, integrity, and authenticability of the session's key negotiation process on the public channel, exhibiting secure and efficient characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of IoT communication protocol device identity authentication and data confidentiality security technology, specifically involving cross-domain batch identity authentication technology for IoT devices based on the PWCBAP (Physically Unclonable Function and Wireless Channel Characteristics) protocol. Background Technology

[0002] With the rapid development of the Internet of Things (IoT), the demand for device interconnection across vendors and management domains has surged, in scenarios such as smart homes, Industrial IoT (IIoT), and Vehicle-to-Everything (V2X). However, traditional identity authentication schemes (such as digital certificates and pre-shared keys) face problems such as complex key management and vulnerability of static credentials to attacks when deployed on a large scale. Furthermore, devices in different security domains struggle to achieve efficient mutual trust, which severely restricts the large-scale application of IoT.

[0003] To ensure the availability and confidentiality of IoT services, servers need to authenticate communication participants such as devices and gateways, and securely and effectively establish session keys on public channels. Many scholars at home and abroad have proposed schemes for IoT identity authentication protocols, such as hardware-based PUF (Physically Unclonable Function) schemes and authentication schemes based on wireless channel characteristics. In recent years, although some studies have attempted to combine PUF with channel fingerprinting, there are still three key drawbacks: (1) Batch authentication requires verification of each device, with a time complexity of O(n), which cannot meet the needs of rapid access for a large number of devices; (2) Cross-domain authentication requires sharing the PUF's CRP (Challenge-Response Pair) or channel characteristic database, which poses a serious risk of privacy leakage; (3) There is a lack of effective defense mechanisms against active attacks (such as channel characteristic forgery and man-in-the-middle attacks). These technical bottlenecks severely limit the practical application of existing schemes in open IoT environments. The cross-domain batch identity authentication method for IoT devices based on the fusion of PUF and wireless channel characteristics proposed in this invention can solve the three problems mentioned above. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention provides a cross-domain batch authentication method for IoT devices based on the PWCBAP protocol to achieve the aforementioned technical objectives.

[0005] To achieve the above objectives, the present invention adopts the following technical solution:

[0006] The authentication method based on the PWCBAP protocol includes the following steps:

[0007] S1, Equipment D ii To the domain server DS i Registration: Device D ii To the domain server DS i Apply for registration, device Dii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information. Device D ii Information D ii C i R i F i and P i Send to domain server DS i Domain Server DS i Information D ii C i R i F i and P i Stored on the server. All requests to cross-domain with the domain server DS... j Device D, which performs key negotiation within the device ii This step will be performed in all cases, and it is transmitted over a secure channel.

[0008] S2, Domain Server DS i Register with Authentication Server (AS): Domain Server (DS) i Request registration from the authentication server AS, domain server DS i Generate PUF excitation DC i and response DR i Domain Server DS i Generate all device D ii PD with a fake identity ii Domain Server DS i Information DS i DC i DR i D ii and PD ii Send to the authentication server. The authentication server receives the DS. i DC i DR i D ii and PD ii It is then stored on the server; the above steps are performed in a secure channel.

[0009] S3, D ji To the domain server DS j Registration: Device D jiTo the domain server DS j Apply for registration, device D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information. Device D ji Information D ji C j R j F j and P j Send to domain server DS j Domain Server DS j Information D ji C j R j F j and P j Stored on the server. All requests to cross-domain with the domain server DS... i Device D, which performs key negotiation within the device ji This step will be performed in all cases, and it is transmitted over a secure channel.

[0010] S4, Domain Server DS j Register with Authentication Server (AS): Domain Server (DS) j Request registration from the authentication server AS, domain server DS j Generate PUF excitation DC j and response DR j Domain Server DS j Generate all device D ji PD with a fake identity ji Domain Server DS j Information DS j DC j DR j D ji and PD ji Send to the authentication server. The authentication server receives the DS. j DC j DR j D ji and PD ji It is then stored on the server; the above steps are performed in a secure channel.

[0011] S5. Authentication Server (AS) generates and distributes information: The Authentication Server (AS) generates its own pseudo-identity (PA). i Domain Server DS i Pseudo-identity PDS i and Domain Server DS j Pseudo-identity PDS j Afterwards, the authentication server AS will... ii PD ii DS i PDS i DC i DR i D ji PD ji DS j PDS j DC j DR j and PA i Stored in memory. The authentication server AS will then store the information PA. i PDS i PDS j PD ji and D ji Send to domain server DS i Domain Server DS i Received message PA i PDS i PDS j PD ji and D ji Then, save the information PA. i PDS i PDS j PD ji and D ji The information PA is stored in the server. i PDS i PDS j and PD ji Send to device D ii Device D ii Information PA i PDS i PDS j and PD ji It is stored in its own memory. The authentication server AS will store the information PA. i PDS i PDS j PD ii and D ii Send to domain server DS j Domain Server DS j Received message PA i PDSi PDS j PD ii and D ii Then, save the information PA. i PDS i PDS j PD ii and D ii The information PA is stored in the server. i PDS i PDS j and PD ii Send to device D ji Device D ji Information PA i PDS i PDS j and PD ii It is stored in its own memory. At this point, the registration phase between all devices and domain servers and the authentication server is complete.

[0012] S6, Equipment D ii Initiate a session: After registration is complete, device D ii Initiate key negotiation. Device D ii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information. Device D ii Generate a random number N1 and a timestamp T1, and calculate the verification information I1. Then, device D... ii Send message M1 to its own domain server DS via a public channel. i ;

[0013] S7, Domain Server DS i Verify and request the inter-domain session key: Domain Server DS i Received from device D ii After message M1, generate message reception timestamp T1. Re Check T1 Re Is -T1 < ΔT1 true? If the verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the following steps. Then, the domain server DS...i Calculate verification information The results are then compared with the I1 sent by M1 to verify. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps. Domain Server DS i Calculate the device's identity D based on the information in memory. ii Verify if the identity exists in its own database. If not, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps. Domain Server DS i Collect all requesting devices and put the pseudo-identities of these n devices into set A = {D} i1 D i2 ,…,D in Domain Server DS i Generate excitation DC i DR response i Given a random number N3 and a timestamp T3, calculate the verification information I3, and then set A = {D} i1 D i2 ,…,D in Encrypt to Ciph A After that, the domain server DS i Send message M3 to the authentication server AS via a public channel;

[0014] S8, Equipment D ji Initiate a session: After registration is complete, device D ji Initiate key negotiation. Device D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information. Device D ji Generate a random number N2 and a timestamp T2, and calculate the verification information I2. The device then sends message M2 to its domain server DS via a public channel. j ;

[0015] S9, Domain Server DS j Verify and request the inter-domain session group key: Domain Server DSj Received from device D ji After message M4, generate message reception timestamp. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the following steps. Then, the domain server DS... j Calculate verification information The results are then compared with the I2 sent by M2 to verify the results. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps. Domain Server DS j Calculate the device's identity D based on the information in memory. ji Verify if the identity exists in its own database. If not, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps. Domain Server DS j Collect all requesting devices and put the pseudo-identities of these n devices into set B = {D} j1 D j2 ,…,D jn Domain Server DS j Generate excitation DC j DR response j Given a random number N4 and a timestamp T4, calculate the verification information I4, and then set B = {D} j1 D j2 ,…,D jn Encrypt to Ciph B After that, the domain server DS j Send message M4 to the authentication server AS via a public channel;

[0016] S10. Authentication Server AS Inter-Domain Session Group Key Generation: The authentication server AS receives the key from device D. ii and D ji After messages M3 and M4, message reception timestamps are generated respectively. and examine and The authentication server (AS) checks whether the verification is successful. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps. The AS then calculates the verification information. and The results were then compared with I3 and I4 sent by M3 and M4 to verify them. and Whether it is true or false. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS will continue to execute subsequent steps. The authentication server AS calculates the set A = {D}. i1 D i2 ,…,D in} and set B = {D j1 D j2 ,…,D jn}, for A = {D i1 D i2 ,…,D in} and B = {D j1 D j2 ,…,D jn Generate inter-domain session group key SK AB Simultaneously generate a random number N5 and a timestamp T5, and calculate SK. A SK B And verification information I5 and I6. Then, the authentication server AS sends message M5 to the domain server DS via a public channel. i Message M6 is sent to the domain server DS via a public channel. j ;

[0017] S11, Domain Server DS i Receive inter-domain session group key: Domain Server DS i After receiving message M5 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the following steps. Then, the domain server DS... i Calculate verification information The results were then compared with the I5 sent by M5 to verify the results. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps. Domain Server DS i Calculate the inter-domain session group key SK based on the information in memory. AB Then generate a random number N6 and a timestamp T6, and calculate SK. ' A And verification information I7. Then the domain server DS i Send message M7 to device D via a public channel.ii ;

[0018] S12, Equipment D ii Receive inter-domain session group key: Device D ii Received from domain server DS i After message M7, generate message reception timestamp. examine Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps. Then, device D... ii Calculate verification information The results were then compared with the I7 sent by M7 to verify the results. Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the following steps. Device D ii Calculate the inter-domain session group key SK based on the information in memory. AB According to the inter-domain session group key SK AB Calculate the domain server DS i equipment D ii PD with a fake identity ii and Domain Server DS j equipment D ji PD with a fake identity ji The session key SK between them. At this point, the domain server DS... i equipment D ii Access to the domain server DS has been obtained j equipment D ji The session key SK.

[0019] S13, Domain Server DS j Receive inter-domain session group key: Domain Server DS j After receiving message M6 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the following steps. Then, the domain server DS... j Calculate verification information The results were then compared with the I6 sent by M6 to verify them. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... jContinue with the following steps. Domain Server DS j Calculate the inter-domain session group key SK based on the information in memory. AB Then generate a random number N7 and a timestamp T7, and calculate SK'. B And verification information I8. Then the domain server DS j Send message M8 to device D via a public channel. ji ;

[0020] S14, Equipment D ji Receive inter-domain session group key: Device D ji Received from domain server DS j After message M8, generate message reception timestamp. examine Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps. Then, device D... ji Calculate verification information The results were then compared with the I8 sent by M8 to verify them. Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the following steps. Device D ji Calculate the inter-domain session group key SK based on the information in memory. AB According to the inter-domain session group key SK AB Calculate the domain server DS j equipment D ji PD with a fake identity ji and Domain Server DS i equipment D ii PD with a fake identity ii The session key SK between them. At this point, the domain server DS... j equipment D ji Access to the domain server DS has been obtained i equipment D ii The session key SK.

[0021] Furthermore, the specific sub-steps of step S1 are as follows:

[0022] S1-1, Equipment D ii Check if you have PUF and WCC. If you only have PUF, device D... ii Randomly generate stimulus C i Using its PUF chip to generate response R i If only WCC is available, then generate the wireless channel fingerprint F. iUsing wireless fingerprint positioning to calculate the location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information. Device identity D is transmitted via a secure channel. ii Incentive-response pair C i ,R i Fingerprint-location pair F i ,P i Send to domain server DS i ;

[0023] S1-2, Domain Server DS i After receiving the above information, store it in the server;

[0024] S1-3, All requests to cross-domain with domain server DS j Device D, which performs key negotiation within the device ii All will proceed to step S1-2.

[0025] Furthermore, the specific sub-steps of step S2 are as follows:

[0026] S2-1, Domain Server DS i Randomly generate PUF stimulus DC i Using its PUF chip to generate response DR i ;

[0027] S2-2, Domain Server DS i Based on the information in memory D ii R i and DS i Generating device D ii PD with a fake identity ii .

[0028] S2-3, Domain Server DS i The domain server's identity DS is transmitted via a secure channel. i PUF stimulus response DC of domain server i and DR i Device Identification D ii and fake identity PD ii Send to the authentication server AS.

[0029] Furthermore, the specific sub-steps of step S3 are as follows:

[0030] S3-1, Equipment D ji Check if you have PUF and WCC. If you only have PUF, device D... ji Randomly generate stimulus Cj Using its PUF chip to generate response R j If only WCC is available, then generate the wireless channel fingerprint F. j Using wireless fingerprint positioning to calculate the location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information. Device identity D is transmitted via a secure channel. ji Incentive-response pair C j ,R j Fingerprint-location pair F j ,P j Send to domain server DS j ;

[0031] S3-2, Domain Server DS j Upon receiving the above information, store it in memory;

[0032] S3-3, All requests to cross-domain and domain server DS i Device D, which performs key negotiation within the device ji All will proceed to step S3-2.

[0033] Furthermore, the specific sub-steps of step S4 are as follows:

[0034] S4-1, Domain Server DS j Randomly generate PUF stimulus DC j Using its PUF chip to generate response DR j ;

[0035] S4-2, Domain Server DS j Based on the information in memory D ji R j and DS j Generating device D ji PD with a fake identity ji .

[0036] S4-3, Domain Server DS j The domain server's identity DS is transmitted via a secure channel. j PUF stimulus response DC of domain server j and DR j Device Identification D ji and fake identity PD ji Send to the authentication server AS.

[0037] Furthermore, the specific sub-steps of step S5 are as follows:

[0038] S5-1, Authentication Server AS receives data from Domain Server DS i and DS j After receiving the message, generate your own pseudo-identity PA. i Domain Server DS i Pseudo-identity PDS i and Domain Server DS j Pseudo-identity PDS j Afterwards, the authentication server AS will... ii PD ii DS i PDS i DC i DR i D ji PD ji DS j PDS j DC j DR j and PA i Stored in memory;

[0039] S5-2, the authentication server AS will send information PA i PDS i PDS j PD ji and D ji Send to domain server DS i Domain Server DS i Received message PA i PDS i PDS j PD ji and D ji Then, save the information PA. i PDS i PDS j PD ji and D ji The information PA is stored in the server. i PDS i PDS j and PD ji Send to device D ii ;

[0040] S5-3, Equipment D ii Information PA i PDS i PDS j and PD ji Stored in its own memory;

[0041] S5-4, the authentication server AS will send information PA i PDSi PDS j PD ii and D ii Send to domain server DS j Domain Server DS j Received message PA i PDS i PDS j PD ii and D ii Then, save the information PA. i PDS i PDS j PD ii and D ii The information PA is stored in the server. i PDS i PDS j and PD ii Send to device D ji ;

[0042] S5-5, Equipment D ji Information PA i PDS i PDS j and PD ii Stored in its own memory;

[0043] Furthermore, the specific sub-steps of step S6 are as follows:

[0044] S6-1, Equipment D ii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information;

[0045] S6-2, Equipment D ii Generate a random number N1 and a timestamp T1, and calculate the verification information I1;

[0046] S6-3, Equipment D ii Send message M1 to its own domain server DS via a public channel. i .

[0047] Furthermore, the specific sub-steps of step S7 are as follows:

[0048] S7-1, Domain Server DS i Received from device D ii After message M1, generate message reception timestamp T1. Re Check T1 Re Is -T1 < ΔT1 true? If the verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the next steps;

[0049] S7-2, Domain Server DS i Calculate verification information The results are then compared with the I1 sent by M1 to verify. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps.

[0050] S7-3, Domain Server DS i Calculate the device's identity D based on the information in memory. ii Verify if the identity exists in its own database. If not, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the next steps;

[0051] S7-4, Domain Server DS i Collect all requesting devices and put the pseudo-identities of these n devices into set A = {D} i1 D i2 ,…,D in};

[0052] S7-5, Domain Server DS i Generate excitation DC i DR response i Given a random number N3 and a timestamp T3, calculate the verification information I3, and then set A = {D} i1 D i2 ,…,D in Encrypt to Ciph A ;

[0053] S7-6, Domain Server DS i Send message M3 to the authentication server AS via a public channel.

[0054] Furthermore, the specific sub-steps of step S8 are as follows:

[0055] S8-1, Equipment Dji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information;

[0056] S8-2, Equipment D ji Generate a random number N2 and a timestamp T2, and calculate the verification information I2;

[0057] S8-3, Equipment D ji Send message M2 to its own domain server DS via a public channel. j .

[0058] Furthermore, the specific sub-steps of step S9 are as follows:

[0059] S9-1, Domain Server DS j Received from device D ji After message M4, generate message reception timestamp. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the next steps;

[0060] S9-2, Domain Server DS j Calculate verification information The results are then compared with the I2 sent by M2 to verify the results. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the next steps;

[0061] S9-3, Domain Server DS j Calculate the device's identity D based on the information in memory. ji Verify if the identity exists in its own database. If not, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the next steps;

[0062] S9-4, Domain Server DS jCollect all requesting devices and put the pseudo-identities of these n devices into set B = {D} j1 D j2 ,…,D jn};

[0063] S9-5, Domain Server DS j Generate excitation DC j DR response j Given a random number N4 and a timestamp T4, calculate the verification information I4, and then set B = {D} j1 D j2 ,…,D jn Encrypt to Ciph B ;

[0064] S9-6, Domain Server DS j Send message M4 to the authentication server AS via a public channel.

[0065] Furthermore, the specific sub-steps of step S10 are as follows:

[0066] S10-1, The authentication server AS receives data from device D. ii and D ji After messages M3 and M4, message reception timestamps are generated respectively. and examine and The authentication server (AS) checks whether the authentication is successful. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps.

[0067] S10-2, Authentication Server AS calculates verification information and The results were then compared with I3 and I4 sent by M3 and M4 to verify them. and The authentication server (AS) checks whether the authentication is successful. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps.

[0068] S10-3, The authentication server AS calculates set A and set B, where A = {D} i1 D i2 ,…,D in} and B = {D j1 D j2 ,…,D jn Generate inter-domain session group key SK AB ;

[0069] S10-4. The authentication server AS generates a random number N5 and a timestamp T5, and calculates SK. ASK B And verification information I5, I6;

[0070] S10-5, Authentication Server AS sends message M5 to Domain Server DS via a public channel. i Message M6 is sent to the domain server DS via a public channel. j .

[0071] Furthermore, the specific sub-steps of step S11 are as follows:

[0072] S11-1, Domain Server DS i After receiving message M5 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the next steps;

[0073] S11-2, Domain Server DS i Calculate verification information The results were then compared with the I5 sent by M5 to verify the results. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the next steps.

[0074] S11-3, Domain Server DS i Calculate the inter-domain session group key SK based on the information in memory. AB ;

[0075] S11-4, Domain Server DS i Generate a random number N6 and a timestamp T6, and calculate SK'. A And verification information I7;

[0076] S11-5, Domain Server DS i Send message M7 to device D via a public channel. ii

[0077] Furthermore, the specific sub-steps of step S12 are as follows:

[0078] S12-1, Equipment D ii Received from domain server DS i After message M7, generate message reception timestamp. examine Is it valid? If verification fails, device D... iiThe authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps;

[0079] S12-2, Equipment D ii Calculate verification information The results were then compared with the I7 sent by M7 to verify the results. Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps;

[0080] S12-3, Equipment D ii Calculate the inter-domain session group key SK based on the information in memory. AB ;

[0081] S12-4, Based on the inter-domain session group key SK AB Calculate the domain server DS i equipment D ii PD with a fake identity ii and Domain Server DS j equipment D ji PD with a fake identity ji The session key SK between them. At this point, the domain server DS... i equipment D ii Access to the domain server DS has been obtained j equipment D ji Session key SK;

[0082] Furthermore, the specific sub-steps of step S13 are as follows:

[0083] S13-1, Domain Server DS j After receiving message M6 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the next steps;

[0084] S13-2, Domain Server DS j Calculate verification information The results were then compared with the I6 sent by M6 to verify them. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the next steps;

[0085] S13-3, Domain Server DS j Calculate the inter-domain session group key SK based on the information in memory. AB ;

[0086] S13-4, Domain Server DS j Generate a random number N7 and a timestamp T7, and calculate SK'. B And verification information I8;

[0087] S13-5, Domain Server DS j Send message M8 to device D via a public channel. ji .

[0088] Furthermore, the specific sub-steps of step S14 are as follows:

[0089] S14-1, Equipment D ji Received from domain server DS j After message M8, generate message reception timestamp. examine Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps;

[0090] S14-2, Equipment D ji Calculate verification information The results were then compared with the I8 sent by M8 to verify them. Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps;

[0091] S14-3, Equipment D ji Calculate the inter-domain session group key SK based on the information in memory. AB ;

[0092] S14-4, Equipment D ji Based on the inter-domain session group key SK AB Calculate the domain server DS j equipment D ji PD with a fake identity ji and Domain Server DS i equipment D ii PD with a fake identity ii The session key SK between them.

[0093] Compared with the prior art, the present invention has the following beneficial effects:

[0094] 1. Strong Mutual Authentication: In this method, mutual authentication between IoT devices, domain servers, and authentication servers relies on the validity of CRPs and FPPs. The domain server stores pre-generated CRPs and FPPs from the devices, while the authentication server stores pre-generated CRPs from the domain server. Attacker A, unable to access the PUF chips of the devices and domain servers, cannot obtain the response value in the "challenge-response pair." The gateway possesses a pre-shared key with the server to ensure the security of communication between the gateway and the devices. Simultaneously, the domain server, acting as an intermediary for communication between the devices and the authentication server, verifies the authenticity of both parties using CRPs generated by the IoT devices. Similarly, the authentication server, acting as an intermediary for communication between domain servers, verifies the authenticity of both parties using CRPs generated by the domain servers.

[0095] 2. Confidentiality: The parameters used in this method are updated each time it is run. Shannon's theorem proves that simple XOR encryption is secure if at least one term in the XOR operation is random. For adversary A, the parameters of the intercepted message change randomly each round. Therefore, this protocol effectively guarantees the confidentiality of data transmitted via simple XOR encryption and reduces transmission overhead.

[0096] 3. Device Anonymity and Unlinkability: This method does not use the real identities of devices. During the registration phase, each device and domain server is aware of the pseudo-identities of other devices and servers. During the authentication phase, all devices and servers will use pseudo-identities to verify the authenticity of the peer's identity. Under normal circumstances, all pseudo-identities and CRPs are changed in each round. Adversary A cannot connect to devices or servers by intercepting messages between devices and domain servers, or between domain servers and authentication servers. Therefore, our protocol provides strong anonymity and unlinkability.

[0097] 4. Robust forward and backward confidentiality: In this method, if an attacker obtains the current session key, they cannot obtain the previous or next session key using the current session key. Furthermore, they cannot obtain the gateway-wireless sensor session key using the server-gateway session key. In this protocol, the session key is generated by combining random numbers, timestamps, CRPs, FPPs, and other information; there is no correlation between session keys, ensuring forward and backward security of the session keys.

[0098] 5. Resistance to Cloning and Physical Attacks: In this method, adversary A cannot obtain data in memory or tamper with related data through side-channel attacks. Because modifications to the device will affect the PUF output, adversary A will not be able to obtain complete PUF stimulus-response pairs. Furthermore, physically unclonable functions are non-replicable, therefore this protocol is resistant to cloning and physical attacks.

[0099] 6. Resistance to replay attacks: This method introduces a timestamp T.n (n = 1, 2, 3…), at the initial stage of each session, both the device and the server check the validity of the timestamp, thus preventing adversary A from obtaining target information or interfering with the secure operation of the protocol through replay attacks. Furthermore, the CAPTCHA in this protocol contains hash and XOR operations on multiple key pieces of information, including fake identities, CRPs, and FPPs, making it impossible to pass verification even with replay. Therefore, this protocol is resistant to replay attacks.

[0100] 7. Resistance to Man-in-the-Middle Attacks: This method involves mutual authentication between the device and the server. The verification code in the protocol contains hashes and XOR operations of multiple key pieces of information, making it impossible for an adversary A to obtain authentication from the device or server using only a few pieces of information. The timestamp also ensures that adversary A cannot tamper with the message through a man-in-the-middle attack. Therefore, this protocol is resistant to man-in-the-middle attacks.

[0101] 8. Resistance to Impersonation Attacks: Each IoT device in this method is equipped with a unique PUF chip, which attackers or malicious devices cannot imitate. Simultaneously, the device generates its location information based on wireless channel characteristics and binds these characteristics to its location. Even if adversary A simulates the device's channel characteristics, it cannot constantly determine the real-time location of certain mobile devices. Finally, adversary A cannot simulate the server because it lacks access to the IoT devices' CRPs and FPPs.

[0102] 9. Resistance to Key Leakage: This method assumes that adversary A obtains the wireless channel characteristics between the device and the domain server, or CRPs information between the device and the domain server, or between the domain server and the authentication server, and wishes to impersonate either the device or the server to verify the other. However, in this protocol, interactive message transmission uses XOR-encrypted data or verification values ​​encrypted with hash values. Even after obtaining the key, although the ciphertext can be decrypted, the obtained message is insufficient to calculate the verification value, nor can the device's verification method be known. Therefore, the protocol is resistant to key leakage attacks.

[0103] 10. Resistance to DoS attacks: In this method, both communicating parties check the message timestamp T at the beginning of each session. n The protocol uses the validity of (n = 1, 2, 3...) and a verification code. If verification fails, the negotiation ends immediately. Therefore, this protocol is resistant to DoS attacks. Attached Figure Description

[0104] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0105] Figure 1 This is a flowchart of the registration phase for PWCBAP protocol devices and domain servers.

[0106] Figure 2 This is a flowchart of the PWCBAP protocol's authentication and key exchange phases.

[0107] Implementation

[0108] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0109] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0110] like Figure 1 and 2 This invention provides an authentication method based on the PWCBAP protocol;

[0111] Authentication methods based on the PWCBAP protocol include:

[0112] S1, Equipment D ii To the domain server DS i Registration: Device D ii To the domain server DS i Apply for registration, device D ii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information. Device D ii Information D ii C i R i F i and P i Send to domain server DS i Domain Server DS i Information D ii C i R i F iand P i Stored on the server. All requests to cross-domain with the domain server DS... j Device D, which performs key negotiation within the device ii This step will be performed in all cases, and it is transmitted over a secure channel.

[0113] Specifically, in this embodiment of the invention, step S1 includes the following steps:

[0114] S1-1, Equipment D ii Check if you have PUF and WCC. If you only have PUF, device D... ii Randomly generate stimulus C i Using its PUF chip to generate response R i =PUF(C i If only WCC is available, then generate the wireless channel fingerprint F. i Using wireless fingerprint positioning to calculate the location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information. Device identity D is transmitted via a secure channel. ii Incentive-response pair C i ,R i Fingerprint-location pair F i ,P i Send to domain server DS i ;

[0115] S1-2, Domain Server DS i After receiving the above information, store it in the server;

[0116] S1-3, All requests to cross-domain with domain server DS j Device D, which performs key negotiation within the device ii All will proceed to step S1-2.

[0117] S2, Domain Server DS i Register with Authentication Server (AS): Domain Server (DS) i Request registration from the authentication server AS, domain server DS i Generate PUF excitation DC i and response DR i Domain Server DS i Generate all device D ii PD with a fake identity ii Domain Server DS i Information DS i DC i DR iD ii and PD ii Send to the authentication server. The authentication server AS receives the DS. i DC i DR i D ii and PD ii It is then stored in memory, and the above steps are performed in a secure channel.

[0118] Specifically, in this embodiment of the invention, step S2 includes the following steps:

[0119] S2-1, Domain Server DS i Randomly generate PUF stimulus DC i Using its PUF chip to generate response DR i =PUF(DC) i );

[0120] S2-2, Domain Server DS i Based on the information in memory D ii R i and DS i Generating device D ii false identity

[0121] S2-3, Domain Server DS i The domain server's identity DS is transmitted via a secure channel. i PUF stimulus response DC of domain server i and DR i Device Identification D ii and fake identity PD ii Send to the authentication server AS.

[0122] S3, D ji To the domain server DS j Registration: Device D ji To the domain server DS j Apply for registration, device D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information. Device D ji Information D ji C jR j F j and P j Send to domain server DS j Domain Server DS j Information D ji C j R j F j and P j Stored on the server. All requests to cross-domain with the domain server DS... i Device D, which performs key negotiation within the device ji This step will be performed in all cases, and it is transmitted over a secure channel.

[0123] Specifically, in this embodiment of the invention, step S3 includes the following steps:

[0124] S3-1, Equipment D ji Check if you have PUF and WCC. If you only have PUF, device D... ji Randomly generate stimulus C j Using its PUF chip to generate response R j =PUF(C j If only WCC is available, then generate the wireless channel fingerprint F. j Using wireless fingerprint positioning to calculate the location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information. Device identity D is transmitted via a secure channel. ji Incentive-response pair C j ,R j Fingerprint-location pair F j ,P j Send to domain server DS j ;

[0125] S3-2, Domain Server DS j Upon receiving the above information, store it in memory;

[0126] S3-3, All requests to cross-domain and domain server DS i Device D, which performs key negotiation within the device ji All will proceed to step S3-2.

[0127] S4, Domain Server DS j Register with Authentication Server (AS): Domain Server (DS) j Request registration from the authentication server AS, domain server DS j Generate PUF excitation DC jand response DR j Domain Server DS j Generate all device D ji PD with a fake identity ji Domain Server DS j Information DS j DC j DR j D ji and PD ji Send to the authentication server. The authentication server receives the DS. j DC j DR j D ji and PD ji It is then stored on a server, and the above steps are performed in a secure channel.

[0128] Specifically, in this embodiment of the invention, step S4 includes the following steps:

[0129] S4-1, Domain Server DS j Randomly generate PUF stimulus DC j Using its PUF chip to generate response DR j =PUF(DC) j );

[0130] S4-2, Domain Server DS j Based on the information in memory D ji R j and DS j Generating device D ji false identity

[0131] S4-3, Domain Server DS j The domain server's identity DS is transmitted via a secure channel. j PUF stimulus response DC of domain server j and DR j Device Identification D ji and fake identity PD ji Send to the authentication server AS.

[0132] S5. Authentication Server (AS) generates and distributes information: The Authentication Server (AS) generates its own pseudo-identity (PA). i Domain Server DS i Pseudo-identity PDS i and Domain Server DS j Pseudo-identity PDS j Afterwards, the authentication server AS will... ii PD ii DS iPDS i DC i DR i D ji PD ji DS j PDS j DC j DR j and PA i Stored in memory. The authentication server AS will then store the information PA. i PDS i PDS j PD ji and D ji Send to domain server DS i Domain Server DS i Received message PA i PDS i PDS j PD ji and D ji Then, save the information PA. i PDS i PDS j PD ji and D ji The information PA is stored in the server. i PDS i PDS j and PD ji Send to device D ii Device D ii Information PA i PDS i PDS j and PD ji It is stored in its own memory. The authentication server AS will store the information PA. i PDS i PDS j PD ii and D ii Send to domain server DS j Domain Server DS j Received message PA i PDS i PDS j PD ii and D ii Then, save the information PA. i PDS i PDS j PD ii and D ii The information PA is stored in the server. i PDS iPDS j and PD ii Send to device D ji Device D ji Information PA i PDS i PDS j and PD ii It is stored in its own memory. At this point, the registration phase between all devices and domain servers and the authentication server is complete.

[0133] Specifically, in this embodiment of the invention, step S5 includes the following steps:

[0134] S5-1, Authentication Server AS receives data from Domain Server DS i and DS j After receiving the message, generate your own pseudo-identity PA. i Domain Server DS i false identity and Domain Server DS j false identity Afterwards, the authentication server AS will... ii PD ii DS i PDS i DC i DR i D ji PD ji DS j PDS j DC j DR j and PA i Stored in memory;

[0135] S5-2, the authentication server AS will send information PA i PDS i PDS j PD ji and D ji Send to domain server DS i Domain Server DS i Received message PA i PDS i PDS j PD ji and D ji Then, save the information PA. i PDS i PDS j PD ji and D ji The information PA is stored in the server. i PDS iPDS j and PD ji Send to device D ii ;

[0136] S5-3, Equipment D ii Information PA i PDS i PDS j and PD ji Stored in its own memory;

[0137] S5-4, the authentication server AS will send information PA i PDS i PDS j PD ii and D ii Send to domain server DS j Domain Server DS j Received message PA i PDS i PDS j PD ii and D ii Then, save the information PA. i PDS i PDS j PD ii and D ii The information PA is stored in the server. i PDS i PDS j and PD ii Send to device D ji ;

[0138] S5-5, Equipment D ji Information PA i PDS i PDS j and PD ii Stored in its own memory;

[0139] S6, Equipment D ii Initiate a session: After registration is complete, device D ii Initiate key negotiation. Device D ii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and Pi All information. Device D ii Generate a random number N1 and a timestamp T1, and calculate the verification information I1. Then, device D... ii Send message M1 to its own domain server DS via a public channel. i .

[0140] Specifically, in this embodiment of the invention, step S6 includes the following steps:

[0141] S6-1, Equipment D ii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i =PUF(C i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information;

[0142] S6-2, Equipment D ii Generate a random number N1 and a timestamp T1, and calculate the verification information I1 = h(D ii ||R i ||P i ||N1||T1);

[0143] S6-3, Equipment D ii Message M1 = {PD ii The domain server DS sends the data (I1, N1, T1) to its own domain server DS via a public channel. i .

[0144] S7, Domain Server DS i Verify and request the inter-domain session key: Domain Server DS i Received from device D ii After message M1, generate message reception timestamp T1. Re Check T1 Re Is -T1 < ΔT1 true? If the verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the following steps. Then, the domain server DS... i Calculate verification information The results are then compared with the I1 sent by M1 to verify. Is it valid? If verification fails, the domain server DS...i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps. Domain Server DS i Calculate the device's identity D based on the information in memory. ii Verify if the identity exists in its own database. If not, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps. Domain Server DS i Collect all requesting devices and put the pseudo-identities of these n devices into set A = {D} i1 D i2 ,…,D in Domain Server DS i Generate excitation DC i DR response i Given a random number N3 and a timestamp T3, calculate the verification information I3, and then set A = {D} i1 D i2 ,…,D in Encrypt to Ciph A After that, the domain server DS i Send message M3 to the authentication server AS via a public channel.

[0145] Specifically, in this embodiment of the invention, step S7 includes the following steps:

[0146] S7-1, Domain Server DS i Received from device D ii After message M1, generate message reception timestamp T1. Re Check T1 Re Is -T1 < ΔT1 true? If the verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the next steps;

[0147] S7-2, Domain Server DS i Calculate verification information The results are then compared with the I1 sent by M1 to verify. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps.

[0148] S7-3, Domain Server DS i Calculate the device's identity based on the information in memory. Verify if the identity exists in its own database. If not, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the next steps;

[0149] S7-4, Domain Server DS i Collect all requesting devices and put the pseudo-identities of these n devices into set A = {D} i1 D i2 ,…,D in};

[0150] S7-5, Domain Server DS i Generate excitation DC i DR response i =PUF(DC) i Using a random number N3 and a timestamp T3, calculate the verification information I3 = h(DS). i ||PA i ||DR i ||N3||T3), then set A = {D i1 D i2 ,…,D in Encryption

[0151] S7-6, Domain Server DS i Send message M3 = {Ciph A PDS i ,I3,N3,T3} are sent to the authentication server AS via a public channel.

[0152] S8, Equipment D ji Initiate a session: After registration is complete, device D ji Initiate key negotiation. Device D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information. Device D ji Generate a random number N2 and a timestamp T2, and calculate the verification information I2. The device then sends message M2 to its domain server DS via a public channel. j .

[0153] Specifically, in this embodiment of the invention, step S8 includes the following steps:

[0154] S8-1, Equipment D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j =PUF(C j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information;

[0155] S8-2, Equipment D ji Generate random number N2 and timestamp T2, and calculate verification information I2 = h(D ji ||R j ||P j ||N2||T2);

[0156] S8-3, Equipment D ji Message M2 = {PD ji The domain server DS sends the data (I2, N2, T2) to its own domain server DS via a public channel. j .

[0157] S9, Domain Server DS j Verify and request the inter-domain session group key: Domain Server DS j Received from device D ji After message M4, generate message reception timestamp. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the following steps. Then, the domain server DS... j Calculate verification information The results are then compared with the I2 sent by M2 to verify the results. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps. Domain Server DS j Calculate the device's identity D based on the information in memory. ji Verify if the identity exists in its own database. If not, the domain server DS... jThis will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps. Domain Server DS j Collect all requesting devices and put the pseudo-identities of these n devices into set B = {D} j1 D j2 ,…,D jn Domain Server DS j Generate excitation DC j DR response j Given a random number N4 and a timestamp T4, calculate the verification information I4, and then set B = {D} j1 D j2 ,…,D jn Encrypt to Ciph B After that, the domain server DS j Send message M4 to the authentication server AS via a public channel.

[0158] Specifically, in this embodiment of the invention, step S9 includes the following steps:

[0159] S9-1, Domain Server DS j Received from device D ji After message M4, generate message reception timestamp. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the next steps;

[0160] S9-2, Domain Server DS j Calculate verification information The results are then compared with the I2 sent by M2 to verify the results. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the next steps;

[0161] S9-3, Domain Server DS j Calculate the device's identity based on the information in memory. Verify if the identity exists in its own database. If not, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the next steps;

[0162] S9-4, Domain Server DS jCollect all requesting devices and put the pseudo-identities of these n devices into set B = {D} j1 D j2 ,…,D jn};

[0163] S9-5, Domain Server DS j Generate excitation DC j DR response j =PUF(DC) j Using a random number N4 and a timestamp T4, calculate the verification information I4 = h(DS). j ||PA i ||DR j ||N4||T4), then set B = {D j1 D j2 ,…,D jn Encryption

[0164] S9-6, Domain Server DS j Send message M4 = {Ciph B PDS j The I4, N4, T4} are sent to the authentication server AS via a public channel.

[0165] S10. Authentication Server AS Inter-Domain Session Group Key Generation: The authentication server AS receives the key from device D. ii and D ji After messages M3 and M4, message reception timestamps are generated respectively. and examine and The authentication server (AS) checks whether the verification is successful. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps. The AS then calculates the verification information. and The results were then compared with I3 and I4 sent by M3 and M4 to verify them. and Whether it is true or false. If the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS will continue to execute subsequent steps. The authentication server AS calculates the set A = {D}. i1 D i2 ,…,D in} and set B = {D j1 D j2 ,…,D jn}, for A = {D i1 D i2 ,…,D in} and B = {D j1D j2 ,…,D jn Generate inter-domain session group key SK AB Simultaneously generate a random number N5 and a timestamp T5, and calculate SK. A SK B And verification information I5 and I6. Then, the authentication server AS sends message M5 to the domain server DS via a public channel. i Message M6 is sent to the domain server DS via a public channel. j .

[0166] Specifically, in this embodiment of the invention, step S10 includes the following steps:

[0167] S10-1, The authentication server AS receives data from device D. ii and D ji After messages M3 and M4, message reception timestamps are generated respectively. and examine and The authentication server (AS) checks whether the authentication is successful. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps.

[0168] S10-2, Authentication Server AS calculates verification information and The results were then compared with I3 and I4 sent by M3 and M4 to verify them. and The authentication server (AS) checks whether the authentication is successful. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps.

[0169] S10-3, Authentication Server AS calculates the set and set For A = {D i1 D i2 ,…,D in} and B = {D j1 D j2 ,…,D jn Generate inter-domain session group key SK AB ;

[0170] S10-4, The authentication server AS generates a random number N5 and a timestamp T5, and calculates... And verification information I5 = h(DS) i ||DR i ||SK A ||N5||T5), I6=h(DS) j ||DRj ||SK B ||N5||T5);

[0171] S10-5, The authentication server AS will send message M5={SK A The numbers I5, N5, and T5 are sent to the domain server DS via a public channel. i Message M6 = {SK B The numbers I6, N5, and T5 are sent to the domain server DS via a public channel. j .

[0172] S11, Domain Server DS i Receive inter-domain session group key: Domain Server DS i After receiving message M5 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the following steps. Then, the domain server DS... i Calculate verification information The results were then compared with the I5 sent by M5 to verify the results. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps. Domain Server DS i Calculate the inter-domain session group key SK based on the information in memory. AB Then generate a random number N6 and a timestamp T6, and calculate SK'. A And verification information I7. Then the domain server DS i Send message M7 to device D via a public channel. ii .

[0173] Specifically, in this embodiment of the invention, step S11 includes the following steps:

[0174] S11-1, Domain Server DS i After receiving message M5 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the next steps;

[0175] S11-2, Domain Server DSi Calculate verification information The results were then compared with the I5 sent by M5 to verify the results. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the next steps.

[0176] S11-3, Domain Server DS i Calculate the inter-domain session group key based on the information in memory.

[0177] S11-4, Domain Server DS i Generate random number N6 and timestamp T6, calculate And verification information I7 = h(D ii ||R i ||F i ||SK A ||N6||T6);

[0178] S11-5, Domain Server DS i Message M7 = {SK' A ,I7,N6,T6} are sent to device D via a public channel. ii

[0179] S12, Equipment D ii Receive inter-domain session group key: Device D ii Received from domain server DS i After message M7, generate message reception timestamp. examine Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps. Then, device D... ii Calculate verification information The results were then compared with the I7 sent by M7 to verify the results. Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the following steps. Device D ii Calculate the inter-domain session group key SK based on the information in memory. AB According to the inter-domain session group key SK AB Calculate the domain server DS i equipment D ii PD with a fake identity ii and Domain Server DS j equipment D jiPD with a fake identity ji The session key SK between them. At this point, the domain server DS... i equipment D ii Access to the domain server DS has been obtained j equipment D ji The session key SK.

[0180] Specifically, in this embodiment of the invention, step S12 includes the following steps:

[0181] S12-1, Equipment D ii Received from domain server DS i After message M7, generate message reception timestamp. examine Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps;

[0182] S12-2, Equipment D ii Calculate verification information The results were then compared with the I7 sent by M7 to verify the results. Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps;

[0183] S12-3, Equipment D ii Calculate the inter-domain session group key based on the information in memory.

[0184] S12-4, Based on the inter-domain session group key SK AB Calculate the domain server DS i equipment D ii PD with a fake identity ii and Domain Server DS j equipment D ji PD with a fake identity ji Session keys between At this point, the domain server DS i equipment D ii Access to the domain server DS has been obtained j equipment D ji Session key SK;

[0185] S13, Domain Server DS j Receive inter-domain session group key: Domain Server DS j After receiving message M6 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the following steps. Then, the domain server DS... j Calculate verification information The results were then compared with the I6 sent by M6 to verify them. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps. Domain Server DS j Calculate the inter-domain session group key SK based on the information in memory. AB Then generate a random number N7 and a timestamp T7, and calculate SK'. B And verification information I8. Then the domain server DS j Send message M8 to device D via a public channel. ji .

[0186] Specifically, in this embodiment of the invention, step S13 includes the following steps:

[0187] S13-1, Domain Server DS j After receiving message M6 from the authentication server AS, a message reception timestamp is generated. examine Is it valid? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the next steps;

[0188] S13-2, Domain Server DS j Calculate verification information The results were then compared with the I6 sent by M6 to verify them. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the next steps;

[0189] S13-3, Domain Server DS j Calculate the inter-domain session group key based on the information in memory.

[0190] S13-4, Domain Server DS j Generate random number N7 and timestamp T7, calculate And verification information I8 = h(Dji ||R j ||F j ||SK B ||N7||T7);

[0191] S13-5, Domain Server DS j Message M8 = {SK' B ,I8,N7,T7} are sent to device D via a public channel. ji .

[0192] S14, Equipment D ji Receive inter-domain session group key: Device D ji Received from domain server DS j After message M8, generate message reception timestamp. examine Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps. Then, device D... ji Calculate verification information The results were then compared with the I8 sent by M8 to verify them. Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the following steps. Device D ji Calculate the inter-domain session group key SK based on the information in memory. AB According to the inter-domain session group key SK AB Calculate the domain server DS j equipment D ji PD with a fake identity ji and Domain Server DS i equipment D ii PD with a fake identity ii The session key SK between them. At this point, the domain server DS... j equipment D ji Access to the domain server DS has been obtained i equipment D ii The session key SK.

[0193] Specifically, in this embodiment of the invention, step S14 includes the following steps:

[0194] S14-1, Equipment D ji Received from domain server DS j After message M8, generate message reception timestamp. examine Is it valid? If verification fails, device D... jiThe authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps;

[0195] S14-2, Equipment D ji Calculate verification information The results were then compared with the I8 sent by M8 to verify them. Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps;

[0196] S14-3, Equipment D ji Calculate the inter-domain session group key based on the information in memory.

[0197] S14-4, Equipment D ji Based on the inter-domain session group key SK AB Calculate the domain server DS j equipment D ji PD with a fake identity ji and Domain Server DS i equipment D ii PD with a fake identity ii Session keys between

[0198] This invention, based on the PWCBAP protocol, uses CRPs and FPPs to implement bidirectional authentication and key negotiation methods between devices and between devices and servers. While maintaining security, it replaces symmetric cryptography with CRPs, reducing computational overhead and shortening authentication time, while using FPPs increases the accuracy of protocol authentication. The PWCBAP protocol not only solves the problem of requiring device-by-device verification during batch authentication, resulting in a time complexity of O(n) that cannot meet the needs of rapid access for large-scale devices, but also addresses the serious privacy leakage risk associated with sharing PUF CRPs (challenge-response pairs) or channel feature databases during cross-domain authentication. Furthermore, it enhances the effective defense mechanism against active attacks (such as side-channel attacks and man-in-the-middle attacks), ensuring the secure operation of the Internet of Things (IoT) and possessing practical significance.

[0199] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.

[0200] The above are merely preferred embodiments of the present invention, and the scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principle of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A cross-domain batch authentication method for IoT devices based on the PWCBAP protocol, comprising a registration phase and an authentication and key exchange phase, characterized in that, The steps are as follows: S1, Equipment D ii To the domain server DS i Registration: Device D ii To the domain server DS i Apply for registration, device D ii Check if you possess both PUF and wireless channel characteristics (WCC). If you only have PUF, then generate the PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i 、R i F i and P i All information; Device D ii Information D ii C i 、R i F i and P i Send to domain server DS i Domain Server DS i Information D ii C i 、R i F i and P i Stored on the server; all requests to cross-domain with the domain server DS j Device D, which performs key negotiation within the device ii This step will be performed in all cases, and the above steps are transmitted over a secure channel; S2, Domain Server DS i Register with Authentication Server (AS): Domain Server (DS) i Request registration from the authentication server AS, domain server DS i Generate PUF excitation DC i and response DR i Domain Server DS i Generate all device D ii PD with a fake identity ii Domain Server DS i Information DS i DC i DR i D ii and PD ii Send to the authentication server; the authentication server receives the DS i DC i DR i D ii and PD ii It is then stored on the server; the above steps are performed in a secure channel. S3, Equipment D ji To the domain server DS j Registration: Device D ji To the domain server DS j Apply for registration, device D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information; Device D ji Information D ji C j R j F j and P j Send to domain server DS j Domain Server DS j Information D ji C j R j F j and P j Stored on the server; all requests to cross-domain with the domain server DS i Device D, which performs key negotiation within the device ji This step will be performed in all cases, and the above steps are transmitted over a secure channel; S4, Domain Server DS j Register with Authentication Server (AS): Domain Server (DS) j Request registration from the authentication server AS, domain server DS j Generate PUF excitation DC j and response DR j Domain Server DS j Generate all device D ji PD with a fake identity ji Domain Server DS j Information DS j DC j DR j D ji and PD ji Send to the authentication server; the authentication server receives the DS j DC j DR j D ji and PD ji It is then stored on the server; the above steps are performed in a secure channel. S5. Authentication Server (AS) generates and distributes information: The Authentication Server (AS) generates its own pseudo-identity (PA). i Domain Server DS i Pseudo-identity PDS i and Domain Server DS j Pseudo-identity PDS j Afterwards, the authentication server AS will... ii PD ii DS i PDS i DC i DR i D ji PD ji DS j PDS j DC j DR j and PA i Stored in memory; The authentication server AS will send information to PA i PDS i PDS j PD ji and D ji Send to domain server DS i Domain Server DS i Received message PA i PDS i PDS j PD ji and D ji Then, save the information PA. i PDS i PDS j PD ji and D ji The information PA is stored in the server. i PDS i PDS j and PD ji Send to device D ii Equipment D ii Information PA i PDS i PDS j and PD ji Stored in its own memory; the authentication server AS stores the information PA. i PDS i PDS j PD ii and D ii Send to domain server DS j Domain Server DS j Received message PA i PDS i PDS j PD ii and D ii Then, save the information PA. i PDS i PDS j PD ii and D ii The information PA is stored in the server. i PDS i PDS j and PD ii Send to device D ji Equipment D ji Information PA i PDS i PDS j and PD ii It is stored in its own memory; at this point, the registration phase of all devices and domain servers with the authentication server is complete; S6, Equipment D ii Initiate a session: After registration is complete, device D ii Start key negotiation; Device D ii Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. i Response R i If only WCC is available, then generate the wireless channel fingerprint F. i Location P i If both PUF and WCC are present, then the corresponding C will be generated. i R i F i and P i All information; Device D ii Generate a random number N1 and a timestamp T1, and calculate the verification information I1; then device D... ii Message M1 = {PD ii The domain server DS sends the data (I1, N1, T1) to its own domain server DS via a public channel. i ; S7, Domain Server DS i Verify and request the inter-domain session key: Domain Server DS i Received from device D ii After message M1, generate message reception timestamp T1. Re Check T1 Re -T1 < ΔT1 is true; if verification fails, the domain server DS i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the next steps; then, the domain server DS i Calculate verification information The results are then compared with the I1 sent by M1 to verify. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps; Domain Server DS i Calculate the device's identity D based on the information in memory. ii Verify whether the identity is in your database; If not in the database, domain server DS i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps; Domain Server DS i Collect all requesting devices and put the pseudo-identities of these n devices into set A = {D} i1 D i2 ,…,D in Domain Server DS i Generate excitation DC i DR response i Given a random number N3 and a timestamp T3, calculate the verification information I3, and then set A = {D} i1 D i2 ,…,D in Encrypt to Ciph A ; after that, the domain server DS i Send message M3 = {Ciph A PDS i The numbers I3, N3, and T3 are sent to the authentication server AS via a public channel. S8, Equipment D ji Initiate a session: After registration is complete, device D ji Start key negotiation; Device D ji Check if you have PUF and WCC. If you only have PUF, then generate PUF stimulus C. j Response R j If only WCC is available, then generate the wireless channel fingerprint F. j Location P j If both PUF and WCC are present, then the corresponding C will be generated. j R j F j and P j All information; Device D ji Generate a random number N2 and a timestamp T2, and calculate the verification information I2; then the device sends the message M2 = {PD} ji The domain server DS sends the data (I2, N2, T2) to its own domain server DS via a public channel. j ; S9, Domain Server DS j Verify and request the inter-domain session group key: Domain Server DS j Received from device D ji After message M4, generate message reception timestamp T2. Re Check T2 Re Is -T2 < ΔT2 true? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the next steps; then, the domain server DS j Calculate verification information The results are then compared with the I2 sent by M2 to verify the results. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps; Domain Server DS j Calculate the device's identity D based on the information in memory. ji Verify whether the identity is in your database; If not in the database, domain server DS j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps; Domain Server DS j Collect all requesting devices and put the pseudo-identities of these n devices into set B = {D} j1 D j2 ,…,D jn Domain Server DS j Generate excitation DC j DR response j Given a random number N4 and a timestamp T4, calculate the verification information I4, and then set B = {D} j1 D j2 ,…,D jn Encrypt to Ciph B ; after that, the domain server DS j Send message M4 = {Ciph B PDS j The numbers I4, N4, and T4 are sent to the authentication server AS via a public channel. S10. Authentication Server AS Inter-Domain Session Group Key Generation: The authentication server AS receives the key from device D. ii and D ji After messages M3 and M4, a message reception timestamp T3 is generated respectively. Re and T4 Re Check T3 Re -T3<ΔT3 and T4 Re The authentication server AS checks if -T4 < ΔT4 is true. If the verification fails, the AS will terminate the authentication key exchange process; otherwise, the AS will continue with subsequent steps. Then, the AS calculates the verification information. and The results were then compared with I3 and I4 sent by M3 and M4 to verify them. and Whether it is valid; if the verification fails, the authentication server AS will terminate the authentication key exchange process; otherwise, the authentication server AS will continue to execute subsequent steps; the authentication server AS calculates the set A = {D}. i1 D i2 ,…,D in } and set B = {D j1 D j2 ,…,D jn }, for A = {D i1 D i2 ,…,D in } and B = {D j1 D j2 ,…,D jn Generate inter-domain session group key SK AB Simultaneously generate a random number N5 and a timestamp T5, and calculate SK. A SK B And verify the information I5 and I6; then the authentication server AS will send message M5={SK} A The numbers I5, N5, and T5 are sent to the domain server DS via a public channel. i Message M6 = {SK B The numbers I6, N5, and T5 are sent to the domain server DS via a public channel. j ; S11, Domain Server DS i Receive inter-domain session group key: Domain Server DS i After receiving message M5 from the authentication server AS, a message reception timestamp T5 is generated. Re Check T5 Re Is -T5 < ΔT5 true? If verification fails, the domain server DS... i Terminate device D ii The authentication key exchange process; conversely, the domain server DS i Continue with the next steps; then, the domain server DS i Calculate verification information The results were then compared with the I5 sent by M5 to verify the results. Is it valid? If verification fails, the domain server DS... i This will terminate the authentication key exchange process; conversely, the domain server DS will... i Continue with the following steps; Domain Server DS i Calculate the inter-domain session group key SK based on the information in memory. AB Then generate a random number N6 and a timestamp T6, and calculate SK. ' A And verification information I7; then the domain server DS i Message M7 = {SK' A ,I7,N6,T6} are sent to device D via a public channel. ii ; S12, Equipment D ii Receive inter-domain session group key: Device D ii Received from domain server DS i After message M7, generate message reception timestamp T6. Re Check T6 Re Is -T6 < ΔT6 true? If the verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the next steps; then, device D ii Calculate verification information The results were then compared with the I7 sent by M7 to verify the results. Is it valid? If verification fails, device D... ii The authentication key exchange process will be terminated; otherwise, device D... ii Continue with the following steps; Device D ii Calculate the inter-domain session group key SK based on the information in memory. AB According to the inter-domain session group key SK AB Calculate the domain server DS i equipment D ii PD with a fake identity ii and Domain Server DS j equipment D ji PD with a fake identity ji The session key SK between them; at this point, the domain server DS i equipment D ii Access to the domain server DS has been obtained j equipment D ji Session key SK; S13, Domain Server DS j Receive inter-domain session group key: Domain Server DS j After receiving message M6 from the authentication server AS, a message reception timestamp T6 is generated. Re Check T6 Re Is -T6 < ΔT6 true? If verification fails, the domain server DS... j Terminate device D ji The authentication key exchange process; conversely, the domain server DS j Continue with the next steps; then, the domain server DS j Calculate verification information The results were then compared with the I6 sent by M6 to verify them. Is it valid? If verification fails, the domain server DS... j This will terminate the authentication key exchange process; conversely, the domain server DS will... j Continue with the following steps; Domain Server DS j Calculate the inter-domain session group key SK based on the information in memory. AB Then generate a random number N7 and a timestamp T7, and calculate SK'. B And verification information I8; then the domain server DS j Message M8 = {SK' B ,I8,N7,T7} are sent to device D via a public channel. ji ; S14, Equipment D ji Receive inter-domain session group key: Device D ji Received from domain server DS j After message M8, generate message reception timestamp T7. Re Check T7 Re Is -T7 < ΔT7 true? If the verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the next steps; then, device D ji Calculate verification information The results were then compared with the I8 sent by M8 to verify them. Is it valid? If verification fails, device D... ji The authentication key exchange process will be terminated; otherwise, device D... ji Continue with the following steps; Device D ji Calculate the inter-domain session group key SK based on the information in memory. AB According to the inter-domain session group key SK AB Calculate the domain server DS j equipment D ji PD with a fake identity ji and Domain Server DS i equipment D ii PD with a fake identity ii The session key SK between them; at this point, the domain server DS j equipment D ji Access to the domain server DS has been obtained i equipment D ii The session key SK.

2. The method for cross-domain batch authentication of IoT devices based on the PWCBAP protocol as described in claim 1, characterized in that, During the registration phase and the authentication and key exchange phase, the authentication conditions of devices in different domains vary depending on the specific scenario, and can be divided into four cases: (1) Devices in the domain only support PUF; (2) Devices in the domain only support WCC; (3) Devices in the domain support both PUF and WCC; (4) Some devices in the domain support PUF and others support WCC. During the registration phase, the domain server has bound the authentication factors (PUF, WCC) supported by each device to its device identifier and stored them in its own memory. During the authentication and key exchange phase, the domain server will determine which authentication factor the device uses based on the device identifier.

3. The method for cross-domain batch authentication of IoT devices based on the PWCBAP protocol as described in claim 1, characterized in that, During the registration phase, the domain server's memory contains a one-to-one mapping between the identity identifiers and pseudo-identities of all devices within the peer domain server. Devices within the domain server only know the pseudo-identities of the peer devices and not their real identities. During the authentication and key exchange phase, the device sends the pseudo-identity of the peer device to the domain server, which then uses the mapping to find the real identity of the peer device and informs the authentication server of the real identity so that the authentication server can generate an inter-domain session group key.

4. The method for cross-domain batch authentication of IoT devices based on the PWCBAP protocol as described in claim 1, characterized in that, During the authentication and key exchange phase, the domain server DS i This will collect data from within its own domain that wants to interact with the domain server DS. j D-device communication ji Device D ii and send its set A to the authentication server AS; Similarly, the domain server DS j This will collect data from within its own domain that wants to interact with the domain server DS. i D-device communication ii Device D ji The system then sends set B to the authentication server AS; upon receiving the message, the authentication server AS generates the inter-domain session group key SK that associates sets A and B. AB .

5. The method for cross-domain batch authentication of IoT devices based on the PWCBAP protocol as described in claim 1, characterized in that, During the authentication and key exchange phase, the intra-domain device will receive the inter-domain session group key SK. AB With h(PD) ii ||PD ji ||SK AB Perform an XOR operation to generate the domain server DS. i equipment D ii PD with a fake identity ii and Domain Server DS j equipment D ji PD with a fake identity ji A unique session key between devices, which is only valid for device D. ii With device D ji Know.

Citation Information

Patent Citations

  • Internet of vehicles cross-domain authentication key negotiation method based on smart card

    CN116015623A

  • Identity authentication method based on BACnet / IP protocol

    CN116582277A