Cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks

Through the cloud-edge collaborative multi-factor identity authentication method, using PUF initialization and binary tree group key structure, the security risks and low efficiency of terminal device identity information transmission in ubiquitous networks are solved, and efficient and secure identity authentication and message transmission are achieved.

CN120528614BActive Publication Date: 2025-09-26CHANGCHUN UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511031545.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-25
Publication Date
2025-09-26
Estimated Expiration
2045-07-25

AI Technical Summary

Technical Problem

In a ubiquitous network environment, the identity information of terminal devices has security risks during transmission and has low transmission efficiency. The existing single authentication method is difficult to meet the security and low power consumption requirements of the device.

Method used

A cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks is adopted. Identity credentials are issued to edge nodes through the cloud. The edge nodes complete the initial registration of PUF challenge-response pairs of terminal devices. Combined with two-way authentication, dynamic threshold strategy and binary tree group key structure, the authentication and message encryption of terminal devices are realized, and an anonymous and traceable group signature is generated.

Benefits of technology

It improves the robustness and transmission efficiency of authentication, reduces communication latency and bandwidth overhead, and can quickly locate malicious devices and dynamically revoke their signature permissions, meeting the requirements of high security and low power consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528614B_ABST
    Figure CN120528614B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of security authentication and ubiquitous network technology, and discloses a cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks. The method realizes cloud-edge two-way authentication by issuing identity credentials based on elliptic curves and parameter initialization of the PUF challenge-response library of the edge node. When the terminal accesses, the multi-factor authentication combining PUF challenge and dynamic threshold is adopted to improve the resistance to forgery and replay attacks. After the authentication is passed, the edge node generates a group public key locally and constructs a binary tree group key structure of preset depth, supporting post-quantum security and efficient group signature management. When a new terminal joins, the method generates a key based on the elliptic curve algorithm and allocates a group signature private key share to realize lightweight member management. The method achieves integrity, confidentiality and traceability while ensuring transmission efficiency, effectively supporting secure communication and dynamic revocation in an edge resource-constrained environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security authentication and ubiquitous network technology, and specifically to a cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks. Background Art

[0002] With the continuous development and integration of satellite communications, mobile communications, network technologies, and computing technologies, modern information networks are evolving toward heterogeneous interconnection and ubiquitous coverage. This has led to a ubiquitous network environment that deeply integrates multiple network forms, including the Internet, mobile Internet, Internet of Things, satellite Internet, integrated space-ground networks, and drone ad hoc networks. This highly dynamic, open, and distributed environment enables terminal devices to access the network and exchange information anytime and anywhere, greatly improving the accessibility and convenience of network services.

[0003] However, the widespread coverage and diverse access methods of ubiquitous networks also present unprecedented security challenges. During communications, when terminal device identity information or sensitive data is transmitted over open channels, there is a risk of privacy leakage. Furthermore, communicating entities are not fully trustworthy. Dishonest entities may maliciously leak device identity information. Attackers can impersonate or forge legitimate devices and launch various attacks, such as chosen plaintext attacks, chosen ciphertext attacks, malware attacks, replay attacks, man-in-the-middle attacks, and physical cloning attacks. Furthermore, traditional authentication mechanisms typically rely on a single authentication method (such as passwords and digital certificates), which cannot meet the security and low-power requirements of devices. To address these security risks and ensure data authenticity and integrity during message transmission, a series of measures are needed to protect the security of devices in ubiquitous networks. Summary of the Invention

[0004] (1) Technical problems to be solved: The present invention aims to solve the problems in the prior art of insecurity and low transmission efficiency of data during physical transmission, and provides a cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks.

[0005] (2) Technical solution: In order to solve the above-mentioned problems of insecurity and low transmission efficiency of data during physical transmission, the present invention provides the following technical solution: a cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks, characterized in that: the method includes the following steps: S1: The cloud pre-issues identity credentials to the edge node, and the edge node completes the initialization registration of the terminal device based on the PUF challenge-response pair.

[0006] S2: The edge node and the cloud exchange authentication messages based on the identity credentials and verify the random number and timestamp to achieve two-way identity authentication.

[0007] S3: When a terminal device requests access to the edge node, the edge node challenges the terminal device based on the PUF challenge-response pair initially registered. The terminal device generates and returns a response based on its own PUF module. The edge node matches the returned response and dynamically determines the matching threshold based on the current network status and security policy. When the matching result meets the threshold, the authentication is considered successful.

[0008] S4: When the authentication is successful, the edge node constructs a binary tree group key structure with a depth of a preset value and generates a group public key locally based on the algorithm parameters published by the cloud.

[0009] S5: When a new terminal device applies to join, the new terminal device generates a key pair based on the elliptic curve algorithm and submits a signature joining request. The edge node allocates a group signature private key share in the binary tree group key structure and sends it to the new terminal device.

[0010] S6: The terminal device symmetrically encrypts the message and generates an anonymous and traceable group signature using the binary tree group key structure. The recipient verifies the signature based on the latest group public key.

[0011] Furthermore, in S1, the identity credential sent by the cloud to the edge node is generated based on an elliptic curve algorithm, and the identity credential includes a unique identifier of the edge node and a timestamp signature.

[0012] Furthermore, the edge node completes the initial registration of the terminal device based on the PUF challenge-response pair, including: the edge node sends a randomly generated PUF challenge sequence to the terminal device; the terminal device uses its own PUF to generate a corresponding response sequence for the PUF challenge sequence and returns it through a secure channel; the edge node saves the PUF challenge sequence and the corresponding response sequence pair by pair in a local database to complete the registration of the terminal device.

[0013] Furthermore, the specific process of S3 is as follows: S31: the edge node randomly extracts several challenges from the PUF challenge-response pairs of the terminal device that is initialized and registered, and sends the several challenges to the terminal device.

[0014] S32: The terminal device generates and returns several corresponding responses based on its own PUF module.

[0015] S33: The edge node matches the received responses with the PUF challenge-response pairs of the terminal device that was initially registered, and counts the number of successful matches.

[0016] S34: The edge node determines a matching threshold based on the current network environment and security requirements.

[0017] S35: When the number of successful matches is greater than or equal to the threshold, the authentication is determined to be successful; otherwise, the authentication is determined to be failed.

[0018] Furthermore, in the S31 , the number of challenges randomly extracted from the PUF challenge-response pairs of the terminal device that are initialized and registered is equal to the number of PUF module units available in the terminal device.

[0019] Furthermore, the specific process of S4 is as follows: S41: Initialize a binary tree locally, and initialize the group information, registry and counter at the same time; wherein the depth of the binary tree is predetermined according to the requirement for the maximum number of group members when the system is deployed.

[0020] S42: Using the lattice cryptographic parameters published by the cloud, discrete Gaussian distribution sampling with errors is used on the polynomial ring of integers modulo prime numbers to generate the tracker's private key and the corresponding error, and the tracker's public key is calculated; the receiver's private key and error are generated in the same way, and the receiver's public key is calculated.

[0021] S43: Use the elliptic curve parameter set published by the cloud to randomly generate the edge node private key locally, and calculate the corresponding elliptic curve public key.

[0022] S44: Combine the tracker public key, the receiver public key, and the elliptic curve public key to form a group public key, and publish the group public key.

[0023] Furthermore, the specific process of S5 is as follows: S51: The new terminal device generates a key pair based on the elliptic curve algorithm released by the cloud, and uses its own private key to digitally sign the generated public key to form a signature joining request.

[0024] S52: After receiving the joining request, the edge node verifies the legitimacy of the digital signature and confirms that the public key has not been registered locally.

[0025] S53: The edge node allocates the first idle leaf node number to the new terminal in the binary tree group key structure, and calculates the corresponding group signature private key share based on the number and the system preset distributed key generation algorithm.

[0026] S54: The edge node packages the leaf node number, group signature private key share, signature validity period and other information into a certificate, sends it to the new terminal device, and updates the binary tree group key structure.

[0027] Furthermore, the S6 specifically includes the following steps: S61: the terminal device randomly generates a symmetric key, and uses the symmetric key to symmetrically encrypt the message to be protected to obtain a symmetric ciphertext.

[0028] S62: The terminal device uses the receiver public key and the tracker public key in the binary tree group key structure to encrypt the symmetric key and the terminal device identifier to obtain the tracker ciphertext and the receiver ciphertext.

[0029] S63: The terminal device performs a hash operation on the tracker ciphertext, the receiver ciphertext and the symmetric ciphertext, and generates a group signature based on the corresponding group signature private key share in the binary tree group key structure.

[0030] S64: The terminal device sends the tracker ciphertext, the receiver ciphertext, the symmetric ciphertext and the group signature to the receiver.

[0031] S65: The recipient verifies the legitimacy of the group signature using the latest group public key.

[0032] Furthermore, the S6 also includes: S66: When the receiver fails to verify the group signature or detects malicious behavior, the tracker decrypts the tracker ciphertext based on the tracker private key, restores the terminal device identification and generates a tracking certificate.

[0033] S67: When the terminal device is confirmed to be malicious or no longer trusted, the edge node adds the leaf node number corresponding to the terminal device to the revocation list, updates the binary tree group key structure locally, removes the corresponding leaf node and recalculates the witness information of the relevant nodes to achieve dynamic revocation of the malicious terminal.

[0034] An embodiment of the present invention also provides a cloud-edge collaborative multi-factor identity authentication system for ubiquitous networks, which is characterized by including: a credential and PUF initialization module: used to pre-issue identity credentials from the cloud to the edge node, and the edge node completes the initialization registration of the terminal device based on the PUF challenge-response pair.

[0035] Cloud-edge two-way authentication module: used for the edge node and the cloud to exchange authentication messages based on the identity credentials and verify the random number and timestamp to achieve two-way identity authentication.

[0036] Dynamic PUF authentication module: When a terminal device requests access to the edge node, the edge node initiates a challenge to the terminal device based on the PUF challenge-response pair initially registered by the terminal device. The terminal device generates and returns a response based on its own PUF module. The edge node matches the returned response and dynamically determines the matching threshold based on the current network status and security policy. When the matching result meets the threshold, the authentication is determined to be successful.

[0037] Group key generation and tree structure module: When authentication is successful, the edge node constructs a binary tree group key structure with a depth of a preset value, and generates a group public key locally based on the algorithm parameters published by the cloud.

[0038] Member joining and private key distribution module: When a new terminal device applies to join, the new terminal device generates a key pair based on the elliptic curve algorithm and submits a signed joining request. The edge node allocates the group signature private key share in the binary tree group key structure and sends it to the new terminal device.

[0039] Message protection and group signature module: used by the terminal device to symmetrically encrypt the message and generate an anonymous and traceable group signature using the binary tree group key structure. The recipient verifies the signature based on the latest group public key.

[0040] (III) Beneficial effects: Compared with the existing technology, the present invention provides a cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks, which has the following beneficial effects: 1. The cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks initiates a hardware challenge to the terminal through the edge node based on the PUF challenge-response registered by the device initialization, and combines the dynamic threshold strategy for response matching. The system adds a physical unclonable function (PUF) as a hardware authentication factor on top of the traditional digital certificate, and adaptively adjusts the required number of matching responses according to the real-time network status and security level. In this way, any middleman or remote attacker cannot forge the correct PUF response at the chip level even if they steal the message; at the same time, the dynamic threshold can avoid frequent false rejections when the network is poor or device resources are limited while ensuring high security, significantly improving the robustness of authentication and user experience, and fundamentally solving the problem of data insecurity due to device forgery during physical transmission.

[0041] 2. This cloud-edge collaborative multi-factor identity authentication method and system for ubiquitous networks first symmetrically encrypts the message through the terminal, and then uses a binary tree group key structure to generate an anonymous and traceable group signature based on the private key share, organically combining the speed advantage of symmetric encryption with the anonymity and traceability advantages of group signatures. During the data transmission stage, the receiver only needs to verify the group signature and decrypt the symmetric key once to fully recover the message, without multiple round trips to the centralized server or performing a separate public key lookup for each sender, which greatly reduces communication latency and bandwidth overhead. At the same time, when a security incident occurs, the authorized tracker can use the private key to decrypt the identity ciphertext encapsulated in the signature, quickly locate the malicious device and dynamically revoke its signing authority, comprehensively improving the system's satisfaction with the dual requirements of low transmission efficiency and security traceability. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 A schematic diagram of the overall process of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0043] Figure 2 Schematic diagram of the interaction rules of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0044] Figure 3 Schematic diagram of sub-step S3 of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0045] Figure 4 Schematic diagram of sub-step S4 of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0046] Figure 5 Schematic diagram of sub-step S5 of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0047] Figure 6 Schematic diagram of sub-step S6 of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0048] Figure 7 A schematic diagram of a challenge-response pair for the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0049] Figure 8 A binary tree diagram of the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0050] Figure 9 A schematic diagram of the public key encryption protocol flow for the cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks provided by the present invention.

[0051] Figure 10 Schematic diagram of the cloud-edge collaborative multi-factor identity authentication system module for ubiquitous networks provided by the present invention. DETAILED DESCRIPTION

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0053] When the system is deployed, the cloud first generates and sends all global algorithm parameters: In the elliptic curve part, the cloud selects the prime field , curve equation coefficients and base points , and determine the prime order of the base point , to meet the security strength of the elliptic curve discrete logarithm problem; in the lattice cryptography part, the order of the polynomial ring is defined in the cloud , modulus and the error distribution parameters , which is used for subsequent key generation based on loop learning with error (RLWE). The cloud also specifies hash functions and pseudorandom number generator specifications to ensure that all hashing and random sampling operations meet unified security requirements. Finally, the cloud constructs and publishes a digital credential template for edge node registration. This template includes the edge node unique identifier field format and the timestamp signature format. All these parameters are distributed to each edge node through the security configuration center, providing algorithmic constraints for subsequent identity credential verification, PUF challenge-response input, and group key structure construction.

[0054] See also Figure 1-2 , a cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks, characterized in that: the method includes the following steps: S1: the cloud sends identity credentials to the edge node in advance, and the edge node completes the initialization registration of the terminal device based on PUF challenge-response pairs.

[0055] Furthermore, in S1, the identity credential sent by the cloud to the edge node is generated based on an elliptic curve algorithm, and the identity credential includes a unique identifier of the edge node and a timestamp signature.

[0056] Specifically, the cloud uses a pre-generated elliptic curve private key to digitally sign the unique identifier and current timestamp of each edge node, forming a certificate containing the edge node identifier and timestamp signature, and sends it to each edge node through the security configuration center; after receiving the certificate, the edge node uses the elliptic curve public key sent by the cloud to verify the signature. If the signature is passed, the certificate is securely stored for subsequent two-way identity authentication and message integrity verification.

[0057] Furthermore, the edge node completes the initial registration of the terminal device based on the PUF challenge-response pair, including: the edge node sends a randomly generated PUF challenge sequence to the terminal device; the terminal device uses its own PUF to generate a corresponding response sequence for the PUF challenge sequence and returns it through a secure channel; the edge node saves the PUF challenge sequence and the corresponding response sequence pair by pair in a local database to complete the registration of the terminal device.

[0058] Specifically, the edge node first sets the number of challenges to , and call the pseudo-random number generator PRNG to generate a random challenge sequence . Then, the edge node sends each Sent to the terminal device; the terminal device locally calls its PUF module to calculate the response for each challenge , and the response sequence Return to the edge node through the same secure channel; after receiving all responses, the edge node will Store each item in the local security database to complete the registration of the terminal device and the initial registration required for subsequent authentication.

[0059] S2: The edge node and the cloud exchange authentication messages based on the identity credentials and verify the random number and timestamp to achieve two-way identity authentication.

[0060] Specifically, the edge node first generates a random number , and its own identity, current timestamp and After receiving the request, the cloud first uses the identity certificate sent to the edge node to verify the legitimacy of the edge node identifier and timestamp, and then based on the random number Generates an authentication response with the identity credentials it holds And return it to the edge node; the edge node receives the authentication response After that, use the locally stored identity credentials to verify its correctness, and then generate a new random number after the verification is passed. , and also calculate the authentication response based on the identity credentials Send to the cloud; final verification by the cloud The legitimacy of the edge node can be verified by verifying its identity. The entire two-way authentication process, through the alternating exchange of random numbers and credential signatures, not only prevents replay attacks but also ensures that the identities of both the cloud and edge nodes are confirmed by each other.

[0061] S3: When a terminal device requests access to the edge node, the edge node challenges the terminal device based on the PUF challenge-response pair initially registered. The terminal device generates and returns a response based on its own PUF module. The edge node matches the returned response and dynamically determines the matching threshold based on the current network status and security policy. When the matching result meets the threshold, the authentication is considered successful.

[0062] For further information, see Figure 3 The specific process of S3 is as follows: S31: The edge node randomly extracts several challenges from the PUF challenge-response pairs of the terminal device that is initialized and registered, and sends the several challenges to the terminal device.

[0063] For further information, see Figure 7 In the S31, the number of challenges randomly extracted from the PUF challenge-response pairs of the terminal device that are initialized and registered is equal to the number of PUF module units available in the terminal device.

[0064] Specifically, the edge node first queries all the PUF challenge-response pairs that have been initialized and registered in the local database, and determines the number of challenges to be extracted based on the total number of PUF hardware modules available on the target terminal device. ; Then, the edge node calls its randomization function and randomly selects The selected challenge list is sent to the terminal device through a preset secure channel at one time, so that the various PUF modules of the terminal device can be called subsequently and multi-factor authentication can be initiated.

[0065] S32: The terminal device generates and returns several corresponding responses based on its own PUF module. Specifically, after receiving the several challenges, the terminal device inputs each challenge into its internal physical unclonable function module and calls each PUF channel to generate a corresponding response. After all responses are generated, the terminal device returns the response list to the edge node through the secure channel pre-established with the edge node for subsequent matching and authentication processing.

[0066] S33: The edge node matches the received responses with the PUF challenge-response pairs of the terminal device that initialized the registration, and counts the number of successful matches. Specifically, the edge node first maps each received response back to the original challenge, retrieves the registration response that matches the challenge in the local security database, and then compares the two to see if they are consistent. For each pair of consistent responses, the match counter is incremented by one. After traversing all returned responses, the edge node can obtain the total number of successful matches so that it can perform threshold judgment in subsequent steps.

[0067] S34: The edge node determines the matching threshold based on the current network environment and security requirements. Specifically, the edge node first obtains the current network environment indicators, such as packet loss rate, latency, and signal-to-noise ratio, through the network monitoring module, and reads the current security requirement level (such as "normal" or "high") from the local security policy configuration. Then, based on these indicators and levels, the edge node searches for the corresponding matching threshold in the pre-defined policy table. For example, when the network environment is bad and the security requirement is normal, the threshold is 1; when the network environment is normal and the security requirement is normal, the threshold is 2; and when the network environment is bad and the security requirement is advanced, the threshold is , in order to ensure that both the reliability of authentication and the availability of the system can be taken into account under different conditions.

[0068] S35: When the number of successful matches is greater than or equal to the threshold, the authentication is determined to be successful, otherwise the authentication is determined to be failed; specifically, the edge node compares the obtained number of successful matches with the determined threshold: when the number of successful matches is greater than or equal to the threshold, the edge node determines that the terminal device has passed the authentication and sends an authentication pass notification to the upper-level business system or terminal device; otherwise, the edge node determines that the authentication has failed, terminates the session process with the terminal device, and can record the failure event or trigger an alarm according to the security policy.

[0069] S4: When the authentication is successful, the edge node constructs a binary tree group key structure with a depth of a preset value and generates a group public key locally based on the algorithm parameters published by the cloud.

[0070] For further information, see Figure 4 and Figure 8 The specific process of S4 is as follows: S41: Initialize a binary tree locally, and initialize the group information, registry and counter at the same time; wherein the depth of the binary tree is predetermined according to the requirement for the maximum number of group members when the system is deployed.

[0071] Specifically, the edge node first reads the maximum number of group members pre-set when the system is deployed. , and calculate the corresponding binary tree depth , making ; Then, create a tree with a depth of The empty binary tree data structure, each node position is assigned an index identifier; then, the group information Initialize to an empty collection and set the registry Clear and set the counter Set to zero; at this point, the edge node completes the framework of the group structure.

[0072] S42: Using the lattice cryptographic parameters published by the cloud, discrete Gaussian distribution sampling with errors is used on the polynomial ring of integers modulo prime numbers to generate the tracker's private key and the corresponding error, and the tracker's public key is calculated; the receiver's private key and error are generated in the same way, and the receiver's public key is calculated.

[0073] Specifically, the edge node first loads the modulus from the polynomial ring parameters and discrete Gaussian distribution parameters sent from the cloud. , order and the error distribution specification ; Then call the Gaussian sampler in sequence, from Sampling tracker private key and error , and according to the public polynomial Calculate the tracker public key ; Similarly, the sampling receiver's private key and error , and calculate the recipient's public key At this point, the edge node has completed the generation of two sets of post-quantum lattice cryptographic public and private key pairs, which will be used for subsequent message encryption and signature tracking functions.

[0074] S43: Generate a random edge node private key locally using the elliptic curve parameter set published by the cloud, and calculate the corresponding elliptic curve public key; Specifically, the edge node first obtains the curve equation and base point from the elliptic curve parameter set published by the cloud. and its prime order ; Then in the interval Randomly select an integer esk as its own private key and use elliptic curve point multiplication operation Calculate the corresponding public key ; The private key esk is securely stored in a local protected storage area, and the public key It will be released after being combined with the grid public key to generate the group public key.

[0075] S44: Combine the tracker public key, the receiver public key, and the elliptic curve public key to form a group public key, and publish the group public key.

[0076] Specifically, the edge node packages and combines the generated tracker public key, receiver public key and elliptic curve public key to form a group public key, and sends the group public key to each network participant through the edge node's publishing interface for subsequent group signature verification, tracking and revocation operations.

[0077] S5: When a new terminal device applies to join, the new terminal device generates a key pair based on the elliptic curve algorithm and submits a signature joining request. The edge node allocates a group signature private key share in the binary tree group key structure and sends it to the new terminal device.

[0078] For further information, see Figure 5 The specific process of S5 is as follows: S51: The new terminal device generates a key pair based on the elliptic curve algorithm published by the cloud, and uses its own private key to digitally sign the generated public key to form a signature joining request; Specifically, the new terminal device first reads the curve equation and base point from the elliptic curve parameter set published by the cloud and its stage , and then call the elliptic curve key generation algorithm locally: in the interval An integer is randomly selected as the private key, and the corresponding public key is obtained by multiplying the base point; then, the new terminal device uses the private key to perform an elliptic curve digital signature operation on the public key generated by itself and the joining request metadata (such as device identification and timestamp) to form a signed joining request, and sends the request message containing the public key, signature and metadata to the edge node through a secure channel.

[0079] S52: After receiving the joining request, the edge node verifies the legitimacy of the digital signature and confirms that the public key has not been registered locally. Specifically, after receiving the signed joining request submitted by the terminal device, the edge node first extracts the public key, signature and metadata of the terminal device from the request message. The signature is then verified using the elliptic curve public key sent from the cloud and stored locally to confirm that the signature matches the attached public key and metadata and that the timestamp is within the permitted range. Next, the edge node queries the local registry to check whether the public key already exists or has been revoked. Only when the signature is legal and the public key has not been registered will the subsequent member joining operation be performed. Otherwise, the joining request will be rejected.

[0080] S53: The edge node assigns the first idle leaf node number to the new terminal in the binary tree group key structure, and calculates the corresponding group signature private key share based on the number and the system's preset distributed key generation algorithm; specifically, the edge node first traverses the leaf nodes in the binary tree group key structure constructed locally, starting from the root node in the order of numbers, and finds the first unassigned leaf node number. ; Then, the edge node calls the system preset distributed key generation algorithm and uses the leaf node number The number is calculated by taking the locally saved group private key seed as input The corresponding group signature private key share; finally, the edge node combines the private key share with the number Record them in the registry to complete the preparation for private key distribution to new terminal devices.

[0081] S54: The edge node packages the leaf node number, group signature private key share, signature validity period and other information into a certificate, sends it to the new terminal device, and updates the binary tree group key structure.

[0082] Specifically, the edge node first organizes the assigned leaf node number, the corresponding group signature private key share, and the valid start and end time of the private key share into a digital certificate according to the predefined certificate format; then, the edge node uses its own private key to sign the digital certificate, and sends the signed certificate to the terminal device through the secure channel established with the new terminal device; after receiving the certificate, the edge node marks the leaf node as allocated in the local binary tree group structure, and updates the witness information of each ancestor node in turn along the path of the leaf node to ensure the integrity and consistency of the binary tree group key structure after the certificate is distributed.

[0083] S6: The terminal device symmetrically encrypts the message and generates an anonymous and traceable group signature using the binary tree group key structure. The recipient verifies the signature based on the latest group public key.

[0084] For further information, see Figure 6, the S6 specifically includes the following steps: S61: the terminal device randomly generates a symmetric key, and uses the symmetric key to symmetrically encrypt the message to be protected to obtain a symmetric ciphertext; specifically, the terminal device first encrypts the plaintext message Using symmetric keys Perform symmetric encryption to obtain symmetric ciphertext : ;in, It is a symmetric encryption algorithm.

[0085] S62: The terminal device uses the receiver's public key and the tracker's public key in the binary tree group key structure to encrypt the symmetric key and the terminal device identifier to obtain the tracker's ciphertext and the receiver's ciphertext; for details, please refer to Figure 9 The terminal device first sends the symmetric key With its own device identification Splice into messages according to predefined format , then in the polynomial ring Call the tracker public key in the binary tree group key structure With the recipient's public key Perform error-ring learning encryption. Devices randomly sample random values ​​on the ring. and the error term and , calculate the tracker ciphertext ,in, .

[0086] Then randomly sample random values and the error term and , calculate the receiver ciphertext ,in, .

[0087] Through the above operations, the terminal devices respectively obtain the tracker ciphertext containing the device identification and the recipient's ciphertext containing the symmetric key , providing encryption support for subsequent group signing and decryption tracking.

[0088] S63: The terminal device performs a hash operation on the tracker ciphertext, the receiver ciphertext, and the symmetric ciphertext, and generates a group signature based on the corresponding group signature private key share in the binary tree group key structure. Specifically, the terminal device first concatenates the tracker ciphertext, the receiver ciphertext, and the symmetric ciphertext into a whole message in a predefined order: .

[0089] And use the hash function sent by the cloud Compute the message digest: .

[0090] The terminal device then retrieves its corresponding group signature private key share from the binary tree group key structure , and generate signature parameters according to the group signature algorithm: randomly select a number , calculate the elliptic curve point : ; and calculate the challenge value : ; and the response value: ; This forms the group signature: This signature can not only ensure the anonymity of the message originating from a legitimate member of the group during verification, but also enable the tracker to use the private key to restore the identity of the specific signer when necessary.

[0091] S64: The terminal device sends the tracker ciphertext, the receiver ciphertext, the symmetric ciphertext and the group signature to the receiver; specifically, the terminal device sends the tracker ciphertext , receiver ciphertext , symmetric ciphertext and group signatures The message is encapsulated into an integrated message and sent to the recipient via a secure channel at once. This message contains the complete encrypted data and the group signature, allowing the recipient to simultaneously complete group signature verification, symmetric key recovery, and message decryption in a single reception operation.

[0092] S65: The recipient verifies the legitimacy of the group signature using the latest group public key.

[0093] Specifically, the receiver first disassembles the received message and extracts the symmetric ciphertext , Tracker ciphertext , receiver ciphertext and group signatures , and recalculate the message digest by concatenating the encrypted parts in a predefined order: ; Then, the receiver obtains the group public key of the current root node from the latest binary tree group public key structure , and use this set of public keys to verify the signature through elliptic curve point multiplication: .

[0094] When the above equation holds true, it means that the signature was indeed generated by a member of the group based on the private key share of digest Z, and the verification succeeds; otherwise, the verification fails and the message is rejected.

[0095] Furthermore, the S6 also includes: S66: When the receiver fails to verify the group signature or detects malicious behavior, the tracker decrypts the tracker ciphertext based on the tracker private key, restores the terminal device identification and generates a tracking certificate.

[0096] Specifically, the tracker first receives the tracker ciphertext Extract two components and then use the tracker's private key Decrypt the ciphertext: first calculate ; Because during encryption, the second component contains After the above subtraction, will fall close to 0 or close to The tracker judges the interval Close to 0, then , near ,but , you can restore the original terminal device identification After recovering the device ID, the tracker packages the ID with the ciphertext source information, timestamp, etc. to generate an undeniable tracking certificate for subsequent security audits and dynamic revocation operations.

[0097] S67: When the terminal device is confirmed to be malicious or no longer trusted, the edge node adds the leaf node number corresponding to the terminal device to the revocation list, updates the binary tree group key structure locally, removes the corresponding leaf node and recalculates the witness information of the relevant nodes to achieve dynamic revocation of the malicious terminal.

[0098] Specifically, when the edge node determines that a terminal device is malicious or no longer trusted through tracking proof or policy, the edge node first adds the leaf node number assigned to the device in the binary tree structure to the locally maintained revocation list; then, the edge node marks the leaf node as "revoked" in the binary tree group structure and physically removes the node, recalculates the witness value at its parent node, and updates the cumulative public key or witness information of all affected internal nodes along the tree path in turn; after the update is completed, the edge node publishes the new tree root information and the updated group public key to ensure that the revoked device will not be able to pass subsequent signature verification, thereby achieving dynamic revocation and effective isolation of malicious terminals.

[0099] See also Figure 10 The embodiment of the present invention also discloses a cloud-edge collaborative multi-factor identity authentication system for ubiquitous networks, characterized in that the system includes: a credential and PUF initialization module: used to pre-issue identity credentials from the cloud to the edge node, and the edge node completes the initialization registration of the terminal device based on the PUF challenge-response pair.

[0100] Cloud-edge two-way authentication module: used for the edge node and the cloud to exchange authentication messages based on the identity credentials and verify the random number and timestamp to achieve two-way identity authentication.

[0101] Dynamic PUF authentication module: When a terminal device requests access to the edge node, the edge node initiates a challenge to the terminal device based on the PUF challenge-response pair initially registered by the terminal device. The terminal device generates and returns a response based on its own PUF module. The edge node matches the returned response and dynamically determines the matching threshold based on the current network status and security policy. When the matching result meets the threshold, the authentication is determined to be successful.

[0102] Group key generation and tree structure module: When authentication is successful, the edge node constructs a binary tree group key structure with a depth of a preset value, and generates a group public key locally based on the algorithm parameters published by the cloud.

[0103] Member joining and private key distribution module: When a new terminal device applies to join, the new terminal device generates a key pair based on the elliptic curve algorithm and submits a signed joining request. The edge node allocates the group signature private key share in the binary tree group key structure and sends it to the new terminal device.

[0104] Message protection and group signature module: used by the terminal device to symmetrically encrypt the message and generate an anonymous and traceable group signature using the binary tree group key structure. The recipient verifies the signature based on the latest group public key.

[0105] The method described in this embodiment tested the algorithms involved in the system key generation, user key generation, joining, signing, verification and tracking processes. In these processes, the execution time of the specific algorithms used, such as encryption, ECC scalar multiplication, ECC point addition, etc., can be achieved below 10 milliseconds. Due to the high efficiency of these algorithms, the execution time of the six steps of the signature execution, namely the system key generation phase, user key generation phase, joining phase, signing phase, verification phase and tracking phase, can also be achieved within a total of 100 milliseconds. Compared with the existing signature algorithm based on bilinear mapping design used in most practical scenarios, the execution efficiency is improved by 30%-50%.

[0106] Therefore, this method not only ensures post-quantum security and physical security, but also has significant performance improvements over existing methods.

[0107] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0108] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks, characterized by: The method comprises the following steps: S1: the cloud sends the identity credentials to the edge node in advance, and the edge node completes the initial registration of the terminal device based on the PUF challenge-response pair; S2: the edge node and the cloud exchange authentication messages based on the identity credentials and verify the random number and timestamp to achieve two-way identity authentication; S3: when the terminal device requests to access the edge node, the edge node challenges the terminal device based on the PUF challenge-response pair of the initially registered terminal device, the terminal device generates and returns a response based on its own PUF module, the edge node matches the returned response, and dynamically determines the correct authentication based on the current network status and security policy. A matching threshold is set, and the authentication is determined to be successful when the matching result meets the threshold; S4: When the authentication is successful, the edge node constructs a binary tree group key structure with a depth of a preset value, and generates a group public key locally based on the algorithm parameters published by the cloud; S5: When a new terminal device applies to join, the new terminal device generates a key pair based on the elliptic curve algorithm and submits a signed joining request. The edge node allocates a group signature private key share in the binary tree group key structure and sends it to the new terminal device; S6: The terminal device symmetrically encrypts the message and generates an anonymous and traceable group signature using the binary tree group key structure. The recipient verifies the signature based on the latest group public key.

2. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 1 is characterized in that: In S1, the identity credential sent by the cloud to the edge node is generated based on an elliptic curve algorithm, and the identity credential includes a unique identifier of the edge node and a timestamp signature.

3. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 2 is characterized in that: The edge node completes the initial registration of the terminal device based on the PUF challenge-response pair, including: the edge node sends a randomly generated PUF challenge sequence to the terminal device; the terminal device uses its own PUF to generate a corresponding response sequence for the PUF challenge sequence and returns it through a secure channel; the edge node saves the PUF challenge sequence and the corresponding response sequence pair by pair in a local database to complete the registration of the terminal device.

4. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 1 is characterized in that: The specific process of S3 is as follows: S31: The edge node randomly extracts several challenges from the PUF challenge-response pairs of the terminal device that has been initially registered, and sends the challenges to the terminal device; S32: The terminal device generates and returns several corresponding responses based on its own PUF module; S33: The edge node matches the received responses with the PUF challenge-response pairs of the terminal device that has been initially registered, and counts the number of successful matches; S34: The edge node determines the matching threshold based on the current network environment and security requirements; S35: If the number of successful matches is greater than or equal to the threshold, the authentication is determined to be successful; otherwise, the authentication is determined to be failed.

5. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 4 is characterized by: In the S31 , the number of challenges randomly extracted from the PUF challenge-response pairs of the terminal device that are registered for initialization is equal to the number of PUF module units available in the terminal device.

6. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 1 is characterized in that: The specific process of S4 is as follows: S41: Initialize a binary tree locally, and initialize the group information, registry and counter at the same time; wherein, the depth of the binary tree is predetermined according to the requirement for the maximum number of group members when the system is deployed; S42: Using the lattice cryptographic parameters published by the cloud, adopt discrete Gaussian distribution sampling with errors on the polynomial ring of integer modulo prime numbers to generate the tracker private key and the corresponding error respectively, and calculate the tracker public key; generate the receiver private key and error in the same way, and calculate the receiver public key; S43: Use the elliptic curve parameter set published by the cloud to randomly generate the edge node private key locally, and calculate the corresponding elliptic curve public key; S44: Combine the tracker public key, the receiver public key and the elliptic curve public key to form a group public key, and publish the group public key.

7. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 1 is characterized in that: The specific process of S5 is as follows: S51: The new terminal device generates a key pair based on the elliptic curve algorithm published on the cloud, and uses its own private key to digitally sign the generated public key to form a signature joining request; S52: After receiving the joining request, the edge node verifies the legitimacy of the digital signature and confirms that the public key has not been registered locally; S53: The edge node assigns the first idle leaf node number to the new terminal in the binary tree group key structure, and calculates the corresponding group signature private key share based on the number and the system preset distributed key generation algorithm; S54: The edge node packages the leaf node number, group signature private key share and signature validity period to form a certificate, sends it to the new terminal device, and updates the binary tree group key structure.

8. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 1 is characterized in that: The S6 specifically includes the following steps: S61: the terminal device randomly generates a symmetric key, and uses the symmetric key to symmetrically encrypt the message to be protected to obtain a symmetric ciphertext; S62: the terminal device uses the receiver public key and the tracker public key in the binary tree group key structure to encrypt the symmetric key and the terminal device identifier respectively to obtain the tracker ciphertext and the receiver ciphertext; S63: the terminal device performs a hash operation on the tracker ciphertext, the receiver ciphertext and the symmetric ciphertext, and generates a group signature based on the corresponding group signature private key share in the binary tree group key structure; S64: the terminal device sends the tracker ciphertext, the receiver ciphertext, the symmetric ciphertext and the group signature to the receiver together; S65: the receiver uses the latest group public key to verify the legitimacy of the group signature.

9. The cloud-edge collaborative multi-factor identity authentication method for ubiquitous networks according to claim 8 is characterized in that: The S6 also includes: S66: When the recipient fails to verify the group signature or detects malicious behavior, the tracker decrypts the tracker ciphertext based on the tracker private key, restores the terminal device identification and generates a tracking certificate; S67: When the terminal device is confirmed to be malicious or no longer trusted, the edge node adds the leaf node number corresponding to the terminal device to the revocation list, and locally updates the binary tree group key structure, removes the corresponding leaf node and recalculates the witness information of the relevant nodes to achieve dynamic revocation of the malicious terminal.

10. A cloud-edge collaborative multi-factor identity authentication system for ubiquitous networks, characterized by: The system includes: a credential and PUF initialization module: used for pre-issuing identity credentials from the cloud to the edge node, and for the edge node to complete the initial registration of the terminal device based on the PUF challenge-response pair; a cloud-edge two-way authentication module: used for the edge node and the cloud to exchange authentication messages based on the identity credentials and verify the random number and timestamp to achieve two-way identity authentication; a dynamic PUF authentication module: used for when the terminal device requests to access the edge node, the edge node to challenge the terminal device based on the initialized registered terminal device PUF challenge-response pair, the terminal device generates and returns a response based on its own PUF module, the edge node matches the returned response, and dynamically determines the match based on the current network status and security policy Threshold, when the matching result meets the threshold, the authentication is determined to be successful; Group key generation and tree structure module: when the authentication is successful, the edge node constructs a binary tree group key structure with a depth of a preset value, and generates a group public key locally based on the algorithm parameters published by the cloud; Member joining and private key distribution module: when a new terminal device applies to join, the new terminal device generates a key pair based on the elliptic curve algorithm and submits a signed joining request, the edge node allocates a group signature private key share in the binary tree group key structure and sends it to the new terminal device; Message protection and group signature module: used for the terminal device to symmetrically encrypt the message and generate an anonymous and traceable group signature using the binary tree group key structure, and the recipient verifies the signature based on the latest group public key.

Citation Information

Patent Citations

  • Cloud side-end integrated identity authentication method and system for distributed energy storage system

    CN118353634A

  • Multi-factor identity authentication method for cloud edge fusion secure storage

    CN118555076A