Industrial Internet of Things three-factor authentication method based on edge computing
Through the three-factor authentication method of edge computing, the problem of incomplete security countermeasures in the industrial Internet of Things is solved, the security verification and identity privacy protection of communication entities are realized, and the counterfeiting and replay attacks are resisted, and communication security and reliability are improved.
Patent Information
- Application Number
- CN202510594147.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-08-22
AI Technical Summary
In the prior art, the security countermeasures of the Industrial Internet of Things such as attack detection, threat perception, access authentication, access permission control, etc. are imperfect, resulting in the industrial Internet of Things under edge computing facing harm and becoming a bottleneck restricting its development.
The three-factor authentication method of industrial Internet of Things is adopted based on edge computing, including industrial users and edge server nodes registering identity information through the cloud center, and authenticating through the three-factor authentication process. The hash function, symmetric encryption and bilinear pairing algorithm are used to generate session keys to ensure communication security and identity privacy.
Effectively avoid fake attacks and replay attacks, ensure communication security, resist man-in-the-middle attacks, ensure identity privacy, and ensure message freshness through timestamps, improving the security and reliability of the industrial Internet of Things.
Smart Images

Figure CN120528635A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and specifically provides an industrial Internet of Things three-factor authentication method based on edge computing. Background Art
[0002] The Industrial Internet of Things (IIoT) is an intelligent industrial system that seamlessly integrates the Internet of Things (IoT) with modern industry, and is one of the core areas of future IoT development. It can combine cutting-edge technologies such as blockchain, cloud computing, big data analytics, and artificial intelligence to optimize industrial production processes through automated data collection, secure communication, and intelligent analysis, significantly improving efficiency and reducing costs. Furthermore, the IIoT, which connects intelligent industrial equipment with industrial management and control platforms, can profoundly transform how industrial sites connect and communicate with real-world users, effectively integrating industrial production with various cutting-edge technologies. Furthermore, applying edge computing to the IIoT can more flexibly implement efficient IIoT production processes and meet requirements for agile access, data optimization, real-time services, and intelligent applications. The advantages of edge computing are evident precisely because of its powerful capabilities at the edge of industrial control networks.
[0003] In the prior art, for example, the technical solution described in the patent with publication number CN118827001A is: a collaborative authentication method for the cloud-edge end of the Internet of Things gateway, including generating three chaotic sequences to obtain verification information, arranging characters to determine the target arrangement, and encoding the verification information and the information to be transmitted through initial and improved arithmetic coding, and finally sending the encoding result as encrypted information to the cloud to achieve collaborative authentication of each edge end.
[0004] The imperfections of existing security countermeasures, such as attack detection, threat perception, access authentication, and access control, are increasingly posing a threat to the Industrial Internet of Things (IIoT) under edge computing, becoming a bottleneck restricting its development. Therefore, leveraging edge computing's advantages in connectivity, computing, and storage, as well as its proximity to endpoints, and researching edge computing-based security technologies applicable to the IIoT, extending security to the edge of the network and preventing threats from occurring at the edge, are crucial for the industry now and in the future. Summary of the Invention
[0005] The purpose of the present invention is to provide an industrial Internet of Things three-factor authentication method based on edge computing to solve the problems of imperfections in the existing security countermeasure technologies in the background technology, such as attack detection, threat perception, access authentication, and access permission control.
[0006] In order to solve the above technical problems, the technical solution adopted by the present invention is:
[0007] An industrial Internet of Things three-factor authentication method based on edge computing includes the following steps:
[0008] Step S1, the industrial user IU registers identity information through the cloud center CC;
[0009] Step S2, the edge server node ESN registers information through the cloud center CC;
[0010] Step S3: The industrial user IU sends an authentication message to the cloud center CC;
[0011] In step S4, the cloud center CC completes the authentication of the industrial user through a three-factor authentication method.
[0012] According to the above technical solution, in step S1, the industrial user registers identity information through the cloud center, which includes two processes: industrial user registration and cloud center authentication;
[0013] Industrial user registration includes the following steps:
[0014] Industrial users first insert their smart card and select the user's real identity ID i , User password PW i and biometric information BI i ;
[0015] The industrial user randomly selects a secret value u i , and calculate the temporary public key U i ; The calculation formula is:
[0016] U i =u i P
[0017] Where u i+ represents a randomly selected secret value, U i represents a temporary public key, and P represents a q-order cyclic additive group G i meso-generator;
[0018] Industrial users randomly select a random value r1 and calculate BIO i and R1;
[0019] BIO i =H1(BI i ||r1)
[0020] R1=H1(ID i ||PW i ||BI i ||r1)
[0021] Where, BIO i, R1 represent hash values; H1 represents collision-resistant hash function; r1 represents random value; PW i Indicates user password BI i Represents biometric information; || represents a string concatenation operation, and the concatenated strings serve as the input of the hash function;
[0022] The industrial user randomly selects a secret value k1 as the AES encryption key, and then encrypts the message to obtain R2;
[0023]
[0024] Where R2 represents the symmetric encryption value, Represents a symmetric encryption formula; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function;
[0025] Then use the public key SK of the cloud center to encrypt k1 to obtain R3, which represents the symmetric encryption value, specifically:
[0026] R3=En SK (k1)
[0027] Where R3 represents the symmetric encryption value, En sk Indicates that k1 is symmetrically encrypted using SK;
[0028] Finally send the message {R2, R3, U i} to the cloud center, which authenticates the identity information after receiving the corresponding message.
[0029] According to the above technical solution, cloud center authentication includes the following steps:
[0030] When CC receives the corresponding authentication message, CC first uses private key s1 to decrypt R3 to obtain AES encryption key k1; then uses k1 to decrypt message R2 to obtain ID i , BI i , R1 and BIO i ; CC verifies user ID by searching the database i If the ID exists in the database i , then CC notifies the user to select a new identity to register, otherwise continue;
[0031] CC calculates R4, and the specific calculation of R4 is as follows:
[0032] R4=H1(ID i ||s1)
[0033] R5=H1(BI i ||s1)
[0034]
[0035] R8=H1(R4||R5||R1)
[0036] Where R4, R5, and R8 represent hash values, and R6 and R7 represent encrypted values obtained through XOR operations. Represents the XOR operation; || represents the string concatenation operation, and the concatenated strings serve as the input of the hash function;
[0037] Finally CC stores the message {ID i , R8, U i}, and send the message {R7, R6} to IU i After receiving the smart card, the message {R7, R6, r1} is stored in the smart card.
[0038] According to the above technical solution, in step S2, the edge server node ESN registers information through the cloud center: j Select its ID j and randomly choose a secret value z j , calculate Z j Value temporary public key;
[0039] Z j =z i P
[0040] Where z j represents a randomly selected secret value, and P represents the q-order cyclic additive group G i meso-generator;
[0041] Then send the message {ID j , Z j}Send to CC;
[0042] When CC receives the corresponding message, CC verifies its identity ID by searching the database j If the ID exists in the database j , then CC notifies ESN j Reselect an identity to register, otherwise continue; CC randomly selects a secret value v j , calculate V j Value, used to assign a public key to the ESN;
[0043] V i =v i P
[0044] V2=H1(ID j ||s1||v j )
[0045] V3=H1(ID j ||s1)
[0046] V4=H1(ID j ||v j )
[0047]
[0048] Where V2, V3, V4, and V5 represent hash values, and V5 represents the encrypted value obtained by the XOR operation. || represents the string concatenation operation, and the concatenated strings serve as the input of the hash function.
[0049] Finally CC stores the message {ID j , v j , V j , V2, V3, Z j} and send the message {V2, V5, v j , V j} Give ESN j , ESN j After receiving the message, it is stored in the database and used to assign the parameters required for authentication to the ESN.
[0050] According to the above technical solution, in step S3, the industrial user IU sends an authentication message to the cloud center CC as follows:
[0051] Industrial User IU i First enter the user's real identity ID i , User password PW i and biometric information BI i and get the stored message from the smart card; Industrial User IU i Calculate BIO′ i :
[0052] BIO′ i =H1(BI i |r1)
[0053] R′ i =H1(ID i ||PW i ||BI i ||1)
[0054]
[0055] R′8=H1(R′4||R′5||R′1)
[0056] Where, BIO′ irepresents the hash value, R′1 and R′8 represent the hash value, R′4 and R′5 represent the encrypted value obtained by the XOR operation; || represents the string concatenation operation, and the concatenated strings are used as the input of the hash function;
[0057] IU i Select the current timestamp T1 and a randomly selected secret value k2 as the AES encryption key, and then encrypt the message to obtain R9:
[0058]
[0059] Where R9 represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula;
[0060] Then use CC's public key SK to encrypt the secret value k2 to get R 10 ;|| represents the string concatenation operation, and the concatenated strings serve as the input of the hash function;
[0061] R 10 =En SK (k2)
[0062] Where R 10 Indicates the encrypted value obtained by the symmetric encryption algorithm; En sk (k2) indicates that k2 is encrypted using a symmetric encryption formula;
[0063] Finally send the message {R9, R 10 , T1} to CC, completing the sending of authentication message.
[0064] According to the above technical solution, in step S4, the cloud center CC completes the authentication of the industrial user through the three-factor authentication method as follows:
[0065] When CC receives the corresponding message, it first verifies whether the timestamp T1 is within the legal range. If so, it continues; otherwise, it rejects the authentication.
[0066] CC uses private key s1 to 10 Decrypt to get the AES encryption key k2, then use k2 to decrypt the message R2 to get the ID i , R'8, T1; CC then verifies the user ID by retrieving the database i ; If the ID exists in the database i , then CC verifies the user identity and obtains R8. CC verifies whether R8 is equal to the received value R'8. If they are equal, then IU is verified. i identity; at this time CC retrieves IU i Corresponding edge server node data {ID j, v j , V j , V2, V3, Z j}; CC selects the current timestamp T2 and randomly selects a secret value k3 as the AES encryption key and calculates R 11 , specifically:
[0067] R 11 =H1(R8||T2)
[0068] Where R 11 Represents a hash value; R8 represents the user hash value stored in the CC database; || represents a string concatenation operation, and the concatenated strings serve as the input of the hash function;
[0069] Then encrypt the message to get R 12 ;
[0070]
[0071] Where R 12 Represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function;
[0072] Then use IU i The public key U i Encrypt k3 to get R 13 , specifically:
[0073]
[0074] Where R 13 Represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula;
[0075] Last message sent {R 12 , R 13 , T2} to CC.
[0076] According to the above technical solution, when IU i After receiving the corresponding message, IU i First, verify whether the timestamp T2 is within the legal range. If it is, continue; otherwise, reject the authentication.
[0077] IU i Use private key u i R 13 Decrypt to get the AES encryption key k3, and then use k3 to decrypt the message R 14 Decrypt to get ID j , V j, V2, V3, Z j , R 11 ; Then IU i Calculate R′ 11 , specifically:
[0078] R′ 11 =H1(R′8||T2)
[0079] Where R′ 11 Represents a hash value; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function;
[0080] IU i Verify R′ 11 and the received value R 11 Are they equal? If they are equal, the identity of CC is verified; IU i Generate the current timestamp T3 and randomly select a secret value x i , calculate the value X i , specifically:
[0081] X i =x i P
[0082] F i =H1(x i V j ||U i ||Z j )
[0083]
[0084] Mes i =H1(F i ||u i Z j ||V2||V3||T3)
[0085] Where, X i represents the public key of the calculation; F i Indicates hash value; PID i Represents the value obtained by the XOR operation; Mes i Represents a hash value; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function;
[0086] Last IU i Send the message {PID i , Mes i , X i , U i , T3} sent to ESN j .
[0087] According to the above technical solution, when ESNj After receiving the corresponding message, ESN j First, verify whether the timestamp T3 is within the legal range. If it is, continue; otherwise, reject the authentication; ESN j Randomly choose a secret value e j Calculate the temporary public key E j , specifically:
[0088] E j =e j P
[0089]
[0090] F j =H1(v j X i ||U i ||Z j )
[0091] V′4=H1(ID j ||v j )
[0092]
[0093] Mes′ i =H1(F j ||z j U i ||V2||V′3||T3)
[0094] Where, E j Indicates a temporary public key; EX j represents the value calculated by the bilinear pairing algorithm; F j Represents the hash value; V′4 represents the hash value; V′3 represents the value obtained by the XOR operation; Mes′ i Represents a hash value; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function;
[0095] ESN j Verify Mes′ i and the received value Mes i Are they equal? If they are equal, then IU is verified. i ESN j Generate current timestamp T4 and calculate session key K j , specifically:
[0096] K j =H2(ID i |ID j ||F j |EX j||T3||T4)
[0097] MK j =H1(K j ||V2||V′3||T4)
[0098]
[0099] Where K j Indicates hash value; MK j represents the hash value; V2 represents the hash value calculated by the hash function; V′3 represents the value obtained by the exclusive OR operation; || represents the string concatenation operation, and the concatenated strings are used as the input of the hash function;
[0100] Then the message {PID j , MK j , T4} sent to IU i .
[0101] According to the above technical solution, when IU i After receiving the message, IU i First, verify whether the timestamp T4 is legal. If it is legal, the authentication continues; otherwise, the authentication is rejected. i Calculate ID j , specifically:
[0102]
[0103] Where, EX j represents the value calculated by the bilinear pairing algorithm; e represents the mapping in the bilinear pairing algorithm; x i represents a random number; P represents the q-order cyclic additive group G i meso-generator;
[0104] Calculate the session key:
[0105]
[0106] MK′ i =H1(K i ||V2||V3||T4)
[0107] IU i Verify MK′ i and the received value MK j Are they equal? If so, then IU i Verify ESN j And verified that the same session key was generated, and finally IU i and ESN j Secure communication is performed through the session key. || represents the string concatenation operation, and the concatenated strings serve as the input of the hash function.
[0108] According to the above technical solution, the session key k i Specifically:
[0109] K i =H2(ID i ||ID j ||F i ||EX i ||T3||T4)
[0110] Where H2 represents the hash function; ID i Indicates the user's real identity, ID j Indicates the edge server node ESN j identity; F i Represents the calculated hash value EX i Represents the value calculated by the bilinear pairing algorithm: EX i =e(E j ,P) xi ;|| represents the string concatenation operation, and the concatenated strings serve as the input of the hash function.
[0111] Compared with the prior art, the present invention has the following beneficial effects:
[0112] Through the method of the present invention, communication entities verify each other by verifying authentication information, avoiding counterfeit attacks, ensuring the security of communication, and ensuring the freshness of messages by time stamps, thereby avoiding replay attacks.
[0113] The session keys generated by the industrial users in the method provided by the present invention are all generated by the industrial users IU i and ESN j The security of the session key is ensured by the secret value sent and the secret value generated by the bidirectional mapping algorithm. In the method provided by the present invention, messages within the communication entities must be authenticated, so any tampering with the information will result in authentication failure. This prevents man-in-the-middle attacks. The method provided by the present invention utilizes the industrial user's identity information for communication by encrypting the identity information, ensuring identity privacy and security. BRIEF DESCRIPTION OF THE DRAWINGS
[0114] Figure 1 This is the authentication flow chart of the present invention. DETAILED DESCRIPTION
[0115] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0116] Example 1
[0117] like Figure 1 As shown, an industrial Internet of Things three-factor authentication method based on edge computing includes the following steps:
[0118] Step S1, the industrial user IU registers identity information through the cloud center CC;
[0119] Step S2, the edge server node ESN registers information through the cloud center CC;
[0120] Step S3: The industrial user IU sends an authentication message to the cloud center CC;
[0121] In step S4, the cloud center CC completes the authentication of the industrial user through a three-factor authentication method.
[0122] Through the method of the present invention, communication entities verify each other by verifying authentication information, avoiding counterfeit attacks, ensuring the security of communication, and ensuring the freshness of messages by time stamps, thereby avoiding replay attacks.
[0123] The session keys generated by the industrial users in the method provided by the present invention are all generated by the industrial users IU i and ESN j The security of the session key is ensured by the secret value sent and the secret value generated by the bidirectional mapping algorithm. In the method provided by the present invention, messages within the communication entities must be authenticated, so any tampering with the information will result in authentication failure. This prevents man-in-the-middle attacks. The method provided by the present invention utilizes the industrial user's identity information for communication by encrypting the identity information, ensuring identity privacy and security.
[0124] Example 2
[0125] This embodiment provides a specific implementation method:
[0126] Initialization and registration:
[0127] The Cloud Center (CC) selects a q-order cyclic additive group G1 whose generator is P. G2 is a q-order cyclic multiplicative group, and CC selects a valid bilinear map satisfying e:G1×G2→G2.
[0128] CC selects a random number s1 as the private key and calculates the public key SK as follows:
[0129] SK=s1P
[0130] Next, CC selects a symmetric encryption and decryption function for En x (·) / Dn x (·) and two cryptographically collision-resistant hash functions H1(·) and H2(·). Finally, CC announces the system parameters {G, P, SK, H1(·), H2(·)}.
[0131] Industrial User IU i (Industrial User, IU) first inserts its smart card and then selects the user's real identity ID i , user password PW i , and biometric information BI i IU i Randomly choose a secret value u i , calculated value: U i =u i P. Then IU i Randomly select a random value r1 and calculate BIO i ; Specifically:
[0132] BIO i =H1(BI i ||r1)
[0133] R1=H1(ID i ||PW i ||BI i ||r1)
[0134] Where, BIO i , R1 represent hash values; H1 represents collision-resistant hash function; r1 represents random value; PW i Indicates user password BI i Represents biometric information; || represents a string concatenation operation, and the concatenated strings serve as the input of the hash function;
[0135] IU i Randomly select a secret value k1 as the AES encryption key, and then encrypt the message to obtain R2;
[0136]
[0137] Where R2 represents the symmetric encryption value, Represents a symmetric encryption formula.
[0138] Then use CC's public key SK to encrypt k1 to get R3; R3 = En SK (k1).
[0139] Finally send the message {R2, R3, U i} to CC. When CC receives the corresponding message, CC first uses the private key s1 to decrypt R3 to obtain the AES encryption key k1, and then uses k1 to decrypt the message R2 to obtain ID i , BI i , R1, BIO i CC verifies user ID by searching the database i If the ID exists in the database i , then CC notifies the user to re-select an identity for registration, otherwise continue.
[0140] CC calculates R4, which is specifically:
[0141] R4=H1(ID i ||s1)
[0142] R5=H1(BI i ||s1)
[0143]
[0144]
[0145] R8=H1(R4||R5||R1)
[0146] Where R4, R5, and R8 represent hash values, and R6 and R7 represent encrypted values obtained through XOR operations. Represents the exclusive OR operation.
[0147] Finally CC stores the message {ID i , R8, U i}, and send the message {R7, R6} to IU i IU i After receiving the smart card, the message {R7, R6, r1} is stored in the smart card.
[0148] Edge server node ESN j (Edge Server Node, ESN) select its identity ID j and randomly choose a secret value z j , calculate z j value:
[0149] Z j =z i P
[0150] Where z j represents a randomly selected secret value, and P represents the q-order cyclic additive group G i Middle generator.
[0151] Then send the message {ID j , Z j} is sent to CC. When CC receives the corresponding message, CC verifies its identity ID by searching the database j If the ID exists in the database j , then CC notifies ESN j Reselect an identity to register, otherwise continue. CC randomly selects a secret value v j , calculate the value v j :
[0152] V j =v i P
[0153] V2=H1(ID j ||s1||v j )
[0154] V3=H1(ID j ||s1)
[0155] V4=H1(ID j ||v j )
[0156]
[0157] Where V2, V3, V4, and V5 represent hash values, and V5 represents the encrypted value obtained through the XOR operation.
[0158] Finally CC stores the message {ID j , v j , V j , V2, V3, Z j} and send the message {V2, V5, v j , V j} Give ESN j .ESN j After receiving the message, it is stored in the database.
[0159] Login and authentication phase
[0160] (1) Industrial User IU i First enter the user's real identity ID i , user password PW i , and biometric information BI i and get the stored message from the smart card. iCalculate BIO′ i , specifically:
[0161] BIO′ i =H1(BI i |r1)
[0162] R′1=H1(ID i ||PW i ||BI i ||r1)
[0163]
[0164] R′8=H1(R′4||R′5||R′1)
[0165] Where, BIO′ i represents the hash value, R′1 and R′8 represent the hash value, and R′4 and R′5 represent the encrypted value obtained by the XOR operation.
[0166] IU i Select the current timestamp T1 and a randomly selected secret value k2 as the AES encryption key, and then encrypt the message to obtain R9:
[0167]
[0168] Where R9 represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula.
[0169] Then use CC's public key SK to encrypt k2 to get R 10 :
[0170] R 10 =En SK (k2) In the formula, R 10 Indicates the encrypted value obtained by the symmetric encryption algorithm; En sk (k2) indicates that k2 is encrypted using a symmetric encryption formula.
[0171] Finally send the message {R9, R 10 , T1} to CC.
[0172] (2) When CC receives the corresponding message, CC first verifies whether the timestamp T1 is within the legal range. If it is, it will continue, otherwise it will refuse authentication. CC uses private key s1 to authenticate R 10 Decrypt to get the AES encryption key k2, and then use k2 to decrypt the message R2 to get the ID i , R'8, T1. CC then verifies the user ID by retrieving the database i If the ID exists in the databasei , then CC verifies the user identity and obtains R8. CC verifies whether R8 is equal to the received value R'8. If they are equal, then IU is verified. i At this time CC retrieves IU i Corresponding edge server node data {ID j , v j , V j , V2, V3, Z j CC selects the current timestamp T2 and randomly selects a secret value k3 as the AES encryption key and calculates R 11 , specifically:
[0173] R 11 =H1(R8||T2)
[0174] Where R 11 Represents the hash value; R8 represents the user hash value stored in the CC database.
[0175] Then encrypt the message to get R 12 , specifically:
[0176]
[0177] Where R 12 Represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula.
[0178] Then use IU i The public key U i Encrypt k3 to get R 13 , specifically:
[0179]
[0180] Where R 13 Represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula.
[0181] Last message sent {R 12 , R 13 , T2} to CC.
[0182] (3) When IU i After receiving the corresponding message, IU i First, verify whether the timestamp T2 is within the legal range. If it is, continue; otherwise, reject the authentication. i Use private key u i R 13 Decrypt to get the AES encryption key k3, and then use k3 to decrypt the message R 14Decrypt to get ID j , V j , V2, V3, Z j , R 11 Then IU i Calculate R′ 11 , specifically:
[0183] R′ 11 =H1(R′8||T2)
[0184] IU i Verify R′ 11 and the received value R 11 Are they equal? If they are equal, the identity of CC is verified. i Generate the current timestamp T3 and randomly select a secret value x i , calculate the value X i
[0185] X i =x i P
[0186] F i =H1(x i V j ||U i ||Z j )
[0187]
[0188] Mes i =H1(F i ||u i Z j ||V2||V3||T3)
[0189] Where, X i represents the public key of the calculation; F i Indicates hash value; PID i Represents the value obtained by the XOR operation; Mes i Represents a hash value.
[0190] Last IU i Send the message {PID i , Mes i , X i , U i , T3} sent to ESN j .
[0191] (4) When ESN j After receiving the corresponding message, ESN j First, verify whether the timestamp T3 is within the legal range. If it is, continue; otherwise, reject the authentication.j Randomly choose a secret value e j , calculate E j , specifically:
[0192] E j =e j P
[0193]
[0194] F j =H1(v j X i ||U i ||Z j )
[0195] V′4=H1(ID j ||v j )
[0196]
[0197] Mes′ i =H1(F j ||z j U i ||V2||V′3||T3)
[0198] Where, E j Indicates a temporary public key; EX j represents the value calculated by the bilinear pairing algorithm; F j Represents the hash value; V′4 represents the hash value; V′3 represents the value obtained by the XOR operation; Mes′ i Represents a hash value.
[0199] ESN j Verify Mes′ i and the received value Mes i Are they equal? If they are equal, then IU is verified. i ESN j Generate current timestamp T4 and calculate session key K j , specifically:
[0200] K j =H2(ID i ||ID j ||F j ||EX j ||T3||T4)
[0201] MK j =H1(K j ||V2||V′3||T4)
[0202]
[0203] Where K j Indicates hash value; MK j represents a hash value; V2 represents a hash value calculated by the hash function; and V′3 represents a value obtained by an exclusive-OR operation.
[0204] Then the message {PID j , MK j , T4} sent to IU i .
[0205] (5)When IU i After receiving the message, IU i First, verify whether the timestamp T4 is legal. If it is legal, the authentication continues, otherwise the authentication is rejected. i Calculate ID j , specifically:
[0206]
[0207]
[0208] Where, EX j represents the value calculated by the bilinear pairing algorithm; e represents the mapping in the bilinear pairing algorithm; x i represents a random number; P represents the q-order cyclic additive group G i Middle generator.
[0209] Calculate the session key K i , specifically:
[0210] MK′ i =H1(K i ||V2||V3||T4)
[0211] IU i Verify MK′ i and the received value MK j Are they equal? If so, then IU i Verify ESN j And verified that the same session key was generated, and finally IU i and ESN j Secure communication via session keys.
[0212] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0213] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will be able to modify the technical solutions described in the aforementioned embodiments or substitute equivalents for some of the technical features. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A three-factor authentication method for industrial Internet of Things based on edge computing, characterized by: The following steps are involved: Step S1, the industrial user IU registers identity information through the cloud center CC; Step S2, the edge server node ESN registers information through the cloud center CC; Step S3: The industrial user IU sends an authentication message to the cloud center CC; In step S4, the cloud center CC completes the authentication of the industrial user through a three-factor authentication method.
2. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 1 is characterized in that: In step S1, the industrial user registers identity information through the cloud center, which includes two processes: industrial user registration and cloud center authentication; Industrial User Registration The following steps are involved: Industrial users first insert their smart card and select the user's real identity ID i , User password PW i and biometric information BI i ; The industrial user randomly selects a secret value u i , and calculate the temporary public key U i ; The calculation formula is: IN i =in i P Where u i+ represents a randomly selected secret value, U i represents a temporary public key, and P represents the q-order cyclic additive group G i meso-generator; Industrial users randomly select a random value r1 and calculate BIO i and R1; BIO i =H1(BI i ||r1) R1=H1(ID i ||PW i ||BI i ||r1) Where, BIO i , R1 represent hash values; H1 represents collision-resistant hash function; r1 represents random value; PW i Indicates user password BI i Represents biometric information; || represents a string concatenation operation, and the concatenated strings serve as the input of the hash function; The industrial user randomly selects a secret value k1 as the AES encryption key, and then encrypts the message to obtain R2; Where R2 represents the symmetric encryption value, Represents a symmetric encryption formula; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function; Then use the public key SK of the cloud center to encrypt k1 to obtain R3, which represents the symmetric encryption value, specifically: R3=One SK (k1) Where R3 represents the symmetric encryption value, En sk Indicates that k1 is symmetrically encrypted using SK; Finally send the message {R2, R3, U i } to the cloud center, which authenticates the identity information after receiving the corresponding message.
3. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 2 is characterized in that: Cloud center certification includes the following steps: When CC receives the corresponding authentication message, CC first uses private key s1 to decrypt R3 to obtain AES encryption key k1; then uses k1 to decrypt message R2 to obtain ID i , BI i , R1 and BIO i ; CC verifies user ID by searching the database i If the ID exists in the database i , then CC notifies the user to select a new identity to register, otherwise continue; CC calculates R4, and the specific calculation of R4 is as follows: R4=H1(ID i ||s1) R5=H1(BI i ||s1) R8=H1(R4||R5||R1) Where R4, R5, and R8 represent hash values, and R6 and R7 represent encrypted values obtained through XOR operations. Represents the XOR operation; || represents the string concatenation operation, and the concatenated strings serve as the input of the hash function; Finally CC stores the message {ID i , R8, U i }, and send the message {R7, R6} to IU i After receiving the smart card, the message {R7, R6, r1} is stored in the smart card.
4. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 3 is characterized by: In step S2, the edge server node ESN registers information through the cloud center: edge server node ESN j Select its identity ID j and randomly choose a secret value z j , calculate Z j Value Temporary Public Key: WITH j =z i P Where z j represents a randomly selected secret value, and P represents the q-order cyclic additive group G i meso-generator; Then send the message {ID j , Z j }Send to CC; When CC receives the corresponding message, CC verifies its identity ID by searching the database j If the ID exists in the database j , then CC notifies ESN j Reselect an identity to register, otherwise continue; CC randomly selects a secret value v j , calculate V j Value, used to assign a public key to the ESN; V j =v i P <h2 style=";text-align:left;direction:ltr">V2=H1(ID<h2 style=";text-align:left;direction:ltr"> j <h2 style=";text-align:left;direction:ltr"> ||s1||v<h2 style=";text-align:left;direction:ltr"> j <h2 style=";text-align:left;direction:ltr"> ) V3=H1(ID j ||s1) V4=H1(ID j ||v j ) Where V2, V3, V4, and V5 represent hash values, and V5 represents the encrypted value obtained by the XOR operation. || represents the string concatenation operation, and the concatenated strings serve as the input of the hash function. Finally CC stores the message {ID j , v j , V j , V2, V3, Z j } and send the message {V2, V5, v j , V j } Give ESN j , ESN j After receiving the message, it is stored in the database and used to assign the parameters required for authentication to the ESN.
5. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 4 is characterized in that: In step S3, the industrial user IU sends an authentication message to the cloud center CC: Industrial User IU i First enter the user's real identity ID i , User password PW i and biometric information BI i and get the stored message from the smart card; Industrial User IU i Calculate BIO′ i : BIO' i =H1(BI i ||r1) R′1=H1(ID i ||PW i ||BI i ||r1) R′8=H1(R′4||R′5||R′1) Where, BIO′ i Represents the hash value, R′1 and R′8 represent the hash value, R′4 and R′5 represent the encrypted value obtained by the XOR operation; || represents the string concatenation operation, and the concatenated strings are used as the input of the hash function: IU i Select the current timestamp T1 and a randomly selected secret value k2 as the AES encryption key, and then encrypt the message to obtain R9: Where R9 represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula; Then use CC's public key SK to encrypt the secret value k2 to get R 10 ;|| represents the string concatenation operation, and the concatenated strings serve as the input of the hash function; R 10 =In SK (k2) Where R 10 Indicates the encrypted value obtained by the symmetric encryption algorithm; En sk (k2) indicates that k2 is encrypted using a symmetric encryption formula; Finally send the message {R9, R 10 , T1} to CC, completing the sending of authentication message.
6. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 5 is characterized in that: In step S4, the cloud center CC completes the authentication of the industrial user through a three-factor authentication method: When CC receives the corresponding message, it first verifies whether the timestamp T1 is within the legal range. If so, it continues; otherwise, it rejects the authentication. CC uses private key s1 to 10 Decrypt to get the AES encryption key k2, then use k2 to decrypt the message R2 to get the ID i , R'8, T1; CC then verifies the user ID by retrieving the database i ; If the ID exists in the database i , then CC verifies the user identity and obtains R8. CC verifies whether R8 is equal to the received value R'8. If they are equal, then IU is verified. i identity; At this time CC retrieves IU i Corresponding edge server node data {ID j , v j , V j , V2, V3, Z j }; CC selects the current timestamp T2 and randomly selects a secret value k3 as the AES encryption key and calculates R 11 , specifically: R 11 =H1(R8||T2) Where R 11 Represents a hash value; R8 represents the user hash value stored in the CC database; || represents a string concatenation operation, and the concatenated strings serve as the input of the hash function; Then encrypt the message to get R 12 ; Where R 12 Represents the encrypted value obtained by the symmetric encryption algorithm; Represents a symmetric encryption formula; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function; Then use IU i The public key U i Encrypt k3 to get R 13 , specifically: Where R 13 Represents the encrypted value obtained by the symmetric encryption algorithm; Represents the symmetric encryption formula: Last message sent {R 12 , R 13 , T2} to CC.
7. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 6 is characterized in that: When IU i After receiving the corresponding message, IU i First, verify whether the timestamp T2 is within the legal range. If it is, continue; otherwise, reject the authentication. IU i Use private key u i R 13 Decrypt to get the AES encryption key k3, and then use k3 to decrypt the message R 14 Decrypt to get ID j , V j , V2, V3, Z j , R 11 ; Then IU i Calculate R′ 11 , specifically: R′ 11 =H1(R′8||T2) Where R′ 11 Represents a hash value; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function; IU i Verify R′ 11 and the received value R 11 Are they equal? If they are equal, the identity of CC is verified; IU i Generate the current timestamp T3 and randomly select a secret value x i , calculate the value X i , specifically: X i =x i P F i =H1(x i V j ||U i ||From j ) <h2 style=";text-align:left;direction:ltr">Mes<h2 style=";text-align:left;direction:ltr"> i <h2 style=";text-align:left;direction:ltr"> =H1(F<h2 style=";text-align:left;direction:ltr"> i <h2 style=";text-align:left;direction:ltr"> ||u<h2 style=";text-align:left;direction:ltr"> i <h2 style=";text-align:left;direction:ltr"> Z<h2 style=";text-align:left;direction:ltr"> j <h2 style=";text-align:left;direction:ltr"> ||V2||V3||T3) Where, X i represents the public key of the computation; F i Indicates hash value; PID i Represents the value obtained by the XOR operation; Mes i Represents a hash value; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function; Last IU i Send the message {PID i , Mes i , X i , U i , T3} sent to ESN j .
8. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 7 is characterized in that: When ESN j After receiving the corresponding message, ESN j First, verify whether the timestamp T3 is within the legal range. If it is, continue; otherwise, reject the authentication; ESN j Randomly choose a secret value e j Calculate the temporary public key E j , specifically: AND j =and j P F j =H1(v j X i ||U i ||From j ) V′4=H1(ID j ||in j ) <h2 style=";text-align:left;direction:ltr">Mes′<h2 style=";text-align:left;direction:ltr"> i <h2 style=";text-align:left;direction:ltr"> =H1(F<h2 style=";text-align:left;direction:ltr"> j <h2 style=";text-align:left;direction:ltr"> ||z<h2 style=";text-align:left;direction:ltr"> j <h2 style=";text-align:left;direction:ltr"> U<h2 style=";text-align:left;direction:ltr"> i <h2 style=";text-align:left;direction:ltr"> ||V2||V′3||T3) Where, E j Indicates a temporary public key; EX j represents the value calculated by the bilinear pairing algorithm; F j Represents the hash value; V′4 represents the hash value; V′3 represents the value obtained by the XOR operation; Mes′ i Represents a hash value; || represents a string concatenation operation, and the concatenated strings serve as input to the hash function; ESN j Verify Mes′ i and the received value Mes i Are they equal? If they are equal, then IU is verified. i ESN j Generate current timestamp T4 and calculate session key K j , specifically: K j =H2(ID i ||ID j ||F j ||EX j ||T3||T4) MK j =H1(K j ||V2||V′3||T4) Where K j Indicates hash value; MK j represents the hash value; V2 represents the hash value calculated by the hash function; V′3 represents the value obtained by the exclusive OR operation; || represents the string concatenation operation, and the concatenated strings are used as the input of the hash function; Then the message {PID j , MK j , T4} sent to IU i .
9. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 8, characterized in that: When IU i After receiving the message, IU i First, verify whether the timestamp T4 is legal. If it is legal, the authentication continues; otherwise, the authentication is rejected. i Calculate ID j , specifically: Where, EX j represents the value calculated by the bilinear pairing algorithm; e represents the mapping in the bilinear pairing algorithm; x i represents a random number; P represents the q-order cyclic additive group G i meso-generator; Calculate the session key: MK′ i =H1(K i ||V2||V3||T4) IU i Verify MK′ i and the received value MK j Are they equal? If so, then IU i Verify ESN j And verified that the same session key was generated, and finally IU i and ESN j Secure communication is performed through the session key. || represents the string concatenation operation, and the concatenated strings serve as the input of the hash function.
10. The three-factor authentication method for industrial Internet of Things based on edge computing according to claim 9, characterized in that: Session key k i Specifically: K i =H2(ID i ||ID j ||F i ||EX i ||T3||T4) Where H2 represents the hash function; ID i Indicates the user's real identity, ID j Indicates the edge server node ESN j identity; F i Represents the calculated hash value EX i Represents the value calculated by the bilinear pairing algorithm: EX i =e(E j , P) xi ;|| represents the string concatenation operation, and the concatenated strings serve as the input of the hash function.
Citation Information
Patent Citations
Internet of Things gateway cloud side-end cooperative authentication method
CN118827001A
PUF-based three-factor anonymous user authentication protocol method in Internet of Things
CN111818039A
Industrial environment authentication method based on edge service
CN114900288A
Security authentication method for agilawood wearable device
CN116599670A
Safety communication control system and method of industrial Internet of Things
CN118101336A