Equipment cross-domain communication method and device, equipment and storage medium

By building a blockchain network based on smart contract algorithms in cross-domain communication between devices, combining physical unclonable functions and post-quantum cryptography standards, generating public and private key pairs and performing authentication, the security issues in cross-domain communication are solved and high security and flexibility between devices are achieved.

CN120769253APending Publication Date: 2025-10-10ZHENGZHOU NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511041122.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing end-to-end authentication schemes have insufficient security in cross-domain communications, especially when devices communicate between different trust domains. They are vulnerable to eavesdropping attacks, replay attacks, physical attacks, and quantum computing attacks, and lack flexibility and scalability.

Method used

A blockchain network based on smart contract algorithms is used, combined with physically unclonable functions and post-quantum cryptography standards to generate public and private key pairs, and authenticate through a three-way handshake mechanism to generate secure session keys, ensuring the security of devices in cross-domain communications.

Benefits of technology

It improves the security of cross-domain communication between devices, strengthens the trust mechanism of devices in a cross-domain environment, prevents private key theft and quantum computing attacks, and improves the flexibility and scalability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120769253A_ABST
    Figure CN120769253A_ABST
Patent Text Reader

Abstract

The invention discloses an equipment cross-domain communication method and device, equipment and a storage medium, and relates to the technical field of Internet of Things security, and the method comprises the steps: calling a ground control station to construct an initial block chain network and a block chain account book with an intelligent contract algorithm based on parameter information; determining and storing the real identity information of the to-be-communicated devices by using the master key of the ground control station, and allocating the to-be-communicated devices to the trust domains in the initial block chain network to obtain a target block chain network; calling a public and private key pair generated by a physical unclonable chip and a post quantum cryptography standard to send a registration request to a ground control station to obtain a registration authentication credential, and synchronizing the registration authentication credential to a block chain account book; and when the to-be-communicated devices in different trust domains perform identity verification, calling the target block chain network to verify the identity verification request and the registration authentication credential, and generating a secure session key after the verification is passed, so as to perform data communication. Therefore, the security of cross-domain communication of the equipment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things security, and in particular to a device cross-domain communication method and device, equipment and a storage medium. BACKGROUND

[0002] At present, with the coordinated evolution of the fifth generation mobile communication (5G) technology and the intelligent sensor network, the Internet of Things (IoT) application integrating advanced sensors and communication technology has become a frontier field of common concern in academia and industry. Internet of Things devices, with their scene adaptability and multi-modal perception ability, have shown significant application value in urban traffic management, ecological environment monitoring, precision agriculture, and smart home. With the continuous expansion of the scale of Internet of Things devices, single-device tasks cannot meet the increasingly complex application requirements. In many practical scenarios, multiple Internet of Things devices working together have become a necessary application mode. Through flexible information exchange, Internet of Things devices in different trust domains can achieve cross-domain cooperation. This not only enhances the overall function of the Internet of Things system, but also broadens the application range of Internet of Things devices and promotes the in-depth development of Internet of Things devices in various fields. For example, in disaster emergency response, unmanned aerial vehicle devices relay communication to provide key signal support and provide disaster positioning for rescue vehicles. In the intelligent transportation system, vehicle-mounted devices and unmanned aerial vehicles work together to monitor traffic flow and road conditions, avoid congested sections, and reduce the probability of accidents. That is, cross-domain communication of different Internet of Things devices greatly improves the efficiency of collaborative management and gradually becomes a promising collaborative mode.

[0003] However, in a cross-domain working environment, devices between different trust domains need to achieve secure and reliable communication and cooperation, and face more severe challenges. Internet of Things devices are usually deployed in open environments and are vulnerable to eavesdropping attacks, replay attacks, and other security threats, and are also vulnerable to physical attacks, cloning attacks, and malicious impersonation attacks. These security risks not only interfere with the normal operation of Internet of Things devices themselves, but also have a serious impact on trusted organizations and infrastructure within the domain. Therefore, how to establish an effective trust mechanism between different trust domains and ensure end-to-end security authentication of different Internet of Things devices in a cross-domain environment has become an urgent challenge.

[0004] Through research, it is found that the existing end-to-end authentication scheme has the following limitations:

[0005] Current end-to-end identity authentication mechanisms based on PUF are mostly limited to a single management domain, and terminal devices within the domain mainly rely on third-party trusted servers to establish trust. When applied to cross-domain collaboration scenarios, there are challenges in CRP secure storage and synchronization, risks of single point of failure and CRP spoofing attacks, and lack of flexibility and scalability.

[0006] Although the distributed architecture of the blockchain provides cross-domain sharing of authentication information for end-to-end authentication of devices, most such implementations require devices to store private keys. Attackers can steal private keys by performing physical attacks (such as capturing or reprogramming), which will pose a significant risk to IOT systems.

[0007] Most existing cross-domain authentication schemes usually integrate traditional cryptographic mechanisms such as ECC, which usually rely on traditional mathematical complexity assumptions and are vulnerable to potential quantum computing attacks.

[0008] As can be seen from the above, how to improve the security of cross-domain communication of devices in the process of cross-domain communication of devices is a problem to be solved at present. SUMMARY

[0009] Therefore, the purpose of the present application is to provide a device cross-domain communication method, device, and storage medium, which can improve the security of cross-domain communication of devices in the process of cross-domain communication of devices. The specific scheme is as follows:

[0010] In a first aspect, the present application provides a device cross-domain communication method, comprising:

[0011] Calling ground control station initialization parameter information, and building an initial blockchain network with a smart contract algorithm based on the parameter information and a blockchain ledger corresponding to the initial blockchain network; the smart contract algorithm is an algorithm for adding, deleting, modifying and inquiring information in the initial blockchain network;

[0012] Determine the real identity information of the to-be-communicated device in the ground control station by using the master key corresponding to the ground control station, and store the real identity information to each to-be-communicated device equipped with a physical unclonable function, and then distribute each to-be-communicated device to each trust domain in the initial blockchain network to obtain a target blockchain network;

[0013] Call the physical unclonable chip in the to-be-communicated device and generate a public-private key pair by using a post-quantum cryptography standard, and then send a registration request to the ground control station in the corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, so that the ground control station synchronizes the registration authentication credential to the target blockchain network and the blockchain ledger;

[0014] When the first to-be-communicated device issues an identity authentication request to the second to-be-communicated device, the target blockchain network is called and the identity authentication request and the corresponding registration authentication credential are verified by using a preset three-way handshake mechanism, and a secure session key is generated after verification, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key; the trust domains corresponding to the first to-be-communicated device and the second to-be-communicated device are different.

[0015] Optionally, the ground control station initializes parameter information, and constructs an initial blockchain network with an intelligent contract algorithm and a blockchain ledger corresponding to the initial blockchain network based on the parameter information, including:

[0016] The ground control station discloses parameter information including a polynomial ring, a random sampling function, a distribution sampling function and a cryptography hash function, and then determines a master key corresponding to the ground control station based on a physically unclonable function and a preset key pool; the master key is used to determine the real identity information corresponding to the to-be-communicated device;

[0017] An initial blockchain network with an intelligent contract algorithm and a blockchain ledger corresponding to the initial blockchain network are constructed based on the parameter information; wherein the initial blockchain network includes a plurality of trust domains corresponding to the ground control station; each trust domain includes a peer node and an ordering node; the blockchain ledger is used to record the credential information of device authentication between each to-be-communicated device in the initial blockchain network.

[0018] Optionally, the real identity information of the to-be-communicated device in the ground control station is determined by using the master key corresponding to the ground control station, and the real identity information is stored in each to-be-communicated device equipped with a physically unclonable function, and then each to-be-communicated device is allocated to each trust domain in the initial blockchain network to obtain a target blockchain network, including:

[0019] The master key corresponding to the ground control station is determined, and then the real identity information corresponding to each to-be-communicated device in the ground control station is determined by using the master key;

[0020] The physically unclonable chip is deployed to each to-be-communicated device, and the real identity information is stored in each to-be-communicated device, and each to-be-communicated device is allocated to each trust domain in the initial blockchain network to obtain a target blockchain network; each ground control station is connected with a preset channel; the physically unclonable chip has the characteristics of exchanging and reversibly encrypting data;

[0021] A preset hash encryption function is used and a hash encryption value corresponding to the ground control station is determined based on the real identity information, and the hash encryption value is set as a blockchain address corresponding to the ground control station, so as to perform insert operations, update operations, query operations and delete operations on the target blockchain network based on the smart contract algorithm and the blockchain address.

[0022] Optionally, calling the physical unclonable chip in the device to be communicated and generating a public-private key pair using a post-quantum cryptography standard, and then sending a registration request to a ground control station in a corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, so that the ground control station synchronizes the registration authentication credential to the target blockchain network and the blockchain ledger, includes:

[0023] Using the physical unclonable chip in the communication device and based on a preset encryption algorithm and a post-quantum cryptography standard to generate a random encryption seed, and then using a preset uniform sampling function and based on the random encryption seed to generate a lattice matrix;

[0024] generating a public-private key pair including a public key and a private key based on the distribution sampling function and the lattice matrix, and then generating temporary identity information and response parameters corresponding to the device to be communicated based on the real identity information using a binary sequence physical unclonable chip in the device to be communicated;

[0025] After receiving the registration request sent by the communication device, the preset registration server in the trust domain calls the preset registration server to perform validity judgment on the registration request, and if the judgment result indicates that the registration request is valid, generates a hash value based on the registration request;

[0026] Determine the registration authentication credential based on the hash value, the public-private key pair, the temporary identity information and the response parameter, and call the smart contract algorithm and the public-private key pair to upload the registration authentication credential to the target blockchain network and the blockchain ledger.

[0027] Optionally, when the first device to communicate sends an identity authentication request to the second device to communicate, calling the target blockchain network and using a preset three-way handshake mechanism to verify the identity authentication request and the corresponding registration authentication credential, and generating a secure session key after the verification is successful, including:

[0028] When the first device to be communicated issues an identity authentication request to the second device to be communicated, the first device to be communicated is called and a corresponding extraction parameter is generated based on the corresponding first real identity identifier, so as to obtain the corresponding first public key, first temporary identity information, first response parameter, and first hash value from the target blockchain network based on the extraction parameter, and a first secret parameter is generated based on the first public key and the first temporary identity information;

[0029] Invoking the first device to communicate and obtaining a corresponding second public key, second temporary identity information, second response parameter, and second hash value from the target blockchain based on a second real identity identifier corresponding to the second device to communicate, and generating a second secret parameter based on the second public key and the second temporary identity information;

[0030] Determine first verification information based on the first public key, the first temporary identity information, the first response parameter, the first hash value, and the first secret parameter, and determine second verification information based on the second public key, the second temporary identity information, the second response parameter, the second hash value, and the second secret parameter;

[0031] Verifying the first verification information and the second verification information; if the verification passes, the information in the target blockchain network has not been tampered with; and calling the corresponding physical unclonable chip and random number to construct encryption information and verification parameters, and then sending parameter information including the encryption information and the verification parameters to the second communication device;

[0032] After the second communication device receives the parameter information, calling the second communication device to calculate a third hash value based on the parameter information and the second temporary identity information, generating a post-quantum private key based on the third hash value, and decrypting the encrypted information using the post-quantum private key to obtain a decrypted secret value, a decrypted random number, and a temporary identity to be verified;

[0033] Based on the temporary identity to be verified, the registration authentication credentials of the first device to be communicated are obtained from the target blockchain network, and the consistency of the registration authentication credentials is verified. After the verification is passed, authentication response information including the secure session key is returned to the first device to be communicated.

[0034] Optionally, after the secure session key is generated after the verification is passed, so that the first device to communicate and the second device to communicate perform data communication based on the secure session key, the method further includes:

[0035] calling a ground control station in an idle trust domain and allocating an identifier for a new device to be joined based on the registration request, and generating real identity information corresponding to the device to be joined based on the identifier and a corresponding to-be-processed public key, and issuing the real identity information to the device to be joined for storage;

[0036] generating a second public-private key pair based on the real identity information and the post-quantum cryptography standard and the physically unclonable function, and generating a temporary identity authentication credential including a temporary identity identifier and an authentication parameter based on the second public-private key pair;

[0037] issuing a registration request including the temporary identity authentication credential to a corresponding ground control station, so that the ground control station generates a hash value based on the registration request, and stores the hash value and the registration request to the target blockchain network using a preset storage function, and then synchronizes a corresponding blockchain ledger to the remaining to-be-communicated devices using a preset consensus mechanism.

[0038] Optionally, the secure session key is generated after the verification passes, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key.

[0039] Defining the query ability of an attacker using a random oracle model; the query ability includes the query ability of eavesdropping communication messages, the query ability of forging and tampering messages, the query ability of leaking session keys, the query ability of leaking long-term keys, and the query ability of accessing hash functions;

[0040] Constructing a progressive security game sequence including an initial security game and subsequent security games; wherein the initial security game is used to simulate an actual attack scenario, and the subsequent security games include simulating eavesdropping attacks, active attacks, encryption algorithm attacks, and physical unclonable function exchange attacks;

[0041] In the initial security game, the semantic security of the session key is defined as the attacker being unable to distinguish between a real key and a random string, and the unclonable property of the physically unclonable function is configured in the first security game simulating eavesdropping attacks; the unclonable property is used to prevent the attacker from constructing an effective session key under the condition of intercepting communication parameters;

[0042] In the second security game simulating active attacks, the uniqueness of the random number and the birthday paradox principle are configured to ignore the hash collision probability, and in the third security game simulating encryption attacks, the indistinguishable security of the post-quantum encryption algorithm is configured, and then in the fourth security game simulating exchange attacks, the computational infeasibility of the exchangeable physically unclonable function is configured; the computational infeasibility is used to prevent the attacker from forging the generation parameters of the session key.

[0043] In a second aspect, the present application provides a device cross-domain communication apparatus, comprising:

[0044] A blockchain ledger construction module is configured to call ground control station initialization parameter information and construct an initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network based on the parameter information; the smart contract algorithm is an algorithm for adding, deleting, modifying or inquiring information in the initial blockchain network;

[0045] A blockchain network construction module is configured to determine real identity information of a to-be-communicated device in the ground control station by using a master key corresponding to the ground control station, store the real identity information to each to-be-communicated device equipped with a physically unclonable function, and then allocate each to-be-communicated device to each trust domain in the initial blockchain network to obtain a target blockchain network;

[0046] A registration and authentication credential determination module is configured to call a physically unclonable chip in the to-be-communicated device and generate a public-private key pair by using a post-quantum cryptography standard, send a registration request to a ground control station in a corresponding trust domain based on the public-private key pair to obtain a registration and authentication credential, and synchronize the registration and authentication credential to the target blockchain network and the blockchain ledger by the ground control station;

[0047] A secure session key determination module is configured to call the target blockchain network and verify an identity verification request and a corresponding registration and authentication credential by using a preset three-way handshake mechanism when a first to-be-communicated device issues the identity verification request to a second to-be-communicated device, and generate a secure session key after verification, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key; the trust domains corresponding to the first to-be-communicated device and the second to-be-communicated device are different.

[0048] In a third aspect, the present application provides an electronic device, comprising:

[0049] A memory is configured to save a computer program;

[0050] A processor is configured to execute the computer program to implement the device cross-domain communication method described above.

[0051] In a fourth aspect, the present application provides a computer readable storage medium configured to save a computer program, wherein the computer program is executed by a processor to implement the device cross-domain communication method described above.

[0052] From the above, before the device cross-domain communication is performed, the ground control station initialization parameter information needs to be called, and the initial blockchain network with the smart contract algorithm is built based on the parameter information and the blockchain ledger corresponding to the initial blockchain network; the real identity information of the ground control station is determined, and the real identity information is stored in each to-be-communicated device equipped with a physically unclonable function, and each to-be-communicated device is stored in each trust domain of the initial blockchain network to obtain a target blockchain network; the ground control station in the to-be-communicated device is called, and a public-private key pair is generated by using the post-quantum cryptography standard and the physically unclonable function, and a registration request is sent to a preset registration server in the corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, and then the registration authentication credential is stored in the target blockchain network; when the first to-be-communicated device issues an identity verification request to the second to-be-communicated device, the target blockchain network is called and the identity verification request and the corresponding registration authentication credential are verified by using a preset three-way handshake mechanism, and a secure session key is generated after the verification is passed, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key and the blockchain ledger.

[0053] From the above, before the device cross-domain communication is performed, the ground control station initialization parameter information needs to be called, and the initial blockchain network with the smart contract algorithm is built based on the parameter information and the blockchain ledger corresponding to the initial blockchain network; the real identity information of the ground control station is determined, and the real identity information is stored in each to-be-communicated device equipped with a physically unclonable function, and each to-be-communicated device is stored in each trust domain of the initial blockchain network to obtain a target blockchain network; the ground control station in the to-be-communicated device is called, and a public-private key pair is generated by using the post-quantum cryptography standard and the physically unclonable function, and a registration request is sent to a preset registration server in the corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, and then the registration authentication credential is stored in the target blockchain network; when the first to-be-communicated device issues an identity verification request to the second to-be-communicated device, the target blockchain network is called and the identity verification request and the corresponding registration authentication credential are verified by using a preset three-way handshake mechanism, and a secure session key is generated after the verification is passed, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key and the blockchain ledger. BRIEF DESCRIPTION OF DRAWINGS

[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are only a part of the embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.

[0055] Figure 1 A device cross-domain communication method flow chart disclosed by the present application;

[0056] Figure 2 A specific device cross-domain communication authentication system schematic diagram disclosed by the present application;

[0057] Figure 3 A specific device cross-domain communication method flow chart disclosed by the present application;

[0058] Figure 4 A specific device cross-domain communication device registration flow chart disclosed by the present application;

[0059] Figure 5 An algorithm schematic diagram for processing a block chain disclosed by the present application;

[0060] Figure 6 An algorithm schematic diagram for registering a device disclosed by the present application;

[0061] Figure 7 A process flow schematic diagram of a device end-to-end mutual authentication process disclosed by the present application;

[0062] Figure 8 A device cross-domain communication device structure schematic diagram disclosed by the present application;

[0063] Figure 9 An electronic device structure diagram disclosed by the present application. DETAILED DESCRIPTION

[0064] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.

[0065] The existing end-to-end authentication scheme has the following limitations: current PUF-based end-to-end identity authentication mechanism is mostly limited to a single management domain, and the terminal devices in the domain mainly rely on a third-party trusted server to establish trust. When applied to a cross-domain collaboration scenario, there are challenges in the secure storage and synchronization of CRPs, risks of single point of failure and CRP spoofing attacks, and lack of flexibility and scalability. Although the distributed architecture of the blockchain provides cross-domain sharing of authentication information for device end-to-end authentication, most such implementations require devices to store private keys. Attackers can steal private keys by performing physical attacks, which will pose a significant risk to IOT systems. Most existing cross-domain authentication schemes usually integrate traditional cryptographic mechanisms such as ECC, which often rely on traditional mathematical complexity assumptions and are vulnerable to potential quantum computing attacks. Therefore, the present application provides a device cross-domain communication method that improves the security of device cross-domain communication.

[0066] Referring to Figure 1 As shown in the figure, the embodiment of the present application discloses a device cross-domain communication method, comprising:

[0067] Step S11, calling the ground control station to initialize parameter information, and constructing an initial blockchain network with a smart contract algorithm based on the parameter information and a blockchain ledger corresponding to the initial blockchain network; the smart contract algorithm is an algorithm for adding, deleting, modifying and querying information in the initial blockchain network.

[0068] In this embodiment, the embodiment of the present application proposes an anti-quantum end-to-end anonymous authentication scheme for implementing cross-domain communication of Internet of Things devices, aiming at the problems of insufficient physical protection, lack of flexibility and scalability, and lack of anti-quantum function in existing device end-to-end security authentication. Specifically, the unmanned aerial vehicle device can realize end-to-end security authentication and key negotiation with the device with the assistance of a private Hyperledger Fabric blockchain network. The distributed nature of the blockchain meets the requirements of flexibility and scalability. In addition, in order to enhance the physical security and anti-quantum capability of the Internet of Things devices, the embodiment of the present application designs a cross-domain authentication mechanism based on lightweight BS-PUF, and integrates Kyber post-quantum encryption primitives based on SRAM PUF (Static Random-Access Memory Physical Unclonable Function) to ensure the keyless storage and anti-quantum characteristics of the scheme. Furthermore, the embodiment of the present application proves the security based on the ROR (Real-Oracle-Random) model and non-formal analysis.

[0069] It is worth mentioning that the process of device cross-domain communication in the embodiment of the application includes initialization, blockchain and smart contract deployment, device registration, cross-domain authentication and key negotiation, device dynamic joining and device revocation, and the like. In the initialization stage, the ground control station GCS can initialize the relevant parameter information and build an initialization blockchain network, and provide public parameter information and a blockchain ledger in the blockchain network for use by each entity in the system. In the blockchain and smart contract deployment stage, all entities in the system join the blockchain network to jointly maintain a blockchain ledger. The blockchain network is built with a smart contract algorithm to ensure the insertion, query, deletion and other operations of each entity on the blockchain ledger.

[0070] In the device registration stage, the device registration flowchart of device cross-domain communication is as shown in Figure 2 Fig. 1: first, the devices deployed in the network can generate a public-private key pair based on the Kyber cryptographic system based on SRAMPUF, and then submit a registration request to the respective domain administrator . Each GCS is responsible for collecting and generating relevant parameters from the device PUF (Physical Unclonable Function, i.e. physical unclonable function), and synchronizing the authentication parameters to the blockchain network for use by devices in other domains for authentication.

[0071] Further, in the device cross-domain authentication and key negotiation stage, when a device in one management domain initiates an identity verification request to a device in another management domain, the devices in different domains can complete mutual identity verification through a three-way handshake mechanism with the assistance of a distributed blockchain network, and then negotiate a unique secure session key for subsequent data transmission. In the device dynamic joining stage, the newly joined device first needs to generate a corresponding public-private key pair according to the SRAMPUF-based Kyber key generation algorithm in the registration stage, and then submit a registration request to the GCS of its own management domain to complete the registration. In the device revocation stage, the domain administrator GCS of the revoked device can call the Delete operation in the smart contract framework to delete the device identity verification credentials in the world state database of Hyperledger Fabric, while the historical transaction records related to these credentials are still saved in the immutable blockchain ledger, to eliminate the inherent centralized revocation list maintenance of the traditional PKI system, while retaining the auditable proof of historical state.

[0072] In the embodiment, the authentication system diagram of device cross-domain communication and the device cross-domain communication method flowchart are as shown in Figure 3 and Figure 4The initialization phase, the blockchain phase and the smart contract deployment phase, the device registration phase, the cross-domain authentication phase and the key agreement device dynamic joining phase, and the device revocation phase are shown, and particularly relate to the initialization phase, the blockchain phase and the smart contract deployment phase, the device registration phase, the cross-domain authentication phase and the key agreement device dynamic joining phase, and the device revocation phase. First, the ground control station registers a server A polynomial ring over a finite field GF(q) can be defined A polynomial ring over a finite field GF(q) can be defined A polynomial ring over a finite field GF(q) can be defined A polynomial ring over a finite field GF(q) can be defined A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、 A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、 A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、 A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、 A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、 A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、 A uniform sampling function, a distribution sampling function and a one-way hash function are generated in the initialization phase 、

[0073] Specifically, the ground control station initialization parameter information is called, and the initial blockchain network with a smart contract algorithm and the blockchain ledger corresponding to the initial blockchain network are constructed based on the parameter information, which can include: the ground control station calls the parameter information including the polynomial ring, the random sampling function, the distribution sampling function and the cryptographic hash function, and then determines the master key corresponding to the ground control station based on the physical unclonable function and the preset key pool; the master key is used to determine the real identity information corresponding to the to-be-communicated device; the initial blockchain network with a smart contract algorithm and the blockchain ledger corresponding to the initial blockchain network are constructed based on the parameter information; wherein the initial blockchain network includes a plurality of trust domains corresponding to the ground control station; each trust domain includes a peer node and an ordering node; the blockchain ledger is used to record the credential information of the device authentication between each to-be-communicated device in the initial blockchain network.

[0074] Step S12, determine the real identity information of the ground control station, and store the real identity information to each to-be-communicated device equipped with a physically unclonable function, then allocate each to-be-communicated device to each trust domain in the initial blockchain network, to obtain a target blockchain network.

[0075] In this embodiment, in the blockchain and smart contract deployment stage, the initial blockchain network can include four different trust domain areas, and each trust area is allocated one peer node and one ordering node, and is managed by a corresponding GCS, and each GCS can also maintain a corresponding copy of the ledger, all connected through channels, and can interact with these channels through respective applications.

[0076] It is worth mentioning that the membership service provider (MSP) can be used to manage the identity certificates of all participating nodes and ordering nodes and access control to the ledger. When a transaction needs to be added to the ledger, the ledger is first transmitted to the subscriber, and then the secure consensus of the transaction is realized through the "execution, ordering and verification" process. In addition, all operational interactions with the blockchain network in the Hyperledger·Fabric architecture are managed through smart contracts. The cryptographic hash value corresponding to the real identity of the device can be used as the corresponding blockchain address, and then the smart contract can enable insert, update, query and delete operations on the blockchain according to the blockchain address. In addition, in order to ensure secure access, the ground control station GCS is specified to have the privilege of performing insert, update and delete operations, while the device is limited to query operations for certificate verification, and the specific algorithm is as Figure 5 shown, wherein algorithm 1 is a blockchain initialization algorithm, algorithm 2 is a blockchain insertion algorithm, algorithm 3 is a blockchain update algorithm, algorithm 4 is a blockchain query algorithm, and algorithm 5 is a blockchain deletion algorithm.

[0077] In this embodiment, in the device registration stage, the device deployed in the network can first generate a public and private key pair based on the Kyber cryptographic system based on the SRAM PUF, and then submit a registration request to the respective domain administrator . Each GCS is responsible for collecting and generating related parameters from the device PUF, and then synchronizing the generated authentication parameters to the blockchain network for authentication and use by devices in other domains. Assuming that the device belongs to the management domain, the device belongs to The management domain, the key generation process of the device terminal device and the identity registration process are as follows: first, a stimulation signal at each power-on is taken as a challenge of the SRAM PUF, and the response generated by the SRAM unit is used as an encryption seed of the Kyber key. In a specific embodiment, the Kyber512 security level encryption algorithm is selected, and and , the security parameters . Taking the device as an example: First, the lattice matrix can be generated by a uniform sampling function , wherein represents a random seed, based on the power-on operation, the hardware secret value obtained by the embodiment of the application and are taken as the Kyber private key and public key seed respectively, and then the private key and the public key are generated based on the distribution sampling function .

[0078] Specifically, the real identity information of the to-be-communicated device in the ground control station is determined by using the master key corresponding to the ground control station, and the real identity information is stored in each to-be-communicated device equipped with a physically unclonable function, and then each to-be-communicated device is allocated to each trust domain in the initial blockchain network to obtain a target blockchain network, which can include: determining the master key corresponding to the ground control station, and then determining the real identity information of the to-be-communicated device in the ground control station corresponding to the master key; deploying a physically unclonable chip to each to-be-communicated device, and storing the real identity information to each to-be-communicated device, and allocating each to-be-communicated device to each trust domain in the initial blockchain network to obtain a target blockchain network; each ground control station is connected with a preset channel; the physically unclonable chip has the characteristics of exchanging and reversibly encrypting data; the hash encryption value corresponding to the ground control station is determined based on the real identity information by using a preset hash encryption function, and the hash encryption value is set as the blockchain address corresponding to the ground control station, so as to perform insertion operation, update operation, query operation and deletion operation on the target blockchain network based on the smart contract algorithm and the blockchain address.

[0079] Step S13, calling the ground control station in the to-be-communicated device, and generating a public-private key pair by using a post-quantum cryptography standard and the physically unclonable function, and then sending a registration request to a preset registration server in the corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, and storing the registration authentication credential in the target blockchain network.

[0080] In a specific embodiment, the device Upon receiving your true identity After that, you first need to calculate the key , and according to the above Algorithm to generate public and private key pairs , and then randomly select groups Generate a temporary group identity and a set of response parameters , then send a registration request To your own registration server . And in After receiving the registration request, first check Is it valid? Then calculate the hash value after the representation is valid. , and register the authentication credentials Stored in the blockchain node for subsequent security authentication between devices. Accept your true identity After that, you first need to calculate the key , and then randomly select a group , and based on Determine the corresponding temporary identity And the response parameters , then send a registration request To your own registration server , and in After receiving the registration request, calculate the hash value , and then by calling The smart contract will register the authentication credentials Upload to the blockchain node. In a specific implementation, the specific algorithm diagrams of Algorithm 6, Algorithm 7 and Algorithm 8 are as follows: Figure 6 shown.

[0081] Specifically, the physical unclonable chip in the to-be-communicated device is called to generate a public-private key pair by using a post-quantum cryptography standard, and then a registration request is sent to a ground control station in a corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, so that the ground control station synchronizes the registration authentication credential to a target blockchain network and a blockchain ledger, which can include: generating a random encryption seed by using the physical unclonable chip in the to-be-communicated device and based on a preset encryption algorithm and a post-quantum cryptography standard, and then generating a lattice matrix by using a preset uniform sampling function and based on the random encryption seed; generating a public-private key pair including a public key and a private key based on a distribution sampling function and based on the lattice matrix, and then generating temporary identity information corresponding to the to-be-communicated device and a response parameter based on real identity information by using a binary sequence physical unclonable chip in the to-be-communicated device; after a preset registration server in the trust domain receives a registration request issued by the to-be-communicated device, the preset registration server is called to judge the validity of the registration request, and if the judgment result represents that the registration request is valid, a hash value is generated based on the registration request; the registration authentication credential is determined based on the hash value, the public-private key pair, the temporary identity information, and the response parameter, and the registration authentication credential is uploaded to the target blockchain network and the blockchain ledger by using a smart contract algorithm and the public-private key pair.

[0082] In step S14, when the first to-be-communicated device issues an identity verification request to the second to-be-communicated device, the target blockchain network is called and the identity verification request and the corresponding registration authentication credential are verified by using a preset three-way handshake mechanism, and a secure session key is generated after verification, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key and the blockchain ledger; the trust domains corresponding to the first to-be-communicated device and the second to-be-communicated device are different.

[0083] In this embodiment, the flowchart of the device end-to-end mutual authentication process is as shown in Figure 7 In the cross-domain authentication and key agreement phase, when a device in one management domain initiates an identity verification request to a device in another management domain, the devices in different domains can complete mutual identity verification through a three-way handshake mechanism with the assistance of a distributed blockchain network, and then mutually negotiate a unique secure session key to perform subsequent data transmission operation by using the secure session key. In one specific implementation, first, the device can calculate its real identity based on its real identity , and extract its public key , unused temporary identity , secret parameter , and verification parameter from the blockchain. At the same time, the device that the device Computing and extracting the corresponding from the blockchain. Subsequently, the embodiments of the present application can determine whether the blockchain information is tampered by verifying and . Then, may calculate the secret value based on its own wherein . Subsequently, may select a random number to calculate the parameters , and then the embodiments of the present application can construct the encrypted information , , and the verification parameters , and finally send to the device . Wherein, .

[0084] Subsequently, after receiving the parameter information , the device may first generate based on its own real identity , and then call algorithm to dynamically generate its own private key , and based on the decryption algorithm of algorithm 8 , it can decrypt by calculating , , , , and , and then verify , , and : If the equation is established, it means that the decrypted information is complete. At the same time, may extract the corresponding from the blockchain based on the decrypted , and then determine whether the blockchain information is tampered by verifying . Subsequently, may calculate the secret value based on its own real identity and , wherein , then calculate the shared secret , the temporary parameter and the encrypted information . Furthermore, select a random number and use a shared secret Perform encryption operation to obtain , and finally calculate the verification hash , and send Give equipment .

[0085] Then, According to the received parameters calculate , , and decrypt it: , and verify the decrypted information , if the equality holds, then Successful verification . Then, Need to continue calculating temporary parameters , encrypted information and shared secret ,in, is the information extracted from the blockchain. Finally, Computable session keys So as to obtain the verification parameters , and send a message Give .when Received message After that, the embodiment of the present application can be calculated by and Generate session keys and verify , if the equality holds, then Successful verification . Ultimately, the device and A unique session key is jointly negotiated .

[0086] Specifically, when the first device to be communicated sends an identity authentication request to the second device to be communicated, the target blockchain network is called and the preset three-way handshake mechanism is used to verify the identity authentication request and the corresponding registration authentication credential, and a secure session key is generated after the verification is passed. It may include: when the first device to be communicated sends an identity authentication request to the second device to be communicated, the first device to be communicated is called and a corresponding extraction parameter is generated based on the corresponding first real identity identifier, so as to obtain the corresponding first public key, first temporary identity information, first response parameter, and first hash value from the target blockchain network based on the extraction parameter, and generate a first secret parameter based on the first public key and the first temporary identity information; the first device to be communicated is called and the corresponding second public key, second temporary identity information, second response parameter, and second hash value are obtained from the target blockchain based on the second real identity identifier of the second device to be communicated, and a second secret parameter is generated based on the second public key and the second temporary identity information; the first secret parameter is generated based on the first public key, the first temporary identity information, the first response parameter, the first hash value, and the first secret parameter. A secret parameter is used to determine the first verification information, and the second verification information is determined based on the second public key, the second temporary identity information, the second response parameter, the second hash value and the second secret parameter; the first verification information and the second verification information are verified. If the verification is successful, the information in the target blockchain network has not been tampered with, and the corresponding physical unclonable chip and random number are called to construct encryption information and verification parameters, and then the parameter information including the encryption information and verification parameters is sent to the second device to be communicated; after the second device to be communicated receives the parameter information, the second device to be communicated is called to calculate a third hash value based on the parameter information and the second temporary identity information, so as to generate a post-quantum private key based on the third hash value, and the encrypted information is decrypted using the post-quantum private key to obtain the decrypted secret value, the decrypted random number and the temporary identity to be verified; based on the temporary identity to be verified, the registration authentication certificate of the first device to be communicated is obtained from the target blockchain network, and the registration authentication certificate is verified for consistency, and after the verification is successful, the authentication response information including the secure session key is returned to the first device to be communicated.

[0087] In this embodiment, during the dynamic device addition phase, if there is a dynamic mission requirement or insufficient device deployment capacity, the embodiment of this application needs to dynamically add auxiliary devices to the mission operation. That is, the newly added device can be sent to its affiliated ground control station ( )Submit a registration request: First, Candidate device Assign a unique identifier , and use calculate As a device In addition, Keep your true identity secret . Then, in Receive your own After that, first you need to The corresponding secret is stored, and then the inherent SRAM PUF function is used to generate an encryption seed, and then a post-quantum secure public-private key pair is constructed based on the Kyber encryption algorithm. . Then, Temporary authentication credentials can be generated, and the temporary authentication credentials include a temporary identity and authentication parameters , and to Send registration request to complete the device registration. After receiving the registration request, the authentication hash value must be calculated first , and then register the tuple by calling the Insert function Stored in blockchain nodes, and synchronized to other distributed ledgers based on consensus mechanism .

[0088] In this embodiment, during the device revocation phase, when it is detected that the device private key is leaked or the device itself needs to be eliminated, the embodiment of the present application needs to perform a device revocation operation. Equipment A cancellation request is submitted to any nearby ground control station hour, According to Directly calling the Delete operation within the smart contract framework deletes the device authentication credentials in the Hyperledger Fabric state database, while the historical transaction records related to these credentials still need to be saved in the immutable blockchain ledger, thereby eliminating the centralized revocation list maintenance inherent in the traditional PKI (Public Key Infrastructure) system while retaining the auditable proof of historical status.

[0089] Specifically, after the verification is passed, a secure session key is generated so that the first device to be communicated and the second device to be communicated can communicate data based on the secure session key. It can also include: calling an idle ground control station in the trust domain and assigning an identifier to the new device to be joined based on the registration request, and generating real identity information corresponding to the device to be joined based on the identifier and the corresponding public key to be processed, and sending the real identity information to the device to be joined for storage; using a physical unclonable function and a post-quantum cryptography standard and based on the real identity information to generate a second public-private key pair, and generating a temporary identity authentication credential including a temporary identity identifier and authentication parameters based on the second public-private key; sending the registration request including the temporary identity authentication credential to the corresponding ground control station, so that the ground control station generates a hash value based on the registration request, and uses a preset storage function to store the hash value and the registration request to the target blockchain network, and then uses a preset consensus mechanism to synchronize the corresponding blockchain ledger to the remaining devices to be communicated.

[0090] It is worth mentioning that this embodiment can simulate the adversary's attack capability based on the oracle model ROR, and prove the time by executing all defined oracle (i.e. oracle) queries. and The protocol proposed by the two participating entities is provably secure in the random oracle model, and each entity can define multiple instances or so-called oracles.

[0091] In this example, two participants and An attempt must be made to complete mutual authentication and negotiate a session key. represent No. instances, represent No. If two instances and If they directly authenticate each other and have the same session key, they are considered partners. Generate a valid session key And the partner has not been sent a Reveal query. Then he is fresh. is a function defined based on the ROR model. This query function is used to test the semantic security (indistinguishability) of the session key. The real session key can be obtained by tossing a coin based on this query or random numbers When session key generation fails or Ongoing with its partners When asked, the attacker When executing this query you will get .

[0092] In the communication model, an attacker may perform various oracle queries to simulate real attacks, where the detailed capabilities of the attacker are as follows: To give an adversary the ability to eavesdrop on all messages transmitted over the public channel between the instances of interception. To simulate an adversary active attack, including the ability to forge, tamper with, or replay transmitted messages, and return correct results when messages are received. To simulate a known session key attack, i.e., to expose the session key held by the adversary . It is worth mentioning that when and its partners are being queried, return , otherwise return the corresponding session key. To simulate an adversary who leaks the long-term key but not the previous session key. After executing this query, return its long-term key, which can be used to simulate forward security. To simulate an adversary who leaks the long-term key but not the previous session key. After executing this query, return its long-term key, which can be used to simulate forward security. To simulate an adversary who leaks the long-term key but not the previous session key. After executing this query, return its long-term key, which can be used to simulate forward security. To simulate an adversary who leaks the long-term key but not the previous session key. After executing this query, return its long-term key, which can be used to simulate forward security. To simulate an adversary who leaks the long-term key but not the previous session key. After executing this query, return its long-term key, which can be used to simulate forward security.

[0093] Subsequently, given two commutative , if there is no , the embodiments of the present application need to calculate or , where is an input random challenge and is defined as the advantage of an adversary that breaks the commutative PUF assumption.

[0094] Further, the embodiments of the present application give a uniformly randomly generated matrix , a random secret and an error vector , and obeys the binomial distribution , where is a positive integer, is a prime power, is defined in the form Polynomial rings over finite fields. When the vector When distinguishing true and uniform random is not feasible in quantum computing, and represents the probability of solving the MRLWE difficulty problem. Subsequently, the embodiment of the present application needs to determine the session key security target, and in this security definition, the embodiment of the present application allows the adversary to Guess bits through oracle queries , in order to distinguish the real session key SK from the random string when the adversary successfully guesses the bit , thereby winning the game. It is defined as the adversary in the protocol in polynomial time The advantage of winning the game if is negligible, then the protocol P is considered secure. Therefore, the advantage of the adversary in breaking the security of the session key protocol is defined as: .

[0095] In a specific embodiment, if the exchange PUF assumption holds and the RLWE (Ring Learning With Errors) problem is difficult, the protocol is secure under the ROR model. is a polynomial-time adversary of the attack scheme, then the attacker The probability of breaking the security of the session key of protocol P is described as follows:

[0096] ;in, Represents the number of hash queries, Represents the number of execute queries, Represents the number of send queries, It is a safety parameter. Indicates opponent The probability of breaking the exchange PUF assumption, represents the probability of solving the MLWE hard problem.

[0097] Among them, different games A challenger that can be used to construct algorithms that simulate descriptions and run in probabilistic polynomial time With opponents The embodiment of the present application sets the opponent to respond to a certain event in the game. The probability of winning is . Then, in each game, the adversary executes the oracle's query and obtains the correct response, and according to the Difference Lemma, unless the event Occurs, otherwise and are indistinguishable from each other. Therefore:

[0098] .

[0099] It is worth mentioning that the game Represents the actual attack model, and based on the proposed protocol semantics security definition can be characterized as:

[0100] ;

[0101] game Used to distinguish by simulating eavesdropping attacks .opponent First execute Query to capture and Communication messages between , and ,in , , and in and After the session key is negotiated between Query and Query to determine whether the returned result is a true session key or a random number.

[0102] It is worth mentioning that even if the opponent intercepts the channel and The embodiment of the present application can also make it impossible for the adversary to calculate the cloning property of BS-PUF. and ,therefore, Unable to be successfully established by the opponent.

[0103] In addition, assuming represents a swap PUF tuple. Therefore, the adversary can break and The session key between The probability of does not increase, so, .

[0104] Furthermore, games For simulation Active attack, opponent First execute Query the fake message to deceive the participants to receive the message, and then use Query checks whether a hash collision occurs. Since all exchanged messages contain a random number, it is impossible to have a collision Query does not collide, and according to the birthday paradox, the probability of collision does not exceed Therefore, .

[0105] Where the game is different from , The process of simulating the Kyber encryption algorithm to encrypt the key information of the protocol, and the game Considers two cases to distinguish . Adversary A performs Query captures The information sent to , Where In Can be uniformly randomly replaced by In Since the Kyber encryption algorithm itself is based on IND-CPA (Indistinguishability under Chosen-Plaintext Attack, i.e., Indistinguishability under Chosen-Plaintext Attack) security, the attacker cannot distinguish between real encrypted ciphertext and random ciphertext, thus breaking the MLWE problem. Similarly, Can be simulated by performing Query to send encrypted information, and the attacker cannot solve the MLWE problem. Therefore, And are indistinguishable, thus obtaining the following conclusion:

[0106] ;

[0107] In the game , assume that the exchanged PUF triplets , , Are simulated as random triplets , and the adversary Guesses the session key by simulating , and Query. In the proposed protocol, the expression of the session key is as follows:

[0108] ;

[0109] Where, , , , .

[0110] Further, due to the unclonability of PUF, it is infeasible for an adversary to and , try to violate the commutativity of PUF and successfully compute and without knowing and . Therefore, it is impossible to generate a session key without violating the commutativity assumption, and and are indistinguishable. Thus, we have: ;

[0111] It is worth mentioning that after the above all game queries are performed by the embodiment of the present application, the adversary may perform queries to guess . Therefore, .

[0112] In summary, the embodiment of the present application can obtain the following by calculation:

[0113] ;

[0114] Finally, the embodiment of the present application can conclude:

[0115] ;

[0116] In addition, the embodiment of the present application mainly meets the following 13 security goals, and the detailed description process is as follows: mutual identity authentication : according to the description of the protocol authentication process, the device can verify the legitimacy of the device by checking the equation . Wherein, , ; ; and and are messages transmitted by the device .

[0117] Further, due to , according to the commutativity of BSPUF, only the with the legitimate can make the equation hold by calculating . Thus, the above verification equation holds, successfully verifying Similarly, according to the BSPUF exchangeability characteristics, Legal equipment Able to calculate Make ,in, .

[0118] therefore, . It can also be seen from this that the equation Established, Successfully verified Therefore, the proposed protocol supports mutual authentication.

[0119] Secure session keys : In the proposed protocol, the device Can be calculated Generate session keys ,equipment Can be calculated Generate session keys , and then After analysis, the equation Established, therefore, the device and equipment Ability to negotiate a shared session key. In addition, the protocol is used to construct of and Both are protected by PUF, so the adversary cannot calculate the session key under the assumption that the PUF cannot be physically accessed. Therefore, this protocol can construct a secure session key.

[0120] Strong anonymity : In security definitions, protocols that simultaneously satisfy anonymity and unlinkability are usually defined as having strong anonymity. According to the proposed protocol, and Authentication messages can be sent separately , and , thus avoiding and Furthermore, the data stored in the blockchain Both have the cloning resistance and one-way hash protection of BSPUF, making it impossible for attackers to infer the true In addition, since the authentication process is used to build a temporary identity and Secret parameters and They are all randomly generated and independent of the session. Therefore, an attacker cannot associate the device identity with the temporary identity of different sessions. Therefore, the protocol meets strong anonymity.

[0121] Forward secrecy : Used in the protocol to generate session keys Temporary parameters of and Based on and Calculated parameters and related parameters , and These are all temporary parameters and have no direct relationship with the long-term key. Therefore, this scheme has perfect forward secrecy.

[0122] Known Session Key Security : According to the protocol design, the session key Based on secret value and Generated temporary shared parameters and and random numbers and The above parameters are unique and independent in each session. Even if it is leaked, the attacker cannot derive the keys for other sessions.

[0123] Protect against session-specific temporary secret leakage attacks : and Used to generate session password Key parameters , , and ,and , , and These temporary parameters are independent of each session. Therefore, even if an attacker intercepts these temporary parameters in one session, they cannot apply them to other sessions. and When , the attacker cannot deduce the shared parameters and , thus unable to construct the current .

[0124] Defending against privileged insider attacks : If an attacker with internal privileges can extract Stored in , but based on the unclonability of BS-PUF and , and , the attacker forges a new Information participation authentication is impossible. In addition, even if the adversary extracts the public , it is difficult for attackers to guess and ,Therefore, it is difficult for attackers to impersonate legitimate entities and establish ,communication with other entities.

[0125] Defending against simulated device attacks :If an attacker wants to impersonate a device To participate in the certification, you must pass To generate encrypted messages Furthermore, even if the attacker obtains Public key , inaccessible In this case, the attacker cannot , deducing the secret value ,in, , so the attacker cannot simulate Successful build , the corresponding ciphertext , and send the correct message pass For devices For example, an attacker cannot Successful build The decryption private key , and then decrypt get . Inaccessible Cannot build successfully under the condition , , , as well as , and thus the attacker cannot simulate Send the right message and through Therefore, the embodiment of the present application does not provide the possibility of simulating device attacks.

[0126] Protection against man-in-the-middle attacks :In the proposed protocol, Sent Contains If a middleman attempts to tamper with ,but Unable to pass Decrypt the correct , thus through Verification, because any parameter modification will result in In addition, due to , ,and , , once in the authentication process, in and and news middle Tampering will result in and Therefore, the protocol is resistant to man-in-the-middle attacks.

[0127] Resisting replay attacks :whenever and When performing a new mutual authentication operation, the parameter and They are all generated independently of the session, thus ensuring the freshness and validity of the transmitted messages. and Both are achieved by building an authentication hash and to achieve mutual authentication. Even if the attacker replays the previous and ,because , and and Already updated, and Verification fails. Therefore, this scheme can resist replay attacks.

[0128] Defense against physical attacks The overall design of the protocol relies not only on the unique exchangeability and reversibility of BSPUF, but also on the tamper-proof, unclonable, and unpredictable properties of PUF. These properties ensure that for any PUF-protected device, an attacker cannot obtain a PUF response from a known challenge, nor can they infer a PUF challenge from an available response. For example, the PUF generated during the registration phase , any calculation Attempts to physically access the PUE will be detected. Therefore, for a device protected by PUF, an attacker cannot obtain any secret parameters based on physical attacks.

[0129] Defending against modeling attacks : The protocol increases the adversary's ability to steal a large amount of data by hiding secret values ​​and dynamic challenges. To model the difficulty of PUF. Specifically, each device is based on similar operations , , secret value Through the PUF inverse function Recovered within the device, and not directly transmitted based on the PUF non-degradability, attackers cannot use public parameters Or obtain the secret value through public channels. In addition, the shared secret temporarily constructed during the authentication process and Protected by PUF and temporary parameters and Random number and The dynamic protection mechanism increases the difficulty of directly obtaining challenges and responses, thereby enhancing the ability to resist modeling attacks.

[0130] Resisting validator theft attacks :For authenticator device authenticator For example, the key and secret parameters The physical properties of BS-PUF and the reversibility assumption ensure that even if an attacker steals the identity stored secretly in the device or public parameters in the blockchain , nor can you clone or export the same and , and the temporary parameters disclosed in the blockchain Also based on PUF protection, the session key will not be leaked Generation parameters Therefore, the proposed protocol can resist validator theft attacks.

[0131] Resisting quantum attacks The protocol integrates SRAMPUF with Kyber post-quantum cryptography to generate dynamic encryption keys, providing strong protection by using encryption keys as key authentication parameters, thereby ensuring the protocol's ability to resist quantum computing attacks.

[0132] Based on the above security goals, the embodiment of the present application provides a comprehensive evaluation mechanism and compares it with the technical means in the documents [1], [2], [3], [4] and [5] to prove the effectiveness of the protocol proposed in the embodiment of the present application. Among them, the above five existing documents are:

[0133] Document [1]: Tan Y, Wang J, Liu J, et al. Blockchain-assisted distributed and lightweight authentication service for industrial unmanned aerial vehicles [J]. IEEE Internet of Things Journal, 2022, 9(18): 16928-16940.

[0134] Document [2]: Shahidinejad A, Abawajy J H. Anonymous blockchain-assisted authentication protocols for secure cross-domain IoD communications [J]. IEEE Transactions on Network Science and Engineering, 2023, 11(3): 2661-2674.

[0135] Document [3]: Zhang Y, Li B, Liu B, et al. A privacy-aware PUFs-based multiserver authentication protocol in cloud-edge IoT systems using blockchain [J]. IEEE Internet of Things Journal, 2021, 8(18): 13958-13974.

[0136] Document [4]: Huang K, Hu H, Lin C. BAKAS-UAV: A Secure Blockchain-Assisted Authentication and Key Agreement Scheme for Unmanned Aerial Vehicles Networks [J]. IEEE Internet of Things Journal, 2024.

[0137] Document [5]: Kwon D K, Son S, Park K, et al. Design of Blockchain-Based Multi-Domain Authentication Protocol for Secure EV Charging Services in V2G Environments [J]. IEEE Transactions on Intelligent Transportation Systems, 2024.

[0138] And the comparison table is shown in Table 1:

[0139] Table 1

[0140]

[0141] Table 1 is a comparison table of security properties of each protocol, which gives a comparative analysis of the security properties of the evaluated protocols. G1 is mutual authentication property; G2 is secure session key property; G3 is strong anonymity property; G4 is perfect forward secrecy property; G5 is known session key security property; G6 is resistance to temporary secret leakage attack property; G7 is resistance to privileged insider attack property; G8 is resistance to impersonation attack property; G9 is resistance to man-in-the-middle attack property; G10 is resistance to replay attack property; G11 is resistance to physical attack property; G12 is resistance to modeling attack property; G13 is resistance to verifier theft attack property; G14 is resistance to quantum attack property; G15 is dynamic device joining property.

[0142] From Table 1, it can be seen that only the protocol proposed in the embodiments of the present application can fully meet all key security requirements, including forward secrecy, secure session key establishment, and identity anonymity. In addition, the protocol of the embodiments of the present application also introduces additional security enhancements, such as resistance to modeling attacks and post-quantum encryption resilience. Notably, the solution of the embodiments of the present application is the only protocol that can mitigate quantum computing threats, thereby addressing a key gap in existing solutions. Specifically, traditional encryption protocols still face threats from physical attacks. While PUF-based protocols mitigate such threats, they introduce new vulnerabilities. Protocols [3] and [4] achieve conditional anonymity through pseudonym mapping, but their design allows GCS to track real identities, and cannot ensure complete anonymity. Protocol [5] provides strong anonymity, but it lacks the ability to resist quantum attacks. In addition, all these solutions rely on computationally intensive operations based on ECC, which are vulnerable to quantum computing attacks, and therefore are not suitable for high-security scenarios. In contrast, inspired by BSPUF, the protocol of the embodiments of the present application utilizes the commutativity and reversibility of BSPUF to establish a lightweight authentication framework, eliminating the computationally intensive operations of ECC or bilinear pairings. In addition, the solution of the embodiments of the present application is the only one that introduces a Kyber post-quantum encryption and dynamic device registration mechanism in the authentication framework. This flexible design not only mitigates the threat of quantum attacks, but also greatly improves the practical adaptability of the protocol. Therefore, the protocol of the embodiments of the present application emerges as a new security enhancement solution, which realizes lightweight authentication, strong anonymity, resistance to quantum encryption, and flexible cross-domain interoperability, and solves the multi-faceted security needs of modern device networks.

[0143] Specifically, after the verification passes to generate a secure session key, so that the first to be communicated device and the second to be communicated device based on the secure session key for data communication, it can also include: defining the query ability of the attacker by using the random oracle model; the query ability includes the query ability of eavesdropping communication messages, the query ability of forging tampered messages, the query ability of leaking session keys, the query ability of leaking long-term keys, and the query ability of accessing hash functions; build a progressive security game sequence including initial security game and subsequent security game; wherein, the initial security game is used to simulate the actual attack scene, and the subsequent security game includes simulating eavesdropping attack, active attack, encryption algorithm attack and physical unclonable function exchange attack; in the initial security game, the semantic security of the session key is defined as the attacker cannot distinguish between the real key and the random string, and in the first security game simulating eavesdropping attack, the unclonable property of physical unclonable function is configured; the unclonable property is used to prevent the attacker from constructing an effective session key under the condition of intercepting communication parameters; in the second security game simulating active attack, the uniqueness of random number and the birthday paradox principle are configured to ignore the hash collision probability, and in the third security game simulating encryption attack, the indistinguishable security of post-quantum encryption algorithm is configured, and then in the fourth security game simulating exchange attack, the computational infeasibility of exchangeable physical unclonable function is configured; the computational infeasibility is used to prevent the attacker from forging the generation parameters of the session key.

[0144] As can be seen from the above, before the device cross-domain communication, the ground control station initialization parameter information needs to be called, and the initial block chain network with smart contract algorithm and the block chain account book corresponding to the initial block chain network are constructed based on the parameter information; then, the real identity information of the ground control station is determined, and the real identity information is stored in each to-be-communicated device equipped with a physical unclonable function, and each to-be-communicated device is stored in each trust domain of the initial block chain network, to obtain a target block chain network; further, the ground control station in the to-be-communicated device is called, and the public and private key pair is generated by using the post-quantum cryptography standard and the physical unclonable function, and the registration request is sent to the preset registration server in the corresponding trust domain based on the public and private key pair, to obtain a registration authentication credential, and then the registration authentication credential is stored in the target block chain network; finally, when the first to-be-communicated device issues an identity verification request to the second to-be-communicated device, the target block chain network is called and the identity verification request and the corresponding registration authentication credential are verified by using the preset three-way handshake mechanism, and a secure session key is generated after the verification passes, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key and the block chain account book. In this way, the security of the device cross-domain communication is improved, and the user experience is improved.

[0145] Correspondingly, referring to Figure 8As shown, the application also provides a device cross-domain communication apparatus, comprising:

[0146] a blockchain ledger construction module 11, configured to call ground control station initialization parameter information, and construct an initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network based on the parameter information; the smart contract algorithm is an algorithm for adding, deleting, modifying and inquiring information in the initial blockchain network;

[0147] a blockchain network construction module 12, configured to determine real identity information of a to-be-communicated device in the ground control station by using a master key corresponding to the ground control station, store the real identity information to each to-be-communicated device equipped with a physically unclonable function, and then allocate each to-be-communicated device to each trust domain in the initial blockchain network to obtain a target blockchain network;

[0148] a registration authentication credential determination module 13, configured to call a physically unclonable chip in the to-be-communicated device and generate a public-private key pair by using a post-quantum cryptography standard, send a registration request to a ground control station in a corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, and synchronize the registration authentication credential to the target blockchain network and the blockchain ledger by the ground control station;

[0149] a secure session key determination module 14, configured to call the target blockchain network and verify an identity verification request and a corresponding registration authentication credential by using a preset three-way handshake mechanism when a first to-be-communicated device issues the identity verification request to a second to-be-communicated device, and generate a secure session key after verification, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key; the trust domains corresponding to the first to-be-communicated device and the second to-be-communicated device are different.

[0150] From the above, before the device cross-domain communication is performed, the ground control station initialization parameter information needs to be called, and the initial blockchain network with the smart contract algorithm is constructed based on the parameter information and the blockchain ledger corresponding to the initial blockchain network; then, the real identity information of the ground control station is determined, and the real identity information is stored in each to-be-communicated device equipped with a physically unclonable function, and each to-be-communicated device is stored in each trust domain of the initial blockchain network, to obtain a target blockchain network; further, the ground control station in the to-be-communicated device is called, and a public-private key pair is generated by using the post-quantum cryptography standard and the physically unclonable function, and a registration request is sent to a preset registration server in the corresponding trust domain based on the public-private key pair, to obtain a registration authentication credential, and then the registration authentication credential is stored in the target blockchain network; finally, when a first to-be-communicated device issues an identity verification request to a second to-be-communicated device, the target blockchain network is called and the identity verification request and the corresponding registration authentication credential are verified by using a preset three-way handshake mechanism, and a secure session key is generated after the verification is passed, so that the first to-be-communicated device and the second to-be-communicated device perform data communication based on the secure session key and the blockchain ledger. In this way, the security of the device cross-domain communication is improved, and the user experience is improved.

[0151] In some specific embodiments, the blockchain ledger construction module 11 can specifically include:

[0152] A main key determination unit is configured to call the ground control station to publicly disclose parameter information including a polynomial ring, a random sampling function, a distribution sampling function and a cryptography hash function, and then determine a main key corresponding to the ground control station based on a physically unclonable function and a preset key pool; the main key is used to determine real identity information corresponding to the to-be-communicated device;

[0153] A blockchain ledger construction unit is configured to construct an initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network based on the parameter information; wherein the initial blockchain network includes a plurality of trust domains corresponding to the ground control station; each of the trust domains includes a peer node and an ordering node; and the blockchain ledger is used to record credential information for device authentication between each of the to-be-communicated devices in the initial blockchain network.

[0154] In some specific embodiments, the blockchain network construction module 12 can specifically include:

[0155] A real identity information determination unit is configured to determine a main key corresponding to the ground control station, and then determine real identity information corresponding to each to-be-communicated device in the ground control station by using the main key;

[0156] The blockchain network construction subunit is configured to deploy a physically unclonable chip to each of the to-be-communicated devices, store the real identity information in each of the to-be-communicated devices, and assign each of the to-be-communicated devices to each trust domain in the initial blockchain network to obtain a target blockchain network; the preset channel is connected between each of the ground control stations; the physically unclonable chip has the characteristics of data exchange and reversible encryption;

[0157] The blockchain address determination unit is configured to determine a hash encryption value corresponding to the ground control station based on the real identity information by using a preset hash encryption function, and set the hash encryption value as a blockchain address corresponding to the ground control station, so as to perform insertion operation, update operation, query operation and deletion operation on the target blockchain network based on the smart contract algorithm and the blockchain address.

[0158] In some embodiments, the registration authentication credential determination module 13 can specifically include:

[0159] The lattice matrix generation unit is configured to generate a random encryption seed based on a preset encryption algorithm and a post-quantum cryptography standard by using the physically unclonable chip in the to-be-communicated device, and then generate a lattice matrix based on the random encryption seed by using a preset uniform sampling function;

[0160] The public-private key pair generation unit is configured to generate a public-private key pair including a public key and a private key based on the distributed sampling function and the lattice matrix, and then generate temporary identity information and a response parameter corresponding to the to-be-communicated device based on the real identity information by using a binary sequence physically unclonable chip in the to-be-communicated device;

[0161] The hash value generation unit is configured to, after a preset registration server in the trust domain receives a registration request issued by the to-be-communicated device, call the preset registration server to judge the validity of the registration request, and if the obtained judgment result represents that the registration request is valid, generate a hash value based on the registration request;

[0162] The registration authentication credential uploading unit is configured to determine a registration authentication credential based on the hash value, the public-private key pair, the temporary identity information and the response parameter, and upload the registration authentication credential to the target blockchain network and the blockchain ledger by using the smart contract algorithm and the public-private key pair.

[0163] In some embodiments, the secure session key determination module 14 can specifically include:

[0164] The extraction parameter generation unit is configured to call the first to-be-communicated device and generate corresponding extraction parameters based on the corresponding first real identity when the first to-be-communicated device issues an identity authentication request to the second to-be-communicated device, to obtain corresponding first public keys, first temporary identity information, first response parameters, and first hash values from the target blockchain network based on the extraction parameters, and to generate first secret parameters based on the first public keys and the first temporary identity information;

[0165] The secret parameter generation unit is configured to call the first to-be-communicated device and obtain corresponding second public keys, second temporary identity information, second response parameters, and second hash values from the target blockchain based on the second real identity corresponding to the second to-be-communicated device, and to generate second secret parameters based on the second public keys and the second temporary identity information.

[0166] The verification information determination unit is configured to determine first verification information based on the first public keys, the first temporary identity information, the first response parameters, the first hash values, and the first secret parameters, and to determine second verification information based on the second public keys, the second temporary identity information, the second response parameters, the second hash values, and the second secret parameters.

[0167] The parameter information issuance unit is configured to verify the first verification information and the second verification information, and if the verification is passed, the information in the target blockchain network has not been tampered with, and to call the corresponding physically unclonable chip and random number to construct encryption information and verification parameters, and then issue parameter information including the encryption information and the verification parameters to the second to-be-communicated device.

[0168] The encryption information decryption unit is configured to, after the second to-be-communicated device receives the parameter information, call the second to-be-communicated device to calculate a third hash value based on the parameter information and the second temporary identity information, to generate a post-quantum private key based on the third hash value, to decrypt the encryption information using the post-quantum private key, to obtain a decrypted secret value, a decrypted random number, and a to-be-verified temporary identity.

[0169] The authentication response information determination unit is configured to obtain the registration authentication credential of the first to-be-communicated device from the target blockchain network based on the to-be-verified temporary identity, to perform consistency verification on the registration authentication credential, and to return authentication response information including a secure session key to the first to-be-communicated device after the verification is passed.

[0170] In some specific embodiments, the device cross-domain communication apparatus can further include:

[0171] a real identity information storage unit, configured to invoke a ground control station in an idle trust domain, and allocate an identifier for a new device to be joined based on the registration request, and generate real identity information corresponding to the device to be joined based on the identifier and a corresponding to-be-processed public key, and issue the real identity information to the device to be joined for storage;

[0172] an identity authentication credential generation unit, configured to generate a second public-private key pair based on the real identity information and by using the physically unclonable function and the post-quantum cryptography standard, and generate a temporary identity authentication credential including a temporary identity identifier and an authentication parameter based on the second public-private key pair;

[0173] a blockchain ledger synchronization unit, configured to issue a registration request including the temporary identity authentication credential to a corresponding ground control station, so that the ground control station generates a hash value based on the registration request, and stores the hash value and the registration request to the target blockchain network by using a preset storage function, and then synchronizes a corresponding blockchain ledger to the remaining to-be-communicated devices by using a preset consensus mechanism.

[0174] In some embodiments, the device cross-domain communication apparatus can further include:

[0175] a query capability determination unit, configured to define query capabilities of an attacker by using a random oracle model; the query capabilities include a query capability of eavesdropping a communication message, a query capability of falsifying and tampering a message, a query capability of leaking a session key, a query capability of leaking a long-term key, and a query capability of accessing a hash function;

[0176] a game sequence determination unit, configured to construct a progressive security game sequence including an initial security game and subsequent security games; the initial security game is used to simulate an actual attack scenario, and the subsequent security games include a simulation of an eavesdropping attack, an active attack, an encryption algorithm attack, and a physically unclonable function exchangeability attack;

[0177] a semantic security definition unit, configured to define semantic security of a session key as that an attacker cannot distinguish a real key from a random string in the initial security game, and configure an unclonable feature of the physically unclonable function in a first security game simulating an eavesdropping attack; the unclonable feature is used to prevent the attacker from constructing an effective session key under the condition of intercepting a communication parameter;

[0178] The computing infeasibility determination unit is configured with the uniqueness of random numbers and the birthday paradox principle in the second secure game simulating active attacks to ignore the hash collision probability, and is configured with the indistinguishable security of post-quantum encryption algorithms in the third secure game simulating encryption attacks, and then is configured with the computing infeasibility of the commutative physically unclonable function in the fourth secure game simulating commutativity attacks; the computing infeasibility is used to prevent the attacker from counterfeiting the generation parameters of the session key.

[0179] Further, the embodiment of the application further discloses an electronic device, Figure 9 is an electronic device 20 structure diagram shown according to an exemplary embodiment, the contents in the figure cannot be considered as any limitation on the use range of the application. The electronic device 20, specifically can include: at least one processor 21, at least one memory 22, power supply 23, communication interface 24, input output interface 25 and communication bus 26. Wherein, the memory 22 is used to store computer program, the computer program is loaded and executed by the processor 21, to realize the related steps in the device cross-domain communication method disclosed in any preceding embodiment. In addition, the electronic device 20 in the embodiment can be an electronic computer.

[0180] In the embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the application, which is not limited specifically herein; the input output interface 25 is used to obtain external input data or output data to the outside world, and the specific interface type can be selected according to the specific application needs, which is not limited specifically herein.

[0181] In addition, the memory 22 as the carrier of resource storage can be read-only memory, random access memory, disk or optical disk, etc., and the resources stored thereon can include operating system 221, computer program 222, etc., and the storage mode can be temporary storage or permanent storage.

[0182] Wherein, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, and can be Windows Server, Netware, Unix, Linux, etc. The computer program 222 can further include computer programs capable of completing other specific work in addition to the computer programs capable of completing the device cross-domain communication method executed by the electronic device 20 disclosed in any preceding embodiment.

[0183] Further, the present application also discloses a computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to implement the device cross-domain communication method disclosed above. For the specific steps of the method, refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.

[0184] The various embodiments described in the specification are progressive in nature, and each embodiment highlights the differences from other embodiments. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts refer to the method part.

[0185] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in general terms in the foregoing description. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0186] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0187] Finally, it should be noted that, in this document, relationship terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0188] The technical solutions provided by the present application are described in detail above, and the principles and implementation manners of the present application are described by using specific examples. The above description of the examples is only used to help understand the method of the present application and its core idea; meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges will be changed, and the above description of the content of the specification should not be understood as a limitation on the present application.

Claims

1. A device cross-domain communication method, characterized in that: include: Calling the ground control station to initialize parameter information, and constructing an initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network based on the parameter information; the smart contract algorithm is an algorithm for adding, deleting, modifying and checking information in the initial blockchain network; Using the master key corresponding to the ground control station, determining the real identity information of the device to be communicated in the ground control station, and storing the real identity information in each of the devices to be communicated equipped with a physical unclonable function, and then assigning each of the devices to be communicated to each trust domain in the initial blockchain network to obtain a target blockchain network; Invoking the physical unclonable chip in the communication device and generating a public-private key pair using the post-quantum cryptography standard, and then sending a registration request based on the public-private key pair to a ground control station in the corresponding trust domain to obtain a registration authentication credential, so that the ground control station synchronizes the registration authentication credential to the target blockchain network and the blockchain ledger; When the first device to be communicated issues an identity authentication request to the second device to be communicated, the target blockchain network is called and the preset three-way handshake mechanism is used to verify the identity authentication request and the corresponding registration authentication credential, and a secure session key is generated after the verification is passed, so that the first device to be communicated and the second device to be communicated can communicate data based on the secure session key; The first device to communicate and the second device to communicate correspond to different trust domains.

2. The device cross-domain communication method according to claim 1, characterized in that: The calling of the ground control station to initialize parameter information, and constructing an initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network based on the parameter information, includes: The ground control station is called to disclose parameter information including a polynomial ring, a random sampling function, a distributed sampling function, and a cryptographic hash function, and then a master key corresponding to the ground control station is determined based on a physical unclonable function and a preset key pool; the master key is used to determine the real identity information corresponding to the device to be communicated; An initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network are constructed based on the parameter information; wherein the initial blockchain network includes several trust domains corresponding to the ground control stations; each of the trust domains includes peer nodes and sorting nodes; and the blockchain ledger is used to record credential information for device authentication between each of the devices to be communicated in the initial blockchain network.

3. The device cross-domain communication method according to claim 2, characterized in that: The method of determining the real identity information of the device to be communicated in the ground control station by using the master key corresponding to the ground control station, storing the real identity information in each device to be communicated equipped with a physical unclonable function, and then assigning each device to be communicated to each trust domain in the initial blockchain network to obtain a target blockchain network includes: Determine a master key corresponding to the ground control station, and then use the master key to determine the real identity information corresponding to each of the devices to be communicated in the ground control station; Deploying a physical unclonable chip to each device to be communicated with, storing the real identity information in each device to be communicated with, and assigning each device to be communicated with to a trust domain in the initial blockchain network to obtain a target blockchain network; a preset channel is connected between each ground control station; the physical unclonable chip has data exchange and reversible encryption characteristics; A preset hash encryption function is used and a hash encryption value corresponding to the ground control station is determined based on the real identity information, and the hash encryption value is set as a blockchain address corresponding to the ground control station, so as to perform insert operations, update operations, query operations and delete operations on the target blockchain network based on the smart contract algorithm and the blockchain address.

4. The device cross-domain communication method according to claim 3, characterized in that: The calling of the physical unclonable chip in the communication device and generating a public-private key pair using the post-quantum cryptography standard, and then sending a registration request to a ground control station in the corresponding trust domain based on the public-private key pair to obtain a registration authentication credential, so that the ground control station synchronizes the registration authentication credential to the target blockchain network and the blockchain ledger, includes: Using the physical unclonable chip in the communication device and based on a preset encryption algorithm and a post-quantum cryptography standard to generate a random encryption seed, and then using a preset uniform sampling function and based on the random encryption seed to generate a lattice matrix; generating a public-private key pair including a public key and a private key based on the distribution sampling function and the lattice matrix, and then generating temporary identity information and response parameters corresponding to the device to be communicated based on the real identity information using a binary sequence physical unclonable chip in the device to be communicated; After receiving the registration request sent by the communication device, the preset registration server in the trust domain calls the preset registration server to perform validity judgment on the registration request, and if the judgment result indicates that the registration request is valid, generates a hash value based on the registration request; Determine the registration authentication credential based on the hash value, the public-private key pair, the temporary identity information and the response parameter, and call the smart contract algorithm and the public-private key pair to upload the registration authentication credential to the target blockchain network and the blockchain ledger.

5. The device cross-domain communication method according to claim 1, characterized in that: When the first device to be communicated issues an identity authentication request to the second device to be communicated, the target blockchain network is called and a preset three-way handshake mechanism is used to verify the identity authentication request and the corresponding registration authentication credential, and a secure session key is generated after the verification is successful, including: When the first device to be communicated issues an identity authentication request to the second device to be communicated, the first device to be communicated is called and a corresponding extraction parameter is generated based on the corresponding first real identity identifier, so as to obtain the corresponding first public key, first temporary identity information, first response parameter, and first hash value from the target blockchain network based on the extraction parameter, and a first secret parameter is generated based on the first public key and the first temporary identity information; Invoking the first device to communicate and obtaining a corresponding second public key, second temporary identity information, second response parameter, and second hash value from the target blockchain based on a second real identity identifier corresponding to the second device to communicate, and generating a second secret parameter based on the second public key and the second temporary identity information; Determine first verification information based on the first public key, the first temporary identity information, the first response parameter, the first hash value, and the first secret parameter, and determine second verification information based on the second public key, the second temporary identity information, the second response parameter, the second hash value, and the second secret parameter; Verifying the first verification information and the second verification information; if the verification passes, the information in the target blockchain network has not been tampered with; and calling the corresponding physical unclonable chip and random number to construct encryption information and verification parameters, and then sending parameter information including the encryption information and the verification parameters to the second communication device; After the second communication device receives the parameter information, calling the second communication device to calculate a third hash value based on the parameter information and the second temporary identity information, generating a post-quantum private key based on the third hash value, and decrypting the encrypted information using the post-quantum private key to obtain a decrypted secret value, a decrypted random number, and a temporary identity to be verified; Based on the temporary identity to be verified, the registration authentication credentials of the first device to be communicated are obtained from the target blockchain network, and the consistency of the registration authentication credentials is verified. After the verification is passed, authentication response information including the secure session key is returned to the first device to be communicated.

6. The device cross-domain communication method according to claim 1, characterized in that: After the secure session key is generated after the verification is passed, so that the first device to communicate and the second device to communicate perform data communication based on the secure session key, the method further includes: Invoke a ground control station in an idle trust domain and assign an identifier to the new device to be added based on the registration request, generate real identity information corresponding to the device to be added based on the identifier and the corresponding public key to be processed, and send the real identity information to the device to be added for storage; Generate a second public-private key pair based on the real identity information using the physical unclonable function and the post-quantum cryptography standard, and generate a temporary identity authentication credential including a temporary identity identifier and authentication parameters based on the second public-private key pair; A registration request including the temporary authentication credentials is sent to the corresponding ground control station so that the ground control station generates a hash value based on the registration request, and uses a preset storage function to store the hash value and the registration request to the target blockchain network, and then uses a preset consensus mechanism to synchronize the corresponding blockchain ledger to the remaining devices to be communicated.

7. The device cross-domain communication method according to any one of claims 1 to 6, characterized in that: After the secure session key is generated after the verification is passed, so that the first device to communicate and the second device to communicate perform data communication based on the secure session key, the method further includes: The attacker's query capabilities are defined using a random oracle model; the query capabilities include the ability to eavesdrop on communication messages, the ability to forge and tamper with messages, the ability to leak session keys, the ability to leak long-term keys, and the ability to access hash functions. Constructing a progressive security game sequence including an initial security game and subsequent security games; wherein the initial security game is used to simulate actual attack scenarios, and the subsequent security games include simulated eavesdropping attacks, active attacks, encryption algorithm attacks, and physical unclonable function commutativity attacks; In the initial security game, the semantic security of the session key is defined as an attacker being unable to distinguish between a real key and a random string, and the uncloning property of the physical uncloning function is configured in the first security game simulating an eavesdropping attack; the uncloning property is used to prevent the attacker from being unable to construct a valid session key under the condition of intercepting communication parameters; In the second security game simulating active attacks, the uniqueness of random numbers and the birthday paradox principle are configured to ignore the probability of hash collisions, and in the third security game simulating encryption attacks, the indistinguishability security of the post-quantum encryption algorithm is configured. Then, in the fourth security game simulating commutative attacks, the computational infeasibility of the commutative physical unclonable function is configured; the computational infeasibility is used to prevent the attacker from forging the generation parameters of the session key.

8. A device cross-domain communication apparatus, characterized in that: include: A blockchain ledger construction module is configured to call the ground control station to initialize parameter information and, based on the parameter information, construct an initial blockchain network with a smart contract algorithm and a blockchain ledger corresponding to the initial blockchain network; the smart contract algorithm is an algorithm for adding, deleting, modifying, and checking information in the initial blockchain network; a blockchain network construction module, configured to determine the true identity information of the devices to be communicated in the ground control station using the master key corresponding to the ground control station, store the true identity information in each of the devices to be communicated equipped with a physical unclonable function, and then assign each of the devices to be communicated to each trust domain in the initial blockchain network to obtain a target blockchain network; a registration authentication credential determination module, configured to call a physical unclonable chip in the communication device and generate a public-private key pair using a post-quantum cryptography standard, and then send a registration request based on the public-private key pair to a ground control station in a corresponding trust domain to obtain a registration authentication credential, so that the ground control station synchronizes the registration authentication credential to the target blockchain network and the blockchain ledger; a secure session key determination module, configured to, when a first device to communicate issues an identity authentication request to a second device to communicate, invoke the target blockchain network and verify the identity authentication request and the corresponding registration authentication credential using a preset three-way handshake mechanism, and generate a secure session key after the verification is successful, so that the first device to communicate and the second device to communicate can communicate data based on the secure session key; The first device to communicate and the second device to communicate correspond to different trust domains.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the device cross-domain communication method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that Used to store a computer program, wherein when the computer program is executed by a processor, the device cross-domain communication method according to any one of claims 1 to 7 is implemented.