System and method for authentication of a communication peer based on a shared key
By configuring and interacting with the peer authentication system of shared key communication to generate SPA extension items, and by using efficiency monitoring and validity analysis modules to optimize the verification process, the problems of high hash calculation time and insufficient resources are solved, thus improving authentication efficiency and security and adapting to diverse authentication needs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CSC FINANCIAL CO LTD
- Filing Date
- 2025-10-30
- Publication Date
- 2026-04-28
AI Technical Summary
In existing peer authentication technologies based on shared keys, hash calculations are time-consuming, shared key caching is insufficient, resource reclamation threads are few, and cross-domain transmission delays and timeout settings at edge nodes are unreasonable, resulting in insufficient matching efficiency and low verification effectiveness of SPA extension items.
A communication peer authentication system and method based on shared keys is provided. The system pre-configures the shared key and generates SPA extension items through the configuration and interaction module. Combined with the efficiency monitoring module and the validity analysis module, the system monitors and analyzes the verification process parameters in real time, optimizes caching and resource reclamation, and improves the verification efficiency and validity.
It comprehensively improves the security, efficiency, and reliability of peer authentication, reduces vulnerabilities and delays in the authentication process, ensures the smoothness and accuracy of authentication, and adapts to diverse authentication needs.
Smart Images

Figure CN121037121B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of key communication technology, specifically to a communication peer authentication system and method based on shared keys. Background Technology
[0002] Existing technologies for peer authentication based on shared keys primarily verify identity through a key pre-shared by both communicating parties. Common protocols and methods include: PAP, which transmits passwords in plaintext and has low security; CHAP, which employs a challenge-response mechanism and hash algorithms such as MD5; EAP-MD5, which is similar to CHAP and commonly used for wireless network authentication; the Kerberos protocol, which introduces ticket and ticket granting services and supports two-way authentication; and authentication methods that rely on a key distribution center (KDC), where the KDC and both communicating parties share keys and transmit session keys through encrypted messages to achieve authentication. These technologies are mostly based on challenge-response mechanisms or rely on third-party key management institutions to complete identity verification.
[0003] For example, Chinese invention patent CN116684093B discloses an identity authentication and key exchange method and system. The method includes receiving first verification information sent by the communication initiator, and querying the information of the first QKD node and the second QKD node after the first verification information is verified; sending a first authentication request to the first QKD node, so that the first QKD node generates a session key in the first QKD node and the second QKD node after verifying the first authentication request; receiving a key distribution session message carrying the identifier of the session key sent by the first QKD node, and forwarding it to the second QKD node; when the second QKD node has a session key corresponding to the identifier of the session key, receiving the identifier of the session key sent by the second QKD node and forwarding the identifier of the session key to the communication initiator so that the communication initiator can apply for a session key from the first QKD node with the identifier of the session key.
[0004] For example, Chinese invention patent CN115913521B discloses a method for identity authentication based on quantum keys. During identity authentication and data transmission, the shared key used for message verification is obtained from a quantum key distribution network. During authentication, the shared quantum key is used to calculate the verification code of the authentication message transmitted by both parties. The identity of the other party and the integrity of the transmitted data are verified by identifying the message verification code. The shared quantum key is cleared after use, and a new key is selected for the next communication. This reduces the complexity of pre-set shared keys, shortens the update cycle of shared quantum keys, and improves key security.
[0005] However, in the process of implementing the embodiments of this application, it was found that the above-mentioned technology has at least the following technical problems: due to the high time consumption of hash calculation, insufficient shared key caching, few resource recycling threads, and unreasonable cross-domain transmission delay and timeout settings of edge nodes, the matching efficiency of SPA extension items is insufficient; due to the asymmetry of client and server verification rules and the lack of overlap in key updates, matching failure occurs, resulting in low verification effectiveness. Summary of the Invention
[0006] To address the technical problems of insufficient matching efficiency and low verification effectiveness of SPA extension items in existing technologies, this invention provides a communication peer authentication system and method based on shared keys. The technical solution is as follows:
[0007] On the one hand, a communication peer authentication system based on shared keys is provided. This system includes: a configuration and interaction module, used for pre-configuring shared keys between the client and server, and generating SPA extension items to assist in communication peer authentication. The client sends the SPA extension item to the server to initiate a communication peer authentication request based on the initial key update overlap period. Upon receiving the client's SPA extension item, the server verifies its validity to complete the client's identity verification. An efficiency monitoring module is used to monitor and analyze the process parameters of the server verifying the validity of the client's SPA extension item in real time, thereby determining whether the efficiency of the server's verification of the client's SPA extension item meets the standard. An effectiveness analysis module is used to collect and parse the result parameters of the server's verification of the client's SPA extension item, thereby determining whether the effectiveness of the server's verification of the client's SPA extension item meets the standard.
[0008] On the other hand, a shared-key-based peer authentication method is provided. This method is applied to a shared-key-based peer authentication system and includes the following steps: Step 1: The client and server pre-configure a shared key and generate a Single-Item Extension (SPA) for assisting peer authentication. The client sends the SPA stub to the server to initiate a peer authentication request based on the initial key update overlap period. After receiving the client's SPA stub, the server verifies its validity to confirm the client's identity. Step 2: The process parameters of the server verifying the validity of the client's SPA stub are monitored and analyzed in real time to determine whether the efficiency of the server in verifying the validity of the client's SPA stub meets the standard. Step 3: The result parameters of the server verifying the validity of the client's SPA stub are collected and parsed to determine whether the effectiveness of the server in verifying the validity of the client's SPA stub meets the standard.
[0009] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following:
[0010] (1) This invention provides a communication peer authentication system and method based on shared keys. Through the coordinated operation of three modules, it comprehensively improves the security, efficiency and reliability of communication peer authentication. The system is based on shared keys and combines SPA extensions to realize authentication. At the same time, by monitoring efficiency and analyzing effectiveness in real time, it forms a complete closed loop from authentication initiation, process optimization to result guarantee, providing all-round support for secure interaction between the two communicating parties.
[0011] (2) The configuration and interaction module, as the core of the system, lays a secure foundation for identity authentication by pre-configuring the shared key and generating SPA extension items. The client initiates an authentication request based on the initial key update overlap period, and the server completes identity verification by verifying the legality of the SPA extension items. This process standardizes the authentication initiation and verification process, reduces vulnerabilities in the authentication process, and ensures the initial security and smoothness of identity authentication.
[0012] (3) The efficiency monitoring module can promptly determine whether the verification efficiency meets the standard by monitoring and analyzing the process parameters of the server-side verification of the legality of SPA extension items in real time. This function can quickly identify efficiency bottlenecks, provide a basis for subsequent optimization and adjustment, avoid communication delays or congestion caused by low verification efficiency, effectively improve the response speed and operating efficiency of the entire identity authentication process, and ensure that the authentication process is efficient and stable.
[0013] (4) The validity analysis module focuses on collecting and parsing the verification result parameters to determine whether the validity of the verification meets the standards. It can accurately assess the reliability of the authentication results, promptly detect potential security risks or misjudgments in the verification process, ensure the accuracy of the server's confirmation of the client's identity, and further enhance the security and credibility of identity authentication. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This is a schematic diagram of the structure of a communication peer identity system based on a shared key, provided in an embodiment of the present invention.
[0016] Figure 2 This is a flowchart of a communication peer authentication method based on a shared key, provided by an embodiment of the present invention.
[0017] Figure 3This is a flowchart illustrating the handshake protocol between the client and server provided in this embodiment of the invention.
[0018] Figure 4 This is a schematic diagram of the identity authentication process provided in an embodiment of the present invention;
[0019] Figure 5 This is a diagram of the status monitoring interface in the key authentication system provided in this embodiment of the invention;
[0020] Figure 6 This is a diagram of the key management interface in the key authentication system provided in this embodiment of the invention. Detailed Implementation
[0021] The technical solution of the present invention will now be described with reference to the accompanying drawings.
[0022] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.
[0023] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0024] Reference Figure 1 As shown, this embodiment of the invention provides a communication peer authentication system based on a shared key. The system includes: a configuration and interaction module, an efficiency monitoring module, an effectiveness analysis module, and a communication database.
[0025] The configuration and interaction module is connected to the efficiency monitoring module, which in turn is connected to the validity analysis module. All three modules—configuration and interaction module, efficiency monitoring module, and validity analysis module—are connected to the communication database. This communication database is used to store various parameters involved in the communication peer authentication system based on shared keys.
[0026] The configuration and interaction module is used for pre-configuring shared keys on the client and server sides and generating SPA extension items to assist in peer authentication. Based on the initial key update overlap period, the client sends the SPA extension item to the server to initiate a peer authentication request. After receiving the client's SPA extension item, the server verifies its validity to complete the client's identity confirmation. The efficiency monitoring module is used to monitor and analyze the process parameters of the server verifying the validity of the client's SPA extension item in real time, thereby determining whether the efficiency of the server in verifying the validity of the client's SPA extension item meets the standard. The validity analysis module is used to collect and parse the result parameters of the server in verifying the validity of the client's SPA extension item, thereby determining whether the validity of the server in verifying the validity of the client's SPA extension item meets the standard.
[0027] Authentication is achieved by adding a Simple Peer Authentication (SPA) extension between the client and server. The pre-configured shared key refers to a default shared key pre-set on both the client and server sides as the basis for authentication. Specifically, the client and server place a default 16-byte binary shared key, which can be generated through security firmware or system parameters. If needed, extensible cryptographic functions (e.g., key-based hash functions) are supported to meet different authentication requirements. The SPA extension contains a hash value of the following information: SHA256([Client Hello|Server Hello].random||external shared key||built-in shared key), taking the first 16 bytes.
[0028] The SHA256 hash function is a commonly used cryptographic hash function that can convert input data of arbitrary length into a fixed-length (256-bit) hash value. It is irreversible and unique, and is used to generate verification information in the SPA extension. The Client Hello is the first message sent by the client when initiating communication with the server, containing information such as the protocol version and cipher suite supported by the client. The Server Hello is the reply message from the server after receiving the Client Hello, containing information such as the protocol version and cipher suite agreed upon by both parties. The random number represents the random number contained in each Client Hello and Server Hello message, used to increase the uniqueness of each communication and prevent replay attacks. The "||" in cryptography represents a data concatenation operation, which is to connect multiple data fragments in sequence into a complete data block (in this case, concatenating the random number in the Client Hello / Server Hello, the external shared key, and the internal shared key).
[0029] When the client sends the Client Hello packet, it appends an SPA extension containing a pre-configured shared key and an external shared key. After receiving the SPA extension from the client, the server verifies its validity using a hash function. At the same time, the server generates a new SPA extension, appends it to the Server Hello packet, and sends it to the client.
[0030] External shared keys are specified via configuration files or command-line arguments. Default values should be kept confidential and set according to the organization's security policy. Additionally, other authentication mechanisms (such as digital certificate stores, lifecycle-based key management, etc.) can be optionally added to enhance authentication resilience.
[0031] Specifically, the process for determining whether the efficiency of the server in verifying the legality of client-side SPA extensions meets the standard is as follows: First, by analyzing the process parameters of the server in verifying the legality of client-side SPA extensions, the SPA extension verification efficiency index is obtained and compared with the preset SPA extension verification efficiency threshold in the communication database; the aforementioned SPA extension verification efficiency threshold refers to the minimum value of the SPA extension verification efficiency index within the specified range.
[0032] When the SPA extension item verification efficiency index is not lower than the SPA extension item verification efficiency threshold, it is determined that the server's efficiency in verifying the legality of the client's SPA extension item meets the standard. At this time, a lightweight secondary verification mechanism is triggered simultaneously. The aforementioned lightweight secondary verification mechanism refers to re-checking only the key identification information, hash value digest, or core verification fields in the extension item. This avoids omissions or potential risks that may exist due to a single verification, and does not significantly increase the processing burden on the server. Thus, a balance is achieved between efficiency and security, ensuring that the possibility of misjudgment or malicious bypass of verification is further reduced on the basis of efficient verification.
[0033] When the SPA extension item verification efficiency index is lower than the SPA extension item verification efficiency threshold, it is determined that the server's efficiency in verifying the legality of the client's SPA extension items is substandard. Based on the SPA extension item verification efficiency index and the SPA extension item verification efficiency threshold, a verification efficiency deviation value is obtained. Based on the verification efficiency deviation value, dual optimization is performed: on the one hand, the cache capacity increase coefficient is matched based on the verification efficiency deviation value to expand the server's SPA extension item cache space. The expanded cache space can store more frequently used SPA extension item verification information, reducing the situation where the server frequently performs repeated calculations or database queries due to cache missing information, and reducing the data reading latency during the verification process. When the client sends the same or similar SPA extension items again, the server can directly and quickly retrieve the data required for verification from the cache, significantly shortening the response time of a single verification, reducing efficiency losses caused by repeated data loading, and rapidly increasing the verification processing volume per unit time, thereby effectively improving the SPA extension item verification efficiency index. On the other hand, the server improves its resource recycling capabilities by matching the increase in the number of resource recycling threads based on the verification efficiency deviation value. More resource recycling threads can speed up the cleanup of invalid, expired, or redundant SPA extension item verification-related resources (such as abandoned connection information) on the server, preventing these resources from occupying memory, processor, and other system resources for a long time, and preventing the decline in verification processing capacity caused by resource congestion. By releasing idle resources in a timely manner, the server's hardware resources can be more concentrated on new SPA extension item verification tasks, ensuring the smoothness of the verification process and indirectly improving the overall verification efficiency of the server. The larger the verification efficiency deviation value, the more the number of resource recycling threads increases, and the faster the resource turnover speed, avoiding verification process blockage caused by resource bottlenecks, and indirectly improving the SPA extension item verification efficiency index.
[0034] The aforementioned acquisition of the verification efficiency deviation value refers to subtracting the SPA extension item verification efficiency index from the SPA extension item verification efficiency threshold. The specific matching process for expanding the server-side SPA extension item cache space by matching the cache capacity increase coefficient based on the verification efficiency deviation value is as follows: a mapping table between the SPA extension item verification efficiency index and the cache capacity increase coefficient is preset in the communication database. The obtained SPA extension item verification efficiency index is input into the communication database. The communication database matches the corresponding cache capacity increase coefficient based on the mapping rules of the mapping table. This coefficient is multiplied by the server-side current SPA extension item cache space base capacity to obtain the expanded cache space capacity. A cache capacity increase coefficient greater than 1 indicates that the server-side current SPA extension item cache capacity needs to be increased by a certain factor.
[0035] The above-mentioned method of matching the increment of the number of resource recycling threads based on the verification efficiency deviation value to improve the resource recycling capability of the server is as follows: The communication database pre-establishes a mapping rule between the verification efficiency deviation value and the increment of the number of resource recycling threads. This rule divides the verification efficiency deviation value into several continuous intervals, each interval corresponding to a fixed increment of the number of resource recycling threads. The obtained verification efficiency deviation value is input into the communication database. The communication database retrieves the corresponding increment of the number of resource recycling threads according to the mapping rule, adds the increment to the current base number of resource recycling threads on the server, and obtains the adjusted total number of resource recycling threads. This completes the process of dynamically matching the increment of the number of threads based on the verification efficiency deviation value and accurately improving the resource recycling capability.
[0036] After dual optimization, the process parameters for server-side verification of the legality of client-side SPA extension items are re-analyzed and marked as verification efficiency re-evaluation index to determine whether the server-side verification of the legality of client-side SPA extension items needs to be optimized a second time.
[0037] In one specific embodiment, the configuration and interaction module serves as the core of the system. Its pre-configured shared key and generated SPA extension items provide a dedicated and encrypted interactive foundation for peer authentication. The client sends an authentication request based on the initial key update overlap period, and the server verifies the legitimacy of the SPA extension items to complete identity confirmation. This process not only standardizes the authentication process but also reduces the risk of key leakage during transmission through the synergy of the shared key and extension items, while avoiding permission confusion caused by improper timing of authentication initiation. Furthermore, the fixed interaction logic ensures clear expectations for the authentication steps between the client and server, reducing interaction errors caused by process ambiguity. While ensuring initial security, it provides a stable operational benchmark for subsequent efficiency optimization and validity verification, improving the maintainability and scalability of the entire authentication system.
[0038] like Figure 5The status monitoring interface of the key authentication system provided in this embodiment of the invention is shown in the diagram. The top navigation bar includes options for key management, authentication policy configuration, authentication log auditing, status monitoring, system settings, and user management. The upper right corner displays the current administrator status. The page presents the system's operating status, currently showing "operating normally," indicating that all services are running normally, the authentication process is stable, and the anomaly monitoring shows no anomalies. No abnormal activity was detected in the past 24 hours. The status was updated at 2:30:22 PM on August 5, 2024. Below is a line graph showing the authentication accuracy rate trend, which can be viewed by day, week, and month. The horizontal axis represents time (00:00-21:00), and the vertical axis represents accuracy (99%-100%), showing the changes in authentication accuracy over different time periods. Below the authentication accuracy rate trend line graph is an identity verification warning list, which includes warning ID, number of warnings, client IP, warning time, status (e.g., pending, processed, need attention), and viewing operation. At the bottom is a button to generate a system operation report.
[0039] Specifically, the process parameters for server-side verification of the legality of client-side SPA extension items are analyzed. The specific analysis process is as follows: buffer hit rate factor, retry avoidance rate factor, and hash calculation time factor are extracted from the process parameters for server-side verification of client-side SPA extension item legality as core evaluation parameters. By presetting the influence strength coefficient of each parameter in the communication database, their weight contribution value to the SPA extension item verification efficiency index is quantified. Finally, a weighted fusion algorithm is used to synthesize the SPA extension item verification efficiency index.
[0040] The aforementioned buffer hit rate factor represents the ratio of the server's buffer hit rate to its threshold value; the aforementioned retry avoidance rate factor represents the ratio of the server's retry avoidance rate to its threshold value; and the aforementioned hash calculation time factor represents the ratio of the server's hash calculation time to its threshold value.
[0041] The SPA extension item verification efficiency index directly reflects the efficiency of the server in verifying the legality of client-side SPA extension items. The specific evaluation method is as follows:
[0042] ;
[0043] ;
[0044] ;
[0045] ;
[0046] In the formula, EVEEI is the SPA extension item verification efficiency index, BHRF is the server-side buffer hit rate factor, BHR is the server-side buffer hit rate, DBHR is the default buffer hit rate in the communication database, RARF is the server-side retry avoidance rate factor, RAR is the server-side retry avoidance rate, DRAR is the default retry avoidance rate in the communication database, HCTF is the server-side hash calculation time factor, HCT is the server-side hash calculation time duration, DHCT is the default hash calculation time duration in the communication database, yp is the effect strength coefficient corresponding to the default buffer hit rate factor in the communication database, yt is the effect strength coefficient corresponding to the default retry avoidance rate factor in the communication database, and yg is the effect strength coefficient corresponding to the default hash calculation time factor in the communication database.
[0047] The aforementioned server-side buffer hit rate refers to the ratio of the number of times the server successfully retrieves the required verification information (such as pre-computed data) from the cache when verifying the legality of the client's SPA extension item to the total number of verification requests. It is obtained by statistically analyzing the ratio of the number of verification requests that hit the cache to the total number of requests per unit time. The aforementioned server-side retry avoidance rate refers to the ratio of the number of duplicate verification requests that the server successfully avoids through optimization mechanisms (such as pre-verification) to the total number of duplicate verification requests that might have originally occurred. It is obtained by statistically analyzing the ratio of the number of duplicate verification requests that are intercepted within a short period of time to the total number of similar duplicate requests. The aforementioned server-side hash calculation time refers to the average time taken by the server to perform hash calculations (such as SHA-256 algorithms) on the SPA extension item sent by the client to generate a verification digest. It is obtained by calculating the average of the total time taken for all hash calculations to be performed to the total number of calculations per unit time.
[0048] The above-mentioned buffer hit rate represents the minimum value of the server's buffer hit rate within the specified range; the above-mentioned retry avoidance rate represents the minimum value of the server's retry avoidance rate within the specified range; the above-mentioned hash calculation time represents the maximum value of the server's hash calculation time within the specified range.
[0049] Improving the buffer hit rate can reduce the reliance on repeated hash calculations (directly reusing cached results), thereby reducing the total hash calculation time; improving the retry avoidance rate can reduce invalid verification requests, which not only reduces the frequency of hash calculation triggers (indirectly reducing time consumption), but also alleviates cache access pressure (avoiding repeated requests crowding out cache resources, which is conducive to maintaining a high buffer hit rate).
[0050] The effect strength coefficients corresponding to the aforementioned buffer hit rate factor indicate that when the buffer hit rate factor changes by a unit magnitude, the SPA extension item verification efficiency index will change accordingly. Similarly, the effect strength coefficients corresponding to the aforementioned retry avoidance rate factor indicate that when the retry avoidance rate factor changes by a unit magnitude, the SPA extension item verification efficiency index will change accordingly. The effect strength coefficients corresponding to the aforementioned hash computation time factor indicate that when the hash computation time factor changes by a unit magnitude, the SPA extension item verification efficiency index will change accordingly. The communication database stores the mapping relationships between the buffer hit rate factor and its corresponding effect strength coefficient, the retry avoidance rate factor and its corresponding effect strength coefficient, and the hash computation time factor and its corresponding effect strength coefficient. For example, when the buffer hit rate factor, retry avoidance rate factor, and hash computation time factor are input into the communication database, the database will generate the corresponding effect strength coefficients for the buffer hit rate factor, the retry avoidance rate factor, and the hash computation time factor based on preset mapping rules, and the numerical range of each effect strength coefficient is strictly controlled between 0 and 1.
[0051] A higher buffer hit rate factor indicates that the cache supports the verification process more effectively, reducing redundant calculations and data reading time, thereby boosting the SPA extension item verification efficiency index. A higher retry avoidance rate factor indicates that the server has a stronger ability to filter redundant verification requests, consumes fewer invalid resources, and makes the verification process smoother, thus increasing the SPA extension item efficiency index. A higher hash calculation time factor indicates that the core calculation steps in a single verification take longer, directly slowing down the verification speed and causing the SPA extension item efficiency index to decrease.
[0052] Furthermore, the process of determining whether to perform secondary optimization on the server-side verification of the client-side SPA extension item's validity involves comparing the verification efficiency review index with the SPA extension item verification efficiency threshold. If the verification efficiency review index is not lower than the SPA extension item verification efficiency threshold, then no secondary optimization is required, and a lightweight secondary verification mechanism is triggered simultaneously. If the verification efficiency review index is lower than the SPA extension item verification efficiency threshold, then secondary optimization is required on the server-side verification of the client-side SPA extension item's validity. The optimization process involves: based on the verification efficiency review index and the SPA extension item verification efficiency threshold, obtaining... Based on the verification efficiency re-evaluation deviation value, an SPA verification timeout reduction coefficient is matched to the verification efficiency re-evaluation deviation value. This shortens the timeout of SPA verification on the server side, allowing the server to more quickly determine that unresponsive requests are invalid and release occupied verification resources in a timely manner. This avoids unnecessary waiting on inefficient verification tasks and allows the server to quickly release occupied computing resources to process new and valid requests. The larger the verification efficiency re-evaluation deviation value, the more significant the reduction in SPA verification timeout. This can quickly filter out invalid waiting, reduce resource waste, and increase the amount of valid verification processed per unit time, thus effectively improving the verification efficiency index of SPA extension items. At the same time, it increases the local SPA verification permissions of edge nodes.
[0053] The aforementioned verification efficiency review deviation value refers to subtracting the verification efficiency review index from the SPA extension item verification efficiency threshold. The specific matching process for the SPA verification timeout reduction coefficient based on the verification efficiency review deviation value is as follows: a mapping rule between the verification efficiency review deviation value and the SPA verification timeout reduction coefficient is pre-established in the communication database. This rule divides the verification efficiency review deviation value into several continuous intervals, each interval corresponding to a fixed SPA verification timeout reduction coefficient. The obtained verification efficiency review deviation value is input into the communication database, which retrieves the corresponding SPA verification timeout reduction coefficient according to the preset mapping rule. This coefficient is multiplied by the current SPA verification timeout duration on the server to obtain the adjusted timeout duration, thereby achieving the purpose of dynamically matching coefficients based on the deviation value and accurately shortening the timeout time. A SPA verification timeout reduction coefficient less than 1 indicates that the SPA verification timeout duration needs to be reduced by a certain factor.
[0054] The aforementioned increase in local SPA verification permissions for edge nodes refers to partially delegating SPA extension item verification tasks, originally primarily handled by the central server, to edge nodes. This grants edge nodes more autonomy in completing verifications. Specifically, edge nodes can directly verify the legitimacy of SPA extension items sent by clients, without uploading all requests to the central server for processing. This adjustment reduces the amount of data transmission and the frequency of interaction between edge nodes and the central server, avoiding verification delays caused by long-distance communication or excessive load on the central server. Simultaneously, edge nodes can flexibly handle verification tasks based on their local network environment and device status, quickly responding to client requests. This improves the overall efficiency of SPA extension item verification, especially in scenarios with multiple concurrent client requests, effectively reducing the pressure on the central server and optimizing resource allocation and response speed throughout the verification system.
[0055] After secondary optimization, the process parameters for server-side verification of the legality of client-side SPA extension items are re-analyzed and marked as the final evaluation index of verification efficiency, thereby determining whether to issue an early warning for the server-side verification of the legality of client-side SPA extension items.
[0056] In one specific embodiment, the efficiency monitoring module dynamically determines whether the verification efficiency meets the standards by tracking and parsing the process parameters of the server-side verification of the legality of SPA extension items in real time. This mechanism not only keenly captures potential efficiency fluctuations in the verification process but also provides the system with an accurate efficiency profile, helping technical personnel to optimize the verification logic and resource allocation strategies in a targeted manner. For example, by analyzing parameter change trends, efficiency risks in high-concurrency scenarios can be predicted in advance, thereby adjusting caching strategies or computing power allocation in advance to avoid verification interruptions caused by sudden loads. At the same time, continuous process monitoring creates a closed-loop feedback of verification efficiency data, providing data support for system iteration and driving the verification mechanism to continuously adapt to complex communication environments. While ensuring stability, it enhances the system's flexibility and adaptability in dealing with diverse authentication needs.
[0057] Specifically, the process of determining whether to issue an alert for the server-side verification of the legality of client-side SPA extension items involves comparing the final verification efficiency index with the SPA extension item verification efficiency threshold. If the final verification efficiency index is not lower than the SPA extension item verification efficiency threshold, then it is determined that no alert should be issued for the server-side verification of the legality of client-side SPA extension items, and a lightweight secondary verification mechanism is triggered simultaneously. The aforementioned lightweight secondary verification mechanism is consistent with the lightweight secondary verification mechanism described above.
[0058] When the final evaluation index of verification efficiency is lower than the threshold of SPA extension item verification efficiency, an early warning will be issued for the process of server-side verification of the legality of client-side SPA extension items.
[0059] It should be explained that the aforementioned warning process for server-side verification of the legality of client-side SPA extensions refers to a system-triggered alert and intervention mechanism that is triggered when the final verification efficiency index falls below the preset SPA extension verification efficiency threshold. This mechanism will promptly inform relevant parties of the inefficiency in the current verification process through preset alarm channels (such as system log markers), clearly indicating the specific circumstances of the failure to meet the verification efficiency standard (such as the extent to which the efficiency index is low).
[0060] Specifically, the process for determining whether the validity of the server-side verification of the client-side SPA extension item meets the standards is as follows: parse the result parameters of the server-side verification of the client-side SPA extension item's legality, derive the server-side verification effectiveness index from it, and then compare it with the preset server-side verification effectiveness threshold in the communication database; the aforementioned server-side verification effectiveness threshold represents the minimum value of the server-side verification effectiveness index within the specified range.
[0061] When the server-side verification effectiveness index is not lower than the server-side verification effectiveness threshold, the server-side verification of the client-side SPA extension item is deemed to have met the effectiveness standard. At the same time, the key parameters of the server are recorded to form an effectiveness trend report. It should be explained that the key parameters recorded on the server side refer to verification process parameters (such as the response time of a single verification), extension item performance parameters (such as the average time taken for the SPA extension item to call the server-side interface), and server-side resource parameters (such as the server's CPU utilization during the verification process). The formation of the effectiveness trend report is based on the key parameters recorded above. Through data analysis over a time dimension, it presents the changing pattern of the server-side verification of the client-side SPA extension item's effectiveness. The report is output in the form of data charts.
[0062] When the server-side verification effectiveness index is lower than the server-side verification effectiveness threshold, it is determined that the validity of the server-side verification client SPA extension item is not up to standard, and the initial key update overlap period is optimized.
[0063] In one specific embodiment, the validity analysis module focuses on collecting and parsing verification result parameters to determine whether the verification validity meets the standards. This module can extract characteristic patterns of verification validity under different scenarios through aggregated analysis of a large number of verification results, providing data support for optimizing verification rules. Simultaneously, it can establish a correlation model between verification validity and server-side resource consumption. By analyzing the dynamic relationship between the two, it can balance verification accuracy and system operating efficiency. For example, while ensuring validity meets standards, it can identify verification steps that can be simplified to reduce resource consumption. Furthermore, the historical validity data accumulated by the module can provide a reference for the verification logic design of new types of SPA extensions, helping to quickly build a verification system adapted to new scenarios, improving the system's adaptability to diverse authentication needs, and allowing the identity authentication mechanism to achieve a better balance between security and flexibility.
[0064] Furthermore, the initial key update overlap period is optimized. The specific optimization process is as follows: Based on the server-side verification effectiveness index and the server-side verification effectiveness threshold, the server-side validity deviation value is obtained. Based on the server-side validity deviation value, a key update overlap period amplification coefficient is matched, thereby extending the initial key update overlap period. The extended overlap period provides a more sufficient time buffer for the verification process: it can reduce verification interruptions caused by insufficient time window, avoid "incomplete verification" from lowering effectiveness; it can also allow the server to execute full verification logic under certain conditions, reduce the probability of misjudgment caused by hasty processing, and improve verification accuracy; at the same time, it enhances fault tolerance to network fluctuations, reduces verification failures caused by delays or packet loss, and ensures the stability of the effectiveness index. Furthermore, the more relaxed time window allows for secondary verification correction, which helps to correct deviations in the initial verification and pushes the server-side verification effectiveness index back up from below the threshold to the standard level, ultimately achieving accurate assurance of the server's confirmation of the client's identity. The client sends an SPA extension to the server according to the optimized key update overlap period, re-initiating the identity authentication request from the communication peer. After receiving the client's SPA extension, the server will re-verify its legitimacy, thereby completing the client's identity confirmation.
[0065] It should be explained that obtaining the server-side validity deviation value mentioned above refers to subtracting the server-side verification effectiveness index from the server-side verification effectiveness threshold. The specific matching process for matching the key update overlap period duration amplification coefficient based on the server-side validity deviation value is as follows: The communication database presets a mapping rule between the server-side validity deviation value and the key update overlap period duration amplification coefficient. This rule divides the validity deviation value into several continuous intervals, each interval corresponding to a fixed key update overlap period duration amplification coefficient. The obtained server-side validity deviation value is input into the communication database. The communication database retrieves the key update overlap period duration amplification coefficient corresponding to the corresponding interval according to the mapping rule, and multiplies this coefficient by the initial key update overlap period duration to obtain the optimized overlap period duration. This achieves the purpose of dynamically matching coefficients based on the validity deviation value and accurately extending the key update overlap period. The key update overlap period duration amplification coefficient greater than 1 indicates the numerical value of the key update overlap period duration that needs to be increased by a certain factor.
[0066] Obtain the optimized key update overlap period and compare it with the defined key update overlap period; the defined key update overlap period refers to the maximum value of the key update overlap period within the specified range.
[0067] If the optimized key update overlap period exceeds the defined key update overlap period, a warning will be issued for the client to send an SPA extension item to the server to re-initiate the peer authentication request; if the optimized key update overlap period does not exceed the defined key update overlap period, no warning will be issued for the client to send an SPA extension item to the server to re-initiate the peer authentication request.
[0068] It should be explained that the aforementioned warning for the client to send SPA extension items to the server to re-initiate the peer authentication request refers to a risk warning mechanism triggered by the system when the optimized key update overlap period exceeds the defined value. This warning will report the abnormal status of the current authentication request to the management end through log records.
[0069] Specifically, the result parameters of the server-side verification of the legality of the client-side SPA extension items are analyzed. The specific analysis process is as follows: the hash full match rate factor, replay attack interception rate factor, and anomaly collaborative interception rate factor are extracted from the result parameters of the server-side verification of the legality of the client-side SPA extension items as core evaluation parameters. At the same time, the comprehensive index of SPA extension item verification efficiency is obtained as a basic performance indicator. By presetting the effect intensity coefficient of each parameter in the communication database, the weight contribution value of each parameter to the server-side verification effectiveness index is quantified. Finally, a weighted fusion algorithm is used to synthesize the server-side verification effectiveness index.
[0070] The aforementioned hash full match rate factor represents the ratio of the server's hash full match rate to its corresponding threshold value; the aforementioned replay attack interception rate factor represents the ratio of the server's replay attack interception rate to its corresponding threshold value; the aforementioned anomaly collaboration interception rate factor represents the ratio of the server's anomaly collaboration interception rate to its corresponding threshold value; the aforementioned SPA extension item verification efficiency comprehensive index refers to the final value of the SPA extension item verification efficiency index, which indicates that the server's efficiency in verifying the legality of the client's SPA extension items meets the standards.
[0071] The server-side validation effectiveness index represents the effectiveness of server-side validation of client-side SPA extensions. The specific evaluation method is as follows:
[0072] ;
[0073] ;
[0074] ;
[0075] ;
[0076] In the formula, SSEI is the server-side verification effectiveness index, EVEEI_z is the comprehensive verification efficiency index of SPA extension items, HFMRF is the server-side hash full match rate factor, HFMR is the server-side hash full match rate, DHFMR is the pre-defined hash full match rate in the communication database, RAIRF is the server-side replay attack interception rate factor, RAIR is the server-side replay attack interception rate, DRAIR is the pre-defined replay attack interception rate in the communication database, ACIRF is the server-side anomaly collaborative interception rate factor, ACIR is the server-side anomaly collaborative interception rate, DACIR is the pre-defined anomaly collaborative interception rate in the communication database, dl is the effect strength coefficient corresponding to the pre-defined hash full match rate factor in the communication database, dm is the effect strength coefficient corresponding to the pre-defined replay attack interception rate factor in the communication database, dj is the effect strength coefficient corresponding to the pre-defined anomaly collaborative interception rate factor in the communication database, and dq is the effect strength coefficient corresponding to the pre-defined comprehensive verification efficiency index of SPA extension items in the communication database.
[0077] It should be explained that the aforementioned hash full match rate refers to the proportion of the number of times the hash value calculated by the receiver (such as the server) completely matches the hash value pre-provided by the sender (such as the client) during the authentication process, out of the total number of hash verifications. It is obtained by statistically analyzing the proportion of times the hash values of the receiver and the sender completely match in the total number of hash verifications. The aforementioned replay attack interception rate refers to the proportion of the number of replay attack attempts that the system successfully identifies and intercepts, out of the total number of replay attack attempts. It is obtained by statistically analyzing the proportion of the number of times the system successfully identifies and intercepts the total number of replay attack attempts. The aforementioned abnormal collaboration interception rate refers to the proportion of the number of abnormal collaboration attack attempts that the system successfully identifies and intercepts, out of the total number of abnormal collaboration attack attempts. It is obtained by statistically analyzing the proportion of the number of times the system identifies and intercepts the total number of abnormal collaboration attack attempts based on collaboration characteristics.
[0078] The above definition of hash full match rate refers to the minimum hash full match rate within the specified range; the above definition of replay attack interception rate refers to the minimum replay attack interception rate within the specified range; the above definition of abnormal collaborative interception rate refers to the minimum abnormal collaborative interception rate within the specified range.
[0079] A high hash full match rate means that the transmitted SPA extension item has not been tampered with, providing a reliable verification basis for subsequent replay attack interception and anomaly collaborative interception, while reducing verification retries caused by data anomalies, directly improving the overall efficiency index of SPA extension item verification; replay attack interception rate and anomaly collaborative interception rate are core indicators of the security defense layer: improving both can effectively filter invalid and malicious SPA extension item requests, reducing the server's resource consumption on invalid verification.
[0080] The influence strength coefficient corresponding to the hash full match rate factor mentioned above indicates the degree of change in the server-side verification effectiveness index when the hash full match rate factor changes by a unit; the influence strength coefficient corresponding to the replay attack interception rate factor mentioned above indicates the degree of change in the server-side verification effectiveness index when the replay attack interception rate factor changes by a unit; the influence strength coefficient corresponding to the anomaly collaborative interception rate factor mentioned above indicates the degree of change in the server-side verification effectiveness index when the anomaly collaborative interception rate factor changes by a unit; and the influence strength coefficient corresponding to the SPA extension item verification efficiency comprehensive index mentioned above indicates the degree of change in the server-side verification effectiveness index when the SPA extension item verification efficiency comprehensive index changes by a unit. The communication database stores the mapping relationships between hash full match rate factors and their corresponding action strength coefficients, replay attack interception rate factors and their corresponding action strength coefficients, anomaly collaborative interception rate factors and their corresponding action strength coefficients, and the comprehensive index of SPA extension item verification efficiency and its corresponding action strength coefficient. For example, when the hash full match rate factor, replay attack interception rate factor, anomaly collaborative interception rate factor, and comprehensive index of SPA extension item verification efficiency are input into the communication database, the communication database will generate the corresponding action strength coefficients for the hash full match rate factor, replay attack interception rate factor, anomaly collaborative interception rate factor, and comprehensive index of SPA extension item verification efficiency based on preset mapping rules, and the numerical range of each action strength coefficient is strictly controlled between 0 and 1.
[0081] A higher hash full match rate factor indicates more reliable server-side data integrity verification and a greater positive contribution to verification effectiveness. A higher replay attack interception rate factor indicates stronger server-side ability to resist replay attacks, reducing invalid interference and improving verification effectiveness. A higher anomaly collaboration interception rate factor indicates more effective server-side defense against collaborative attacks, reducing the risk of the verification system being breached and positively supporting effectiveness. A higher comprehensive index value of SPA extension item verification efficiency indicates higher server-side efficiency in processing verification requests, reducing resource waste and directly improving overall verification effectiveness.
[0082] In one specific embodiment, this invention provides a communication peer authentication system based on a shared key. Through the synergistic interaction of three modules, it not only enhances the security, efficiency, and reliability of authentication but also achieves a lightweight design of the authentication logic through deep integration of the shared key and SPA extensions. This eliminates the need for complex third-party trust mechanisms, enabling the establishment of a direct and trusted identity verification channel between communicating parties, thus reducing system deployment complexity and maintenance costs. Simultaneously, the closed-loop mechanism of real-time efficiency monitoring and effectiveness analysis ensures stable authentication performance even under high concurrency requests or sudden security threats. This avoids resource redundancy caused by excessive protection and prevents security vulnerabilities resulting from rigid policies, providing flexible and controllable identity authentication guarantees for communication interactions in different scenarios.
[0083] Reference Figure 3 The flowchart of the handshake protocol between the client and server provided in this embodiment of the invention shows that the client and server complete a complete TLCP establishment process as follows: The client sends a client Hello message to the server, which is the cryptographic algorithm supported by the client; the server returns a server Hello message to the client, selecting the corresponding cryptographic algorithm; the server returns a server certificate to the client, which is the server site certificate, and the client authenticates the server site certificate; the server returns a server key exchange message to the client, sending key exchange parameters according to the key exchange algorithm; the server returns a certificate request to the client, requesting the client to submit a certificate for authentication; the server returns a server Hello Done message to the client, indicating that the server has completed this stage of the operation; the client sends a client certificate to the server, which is the client digital certificate; the client sends a client key exchange message to the server, which is the client key exchange data; the client sends a client certificate verification message to the server, which is the client signature result; the client sends a change cipher to the server. The client completes this phase of the handshake by sending a Spec (Change Cipher Specification) and a Finish (Finish). The server returns a Change Cipher Spec and a Finish (Finish) to the client, completing the handshake process.
[0084] Specifically, the client's identity is verified by confirming its legitimacy. The verification process is as follows:
[0085] The client sends a ClientHello containing the SPA extension to the server. Upon receiving the ClientHello, the server verifies the validity of the client's SPA extension. If the SPA extension is not included or does not match, the connection is closed. Otherwise, the server verifies the client's identity and simultaneously sends a ServerHello containing the SPA extension to the client. Upon receiving the ServerHello, the client verifies the validity of the server's SPA extension. If the SPA extension is not included or does not match, the connection is closed. Otherwise, the client verifies the server's identity, thus completing two-way identity verification and establishing a TLCP connection.
[0086] Reference Figure 4 As shown in the schematic diagram of the identity authentication process provided in this embodiment of the invention, the client and server complete the identity verification process through SAP extension items as follows: The client sends a ClientHello containing the SAP extension item; the server receives the ClientHello from the client and verifies the validity of the client's SAP extension item. If the client does not contain the SAP extension item or the SAP extension item does not match, the connection is closed; the client receives the ServerHello from the server and verifies the validity of the server's SAP extension item. If the server does not contain the SAP extension item or the SAP extension item does not match, the connection is closed. Otherwise, after both parties complete the identity verification, a TLCP connection is established.
[0087] Reference Figure 2 As shown, the second aspect of the present invention provides a communication peer authentication method based on a shared key, comprising: Step 1, the client and the server pre-configure a shared key and generate a SPA extension item for assisting communication peer authentication; the client sends the SPA extension item to the server to initiate a communication peer authentication request based on the initial key update overlap period; after receiving the client's SPA extension item, the server verifies its legality to complete the client's identity confirmation; Step 2, the process parameters of the server verifying the legality of the client's SPA extension item are monitored and analyzed in real time to determine whether the efficiency of the server in verifying the legality of the client's SPA extension item meets the standard; Step 3, the result parameters of the server verifying the legality of the client's SPA extension item are collected and parsed to determine whether the effectiveness of the server in verifying the legality of the client's SPA extension item meets the standard.
[0088] Reference Figure 6The key management interface diagram of the key authentication system provided in this embodiment of the invention is shown. The top navigation bar has options for key management, authentication policy configuration, authentication log auditing, status monitoring, system settings, and user management. Currently, the user is on the key management page, with the administrator's identity displayed in the upper right corner. The page title is "Key Management Center," and this page is used to manage the creation, allocation, and status monitoring of all shared keys. Below is the key list, where users can search by key ID or client, and there are buttons for selecting an ID and generating a new key. The key list displays the key ID, such as ECC-P256, key type (built-in, external, random number), creation time, associated client (such as Client-Web-01), status (valid, about to expire, expired), and viewing operations. The bottom displays the current page (page 1), showing 1-5 records, for a total of 24 records, which can be viewed in pages.
[0089] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.
[0090] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.
[0091] In this invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.
[0092] It should be understood that, in various embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0093] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0094] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A communication peer authentication system based on shared keys, characterized in that, include: The configuration and interaction module is used for pre-configuring shared keys on the client and server sides and generating SPA extension items to assist in peer authentication. Based on the initial key update overlap period, the client sends the SPA extension item to the server to initiate a peer authentication request. After receiving the client's SPA extension item, the server verifies its validity to complete the client's identity confirmation. The SPA extension item contains the first 16 bytes of the following hash value: SHA256(ClientHello.random||external shared key||built-in shared key). ClientHello is the first message sent by the client when initiating communication with the server, and random represents the random number contained in the ClientHello message. The efficiency monitoring module is used to monitor and analyze the process parameters of the server-side verification of the legality of client-side SPA extension items in real time and obtain the SPA extension item verification efficiency index. This determines whether the efficiency of the server-side verification of client-side SPA extension item legality meets the standards. The specific analysis process is as follows: Buffer hit rate factor, retry avoidance rate factor, and hash calculation time factor are extracted from the process parameters of the server-side verification of client-side SPA extension item legality as core evaluation parameters. By pre-setting the influence strength coefficient of each parameter in the communication database, their weight contribution value to the SPA extension item verification efficiency index is quantified. Finally, a weighted fusion algorithm is used to synthesize the SPA extension item verification efficiency index. The SPA extension item verification efficiency index reflects the efficiency of the server-side verification of the legality of client-side SPA extension items. The hit rate factor represents the ratio of the server's buffer hit rate to its threshold value; the retry avoidance rate factor represents the ratio of the server's retry avoidance rate to its threshold value; and the hash calculation time factor represents the ratio of the server's hash calculation time to its threshold value. When the SPA extension item verification efficiency index is lower than the SPA extension item verification efficiency threshold, it is determined that the server's efficiency in verifying the legality of the client's SPA extension item is substandard. The verification efficiency deviation value is obtained by subtracting the SPA extension item verification efficiency index from the SPA extension item verification efficiency threshold. Based on the verification efficiency deviation value, dual optimization is performed: the cache capacity increase coefficient is matched based on the verification efficiency deviation value to expand the server's SPA extension item cache space, and the resource reclamation thread number increment is matched based on the verification efficiency deviation value to improve the server's resource reclamation capability. The validity analysis module collects and analyzes the result parameters of the server-side verification of the legality of client-side SPA extension items, and obtains the server-side verification effectiveness index. This index determines whether the server-side verification of client-side SPA extension items meets the required effectiveness standards. The specific analysis process is as follows: Hash full match rate factor, replay attack interception rate factor, and anomaly collaborative interception rate factor are extracted from the result parameters of the server-side verification of client-side SPA extension item legality as core evaluation parameters. A comprehensive SPA extension item verification efficiency index is obtained as a basic performance indicator. By pre-setting the influence strength coefficient of each parameter in the communication database, their weight contribution value to the server-side verification effectiveness index is quantified. A weighted fusion algorithm is used to synthesize the server-side verification effectiveness index. The server-side verification effectiveness index represents the effectiveness of the server-side verification of client-side SPA extension items, and the hash full match rate factor characterizes the server-side hash full match rate. The ratio of the matching rate to its corresponding threshold value; the replay attack interception rate factor represents the ratio of the server's replay attack interception rate to its corresponding threshold value; the abnormal collaboration interception rate factor represents the ratio of the server's abnormal collaboration interception rate to its corresponding threshold value; the SPA extension item verification efficiency comprehensive index refers to the final value of the SPA extension item verification efficiency index of the server verifying the legality of the client's SPA extension item. When the server verification effectiveness index is lower than the server verification effectiveness threshold, it is determined that the server's verification of the client's SPA extension item is not effective. At the same time, the initial key update overlap period is optimized. The specific optimization process is as follows: subtract the server verification effectiveness index from the server verification effectiveness threshold to obtain the server effectiveness deviation value. Based on the server effectiveness deviation value, a key update overlap period increase coefficient is matched to extend the initial key update overlap period.
2. The communication peer authentication system based on shared key according to claim 1, characterized in that: The process for determining whether the efficiency of the server-side verification of the legality of the client-side SPA extension item meets the standard is as follows: First, by analyzing the process parameters of the server-side verification of the legality of client-side SPA extension items, the SPA extension item verification efficiency index is obtained and compared with the preset SPA extension item verification efficiency threshold in the communication database. When the SPA extension item verification efficiency index is not lower than the SPA extension item verification efficiency threshold, it is determined that the efficiency of the server in verifying the legality of the client's SPA extension item meets the standard, and a lightweight secondary verification mechanism is triggered synchronously. After dual optimization, the process parameters for server-side verification of the legality of client-side SPA extension items are re-analyzed and marked as verification efficiency re-evaluation index to determine whether the process for server-side verification of the legality of client-side SPA extension items needs to be optimized a second time.
3. The communication peer authentication system based on shared key according to claim 2, characterized in that: The process of determining whether to perform secondary optimization on the server-side verification of the legality of the client-side SPA extension item is as follows: The verification efficiency reassessment index is compared with the verification efficiency threshold of the SPA extension item; When the verification efficiency review index is not lower than the SPA extension item verification efficiency threshold, it is determined that the process of server-side verification of the legality of client-side SPA extension items will not be optimized again, and a lightweight secondary verification mechanism will be triggered simultaneously. When the verification efficiency review index is lower than the SPA extension item verification efficiency threshold, it is determined that the process of server-side verification of the legality of client-side SPA extension items will be optimized a second time. The specific optimization process is as follows: based on the verification efficiency review index and the SPA extension item verification efficiency threshold, the verification efficiency review deviation value is obtained. Based on the verification efficiency review deviation value, the SPA verification timeout duration reduction coefficient is matched to shorten the timeout duration of server-side SPA verification and increase the local SPA verification permissions of edge nodes. After secondary optimization, the process parameters for server-side verification of the legality of client-side SPA extension items are re-analyzed and marked as the final evaluation index of verification efficiency, thereby determining whether to issue an early warning for the server-side verification of the legality of client-side SPA extension items.
4. The communication peer authentication system based on shared key according to claim 3, characterized in that: The specific process for determining whether to issue a warning during the server-side verification of the legality of the client-side SPA extension item is as follows: The final evaluation index of verification efficiency is compared with the verification efficiency threshold of the SPA extension item; When the final evaluation index of verification efficiency is not lower than the verification efficiency threshold of SPA extension items, it is determined that no warning will be issued for the process of server-side verification of the legality of client SPA extension items. At this time, a lightweight secondary verification mechanism is triggered simultaneously. When the final evaluation index of verification efficiency is lower than the threshold of SPA extension item verification efficiency, an early warning will be issued for the process of server-side verification of the legality of client-side SPA extension items.
5. The communication peer authentication system based on shared key according to claim 1, characterized in that: The specific process for determining whether the validity of the client-side SPA extension item verified by the server meets the criteria is as follows: The result parameters of the server-side verification of the legality of the client SPA extension items are analyzed to obtain the server-side verification effectiveness index, and then compared with the preset server-side verification effectiveness threshold in the communication database. When the server-side verification effectiveness index is not lower than the server-side verification effectiveness threshold, it is determined that the server-side verification of the client SPA extension item has met the effectiveness standard. At the same time, the key parameters of the server are recorded to form an effectiveness trend report.
6. The communication peer authentication system based on shared key according to claim 1, characterized in that: The optimization of the initial key update overlap period also includes: The client updates the overlap period according to the optimized key, sends the SPA extension item to the server, and re-initiates the authentication request for the communication peer. After receiving the SPA extension item from the client, the server will re-verify its legitimacy to complete the identity confirmation of the client. Obtain the optimized key update overlap period duration and compare it with the defined key update overlap period duration; If the optimized key update overlap period exceeds the defined key update overlap period, an early warning will be issued for the client to send SPA extension items to the server to re-initiate the peer authentication request. If the optimized key update overlap period does not exceed the defined key update overlap period, no warning will be issued if the client sends an SPA extension item to the server to re-initiate the peer authentication request.
7. The communication peer authentication system based on shared key according to claim 1, characterized in that: The verification of its legitimacy is used to confirm the client's identity. The specific verification process is as follows: The client sends a ClientHello containing the SPA extension to the server. Upon receiving the ClientHello, the server verifies the validity of the client's SPA extension. If the SPA extension is not included or does not match, the connection is closed. Otherwise, the server verifies the client's identity and simultaneously sends a ServerHello containing the SPA extension to the client. Upon receiving the ServerHello, the client verifies the validity of the server's SPA extension. If the SPA extension is not included or does not match, the connection is closed. Otherwise, the client verifies the server's identity, thus completing two-way identity verification and establishing a TLCP connection.
8. A communication peer authentication method based on shared keys, applied to the communication peer authentication system based on shared keys as described in any one of claims 1 to 7, characterized in that: include: Step 1: The client and server pre-configure a shared key and generate an SPA extension item to assist in the authentication of the communication peer. Based on the initial key update overlap period, the client sends the SPA extension item to the server to initiate the authentication request for the communication peer. After receiving the SPA extension item from the client, the server verifies its legality to complete the authentication of the client's identity. Step 2: Monitor and analyze the process parameters of the server-side verification of the legality of client-side SPA extension items in real time, so as to determine whether the efficiency of the server-side verification of the legality of client-side SPA extension items meets the standard. Step 3: Collect and parse the result parameters of the server-side verification of the legality of the client-side SPA extension items, so as to determine whether the server-side verification of the validity of the client-side SPA extension items meets the standards.
Citation Information
Patent Citations
Method for identity authentication based on quantum key
CN115913521B
Identity Authentication and Key Exchange Methods and Systems
CN116684093B
Authentication method and device
CN111901355A
Smart power grid LWM2M protocol security access control method and system
CN116170806A