A multi-level key dispersion method supporting cross-domain interoperability of tunnel mechatronic systems

By employing national cryptographic algorithms and traceable identifiers to construct dispersion factors in the electromechanical system of highway tunnels, the problems of static key setting and cross-domain interoperability are solved, achieving high-strength identity authentication and lightweight certificate management, thereby improving the security and convenience of the system.

CN121125093BActive Publication Date: 2026-02-27RES INST OF HIGHWAY MINIST OF TRANSPORT
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511439330.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2026-02-27
Estimated Expiration
2045-10-10

AI Technical Summary

Technical Problem

Highway tunnel electromechanical systems lack systematic solutions for secure data transmission. Static key settings lead to a high risk of leakage and make it difficult to support cross-domain interoperability. Traditional solutions cannot meet the high-strength authentication and lightweight certificate management needs of resource-constrained devices.

Method used

Employing non-singular elliptic curve parameters and national cryptographic algorithms, the system generates a master private key and a public key through a trusted center. It constructs a dispersion factor by combining traceable identifiers, provincial identifiers, and municipal identifiers, and derives session keys and authentication keys using national cryptographic hash functions. This enables cross-domain authentication and encrypted communication between devices and controllers, and supports dynamic key updates and traceability.

Benefits of technology

It achieves identity trust and risk isolation in cross-domain interoperability, reduces the computing and communication overhead of resource-constrained devices, ensures the forward security and ease of operation and maintenance of the system, and meets the secure communication requirements of national cryptographic standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125093B_ABST
    Figure CN121125093B_ABST
Patent Text Reader

Abstract

The application discloses a multi-stage key dispersion method for supporting cross-domain interoperation of a tunnel electromechanical system, and comprises the following steps: a trusted center generates non-singular elliptic curve parameters, a system master private key and a system public key, and then publishes the public parameters; the tunnel management center safely distributes the public parameters to the tunnel electromechanical equipment; the tunnel electromechanical equipment combines a traceable identifier, a province domain identifier, a city domain identifier and a tunnel identifier to construct a dispersion factor; based on the dispersion factor, a partial private key and a device self-selected private key, a unique session key and an authentication key are derived through a national encryption hash function to realize strong binding of the key, the physical position of the device and the management attribution; the device key is strongly bound to the physical position and the management attribution of the device through the hash function, the identity mutual trust and the risk isolation problem in the cross-domain interoperation are solved, the calculation and communication overhead of the resource-restricted industrial device is reduced, and the difficult problem of applying a high-performance security protocol to the embedded device is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of key distribution, in particular to a multi-level key distribution method supporting cross-domain interoperation of tunnel electromechanical systems. BACKGROUND

[0002] At present, the highway tunnel electromechanical system lacks a systematic overall solution in data security transmission. The existing system mostly uses simple fixed passwords or pre-shared keys for device authentication and communication encryption. This method has the problems of static key setting, long-term invariability, and the same key being repeatedly used in multiple devices, making it difficult to achieve the goal of "one machine one key". Once the key is leaked, attackers can access multiple devices, causing large-scale security risks. Secondly, the traditional scheme cannot support cross-tunnel and cross-regional device interoperation. Due to the lack of device identity trust mechanism between different management domains, identity verification and key negotiation cannot be seamlessly performed, restricting data sharing and business collaboration.

[0003] In addition, the number of electromechanical devices in highway tunnels is large, and the deployment environment is complex. Most of the devices are resource-constrained embedded terminals and cannot bear the heavy certificate management and cryptographic operation overhead in traditional public key infrastructures. Although some technologies attempt to use national cryptographic algorithms to achieve dynamic key management (CN118074976A) and ensure node-level data security (CN202311169768.7), they do not propose a cross-domain interoperation, lightweight authentication and key distribution mechanism for highway tunnel electromechanical systems, especially lacking a comprehensive design combining multi-level regional factors binding and lightweight certificates.

[0004] Therefore, in the resource-constrained highway tunnel electromechanical environment, it is imperative to build a secure communication system that has high-strength identity authentication, dynamic key update, supports cross-domain interoperation, and meets the national cryptographic standard. Therefore, there is an urgent need for a new key management and distribution mechanism that is deeply optimized for this scenario to solve the above problems and improve the network security protection capability of the highway tunnel electromechanical system. SUMMARY

[0005] The purpose of the present application is to provide a multi-level key distribution method supporting cross-domain interoperation of tunnel electromechanical systems.

[0006] To achieve the above purpose, the present application is implemented according to the following technical scheme:

[0007] The present application comprises the following steps:

[0008] S1 system initialization phase:

[0009] The trusted center generates non-singular elliptic curve parameters, system master private key and system public key, and then publishes public parameters;

[0010] The tunnel electromechanical device submits the hardware identity and the tunnel identity to the tunnel management center of the corresponding area, the tunnel management center forwards the registration information to the trusted center, and then verifies the partial private key and the traceable device identifier corresponding to the tunnel electromechanical device, and distributes the partial private key and the traceable device identifier to the tunnel electromechanical device through the tunnel management center;

[0011] S2 multi-level regional key dispersion stage:

[0012] The tunnel electromechanical device combines the traceable identifier, the provincial identifier, the municipal identifier and the tunnel identifier to construct a dispersion factor;

[0013] Based on the dispersion factor, the partial private key and the device self-selected private key, a unique session key and an authentication key are derived through a national encryption hash function to realize the strong binding of the key and the physical location and management attribution of the device;

[0014] S3 cross-domain data interoperation stage:

[0015] The first regional device and the second regional controller perform bidirectional authentication through the national encryption SM2 algorithm, and independently calculate the same session key based on the negotiated shared key and the regional dispersion factor, and use the SM4 algorithm to encrypt the communication.

[0016] Further, in the device registration stage, the step of verifying the validity of the partial private key includes:

[0017] Checking whether the scalar product of the partial private key and the base point is equal to the linear combination of the device public key point and the system public key, if yes, receiving, otherwise discarding.

[0018] Further, the trusted center randomly selects elliptic curve parameters and a master private key, calculates a system public key, generates public parameters, and the public parameters include elliptic curve parameters, a system public key, and a hash function; the hash function to All are implemented by using the national encryption SM3 algorithm, and the hash function includes:

[0019] ,

[0020] ,

[0021] ,

[0022] ,

[0023] ,

[0024] Among them, Indicates the bit length of the negotiated key.

[0025] Further, in the multi-level regional key dispersion stage:

[0026] The device complete private key is composed of the partial private key and the self-selected private key, and the corresponding public key is the scalar product of the self-selected private key and the base point.

[0027] The session key and the authentication key are generated by the joint calculation of the dispersion factor, the partial private key and the self-selected private key through the national SM3 hash function.

[0028] Further, the cross-domain data interoperation stage specifically includes:

[0029] a. The device uses the complete private key to perform SM2 signature on the timestamp and the encrypted identity information.

[0030] b. The controller verifies the signature validity by calculating whether the relationship of the signature value and the device public key material is established.

[0031] c. Both parties encrypt the communication based on the derived session key and the SM4 algorithm.

[0032] Further, the trusted center or the tunnel management center periodically issues a key update instruction, and the device generates a new private key and a session key; when the device is identified as malicious, the trusted center queries the real identity according to the traceable identifier and adds it to the blacklist.

[0033] Further, the elliptic curve randomly uses the non-singular curve recommended by the national SM2, which satisfies the equation y²=x³+ax+bmodp, and the discriminant 4a³+27b²≠0, wherein p is a large prime number.

[0034] Further, the tunnel electromechanical device includes a sensor, an actuator, a lighting device or a fan controller.

[0035] Further, the key update step of the tunnel electromechanical device during cross-domain migration:

[0036] When the tunnel electromechanical device is migrated from the first region to the second region, the tunnel management center of the second region initiates a migration authorization request to the trusted center;

[0037] After the trusted center verifies, the hardware identifier and the partial private key of the device are kept unchanged, and only the associated regional dispersion factor is updated to the provincial identifier, the municipal identifier and the tunnel identifier of the second region;

[0038] After the tunnel electromechanical device is powered on in the second region, a new session key is derived based on the new regional dispersion factor, and the authentication and communication with the system in the second region are completed.

[0039] Further, in the multi-level regional key dispersion step, the formula for the device to derive the session key is:

[0040]

[0041] H4 is the SM3 hash function, and xi is the personalized private key selected by the device.

[0042] The beneficial effects of this invention are:

[0043] This invention solves the problems of identity trust and risk isolation in cross-domain interoperability by strongly binding device keys to their physical location and management ownership through hash functions. Based on a lightweight pseudonymous certificate-based authentication and key negotiation protocol, it supports on-demand key updates and secure traceability, effectively ensuring the forward security and ease of operation and maintenance of the system. While meeting the security strength of national cryptographic algorithms, it reduces the computing and communication overhead of resource-constrained industrial equipment and solves the problem of high-performance security protocols for embedded device applications. Attached Figure Description

[0044] Figure 1 This is an application scenario for data transmission interoperability in tunnel electromechanical systems provided in this embodiment of the invention;

[0045] Figure 2 This is an overall flowchart of cross-domain interoperability of data in the electromechanical system of a highway tunnel provided in an embodiment of the present invention;

[0046] Figure 3 This is a flowchart of the method for dynamically distributing cross-domain interoperability keys for highway tunnel electromechanical systems provided in this embodiment of the invention;

[0047] Figure 4 This is a schematic diagram of the dynamic distribution principle of multi-level regional keys for highway tunnel electromechanical system data provided in an embodiment of the present invention. Detailed Implementation

[0048] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. The illustrative embodiments of the invention are provided to explain the invention, but are not intended to limit the invention.

[0049] like Figure 1 As shown, the present invention includes the following steps: S1 System initialization phase:

[0050] The Trusted Center generates non-singular elliptic curve parameters, the system master private key, and the system public key, and then publishes the public parameters.

[0051] The tunnel electromechanical equipment submits hardware identifiers and tunnel identifiers to the tunnel management center in the corresponding area. The tunnel management center forwards the registration information to the trusted center and then verifies and generates a partial private key and traceable device identifier corresponding to the tunnel electromechanical equipment. These are then securely distributed to the tunnel electromechanical equipment through the tunnel management center.

[0052] S2 multi-level regional key dispersion phase:

[0053] The tunnel electromechanical device combines traceable identifiers, provincial identifiers, municipal identifiers, and tunnel identifiers to construct dispersion factors;

[0054] Based on the dispersion factors, partial private keys, and device-selected private keys, a unique session key and authentication key are derived through a national encryption hash function to achieve strong binding of the key with the physical location and management attribution of the device;

[0055] S3 cross-domain data interoperability phase:

[0056] The first regional device and the second regional controller perform mutual authentication through the national encryption SM2 algorithm, and independently calculate the same session key based on the negotiated shared key and regional dispersion factors, and use the SM4 algorithm to encrypt the communication.

[0057] As shown in Figure 2 , it includes five stages: system initialization, device and certificate distribution, key dispersion and derivation, tunnel authentication and secure communication, and key update and traceability. The entire process follows the national encryption SM2 and SM4 algorithm specifications.

[0058] Step 1: The trusted center CA is responsible for the global initialization of the system, generating system master keys and public parameters;

[0059] 1) CA randomly selects a non-singular elliptic curve recommended by the national encryption SM2 , where , , and p is a large prime number;

[0060] 2) A q-order cyclic group G is formed by the points on the elliptic curve E and the point O at infinity, and a generator P of G is randomly selected;

[0061] 3) CA randomly selects as the system master private key, and calculates the system public key , where and s are the public key and private key of the system, respectively;

[0062] 4) CA selects a series of national encryption hash functions and cryptographic algorithms, , , , , ;

[0063] 5) CA discloses the system public parameters: , the system master private key s is strictly stored in the hardware security module (HSM);

[0064] Step two: Tunnel electromechanical equipment in production factory or deployment, need to register to the tunnel management center TMC, and issued by CA lightweight pseudonym certificate;

[0065] 6) Registration request: device Its unique hardware identity Serial number and tunnel code Sent to the corresponding tunnel management center, denoted by . Generate registration information ;

[0066] 7) Relay request: Forward to the trusted center CA using secure channel ;

[0067] 8) Randomly selected , calculate partial public key point: , generate device traceable identifier , this pseudonym is fixed, used for CA trace. Calculate verification parameters: , where is the certificate validity period, then calculate partial private key , CA local save traceable list ;

[0068] 9) Distribute certificate: CA sends To , and then Safely inject into the device Hardware security module HSM;

[0069] 10) Step three: multi-level regional key dispersion and derivation: after starting, the device Di uses the partial private key PSKi issued by CA and securely stored in HSM, the selected personalized private key xi, and the multi-level regional dispersion factor to locally derive a unique communication key. As shown in Figure 3 The key dynamic dispersion and authentication of highway tunnel electromechanical system are shown in the whole process;

[0070] 11) After receiving , the device first verifies its validity, checks whether Holds, if so, receive, otherwise discard.

[0071] 12) Generate device personalized key pair, device Select As its personalized private key, and calculate the corresponding , its complete private key is ; ​

[0072] 13) Constructing the dispersion factor, combining the device's and its provincial and municipal identifiers ID and tunnel identifier TunnelID, constructing its unique dispersion factor ;

[0073] 14) Deriving the session key, using the SM3 hash function, based on the dispersion factor, partial private key, and personalized private key to derive the final session key and authentication key AK, , This mechanism ensures "one machine, one key, one domain", even if the same batch of devices are used in different tunnels, different keys will be used;

[0074] Step four: Establishing a secure communication link between the device and the controller in the tunnel, as shown in Figure 4 , which shows the core logic of key derivation and verification;

[0075] 15) When the device needs to communicate with the controller C, generate an authentication request message;

[0076] 16) Using its own complete private key to perform SM2 signature on the current timestamp and ; ;

[0077] 17) Send the request message { to the controller;

[0078] 18) The controller C verifies the freshness of the timestamp ;

[0079] 19) Use the device's public key material to verify the signature and verify 's validity, calculate whether they are equal through the formula to determine the validity of the signature. Where represents the hash digest of the message, is the signature value extracted from the message, and M is the message plaintext, where ;

[0080] 20) After verification, the controller C uses its own private key to decrypt to obtain , thereby confirming the device identity;

[0081] 21) The controller C calculates the same session key and authentication key AK based on and the known regional code, using the same key dispersion algorithm as the device;

[0082] 22) After that, both sides use the derived and the national SM4 algorithm to encrypt the data communication, and use the authentication key AK to verify the message integrity;

[0083] Step five: key update and traceability;

[0084] 23) Key update and traceability: Or the CA can issue a key update instruction periodically, and the new instruction is encrypted using the current valid public key of the device and broadcasted. After receiving the instruction, the device safely executes the key update algorithm in the HSM to generate a new and , realizing the forward security of the key;

[0085] 24) When a traceable device identifier corresponding device is identified as a malicious device, the tunnel management center can report it to the CA. The CA queries the real identity and the tunnel to which it belongs according to the traceability list stored locally , and adds it to the blacklist and revokes its certificate;

[0086] In the embodiment, the implementation process of the method is illustrated by taking the transmission of a coordination instruction from a sensing device of tunnel B (B city of A province) to an execution device of tunnel A (D city of C province) as an example:

[0087] System initialization and device registration: the trusted center CA generates a master key pair for the whole system. The D city cloud control center (TMC TY ) and the B city cloud control center (TMC SJZ ) register with the CA respectively and obtain their respective management domain certificates.

[0088] Key distribution and regional binding: first, generate a key for the sensing device. The CA generates a partial private key PSK i for the sensor (assuming that the HWID i is SN-123) and combines it with the regional factor (for example, A province ID = 13, B city ID = 01, and tunnel B ID = 002) to calculate the traceable identifier PID i . Finally, the communication key is derived from the formula SK session = SM3(PID i || 13 || 01 || 002 || PSK i || x i ).

[0089] ​The execution device key of D city is derived from its regional factor (C province ID=14, D city ID=01, tunnel A ID=001).

[0090] The sensing device of tunnel B detects the abnormality of the environmental index, signs the data using the key derived based on the regional factor of "A province B city", and sends the data, signature, traceable identifier PID of tunnel B, and regional factor (13, 01, 002) to the D cloud control center. i

[0091] After receiving the request, the D city cloud control center extracts the regional factor and traceable identifier, and submits them to the CA for cross-domain legality verification. The CA verifies that the certificate is signed by itself, and that the registration region information is completely matched with the regional factor (13, 01, 002) in the message.

[0092] After verification, the D city cloud control center can trust that the data is indeed from the legal device under the jurisdiction of A province B city, rather than a fake device.

[0093] The D city cloud control center generates a control instruction according to the trusted data, and signs the instruction using the key derived based on the regional factor of "C province D city", and sends it to the execution device of tunnel A. After verifying the legality of the instruction signature, the execution device executes the corresponding operation.

[0094] The above has carried out the detailed introduction to the embodiment of the present application, the principle and implementation mode of the present application have been described in this paper by applying specific examples; the above embodiment is only used to help understanding the core idea of the present application; at the same time, for the general technical personnel in the art, according to the idea of the present application, the specific implementation mode and application range will be changed; according to the above, the content of the specification should not be understood as the limitation of the present application.​

Claims

1. A multi-level key distribution method supporting cross-domain interoperability of tunnel electromechanical systems, characterized in that, include: S1 system initialization phase: The Trusted Center generates non-singular elliptic curve parameters, the system master private key, and the system public key, and then publishes the public parameters. The tunnel electromechanical equipment submits hardware identifiers and tunnel identifiers to the tunnel management center in the corresponding area. The tunnel management center forwards the registration information to the trusted center and then verifies and generates a partial private key and traceable device identifier corresponding to the tunnel electromechanical equipment. These are then securely distributed to the tunnel electromechanical equipment through the tunnel management center. S2 multi-level geographical key distribution stage: The tunnel electromechanical equipment combines traceability identifiers, provincial identifiers, municipal identifiers, and tunnel identifiers to construct a dispersion factor; Based on the dispersion factor, partial private key and device-selected private key, a unique session key and authentication key are derived through the national cryptographic hash function to achieve a strong binding between the key and the physical location and management ownership of the device; S3 cross-domain data interoperability phase: The first regional device and the second regional controller use the national cryptographic SM2 algorithm for bidirectional authentication, and independently calculate the same session key based on the negotiated shared key and regional dispersion factor, and use the SM4 algorithm to encrypt communication.

2. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, During the device registration phase, the steps for verifying the validity of a portion of the private key include: Check if the scalar product of the partial private key and the base point is equal to a linear combination of the device public key and the system public key. If it is true, accept it; otherwise, discard it.

3. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, The trusted center randomly selects elliptic curve parameters and a master private key, calculates the system public key, and generates public parameters, which include elliptic curve parameters, the system public key, and a hash function; the hash function... to All are implemented using the national cryptographic SM3 algorithm, and the hash function includes: , , , , , in, Indicates the bit length of the negotiation key.

4. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, In the multi-level geographical key distribution stage: The complete private key of a device consists of a partial private key and a self-selected private key, and the corresponding public key is the scalar product of the self-selected private key and the base point. The session key and authentication key are generated by jointly calculating the dispersion factor, a portion of the private key, and a self-selected private key using the national cryptographic SM3 hash function.

5. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, The cross-domain data interoperability phase specifically includes: Device A uses the full private key to perform an SM2 signature on the timestamp and encrypted identity information; b. The controller verifies the validity of the signature by calculating whether the relationship between the signature value and the device public key material holds true. c. Both parties communicate using encrypted encryption based on the derived session key and the SM4 algorithm.

6. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, The Trusted Center or Tunnel Management Center periodically issues key update instructions, and the device generates a new private key and session key; when a device is identified as malicious, the Trusted Center queries its true identity based on the traceable identifier and adds it to the blacklist.

7. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, The elliptic curve is randomly selected from the non-singular curves recommended by the Chinese national cryptographic standard SM2, satisfying the equation y²=x³+ax+bmodp, and the discriminant 4a³+27b²≠0, where... p is a large prime number.

8. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, The tunnel electromechanical equipment includes sensors, actuators, lighting equipment, or fan controllers.

9. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, Key update steps during cross-domain migration of tunnel electromechanical equipment: When the tunnel electromechanical equipment is moved from the first region to the second region, the tunnel management center in the second region initiates a migration authorization request to the trusted center. After the trusted center verifies the device, the hardware identifier and some private keys remain unchanged. Only the associated geographical dispersion factor is updated to the provincial identifier, city identifier and tunnel identifier of the second region. After the tunnel electromechanical equipment is powered on in the second region, it re-derives a new session key based on the new regional dispersion factor and completes authentication and communication with the system in the second region.

10. The multi-level key distribution method for supporting cross-domain interoperability of tunnel electromechanical systems according to claim 1, characterized in that, In the multi-level geographical key distribution stage, the formula for the device to derive the session key is: Where H4 is the national cryptographic SM3 hash function, x i A personalized private key that the device chooses itself.

Citation Information

Patent Citations

  • Highway intelligent tunnel electromechanical system based on highway operation system

    CN117201134A

  • Security encryption method for electromechanical facility based on domestic password

    CN118074976A

  • Multi-level Internet of Things communication supervision method and system based on identity signature

    CN118590304A

  • Data transmission method and device based on multilayer encryption, equipment and medium

    CN119316224A