Communication Authentication Using ASCON-AEAD for Low-Power Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security authentication solutions in communications technologies suffer from poor authentication attributes, leading to inefficient computational overheads and high energy consumption, particularly in resource-limited environments.
Innovation Solution
A communication method and device that generates authentication information based on a shared key, incorporating device and service-related information, and uses a lightweight ASCON-AEAD algorithm to integrate authentication and encryption into a single operation, reducing computational overheads and energy consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security authentication protocols are used, then authentication can be performed, but authentication attributes are poor and computational overhead is high
Solution Approach 1:
The patent combines authentication and encryption operations into a single integrated operation using the ASCON-AEAD algorithm. This merging of functions reduces computational overhead by eliminating redundant processing steps while maintaining strong authentication attributes through the unified security mechanism.
Solution Approach 2:
The patent changes the parameter set used in authentication by incorporating multiple information types (service-related information, device identity, random numbers) into the authentication information generation process. This parameter expansion enhances authentication attributes without proportionally increasing computational complexity.
2Reliability
If traditional security authentication protocols are used, then authentication can be performed, but energy consumption is high
Solution Approach 1:
By merging authentication and encryption into a single operation, the patent reduces the total number of computational steps required, thereby lowering energy consumption. The integrated ASCON-AEAD algorithm performs both security functions simultaneously, eliminating the energy waste associated with sequential processing.
Solution Approach 2:
The patent employs lightweight cryptographic primitives and temporary random numbers that are generated and discarded after use. This approach uses computationally efficient, low-cost cryptographic operations that consume minimal energy compared to traditional heavy-duty authentication protocols.
3Reliability
If more information is included in authentication, then authentication attributes improve, but computational overhead increases
Solution Approach 1:
The patent strategically changes the parameter set by selecting specific information elements (service-related information, device identity, random numbers) that provide high authentication value with minimal computational cost. This parameter optimization enhances authentication attributes while maintaining computational efficiency.
Solution Approach 2:
The patent incorporates multiple types of information into authentication information generation, using partial authentication data from different sources. This partial action approach ensures sufficient authentication attributes are achieved without processing every possible data element, thereby maintaining computational efficiency.
Data Source
Figure 1~2
Figure 3A~4
Figure 5~6
AI summary
Provided are communication methods and communication devices. One method comprises: on the basis of a shared key, a first device generates a first key; the first device receives a second random number of a second device; on the basis of the first key, the first device generates first authentication information of the first device; and the first device sends a first message to the second device, the first message comprising the first authentication information, and the first authentication information being generated according to one or more of the following information: device information, service-related information, an identifier of a device forwarding the first message, and a first random number and a second random number of the first device. Compared with the prior art, the first authentication information of the present application can carry more information. Therefore, the present application can provide authentication attributes, such that first authentication information-based security authentication processes can verify more information. In addition, the first authentication information-based security authentication processes can also negotiate about keys.