Wireless Sensor Network Mutual Authentication Using Diversified Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mutual identity authentication methods for wireless sensor networks face security deficiencies due to single authentication elements, vulnerability to hash function attacks, and high power consumption, particularly with limited calculation capabilities of terminal nodes.

Innovation Solution

A novel mutual authentication method that uses five diversified authentication elements: node identity ID, matrix password MX, random number R, administrator number AN, and administrator key AK, which enhance security by combining these elements through SHA1 transformations to calculate variance and energy values, thereby preventing targeted attacks and reducing computational burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication elements are used to enhance security, then security is improved, but time consumption and communication burden increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple authentication elements (identity ID, matrix password, random number, administrator number, and administrator key) into a unified authentication framework where all elements are processed together through SHA1 transformations. This merging approach allows comprehensive security verification while streamlining the authentication flow to reduce time consumption compared to sequential verification of each element separately.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary setup by pre-configuring the authentication elements (identity ID, matrix password, administrator number, and administrator key) in both the terminal node and platform before actual authentication occurs. The platform pre-generates and stores the necessary authentication data, so that during runtime authentication, the process is expedited by using pre-prepared verification materials rather than generating them in real-time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple authentication elements are used to enhance security, then security is improved, but communication burden increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcommunication burden
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges multiple authentication elements into consolidated data structures (such as combining identity ID, matrix password, and administrator key into unified authentication packets). This reduction in the number of separate communication messages decreases the overall communication burden while maintaining comprehensive security verification across all authentication elements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system uses cryptographic copying where the platform generates authentication elements and distributes verified copies to terminal nodes. These copied authentication data (identity ID, matrix password, administrator number) are then verified locally without requiring continuous communication, thereby reducing ongoing communication burden while maintaining security through the distributed copies.

Inventive Principle:
Principle #26Copying

3Reliability

If traditional authentication methods are used, then calculation capability requirements are low, but security is insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidcalculation capability requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex cryptographic mechanisms (such as ECDSA private key operations and multiple hash verification rounds) with streamlined SHA1 transformation operations on consolidated authentication elements. This substitution maintains strong security through the use of five diversified authentication elements while reducing the computational complexity and processing requirements for terminal nodes with limited capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the authentication parameters from traditional single-element or two-element approaches to a five-element framework (identity ID, matrix password, random number, administrator number, administrator key). This parameter expansion enhances security diversity while the use of efficient SHA1 transformations keeps the computational burden manageable for resource-constrained wireless sensor network nodes.

Inventive Principle:
Principle #35Parameter changes

4Ease of operation

If hash function verification is used to combine multiple elements, then authentication is simplified, but vulnerability to collision attacks increases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidcollision attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple authentication elements into unified SHA1 transformation operations rather than separately hashing each element and combining results. This merging approach simplifies the authentication process into a single verification step while enhancing collision resistance by ensuring all five elements (identity ID, matrix password, random number, administrator number, administrator key) are integrated into each transformation, making it computationally infeasible to find collisions.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2773062B1Mutual identity authentication method and system for wireless sensor network
Publication Date: 2018.10.24 ZTE CORP
  • EP2773062B1 patent drawingFigure 1
  • EP2773062B1 patent drawingFigure 2~3
  • EP2773062B1 patent drawing

AI summary

A mutual identity authentication method and system for a wireless sensor network are provided. In embodiments of the present document, authentication elements used in authentication are diversified, thus achieving the purpose of enhancing security of identity authentication. On the other hand, the embodiments of the present document avoid using a private key element currently under the risk of many attack measures, and therefore can effectively prevent the system from being damaged by some targeted attacks.