1.School of Information and Communication Engineering,Beijing University of Posts and Telecommunications,Beijing 100876,China
2.School of Cyberspace Security,Beijing University of Posts and Telecommunications/ Key Laboratory of Trustworthy Distributed Computing and Service,Ministry of Education,Beijing 100876,China
3.Education Management Information Center,Ministry of Education,Beijing 100816,China
4.School of Automation,Beijing Institute of Technology,Beijing 100081,China
5.Beijing Institute of Astronautical Systems Engineering,Beijing 100000,China
6.National Computer Emergency Network Response Technical Team/ Coordination Center of China,Beijing 100029,China
Aiming at the problems of weak keys, low security and many loopholes in the lightweight cryptography and authentication protocols used in most authentication models of the Internet of Things, a multi-factor enhanced authentication model was proposed based on zero-knowledge proof. The model was composed of one-way one-time computing type tasks, and combines various consensus verification technologies to form a multi-factor consensus verification method. And through the distributed consensus mechanism of the blockchain architecture, the enhanced processing function of multi-factor one-time difficult tasks had been realized. At the same time, flexible access control and privacy protection were realized by dynamically setting the type of evidence in the token. Finally, a simulation experiment was carried out to verify, and a prototype scene was constructed for the offline smart lock scene. Experimental results show that the model implements concise peer-to-peer verification of dynamic difficulty policies, exhibiting millisecond-level high performance and flexibility. Compared with other IoT authentication models, it has better security and practicality.
对于身份和权限的连续验证,为保障数据源头的真实性,传统的方式主要通过密码认证技术来保持数据的私密性。为进一步提高安全性,可考虑使用短信、证书、环境和生物特征等多因素,采用多步交互式方法识别对方身份,完成认证。在物联网设备之间完成端到端身份验证是一项挑战性的任务。首先,设备所在的物理环境和互联网中充满潜在的恶意用户。其次,虽然基于物理接近度和管理员PIN设置,便于绑定和解除设备以及建立信任关系,但是带来了中间人攻击、物理挟持以及暴力破解等风险。由于设备类型众多、与各系统的交互频繁,导致缺乏动态的自动或半自动的注册管控机制。再者由于物联网设备资源有限,导致身份验证机制薄弱,因此针对相关薄弱环节的恶意软件已经成为实现物联网安全功能的重要威胁。在物联网这种异构和复杂[6]的网络环境中,身份和授权是基本安全流程的重要组成部分[7],针对以上问题,Luk等[8]提出了身份认证的7个需要满足的属性。Yao等[9]提出了一种快速单向累加器,实现了轻量级多播认证机制。Cirani等[10]提出一种基于OAuth的物联网安全服务场景中授权服务架构,能够轻量化实现信任的多方传导。Devi等[11]提出一种物联网应用的相互认证方案,借助硬件设备ID自动识别和控制接入方。Lamport等[12]提出一次性动态密码(OTP)概念,设计在不安全通信中进行密码验证,实现长周期的持续安全保障。Shivraj等[13]提出一种轻量级的IBE-ECC算法,用于认证物联网设备和应用,并在云服务器中生成OTP以提高性能。Kairaldeen等[14]通过修改默克尔树内部的数据结构算法构建各种哈希函数来检查基于用户签名的身份管理框架,提高了区块链网络中的用户完整性检查性能。虽然这些方法利用轻量化认证和在第三方服务器运行复杂任务,解决了设备的耗电以及资源占用问题,但未考虑DDoS(distributed denial of service)攻击、中间人攻击和物理威胁等问题。
算法1中的HPC可根据当前的安全级别定义,k在1~5范围内动态叠加五个事实的验证算法,使用上述的ECC签名、PoW、同态加密E、Nyberg单向累加器以及zk-SNARKS简明单向零知识证明算法生成令牌串,增强验证串的难度(公式11)。在各种需要保护访问和验证真实性场景的情况下,都可以使用这种动态增强性令牌串,进行PoV(Proof of Verify)证明。
LINF H, LÜX, YOUI, et al. A novel utility based resource management scheme in vehicular social edge computing[J]. IEEE Access, 2018, 6: 66673-66684. DOI: 10.1109/ACCESS.2018.2878879 .
[2]
SUJ T, LINF H, ZHOUX W, et al. Steiner tree based optimal resource caching scheme in fog computing[J]. China Communications, 2015, 12(8): 161-168. DOI: 10.1109/CC.2015.7224698 .
[3]
RIDHAWI IAL, OTOUMS, ALOQAILYM, et al. Providing secure and reliable communication for next generation networks in smart cities[J]. Sustainable Cities and Society, 2020, 56: 102080. DOI: 10.1016/j.scs.2020.102080 .
XIAOG L, XIAOM J, GAOG J, et al. Incentive mechanism design for federated learning: A two-stage stackelberg game approach[C]//2020 IEEE 26th International Conference on Parallel and Distributed Systems (ICPADS). New York: IEEE Press, 2021: 148-155. DOI: 10.1109/ICPADS51040.2020.00029 .
[6]
GHEMAWATS, GOBIOFFH, LEUNGS T. The Google file system[C]//Proceedings of the 19th ACM symposium on Operating systems principles. New York: ACM, 2003: 29-43. DOI: 10.1145/945445.945450 .
[7]
KIMH, LEEE A. Authentication and authorization for the Internet of Things[J]. IT Professional, 2017, 19(5): 27-33. DOI: 10.1109/MITP.2017.3680960 .
[8]
LUK M, PERRIGA, WHILLOCKB. Seven cardinal properties of sensor network broadcast authentication[C]// Proceedings of the 4th ACM Workshop on Security of Ad-Hoc and Sensor Networks. New York: ACM, 2006: 147-156. DOI: 10.1145/1180345.1180364 .
[9]
YAOX X, HANX G, DUX J, et al. A lightweight multicast authentication mechanism for small scale IoT applications[J]. IEEE Sensors Journal, 2013, 13(10): 3693-3701. DOI: 10.1109/JSEN.2013.2266116 .
[10]
CIRANIS, PICONEM, GONIZZIP, et al. IoT-OAS: An OAuth-based authorization service architecture for secure services in IoT scenarios[J]. IEEE Sensors Journal, 2015, 15(2): 1224-1234. DOI: 10.1109/JSEN.2014.2361406 .
[11]
GOKULNATHC B, DEVIG U, BALANE V, et al. Mutual authentication scheme for IoT application[J]. Indian Journal of Science and Technology, 2015, 8(26):1-5. DOI: 10.17485/ijst/2015/v8i26/80996 .
[12]
LAMPORTL. Password authentication with insecure communication[J]. Communications of the ACM, 1981, 24(11): 770-772. DOI: 10.1145/358790.358797 .
[13]
SHIVRAJV L, RAJANM A, SINGHM, et al. One time password authentication scheme based on elliptic curves for Internet of Things (IoT)[C]//2015 5th National Symposium on Information Technology: Towards New Smart World (NSITNSW). New York: IEEE Press, 2015: 1-6. DOI: 10.1109/NSITNSW.2015.7176384 .
[14]
KAIRALDEENA R, ABDULLAHN F, ABU-SAMAHA, et al. Peer-to-peer user identity verification time optimization in IoT blockchain network[J]. Sensors, 2023, 23(4): 2106. DOI: 10.3390/s23042106 .
[15]
NAKAMOTOS. Bitcoin: A Peer-to-Peer Electronic Cash System[EB/OL]. [2023-04-01].DOI: 10.2139/ssrn.3977007 .
[16]
MARIJAND, LALC. Blockchain verification and validation: Techniques, challenges, and research directions[J]. Computer Science Review, 2022, 45: 100492. DOI: 10.1016/j.cosrev.2022.100492 .
[17]
KALAPAAKINGA P, KHALILI, YIX. Blockchain-based federated learning with SMPC model verification against poisoning attack for healthcare systems[J]. IEEE Transactions on Emerging Topics in Computing, 2023, PP(99): 1-11. DOI: 10.1109/TETC.2023.3268186 .
[18]
KOBLITZN, MENEZESA, VANSTONES. The state of elliptic curve cryptography[J]. Designs, Codes and Cryptography, 2000, 19: 173-193. DOI: 10.1023/A: 1008354106356 .
[19]
COURTOISN T, GRAJEKM, NAIKR. Optimizing SHA256 in bitcoin mining[C]// Cryptography and Security Systems. Heidelberg: Springer,2014: 131-144. DOI: 10.1007/978-3-662-44893-9_12 .
[20]
GOLDWASSERS, MICALIS, RACKOFFC. The knowledge complexity of interactive proof systems[J]. SIAM Journal on Computing, 1989, 18(1): 186-208. DOI: 10.1137/0218012 .
[21]
GERVAISA, KARAMEG O, WÜSTK, et al. On the security and performance of proof of work blockchains[C]// Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2016: 3-16. DOI: 10.1145/2976749.2978341 .
[22]
GEBOTYSC H, WHITEB A, MATEOSE. Preaveraging and carry propagate approaches to side-channel analysis of HMAC-SHA256[J]. ACM Transactions on Embedded Computing Systems, 2016, 15(1): 1-19. DOI: 10.1145/2794093 .
[23]
STEFFENS, BICHSELB, BAUMGARTNERR, et al. ZeeStar: Private smart contracts by homomorphic encryption and zero-knowledge proofs[C]//2022 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2022: 179-197. DOI: 10.1109/SP46214.2022.9833732 .
[24]
NIN, ZHUY X. Enabling zero knowledge proof by accelerating zk-SNARK kernels on GPU[J]. Journal of Parallel and Distributed Computing, 2023, 173: 20-31. DOI: 10.1016/j.jpdc.2022.10.009 .
[25]
ZCASH. A Privacy-Protecting, Digital Currency[EB/OL]. [2023-02-01].