Method for combining authentication and secret keys management mechanism in a sensor network
Abstract
A method for combining authentication and secret keys management mechanism in a sensor network includes the following steps: 1) pre-distribution of the secret key, which includes 1.1) the pre-distribution of the communication secret key and 1.2) the pre-distribution of the initial broadcast message authentication secret key; 2) authentication, which includes 2.1) the authentication of the node identity and 2.2 the authentication of the broadcast message;and 3 negotiation of the session secret key by the nodes.
Term
Projected expiry 29 December 2029.
- Priority and filed
- Granted
- Today
- Projected expiry
11 claims: 7 independent, 4 dependent
- 11)鍵の予備配布を行い、即ち、 1.1 ) 配置サーバによって、 ネットワークを構築する前に、ノード間のセキュリティ接続を確立するための通信鍵をノードに予備配布する通信鍵の予備配布を行い、 1.2 ) 配置サーバによって、 ネットワークを構築する前に、ブロードキャストメッセージを認証するための初期鍵をブロードキャストメッセージ受信ノードに予備配布する初期ブロードキャストメッセージ認証鍵の予備配布を行い、 2) 認証を行い、即ち、 2.1 ) ネットワークを構築した後に、通信ノードは通信する前に、相手の身分の正当性を認証するノード身分認証を行い、 2.2 )ネットワークを構築した後に、ネットワークにブロードキャストが存在する時に、ブロードキャストメッセージ受信ノードはブロードキャストメッセージの正当性を認証するブロードキャストメッセージ認証を行い、 3 ) ノードはセッション鍵の合意を行い、即ち、 ノード身分認証が成功した後に、ノード身分認証の過程の結果に基づいて、ノードの間でセッション鍵を合意して生成することを含 み、 前記のステップ2.1)において、ネットワークが構築された後に、ノード通信の前に、ノードの間で共有鍵を確立してから、共有鍵に基づいて予備共有鍵による認証を行い、 前記の予備共有鍵による認証過程は、 a)ノードAは乱数N A を生成してノードBに送信し、 b)ノードBは乱数N B を生成し、ノードAとのセッション鍵SK=F(PSK, N B ||N A )を算出し、その後にセッション鍵SKを用いてメッセージ認証コードMAC 1 =H (SK, N B ||N A )を生成し、メッセージN B ||N A ||MAC 1 を構成してノードAに送信し、 c)ノードAは、まず、メッセージにおける乱数 N A がステップa)でのノードBに送信した乱数と一致するか否かをチェックし、一致しない場合に、認証を終了し、一致する場合にノードBとのセッション鍵SK=F(PSK, N B ||N A )を算出し、SKを利用して認証コードMAC 2 =H(SK,Ν Β ||Ν Α )を生成し、MAC 2 =MAC 1 の場合に、ノードAはMAC 3 =H(SK,Ν Β )を算出し、メッセージN B ||MAC 3 を構成してノードBに送信することを含み、 ただし、前記PSKは予備共有鍵を示し、Fは鍵生成アルゴリズムを示し、Hは一方向ハッシュ関数を示す ことを特徴とするセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 2前記のステップ1.1)は、 1.1.1 ) 配置サーバによって、 ネットワークを構築する前に、ネットワークの規模に基づいて鍵プールを生成し、 1.1.2 ) 配置サーバによって、 ネットワークにおけるノードの数および所望するネットワークの接続性に基づいて、すべてのノードに鍵を予備配布すること、 を含むことを特徴とする請求項1に記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 3基本的なランダム鍵予備配布の方法を採用し、前記のステップ1.1.1 )において、センサーネットワークを構築する前に、配置サーバは、まず、鍵の総数がPの鍵プールおよび鍵プールにおけるすべての鍵の鍵フラグを生成し、 前記ステップ1.1.2 )において、 配置サーバによって、 ネットワークにおけるノードの数、所望するネットワークの接続性およびノードの所望する近隣ノードの数に基づいて、ノードごとに鍵プールからk個の異なる鍵をランダムに選択して鍵 チェーン を構成して、当該ノードにロードし、ただし、k<<P であることを特徴とする請求項2に記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 4前記のステップ1.2)は、 1.2.1) ネットワークを構築する前に、配置サーバはネットワークの規模およびブロードキャストノードの特徴に基づいて、ブロードキャストメッセージ認証鍵 チェーン を生成し、 1.2.2 ) 配置サーバはブロードキャストメッセージ認証鍵 チェーン における初期鍵を、すべてのブロードキャストメッセージ受信ノードに予備配布することを含むことを特徴とする請求項1ないし3の何れかに記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 5μTESLAブロードキャストメッセージ認証方法を採用し、前記のステップ1.2.1)において、ネットワークを構築する前に、配置サーバはブロードキャストノードの生存期間、ブロードキャストメッセージ認証鍵の公開遅延(disclosing delay )の パラーメータに基づいて、ブロードキャストメッセージを認証するための一方向ハッシュ チェーン 、即ち、ブロードキャストメッセージ認証鍵 チェーン を生成し、 前記のステップ1.2.2)において、配置サーバはブロードキャストメッセージ認証鍵 チェーン を、ブロードキャストノードに配布し、当該鍵 チェーン における チェーン ヘッド鍵を、すべてのブロードキャストメッセージ受信ノードに配布することを特徴とする請求項4に記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 6前記のステップ2.2)において、ネットワークにブロードキャストが存在する場合に、ノードは、予備配布した初期ブロードキャストメッセージ認証鍵に基づいてブロードキャストメッセージの正当性を認証することを特徴とする請求項1ないし 5 の何れかに記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 7μTESLAブロードキャストメッセージ認証方法を採用し、前記の、ノードが予備配布した初期ブロードキャストメッセージ認証鍵に基づいてブロードキャストメッセージの正当性を認証することは、ブロードキャストノードがブロードキャストメッセージ認証鍵 チェーン における、ある鍵K i を利用して、ブロードキャストすべきメッセージに対してMAC演算を行い、ブロードキャストメッセージをMAC値とともにブロードキャストメッセージ受信ノードに送信し、予め設定されたブロードキャストメッセージ認証鍵の公開遅延が行われた後に、ブロードキャストノードがK i をブロードキャストメッセージ受信ノードに送信し、受信ノードが予備配布した初期ブロードキャストメッセージ認証鍵に基づいて、まずK i の有効性を検証し、その後にK i に基づいてブロードキャストメッセージのMAC値の正当性を検証することにより、ブロードキャストメッセージの正当性を検証することを含むことを特徴とする請求項 6 に記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 8前記のステップ3)は、 3.1 )ノードの間にポイントツーポイントの通信が必要する場合に、認証過程の結果に基づいて、ノードの間でユニキャストセッション鍵の合意を行い、 3.2 )ノードの間に一対複数の通信が必要する場合に、認証過程およびユニキャストセッション鍵の合意の結果に基づいて、ノードの間でマルチキャストセッション鍵の合意を行うことを含むことを特徴とする請求項1ないし 7 の何れかに記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 9前記のステップ3.2)におけるマルチキャストセッション鍵の合意のステップは、 a ) マルチキャストノードはマルチキャストセッション鍵MSKを生成し、 b ) マルチキャストノードは、 マルチキャストメッセージ受信ノードとの間で生成したユニキャストセッション鍵を利用して、MSKを暗号化してマルチキャストメッセージ受信ノードに送信し、マルチキャストメッセージ受信ノードはMSKを保存してマルチキャストノードに応答することを含むことを特徴とする請求項 8 に記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 10前記ノードは、センサーネットワークにおける基地局、クラスタノード 、汎用ノードであることを特徴とする請求項1ないし 9 の何れかに記載のセンサーネットワーク認証と鍵管理メカニズムとの統合方法。
- 11配置サーバとノードとを含み、前記ノードは、ブロードキャストノードと、ブロードキャストメッセージ受信ノードと、マルチキャストメッセージ受信ノードと、マルチキャストノードとを含み、前記配置サーバは、通信鍵と初期ブロードキャストメッセージ認証鍵をノードに予備配布し、前記ノードは、認証とセッション鍵の合意を行い、但し、前記ブロードキャストノードはブロードキャストメッセージをブロードキャストメッセージ受信ノードに送信し、前記ブロードキャストメッセージ受信ノードはブロードキャストノードのブロードキャストメッセージを受信して処理し、前記マルチキャストノードはマルチキャストメッセージをマルチキャストメッセージ受信ノードに送信し、前記マルチキャストメッセージ受信ノードはマルチキャストノードのマルチキャストメッセージを受信して処理 し、 前記認証において、ネットワークが構築された後に、ノード通信の前に、ノードの間で共有鍵を確立してから、共有鍵に基づいて予備共有鍵による認証を行い、 前記の予備共有鍵による認証は、 a) ノードAは乱数N A を生成してノードBに送信し、 b)ノードBは乱数N B を生成し、ノードAとのセッション鍵SK=F(PSK, N B ||N A )を算出し、その後にセッション鍵SKを用いてメッセージ認証コードMAC 1 =H (SK, N B ||N A )を生成し、メッセージN B ||N A ||MAC 1 を構成してノードAに送信し、 c)ノードAは、まず、メッセージにおける乱数 N A がステップa)でのノードBに送信した乱数と一致するか否かをチェックし、一致しない場合に、認証を終了し、一致する場合にノードBとのセッション鍵SK=F(PSK, N B ||N A )を算出し、SKを利用して認証コードMAC 2 =H(SK,Ν Β ||Ν Α )を生成し、MAC 2 =MAC 1 の場合に、ノードAはMAC 3 =H(SK,Ν Β )を算出し、メッセージN B ||MAC 3 を構成してノードBに送信することを含み、 ただし、前記PSKは予備共有鍵を示し、Fは鍵生成アルゴリズムを示し、Hは一方向ハッシュ関数を示す ことを特徴とするセンサーネットワーク認証と鍵管理メカニズムとの統合システム。
Independent claims11
27 paragraphs, as filed
0001This application claims the priority of a Chinese patent application filed with the China Patent Office on July 15, 2009, with an application number of 200910023382.9 and an invention name of "method of integrating sensor network authentication and key management mechanism". However, all the contents will be incorporated into this application. The present invention relates to a method of integrating sensor network authentication with a key management mechanism.
0002The sensor network consists of a large number of small, inexpensive, battery-powered sensor nodes with wireless communication and monitoring capabilities. These nodes are closely located in the monitoring area to achieve the purpose of monitoring the physical world. Wireless sensor networks are a new research direction in information technology and have the potential to be widely applied in areas such as environmental monitoring, military, national defense, traffic restrictions, housing complex safety defense, forest fire prevention, and target positioning.
0003Security issues in sensor networks are especially important as sensor nodes are typically located in unmanned or enemy areas. The sensor network is a data-centric data collection platform, and the construction of security sensor network authentication and key management infrastructure is the basis for realizing data security integration, storage and access control. Currently, research on sensor network security technologies has already made great progress, and many sensor network security technologies have already been designed. Key management is the basis of sensor network security and is a supporting technology for realizing node secret communication and identity authentication between nodes. Generally, key pre-distribution before network construction and key establishment after network construction It consists of two stages: and session key agreement. Authentication is divided into message authentication and identity authentication. Sensor networks broadcast important functions such as creating routing tables, querying networks, updating software, synchronizing time, and managing networks. Due to its radio and broadcast characteristics, broadcast information can be tampered with or inserted malicious information by an attacker, so an authentication mechanism must be introduced to ensure the legitimacy and completeness of the broadcast information. is there. Broadcast message authentication technology is also the basis of sensor network security. Identity verification is the basis of computer network security, as well as the basis of sensor network security, and is used to authenticate the identity and effectiveness of both communications. Key management and authentication are both essential and mutually supported in sensor network security solutions as core security mechanisms. The authentication mechanism needs to be provided with a pre-shared or initial key by the key pre-distribution technique in the key management mechanism. On the other hand, the session key in the key management mechanism The consensus technology is based on the results of identity verification technology. Only by the cooperation of these two, a basic sensor network security solution can be constructed. However, current sensor network key management and authentication mechanisms do not take into account the integration between the two at design time and cannot provide complete secret communication and authentication services to the sensor network. There are still security risks.
<p num="0004"> To solve problems existing in the background technology, the present invention integrates sensor network authentication and integrated sensor network authentication by aligning security mechanisms such as sensor network key management, identity authentication, and broadcast message authentication in the protocol processing process. It formed a key management method and provided a basic solution for sensor network security.</p>
<p num="0005"> The technical solution according to the invention provided a method of integrating sensor network authentication with a key management mechanism. The method is characterized by including the following steps. That is,</p><p num="0006"> 1) Pre-distribute the key, that is,</p><p num="0007"> 1.1) Pre-distribute the communication key to establish the security connection between the nodes before building the network. Pre-distribute the communication key to the nodes.</p><p num="0008"> 1.2) Before building the network, pre-distribute the initial key for authenticating the broadcast message to the broadcast message receiving node. Pre-distribute the initial broadcast message authentication key.</p><p num="0009"> 2) Authenticate, that is,</p><p num="0010"> 2.1) After building the network, before communicating, the communication node performs node identity authentication to authenticate the identity of the other party, and then performs node identity authentication.</p><p num="0011"> 2.2) After building the network, when there is a broadcast on the network, the broadcast message receiving node performs broadcast message authentication to authenticate the validity of the broadcast message.</p><p num="0012"> 3) The node agrees on the session key, i.e.</p><p num="0013"> This includes agreeing and generating a session key between nodes based on the result of the node identification process after successful node identification.</p><p num="0014"> The specific implementation method of step 1.1) above is as follows.</p><p num="0015"> 1.1.1) Before building the network, generate a key pool based on the size of the network and</p><p num="0016"> 1.1.2) Pre-distribute keys to all nodes based on the number of nodes in the network and the desired network connectivity.</p><p num="0017"> The basic random key pre-distribution method is adopted, and the specific implementation method of step 1.1) above is as follows. That is, before building the sensor network, the deployment server first generates key flags for all keys in the key pool and key pool where the total number of keys is P, and then the number of nodes in the network, of the desired network. Randomly select k different keys from the key pool for each node based on connectivity and the number of neighboring nodes desired by the node.<u style="single">chain</u>And load it on the node, where k << P.</p><p num="0018"> The specific implementation method of step 1.2) above is as follows. That is,</p><p num="0019"> 1.2.1) Before building the network, the deployment server has a broadcast message authentication key based on the size of the network and the characteristics of the broadcast node.<u style="single">chain</u>To generate</p><p num="0020"> 1.2.2) The deployment server is the broadcast message authentication key<u style="single">chain</u>Pre-distribute the initial key in to all broadcast message receiving nodes.</p><p num="0021"> The μTESLA broadcast message authentication method is adopted, and the specific implementation method of step 1.2) above is as follows. That is, before building the network, the deployment server has a one-way hash to authenticate the broadcast message based on parameters such as the lifetime of the broadcast node and the delay in publishing the broadcast message authentication key.<u style="single">chain</u>That is, the broadcast message authentication key<u style="single">chain</u>Is then generated by the deployment server with a broadcast message authentication key<u style="single">chain</u>Is distributed to the broadcast node, and the key is<u style="single">chain</u>In<u style="single">chain</u>Distribute the head key to all broadcast message receiving nodes.</p><p num="0022"> The specific implementation method of step 2.1) above is as follows. That is, after the network is constructed, before node communication, a shared key is established between the nodes, and then authentication is performed using a preliminary shared key based on the shared key, or other preset authentication methods. Identity authentication between nodes is performed based on.</p><p num="0023"> The authentication process using the preliminary shared key described above</p><p num="0024"> a) Node A is a random number N<sub>A</sub>Is generated and sent to node B,</p><p num="0025"> b) Node B is a random number N<sub>B</sub>Is generated and the session key with node A SK = F (PSK, N)<sub>B</sub>|| N<sub>A</sub>) Is calculated, and then the message authentication code MAC is used using the session key SK.<sub>1</sub>= H (SK, N<sub>B</sub>|| N<sub>A</sub>) And message N<sub>B</sub>|| N<sub>A</sub>|| MAC<sub>1</sub>To configure and send to node A,</p><p num="0026"> c) Node A first has a random number in the message <u style="single">N</u><sub><u style="single">A</u></sub>Checks whether it matches the random number sent to node B in step a), and if it does not match, the authentication ends, and if it matches, the session key with node B SK = F (PSK, N)<sub>B</sub>|| N<sub>A</sub>) Is calculated and the authentication code MAC2 = H (SK, Ν) is used using SK.<sub>Β</sub>|| Ν<sub>Α</sub>) And MAC<sub>2</sub>= MAC<sub>1</sub>In the case of, node A is MAC<sub>3</sub>= H (SK, Ν<sub>Β</sub>) Is calculated and message N<sub>B</sub>|| MAC<sub>3</sub>Includes configuring and sending to node B.</p><p num="0027"> However, the PSK indicates a pre-shared key, F indicates a key generation algorithm, and H indicates a one-way hash function.</p><p num="0028"> The specific implementation method of step 2.2) above is as follows. That is, when a broadcast exists on the network, the node authenticates the validity of the broadcast message based on the pre-distributed initial broadcast message authentication key.</p><p num="0029"> The μTESLA broadcast message authentication method is adopted, and the specific implementation method of step 2.2) above is as follows. That is, the broadcast node is the broadcast message authentication key.<u style="single">chain</u>In, a key K<sub>i</sub>Performs a MAC operation on the message to be broadcast, sends the broadcast message together with the MAC value to the broadcast message receiving node, delays the publication of the preset broadcast message authentication key, and then the broadcast node. Is K<sub>i</sub>To the broadcast message receiving node, and based on the initial broadcast message authentication key pre-distributed by the receiving node, first K<sub>i</sub>Verify the effectiveness of, then K<sub>i</sub>The validity of the broadcast message is verified by verifying the validity of the MAC value of the broadcast message based on.</p><p num="0030"> The specific method for realizing step 3) above is as follows. That is,</p><p num="0031"> 3.1) When point-to-point communication is required between the nodes, a unicast session key agreement is made between the nodes based on the result of the authentication process.</p><p num="0032"> 3.2) When one-to-many communication is required between nodes, a multicast session key agreement is made between the nodes based on the authentication process and the result of the unicast session key agreement.</p><p num="0033"> The agreement method in step 3) above is as follows. That is,</p><p num="0034"> a) The multicast node generates a multicast session key MSK</p><p num="0035"> b) Using the unicast session key generated with the multicast message receiving node, the MSK is encrypted and sent to the multicast message receiving node, and the multicast message receiving node stores the MSK and responds to the multicast node.</p><p num="0036"> In step 3) above, when a broadcast is present on the network, the broadcast message receiving node authenticates the validity of the broadcast message.</p><p num="0037"> The above nodes are base stations, cluster nodes, and general-purpose nodes in the sensor network.</p><p num="0038"> The deployment server includes a broadcast node, a broadcast message receiving node, a multicast message receiving node, and a multicast node, and the deploying server provides a communication key and an initial broadcast message authentication key to the node. Pre-distributed, the node authenticates and agrees on a session key, provided that the broadcast node sends a broadcast message to the broadcast message receiving node, and the broadcast message receiving node receives and processes the broadcast node's broadcast message. An integrated system of sensor network authentication and key management mechanism, wherein the multicast node sends a multicast message to a multicast message receiving node, and the multicast message receiving node receives and processes the multicast message of the multicast node. Is.</p><p num="0039"> The merits of the present invention are as follows. That is, the present invention provides a method for integrating sensor network authentication and a key management mechanism, and integrates basic security technologies by sensor networks such as key management, identity authentication, and broadcast message authentication in a process to ensure sensor network security. Build the infrastructure. The present invention first aligns the key pre-distribution in the sensor network key management technology with the pre-distribution process of the initial broadcast message authentication key in the broadcast message authentication technology, and before the network is constructed, the communication key and the initial broadcast message. Pre-distribute the authentication key to the network nodes to provide support for identity verification, secret communication, and broadcast message authentication after the network is built. Next, combine broadcast message authentication with the identity verification and session key agreement process. This allows authentication for broadcast messages to be provided at the same time as performing identity verification and session key agreement. By matching the sensor network basic security technology, the present invention constitutes a sensor network security system structure and forms a basic sensor network security solution.</p>
0040<figref num="1">It is a flowchart of the integration method provided by this invention.</figref>
0041With reference to FIG. 1, the present invention provides a method of integrating sensor network authentication and key management mechanisms. The method includes the following steps. That is,
00421) Pre-distribute the key. The step mainly includes the following two sub-steps. That is,
00431.1) Pre-distribute the communication key, that is, pre-distribute the communication key for establishing a security connection between the nodes to the nodes before building the network. The specific implementation method is as follows. .. That is,
00441.1.1) Before building the network, generate a key pool according to the size of the network and
00451.1.2) Pre-distribute keys to all nodes depending on the number of nodes in the network and the desired network connectivity.
0046By the basic random key pre-distribution method, before building a sensor network, the deployment server first generates key flags for key pools with a total number of keys P and all keys in the key pool, and then the network. Randomly select k different keys from the key pool for each node based on the number of nodes in, the desired network connectivity, and the desired number of neighbors of the node.<u style="single">chain</u>Is configured and loaded on the node. However, k << P. By such a random pre-distribution method, adjacent nodes can share a key with a certain probability, a security connection can be established, and the desired network connectivity can be ensured after the network is constructed.
00471.2) Pre-distribute the initial broadcast message authentication key, that is, pre-distribute the initial key for authenticating the broadcast message to the broadcast message receiving node before building the network. The specific implementation form is as follows. It's a street. That is,
00481.2.1) Before building the network, the deployment server has a broadcast message authentication key based on the size of the network and the characteristics of the broadcast node.<u style="single">chain</u>To generate
00491.2.2) The deployment server is the broadcast message authentication key<u style="single">chain</u>Pre-distribute the initial key in to all broadcast message receiving nodes.
0050With the μTESLA broadcast message authentication method, the deployment server is one-way to authenticate broadcast messages based on parameters such as the lifetime of the broadcast node and the disclosing delay of the broadcast message authentication key before building the network. hash<u style="single">chain</u>That is, the broadcast message authentication key<u style="single">chain</u>Is then generated by the deployment server with a broadcast message authentication key<u style="single">chain</u>Is distributed to the broadcast node, and the key is<u style="single">chain</u>In<u style="single">chain</u>Distribute the head key to all broadcast message receiving nodes. The placement server gives the broadcast node a broadcast message authentication key.<u style="single">chain</u>It is also possible to adopt an on-run method when transmitting.
00512) Authenticate. It mainly includes the following two substeps. That is,
00522.1) After authenticating the identity of the node, that is, after constructing the network, the communication node authenticates the identity of the other party before communicating. As a concrete implementation form, after building a network and before node communication, a shared key is established between nodes, and then authentication is performed using a preliminary shared key based on the shared key, or preset. Authenticate the identity between nodes based on other authentication methods.
0053Authentication is performed based on the shared key PSK by the authentication method based on the pre-shared key. The authentication method adopts the following steps. That is, a) Node A is a random number N<sub>A</sub>Is generated and sent to node B, and b) B is a random number N.<sub>B</sub>Is generated and the session key with node A SK = F (PSK, N)<sub>B</sub>|| N<sub>A</sub>) Is calculated, and then the message authentication code MAC is used by SK.<sub>1</sub>= H (SK, N<sub>B</sub>|| N<sub>A</sub>) And message N<sub>B</sub>|| N<sub>A</sub>|| MAC<sub>1</sub>And send to node A, c) node A first random numbers in the message <u style="single">N</u><sub><u style="single">A</u></sub>Checks if it matches the random number sent to node B in step a) by itself, and if it does not match, it terminates authentication, and if it does, the session key SK = F (PSK) with node B. , N<sub>B</sub>|| N<sub>A</sub>) Is calculated and the authentication code MAC is used using SK.<sub>2</sub>= H (SK, Ν<sub>Β</sub>|| Ν<sub>Α</sub>) And MAC<sub>2</sub>= MAC<sub>1</sub>In the case of, A is MAC<sub>3</sub>= H (SK, Ν<sub>Β</sub>) Is calculated and message N<sub>B</sub>|| MAC<sub>3</sub>Is configured and sent to node B. However, the PSK indicates a pre-shared key, F indicates a key generation algorithm, and H indicates a one-way hash function.
00542.2) After performing broadcast message authentication, that is, after building the network, when the broadcast exists in the network, the broadcast message receiving node authenticates the validity of the broadcast message. The specific implementation method is as follows. That is, when a broadcast exists on the network, the node authenticates the validity of the broadcast message based on the pre-distributed initial broadcast message authentication key. Broadcast message authentication can occur at any time after the network is built, eg, during the session key agreement process, based on the broadcast situation in the network.
0055By the μTESLA broadcast message authentication method, the broadcast node first has a broadcast message authentication key.<u style="single">chain</u>A key in K<sub>i</sub>Performs a MAC operation on the message to be broadcast, sends the broadcast message together with the MAC value to the broadcast message receiving node, and then broadcasts after the public delay of the preset broadcast message authentication key. Node is K<sub>i</sub>Is sent to the broadcast message receiving node, and the receiving node first K based on the pre-distributed initial broadcast message authentication key.<sub>i</sub>Verify the effectiveness of, then K<sub>i</sub>The validity of the broadcast message is verified by verifying the validity of the MAC value of the broadcast message based on.
00563) Agree the session key, that is, after the node identification is successful, the session key is agreed and generated between the nodes based on the result of the node identification. In this process, when a broadcast is present on the network, the broadcast message receiving node authenticates the validity of the broadcast message and is completed primarily by the following substeps. That is,
00573.1) When point-to-point communication is required between nodes, a unicast session key agreement is made between the nodes based on the result of the authentication process.
00583.2) When one-to-many communication is required between nodes, a multicast session key agreement is made between the nodes based on the authentication process and the result of the unicast session key agreement.
0059The following steps can be adopted as a specific agreement method. That is, a) the multicast node generates a multicast session key MSK, and b) uses the unicast session key generated with the multicast message receiving node to encrypt the MSK and send it to the multicast message receiving node, and multicast. The message receiving node stores the MSK and responds to the multicast node.
0060The node in the present invention means various network entities in a sensor network, and includes, but is not limited to, a base station, a cluster node, a general-purpose node, and the like.
0061An integrated system of sensor network authentication and key management mechanism, including a deployment server and a node, the node including a broadcast node, a broadcast message receiving node, a multicast message receiving node, and a multicast node. Pre-distributes the communication key and initial broadcast message authentication key to the node, the node agrees on authentication and session key, the broadcast node sends the broadcast message to the broadcast message receiving node, and the broadcast message receiving node is the broadcast node. The broadcast message is received and processed by the multicast node, the multicast message is sent to the multicast message receiving node, and the multicast message receiving node is an integrated system that receives and processes the multicast message of the multicast node.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2008543245A | Cites | Japan |
| CN101232378A | Cites | China |
| S. Zhu et al.,LEAP: efficient security mechanisms for large-scale distributed sensor networks,Proceedings of the 10th ACM conference on Computer and communications security (CCS '03),ACM,2003年,pp. 62-72,[2013年4月11日検索],インターネット,URL,http://dl.acm.org/citation.cfm?id=948120 | Non-patent | – |
| S. A. Camtepe et al.,Key Distribution Mechanisms for Wireless Sensor Networks: a Survey,Technical Report,Department of Computer Science,Rensselaer Polytechnic Institute,2005年 3月23日,TR-05-07,[2013年4月11日検索],インターネット,URL,www.cs.rpi.edu/research/pdf/05-07.pdf | Non-patent | – |
12 members in 6 offices
Members12
| Document | Office | Kind | |
|---|---|---|---|
| CN101610452A | China | A | |
| WO2011006341A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN101610452B | China | B | |
| US2012114124A1 | United States of America | A1 | |
| KR20120047911A | Republic of Korea | A | |
| EP2456243A1 | European Patent Office (EPO) | A1 | |
| JP2012533237A | Japan | A | |
| US8571223B2 | United States of America | B2 | |
| JP5367168B2This record | Japan | B2 | |
| KR101486030B1 | Republic of Korea | B1 | |
| EP2456243A4 | European Patent Office (EPO) | A4 | |
| EP2456243B1 | European Patent Office (EPO) | B1 |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 5367168
- Application
- 2012519869
Titles2
- Japanese
- センサーネットワーク認証と鍵管理メカニズムの統合方法
- English
- How to integrate sensor network authentication and key management mechanism
Classification
- CPC, 14
- H04L9/0822
- H04L9/083
- H04L9/3242
- H04L63/062
- H04L63/126
- H04L2209/601
- H04L2209/805
- H04W84/18
- H04L9/0833
- H04L63/065
- H04L9/3228
- H04W12/041
- H04W12/069
- H04L9/50
- IPC, 6
- H04L9 32
- H04L9 08
- G09C1 00
- H04W12 0431
- H04W12 0433
- H04W12 06