节点文献
面向无人机网络的SM2隐式证书认证协议
SM2 Implicit Certificate Authentication Protocol for IoD
【作者】 刘强;
【作者基本信息】 西安电子科技大学 , 工程硕士(专业学位), 2022, 硕士
【摘要】 随着无人机技术的快速发展和空域的逐渐开放,无人机网络在农业、工业和军事等领域将得到更广泛的应用。由于无人机通信信道的开放性,确保无人机网络的安全和隐私至关重要。鉴于基于对称密码机制的安全协议存在自身无法克服的缺陷,公钥密码机制更适用于无人机网络中通信实体间的身份认证、会话密钥的建立和消息认证。而公钥认证(即公钥与身份的绑定)是保证公钥密码机制安全性的前提。但是,现有的公钥认证协议因计算效率低、通信开销大等问题,不适用于资源受限的无人机场景。另外,当前的公钥基础设施(Public Key Infrastructure,PKI)都依赖受信任的签署证书。但是,单独由CA颁发证书存在签署欺诈证书和证书透明度(Certificate Transparency,CT)弱的问题。谷歌提出的CT方案,使证书颁发对所有人公开可见,以增强CA参与签署证书过程的可信度。然而,基于签名证书时间戳(Signed Certificate Timestamp,SCT)的CT方案需要较高的计算成本验证SCT,同样不适用于资源受限的无人机场景。为此,本文致力于研究适用于无人机场景的公钥认证协议,根据CA的可信度,提出了两种公钥认证协议。在CA可信的情况下,提出了基于SM2的隐式证书认证方案,以解决现有的公钥认证协议计算效率低、通信开销大的问题。在CA不完全可信的情况下,提出了基于SM2的隐式证书透明度认证方案,以解决基于SCT的CT方案存在的问题,提高了公钥认证协议的证书透明度和撤销透明度。本文具体的研究成果概括如下:1.在CA可信的前提条件下,提出了一种基于SM2的隐式证书协议,并进一步将其与SM2密钥交换协议相结合,给出了认证密钥协商协议。随后,探索了基于Four Q曲线的协议优化实现。方案总体上实现了无人机网络中通信实体身份和公钥的绑定,完成了双方的身份认证并建立会话密钥。安全性上,协议符合SM2签名算法标准,可以抵抗常见的对现有无人机协议的攻击手段,特别是替换公钥的中间人攻击。实验证明该方案运算效率高、带宽开销低,可用于资源受限的无人机通信网络。2.在CA不完全可信的前提条件下,基于SM2隐式证书的构造规则提出了基于SM2的隐式证书透明度(SM2-based Implicit Certificate Transparency,SICT)协议。首先,在SICT协议的证书颁发过程中,提交到公共日志的SM2隐式证书与用户收到的证书一致,这降低了使用SM2隐式证书部署CT方案的复杂度。其次,在SICT协议的证书接收过程中,证书持有者证明证书有效性的同时验证了该证书的证书透明度,解决了传统PKI部署基于SCT的CT方案存在的问题。另外,为了进一步降低CA颁发伪造证书的可能性,在SICT协议基础上利用区块链技术提出基于区块链的证书透明度协议。该协议实现了证书在区块链上的注册、更新、撤销和查找功能,加强了SICT协议的证书透明度和撤销透明度。实验结果表明协议的计算开销低,适用于无人机通信网络。
【Abstract】 With the rapid development of UAV technology and the gradual opening of airspace,the Internet of Drones(Io D)will be more widely used in agriculture,industry,and military fields.Due to the open nature of drone communication channels,ensuring the security and privacy of drone networks is critical.In view of the insurmountable defects of the security protocol based on the symmetric cryptography mechanism,the public key cryptography mechanism is more suitable for identity authentication,the establishment of session keys and message authentication between communication entities in the Io D.And public key authentication(that is,the binding of public key and identity)is the premise to ensure the security of public key cryptography.However,the existing public key authentication protocols are not suitable for resource-constrained Io D due to low computational efficiency and high communication overhead.In addition,current public key infrastructure(PKI)all relied on a trusted Certificate Authority(CA)to sign certificates.However,issuing certificates by CA alone has the problems of signing fraudulent certificates and weak Certificate Transparency(CT).The CT scheme proposed by Google makes certificate issuance publicly visible to everyone to enhance the credibility of CAs involved in the process of signing certificates.However,the CT scheme based on Signed Certificate Timestamp(SCT)requires high computational cost to verify SCT,and is also not suitable for resource-constrained Io D.To this end,this paper is devoted to the research of public key authentication protocols suitable for UAV scenarios.According to the credibility of CA,two public key authentication protocols are proposed.When the CA is trusted,an implicit certificate authentication scheme based on SM2 is proposed to solve the problems of low computational efficiency and high communication overhead in the existing public key authentication protocols.In the case that the CA is not completely trusted,an implicit certificate transparency authentication scheme based on SM2 is proposed to solve the problems existing on the CT scheme based on SCT and improve the certificate transparency and revocation transparency of the public key authentication protocol.The specific research results of this paper are summarized as follows:1.Under the premise that the CA is trusted,an implicit certificate protocol based on SM2 is proposed,and it is further combined with the SM2 key exchange protocol to give an authenticated key agreement protocol.Subsequently,the protocol optimization implementation based on the Four Q curve is explored.The scheme generally realizes the binding of the communication entity identity and the public key in the Io D,completes the identity authentication of both parties and establishes the session key.In terms of security,the protocol conforms to the SM2 signature algorithm standard,which can resist common attack methods on existing drone protocols,especially the man-in-the-middle attack that replaces the public key.Experiments show that the scheme has high computational efficiency and low bandwidth overhead,and can be used in resource-constrained Io D.2.The SM2-based Implicit Certificate Transparency(SICT)protocol is proposed based on the construction rules of the SM2 implicit certificate under the premise that the CA is not completely trusted.First of all,in the certificate issuance process of the SICT protocol,the SM2 implicit certificate submitted to the public log is consistent with the certificate received by the user,which reduces the complexity of deploying the CT scheme using the SM2 implicit certificate.Then,during the certificate receiving process of the SICT protocol,the certificate holder verifies the validity of the certificate and verifies the certificate transparency of the certificate,which solves the problems existing in the traditional PKI deployment of the SCT-based CT scheme.Furthermore,in order to reduce the possibility of CAs issuing forged certificates,a blockchain-based certificate transparency protocol is proposed based on the SICT protocol using blockchain technology.This protocol realizes the functions of registration,renewal,revocation and search of certificates on the blockchain,and enhanced certificate transparency and revocation transparency of the SICT protocol.The experimental results show that the protocol has low computational overhead and is suitable for IoD.
【Key words】 IoD; SM2 implicit certificates; authenticated key agreement; CT; blockchain;