吉林大学学报(工学版) ›› 2026, Vol. 56 ›› Issue (3): 772-778.doi: 10.13229/j.cnki.jdxbgxb.20241032

• 计算机科学与技术 • 上一篇    

应用轻量级双向认证协议的公共数据安全优化算法

张悦1(),周鑫2   

  1. 1.中国人民公安大学 涉外警务学院,北京 100089
    2.国防科技大学 信息通信学院,武汉 430000
  • 收稿日期:2024-09-23 出版日期:2026-03-01 发布日期:2026-03-31
  • 作者简介:张悦(1996-),女,讲师,博士研究生.研究方向:公共安全.E-mail:13261708806@163.com
  • 基金资助:
    国家自然科学基金项目(62201581)

Public data security optimization algorithm using lightweight bidirectional authentication protocol

Yue ZHANG1(),Xin ZHOU2   

  1. 1.School of International Policing,People's Public Security University of China,Beijing 100089,China
    2.College of Information and Communication,National University of Defense Technology,Wuhan 430000,China
  • Received:2024-09-23 Online:2026-03-01 Published:2026-03-31

摘要:

针对公共数据来源广、信息量大、敏感性高且单向身份认证网络易遭受多种攻击,导致公共数据安全性不足的问题,提出了一种应用轻量级双向认证协议的公共数据安全优化算法。该算法结合物理不可克隆函数(PUF)和同步化随机数,获得轻量级双向认证协议,降低优化过程中的运算和通信开销。通过可信网络连接对协议接入过程中用户读写器的可信度进行认证,将同步化随机数设置于用户读写器与公共数据电子标签两端,并将PUF融入公共数据电子标签内,增强海量公共数据电子标签密钥对各类攻击的抵抗性能,完成用户读写器与公共数据电子标签的双向身份认证,实现敏感数据的安全优化防护。研究结果表明,该算法可有效抵抗公共数据存储和传输过程中的去同步化攻击、克隆攻击、中间人攻击等10种攻击,且具有较低的时延,可保障公共数据的安全性。

关键词: 轻量级, 双向认证协议, 公共数据, 安全优化, 不可克隆函数, 同步化随机数

Abstract:

To address the problem of insufficient security of public data caused by its characteristics of wide sources, large information volume, and high sensitivity, as well as the vulnerability of one-way authentication networks to various attacks, an optimized public data security algorithm applying a lightweight mutual authentication protocol was proposed. A lightweight mutual authentication protocol was obtained by combining Physical Unclonable Functions (PUF) with synchronized random numbers in this algorithm, which reduces the computational and communication overheads during the optimization process. The credibility of user readers during protocol access was authenticated through trusted network connections. Synchronized random numbers were deployed at both ends of user readers and public data electronic tags, and PUF was integrated into the public data electronic tags to enhance the resistance of keys in massive public data electronic tags against various attacks. Thus, mutual identity authentication between user readers and public data electronic tags was completed, and secure optimized protection of sensitive data was achieved. The research results show that the algorithm can effectively resist 10 types of attacks, including de synchronization attacks, cloning attacks, and man in the middle attacks, during the storage and transmission of public data, and has low latency, which can ensure the security of public data.

Key words: lightweight, bidirectional authentication protocol, public data, safety optimization, unclonable functions, synchronize random numbers

中图分类号: 

  • TP393

表1

算法关键符号及定义"

符号定义
R后台服务器
U公共数据电子标签
S用户读写器
ID U公共数据电子标签的真实身份标志
IDU,old'公共数据电子标签的前一轮临时身份标志
IDU,new'公共数据电子标签的本轮临时身份标志
bm公共数据电子标签与用户读写器的同步化随机数
(PUF m,PUF m+1PUF函数的初始验证对
Key j,new公共数据电子标签与用户读写器的本轮共享密钥
Key j,old公共数据电子标签与用户读写器的前一轮共享密钥
PUF(·)随机置换函数
按位异或运算
Mj用户读写器生成的随机数
CRC循环校验函数
A1~A5公共数据电子标签与用户读写器之间的交换信息

图1

基于轻量级双向认证协议的公共数据安全防护结构图"

图2

实验环境"

表2

各方法的安全防护优化结果"

攻击方式

本文

算法

差分隐私方法

双账本

方法

区块链

方法

区块联盟链方法
中间人攻击可抵抗可抵抗不可抵抗可抵抗可抵抗
窃听攻击可抵抗不可抵抗可抵抗可抵抗可抵抗
去同步化攻击可抵抗可抵抗可抵抗不可抵抗可抵抗
数据篡改攻击可抵抗可抵抗不可抵抗不可抵抗可抵抗
DDoS攻击可抵抗不可抵抗可抵抗可抵抗可抵抗
克隆攻击可抵抗可抵抗可抵抗不可抵抗可抵抗
勒索软件攻击可抵抗可抵抗可抵抗可抵抗不可抵抗
追踪攻击可抵抗可抵抗可抵抗可抵抗不可抵抗
重放攻击可抵抗可抵抗不可抵抗可抵抗不可抵抗
钓鱼攻击可抵抗可抵抗不可抵抗可抵抗可抵抗

图3

各方法安全防护优化中的检验指标值"

[1] 刘海鸥, 周颖玉, 王海英. 基于区块链的突发公共卫生事件政府数据开放共享模型研究[J]. 现代情报,2022, 42(10): 79-89.
Liu Hai-ou, Zhou Ying-yu, Wang Hai-ying. Research on open sharing model of government data of public health emergencies based on blockchain[J].Modern Information, 2022, 42(10): 79-89.
[2] 张利华, 曹宇, 张赣哲, 等. 基于区块链的微电网数据安全存储与删除验证方案[J]. 计算机工程与设计, 2023, 44(4): 967-976.
Zhang Li-hua, Cao Yu, Zhang Gan-zhe, et al. Microgrid data security storage and deletion verification scheme based on blockchain[J].Computer Engineering and Design, 2023, 44(4): 967-976.
[3] 孔庆阳, 何乐生, 金浩男, 等. 体测设备物联网数据安全传输机制的设计与实现[J]. 计算机应用, 2022,42(): 180-185.
Kong Qing-yang, He Le-sheng, Jin Hao-nan, et al. Design and implementation of security transmission mechanism of Internet of Things data for physical measurement equipment[J].Computer Application, 2022, 42(Sup.2): 180-185.
[4] 苏艳霞, 王庆生, 陈永乐. 基于数据分割的云存储中数据的安全共享[J]. 计算机工程与设计, 2021, 42(10): 2742-2747.
Su Yan-xia, Wang Qing-sheng, Chen Yong-le. Secure sharing of data in cloud storage based on data segmentation[J].Computer Engineering and Design, 2021, 42(10): 2742-2747.
[5] 程顺达. 基于安全性验证的云数据存储与访问算法[J].沈阳工业大学学报, 2023, 45(5): 565-570.
Cheng Shun-da. Cloud data storage and access algorithm based on security verification[J].Journal of Shenyang University of Technology, 2023, 45(5): 565-570.
[6] 康海燕, 邓婕. 面向医疗数据安全存储的增强混合加密方法[J]. 北京理工大学学报, 2021, 41(10): 1058-1068.
Kang Hai-yan, Deng Jie. Enhanced hybrid encryption for secure storage of medical data[J].Journal of Beijing Institute of Technology, 2021, 41(10): 1058-1068.
[7] 吴万青, 赵永新, 王巧, 等. 一种满足差分隐私的轨迹数据安全存储和发布方法[J]. 计算机研究与发展, 2021, 58(11): 2430-2443.
Wu Wan-qing, Zhao Yong-xin, Wang Qiao, et al. A method for safe storage and publication of trajectory data that satisfies differential privacy[J].Computer Research and Development, 2021, 58(11): 2430-2443.
[8] 赵骏, 戴欢, 唐毅, 等. 基于双账本的物联网数据存储与共享方法[J]. 计算机工程与设计, 2023, 44(11):3276-3282.
Zhao Jun, Dai Huan, Tang Yi, et al. Internet of things data storage and sharing method based on double ledger[J]. Computer Engineering and Design, 2023, 44(11): 3276-3282.
[9] Li D, Han D Z, Crespi N, et al. A blockchain-based secure storage and access control scheme for supply chain finance[J]. Journal of Supercomputing,2023, 79(1): 109-138.
[10] 万征, 丁超, 余岚, 等. 一种基于区块链的大健康数据存储和共享模型[J]. 小型微型计算机系统, 2023,44(3): 636-645.
Wan Zheng, Ding Chao, Yu Lan, et al. A blockchain-based big health data storage and sharing model[J].Small Microcomputer System, 2023, 44(3): 636-645.
[11] 贺嘉琦, 彭长根, 付章杰, 等. 面向RFID的轻量级双向认证协议[J]. 计算机工程与应用, 2023, 59(18):268-277.
He Jia-qi, Peng Chang-gen, Fu Zhang-jie, et al. Lightweight bidirectional authentication protocol for RFID[J].Computer Engineering and Applications, 2023, 59(18): 268-277.
[12] 陈飞鸿, 张锋, 陈军宁, 等. 基于RRAM PUF的轻量级RFID认证协议[J]. 计算机工程与应用, 2021, 57(1): 141-149.
Chen Fei-hong, Zhang Feng, Chen Jun-ning, et al. Lightweight RFID authentication protocol based on RRAM PUF[J].Computer Engineering and Applications, 2021, 57(1): 141-149.
[13] 吴恺凡, 殷新春. 一种支持三方认证的轻量级RFID双向认证协议[J]. 小型微型计算机系统, 2022, 43(10): 2205-2213.
Wu Kai-fan, Yin Xin-chun. A lightweight RFID bidirectional authentication protocol that supports three-party authentication[J].Small Microcomputer System, 2022, 43(10): 2205-2213.
[14] 郭奕旻, 张振峰, 熊平, 等. 基于PUF的轻量级雾辅助物联网认证协议[J]. 计算机学报, 2022, 45(7):1412-1430.
Guo Yi-min, Zhang Zhen-feng, Xiong Ping, et al. Lightweight fog assisted iot authentication protocol based on PUF[J]. Journal of Computer Science, 2022, 45(7): 1412-1430.
[15] 吴斌, 严建峰. 基于区块链技术的分布式可信网络接入认证[J]. 计算机仿真, 2021, 38(1): 277-281.
Wu Bin, Yan Jian-feng. Distributed trusted network access authentication based on blockchain technology[J].Computer Simulation, 2021, 38(1): 277-281.
[1] 冯志刚,王首起,于明月. 基于变分模态提取及轻量级网络的滚动轴承故障诊断[J]. 吉林大学学报(工学版), 2025, 55(6): 1883-1891.
[2] 霍光,林大为,刘元宁,朱晓冬,袁梦,盖迪. 基于多尺度特征和注意力机制的轻量级虹膜分割模型[J]. 吉林大学学报(工学版), 2023, 53(9): 2591-2600.
[3] 姜斌祥,许鸿奎,何丹. 基于区块链的毒品检验大数据效率改进[J]. 吉林大学学报(工学版), 2022, 52(7): 1666-1678.
[4] 陈永,卢晨涛,王镇. 基于轻量级网络的铁路感兴趣区域异物侵限检测[J]. 吉林大学学报(工学版), 2022, 52(10): 2405-2418.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!