基于SM9标识密码的测控物联网零信任轻量级认证与密钥
投稿时间:2026-05-11  修订日期:2026-06-11  点此下载全文
引用本文:
摘要点击次数: 64
全文下载次数: 0
作者单位邮编
王蕴瑜* 中国联合网络通信有限公司广东省分公司 510000
中文摘要:针对测控物联网终端资源受限、传统PKI证书管理开销大、网络边界防御失效等问题, 提出一种基于SM9标识密码的测控物联网零信任轻量级认证与密钥分发机制。该方法以零信任”永不信任、持续验证”理念为指导, 在零信任网关侧部署单包授权(SPA)模块实现端口隐藏, 结合SM9标识签名实现终端身份的高效验证;在密钥协商阶段, 基于双线性对运算设计了仅含一次终端侧双线性对运算的轻量级会话密钥协商协议, 并通过预计算与缓存策略将常量项开销前移至离线阶段;同时引入动态信任评估引擎对会话过程进行持续监控与基于棘轮的密钥滚动更新。安全性分析表明, 该方案在BAN逻辑下满足相互认证与会话密钥保密性, 能抵抗重放、中间人、伪装等典型攻击。在STM32F407终端、树莓派4B网关与服务器构成的测控物联网测试床上的实验表明, 与基于PKI证书的TLS 1.3方案相比, 本方法在终端侧的认证与密钥协商总耗时降低约58.3%, 通信开销降低约62.7%, 存储开销降低约74.3%, 能耗降低约58.3%;与标准SM9密钥交换协议相比, 终端在线计算耗时降低约44.5%, 能够较好地满足资源受限测控物联网场景的安全接入需求。
中文关键词:SM9标识密码  零信任  测控物联网  接入认证  密钥分发  双线性对
 
A Zero-Trust Access Authentication and Lightweight Key Distribution Method Based on SM9 Identity-Based Cryptography for Measurement-and-Control IoT
Abstract:To address the challenges of resource-constrained terminals, heavy PKI certificate management overhead, and the failure of perimeter defense in measurement-and-control IoT (MC-IoT), this paper proposes a zero-trust access authentication and lightweight key distribution method based on SM9 identity-based cryptography. Following the zero-trust principle of “never trust, always verify”, a Single Packet Authorization (SPA) module is deployed on the zero-trust gateway to achieve port concealment, while SM9 identity-based signatures provide efficient terminal identity verification. A lightweight session key agreement protocol with only one terminal-side bilinear pairing is designed, and the constant pairing factor is shifted to an offline pre-computation phase. A dynamic trust evaluation engine continuously monitors the session and triggers ratchet-based key rolling updates. BAN-logic analysis proves mutual authentication and session-key secrecy, and the protocol resists replay, man-in-the-middle, and impersonation attacks. Experiments on a testbed consisting of STM32F407 terminals, a Raspberry Pi 4B gateway and a server show that, compared with PKI-based TLS 1.3, the proposed method reduces handshake latency by 58.3%, communication overhead by 62.7%, terminal storage by 74.3%, and energy consumption by 58.3%; compared with the standard SM9 key-exchange protocol, terminal-side online computation latency is further reduced by 44.5%, satisfying the security access requirements of resource-constrained MC-IoT scenarios.
keywords:SM9 identity-based cryptography  zero trust  measurement and control IoT  access authentication  key distribution  bilinear pairing
查看全文   查看/发表评论   下载pdf阅读器