IoT Data Acquisition System and Method Based on Distributed Digital Identity

By adopting distributed digital identity technology in the IoT data acquisition system, combining blockchain and public key cryptography system, the problems of secure transmission, authentication management and shared authorization of IoT data acquisition are solved, and the security and legality of data acquisition are realized.

CN114238897BActive Publication Date: 2025-06-17四川启睿克科技有限公司
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202111611718.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-27
Publication Date
2025-06-17
Estimated Expiration
2041-12-27

AI Technical Summary

Technical Problem

The prior art is difficult to effectively solve the problems of secure data transmission, authentication management and shared authorization in IoT data collection, especially in the multi-receiver scenarios.

Method used

The Internet of Things data acquisition system based on distributed digital identity is adopted, combined with the blockchain and the public key cryptography system, and identity authentication and authorization, two-way authentication and key negotiation are realized through the distributed digital identity infrastructure to ensure the security and legality of data acquisition.

Benefits of technology

It realizes data secure transmission, authentication management and sharing authorization for IoT data collection, and provides a trusted and controllable solution for data collection, suitable for a variety of IoT data collection and sharing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238897B_ABST
    Figure CN114238897B_ABST
Patent Text Reader

Abstract

The present invention discloses an Internet of Things data acquisition system based on distributed digital identities, comprising: a management system, a receiving end, a collection end, and a distributed identity infrastructure. Among them, the management system, the receiving end, and the collection end are all registered with digital identity IDs in the distributed identity infrastructure. Specifically: The management system manages all Internet of Things devices, authorizes the receiving end according to the user's request, and dispenses and manages the collection end; The receiving end is controlled by the user and is used to receive the data collected by the Internet of Things; The collection end is a specific Internet of Things device that completes data collection; The distributed digital identity infrastructure provides functions related to address resolution, data uploading to the chain, and public key storage in distributed digital identity management; The present invention also discloses a method for Internet of Things data acquisition based on distributed digital identities. The present invention can effectively solve the problems of data security transmission, data sharing, and authentication management in Internet of Things data acquisition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the Internet of Things, and in particular to an Internet of Things data acquisition system and method based on distributed digital identity. Background Art

[0002] With the continuous popularization of Internet of Things devices and the continuous enrichment of related applications, Internet of Things devices are gradually developing from being deployed and used by one party to being deployed by one party and used by multiple parties. For example, data such as temperature, humidity, and video monitoring in a warehouse can be obtained simultaneously by multiple different users who rent the warehouse. Since the data collected by the Internet of Things involves sensitive information such as business secrets and personal privacy, the security of data during the collection, transmission, and storage processes, as well as the legality of data acquisition and use, have become the focus of attention in Internet of Things security.

[0003] Blockchain technology is a distributed storage solution that involves knowledge in multiple disciplines such as mathematics, cryptography, and computer science, and has characteristics such as decentralization, immutability, full traceability, traceability, collective maintenance, and openness and transparency. Blockchain technology can meet the requirements of Internet of Things data acquisition for data security, traceability, etc., but the characteristic of data openness and transparency of this technology cannot be directly used to solve the problem of acquisition confidentiality.

[0004] The public key cryptosystem solves the key negotiation problem in symmetric cryptography by separating the encryption key and the decryption key. The public key and the private key are used in pairs. The trusted party publishes its public key, and other users can use the published public key to verify whether the trusted party holds the private key to confirm the identity of the trusted party. The public key cryptosystem can solve the key distribution and data encryption in Internet of Things data acquisition, but it requires a trust center to solve the identity trust problem between the acquisition end and the receiving end.

[0005] Distributed digital identity is based on blockchain technology. By utilizing the decentralized feature of blockchain, it can effectively overcome the problem of a single service provider's control over user accounts. At the same time, its immutable feature can effectively solve the identity trust problem, thereby providing a safe and reliable solution for the creation, maintenance, and confirmation of digital identity.

[0006] Regarding the problem of Internet of Things data acquisition, currently, the industry has proposed various solutions by combining blockchain technology in aspects such as data secure transmission, authentication management, and sharing authorization.

[0007] In terms of data security transmission, the patent "A Blockchain Encryption Method for Production Process Data of Multiple Types of Enterprises (Patent No.: 202110632767.6)" proposes a blockchain encryption method for production process data of multiple types of enterprises to address the transmission problem of sensitive data and solves the data sharing problem based on the RSA encryption algorithm. The patent "Internet of Things Data Acquisition System, Method, Medium and Device Based on Privacy Computing" (Patent No.: 202110674134.1) proposes a scheme based on attribute encryption for the privacy protection problem in data sharing to protect privacy by hiding user attributes. The above schemes solve the data security protection problem, but do not propose a solution to the data acquisition authorization problem under multiple receivers.

[0008] In terms of acquisition authentication, the patent "Trusted Acquisition and Storage Based on the Digital Identity of Intelligent Internet of Things Devices (Patent No.: 202010113663.X)" proposes a scheme combining product ID, device ID and dynamic device password for verifying the data to be uploaded to address the authenticity problem before the information is uploaded to the chain, but this scheme does not solve the data transmission security and data sharing problems, nor does it solve the problem of two-way authentication. The patent "Enterprise Electronic Ledger Energy Consumption Data Acquisition System Based on Blockchain" (Patent No.: 202110979754.6) proposes a data security acquisition method based on a trust channel for the problems of difficult data acquisition and low data reliability in energy consumption data acquisition, but this scheme only solves the trust problem between the acquisition end and the receiving end, and does not clarify how the acquisition end and the receiving end perform two-way authentication to ensure the legitimacy of each other.

[0009] In terms of acquisition sharing authorization, the patent "Device Monitoring Method and Device, Monitoring Equipment and Storage Medium Based on the Internet of Things" (Patent No.: 202110750034.2) proposes a blockchain-based state data acquisition method for the data integrity problem in the process of running state data acquisition. This scheme uses the blockchain to store device information for device matching and rights confirmation during information acquisition, but does not consider the data acquisition security and data sharing problems. The patent "Enterprise Electronic Ledger Energy Consumption Data Acquisition System Based on Blockchain" (Patent No.: 202110979754.6) proposes a method based on the binding of enterprise ID and device ID for rights confirmation for the problems of difficult data acquisition and low data reliability in energy consumption data acquisition, but does not provide a solution idea for how to perform authorization transfer.

[0010] From the existing technical solutions, there is no relatively complete solution for aspects such as data security transmission, authentication management and sharing authorization in Internet of Things data acquisition, nor can an efficient solution be simply formed by combining multiple solutions. Summary of the Invention

[0011] In view of the security issues such as transmission, storage, and sharing faced in the process of Internet of Things (IoT) data collection, based on the existing IoT data collection solutions and combining blockchain and public key cryptosystem, the present invention proposes an IoT data collection system and method based on distributed identity authentication technology, which can effectively solve the problems of data security transmission, data sharing, and authentication management in IoT data collection.

[0012] To achieve the above object, the technical solution adopted by the present invention is: an IoT data collection system based on distributed digital identity, comprising: a management system, a receiving end, a collection end, and a distributed identity infrastructure, wherein the management system, the receiving end, and the collection end are all registered with digital identity IDs in the distributed identity infrastructure; specifically:

[0013] The management system manages all IoT devices, authorizes the receiving end according to the user's request, and conducts deployment management on the collection end;

[0014] The receiving end is controlled by the user and is used to receive the data collected by the IoT;

[0015] The collection end is a specific IoT device that completes data collection;

[0016] The distributed digital identity infrastructure provides functions related to address resolution, data on-chain, and public key preservation in distributed digital identity management.

[0017] The present invention also provides an IoT data collection method based on distributed digital identity, which uses the above-mentioned IoT data collection system based on distributed digital identity. The method includes identity authentication and authorization, and two-way authentication and key negotiation; wherein:

[0018] Identity authentication and authorization are responsible for issuing data collection and sharing policies and verifying the identities of each component;

[0019] Two-way authentication and key negotiation complete the establishment of an encrypted channel from the collection end to the receiving end, and the same collection terminal shares and sends data to different data receiving ends through the encrypted channel.

[0020] As a further improvement of the present invention, the identity authentication and authorization specifically include the following steps:

[0021] 1) The management system sets the receiving end as receiving end 1 for collection end 1 according to the user's request, and encrypts and sends the digital identity ID, access address, and operation permission of receiving end 1 with the private key;

[0022] 2) The management system authorizes receiving end 1 to use collection end 1, and encrypts and sends the digital identity ID of collection end 1 and the operation permission for collection end 1 with the private key;

[0023] 3) The acquisition end 1 requests the identity document of the management system from the distributed digital identity infrastructure;

[0024] 4) The distributed digital identity infrastructure returns the document. After the acquisition end 1 obtains the public key of the management end and verifies the legal identity of the management system, it decrypts the encrypted data to obtain the digital identity ID, access address, and operation permissions of the receiving end 1;

[0025] 5) The acquisition end 1 requests the identity document of the receiving end 1 from the distributed digital identity infrastructure;

[0026] 6) The distributed digital identity infrastructure returns the document. The acquisition end 1 obtains the public key of the receiving end 1;

[0027] 7) The receiving end 1 requests the identity document of the management system from the distributed digital identity infrastructure;

[0028] 8) The distributed digital identity infrastructure returns the document. The receiving end 1 obtains the public key of the management end. After verifying the legal identity of the management system, it decrypts the encrypted data to obtain the digital identity ID and operation permissions of the acquisition end 1;

[0029] 9) The receiving end 1 requests the identity document of the acquisition end 1 from the distributed digital identity infrastructure;

[0030] 10) The distributed digital identity infrastructure returns the document. The receiving end 1 obtains the public key of the acquisition end 1.

[0031] As a further improvement of the present invention, the mutual authentication and key negotiation specifically include the following steps:

[0032] 1) The acquisition end 1 sets the receiving end as the receiving end 1, and encrypts and sends the random number Ra to the receiving end 1 using the public key of the receiving end 1;

[0033] 2) The receiving end 1 decrypts with the private key to obtain the random number Ra;

[0034] 3) The receiving end 1 generates a new random number Rb, encrypts it with the public key of the acquisition end 1, and sends the random numbers Ra and Rb to the acquisition end 1;

[0035] 4) The acquisition end 1 decrypts with the private key to obtain the random numbers Ra and Rb, and confirms the identity of the receiving end 1;

[0036] 5) The acquisition end 1 encrypts and sends the random number Rb to the receiving end 1 using the public key of the receiving end 1;

[0037] 6) The receiving end 1 decrypts with the private key to obtain the random number Rb, and confirms the identity of the acquisition end 1;

[0038] 7) The acquisition end 1 and the receiving end 1 complete the identity confirmation, and use the combined random numbers Ra and Rb as the key for encrypted data communication.

[0039] The beneficial effects of the present invention are as follows:

[0040] While providing secure data collection, the present invention also provides solutions for data collection sharing and authorization, and can be applied to various Internet of Things (IoT) data collection sharing scenarios. For example, in scenarios such as smart homes, smart agriculture, and smart factories, the flexible authorization can be used to meet the sharing needs of family members, farm administrators, and factory production personnel for on-site data collection; at the same time, it can also be applied to the field of data analysis services. For example, data service providers can directly collect on-site data under the authorization of users to provide services such as fault diagnosis, process optimization, and security analysis for users. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 It is a block diagram of the system composition of an embodiment of the present invention;

[0042] Figure 2 It is a schematic diagram of identity authentication and authorization in an embodiment of the present invention;

[0043] Figure 3 It is a schematic diagram of two-way authentication and key negotiation in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0045] Embodiment

[0046] Collection end: Refers to the IoT device for data collection.

[0047] Receiving end: Refers to the destination of the IoT data collection, and one collection end may send the collected data to multiple receiving ends.

[0048] This embodiment proposes a solution based on distributed digital identity for data security transmission, authentication management, and sharing authorization in IoT data collection.

[0049] Data security transmission means maintaining the integrity, non-tampering, and confidentiality of data through data encryption during the IoT data collection process. This embodiment mainly proposes a solution to the problem of how to perform key negotiation in data encrypted transmission.

[0050] The authentication management problem refers to the need to confirm the identities of the collection end and the data receiving end through authentication during the data collection process. This embodiment mainly proposes a solution to the problem of how to perform two-way authentication between the collection end and the receiving end during the collection process.

[0051] The shared authorization issue refers to the problem of acquisition authorization and data sharing during data acquisition, where multiple acquisition terminals send data to multiple receiving terminals. This embodiment proposes a solution to the authorization management problem of the system's authorized receiving end for collecting data from specific acquisition ends.

[0052] As Figure 1 shown, an Internet of Things data acquisition system based on distributed digital identities consists of a management system, receiving ends, acquisition ends, and a distributed identity infrastructure. The management system, receiving ends, and acquisition ends are all registered with digital identity IDs in the distributed identity infrastructure.

[0053] The management system manages all Internet of Things devices, authorizes the receiving ends according to user requests, and allocates and manages the acquisition ends; the receiving ends are controlled by users and are used to receive data acquired by the Internet of Things; the acquisition ends are specific Internet of Things devices that complete data acquisition; the distributed digital identity infrastructure provides related functions such as address resolution, data uploading to the chain, and public key storage in distributed digital identity management.

[0054] Based on this composition scheme, data security transmission, authentication management, and shared authorization in Internet of Things data acquisition are realized by two processes: identity authentication and authorization, and mutual authentication and key negotiation. Among them, identity authentication and authorization are responsible for issuing data acquisition sharing policies and verifying the identities of each component, and mutual authentication and key negotiation complete the establishment of an encrypted channel from the acquisition end to the receiving end. The same acquisition terminal shares data and sends it to different data receiving ends through the encrypted channel.

[0055] Identity authentication and authorization process:

[0056] As Figure 2 shown, in this embodiment, when binding the authorization between the acquisition end and the receiving end, the management system respectively notifies the receiving end and the acquisition end of the digital identity IDs of the opposite ends. The device end confirms the identity of the opposite end device based on the distributed digital identity infrastructure, and establishes a trusted data acquisition channel after passing the identity verification.

[0057] This embodiment selects "acquisition end 1" and "receiving end 1" as examples to illustrate the authorization process, and the process is as follows:

[0058] 1) The management system sets the receiving end as "receiving end 1" for "acquisition end 1" according to the user request, and encrypts and sends the digital identity ID, access address, and operation permission of "receiving end 1" using the private key;

[0059] 2) The management system authorizes the available acquisition end for "receiving end 1" as "acquisition end 1", and encrypts and sends the digital identity ID of "acquisition end 1" and the operation permission for the acquisition end using the private key;

[0060] 3) The "collection end 1" requests the identity document of the management system from the distributed digital identity infrastructure;

[0061] 4) The distributed digital identity infrastructure returns the document. After the "collection end 1" obtains the public key of the management end and verifies the legal identity of the management system, it decrypts the encrypted data to obtain the digital identity ID, access address, and operation permissions of the "reception end 1";

[0062] 5) The "collection end 1" requests the identity document of the "reception end 1" from the distributed digital identity infrastructure;

[0063] 6) The distributed digital identity infrastructure returns the document. The "collection end 1" obtains the public key of the "reception end 1";

[0064] 7) The "reception end 1" requests the identity document of the management system from the distributed digital identity infrastructure;

[0065] 8) The distributed digital identity infrastructure returns the document. After the "reception end 1" obtains the public key of the management end and verifies the legal identity of the management system, it decrypts the encrypted data to obtain the digital identity ID and operation permissions of the "collection end 1";

[0066] 9) The "reception end 1" requests the identity document of the "collection end 1" from the distributed digital identity infrastructure;

[0067] 10) The distributed digital identity infrastructure returns the document. The "reception end 1" obtains the public key of the "collection end 1".

[0068] Two-way authentication and key negotiation process:

[0069] As Figure 3 shown, when the collection end and the reception end complete the authorization process, the collection end initiates the two-way authentication process and completes the negotiation of the communication key.

[0070] This embodiment selects the "collection end 1" and the "reception end 1" as examples to illustrate the authorization process, and the process is as follows:

[0071] 1) The "collection end 1" sets the reception end as the "reception end 1" and encrypts and sends the random number Ra to the "reception end 1" using the public key of the "reception end 1";

[0072] 2) The "reception end 1" decrypts with the private key to obtain the random number Ra;

[0073] 3) The "reception end 1" generates a new random number Rb, encrypts Ra and Rb with the public key of the "collection end 1" and sends them to the "collection end 1";

[0074] 4) The "collection end 1" decrypts with the private key to obtain the random numbers Ra and Rb and confirms the identity of the "reception end 1";

[0075] 5) The "Collection End 1" encrypts and sends the random number Rb to the "Receiving End 1" using the public key of the "Receiving End 1".

[0076] 6) The "Receiving End 1" decrypts with the private key to obtain the random number Rb and confirms the identity of the "Collection End 1".

[0077] 7) The "Collection End 1" and the "Receiving End 1" complete the identity confirmation and perform encrypted data communication after combining the random numbers Ra and Rb into a key.

[0078] The above-described embodiments only represent the specific implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention.

Claims

1. An Internet of Things data collection method based on distributed digital identity, characterized in that, Implemented by an Internet of Things data acquisition system based on distributed digital identities. The system includes: a management system, a receiving end, a collection end, and a distributed identity infrastructure. Among them, the management system, the receiving end, and the collection end are all registered with digital identity IDs in the distributed identity infrastructure. Specifically: The management system manages all Internet of Things devices, authorizes the receiving end according to the user's request, and allocates and manages the collection end; The receiving end is controlled by the user and is used to receive the data collected by the Internet of Things; The collection end is a specific Internet of Things device that completes data collection; The distributed digital identity infrastructure provides functions related to address resolution, data uploading to the chain, and public key storage in distributed digital identity management; The method includes identity authentication and authorization, two-way authentication and key negotiation; among them: Identity authentication and authorization are responsible for issuing data collection sharing policies and verifying the identities of each component; The identity authentication and authorization specifically include the following steps: 1) The management system sets the receiving end as the receiving end (1) according to the user's request and encrypts and sends the digital identity ID, access address, and operation permissions of the receiving end (1) with its private key; 2) The management system authorizes the receiving end (1) to use the collection end as the collection end (1) and encrypts and sends the digital identity ID of the collection end (1) and the operation permissions for the collection end with its private key; 3) The collection end (1) requests the identity document of the management system from the distributed digital identity infrastructure; 4) The distributed digital identity infrastructure returns the document. After the collection end (1) obtains the public key of the management end and verifies the legal identity of the management system, it decrypts the encrypted data to obtain the digital identity ID, access address, and operation permissions of the receiving end (1); 5) The collection end (1) requests the identity document of the receiving end (1) from the distributed digital identity infrastructure; 6) The distributed digital identity infrastructure returns the document. The collection end (1) obtains the public key of the receiving end (1); 7) The receiving end (1) requests the identity document of the management system from the distributed digital identity infrastructure; 8) The distributed digital identity infrastructure returns the document. After the receiving end (1) obtains the public key of the management end and verifies the legal identity of the management system, it decrypts the encrypted data to obtain the digital identity ID and operation permissions of the collection end (1); 9) The receiving end (1) requests the identity document of the collection end (1) from the distributed digital identity infrastructure; 10) The distributed digital identity infrastructure returns the document. The receiving end (1) obtains the public key of the collection end (1); Two-way authentication and key negotiation complete the establishment of an encrypted channel from the collection end to the receiving end. The same collection terminal shares and sends data to different data receiving ends through the encrypted channel.

2. The Internet of Things data collection method based on distributed digital identity according to claim 1, characterized in that, The two-way authentication and key negotiation specifically include the following steps: 1) The collection end (1) sets the receiving end as the receiving end (1) and encrypts and sends the random number Ra to the receiving end (1) with the public key of the receiving end (1); 2) The receiving end (1) decrypts with its private key to obtain the random number Ra; 3) The receiving end (1) generates a new random number Rb, encrypts the random numbers Ra and Rb with the public key of the collection end (1), and sends them to the collection end (1); 4) The acquisition end (1) decrypts with the private key to obtain the random number Ra and the random number Rb, and confirms the identity of the receiving end (1); 5) The acquisition end (1) encrypts with the public key of the receiving end (1) and sends the random number Rb to the receiving end (1); 6) The receiving end (1) decrypts with the private key to obtain the random number Rb, and confirms the identity of the acquisition end (1); 7) The acquisition end (1) and the receiving end (1) complete the identity confirmation, and use the random number Ra and the random number Rb to merge into a key and then perform encrypted data communication.

Citation Information

Patent Citations

  • Trusted Collection and Recording Method and Device Based on Digital Identity of Smart IoT Devices

    CN110958276B

  • Equipment monitoring method and device based on Internet of Things, monitoring equipment and storage medium

    CN113204599A

  • Internet of Things data acquisition system and method based on privacy computing, medium and equipment

    CN113343296A

  • Block chain encryption method for multi-type enterprise production process data

    CN113364590A

  • Enterprise electronic standing book energy consumption data acquisition system based on block chain

    CN113433918A