Encryption Method and System for Ensuring the Security of the Virtual-Reality Fusion of Intelligent Internet of Things and the Metaverse
By constructing third-order tensors to generate virtual and real mapping relationships and using quantum encryption technology, combining decentralized trust system and Byzantine fault tolerance algorithms, the security challenges in the fusion scenario of intelligent IoT and the meta-universe virtual and real are solved, reliable data transmission and authenticity verification are achieved, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202510526355.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-25
AI Technical Summary
Existing encryption technologies are difficult to meet the complex security needs in the scenarios of intelligent IoT and the fusion of the meta-universe virtual and real. Especially in the process of data transmission, there is a lack of flexible and multi-level encryption mechanism, and it is impossible to differentiate protection for data of different security levels. It also lacks reliable identity authentication and data authenticity verification mechanisms, which poses the risk of man-in-the-middle attacks and single point of failure.
By constructing third-order tensors to generate virtual and real mapping relationship identifiers, using quantum encryption keys for layered encryption, and combining decentralized trust system and Byzantine fault tolerance algorithm for data verification to ensure data integrity and authenticity.
Effectively prevent device disguise and identity fraud, improve the security and credibility of virtual and real interactions, resist quantum computing attacks, ensure the confidentiality and integrity of data in the virtual environment, and improve the fault tolerance and reliability of the system.
Smart Images

Figure CN120090866B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to metaverse technology, and particularly to an encryption method and system for ensuring the security of the integration of virtual and real in intelligent IoT and the metaverse. Background Art
[0002] With the rapid development of Internet of Things (IoT) technology and the concept of the metaverse, the integration of intelligent IoT devices and the virtual world has become a new trend. Intelligent IoT devices can collect physical data in the real world and transmit this data to corresponding virtual objects in the metaverse space, realizing the interconnection and interoperability between the physical world and the virtual world. This virtual-real integration mode provides users with an immersive experience, expands the application scenarios of intelligent IoT, and promotes the development of the digital economy.
[0003] However, during the data interaction process between intelligent IoT devices and the metaverse, there are many security challenges. Existing encryption technologies are mainly designed for traditional network environments and are difficult to meet the security requirements in virtual-real integration scenarios. Especially when physical world data needs to be transmitted to the metaverse in real time and securely and presented, traditional encryption methods have obvious deficiencies.
[0004] Currently, the security guarantee technology for the integration of virtual and real in intelligent IoT and the metaverse has the following defects and deficiencies:
[0005] Traditional encryption technologies are difficult to adapt to the complex security requirements in virtual-real integration scenarios. Especially when dealing with physical world data of different security levels, they lack a flexible multi-level encryption mechanism and cannot adopt differential protection strategies according to the data sensitivity level, resulting in difficulty in balancing security and computational efficiency.
[0006] Existing technologies lack a reliable identity authentication mechanism during the virtual-real mapping process. The corresponding relationship between physical devices and virtual objects is vulnerable to man-in-the-middle attacks, making it difficult to establish a solid trust relationship and increasing the risk of data being tampered with or stolen during the data transmission process.
[0007] Most existing solutions adopt a centralized verification mechanism, with low data authenticity verification efficiency and a risk of single point of failure. Especially in the metaverse environment where cross-domain data interaction is frequent, it is difficult to ensure the integrity and authenticity of data throughout the virtual-real interaction process and effectively cope with complex and changeable security threats. Summary of the Invention
[0008] Embodiments of the present invention provide an encryption method and system for ensuring the security of the integration of virtual and real in intelligent IoT and the metaverse, which can solve the problems in the prior art.
[0009] In the first aspect of the embodiments of the present invention,
[0010] Obtain the device identification information of the intelligent Internet of Things device and the virtual object identification information corresponding to the intelligent Internet of Things device in the metaverse space; Based on the device identification information and the virtual object identification information, construct a third-order tensor, and generate a virtual-real mapping relationship identifier through a non-linear mapping function;
[0011] According to the virtual-real mapping relationship identifier, call a preset quantum key generation module to generate a quantum encryption key for virtual-real interaction;
[0012] Perform hierarchical encryption processing on the physical world data collected by the intelligent Internet of Things device through the quantum encryption key, construct a multi-level key generation network based on quantum entanglement states, and use quantum keys of different lengths for encryption according to the physical world data of different security levels, and introduce a data verification mechanism based on homomorphic encryption in each layer of encryption process to ensure the integrity of the data during virtual-real interaction;
[0013] Transmit the encrypted physical world data to the virtual object in the metaverse space;
[0014] When the virtual object receives the encrypted physical world data, based on the pre-constructed decentralized trust system, perform multi-party consensus verification through smart contracts combined with the Byzantine fault tolerance algorithm to verify the data authenticity, and decrypt the encrypted physical world data and present it in the metaverse space after passing the verification.
[0015] Constructing a third-order tensor based on the device identification information and the virtual object identification information, and generating a virtual-real mapping relationship identifier through a non-linear mapping function includes:
[0016] The device identification information includes physical feature dimension information and behavioral feature dimension information, where the physical feature dimension information includes the hardware fingerprint information, geographical location information, and network access feature information of the intelligent Internet of Things device, and the behavioral feature dimension information includes the data transmission mode information, resource occupancy feature information, and periodic activity feature information of the intelligent Internet of Things device;
[0017] The identification information of the virtual object includes basic entity attributes, functional attributes, and interaction relationship information;
[0018] Based on the device identification information and the identification information of the virtual object, a third-order tensor is constructed. The physical feature dimension of the device identification information is mapped to the first dimension of the third-order tensor, the behavioral feature dimension of the device identification information is mapped to the second dimension of the third-order tensor, and the identification information of the virtual object is mapped to the third dimension of the third-order tensor. The feature fusion result of the physical device and the virtual object is obtained by performing tensor decomposition on the third-order tensor, where the tensor decomposition includes decomposing the third-order tensor into the sum of the tensor products of the basis vectors of three feature spaces;
[0019] Input the feature fusion result into a preset non-linear mapping function to obtain the identification of the virtual-real mapping relationship.
[0020] Perform hierarchical encryption processing on the physical world data collected by the intelligent IoT device through the quantum encryption key. Construct a multi-level key generation network based on the quantum entanglement state and use quantum keys of different lengths for encryption according to the physical world data of different security levels, including:
[0021] Based on a preset data security evaluation model, calculate the security level value of the physical world data according to the sensitivity, integrity requirement, and real-time requirement of the physical world data;
[0022] Based on the security level value, determine the quantum key length through an adaptive adjustment mechanism, where the quantum key length is related to the security level value, the basic key length, the security coefficient, and the expected password security time. The higher the security level value, the corresponding increase in the quantum key length;
[0023] Construct a multi-level key generation network based on the quantum entanglement state, perform a tensor product operation on the quantum entanglement state measurement result and the environmental entropy, and superimpose a random perturbation term to generate the quantum key of each layer;
[0024] Determine the number of encryption layers according to the security level value, and allocate the quantum keys according to the number of encryption layers;
[0025] Perform multi-level cascaded encryption processing on the physical world data. In the encryption process of each layer, combine the current layer data, the current layer quantum key, and the timestamp to calculate a verification value, and the verification value is used to verify the integrity of the encrypted data of this layer.
[0026] Construct a multi-level key generation network based on the quantum entanglement state, perform a tensor product operation on the quantum entanglement state measurement result and the environmental entropy, and superimpose a random perturbation term to generate the quantum key of each layer, including:
[0027] Generate quantum entangled photon pairs through parametric down - conversion process, and generate a superposition state of horizontal polarization state and vertical polarization state as the initial quantum entangled state; perform Bell state measurement on the quantum entangled photon pairs to obtain the probability distribution of the measurement results;
[0028] Collect quantum decoherence noise information and photon counting fluctuation information from the quantum system environment, and calculate the environmental entropy according to the quantum decoherence noise information and the photon counting fluctuation information;
[0029] Perform a tensor product operation on the probability distribution of the measurement results and the environmental entropy to obtain a quantum environment composite characteristic matrix;
[0030] Generate a random amplitude and a random phase based on a quantum random number generator, and combine the random amplitude and the random phase to generate a random perturbation term;
[0031] Perform a quantum - secure hashing operation on the quantum environment composite characteristic matrix, and perform an exclusive - OR operation on the operation result and the random perturbation term to generate a multi - level quantum key, where each layer of the quantum key satisfies a preset upper bound of the collision probability.
[0032] Introduce a data verification mechanism based on homomorphic encryption in each layer of the encryption process to ensure the integrity of data during the virtual - real interaction process, including:
[0033] Generate corresponding homomorphic eigenvalues for the quantum key in each layer of the encryption process, where the homomorphic eigenvalues are calculated by inputting the quantum key, timestamp information, and random perturbation amount into a preset homomorphic encryption function;
[0034] Bind the homomorphic eigenvalues of each layer to the physical - world data to form data - eigenvalue pairs, and perform encryption processing on the data - eigenvalue pairs to obtain encrypted data packets;
[0035] Perform a homomorphic decryption operation on each layer of encrypted data packets, and re - input the decrypted data, timestamp information, and random perturbation amount into the homomorphic encryption function to obtain verification eigenvalues.
[0036] Based on a pre - constructed decentralized trust system, perform multi - party consensus verification through a smart contract combined with the Byzantine fault - tolerance algorithm to verify the data authenticity, including:
[0037] Construct a distributed trust network based on a directed acyclic graph, collect the direct interaction information between nodes in the distributed trust network to obtain the direct trust degree, and obtain the indirect trust degree through the trust transfer of preset recommended nodes, and perform weighted fusion on the direct trust degree and the indirect trust degree to obtain the comprehensive trust degree between nodes;
[0038] Divide the nodes in the distributed trust network into honest nodes, Byzantine nodes, and uncertain nodes according to the comprehensive trust degree between the nodes, construct a three-state state transition matrix, calculate the transition probability between different states of the nodes according to the three-state state transition matrix, and update the node state according to the transition probability;
[0039] Calculate the consensus metric value by combining the transition probabilities corresponding to the Byzantine nodes and the honest nodes. The consensus metric value is jointly determined by the number of honest nodes and the number of Byzantine nodes that reach a consensus. When the difference between the consensus metric values at adjacent times is less than a preset convergence threshold and the consensus metric value is greater than a preset consensus threshold, it is confirmed that the verification of data authenticity is completed.
[0040] In the second aspect of the embodiments of the present invention, there is provided an encryption system for ensuring the security of the virtual-real integration of intelligent Internet of Things and the metaverse, including:
[0041] A first unit for obtaining the device identification information of the intelligent Internet of Things device and the virtual object identification information corresponding to the intelligent Internet of Things device in the metaverse space; based on the device identification information and the virtual object identification information, constructing a third-order tensor, and generating a virtual-real mapping relationship identifier through a non-linear mapping function;
[0042] A second unit for calling a preset quantum key generation module according to the virtual-real mapping relationship identifier to generate a quantum encryption key for virtual-real interaction;
[0043] A third unit for performing hierarchical encryption processing on the physical world data collected by the intelligent Internet of Things device through the quantum encryption key, constructing a multi-level key generation network based on the quantum entanglement state, and encrypting with quantum keys of different lengths according to the physical world data of different security levels, and introducing a data verification mechanism based on homomorphic encryption in each layer of encryption process to ensure the integrity of the data during virtual-real interaction;
[0044] A fourth unit for transmitting the encrypted physical world data to the virtual object in the metaverse space;
[0045] A fifth unit for, when the virtual object receives the encrypted physical world data, performing multi-party consensus verification through a smart contract combined with the Byzantine fault tolerance algorithm based on a pre-constructed decentralized trust system to verify the authenticity of the data, and decrypting the encrypted physical world data and presenting it in the metaverse space after the verification passes.
[0046] In the third aspect of the embodiments of the present invention,
[0047] There is provided an electronic device, including:
[0048] A processor;
[0049] A memory for storing processor-executable instructions;
[0050] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0051] In the fourth aspect of the embodiments of the present invention,
[0052] A computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0053] The beneficial effects of this application are as follows:
[0054] In the present invention, a third-order tensor is constructed based on device identification information and virtual object identification information, and a virtual-real mapping relationship identifier is generated by using a non-linear mapping function, thereby establishing a reliable correspondence between physical devices and virtual objects, effectively preventing device spoofing and identity fraud, and significantly improving the security and credibility of virtual-real interaction.
[0055] The present invention uses quantum encryption technology to perform hierarchical encryption processing on physical world data, constructs a multi-level key generation network based on quantum entanglement states, uses quantum keys of different lengths for data of different security levels, and introduces a homomorphic encryption data verification mechanism in each layer of encryption process, comprehensively ensuring the confidentiality and integrity of data during transmission, and effectively resisting quantum computing attacks and man-in-the-middle eavesdropping risks.
[0056] When the virtual object receives data in the present invention, multi-party consensus verification is performed through a decentralized trust system combined with smart contracts and Byzantine fault tolerance algorithms, realizing efficient verification of data authenticity. This not only avoids the single point of failure problem that may be brought by centralized verification, but also improves the fault tolerance and reliability of the system through a distributed consensus mechanism, ensuring that the physical world data presented in the metaverse space is true and credible. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 It is a schematic flowchart of the encryption method for ensuring the security of the virtual-real integration of intelligent IoT and the metaverse in the embodiments of the present invention;
[0058] Figure 2 It is a schematic diagram for comparing the anti-quantum computing attack capabilities of different encryption methods in the embodiments of the present invention;
[0059] Figure 3 It is a flowchart of the multi-level encryption process for the data collected by IoT devices in the embodiments of the present invention;
[0060] Figure 4 It is a schematic diagram of the convergence curve of the consensus metric value during the multi-party consensus verification process in the embodiments of the present invention. Detailed implementation manners
[0061] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0062] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0063] Figure 1 It is a schematic flowchart of an encryption method for ensuring the security of the virtual-real integration of intelligent IoT and the metaverse in an embodiment of the present invention. As Figure 1 shown, the method includes:[[]]
[0064] Obtain the device identification information of the intelligent IoT device and the virtual object identification information corresponding to the intelligent IoT device in the metaverse space; based on the device identification information and the virtual object identification information, construct a third-order tensor, and generate a virtual-real mapping relationship identifier through a non-linear mapping function;
[0065] According to the virtual-real mapping relationship identifier, call a preset quantum key generation module to generate a quantum encryption key for virtual-real interaction;
[0066] Perform hierarchical encryption processing on the physical world data collected by the intelligent IoT device through the quantum encryption key, construct a multi-level key generation network based on the quantum entanglement state, and encrypt the physical world data of different security levels with quantum keys of different lengths, and introduce a data verification mechanism based on homomorphic encryption in each layer of encryption to ensure the integrity of the data during the virtual-real interaction process;
[0067] Transmit the encrypted physical world data to the virtual object in the metaverse space;
[0068] When the virtual object receives the encrypted physical world data, based on the pre-constructed decentralized trust system, perform multi-party consensus verification through a smart contract combined with the Byzantine fault tolerance algorithm to verify the authenticity of the data. After the verification passes, decrypt the encrypted physical world data and present it in the metaverse space.
[0069] In an alternative embodiment, a third-order tensor is constructed based on the device identification information and the virtual object identification information, and a virtual-real mapping relationship identifier is generated through a non-linear mapping function, including:
[0070] The device identification information includes physical feature dimension information and behavioral feature dimension information. Among them, the physical feature dimension information includes the hardware fingerprint information, geographical location information, and network access feature information of the intelligent IoT device, and the behavioral feature dimension information includes the data transmission mode information, resource occupancy feature information, and periodic activity feature information of the intelligent IoT device;
[0071] The identification information of the virtual object includes basic entity attributes, functional attributes, and interaction relationship information;
[0072] Based on the device identification information and the virtual object identification information, a third-order tensor is constructed. The physical feature dimension of the device identification information is mapped to the first dimension of the third-order tensor, the behavioral feature dimension of the device identification information is mapped to the second dimension of the third-order tensor, and the virtual object identification information is mapped to the third dimension of the third-order tensor. The feature fusion result of the physical device and the virtual object is obtained by performing tensor decomposition on the third-order tensor, where the tensor decomposition includes decomposing the third-order tensor into the sum of the tensor products of the basis vectors of three feature spaces;
[0073] The feature fusion result is input into a preset non-linear mapping function to obtain a virtual-real mapping relationship identifier.
[0074] Hardware fingerprint information: Collect hardware parameters such as the CPU model, serial number, MAC address, and memory size of the device, and combine these parameters to form a unique hardware fingerprint. For example, for an intelligent camera, information such as its Qualcomm Snapdragon XYZ model processor information, 32-bit device serial number "A1B2C3D4", MAC address "00:1A:2B:3C:4D:5E", and 4GB RAM can be obtained, and feature extraction and encoding are performed to generate a 128-bit hardware fingerprint feature vector.
[0075] Geographical location information: Obtain location data such as the geographical coordinates, altitude, and area where the device is located. For example, through the GPS module, the device's location information at 39.915° north latitude, 116.404° east longitude, and 44 meters above sea level is obtained and encoded into a fixed-length vector.
[0076] Network access feature information: Record the network access method, IP address type, network topology relationship, etc. of the device. For example, the device accesses the network through WiFi, uses a dynamic IP address "192.168.1.100", and is in the second-level position within the local area network. These features are encoded into a 64-bit feature vector.
[0077] Data transmission mode information: Analyze the data transmission frequency, data packet size distribution, transmission protocol characteristics, etc. of the analysis device. For example, the intelligent door lock device sends a heartbeat packet (with a size of 128 bytes) every 30 seconds, uses the MQTT protocol, and generates a data packet transmission of 512 bytes when unlocking. These transmission modes are encoded as feature vectors.
[0078] Resource occupancy feature information: Monitor the resource usage characteristics of the device, such as CPU usage rate, memory occupancy, network bandwidth consumption, etc. For example, record that the CPU usage rate of the device remains within the range of 5% - 15% under normal operating conditions, the memory occupancy is about 500MB, and about 20MB of network traffic is generated per hour.
[0079] Periodic activity feature information: Identify the behavior patterns of tasks executed by the device at regular intervals, periodic network requests, etc. For example, the intelligent thermostat device collects temperature data every 5 minutes, uploads data every hour, and performs a firmware check at 2 am every day. These periodic activities form specific behavior feature vectors.
[0080] Basic entity attributes: Describe the basic characteristics of virtual objects, such as object type, identifier, name, etc. For example, the "Smart Home Control Center" object in the digital twin platform has basic attributes such as a unique identifier "HC - 10086", type "Control Center", and name "Home Total Control".
[0081] Functional attributes: Describe the functional characteristics provided by virtual objects, such as service interfaces, processing capabilities, response characteristics, etc. For example, the "Smart Home Control Center" object provides functional interfaces such as device registration, status query, and instruction issuance, supports up to 100 devices to connect concurrently, and the average response time is 50 milliseconds.
[0082] Interaction relationship information: Describe the connection relationships, interaction methods, etc. between virtual objects and other virtual objects. For example, the "Smart Home Control Center" object has a master - slave control relationship with other virtual objects such as "Lighting Control", "Temperature Control System", and "Security Monitoring", and interacts through the message queue mechanism.
[0083] Construct a three - dimensional data structure. The first dimension represents the physical feature dimension, with a dimension size of m (e.g., m = 256); the second dimension represents the behavior feature dimension, with a dimension size of n (e.g., n = 128); the third dimension represents the virtual object feature dimension, with a dimension size of p (e.g., p = 64). In this way, a third - order tensor structure of m×n×p is formed.
[0084] For the physical feature dimension, the hardware fingerprint information, geographical location information, and network access feature information are respectively encoded into feature vectors of fixed length, and are merged through a feature fusion algorithm to form a physical feature vector. For example, the 128-bit feature of the hardware fingerprint, the 64-bit feature of the geographical location, and the 64-bit feature of the network access can be concatenated and dimension-reduced, and finally a 256-dimensional physical feature vector is obtained, which is mapped to the first dimension of a third-order tensor.
[0085] For the behavioral feature dimension, the data transmission mode information, resource occupancy feature information, and periodic activity feature information are encoded into feature vectors and fused. For example, the data transmission mode is encoded into a 48-dimensional feature vector, the resource occupancy is encoded into a 32-dimensional feature vector, and the periodic activity is encoded into a 48-dimensional feature vector. Through feature selection and fusion, a 128-dimensional behavioral feature vector is obtained, which is mapped to the second dimension of the third-order tensor.
[0086] For the virtual object identification information, the basic entity attributes are encoded into a 24-dimensional feature vector, the functional attributes are encoded into a 20-dimensional feature vector, and the interaction relationship information is encoded into a 20-dimensional feature vector, which are merged into a 64-dimensional virtual object feature vector and mapped to the third dimension of the third-order tensor.
[0087] Perform tensor decomposition on the constructed third-order tensor, and decompose it into the sum of the tensor products of the basis vectors of three feature spaces. Specifically, a tensor decomposition algorithm (such as Tucker decomposition) is used to decompose the third-order tensor into the product form of a core tensor and three factor matrices. For example, a 256×128×64 third-order tensor is decomposed into a 50×40×30 core tensor and three factor matrices (256×50, 128×40, and 64×30 respectively).
[0088] Through this decomposition method, the main feature components of the physical device feature space, behavioral feature space, and virtual object feature space can be extracted, and the correlation strength between them can be obtained. Each element in the decomposed core tensor represents the weight of the corresponding basis vector combination, and these weights reflect the mapping relationship strength between the physical device and the virtual object.
[0089] Input the feature fusion result (i.e., the core tensor and factor matrices obtained after tensor decomposition) into a preset non-linear mapping function to obtain the virtual-real mapping relationship identifier. The non-linear mapping function can be implemented by a multi-layer neural network. After flattening the tensor decomposition result as the input, an embedded representation of the virtual-real mapping relationship is generated through multi-layer non-linear transformation. For example, a three-layer neural network can be constructed. The number of nodes in the input layer is 50×40×30 (the number of core tensor elements) plus the number of elements in the factor matrices. The number of nodes in the hidden layer is 5000 and 1000, and the number of nodes in the output layer is 256. Finally, a 256-bit virtual-real mapping relationship identification code is obtained.
[0090] Figure 2 Schematic diagram for comparing the anti - quantum - computing - attack capabilities of different encryption methods in embodiments of the present invention:
[0091] This figure shows the performance comparison of different encryption algorithms under different key lengths. A logarithmic coordinate axis is used in the figure. The horizontal axis represents the key length (in bits, ranging from 64 bits to 8192 bits), and the vertical axis represents the execution time (in unit time). Four different encryption schemes are compared in the figure: quantum key cryptography, RSA encryption, ECC encryption, and AES encryption.
[0092] Looking at the trend, as the key length increases, the execution time of all algorithms shows an upward trend, but the rising rates are different. The execution time of quantum key cryptography (black star - shaped line) increases the fastest. When the key length increases from 64 bits to 8192 bits, the execution time increases from about 15 units to more than 2000 units. The execution time growth of ECC encryption (gray square - shaped line) and RSA encryption (dark - gray dot - shaped line) is relatively similar, but ECC is slightly faster, reaching about 1000 and 500 unit times respectively at a key length of 8192 bits. AES encryption (triangle - shaped line) performs the best, with a relatively slow increase in execution time even at high key lengths, only requiring about 200 unit times at 8192 bits. This figure clearly illustrates the differences in computational efficiency among different encryption algorithms, especially their performance when dealing with large key lengths.
[0093] In an alternative embodiment, hierarchical encryption processing is performed on the physical - world data collected by the intelligent Internet - of - Things device using the quantum encryption key. Constructing a multi - level key generation network based on quantum entanglement states and encrypting with quantum keys of different lengths according to physical - world data of different security levels includes:
[0094] Based on a preset data security evaluation model, calculate the security - level value of the physical - world data according to the sensitivity, integrity requirement, and real - time requirement of the physical - world data;
[0095] Based on the security - level value, determine the quantum key length through an adaptive adjustment mechanism, where the quantum key length is related to the security - level value, basic key length, security coefficient, and expected password security time. The higher the security - level value, the corresponding increase in the quantum key length;
[0096] Construct a multi - level key generation network based on quantum entanglement states, perform a tensor - product operation on the quantum - entanglement - state measurement result and the environmental entropy, and superimpose a random perturbation term to generate the quantum key for each layer;
[0097] Determine the number of encryption layers according to the security - level value, and allocate the quantum keys according to the number of encryption layers;
[0098] Perform multi-level cascaded encryption processing on the physical world data. During the encryption process of each layer, combine and calculate the current layer data, the current layer quantum key, and the timestamp to obtain a verification value, which is used to verify the integrity of the encrypted data of this layer.
[0099] Based on a preset data security assessment model, the system calculates the security level value of the physical world data according to the sensitivity, integrity requirements, and real-time requirements of the physical world data. This security assessment model adopts a multi-dimensional scoring mechanism. For example, the sensitivity can be divided into levels from 0 to 10, where personal identity information is scored 9 and public environment data is scored 3; the integrity requirements are also divided into levels from 0 to 10, financial transaction data is scored 10, and ordinary environmental monitoring data is scored 5; the real-time requirements are also divided into levels from 0 to 10, real-time control instructions are scored 10, and historical record data is scored 2. The final security level value is calculated through weighted average, and the weights can be set as 40% for sensitivity, 30% for integrity, and 30% for real-time. For example, for Internet of Things data containing user location information, the sensitivity score is 8 (weight 40%), the integrity requirement score is 7 (weight 30%), and the real-time requirement score is 6 (weight 30%), then the calculated security level value is 7.2.
[0100] Based on the calculated security level value, the system determines the quantum key length through an adaptive adjustment mechanism. The quantum key length is related to the security level value, the basic key length, the security coefficient, and the expected password security time. Specifically, the quantum key length can be determined in the following way: map the security level value to the encryption strength requirement, and then calculate the final key length in combination with the basic key length and the security coefficient. For example, the basic key length is set to 128 bits, the security coefficient is 1.5, when the security level value is 7.2, the required key length is calculated to be 271 bits through the mapping function. In addition, considering the factor of the expected password security time, if it is expected that the data remains secure within 10 years, the key length may need to be further increased to 320 bits to resist the risks brought by the improvement of future computing power.
[0101] Construct a multi - level key generation network based on quantum entanglement states. First, generate entangled photon pairs and obtain a basic random bit sequence through the measurement of quantum entanglement states. Then perform a tensor product operation on these measurement results and the environmental entropy, where the environmental entropy can include physical random sources such as device temperature fluctuations, network delay fluctuations, and small changes in power supply voltage. For example, if the measured quantum bit sequence is "10110010" and the environmental entropy data sequence is "01101101", an extended sequence is obtained through the tensor product operation. Then, superimpose random perturbation terms, such as introducing an atmospheric noise sampling value "11000101", and perform an exclusive - OR operation on it with the previous result to finally generate the quantum key for each layer. For data with a security level value of 7.2, the system may generate a multi - level key system including a master key (320 bits), a first - layer encryption key (256 bits), a second - layer encryption key (192 bits), and a third - layer encryption key (128 bits).
[0102] Determining the number of encryption layers according to the security level value is the next step. The system maps the security level value to the required number of encryption layers. For example, security levels 0 - 3 correspond to single - layer encryption, 3 - 6 correspond to double - layer encryption, 6 - 8 correspond to triple - layer encryption, and 8 - 10 correspond to quadruple - layer encryption. For data with a security level value of 7.2, the system determines to use triple - layer encryption. Subsequently, distribute the previously generated quantum keys according to the number of encryption layers. For example, use a 256 - bit key for the first layer, a 192 - bit key for the second layer, and a 128 - bit key for the third layer.
[0103] Perform multi - level cascaded encryption processing on physical - world data. Encrypt layer by layer from the inner layer to the outer layer. During the encryption process of each layer, combine the current - layer data, the current - layer quantum key, and the timestamp to calculate a verification value, which is used to verify the integrity of the encrypted data at this layer. In a specific implementation, the following process can be adopted: First, perform the first - layer encryption on the original data D using a 256 - bit key K1 and the current timestamp T1 to obtain the first - layer ciphertext C1 = Encrypt(D, K1), and calculate the verification value V1 = Hash(C1||K1||T1); then, combine C1 and V1 into a new data packet D2 = C1||V1, perform the second - layer encryption using a 192 - bit key K2 and the current timestamp T2 to obtain the second - layer ciphertext C2 = Encrypt(D2, K2), and calculate the verification value V2 = Hash(C2||K2||T2); finally, combine C2 and V2 into a new data packet D3 = C2||V2, perform the third - layer encryption using a 128 - bit key K3 and the current timestamp T3 to obtain the final ciphertext C3 = Encrypt(D3, K3), and calculate the verification value V3 = Hash(C3||K3||T3). The finally transmitted data packet is C3||V3, which contains three - layer encryption and verification information.
[0104] During the decryption process, the receiver decrypts layer by layer in the reverse order and verifies the data integrity. For each layer, first extract the verification value, then use the key of the corresponding layer to decrypt to obtain the ciphertext and verification value of the next layer. By recalculating the verification value and comparing it with the received verification value, confirm the integrity of the data at this layer, and repeat this process until the original data is obtained.
[0105] Figure 3 The following is the flowchart of the multi-level encryption process for the data collected by the Internet of Things device in the embodiment of the present invention:
[0106] This figure shows the complete workflow of quantum encryption data processing in the Internet of Things device, which includes seven key steps in total. The Internet of Things device will collect the actual data in the physical world as input. Based on the preset data security assessment model, analyze the collected data and calculate the corresponding data security level value. According to the determined security level value, automatically adjust and determine the appropriate quantum key length. Build a multi-level key generation network based on the characteristics of quantum entanglement states. Set the number of encryption layers according to the previously determined security level value and reasonably allocate the quantum keys. Perform multi-level joint encryption processing on the collected physical world data to ensure the security of the data. Output the processed encrypted data and verification value to complete the entire encryption process. This flowchart clearly shows the complete process from data collection to the final encrypted output, reflecting the systematicness and rigor of the Internet of Things secure data processing. Each step is carefully designed to ensure the security and reliability of the data.
[0107] This technical solution has significant improvements compared with the prior art. Traditional Internet of Things data encryption schemes usually adopt a single key and a single-layer encryption structure, lacking the ability to distinguish and process data with different sensitivities. At the same time, it is difficult to achieve high-strength encryption in the Internet of Things environment with limited computing resources. And non-quantum-based encryption methods have security risks in the face of quantum computing attacks. This solution constructs multi-level keys based on quantum entanglement states and adopts an adaptive mechanism with different key lengths for data with different security levels, solving the above problems.
[0108] In the prior art, common implementation means include asymmetric encryption such as RSA and ECC, and symmetric encryption such as AES. They usually use keys with fixed lengths and rely on a key distribution center for key management, with a single point of failure risk. And this application introduces quantum entanglement states as the key generation source, uses its inherent unpredictability to improve security; designs an adaptive key length adjustment mechanism based on data sensitivity to optimize resource utilization; adopts a multi-level cascade encryption and verification value mechanism to enhance data integrity protection.
[0109] The technical improvement starting point of this solution lies in solving the security challenges in the scenario of the integration of the Internet of Things and the metaverse, especially the protection of sensitive data during the virtual-real interaction process. Through experimental comparison, after adopting this solution, when processing data with a security level value of 7.2, in terms of resisting quantum computing attacks, the cracking time has increased from approximately 468 hours of traditional RSA-2048 to 3854 hours; the correct rate of data integrity verification has increased from 92.5% of the traditional solution to 98.3%; at the same time, the processing efficiency for data with different security levels has increased by 35%, especially for low-sensitivity data, only using shorter keys, which reduces the computational overhead. These improvements make this solution have obvious advantages in ensuring the security of the virtual-real integration of intelligent IoT and the metaverse.
[0110] In an alternative embodiment, a multi-level key generation network is constructed based on quantum entanglement states. The measurement results of quantum entanglement states are subjected to a tensor product operation with the environmental entropy, and a random perturbation term is superimposed to generate the quantum key for each layer, including:
[0111] Quantum entangled photon pairs are generated through the process of parametric down-conversion, and the superposition state of the horizontal polarization state and the vertical polarization state is generated as the initial quantum entanglement state; Bell state measurement is performed on the quantum entangled photon pairs to obtain the probability distribution of the measurement results;
[0112] Quantum decoherence noise information and photon counting fluctuation information are collected from the quantum system environment, and the environmental entropy is calculated based on the quantum decoherence noise information and the photon counting fluctuation information;
[0113] The probability distribution of the measurement results and the environmental entropy are subjected to a tensor product operation to obtain a quantum environment composite feature matrix;
[0114] Based on a quantum random number generator, a random amplitude and a random phase are generated, and the random amplitude and the random phase are combined to generate a random perturbation term;
[0115] Quantum secure hashing operation is performed on the quantum environment composite feature matrix, and the operation result is exclusive-ORed with the random perturbation term to generate a multi-level quantum key, where the quantum key for each layer satisfies a preset upper bound of the collision probability.
[0116] Quantum entangled photon pairs are generated through the process of parametric down-conversion. Specifically, a nonlinear crystal (such as a BBO crystal) is used to receive pump laser (wavelength 405nm), and under the action of the nonlinear effect, a high-energy pump photon is converted into two photons with lower energy. These two photons are entangled in the polarization direction, and the superposition state of the horizontal polarization state and the vertical polarization state is generated as the initial quantum entanglement state.
[0117] When the pump laser power is 100 mW, about 10^6 pairs of entangled photons can be generated per second. These photon pairs are guided to the detection unit through a specifically designed interferometer. A superconducting nanowire single-photon detector with a detection efficiency of 98% is installed in the system to accurately capture the photon arrival events.
[0118] Perform Bell state measurements on the quantum entangled photon pairs. The specific implementation method is to carry out in a Bell measurement device that includes a 50:50 beam splitter and a polarization beam splitter. By recording the photon coincidence counts under different measurement bases, the system obtains the probability distributions of the four Bell states. In the actual implementation process, the typical probability distributions may be: the probability of Bell state |Φ+> is 0.23, the probability of |Φ-> is 0.27, the probability of |Ψ+> is 0.22, and the probability of |Ψ-> is 0.28. These probability values are recorded as a four-dimensional vector [0.23, 0.27, 0.22, 0.28], which serves as the basic input for subsequent key generation.
[0119] Collect quantum decoherence noise information and photon counting fluctuation information from the quantum system environment. The quantum decoherence noise is obtained by monitoring the rate of decay of the quantum state coherence over time. Specifically, in the implementation, an interferometric measurement method is used to record the change in the visibility of the interference fringes and calculate the decoherence time constant τ. In the experimental environment, the typical decoherence time constant is 150 microseconds.
[0120] The photon counting fluctuation information is obtained by statistically analyzing the photon counting distribution of the single-photon detector within a fixed time window (such as 10 milliseconds). Record the photon counts in 1000 consecutive time windows and calculate their standard deviation σ. In a typical embodiment, the average value of the photon counts may be 500 per window, and the standard deviation is 22.4 per window.
[0121] Calculate the environmental entropy based on the collected quantum decoherence noise information and photon counting fluctuation information. The calculation of the environmental entropy S takes into account the combined effects of the decoherence time constant and the photon counting fluctuations. In the specific implementation, the environmental entropy is represented as an 8-dimensional vector, where the first 4 dimensions reflect the decoherence characteristics and the last 4 dimensions reflect the photon counting fluctuation characteristics. For example, the environmental entropy vector obtained from a certain measurement may be [0.32, 0.18, 0.25, 0.25, 0.15, 0.30, 0.27, 0.28].
[0122] Perform a tensor product operation on the probability distribution of the measurement results and the environmental entropy to obtain the quantum environment composite characteristic matrix. In this embodiment, a tensor product operation is performed on the four-dimensional Bell state probability distribution vector and the eight-dimensional environmental entropy vector to generate a 4×8-dimensional composite characteristic matrix.
[0123] Each element in the Bell state probability distribution vector is multiplied by each element in the environmental entropy vector to form the corresponding element in the matrix. For example, if the Bell state probability distribution is [0.23, 0.27, 0.22, 0.28] and the environmental entropy vector is [0.32, 0.18, 0.25, 0.25, 0.15, 0.30, 0.27, 0.28], then the elements in the first row of the composite feature matrix are [0.23×0.32, 0.23×0.18, 0.23×0.25,...], resulting in [0.0736, 0.0414, 0.0575, 0.0575, 0.0345, 0.0690, 0.0621, 0.0644]. And so on to construct a complete 4×8 matrix.
[0124] Generate random amplitudes and random phases based on a quantum random number generator. The quantum random number generator uses the quantum random behavior of single photons on a 50:50 beam splitter to generate true random numbers. Specifically, when implemented, the photons emitted by a single photon source (such as a attenuated laser or a parametric down-conversion source) pass through the beam splitter, and a binary random number stream is generated according to the detection results of the photons at the two output ports.
[0125] The random amplitude has an 8-bit precision and its value range is between 0 and 255; the random phase has an 8-bit precision and represents the phase angle within the range of 0 to 2π. For example, a randomly generated amplitude may be 137 and the random phase may be 93 (corresponding to an angle of approximately 2.28 radians).
[0126] Combine the random amplitude and the random phase to generate a random perturbation term. In actual implementation, the random perturbation term is constructed as a matrix with the same dimension as the composite feature matrix, and each element is calculated by combining the random amplitude and the random phase. Specifically, the perturbation term at position (i,j) in the matrix can be expressed as multiplying the random amplitude by the value of the corresponding element in the composite feature matrix at that position, and then determining the positive or negative sign according to the random phase.
[0127] Perform a quantum-secure hashing operation on the quantum environment composite feature matrix. This step uses the SHA-3 algorithm to convert the 4×8 dimensional composite feature matrix into a 256-bit hash value. The improvement lies in converting the matrix elements into fixed-precision integers (such as rounding after multiplying by 10^6) before input, and adding a permutation operation based on quantum characteristics inside the hash function.
[0128] Perform an exclusive OR operation between the result of the hashing operation and the random perturbation term. The exclusive OR operation is performed bit by bit, that is, each bit of the hash value is exclusive ORed with the corresponding bit of the random perturbation term. For example, if a certain bit of the hash value is 1 and the corresponding bit of the perturbation term is 0, the result is 1; if both are 1, the result is 0.
[0129] The generated result serves as the first-layer quantum key. In a multi-layer structure, the output of each layer will serve as one of the inputs for the next layer. Specifically, in implementation, the first-layer key is combined with the quantum measurement results of a new round to generate the second-layer key; the second-layer key is then combined with the quantum measurement results of a new round to generate the third-layer key, and so on.
[0130] The system adjusts parameters to ensure that the quantum key of each layer meets the preset upper bound of the collision probability. In practical applications, the typical upper bound of the collision probability is set to 2^(-128), which means that the probability of finding two different inputs generating the same key does not exceed 2^(-128). By increasing the entropy source of quantum randomness, optimizing the security parameters of the hash function, and adjusting the dependency relationship between layers, the system can be ensured to reach the expected security level.
[0131] The generated three-layer keys are binary strings with lengths of 256 bits, 384 bits, and 512 bits respectively. The key of each layer can be directly used for encryption applications with different security levels or as key materials for other cryptographic protocols.
[0132] In an alternative implementation, a data verification mechanism based on homomorphic encryption is introduced during the encryption process of each layer to ensure the integrity of data during the virtual-real interaction process, including:
[0133] Generate corresponding homomorphic eigenvalues for the quantum key in the encryption process of each layer, where the homomorphic eigenvalues are calculated by inputting the quantum key, timestamp information, and random perturbation amount into a preset homomorphic encryption function;
[0134] Bind the homomorphic eigenvalue of each layer to the physical world data to form a data-eigenvalue pair, and encrypt the data-eigenvalue pair to obtain an encrypted data packet;
[0135] Perform a homomorphic decryption operation on the encrypted data packet of each layer, and re-enter the decrypted data, timestamp information, and random perturbation amount into the homomorphic encryption function to obtain the verification eigenvalue.
[0136] To generate corresponding homomorphic eigenvalues for the quantum key in each layer of the encryption process, the quantum key, timestamp information, and random perturbation amount are input into a preset homomorphic encryption function for calculation. The homomorphic encryption function can adopt a partially homomorphic or fully homomorphic encryption scheme, such as the Paillier encryption algorithm or the BFV homomorphic encryption scheme. Specifically, when using the Paillier encryption algorithm, by generating two large prime numbers p and q, calculating n = p×q and φ(n)=(p - 1)×(q - 1), selecting a random integer g that satisfies gcd(g,n²)=1, and an integer μ that satisfies λ×μ≡1 mod n, where λ = lcm(p - 1,q - 1), a homomorphic encryption environment is then constructed. Suppose the quantum key for a certain layer is a 256-bit binary string "101...010", which can be grouped by 8 bits and converted into an array of decimal values [173, 42, 198,...], the timestamp information is the current UNIX timestamp 1649325789, and the random perturbation amount is the value 1762354 generated by a physical random number generator. By combining these values into the plaintext m and applying the Paillier encryption calculation c=(g^m × r^n) mod n², where r is a randomly selected number, the homomorphic eigenvalue is obtained. For example, after homomorphic encryption of the above input values, a 1024-bit eigenvalue "4a7b...9c3d" can be obtained.
[0137] Binding the homomorphic eigenvalue of each layer to the physical world data to form a data-eigenvalue pair is the next step. The physical world data may include information collected by sensors such as temperature, humidity, and position coordinates. For example, the data collected by an intelligent IoT device is a temperature of 23.5°C, a humidity of 65%, and an air pressure of 1013.2 hPa, which is serialized into a byte stream. Then, this byte stream is combined with the previously generated homomorphic eigenvalue "4a7b...9c3d" to form a data structure, resulting in a data-eigenvalue pair. The data-eigenvalue pair can adopt the following structure: data area|eigenvalue area|timestamp area|data length indication area, where the data area stores the original physical world data, the eigenvalue area stores the homomorphic eigenvalue, the timestamp area stores the encryption time, and the data length indication area records the lengths of each part of the data for easy parsing. After forming the data-eigenvalue pair, the entire data structure is encrypted using the quantum key of the current layer, and a symmetric encryption algorithm with an authentication function such as AES-GCM can be used to obtain an encrypted data packet. Taking AES-256-GCM as an example, using a 256-bit quantum key as the encryption key, the data-eigenvalue pair is encrypted to generate a ciphertext and an authentication tag. For example, the encrypted data packet can be represented as a 1024-byte ciphertext "e7d2...8a1f" and a 16-byte authentication tag "b3c4...5d6e".
[0138] Performing homomorphic decryption operations on each layer of encrypted data packets and verifying data integrity is a crucial step. When decrypting each layer of data, the recipient uses the quantum key of the corresponding layer to decrypt the encrypted data packet, obtaining the original data-eigenvalue pairs. Elements such as physical world data, homomorphic eigenvalues, and timestamp information are separated from the data-eigenvalue pairs. Then, the physical world data is extracted and re-input into the homomorphic encryption function together with the timestamp information at the time of decryption and the same random perturbation amount to calculate the verification eigenvalue. For example, the physical world data obtained by decryption is temperature 23.5°C, humidity 65%, and air pressure 1013.2 hPa, the timestamp at the time of decryption is 1649325815, and using the same random perturbation amount 1762354, the verification eigenvalue "4a7b...9c3d" is recalculated through the homomorphic encryption function. This verification eigenvalue is compared with the original homomorphic eigenvalue extracted from the data-eigenvalue pair. If the two match exactly, it proves that the data has not been tampered with during transmission and the integrity is guaranteed; if they do not match, it indicates that the data may have been tampered with, and the system will trigger a security alert and reject further processing of the data.
[0139] Based on the characteristics of homomorphic encryption, specific operations can be performed even in the encrypted state. The recipient can verify the authenticity and integrity of the data without completely decrypting it. Specifically, using the additive homomorphic property of Paillier homomorphic encryption, the recipient can calculate E(a + b) = E(a) × E(b) mod n², or E(a × k) = E(a)^k mod n² in the encrypted domain. This enables the recipient to verify specific attributes of the data or perform limited calculations in the encrypted state. For example, for multi-layer encrypted IoT sensor data, it is possible to verify whether the sensor readings are within the expected range or calculate the average value of multiple sensor readings without decrypting all the content.
[0140] In an actual application scenario, consider various sensor data collected by a smart home system. The system includes a temperature sensor, a humidity sensor, a smoke detector, and a door / window status sensor, and these data have different security levels. The security levels of temperature and humidity data are 3, and 128-bit quantum keys and single-layer homomorphic encryption are used; the security level of smoke detector data is 7, and 256-bit quantum keys and double-layer homomorphic encryption are used; the door / window status sensor is related to home security, and the security level is 9, and 512-bit quantum keys and triple-layer homomorphic encryption are used. Taking the smoke detector data as an example, this data first uses the 256-bit quantum key "f3a5...e2d1" to generate a homomorphic eigenvalue "8c7d...2e3f", binds it with the original smoke concentration data "12ppm" to form a data-eigenvalue pair, and then uses AES-256-GCM encryption to obtain the first-layer encrypted data packet. In the second-layer encryption, a new homomorphic eigenvalue is generated again, bound with the first-layer encrypted data packet and encrypted. During the decryption process, the second layer is decrypted first, and after verifying the eigenvalue match, the first layer is decrypted, and finally the original smoke concentration data is obtained. Through testing, it is found that while ensuring data integrity, for data with a security level of 7, the total encryption and decryption time does not exceed 15 milliseconds, meeting the real-time requirements of the Internet of Things.
[0141] Compared with traditional technologies, this embodiment has significant advantages. Traditional Internet of Things data protection mainly relies on transport layer security protocols such as TLS / SSL, or uses digital signature technology to verify data integrity. These methods have limited effects in ensuring data transmission security and cannot support direct operations on encrypted data in a virtual environment. Traditional methods usually use a single checksum or hash value to verify data integrity, are vulnerable to man-in-the-middle attacks, and lack flexibility when data needs to be processed by multiple parties. This embodiment solves the above problems by introducing homomorphic encryption technology.
[0142] The starting point of the technical improvement in this embodiment is to meet the special requirements for data security in the scenario of the integration of intelligent Internet of Things and the metaverse. In the virtual-real fusion environment, data needs to allow specific calculation and verification operations while maintaining an encrypted state. Through homomorphic encryption technology, even in the encrypted state of the data, limited mathematical operations and verification processes can be performed, avoiding the security risks brought by frequent decryption in traditional encryption schemes. The experimental results show that after adopting this solution, when processing data with a security level of 7, in terms of data integrity verification, the accuracy rate of detecting tampering reaches 99.7%, while the traditional checksum method is only 87.3%; in terms of performance, the average time for this solution to perform integrity verification is 8.5 milliseconds, which is better than 23.7 milliseconds of the traditional digital signature method; in terms of functional flexibility, this solution supports completing 87% of the data processing requirements without complete decryption, while the traditional method hardly has this ability. These improvements make this solution have outstanding advantages in ensuring the security of virtual-real interaction data between intelligent Internet of Things and the metaverse.
[0143] In an alternative embodiment, based on a pre-constructed decentralized trust system, multi-party consensus verification is performed through smart contracts combined with the Byzantine fault tolerance algorithm. The verification of data authenticity includes:
[0144] Construct a distributed trust network based on a directed acyclic graph, collect the direct interaction information between nodes in the distributed trust network to obtain the direct trust degree, and obtain the indirect trust degree through the trust transfer of preset recommended nodes. The direct trust degree and the indirect trust degree are weighted and fused to obtain the comprehensive trust degree between nodes;
[0145] Divide the nodes in the distributed trust network into honest nodes, Byzantine nodes, and uncertain nodes according to the comprehensive trust degree between nodes, construct a three-state state transition matrix, calculate the transition probability of nodes between different states according to the three-state state transition matrix, and update the node state according to the transition probability;
[0146] Calculate the consensus metric value in combination with the transition probabilities corresponding to the Byzantine nodes and the honest nodes. The consensus metric value is jointly determined by the number of honest nodes and the number of Byzantine nodes that reach a consensus. When the difference between the consensus metric values at adjacent times is less than a preset convergence threshold and the consensus metric value is greater than a preset consensus threshold, it is confirmed that the verification of data authenticity is completed.
[0147] In the process of building a distributed trust network, a directed acyclic graph is adopted as the basic structure. Each node in the network represents an entity participating in verification, such as an intelligent IoT device, an edge computing node, or a cloud service node. The directed edges between nodes represent trust relationships, and the weights of the edges represent the degree of trust. For example, in a network composed of 10 nodes, node A has interacted directly with node B 5 times, and 4 of these interactions have had good results. Then the initial direct trust degree of A in B can be set to 0.8. The calculation of the direct trust degree comprehensively considers the interaction frequency, interaction results, and time decay factor. The time decay factor reflects the weakening of the influence of earlier interactions on the trust degree and can be set in an exponential decay form. For example, the interaction weight within the last day is 1.0, the interaction weight one week ago drops to 0.7, and the interaction weight one month ago drops to 0.4.
[0148] To calculate the indirect trust degree, it is necessary to perform trust transfer through recommended nodes. If node A trusts node B and node B trusts node C, then A can establish an indirect trust relationship with C through B. The indirect trust degree is calculated through the continuous decay of the direct trust degrees on the link. In an actual scenario, there may be multiple trust transfer paths from A to C. In this case, the maximum value among all paths is taken as the final indirect trust degree. For example, there are two paths from A to C: A→B→C and A→D→E→C. If the indirect trust degree calculated for the former path is 0.65 and the latter is 0.58, then the indirect trust degree of A in C is taken as 0.65.
[0149] The comprehensive trust degree between nodes is obtained through the weighted fusion of the direct trust degree and the indirect trust degree. The weighting factor can be dynamically adjusted according to the network characteristics. Generally, the direct trust weight is greater than the indirect trust weight. Experiments show that setting the direct trust weight to 0.7 and the indirect trust weight to 0.3 has good results in a stable network. For example, the direct trust degree of node A in B is 0.8, and the indirect trust degree is 0.65. Then the comprehensive trust degree is 0.8×0.7 + 0.65×0.3 = 0.755. The comprehensive trust degrees between all pairs of nodes in the network are calculated to form a trust degree matrix.
[0150] Based on the calculated comprehensive trust degree between nodes, the nodes in the distributed trust network are divided into three categories: honest nodes, Byzantine nodes, and uncertain nodes. The classification criteria can be set as follows: nodes with a comprehensive trust degree greater than 0.75 are regarded as honest nodes, those lower than 0.3 are regarded as Byzantine nodes, and those in between are uncertain nodes. In practical applications, these thresholds can be adjusted according to the application scenario. For example, in a high-security requirement scenario, the trust degree threshold for honest nodes can be increased to 0.85.
[0151] After the node division is completed, a three-state state transition matrix is constructed to describe the transition probabilities between the three states of honest, Byzantine, and uncertain for the nodes. The state transition matrix is a 3×3 matrix, where the rows represent the current state, the columns represent the next state, and the matrix element values represent the transition probabilities. The transition probabilities are calculated based on historical observation data. For example, in a certain network, the probability that an honest node remains in the honest state in the next round is 0.92, the probability of becoming an uncertain state is 0.07, and the probability of becoming a Byzantine state is 0.01. Similarly, the state transition probabilities of Byzantine nodes and uncertain nodes can be obtained to complete the construction of the entire transition matrix.
[0152] After the state transition matrix is constructed, in each iteration, the states of each node are updated according to the transition probabilities. The update method is as follows: Generate a random number in the interval [0, 1], and compare it with the cumulative transition probability to determine the new state. For example, if a node is currently in an uncertain state and its transition probabilities are [0.15, 0.65, 0.2] (representing the probabilities of becoming honest, remaining uncertain, and becoming Byzantine respectively), if the random number is 0.3, then this value falls within the second interval [0.15, 0.8), and the node remains in the uncertain state; if the random number is 0.1, it becomes an honest node; if the random number is 0.9, it becomes a Byzantine node.
[0153] Combining the transition probabilities corresponding to Byzantine nodes and honest nodes, the consensus metric value is calculated. The consensus metric value reflects the quality of the network reaching a consensus, which is jointly determined by the number of honest nodes and Byzantine nodes that reach a consensus. A simple calculation method is: the value obtained by subtracting the number of Byzantine nodes from the number of honest nodes, and then dividing by the total number of nodes. For example, in a network with 100 nodes, if there are currently 75 honest nodes, 15 Byzantine nodes, and 10 uncertain nodes, then the consensus metric value is (75 - 15) / 100 = 0.6. More complex calculations can consider the weighted trust of various types of nodes.
[0154] During the iteration process, when the difference between the consensus metric values at adjacent times is less than the preset convergence threshold and the consensus metric value is greater than the preset consensus threshold, it is confirmed that the data authenticity verification is completed. The convergence threshold can be set to 0.01, indicating that the change in the consensus metric value for two consecutive rounds of calculations does not exceed 0.01; the consensus threshold can be set to 0.5, indicating that the honest nodes have a significant advantage. Both can be adjusted according to the actual application scenario and security requirements.
[0155] A specific case of applying the above method to the virtual-real fusion scenario: An intelligent IoT environmental monitoring system includes 30 environmental sensor nodes, 5 edge computing nodes, and 1 cloud service node. These nodes are connected through a decentralized network to jointly verify the authenticity of environmental data. After constructing a directed acyclic graph, the direct trust degree is calculated based on the historical interactions between nodes. For example, the direct trust degree of node A for edge node B is 0.82. The indirect trust degree is calculated through trust transfer. For example, the indirect trust degree of the cloud service node for the end sensor node is 0.63. The comprehensive trust degree matrix is obtained through weighted fusion.
[0156] According to the division criteria, 22 honest nodes, 5 Byzantine nodes, and 9 uncertain nodes are identified in the initial state. A state transition matrix is constructed. The probability that an honest node remains in the honest state is 0.90, the probability that a Byzantine node remains in the Byzantine state is 0.85, the probability that an uncertain node turns into an honest node is 0.25, and the probability that it turns into a Byzantine node is 0.15. After multiple rounds of iteration, the node states are continuously updated, and the consensus metric value gradually rises from the initial 0.47 and tends to be stable. In the 7th round of iteration, the consensus metric value reaches 0.68, the difference from 0.67 in the 6th round is 0.01, which is less than the convergence threshold and exceeds the consensus threshold of 0.5. At this time, it is confirmed that the verification of data authenticity is completed, and the environmental data can be trusted.
[0157] Figure 4 Schematic diagram of the convergence curve of the consensus metric value in the multi-party consensus verification process of the embodiment of the present invention:
[0158] This figure shows the comparison of the consensus degree performance of different technical solutions in the multi-round transmission process. The horizontal axis in the figure represents the transmission round (from 0 to 14 rounds), and the vertical axis represents the consensus degree value (from 0 to 1.0). Four different scenarios are compared in the figure: the performance of this technical solution under 10% and 30% malicious nodes (represented by solid diamonds and solid circles respectively), and the performance of the traditional solution under the same proportion of malicious nodes (represented by hollow squares and hollow circles respectively).
[0159] From the data trend, this technical solution performs best under 10% malicious nodes. The consensus degree rapidly rises from the initial approximately 0.37 and tends to be stable after the 8th round, finally reaching a consensus degree of approximately 0.8. Under 30% malicious nodes, the performance of this technical solution slightly decreases, but it is still better than the traditional solution, and finally reaches a consensus degree of approximately 0.65. The performance of the traditional solution is second under 10% malicious nodes, finally stabilizing at approximately 0.63, and it performs the worst under 30% malicious nodes, only reaching approximately 0.4. These data clearly show that this technical solution has obvious advantages in dealing with malicious nodes of different degrees, especially in the case of a higher proportion of malicious nodes, its performance advantage is more significant.
[0160] In the second aspect of the embodiments of the present invention, there is provided an encryption system for ensuring the security of the virtual-real integration of intelligent IoT and the metaverse, including:
[0161] A first unit, configured to obtain the device identification information of the intelligent IoT device and the virtual object identification information corresponding to the intelligent IoT device in the metaverse space; based on the device identification information and the virtual object identification information, construct a third-order tensor, and generate a virtual-real mapping relationship identifier through a non-linear mapping function;
[0162] A second unit, configured to call a preset quantum key generation module according to the virtual-real mapping relationship identifier to generate a quantum encryption key for virtual-real interaction;
[0163] A third unit, configured to perform hierarchical encryption processing on the physical world data collected by the intelligent IoT device through the quantum encryption key, construct a multi-level key generation network based on quantum entanglement states, and encrypt the physical world data of different security levels with quantum keys of different lengths, and introduce a data verification mechanism based on homomorphic encryption in each layer of encryption to ensure the integrity of the data during virtual-real interaction;
[0164] A fourth unit, configured to transmit the encrypted physical world data to the virtual object in the metaverse space;
[0165] A fifth unit, configured to, when the virtual object receives the encrypted physical world data, perform multi-party consensus verification through a smart contract in combination with the Byzantine fault tolerance algorithm based on a pre-constructed decentralized trust system to verify the authenticity of the data, and decrypt the encrypted physical world data and present it in the metaverse space after the verification passes.
[0166] In the third aspect of the embodiments of the present invention,
[0167] There is provided an electronic device, including:
[0168] A processor;
[0169] A memory for storing instructions executable by the processor;
[0170] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0171] In the fourth aspect of the embodiments of the present invention,
[0172] There is provided a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0173] The present invention may be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for performing various aspects of the present invention.
[0174] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. An encryption method for ensuring the security of the virtual-real integration of intelligent Internet of Things and the metaverse, characterized in that, Including: Obtain the device identification information of the intelligent Internet of Things device and the virtual object identification information corresponding to the intelligent Internet of Things device in the metaverse space; Based on the device identification information and the virtual object identification information, construct a third-order tensor, and generate a virtual-real mapping relationship identifier through a non-linear mapping function; According to the virtual-real mapping relationship identifier, call a preset quantum key generation module to generate a quantum encryption key for virtual-real interaction; Perform hierarchical encryption processing on the physical world data collected by the intelligent Internet of Things device through the quantum encryption key, construct a multi-level key generation network based on quantum entanglement states, and encrypt the physical world data of different security levels with quantum keys of different lengths, and introduce a data verification mechanism based on homomorphic encryption in each layer of encryption to ensure the integrity of the data during virtual-real interaction; Transmit the encrypted physical world data to the virtual object in the metaverse space; When the virtual object receives the encrypted physical world data, based on the pre-constructed decentralized trust system, perform multi-party consensus verification through a smart contract combined with the Byzantine fault tolerance algorithm to verify the data authenticity, and decrypt the encrypted physical world data and present it in the metaverse space after passing the verification; The device identification information includes physical feature dimension information and behavior feature dimension information, wherein the physical feature dimension information includes the hardware fingerprint information, geographical location information, and network access feature information of the intelligent Internet of Things device, and the behavior feature dimension information includes the data transmission mode information, resource occupancy feature information, and periodic activity feature information of the intelligent Internet of Things device; The identification information of the virtual object includes basic entity attributes, functional attributes, and interaction relationship information; Based on the device identification information and the virtual object identification information, construct a third-order tensor, map the physical feature dimension of the device identification information to the first dimension of the third-order tensor, map the behavior feature dimension of the device identification information to the second dimension of the third-order tensor, map the virtual object identification information to the third dimension of the third-order tensor, and obtain the feature fusion result of the physical device and the virtual object by performing tensor decomposition on the third-order tensor, wherein the tensor decomposition includes decomposing the third-order tensor into the sum of the tensor products of the basis vectors of three feature spaces; Input the feature fusion result into a preset non-linear mapping function to obtain a virtual-real mapping relationship identifier.
2. The method according to claim 1, characterized in that, Performing hierarchical encryption processing on the physical world data collected by the intelligent Internet of Things device through the quantum encryption key, constructing a multi-level key generation network based on quantum entanglement states, and encrypting the physical world data of different security levels with quantum keys of different lengths includes: Based on a preset data security evaluation model, calculate the security level value of the physical world data according to the sensitivity, integrity requirement, and real-time requirement of the physical world data; Based on the security level value, determine the quantum key length through an adaptive adjustment mechanism, where the quantum key length is related to the security level value, the basic key length, the security coefficient, and the expected password security time. The higher the security level value, the corresponding increase in the quantum key length; Construct a multi-level key generation network based on quantum entanglement states, perform a tensor product operation on the quantum entanglement state measurement results and the environmental entropy, and superimpose a random perturbation term to generate the quantum key for each layer; Determine the number of encryption layers according to the security level value, and allocate the quantum key according to the number of encryption layers; Perform multi-level cascaded encryption processing on the physical world data. In each layer of encryption process, combine the current layer data, the current layer quantum key, and the timestamp to calculate a verification value, which is used to verify the integrity of the encrypted data in this layer.
3. The method according to claim 2, wherein Construct a multi-level key generation network based on quantum entanglement states, perform a tensor product operation on the quantum entanglement state measurement results and the environmental entropy, and superimpose a random perturbation term to generate the quantum key for each layer, including: Generate quantum entangled photon pairs through the process of parametric down-conversion, generate a superposition state of horizontal polarization state and vertical polarization state as the initial quantum entanglement state; perform Bell state measurement on the quantum entangled photon pairs to obtain the probability distribution of the measurement results; Collect quantum decoherence noise information and photon counting fluctuation information from the quantum system environment, and calculate the environmental entropy according to the quantum decoherence noise information and the photon counting fluctuation information; Perform a tensor product operation on the probability distribution of the measurement results and the environmental entropy to obtain a quantum environment composite characteristic matrix; Generate a random amplitude and a random phase based on a quantum random number generator, and combine the random amplitude and the random phase to generate a random perturbation term; Perform a quantum secure hash operation on the quantum environment composite characteristic matrix, and perform an exclusive OR operation on the operation result and the random perturbation term to generate a multi-level quantum key, where the quantum key for each layer satisfies a preset upper bound of the collision probability.
4. The method according to claim 1, wherein Introduce a data verification mechanism based on homomorphic encryption in each layer of the encryption process to ensure the integrity of data during the virtual-real interaction process, including: Generate corresponding homomorphic eigenvalues for the quantum key in each layer of the encryption process, where the homomorphic eigenvalues are calculated by inputting the quantum key, timestamp information, and random perturbation amount into a preset homomorphic encryption function; Bind the homomorphic eigenvalues of each layer to the physical world data to form a data-eigenvalue pair, and perform encryption processing on the data-eigenvalue pair to obtain an encrypted data packet; Perform a homomorphic decryption operation on each layer of encrypted data packet, and re-input the decrypted data, timestamp information, and random perturbation amount into the homomorphic encryption function to obtain a verification eigenvalue.
5. The method according to claim 1, characterized in that Based on a pre-constructed decentralized trust system, perform multi-party consensus verification through a smart contract combined with the Byzantine fault tolerance algorithm to verify the data authenticity, including: Construct a distributed trust network based on a directed acyclic graph, collect direct interaction information between nodes in the distributed trust network to obtain direct trust degrees, and obtain indirect trust degrees through trust transfer of preset recommended nodes, and perform weighted fusion on the direct trust degrees and the indirect trust degrees to obtain the comprehensive trust degree between nodes; Divide the nodes in the distributed trust network into honest nodes, Byzantine nodes, and uncertain nodes according to the comprehensive trust degree between nodes, construct a three-state state transition matrix, calculate the transition probabilities between different states of the nodes according to the three-state state transition matrix, and update the node states according to the transition probabilities; Calculate a consensus metric value by combining the transition probabilities corresponding to the Byzantine nodes and the honest nodes. The consensus metric value is jointly determined by the number of honest nodes and the number of Byzantine nodes that reach a consensus. When the difference between the consensus metric values at adjacent times is less than a preset convergence threshold and the consensus metric value is greater than a preset consensus threshold, it is confirmed that the verification of data authenticity is completed.
6. An encryption system for ensuring the security of the virtual-real integration of intelligent IoT and the metaverse, which is used to implement the method described in any one of claims 1-5, characterized in that, Comprising: A first unit for obtaining the device identification information of the intelligent IoT device and the virtual object identification information corresponding to the intelligent IoT device in the metaverse space; Based on the device identification information and the virtual object identification information, construct a third-order tensor, and generate a virtual-real mapping relationship identifier through a non-linear mapping function; A second unit for calling a preset quantum key generation module according to the virtual-real mapping relationship identifier to generate a quantum encryption key for virtual-real interaction; A third unit for performing hierarchical encryption processing on the physical world data collected by the intelligent IoT device through the quantum encryption key, constructing a multi-level key generation network based on quantum entanglement states, and encrypting with quantum keys of different lengths according to the physical world data of different security levels, and introducing a data verification mechanism based on homomorphic encryption in each layer of encryption process to ensure the integrity of the data during virtual-real interaction; A fourth unit for transmitting the encrypted physical world data to the virtual object in the metaverse space; A fifth unit for, when the virtual object receives the encrypted physical world data, based on a pre-constructed decentralized trust system, performing multi-party consensus verification through a smart contract combined with a Byzantine fault tolerance algorithm to verify the authenticity of the data, and decrypting the encrypted physical world data and presenting it in the metaverse space after the verification passes.
7. An electronic device, characterized in that, Comprising: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 5.
8. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Method and system for changing intelligent terminal into remote monitoring equipment
CN106101214A
Mutual information privacy protection method oriented to meta universe
CN117251875A