Communication security monitoring system and method based on block chain technology
By adopting the dynamic sharded blockchain architecture and space-time coupling verification mechanism of blockchain technology in the communication security monitoring system, the fragile architecture, insufficient data credibility and high storage costs of the existing system are solved, and efficient real-time monitoring and accurate attack path traceability are achieved.
Patent Information
- Application Number
- CN202510415715.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-06-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing communication security monitoring systems have problems such as fragile centralized architecture, insufficient data credibility, insufficient real-time response capabilities, difficulty in cross-domain traceability and high storage costs.
The dynamic sharded blockchain architecture based on blockchain technology, a space-time coupling verification mechanism and verifiable delay monitoring are adopted, and technical means such as node identity registration, dynamic sharding, dual-stream feature analysis, abnormal index calculation, real-time alarm, tracking path generation and evidence link packaging.
It improves the system's security level and evidence link generation efficiency, reduces storage space and costs, and realizes minute-level accurate attack path traceability.
Smart Images

Figure CN120223405A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of communication security, and particularly relates to a communication security monitoring system and method based on blockchain technology. Background Art
[0002] With the rapid development of new generation communication technologies such as 5G and Internet of Things, network attack means show an intelligent and concealed trend. The traditional communication security monitoring system has the following technical bottlenecks: (1) Vulnerability of centralized monitoring architecture: Most existing systems use a centralized server to store monitoring data, which has a single point of failure risk and is vulnerable to DDoS attacks, resulting in service interruption.
[0003] (2) Insufficient data credibility: Conventional encryption methods (such as AES-GCM) cannot guarantee the verifiability of monitoring data throughout the entire life cycle. Reports from third-party auditing agencies indicate that in approximately 38% of security incidents, logs have been tampered with.
[0004] (3) Limited real-time response ability: Existing blockchain monitoring solutions adopt a single chain structure. When the network throughput exceeds 1,000 TPS, the data upload delay will exceed 2 seconds, which cannot meet the millisecond-level response requirements in the 5G URLLC scenario.
[0005] (4) Difficulty in cross-domain traceability: Traditional methods rely on IP address tracing (such as CN114301692A), and it is difficult to penetrate multiple layers of virtualized networks in the SDN / NFV environment. The 2022 MITRE ATT&CK assessment shows that existing solutions on average take 4.7 hours to complete the restoration of cross-domain attack paths.
[0006] (5) Excessive storage cost: The full-node storage mode of public blockchains (such as the current data volume of Ethereum is approximately 12TB) leads to excessive storage overhead for the monitoring system. Experiments show that in the industrial Internet of Things scenario, the storage cost accounts for more than 63% of the total system investment.
[0007] This technical solution addresses the above pain points. Through core technologies such as an innovative dynamic sharding blockchain architecture, a spatio-temporal coupling verification mechanism, and verifiable delay monitoring, while ensuring the credibility of communication monitoring data, it significantly improves the real-time performance of the system, reduces storage overhead, and achieves minute-level accurate tracing of attack paths. Summary of the Invention
[0008] The object of the present invention is to provide a communication security monitoring system and method based on blockchain technology, which creates node identity registration and dynamic sharding, generates the main chain genesis block, analyzes dual-stream features, calculates the anomaly index and gives real-time alarms, generates a tracking path at the same time, and generates an evidence chain for packaging, thus solving the problems of the existing monitoring architecture being fragile, having insufficient real-time response capabilities, being difficult to trace across domains, and having high storage costs.
[0009] To solve the above technical problems, the present invention is realized through the following technical solutions: The present invention is a communication security monitoring method based on blockchain technology, including the following steps: Step S1, system initialization: create node identity registration and dynamic sharding, and generate the main chain genesis block; Step S2, communication data collection: deploy an adaptive probe, perform sharding encryption processing on the communication data, and generate a timestamp proof; Step S3, blockchain storage: construct a three-dimensional storage structure to achieve hybrid consensus; Step S4, data security monitoring: analyze the dual-stream features, calculate the anomaly index and give real-time alarms; Step S5, dynamic policy update: execute a smart contract to update the reputation of each node; Step S6, cross-chain traceability: generate a tracking path and generate an evidence chain for packaging; Step S7, maintenance stage: automatically reorganize the shards and perform key rotation.
[0010] As a preferred technical solution, in the step S1, the specific process of node identity registration is as follows: Step S11: Collect device inherent features and dynamic environment parameters to generate a composite fingerprint; the device inherent features include hardware immutable parameters such as CPU microcode serial number, MAC address, and TPM module fingerprint; the dynamic environment parameters obtain instantaneous features such as the current clock deviation and power noise fingerprint through the executable environment; the specific formula of the composite fingerprint is as follows: ; In the formula, represents the final composite fingerprint, represents a cryptographic hash function, represents a string concatenation operator, represents a unique hardware identifier, represents the access control address of the device, represents the deviation between the device clock and the global clock, represents a bitwise or bytewise concatenation symbol, Denote the modulo operation on the hash result; the generated composite fingerprint can also be processed for anti-interference, that is, the measurement error is eliminated by the fuzzy extractor; Step S12: Select the NTRU-509 parameter set and construct the private key polynomial and the public key polynomial; in the NTRU algorithm, the polynomial of the private key is , and the public key polynomial is ; where is the modulus parameter, is a randomly selected sparse polynomial, denotes the polynomial modulo inverse element, identifies modulo multiplicative inverse element, denotes the private key polynomial; Step S13: Construct a signature certificate and generate a short signature; the short signature is generated by the EdDSA algorithm, and the signature private key is protected by the TEE; Step S14: Write the certificate into the smart contract to complete the registration of the blockchain, which requires the Byzantine consensus of at least three verification nodes; Step S15: Use the Shamir threshold scheme to split the private key into shards and store the shards in the blockchain nodes, and the recovery requires shards.
[0011] As a preferred technical solution, in the step S1, the dynamic sharding calculates the sharding coefficient according to the real-time network state, and the specific calculation formula is as follows: ; where is the sharding coefficient, denotes the reputation value of node i, denotes the current network traffic peak, denotes the current network average traffic, denotes the network delay parameter.
[0012] As a preferred technical solution, in the step S2, the specific formula for sharding and encrypting the communication data is as follows: ; where denotes the ciphertext, a tuple composed of two parts: the vector and the scalar ; denotes the random vector, an n-dimensional vector uniformly randomly sampled from the integer ring modulo , unique for each encryption; denotes the key, a binary secret vector used to produce the encryption structure; denotes the error term, which is small noise sampled from a discrete Gaussian distribution; denotes the plaintext message, a single-bit data, taking 0 or 1, and is extended to an integer through encoding; denotes the modulus, and all operations are carried out in the integer ring modulo , usually taking a large prime number; When generating the ciphertext, according to the input single-bit plaintext, formulate an encoding rule; the encoding rule is as follows: If , then it is encoded as 0; If , then it is encoded as ; Randomly sample an n-dimensional vector from the integer ring modulo , , calculate the key and the dot product of the vector . The calculation formula of the dot product is as follows: ; then add the error term to complete the calculation of the ciphertext . Therefore, the scalar value of the ciphertext is: ; So the final output format of the ciphertext obtained is: .
[0013] As a preferred technical solution, in the step S3, the structure of the three-dimensional storage includes: horizontal sharding, vertical layering, and time slicing; the horizontal sharding adopts a horizontal sharding strategy, divides data blocks according to the protocol types of HTTP / MQTT / CoAP, and independently deploys an encryption engine for each shard; cross-protocol collaborative optimization can also be performed, and the shard distribution is automatically optimized using the protocol feature vector matrix; the vertical layering is performed according to the sensitivity of the information, and at the same time, 3D XPoint is used to achieve accelerated layered storage; the time slicing performs incremental snapshots through a sliding event window and constructs a spatio-temporal index tree to trace the information. This three-dimensional storage structure realizes parallel processing through protocol sharding, ensures data security through sensitivity layering, and supports spatio-temporal traceability through time slicing, forming a three-dimensional storage system with self-optimization capabilities.
[0014] As a preferred technical solution, in step S4, the analysis of the dual-stream features adopts a dual-channel LSTM structure, which processes the traffic features and blockchain features separately, and performs feature fusion and classification; the traffic feature stream (8 dimensions: delay Δt, packet rate pps, entropy value, etc.) and the blockchain feature stream (6 dimensions: transaction rate, Gas consumption, confirmation time, etc.) are respectively input into independent LSTM branches; each of the LSTM branches adopts a 128-unit hidden layer, models the temporal dependence through a gating mechanism (input gate, forget gate, output gate), the activation functions are Sigmoid and tanh, the 128-dimensional hidden states output by the dual-stream LSTM are concatenated into a 256-dimensional vector, and after dimensionality reduction through a fully connected layer (ReLU activation), a joint feature representation is generated, and it is mapped to 5 types of states (normal / 4 types of anomalies) through a Softmax output layer. The loss function adopts cross-entropy + L2 regularization, uses an Adam optimizer (initial lr = 0.001) in cooperation with a cosine annealing strategy, and introduces Dropout (rate = 0.2) to prevent overfitting. The input data is preprocessed by a sliding window (T = 10, stride = 2) and normalization; The formula for the anomaly index is as follows: ; In the formula, represents the anomaly index at time t, ranging from (0, 1), and the larger the value, the higher the anomaly probability; represents the Sigmoid function, which maps the linear combination to a probability value. 0.8 is the weight of the real-time traffic feature indicating its immediate contribution to the anomaly, and 0.6 is the weight of the integral term of the blockchain historical feature, indicating the persistent impact of historical data; represents the real-time traffic feature vector, represents the time-weighted integral of the blockchain feature, t - 5 represents the past 5 seconds, represents time and
[0015] As a preferred technical solution, in step S5, the formula for calculating the reputation influence factor of a node is as follows: ; The formula for calculating the reputation score based on the reputation influence factor is: ; In the formula, is the influence factor, is the proportion coefficient, is the reward coefficient, is the penalty coefficient, is the node parameter, is the number of normal messages, is the number of abnormal messages It is an abnormal consensus. If there is an abnormality, it is 1; otherwise, it is 0. It is the credit score.
[0016] As a preferred technical solution, in step S6, the target key value is hashed by Keccak256 to generate a 64-bit hexadecimal code, and the path is compressed in segments of 4 characters according to the quadtree structure; recursively traverse the branch / extension / leaf nodes from the root node, dynamically match the path segments and push the hashes of the passed nodes onto the stack; adopt the 16-fork jump of the branch node and the shared prefix of the extension node for optimization to generate a path proof containing the node hash chain, and finally confirm the path integrity through the chained hash verification equation; The specific implementation process is as follows: Step 1. Perform key value preprocessing: The input key k is first hashed by the Keccak256 hash algorithm to generate a 64-bit hexadecimal string (such as 8f3a1b5d...), and the hexadecimal prefix encoding (HP encoding) is used to distinguish the path types: add the 0x20 prefix to the path with an even length, and add the 0x3n prefix (n is the number of half bytes) to the path with an odd length, so as to be compatible with the path identifiers of the extension nodes and the leaf nodes.
[0017] Step 2. Quadtree structured traversal: Starting from the root node, decompose the key value path layer by layer according to the 4-nibble segments (such as splitting 8f3a1b5d into 8f3a→1b5d), and match the nodes through the recursive algorithm. Among them, Branch node: Jump to the corresponding child node according to the first character (0-f) of the current path segment (for example, the first character 8 of the path segment 8f3a points to the 8th child node); Extension node: Match the shared prefix (such as 8f3a). If it is completely matched, jump to the child node to continue querying the remaining path; Leaf node: After verifying the complete path match, return the stored value, and record the hashes of all nodes on the path at the same time.
[0018] Step 3. Dynamic path compression: Use the sliding window LZ77 algorithm to detect repeated path patterns: Find the longest repeated substring (maximum 4 characters) within a 16-character window, and replace the repeated segment with a (offset, length) tuple. For example, the path 8f3a8f3a is compressed to 8f3a+(0,4), and the storage space is reduced by 50%; Step 4. Generate a hash chain: Build a verification chain from bottom to top; among them: Hash of leaf node: H_leaf = Keccak256(HP(path) || value); Extended node hash: H_extension = Keccak256(HP(prefix) || child_hash); Branch node hash: H_branch = Keccak256(child_0 ||... || child_f || value); Finally, the generated path proof is π(k) = [H_leaf, H_extension, H_branch,..., H_root], forming a strict hash dependency chain.
[0019] As a preferred technical solution, in step S7, the condition for key rotation is triggered by any one of the following: node offline rate > 15%, latency increase And regular maintenance every 24 hours; Generate dynamic key components through polynomial secret sharding, combine zero-knowledge verification to achieve shard validity proof, use Lagrange coefficient to aggregate public keys and introduce a weight dynamic adjustment algorithm, complete key update without reconstructing the main private key, and at the same time, through forward security algorithm and quantum-resistant hash binding technology, achieve verifiable rotation of key shards and secure erasure of historical keys, effectively solving the contradiction between security and real-time of key update in distributed systems.
[0020] The present invention is a communication security monitoring system based on blockchain technology, including an infrastructure layer, a data layer, a service layer, an application layer, an evaluation layer, and a smart contract layer; The infrastructure layer is physical hardware infrastructure, specifically including: computers, servers, network devices, security monitoring devices, probes, access control, and memories; The data layer includes a data collection module, a data preprocessing module, a data analysis module, and a data storage module; The service layer includes a security management module, an abnormal data analysis module, and an alarm module; The application layer includes an identity authentication module, a user management module, and an access control module; The evaluation layer includes a security log module and a usage evaluation feedback module; The security log is used to record log information of protection, monitoring, auditing, and scanning; The usage evaluation feedback module is used to store feedback information after user usage; The smart contract layer is used to execute preset rules and operations.
[0021] The present invention has the following beneficial effects: (1) The present invention creates node identity registration and dynamic sharding, generates the genesis block of the main chain, analyzes dual-stream features, calculates anomaly indices and issues real-time alerts, generates a tracking path, and generates an evidence chain for packaging, thereby improving the security level of the system and the efficiency of evidence chain generation, and reducing storage space and costs.
[0022] (2) When registering node identities, the present invention uses the NTRU algorithm to generate an identity key pair bound to the hardware fingerprint, combines blockchain security technology to achieve trusted identity authentication, and through the deep coupling of the hardware fingerprint and the NTRU algorithm, while achieving quantum security, ensures the uniqueness and non-forgeability of node identities, and improves the security level of the system.
[0023] (3) The present invention fuses three heterogeneous dimensions of node reputation, traffic characteristics, and network latency through a non-linear formula to make sharding more reasonable, and realizes the non-linear response of latency impact through the Sigmoid function. When N>15ms, the penalty coefficient rises sharply, effectively avoiding the overall performance being dragged down by high-latency shards, and ensuring high throughput during traffic bursts.
[0024] (4) The three-dimensional storage structure of the present invention realizes parallel processing through protocol sharding, safeguards data security through sensitivity layering, and supports spatio-temporal traceability through time slicing, forming a three-dimensional storage system with self-optimization capabilities, improving query efficiency, and reducing storage space.
[0025] (5) When performing cross-chain traceability, the present invention changes the traditional binary path to a quaternary system, performs a structured traversal of the quadtree, starts from the root node, decomposes the key-value path layer by layer according to four-character segments, uses the sliding window LZ77 algorithm to detect repeated path patterns, generates a tracking path, and packages the evidence chain, reducing the evidence chain generation time, consumption, and path storage space.
[0026] (6) The present invention generates dynamic key components through polynomial secret sharding, combines zero-knowledge verification to prove the validity of sharding, aggregates public keys using Lagrange coefficients and introduces a weight dynamic adjustment algorithm to complete key updates without reconstructing the main private key. At the same time, through the forward security algorithm and anti-quantum hash binding technology, it realizes the verifiable rotation of key shards and the secure erasure of historical keys, effectively solving the contradiction between the security and real-time nature of key updates in distributed systems.
[0027] Of course, any product implementing the present invention does not necessarily need to achieve all the above-mentioned advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0029] Figure 1 Flowchart of a communication security monitoring method based on blockchain technology of the present invention; Figure 2 Schematic structural diagram of a communication security monitoring system based on blockchain technology of the present invention. Specific embodiments
[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0031] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0032] To make the purpose, technical solutions and advantages of the present application clearer, the following will be combined with the attached Figure 1-2 A further detailed description will be made of the embodiments of the present application.
[0033] Before introducing the embodiments of the present application, relevant explanations will be made first on the application analysis of blockchain in communication security monitoring.
[0034] I. Decentralized identity authentication and access control The blockchain technology constructs a decentralized identity management system through the distributed ledger feature, encrypts and stores the digital identity information of both communication parties on the chain, and ensures the uniqueness and authenticity of the identity. The smart contract automatically verifies the access permission, effectively preventing the access of forged identities or unauthorized devices to the communication network, and reducing the risk of illegal intrusion from the source. For example, in the communication scenario of Internet of Things devices, the blockchain can dynamically verify the device identity to avoid malicious nodes disguising as legitimate devices to initiate attacks.
[0035] II. Protection of communication data integrity The chain structure of the blockchain ensures the immutability of data through the hash value association mechanism. Data such as logs and transmission content generated during communication monitoring are encrypted and distributedly stored on multiple nodes after encryption. Any tampering behavior will be recognized by other nodes and rejected for synchronization. This feature is particularly applicable to high-security scenarios such as 5G communication and satellite communication, ensuring the traceability of the entire data life cycle. For example, once the communication data collected by mobile monitoring devices is uploaded to the blockchain, the original state can be verified through timestamps.
[0036] III. Threat Intelligence Sharing and Collaborative Defense The threat intelligence platform based on the blockchain can realize the distributed storage and sharing of communication network attack characteristics and vulnerability information. The transparency and immutability of the data on the chain enable efficient cooperation among different institutions, real-time update of attack defense strategies, and improvement of the response speed to new attack methods (such as DDoS and man-in-the-middle attacks). For example, the risk warning mechanism can be automatically triggered through smart contracts to dynamically adjust the communication network firewall rules.
[0037] IV. Encrypted Communication and Privacy Protection The blockchain combined with asymmetric encryption technology can provide end-to-end protection for communication data. The sender encrypts the data using the recipient's public key, and only the authorized party holding the private key can decrypt it, effectively preventing the communication content from being stolen or eavesdropped. In remote monitoring scenarios, sensitive information such as medical health data and industrial control instructions is transmitted through the blockchain, which not only ensures privacy but also meets regulatory compliance requirements.
[0038] V. Audit Traceability and Liability Identification All operations during the communication monitoring process are recorded on the blockchain, forming a complete audit chain containing information such as timestamps and operation subjects. When a security incident occurs, the attack path can be quickly located and the liable party can be traced through the data on the chain. For example, abnormal data in the logistics communication network can be accurately analyzed for the tampering loop in combination with the blockchain record.
[0039] In order to make the purpose, technical solutions, and advantages of the present application clearer and more understandable, the following further details the present application in conjunction with the Figure 1-2 accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0040] Embodiment 1 Please refer to Figure 1 As shown in the figure, the present invention is a communication security monitoring method based on blockchain technology, including the following steps: Step S1, system initialization: Create node identity registration and dynamic sharding and generate the main chain genesis block; Step S2, communication data collection: Deploy adaptive probes, perform sharding encryption processing on communication data, and generate timestamp proofs; Step S3, Blockchain Storage: Construct a three-dimensional storage structure to achieve hybrid consensus; Step S4, Data Security Monitoring: Analyze the dual-stream features, calculate the anomaly index, and issue real-time alerts; Step S5, Dynamic Policy Update: Execute the smart contract to update the reputation of each node; Step S6, Cross-chain Traceability: Generate a tracking path and generate an evidence chain for packaging; Step S7, Maintenance Phase: Automatically perform shard recombination and key rotation.
[0041] In step S1, the specific process of node identity registration is as follows: Step S11: Collect the device's inherent features and dynamic environment parameters to generate a composite fingerprint; the device's inherent features include hardware immutable parameters such as CPU microcode serial number, MAC address, and TPM module fingerprint; the dynamic environment parameters obtain instantaneous features such as the current clock deviation and power noise fingerprint through the executable environment; the specific formula for the composite fingerprint is as follows: ; In the formula, represents the final composite fingerprint, represents the cryptographic hash function, represents the string concatenation operator, represents the unique hardware identifier, represents the access control address of the device, represents the deviation between the device clock and the global clock, represents the bitwise or byte concatenation symbol, represents the modulo operation on the hash result; the generated composite fingerprint can also be subjected to anti-interference processing, that is, the measurement error is eliminated through a fuzzy extractor; Step S12: Select the NTRU-509 parameter set and construct the private key polynomial and the public key polynomial; in the NTRU algorithm, the private key polynomial is , and the public key polynomial is ; In the formula, is the modulus parameter, is a randomly selected sparse polynomial, represents the polynomial modulo inverse element, identifies modulo multiplicative inverse element, represents the private key polynomial; Step S13: Construct a signature certificate and generate a short signature; the short signature is generated by the EdDSA algorithm, and the signature private key is protected by the TEE; Step S14: Write the certificate into the smart contract to complete the registration of the blockchain, which requires Byzantine consensus through at least three verification nodes; Step S15: Use the Shamir threshold scheme to split the private key into shards and store the shards in the blockchain nodes, and recovery requires
[0042] In Step S1, the dynamic sharding calculates the sharding coefficient according to the real-time network status, and the specific calculation formula is as follows: ; Specifically, is the reputation benchmark item, is the traffic fluctuation item, is the delay penalty item; In the formula, is the sharding coefficient, represents the reputation value of node i, represents the current network traffic peak value, represents the current network average traffic, represents the network delay parameter; Shard according to the value of the sharding coefficient S, and the specific sharding situation is as follows: For the first time, the three heterogeneous dimensions of node reputation, traffic characteristics, and network delay are fused through a non-linear formula. Compared with the traditional single-index sharding method, the sharding rationality is improved by 63%. The non-linear response of the delay impact is realized through the Sigmoid function. When N>15ms, the penalty coefficient rises sharply, effectively avoiding the overall performance being dragged down by high-delay shards, and ensuring high throughput during traffic bursts.
[0043] In Step S2, the specific formula for sharding and encrypting communication data is as follows: ; In the formula, represents the ciphertext, a tuple consisting of two parts: the vector and the scalar ; represents the random vector, an n-dimensional vector uniformly randomly sampled from the integer ring of modulus , unique for each encryption; represents the key, a binary secret vector used to generate the encryption structure; represents the error term, a small noise sampled from the discrete Gaussian distribution; represents the plaintext message, a single-bit data, taking 0 or 1, and extended to an integer through encoding; represents the modulus, and all operations are performed in the integer ring of modulus , usually taking a large prime number; When generating ciphertext, encoding rules are formulated according to the input single-bit plaintext; the encoding rules are as follows: If , it is encoded as 0; If , it is encoded as ; Randomly sample an n-dimensional vector from the integer ring modulo , , calculate the key and the point set of the vector . The calculation formula of the point set is as follows: ; Then add the error term to complete the calculation of the ciphertext . Therefore, the scalar value of the ciphertext is: ; So the final output format of the ciphertext obtained is: .
[0044] In step S3, the structure of three-dimensional storage includes: horizontal sharding, vertical layering, and time slicing; horizontal sharding adopts the horizontal sharding strategy, divides data blocks according to protocol types such as HTTP / MQTT / CoAP, and independently deploys an encryption engine for each shard to achieve protocol-level security isolation; cross-protocol collaborative optimization can also be performed, and the shard distribution is automatically optimized using the protocol feature vector matrix; vertical layering is performed according to the sensitivity of information, and the sensitivity layering criteria are as follows in the table: At the same time, 3D XPoint is used to achieve layered storage acceleration; time slicing performs incremental snapshots through a sliding event window and constructs a spatio-temporal index tree to trace information. This three-dimensional storage structure realizes parallel processing through protocol sharding, ensures data security through sensitivity layering, and supports spatio-temporal traceability through time slicing, forming a three-dimensional storage system with self-optimization capabilities.
[0045] In step S4, a dual-channel LSTM structure is adopted for the analysis of the dual-stream features, which processes the traffic features and blockchain features separately, and performs feature fusion and classification. The traffic feature stream (8 dimensions: delay Δt, packet rate pps, entropy value, etc.) and the blockchain feature stream (6 dimensions: transaction rate, Gas consumption, confirmation time, etc.) are respectively input into independent LSTM branches. Each LSTM branch uses a hidden layer with 128 units to model the temporal dependence through a gating mechanism (input gate, forget gate, output gate), and the activation functions are Sigmoid and tanh. The 128-dimensional hidden states output by the dual-stream LSTM are concatenated into a 256-dimensional vector, and after dimensionality reduction through a fully connected layer (activated by ReLU), a joint feature representation is generated, and it is mapped to 5 types of states (normal / 4 types of anomalies) through a Softmax output layer. The loss function uses cross-entropy + L2 regularization, and the Adam optimizer (initial lr = 0.001) is used in conjunction with a cosine annealing strategy, and Dropout (rate = 0.2) is introduced to prevent overfitting. The input data is preprocessed by a sliding window (T = 10, stride = 2) and normalization; The abnormal index calculation formula is as follows: ; In the formula, represents the abnormal index at time t, with a range of (0, 1). The larger the value, the higher the probability of anomaly; represents the Sigmoid function, which maps the linear combination to a probability value. 0.8 is the weight of the real-time traffic feature indicating its immediate contribution to the anomaly, and 0.6 is the weight of the integral term of the blockchain historical feature, indicating the persistent influence of historical data; represents the real-time traffic feature vector, represents the time-weighted integral of the blockchain feature, t - 5 represents the past 5 seconds, represents time and
[0046] According to the calculation result of, the alarm classification strategy is as follows: The specific implementation process is as follows: Step S41, real-time traffic feature collection: Deploy lightweight probes on the SDN switch or edge node, and use DPDK or eBPF technology to capture traffic; The blockchain feature collection subscribes to blockchain events (such as transaction pool updates, block generation), and the feature update frequency is synchronized with the main chain block production (for example, updated every 3 seconds); Step S42, approximate calculation of the integral term: The sampling interval is usually consistent with the blockchain feature update frequency (such as = 3s), and the number of samples within the window ; Step S43, Feature Fusion and Normalization: Determine the optimal weight combination through grid search on the training set, set the weights to real-time feature weight 0.8 and historical blockchain feature weight 0.6, and perform normalization processing on each dimension of the real-time traffic features and blockchain features; Step S44, Sigmoid Function Calculation and Threshold Judgment: Conduct threshold comparison and set the conditions for triggering an alarm; Step S45, Real-time Optimization Strategy: Use FPGA or GPU to accelerate matrix operations and integral calculations, allocate the processing of traffic features and blockchain features to different threads for parallel computing; when an anomaly is detected, record the and snapshot for subsequent analysis.
[0047] In Step S5, the calculation formula for the reputation impact factor of a node is as follows: ; The formula for calculating the reputation score based on the reputation impact factor is: ; In the formula, is the impact factor, is the proportion coefficient, is the reward coefficient, is the penalty coefficient, is the node parameter, is the number of normal messages, is the number of abnormal messages, is the abnormal consensus, which is 1 if there is an anomaly and 0 otherwise, is the reputation score.
[0048] In Step S6, generate a 64-bit hexadecimal encoding for the target key-value through Keccak256 hashing, and compress the path in segments of 4 characters according to the quadtree structure; recursively traverse the branch / extension / leaf nodes from the root node, dynamically match the path segments and push the hashes of the passed nodes onto the stack; adopt 16-way jumps for branch nodes and shared prefixes for extension nodes for optimization, generate a path proof containing the node hash chain, and finally confirm the path integrity through the chained hash verification equation; The specific implementation process is as follows: Step 1, Perform key-value preprocessing: The input key k first generates a 64-bit hexadecimal string (such as 8f3a1b5d...) through the Keccak256 hashing algorithm, and uses hexadecimal prefix encoding (HP encoding) to distinguish path types: add a 0x20 prefix to paths of even length and a 0x3n prefix (n is the number of half-bytes) to paths of odd length, so as to be compatible with the path identifiers of extension nodes and leaf nodes.
[0049] Step 2, Quadtree Structured Traversal: Starting from the root node, decompose the key-value path layer by layer according to 4-nibble (e.g., split 8f3a1b5d into 8f3a→1b5d), and match nodes through a recursive algorithm. Among them, Branch Node: Jump to the corresponding child node according to the first character (0-f) of the current path segment (e.g., the first character 8 of the path segment 8f3a points to the 8th child node); Extension Node: Match the shared prefix (e.g., 8f3a). If it is completely matched, jump to the child node to continue querying the remaining path; Leaf Node: After verifying the complete path match, return the stored value, and record the hashes of all nodes on the path.
[0050] Step 3, Dynamic Path Compression: Use the sliding window LZ77 algorithm to detect repeated path patterns: Find the longest repeated substring (maximum 4 characters) within a 16-character window, and replace the repeated segment with a (offset, length) tuple. For example, the path 8f3a8f3a is compressed to 8f3a+(0,4), reducing the storage space by 50%; Step 4, Generate Hash Chain: Build a verification chain from bottom to top; among them: Hash of Leaf Node: H_leaf = Keccak256(HP(path) || value); Hash of Extension Node: H_extension = Keccak256(HP(prefix) || child_hash); Hash of Branch Node: H_branch = Keccak256(child_0 ||... || child_f ||value); Finally, generate the path proof as π(k) = [H_leaf, H_extension, H_branch,..., H_root], forming a strict hash dependency chain.
[0051] In step S7, the condition for key rotation is triggered by any one of the following: node offline rate > 15%, increase in latency and regular maintenance every 24 hours; generate dynamic key components through polynomial secret sharing, combine zero-knowledge verification to achieve proof of shard validity, aggregate public keys using Lagrange coefficients and introduce a weight dynamic adjustment algorithm, complete key update without reconstructing the main private key, and at the same time, through forward security algorithms and quantum-resistant hash binding technologies, achieve verifiable rotation of key shards and secure erasure of historical keys, effectively solving the contradiction between security and real-time of key update in distributed systems.
[0052] Embodiment 2 Referring to Figure 2 As shown, the present invention is a communication security monitoring system based on blockchain technology, which can be used to execute the method content of Embodiment 1 of the present invention, including: an infrastructure layer, a data layer, a service layer, an application layer, an evaluation layer, and a smart contract layer; the infrastructure layer is a physical hardware infrastructure, specifically including: computers, servers, network devices, security monitoring devices, probes, access control devices, and memories; the data layer includes a data acquisition module, a data preprocessing module, a data analysis module, and a data storage module; the service layer includes a security management module, an abnormal data analysis module, and an alarm module; the application layer includes an identity authentication module, a user management module, and an access control module; the evaluation layer includes a security log module and a usage evaluation feedback module; the security log is used to record log information of protection, monitoring, auditing, and scanning; the usage evaluation feedback module is used to store feedback information after users use; the smart contract layer is used to execute preset rules and operations.
[0053] It should be noted that in the above system embodiments, the various units included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.
[0054] In addition, those of ordinary skill in the art can understand that all or part of the steps in implementing the methods of the above embodiments can be completed by instructing relevant hardware through a program, and the corresponding program can be stored in a computer-readable storage medium.
[0055] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A communication security monitoring method based on blockchain technology, characterized in that: The steps include: Step S1, system initialization: create node identity registration and dynamic sharding and generate the main chain genesis block; Step S2, communication data collection: deploy adaptive probes, perform fragmented encryption on the communication data, and generate a timestamp certificate; Step S3, blockchain storage: construct a three-dimensional storage structure and reach a hybrid consensus; Step S4, data security monitoring: analyzing the dual-stream features, calculating the abnormality index and issuing real-time alarms; Step S5, dynamic strategy update: execute the smart contract and update the reputation of each node; Step S6, cross-chain tracing: Generate a tracing path and generate an evidence chain for packaging; Step S7, maintenance phase: automatic shard reorganization and key rotation.
2. According to a communication security monitoring method based on blockchain technology according to claim 1, it is characterized in that: In step S1, the specific process of node identity registration is as follows: Step S11: Collecting device inherent characteristics and dynamic environment parameters to generate a composite fingerprint; the specific formula of the composite fingerprint is as follows: ; In the formula, represents the final composite fingerprint, represents a cryptographic hash function, Represents the string concatenation operator, Indicates a unique hardware identifier. Indicates the access control address of the device. Indicates the deviation between the device clock and the global clock. Indicates bitwise or bytewise concatenation symbols. Indicates the modulus operation on the hash result; Step S12: Select the NTRU-509 parameter set and construct the private key polynomial and the public key polynomial; Step S13: construct a signature certificate and generate a short signature; Step S14: Write the certificate into the smart contract to complete the registration of the blockchain; Step S15: Use Shamir's threshold scheme to split the private key into shards, and store the shards in the blockchain node.
3. According to a communication security monitoring method based on blockchain technology according to claim 1, it is characterized in that: In step S1, dynamic sharding calculates the sharding coefficient according to the real-time network status. The specific calculation formula is as follows: ; In the formula, is the fragmentation coefficient, represents the reputation value of node i, Indicates the current network traffic peak value. Indicates the current average network traffic. Indicates the network delay parameter.
4. According to a method for monitoring communication security based on blockchain technology according to claim 1, it is characterized in that: In step S2, the specific formula for performing fragment encryption processing on the communication data is as follows: ; In the formula, Represents the ciphertext, a tuple consisting of two parts: vector and scalar ; represents a random vector, represents the key, represents the error term, Represents a plaintext message, Represents the modulus; When generating the ciphertext, an encoding rule is formulated according to the input single-bit plaintext; Randomly sample n-dimensional vectors from the integer ring and calculate the key With vector point set, and then add the error term , complete the ciphertext Calculation.
5. According to a method for monitoring communication security based on blockchain technology as claimed in claim 1, it is characterized in that: In step S3, the structure of the three-dimensional storage includes: horizontal slicing, vertical layering and time slicing; the horizontal slicing adopts a horizontal slicing strategy, divides the data blocks according to the HTTP / MQTT / CoAP protocol type, and independently deploys an encryption engine for each slicing; the vertical layering is layered according to the sensitivity of the information, and 3D XPoint is used to achieve layered storage acceleration; the time slicing takes incremental snapshots through a sliding event window, and constructs a spatiotemporal index tree to trace the information.
6. According to a communication security monitoring method based on blockchain technology according to claim 1, it is characterized in that: In step S4, a dual-channel LSTM structure is used to analyze the dual-stream features, and the traffic features and blockchain features are processed separately to perform feature fusion and classification; the traffic feature stream and the blockchain feature stream are input into independent LSTM branches respectively; Each LSTM branch uses a 128-unit hidden layer, and models temporal dependency through a gating mechanism. The activation functions are Sigmoid and tanh. The 128-dimensional hidden state output by the dual-stream LSTM is spliced into a 256-dimensional vector, and a joint feature representation is generated after dimensionality reduction by a fully connected layer. It is mapped to 5 categories of states through a Softmax output layer. The loss function uses cross entropy + L2 regularization, uses an Adam optimizer with a cosine annealing strategy, introduces Dropout to prevent overfitting, and the input data is preprocessed by sliding windows and normalization. The calculation formula of the abnormal index is as follows: ; In the formula, represents the anomaly index at time t, represents the Sigmoid function, represents the real-time traffic feature vector, A time-weighted integral representing the characteristics of a blockchain, Indicates time The blockchain feature vector of .
7. According to a method for monitoring communication security based on blockchain technology as claimed in claim 1, it is characterized in that: In step S5, the calculation formula of the node's reputation impact factor is as follows: ; The formula for calculating the reputation score according to the reputation impact factor is: ; In the formula, is the impact factor, is the specific gravity coefficient, is the reward coefficient, is the penalty coefficient, is the node parameter, is the normal amount of information, is the number of abnormal information, For abnormal consensus, For the credit score.
8. According to a method for monitoring communication security based on blockchain technology as claimed in claim 1, it is characterized in that: In step S6, the target key value is hashed by Keccak256 to generate a 64-bit hexadecimal code, and the path is compressed by 4-character segments through a quadtree structure; the branch / extension / leaf nodes are recursively traversed from the root node, the path segments are dynamically matched, and the hashes of the passed nodes are pushed into the stack; The branch node 16-fork jump and extended node shared prefix optimization are adopted to generate a path proof containing a node hash chain, and finally the path integrity is confirmed by the chain hash verification equation.
9. According to a method for monitoring communication security based on blockchain technology as claimed in claim 1, it is characterized in that: In step S7, the key rotation is triggered by any of the following conditions: node offline rate>15%, delay increase And regular maintenance every 24 hours.
10. A communication security monitoring system based on blockchain technology, comprising an infrastructure layer, a data layer, a service layer, an application layer, an evaluation layer and a smart contract layer, characterized in that: The infrastructure layer is the physical hardware infrastructure, specifically including: computers, servers, network equipment, security monitoring equipment, probes, access control and storage; The data layer includes a data acquisition module, a data preprocessing module, a data analysis module and a data storage module; The service layer includes a security management module, an abnormal data analysis module and an alarm module; The application layer includes an identity authentication module, a user management module, and an access control module; The evaluation layer includes a security log module and a usage evaluation feedback module; the security log is used to record log information of protection, monitoring, auditing, and scanning; the usage evaluation feedback module is used to store feedback information after user use; The smart contract layer is used to execute preset rules and operations.
Citation Information
Patent Citations
Attack prediction method and device, medium and equipment
CN114301692A
Cited By
Whole-process information tracing method and system for Internet commodity supply chain
CN121052848A
AI-driven block chain hybrid consensus dynamic hierarchical optimization method and system
CN121441920A