Internet of Things data security collaborative defense system based on edge computing
Through the IoT data security collaborative defense system of edge computing, the contradiction between resource constraints, real-time response and cross-domain collaboration in IoT security protection is solved, lightweight encryption and dynamic trust assessment are realized, security collaborative defense capabilities in the IoT environment are improved, and real-time response at the edge and global security situation awareness are achieved.
Patent Information
- Application Number
- CN202510734579.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing IoT security protection has conflicts with the constraints of terminal device resources and the needs of complex encryption algorithms, the conflicts with the real-time response requirements on the edge side and the delay in cloud decision-making, cross-domain collaborative defense and privacy protection, lack of trusted authentication links from terminal-edge-cloud, the risk of identity counterfeiting attacks increases, and the static defense rule base is difficult to cope with dynamically changing attack patterns. The lack of consensus mechanisms for cross-layer security strategies leads to a high conflict rate of defense strategies.
The IoT data security collaborative defense system based on edge computing is adopted, including the terminal device layer, the edge computing layer, the fog computing layer and the cloud collaboration layer. Combined with lightweight cryptography, dynamic trust evaluation and cross-layer collaborative decision-making, it realizes encrypted transmission of terminal devices, real-time threat detection and collaborative response of edge layers, threat intelligence sharing of fog computing layer and global strategy generation in the cloud.
Real-time response at the edge and global security situation awareness are realized, lightweight cryptography and dynamic trust assessment are integrated, multi-level collaborative protection in the Internet of Things environment, reducing the risk of identity counterfeiting attacks, and improving the dynamic adaptability and synergy efficiency of defense strategies.
Smart Images

Figure CN120263548A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things data defense, and in particular to an Internet of Things data security collaborative defense system based on edge computing. Background Art
[0002] With the rapid development of Internet of Things technology, the ubiquitous access of a large number of heterogeneous terminal devices has posed a severe challenge to the traditional centralized cloud security architecture; there are three core contradictions in the current Internet of Things security protection: First, the contradiction between the resource limitation of terminal devices and the demand for complex encryption algorithms. Traditional asymmetric encryption schemes such as RSA are difficult to implement on low-power devices; Second, the contradiction between the real-time response requirement on the edge side and the delay of centralized decision-making in the cloud. Existing solutions have a decision-making delay of more than 200 ms on average when dealing with zero-day attacks; Third, the contradiction between cross-domain collaborative defense and privacy protection. The security mechanism based on the centralized trust model is prone to form a single point of failure; Although edge computing technology has alleviated the cloud load pressure through local data processing, the existing edge security solutions generally lack a trusted authentication link from the terminal to the edge to the cloud, increasing the risk of identity spoofing attacks; The static defense rule library is difficult to cope with the dynamically changing attack patterns; The cross-layer security policy lacks a consensus mechanism, resulting in a high conflict rate of defense policies; Therefore, there is an urgent need to develop an Internet of Things data security collaborative defense system that can integrate lightweight cryptography, dynamic trust assessment, and cross-layer collaborative decision-making to ensure edge real-time response and global security situation awareness. Summary of the Invention
[0003] In order to overcome the deficiencies that the existing edge security solutions generally lack a trusted authentication link from the terminal to the edge to the cloud, increasing the risk of identity spoofing attacks; the static defense rule library is difficult to cope with the dynamically changing attack patterns; the cross-layer security policy lacks a consensus mechanism, resulting in a high conflict rate of defense policies, the technical problem to be solved by the present invention is to provide an Internet of Things data security collaborative defense system that can integrate lightweight cryptography, dynamic trust assessment, and cross-layer collaborative decision-making to ensure edge real-time response and global security situation awareness.
[0004] The present invention is achieved by the following specific technical means: An Internet of Things data security collaborative defense system based on edge computing, including a terminal device layer, an edge computing layer, a fog computing layer, and a cloud collaboration layer that work together; Terminal device layer: Multiple Internet of Things devices, each device built-in with a lightweight security module. The security module includes: a Trusted Execution Environment (TEE) or a Hardware Security Module (HSM), which is used to store keys and perform identity authentication based on Elliptic Curve Cryptography (ECC) certificates; a dynamic token generation module, which generates a device fingerprint by extracting device hardware features and realizes continuous authentication in combination with the zero-trust architecture; a lightweight security proxy module, which contains a hardware acceleration unit and supports low-power AI inference, data preprocessing (homomorphic encryption or differential privacy desensitization), and lightweight encryption (SM4 or ChaCha20 algorithm); a dynamic encryption channel module, which is used to establish encrypted communication with the edge computing layer. Edge computing layer: Multiple edge nodes, deploying lightweight intrusion detection and defense units, edge AI models, and local streaming data analysis engines, which are used for local threat detection, abnormal data filtering, and autonomous decision-making in case of network disconnection. Fog computing layer: A regional security coordinator, which updates the detection model parameters, a distributed threat detection engine, and a cross-layer collaboration component through a federated learning framework. The cross-layer collaboration component uses the PBFT consensus algorithm to verify threat intelligence and realizes threat intelligence sharing and policy synchronization. Cloud collaboration layer: A global security center, including a threat intelligence platform, a federated learning model training module, a security policy manager, and an attack tracing module, which are used to generate global defense policies, dynamically issue defense policies, and trace attacks. System collaboration mechanism: A quantum security communication module, a dynamic certificate authentication unit, an elastic resource scheduling component, and a blockchain-based audit closed-loop module to ensure the security and scalability of the system.
[0005] Furthermore, the hardware acceleration unit of the lightweight security proxy module uses a low-power AI inference chip, which supports real-time threat detection and local encryption, and the power consumption is less than 1W.
[0006] Furthermore, the edge AI model is regularly updated in the fog computing layer through a federated learning framework and includes an incremental learning module to adapt to new attack patterns. The update frequency is dynamically adjusted according to network load, and the incremental learning module uses an online learning method to update model parameters.
[0007] Furthermore, the following operations are realized between the fog computing layer and the cloud collaboration layer through a two-way policy synchronization mechanism: The cloud sends a threat feature library and an incremental update of the AI model to the edge nodes. The edge nodes report security event metadata to the cloud for generating global defense policies. Among them, the synchronization process uses a verification mechanism based on digital signatures and hash chains.
[0008] Furthermore, the dynamic encryption channel module adopts the ChaCha20-Poly1305 algorithm and integrates the HORS signature authentication mechanism based on the hash chain to ensure the security and integrity of the communication between the terminal device and the edge node.
[0009] Furthermore, the attack traceability module uses a graph neural network to construct a cross-node attack path map and locates the attack source by combining the spatio-temporal features and geographical location data stored in the blockchain.
[0010] Furthermore, the quantum secure communication module includes: A post-quantum key exchange protocol based on the learning with errors (LWE) problem; A pre-generated quantum key pool for realizing delay-free key replacement during emergency communication switching.
[0011] Furthermore, the rule base of the lightweight intrusion detection and defense unit is updated in real time with threat intelligence sent from the cloud and supports collaborative execution of traffic cleaning with neighboring edge nodes.
[0012] Furthermore, the collaborative defense method of the system includes the following steps: Step 1: The terminal device layer generates a data hash value through the TEE, encrypts and transmits it to the edge node through the dynamic encryption channel, and performs dynamic identity authentication using the zero-trust architecture; Step 2: The edge computing layer performs local threat detection. If an anomaly is detected, it triggers collaborative verification with neighboring nodes and processes encrypted data in real time through the hardware acceleration unit; Step 3: The fog computing layer jointly analyzes the edge node data through the federated learning framework, verifies the threat intelligence using the PBFT consensus algorithm, and generates a cross-layer defense strategy; Step 4: The cloud collaborative layer integrates the global threat intelligence to generate an optimization strategy, sends it to the edge node through the smart contract, and completes the attack traceability and audit closed-loop based on the blockchain log; Step 5: When the communication is interrupted, the edge node makes an autonomous decision to disconnect from the network according to the preset strategy, and the cloud balances the encryption algorithm load through dynamic resource scheduling.
[0013] Compared with the prior art, the present invention has the following beneficial effects: The present invention achieves the effects of integrating lightweight cryptography, dynamic trust assessment, and cross-layer collaborative decision-making to ensure edge real-time response and global security situation awareness. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 It is a schematic diagram of the system architecture of the present invention.
[0015] Figure 2 It is a schematic diagram of the decomposition of the system architecture of the present invention.
[0016] Figure 3 This is the flow chart of the collaborative defense method of the present invention. Specific embodiments
[0017] The present invention will be further described below with reference to the accompanying drawings: Embodiment
[0018] The Internet of Things data security collaborative defense system based on edge computing, as Figures 1 - 3 shown, includes a terminal device layer, an edge computing layer, a fog computing layer, and a cloud collaborative layer that work together; Terminal device layer: Multiple Internet of Things devices, each device is built-in with a lightweight security module, and the security module includes: a trusted execution environment (TEE) or a hardware security module (HSM), which is used to store keys and perform identity authentication based on elliptic curve cryptography (ECC) certificates; a dynamic token generation module, which generates a device fingerprint by extracting device hardware features and realizes continuous authentication in combination with the zero-trust architecture; a lightweight security proxy module, which contains a hardware acceleration unit and supports low-power AI inference, data preprocessing (homomorphic encryption or differential privacy desensitization), and lightweight encryption (SM4 or ChaCha20 algorithm); a dynamic encryption channel module, which is used to establish encrypted communication with the edge computing layer; Edge computing layer: Multiple edge nodes, which deploy lightweight intrusion detection and defense units, edge AI models, and local streaming data analysis engines, and are used for local threat detection, abnormal data filtering, and autonomous decision-making in case of network disconnection; Fog computing layer: A regional security coordinator, which updates the detection model parameters, a distributed threat detection engine, and a cross-layer collaboration component through a federated learning framework. The cross-layer collaboration component uses the PBFT consensus algorithm to verify threat intelligence and realizes threat intelligence sharing and policy synchronization; Cloud collaborative layer: A global security center, which includes a threat intelligence platform, a federated learning model training module, a security policy manager, and an attack traceability module, and is used for generating global defense policies, dynamically issuing defense policies, and attack traceability; System collaboration mechanism: A quantum security communication module, a dynamic certificate authentication unit, an elastic resource scheduling component, and an audit closed-loop module based on blockchain to ensure the security and scalability of the system.
[0019] Working principle: The Internet of Things data security collaborative defense system realizes dynamic security protection based on a four - level architecture of "terminal - edge - fog - cloud". The terminal device layer generates device fingerprints based on ECC certificates through the built - in Trusted Execution Environment (TEE) or Hardware Security Module (HSM). The hardware acceleration unit (power consumption <1W) of the lightweight security proxy module performs AI pre - processing and SM4 / ChaCha20 lightweight encryption on the collected data, and transmits it to the edge node through a ChaCha20 - Poly1305 dynamic encryption channel integrated with HORS signature. At the same time, an additional hardware feature hash chain is used to achieve zero - trust continuous authentication. The edge computing layer uses a local streaming engine and a real - time updated intrusion detection rule library for threat analysis, performs deep packet inspection through a low - power AI chip, triggers adjacent node collaborative verification to isolate abnormal traffic, and encrypts and uploads security event metadata to the fog computing layer. The fog layer aggregates data from multiple edge nodes through a federated learning framework, uses the PBFT consensus algorithm to verify the authenticity of threat intelligence, combines an incremental learning module to dynamically optimize the parameters of the detection model, and updates the defense strategy based on LWE post - quantum key synchronization. The cloud - based collaborative layer integrates global intelligence, constructs a cross - domain attack graph using graph neural networks, issues optimized strategies to edge nodes through smart contracts, and relies on the blockchain to record attack traceability data to achieve three - dimensional visualization positioning. When the network is interrupted, the edge node starts an autonomous decision - making mechanism to execute local fusing, and the cloud ensures emergency communication security through a quantum key pool and elastic resource scheduling. Finally, a "detection - defense - verification" cycle driven by a blockchain audit closed - loop is formed, achieving edge response at the 50ms level, PBFT consensus with 33% fault tolerance, and post - quantum encryption migration ability, and achieving multi - level collaborative protection in the Internet of Things environment.
[0020] Embodiment 1: Threat detection and defense mechanism based on hierarchical collaboration: Terminal security authentication and encrypted transmission: When the terminal device starts, it loads the pre - set ECC certificate through TEE / HSM to perform device identity authentication. The dynamic token generation module extracts hardware fingerprints (such as MAC address, chip ID hash value), generates a time - stamp - based dynamic token, and continuously verifies the trusted state of the device in combination with the zero - trust architecture. After data collection, the lightweight security proxy starts the hardware acceleration unit to perform differential privacy desensitization (such as adding Laplace noise) or SM4 homomorphic encryption on sensitive data, and establishes a dynamic encryption channel through the ChaCha20 - Poly1305 algorithm. At the same time, HORS signature (one - time signature based on hash chain) is used to ensure the integrity of data packets and prevent replay attacks; Edge - layer real - time threat detection and collaborative response: After receiving data, the edge node's hardware acceleration unit performs decryption and lightweight AI inference (such as 1D-CNN model) in parallel to detect data anomalies (such as traffic mutations, protocol violations). If a potential threat is detected, it immediately triggers the intrusion detection unit of adjacent edge nodes for cross-verification and filters false positives through a consensus mechanism; the local streaming analysis engine performs windowed statistics on the data (such as entropy value calculation within a sliding window), and combines with the threat feature library (such as CVE vulnerability signatures) issued by the cloud to identify known attack patterns. When a high-risk event is detected, the traffic cleaning module is activated to redirect abnormal traffic to the sandbox isolation area; Federated learning and threat intelligence sharing in the fog computing layer: The regional security coordinator aggregates the threat logs of multiple edge nodes and updates the edge AI model using a federated learning framework: each edge node uploads model gradients (such as stochastic gradient descent parameters), and the fog node aggregates the gradients through Paillier homomorphic encryption to generate a global incremental model. The update frequency is dynamically adjusted according to network load, with sparse updates (such as every 30 minutes) during peak periods and dense updates (every 5 minutes) during low load; the cross-layer collaboration component uses the PBFT consensus algorithm to verify the authenticity of threat intelligence: after the edge node submits threat evidence, at least 2 / 3 of the fog nodes verify the consistency of its digital signature and hash chain, and after passing, write this intelligence into the blockchain ledger to achieve cross-regional policy synchronization; Global policy generation and attack traceability in the cloud: The global security center integrates the metadata reported by multiple fog layers and constructs an attack path graph using a graph neural network (GNN): nodes represent devices / IP addresses, and the edge weights are determined by communication frequency and anomaly scores. The attack jump points are located through community discovery algorithms; the federated learning model training module uses transfer learning techniques to transfer historical attack patterns (such as DDoS behavior characteristics) to new threat detection, generates optimized AI model parameters, and distributes them to edge nodes through smart contracts. At the same time, the attack traceability module combines the spatio-temporal metadata (such as GPS coordinates, timestamp hash) stored in the blockchain to restore the attack chain timeline.
[0021] Example 2: Dynamic elastic defense and autonomous decision-making mechanism: Quantum secure communication and dynamic certificate switching: The quantum-secure communication module pre-generates an LWE post-quantum key pool (storing 1,000 key pairs). When it detects a man-in-the-middle attack on the traditional encryption channel, it immediately switches to the quantum key. The key switching process uses dual-path verification: the primary channel uses the new quantum key, and the backup channel retains the old key until the handshake confirmation is completed, ensuring zero-latency switching. The dynamic certificate authentication unit monitors the ECC certificate lifecycle. When the certificate is approaching expiration (e.g., the remaining validity period < 24 hours), it automatically applies to the cloud for an update. The update process uses blind signature technology. The terminal only provides the certificate hash value, and the cloud signs and returns it to avoid the risk of private key leakage. Edge layer offline autonomous decision-making and elastic load: When the edge node is disconnected from the cloud, it starts a preset emergency decision tree: First, it checks the timeliness of the local threat intelligence library. If it has expired for more than the threshold (e.g., 5 minutes), it enables a lightweight Bayesian inference model to autonomously determine the attack type based on the probability distribution of historical data (e.g., if the probability of detecting a SYN Flood attack exceeds 90%, it triggers a block). The elastic resource scheduling component dynamically allocates the computing power of the hardware acceleration unit: In the normal state, 70% of the computing power is used for AI inference, and 30% is used for encryption. When a high-load attack is detected, the encryption task is migrated to the fog layer, and the edge layer's computing power is fully used for real-time detection, and redundant calculations through neighboring nodes ensure processing continuity. Incremental learning and adaptation to new attacks: The incremental learning module of the edge AI model adopts an online active learning strategy: For abnormal samples with a confidence level lower than the threshold (e.g., < 85%), it triggers an artificial review interface. After review and confirmation, it generates labeled data to fine-tune the model. At the same time, the model embeds an attention mechanism to automatically increase the weight for new attack features (such as zero-day vulnerability exploitation traffic), ensuring that the detection model converges within 24 hours. The distributed threat detection engine in the fog computing layer uses heterogeneous model fusion technology: Different edge nodes deploy different detection models (such as LSTM, random forest). The fog layer comprehensively determines the global threat level through a weighted voting mechanism (using the historical accuracy of the model as the weight) to avoid the blind spot of a single model. Blockchain auditing and policy closed-loop control: All security event and policy change records are written into a permissioned blockchain (Hyperledger Fabric). The audit closed-loop module realizes policy rollback through smart contracts: If the newly issued defense policy causes the false positive rate to rise (e.g., exceeds 5%), it automatically triggers a rollback to the previous stable version and freezes the write permission of the problem policy submitter. The resource scheduling logs and attack path graphs are stored in IPFS, and the blockchain only stores the content hash. During auditing, by comparing the consistency of the hash on the chain with the IPFS data, efficient evidence collection is achieved and chain storage expansion is avoided.
[0022] Although the present disclosure has been described in detail with reference to exemplary embodiments, the present disclosure is not limited thereto, and it will be apparent to those skilled in the art that various modifications and changes can be made thereto without departing from the scope of the present disclosure.
Claims
1. An Internet of Things data security collaborative defense system based on edge computing, characterized in that It includes a collaborative terminal device layer, an edge computing layer, a fog computing layer, and a cloud collaborative layer; Terminal device layer: Multiple Internet of Things devices, each device is built-in with a lightweight security module. The security module includes: a trusted execution environment or a hardware security module for storing keys and performing identity authentication based on elliptic curve cryptography certificates; a dynamic token generation module that generates a device fingerprint by extracting device hardware features and realizes continuous authentication in combination with the zero-trust architecture; a lightweight security proxy module that includes a hardware acceleration unit and supports low-power AI inference, data preprocessing, and lightweight encryption; a dynamic encryption channel module for establishing encrypted communication with the edge computing layer; Edge computing layer: Multiple edge nodes, deploying lightweight intrusion detection and defense units, edge AI models, and local streaming data analysis engines for local threat detection, abnormal data filtering, and autonomous decision-making in case of network disconnection; Fog computing layer: A regional security coordinator that updates the detection model parameters, a distributed threat detection engine, and a cross-layer collaboration component through a federated learning framework. The cross-layer collaboration component uses the PBFT consensus algorithm to verify threat intelligence and realizes threat intelligence sharing and policy synchronization; Cloud collaborative layer: A global security center, including a threat intelligence platform, a federated learning model training module, a security policy manager, and an attack traceability module for generating global defense policies, dynamically issuing defense policies, and attack traceability; System collaboration mechanism: A quantum security communication module, a dynamic certificate authentication unit, an elastic resource scheduling component, and a blockchain-based audit closed-loop module to ensure the security and scalability of the system.
2. The Internet of Things data security collaborative defense system based on edge computing according to claim 1, wherein The hardware acceleration unit of the lightweight security proxy module uses a low-power AI inference chip, supports real-time threat detection and local encryption, and has a power consumption of less than 1W.
3. The Internet of Things data security collaborative defense system based on edge computing according to claim 1, characterized in that, The edge AI model is regularly updated in the fog computing layer through a federated learning framework and includes an incremental learning module to adapt to attack patterns. The update frequency is dynamically adjusted according to network load, and the incremental learning module uses an online learning method to update model parameters.
4. The Internet of Things data security collaborative defense system based on edge computing according to claim 1, characterized in that The following operations are realized between the fog computing layer and the cloud collaborative layer through a two-way policy synchronization mechanism: The cloud sends the threat feature library and the incremental update of the AI model to the edge node; The edge node reports the security event metadata to the cloud for generating global defense policies: Among them, the synchronization mechanism uses a verification mechanism based on digital signatures and hash chains.
5. The Internet of Things data security collaborative defense system based on edge computing according to claim 1, characterized in that, The dynamic encryption channel module uses the ChaCha20-Poly1305 algorithm and integrates the HORS signature authentication mechanism based on the hash chain.
6. The edge-computing-based IoT data security collaborative defense system according to claim 1, characterized in that, The attack traceability module uses a graph neural network to construct a cross-node attack path map and locates the attack source in combination with the spatio-temporal features and geographical location data stored in the blockchain.
7. The edge computing-based IoT data security collaborative defense system according to claim 1, wherein, The quantum security communication module includes: A post-quantum key exchange protocol based on learning-based encryption problems; A pre-generated quantum key pool for realizing delay-free key replacement during emergency communication switching.
8. The Internet of Things data security collaborative defense system based on edge computing according to claim 1, wherein, The rule library of the lightweight intrusion detection and defense unit is updated in real time with the threat intelligence sent by the cloud and supports collaborating with neighboring edge nodes to perform traffic cleaning.
9. An Internet of Things data security collaborative defense system based on edge computing, characterized in that, It includes the following steps: Step 1: The terminal device layer generates a data hash value through the TEE, encrypts and transmits it to the edge node using a dynamic encryption channel, and performs dynamic authentication using a zero-trust architecture; Step 2: The edge computing layer performs local threat detection. If an anomaly is detected, it triggers collaborative verification with neighboring nodes and processes encrypted data in real time through a hardware acceleration unit; Step 3: The fog computing layer jointly analyzes edge node data through a federated learning framework, verifies threat intelligence using the PBFT consensus algorithm, and generates cross-layer defense strategies; Step 4: The cloud collaboration layer integrates global threat intelligence to generate optimization strategies, issues them to the edge nodes through smart contracts, and completes the attack traceability and audit loop based on blockchain logs; Step 5: In case of communication interruption, the edge node executes a network disconnection autonomous decision according to the preset strategy, and the cloud balances the encryption algorithm load through dynamic resource scheduling.
Citation Information
Patent Citations
Identity information authentication method, server, client and system
CN111212095A
Access control method and device based on zero-trust security and storage medium
CN114679293A
Network information security evaluation test system
CN117527348A
Internet of vehicles security authentication method based on cluster and multi-layer block chain
CN117692899A
Active immune defense strategy generation method under cloud-side cooperation
CN119602985A
Cited By
Method and device for constructing data security agent based on large model
CN120474842A
Method and device for constructing data security intelligent body based on large model
CN120474842B
Railway intelligent operation and maintenance secure transmission method based on multi-modal data fusion and application
CN120711377A
Annular edge computing device
CN120872598A
Federal RPA-based power system safety protection method and system
CN120934839A