Internet of Things equipment security authentication and data encryption transmission system and method
Through the IoT device security authentication and data encryption transmission system combined with lightweight symmetric key authentication and edge computing, the problem of device resource limitation and key management difficulties is solved, and efficient and secure data transmission and device protection is achieved.
Patent Information
- Application Number
- CN202510402595.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-11
AI Technical Summary
Existing IoT devices have problems such as limited device resources and difficulty in key management in terms of secure authentication and data encryption transmission, resulting in insufficient security and efficiency.
The lightweight symmetric key authentication mechanism is adopted, and device identity authentication is performed in combination with edge computing, and through dynamic permission adjustment and localized key management, the lightweight encryption algorithm and hash algorithm are used to transmit data to prevent replay attacks.
It realizes secure authentication and data encryption transmission of IoT devices in resource-constrained environments, prevents illegal device access, data leakage and tampering, improves system adaptability and response speed, and reduces computing resource consumption.
Smart Images

Figure CN120301630A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things (IoT) devices, and particularly to an IoT device security authentication and data encrypted transmission system and method. Background Art
[0002] The popularization of Internet of Things (IoT) devices has brought great convenience to life, but at the same time, it has also brought many security risks. The security authentication and data encrypted transmission of IoT devices are key technologies to protect user privacy and data security. Currently, there are problems such as limited device resources and difficult key management.
[0003] Prior Art One, a Chinese patent with the application number 202411294930.2 discloses a smart water conservancy IoT data security encrypted transmission system and method, including a data encryption module, an identity authentication module, a data decryption module, and a transmission security analysis module; the data encryption module is used to encrypt the sensor number and the collected data; the identity authentication module is used to ensure that only authenticated users can access the data; the data decryption module is used to decrypt the received encrypted image; the transmission security analysis module is used to analyze the security status during the data transmission process. Although it can effectively ensure the security of smart water conservancy IoT data transmission; however, the key management is difficult, the computational overhead is large, and it is not suitable for low-power devices.
[0004] Prior Art Two, a Chinese patent with the application number 202410556010.7 discloses a data collection method and system based on blockchain and IoT security chips. By using the unclonable function of the IoT security chip, the unique digital identity of the IoT device is designed and implemented to ensure the identity correctness and the device operation program correctness, and prevent the intrusion of malicious devices; by using blockchain technology, a blockchain-based digital certificate system is designed and implemented, and key data is stored; by using the MQTTS protocol, a two-way identity authentication method based on the blockchain digital identity certificate is designed and implemented, and the transmitted data is encrypted for transmission to protect the security and correctness of the data. Although the uniqueness of the IoT device identity, security authentication, secure data collection, and secure data transmission are achieved by adopting blockchain technology, IoT security chips, and the MQTTS protocol; however, the IoT device uses an outdated communication protocol and is easily attacked by a man-in-the-middle or data tampering.
[0005] Prior Art III, a Chinese patent with application number 202410038386.9, discloses an Internet of Things (IoT) data subscription method, device, and medium. The method includes: transmitting the collected IoT data according to a preset target server to determine the uploaded data; performing subscription processing on the uploaded data regarding the data source, and determining the subscription execution result information based on the permission attributes of the subscribed data; deploying the subscription execution result information through a preset smart contract to obtain the subscription permission information; encrypting the subscribed data under an encryption public key according to the subscription permission information to obtain the encrypted transmission data; and transmitting the encrypted transmission data to the subscriber. Although it solves the technical problems in the existing data subscription system where subscription information is easily stored centrally and the push policy is easily tampered with, resulting in the inefficiency, low credibility, and lack of security guarantee of the IoT platform, the IoT devices lack an automatic update mechanism, leading to known vulnerabilities not being repaired in time and becoming targets for attackers.
[0006] Currently, Prior Art I, Prior Art II, and Prior Art III have problems of limited device resources and difficult key management. Therefore, the present invention provides an IoT device security authentication and data encryption transmission system and method. Summary of the Invention
[0007] To achieve the above objectives, the present invention adopts the following technical solutions:
[0008] On one hand, the present invention provides an IoT device security authentication and data encryption transmission system, comprising:
[0009] A device identity authentication component, which is used to authenticate the legitimate identity of the IoT device with a lightweight symmetric key and dynamically adjust the access permissions according to the state and environment of the IoT device; dynamically adjust the permissions according to factors such as device location, time, and network status;
[0010] A key management component, which is used to generate and distribute keys after the IoT device passes the access permission authentication; the IoT devices use a key exchange protocol to exchange keys, and combined with edge computing, local key management is realized at the edge nodes;
[0011] A lightweight encryption component, which is used to transmit the data containing the key and the key exchange protocol to the target device, and uses lightweight encryption and hash algorithms to encrypt the transmission data during transmission, and uses timestamps and random numbers to prevent replay attacks.
[0012] In an optional implementation, the device identity authentication component comprises:
[0013] An operation module, responsible for performing hash operations and exclusive-or operations through the initial symmetric key, unique identifier, random number, timestamp, location information, and network status information of the IoT device; adopting a non-linear transformation function and a dynamic weight matrix, and dynamically adjusting the authentication strength in combination with the environmental status of the IoT device;
[0014] An environmental factor processing module, responsible for normalizing the environmental status of the IoT device, and converting the environmental factor into a standardized value through a normalization function for permission adjustment;
[0015] A dynamic permission adjustment module, responsible for dynamically adjusting the access permission of the IoT device according to the identity authentication result of the IoT device and the normalized value of the environmental factor; generating the final permission value through a dynamic permission adjustment function in combination with the device status and environmental factors.
[0016] In an optional implementation, the expression for generating the final permission value in combination with the device status and environmental factors:
[0017]
[0018] In the formula, A represents the comprehensive authentication and permission adjustment result; H(·) represents a lightweight hash function; K i represents the initial symmetric key of the device; D i represents the unique identifier of the device; R represents a random number; T represents a timestamp; L represents the device location information; N represents the network status information; represents the bitwise exclusive-or operation; \parallel) represents the string concatenation operation; G(·) represents a non-linear transformation function; W represents a dynamic weight matrix, which is dynamically adjusted according to the device status and environmental factors; [L, T, N] represents the vector combination of location, time, and network status; f(·) represents a dynamic permission adjustment function, which generates a permission value in combination with the device status and environmental factors; g(·) represents an environmental factor normalization function for adjusting the range of the permission value.
[0019] In an optional implementation, the key management component includes:
[0020] A key generation module, responsible for generating a dynamic key and initializing the basic parameters of the key management component; using the initial symmetric key, unique identifier, random number, timestamp, location information, and network status of the device as inputs; generating a dynamic key through a hash function and a non-linear transformation function; initializing the environmental status vector and the dynamic weight matrix, and dynamically adjusting the weight matrix according to the device status and environment for subsequent key generation and distribution logic;
[0021] The key distribution module is responsible for securely distributing keys between Internet of Things devices and generating shared keys through a key exchange protocol; encrypting the keys, timestamps, and random numbers generated by the key exchange protocol using dynamic keys, and distributing the encrypted keys to target devices;
[0022] The key verification module is responsible for verifying the validity and integrity of keys and generating final dynamic keys, using the shared key, dynamic key, timestamp, random number, and location information as inputs; generating a key verification value through a hash function and bitwise XOR operation.
[0023] In an alternative embodiment, where K final = V key ·H(K update |K dist |K ex |K gen |T|R|L i |L j |N)·G(W·S i ·S j )
[0024] In the formula, K final represents the final dynamic key for secure communication between devices; V key represents the key verification value for verifying the validity and integrity of keys; K update represents the updated key for preventing key leakage and replay attacks; K dist represents the distributed key for securely distributing keys between devices; K ex represents the shared key generated by the key exchange protocol for secure communication between devices; K gen represents the generated dynamic key based on the access rights and environmental status of the device; T represents the timestamp for preventing replay attacks and ensuring the dynamic nature of keys; L i represents the location information of Internet of Things device i for dynamically adjusting the key generation and distribution logic; L j represents the location information of Internet of Things device j for dynamically adjusting the key generation and distribution logic; N represents the network status information of the device for dynamically adjusting the key generation and distribution logic; S i represents the environmental status vector of Internet of Things device i for dynamically adjusting the key generation and distribution logic; S j represents the environmental status vector of Internet of Things device j for dynamically adjusting the key generation and distribution logic.
[0025] In an alternative embodiment, the key management component includes:
[0026] The device status perception module is responsible for each Internet of Things device to perceive its own status and environmental status in real time, and encode the data into an environmental status vector; the edge node dynamically adjusts the parameters of the key exchange protocol according to the status and environmental data of the Internet of Things device;
[0027] The key generation logic module is responsible for coordinating the key exchange process of Internet of Things devices within the region. The edge node generates a dynamic weight matrix according to the real-time status and environmental data of the Internet of Things device, which is used to adjust the logic of key generation and distribution;
[0028] The exchange protocol generation module is responsible for the edge node to generate a dynamic key exchange protocol according to the dynamic status and environmental data of the Internet of Things device, which includes key exchange parameters and also includes dynamic adjustment parameters; the edge node distributes the generated dynamic key exchange protocol to the target device;
[0029] The local key management module is responsible for dynamically allocating computing resources for each edge node according to the real-time status and environmental data of the Internet of Things device; the edge node generates dynamic keys and shared keys according to the dynamic status and environmental data of the Internet of Things device; the edge node distributes the generated keys to the target device, and at the same time records the distribution path and timestamp of the keys.
[0030] In an optional implementation, the local key management module includes:
[0031] The device status impact calculation sub-module is responsible for each Internet of Things device, extracting the elements of its status vector, and multiplying them by the corresponding dynamic weights and resource allocation coefficients; adjusting the weights using the Gaussian function; summing up the weighted status vectors of all Internet of Things devices;
[0032] The environmental status impact calculation sub-module is responsible for each environmental status, extracting the elements of its status vector, and multiplying them by the corresponding weight coefficients, using the logarithmic function to smooth the impact of the environmental status; summing up the weighted environmental status vectors;
[0033] The comprehensive calculation sub-module is responsible for dividing the impact of the Internet of Things device by the environmental impact to obtain a preliminary resource allocation ratio, multiplying it by the resource allocation ratio factor for global adjustment of the resource allocation ratio; using the sine function to introduce time-periodic fluctuations, and combining the adjusted ratio with the time-periodic fluctuations to obtain the final computing resource allocation value.
[0034] In an optional implementation, the formula for the computing resource allocation value:
[0035]
[0036] In the formula, R′ represents the computing resources allocated to the target device; s represents the dimension of the status vector of the Internet of Things device itself; C rrepresents the element of the self - state vector of the r - th Internet of Things device; W r represents the dynamic weight corresponding to the r - th Internet of Things device; η r represents the resource allocation coefficient, which is used to adjust the impact of the self - state of the Internet of Things device on resource allocation; u represents the dimension of the environmental state vector; D t represents the element of the t - th environmental state vector; θ t represents the weight coefficient of the environmental state vector; λ represents the resource allocation ratio factor, which is used to globally adjust the ratio of resource allocation; T r represents the real - time timestamp of the r - th device; μ r represents the mean value of the timestamps of the r - th Internet of Things device; σ r represents the standard deviation of the timestamps of the r - th Internet of Things device; V t represents the real - time value of the t - th environmental state vector; k t represents the reference value of the t - th environmental state vector; T′ represents the current system time; τ represents the time - period parameter, which is used to adjust the impact of time fluctuation.
[0037] In an optional implementation, the lightweight encryption component includes:
[0038] The data chunking and encryption module is responsible for dividing the data to be transmitted into multiple data chunks of a fixed size, and each data chunk is encrypted using a temporary key; the encryption process uses a lightweight encryption algorithm based on chaotic mapping, and by introducing the randomness and unpredictability of the chaotic sequence, the encryption strength is enhanced;
[0039] The hash protection module is responsible for generating a hash value for each encrypted data chunk using a lightweight hash algorithm based on non - linear transformation; by performing multiple rounds of non - linear operations on the data chunk and the dynamic key, a unique hash value is generated to verify the integrity of the data;
[0040] The timestamp and random number embedding module is responsible for embedding the timestamp and random number in each data chunk. The timestamp is used to record the time when the data is generated, and the random number is used to increase the uniqueness of the data, and together with the encrypted data chunk and the hash value, they form a complete data packet.
[0041] On the other hand, the present invention provides an Internet of Things device security authentication and data encryption transmission method, including the following steps:
[0042] Authenticate the legitimate identity of the Internet of Things device using a lightweight symmetric key, and dynamically adjust the access permission according to the state of the Internet of Things device and the environment; dynamically adjust the permission according to factors such as device location, time, and network status;
[0043] After passing the access permission authentication, the Internet of Things device generates and distributes keys; the Internet of Things devices use a key exchange protocol to exchange keys, and combined with edge computing, local key management is implemented at the edge node;
[0044] Transmit the data containing the key and the key exchange protocol to the target device. When transmitting, use lightweight encryption and hash algorithms to encrypt the transmitted data, and use timestamps and random numbers to prevent replay attacks.
[0045] The device identity authentication component of the present invention ensures the legal identity of the Internet of Things device through a symmetric key authentication mechanism; symmetric key authentication has the characteristics of low computational resource consumption and fast response speed, and is very suitable for resource-constrained Internet of Things devices; according to factors such as the device's status (such as battery power, operating mode), environment (such as location, network quality), and time, dynamically adjust the device's access permission, and the flexibility can effectively cope with the complex and changeable scenarios in the Internet of Things environment; through dynamic permission management, unauthorized devices can be prevented from accessing the network, and at the same time, the access permission of the device can be restricted in a timely manner when the device status is abnormal, reducing security risks. After the device passes the identity authentication, the key management component can quickly generate and distribute keys to ensure the communication security between devices; through an efficient key exchange protocol, devices can safely share keys and avoid the risk of key leakage; combined with edge computing technology, key management can be completed locally at the edge node, reducing the dependence on the central server and improving the response speed and reliability of the system. The lightweight encryption component uses a lightweight encryption algorithm suitable for Internet of Things devices to ensure the security of data transmission, while reducing the occupation of device resources; perform integrity verification on the data through a hash algorithm to prevent the data from being tampered with during transmission; use the timestamp and random number mechanism to effectively prevent attackers from obtaining sensitive information through replay attacks. Description of the Drawings
[0046] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings:
[0047] Figure 1 It is a block diagram of the Internet of Things device security authentication and data encryption transmission system provided in Embodiment 1 of the present invention;
[0048] Figure 2 It is a block diagram of the device identity authentication component provided in Embodiment 2 of the present invention;
[0049] Figure 3 It is the block diagram of the key management component provided in Embodiment 3 of the present invention Figure 1 ;
[0050] Figure 4 It is the block diagram of the key management component provided in Embodiment 4 of the present inventionFigure 2 ;
[0051] Figure 5 This is the block diagram of the localization key management module provided in Embodiment 5 of the present invention;;
[0052] Figure 6 This is the block diagram of the lightweight encryption component provided in Embodiment 6 of the present invention;
[0053] Figure 7 This is the flowchart of the method for secure authentication and data encrypted transmission of Internet of Things devices provided in Embodiment 7 of the present invention;
[0054] Figure 8 This is the block diagram of the electronic device provided by the present invention;
[0055] Figure 9 This is the block diagram of the computer-readable storage medium provided by the present invention. Detailed implementation manners
[0056] Next, the technical solutions in the embodiments of the present invention will be described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.
[0057] Hereinafter, terms such as "first" and "second" are only used for convenience of description, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise stated, the meaning of "a plurality" is two or more.
[0058] In the present invention, unless otherwise clearly defined and limited, the term "connection" should be understood in a broad sense. For example, "connection" can be a fixed mechanical connection, a detachable mechanical connection, or integrated; or, "connection" can be a direct connection, or an indirect connection through an intermediate medium. In addition, unless otherwise clearly defined and limited, the term "coupling" should be understood in a broad sense. For example, "coupling" can be a direct electrical connection. For example, two components are in physical contact and electrically conduct; it can also be understood that in a circuit structure, different components are electrically connected through a printed circuit board (PCB) copper foil or a wire and other physical lines that can transmit electrical signals to transmit electrical signals; or, "coupling" can be an indirect electrical connection between two components through an intermediate medium; or, "coupling" can be an electrical connection between two components in an air / non-contact manner. For example, two components are electrically connected by means of capacitive coupling to transmit electrical signals.
[0059] In the embodiments of the present invention, orientation terms such as "upper", "lower", "left", "right", etc. may include, but are not limited to, being defined relative to the orientation of the components shown in the drawings. It should be understood that these directional terms can be relative concepts, which are used for relative description and clarification, and they can change accordingly with the change of the orientation of the components shown in the drawings.
[0060] Embodiments of the present invention can be used for devices in smart homes (such as smart door locks, cameras, thermostats, lighting systems, etc.) that require secure communication to prevent illegal device access or data leakage; dynamically adjust device permissions according to the location and time of family members (for example, only when at home can the door lock be controlled); implement local key management through edge computing, reduce dependence on cloud services, improve response speed and privacy protection; be suitable for resource-constrained smart home devices, ensuring data security while reducing computational overhead. Sensors, controllers, and monitoring devices in industrial Internet of Things (IIoT) require secure communication to prevent production data from being tampered with or leaked; dynamically adjust permissions according to device status (such as operating status, fault status) and environment (such as workshop location) to ensure secure access to critical devices; ensure secure communication between devices through a key exchange protocol to prevent data from being stolen or tampered with; timestamp and random number mechanisms can effectively prevent replay attacks, ensuring the timeliness and integrity of industrial data. Infrastructure in smart cities (such as traffic lights, environmental monitoring sensors, public security cameras, etc.) requires secure communication to ensure the safety and reliability of urban operations, dynamically adjust permissions according to device location and time (for example, traffic lights only allow specific devices to access during peak hours); implement local key management through edge nodes, reduce data transmission latency, and improve system response speed; be suitable for smart city devices with large-scale deployment, ensuring data security while reducing resource consumption. Smart healthcare (such as remote monitoring devices, smart medicine boxes, health sensors, etc.) requires secure communication to protect the privacy of patients and the security of medical data, dynamically adjust device permissions according to the patient's status (such as condition, location) to ensure the security of data access; ensure secure communication between medical devices through a key exchange protocol to prevent data leakage or tampering; timestamp and random number mechanisms can effectively prevent replay attacks, ensuring the timeliness and reliability of medical data. Vehicles, roadside units (RSUs), and traffic management centers in intelligent transportation require secure communication to ensure the security and real-time nature of traffic data; dynamically adjust permissions according to vehicle location and traffic status to ensure secure access to critical data; implement local key management through edge computing, reduce data transmission latency, and improve system response speed; be suitable for resource-constrained in-vehicle devices and roadside units, ensuring data security while reducing computational overhead. Sensors, irrigation devices, and monitoring devices in agricultural Internet of Things require secure communication to ensure the security and reliability of agricultural production data, dynamically adjust permissions according to device status (such as soil humidity, temperature) and environment (such as farmland location) to ensure secure access to critical devices; ensure secure communication between devices through a key exchange protocol to prevent data from being stolen or tampered with; timestamp and random number mechanisms can effectively prevent replay attacks, ensuring the timeliness and integrity of agricultural data.Tracking devices, sensors, and monitoring devices in logistics and supply chain management require secure communication to ensure the security and reliability of cargo data; dynamically adjust permissions based on device location and time to ensure secure access to critical data; implement local key management through edge computing to reduce data transmission latency and improve system response speed; suitable for resource-constrained logistics devices to ensure data security while reducing computational overhead. Embodiments of the present invention can be widely applied to fields such as smart home, industrial Internet of Things, smart city, smart healthcare, smart transportation, agricultural Internet of Things, and logistics and supply chain management through technical means such as device identity authentication, dynamic permission adjustment, key management, lightweight encryption, and replay attack prevention.
[0061] Embodiment 1:
[0062] As Figure 1 shown, an embodiment of the present invention provides an Internet of Things device security authentication and data encryption transmission system, comprising:
[0063] A device identity authentication component for lightweight symmetric key authentication of the legitimate identity of Internet of Things devices and dynamically adjusting access permissions according to the status and environment of Internet of Things devices; dynamically adjusting permissions according to factors such as device location, time, and network status;
[0064] A key management component for generating and distributing keys after the Internet of Things devices pass the access permission authentication; using a key exchange protocol for key exchange between Internet of Things devices, and implementing local key management at the edge node in combination with edge computing;
[0065] A lightweight encryption component for transmitting data containing keys and the key exchange protocol to the target device, and encrypting the transmitted data using lightweight encryption and hash algorithms during transmission, and using timestamps and random numbers to prevent replay attacks.
[0066] In the above embodiments, the device identity authentication component ensures the legitimate identity of IoT devices through a symmetric key authentication mechanism. Symmetric key authentication features low computational resource consumption and fast response speed, making it very suitable for resource-constrained IoT devices. According to factors such as the device's status (e.g., battery level, operating mode), environment (e.g., location, network quality), and time, the access permissions of the device are dynamically adjusted. The flexibility can effectively handle the complex and changeable scenarios in the IoT environment. Through dynamic permission management, unauthorized device access to the network can be prevented, and at the same time, the access permissions of the device can be restricted in a timely manner when the device status is abnormal, reducing security risks. Significance: Ensuring that only authenticated devices can access the network, preventing illegal devices from threatening the system; the dynamic permission adjustment mechanism can adapt to the diverse needs of IoT devices, enhancing the adaptability and security of the system; the lightweight authentication mechanism reduces the occupancy of device computing resources and extends the service life of the device. After the device passes the identity authentication, the key management component can quickly generate and distribute keys to ensure the security of communication between devices. Through an efficient key exchange protocol, devices can securely share keys, avoiding the risk of key leakage. Combining edge computing technology, key management can be completed locally at the edge node, reducing the dependence on the central server and enhancing the response speed and reliability of the system. Significance: Key management is the core to ensure the security of data transmission. Through the key exchange protocol and local management, man-in-the-middle attacks and data leakage can be effectively prevented; the support of edge computing reduces network latency and improves the real-time performance and efficiency of the system; local key management enables the system to support more device accesses while reducing the load pressure on the central server. The lightweight encryption component uses a lightweight encryption algorithm suitable for IoT devices to ensure the security of data transmission while reducing the occupancy of device resources. The integrity of the data is verified through a hash algorithm to prevent the data from being tampered with during transmission. The timestamp and random number mechanism are used to effectively prevent attackers from obtaining sensitive information through replay attacks. Significance: The combination of encryption and hash algorithms ensures the confidentiality and integrity of data during transmission; the anti-replay attack mechanism further enhances the security of the system, preventing malicious attackers from damaging the system; the lightweight encryption algorithm reduces the demand for device computing resources, enabling the system to operate efficiently in resource-constrained IoT devices.
[0067] In summary, through the collaborative work of three components, namely device identity authentication, key management, and lightweight encryption, this embodiment achieves comprehensive security protection for Internet of Things (IoT) devices. Through identity authentication, key management, and encrypted transmission, it effectively prevents security issues such as illegal device access, data leakage, and tampering. The support of lightweight algorithms and edge computing enables the system to operate efficiently in resource-constrained environments. Dynamic permission adjustment and localized key management enable the system to adapt to complex IoT environments and meet diverse requirements. It supports large-scale device access and has good scalability and adaptability. It can not only provide solid security guarantees for IoT devices but also lay a technical foundation for the wide promotion of IoT applications.
[0068] Embodiment 2:
[0069] As Figure 2 shown, based on Embodiment 1, the device identity authentication component provided by the embodiment of the present invention includes:
[0070] An operation module responsible for performing hash operations and exclusive OR operations through the initial symmetric key, unique identifier, random number, timestamp, location information, and network status information of the IoT device; adopting a non-linear transformation function and a dynamic weight matrix to dynamically adjust the authentication strength in combination with the environmental state of the IoT device;
[0071] An environmental factor processing module responsible for normalizing the environmental state of the IoT device, and converting the environmental factors into a standardized value through a normalization function for permission adjustment;
[0072] A dynamic permission adjustment module responsible for dynamically adjusting the access permissions of the IoT device according to the IoT device identity authentication result and the normalized value of the environmental factor; generating the final permission value through a dynamic permission adjustment function in combination with the device state and environmental factors.
[0073] Wherein:
[0074]
[0075] In the formula, A represents the comprehensive authentication and permission adjustment result; H(·) represents a lightweight hash function; K i represents the initial symmetric key of the device; D i represents the unique identifier of the device; R represents a random number; T represents a timestamp; L represents the device location information; N represents the network status information; denotes bitwise XOR operation; \parallel) denotes string concatenation operation; G(·) denotes a non - linear transformation function; W represents a dynamic weight matrix (3x1 matrix), which is dynamically adjusted according to device status and environmental factors; [L, T, N] represents a vector combination of position, time, and network status; f(·) denotes a dynamic permission adjustment function that generates permission values by combining device status and environmental factors; g(·) denotes an environmental factor normalization function used to adjust the range of permission values.
[0076] In the above - mentioned embodiment, the operation module encrypts and obfuscates the device's initial symmetric key, unique identifier, random number, timestamp, location information, and network status information through a lightweight hash function and bitwise XOR operation to generate an irreversible authentication value; through a non - linear transformation function and a dynamic weight matrix, the authentication strength is dynamically adjusted in combination with the device's environmental status (location, time, network status) to ensure the anti - attack and adaptability of the authentication process. Significance: The hash operation and XOR operation ensure the security of the authentication process, preventing key leakage and replay attacks; through the dynamic weight matrix and non - linear transformation, the authentication strength can be dynamically adjusted according to the device's environmental status to meet different security requirements; the use of a lightweight hash function is suitable for resource - constrained IoT devices, reducing the computational overhead. The environmental factor processing module converts the device's environmental status into a standardized value through a normalization function; the normalized environmental factor can quantify the device's environmental status, providing a basis for subsequent permission adjustment. Significance: Converting environmental factors with different dimensions into standardized values is convenient for calculation and comparison; the normalization function can be designed according to actual needs to adapt to different application scenarios; by quantifying the environmental status, the permission value can be dynamically adjusted to ensure the security of the device in different environments. The dynamic permission adjustment module generates the final permission value through a dynamic permission adjustment function, combining the device identity authentication result and the environmental factor normalization value; the permission value reflects the access permission level of the device and can be dynamically adjusted according to device status and environmental factors. Significance: By dynamically adjusting the permission value, more refined access control can be achieved to ensure the reasonable distribution of access permissions for the device in different environments; dynamic permission adjustment can adjust the permission value in real - time according to the device's environmental status to prevent unauthorized access; the permission value can change dynamically according to device status and environmental factors to ensure the optimal performance of the system in different scenarios.
[0077] In summary, in this embodiment, through hash operation, XOR operation, non - linear transformation, and dynamic weight matrix, the security of device identity authentication is ensured; through environmental factor normalization and dynamic permission adjustment, the dynamic adjustment of authentication strength and permission value is achieved.
[0078] Embodiment 3:
[0079] As Figure 3As shown in the figure, based on Embodiment 1, the key management component provided by the embodiment of the present invention includes:
[0080] A key generation module, responsible for generating dynamic keys and initializing the basic parameters of the key management component; using the initial symmetric key, unique identifier, random number, timestamp, location information, and network status of the device as inputs; generating dynamic keys through a hash function and a non-linear transformation function; initializing the environmental state vector and the dynamic weight matrix, and dynamically adjusting the weight matrix according to the state and environment of the device for subsequent key generation and distribution logic;
[0081] A key distribution module, responsible for securely distributing keys between Internet of Things devices and generating shared keys through a key exchange protocol; encrypting the keys, timestamps, and random numbers generated by the key exchange protocol using the dynamic key, and distributing the encrypted keys to the target devices;
[0082] A key verification module, responsible for verifying the validity and integrity of the keys and generating the final dynamic key, using the shared key, dynamic key, timestamp, random number, and location information as inputs; generating a key verification value through a hash function and a bitwise exclusive OR operation.
[0083] Where, K final = V key ·H(K update |K dist |K ex |K gen |T|R|L i |L j |N)·G(W·S i ·Sj
[0084] In the formula, K final represents the final dynamic key for secure communication between devices; V key represents the key verification value for verifying the validity and integrity of the keys; K update represents the updated key for preventing key leakage and replay attacks; K dist represents the distributed key for securely distributing keys between devices; K ex represents the shared key generated by the key exchange protocol for secure communication between devices; K gen represents the generated dynamic key based on the access rights and environmental status of the device; T represents the timestamp for preventing replay attacks and ensuring the dynamic nature of the keys; L i represents the location information of Internet of Things device i for dynamically adjusting the key generation and distribution logic; L jRepresents the location information of the Internet of Things device j, which is used to dynamically adjust the generation and distribution logic of keys; N represents the network status information of the device, which is used to dynamically adjust the generation and distribution logic of keys; S i Represents the environmental state vector of the Internet of Things device i, which is used to dynamically adjust the logic of key generation and distribution; S j Represents the environmental state vector of the Internet of Things device j, which is used to dynamically adjust the logic of key generation and distribution.
[0085] In the above embodiments, the generation process of the dynamic keys of the key generation module has a high degree of randomness and dynamics, which can effectively prevent key leakage and replay attacks; the dynamic adjustment mechanism enables the key generation logic to adaptively change according to the real-time status and environmental data of the device, improving the flexibility and security of the system. Significance achieved: The generation process of the dynamic keys is based on the real-time status and environmental data of the device, making the keys highly dynamic and random, effectively preventing key leakage and replay attacks; the introduction of the environmental state vector and the dynamic weight matrix enables the key generation logic to adaptively adjust according to the real-time status and environmental data of the device, improving the flexibility and security of the system; the key generation module initializes the basic parameters of the key management component, providing basic support for subsequent key distribution and verification, ensuring the integrity and consistency of the key management process. The encryption distribution mechanism of the key distribution module ensures the security of the key during transmission, preventing the key from being stolen or tampered with; the generation process of the shared key is based on the dynamic status and environmental data of the device, ensuring the dynamics and security of the key. Significance achieved: The key distribution module ensures the security of the key during transmission through the encryption mechanism, preventing the key from being stolen or tampered with; the key distribution module dynamically adjusts the key distribution logic according to the real-time status and environmental data of the device, improving the efficiency and flexibility of key distribution; the key distribution module generates a shared key for secure communication between devices, ensuring the security and reliability of the communication process. The verification mechanism of the key verification module ensures the integrity and consistency of the key during generation and distribution; the dynamic key is used for secure communication between devices, ensuring the security and reliability of the communication process. Significance achieved: The key verification module generates a key verification value through a hash function and a bitwise exclusive OR operation, ensuring the integrity and consistency of the key during generation and distribution; the key verification module generates the final dynamic key for secure communication between devices, ensuring the security and reliability of the communication process; the key verification module prevents key leakage and replay attacks through the introduction of timestamps and random numbers, ensuring the dynamics and security of the key.
[0086] In summary, each module of the key management component in this embodiment ensures the security of keys during the generation, distribution, and use processes through dynamic key generation, secure key distribution, and key verification, effectively preventing key leakage, tampering, and replay attacks; each module of the key management component dynamically adjusts the key generation, distribution, and verification logic according to the real-time status and environmental data of the device, improving the dynamicity and self-adaptability of the system; each module of the key management component generates and distributes shared keys and final dynamic keys for secure communication between devices, ensuring the security and reliability of the communication process; each module of the key management component dynamically adjusts the key generation, distribution, and verification logic according to the real-time status and environmental data of the device, improving the flexibility and efficiency of the system.
[0087] Embodiment 4:
[0088] As Figure 4 shown, based on Embodiment 1, the key management component provided by the embodiment of the present invention includes:
[0089] The device status perception module is responsible for perceiving the real-time status of each Internet of Things device (such as battery power, signal strength, computing power) and environmental status (such as temperature, humidity, location information), and encoding the data into an environmental status vector; the edge node dynamically adjusts the parameters of the key exchange protocol (such as key length, encryption algorithm complexity, communication frequency, etc.) according to the status and environmental data of the Internet of Things device.
[0090] The key generation logic module is responsible for coordinating the key exchange process of Internet of Things devices within the region. The edge node generates a dynamic weight matrix according to the real-time status and environmental data of the Internet of Things device, which is used to adjust the logic of key generation and distribution.
[0091] The exchange protocol generation module is responsible for the edge node to generate a dynamic key exchange protocol according to the dynamic status and environmental data of the Internet of Things device, including key exchange parameters (such as shared keys and timestamps), and also including dynamic adjustment parameters (such as weight matrix and environmental status vector); the edge node distributes the generated dynamic key exchange protocol to the target device.
[0092] The local key management module is responsible for dynamically allocating computing resources for each edge node according to the real-time status and environmental data of the Internet of Things device; the edge node generates dynamic keys and shared keys according to the dynamic status and environmental data of the Internet of Things device; the edge node distributes the generated keys to the target device, and at the same time records the key distribution path and timestamp.
[0093] In the above embodiments, the device status perception module encodes the perceived data into an environmental status vector, providing dynamic input for key management. Significance: By perceiving the device status and environmental changes in real time, the key management strategy can be dynamically adjusted to avoid security vulnerabilities caused by insufficient device resources or environmental changes; the perception module helps to allocate resources reasonably, avoiding high-energy-consuming encryption operations in low battery or weak signal situations, and extending the device lifespan. The localized key management module adjusts the logic of key generation and distribution using a weight matrix to ensure that the key management process matches the device status and environment. Significance: The dynamic weight matrix makes key management more flexible, enabling real-time adjustment of key generation and distribution strategies according to device status and environmental changes, enhancing the system's anti-attack ability; through localized key management, the key exchange process among devices within the region is more efficient, reducing the latency and risk of cross-region communication. The exchange protocol generation module can adjust the encryption strategy in real time according to device status and environmental changes by dynamically generating a key exchange protocol, preventing the fixed protocol from being cracked by attackers; the dynamic protocol optimizes the communication frequency and the complexity of the encryption algorithm, ensuring efficient key exchange on resource-constrained devices. The dynamic allocation of computing resources by the localized key management module ensures that the key generation and distribution process does not consume excessive device resources, improving the overall system efficiency; recording the key distribution path and timestamp facilitates subsequent auditing and tracking, enhancing the transparency and security of the system.
[0094] In summary, this embodiment can adjust the key management strategy in real time according to device status and environmental changes, improving security and efficiency; reasonably allocate computing resources, avoid resource waste, and extend the device lifespan; reduce communication latency and resource consumption through dynamic protocol generation and localized management; the dynamic key generation and distribution mechanism effectively resists attacks, ensuring data privacy and communication security. It not only improves the security of the Internet of Things system but also takes into account resource efficiency and dynamic adaptability, providing a solid technical guarantee for the wide application of the Internet of Things.
[0095] Embodiment 5:
[0096] As Figure 5 shown, based on Embodiment 4, the localized key management module provided by the embodiment of the present invention includes:
[0097] The device status impact calculation sub-module is responsible for, for each Internet of Things device, extracting the elements of its status vector, multiplying them by the corresponding dynamic weights and resource allocation coefficients; adjusting the weights using a Gaussian function; and summing up the weighted status vectors of all Internet of Things devices;
[0098] The environmental status impact calculation sub-module is responsible for, for each environmental status, extracting the elements of its status vector, multiplying them by the corresponding weight coefficients, and smoothing the impact of the environmental status using a logarithmic function; summing up the weighted environmental status vectors;
[0099] The comprehensive calculation sub-module is responsible for dividing the impact of the IoT device by the environmental impact to obtain a preliminary resource allocation ratio, multiplying it by the resource allocation ratio factor for global adjustment of the resource allocation ratio; introducing time-periodic fluctuations using the sine function and combining the adjusted ratio with the time-periodic fluctuations to obtain the final calculated resource allocation value.
[0100] Among them, the calculation resource allocation formula:
[0101]
[0102] In the formula, R′ represents the computing resources allocated to the target device; s represents the dimension of the IoT device's own state vector; C r represents the element of the r-th IoT device's own state vector (such as battery power, signal strength, computing power); W r represents the dynamic weight corresponding to the r-th IoT device; η r represents the resource allocation coefficient, which is used to adjust the impact of the IoT device's own state on resource allocation; u represents the dimension of the environmental state vector; D t represents the element of the t-th environmental state vector (such as temperature, humidity, location information); θ t represents the weight coefficient of the environmental state vector; λ represents the resource allocation ratio factor for global adjustment of the resource allocation ratio; T r represents the real-time timestamp of the r-th device; μ r represents the mean value of the timestamps of the r-th IoT device (the average of historical data); σ r represents the standard deviation of the timestamps of the r-th IoT device (the volatility of historical data); V t represents the real-time value of the t-th environmental state vector; k t represents the reference value of the t-th environmental state vector; T′ represents the current system time; τ represents the time period parameter for adjusting the impact of time fluctuations.
[0103] In the above embodiments, the device status impact calculation sub-module ensures more accurate resource allocation and avoids resource waste or insufficiency through real-time monitoring and dynamic adjustment of the IoT device status. The device status may change over time (such as battery power decline, signal fluctuation), and this module can dynamically adapt to these changes to ensure the stability and efficiency of the system. Through time volatility processing, it reduces the resource allocation deviation caused by abnormal device timestamps and improves the robustness of the system. The environmental status impact calculation sub-module ensures that resource allocation can adapt to environmental changes (such as a decrease in device performance may be caused by an increase in temperature) through real-time monitoring of the environmental status. The introduction of the logarithmic function avoids the drastic impact of sudden changes in the environmental status on resource allocation and ensures the smoothness of resource allocation. By comprehensively considering environmental factors, it reduces the resource allocation deviation caused by environmental changes and improves the overall stability of the system. The comprehensive calculation sub-module dynamically optimizes resource allocation through the comprehensive calculation of device status and environment to ensure the efficient use of resources. The introduction of time periodic fluctuations enables resource allocation to adapt to time changes (such as periodic demand changes during day and night, seasons, etc.) and improves the flexibility and adaptability of the system. Through the global adjustment factor, it ensures the balance of resource allocation in the overall system and avoids local resource overload or idleness.
[0104] In summary, the localization key management module of this embodiment realizes the dynamic and accurate allocation of computing resources through the collaborative work of the device status impact calculation sub-module, the environmental status impact calculation sub-module, and the comprehensive calculation sub-module. This embodiment ensures the efficiency and accuracy of resource allocation through multi-dimensional status monitoring and dynamic adjustment. It can adapt to the dynamic requirements of device status, environmental status, and time changes, improve the stability and robustness of the system. Through global adjustment and time periodic fluctuations, it ensures the flexibility and balance of resource allocation in the overall system. It not only improves the efficiency of resource allocation but also provides strong support for the stable operation and dynamic optimization of the IoT system.
[0105] Embodiment 6:
[0106] As Figure 6 shown, based on Embodiment 1, the lightweight encryption component provided by the embodiment of the present invention includes:
[0107] The data chunking and encryption module is responsible for dividing the data to be transmitted into multiple data chunks of a fixed size, and each data chunk is encrypted using a temporary key. The encryption process uses a lightweight encryption algorithm based on chaotic mapping. By introducing the randomness and unpredictability of the chaotic sequence, the encryption intensity is enhanced.
[0108] The hash protection module is responsible for generating a hash value for each encrypted data chunk using a lightweight hash algorithm based on non-linear transformation. By performing multiple rounds of non-linear operations on the data chunk and the dynamic key, a unique hash value is generated to verify the integrity of the data.
[0109] The timestamp and random number embedding module is responsible for embedding the timestamp and random number in each data block. The timestamp is used to record the time when the data is generated, and the random number is used to increase the uniqueness of the data. Together with the encrypted data block and the hash value, they form a complete data packet.
[0110] Among them,
[0111]
[0112] In the formula, P i′ represents the i'-th complete data packet; represents the encryption result of the j'-th sub-part of the i'-th data block; S(·) represents the chaotic mapping function that generates a chaotic sequence; α', β' represent the parameters of the chaotic mapping; X n , Y n represent the current state variables of the chaotic mapping; D j′ represents the j'-th sub-part of the data block; R j′ represents the j'-th sub-part of the dynamic key; H i′ represents the hash value; T i′ represents the timestamp; N i′ represents the random number; k represents the number of sub-parts of the data block.
[0113] In the above embodiments, the data after chunking by the data chunking and encryption module can be encrypted in parallel, improving the encryption efficiency; each data chunk is encrypted with a temporary key to ensure that even if part of the data is cracked, it will not affect the security of other data chunks; the chaotic sequence has high randomness and unpredictability, which can effectively withstand brute - force and statistical analysis attacks and enhance the encryption strength. Significance: Through chunking and encryption with temporary keys, the security of data transmission is improved and the risk of data leakage is reduced; the introduction of the chaotic mapping algorithm makes the encryption process more complex, capable of dealing with attack means of modern computing power and ensuring that data is difficult to be cracked during transmission. The hash protection module uses a lightweight hash algorithm to generate a unique hash value for each encrypted data chunk to verify the integrity of the data; by performing multiple rounds of non - linear operations on the data chunk and the dynamic key, a hash value is generated to ensure the uniqueness and non - forgery of the hash value. Significance: The existence of the hash value enables the receiving party to quickly verify whether the data has been tampered with during transmission, ensuring the integrity of the data; the participation of the dynamic key increases the complexity of the hash value, preventing attackers from tampering with data by forging hash values. The timestamp and random number embedding module records the time when the data is generated, facilitating the tracking of the timeliness and sequence of the data; increasing the uniqueness of the data, preventing replay attacks and forged data packets; the timestamp, random number, encrypted data chunk, and hash value together form a complete data packet, ensuring the integrity and traceability of the data. Significance: The embedding of the timestamp gives the data a time attribute, facilitating auditing and tracking; the introduction of the random number increases the uniqueness of the data, effectively preventing replay attacks and ensuring the authenticity and freshness of the data packet; the complete data packet structure ensures the integrity and verifiability of the data during transmission.
[0114] In summary, each module of the lightweight encryption component in this embodiment constructs an efficient and secure data transmission system through technical means such as chunk encryption, hash protection, and timestamp embedding. It not only improves the confidentiality and integrity of the data, but also enhances the uniqueness and traceability of the data through the introduction of timestamps and random numbers. This is particularly important in resource - constrained environments (such as Internet of Things devices), which can balance performance and efficiency while ensuring security.
[0115] Embodiment 7:
[0116] As Figure 7 shown, based on Embodiments 1 - 6, the method for secure authentication and data encrypted transmission of Internet of Things devices provided by the embodiment of the present invention includes the following steps:
[0117] S100: Use a lightweight symmetric key to authenticate the legitimate identity of the Internet of Things device and dynamically adjust the access rights according to the state and environment of the Internet of Things device; dynamically adjust the permissions according to factors such as device location, time, and network status;
[0118] S200: After the Internet of Things device passes the access permission authentication, it generates and distributes keys; the Internet of Things devices use a key exchange protocol to perform key exchange, and combined with edge computing, local key management is realized at the edge node;
[0119] S300: Transmit the data containing the key and the key exchange protocol to the target device. When transmitting, lightweight encryption and hash algorithms are used to encrypt the transmitted data, and timestamps and random numbers are used to prevent replay attacks.
[0120] In the above embodiments, for S100 device identity authentication and dynamic permission adjustment, through symmetric key authentication, the legal identity of the Internet of Things device is ensured, the consumption of computing resources is reduced, which is suitable for resource-constrained Internet of Things devices; according to factors such as the device's status (such as battery power, operating status), environment (such as location, time), and network status (such as signal strength, latency), the access permission of the device is dynamically adjusted. This dynamic adjustment mechanism can effectively meet the security requirements of the device in different scenarios and avoid abuse or insufficiency of permissions. Significance: Through identity authentication and dynamic permission management, illegal devices are prevented from accessing the network, reducing security risks; dynamic permission adjustment can reasonably allocate resources according to actual needs, avoiding unnecessary resource waste; in the diverse scenarios of Internet of Things device deployment, dynamic permission adjustment can flexibly meet different security requirements and improve the adaptability of the system. For S200 key generation, distribution, and local key management, after the device passes the authentication, keys are generated and distributed to ensure the security of communication between devices; through a key exchange protocol (such as the Diffie-Hellman protocol), secure key exchange between devices is achieved, avoiding the key being stolen during transmission; combined with edge computing, local key management is realized at the edge node, reducing the single-point failure risk of centralized key management, and at the same time reducing the latency and bandwidth consumption of key management. Significance: Through the key exchange protocol and local key management, it is ensured that the communication data between devices will not be stolen or tampered with; edge computing and local key management can reduce the dependence on the centralized system, improving the fault tolerance and reliability of the system; local key management reduces the latency and bandwidth consumption of key transmission, improving the overall performance of the system. For S300 data transmission encryption and anti-replay attack, lightweight encryption algorithms and hash algorithms are used to encrypt and perform integrity verification on the transmitted data to ensure the confidentiality and integrity of the data during transmission; through the timestamp and random number mechanism, replay attacks (that is, an attacker repeatedly sends captured data packets) are prevented, ensuring the timeliness and uniqueness of the data. Significance: Encryption and hash algorithms can effectively prevent the data from being stolen or tampered with during transmission, ensuring the confidentiality and integrity of the data; the timestamp and random number mechanism can effectively resist replay attacks, improving the security of the system; lightweight encryption and hash algorithms can reduce the consumption of computing resources while ensuring security, which is suitable for resource-constrained Internet of Things devices.
[0121] In summary, through multiple technical means such as identity authentication, dynamic permission adjustment, key management, and data transmission encryption, the present embodiment achieves comprehensive protection for Internet of Things devices. Its significance is mainly reflected in: through identity authentication, key management, and data encryption, it effectively prevents illegal device access, data theft, and tampering, enhancing the overall security of the system; lightweight algorithms and localized key management reduce the consumption of computing resources and network bandwidth, making it suitable for resource-constrained Internet of Things environments; the application of dynamic permission adjustment and edge computing enables the system to flexibly respond to complex Internet of Things scenarios, enhancing the adaptability and reliability of the system. It can not only meet the requirements of Internet of Things devices in terms of security, performance, and resource utilization, but also provide a solid technical guarantee for the wide application of the Internet of Things.
[0122] Figure 8 A block diagram of an exemplary electronic device suitable for implementing the embodiments of the present invention is shown.
[0123] The electronic device may include a central processing unit / microprocessor / master control chip, etc.; a storage medium, coupled to the central processing unit / microprocessor / master control chip, etc., and storing computer-executable instructions therein for performing the steps of the various methods of the embodiments of the present invention when executed by the processor.
[0124] The central processing unit / microprocessor / master control chip, etc. may include, but are not limited to, for example, one or more processors or microprocessors, etc.
[0125] The storage medium may include, but are not limited to, for example, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, computer storage media (such as hard disks, floppy disks, solid-state drives, removable disks, CD-ROMs, DVD-ROMs, Blu-ray discs, etc.).
[0126] In addition, the electronic device may further include (but is not limited to) a data bus, an input / output bus / external bus / device bus, etc., a display, and input / output devices (such as a keyboard, a mouse, a speaker, etc.).
[0127] The central processing unit / microprocessor / master control chip, etc. may communicate with external devices via an I / O bus through a wired or wireless network (not shown).
[0128] The storage medium may also store at least one computer-executable instruction for performing the steps of the various functions and / or methods in the embodiments described in the present technology when run by the central processing unit / microprocessor / master control chip, etc.
[0129] In one embodiment, the at least one computer-executable instruction may also be compiled into or form a software product, and when one or more computer-executable instructions are run by a processor, each function and / or step of the method in the embodiments described in this technology is executed.
[0130] Figure 9 FIG. shows a schematic diagram of a computer-readable storage medium according to an embodiment of the present invention.
[0131] As shown in Figure 9 the figure, instructions are stored on a non-transitory computer-readable storage medium, and the instructions are, for example, computer-readable instructions. When the computer-readable instructions are run by a processor, each method described above can be executed. The non-transitory computer-readable storage medium includes, but is not limited to, for example, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. Non-transitory non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, the non-transitory computer-readable storage medium may be connected to a computing device such as a computer. Then, when the computer-readable instructions stored on the computer-readable storage medium are run on the computing device, each method described above can be performed.
[0132] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.
[0133] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0134] In addition, each functional unit in various embodiments of the present invention may be integrated in one processing unit, or each unit may exist physically separately, or two or more units may be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0135] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for executing all or part of the steps of the methods of the various embodiments of the present invention through a computer device (which can be a personal computer, a server, or a network device, etc.). The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (English full name: Read-Only Memory, English abbreviation: ROM), random access memories (English full name: Random Access Memory, English abbreviation: RAM), magnetic disks, or optical discs that can store program codes.
[0136] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. An Internet of Things device security authentication and data encrypted transmission system, characterized in that, It includes: An equipment identity authentication component, which is used to authenticate the legal identity of Internet of Things devices with lightweight symmetric keys, and dynamically adjust access permissions according to the status and environment of Internet of Things devices; dynamically adjust permissions according to factors such as device location, time, and network status; A key management component, which is used to generate and distribute keys after the Internet of Things devices pass the access permission authentication; the Internet of Things devices use a key exchange protocol to exchange keys, and combined with edge computing, implement local key management at edge nodes; A lightweight encryption component, which is used to transmit data containing keys and key exchange protocols to target devices. When transmitting, lightweight encryption and hash algorithms are used to encrypt the transmitted data, and timestamps and random numbers are used to prevent replay attacks.
2. The Internet of Things device security authentication and data encrypted transmission system according to claim 1, characterized in that, The equipment identity authentication component includes: An operation module, which is responsible for performing hash operations and exclusive OR operations through the initial symmetric key, unique identifier, random number, timestamp, location information, and network status information of the Internet of Things device; using a non-linear transformation function and a dynamic weight matrix, dynamically adjusting the authentication strength in combination with the environmental state of the Internet of Things device; An environmental factor processing module, which is responsible for normalizing the environmental state of the Internet of Things device. Through a normalization function, the environmental factors are converted into a standardized value for permission adjustment; A dynamic permission adjustment module, which is responsible for dynamically adjusting the access permissions of Internet of Things devices according to the equipment identity authentication results and the normalized values of environmental factors; Generate the final permission value through a dynamic permission adjustment function, combining the device state and environmental factors.
3. The Internet of Things device security authentication and data encrypted transmission system according to claim 2, characterized in that, The expression for generating the final permission value by combining the device state and environmental factors: Wherein, A represents the result of comprehensive authentication and permission adjustment; H(·) represents a lightweight hash function; K i represents the initial symmetric key of the device; D i represents the unique identifier of the device; R represents a random number; T represents a timestamp; L represents the device location information; N represents the network status information; represents the bitwise exclusive OR operation; \parallel) represents the string concatenation operation; G(·) represents a non-linear transformation function; W represents a dynamic weight matrix, which is dynamically adjusted according to the device status and environmental factors; [L, T, N] represents the vector combination of location, time, and network status; f(·) represents a dynamic permission adjustment function, which generates a permission value by combining the device status and environmental factors; g(·) represents an environmental factor normalization function, which is used to adjust the range of the permission value.
4. The Internet of Things device security authentication and data encrypted transmission system according to claim 1, characterized in that The key management component includes: A key generation module, which is responsible for generating dynamic keys and initializing the basic parameters of the key management component; using the initial symmetric key, unique identifier, random number, timestamp, location information, and network status of the device as inputs; generating dynamic keys through a hash function and a non-linear transformation function; Initialize the environmental state vector and the dynamic weight matrix, and dynamically adjust the weight matrix according to the device state and environment for subsequent key generation and distribution logic; A key distribution module, which is responsible for securely distributing keys between Internet of Things devices and generating shared keys through a key exchange protocol; Encrypt the keys, timestamps, and random numbers generated by the key exchange protocol with dynamic keys, and distribute the encrypted keys to target devices; A key verification module, which is responsible for verifying the validity and integrity of keys and generating the final dynamic keys. Use the shared key, dynamic key, timestamp, random number, and location information as inputs; generate a key verification value through a hash function and a bitwise exclusive OR operation.
5. The Internet of Things device security authentication and data encrypted transmission system according to claim 4, wherein Among them, K final = V key ·H(K update |K dist |K ex |K gen |T|R|L i |L j |N)·G(W·S i ·S j ) Wherein, K final represents the final dynamic key for secure communication between devices; V key represents the key verification value for verifying the validity and integrity of the key; K update represents the updated key for preventing key leakage and replay attacks; K dist represents the distributed key for securely distributing keys between devices; K ex represents the shared key generated by the key exchange protocol for secure communication between devices; K gen represents the generated dynamic key based on the access rights and environmental status of the device; T represents the timestamp, which is used to prevent replay attacks and ensure the dynamics of the key; L i represents the location information of the IoT device i, which is used to dynamically adjust the key generation and distribution logic; L j represents the location information of the IoT device j, which is used to dynamically adjust the key generation and distribution logic; N represents the network status information of the device, which is used to dynamically adjust the key generation and distribution logic; S i represents the environmental state vector of the IoT device i, which is used to dynamically adjust the logic of key generation and distribution; S j represents the environmental state vector of the IoT device j, which is used to dynamically adjust the logic of key generation and distribution.
6. The Internet of Things device security authentication and data encrypted transmission system according to claim 1, characterized in that, The key management component includes: A device state perception module, which is responsible for each Internet of Things device to perceive its own state and environmental state in real time and encode the data into an environmental state vector; the edge node dynamically adjusts the parameters of the key exchange protocol according to the state and environmental data of the Internet of Things device; A key generation logic module, which is responsible for coordinating the key exchange process of Internet of Things devices in the region. The edge node generates a dynamic weight matrix according to the real-time state and environmental data of the Internet of Things device to adjust the logic of key generation and distribution; The exchange protocol generation module is responsible for the edge node to generate a dynamic key exchange protocol based on the dynamic state and environmental data of the IoT device, which includes key exchange parameters and also dynamic adjustment parameters; the edge node distributes the generated dynamic key exchange protocol to the target device; The local key management module is responsible for dynamically allocating computing resources for each edge node according to the real-time state and environmental data of the IoT device; The edge node generates dynamic keys and shared keys based on the dynamic state and environmental data of the IoT device; the edge node distributes the generated keys to the target device and records the distribution path and timestamp of the keys at the same time.
7. The Internet of Things device security authentication and data encrypted transmission system according to claim 6, characterized in that, The local key management module includes: The device state impact calculation sub-module is responsible for each IoT device to extract its state vector elements, multiply them by the corresponding dynamic weights and resource allocation coefficients; adjust the weights using the Gaussian function; sum the weighted state vectors of all IoT devices; The environmental state impact calculation sub-module is responsible for each environmental state to extract its state vector elements, multiply them by the corresponding weight coefficients, and use the logarithmic function to smooth the impact of the environmental state; sum the weighted environmental state vectors; The comprehensive calculation sub-module is responsible for dividing the impact of the IoT device by the environmental impact to obtain a preliminary resource allocation ratio, multiplying it by the resource allocation ratio factor for globally adjusting the resource allocation ratio; Use the sine function to introduce time-periodic fluctuations, and combine the adjusted ratio with the time-periodic fluctuations to obtain the final computing resource allocation value.
8. The Internet of Things device security authentication and data encrypted transmission system according to claim 7, characterized in that, The formula for the computing resource allocation value: where R ′ represents the computing resources allocated to the target device; s represents the dimension of the state vector of the IoT device itself; C r represents the element of the state vector of the r-th IoT device itself; W r represents the dynamic weight corresponding to the r-th IoT device; η r represents the resource allocation coefficient, which is used to adjust the impact of the IoT device's own state on resource allocation; u represents the dimension of the environmental state vector; D t represents the element of the t-th environmental state vector; θ t represents the weight coefficient of the environmental state vector; λ represents the resource allocation ratio factor, which is used to globally adjust the ratio of resource allocation; T r represents the real-time timestamp of the r-th device; μ r represents the mean value of the timestamps of the r-th IoT device; σ r represents the standard deviation of the timestamps of the r-th IoT device; V t represents the real-time value of the t-th environmental state vector; κ t represents the reference value of the t-th environmental state vector; T ′ represents the current system time; τ represents the time period parameter, which is used to adjust the impact of time fluctuations.
9. The Internet of Things device security authentication and data encrypted transmission system according to claim 1, characterized in that, The lightweight encryption component includes: The data chunking and encryption module is responsible for dividing the data to be transmitted into multiple fixed-size data chunks, and each data chunk is encrypted using a temporary key; the encryption process uses a lightweight encryption algorithm based on chaotic mapping to enhance the encryption intensity by introducing the randomness and unpredictability of the chaotic sequence; The hash protection module is responsible for generating a hash value for each encrypted data chunk using a lightweight hash algorithm based on non-linear transformation; Generate a unique hash value through multiple rounds of non-linear operations on the data chunk and the dynamic key for verifying the integrity of the data; The timestamp and random number embedding module is responsible for embedding the timestamp and random number in each data chunk. The timestamp is used to record the time when the data is generated, and the random number is used to increase the uniqueness of the data, which together with the encrypted data chunk and the hash value form a complete data packet.
10. A method for secure authentication and data encrypted transmission of Internet of Things devices, characterized in that, It includes the following steps: Authenticate the legal identity of the IoT device using a lightweight symmetric key and dynamically adjust the access permission according to the IoT device state and environment; dynamically adjust the permission according to factors such as device location, time, and network state; After passing the access permission authentication, the IoT device generates and distributes keys; the IoT devices use the key exchange protocol to exchange keys and implement local key management at the edge node in combination with edge computing; Transmit the data containing the keys and the key exchange protocol to the target device. When transmitting, use lightweight encryption and hash algorithms to encrypt the transmitted data, and use timestamps and random numbers to prevent replay attacks.
Citation Information
Patent Citations
Internet of Things data subscription method and device based on smart contract and medium
CN117857188A
Data acquisition method and system based on block chain and Internet of Things security chip
CN118316713A
Intelligent water affair Internet of Things data security encryption transmission system and method
CN119051967A
Cited By
Server data encryption method based on dynamic key exchange
CN120768701A
Server data encryption method based on dynamic key exchange
CN120768701B