Blockchain-based internet of things information security auditing system
By using a blockchain-based IoT information security audit system, the problem of isolated IoT data has been solved, enabling secure data transmission and storage, and enhancing data security and traceability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- WUHAN HONGXU INFORMATION TECH
- Filing Date
- 2022-02-14
- Publication Date
- 2026-04-10
AI Technical Summary
Existing IoT auditing platforms are unable to effectively conduct security audits, and IoT data exists in silos, resulting in a lack of security guarantees for data transmission, processing, and storage.
An IoT information security audit system based on blockchain is adopted, including the device layer, service layer and application layer. It uses blockchain technology for identity authentication, on-chain operations, access control and security auditing, and uses distributed ledger, smart contracts and hybrid encryption algorithms to ensure data security.
It enables secure transmission and storage of IoT data, preventing data loss, system failure, and data theft or tampering, thus improving data security and traceability.
Smart Images

Figure CN114528573B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of blockchain application, and particularly relates to an Internet of Things information security auditing system based on a blockchain. BACKGROUND
[0002] The Internet of Things is a product of another revolutionary development of the information industry, and the Internet of Things today is one of the important productive forces for promoting the rapid development of the economy. At the same time, due to the rapid development of information technology, the Internet of Things promotes social development and facilitates people's lives, but also brings some security risks.
[0003] Much of the data collected by devices in the Internet of Things is sensitive data, and from the perspective of business or management supervision, the corresponding transmission, processing and storage of data need to be operated in a secure environment. Under the existing traditional Internet of Things auditing platform, Internet of Things data exists in an isolated manner and cannot be effectively audited. SUMMARY
[0004] In view of the problems in the prior art, an Internet of Things information security auditing system based on a blockchain is provided.
[0005] The present application provides an Internet of Things information security auditing system based on a blockchain, comprising a device layer, a service layer, an application layer and a system server interface.
[0006] The device layer is configured to collect Internet of Things information through an Internet of Things device and upload the Internet of Things information to the service layer.
[0007] The service layer is configured to perform identity authentication on the Internet of Things information based on a blockchain, perform a chain operation on the Internet of Things information if the identity authentication is passed, and perform access control on the Internet of Things information on the blockchain in the form of a blockchain transaction.
[0008] The application layer is configured to track the Internet of Things information on the blockchain and verify whether the Internet of Things information is secure.
[0009] The system server interface is configured to provide an operation interface for participants of the blockchain.
[0010] According to the Internet of Things information security auditing system based on a blockchain, the service layer is configured to record the digital certificate and public key of the Internet of Things device in a distributed ledger, and perform identity authentication on the Internet of Things information according to the digital certificate and public key of the Internet of Things device.
[0011] According to the application, a blockchain-based Internet of Things information security auditing system is provided, wherein the service layer is configured to perform a hash operation on a timestamp corresponding to the Internet of Things information, a user credential, a random number, and a hash value of a previous block of a block to which the Internet of Things information is to be stored, and generate the digital certificate.
[0012] According to the application, a blockchain-based Internet of Things information security auditing system is provided, wherein each block in the blockchain comprises a block header and a block body.
[0013] The block header comprises a timestamp corresponding to the Internet of Things information, a user credential, a random number, and a hash value of a previous block of each block.
[0014] The block body comprises an ID, location information, and device status of the Internet of Things device.
[0015] According to the application, a blockchain-based Internet of Things information security auditing system is provided, wherein the service layer is configured to:
[0016] The private key of the sender of the Internet of Things information in the blockchain and the public key of the receiver are stored in the cloud, and the public key of the sender and the private key of the receiver are stored in the cloud.
[0017] The public key of the sender is obtained from the cloud to encrypt the Internet of Things information on the block of the sender, and the private key of the sender is obtained from the cloud to decrypt the Internet of Things information on the block of the sender.
[0018] The public key of the receiver is obtained from the cloud to encrypt the Internet of Things information on the block of the receiver, and the private key of the receiver is obtained from the cloud to decrypt the Internet of Things information on the block of the receiver.
[0019] According to the application, a blockchain-based Internet of Things information security auditing system is provided, wherein the service layer is configured to generate the private key of the sender according to the user credential and the random number on the block of the sender, and generate the public key of the sender according to the user credential and the private key corresponding to the sender.
[0020] The private key of the receiver is generated according to the user credential and the random number on the block of the receiver, and the public key of the receiver is generated according to the user credential and the private key corresponding to the receiver.
[0021] According to the application, a blockchain-based Internet of Things information security auditing system is provided, wherein the application layer is configured to calculate a hash value of a previous block of each block, compare the calculated hash value of the previous block of each block with the hash value of the previous block in each block, and verify whether the Internet of Things information is secure according to the comparison result.
[0022] The application provides a blockchain-based Internet of Things information security auditing system, and the service layer is used for accessing the Internet of Things information on the blockchain by using a smart contract access control strategy.
[0023] The application provides a blockchain-based Internet of Things information security auditing system, and the Internet of Things device comprises one or more of a concentration detection device, a temperature and humidity detection device, a smoke detection device, an illumination intensity detection device, a monitoring probe device and a GPS positioning device.
[0024] The application provides a blockchain-based Internet of Things information security auditing system, and the system server interface adopts a RESTful interface.
[0025] The application provides a blockchain-based Internet of Things information security auditing system, which collects, authenticates, chains, access controls and security audits the Internet of Things information through the device layer, the service layer, the application layer and the system server interface, and performs the security auditing of the Internet of Things information based on the blockchain technology, so that the data loss caused by misoperation is avoided, the whole system is not paralyzed due to the invalidity of the central node, and the data is not stolen or even tampered due to the operation permission problem, and the safety of the data is improved. BRIEF DESCRIPTION OF DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0027] Figure 1 It is a structure schematic diagram of the blockchain-based Internet of Things information security auditing system provided by the application.
[0028] Figure 2 It is a structure schematic diagram of the blockchain in the blockchain-based Internet of Things information security auditing system provided by the application. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical solutions and advantages of the application more clear, the technical solutions in the application will be clearly and completely described below in combination with the drawings in the application. Obviously, the described embodiments are some embodiments of the application, rather than all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the application.
[0030] The following will be described in combination with Figure 1The application discloses a blockchain-based Internet of Things information security audit system, which comprises a device layer 10, a service layer 20, an application layer 30 and a system server interface 40.
[0031] The device layer 10 is used for collecting Internet of Things information through Internet of Things devices and uploading the Internet of Things information to the service layer.
[0032] The device layer 10 mainly utilizes Radio Frequency Identification (RFID), infrared sensors, global positioning systems and other Internet of Things devices to connect all articles and the Internet according to an agreed communication transmission protocol, and to exchange and communicate information. The intelligent identification, positioning, tracking, monitoring and management Internet of Things information is uploaded to the service layer.
[0033] The service layer 20 is used for identity authentication of the Internet of Things information based on a blockchain, and in the case that the identity authentication is passed, the Internet of Things information is chained and accessed in the form of a blockchain transaction.
[0034] The blockchain has the characteristics of decentralization, non-tamperability and traceability, and can realize all Internet of Things data interconnection, traceability and sharing. The service layer 20 utilizes the blockchain technology to realize the identity authentication and access control functions, and provides a secure basis for data authentication and use. In the case that the identity authentication is passed, the registration of the Internet of Things devices, the reporting of LBS (Location Based Service) and the uploading of the device state logs are realized in the form of a blockchain transaction.
[0035] The service layer 20 applies the access control strategy based on the blockchain to create, manage and execute the access control strategy and the permission.
[0036] The application layer 30 is used for tracking the Internet of Things information on the blockchain and verifying whether the Internet of Things information is safe.
[0037] The application layer 30 is used for cloud computing services, security audit and early warning applications. The security data in the blockchain is subjected to information processing, and the cloud computing service based on the blockchain technology is provided. The security audit and early warning strategy is based on the blockchain technology, and the data tracking strategy is added to the programmable smart contract, so that the data source and the data processing process are automatically tracked.
[0038] After the whole life cycle data from the source to the use is acquired, the security audit report is generated by real-time analysis of the log information, the attack behavior of an attacker on the system can be found, the security threat situation is evaluated and analyzed by using data fusion, data mining, intelligent analysis and visualization technology, and timely early warning and active vulnerability repair are realized.
[0039] The system server interface 40 is configured to provide an operation interface for participants of the blockchain.
[0040] The system server interface is configured to facilitate the operation of each participant of the blockchain, and to realize the collection, storage and use of data.
[0041] In the embodiment, the device layer, the service layer, the application layer and the system server interface are used to collect, authenticate, chain, access control and security audit the Internet of Things information, and the security audit of the Internet of Things information is performed based on the blockchain technology. As a result, data loss caused by misoperation, system paralysis caused by the invalidity of a central node, and data theft or tampering caused by operation permission problems can be avoided, and the security of data is improved.
[0042] On the basis of the above embodiment, the service layer is configured to record the digital certificate and the public key of the Internet of Things device through a distributed ledger, and to perform identity authentication on the Internet of Things information according to the digital certificate and the public key of the Internet of Things device.
[0043] The service layer records the digital certificate and the public key through a distributed ledger based on the identity authentication strategy of the blockchain technology. Alternatively, the digital certificate submitted by the device layer is compared with the digital certificate generated by the service layer, and the public key of the Internet of Things device submitted by the device layer is compared with the public key of the Internet of Things device pre-stored in the service layer. If the digital certificate and the public key are consistent, the identity authentication is passed, and the Internet of Things information collected by the Internet of Things device is chained; otherwise, the identity authentication is not passed, and the Internet of Things information collected by the Internet of Things device is not chained.
[0044] On the basis of the above embodiment, the service layer is configured to perform a hash operation on a timestamp corresponding to the Internet of Things information, a user credential, a random number and a hash value of a previous block of a block to which the Internet of Things information is to be stored, to generate the digital certificate.
[0045] The timestamp corresponding to the Internet of Things information refers to the time at which the service layer receives the Internet of Things information, the user credential refers to a credential for whether the Internet of Things information collected by the Internet of Things device can be chained, and the random number is generated by a random number generator. The previous block refers to a block in which the Internet of Things information is most recently stored.
[0046] The service layer performs a hash operation on the timestamp corresponding to the Internet of Things information, the user credential, the random number and the hash value of the previous block based on the blockchain. The digital certificate is generated according to the hash operation result of the timestamp, the user credential, the random number and the hash value. For example, the hash operation result of the timestamp, the user credential, the random number and the hash value is spliced to obtain the digital certificate.
[0047] On the basis of the above embodiment,Figure 2 As shown, each block in the blockchain includes a block header and a block body; the block header includes a timestamp, a user credential, a random number and a hash value of the previous block of each block corresponding to the Internet of Things information; and the block body includes an ID, location information and device status of the Internet of Things device.
[0048] Specifically, the information of the block header is used for identity authentication, and a digital certificate corresponding to the Internet of Things information is generated according to the information of the block header. The attribute information of the physical network device is stored in the block body. By using the distributed and decentralized blockchain, single point failure can be avoided, and the process of establishing a channel with the authentication center is also saved. By using the traceability of the blockchain, the whole life cycle management of the Internet of Things device identity generation, authentication, use and cancellation is realized.
[0049] On the basis of the above-mentioned embodiments, the service layer in this embodiment is configured to: store a private key of a sender of the Internet of Things information in the blockchain and a public key of a receiver in the cloud; and store a public key of the sender and a private key of the receiver in the cloud.
[0050] Since the information of each node in the blockchain is synchronized, when the Internet of Things information of a certain Internet of Things device is chained, the node corresponding to the Internet of Things device as the sender will send the Internet of Things information to other nodes in the blockchain, and the other nodes as the receivers.
[0051] Optionally, in order to guarantee the security of data, the private key of the sender and the public key of the receiver are encrypted and combined to generate a corresponding security key. The public key of the sender and the private key of the receiver are encrypted and combined to generate a corresponding security key. The security key is sent to the cloud. By combining the two keys, the public key and the private key of the sender and the public key and the private key of the receiver are obtained through key pair exchange between the cloud storage layers, so that a higher security level is obtained.
[0052] The public key of the sender is obtained from the cloud to encrypt the Internet of Things information on the block of the sender, and the private key of the sender is obtained from the cloud to decrypt the Internet of Things information on the block of the sender.
[0053] When the Internet of Things information on the block of the sender is encrypted and decrypted, the public key and the private key of the sender are obtained from the combined key pair in the cloud.
[0054] The public key of the receiver is obtained from the cloud to encrypt the Internet of Things information on the block of the receiver, and the private key of the receiver is obtained from the cloud to decrypt the Internet of Things information on the block of the receiver.
[0055] When the IoT information on the block of the receiver is encrypted and decrypted, the public key and the private key of the receiver are obtained from the merged key pair in the cloud.
[0056] The hybrid encryption algorithm based on the blockchain adopted by the service layer in this embodiment guarantees the confidentiality of the data and enhances the security of the generated key pair, making it difficult to be cracked and read by the cloud provider or other attackers.
[0057] On the basis of the above-mentioned embodiments, the service layer in this embodiment is configured to generate the private key of the sender according to the user credential and the random number on the block of the sender, and generate the public key of the sender according to the user credential and the private key corresponding to the sender.
[0058] First, a hash value of a private key is generated using the SHA256 hash algorithm; then the generated hash value is sent as a random number generator seed to generate a random number; and finally, a private key is generated according to the user credential and the random number. The user credential and the random number can be spliced to obtain the private key after being calculated using a symmetric algorithm. The user credential and the private key can be spliced to obtain the public key after being calculated using a symmetric algorithm.
[0059] The private key and the public key of the receiver are obtained in the same way as the private key and the public key of the sender.
[0060] The private key and the public key of the receiver are obtained in the same way as the private key and the public key of the sender.
[0061] In this embodiment, the private key and the public key of the receiver and the sender are obtained through the user credential, which greatly enhances the security of the generated key pair, making it difficult to be cracked and read by the cloud provider or other attackers.
[0062] On the basis of the above-mentioned embodiments, the application layer in this embodiment is configured to calculate the hash value of the previous block of each block, compare the calculated hash value of the previous block of each block with the hash value of the previous block in each block, and verify whether the IoT information is safe according to the comparison result.
[0063] According to the comparison between the hash value of the previous block in each block and the hash value of the actual previous block of each block, if the two are consistent, it means that the block has not been lost, and the block is normal, and the method continues to trace the previous block of the previous block; if the two are inconsistent, it means that the block has been lost or changed, and the data is abnormal, and the tracing is stopped, and a data abnormality alarm is given.
[0064] On the basis of the above-mentioned embodiments, the service layer in this embodiment is configured to access the IoT information on the blockchain according to the access control policy of the smart contract.
[0065] Specifically, the service layer builds an access control system based on a blockchain, which combines concepts related to transactions in the blockchain with users, devices, permissions, attributes, and environments in traditional Internet of Things access control, creates, manages, and executes access control policies and permissions in the form of blockchain transactions, encodes access control rules in an automatically executable format using a smart contract, performs automated permission management, prevents illegal user intrusion, only allows legal users to access system resources according to their access control policies, and prevents fraudulent denial of permissions granted by the policy. The blockchain records the entire life cycle of the access control policy and permission from creation to transfer, and on this basis, distributed, traceable, and tamper-proof security log auditing can be performed.
[0066] On the basis of the above-mentioned embodiments, the Internet of Things device in the present embodiment comprises one or more of a concentration detection device, a temperature and humidity detection device, a smoke detection device, an illumination intensity detection device, a monitoring probe device, and a GPS (Global Positioning System) positioning device.
[0067] The device layer comprises a plurality of different kinds of data detection devices and corresponding device gateways. The Internet of Things device is a sensing detection device, which is used to identify and sense various detection objects and collect corresponding data information.
[0068] On the basis of the above-mentioned embodiments, the system server interface in the present embodiment is a RESTful interface.
[0069] The system server interface adopts a RESTful interface with high universality. The RESTful interface is a lightweight interface and is resource-oriented, which is self-explanatory. Its data description is simple, and it generally uses XML and JSON for data exchange. It can reduce the version granularity of services and the coupling of consumers to the internal implementation details of services.
[0070] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A blockchain-based information security auditing system for Internet of Things, characterized in that, The system comprises a device layer, a service layer, an application layer and a system server interface; The device layer is configured to collect Internet of Things information through an Internet of Things device and upload the Internet of Things information to the service layer; The service layer is configured to perform identity authentication on the Internet of Things information based on a blockchain, including: The distributed ledger records the digital certificate and the public key of the Internet of Things device, compares the digital certificate submitted by the device layer with the digital certificate generated by the service layer, compares the public key of the Internet of Things device submitted by the device layer with the public key of the Internet of Things device pre-stored in the service layer, and if the digital certificate and the public key are consistent, the identity authentication is passed; In the case of passing the identity authentication, the Internet of Things information is chained and the access control of the Internet of Things information on the blockchain is performed in the form of a blockchain transaction; The service layer is configured to generate a first hash value of a private key of a sender of the Internet of Things information and a second hash value of a private key of a receiver of the Internet of Things information using a SHA256 hash algorithm respectively; The first hash value and the second hash value are sent as seeds of random number senders to generate a first random number and a second random number respectively; The private key of the sender is generated by calculating and splicing the user credentials on the block of the sender and the first random number based on a symmetric algorithm, and the public key of the sender is generated by calculating and splicing the user credentials and the private key corresponding to the sender based on the symmetric algorithm; The private key of the receiver is generated by calculating and splicing the user credentials on the block of the receiver and the second random number based on a symmetric algorithm, and the public key of the receiver is generated by calculating and splicing the user credentials and the private key corresponding to the receiver based on the symmetric algorithm; The application layer is configured to track the Internet of Things information on the blockchain and verify whether the Internet of Things information is safe, including: The hash value of the previous block of each block is calculated, the calculated hash value of the previous block of each block is compared with the hash value of the previous block in each block, and whether the Internet of Things information is safe is verified according to the comparison result; The system server interface is configured to provide an operation interface for participants of the blockchain. 2.The blockchain-based IoT information security auditing system of claim 1, wherein, The service layer is configured to perform hash operation on the timestamp corresponding to the Internet of Things information, the user credentials, the random number and the hash value of the previous block of the block to which the Internet of Things information is to be stored, and generate the digital certificate. 3.The blockchain-based IoT information security auditing system of claim 2, wherein, Each block in the blockchain comprises a block header and a block body; The block header comprises the timestamp corresponding to the Internet of Things information, the user credentials, the random number and the hash value of the previous block of each block; The block body comprises the ID, location information and device state of the Internet of Things device. 4.The blockchain-based IoT information security auditing system of claim 3, wherein, The service layer is configured to: merge and store the private key of the sender of the Internet of Things information and the public key of the receiver of the Internet of Things information in the cloud, and merge and store the public key of the sender and the private key of the receiver in the cloud; The public key of the sender is obtained from the cloud to encrypt the Internet of Things information on the block of the sender, and the private key of the sender is obtained from the cloud to decrypt the Internet of Things information on the block of the sender. The public key of the receiver is obtained from the cloud to encrypt the Internet of Things information on the block of the receiver, and the private key of the receiver is obtained from the cloud to decrypt the Internet of Things information on the block of the receiver. 5.The blockchain-based IoT information security auditing system of any one of claims 1-4, wherein, The service layer is configured to access the Internet of Things information on the blockchain according to an access control policy of a smart contract. 6.The blockchain-based IoT information security auditing system of any one of claims 1-4, wherein, The Internet of Things device comprises one or more of a concentration detection device, a temperature and humidity detection device, a smoke detection device, an illumination intensity detection device, a monitoring probe device, and a GPS positioning device.
7. The blockchain-based IoT information security auditing system according to any one of claims 1-4, wherein, The system server interface adopts a RESTful interface.
Citation Information
Patent Citations
Block chain-based method for accessing power Internet of Things terminal
CN109495516A
Internet of Things service architecture based on lightweight block chain nodes
CN110099055A
Collaborative fine-grained access control method based on block chain
CN111147460A