A trust measurement and remote attestation method and system for the perception layer of the Internet of Things
By establishing a trusted metric model of static and dynamic parameters at the IoT perception layer, combining the weight calculation and group signature technology of different networking modes, the trusted metric and remote proof problems of the IoT perception layer are solved, and multi-dimensional, fine-grained evaluation and security guarantee for perception nodes are achieved.
Patent Information
- Application Number
- CN202210486938.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-06
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2042-05-06
AI Technical Summary
The existing IoT perception layer trusted metric model cannot meet the needs of heterogeneity, large-scaleness and dynamics, has high computational complexity, and cannot effectively protect the privacy information of the perception nodes and resist complex attacks.
A trustworthy metric model is established based on the static and dynamic parameters of the perceived node. Through weight calculations under different networking modes, a comprehensive evaluation of static trustworthy metric values, dynamic trustworthy metric values and energy trustworthy values is realized, and a trustworthy proof is performed through group signatures and anonymous analysis to ensure the security and privacy protection of the perceived nodes.
It realizes multi-dimensional, fine-grained credible measurements of IoT perception layer nodes, ensures the trustworthiness and security of the data source, reduces the computational complexity, improves the network's resistance to attacks and dynamic adaptability, and protects the privacy of perceived data.
Smart Images

Figure CN114900294B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of trusted computing, and more specifically, to a trust measurement and remote attestation method and system for an Internet of Things perception layer. Background Art
[0002] The Internet of Things (IoT) is a complex network of interconnected physical objects (so-called "things"). It serves as a bridge between the real world and the digital world. It uses technologies such as radio frequency identification, sensors, and global positioning to model information about the physical world, and relies on various communication infrastructures to facilitate the exchange of data. The IoT's unique characteristics enable its application in virtually all human activities. Through the IoT, people can achieve more sophisticated management of industrial and agricultural production, as well as social life. Therefore, research into the theory and application of the IoT is crucial for the future development of my country's industrial manufacturing, information industry, and even modern agriculture.
[0003] To improve IoT security and reduce resource consumption for monitoring and prevention at the IoT's perception layer, further research is needed on trustworthy measurement models applicable to IoT sensor nodes. However, current research in this area is still in its early stages and faces numerous challenges. Trustworthy operation of perception-layer nodes is the cornerstone for secure data transmission between nodes, and research on measurement models applicable to the IoT's perception layer is crucial. However, existing research has largely focused on addressing trust issues within the IoT within specific application scenarios. In current IoT environments, research on trustworthy measurement models for sensor nodes primarily relies on their previous behavior, historical state, and behavioral data.
[0004] However, existing research on IoT trust models primarily focuses on addressing trust issues within specific application scenarios. Furthermore, most trust models are divorced from the real-world context of the IoT and fail to fully consider the limited and highly variable computing and storage capabilities of IoT devices, rendering these measurement models incapable of direct application to the IoT. Furthermore, existing trust measurement models for perception-layer nodes are almost always designed based on prior behavioral data. However, this measurement process fails to comprehensively consider subjective judgment and objective evaluation, nor does it integrate static and dynamic trust metrics. Furthermore, current trust measurement models are insufficient for the heterogeneous, large-scale, and dynamic nature of IoT perception networks. Finally, current trust measurement models suffer from high computational complexity, making them unsuitable for the IoT perception layer, where computing power and resources are limited.
[0005] Trusted computing is the process of incorporating certain features of closed, proprietary systems into open systems. Trusted computing incorporates mechanisms and components in hardware and software that can check and enforce system integrity and allow authentication to remote systems. System trustworthiness can be achieved through attestation, which allows trust to be established in untrusted environments. Therefore, trusted remote attestation is one of the most important issues in trusted computing. Remote attestation refers to the process of proving the trustworthiness of an unknown entity without physical contact. It is a core function of a trusted computing platform, whereby a trusted computing platform verifies its identity and operational status through external attestation requests. In the IoT context, compared to identity authentication, this process not only authenticates the identity of IoT entities and the platform, but also ensures IoT security by monitoring the platform's runtime security.
[0006] At present, remote attestation of trusted computing platforms mainly includes attestation of platform identity, attestation of platform configuration environment and attestation of platform runtime environment. Attestation of platform identity can confirm the reliability of the other party's identity through anonymous attestation. To prove the trustworthiness of the platform configuration environment, it is only necessary to prove the trustworthiness of the platform configuration register. The trusted platform module digitally signs the PCR value, so that the integrity of the platform environment can be measured. To prove the trustworthiness of the platform runtime environment, (1) platform hardware (2) platform software (3) platform firmware (4) operating system (5) upper application platform can be proved respectively. In the field of trusted computing, remote attestation mainly includes three parties: trusted computing platform, trusted third party and remote verification party. The platform that provides trusted security mechanism and trusted service in remote attestation computer system is a trusted computing platform. This platform mainly ensures the security of the system by building a trust chain through a trusted trust root. In the remote attestation process, it is mainly through the integrity measurement and reporting of the entity, and then using its own trusted root to sign the information to be proved. The remote verifier refers to the party requesting the certificate. It can initiate a certificate request to the trusted computing platform. After receiving the report from the trusted computing platform, it will verify the integrity log and signature of the platform. The trusted third party is mainly responsible for issuing, verifying, and revoking certificates to prevent the trusted computing platform and the remote verifier from deceiving by forging identities.
[0007] IoT terminals typically sense, process, and transmit sensory information, which often contains sensitive data and is therefore highly susceptible to malicious attacks. To verify that a terminal is secure, the integrity of its underlying devices must be ensured. Remote attestation allows remote verification devices to authenticate the source of data. This technology is a key security mechanism that emerged as trusted computing technology extends to the IoT. It offers many advantages over existing identity authentication mechanisms, which can only provide simple authentication but are unable to authenticate the attributes and behaviors of the entire computing platform. Furthermore, these mechanisms are incapable of resisting platform identity attacks, forgery attacks, collusion attacks, and other attacks. Remote attestation, however, allows verification of information accuracy and integrity, and allows the remote verifier to authenticate the entire platform during interaction and verify its trusted state.
[0008] However, the core mission of the Internet of Things (IoT) is to collect, transmit, and process data. The IoT's perception layer is heterogeneous and complex, and the trustworthiness of the source of perception data directly impacts the security of the entire IoT. Furthermore, as IoT applications expand, especially with increasingly sophisticated sensor technology, the amount of perception data generated is exploding. However, current trustworthy measurement models for IoT perception nodes and remote attestation mechanisms for the IoT perception layer have yet to fundamentally address these challenges, such as how to perform multi-dimensional, fine-grained static and dynamic measurements of perception nodes and how to effectively protect the privacy of attestation nodes. Therefore, research is needed on trustworthy measurement models for IoT perception nodes and remote attestation schemes for data provenance within the IoT perception layer.
[0009] To address the above issues, there is an urgent need for a trust measurement and remote proof method and system for the perception layer of the Internet of Things. Summary of the Invention
[0010] To address the shortcomings of the existing technology, the present invention aims to provide a trust measurement and remote attestation method and system for the perception layer of the Internet of Things. This method implements the calculation of static trust measurement values, dynamic trust measurement values, and energy trust values in different ways, based on the different networking modes of the perception layer of the Internet of Things. This method thus enables the grouping of node trust logic and the remote acquisition of trust attestation.
[0011] The present invention adopts the following technical solutions.
[0012] The first aspect of the present invention relates to a trust measurement and remote certification method for the perception layer of the Internet of Things. The method includes the following steps: Step 1, establishing a trust measurement model based on the static parameters and dynamic parameters of the perception nodes in the perception layer, and obtaining the weights of different trust measurement models based on measurement time and information entropy in different networking modes of the perception layer of the Internet of Things to achieve the solution of the comprehensive trust value; Step 2, using the comprehensive trust value and the energy trust value of the perception node to perform trustworthy logical grouping on the perception nodes; Step 3, generating a group signature of the perception node through a dynamically updated key, and achieving trustworthy certification of the perception node from a remote node based on unforgeability analysis and anonymity analysis.
[0013] Preferably, the networking modes of the Internet of Things perception layer include a centralized networking mode and a distributed networking mode.
[0014] Preferably, the trust measurement model includes a static trust measurement model and a dynamic trust measurement model.
[0015] Preferably, in the centralized networking mode, the static trust measurement model of the perception node includes a physical attribute trust evaluation model, a hardware attribute trust evaluation model, a software attribute trust evaluation model, a network attribute trust evaluation model and a static attribute trust measurement model.
[0016] Preferably, in the distributed networking mode, the dynamic trust measurement model of the perception node is a weighted sum of bidirectional static measurement values between the perception node and other nodes in the perception layer of the Internet of Things.
[0017] Preferably, in a distributed network, the one-way static metric between the sensing node and any other node in the IoT sensing layer is the access right pr of any other node to the sensing node for the current process of the sensing node. i , the weighted sum of the intersection of the two, the allowed access rights pu of any one of the other nodes in the perception node for the current process of the perception node; wherein, i is the number of all processes between the perception node and any other node; the weighted sum of the intersection of the two includes all processes between the perception node and any other node.
[0018] Preferably, the weight of the weighted sum of the intersection of the two is the derivative of the number of all processes of the perception node with respect to other current nodes.
[0019] Preferably, in the centralized networking mode, the dynamic trust measurement model of the perception node includes a data packet forwarding rate trust measurement model, a data packet repetition rate trust measurement model, a data packet delay trust measurement model, a data forwarding traffic trust measurement model, a node channel state trust measurement model, and a dynamic attribute comprehensive trust measurement model.
[0020] Preferably, in the distributed networking mode, the dynamic trust measurement model of the sensing node includes a direct trust measurement model and a recommended trust measurement model.
[0021] The second aspect of the present invention relates to a trust measurement and remote certification system for the perception layer of the Internet of Things, wherein the system is implemented using the trust measurement and remote certification method for the perception layer of the Internet of Things described in the first aspect of the present invention.
[0022] The beneficial effect of the present invention is that, compared with the prior art, the trust measurement and remote attestation method and system of the perception layer of the Internet of Things in the present invention can propose a multi-faceted and fine-grained trust measurement model suitable for perception nodes for the perception layer of the Internet of Things. In order to solve the problem that the current model cannot meet the current status of the Internet of Things and lacks objectivity and dynamism, a corresponding trust measurement model is constructed in the centralized and distributed modes of the perception layer. Then, according to the measurement results of the perception nodes, a trusted logical grouping is performed to construct a trusted group with different trust levels, thereby ensuring the safe operation of the perception layer nodes. Secondly, based on the trusted logical grouping of the perception layer and for the centralized networking mode, a trusted attestation of the perception data source is realized through a remote attestation mechanism based on group signatures. This mechanism can effectively ensure the credibility of the data source without leaking the privacy of the data source. It can also achieve traceability when the remote node does not trust the other party. Experimental simulation shows that this mechanism has high operating efficiency and low computing performance consumption, and can effectively verify the status of the perception data source. For the distributed networking mode, the trusted proof of data source is achieved through threshold ring signature technology. This scheme has anonymity and unforgeability. Experimental simulation shows that this mechanism meets good anti-attack and network dynamic adaptability, and can ensure the secure transmission of perception data. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 This is a schematic diagram of the steps of a trust measurement and remote attestation method for the perception layer of the Internet of Things in this application;
[0024] Figure 2 The trusted node rate of this application when malicious nodes account for 5%;
[0025] Figure 3 The trusted node rate of this application when malicious nodes account for 15%;
[0026] Figure 4 The trusted data rate of this application when malicious nodes account for 5%;
[0027] Figure 5 The trusted data rate of this application when malicious nodes account for 15%;
[0028] Figure 6 The energy surplus rate for this application;
[0029] Figure 7 The success rate of trusted interaction in a perception network with low node interaction frequency in this application;
[0030] Figure 8 It is the success rate of trusted interaction in a perception network with high node interaction frequency in this application. DETAILED DESCRIPTION
[0031] The present application will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present application.
[0032] like Figure 1 As shown, a trust measurement and remote proof method for the perception layer of the Internet of Things includes the following steps: Step 1, establishing a trust measurement model based on the static parameters and dynamic parameters of the perception nodes in the perception layer, and obtaining the weights of different trust measurement models based on the measurement time and information entropy in different networking modes of the perception layer of the Internet of Things to achieve the solution of the comprehensive trust value; Step 2, using the comprehensive trust value and the energy trust value of the perception node to perform trustworthy logical grouping on the perception nodes; Step 3, generating a group signature of the perception node through a dynamically updated key, and achieving trustworthy proof of the perception node from a remote node based on unforgeability analysis and anonymity analysis.
[0033] As can be understood, this paper proposes a comprehensive trust measurement model for static and dynamic trustworthiness of perception nodes at the IoT perception layer. This model, based on static node measurement and centered on dynamic measurement, combines direct and recommended trust values to achieve a comprehensive measurement of perception nodes. This model objectively reflects the trustworthiness of nodes, effectively identifying malicious nodes and ensuring the overall security of the IoT perception layer.
[0034] Due to the heterogeneity of the perception layer of the Internet of Things, the trustworthiness measurement of different types of perception nodes needs to consider commonalities and characteristics. Generally, the trustworthiness measurement of perception nodes should include static attribute measurement and dynamic attribute measurement.
[0035] In a centralized model, the IoT perception layer typically consists of sensor nodes, cluster head nodes, and sink nodes. If a sensor node wishes to join a trusted node group, its superior node (the cluster head or sink node) must first ensure that the node's static attributes are trustworthy. Furthermore, before data can be exchanged between sensor nodes, the trustworthiness of both parties' static attributes must also be ensured. This is done by first verifying the static trustworthiness of the node and then by verifying its dynamic security through dynamic trustworthiness. (Because a node's static attributes are preset by the manufacturer and generally do not change, static attribute security does not guarantee node security; a comprehensive assessment of both dynamic and static attribute values is required.) This approach reflects the node's dynamic security. If the combined trustworthiness of a sensor node exceeds a threshold preset by the superior node, the node is allowed to join the group; otherwise, it is not allowed. Ultimately, through these layers of measurement, the trustworthiness of each node and the trusted logical network are guaranteed from the bottom up. In a distributed model, since nodes have similar computing power and resource sizes, each node can transmit data and make trustworthy decisions about its neighboring sensor nodes. In this model, due to the complexity of node dynamic behavior, each node exhibits significant differences in perceived data transmission rate, transmission latency, and packet loss. Determining a node's trustworthiness solely based on these dynamic attributes cannot fully and objectively reflect the node's true trustworthiness. Therefore, the trustworthiness of a perception node in this networking model is determined by combining a subjective direct trust value with an objective recommended trust value. To accurately and objectively measure the trustworthiness of perception layer nodes, we first need to abstract and formalize the different types of nodes in the perception layer. We then provide a detailed discussion of the trustworthiness measurement process for perception nodes in each of the two networking models.
[0036] Preferably, in the centralized networking mode, the static trust measurement model of the perception node includes a physical attribute trust evaluation model, a hardware attribute trust evaluation model, a software attribute trust evaluation model, a network attribute trust evaluation model and a static attribute trust measurement model.
[0037] It's understandable that the IoT's perception layer typically consists of three types of nodes: perception nodes, cluster head nodes, and sink nodes. Perception nodes generally refer to ordinary nodes without computing or network-carrying capabilities, and attacks against them are mostly physical. Cluster head nodes and sink nodes generally refer to nodes with computing and network-carrying capabilities. The abstract description model for heterogeneous nodes in the IoT studied in this paper focuses primarily on perception nodes, thus enabling a formalized abstraction of perception nodes.
[0038] First, the physical property description of the node can be implemented using PD = (nm, sd, md, wt, nf, sn, af, pk). This vector can be used as the unique physical identification information of the node. It usually consists of physical mass nm, appearance description sd, material description md, normal operating temperature wt, equipment manufacturer mf, production serial number sn, affiliated organization af and identity proof key pk.
[0039] Secondly, the intrinsic information attribute vector mainly describes the hardware and software information of the sensing node, which is usually composed of hardware information hw, operating system information and application ho, and network address na, and can be described by IA = (hw, ho, na). The task status attribute vector mainly describes the data carrying task of the sensing node, the node transmission status and the link status. It is usually composed of the requested data rd, the actual data sent sd, the node network available bandwidth tb, the node channel ch, the data required response time rt, and the actual data response time st. It can be described by NS = (rd, sd, tb, ch, rt, st). The operation status attribute vector mainly describes the dynamic change process of the operation status of the sensing node. Therefore, this vector should include: the node real-time trust metric value T, historical trust change information ht = (tr[1], tr[2], ..., tr[n-1]), the trust status valid time window Δt, where ht represents the set of historical trust metric values excluding the current trust metric value within the trust status valid time window, and the node energy state en, which can be described by SD = (T, th, Δt, en).
[0040] In summary, the formal description of a sensor node can be represented by the four-tuple ND = (PD, IA, NS, SD). Because sensor nodes, cluster heads, and sink nodes play different roles, their corresponding formal descriptions differ slightly. For example, with respect to the node task state description vector, sensor nodes focus solely on how to send data to the outside world, while cluster heads and sink nodes also focus on how data is forwarded. Furthermore, as superior nodes to sensor nodes, they must constantly monitor the status of the sensor node set in order to monitor it. Therefore, the following describes the node task state description vector and node set description vector for cluster heads and sink nodes, respectively. The descriptions of other attributes remain the same as for sensor nodes.
[0041] The task state attribute vector can be described by NS = (D, T, rd, sd, tb, ch, rt): where D = {d1, d2...dn} represents the data sent by the data aggregation node or cluster head node when requesting each ordinary node, T = {t1, t2...tn} represents the time when the data of each sensing node is sent to the data aggregation node or cluster head node, and the other definitions are the same as those of ordinary nodes.
[0042] The node set attribute vector can be described by S = (M, T). Since the cluster head node needs to perform trust measurement on the sensor node, it is necessary to maintain a list of trusted sensor nodes in the cluster head node. Similarly, a list of trusted cluster head nodes also needs to be maintained in the aggregation node, where M = (m1, m2.......mn) represents the sensor node and cluster head node (mi stores the basic hardware information of the node and the summary value of the operating system and key processes), and T = (t1, t2.......tn) represents the trust measurement value of each node.
[0043] For the centralized networking mode, the upper node (i.e., cluster head node) of the sensing node (a1, a2, ..., an) is defined as (aπ1, aπ2, ..., aπm). In this sensing node group, the sensing node must authenticate its static attributes (i.e., the node's own computing environment) to the upper node to ensure that it is secure and trustworthy. Assuming that the static attributes of the sensing node need to include its own physical attributes, hardware attributes, software attributes, and network attributes, the static attributes of the sensing node can be formally described as a four-tuple C = (P d ,Hw,Sh,Ne), where the physical properties are formalized as P d =(p0,p1,p2,...,pn), the hardware attributes are formalized into H w =(h0,h1,h2,...,hn), where h0 represents the characteristic value of its own information collection module and information calculation module, hi represents the characteristic value of its other hardware (such as motherboard, network card, etc.), software attributes are formalized as Sh=(s0,s1,s2,...,sn), s0 represents the characteristic value of its own operating system boot program, si represents the characteristic value of other common software (such as daemon process), network attributes are formalized as Ne=(ad,pa,c1,c2,...,cn), ad is the characteristic value of IP address, pa is the characteristic value of MAC address, c1,c2,...,cn are the characteristic values of network communication-related programs running on the node itself.
[0044] The upper node converts the quaternary C=(P d , Hw, Sh, Ne) measures the trust state of the static attributes of the sensing node ai according to the static attribute trust measurement function Mce(C). Due to the above description of the static attributes of the sensing node, the static attribute trust measurement function Mce(C) should be applied to the quaternary C = (P d ,Each static attribute in Hw, Sh, Ne) is measured one by one.
[0045] If pi′ is the physical attribute submitted by the sensing node to the cluster head node when the sensing network is in the initial state, the cluster head node will record and store this information. Therefore, the calculation process of the physical attribute trust evaluation function Mce[1](Pd) represents that the physical inherent information attribute of the sensing node cannot be changed. Because this attribute is the only physical identification feature of the sensing node, if it changes, it means that the node is likely to be attacked. Therefore, Mce[1](Pd) is expressed as follows:
[0046]
[0047] In addition, if h0′ and hi′ represent all hardware values transmitted when the sensing node performs initial registration and authenticates to the cluster head node, then the cluster head node records and stores this information in advance.
[0048] Mce[2](Hw) represents the critical hardware parts of the sensing node, such as the hardware of the information collection and computing module, which cannot be replaced. However, the non-critical parts {h1,h2,....hn} of the sensing node, such as the power supply, can be replaced. Whether the hardware can be replaced is determined by the corresponding security mechanism of the upper node. Therefore, Mce[2](Hw) can be expressed as follows:
[0049]
[0050] Third, the software attribute of the perception node is described as Sh = (s0, s1, s2, ..., sn), where s0 represents the operating system boot program, s1 represents the operating system kernel, s2 to sk represent the more important information collection and related applications, and s k+1 sn represents some non-critical applications of itself, so Mce[3](Sh) can be expressed as follows:
[0051]
[0052] In this function, si′ represents all software attribute information transmitted by the sensing node to the cluster head node during initialization. The upper node stores this information to achieve further trustworthiness. The above formula indicates that key programs such as the bootloader and operating system cannot be tampered with. If they are modified, the node is no longer trustworthy. However, other common applications may be deployed later. Therefore, this function has a certain degree of slack, which is confirmed by the upper node.
[0053] In addition, the network attribute trust evaluation function can be measured based on the node's network attribute Ne = (ad, pa, c1, c2, ..., ck), and it is stipulated that ad' and pa' are the network address information and physical address information of the common node recorded by the cluster head node. The function f(ci) represents the trust measurement of the relevant network process of the perception node, then Mce[4](Ne) is described as:
[0054]
[0055]
[0056] In the above function, ∑Log L(ci) represents the number of failed interactions of the upper node with the current interaction process in the perception node in the historical log. The measurement function of the interaction process calculates the trust value based on the success rate of the historical communication tasks.
[0057] For each trust metric function description of Mce[1](Pd), Mce[2](Hw), Mce[3](Sh) and Mce[4](Ne) above, the trust of each dimension of static attribute component can be obtained through trust metric. Therefore, the final perception node static attribute trust metric function Mce(C) can be calculated as follows:
[0058] Mce(C)=α1Mce[1](Pd)+α2Mce[2](Hw)+α3Mce[3](Sh)+α4Mce[4](Ne)
[0059] In the above formula, α1+α2+α3+α4=1, α1, α2, α3, and α4 represent weights. The weights need to be adjusted accordingly according to different perception layer networks. Generally, α1, α2, α3, and α4 are each taken as 1 / 4.
[0060] Preferably, in the distributed networking mode, the dynamic trust measurement model of the perception node is a weighted sum of bidirectional static measurement values between the perception node and other nodes in the perception layer of the Internet of Things.
[0061] The above describes a centralized perception layer networking model. For distributed networking models (such as the Internet of Vehicles and the Industrial Distributed Internet of Things), a population of perception nodes (a1, α2, ..., an) is defined. Any node ai in this population can measure the static attributes of the perception nodes it interacts with. Conversely, any node interacting with node ai can also perform trust measurements on it. Only when both parties have completed trust measurements of each other using their own trust policies can a bidirectional trusted connection be established, allowing subsequent communication. blt(ai, aj) can be defined as a bidirectional trust measurement function, using which any two perception nodes ai and aj can perform trust measurements on each other's static attributes. Therefore, in this networking model, the trust status of a perception node must be determined by comprehensively calculating the trust measurements of its static attributes from multiple perception nodes. Data exchange with the node is permitted only when the node is in a trusted state; otherwise, interaction is denied according to the node's respective policies.
[0062] According to the formal description of the sensing node above, the static attributes of any sensing node can be expressed by the four-tuple C = (P d , Hw, Sh, Ne). In this model, the interaction between the sensing nodes ai and aj is point-to-point, so the nodes should measure the communication process established between them and related to the interaction. Therefore, the trust measurement of the static attribute of aj by ai is expressed as:
[0063] Assume that the communication processes between ai and aj are {c1, c2, ..., cl} in sequence. It is now stipulated that {c1, c2, ..., cx} are processes in ai, and {cx+1, cx+2, ..., cl} are processes in aj. If the processes {cx+1, cx+2, ..., cl} in aj can successfully complete the communication and related operations, the permission set that must be satisfied is {prx+1, prx+2....prl}. Assume that the access rights that ai can allow to other processes are pu, then the trust measurement function fm(ai, aj) of ai to aj is expressed as follows:
[0064]
[0065] Correspondingly, if the set of permissions that processes c1, c2, ..., cx in ai must satisfy to complete communication and related operations is {pr1, pr2....prx}, and the access rights that aj can allow to other processes are pm, then the trust measurement function fm(aj, ai) of aj for ai is expressed as follows:
[0066]
[0067] Assume that a set of sensing nodes {aj,aj+1,...,ak} senses a at time t. i The set of bidirectional trust measurement results is {blt(ai,aj)[1],blt(ai,aj+1)[2],...,blt(ai,ak)[k]}, so {a j ,a j+1 ,...,a k} for sensor node a i The static trust measurement result of is finally expressed as:
[0068]
[0069] Because in the node group of this networking mode, not all nodes are exactly the same, some nodes have high credibility, while some nodes have low credibility, so it is necessary to increase the measurement weight of these high credibility nodes to other nodes. In the above formula (3-9), d(a j ) to adjust different nodes to a i The specific weight of the static metric, the weight function can be defined as:
[0070]
[0071] With the increasing adoption of IoT technology, the IoT's perception layer is becoming increasingly vulnerable to security threats such as data interception, tampering, and forgery. While traditional security mechanisms can mitigate some of these threats, they are unable to effectively address more complex attacks, such as collusion attacks. Generally speaking, if a sensing node within a group within the perception layer is attacked maliciously, resulting in network damage and tampering of received and transmitted data, the dynamic properties of the attacking sensing node will become abnormal. Therefore, in addition to static measurement of sensing nodes, trust assessment of their dynamic properties is also crucial for the secure operation of the perception layer.
[0072] In a centralized network of sensor nodes, if the cluster head or sink node cannot accurately measure the trustworthiness of its subordinate nodes, there is no way to effectively manage the sensor node population. Therefore, in addition to the static trustworthiness measurement functions of nodes in the previous section, this section introduces several representative dynamic attribute measurement functions for node data packet forwarding rate, repetition rate, transmission delay, forwarding flow, and channel status. By performing multi-dimensional dynamic trustworthiness measurement on sensor nodes, we can effectively reflect the dynamic changes in the trustworthiness of a sensor node.
[0073] Since the malicious attacks launched against the sensing nodes mainly include data theft, data tampering, data injection, etc., in order to monitor whether the node is attacked, the data packet forwarding rate becomes an important indicator to detect whether the sensing node is abnormal. π To the sensor node α i Request sd data group, but α i However, only rd (rd≤sd) data packets are transmitted, so through T dt (α π ,α i ,t) can calculate α π To α i The trusted values of this dynamic attribute are:
[0074]
[0075] When a sensing node is attacked, it may repeatedly forward data, so this dynamic attribute can effectively determine whether the node is normal. If the data packet repetition rate R is small, it means that the node is relatively trustworthy, but if the value of R continues to increase and is greater than or equal to the threshold of this attribute, it means that the node is likely to have been attacked. Therefore, through T dr (α π ,α i ,t) can calculate α π To α i The trusted values of this dynamic attribute are:
[0076]
[0077] Where δ>1, the size of β depends on the upper node α π .
[0078] When the sensing node forwards data to the upper node, the transmission delay d is rt-st. There may be time delays due to signal interference or force majeure factors, but the existence of normal delay must also be considered. Therefore, this dynamic attribute can fluctuate within a tolerable range. However, once it exceeds the normal range, it can be considered that the sensing node is likely to be attacked. If the transmission delay d is less than the threshold, the upper node can trust the sensing node; otherwise, the possibility of the node being untrustworthy will increase, and the trust value of this attribute will continue to decrease. Therefore, through T d (α π ,α i ,t) can calculate α π To α i The credible value of the data packet forwarding delay attribute is:
[0079]
[0080] Where α = 0.1, and the critical value γ depends on the specific IoT perception layer environment.
[0081] Since the data flow forwarded by the node in different states may be slightly different, for example, a sudden increase in data flow indicates that the node may be attacked, so when the sensing node transmits data to the superior node, the cluster head node α π The sensing node α can be i Perform dynamic measurement. Therefore, through T df (α π ,α i ,t) can calculate α π To α i The trusted values of the dynamic attributes of data forwarding traffic are:
[0082]
[0083] in the formula T s is α i The initial credibility value obtained during initialization. If the data flow rate transmitted by the sensing node is 0, it means that it has not yet interacted with the cluster head node. The credibility of the node is T s , Then, when the node transmission data traffic gradually increases, α i The credibility of the node will continue to increase, but there will be a threshold. When approaching the threshold, the credibility of the node will not continue to increase but will decrease. This critical value must be set based on the specific considerations of different IoT perception layers.
[0084] Perception node α i The trustworthy state of α is closely related to the running state of its own task. i The task state vector is expressed as NS = (rd, sd, tb, cb, rt), and the cluster head node α π According to α i The mathematical expectations of actual transmission data and transmission time during data forwarding are Then T ct (α π ,α i ,t) is calculated as follows:
[0085]
[0086] ε1+ε2=1, ch represents the node channel state, which indicates the reliability of the node communication channel per unit time. If no special instructions are given, ε1=ε2=1 / 2 can be taken, which means that the actual sent data and data delay have the same importance. π The threshold value of this attribute is specified as hs. If T ct (απ ,α i ,t)<hs, let T ct (α π ,α i ,t)=0, otherwise, T ct (α π ,α i ,t) is subject to the actual credible value. ct (α π ,α i The calculation process of t) reflects the requirements of different task states for data transmission volume and delay. For example, medical wearable devices may have extremely high requirements for data transmission volume and data delay. The value corresponding to hs will be very demanding.
[0087] In summary, in this networking mode, the above dynamic attribute measurement functions represent the upper node α at time t. π For sensor node α i The trusted evaluation values of each dynamic attribute of , now assume that during the Δt time period of (t-Δt, t), α i The data is forwarded n times in total, then within this time window, α π To α i The sum of each dynamic attribute credibility measure is {T1,T2.......T n}, then the dynamic attribute comprehensive trust metric value of the sensing node can be expressed as:
[0088]
[0089] In the above formula, It is an attenuation formula, which indicates that the dynamic credibility of the sensing node will decay over time. It can make the credibility measurement value of the dynamic attribute obtain a reasonable weight over time. υ is the attenuation speed factor, and the size of this parameter depends on the specific IoT perception environment.
[0090] In a distributed networking model, perception networks are dynamic, scalable, and complex. Furthermore, the distances between nodes often change, and communication is not entirely reliable. The trust measurement of static node attributes described above alone cannot guarantee node security. Therefore, dynamic measurement must be added to the static node measurement. Furthermore, direct trust is subjective and cannot accurately characterize the trustworthy state of nodes. To address these issues, we propose a comprehensive trust measurement model for this networking model. This model is based on static node measurement, centered on dynamic direct measurement, and referenced by dynamic recommended trust. This model ensures the comprehensiveness and objectivity of node trustworthiness. The dynamic trust measurement of perception nodes is divided into two parts: direct trust measurement and recommended trust measurement.
[0091] Direct trust is a perceiving node's subjective expectation of a target node's future behavior in a specific environment and at a specific time, based on its experience with other nodes. Typically, the trust relationship between nodes can be represented by the current interaction results and historical experience between them. Using corresponding trust calculation methods, the direct trust value between them can be calculated.
[0092] First, we define the interaction experience between nodes in the perception layer. This is the record of a node completing its data forwarding task when forwarding data in the perception layer. The interaction results are divided into two categories: success and failure. If we want to calculate the trust value of a node, each node needs to save a data interaction history table. This table is used to store its interactions with other nodes. The recorded data includes: the node's unique ID, the number of successful interactions x, the number of failed interactions y, and the trust value T. d And the trust update cycle T. Furthermore, to address the frequent trust value calculations caused by constant interactions between nodes and eliminate the uncertainty of the impact of short time periods on node trust values, T can be set to adjust when the trust calculation process between nodes occurs. Generally, Bayesian estimation can truly reflect the probability of future node behavior based on the historical behavior experience of a node. Therefore, Bayesian estimation can be used to calculate the probability of successful interaction between nodes. The mathematical expectation of the number of successful interactions between nodes is then used to represent their direct trust value.
[0093] Assume that at time (t0,t c ) range, node α i With α j There are z interactions between nodes, including x successful interactions and y failed interactions. If the probability of a successful interaction between nodes is θ, then the probability of successful interaction between nodes x times conforms to the binomial distribution and can be expressed as P(D|θ)=θ x (1-θ) y According to Bayesian theory, α i With α j The probability density function f(θ) of a successful interaction follows a β distribution with parameters (x+1,y+1), then α j To α i The direct trust between can be described as:
[0094]
[0095] And given so
[0096]
[0097] So E(θ) can be calculated based on f(θ):
[0098]
[0099] In summary, α i and α j The direct trust value between can be expressed as:
[0100]
[0101] In order to reduce the error caused by abnormal behavior due to factors such as weak communication signals or signal interference and improve the accuracy of node trust characterization, the node same service quality judgment index is designed To determine the overall performance of the node between measurement cycles, it can be used to punish untrustworthy nodes and reward trustworthy nodes. The formula is as follows:
[0102]
[0103] If the node generates untrusted services, then a=p, is the penalty factor of the node service; on the contrary, if the node generates a credible service, then a=r, Is the reward factor for node service. Each represents the number of untrustworthy and trustworthy behaviors generated by the node in a measurement period.
[0104] The above direct trust value is determined based on the historical interaction records between nodes. The trust value will decay over time. Usually, the behavior closest to the current moment can better reflect the accuracy, so the timeliness of the value also needs to be considered. When the interaction between nodes is completed, if node α j The resulting behavior is untrustworthy, so recalculate as well as On the contrary, if node α j The resulting behavior is credible, then recalculate as well as Finally, the direct trust value is obtained.
[0105] Among them, In, x h Represents α i To α j Historical trust records of credible behavior, in middle, y h Represents α i To α j Historical trust records of untrustworthy behavior, α / [α+(t c-t0)] is the time decay factor, and α is the rate adjustment factor. Through this trust decay function, the initial decay rate of direct trust can be smaller than that of the exponential function, which can better preserve the judgment of recent interactive behaviors on direct trust values.
[0106] Due to the large-scale, highly dynamic, and open nature of the IoT's perception layer, trust is often subjective and vulnerable to security threats and illegal attacks, which can turn honest recommenders into malicious ones. Therefore, obtaining accurate and objective trust in recommenders is challenging. The information provided by recommenders often has the following potential outcomes: correct recommendations from honest and reliable nodes, incorrect recommendations from dishonest and reliable nodes, and malicious recommendations from attacked nodes. Therefore, a trust function that aims to provide reliable recommendations must address multiple trust issues through trust merging rules. This function should be able to correctly distinguish between malicious and fair recommendations from nodes.
[0107] In this paper, a certain sensor node α i The similarity between the recommended trust values of each node within the communication range and the average recommended trust value is used as the weight. If the recommended trust value given by a node is very different from the average trust expectation value, the weight of the final result of this node should be adjusted to make it smaller, because this node has an abnormal situation of malicious slander. The first step is to get the average value of all recommended trusts. Assume that for the perception node α i The total recommended trust value sequence is {m r1 ,m r2 ,...,m rk}, then the mathematical expectation of recommendation trust is calculated as follows:
[0108]
[0109] The weight of each recommendation trust can be calculated using the Euclidean space distance similarity method. The specific calculation method is as follows:
[0110]
[0111] Therefore, according to the recommendation trust sequence and the weight of each recommendation trust, the perception node α i The recommendation trust calculation can be calculated as follows:
[0112]
[0113] In order to make the perceptual node α iThe final measurement result is objective and accurate. The credibility of static and dynamic attributes must be fully considered. The reason is that the credibility of the static attributes of a node does not mean that its dynamic attributes are also credible. However, if the static attributes of a node are unreliable, there is no need to perform dynamic measurement, because the static credibility of a node is the premise of the node being in a safe state. Therefore, in this mode, for the range of (t-Δt, t) for α i The credibility measurement result can be calculated as follows:
[0114]
[0115] In the above formula, It means that within the Δt time window, the earlier the node is comprehensively measured, the greater the proportion of the credibility value of the node's static attributes. It is obvious that the static attribute credibility of a perception node accounts for the largest proportion at the initial moment, but as time goes by, the dynamic attribute credibility will account for an increasingly larger proportion.
[0116] According to their respective metric functions, we know that node α i Direct trust value and recommended trust value In order to objectively and comprehensively measure the trustworthiness of the node, the two must be calculated comprehensively. Therefore, the weights of the two trust values in the comprehensive trust value must be calculated. However, the commonly used methods for determining weights are: average weight method, expert experience method, and judgment based on simulation experiment results. These methods are too subjective and cannot accurately reflect the actual measurement results. Moreover, once these coefficients are determined, it is difficult to adjust them dynamically, which runs counter to the concepts of dynamic and adaptive nature of the IoT perception layer.
[0117] For this purpose, information entropy is used, which can represent the degree of disorder of information, can resolve uncertainty, and has the characteristics of monotonicity, non-negativity and accumulation. According to the definition of information entropy, the information entropy of a discrete random variable X can be expressed as: Then according to its definition, the information entropy of the direct trust value Information entropy and recommendation trust value It can be calculated by the following formula:
[0118]
[0119]
[0120] Then, the adaptive weight ω of the direct trust value and the recommended trust value is calculated d With ω r
[0121]
[0122]
[0123] In summary, node α i The comprehensive credibility value is
[0124] Because the Internet of Things and social communities share certain similarities, the Internet of Things, affiliated with various organizations, can be viewed as a collection of structures and functions. This collection can be imagined as a social community. Within this social community, sensing nodes must abide by the same rules and enjoy the same resources. Furthermore, just like interpersonal communication in society, various nodes in the sensing layer frequently exchange data, all of which collectively influence the development of their social communities. This section will build on the comprehensive trustworthiness of nodes in centralized and distributed modes discussed above, and combine this with energy trustworthiness to construct a trusted group of sensing nodes through a trusted logic grouping mechanism.
[0125] In the perception layer, data transmission between various nodes is generally based on a logical structure based on clusters and centered around cluster head nodes. Perception nodes usually send the collected data directly to cluster head nodes, which then integrate the received data and forward the integrated data to the aggregation node via one or more hops. Generally, perception nodes need to rely on mobile power supplies to power themselves, and the life cycle of each perception node is closely related to the life cycle of the entire perception network. If the energy of a perception node in a node group is consumed excessively, it will cause the node to fail prematurely, thus affecting the entire perception layer. Therefore, it is necessary to obtain the remaining energy of the perception node in a timely manner to derive the node energy trust value, because the energy status of the node is crucial to the safe operation of the perception layer. However, because the energy levels of perception nodes vary, more secure nodes are usually used for data forwarding during data transmission, resulting in excessive energy consumption of these highly trusted nodes, which may cause unbalanced traffic load or network fragmentation in the Internet of Things. Therefore, the energy status of the perception node is used as a key dimension of trustworthiness measurement by evaluating the α value of the perception node. i The energy consumed in the process of sending and receiving information can confirm the energy state of the node. Assume that as of time t, the sensing node α i The energy consumed by sending and receiving data is calculated as follows:
[0126] E rece (n,d)=E ecost ·n
[0127]
[0128] Where n represents the number of bits sent and received by the node up to time t, and d is the number of bits received by node α. i With node αj The physical distance between them, d0 represents the threshold of the transmission distance, E ecost Indicates the energy consumption per bit for data exchange between nodes, E mp It represents the energy consumed to meet the specified signal-to-noise ratio, E ecost and E mp It is artificially preset. Therefore, according to the formula, we can know that node α i Total energy consumption during data forwarding E consume for:
[0129]
[0130] Finally, if the initial energy of the node is E Init , E consume represents the energy consumed by sending data, E0 represents the energy consumed by normal operation, then node α i Remaining energy E residue It can be calculated as:
[0131] E residue =E Init -E consume -E0
[0132] If the node's residual energy E residue Not less than the energy threshold E threshold , indicating that the node is capable of cooperation; otherwise, no matter how high the node's comprehensive credibility is, data transmission cannot be carried out. Therefore, we define node α i Energy credibility T E for:
[0133]
[0134] In the centralized networking mode, according to the above description of the sensing node α i From the formal description of , we can see that its operating state can be described as SD=(T,ht,Δt,T E ), where T is the cluster head node according to the comprehensive trust metric function T(α π ,α i ,t) calculated α i The comprehensive metric value of Δt represents the effective time window of the trusted state, ht represents the set of historical trusted metric values excluding the current trusted metric value within a Δt time window, T E is the α calculated by the cluster head node according to formula (3-34) i The energy credibility value.
[0135] Assume that the set of sensing nodes belonging to a certain organization is {α1,α2,...,α n}, the cluster head node set is {α π1 ,απ2 ,...,α πm}, the cluster head node should group the set of sensing nodes into trustworthy logical groups. First, α π Calculate the trustworthy discrimination of all sensing nodes within its communication radius, which can be obtained by sensing node α i Operation status SD=(T,ht,Δt,T E ) is calculated. Assume that at time t, α i The comprehensive measurement value is T(α π ,α i ,t) and the energy measurement value is T E (α π ,α i ,t), since the trust measurement in this paper is a progressive measurement process, the dynamic measurement of the node in Section 3.2.3 is at a certain moment and is not continuous, so α i Whether it is trustworthy, the cluster head node needs to analyze α i In [t i ,t i+1 ] time period, and also need to refer to the node energy state to finally decide whether to include the sensing node in the trusted logic group. The node trustworthiness discrimination F tc The calculation is as follows:
[0136]
[0137] The cluster head node α π Preset threshold th, if F tc (α π ,α i )≥th, then α i You can add α π The trusted logical grouping headed by the , otherwise not allowed to join, ultimately realizing the construction of a trusted group in the perception layer of the Internet of Things.
[0138] In this mode, set G i is any group of sensing nodes, cluster head node α πi The sensing nodes within the communication radius are {α1,α2,...,α k}, these nodes are in [t i ,t i+1 ] The operation status measurement values within the time period are (F tc (α πi ,α1),F tc (α πi ,α2),...,F tc (α πi ,α k )), then α πi The trust mathematical expectation of the node cluster centered on can be calculated as Then {α π1 ,α π2 ,...,α πm The mathematical expectation of each cluster is Since energy is crucial for the stable operation of the perception layer, let {α π1 ,α π2 ,...,α πm The energy surplus of} is respectively (E π1 ,E π2 ,...,E πm ), and finally the group G can be calculated i The trust expectations are as follows:
[0139]
[0140] In this model, since nodes are equal to each other and there is no management-managed relationship, nodes need to "negotiate" with other nodes within their communication radius to gradually build a trusted logical grouping of nodes with similar characteristics. This process can be described as follows:
[0141] Assume that there are n sensing nodes {α1,α2,...,α n}, similar to the centralized networking mode, the sensing node α j The running state feature vector can be described as SD = (T, ht, Δt, T E ), if α j The nodes within the communication radius are {α1,α2,...,α k}, α j Each sensing node except itself is calculated through the trustworthy discrimination function, α j First, nodes with similar credibility are regarded as candidate nodes for credible logical grouping. In this mode, α j If you request α i To add its own logical grouping, the two nodes need to perform a two-way trust difference calculation, so α j To α i The calculation is as follows:
[0142]
[0143] Similarly, α i To α j The calculation is:
[0144]
[0145] If F is known according to formula (3-37) and formula (3-38) tc (α j ,α i ) and Ftc (α i ,α j ), the credible logic grouping function is obtained as:
[0146] θ=|F tc (α j ,α i )-F tc (α i ,α j )| (3-39)
[0147] Perception node α j Preset trust difference threshold th, if θ<th, then α i You can add α j The member is in the trusted logical group, otherwise he is not allowed to join.
[0148] In this mode, set G j is any group of sensing nodes, the set of sensing nodes is {α1,α2,...,α n}, given that node α i and α j are equal to each other, let {α1,α2,...,α n} in [t i ,t i+1 The remaining energy in the time period is (E1, E2, ..., E n ) and operational status metrics (F tc (α j ,α1),F tc (α j ,α2),...,F tc (α j ,α k )), finally, the node group G can be calculated j The trust expectations are as follows:
[0149]
[0150] We can get k sensing node groups {G1,G2,...,G k The group trust expectation set of} is Since the main task of the sensing node is to collect and transmit data, the expected trust value of the sensing node group in a region must take into account the communication bandwidth occupied by different sensing node groups. Let the group {G1, G2, ..., G k The communication bandwidth occupied by {B1,B2,...,B k}, then the expected trust value of the regional perception node group can be calculated as follows:
[0151]
[0152] It can be seen that the trust expectation of the sink node is If a group of sensing nodes satisfies Then the node group is a credible group, otherwise it is an untrustworthy group. And it is stipulated that is the node group trust differentiation, which can be based on d i The trusted logical groups of sensing nodes are divided into m trust levels (δ1, δ2, ..., δ m ), 0≤δ i ≤1,(i=1,2,....,m), the trust level vector is Ω={δ1,δ2,......,δ m}, δ1<δ2<.....<δ m There are m kinds of priority levels for data transmission of sensing nodes in an area (corresponding to The value of Ω={δ1,δ2,......,δ m} is ordered, so the perception node data sending priority vector is also ordered, so we can get the perception node a i Data sending priority:
[0153]
[0154] where δ1, δ2, ..., δ m The specific value of is determined by the logical grouping of the sensing nodes. For the centralized networking mode, the management node has a i After completing the trust measurement, the data transmission priority can be determined. For the distributed networking mode, the data transmission priority is usually determined by the aggregation node.
[0155] In this invention, in a centralized mode, the static attributes of the perception nodes are first trusted, followed by the dynamic attributes of the nodes. Finally, the trustworthiness of the node is determined by combining the static trustworthiness results with the static trustworthiness results. In a distributed mode, the node's direct trustworthiness is first determined, followed by the node's recommended trustworthiness. Finally, the direct trustworthiness and recommended trustworthiness are combined to determine whether the node is trustworthy. Furthermore, based on the comprehensive trustworthiness measurements of the perception nodes in these two networking modes, a trusted group of perception nodes is constructed under the corresponding networking strategies of each mode, using the perception node trustworthiness discrimination function and the trusted logic grouping mechanism. This ensures the secure operation of the entire perception layer network.
[0156] For the trusted logical grouping of sensing nodes, suppose there are k sensing node groups {G1, G2, ..., G k}, ensuring the secure operation of the perception layer through trust metrics and trusted logical grouping. To further address the above issues, this paper studies the trustworthiness of data sources within a group of perception nodes. It then verifies the trustworthiness of perception node data sources using a trustworthiness-based remote attestation mechanism in different perception node logical groups, both in centralized and distributed networking modes.
[0157] For some special scenarios in the Internet of Things, if the specific trust values of sensor nodes need to be tracked dynamically and in real time, the trustworthiness of the nodes at any given moment can be determined through the comprehensive trust measurement model for sensor nodes in the previous chapter. In a centralized sensor node group, if a node within the group wants to transmit data outside the group, it first needs to prove that the node itself is trustworthy. This can be done by processing the node's trust value with relevant data and then sending it to a remote node. The remote node can determine whether the data source node is trustworthy based on the information it receives. If the remote node has doubts about the information or believes that the data source node is untrustworthy, it can trace back to the data source node's superior node (management node) to further evaluate the trustworthiness of the data source node and decide whether to continue interacting with it based on the final query result.
[0158] In the centralized networking mode of the perception layer, the superior node in a perception node group will perform real-time credibility measurement on the data source node. The data source node first formally describes the superior node's measurement value, timestamp and some other related attributes into a remote proof vector.
[0159] When a member node in a node group needs to be verified by a remote node, the data source node only needs to prove that it belongs to the trusted group, so as not to expose the privacy of the node. The source node and its upper node complete the group signature of the remote proof vector together, which needs to achieve security requirements such as correctness, unforgeability, anonymity, traceability, forward security, and non-frameability.
[0160] When the source node transmits data to the remote node, it decides whether to trust the data source node based on the remote node's security policy. If it does not trust the source node, it can verify the received group signature and view the relevant information of the source node by opening the signature. It can also perform a trusted query on the parent node of the data source node. If the result is untrustworthy, it can refuse to interact with the source node.
[0161] The signing, verification, and signature opening process of the group signature scheme is described below. The superior node in a group of sensor nodes serves as the group manager, generally considered a trusted third party, and the proving node is an ordinary sensor node. The general manager (GM) first performs the signature information initialization process. The GM typically initializes the group's private key, public key, and corresponding functions required by the system.
[0162] The specific process is as follows:
[0163] 1) GM first sets a security factor m and randomly selects a secret large prime number Q. Then, it stipulates that (G1, +) and (G2, □) are Q-order cyclic groups, the generator of G1 is G, and then stipulates a bilinear map e:G1×G1→G2. Then, it gives a collision-free hash function H:{0,1} * →G1, GM randomly selects Let g s =α as the group's private key, then the group's public key is g x =αG∈G1;
[0164] 2) GM will (G1, G2, e, Q, G, H, g x ) is published to the outside world as a public parameter, g s It is used as a private parameter.
[0165] When a sensing node wants to join the group, it needs to first conduct an identity interaction authentication protocol with the GM. The authentication process is as follows:
[0166] CIN of each participant in the group signature i Randomly select i ∈Z q * As its private key, and then S i =s i G is used as its public key. If GM and ordinary nodes can interact through secure communication means, then ordinary nodes will become legitimate nodes of the perception group after successfully completing identity authentication:
[0167] 1) CIN i To become a legal member of the group, you first need to send the node public key S i Transmit to GM and request registration;
[0168] 2) When GM completes authentication of the common node, any choice And concluded Then Transfer to CIN i If the above steps are completed successfully, the node can be considered as a legitimate node of this group, and GM will record To the legal group member information set L1.
[0169] 1) CIN i Any choice Then we can conclude in is the initial key, and then in the tth time period, Finally concluded From this we can see that CIN i The keys that fall within this time range are Discard after calculation and
[0170] 2) GM's choice Then we can conclude in is the initial key, and then in the tth time period, Finally concluded From this we can see that the key of GM in this time period is Discard after calculation and
[0171] CIN i The message to be co-signed with GM is CIN i The trust metric value T and other related attributes of the node are connected in series using the symbol ||, m=T□OR, then CIN i With GM, the message m∈{0,1} * The process of completing group signature is as follows:
[0172] 1) CIN i First get a signature Then transmit To GM.
[0173] 2) GM gets Then by S i To determine CIN i If the node fails to pass the authentication, GM will not cooperate with it. If it passes the authentication, GM will calculate CIN according to the key update process. i Signature key within time period t Then we can conclude and If the formula is equal, then GM can deduce and And record To the group member signature information set L2, the group signature of message m is recorded as Δ = (σ i,t ,T i,t ). If the formula is not equal, execute step 1) again.
[0174] When the remote verifier V receives the group signature Δ=(σ i,t ,T i,t ), first calculate μ=H(m), then judge e(G,σi,t )=e(g x +T i,t ,μ), if the left and right sides of the formula are equal, it can be considered that Δ=(σ i,t ,T i,t ) is correct, subsequent interactions can be carried out. If they are not equal, V should immediately stop receiving the signature and data from the source node.
[0175] When a remote verifier V questions a group signature, he can track down the group member who generated the signature with the help of cooperation with GM. GM can first open Δ=(σ i,t ,T i,t ), and then verify the real signing node through the legal group member set L1 and group member signature information set L2 recorded by GM.
[0176] If we want to test Δ=(σ i,t ,T i,t ) is determined by CIN i The group administrator GM performs the legal signature for m within the time period t. If this is true, it can be explained that ε i,t It is indeed necessary to go through the group administrator GM and group member CIN i A jointly generated group signature.
[0177] In order to ensure the security of the group signature scheme, the following detailed analysis is required:
[0178] If Δ=(σ i,t ,T i,t ) is composed of group member node CIN i The signature of message m within the time period t. When the remote verifier V receives Δ=(σ i,t ,T i,t ), calculated as follows:
[0179]
[0180] Therefore, it can be seen from the formula that Δ=(σ i,t ,T i,t )correct.
[0181] If we want to test Δ=(σ i,t ,T i,t ) Is it CIN i The signature of message m within the time period t. The group manager GM can calculate it as follows:
[0182]
[0183] Know that ε i,t It must be done by the group administrator GM and group members CINi Co-produced.
[0184] If (σ i,l ,T i,t ) is from CIN i For the signature of message m, the specific calculation process is:
[0185]
[0186] From this we can see that (σ i,l ,T i,t ) is through group member CIN i The multi-signature completed by the group administrator GM is (σ i,l ,T i,t ) is obtained through the specific calculation process, Θ1 is the group member CIN i The signature completed together with the group manager GM, Θ2 is the group member CIN i Regarding the BLS signature of message m, Θ3 is the BLS signature of the group manager GM and group member CIN. i Each BLS signature of message m, since Θ1, Θ2 and Θ3 all satisfy the unforgeability, so Δ=(σ i,t ,T i,t ) also satisfies the unforgeability property.
[0187] The anonymity of the signature means that for a given group signature, only the group administrator GM can open the signature and trace it to the real signing node, that is, assuming there are different CIN i With CIN h (i≠h) For the same message m, the signature is indistinguishable (σ i,t ,T i,t ) and (σ h,t ,T h,t ). If the attacker obtains GM and CIN through illegal means i 、CIN h However, it is necessary to assume that GM is in a trusted state. The attacker can open all the keys except Δ=(σ i,t ,T i,t ) all arbitrary signatures. Assume that the attacker has a message m, CIN i With CIN h We can get (σ i,t ,T i,t ) and (σ h,t ,T h,t ), we can see that the attacker can distinguish (σ i,t ,T i,t ) and (σ h,t ,T h,t) is because it is assumed that the attacker can solve the CDH problem on G1. The detailed analysis process is as follows:
[0188] If the attacker knows the group members CIN i The group signature for message m is (σ i,t ,T i,t ), as well as group administrator GM and group member CIN i , so we can get:
[0189] ω=αH(m),μ i =s i H(m),ν i =σ i,t -ω-μ i ,because
[0190] Therefore, satisfy make Also because
[0191]
[0192] From the above process, it can be seen that it is easy to get ν i =abG, which means that although the attacker can solve a CDH problem, this problem cannot be calculated on G1, which indirectly means that the attacker cannot successfully implement this attack, thus satisfying anonymity.
[0193] Through the above group signature implementation scheme, we can get that Δ=(σ i,t ,T i,t ) is a combination of GM and CIN i Produced in collaboration. i If you want to provide a legal group signature, you must cooperate with the GM, and the CIN is also recorded in the group administrator GM i The specific identity and public key When the remote verifier V raises doubts after receiving the signature, GM can open Δ=(σ i,t ,T i,t ), and then the real signature node can be traced back according to the group member information list recorded in GM.
[0194] If there are two signatures, only GM can identify whether they are signed by the same CIN. i If the signature is made, it is said to be unrelated. Assume that CIN i In different time periods t and t+Δt, for different messages m t With m t+Δt And we get (σ i,t ,Ti,t ) and (σ i,t+Δt ,T i,t+Δt ). If the attacker can distinguish (σ i,t ,T i,t ) and (σ i,t+Δt ,T i,t+Δt ), and the attacker knows (σ i,t ,T i,t ) is CIN i In time period t, for message m t The attacker also obtained the signature of GM and CIN i However, it is necessary to ensure that GM is in a safe state, so we know that ω=αH(m t ),μ i =s i H(m t ),ν i =σ i,t -ω-μ i , Can prove is the CDH problem on group G1. Since this problem on group G1 cannot be completed, if we want to judge (σ i,t ,T i,t ) and (σ i,t+Δt ,T i,t+Δt ) is not related, but it is impossible not to open them.
[0195] As can be seen from the above, this group signature scheme is unforgeable. Therefore, if other nodes except the signing node do not have the key of the group member, it is impossible to forge a legitimate signing node to sign. Therefore, this scheme is not framed. As can be seen from the above, this group signature scheme is unforgeable. When GM wants to communicate with the signing node CIN i When collaborating to generate a valid group signature, GM needs to authenticate CIN i Therefore, even if some nodes in the group want to collude to forge a legitimate signature, if the GM does not cooperate with them, it is impossible to construct a legitimate group signature that can be normally traced by the GM.
[0196] Assuming CIN i You can choose any To determine the key The replacement of CIN and the change of time period will not affect the selection of random numbers, and the signature key can be updated without restriction. i The key in the time period t is If the attacker wants to obtain the key before time period t, he must obtain CIN iBefore time period t, k=0,1,2,3,4,···t-1 but After any key is obtained for time period t, it is destroyed. Therefore, if an attacker wants to obtain the key within time period t-1, get Then this process can be summarized as solving the discrete logarithm problem on the group G1, from which we can see that the attacker cannot obtain the key in time period t. The key before time period t can be guessed to forge the signature. Therefore, this scheme has forward security.
[0197] In summary, for the centralized networking mode of the perception layer, the group signature scheme based on node trusted logical grouping proposed in this section realizes the trusted proof of the data source. Through the analysis and proof of the security of the scheme, it can be seen that the scheme can effectively protect the confidentiality of the identity of group members, and has forward security, unforgeability, traceability, and resistance to conspiracy attacks and frame-up attacks. At the same time, the group signature length of this scheme is relatively short, which can effectively reduce the communication and computing overhead of the IoT terminal and is more practical. Therefore, the scheme proposed in this article is safe and efficient, and can be better applied to the centralized networking scenario of the perception layer.
[0198] In this networking model, the perception nodes first divide the perception layer into several logical groups using the trust measurement model and trusted logical grouping described in Chapter 3. This process effectively excludes untrusted nodes. Since different logical groups have different levels of trust, when a perception node performs remote authentication, the remote node can only learn which logical group it belongs to, but cannot track the actual node itself. Given that in this networking model, the data of perception nodes in a region is ultimately transmitted to the network layer by the aggregation node, multiple aggregation nodes must exist in the region for security and reliability. The aggregation node can then divide all perception nodes within its jurisdiction into several logical groups. Perception nodes in different logical groups use a threshold ring signature strategy to sign their trustworthiness information, enabling external trusted verification.
[0199] First, sink nodes at the region's boundaries perform a trustworthiness measurement on the sensor nodes within their jurisdiction using the model proposed in Chapter 3 of this paper. This measurement process is based on the static trustworthiness of sensor nodes, with a focus on the dynamic trustworthiness of sensor nodes within a given time window. It combines subjective direct trust with objective recommended trust to derive a comprehensive measure of the sensor nodes. Then, through a trusted logical grouping mechanism, sensor nodes with similar characteristics are grouped together as a trusted group. When proving to the outside world, a node only needs to prove its membership in a trusted group, thus preserving its identity and location privacy. Second, in this networking model, sensor nodes are typically managed by sink nodes. Therefore, sensor nodes in different logical groups can sign their trustworthiness information using a threshold ring signature strategy. Remote nodes then analyze the signature verification results to determine the trustworthiness of the data source. If the source is questionable, they can refuse further interaction with it, thus achieving unconditional anonymity and unforgeability.
[0200] First, select the large prime cyclic groups G and G of order P. T ,e:G×G→G T is a bilinear map. and Both are secure hash functions, through which any node's unique ID can be matched with the m that needs to be signed to generate a number of bits n u With n m The signing process in this paper includes the following steps:
[0201] Z p is an integer domain, arbitrarily choose α∈Z p , g is a generator of G, then let g1=g α , arbitrarily choose g2,u′,m′∈G1,n u bit vector n m bit vector And arbitrarily choose u i ,m i ∈G, so the parameter is The system master key is
[0202] Knowing the ID of each sensor node, let u = H u (ID) is the node ID u Bit vector, u[i] represents the bit vector at the i-th position, is a list of i with u[i]=1, randomly select r u ∈Z p , then the private key of the node ID is
[0203] After the system parameters are established, the signature node will sign the message m (message m is the credibility of the perception node). For the sake of description, it is assumed that there are n perception nodes {ID1, ID2, ID3…, ID n}, since each node has a unique ID, it can be assumed that the ID list of the t nodes that actually sign is {ID1, ID2, ID3…, ID t}, then the remaining node identifier list is {ID t+1 ,ID t+2 ,…,ID n}, where t<n. The real signing node should complete the signature according to the following process:
[0204] All signing node IDs i Any choice And set it as the secret parameter of the node, then all signature node IDs i (i=1,2....t) respectively in the construction coefficient Z p Next, select the t-1 degree polynomial f i (x):
[0205] f i (x) = a i,0 +a i,1 x+......+a i,t-1 x t-1
[0206] Let s i =a i,0 , each ID i get Then share it with all signature nodes except itself, and then get s i,j =f i (j), and then share them to all nodes except itself (all other members in the signature subset), and record s i,i =f i (i).
[0207] Then the node ID j Get ID i Broadcast i,j , and then through If the results are equal, the test is successful.
[0208] All node IDs i All need to find out their own secrets
[0209] It can be seen that in the signature node set {ID1, ID2, IDi …,ID t}, the real signing node ID i The private key is (d i,1 ,d i,2 ), then M=H m (L,m,t). Let is a list of sequence numbers l where the bit vector M[l]=1 of m, we get:
[0210]
[0211] In the above formula (4-6), is the Lagrange coefficient.
[0212] 5) In {ID1, ID2, ID i …,ID t For each node in the set, arbitrarily select r1, r2, ... r n ∈Z p ,make Therefore, we can get
[0213]
[0214] Finally, the message m and the node list {ID1, ID2, ID3…, ID n The threshold ring signature of} is as follows σ=(V,R1,…,R n ,R m ,f).
[0215] The remote node should use the following process to calculate σ=(V,R1,…,R n ,R m ,f) to test. Verify σ=(V,R1,…,R n ,R m ,f) Is the generation process in the node list {ID1, ID2, ID3…, ID n} is completed by no less than t signature nodes.
[0216] The remote node first verifies whether the number of f is correct, and then checks R m Is it related to g f(0) If they are equal, then continue with the following test, otherwise, it means the verification is unsuccessful. Are they equal? If so, it means σ=(V,R1,…,R n ,R m ,f) is correct and legal, the signature can be accepted and the subsequent interaction can continue, otherwise the signature is rejected. In order to ensure the security of the threshold ring signature, it is necessary to verify that it meets the correctness, anonymity and unforgeability properties respectively.
[0217] Assume that the set {ID1, ID2, ID3…, ID n If all the sensing nodes in} can faithfully execute the signature protocol, the signer can correctly generate the signature for the message m, and accordingly, the verifier can also successfully verify it.
[0218] because so Next, the signature σ is calculated as follows:
[0219]
[0220] According to the above proof process, as long as the signer generates the signature correctly according to the signature protocol, the signer can obtain a legal signature and thus obtain the certificate.
[0221] The signature scheme in this paper has unconditional anonymity, that is, for the node set {ID1, ID2, ID3…, ID n}For the threshold ring signature generated by , the probability that an attacker can successfully guess the true signature set is less than 1 / d, so it has unconditional anonymity.
[0222] because is through the node set {ID1,ID2,ID i …,ID t} is chosen arbitrarily, so the private secret of the signing node is x i is irregular. Moreover, R in the signature σ t+1 ,…,R n ,R m It is also irregular and does not reveal the relevant characteristics of the real signature node. i For (i=1,2,…,t), It can be seen that R i (i=1,…,t) has no pattern. And because:
[0223]
[0224] Represents the master key, r ID1 +r1,…r IDt +r t …r t+1 ,…r n ,The selection of f(0) is all irregular, so it cannot represent any features related to the real signature node.
[0225] So, assuming that the attacker has unlimited computing power and intercepts {ID1, ID2, ID3…, ID n}, the probability that an attacker can successfully guess the actual signature subset is no more than 1 / d, that is, the attacker cannot trace the private keys of all signature nodes in {ID1, ID2, ID3…, ID n}. Therefore, the scheme satisfies unconditional anonymity.
[0226] Based on the CDH difficulty problem, this signature process is unforgeable. Only when all given nodes cooperate can a correct signature be generated. Any node or a subset of nodes in the group cannot generate a correct signature.
[0227] If attacker A can forge signatures of a subset of valid signatures with a non-negligible probability, then an algorithm B with probabilistic polynomial computational complexity can be constructed. If B can solve the CDH problem with a probability of ε' within a time period t by calling A,
[0228] Preset a CDH instance of B (g,g a ,g b ), we want to solve the CDH problem through A, and then get g ab , let B pretend to be A's challenger, which can be divided into the following steps:
[0229] 1) System initialization. B regulations l u =2(q e +q s ), l m =2q s , q of this formula e represents how many times A has queried the private key, q s Represents how many times A has performed signature key queries. Arbitrary selection of k u With k m , and make 0≤k u ≤n u and 0≤k m ≤n m , then assume that l u (n u +1)<p and l m (n m +1)<p. B randomly selects and the number of digits is n u X=(x i ), x i ∈Z lu ; Random selection The sum of the digits is n m Z=(z k ), Finally, B randomly selects y′,w′∈Z p , the number of digits is n u Y=(yi ), the number of digits is n m W=(w i ), y i ,w i ∈Z p .
[0230] The bit vector u=H of the unique ID of the node in the perception node list L and the signature message u (ID) and M=H m (L, m, t). The regulations are as follows:
[0231]
[0232]
[0233]
[0234]
[0235] B calls all the parameters in the above signature scheme: g1 = g a , g2=g b ,
[0236] 1≤i≤n u , 1≤i≤n m
[0237] Therefore, we can see that the above parameters are no different from the public parameters obtained by the attacker. It can also launch
[0238]
[0239]
[0240] B then transmits these parameters to A.
[0241] 2) Query: If A makes the following query, B will respond as follows:
[0242] Private key query: A identifies the node as ID u When the private key of F(ID u )≠0modp holds, B can also calculate its private key is B randomly selects r u ∈Z p , then we get:
[0243]
[0244] let Can know d IDu Identify the node ID u The legitimate private key.
[0245]
[0246]
[0247] For A, the private key constructed by B is exactly the same as the private key generated by the real challenger. If F(u) = 0 mod p, the above process cannot continue and B cannot succeed.
[0248] Signature query: query L={ID1,ID2…,ID n}, when the threshold value is t (t<n) and for m signature, B first calculates M=H m (L,m,t), and then generate the (t,n) threshold ring signature through the following process:
[0249] (a) B randomly selects s, a0, a1, ... a t-1 ∈Z p Then set the t-1 degree polynomial f(x) = a0 + a1x, ... a t-1 x t-1 ,s=a0.
[0250] (b) If L = {ID1, ID2…, ID n There are no less than t IDs in i , i∈(1,2,…,n), so that F(ID i )≠0modp holds. Let γ be the value that makes F(ID i )≠0mod p, then we can set γ=(1,2,…t). B first calculates its private key according to the private key query process, and then obtains the node IDs of all nodes that perform threshold ring signatures. i =(1,2,…t)’s private secret x i =f(i), and then construct the corresponding threshold ring signature through the signature generation process in this scheme.
[0251] If the node list L is such that F(ID i )≠0mod p, the number of nodes for which (i∈1,2,…,n) is true is less than t, and B can also construct a threshold ring signature. Let K(M)≠0mod p, then B arbitrarily selects r1,…r n ,r m ∈Z p , we get:
[0252]
[0253] In the above formula, This shows that σ is valid. If K(M) = 0 mod p, then the above process stops and B fails.
[0254] 3) Forgery: A can forge The threshold ring signature σ* of the threshold value t and m*. If B succeeds in this process, then B should verify the following formula:
[0255]
[0256]
[0257] As long as one of the two formulas is not satisfied, B will fail. If both formulas are satisfied, B can be obtained:
[0258]
[0259] The result obtained from the above formula is the answer to the CDH difficult problem.
[0260] Therefore, if the probability of an attacker successfully forging a legitimate threshold ring signature is not negligible, there must be a corresponding algorithm that can solve this difficult problem. However, this contradicts the assumption of the discrete logarithm problem. Therefore, it can be seen that the threshold ring signature scheme in this chapter is unforgeable.
[0261] In summary, for the distributed networking mode of the perception layer, the (t,n) threshold ring signature scheme based on node trusted logical grouping designed in this section under the standard model realizes the trusted proof of the data source. Through the analysis and proof of the security of the scheme, it can be seen that the scheme can effectively protect the privacy information of the proving node, has unconditional anonymity and meets the unforgeability. At the same time, the signature length of the scheme is relatively short. Therefore, the scheme proposed in this paper is safe and efficient, and is suitable for perception nodes with limited computing resources.
[0262] This application measures the trustworthiness of perception nodes in centralized networking mode and distributed networking mode respectively, and then constructs trusted logical groupings according to different networking strategies, so as to achieve the safe operation of the perception layer. On this basis, in order to solve the source trust problem of perception layer nodes during data transmission, the remote proof mechanism in centralized and distributed networking modes is studied respectively. In the centralized networking mode, the remote proof process is completed through the group signature scheme. The privacy of the node is not exposed during the proof process. The verification node can initiate a query to the management node at the source of the data based on the received signature to see whether the node is a trusted node. It can also trace the node when a dispute occurs in the data, thereby achieving the purpose of dynamic tracking of the node. In the distributed networking mode, the remote proof process is completed through the threshold ring signature scheme. The scheme has unconditional anonymity and unforgeability, and has good anti-attack capabilities, which can effectively ensure the trustworthiness of node data transmission.
[0263] This paper will conduct a simulation experiment under the IoT perception network for the solution proposed in the previous article, and make a corresponding brief analysis. This paper uses the Window10 operating system as the operating platform, installs the Ubuntu virtual machine environment, and uses the NS2 network simulation software to build a simulated perception network to evaluate the effectiveness of the trust measurement model proposed in this article and the effectiveness and dynamic adaptability of the remote proof scheme. There are three types of nodes in this simulation experiment, namely, aggregation nodes, cluster head nodes and perception nodes. First, all types of nodes are randomly deployed in an area of 200m*200m, and the simulation perception network running time is set to 1000s. By default, the aggregation node manages the cluster head node, and the cluster head node manages the perception node. The detailed experimental parameters simulated in this section are shown in Table 1 below:
[0264]
[0265] Table 1 Simulation test parameter settings
[0266] As the malicious attacks faced by the perception layer are becoming increasingly complex, any perception node and group are extremely vulnerable to attacks. The trust measurement model proposed in this paper, which is based on the static trust measurement of nodes and the dynamic trust measurement of nodes as the core, can effectively perceive malicious attacks and attacked nodes. When the node faces an attack, it can take protective measures in the first time and ensure its own security. However, it is impossible to simulate all types of attacks suffered by the perception nodes. Therefore, only the most typical attack types are simulated to evaluate the correctness of the proposed model and the effectiveness of the remote proof scheme. Among all the perception nodes simulated above, there are two types: normal nodes and malicious nodes. Among them, the malicious nodes mainly carry out three types of malicious behaviors in the simulation experiment: (1) forgery attack (2) flooding attack (3) selective attack.
[0267] In this simulated perception network, when facing attacks from malicious perception nodes, a detailed comparison is made between the proposed solution and the defense mechanism for perception nodes proposed in the prior art. Assuming that at the initial moment, all nodes are trustworthy, and due to the presence of some malicious nodes, as the number of interactions between nodes increases, the number of malicious nodes increases accordingly. Therefore, the operating states of the perception area are simulated when the malicious nodes account for 5% and 15%, and then the comparison of the trustworthy node rate in the area is obtained. Figure 2 and Figure 3 as follows:
[0268] It can be seen from the simulation experiment comparison results that within the perception node area, as the perception network operation time changes and the proportion of malicious nodes increases, the present invention can very efficiently identify whether a node is an untrustworthy node with malicious behavior, and then eliminate the untrustworthy node from the perception area where it is located, thereby ensuring the credibility of the nodes in the perception area, realizing the safe operation of the perception network and the safe transmission of data in the perception network.
[0269] The remote proof between nodes in the perception layer is simulated, and various attack methods of malicious nodes mentioned above are used to verify the correctness, effectiveness and network dynamic adaptability of the scheme studied in this paper. Figure 4 and Figure 5 The comparison results of node trusted data reception rate when malicious nodes account for 5% and 15% of all nodes are shown respectively. Among them, Scheme 1 represents the use of traditional perception node authentication scheme, and Scheme 2 represents the scheme of interaction without remote proof.
[0270] In the perception network area, when the malicious nodes account for 5% and 15% respectively, the remote attestation scheme proposed in this paper can efficiently ensure the trustworthy data rate of remote nodes receiving data. The reason why it is better than Scheme 1 and Scheme 2 is that the remote attestation scheme proposed in this paper can ensure the security and trustworthiness of the node before the data source node transmits the data.
[0271] Figure 6 is the energy surplus rate of this application. The remote attestation scheme proposed in this paper consumes slightly more energy than Scheme 1 and Scheme 2. The reason is that the computational complexity of this scheme is higher than that of Scheme 1 and Scheme 2. Therefore, the energy consumption rate per unit time must be greater than that of Scheme 1 and Scheme 2, but it will not significantly affect the service life of the perception node. However, it can be seen from the above that the security of this scheme is far superior to Scheme 1 and Scheme 2. Comprehensively weighing the comparison results of security and energy consumption, it can be seen that the remote attestation scheme in this paper obtains better security through less energy consumption, and is more suitable for the actual Internet of Things perception layer.
[0272] Because perception networks are subject to numerous instabilities and can change at any time, the ability of a perception network to operate reliably despite external factors is called dynamic adaptability. If a trust model can accurately and consistently measure the trustworthiness of perception nodes despite complex and dynamic external factors, then the measurement model is considered effective and possesses strong dynamic adaptability. In different IoT perception networks, node interactions can vary significantly due to varying deployment environments. For example, some perception networks have limited computing resources, so nodes do not interact frequently. In other environments, such as the Internet of Vehicles, frequent node interactions may be required. Therefore, the proposed solution's network dynamic adaptability is verified by comparing it with Solutions 1 and 2 under different perception networks.
[0273] (1) SRF represents the communication frequency between nodes. The value of SRF represents the busyness of the sensing network. The value range is [0, 1]. The larger the value, the more frequent the communication between nodes. Usually, this value is set to a constant according to the different sensing networks deployed.
[0274] (2) TDF represents the dynamic change frequency of the entire perception network. Because perception nodes may join or leave at any time, this value can be used to represent the dynamic changes of the perception network. The value changes in the range [0,1]. Usually, this value is set to a constant based on the different perception networks deployed.
[0275] This simulation experiment uses the node trusted interaction success rate (TSSP) to represent the dynamic adaptability of the remote attestation model. The larger the TSSP, the stronger the dynamic adaptability of the model. Assuming that ST(ΔT) is the number of successful communications between nodes and GT(ΔT) is the total number of communications between nodes, including those with failed communications, TSSP can be expressed as:
[0276] ΔT is the communication time window.
[0277] The remote attestation scheme in this paper is compared with other schemes in terms of dynamic adaptability in different perception network environments, such as Figure 7 and 8 As shown in the figure, SRF = 0.9, TDF = 0.8, indicating that the perception network in this scenario often changes and the communication between nodes is relatively frequent.
[0278] In summary, compared with Scheme 1 and Scheme 2, this scheme is more suitable for the perception layer of the Internet of Things. This is because the remote attestation scheme in this paper is based on the real-time comprehensive trust measurement of nodes, fully considers the characteristics of perception nodes in different networking modes, and can more accurately and objectively describe the security of nodes. Therefore, this scheme has better network dynamic adaptability.
[0279] The beneficial effect of the present invention is that, compared with the prior art, the trust measurement and remote attestation method and system of the perception layer of the Internet of Things in the present invention can propose a multi-faceted and fine-grained trust measurement model suitable for perception nodes for the perception layer of the Internet of Things. In order to solve the problem that the current model cannot meet the current status of the Internet of Things and lacks objectivity and dynamism, a corresponding trust measurement model is constructed in the centralized and distributed modes of the perception layer. Then, according to the measurement results of the perception nodes, a trusted logical grouping is performed to construct a trusted group with different trust levels, thereby ensuring the safe operation of the perception layer nodes. Secondly, based on the trusted logical grouping of the perception layer and for the centralized networking mode, a trusted attestation of the perception data source is realized through a remote attestation mechanism based on group signatures. This mechanism can effectively ensure the credibility of the data source without leaking the privacy of the data source. It can also achieve traceability when the remote node does not trust the other party. Experimental simulation shows that this mechanism has high operating efficiency and low computing performance consumption, and can effectively verify the status of the perception data source. For the distributed networking mode, the trusted proof of data source is achieved through threshold ring signature technology. This scheme has anonymity and unforgeability. Experimental simulation shows that this mechanism meets good anti-attack and network dynamic adaptability, and can ensure the secure transmission of perception data.
[0280] The applicant of the present invention has made a detailed explanation and description of the implementation examples of the present invention in conjunction with the drawings in the specification. However, those skilled in the art should understand that the above implementation examples are only preferred implementation plans of the present invention, and the detailed description is only to help readers better understand the spirit of the present invention, and is not a limitation on the scope of protection of the present invention. On the contrary, any improvements or modifications based on the inventive spirit of the present invention should fall within the scope of protection of the present invention.
Claims
1. A trust measurement and remote attestation method for the perception layer of the Internet of Things, characterized by: The method comprises the following steps: Step 1: establishing a trust measurement model based on the static parameters and dynamic parameters of the perception nodes in the perception layer, and obtaining weights of different trust measurement models based on measurement time and information entropy in different networking modes of the IoT perception layer to achieve the solution of the comprehensive trust value; The trust measurement model includes a static trust measurement model and a dynamic trust measurement model; The dynamic trust measurement model includes a plurality of dynamic attribute measurement functions, wherein the functions include at least a forwarding flow function and a channel state function; The forwarding flow function describes the cluster head node α π For sensor node α i The function of the trust value measured on the dynamic attributes of data forwarding traffic is: Where, T s is the credibility value; t is the calculation time, The channel state function describes the requirements for data transmission volume and delay under different communication task states. The function is: Where ch is the node channel state ε1+ε2=1, rd, sd, tb, and rt are the data requested to be sent, the data actually sent, the available bandwidth of the node network, and the data request response time, respectively. and are the mathematical expectations of sd and rt respectively; Then in the time window {T1, T2.......Tn}, the cluster head node α π The comprehensive trustworthiness metric of the dynamic attributes of any sensing node is: Where t-Δt is the starting time of the time window Δt, and t is the ending time of the time window Δt. Δt is the time window, n is the number of data forwarding times within the time window, decays over time, v is the decay factor, T k is the dynamic attribute trust metric value during the k-th data forwarding, which at least includes the forwarding flow function value and the channel state function value; Step 2, using the comprehensive credibility value and the energy credibility value of the sensing node to perform a credibility logic grouping on the sensing node; In the kth calculation, the definition of the interaction experience between nodes ij in the perception layer is given, with success or failure as two different interaction results. According to the number of successful interactions x and the number of failed interactions y, which take into account the penalty factor of node service, the direct trust value between nodes is calculated using Bayesian estimation. For any sensor node α i , calculate the weighted recommendation trust value of each node within its communication range through the Euclidean space distance similarity judgment method Use the information entropy algorithm to obtain any sensor node α i The comprehensive credibility value T(α π ,α i ,t); At the same time, get any perception node α i The energy measurement value T E (α π ,α i ,t), through any sensing node α i The comprehensive credibility and energy measurement of the node are used to calculate the node credibility distinction and group trust expectation; wherein the node credibility distinction is: is the weight, The group trust expectation is: G i Any sensor node α is included in the multiple sensor node groups of the current iteration i groups, E πi is the remaining energy between nodes, T πi is the trust mathematical expectation of the node cluster, According to the node credibility distinction, any perception node α i Divide into any cluster head node, and urge any sensing node α according to the way of maximizing the group trust expectation i Implement communication negotiation with other nodes within the communication radius to build multiple trusted logical groups with similar characteristics; Step 3: Generate the group signature of the perception node through the dynamically updated key, and implement the trustworthy proof of the perception node from the remote node based on the unforgeability analysis and anonymity analysis.
2. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 1, characterized in that: The networking modes of the Internet of Things perception layer include a centralized networking mode and a distributed networking mode.
3. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 2, characterized in that: In the centralized networking mode, the static trust measurement model of the perception node includes a physical attribute trust evaluation model, a hardware attribute trust evaluation model, a software attribute trust evaluation model, a network attribute trust evaluation model and a static attribute trust measurement model.
4. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 3, characterized in that: In the distributed networking mode, the dynamic trust measurement model of the perception node is a weighted sum of bidirectional static measurement values between the perception node and other nodes in the Internet of Things perception layer.
5. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 4, characterized in that: In the distributed networking, the one-way static metric between the sensing node and any other node in the IoT sensing layer is the access right pr of any other node to the sensing node for the current process of the sensing node. i , a weighted sum of the intersection of the two of the permitted access rights pu of any one of the other nodes in the sensing node for the current process of the sensing node; Wherein, i is the number of all processes between the sensing node and any of the other nodes; The weighted sum of the intersection of the two includes all processes between the perception node and any of the other nodes.
6. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 5, characterized in that: The weight of the weighted sum of the intersection of the two is the derivative of the number of all processes of the current other nodes of the perception node.
7. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 6, characterized in that: In the centralized networking mode, the dynamic trust measurement model of the perception node includes a data packet forwarding rate trust measurement model, a data packet repetition rate trust measurement model, a data packet delay trust measurement model, a data forwarding flow trust measurement model, a node channel state trust measurement model, and a dynamic attribute comprehensive trust measurement model.
8. The trust measurement and remote attestation method for the perception layer of the Internet of Things according to claim 7, characterized in that: In the distributed networking mode, the dynamic trust measurement model of the sensing node includes a direct trust measurement model and a recommended trust measurement model.
9. A trust measurement and remote attestation system for the perception layer of the Internet of Things, characterized by: The system is implemented by using a trust measurement and remote certification method for the Internet of Things perception layer as described in any one of claims 1-8.