An edge computing key management method for IoT user perception data trusted on-chain
By employing edge computing key management methods and utilizing oracle systems and key priority pre-distribution technology, the secure transmission of off-chain sensing data and on-chain latency issues in blockchain systems have been resolved. This has enabled efficient and secure on-chain sensing data transmission, reduced costs, and improved network connectivity and resistance to data capture.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-01
- Publication Date
- 2026-05-15
AI Technical Summary
The secure transmission of off-chain sensing data and the latency issues in uploading data to the blockchain system are problems that current technologies cannot effectively guarantee, thus threatening the credibility and security of on-chain data.
An edge computing key management method is adopted to ensure the trusted uploading of IoT user perception data to the blockchain. By using an oracle system and a key priority pre-distribution method, a key container and key ring are established to generate a shared key. Key management is then carried out in the edge network, reducing computing, communication and storage costs.
It improves the security of off-chain sensing data transmission, reduces the latency of sensing data uploading to the chain, reduces the computation, communication and storage costs of key management, and enhances the network connectivity performance and anti-capture capabilities of IoT user smart devices.
Smart Images

Figure CN116249108B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of secure data transmission in mobile edge computing, specifically relating to an edge computing key management method for trusted uploading of IoT user-perceived data to the blockchain. Background Technology
[0002] Sensing data from mobile crowdsourcing networks is uploaded to the blockchain system via transactions. The uploaded sensing data is permanently stored on the blockchain through a node consensus mechanism. Sensing data not stored on the blockchain in the physical world is called off-chain sensing data. Blockchain is a unified accounting method for storing sensing data, requiring collaborative maintenance by multiple network nodes. Cryptographic technology ensures the security of sensing data transmission and access. The multi-node consensus and tamper-resistance characteristics of blockchain mean that once sensing data is uploaded to the blockchain system, funds can be fixed within the blockchain, and smart contracts can be executed to verify, store, and maintain the on-chain sensing data. Therefore, blockchain systems have high requirements for the authenticity and security of uploaded sensing data. However, in real-world scenarios, the cryptographic methods of the blockchain system itself can only ensure the reliability of sensing data already transacted on the blockchain, not verify the reliability and security of sensing data before it was uploaded. If untrusted sensing data is uploaded to the blockchain, it means that the sensing data already transacted on the blockchain has been tampered with at its source, resulting in adverse effects far exceeding those of traditional centralized models, and undermining the security and trustworthiness of the blockchain system.
[0003] Smart contracts, unique to blockchain technology, are executable code running on the blockchain and protocols that facilitate the transfer of sensing data between untrusted nodes. A limitation of smart contracts is their inability to manipulate data outside the blockchain. This provides an opportunity for trusted entities like oracles, which can acquire sensing data from off-chain data sources and upload it to on-chain smart contracts. Simultaneously, IoT user smart devices can also support the on-chain uploading of trusted sensing data. In blockchain applications, combining smart contracts with mobile edge computing allows network nodes to be deployed near IoT user smart devices, facilitating the verification and execution of blockchain transactions. Therefore, there is an urgent need to research secure mechanisms for the trusted uploading of off-chain sensing data to the blockchain to ensure the reliability of sensing data within the blockchain system.
[0004] To address the issues of secure transmission of off-chain sensing data and latency in uploading sensing data to the blockchain system, this paper proposes an edge computing key management method for trusted uploading of IoT user sensing data to the blockchain. This method improves the security of off-chain sensing data transmission and reduces the latency of uploading sensing data to the blockchain. The design utilizes a remote cloud-based IoT center as the main chain of the blockchain, edge server servers as sub-chains of software and hardware oracles, and mobile devices of IoT terminals as sub-chains of software, hardware, and human oracles. This provides secure and efficient sensing data transmission through collaborative optimization of oracles across the cloud center, edge servers, and sensing terminal devices, achieving low-latency block uploading and ensuring that the latency of uploading tens of millions of sensing data points to the blockchain is less than 1 second. Summary of the Invention
[0005] The purpose of this invention is to address the aforementioned problems in existing technologies and provide an edge computing key management method for the trusted uploading of IoT user-perceived data to the blockchain. Compared with four other blockchain key management methods based on mobile edge computing developed in the past three years, the method proposed in this invention reduces computational, communication, and storage costs in key management methods.
[0006] The edge computing key management method for trusted on-chaining of IoT user-perceived data provided by this invention is shown in the appendix. Figure 15 It mainly includes the following key steps:
[0007] 1. Model Establishment:
[0008] 1.1 Blockchain Oracle System Process;
[0009] Section 1.2, Construction of an oracle-based IoT user edge computing key management system model;
[0010] The second method is a key pre-distribution method based on IoT user key priority.
[0011] 2.1 Edge-Centered Network Model;
[0012] 2.1.1. Establish a key container;
[0013] 2.1.2. Generate the key ring;
[0014] 2.1.3. Generate a shared key;
[0015] Section 2.2, Key pre-distribution method based on key priority;
[0016] Section 2.2.1, Pre-distributed Keys;
[0017] 2.2.2 Generate a key with high priority based on the IoT user node key;
[0018] Section 2.2.3, IoT user node sensing data transmission strategy;
[0019] Section 2.2.4, Connectivity Analysis of IoT User Nodes;
[0020] Section 2.2.5, Security Analysis of Sensor Data Transmission by IoT User Nodes;
[0021] Section 2.2.6, Cost Analysis of IoT User Node Sensing Data Calculation and Transmission;
[0022] Section 2.2.7 Performance analysis of IoT user nodes' resistance to capture;
[0023] 3. Oracle-based IoT user edge computing key management method:
[0024] 3.1 Problem Definition;
[0025] 3.2 Mobility analysis of IoT users;
[0026] Section 3.3, Security Analysis of Key Management Methods;
[0027] 4. Algorithm Description:
[0028] 4.1 Calculate the public and private keys for digital signatures of the IoT user's smart device. Select random variables and generate the public and private keys for communication of the IoT user's smart device. The public and private keys for digital signatures of the IoT user's smart device are transmitted to the blockchain oracle via radio waves. The private keys for digital signatures of the IoT user's smart device are stored locally in the IoT user's smart device. Calculate the connectivity rate of the IoT user's smart device. Calculate the resistance to capture performance of the IoT user's smart device according to formula (11).
[0029] 4.2 The IoT user smart device selects a random variable and generates a digital signature of the IoT user smart device's communication public key and a set of digital signatures for the IoT user smart device's communication public key. A random variable stored locally in the IoT user smart device is selected, and the private address for transmitting sensing data by masking identity information in the blockchain oracle is calculated. The IoT user smart device transmits the digital signature of the communication public key to the newly moved sub-edge network via radio waves. Then, all IoT user smart devices in the sub-edge network verify the digital signature of the communication public key based on the digital signature public key.
[0030] 4.3 Calculate the random variables in the block header information of the blockchain. In the sub-edge network, IoT user smart devices verify the communication public key based on the digital signature public key. Within the timestamp value, they package the received communication public key data into a block. The IoT user smart device exhaustively enumerates the random variables in the block header information of the blockchain to derive a hash function that meets the difficulty coefficient. When the IoT user smart device completes the solution to the mathematical problem in the proof-of-work consensus mechanism, a block is generated that includes the keys of all newly moved IoT user smart devices into the sub-edge network, and the IoT user smart devices are moved into the sub-edge network.
[0031] 4.4. In the process of moving IoT user smart devices into the sub-edge network, a communication public key, digitally signed using a digital signature private key, is transmitted via radio waves to the newly moved sub-edge network. The IoT user smart device verifies the communication public key using the digital signature public key. The number of IoT user smart devices in the newly moved sub-edge network is tracked using transaction data in the blockchain to verify the identity information of the IoT user smart devices. The probability of an IoT user smart device moving into or out of the sub-edge network is calculated. If the verification of the IoT user smart device's identity information is successful, the IoT user smart device moves into the new sub-edge network; otherwise, the IoT user smart device generates a new set of communication public and private keys and applies to move into the sub-edge network again. When an IoT user smart device moves out of the sub-edge network, the communication public key is saved in the blockchain network. Since the blockchain network can only be added to and cannot be modified, when the next IoT user smart device moves into the sub-edge network's tree-structure acyclic graph, the identity information of the IoT user smart device can be quickly verified using the saved key data.
[0032] 5. Experimental Analysis:
[0033] Section 5.1 Experimental Environment and Parameter Settings;
[0034] 5.2. Connectivity probability of IoT user nodes;
[0035] 5.3 The resistance of IoT user nodes to capture;
[0036] 5.4 Computational cost of key management methods;
[0037] 5.5 Storage cost of key management methods;
[0038] 5.6 Communication costs of key management methods;
[0039] Section 5.7, Cost Control Parameter Analysis;
[0040] 5.8 Security features against attacks.
[0041] Advantages and positive effects of the present invention:
[0042] To address the issue of trusted uploading of sensor data from IoT edge servers outside the blockchain system, and the high computational, communication, and storage costs involved in this process, this invention designs an edge computing key management method (OMECKM, based on an Oracle machine module) for trusted uploading of IoT user sensor data to the blockchain. The advantages and positive effects of this invention are as follows:
[0043] (1) Design a key pre-distribution method based on location priority in mobile edge computing, establish a correspondence between the key in the key container and the location of the IoT user smart device node, calculate the distance between the IoT user smart device node and the key, calculate the distance priority according to the distance size, and select the key with the higher distance priority, so that the key management method can achieve strong network connectivity performance and improve the resistance of IoT user smart device nodes to capture.
[0044] (2) The edge network is divided into several sub-edge networks. Based on the number of IoT user smart devices in the sub-edge networks and the computing and storage capabilities of the edge center servers in the sub-edge networks, the sub-edge networks serve as key tree nodes in the key tree structure. In the sub-edge networks, all IoT users collaboratively maintain their blockchain oracles. The key data stored in the blockchain oracles of the sub-edge networks is uploaded to the next-level key tree node in the key tree structure, and finally the key data is stored in the root node of the key tree structure. This achieves the protection against double-spending attacks in the blockchain network and reduces the computing, communication, and storage costs of the blockchain key management method based on mobile edge computing. Attached Figure Description
[0045] Figure 1 This is a flowchart of a blockchain oracle system;
[0046] Figure 2 This is a model diagram of an oracle-based IoT user edge computing key management system;
[0047] Figure 3 It is a partially connected probability graph of the OMECKM key pre-distribution method;
[0048] Figure 4 It is a partially connected probability graph of the key pre-distribution method for a single key cycle;
[0049] Figure 5 It is a partially connected probability graph of a key pre-distribution method with multiple key cycles;
[0050] Figure 6 This is a performance graph of IoT user smart mobile device nodes resisting capture;
[0051] Figure 7 This is a computational cost diagram of the key management method;
[0052] Figure 8 This is a graph showing the memory cost of IoT user smart mobile device nodes;
[0053] Figure 9 This is a diagram showing the storage cost of key management methods;
[0054] Figure 10 This is a diagram showing the communication cost of IoT user smart mobile device nodes;
[0055] Figure 11 This is a communication cost diagram for key management methods;
[0056] Figure 12 This is a diagram showing the effect of different percentage control parameters on key management costs;
[0057] Figure 13 This is a diagram showing the effect of the same percentage control parameters on key management costs.
[0058] Figure 14 This is a security performance diagram for resisting double-consumption attacks;
[0059] Figure 15 This is a flowchart of an edge computing key management method for trusted on-chain IoT data. Detailed Implementation
[0060] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. The examples given are for illustrative purposes only and are not intended to limit the scope of the invention.
[0061] To more clearly describe the edge computing key management method for trusted on-chaining of IoT user-perceived data, this example uses the Windows 10 operating system, Eclipse as the development tool, Java as the development language, and JDK-8u221 as the software development kit to complete data processing and analysis. The detailed implementation process is as follows:
[0062] First, model establishment.
[0063] 1.1 Blockchain Oracle System Process.
[0064] Oracles are typically third-party services within a blockchain, serving as the interface between external data sources and execution programs. Oracles are solely responsible for the reliable collection of data and do not interfere with blockchain transactions. An oracle system, for example... Figure 1 As shown, through the user-end application software, mobile IoT users submit oracle service requests via smart contracts. By utilizing the oracle service interface of the internal smart contract, the user notifies the blockchain execution program that they wish to conduct a transaction involving oracle services. The execution program detects the mobile IoT user's service request and sends it to the oracle using its internal communication component. This service request encapsulates information about requesting external sensing data sources. Upon receiving the service request, the oracle requests sensing data from the external sensing data source at time intervals set by a timer. After acquiring the sensing data, it uploads it to the transaction generator to generate a new internal callback transaction. The oracle then digitally signs this transaction and uploads it to the verification nodes in the trusted execution environment. An oracle consensus mechanism with an approval threshold provides security for the verification nodes, ensuring the immutability of the transaction. The trusted execution environment sends this callback transaction to the execution program to arrange, control, and store the acquired sensing data, thus completing a blockchain transaction involving oracle services.
[0065] Section 1.2, Construction of an IoT user edge computing key management system model based on oracle.
[0066] The edge network is divided into several sub-edge networks and sub-fog networks. An oracle-based edge computing key management system model is as follows: Figure 2As shown, the blockchain oracle stores the encrypted communication public keys of all mobile IoT user smart devices. Mobile IoT users rely on the communication public keys stored in the blockchain oracle in the sub-edge network to transmit sensing data with other IoT users in the same sub-edge network. The consensus of the blockchain oracle in the sub-edge network can be uploaded to the oracle in the sub-fog network near the cloud center. The blockchain transaction data of the lower-level sub-edge network is uploaded to the network nodes of the upper-level blockchain. The network nodes use a verifiable random method to select several network nodes to verify the blockchain. The network nodes in the upper-level blockchain transmit blocks via radio waves in the sub-edge network. When an IoT user smart device moves to another sub-edge network, the IoT user in the new sub-edge network can verify the key data of the local IoT user and the blockchain oracle in the higher-level sub-edge network, and verify whether the newly moved IoT user smart device has completed identity verification in the remaining sub-edge networks, thereby quickly verifying the identity information of the IoT user smart device. Because the blockchain is a linear queue structure with a trusted timestamp, and the key data in it can be tracked through a linear mapping, the required transaction behavior in the blockchain can be effectively tracked, reducing the cost of key generation. In a sub-edge network, IoT users can verify key data using a trusted timestamp in the blockchain oracle. The first key data entry related to a newly moved IoT user's smart device is the latest key data, due to the dynamic sequence nature of the blockchain, where only additions are allowed, not rewriting. When an IoT user's smart device moves into a new sub-edge network, the blockchain oracle generates a new set of public and private communication keys. The public key is stored in the blockchain oracle and transmitted to the edge network via radio waves. The local IoT user's smart device in the sub-edge network stores the private communication key. IoT users can encrypt sensing data using the public key in the blockchain oracle, and IoT user's smart devices can transmit sensing data to each other. The local IoT user's smart device in the sub-edge network stores the corresponding private communication key, which can decrypt the sensing data encrypted with the public key. IoT user's smart devices can be directly removed from the tree-like acyclic graph of the mobile edge network without any further action.
[0067] The second method is a key pre-distribution method based on IoT user key priority.
[0068] 2.1 Edge-Center Network Model.
[0069] Within the coverage area of the mobile IoT edge center network, IoT user smart mobile device nodes collect and transmit sensing data, and need to transmit the sensing data to the edge center server within each specified period.
[0070] 2.1.1. Establish a key container.
[0071] In the edge-centric network model, after each defined key cycle, the key container needs to be replaced. Initially, the key container contains m randomly generated keys. At the end of each key cycle, two adjacent keys are XORed to generate a key for the next key container according to a secure hash method H. The key container variable is assigned a default value, as shown in formula (1).
[0072] Z0={z 0,1 , z 0,2 , z 0,3 , ..., z 0,m-1 , z 0,m} (1)
[0073] In formula (1), 0 represents the 0th key period of key container initialization, Z is the key container, Z0 is the key container of the 0th key period, z is the key, and z 0,1 z is the first key in the 0th key period. 0,m This is the m-th key in the 0th key period, where m is the number of keys in the key container, and all keys are randomly generated.
[0074] The key of the key container in the t-th key period is shown in formula (2).
[0075] Z t ={z t,1 , z t,2 , z t,3 , ..., z t,m-1 , z t,m} (2)
[0076] Where t is the t-th key period, Z t Let z be the key container for the t-th key period. t,1 Let z be the first key in the t-th key period. t,m Let Z be the m-th key in the t-th key period. The m-th key (the last key) in the key container Zt of the t-th key period is randomly generated to obtain a new key z. t,m .
[0077] The keys in the key container during the (t+1)th key period are shown in formula (3).
[0078] Z t+1 ={z t+1,1 , z t+1,2 , z t+1,3 , ..., z t+1,m-1 , z t+1,m} (3)
[0079] Wherein, the key container Z of the (t+1)th key period t+1 The first key z t+1,1 Z is the key container for the t-th key period (the previous key period). t The first key z in t,1 and the second key z t,2 Performing an XOR operation and a secure hash method H yields the key container Z for the (t+1)th key period. t+1 The first key in the key. The key container Z in the (t+1)th key period. t+1 The second key z t+1,2 Z is the key container for the t-th key period (the previous key period). t The second key z t,2 and the third key z t,3 Performing an XOR operation and a secure hash method H yields the key container Z for the (t+1)th key period. t+1 The second key in the system.
[0080] The key generation process is shown in formula (4).
[0081]
[0082] Where s is the s-th key. t+1,s Z is the key container for the (t+1)th key period. t+1 The s-th key, z t+1,s Z is the key container for the t-th key period (the previous key period). t The s-th key z t,s and the (s+1)th key z t,s+1 Performing an XOR operation and a secure hash method H yields the key container Z for the (t+1)th key period. t+1 The s-th key in the key. The key container Z in the (t+1)-th key period. t+1 A new key z is generated randomly from the m-th key (the last key). t+1,m .
[0083] 2.1.2 Generate the key ring.
[0084] During key pre-distribution, each IoT user smart mobile device node selects x consecutive keys from the key container of the current key period to save as one key ring, requiring y key rings to be saved. Therefore, the number of keys saved by the IoT user smart mobile device node is w = x * y. The IoT user smart mobile device node transmits sensing data with other IoT user nodes through the saved keys. Following the normal distribution of the sensing task execution time l of the IoT user smart mobile device node, x = (1 / 2)l is set. Keys are selected using a pseudo-random function P, ensuring that the same IoT user smart mobile device node cannot generate two adjacent key rings.
[0085] 2.1.3. Generate a shared key.
[0086] If IoT user smart mobile device node N1 performs its sensing task during the t-th key period, then IoT user node N1 needs to securely transmit sensing data with other IoT user smart mobile device nodes within the key period interval [t, t+1-1]. If IoT user smart mobile device node N1 performs its sensing task during the t-th key period, and IoT user smart mobile device node N2 performs its sensing task during the r-th key period, and t≤r, then IoT user node N1 and IoT user node N2 need to use the same key within the key period interval [r, t+1]. A shared key for transmitting sensing data between IoT user smart mobile device nodes N1 and N2 is obtained by performing an XOR operation and a secure hash method H on all identical keys.
[0087] Section 2.2, Key pre-distribution method based on key priority.
[0088] 2.2.1 Pre-distributed keys.
[0089] Each key element in the key container is perfectly matched with each location element of the IoT user smart mobile device node within the coverage area of the mobile IoT edge center server. During the key pre-distribution process, the IoT user smart mobile device node selects y key rings from the key container, with x consecutive keys in each ring, storing a total of w = x * y distinct keys. Simultaneously, it stores the identity identifier of the first key in each key ring, forming a set of key ring identity identifiers I = {i1, i2, i3, ..., i...}. y-1 i y}, where i y y is the identifier of the key ring group.
[0090] 2.2.2 Generate a key with high priority based on the IoT user node key.
[0091] Within the coverage area of the mobile IoT edge center, generate the location coordinates (u, v) of the IoT user's smart mobile device node and the location coordinates (p, q) of the key in the key container, and calculate the distance D between the location of the IoT user's smart mobile device node and the location of the key in the key container, as shown in formula (5).
[0092] D = sqrt[(up)] 2 -(vq) 2 (5)
[0093] The distance priority of IoT user nodes is calculated from smallest to largest based on the distance between the location of the IoT user's smart mobile device node and the location of the key in the key container. The location priority of the sensing nodes is sorted from highest to lowest as {1, 2, 3, ..., o, ..., n}, where n is the number of keys pre-distributed to the IoT user's smart mobile device node, and o is the number of keys stored by the IoT user's smart mobile device node. If the IoT user's smart mobile device node stores o keys, then keys with a location priority lower than o are deleted.
[0094] 2.2.3 IoT User Node Sensing Data Transmission Strategy.
[0095] After selecting a key for an IoT user's smart mobile device node, the key ring identifier is transmitted via radio waves to search for neighboring IoT user's smart mobile device nodes with the same key. If IoT user's smart mobile device node N1 and its neighboring IoT user's smart mobile device node N2 have a uniquely identical key, this identical key is selected as the shared key for secure transmission of sensing data. If IoT user's smart mobile device node N1 and its neighboring IoT user's smart mobile device node N2 have multiple identical keys, an XOR operation and a secure hash method H are performed on all identical keys to obtain the shared key, and then secure sensing data is transmitted.
[0096] Section 2.2.4, Connectivity Analysis of IoT User Nodes.
[0097] If n pre-distributed keys for IoT user smart mobile device nodes are selected without repetition from the key container, then... If there are 10 possibilities, then the ratio of any two key selections not producing the same key is 10. The probability Q that adjacent IoT user smart mobile device nodes have the same key is shown in formula (6).
[0098]
[0099] The key container contains m keys, and the IoT user's smart mobile device node stores o keys.
[0100] The size of the space R(S) where the keys stored by the two IoT user smart mobile device nodes intersect is calculated as shown in formula (7).
[0101] R(S) = 2 * [arccos(S / 2o)] * o 2 -S*sqrt(o 2 -S 2 / 4) (7)
[0102] The distance between the two IoT user smart mobile device nodes is S.
[0103] The number of keys G stored by IoT user smart mobile device nodes in the range R(S). o,S As shown in formula (8).
[0104] G o,S =rounddown[o*R(S) / m] (8)
[0105] The number of keys G distributed within the space R(S) where the keys stored by two IoT user smart mobile device nodes intersect. m,S As shown in formula (9).
[0106] G m,S =rounddown[n*R(S) / k] (9)
[0107] Therefore, the coverage range of the mobile IoT edge center server is k. The probability that adjacent IoT user smart mobile device nodes have the same key in the location priority-based IoT user node key pre-distribution method is the connectivity rate Q(S) of the IoT user smart mobile device nodes, as shown in formula (10).
[0108]
[0109] Section 2.2.5, Security Analysis of Sensor Data Transmission by IoT User Nodes.
[0110] The location-priority-based IoT user node key pre-distribution method calculates the location priority of keys, retaining those with higher location priorities. This reduces the number of keys stored by the IoT user smart mobile device node, thus reducing the number of keys that might be exposed if the IoT user smart mobile device node is captured by an attacker. This method ensures both forward and backward confidentiality of the keys. When performing sensing tasks, the IoT user smart mobile device node uses a different key for each key cycle. The key for the new cycle replaces the key from the previous cycle, while the key from the previous cycle is deleted, ensuring forward confidentiality. The computing and storage capabilities of the IoT user smart mobile device node within the coverage area of the mobile IoT edge server are limited. If the IoT user node is captured by an attacker, the limited number of keys captured will become useless over time, ensuring backward confidentiality of the key pre-distribution method.
[0111] Section 2.2.6, Cost Analysis of IoT User Node Sensing Data Calculation and Transmission.
[0112] The location-priority-based IoT user node key pre-distribution method calculates and sorts key distance priorities, then selects the final stored key through a comparison method. This method has relatively low computational cost, and its impact on overall algorithm performance is acceptable. Increasing the ratio of adjacent IoT user smart device nodes having the same key reduces the transmission cost of sensed data and the amount of radio waves transmitted between adjacent IoT user smart device nodes. The energy lost in transmitting sensed data by IoT user smart device nodes far exceeds the energy lost in computation. The location-priority-based IoT user node key pre-distribution method slightly increases the computational cost of sensed data to reduce the transmission cost of sensed data, thereby enhancing the performance of the IoT user node key pre-distribution method.
[0113] Section 2.2.7 Performance analysis of IoT user nodes' resistance to capture.
[0114] Assume the number of IoT user smart mobile device nodes captured by the attacker is I. capture The total number of IoT user smart mobile device nodes is 'a', and the resistance to capture rate of IoT user smart mobile device nodes is U. ResistCapture As shown in formula (11).
[0115] U ResistCapture =1-I capture / a (11)
[0116] Among them, I capture / a represents the percentage of IoT user smart mobile device nodes captured by the attacker.
[0117] Third, an oracle-based method for managing IoT user edge computing keys.
[0118] 3.1 Problem Definition.
[0119] The mobility of mobile IoT user smart devices increases the frequency of changing and distributing a public key and its corresponding private key. When a mobile IoT user smart device moves into or out of a sub-edge network, the edge center key administrator of the sub-edge network changes and distributes the keys of the mobile IoT user smart devices in real time, thereby ensuring the security of the sub-edge network. The construction of the key tree structure and the cost of key transformation and distribution depend on the delineation of the sub-edge network. With a fixed number of mobile IoT user smart devices in the mobile edge network, if the number of mobile IoT user smart devices in the sub-edge network is large, the mobility of mobile IoT users will result in higher key transformation costs and lower key distribution costs. If the number of mobile IoT user smart devices in the sub-edge network is small, the increased number of sub-edge network devices leads to lower key transformation costs and higher key distribution costs.
[0120] The defined mobile edge network is modeled as a tree-like, acyclic structure. Figure X = (Y, Z), where Y is the set of sub-edge networks and Z is the set of relationships among the sub-edge networks. Mobile IoT users within the sub-edge networks can transmit sensing data to each other. The tree structure of the mobile edge network is acyclic. Figure X The complete delineation of X is X = {X1, X2, ..., X...} d}, where d represents the total number of possible mobile edge network configurations. The acyclic graph configuration of the tree structure for the j-th type of mobile edge network is X. j =(Y j Z j ), where Y j For the j-th sub-edge network set, Z j Let j be the relation set of the j-th sub-edge network. The oracle-based key management method for IoT user edge computing requires implementing a tree-like, acyclic structure for the mobile edge network. Figure X The optimal delineation is aimed at minimizing the key transformation cost, key distribution cost, and key storage cost when mobile IoT users move into or out of the sub-edge network set Y.
[0121] The objective function of the oracle-based IoT user edge computing key management method is shown in Equation (12).
[0122]
[0123] Among them, M h For the j-th sub-edge network set Yj In the h-th sub-edge network, E represents the total cost of key management in the oracle-based IoT user edge computing key management method, E(M) h Y is the j-th sub-edge network set. j The total cost of key management in the h-th sub-edge network includes three parts: key transformation cost, key distribution cost, and key storage cost. J(M) h Y is the j-th sub-edge network set. j The key transformation cost of the h-th sub-edge network, K(M) h Y is the j-th sub-edge network set. j The key distribution cost of the h-th sub-edge network, L(M) h Y is the j-th sub-edge network set. j The key storage cost of the h-th sub-edge network. η is the control parameter for key transformation cost; θ is the control parameter for key distribution cost; λ is the control parameter for key storage cost, satisfying η, θ, λ∈(0,1).
[0124] The goal of oracle-based key management methods for IoT user edge computing is to achieve a loop-free tree structure in mobile edge networks. Figure X To obtain the optimal delineation result X from all delineation scenarios. best The corresponding optimal sub-edge network set Y best The goal is to minimize the total cost E of key management. The objective function is min∑E(M) h The following constraints must be satisfied. Constraint 1: Constraint 1 ensures that the tree structure of the j-th mobile edge network is delineated as an acyclic graph. j It is a tree-like, acyclic structure of the mobile edge network. Figure X The optimal delineation result X best The subtree-like structure in the graph is acyclic. Constraint 2: Satisfying constraint 2 ensures that the tree structure of all sub-edge networks in the j-th type of mobile edge network is acyclic, as shown in case X. j Middle. Constraint 3: Satisfying constraint 3 ensures that there are no intersecting acyclic graphs in all subtree structures, and that the same mobile IoT user exists uniquely in a single sub-edge network.
[0125] The j-th sub-edge network set Y j The key transformation cost J(M) of the h-th sub-edge network h As shown in formula (13).
[0126] J(M h ) = A h ×T(M h )+B h(13)
[0127] Among them, T(M h Y is the j-th sub-edge network set. j The h-th sub-edge network M h Acyclic structures in the tree structure of mobile edge networks Figure X j The sum of in-degree and out-degree, A h Let Y be the j-th sub-edge network set in milliseconds. j The h-th sub-edge network M h The number of changes in China Mobile IoT users, B h For the j-th sub-edge network set Y j The h-th sub-edge network M h The computational cost of executing a blockchain oracle consensus mechanism.
[0128] The j-th sub-edge network set Y j The key distribution cost K(M) of the h-th sub-edge network h As shown in formula (14).
[0129] K(M h ) = F h ×V h (14)
[0130] Among them, F h For the j-th sub-edge network set Y j The h-th sub-edge network M h The number of China Mobile IoT users, V h For the j-th sub-edge network set Y j The h-th sub-edge network M h Communication speed of key distribution in China.
[0131] The j-th sub-edge network set Y j The key storage cost L(M) of the h-th sub-edge network h As shown in formula (15).
[0132] L(M h ) = F h ×W h (15)
[0133] Among them, W h For the j-th sub-edge network set Y j The h-th sub-edge network M h The length of the key transmitted in the middle.
[0134] 3.2 Mobility analysis of IoT users.
[0135] IoT user smart devices are randomly moved in and out of the sub-edge network. In the worst case, all IoT user smart devices in the sub-edge network are randomly and sequentially moved into the acyclic tree structure of the mobile edge network. Figure X In the middle, then randomly moving out and moving in to the tree-like acyclic structure of the mobile edge network. Figure X The remaining arbitrary sub-edge networks are eventually removed from the sub-edge network. Assume there are *i* IoT user smart devices in the mobile edge network and *δ* sub-edge networks. Each IoT user smart device has a probability of 1 / δ of selecting a sub-edge network to join, so all IoT user smart devices randomly and evenly select the sub-edge network to join. The tree structure of the mobile edge network is acyclic. Figure X The process of IoT user smart devices moving into and out of the sub-edge network follows a Poisson distribution. The probability Λ of IoT user smart devices moving into and out of the sub-edge network is shown in Equation (16).
[0136] Λ(ζ)=[Ψ ζ / (ζ!)]×(1 / e Ψ (16)
[0137] Where Λ represents the probability of an IoT user smart device moving into or out of the sub-edge network, ζ represents the ζ-th IoT user smart device, and ζ∈[1,i], Ψ represents the expected probability of an IoT user smart device moving into or out of the sub-edge network, and Ψ=i / δ, e is the natural logarithm, and e≈2.71828. In the oracle-based IoT user edge computing key management method, the timestamp value θ is derived based on the execution time of the oracle's consensus mechanism. At any timestamp value θ, all IoT user smart devices that have moved into the sub-edge network can choose to move out of the sub-edge network at the next timestamp value (θ+1).
[0138] Section 3.3 Security Analysis of Key Management Methods
[0139] Employing a distributed blockchain oracle enables trusted and efficient key services in key management methods for mobile edge computing. Each IoT user smart device possesses a set of communication keys, including a public key and a private key, and a set of digital signature keys, including a public key and a private key. Sensing data encrypted with the public key can only be decrypted using the corresponding private key. The IoT user smart device transmits its public key to other IoT user smart devices in the sub-edge network via radio waves. The digital signature key set of the IoT user smart device verifies the trustworthiness of the communication public key when transmitting sensing data. IoT users in the sub-edge network verify the public key of the IoT user smart device according to the timestamp value, solve the mathematical problem in the oracle consensus mechanism through mutual game theory, and generate the next block. The first IoT user to complete the consensus mechanism operation in the oracle needs to transmit the trusted verified public key to a block and add the block to the blockchain. The IoT user smart device can use the communication public key in the oracle to transmit sensing data to other IoT user smart devices in the sub-edge network. Blockchain is a decentralized sensing data center that can only be added to but not rewritten. All IoT users in the blockchain network have a copy of all sensing data on the blockchain, jointly proving the completion of consensus. All sensing data that has been added to the blockchain cannot be rewritten.
[0140] The oracle-based IoT user edge computing key management method in this invention ensures both forward and backward confidentiality of the sensed data. The IoT user smart device uses a public key stored in the blockchain to transmit sensed data with other IoT user smart devices, while the private key is always stored locally on the IoT user smart device. If rapid identity verification fails, a new set of public and private keys is generated only when the IoT user moves to the next sub-edge network; otherwise, no key generation is required. Attackers cannot steal the plaintext sensed data from the IoT user smart device because they would need to obtain the IoT user smart device's private key or control 51% of the network nodes in the blockchain network, which is proven impossible in Theorem 5.1. Therefore, the oracle-based IoT user edge computing key management method in this invention ensures backward confidentiality of the sensed data. Furthermore, although the physical location of the IoT user smart device is constantly moving, the private key is always stored locally on the IoT user smart device. Therefore, the oracle-based IoT user edge computing key management method in this invention does not need to maintain forward confidentiality of the sensed data in previous sub-edge networks; that is, the method in this invention can ensure forward confidentiality of the sensed data.
[0141] 4. Algorithm description.
[0142] In Algorithm 4.1, in the oracle-based IoT user edge computing key management method of Algorithm 1, according to formulas (4) and (5), the ζ-th IoT user smart device calculates the digital signature public key χ. ζ,sign_public and digital signature private key χ ζ,sign_privacy Choose a random variable. Union operation It can generate the communication public key χ for the ζth IoT user smart device. ζ,public =(ω,χ) ζ,sign_public ) and communication private key The public key for the digital signature of the ζth IoT user smart device is χ. ζ,sign_public and communication public key χ ζ,public The digital signature private key χ of the ζth IoT user smart device is transmitted to the blockchain oracle via radio waves. ζ,sign_privacy and communication private key χ ζ,privacy The data is stored in the local IoT user smart device. The connectivity rate of the ζ-th IoT user smart device is calculated according to formula (10). The anti-capture performance of the ζ-th IoT user smart device is calculated according to formula (11).
[0143] 4.2 The ζ-th IoT user smart device selects a random variable κ∈H and generates the communication public key χ for the ζ-th IoT user smart device. ζ,public Digital signature The digital signature set of the public key for communication of IoT user smart devices is Ω={φ 1,sign ,φ 2,sign ,…,φ ζ,sign ,…,,φ i,sign}in, Hash function and Choose a random variable σ∈Z stored in the local IoT user smart device. l Calculate the private address of the ζ-th IoT user smart device in the blockchain oracle, which masks the identity information and transmits sensing data. The ζth IoT user smart device transmits the communication public key χ via radio waves. ζ,public Digital signature φ ζ,sign To the newly moved sub-edge network, and then all IoT user smart devices in the sub-edge network according to the digital signature public key χ ζ,sign_public Verify communication public key χ ζ,public Digital signature φ ζ,sign .
[0144] In section 4.3, l represents a random variable in the block header information of the blockchain. The ζ-th IoT user smart device in the sub-edge network uses the digital signature public key χ... ζ,sign_public Verify communication public key χ ζ,public Within the timestamp value, the received communication public key χ is packaged and received. ζ,public Data is fed into a block. IoT user smart devices exhaustively search for a hash function that meets the difficulty coefficient based on the random variable 'l' in the block header information of the blockchain. in, This is the header information of the block body. This is a 256-bit secure hash function. When an IoT user smart device completes the mathematical problem-solving in the proof-of-work consensus mechanism, i.e., the number of header zeros in the SHA-256 hash algorithm is the same as the number of header zeros in the previous hash function, a block containing the keys of all newly moved IoT user smart devices into the sub-edge network is generated, and the ζ-th IoT user smart device is moved into the j-th sub-edge network.
[0145] 4.4 The ζ-th IoT user smart device is moved into the (j+1)-th sub-edge network, and transmitted via radio waves according to the digital signature private key χ. ζ,sign_privacy Public key χ for completing digital signature ζ,public =(ω,χ) ζ,sign_public The ζ-th IoT user smart device is moved to the (j+1)th sub-edge network. The ζ-th IoT user smart device uses the digital signature public key χ... ζ,sign_public Verify communication public key χ ζ,public The number of the μth IoT user smart device in the newly moved sub-edge network j+1 is tracked by the transaction behavior data in the blockchain to verify the identity information of the ζth IoT user smart device. According to formula (16), the probability Λ of the ζth IoT user smart device moving into and out of the sub-edge network is calculated. If the identity information of the ζth IoT user smart device is verified, the ζth IoT user smart device moves into the new sub-edge network j+1; otherwise, the ζth IoT user smart device generates a new set of communication public keys χ. ζ,public and communication private key χ ζ,privacy And apply again to move into the j+1 sub-edge network. When the ζ-th IoT user smart device moves out of the j+1-th sub-mobile edge network, save the communication public key χ. ζ,public In a blockchain network, since the blockchain network can only be added to and cannot be modified, when an IoT user smart device is moved into the acyclic graph of the sub-edge network tree structure, the identity information of the IoT user smart device can be quickly verified through the stored key data. According to formula (12), the total cost of key management in the oracle-based IoT user edge computing key management method is calculated.
[0146] The steps of Algorithm 1 are as follows:
[0147]
[0148]
[0149]
[0150] 5. Experimental analysis.
[0151] Section 5.1 Experimental Environment and Parameter Settings.
[0152] The experiment used Windows 10 operating system, Eclipse as the development tool, Java as the development language, and JDK-8u221 as the software development kit to complete data processing and analysis. The experimental parameters for the key pre-distribution method for IoT user smart mobile device nodes are set as shown in Table 1. The number of keys in the key container (m) was set to 8000, the coverage range of the mobile IoT edge center server (k) was 500m x 500m, the number of IoT user smart mobile device nodes (a) was 600, the area (b) for transmitting sensing data by the IoT user smart mobile device nodes was 50m, the time limit (l) for the IoT user smart mobile device nodes to perform sensing tasks was 60 minutes, and the number of keys in the key ring (x) was 10. Assuming each key cycle contains 20 sub-key cycles (c), the experimental key cycle range was [0, 2^10]. After each new key cycle began, the keys in the key container were changed. The experiment was executed 50 times, and the average value was used as the experimental result.
[0153] Table 1 Experimental parameter settings
[0154]
[0155]
[0156] The four blockchain key management methods used in the comparative experiment are: Method 1: A key management and authentication method based on a consortium blockchain; Method 2: A decentralized key management method for the Internet of Vehicles based on blockchain; Method 3: A blockchain key management method based on mobile edge computing; Method 4: A blockchain key management method for mobile IoT based on fog networks.
[0157] 5.2 Connectivity probability of IoT user nodes.
[0158] The connectivity probability of IoT user smart mobile device nodes includes overall connectivity probability and partial connectivity probability. Overall connectivity probability is the probability that two IoT user smart mobile device nodes will securely transmit sensed data through another IoT user smart mobile device node or multiple IoT user smart device nodes. Partial connectivity probability is the ratio of any two adjacent IoT user smart mobile device nodes sharing the same key. Two adjacent IoT user smart mobile device nodes are defined as those whose distance is no greater than their sensed data transmission range.
[0159] Methods 2, 3, and the OMECKM key pre-distribution method all have an overall connectivity probability of 100%. This section mainly analyzes the partial connectivity probability of IoT user smart mobile device nodes. In mobile IoT edge computing networks, a partial connectivity probability of 80% is sufficient to achieve secure transmission of sensing data between IoT user smart mobile device nodes. The number of keys pre-distributed to the IoT user smart mobile device nodes are 550, 500, 450, 400, and 350, respectively. Experiments on the partial connectivity probability of the OMECKM key pre-distribution method are as follows... Figure 3 As shown, by generating key priorities based on the distance priority of IoT user smart mobile device nodes, and saving different numbers of keys, corresponding partial connectivity probabilities are obtained. Selecting different numbers of pre-distributed keys and the number of keys retained by IoT user nodes can change the partial connectivity probability of IoT user nodes. Increasing the number of pre-distributed keys increases the ratio of adjacent IoT user smart mobile device nodes having the same key; the number of keys saved by IoT user smart mobile device nodes is directly proportional to the partial connectivity probability. In the OMECKM key pre-distribution method, the partial connectivity probability of IoT user smart mobile device nodes is minimum when the number of pre-distributed keys is 350, and maximum when the number of pre-distributed keys is 550. When the number of pre-distributed keys is 350 and the number of saved keys is 250, and when the number of pre-distributed keys is 550 and the number of saved keys is 175, the partial connectivity probability of IoT user smart mobile device nodes reaches over 80%, which can meet the requirements for secure transmission of sensing data between IoT user nodes.
[0160] Experiments on the partial connectivity probabilities of Method 3 and the OMECKM key pre-distribution method within a single key cycle are as follows: Figure 4As shown, the number of keys pre-distributed to IoT user smart mobile device nodes are 550, 500, and 450, respectively. Key priority is calculated based on the distance priority of the IoT user smart mobile device nodes. Different numbers of keys are stored in the pre-distributed keys, and the corresponding partial connectivity probabilities are obtained experimentally. With the increase of the number of pre-distributed keys and the number of stored keys, the partial connectivity probabilities of both Method 3 and the OMECKM key pre-distribution method increase accordingly. When the number of pre-distributed keys and the number of stored keys are the same, the partial connectivity probability of the OMECKM key pre-distribution method is higher than that of Method 3. When the number of pre-distributed keys is 350, the partial connectivity probability of IoT user smart mobile device nodes in Method 3 is the lowest; when the number of pre-distributed keys is 550, the partial connectivity probability of IoT user smart mobile device nodes in the OMECKM key pre-distribution method is the highest. When the number of pre-distributed keys is 450 and the number of stored keys is 300, and when the number of pre-distributed keys is 550 and the number of stored keys is 200, the partial connectivity probability of IoT user smart mobile device nodes reaches over 80%, which can meet the requirements for secure transmission of sensing data between IoT user nodes.
[0161] Experimental comparisons of the overall connectivity probability of Method 2, Method 3, and the OMECKM key pre-distribution method across multiple key cycles, for example... Figure 5 As shown, the key period ranges from [0, 2^10]. In Methods 2 and 3, the number of keys pre-distributed to IoT user smart mobile device nodes are 375, 350, and 325, respectively. In the OMECKM key pre-distribution method, the number of keys pre-distributed to IoT user smart mobile device nodes are 550, 500, and 450, respectively. After calculating the key priority based on the distance priority of the IoT user smart mobile device nodes, 300 keys are stored in each method. Experiments compare the overall connectivity probabilities of Methods 2, 3, and the OMECKM key pre-distribution method. The OMECKM key pre-distribution method can achieve a higher partial connectivity probability of IoT user smart mobile device nodes using fewer keys than Methods 2 and 3.
[0162] 5.3 The performance of IoT user nodes in resisting capture.
[0163] In the edge-centric network of mobile IoT, the resistance to capture of IoT user smart mobile device nodes is defined as the ratio of the remaining uncaptured IoT user nodes to secure communication after an attacker has captured several IoT user nodes. The resistance to capture of IoT user smart mobile device nodes in Methods 2, 3, and the OMECKM key pre-distribution method is as follows: Figure 6As shown in the diagram, within each key cycle, the attacker randomly captures 2, 4, or 6 IoT user smart mobile device nodes and steals all the keys stored in the main memory of the captured IoT user smart mobile device nodes at that time. The attacker then begins attacking the edge network of the mobile IoT. The experiment compares Method 2, Method 3, and the OMECKM key pre-distribution method, where the connectivity probability of the IoT user smart mobile device nodes is above 80%. In the OMECKM key pre-distribution method, 450 keys are pre-distributed. After calculating the key priority based on the distance priority of the IoT user smart mobile device nodes, 275 keys are stored. Method 3 selects 325 keys, and Method 2 selects 350 keys. Under the condition that the partial connectivity probability of the IoT user smart mobile device nodes is the same, the OMECKM key pre-distribution method uses fewer keys than Method 3 and Method 2, achieving stronger resistance to capture by the IoT user nodes.
[0164] 5.4 Computational cost of key management methods.
[0165] like Figure 7 As shown, the number of IoT user smart device nodes is set to 120, 180, 240, 300, 360, 420, 480, 540, and 600 respectively. The computational cost of the key management method is the sum of the central processing unit operation time of all IoT user smart devices during the key transformation phase. According to formula (13), the computational cost in the OMECKM method includes the cost of generating the key, defining the tree structure of the mobile edge network, and acyclicity. Figure X The cost of key transformation in the OMECKM method is comparable to the cost of solving mathematical problems in the proof-of-work consensus mechanism within oracles. The key transformation cost in the OMECKM method is reduced by an average of 81.05%, 30.13%, 18.26%, and 4.88% compared to methods 1, 2, 3, and 4, respectively. When the number of IoT user smart devices is in the range [120, 240], the key transformation costs of the OMECKM method and method 4 are similar. When the number of IoT user smart devices is in the range [240, 600], the computational performance of the OMECKM method continuously improves as the number of IoT user smart devices increases, thus enabling the use of more computing power to solve mathematical problems in the proof-of-work consensus mechanism within oracles.
[0166] 5.5 Storage cost of key management methods.
[0167] In the edge computing network of mobile IoT, IoT user smart mobile device nodes can securely transmit sensing data if they achieve a partial connectivity probability of over 80%. The experiment compares key pre-distribution methods with a partial connectivity probability of over 80%. Assume the storage capacity of the key ring identity I in the IoT user smart mobile device node is 16 bits, and the size of each key in the IoT user node is 256 bits. Storing the key container in the IoT user smart mobile device node stores the pre-distributed keys. Key priorities are calculated based on the distance priority of the IoT user smart mobile device node, and keys with lower priorities are discarded to restore main memory capacity. This does not increase the storage cost of the IoT user smart mobile device node. The OMECKM key pre-distribution method can achieve the same or higher partial connectivity probability using fewer keys than methods 2 and 3. The storage costs of methods 2, 3, and the OMECKM key pre-distribution method, i.e., main memory usage, are as follows: Figure 8 As shown.
[0168] Wherein, the horizontal axis M2 (325) represents that the number of keys pre-distributed and stored in method 2 is 325; M3 (300) represents that the number of keys pre-distributed and stored in method 3 is 300; MP300 (275) represents that the number of keys pre-distributed is 300 and the number of keys stored is 275; MP (250) represents that the number of keys pre-distributed is 325 and the number of keys stored is 250; MP350 (225) represents that the number of keys pre-distributed is 350 and the number of keys stored is 225. The number of IoT user smart device nodes is set to 35. Although the OMECKM key pre-distribution method requires a large number of keys to be stored at the beginning, after the IoT user smart device node calculates and executes the key priority based on its distance priority, it will discard the key with lower key priority and restore the capacity in the main memory, so there is no situation of increasing the main memory usage. The OMECKM key pre-distribution method increases the partial connectivity probability of IoT user smart device nodes and reduces the number of keys in the key pre-distribution method, thereby reducing the main memory usage.
[0169] like Figure 9As shown, the number of IoT user smart device nodes is set to 120, 180, 240, 300, 360, 420, 480, 540, and 600 respectively. According to formula (15), the storage cost of the key management method is the size of the key data stored by the IoT user smart device nodes and the edge center key administrator of the sub-edge network during the key storage phase. The storage cost of the OMECKM method is reduced by an average of 30.96%, 12.51%, 9.02%, and 4.13% compared to the key storage costs of methods 1, 2, 3, and 4. The OMECKM method adopts a distributed key management method, in which all IoT users in the blockchain network have copies of all the perceived data on the blockchain, jointly proving the completion of consensus. IoT user smart device nodes discard keys with lower key priorities according to key priorities, reducing the main memory capacity.
[0170] 5.6 Communication costs of key management methods.
[0171] When IoT user smart mobile device nodes move into the coverage area of the mobile IoT edge center network, they need to securely transmit sensing data with neighboring IoT user smart mobile devices. The communication costs of Method 2, Method 3, and the OMECKM key pre-distribution method are as follows: Figure 10 As shown. The number of IoT user smart device nodes is set to 20. The communication costs of the following five key pre-distribution strategies with a partial connectivity probability of 80% for IoT user smart mobile device nodes are compared: 1) Method 2: 325 keys are pre-distributed and stored; 2) Method 3: 300 keys are pre-distributed and stored; 3) OMECKM key pre-distribution method: 300 keys are pre-distributed and 275 keys are stored; 4) OMECKM key pre-distribution method: 325 keys are pre-distributed and 250 keys are stored; 5) OMECKM key pre-distribution method: 350 keys are pre-distributed and 225 keys are stored. Among them, the OMECKM key pre-distribution method discards more keys with lower priority after performing key priority filtering. Compared with Method 2 and Method 3, the communication cost of IoT user smart mobile device nodes is significantly reduced.
[0172] like Figure 11As shown, the number of IoT user smart device nodes is set to 120, 180, 240, 300, 360, 420, 480, 540, and 600 respectively. The communication cost of the key management method is the size of the sensed data transmitted during the key allocation phase. According to formula (14), the communication cost of the OMECKM method is generated by the IoT user smart device nodes transmitting the communication public key via radio waves. In the OMECKM method, all IoT user smart device nodes transmit their communication public key to their respective sub-edge networks via radio waves, and the blocks generated by the IoT user smart device nodes are transmitted to all IoT user smart device nodes in the sub-edge networks via radio waves. The communication cost of the OMECKM method is reduced by an average of 27.41%, 19.78%, 16.03%, and 3.75% compared to the key allocation costs of methods 1, 2, 3, and 4.
[0173] Section 5.7, Cost Control Parameter Analysis.
[0174] In the oracle-based IoT user edge computing key management method, the total cost of key management is controlled by the control parameter η for key transformation cost, the control parameter θ for key distribution cost, and the control parameter λ for key storage cost. The number of IoT user smart devices is set to a range of [100, 300]. Figure 12 and Figure 13 Explain the cost of key management and its relationship with the three control parameters. Figure 12 This illustrates the effect of the three control parameters on the total cost of the OMECKM method when all three parameters have the same proportion. The control parameters for key transformation cost (η), key distribution cost (θ), and key storage cost (λ) are set to values of 0.2; 0.1; 0.1, 0.3; 0.2; 0.1, 0.4; 0.3; 0.2, 0.5; 0.4; 0.3 and 0.6; 0.5; 0.4, respectively. Increasing the three control parameters linearly increases the total cost of the OMECKM method. Figure 13 This study illustrates the effect of the three control parameters on the total cost of the OMECKM method when they are set to different proportions. The control parameters for key transformation cost (η), key distribution cost (θ), and key storage cost (λ) are set to values of 0.1; 0.1; 0.1, 0.3; 0.3; 0.3, 0.5; 0.5; 0.5, 0.7; 0.7; 0.7, and 0.9; 0.9; 0.9, respectively. As the three control parameters increase, the total cost of the OMECKM method increases linearly. Therefore, the control parameters for key transformation cost (η), key distribution cost (θ), and key storage cost (λ) are positively correlated with the cost of key management.
[0175] 5.8 Security features against attacks.
[0176] like Figure 14 As shown, in blockchain oracles, since network nodes only consider the longest blockchain as a viable chain, the computing power of IoT user smart device nodes is reflected in their probability β of generating new blocks. The double-consumption attack that the OMECKM method may encounter is caused by the proof-of-work consensus mechanism in the oracle. IoT user smart device nodes exhaustively derive a hash function that meets the difficulty coefficient based on the random variable l of the block header information in the blockchain. When an IoT user smart device node solves the mathematical problem in the proof-of-work consensus mechanism—that is, when the number of header zeros in the SHA-256 hash algorithm is the same as the number of header zeros in the previous hash function—a block body is generated that includes the keys of all newly moved IoT user smart devices into the sub-edge network. If an attacker in the blockchain network possesses computing power equal to or greater than 51% of the network nodes, meaning the probability β of an IoT user smart device node generating a new block body is ≥0.51, a longer blockchain needs to be generated to complete the attack. Setting the total number of blocks Γ that the attacker lags behind trusted network nodes when launching a double-consumption attack to 15, 20, 25, 30, and 35, the probability β of the IoT user smart device node generating a new block body is 0.510, 0.535, 0.560, 0.585, and 0.610, respectively. The greater the number of blocks Γ that the attacker lags behind trusted network nodes when launching a double-consumption attack, the greater the number of blocks the attacker must surpass to complete the attack. When an attacker launches a double-consumption attack, if the number of blocks Γ = 35 that the attacker lags behind trusted network nodes, the attacker in the blockchain network would need to catch up on approximately 900 blocks to complete the attack, which is extremely difficult to implement in practice. Therefore, the OMECKM method employs an oracle-based proof-of-work consensus mechanism, which possesses both credibility and effectiveness.
Claims
1. A method for managing edge computing keys for trusted uploading of IoT user-perceived data to the blockchain, characterized in that... The method includes the following steps:
1. Model Establishment: 1.1 Establish the service process of the blockchain oracle system; Section 1.2, Construction of an oracle-based IoT user edge computing key management system model; When an IoT user smart device moves into another sub-edge network, the IoT user in the new sub-edge network can verify the key data of the local IoT user and the blockchain oracle in the higher-level sub-edge network, and verify whether the newly moved IoT user smart device has completed identity verification in the other sub-edge networks, thus quickly verifying the identity information of the IoT user smart device. When an IoT user smart device moves into a new sub-edge network, the blockchain oracle will generate a new set of communication public keys and communication private keys. The blockchain oracle stores the communication public key and transmits it to the edge network via radio waves. The local IoT user smart device in the sub-edge network stores the communication private key. The IoT user can encrypt sensing data in the blockchain oracle using the communication public key, and IoT user smart devices can transmit sensing data to each other. The local IoT user smart device in the sub-edge network stores the communication private key corresponding to the communication public key and decrypts the sensing data encrypted by the communication public key. The second method is a key pre-distribution method based on IoT user key priority. 2.1 Edge-Centered Network Model; Within the coverage area of the mobile IoT edge center network, IoT user smart mobile device nodes collect and transmit sensing data, and need to transmit the sensing data to the edge center server within each specified period. 2.1.
1. Establish a key container; In the edge-centric network model, after each defined key cycle, the key container needs to be replaced. Initially, the key container contained... A randomly generated key is used. At the end of each key cycle, two adjacent keys are XORed to generate a key for the next key container according to a secure hash method. 2.1.
2. Generate the key ring; During the key pre-distribution process, each IoT user's smart mobile device node selects a key from the key container of the current key period. A series of consecutive keys are stored as a key ring, which needs to be saved. In a key ring, IoT user smart mobile device nodes transmit sensing data to other IoT user nodes using a stored key, according to the time it takes for the IoT user smart mobile device nodes to perform sensing tasks. The key is selected using a pseudo-random function based on the normal distribution of the key. The same IoT user's smart mobile device node cannot generate two adjacent key rings. 2.1.
3. Generate a shared key; If IoT user's smart mobile device node The time to perform the perception task is in the One key cycle, then IoT user node Need to The key period interval and other IoT user smart mobile device nodes securely transmit sensing data, if the IoT user smart mobile device nodes The time to perform the perception task is in the One key cycle, IoT user smart mobile device node The time to perform the perception task is in the One key cycle, and Then IoT user nodes and IoT user nodes Need to Establish identical keys within a key period interval, and perform XOR logical operations and secure hashing methods on all identical keys. Obtain IoT user smart mobile device nodes and IoT user smart mobile device nodes Shared key for transmitting sensing data ; Section 2.2, Key pre-distribution method based on key priority; Section 2.2.1, Pre-distributed Keys; The process involves perfectly matching each key element in the key container with each location element of the IoT user smart mobile device node within the coverage area of the mobile IoT edge center server. During the key pre-distribution process, the IoT user smart mobile device node selects from the key container. Group key rings, each group A total of [number] consecutive keys are stored. Each key ring contains a unique key, and the identity of the first key in each key ring is stored. 2.2.2 Generate a key with high priority based on the IoT user node key; Generate the location coordinates of IoT user smart mobile device nodes within the coverage area of the mobile IoT edge center. and the coordinates of the key's position in the key container Calculate the distance between the location of the IoT user's smart mobile device node and the location of the key in the key container. The distance priority of IoT user nodes is calculated from smallest to largest based on the distance between the IoT user's smart mobile device node location and the key location in the key container. If the IoT user's smart mobile device node stores... If a key is used, the location of the IoT user's smart mobile device node will be deleted if its priority is lower than that of the key. The key; Section 2.2.3, IoT user node sensing data transmission strategy; After selecting the key for the IoT user smart mobile device node, the key ring identity is transmitted via radio waves. This searches for neighboring IoT user smart mobile device nodes with the same key. If the IoT user smart mobile device node... and adjacent IoT user smart mobile device nodes If there is a unique and identical key, then that identical key is selected as the shared key for secure transmission of sensed data. This applies if the IoT user's smart mobile device node... and adjacent IoT user smart mobile device nodes If multiple identical keys are available, an XOR operation and a secure hash method are performed on all identical keys to obtain a shared key, and secure data transmission is then performed.
3. Oracle-based IoT user edge computing key management method: The use of distributed blockchain oracles enables trusted and efficient key services in key management methods for mobile edge computing. Each IoT user smart device has a set of communication keys, including a public key and a private key, as well as a set of digital signature keys, including a public key and a private key. Sensing data encrypted with the public key is decrypted using only the corresponding private key. The IoT user smart device transmits the public key to other IoT user smart devices in the sub-edge network via radio waves. The digital signature key set of the IoT user smart device verifies the trustworthiness of the communication public key when transmitting sensing data. IoT users in the sub-edge network verify the public key of the IoT user smart device according to the timestamp value. Through mutual game theory, the mathematical problem in the oracle consensus mechanism is solved, and the next block is generated. The first IoT user to complete the consensus mechanism operation in the oracle needs to transmit the trusted verified public key to a block and add the block to the blockchain. The IoT user smart device can use the communication public key in the oracle to transmit sensing data to other IoT user smart devices in the sub-edge network.
4. Algorithm Description: 4.1 The IoT user smart device calculates the digital signature public key and digital signature private key, selects random variables, and generates the communication public key and communication private key of the IoT user smart device. The digital signature public key and communication public key of the IoT user smart device are transmitted to the blockchain oracle via radio waves. The digital signature private key and communication private key of the IoT user smart device are stored in the local IoT user smart device. 4.2 The IoT user smart device selects random variables and generates a digital signature of the communication public key of the IoT user smart device and a set of digital signatures of the communication public key of the IoT user smart device. It selects random variables stored in the local IoT user smart device and calculates the private address of the IoT user smart device in the blockchain oracle that masks the identity information of the sensing data. 4.
3. IoT user smart devices exhaustively search for random variables in the block header information of the blockchain to obtain a hash function that meets the difficulty coefficient. When the IoT user smart device completes the solution of the mathematical problem in the proof-of-work consensus mechanism, it generates a block containing the keys of all newly moved IoT user smart devices into the sub-edge network. The IoT user smart devices are then moved into the sub-edge network. 4.4 Calculate the probability of IoT user smart devices moving into and out of the sub-edge network. If the identity information of the IoT user smart device is verified, the IoT user smart device moves into the new sub-edge network. Otherwise, the IoT user smart device generates a new set of communication public keys and communication private keys and applies to move into the sub-edge network again. When the IoT user smart device moves out of the sub-edge network, the communication public key is saved in the blockchain network.
2. The edge computing key management method for trusted on-chaining of IoT user-perceived data according to claim 1, characterized in that: 1.1 The process for establishing a blockchain oracle system service is as follows: Through user-side application software, mobile IoT users submit oracle service requests via smart contracts. By utilizing the oracle service interface of the internal smart contract, the blockchain execution program is notified that the mobile IoT user wishes to conduct a transaction that includes oracle services. The execution program detects the mobile IoT user's service request to the oracle and sends it to the oracle using its internal information communication component. This service request encapsulates information about requesting external sensing data sources. Upon receiving the service request, the oracle requests sensing data from the external sensing data source at time intervals set by a timer. After obtaining the sensing data, it uploads it to the transaction generator to generate a new internal callback transaction and performs a digital signature on the transaction. This transaction is then uploaded to the verification node in the trusted execution environment. The oracle consensus mechanism, based on an approval threshold, provides security for the verification node, ensuring the immutability of the transaction. The trusted execution environment sends this callback transaction to the execution program to arrange, control, and store the acquired sensing data, completing a blockchain transaction that includes oracle services.