Dynamic network trusted group communication method, device, system and readable storage medium
Patent Information
- Application Number
- CN202111647269.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-30
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2041-12-30
AI Technical Summary
[0003]目前,针对上述问题采用的动态通信系统中身份验证的方案存在易被攻击以及难以调查取证的问题,将对整个网络的安全产生很大的威胁
[0039] This invention provides a dynamic network trusted group communication method, apparatus, system, and readable storage medium. A first edge device receives a data transmission request from a second edge device distributed by a blockchain. The second edge device is a registered edge device that has pre-joined the dynamic network. Based on the data transmission request, attribute information of the second edge device is obtained from the attribute server, and the obtained attribute information is compared with the attribute information in the data transmission request. Consensus is reached with other voting nodes in the blockchain system based on the comparison result. If the number of identical voting nodes is greater than or equal to a preset value, the data transmission request of the second edge device is approved. This invention achieves trusted distributed authentication between dynamic network devices through a blockchain system, avoiding system failure caused by single points of failure. Simultaneously, through the blockchain consensus algorithm, the system can be fault-tolerant to a small number of malicious nodes (when using a Byzantine consensus algorithm, fault tolerance to 1/3 of malicious nodes can be achieved), resulting in higher security.
Smart Images

Figure CN116437343B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile communication technology, and in particular to a dynamic network trusted group communication method, apparatus, system, and readable storage medium. Background Technology
[0002] With the development of wireless communication technology, dynamic networks have been widely used in many scenarios. In traditional edge device network systems, dynamic network participants, servers, and / or controllers are potential attack vectors that can be compromised or abused to facilitate other malicious network activities. Attackers can deceive edge devices to join their self-organizing networks and thereby obtain communication information within the network.
[0003] Currently, the authentication schemes used in dynamic communication systems to address the above issues are vulnerable to attacks and difficult to investigate and collect evidence, posing a significant threat to the security of the entire network. Summary of the Invention
[0004] In view of this, embodiments of the present invention aim to provide a dynamic network trusted group communication method, apparatus, system, and readable storage medium.
[0005] To achieve the above objectives, the technical solution of this invention is implemented as follows:
[0006] This invention provides a trusted group communication method for dynamic networks. The method is applied to a first edge device in a dynamic network, where the first edge device is selected as a voting node in a blockchain system. The blockchain system further includes an attribute server that stores attribute information of registered edge devices. The method includes:
[0007] Receive data transmission requests from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network;
[0008] The attribute information of the second edge device is obtained from the attribute server based on the data transmission request, and the obtained attribute information is compared with the attribute information in the data transmission request.
[0009] The comparison results based on attribute information are used to reach a consensus with other voting nodes in the blockchain system. If the number of voting nodes with the same result is greater than or equal to a preset value, the data transmission request of the second edge device is approved.
[0010] The data transmission request includes:
[0011] The identity information of the sending edge device and the receiving edge device in the data transmission request; wherein...
[0012] The identity information includes: the machine attributes of the edge device and the status attributes of the edge device.
[0013] Optionally, when the first edge device is a leader node in the blockchain system, before receiving the data transmission request from the second edge device distributed by the blockchain, the method further includes:
[0014] The identity information of the sending edge device and the receiving edge device of the data transmission request is verified based on the smart contract. If the verification is successful, the data transmission request is distributed to other voting nodes in the blockchain system; otherwise, the data transmission request of the second edge device is rejected.
[0015] Optionally, after reaching consensus with other voting nodes in the blockchain system, the method further includes:
[0016] Write the following content into the blockchain:
[0017] The result of consensus;
[0018] After the data transmission request of the second edge device is approved, the second edge device will then perform the relevant data transmission operations.
[0019] The step of obtaining the attribute information of the second edge device from the attribute server based on the data transmission request includes:
[0020] Obtain the machine attributes of the second edge device from the data transmission request;
[0021] Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet;
[0022] Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
[0023] Optionally, when the comparison result based on attribute information is used to reach consensus with other voting nodes in the blockchain system, the method further includes:
[0024] If the comparison result shows that the number of identical voting nodes is less than a preset value, the data transmission request of the second edge device is rejected.
[0025] Optionally, before receiving the data transmission request from the second edge device distributed by the blockchain, the method further includes:
[0026] The system receives the public key, private key, and digital certificate configured and issued for the first edge device by the system administrator during the edge device registration phase.
[0027] The voting nodes in the blockchain system are: edge devices and / or edge device controllers and / or cloud devices.
[0028] This invention also provides a dynamic network trusted group communication device, which is applied to a first edge device in a dynamic network. The first edge device is selected as a voting node in a blockchain system. The blockchain system further includes an attribute server that stores attribute information of registered edge devices. The device includes:
[0029] The transceiver module is used to receive data transmission requests from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network.
[0030] An attribute processing module is used to obtain attribute information of the second edge device from the attribute server based on the data transmission request, and compare the obtained attribute information with the attribute information in the data transmission request;
[0031] The consensus processing module is used to reach a consensus with other voting nodes in the blockchain system based on the comparison results of attribute information. If the number of identical voting nodes is greater than or equal to a preset value, the data transmission request of the second edge device is approved.
[0032] This invention also provides a dynamic network trusted group communication system, which is a fusion system of dynamic network system and blockchain system, including:
[0033] A first edge device in a dynamic network is used to receive data transmission requests from a second edge device distributed by the blockchain; obtain attribute information of the second edge device from the attribute server based on the data transmission request, and compare the obtained attribute information with the attribute information in the data transmission request; reach consensus with other voting nodes in the blockchain system based on the comparison result of the attribute information, and if the number of identical voting nodes is greater than or equal to a preset value, then agree to the data transmission request of the second edge device.
[0034] The attribute server in the blockchain system is used to store the attribute information of registered edge devices;
[0035] The first edge device is selected as a voting node in the blockchain system; the second edge device is a registered edge device that is to be pre-joined in the dynamic network.
[0036] This invention also provides a dynamic network trusted group communication device, which includes: a processor and a memory for storing computer programs capable of running on the processor.
[0037] When the processor runs the computer program, it executes the steps of the above method.
[0038] This invention also provides a readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the above-described method.
[0039] This invention provides a dynamic network trusted group communication method, apparatus, system, and readable storage medium. A first edge device receives a data transmission request from a second edge device distributed by a blockchain. The second edge device is a registered edge device that has pre-joined the dynamic network. Based on the data transmission request, attribute information of the second edge device is obtained from the attribute server, and the obtained attribute information is compared with the attribute information in the data transmission request. Consensus is reached with other voting nodes in the blockchain system based on the comparison result. If the number of identical voting nodes is greater than or equal to a preset value, the data transmission request of the second edge device is approved. This invention achieves trusted distributed authentication between dynamic network devices through a blockchain system, avoiding system failure caused by single points of failure. Simultaneously, through the blockchain consensus algorithm, the system can be fault-tolerant to a small number of malicious nodes (when using a Byzantine consensus algorithm, fault tolerance to 1 / 3 of malicious nodes can be achieved), resulting in higher security.
[0040] Furthermore, by leveraging the immutable and traceable characteristics of the blockchain system, traceable evidence storage (all written to the blockchain) of all communication and authentication processes in the edge device network is achieved, enabling auditing and tracing of communication processes during task execution, as well as evidence storage and investigation of attacks after they are received. Attached Figure Description
[0041] Figure 1 This is a schematic diagram of the dynamic network trusted group communication method according to an embodiment of the present invention;
[0042] Figure 2 This is a schematic diagram of the structure of the dynamic network trusted group communication device according to an embodiment of the present invention;
[0043] Figure 3 This is a schematic diagram of the dynamic network trusted group communication system structure according to an embodiment of the present invention;
[0044] Figure 4 This is a schematic diagram of a blockchain-based trusted edge device network communication system as described in an embodiment of the present invention. Detailed Implementation
[0045] The present invention will now be described in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The present application will now be described in detail with reference to the accompanying drawings and embodiments.
[0046] Given the wireless nature of edge device network communication, to ensure its security, effective authentication of devices (and users) is necessary to minimize attacks on the edge device network (such as spoofed data and command injection). Furthermore, to guarantee system security, the system should also possess the capability for secure data traceability.
[0047] This invention addresses the vulnerabilities and difficulties in investigation and evidence collection inherent in authentication schemes within dynamic communication systems. It utilizes blockchain to construct an authentication and trusted group communication scheme, providing secure, reliable, and traceable dynamic network communication for edge devices.
[0048] This invention provides a trusted group communication method for dynamic networks. The method is applied to a first edge device in a dynamic network, where the first edge device is selected as a voting node in a blockchain system. The blockchain system also includes an attribute server that stores attribute information of registered edge devices. Figure 1 As shown, the method includes:
[0049] Step 101: Receive a data transmission request from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network;
[0050] Step 102: Obtain the attribute information of the second edge device from the attribute server based on the data transmission request, and compare the obtained attribute information with the attribute information in the data transmission request;
[0051] Step 103: Based on the comparison results of attribute information, reach a consensus with other voting nodes in the blockchain system. If the number of identical voting nodes is greater than or equal to a preset value, then agree to the data transmission request of the second edge device.
[0052] In this embodiment of the invention, the data transmission request includes:
[0053] The identity information of the sending edge device and the receiving edge device in the data transmission request; wherein...
[0054] The identity information includes: the machine attributes of the edge device and the status attributes of the edge device.
[0055] In one embodiment of the present invention, when the first edge device is a leader node in the blockchain system, before receiving the data transmission request from the second edge device distributed by the blockchain, the method further includes:
[0056] The identity information of the sending edge device and the receiving edge device of the data transmission request is verified based on the smart contract. If the verification is successful, the data transmission request is distributed to other voting nodes in the blockchain system; otherwise, the data transmission request of the second edge device is rejected.
[0057] In one embodiment of the present invention, after reaching consensus with other voting nodes in the blockchain system, the method further includes:
[0058] Write the following content into the blockchain:
[0059] The result of consensus;
[0060] After the data transmission request of the second edge device is approved, the second edge device will then perform the relevant data transmission operations.
[0061] In this embodiment of the invention, obtaining the attribute information of the second edge device from the attribute server based on the data transmission request includes:
[0062] Obtain the machine attributes of the second edge device from the data transmission request;
[0063] Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet;
[0064] Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
[0065] In one embodiment of the present invention, when the comparison result based on attribute information is used to reach consensus with other voting nodes in the blockchain system, the method further includes:
[0066] If the comparison result shows that the number of identical voting nodes is less than a preset value, the data transmission request of the second edge device is rejected.
[0067] In one embodiment of the present invention, before receiving the data transmission request from the second edge device distributed by the blockchain, the method further includes:
[0068] The system receives the public key, private key, and digital certificate configured and issued for the first edge device by the system administrator during the edge device registration phase.
[0069] In this embodiment of the invention, the voting nodes in the blockchain system are: edge devices and / or edge device controllers and / or cloud devices.
[0070] This invention also provides a dynamic network trusted group communication device, which is applied to a first edge device in a dynamic network. The first edge device is selected as a voting node in a blockchain system. The blockchain system further includes an attribute server that stores attribute information of registered edge devices. Figure 2 As shown, the device includes:
[0071] The transceiver module 201 is used to receive data transmission requests from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network.
[0072] The attribute processing module 202 is used to obtain attribute information of the second edge device from the attribute server based on the data transmission request, and compare the obtained attribute information with the attribute information in the data transmission request;
[0073] The consensus processing module 203 is used to reach a consensus with other voting nodes in the blockchain system based on the comparison results of attribute information. If the number of identical voting nodes is greater than or equal to a preset value, the data transmission request of the second edge device is approved.
[0074] In this embodiment of the invention, the data transmission request includes:
[0075] The identity information of the sending edge device and the receiving edge device in the data transmission request; wherein...
[0076] The identity information includes: the machine attributes of the edge device and the status attributes of the edge device.
[0077] In one embodiment of the present invention, when the first edge device is a leader node in the blockchain system, before the transceiver module 201 receives the data transmission request from the second edge device distributed by the blockchain,
[0078] It is also used to verify the identity information of the sending edge device and the receiving edge device of the data transmission request based on the smart contract. If the verification is successful, the data transmission request is distributed to other voting nodes in the blockchain system; otherwise, the data transmission request of the second edge device is rejected.
[0079] In one embodiment of the present invention, after the consensus processing module 203 reaches a consensus with other voting nodes in the blockchain system, it is further configured to write the following content into the blockchain:
[0080] The result of consensus;
[0081] After the data transmission request of the second edge device is approved, the second edge device will then perform the relevant data transmission operations.
[0082] In this embodiment of the invention, the attribute processing module 202 obtains attribute information of the second edge device from the attribute server based on the data transmission request, including:
[0083] Obtain the machine attributes of the second edge device from the data transmission request;
[0084] Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet;
[0085] Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
[0086] In one embodiment of the present invention, when the consensus processing module 203 reaches consensus with other voting nodes in the blockchain system based on the comparison results of attribute information, it is further used to...
[0087] If the number of identical voting nodes is less than a preset value, the second edge device is refused data transmission.
[0088] In one embodiment of the present invention, before the transceiver module 201 receives the data transmission request from the second edge device distributed by the blockchain, it is also used to receive the public key, private key and digital certificate configured by the system administrator for the first edge device during the edge device registration phase.
[0089] In this embodiment of the invention, the voting nodes in the blockchain system are: edge devices and / or edge device controllers and / or cloud devices.
[0090] This invention also provides a dynamic network trusted group communication system, such as... Figure 3 As shown, this system is a fusion of dynamic network systems and blockchain systems, including:
[0091] The first edge device 301 in the dynamic network is used to receive data transmission requests from the second edge device distributed by the blockchain; obtain attribute information of the second edge device from the attribute server based on the data transmission request, and compare the obtained attribute information with the attribute information in the data transmission request; and reach a consensus with other voting nodes 304 in the blockchain system based on the comparison result of the attribute information. If the number of identical voting nodes is greater than or equal to a preset value, the data transmission request of the second edge device is agreed upon.
[0092] The attribute server 302 in the blockchain system is used to store the attribute information of registered edge devices.
[0093] The first edge device is selected as a voting node in the blockchain system; the second edge device 303 is a registered edge device that is to be pre-joined in the dynamic network.
[0094] Here, the function of the first edge device 301 is the same as described above. Figure 2 The functions of the first edge device are the same, and will not be described in detail here.
[0095] like Figure 3 As shown, the system also includes a system administrator 305, who is responsible for system initialization and registration of edge devices, configuring public and private keys for the edge devices, and issuing digital certificates.
[0096] This invention also provides a dynamic network trusted group communication device, which includes: a processor and a memory for storing computer programs capable of running on the processor.
[0097] When the processor runs the computer program, it performs the following:
[0098] Receive data transmission requests from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network;
[0099] The attribute information of the second edge device is obtained from the attribute server based on the data transmission request, and the obtained attribute information is compared with the attribute information in the data transmission request.
[0100] The comparison results based on attribute information are used to reach a consensus with other voting nodes in the blockchain system. If the number of voting nodes with the same result is greater than or equal to a preset value, the data transmission request of the second edge device is approved.
[0101] The data transmission request includes:
[0102] The identity information of the sending edge device and the receiving edge device in the data transmission request; wherein...
[0103] The identity information includes: the machine attributes of the edge device and the status attributes of the edge device.
[0104] When the first edge device is the leader node in the blockchain system, before receiving the data transmission request from the second edge device distributed by the blockchain, the processor is also used to run the computer program, executing:
[0105] The identity information of the sending edge device and the receiving edge device of the data transmission request is verified based on the smart contract. If the verification is successful, the data transmission request is distributed to other voting nodes in the blockchain system; otherwise, the data transmission request of the second edge device is rejected.
[0106] After reaching consensus with other voting nodes in the blockchain system, the processor is also used to execute the following when running the computer program:
[0107] Write the following content into the blockchain:
[0108] The result of consensus;
[0109] After the data transmission request of the second edge device is approved, the second edge device will then perform the relevant data transmission operations.
[0110] When the processor retrieves the attribute information of the second edge device from the attribute server based on the data transmission request, it also executes the following when running the computer program:
[0111] Obtain the machine attributes of the second edge device from the data transmission request;
[0112] Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet;
[0113] Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
[0114] When the comparison result based on attribute information is used to reach consensus with other voting nodes in the blockchain system, the processor is also used to execute the following when running the computer program:
[0115] If the comparison result shows that the number of identical voting nodes is less than a preset value, the data transmission request of the second edge device is rejected.
[0116] Before receiving the data transmission request from the second edge device distributed by the blockchain, the processor is also configured to execute the following when running the computer program:
[0117] The system receives the public key, private key, and digital certificate configured and issued for the first edge device by the system administrator during the edge device registration phase.
[0118] The voting nodes in the blockchain system are: edge devices and / or edge device controllers and / or cloud devices.
[0119] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above program modules when performing dynamic network trusted group communication. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the apparatus provided in the above embodiments and the corresponding method embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.
[0120] In an exemplary embodiment, the present invention also provides a readable storage medium, which may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM; or it may be a device including one or any combination of the above-mentioned memories, such as a mobile phone, computer, tablet device, personal digital assistant, etc.
[0121] This invention also provides a readable storage medium storing a computer program thereon, which, when executed by a processor, performs the following:
[0122] Receive data transmission requests from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network;
[0123] The attribute information of the second edge device is obtained from the attribute server based on the data transmission request, and the obtained attribute information is compared with the attribute information in the data transmission request.
[0124] The comparison results based on attribute information are used to reach a consensus with other voting nodes in the blockchain system. If the number of voting nodes with the same result is greater than or equal to a preset value, the data transmission request of the second edge device is approved.
[0125] The data transmission request includes:
[0126] The identity information of the sending edge device and the receiving edge device in the data transmission request; wherein...
[0127] The identity information includes: the machine attributes of the edge device and the status attributes of the edge device.
[0128] When the first edge device is the leader node in the blockchain system, before receiving the data transmission request from the second edge device distributed by the blockchain, the computer program, when run by the processor, also executes:
[0129] The identity information of the sending edge device and the receiving edge device of the data transmission request is verified based on the smart contract. If the verification is successful, the data transmission request is distributed to other voting nodes in the blockchain system; otherwise, the data transmission request of the second edge device is rejected.
[0130] After reaching consensus with other voting nodes in the blockchain system, the computer program, when run by the processor, also executes:
[0131] Write the following content into the blockchain:
[0132] The result of consensus;
[0133] After the data transmission request of the second edge device is approved, the second edge device will then perform the relevant data transmission operations.
[0134] When the computer program is executed by the processor, it also performs the following when retrieving the attribute information of the second edge device from the attribute server based on the data transmission request:
[0135] Obtain the machine attributes of the second edge device from the data transmission request;
[0136] Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet;
[0137] Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
[0138] When the comparison result based on attribute information is used to reach consensus with other voting nodes in the blockchain system, the computer program, when run by the processor, also executes:
[0139] If the comparison result shows that the number of identical voting nodes is less than a preset value, the data transmission request of the second edge device is rejected.
[0140] Before receiving the data transmission request from the second edge device distributed by the blockchain, the computer program, when run by the processor, also executes:
[0141] The system receives the public key, private key, and digital certificate configured and issued for the first edge device by the system administrator during the edge device registration phase.
[0142] The voting nodes in the blockchain system are: edge devices and / or edge device controllers and / or cloud devices.
[0143] The present invention will now be described in conjunction with specific scenario examples.
[0144] Figure 4 This is a schematic diagram of a blockchain-based trusted edge device network communication system in this embodiment. Figure 4 As shown, it includes: a system administrator, data senders and receivers, and a blockchain system; the blockchain system includes: an attribute server, a verification consensus module, and a block building module; of course, the blockchain system also includes voters (edge devices and / or edge device controllers and / or cloud devices) who verify the consensus of the data senders and receivers; wherein,
[0145] The system administrator can be located in a dynamic network of edge devices, and is responsible for system initialization and registration of edge devices, configuring public and private keys for the edge devices, and issuing digital certificates.
[0146] The sender and receiver of the data are used to obtain the data required to perform the task through the blockchain system;
[0147] The attribute server is used to store attribute information of registered edge devices;
[0148] The verification consensus module is used to verify and reach consensus on the edge devices (senders and receivers of data) to be executed. The edge devices that reach consensus can obtain data to execute the task.
[0149] The block construction module is used to write the consensus results and perform related operations for data transmission after consensus.
[0150] Here, the attribute information stored by the attribute server refers to the attributes of edge devices in the network, which can be persistent or short-term. Persistent data includes edge device machine-related data, such as brand model, device identifier, and other identification information; this data is usually fixed. Short-term data typically includes state-related data, such as session-related data, task-related data, and the real-time status of the edge device; this type of data is usually dynamic.
[0151] In this embodiment, system initialization and edge device registration can be performed using a System Administrator (SA) and a Trusted Node (TN) within the edge device network. In the edge device network, the TN is another set of pre-defined trusted nodes. Once the edge device is successfully registered, it can execute the assigned tasks.
[0152] During the execution of tasks by edge devices, data transmission is required. Therefore, the edge device sends a data transmission request to the blockchain, which processes the request through a smart contract and then sends the request to the property server to obtain the edge device's attributes.
[0153] After the smart contract verifies the edge device's attributes and the result is agreed upon through the consensus protocol, it is written to the blockchain. The edge device will then be allowed to transmit permitted data from the blockchain, and the data transmission operation will also be written to the blockchain.
[0154] In this embodiment, the edge device is always the initiator of data transmission, and the receiver is another edge device or controller. The data transmission service is set as a transaction on the blockchain, and the blockchain is deployed in the base station to support the edge device network management system.
[0155] When an edge device seeking to join the network sends a data transmission request to the blockchain system, the blockchain's leader node distributes the request to voting nodes. These voting nodes can be edge device controllers (described below as members of the voting nodes) or cloud devices within the network. These voting nodes endorse, verify, and vote on the formula results within the blockchain system, and together with the leader node, complete block production through the consensus protocol.
[0156] Furthermore, each voting node and many edge device nodes can form a cluster, and each cluster can access the property server through the key of each edge device node. When the leader node distributes a data transmission request from an edge device to a voting node, it can also distribute the request to the edge device controller and the property server.
[0157] This embodiment can include multiple attribute servers, each containing a type of attribute for the edge devices. Voting nodes obtain the corresponding edge device attributes by accessing multiple attribute servers, then verify the attributes, endorse the results, and return them to the Leader node. Since one voting node accesses one attribute server to verify one attribute of the edge device, multiple voting nodes accessing multiple attribute servers can obtain the final result: whether the edge device has communication rights. The Leader node, after receiving the result, returns it to the edge device. If the edge device is allowed, it can communicate with other edge devices; otherwise, it cannot communicate with other edge devices.
[0158] based on Figure 4 The system implementation method shown includes the following stages:
[0159] Step 1: System initialization;
[0160] This step involves system initialization and registration of edge devices to form a trusted network. This process mainly consists of two parts:
[0161] (i) System Settings:
[0162] First, a safety parameter λ is chosen. The system administrator then generates a prime number q with λ bits and three multiplicative cyclic groups G1, G2, and G3, all prime numbers of order q. T Let q∈G1 and p∈G2 be two generators in generating groups G1 and G2, and let bilinear mappings... This is a bilinear mapping between these three multiplicative cyclic groups. The parameters are generated by the system administrator. Where H:{0,1} * The system administrator selects a group. The private key SA used by the system administrator sk The trusted node TN selects a group. TN as the private key for TN sk And calculate Y = yp as the public key TN. pk The system administrator then selected a symmetric encryption algorithm and its corresponding key.
[0163] The system then begins deploying key management contracts, distribution contracts, verification contracts, and counting contracts, generating a corresponding public key for each contract.
[0164] (ii) Edge device registration:
[0165] If an edge device wants to join the network, it needs to register within the system. During registration, the system administrator needs to generate a public key U for the edge device. pki and private key U ski Where i ∈ N, and N is the number of edge devices in the system. The address U of the edge device... Addri Generated from the public key of the edge device. The system administrator generates the edge device U. i Choose a random number And calculate Send to TN TN stands for edge device U i Random selection And calculate And Store it. Edge device acquisition. U is the key used for signing. sigi Subsequently, the system administrator will issue a digital certificate for each edge device. Through the registration process, each edge device participating in the network will obtain its own public key, private key, signing key, and digital certificate.
[0166] The key generation method described above is existing technology and will not be detailed here.
[0167] Step 2: Send a data transmission request;
[0168] This section will process data transmission requests submitted to the system by the data sender. In this embodiment, the initial processing of the request is performed by a smart contract running on the blockchain.
[0169] The smart contract checks the state involved in the data transmission request and compares it with the set of attributes related to the state. When the request meets the constraints, the request is accepted by the blockchain and proceeds to the next step of processing.
[0170] Here, the attribute set includes pre-configured network access constraints, which may include location, time, and task content, etc.
[0171] The data transmission request includes: the identity information of the sender and receiver of the transmission request; the identity information includes machine attributes and status attributes.
[0172] Step 3: Distributing data transmission requests;
[0173] Here, the blockchain distributes the requests to the appropriate voters.
[0174] To securely distribute requests, the blockchain sends the data transmission request to each voter through a channel protected by a security protocol, based on the public keys of each participant in the blockchain.
[0175] Step 4: Attribute retrieval;
[0176] Voters read attribute values from the attribute server (AS) to obtain the attribute information required for each request validation.
[0177] The attribute server stores the status attributes of the edge device at various points in time, such as the flight path of the edge device and the location of the edge device at a certain moment.
[0178] Here, each edge device has a blockchain node (also referred to as a wallet in this article). The administrator of the edge device network distributes keys to the edge devices through a key management contract, and the edge devices obtain keys from a secure database managed by the blockchain (pre-configured through a key-sharing mechanism).
[0179] When a new edge device (as a blockchain node) joins the edge device network, it obtains a key by sending a transaction through a key management contract. After verifying the edge device's identity, the contract provides the edge device with the key containing unlock count information. The edge device then stores the key in a wallet managed by the blockchain system.
[0180] When an edge device leaves the edge device network, the edge device network administrator retrieves the key from the wallet via a key management contract.
[0181] When a new edge device joins the edge device network, the previously retrieved key is distributed to the new edge device's wallet. The edge device controller's wallet is also assigned a key that can unlock the property server indefinitely, and obtains the property server's address through a key management contract.
[0182] To facilitate the matching of communication attributes of edge devices, the edge device (voter) needs to send its key to the attribute server. The edge device controller then sends its key to the attribute server via a key management contract using the attribute server's address information to access the attribute server. The contract manages the key, decrements the edge device's key unlock count by one, and updates information to both the edge device and the administrator.
[0183] When the property server receives the edge device's key from the key management contract, it records the number of times the edge device unlocks the property server to prove whether the edge device has the right to access the property server through the key management contract. When the edge device sends its key to the property server, the property server records the number of times the edge device's key is unlocked to verify the behavior of the edge device's key distribution operation. After the property server receives multiple keys from the edge device and its controller, the edge device and controller can access the property server and find the corresponding state attributes based on the time points in the communication requests from the communicating edge devices. Then, voters compare these state attributes with the state attributes contained in the communication requests to obtain matching results. Here, the edge device controller also acts as a voter.
[0184] To allocate keys to edge devices and edge device controllers for accessing the property server, the Shamir(t, n) threshold key sharing mechanism can be used. The blockchain broadcasts communication requests from the communicating edge devices to the voting edge devices. When a voting edge device receives a request and agrees to vote to verify the properties of the communicating edge device, it sends this agreement message to the edge device controller. The edge device controller sends its key to the property server, informing the property server of the number of keys from the voting edge devices to access the property server and retrieve the desired properties. The threshold key 't' is set to the minimum number of voting edge devices. When the minimum value is reached, the edge device controller allows the voting edge devices to vote; otherwise, the blockchain continues broadcasting communication requests until the number of voting edge devices is greater than or equal to 't'.
[0185] Because of the (t, n) threshold key management, the key is distributed into n fragments. If any t individuals among the n individuals holding fragments cooperate, the original key can be recovered and a vote can be taken.
[0186] In the above scheme, the process of obtaining attribute information based on the key is existing technology, and those skilled in the art can also use other key processing methods.
[0187] Step 5: Verification and Consensus;
[0188] This step primarily aims to achieve consensus among all voters. Before the edge device can successfully execute the task (transmit data), the property server needs to verify the edge device. Therefore, the system administrator, property server, voters, and the edge device that needs to execute the task must ensure consistency (through a blockchain consensus algorithm) to ensure successful task execution by the edge device. Specifically:
[0189] The system administrator distributes private keys and property server addresses to edge devices in the system via smart contracts. The edge devices then store these private keys and property server addresses in their own wallets. Similarly, a key management contract distributes the private keys and property server addresses to the edge device controllers.
[0190] When an edge device about to perform a task needs to pass attribute verification, a subset of edge devices in the entire system can participate in the attribute verification. The edge device controller can obtain the attributes of the edge device about to perform the task by accessing the attribute server.
[0191] Edge devices for attribute verification are selected based on a key management contract, and the number of these edge devices should exceed a preset threshold (a threshold required by cryptographic principles). Edge device controllers can access the attribute server through these edge devices, and voters can obtain the attributes of the edge devices to determine whether they can perform tasks. During this determination process, all operations performed by entities are recorded in the blockchain after reaching consensus through a blockchain consensus algorithm. This ensures that a few malicious nodes cannot tamper with or affect the correct execution of the trusted communication process, and that all processes are reliably documented.
[0192] As can be seen, this embodiment of the invention achieves trusted distributed authentication between dynamic network devices through a blockchain system, avoiding system failure caused by a single point of failure. Simultaneously, through the blockchain consensus algorithm, the system can be guaranteed to tolerate a small number of malicious nodes (when using a Byzantine consensus algorithm, it can tolerate 1 / 3 of malicious nodes), thus providing higher security.
[0193] Furthermore, by leveraging the immutable and traceable characteristics of the blockchain system, traceable evidence storage (all written to the blockchain) of all communication and authentication processes in the edge device network is achieved, enabling auditing and tracing of communication processes during task execution, as well as evidence storage and investigation of attacks after they are received.
[0194] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. A method for trusted group communication in dynamic networks, characterized in that, This method is applied to a first edge device in a dynamic network, where the first edge device is selected as a voting node in a blockchain system. The blockchain system also includes an attribute server that stores attribute information of registered edge devices. The method includes: The system receives a data transmission request from a second edge device distributed by the blockchain. The second edge device is a registered edge device that is about to join the dynamic network. The data transmission request includes the identity information of the sending edge device and the receiving edge device. The identity information includes the machine attributes and state attributes of the edge device. The attribute information of the second edge device is obtained from the attribute server based on the data transmission request, and the obtained attribute information is compared with the attribute information in the data transmission request. The comparison results based on attribute information are used to reach a consensus with other voting nodes in the blockchain system. If the number of voting nodes with the same comparison result is greater than or equal to a preset value, the data transmission request of the second edge device is approved. The step of obtaining the attribute information of the second edge device from the attribute server based on the data transmission request includes: Obtain the machine attributes of the second edge device from the data transmission request; Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet; Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
2. The method according to claim 1, characterized in that, When the first edge device is the leader node in the blockchain system, before receiving the data transmission request from the second edge device distributed by the blockchain, the method further includes: The identity information of the sending edge device and the receiving edge device of the data transmission request is verified based on the smart contract. If the verification is successful, the data transmission request is distributed to other voting nodes in the blockchain system; otherwise, the data transmission request of the second edge device is rejected.
3. The method according to claim 1, characterized in that, After reaching consensus with other voting nodes in the blockchain system, the method further includes: Write the following content into the blockchain: The result of consensus; After the data transmission request of the second edge device is approved, the second edge device will then perform the relevant data transmission operations.
4. The method according to claim 1, characterized in that, When the comparison result based on attribute information is used to reach consensus with other voting nodes in the blockchain system, the method further includes: If the comparison result shows that the number of identical voting nodes is less than a preset value, the data transmission request of the second edge device is rejected.
5. The method according to claim 1, characterized in that, Before receiving the data transmission request from the second edge device distributed by the blockchain, the method further includes: Receive the public key, private key, and digital certificate configured and issued by the system administrator for the first edge device during the edge device registration phase.
6. The method according to claim 1, characterized in that, The voting nodes in the blockchain system are: edge devices and / or edge device controllers and / or cloud devices.
7. A dynamic network trusted group communication device, characterized in that, The device is applied to a first edge device in a dynamic network, which is selected as a voting node in a blockchain system. The blockchain system also includes an attribute server that stores attribute information of registered edge devices. The device comprises: The transceiver module is used to receive data transmission requests from a second edge device distributed by the blockchain; the second edge device is a registered edge device that is to be pre-joined in the dynamic network; wherein, the data transmission request includes the identity information of the sending edge device and the receiving edge device; the identity information includes the machine attributes and status attributes of the edge device; An attribute processing module is used to obtain attribute information of the second edge device from the attribute server based on the data transmission request, and compare the obtained attribute information with the attribute information in the data transmission request; The consensus processing module is used to reach a consensus with other voting nodes in the blockchain system based on the comparison results of attribute information. If the number of voting nodes with the same comparison result is greater than or equal to a preset value, the data transmission request of the second edge device is approved. The attribute processing module is further configured to obtain the machine attributes of the second edge device from the data transmission request; Obtain the private key and property server address of the first edge device distributed by the system administrator from the first edge device's own wallet; Based on the private key and the address of the attribute server, the status attribute corresponding to the machine attribute of the second edge device is obtained from the attribute server.
8. A dynamic network trusted group communication system, characterized in that, This system is a fusion of dynamic network systems and blockchain systems, including: A first edge device in a dynamic network is used to receive data transmission requests from a second edge device distributed by the blockchain. The data transmission request includes the identity information of the sending and receiving edge devices. The identity information includes the machine attributes and state attributes of the edge devices. Based on the data transmission request, the device retrieves attribute information of the second edge device from an attribute server in the blockchain system and compares the retrieved attribute information with the attribute information in the data transmission request. Based on the comparison result, the device reaches consensus with other voting nodes in the blockchain system. If the number of identical voting nodes is greater than or equal to a preset value, the device agrees to the data transmission request of the second edge device. The attribute server in the blockchain system is used to store the attribute information of registered edge devices; The first edge device is selected as a voting node in the blockchain system; the second edge device is a registered edge device that is to be pre-joined in the dynamic network. The step of obtaining the attribute information of the second edge device from the attribute server in the blockchain system based on the data transmission request includes: obtaining the machine attribute of the second edge device from the data transmission request; obtaining the private key of the first edge device distributed by the system administrator and the address of the attribute server from the wallet of the first edge device itself; and obtaining the status attribute corresponding to the machine attribute of the second edge device from the attribute server based on the private key and the address of the attribute server.
9. A dynamic network trusted group communication device, characterized in that, The device includes: a processor and a memory for storing computer programs that can run on the processor. When the processor is used to run the computer program, it performs the steps of the method according to any one of claims 1-6.
10. A readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1-6.
Citation Information
Patent Citations
Edge trajectory protection method based on block chain
CN113656831A
Block chain-based access control method capable of hiding policies and attributes
CN113836222A