A secure communication system, method, and storage medium

By leveraging blockchain technology and the Industrial Internet identifier resolution system, a dataset is constructed for both devices and servers to perform identity authentication and key exchange. This solves the security and data exchange issues between IoT platforms and smart devices, enabling secure access and data communication for devices from multiple manufacturers and of various types.

CN117294417BActive Publication Date: 2026-08-04PIPECHINA SOUTH CHINA CO +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PIPECHINA SOUTH CHINA CO
Filing Date
2023-10-09
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In industrial scenarios, the security of identity authentication between IoT platforms and smart devices varies, and the protection of communication keys is insufficient, resulting in low communication security. Furthermore, existing data exchange methods have poor applicability in large-scale scenarios with multiple product categories, high integration costs, and the risk of communication key leakage.

Method used

By using blockchain technology to construct user terminal and server datasets, commands are initiated through device and server identity authentication, device and server identity authentication results are generated, and key exchange is carried out to establish a secure communication link. Data exchange is realized by combining the industrial internet identifier resolution system and smart contracts.

Benefits of technology

It enables secure access for devices from multiple manufacturers, of various types, and in large quantities, reducing the difficulty and cost of connecting new devices to the IoT platform, improving data communication security, avoiding replay attacks, tampering attacks, and man-in-the-middle attacks, and ensuring the security of devices and data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117294417B_ABST
    Figure CN117294417B_ABST
Patent Text Reader

Abstract

The application provides a kind of secure communication system, method and storage medium, belong to communication security field, according to user terminal equipment data, user terminal data set and user terminal secret key are constructed;According to the device identity authentication initiation instruction, user terminal secret key and user terminal data set, device identity authentication result is obtained by device identity authentication;Import server data, according to server data, server data set and server secret key are constructed;According to the server identity authentication initiation instruction, server secret key and server data set, server identity authentication result is obtained by server identity authentication;According to the server identity authentication result and user terminal secret key, secure communication result is obtained by secret key exchange.The application is used for the scene of multi-manufacturer, multi-type, large quantity of equipment security access between internet of things platform and device based on two-way identity authentication to establish secure communication link, effectively reduces the difficulty and cost of new equipment access of internet of things platform, and improves data communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates primarily to the field of communication security technology, specifically to a secure communication system, method, and storage medium. Background Technology

[0002] In industrial settings, such as Figure 2 As shown, smart devices are typically manufactured by equipment manufacturers, who initialize information such as device identification and root keys during the production phase. Users purchase the devices from manufacturers, who then install and deliver them to the user's actual industrial environment. For considerations of real-time performance, security, privacy, and intelligence, edge computing often employs near-field deployment of platform software for computation and storage.

[0003] In edge computing scenarios, numerous security issues persist between IoT platforms and smart devices. Existing technologies primarily focus on device authentication, but the security of authentication methods varies significantly, posing risks of impersonation and forgery. Furthermore, while secure communication between platforms and devices often relies on encryption via communication keys, insufficient protection measures are in place for core data such as communication keys (either the keys are fixed or their update process is insecure), resulting in overall low security for communication between platforms and devices. Regarding data exchange, existing security systems lack secure, reliable, and universally applicable data exchange channels between users and device manufacturers. Traditional methods like data import / export and interface integration are commonly used for data sharing, but these techniques are poorly suited for large-scale, multi-category scenarios, incur high integration costs, and lack adequate sharing strategies and update mechanisms for communication keys, posing a risk of key leakage and directly impacting overall security. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a secure communication system, method and storage medium to address the shortcomings of the prior art.

[0005] The technical solution of this invention to solve the above-mentioned technical problems is as follows: A secure communication system, comprising: a manufacturing terminal, a blockchain, an Internet of Things platform, and a user terminal.

[0006] The manufacturing terminal is used to import data from multiple user terminal devices, and to construct a user terminal dataset and multiple user terminal keys based on the data from the multiple user terminal devices.

[0007] The user terminal is used to generate a device authentication initiation command;

[0008] The blockchain is used to perform device identity authentication based on the device identity authentication initiation command, multiple user terminal keys and the user terminal dataset, and obtain the device identity authentication result.

[0009] The IoT platform is used to import multiple server-side data, and construct a server-side dataset and multiple server-side keys based on the multiple server-side data.

[0010] The user terminal is also used to generate a server-side authentication initiation command based on the device authentication result.

[0011] The blockchain is also used to perform server identity authentication based on the server identity authentication initiation command, multiple server keys and the server dataset, and obtain the server identity authentication result.

[0012] The user terminal is also used to exchange keys based on the server's authentication result and multiple user terminal keys to obtain a secure communication result.

[0013] Another technical solution of the present invention to solve the above-mentioned technical problems is as follows: A secure communication method, comprising the following steps:

[0014] Import data from multiple user terminal devices, and construct a user terminal dataset and multiple user terminal keys based on the data from the multiple user terminal devices;

[0015] Generate device authentication initiation command;

[0016] Based on the device identity authentication initiation command, multiple user terminal keys, and the user terminal dataset, device identity authentication is performed to obtain the device identity authentication result.

[0017] Import multiple server-side data, and construct a server-side dataset and multiple server-side keys based on the multiple server-side data;

[0018] Generate a server-side authentication initiation command based on the device authentication result;

[0019] Based on the server-side authentication initiation command, multiple server-side keys, and the server-side dataset, server-side authentication is performed to obtain the server-side authentication result.

[0020] Based on the server-side authentication result and the multiple user terminal keys, a key exchange is performed to obtain a secure communication result.

[0021] The beneficial effects of this invention are as follows: By constructing a user terminal dataset and user terminal key based on user terminal device data, obtaining device identity authentication results based on device identity authentication initiation command, multiple user terminal keys, and user terminal dataset, constructing a server dataset and server key based on server data, generating a server identity authentication initiation command based on device identity authentication results, obtaining server identity authentication results based on server identity authentication initiation command, server key, and server dataset, and obtaining secure communication results through key exchange based on server identity authentication results and user terminal keys, this invention enables the establishment of secure communication links between IoT platforms and devices based on two-way identity authentication in scenarios involving multiple manufacturers, various types, and large quantities of devices. This effectively reduces the difficulty and cost of new device access to IoT platforms and improves data communication security. Attached Figure Description

[0022] Figure 1 This is a block diagram of a secure communication system provided in an embodiment of the present invention;

[0023] Figure 2 This is a logical diagram illustrating device manufacturing, users, and an Internet of Things platform according to an embodiment of the present invention.

[0024] Figure 3 A flowchart of identifier resolution provided in an embodiment of the present invention;

[0025] Figure 4 This is a system architecture diagram of a secure communication system provided in an embodiment of the present invention;

[0026] Figure 5 This is a flowchart illustrating a secure communication system provided in an embodiment of the present invention;

[0027] Figure 6 This is a flowchart illustrating a secure communication method provided in an embodiment of the present invention. Detailed Implementation

[0028] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0029] Figure 1 This is a block diagram of a secure communication system provided in an embodiment of the present invention.

[0030] like Figure 1 As shown, a secure communication system includes: a manufacturing terminal, a blockchain, an IoT platform, and a user terminal.

[0031] The manufacturing terminal is used to import data from multiple user terminal devices, and to construct a user terminal dataset and multiple user terminal keys based on the data from the multiple user terminal devices.

[0032] The user terminal is used to generate a device authentication initiation command;

[0033] The blockchain is used to perform device identity authentication based on the device identity authentication initiation command, multiple user terminal keys and the user terminal dataset, and obtain the device identity authentication result.

[0034] The IoT platform is used to import multiple server-side data, and construct a server-side dataset and multiple server-side keys based on the multiple server-side data.

[0035] The user terminal is also used to generate a server-side authentication initiation command based on the device authentication result.

[0036] The blockchain is also used to perform server identity authentication based on the server identity authentication initiation command, multiple server keys and the server dataset, and obtain the server identity authentication result.

[0037] The user terminal is also used to exchange keys based on the server's authentication result and multiple user terminal keys to obtain a secure communication result.

[0038] It should be understood that the manufacturing terminal may be an equipment manufacturer, and the user terminal may be an Internet of Things (IoT) device such as a smart gateway, smart access control system, smart instrumentation, or robot.

[0039] It should be understood that the device identity authentication result is sent to the device (i.e., the user terminal) to complete the device identity verification process.

[0040] It should be understood that the server-side authentication result is sent to the device (i.e., the user terminal) to complete the server-side identity verification process.

[0041] In the above embodiments, by constructing a user terminal dataset and user terminal key based on user terminal device data, obtaining a device identity authentication result based on the device identity authentication initiation command, multiple user terminal keys, and the user terminal dataset, constructing a server dataset and server key based on server data, generating a server identity authentication initiation command based on the device identity authentication result, obtaining a server identity authentication result based on the server identity authentication initiation command, server key, and server dataset, and obtaining a secure communication result through key exchange based on the server identity authentication result and the user terminal key, a secure communication link is established between the IoT platform and devices based on two-way identity authentication in scenarios involving multiple manufacturers, multiple types, and large quantities of devices. This effectively reduces the difficulty and cost of new device access to the IoT platform and improves data communication security.

[0042] Optionally, as an embodiment of the present invention, such as Figure 1 and Figure 3 As shown, in the manufacturing terminal, the process of constructing a user terminal dataset and multiple user terminal keys based on data from multiple user terminal devices includes:

[0043] Each user terminal device data is assigned an identifier to obtain user terminal identifier data corresponding to each user terminal device data.

[0044] Generate multiple user terminal keys corresponding to the user terminal device data, and obtain the original user terminal public key corresponding to each user terminal device data from each of the user terminal keys;

[0045] The blockchain is used to generate an original user terminal public key ID corresponding to the data of each user terminal device based on the original user terminal public key of each original user terminal.

[0046] The manufacturing terminal is also used to take each user terminal identification data and the original user terminal public key ID corresponding to each user terminal device data as device identification registration data corresponding to each user terminal device data, and construct a dataset of all the device identification registration data through an identifier resolution system tool to obtain a user terminal dataset.

[0047] It should be understood that each of the aforementioned user terminal device data is assigned an identifier, i.e., device coding.

[0048] Specifically, before installation and delivery, the equipment manufacturer completes equipment data collection, equipment coding (i.e., assigning identifiers to the data of each user terminal device), key initialization, public key uploading to the blockchain, and finally registers the equipment information, equipment public key storage blockchain ID, and other information to the enterprise node in the form of identifier registration.

[0049] Specifically, such as Figure 3 As shown, the Industrial Internet Identifier Resolution System (i.e., the Identifier Resolution System Tool), as an important component of the Industrial Internet network architecture, is equivalent to the Domain Name System (DNS) in the Internet field. It is one of the core infrastructures of the Industrial Internet, and its core consists of two parts: identifier coding and the resolution system. The identifier code serves as the "identity card" for machines, items, and digital objects, possessing uniqueness. The resolution system utilizes the identifier to uniquely locate and query information about machines, items, and digital objects. The specific process is as follows:

[0050] Step 1: The identification application sends an identification resolution request to the recursive resolution node to obtain the identification information;

[0051] Steps 2 and 3: The recursive parsing node sends an identifier resolution request to the root node to obtain the information of the first-level node to which the identifier belongs; the root node accepts and responds to the identifier resolution request sent by the recursive parsing node, retrieves the corresponding first-level node for the identifier by querying the registration information, and returns the first-level node information to the recursive parsing node.

[0052] Steps 4 and 5: The recursive parsing node sends an identifier resolution request to the first-level node to obtain the information of the second-level node to which the identifier belongs; the first-level node accepts and responds to the identifier resolution request sent by the recursive parsing node, retrieves the second-level node that responded with the prefix by querying the registration information, and returns the second-level node information to the recursive parsing node.

[0053] Steps 6 and 7: The recursive parsing node sends an identifier resolution request to the second-level node to obtain the information of the third-level node to which the identifier belongs; the second-level node accepts and responds to the identifier resolution request sent by the recursive parsing node, retrieves the third-level node that responded with the prefix by querying the registration information, and returns the third-level node information to the recursive parsing node.

[0054] Steps 8 and 9 (optional): The recursive parsing node sends an identifier resolution request to the third-level node to obtain the resolution result; the third-level node is responsible for accepting and responding to the identifier resolution request sent by the recursive parsing node, retrieving the value set corresponding to the identifier by querying the local database, and returning the resolution result to the recursive parsing node.

[0055] Step 10: The recursive parsing node returns the parsing result to the identifier application. The parsing result can be the value set corresponding to the identifier, or the information of the third-level node to which the identifier belongs.

[0056] Steps 11 and 12 (optional): When the identification application obtains the resolution result from the recursive resolution node as the information of the third-level node to which the identification belongs, the identification application directly sends an identification resolution request to the third-level node to which the identification belongs in order to obtain the identification information; the third-level node to which the identification belongs is responsible for accepting and responding to the identification resolution request, retrieving the value set corresponding to the identification by querying the local database, and returning the resolution result to the identification application.

[0057] In the above embodiments, a user terminal dataset and multiple user terminal keys are constructed based on data from multiple user terminal devices, effectively avoiding replay attacks, tampering attacks, and man-in-the-middle attacks, and ensuring data security, device security, and cloud service security.

[0058] Optionally, as an embodiment of the present invention, in the blockchain, the process of performing device identity authentication based on the device identity authentication initiation command, multiple user terminal keys, and the user terminal dataset to obtain the device identity authentication result includes:

[0059] Generate a device identity challenge code based on the device identity authentication initiation command;

[0060] The user terminal is used to filter out the user terminal private key from a plurality of user terminal keys according to a preset device identification code;

[0061] The device identity challenge code is hashed using the first signature algorithm to obtain the hashed device identity challenge code.

[0062] The hashed device identity challenge code is encrypted using the user terminal private key to obtain the device identity authentication code.

[0063] The IoT platform is used to send the device identity challenge code and the device identity authentication code to the blockchain according to the first smart contract protocol;

[0064] The blockchain is used to obtain the target public key ID from the user terminal dataset according to the preset device identification code, and to obtain the target user terminal public key according to the target public key ID;

[0065] The device authentication code is decoded based on the target user terminal public key to obtain the device authentication source data;

[0066] The device identity challenge code is hashed using the first signature algorithm to obtain the device identity verification code;

[0067] The device identity verification code is authenticated based on the device identity authentication source data to obtain the device identity authentication result.

[0068] It should be understood that the first signature algorithm refers to a digital signature algorithm. A digital signature is a string of numbers that only the sender of the information can generate and that cannot be forged by others. This string of numbers also serves as valid proof of the authenticity of the information sent by the sender. A digital signature is an alphanumeric string obtained by processing the information to be transmitted through a one-way function, used to authenticate the source of the information and verify whether the information has been altered during transmission. The three most widely used signature algorithms are: Rabin signature, DSS signature, and RSA signature.

[0069] Specifically, the user terminal private key is selected from multiple user terminal keys according to the preset device identification code. That is, the user terminal key corresponding to the preset device identification code is first selected from multiple user terminal keys according to the preset device identification code, and the user terminal private key is extracted from the selected user terminal key.

[0070] It should be understood that the first smart contract protocol is a computer protocol designed to disseminate, verify, or execute contracts in an informational manner. Smart contracts allow for trusted transactions without the need for a third party; these transactions are traceable and irreversible. The purpose of smart contracts is to provide a security approach superior to traditional contracts and to reduce other transaction costs associated with contracts.

[0071] To understand, hashing transforms an input of arbitrary length (also called a pre-image) into a fixed-length output, known as a hash value, using a hash algorithm. This transformation is a compression mapping; that is, the space of hash values ​​is usually much smaller than the space of inputs. Different inputs may hash to the same output, so it is impossible to determine a unique input value from the hash value. Simply put, it is a function that compresses a message of arbitrary length into a message digest of a fixed length.

[0072] Specifically, the authentication code generation algorithm (i.e., hashing the device identity challenge code using the first signature algorithm to obtain the hashed device identity challenge code; encrypting the hashed device identity challenge code according to the user terminal's private key to obtain the device identity authentication code) is as follows:

[0073] The challenge code signature is given by `sign = hash(challenge_code)`.

[0074] Authenticator code auth_code = crypt(sign),

[0075] Here, hash is a digest generation function, such as MD5; crypt is an asymmetric encryption function, such as RSA.

[0076] Specifically, the device applies for a challenge code (i.e., device identity challenge code) from the blockchain via an IoT platform using a smart contract (smart contract 1). After obtaining the challenge code challenge_code1 (i.e., device identity challenge code), the device hashes the challenge code (i.e., device identity challenge code) using a signature algorithm (i.e., the first signature algorithm), and encrypts the hash result (i.e., the hashed device identity challenge code) with the device's private key (i.e., the user terminal's private key) to generate an authentication code auth_code (i.e., device identity authentication code). The device then sends the authentication code auth_code (i.e., device identity authentication code) and the original challenge code challenge_code1 (i.e., device identity challenge code) to the blockchain via the IoT platform. The blockchain smart contract (Smart Contract 2) obtains the blockchain address of the device's public key based on the device's identification code and through the identification resolution process of the Industrial Internet Identifier Resolution System (i.e., the user terminal dataset), thereby obtaining the device's public key (i.e., the target user terminal public key). The blockchain smart contract decodes the authentication code auth_code (i.e., the device identity authentication code) using the device's public key (i.e., the target user terminal public key) to obtain the source data of the authentication code (Source Data 1) (i.e., the device identity authentication source data). The blockchain smart contract uses the same signature algorithm to hash the challenge code (i.e., the device identity challenge code) to obtain the verification code Check_code (i.e., the device identity verification code).

[0077] In the above embodiments, device identity authentication is performed based on the device identity authentication initiation command, multiple user terminal keys, and user terminal dataset to obtain the device identity authentication result. This achieves secure data communication between the IoT platform and the user terminal, while ensuring that device manufacturers only need to connect once to adapt to multiple IoT platforms, and IoT platform developers only need to connect once to access IoT devices from multiple manufacturers and of multiple types, thus reducing the connection cost.

[0078] Optionally, as an embodiment of the present invention, in the blockchain, the process of authenticating the device identity verification code based on the device identity authentication source data to obtain the device identity authentication result includes:

[0079] Verify whether the device identity authentication source data is the same as the device identity verification code. If the verification is successful, the first preset device identity authentication information is used as the device identity authentication result; if the verification fails, the second preset device identity authentication information is used as the device identity authentication result.

[0080] It should be understood that the first preset device identity authentication information can be valid device identity verification, and the second preset device identity authentication information can be invalid device identity verification.

[0081] Specifically, the source data (source data 1) of the verification code (i.e., device identity verification code) and the authentication code auth_code (i.e., device identity authentication source data) are compared in the form of string comparison. If the comparison results are consistent, the device identity verification is valid; otherwise, the device identity is invalid.

[0082] In the above embodiments, the device identity verification code is authenticated based on the device identity authentication source data to obtain the device identity authentication result. This achieves secure data communication between the IoT platform and smart devices, while ensuring that device manufacturers only need to connect once to adapt to multiple IoT platforms, and IoT platform developers only need to connect once to access IoT devices from multiple manufacturers and of multiple types, thus reducing the connection cost.

[0083] Optionally, as an embodiment of the present invention, such as Figure 1 and Figure 3 As shown, in the IoT platform, the process of constructing a server-side dataset and multiple server-side keys based on multiple server-side data includes:

[0084] Each of the server-side data is assigned an identifier to obtain server-side identifier data corresponding to each of the server-side data.

[0085] Generate multiple server keys corresponding to the server data, and obtain the original server public key corresponding to each of the server data from each of the server keys;

[0086] The blockchain is used to generate an original server public key ID corresponding to each of the server data based on each of the original server public keys.

[0087] The IoT platform is also used to take each of the server identifier data and the original server public key ID corresponding to each of the server data as server identifier registration data corresponding to each of the server data, and construct a dataset for all the server identifier registrations through the identifier resolution system tool to obtain the server dataset.

[0088] It should be understood that assigning an identifier to each of the aforementioned server-side data is equivalent to server-side coding.

[0089] Specifically, the IoT platform completes server-side data collection, server-side coding (i.e., assigning identifiers to each of the server-side data), key initialization, public key uploading to the blockchain, and finally registers server-side information, server-side public key storage blockchain ID, and other information to the enterprise node in the form of identifier registration.

[0090] Specifically, such as Figure 3As shown, the Industrial Internet Identifier Resolution System (i.e., the Identifier Resolution System Tool), as an important component of the Industrial Internet network architecture, is equivalent to the Domain Name System (DNS) in the Internet field. It is one of the core infrastructures of the Industrial Internet, and its core consists of two parts: identifier coding and the resolution system. The identifier code serves as the "identity card" for machines, items, and digital objects, possessing uniqueness. The resolution system utilizes the identifier to uniquely locate and query information about machines, items, and digital objects. The specific process is as follows:

[0091] Step 1: The identification application sends an identification resolution request to the recursive resolution node to obtain the identification information;

[0092] Steps 2 and 3: The recursive parsing node sends an identifier resolution request to the root node to obtain the information of the first-level node to which the identifier belongs; the root node accepts and responds to the identifier resolution request sent by the recursive parsing node, retrieves the corresponding first-level node for the identifier by querying the registration information, and returns the first-level node information to the recursive parsing node.

[0093] Steps 4 and 5: The recursive parsing node sends an identifier resolution request to the first-level node to obtain the information of the second-level node to which the identifier belongs; the first-level node accepts and responds to the identifier resolution request sent by the recursive parsing node, retrieves the second-level node that responded with the prefix by querying the registration information, and returns the second-level node information to the recursive parsing node.

[0094] Steps 6 and 7: The recursive parsing node sends an identifier resolution request to the second-level node to obtain the information of the third-level node to which the identifier belongs; the second-level node accepts and responds to the identifier resolution request sent by the recursive parsing node, retrieves the third-level node that responded with the prefix by querying the registration information, and returns the third-level node information to the recursive parsing node.

[0095] Steps 8 and 9 (optional): The recursive parsing node sends an identifier resolution request to the third-level node to obtain the resolution result; the third-level node is responsible for accepting and responding to the identifier resolution request sent by the recursive parsing node, retrieving the value set corresponding to the identifier by querying the local database, and returning the resolution result to the recursive parsing node.

[0096] Step 10: The recursive parsing node returns the parsing result to the identifier application. The parsing result can be the value set corresponding to the identifier, or the information of the third-level node to which the identifier belongs.

[0097] Steps 11 and 12 (optional): When the identification application obtains the resolution result from the recursive resolution node as the information of the third-level node to which the identification belongs, the identification application directly sends an identification resolution request to the third-level node to which the identification belongs in order to obtain the identification information; the third-level node to which the identification belongs is responsible for accepting and responding to the identification resolution request, retrieving the value set corresponding to the identification by querying the local database, and returning the resolution result to the identification application.

[0098] In the above embodiments, a server-side dataset and multiple server-side keys are constructed based on multiple server-side data, realizing end-to-end encryption in data communication scenarios between the IoT platform and devices. This meets the secure access requirements of multiple manufacturers, multiple types, and large quantities of devices in industrial scenarios, and effectively reduces the difficulty and cost of connecting new devices to the IoT platform.

[0099] Optionally, as an embodiment of the present invention, in the blockchain, the process of performing server-side identity authentication based on the server-side identity authentication initiation command, multiple server-side keys, and the server-side dataset to obtain the server-side identity authentication result includes:

[0100] The IoT platform is used to generate a server-side identity challenge code generation instruction based on the server-side identity authentication initiation instruction.

[0101] The blockchain is used to generate a server-side identity challenge code according to the server-side identity challenge code generation instruction.

[0102] The IoT platform is also used to filter out a server private key from a plurality of server keys according to a preset server identifier code;

[0103] The server-side identity challenge code is hashed using the second signature algorithm to obtain the hashed server-side identity challenge code.

[0104] The hashed server identity challenge code is encrypted using the server's private key to obtain the server identity authentication code.

[0105] The server-side identity challenge code and the server-side identity authentication code are sent to the blockchain in accordance with the second smart contract protocol;

[0106] The blockchain is also used to obtain the target server public key ID from the server dataset according to the preset server identifier code, and to obtain the target server public key according to the target server public key ID;

[0107] The server authentication code is decoded using the target server public key to obtain the server authentication source data.

[0108] The server-side identity challenge code is hashed using the second signature algorithm to obtain the server-side identity verification code.

[0109] The server identity verification code is authenticated based on the server identity authentication source data to obtain the server identity authentication result.

[0110] It should be understood that the second signature algorithm refers to the algorithm for digital signatures. A digital signature is a string of numbers that only the sender of the information can generate and that cannot be forged by others. This string of numbers also serves as valid proof of the authenticity of the information sent by the sender. A digital signature is an alphanumeric string obtained by processing the information to be transmitted through a one-way function, used to authenticate the source of the information and verify whether the information has been altered during transmission. The three most widely used signature algorithms are: Rabin signature, DSS signature, and RSA signature.

[0111] Specifically, the server private key is selected from multiple server keys according to the preset server identifier code. That is, the server key corresponding to the preset server identifier code is first selected from multiple server keys according to the preset server identifier code, and the server private key is extracted from the selected server key.

[0112] It should be understood that the second smart contract protocol is a computer protocol designed to disseminate, verify, or execute contracts in an informational manner. Smart contracts allow for trusted transactions without the need for a third party; these transactions are traceable and irreversible. The purpose of smart contracts is to provide a security approach superior to traditional contracts and to reduce other transaction costs associated with contracts.

[0113] To understand, hashing transforms an input of arbitrary length (also called a pre-image) into a fixed-length output, known as a hash value, using a hash algorithm. This transformation is a compression mapping; that is, the space of hash values ​​is usually much smaller than the space of inputs. Different inputs may hash to the same output, so it is impossible to determine a unique input value from the hash value. Simply put, it is a function that compresses a message of arbitrary length into a message digest of a fixed length.

[0114] Specifically, the authentication code generation algorithm (i.e., hashing the server-side identity challenge code using the second signature algorithm to obtain the hashed server-side identity challenge code; encrypting the hashed server-side identity challenge code using the server-side private key to obtain the server-side authentication code) is as follows:

[0115] The challenge code signature is given by `sign = hash(challenge_code)`.

[0116] Authenticator code auth_code = crypt(sign),

[0117] Here, hash is a digest generation function, such as MD5; crypt is an asymmetric encryption function, such as RSA.

[0118] Specifically, the device requests a challenge code (i.e., the server-side identity challenge code) from the blockchain via an IoT platform using a smart contract (smart contract 1). After obtaining the challenge code challenge_code1 (i.e., the server-side identity challenge code), the device hashes the challenge code (i.e., the server-side identity challenge code) using a signature algorithm (i.e., the second signature algorithm), and encrypts the hash result (i.e., the hashed server-side identity challenge code) with the server's private key to generate an authentication code auth_code (i.e., the server-side identity authentication code). The device then sends the authentication code auth_code (i.e., the server-side identity authentication code) and the original challenge code challenge_code1 (i.e., the server-side identity challenge code) to the blockchain via the IoT platform. The blockchain smart contract (smart contract 2) obtains the blockchain address of the device's public key based on the device's identification code and through the identification resolution process of the Industrial Internet Identifier Resolution System (i.e., the server-side dataset), thereby obtaining the device's public key (i.e., the target server-side public key); the blockchain smart contract decodes the authentication code auth_code (i.e., the server-side identity authentication code) using the device's public key (i.e., the target server-side public key) to obtain the source data of the authentication code (source data 1) (i.e., the server-side identity authentication source data); the blockchain smart contract uses the same signature algorithm to hash the challenge code (i.e., the server-side identity challenge code) to obtain the verification code Check_code (i.e., the server-side identity verification code).

[0119] In the above embodiments, server-side identity authentication is performed based on the server-side identity authentication initiation command, multiple server-side keys, and server-side dataset to obtain the server-side identity authentication result. This achieves end-to-end encryption for data communication between the IoT platform and devices, meets the secure access requirements of multiple manufacturers, types, and large quantities of devices in industrial scenarios, and effectively reduces the difficulty and cost of accessing new devices to the IoT platform.

[0120] Optionally, as an embodiment of the present invention, in the blockchain, the process of authenticating the server identity verification code based on the server identity authentication source data to obtain the server identity authentication result includes:

[0121] Verify whether the server-side identity authentication source data is the same as the server-side identity verification code. If the verification is successful, the first preset server-side identity authentication information is used as the server-side identity authentication result; if the verification fails, the second preset server-side identity authentication information is used as the server-side identity authentication result.

[0122] It should be understood that the first preset server-side identity authentication information can be valid server-side identity verification, and the second preset server-side identity authentication information can be invalid server-side identity verification.

[0123] Specifically, the source data (source data 1) of the verification code (i.e., the server-side identity verification code) and the authentication code auth_code (i.e., the server-side identity authentication source data) are compared in the form of string comparison. If the comparison results are consistent, the device identity verification is valid; otherwise, the device identity is invalid.

[0124] In the above embodiments, the server identity verification code is authenticated based on the server identity authentication source data to obtain the server identity authentication result, realizing end-to-end encryption in the data communication scenario between the IoT platform and the device. This meets the secure access requirements of multiple manufacturers, multiple types, and large quantities of devices in industrial scenarios, and effectively reduces the difficulty and cost of accessing new devices to the IoT platform.

[0125] Optionally, as an embodiment of the present invention, the process of exchanging keys in the user terminal based on the server authentication result and multiple user terminal keys to obtain a secure communication result includes:

[0126] Generate a key exchange instruction based on the server-side authentication result;

[0127] The IoT platform is used to generate a communication key according to the key exchange instruction;

[0128] The blockchain is used to encrypt the communication key based on the public key of the target user terminal to obtain the encrypted communication key;

[0129] The user terminal is used to decrypt the encrypted communication key according to the user terminal private key to obtain the decrypted communication key;

[0130] Import business data, and encrypt the business data according to the decrypted communication key to obtain encrypted business data;

[0131] The IoT platform is also used to decrypt the encrypted business data according to the communication key to obtain a secure communication result.

[0132] It should be understood that the encryption and decryption algorithm for the new communication key (i.e., the communication key) is as follows:

[0133] secret_str=crypt(session_secret),

[0134] session_secret=decrypt(secret_str),

[0135] Here, crypt and decrypt are the asymmetric encryption and decryption functions, respectively.

[0136] It should be understood that the target user terminal public key is the target public key ID obtained from the user terminal dataset according to the preset device identifier code, and the target user terminal public key obtained according to the target public key ID.

[0137] It should be understood that the user terminal private key is the user terminal private key selected from a plurality of user terminal keys according to a preset device identification code.

[0138] Specifically, the device (i.e., the user terminal) requests a new communication key from the IoT platform. After receiving the request, the IoT platform generates a new communication key session_secret and sends it to the blockchain. Relying on the smart contract (smart contract 3), the IoT platform encrypts the session_secret using the device's public key (i.e., the target user terminal's public key) to generate the encrypted session_secret, which is then sent to the device (i.e., the user terminal).

[0139] The device (i.e., the user terminal) uses its private key (i.e., the user terminal's private key) to encrypt the session_secret (i.e., the encrypted communication key) and obtain the session_secret (i.e., the decrypted communication key). At this point, the IoT platform and the device have completed the exchange of the new key, and all subsequent business data communication will use this session_secret for encryption and decryption.

[0140] In the above embodiments, a secure communication result is obtained by exchanging keys based on the server-side authentication result and the keys of multiple user terminals. This allows the exchange of new keys to be completed without the leakage of the root key of the IoT platform and smart devices, thereby improving data privacy and ensuring that the communication key is changed in a timely manner without the leakage of the root key. In particular, when the same device is connected to different IoT platforms, the communication key change is effectively avoided, such as replay attacks, tampering attacks, and man-in-the-middle attacks.

[0141] Alternatively, as another embodiment of the present invention, the present invention can solve the following security problems existing between the Internet of Things platform and smart devices, the security problems being as follows:

[0142] 1) The issue of two-way mutual trust between the platform and devices based on identity authentication

[0143] The IoT device of this invention remotely accesses a cloud server via an IoT access protocol. The server needs to verify the device's identity to ensure that messages from the device are legitimate and trustworthy; the device needs to verify the server's identity to ensure that commands from the server are legitimate and trustworthy.

[0144] 2) Secure communication between the platform and devices based on communication keys

[0145] After the device of this invention is installed and delivered in an industrial setting, it is connected to the cloud platform via the Internet of Things. In order to ensure data security, device security, and cloud service security, effective measures must be taken to prevent replay attacks, tampering attacks, man-in-the-middle attacks, etc. in data communication between the platform and the device.

[0146] 3) Trusted data exchange issues between users and equipment manufacturers

[0147] The IoT device authentication data of this invention is maintained on the manufacturer's server, and the device needs to perform identity authentication with the user's IoT platform when it is connected. A secure and reliable communication link is required between the two to achieve data exchange.

[0148] 4) Smart device key leakage issue

[0149] This invention introduces a mechanism to ensure that communication key exchange is completed in a timely manner without leaking the root key, especially when the same device is connected to different IoT platforms.

[0150] 5) Security communication compatibility issues when multiple manufacturers, various types, and large quantities of devices are connected to the IoT platform.

[0151] In industrial scenarios, there are often multiple manufacturers, various types, and large quantities of devices waiting to be connected to the IoT platform. The IoT platform urgently needs a universal and compatible secure communication strategy. This invention enables IoT devices to access the platform at low cost, high efficiency, and fast speed.

[0152] Optionally, as another embodiment of the present invention, the present invention realizes end-to-end encryption in the data communication scenario between the IoT platform and the device, meets the secure access requirements of multiple manufacturers, multiple types and large quantities of devices in industrial scenarios, and effectively reduces the difficulty and cost of accessing new devices to the IoT platform.

[0153] Alternatively, as another embodiment of the present invention, the invention is summarized as follows:

[0154] (1) The issue of mutual trust between the platform and devices based on identity authentication

[0155] To address the identity authentication issue between the platform and devices, a combination of public-private key pairs, cryptography, and blockchain technology is proposed.

[0156] (2) Secure communication between the platform and devices based on communication keys

[0157] Secure communication between the platform and devices includes the following two aspects:

[0158] 1) Communication key exchange

[0159] Based on prior identity authentication, a two-way secure data communication link is established between the blockchain and the device, and the exchange of communication keys between the IoT platform and the device is completed through this link.

[0160] 2) Secure communication based on communication keys

[0161] Based on communication keys, combined with challenge codes, timestamps, signatures, and other calculations, secure communication between the platform and devices is achieved, avoiding replay attacks, tampering attacks, man-in-the-middle attacks, and other attacks targeting IoT platforms and smart devices.

[0162] (3) Trusted data exchange between users and equipment manufacturers

[0163] Based on industrial internet identifier resolution and blockchain technology, data silos are broken down by using blockchain smart contracts to directly access identifier resolution, thus enabling trusted data exchange.

[0164] (4) Smart device key leakage problem

[0165] 1) To address the issue of key leakage in smart devices, a strategy for automatic communication key change is proposed, particularly for automatic communication key change in scenarios where devices are connected to new IoT platforms.

[0166] 2) To ensure that the root key data is not leaked, the root key is not exchanged throughout the entire data interaction process between the device and the IoT platform. Instead, a new communication key is exchanged only through the secure path of the root key, so that the root key is available but not visible.

[0167] (5) Security communication compatibility issues when multiple manufacturers, multiple types, and large quantities of devices are connected to the IoT platform.

[0168] To address this issue, it is proposed to use industrial internet identifier resolution technology to build a basic information sharing network. This will reduce the difficulty for equipment manufacturers to connect to different IoT platforms, and also reduce the difficulty and cost for IoT platforms to connect to different manufacturers and different types of equipment.

[0169] Alternatively, as another embodiment of the present invention, the beneficial effects of the present invention are as follows:

[0170] (1) Reduced connection cost: Based on this invention, secure data communication between IoT platforms and smart devices is achieved, while ensuring that device manufacturers can adapt to multiple IoT platforms with only one connection, and IoT platform developers can access multiple manufacturers and types of IoT devices with only one connection.

[0171] (2) Data is available but not visible, and confidentiality is improved: The exchange of new keys is completed without the leakage of the root key (public-private key pair) of the IoT platform and smart devices, thus improving data privacy and confidentiality.

[0172] Alternatively, as another embodiment of the present invention, such as Figure 4 As shown, the principle of this invention is as follows:

[0173] This system consists of the following four parts:

[0174] (1) Blockchain

[0175] The logic for smart device identity authentication and key exchange is maintained on the blockchain in the form of smart contracts. Device manufacturers and users' application software operate on-chain data through smart contracts.

[0176] (2) Equipment manufacturers

[0177] Equipment manufacturers build system platforms for equipment information management, identifier resolution and coding, etc., to realize functions such as equipment information collection, equipment coding, and equipment information registration on enterprise nodes. In addition, during the equipment manufacturing stage, equipment manufacturers assign public and private key pairs to the equipment and upload the equipment public key to the blockchain for use in verifying the equipment identity based on blockchain smart contracts.

[0178] (3) User

[0179] The user end builds an IoT platform for network access of smart devices, and at the same time assigns a public and private key pair to the platform, and uploads the platform's public key to the blockchain for use in verifying the identity of the server based on blockchain smart contracts.

[0180] (4) Identifier Resolution System

[0181] The identifier resolution enterprise node maintains the following information:

[0182] ① The correspondence between the equipment industrial internet identification code and the equipment public key blockchain ID, equipment information, and manufacturer information;

[0183] ② The correspondence between the industrial internet identifier code of the IoT platform and the public key blockchain ID of the IoT platform.

[0184] The specific principle of the system of this invention is described as follows:

[0185] (1) Before installation and delivery

[0186] During the device manufacturing phase, the manufacturer generates a public-private key pair for the device, uploads the public key to the blockchain, and maintains the private key locally on the device. Subsequently, the device identity is verified by checking the private key through a blockchain smart contract.

[0187] (2) After installation and delivery

[0188] 1) IoT platform developers allocate public and private key pairs to the IoT platform, upload the public key to the blockchain, and maintain the private key locally on the server. The server identity is subsequently verified by verifying the private key through a blockchain smart contract.

[0189] 2) After the device and the server complete identity authentication, a new communication key is issued based on the secure communication link established by the blockchain for the secure encryption of subsequent business flow data.

[0190] Alternatively, as another embodiment of the present invention, such as Figure 5 As shown, the specific solution of the present invention is as follows:

[0191] (1) Before installation and delivery

[0192] Before installation and delivery, the equipment manufacturer completes equipment data collection, equipment coding, key initialization, and public key uploading to the blockchain. Finally, the equipment information, equipment public key storage blockchain ID, and other information are registered to the enterprise node in the form of identifier registration.

[0193] (2) After installation and delivery

[0194] 1) Device authentication stage

[0195] ① The device requests a challenge code from the blockchain via an IoT platform using a smart contract (Smart Contract 1);

[0196] ② After obtaining the challenge code challenge_code1, the device hashes the challenge code using a signature algorithm and encrypts the hash result with the device's private key to generate the authentication code auth_code;

[0197] ③ The device sends the authentication code auth_code and the original challenge code challenge_code1 to the blockchain smart contract (smart contract 2) through the IoT platform;

[0198] ④ The blockchain smart contract (smart contract 2) obtains the blockchain address of the public key corresponding to the device through the identification resolution process of the industrial internet identification resolution system based on the device's identification code, and then obtains the device's public key;

[0199] ⑤ The blockchain smart contract decodes the authentication code auth_code using the device's public key to obtain the source data of the authentication code (source data 1);

[0200] ⑥ The blockchain smart contract uses the same signature algorithm to hash the challenge code to obtain the check code check_code. The check code and the source data (source data 1) of the authentication code auth_code are compared in the form of string comparison. If the comparison results are consistent, the device identity verification is valid; otherwise, the device identity is invalid.

[0201] ⑦ Send the device identity authentication result to the device to complete the device identity verification process.

[0202] 2) Server-side identity authentication stage

[0203] The server-side authentication process is similar to the device-side authentication process, and will not be described in detail.

[0204] 3) New communication key exchange phase

[0205] ① The device requests a new communication key from the IoT platform;

[0206] ② After receiving the application, the IoT platform generates a new communication key session_secret and sends session_secret to the blockchain. Relying on the smart contract (smart contract 3), the session_secret is encrypted using the device's public key to generate session_secret ciphertext, which is then sent to the device.

[0207] ③ The device uses its private key to encrypt the session_secret and obtain the session_secret. At this point, the IoT platform and the device have completed the exchange of the new key, and all subsequent business data communication will use this session_secret for encryption and decryption.

[0208] 4) Update session_secret (optional step)

[0209] For security reasons, IoT platforms and smart devices can re-initiate the two-way authentication process based on a timed policy (see 1)-3 for details, which will not be repeated here), thereby realizing the timed update of session_secret and further reducing the risk of communication key leakage.

[0210] Alternatively, as another embodiment of the present invention, the business data stream encryption and decryption algorithm of the present invention is as follows:

[0211] secret_data=crypt_calc(logic_data, session_secret, nonce),

[0212] logic_data, session_secret, nonce=decrypt_calc(secret_data),

[0213] In this context, logiC_data represents business data, nonce represents a random number, session_secret represents the new communication key, and crypt_calc and deCrypt_calc represent symmetric encryption and decryption algorithms, such as AES.

[0214] Figure 6 This is a flowchart illustrating a secure communication method provided in an embodiment of the present invention.

[0215] Alternatively, as another embodiment of the present invention, such as Figure 6 As shown, a secure communication method includes the following steps:

[0216] Import data from multiple user terminal devices, and construct a user terminal dataset and multiple user terminal keys based on the data from the multiple user terminal devices;

[0217] Generate device authentication initiation command;

[0218] Based on the device identity authentication initiation command, multiple user terminal keys, and the user terminal dataset, device identity authentication is performed to obtain the device identity authentication result.

[0219] Import multiple server-side data, and construct a server-side dataset and multiple server-side keys based on the multiple server-side data;

[0220] Generate a server-side authentication initiation command based on the device authentication result;

[0221] Based on the server-side authentication initiation command, multiple server-side keys, and the server-side dataset, server-side authentication is performed to obtain the server-side authentication result.

[0222] Based on the server-side authentication result and the multiple user terminal keys, a key exchange is performed to obtain a secure communication result.

[0223] Optionally, another embodiment of the present invention provides a secure communication system, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the secure communication method described above. This system can be a computer or similar system.

[0224] Optionally, another embodiment of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the secure communication method described above.

[0225] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.

[0226] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described apparatus and unit can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0227] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0228] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of the present invention, depending on actual needs.

[0229] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0230] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. This is understood to mean that the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0231] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A secure communication system, characterized by include: Manufacturing terminals, blockchain, IoT platforms, and user terminals. The manufacturing terminal is used to import data from multiple user terminal devices, and to construct a user terminal dataset and multiple user terminal keys based on the data from the multiple user terminal devices. The user terminal is used to generate a device authentication initiation command; The blockchain is used to perform device identity authentication based on the device identity authentication initiation command, multiple user terminal keys and the user terminal dataset, and obtain the device identity authentication result. The IoT platform is used to import multiple server-side data, and construct a server-side dataset and multiple server-side keys based on the multiple server-side data. The user terminal is also used to generate a server-side authentication initiation command based on the device authentication result. The blockchain is also used to perform server identity authentication based on the server identity authentication initiation command, multiple server keys and the server dataset, and obtain the server identity authentication result. The user terminal is also used to exchange keys based on the server's authentication result and multiple user terminal keys to obtain a secure communication result. In the manufacturing terminal, the process of constructing a user terminal dataset and multiple user terminal keys based on data from multiple user terminal devices includes: Each user terminal device data is assigned an identifier to obtain user terminal identifier data corresponding to each user terminal device data. Generate multiple user terminal keys corresponding to the user terminal device data, and obtain the original user terminal public key corresponding to each user terminal device data from each of the user terminal keys; The blockchain is used to generate an original user terminal public key ID corresponding to the data of each user terminal device based on the original user terminal public key of each original user terminal. The manufacturing terminal is also used to take each user terminal identification data and the original user terminal public key ID corresponding to each user terminal device data as device identification registration data corresponding to each user terminal device data, and construct a dataset of all the device identification registration data through an identifier resolution system tool to obtain a user terminal dataset. In the blockchain, the process of performing device identity authentication based on the device identity authentication initiation command, multiple user terminal keys, and the user terminal dataset to obtain the device identity authentication result includes: Generate a device identity challenge code based on the device identity authentication initiation command; The user terminal is used to filter out the user terminal private key from a plurality of user terminal keys according to a preset device identification code; The device identity challenge code is hashed using the first signature algorithm to obtain the hashed device identity challenge code. The hashed device identity challenge code is encrypted using the user terminal private key to obtain the device identity authentication code. The IoT platform is used to send the device identity challenge code and the device identity authentication code to the blockchain according to the first smart contract protocol; The blockchain is used to obtain the target public key ID from the user terminal dataset according to the preset device identification code, and to obtain the target user terminal public key according to the target public key ID; The device authentication code is decoded based on the target user terminal public key to obtain the device authentication source data; The device identity challenge code is hashed using the first signature algorithm to obtain the device identity verification code; The device identity verification code is authenticated based on the device identity authentication source data to obtain the device identity authentication result; In the blockchain, the process of authenticating the device identity verification code based on the device identity authentication source data to obtain the device identity authentication result includes: Verify whether the device identity authentication source data is the same as the device identity verification code. If the verification is successful, the first preset device identity authentication information is used as the device identity authentication result; if the verification fails, the second preset device identity authentication information is used as the device identity authentication result.

2. The secure communication system according to claim 1, characterized in that, In the IoT platform, the process of constructing a server-side dataset and multiple server-side keys based on multiple server-side data includes: Each of the server-side data is assigned an identifier to obtain server-side identifier data corresponding to each of the server-side data. Generate multiple server keys corresponding to the server data, and obtain the original server public key corresponding to each of the server data from each of the server keys; The blockchain is used to generate an original server public key ID corresponding to each of the server data based on each of the original server public keys. The IoT platform is also used to take each of the server identifier data and the original server public key ID corresponding to each of the server data as server identifier registration data corresponding to each of the server data, and construct a dataset for all the server identifier registrations through the identifier resolution system tool to obtain the server dataset.

3. The secure communication system according to claim 2, characterized in that, In the blockchain, the process of performing server-side identity authentication based on the server-side identity authentication initiation command, multiple server-side keys, and the server-side dataset to obtain the server-side identity authentication result includes: The IoT platform is used to generate a server-side identity challenge code generation instruction based on the server-side identity authentication initiation instruction. The blockchain is used to generate a server-side identity challenge code according to the server-side identity challenge code generation instruction. The IoT platform is also used to filter out a server private key from a plurality of server keys according to a preset server identifier code; The server-side identity challenge code is hashed using the second signature algorithm to obtain the hashed server-side identity challenge code. The hashed server identity challenge code is encrypted using the server's private key to obtain the server identity authentication code. The server-side identity challenge code and the server-side identity authentication code are sent to the blockchain in accordance with the second smart contract protocol; The blockchain is also used to obtain the target server public key ID from the server dataset according to the preset server identifier code, and to obtain the target server public key according to the target server public key ID; The server authentication code is decoded using the target server public key to obtain the server authentication source data. The server-side identity challenge code is hashed using the second signature algorithm to obtain the server-side identity verification code. The server identity verification code is authenticated based on the server identity authentication source data to obtain the server identity authentication result.

4. The secure communication system according to claim 3, characterized in that, In the blockchain, the process of authenticating the server-side identity verification code based on the server-side identity authentication source data to obtain the server-side identity authentication result includes: Verify whether the server-side identity authentication source data is the same as the server-side identity verification code. If the verification is successful, the first preset server-side identity authentication information is used as the server-side identity authentication result; if the verification fails, the second preset server-side identity authentication information is used as the server-side identity authentication result.

5. The secure communication system according to claim 1, characterized in that, In the user terminal, the process of exchanging keys based on the server authentication result and multiple user terminal keys to obtain a secure communication result includes: Generate a key exchange instruction based on the server-side authentication result; The IoT platform is used to generate a communication key according to the key exchange instruction; The blockchain is used to encrypt the communication key based on the public key of the target user terminal to obtain the encrypted communication key; The user terminal is used to decrypt the encrypted communication key according to the user terminal private key to obtain the decrypted communication key; Import business data, and encrypt the business data according to the decrypted communication key to obtain encrypted business data; The IoT platform is also used to decrypt the encrypted business data according to the communication key to obtain a secure communication result.

6. A secure communication method based on the secure communication system according to any one of claims 1 to 5, characterized in that, Includes the following steps: Import data from multiple user terminal devices, and construct a user terminal dataset and multiple user terminal keys based on the data from the multiple user terminal devices; Generate device authentication initiation command; Based on the device identity authentication initiation command, multiple user terminal keys, and the user terminal dataset, device identity authentication is performed to obtain the device identity authentication result. Import multiple server-side data, and construct a server-side dataset and multiple server-side keys based on the multiple server-side data; Generate a server-side authentication initiation command based on the device authentication result; Based on the server-side authentication initiation command, multiple server-side keys, and the server-side dataset, server-side authentication is performed to obtain the server-side authentication result. Based on the server-side authentication result and the multiple user terminal keys, a key exchange is performed to obtain a secure communication result.

7. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, the secure communication method as described in claim 6 is implemented.