A blockchain reputation management system for Internet of Things identification and resolution
By introducing a blockchain reputation management mechanism into the Internet of Things identification resolution system, dynamically calculate the node reputation value and identify malicious nodes, the challenges of existing systems in terms of architecture, scalability and security are solved, and a distributed, decentralized, and secure Internet of Things identification resolution system is realized.
Patent Information
- Application Number
- CN202411033798.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-30
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-07-30
AI Technical Summary
Existing IoT Identity Resolution Systems have challenges in architecture, scalability and security, including single point of failure caused by centralized architectures, inability to meet the identification and resolution requirements of massive devices, and insufficient security to prevent illegal control and malicious attacks.
A blockchain reputation management system for the Internet of Things is proposed. By introducing a reputation management mechanism on the blockchain, the reputation value is dynamically calculated based on the behavior of nodes, and malicious nodes are identified and isolated, so as to realize distributed and decentralized identification resolution and management.
It realizes a multi-center, tamper-free data storage solution, enhances the security and scalability of the system, effectively prevents malicious attacks and illegal controls, and ensures the security of the terminal and operations.
Smart Images

Figure CN119172099B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of blockchain, and particularly relates to a blockchain reputation management system for Internet of Things (IoT) identification and resolution. Background Art
[0002] The Internet of Things (IoT) enables the interconnection of people, machines, and things through embedded sensors, smart devices, and software systems, providing a comprehensive solution for automated data collection, environmental monitoring, and intelligent control. Correct identification and resolution of devices connected to the IoT are prerequisites for inter-device communication, client monitoring and control of devices, and connection to cloud servers for data processing and analysis. Therefore, IoT device identification and resolution are prerequisites for the development, deployment, and operation of large-scale IoT applications and services.
[0003] Due to the particularity of IoT devices, higher requirements are imposed on the security, stability, and scalability of identification and resolution services. Facing a large-scale IoT environment, to support the interconnection of a vast number of objects, the IoT identification and resolution system still faces many challenges.
[0004] At the architecture level, currently, multiple standards and naming formats coexist within the IoT, posing a huge challenge to the retrieval and understanding of objects. At the same time, mainstream identification and resolution systems adopt a centralized hierarchical architecture with a single control point. Upper-layer nodes in the architecture have control over their lower-layer nodes and can even manipulate the services of the entire lower-layer node network. The unequal service node permissions in the architecture may lead to the illegal control of the resolution service or even the inability to provide the service. Some mechanisms attempt to implement a multi-root structure at the top-level node to decentralize control, but the problems existing in the resolution architecture have not been fundamentally solved.
[0005] At the scalability level, there is a wide variety of objects within the IoT. The identification and resolution system should be able to meet the diverse and customized requirements of identification and resolution results and should have a certain degree of forward-looking, that is, have a large enough naming space to cope with the future addition of a vast number of devices and meet the high-concurrency registration and resolution of IoT devices. Currently, most identification and resolution systems are not designed specifically for the IoT, have weak resource description capabilities, and all rely on identification service platforms established by third parties. The manual configuration of a large number of IoT device identifiers consumes time and labor costs and is difficult to meet the requirements of large-scale deployment and management.
[0006] In terms of security, security is the cornerstone of building a reliable and sustainable Internet of Things. However, the current Internet of Things identification and resolution system does not fully consider the security risks therein. The security of the identification and resolution system mainly includes terminal security, data security, and operation security [4]. Terminal security includes client security and server security. The identification and resolution system should be able to ensure the authentication and privacy of the client, such as anonymous requests, and also prevent cache poisoning, domain name hijacking, and DDoS attacks against the server, etc.; data security should ensure the transmission security and storage security of the identifier; operation security means that participants perform operations within their rights. In the current centralized resolution system, the power of the central node is overly concentrated, there are risks of improper control and censorship of data, and the DDoS attacks faced by the central node have also become the core weak link in the tree structure. Therefore, the current identification and resolution system cannot effectively ensure terminal security. At the same time, the identification naming and resolution are at risk of being tampered with. Most of the current mainstream identification schemes do not set access control permissions and cannot ensure data security and operation security either. Summary of the Invention
[0007] The object of the present invention is to propose a blockchain reputation management system for Internet of Things identification and resolution, which makes up for the defects of the current Internet of Things identification and resolution system. The server nodes of the blockchain reputation management system for Internet of Things identification and resolution have equal permissions, meet the interconnection and interoperability of multi-source heterogeneous data, and realize the automatic and unique allocation and registration of identifiers. In addition, on the basis of the inherent security of the blockchain, a reputation management mechanism is introduced to evaluate the reputation values of blockchain nodes according to established rules, adjust the permissions of nodes in the mechanism accordingly, and effectively identify and isolate malicious nodes, further enhancing the security of the mechanism.
[0008] To achieve the above object, the present invention provides a blockchain reputation management system for Internet of Things identification and resolution, and the system includes:
[0009] IoT devices, which are used to request or provide identifiers; the IoT devices include non-restricted devices and restricted devices, where the restricted devices are represented as I w ={I w1 , I w2 , I w3 ... I wi , I wn}, and the non-restricted devices are represented as I s ={I s1 , I s2 , I s3 ... Is i , I sn};
[0010] Identify server nodes, which are used to represent the nodes of the blockchain consensus mechanism. The identify server nodes include edge nodes and unrestricted device nodes; among them, the edge nodes are regarded as restricted devices I w The server of w performs identification resolution, and each edge node stores a blockchain copy. Then the edge nodes are represented as Eg = {Eg1, Eg2, Eg3... Eg i , Eg n}; The unrestricted device nodes are unrestricted devices, so the unrestricted devices are represented as I s = {I s1 , I s2 , I s3 ... Is i , I sn};
[0011] Smart contract, which is used to define the consensus threshold thr c and the node threshold thr n , calculate the reputation value R. When R < thr c then it cannot participate in the blockchain consensus. When R < thr n then it is removed from the consortium chain. For the node identifiers that meet the consensus threshold thr c and the node threshold thr n , perform identification resolution and automatically execute the process of identification resolution; among them, the identifier is used to automatically allocate and register the contract sc1, the reputation management contract sc2, and the priority management contract sc3, which are respectively represented by the smart contract sc i = {sc1, sc2, sc3}.
[0012] Furthermore, the restricted device I w selects the nearest edge node Eg for identification resolution according to the geographical location. The restricted device I w also communicates with the edge node Eg based on the IP address.
[0013] Furthermore, the reputation value is calculated as follows:
[0014] The reputation management contract sc2 extracts the reputation information of the edge nodes and calculates the reputation value R(Eg i , t) value. R(Eg i , t) represents the reputation value of the edge node Eg i at time t, which is expressed as follows:
[0015]
[0016] The reputation management contract sc2 extracts the reputation information of the edge nodes and calculates the reputation value R(Eg i , t) value. R(Eg i,t) represents the edge node Eg i The credit value at time t is expressed as follows:
[0017]
[0018] Among them, k represents a fixed value, and the fixed value is 1; e -0.01t represents the attenuation function; represents the consensus success rate, cs t represents the number of times node i has successfully reached a consensus at time t, c t represents the total number of consensus times at time t, c represents the total number of consensus times; represents the registration success rate, rs t represents the number of successful registrations, r t represents the total number of registrations at time t, r represents the total number of registrations; represents the number of times the node's consensus time is less than the average consensus time T of all nodes at a certain time e ; represents the number of times the node's consensus time T is greater than the average consensus time T of all nodes at a certain time e ; represents the malicious formula behavior impact factor, M c represents the impact factor of malicious behavior during consensus, represents the impact weight at the a-th consensus malicious act, n represents the total impact weight of malicious acts during consensus, M represents the total impact factor of malicious acts, and a represents the impact weight at the a-th consensus malicious act; represents the malicious registration impact factor, M r represents the malicious behavior during registration identification, represents the impact weight at the b-th registration malicious act.
[0019] Furthermore, the credit value calculation also includes calculating the credit value for the non-restricted device identifier I s which is expressed as follows:
[0020]
[0021] Among them, R(Is i ,t) represents the credit value of the non-restricted device Is i at time t, α and β represent optimization factors, cs t represents the number of times node i has successfully reached a consensus at time t, c t represents the total number of consensus times at time t.
[0022] Furthermore, since the credit value calculation formulas for the two types of nodes are different, therefore, the credit value is normalized, which is expressed as follows:
[0023]
[0024] Among them, R(Eg i , Is i , t) norm represents the normalized reputation value of the edge node or non-restricted device node at time t, and R represents the reputation value;
[0025] The behaviors of all nodes are managed by the reputation management contract sc2, and the reputation management contract sc2 regularly calculates the node reputation value within t time intervals When , this node will be removed from the blockchain network, thus unable to participate in identity resolution and data exchange with other devices; when the consensus starts, the reputation management contract sc2 will compare the recently updated reputation value of the node with the preset threshold, and when , then the current node cannot participate in the consensus.
[0026] Furthermore, the automatic allocation and registration contract includes the transaction initialization implemented by three smart contracts and the consensus completed by the blockchain network.
[0027] Furthermore, the transaction initialization specifically includes:
[0028] The node first submits a request packet containing <Device information, SensitiveInformation, Public key, Others> according to the requirements, and marks the registration with Device information as the internal identifier and the registration with Others as the external identifier. Subsequently, the automatic allocation and registration contract sc1 processes the request information and conducts a preliminary compliance review. After confirming that the request information is compliant, the automatic allocation and registration contract sc1 generates an internal identifier for uniquely identifying the device according to the established rules, in the format of <Device information>*<unique_id>, where unique_id consists of the node ID and the timestamp. The contract checks whether there is marked sensitive information in the user registration request. If such information exists, it is signed by the public key of the requester to generate sign (sensitiveinformation) , then the system assigns an IPv6 address to it, and aggregates IPv6, others, and sign (sensitiveinformation) as the external identifier, and binds this external identifier to the corresponding internal identifier as a transaction, ready to enter the transaction sorting stage;
[0029] The reputation management smart contract sc2 monitors and records the node transaction situation, including the consensus success rate, registration success rate, consensus time, and compliance verification result. When the node submits a registration request, the reputation management smart contract sc2 calculates the reputation value of the node at the current moment;
[0030] The transaction priority management contract sc3 obtains the node reputation value from the reputation management smart contract sc2, then sorts the transactions within a certain time window according to the size of the node reputation value, and finally adds them to the transaction pool in an orderly manner for processing.
[0031] Further, the consensus specifically includes: The PBFT packaging thread is responsible for taking out transactions from the transaction pool, encapsulating the transactions into PBFTPrepare packets and handing them over to the consensus thread for processing. The PBFTEngine receives PBFT consensus message packets through the PBFTSealer or the P2P network, starts the consensus process, and finally writes the consensus-reached block into the blockchain and deletes the transactions that have been chained from the transaction pool.
[0032] Further, the identifier resolution specifically includes: The non-restricted device node I s obtains the IP address of the target device by sending a resolution request to the nearby edge node Eg. For the restricted device I w can directly query the local ledger to obtain it. The edge node Eg internally maintains a list of the restricted device nodes I s it manages, and avoids overload of requests from a certain restricted device node I s by detecting the data traffic frequency.
[0033] Further, the four trends of the reputation value include gradually rising, rising first and then falling, gradually falling, and falling first and then rising.
[0034] The beneficial technical effects of the present invention are at least as follows:
[0035] The blockchain of the present invention realizes a multi - center and tamper - proof data storage solution by means of multi - point synchronization, sharing, and replicating data. This fair and peer - to - peer service solves the challenges at the architecture level of the current identification and resolution system; its hash chain structure prevents the illegal tampering of identifier naming and resolution data, ensuring data security; the distributed architecture effectively resists DDoS attacks and enhances terminal security. However, directly establishing an identification and resolution system based on the blockchain cannot fully guarantee terminal security because the nodes participating in the blockchain are driven by rationality and interests and may exhibit selfish or malicious behaviors, and it is difficult for the blockchain to effectively restrict the malicious behaviors of illegal nodes. Therefore, to encourage the nodes in the blockchain to actively and honestly participate in the system, through the quantitative evaluation of the behaviors of blockchain nodes during the identification and resolution cycle, this paper proposes an identification and resolution system of the blockchain based on reputation. The smart contract written dynamically calculates the reputation value according to the behaviors of the nodes in consensus and registration, and uses the reputation value to identify and confirm malicious nodes within the mechanism. The reputation value not only determines the parsing and consensus permissions of the nodes but also affects the verification priority of the nodes submitting registration requests, thereby enhancing the controllability of the mechanism over the nodes and ensuring operation security. In summary, this paper proposes a reputation - based blockchain - compatible, peer - to - peer, scalable, and secure IoT identification and resolution system, providing a new perspective for device identification and network service lookup. The main contributions include:
[0036] 1. At the architecture level, decouple the identification management and the central institution, design an equal and autonomous distributed resolution system. The identifier extension in the proposed general architecture enables simple and seamless migration of various naming formats to this system, achieving compatibility with the current heterogeneous identifier formats, thereby realizing data interoperability and unified scheduling of resources.
[0037] 2. At the scalability level, the proposed identification naming scheme supports multiple types of identification entities, automated identification assignment and registration, and the identification resolution realizes privacy and customization requirements.
[0038] 3. At the security level, formulate a reputation model suitable for IoT identification and resolution, dynamically monitor devices by quantifying node behaviors, effectively identify malicious nodes, and manage the request priorities of nodes and the consensus, parsing, and other permissions of nodes according to the reputation value, further enhancing terminal security and operation security. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The present invention is further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the following drawings.
[0040] Figure 1 It is a framework diagram of a blockchain reputation management system for IoT identification and resolution of the present invention.
[0041] Figure 2 Schematic diagram of the identification allocation and registration process for the embodiments of the present invention.
[0042] Figure 3 Schematic diagram of the identification resolution process for the embodiments of the present invention.
[0043] Figure 4 Schematic diagrams of four trends of the comprehensive reputation scores of consensus and registration instances within 100 time units simulated for the embodiments of the present invention.
[0044] Figure 5 Schematic diagram of the response of the embodiments of the present invention and RTChain to the behavior of malicious nodes.
[0045] Figure 6 Schematic diagram of the recovery ability of nodes after a long period of malicious behavior for the embodiments of the present invention.
[0046] Figure 7 Schematic diagram of the impact of the consensus efficiency factor in the reputation model tested for the embodiments of the present invention on network performance.
[0047] Figure 8 Schematic diagram of the impact of the incentive node consensus efficiency on the system efficiency for the embodiments of the present invention.
[0048] Figure 9 Schematic diagram of the single - time allocation registration and resolution time for the embodiments of the present invention.
[0049] Figure 10 Schematic diagram of the concurrent allocation registration and resolution time for the embodiments of the present invention. Detailed implementation manners
[0050] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements with the same or similar functions throughout. The embodiments described by referring to the accompanying drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.
[0051] Embodiment 1
[0052] As Figure 1 shown, a blockchain reputation management system for Internet of Things identification resolution according to the present invention, the system includes:
[0053] IoT devices, used to request or provide identifiers; the IoT devices include non - restricted devices and restricted devices, where the restricted devices are represented as I w ={I w1 , I w2 , I w3 ...,Iwi , I wn , the non - restricted device is represented as I s = {I s1 , I s2 , I s3 ... Is i , I sn};
[0054] The identity server node is used to represent the node of the blockchain consensus mechanism. The identity server node includes an edge node and a non - restricted device node; among them, the edge node is used as the restricted device I w of the server for identity resolution, and each edge node stores a blockchain copy. Then the edge node is represented as Eg = {Eg1, Eg2, Eg3... Eg i , Eg n}; The non - restricted device node is the non - restricted device, so the non - restricted device is represented as I s = {I s1 , I s2 , I s3 ... Is i , I sn}; The present invention selects the consortium blockchain with the highest throughput as the underlying infrastructure. The blockchain nodes are the server nodes for identity resolution, which are divided into edge nodes and non - restricted device nodes. I w cannot directly assume the role of blockchain nodes, store blockchain data copies or participate in the computationally intensive consensus mechanism. Therefore, the edge node is used as the I w server for identity resolution;
[0055] Smart contract, used to define the consensus threshold thr c and the node threshold thr n , calculate the reputation value R. When R < thr c then it cannot participate in the blockchain consensus. When R < thr n then it is removed from the consortium blockchain. For the node identities that meet the consensus threshold thr c and the node threshold thr n , perform identity resolution and automatically execute the identity resolution process; among them, the identifier is used to automatically allocate and register the contract sc1, the reputation management contract sc2, and the priority management contract sc3, which are respectively represented by the smart contract sc i = {sc1, sc2, sc3}; The present invention uses smart contracts for identity resolution. Smart contracts, as scripts embedded in the blockchain, have ACID properties (Atomicity, Consistency, Isolation, Durability) and are used to automatically execute multi - step processes.
[0056] Furthermore, as Figure 1 shown, the restricted device I w selects the nearest edge node Eg according to the geographical location for identity resolution, and the restricted device I w also communicates with the edge node Eg based on the IP address.
[0057] Specifically, nodes will maximize profits through selfish behavior, which will pose a threat to the system. Therefore, in the present invention, a reputation model is constructed and continuous reputation management is carried out to dynamically monitor the behavior of devices and timely detect potential malicious activities. The core of the reputation model lies in quantifying the behavior of nodes, which is used as the standard for calculating and updating the reputation score, and is transparently managed by a smart contract. Nodes that act in accordance with established rules will enhance their own reputation value, while violating these rules will result in a deduction of the reputation value. The reputation score not only affects whether it can join the system and its decision-making ability within the system, but also affects the priority of its registration request. A consensus threshold thr c and a node threshold thr n are set in the system. When R < thr c , it cannot participate in the blockchain consensus. When R < thr n , it will be removed from the consortium chain, meaning that it cannot perform identity resolution. The calculation rule of the reputation value promotes the consensus efficiency of blockchain nodes. For Eg, since it is responsible for the identity registration of multiple surrounding I w , the higher its R value, the higher the priority of the submitted registration request, and it will be registered faster, thus encouraging nodes to actively and honestly participate in the system.
[0058] Furthermore, the reputation value is calculated as follows:
[0059] The reputation management contract sc2 extracts the reputation information of the edge node and calculates the reputation value R(Eg i ,t) of the edge node identifier. R(Eg i ,t) represents the reputation value of the edge node Eg i at time t, which is expressed as follows:
[0060]
[0061] Among them, k represents a fixed value, and the fixed value is 1; e -0.01t represents a decay function; represents the consensus success rate, cs t represents the number of times the i-th node reaches consensus successfully at time t, c t represents the total number of consensus at time t, c represents the total number of consensus; represents the registration success rate, rs t represents the number of successful registrations, r tLet \(t\) represent the total number of registrations at time \(t\), and \(r\) represent the total number of registrations; Indicates the number of times when the node consensus time is less than the average consensus time \(T\) of all nodes for a certain time e ; Indicates the number of times when the consensus time \(T\) of this node is greater than the average consensus time \(T\) of all nodes for a certain time e ; Indicates the malicious formula behavior impact factor, \(M\) c Indicates the impact factor of malicious behavior during consensus Indicates the impact weight when malicious behavior occurs during the \(a\)-th consensus. \(n\) represents the total weight of the impact during consensus, \(M\) represents the impact factor of the total malicious behavior, and \(a\) represents the impact weight when malicious behavior occurs during the \(a\)-th consensus; Indicates the malicious registration impact factor, \(M\) r Indicates the malicious behavior when registering the identifier Indicates the impact weight when malicious behavior occurs during the \(b\)-th registration.
[0062] Specifically, for \(I\) s , since it only requires one registration, the impact of the registration success rate and malicious registration on the reputation value is cancelled. Because each \(I\) s When applying to become a blockchain node, an identifier will be assigned to it and registered to the present invention. After successful registration, the registration request system of this node will ignore it. The rest is the same as \(Eg\).
[0063] Furthermore, the reputation value calculation further includes calculating the reputation value for the non-restricted device identifier \(I\) s , which is expressed as follows:
[0064]
[0065] Among them, \(R(I_s\) i ,t)\) represents the reputation value of the non-restricted device \(I_s\) i at time \(t\). \(\alpha\), \(\beta\) represent optimization factors, with magnitudes of 1.5 respectively. \(cs\) t represents the number of times the \(i\)-th node's consensus is successful at time \(t\), and \(c\) t represents the total number of consensus at time \(t\).
[0066] Furthermore, since the reputation value calculation formulas for the two types of nodes are different, the reputation value is normalized, which is expressed as follows:
[0067]
[0068] Among them, \(R(Eg\) i ,I_s\) i ,t)\) norm represents the normalized reputation value of the edge node or non-restricted device node at time \(t\), and \(R\) represents the reputation value;
[0069] The behaviors of all nodes are managed by the reputation management contract sc2, and the reputation management contract sc2 regularly calculates the node reputation values within t time intervals. When this happens, the node will be removed from the blockchain network, thus unable to participate in identity resolution and data exchange with other devices; when consensus starts, the reputation management contract sc2 will compare the recently updated reputation value of the node with a preset threshold. When this occurs, the current node cannot participate in the consensus.
[0070] In addition, the reputation model endows IoT devices with the ability to determine the credibility of the received data based on the reputation values of the communication counterparts, thus introducing a quantitative and continuous trust mechanism in internal interactions.
[0071] Furthermore, there are also rules for identifier naming. The identifier can easily migrate the existing identifiers to this system. The identifiers are divided into internal identifiers and external identifiers. The internal identifiers are used for uniquely identifying and managing devices within the system, and the external identifiers are used for external systems to identify and access IoT devices. Most of the information in the identifier can be defined by the device owner himself.
[0072] Among them, the internal identifier uses a two-level hierarchical structure, and the basic format is <Device information>*<unique_id>.
[0073] Device information: The prefix information is defined by the device owner, including but not limited to information such as device type, device manufacturer, and device owner.
[0074] unique_id: The suffix serves as a unique identifier to ensure the uniqueness of the device identifier.
[0075] When registering the identifier, the prefix is automatically submitted by the client according to the actual situation. If the client submits maliciously, it will be detected by the blockchain and its reputation value will be reduced. The unique_id in the suffix is globally and uniquely generated and assigned by the smart contract.
[0076] The core problem of decentralized distributed identifier registration is how to achieve secure generation of identifiers without a central node and avoid identifier conflicts. Therefore, in the present invention, the unique_id consists of the node ID and the UNIX timestamp at the current generation moment. This method ensures the uniqueness of each identifier because the timestamp provides a continuously changing value, and the node ID ensures that even at the same timestamp, the identifiers generated by different nodes will be unique. Such a design not only solves the problem of identifier uniqueness, but also, due to its basis on the timestamp, facilitates tracking and management of the identifier generation time, providing a certain degree of traceability for the system.
[0077] To meet the diverse and differentiated requirements of the Internet of Things, the parsing result is converted from the IP address in the Internet into multi-type data, and user-defined parsing results are supported. Therefore, the external identifier includes some specific information of the device, and the specific format is: <IPv6, Others, sign (sensitiveinformation) >
[0078] IPv6 address: Used for network communication between devices.
[0079] Others: Represents custom information, such as item introduction, manufacturer information, etc.
[0080] sign (sensitiveinformation) : Considering that some information often involves privacy and security issues, such as location and status information, if the registration request submitted by the device owner contains such sensitive information, the system will use the registrant's public key to sign it, and the relevant content can only be viewed after decryption.
[0081] To be compatible with the current multi-type identifier management rules, the device can use the current identifier as a prefix, and then the blockchain assigns a suffix <unique_id> to join the present invention. This method does not rely on a central institution and can easily connect various current identifier formats to the system to achieve unified management. For example, a device marked with the handle identifier 20.1000 / abc123xyz wants to join this system, then it can apply to the blockchain for the assignment of a unique_id to form <20.1000 / abc123xyz>*<unique_id>, and then register it to the present invention to achieve the functions of data retrieval and data exchange.
[0082] Furthermore, the automatic assignment and registration contract includes the transaction initialization implemented by three smart contracts and the consensus completed by the blockchain network.
[0083] Specifically, the traditional centralized identifier generation method means that when obtaining an identifier, it is necessary to apply to a public authority server. The concentration of power in a third party is prone to single-point failures, and centralized data storage increases the risk of privacy leakage. The decentralized identifier generation method enhances the transparency of the system and the autonomy of users through decentralized control and processing. It not only solves the complexity of manual configuration but also effectively avoids the risk of single-point failures by abandoning the dependence on a trusted third party. In this method, the identifier is not assigned by an authoritative service node but obtained through consensus. The flowchart of identifier allocation and registration is as shown in Figure 2 shown. This process is mainly divided into two stages. The first stage is transaction initialization, which is implemented by three smart contracts; the second stage is consensus, which is completed by the blockchain network.
[0084] Furthermore, the transaction initialization specifically includes:
[0085] The node first submits a request packet containing <Device information, SensitiveInformation, Public key, Others> according to the requirements, and marks the registration with Device information as the internal identifier and the registration with Others as the external identifier. Subsequently, the automatic allocation and registration contract sc1 processes the request information and conducts a preliminary compliance review. After confirming that the request information is compliant, the automatic allocation and registration contract sc1 generates an internal identifier for uniquely identifying the device according to the established rules. The format is <Device information>*<unique_id>, where unique_id consists of the node ID and the timestamp. The contract checks whether there is marked sensitive information in the user registration request. If such information exists, it is signed by the public key of the requester to generate sign (sensitiveinformation) , then the system assigns an IPv6 address to it, and aggregates IPv6, others, and sign (sensitiveinformation) into the external identifier. This external identifier is bound to the corresponding internal identifier as a transaction and is ready to enter the transaction sorting stage;
[0086] The reputation management smart contract sc2 monitors and records the node transaction situation, including the consensus success rate, registration success rate, consensus time, and compliance verification results. When a node submits a registration request, the reputation management smart contract sc2 calculates the reputation value of the node at the current moment;
[0087] The transaction priority management contract sc3 obtains the node reputation value from the reputation management smart contract sc2, then sorts the transactions within a certain time window according to the size of the node reputation value, and finally adds them to the transaction pool in an orderly manner for processing.
[0088] Further, the consensus specifically includes: The PBFT packaging thread is responsible for retrieving transactions from the transaction pool, encapsulating the transactions into PBFTPrepare packets and handing them over to the consensus thread for processing. The PBFTEngine receives PBFT consensus message packets through the PBFTSealer or the P2P network, initiates the consensus process, and finally writes the block that reaches consensus into the blockchain and deletes the transactions that have been chained from the transaction pool.
[0089] Further, the identifier resolution, as Figure 3 shown, specifically includes: The non-restricted device node I s initiates a resolution request to the nearby edge node Eg to obtain the IP address of the target device. For the restricted device I w it can directly query the local ledger to obtain it. The edge node Eg internally maintains a list of the restricted device nodes I s it manages, and avoids overloading the request of a certain restricted device node I s by detecting the data traffic frequency.
[0090] Specifically, the process of identifier resolution is a process of mutual mapping between the internal identifier and the external identifier of the Internet of Things. In the present invention, not only can the identifier information of Internet of Things devices be stored, but also the necessary DNS information can be recorded, thereby allowing Internet of Things devices to be seamlessly integrated into cloud services, data centers, and other network infrastructures, and more conveniently interoperating with existing Internet infrastructures and other online services. Through this system, the basic information of the device can be retrieved conveniently, and at the same time, the device owner can obtain data on the current location and status of the device. When an Internet of Things device needs to exchange data with a remote service on the Internet or devices in the Internet of Things communicate with each other, a communication connection is established through the other party's IP address to ensure correct reception and transmission of information.
[0091] The architecture of the system will affect the security, robustness, and latency of the resolution service. The current hierarchical tree structure of identifiers may not be resolvable due to denial-of-service attacks and node hijacking. The identifier resolution process of the present invention breaks the current hierarchical structure of Internet of Things resolution and transforms it into a distributed peer-to-peer resolution. In this new mode, the resolution action no longer relies on complex hierarchical relationships, but directly obtains external identifier information by querying internal identifiers between blockchain nodes. Each resolution node in the peer-to-peer resolution has the same resolution authority, and each resolution node has no right to tamper with and discard the resolution requests of other nodes, avoiding illegal control of the resolution service and facilitating the construction of a decentralized and peer-to-peer resolution ecosystem.
[0092] The heterogeneity of Internet of Things (IoT) identifiers is one of the bottlenecks faced by the IoT. The general identifier format of the present invention can easily migrate the currently existing identifier formats into this mechanism, breaking through the information silos in identifier resolution and achieving compatibility and interoperability. By integrating blockchain and edge nodes, the communication problems between restricted devices are solved. By dispersing the parsing tasks to each blockchain node, the burden on a single central node is reduced. And through direct or indirect P2P lookup, the communication efficiency is improved. The present invention can provide a complete, secure and robust parsing mechanism for IoT devices.
[0093] Embodiment 2
[0094] The system configuration and tools used in the experimental tests are shown in Table 1. The performance tests were mainly carried out from two aspects. First, the changing trends under different conditions of the reputation formula and the malicious node recognition ability were tested. Then, the time overhead and parallel execution ability of automatic allocation and registration were tested.
[0095] Table 1 Test Environment
[0096]
[0097]
[0098] To test the effectiveness of the blockchain reputation management system for IoT identifier resolution, according to the formula in Section 3.2 to update the reputation value, four typical trends of the comprehensive reputation scores of consensus and registration instances within 100 time units were simulated: gradually increasing, increasing first and then decreasing, gradually decreasing, and decreasing first and then increasing. The results are as Figure 4 shown.
[0099] a. Nodes without malicious behavior - Reputation value gradually increasing: This situation simulates the changing trend of the reputation value when there is no malicious consensus or malicious registration by nodes. The fluctuations in the curve are caused by the number of times when the consensus time at each moment is less than the average consensus time. The behavior of the reputation value growing rapidly and then gradually slowing down simulates the natural development process of trust in the real world. The rapidly rising reputation value when a new node joins the network reflects the system's initial trust incentive for the newly joined node and can prevent it from being identified as a malicious node due to too small a reputation value. However, as time goes by, it becomes more difficult to increase trust, and nodes need to maintain and improve their reputation through continuous positive behavior.
[0100] b. Malicious behavior occurs midway through the node - the reputation value first rises and then falls: This scenario simulates that there is no malicious behavior within the first 35 time units, and random registration failures and consensus failures occur in the subsequent time. Considering that in the real world, node registration failures or consensus failures may be caused by either accidental failures or malicious behavior, in the blockchain reputation management system for Internet of Things identity resolution, problem nodes are allowed to regain trust by demonstrating their reliability and normal behavior within a certain period of time. However, as can be seen from the slope, the recovery process is relatively slow, which can ensure that the system can observe the behavior of nodes for a long time, thus maintaining the overall trust of the network environment.
[0101] C. Malicious behavior occurs at the beginning of the node - the reputation value gradually decreases: This scenario simulates that the node starts to act maliciously from the beginning. The rapid decrease in the reputation value at the beginning can ensure that the system quickly responds to potential threats, demonstrating the system's high sensitivity to abnormal behavior.
[0102] d. The node stops after starting to act maliciously - the reputation value first decreases and then increases: This scenario simulates that the node conducts malicious behavior within the first 35 time units and then stops the malicious behavior, aiming to test the recovery ability of the reputation value. As can be seen from the figure, once the node shows obvious and continuous malicious behavior, the system will remain vigilant about it and have long-term memory of it. The difference between Figure d and Figure b is that the failure behavior of the node in Figure b is accidental, while in the case of Figure d, the continuous multiple failure behaviors of the node will be judged as intentional malicious behavior, so the reputation value cannot be restored.
[0103] As Figure 5 shown, the responses of the blockchain reputation management system for Internet of Things identity resolution and RTChain to malicious node behaviors. As can be seen from the figure, after the reputation value rises to the same value, the node randomly executes malicious behavior. The rate of decrease in the reputation value, that is, the response ability, in the blockchain reputation management system for Internet of Things identity resolution is higher than that of RTChain. This indicates that the blockchain reputation management system for Internet of Things identity resolution has a higher sensitivity in identifying malicious nodes and can identify and isolate malicious nodes faster.
[0104] As Figure 6As shown, the recovery ability of nodes after a long period of malicious behavior is tested. In the figure, the nodes experience malicious behavior for the first 35 time units and then return to normal behavior. It can be seen from the figure that in the blockchain reputation management system for Internet of Things identity resolution, even if the nodes continuously remedy after continuous malicious behavior, the reputation value cannot increase significantly. Because malicious behavior brings long-term memory to the reputation value. This method reduces the means for nodes to manipulate the reputation through periodic malicious behavior and superficial good behavior, ensuring that only nodes with truly continuous good performance can maintain a high reputation, thus enhancing the authenticity and reliability of the entire system. In RTChain, previous malicious behavior does not affect the subsequent increase in the reputation value, so the ability to restrict nodes is relatively weak.
[0105] As Figure 7 shown, the influence of consensus efficiency on the reputation value size is tested under the condition that other conditions (consensus success rate, registration success rate) are the same. As Figure 7 shown, when other conditions are the same, the more times the consensus time of the node is lower than the average level, the higher the increase in the reputation value. This mechanism ensures that more efficient nodes receive corresponding incentives, that is, in the absence of malicious behavior, the difference in the reputation value mainly reflects the pros and cons of the node's consensus efficiency. In order to obtain a higher registration request priority and maintain a positive position in the blockchain network, nodes must continuously optimize their consensus efficiency to ensure that their processing speed is faster than the average consensus time. This design encourages participants to invest resources to improve the consensus speed. Figure 8 It further shows the influence of different numbers of nodes improving the consensus efficiency to different degrees on the overall average consensus time. Here, it is assumed that the initial average consensus time is 100 and the number of nodes is 1000. It can be seen that as the number of nodes with a consensus time less than the average consensus time increases, and the increase in time also increases, the overall consensus efficiency is continuously improving.
[0106] Furthermore, performance tests of identity automatic allocation, registration, and identity resolution in the blockchain reputation management system for Internet of Things identity resolution in single and high-concurrency scenarios are carried out.
[0107] Specifically, first, 100 single-time performance tests are carried out. As Figure 9 shown, the identity registration is between 143ms - 651ms, and the identity resolution time is between 103ms - 123ms.
[0108] To test whether the blockchain reputation management system for Internet of Things identity resolution can meet the requirements of large-scale deployment of the Internet of Things, this section of the experiment simulates a large number of devices in the Internet of Things sending registration requests and resolution requests simultaneously, and tests the performance in high-concurrency scenarios. The test results are as Figure 10As shown. Each concurrency count is tested 10 times, and then the average value is taken. For identifier resolution, since it does not involve consensus, the time fluctuation in the 10 tests of each group is very small and can basically be ignored. For identifier allocation and registration, consensus is required, and the time will fluctuate due to network conditions, etc. The fluctuation situation is as shown by the waves in Figure 10 When facing concurrent requests ranging from 10,000 to 100,000 times, the time required for both increases with the increase in the concurrency count. When the high-concurrency resolution reaches 100,000 times, the time does not exceed 1 minute. When the high-concurrency identifier allocation and registration reach 100,000 times, the time does not exceed 10 minutes. And the error rates of both in the test are 0%, which proves the efficiency and effectiveness of the automatic allocation registration and distributed resolution of the blockchain reputation management system for Internet of Things identifier resolution. In actual application deployment, when applied to higher-performance servers and more optimized network environments, the processing time is expected to be much lower than the current test results.
[0109] In the blockchain reputation management system for Internet of Things identifier resolution, by combining the consortium blockchain, edge computing, and the reputation management mechanism involved according to the characteristics of Internet of Things identifier resolution, a more secure and trustworthy management service model is obtained compared with the current Internet of Things identifier management. Table 2 shows the comparison of the security performance between the blockchain reputation management system for Internet of Things identifier resolution and different solutions.
[0110] Table 2 Comparison of Security Performance of Different Solutions
[0111]
[0112] Furthermore, it will also protect the security of the terminal:
[0113] Specifically, (1) Client security. The blockchain identifies users through anonymous wallet addresses, making it difficult for potential attackers to associate the resolution records with the user's identity, realizing anonymous requests. In addition, the customizable resolution results encrypt sensitive information, protecting the privacy of the client resolution results.
[0114] (2) Server security. Although there are currently various Internet of Things (IoT) identification and resolution systems, the identifiers in these technologies mainly rely on the allocation by trusted institutions. When dealing with the registration requests of a large number of and rapidly growing IoT devices, the centralized system faces huge pressure on resources and time, and the centralized storage of registration information may become a high-value target for attackers. Once the system is attacked, suffers a technical failure, or experiences any form of interruption, it may lead to the paralysis of the entire service and the leakage of user information. However, the blockchain reputation management system for IoT identification and resolution automates the allocation and registration of identifiers through smart contracts, decentralizes the control of identifiers to participants, and blockchain nodes serve as the servers for identification and resolution. Each node stores a complete copy. Even if some nodes are attacked, the entire network can still operate normally. Moreover, if a node frequently and maliciously initiates registration requests, it will be recognized as a malicious registration behavior by the system, and then its reputation value will be reduced. As shown in the above tests, this node will be quickly recognized and processed, thus ensuring server security.
[0115] In the blockchain reputation management system for IoT identification and resolution, the basic structure of the blockchain is utilized to record the identification information of IoT devices in blocks. Each block not only contains data but also stores the hash value of the previous block, thus constructing a secure and irreversible data chain. If an attacker wants to change a block, they not only need to recalculate the hash value of that block but also need to recalculate all subsequent blocks on the entire chain and quickly update the information of the entire blockchain before other nodes in the network verify the tampered content. This attack method is almost infeasible in actual operation due to the resources and time required. In addition to the inherent security features of the blockchain, the reputation model in the blockchain reputation management system for IoT identification and resolution can identify malicious nodes based on their behaviors, making up for the problem that the consortium blockchain cannot prevent malicious behaviors among inter-chain nodes and providing the credibility of identification and resolution from the source.
[0116] In the blockchain reputation management system for IoT identity resolution, in order to ensure the legitimacy of the participants, the system adopts a certificate-based identity authentication mechanism to ensure that the participants are authorized nodes. The node certificate is the key credential of the legal participant and is issued by the certification authority (CA). When a node applies to join the blockchain network, it needs to submit its detailed information (hardware information, MAC address, etc.) to the CA. The CA verifies the authenticity of the applicant's information through various means online and offline. After the review is passed, the CA will issue a certificate to the node. In order to strengthen the security of the system, the blockchain reputation management system for IoT identity resolution regulates the node behavior through the reputation value to ensure the honest cooperation of the nodes. When the node is removed from the blockchain network due to malicious behavior and the reputation value is too low, in order to prevent the node from rejoining the network, the blockchain reputation management system for IoT identity resolution will maintain a blacklist of nodes that have been removed from the network, which stores the certificate information of these nodes. When the node removed due to malicious behavior reapplies for a certificate from the CA, the CA detects whether the node is an illegal node by comparing the information in the blacklist and further verification, and thus refuses to rejoin. In addition, the reputation value can also refine the authority allocation of nodes, and nodes can also use the reputation value to judge each other's trust level, providing an accurate trust reference for the interaction between nodes and ensuring the trusted interaction of the entire blockchain reputation management system for IoT identity resolution.
[0117] Although embodiments of the present invention have been shown and described, those skilled in the art will appreciate that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.
Claims
1. A blockchain reputation management system for IoT identity resolution, characterized in that: The system comprises: IoT device, used to request or provide an identifier; the IoT device includes an unrestricted device and a restricted device, wherein the restricted device is represented by I w = {I w1 ,I w2 ,I w3 ..., I wi , I wn }, non-restricted devices are represented by I s = {I s1 ,I s2 ,I s3 ...Is i , I sn }; The identification server node is used to represent the node of the blockchain consensus mechanism, and the identification server node includes an edge node and an unrestricted device node; wherein the edge node is used as a restricted device node. w The server performs identity resolution, and each edge node stores a copy of the blockchain, then the edge node is represented by Eg = {Eg1, Eg2, Eg3...Eg i ,Eg n }; The non-restricted device node is the non-restricted device, and the non-restricted device is represented by I s = {I s1 ,I s2 ,I s3 ...Is i , I sn }; Smart contract to define the consensus threshold thr c and node threshold thr n , calculate the reputation value R, when R <thr c Then it cannot participate in the blockchain consensus, R <thr n The alliance chain is removed, and the consensus threshold thr c and node threshold thr n The node identifier is parsed and the identifier parsing process is automatically executed; wherein the identifier is used to automatically allocate and register the contract sc1, the reputation management contract sc2 and the priority management contract sc3, respectively using the smart contract sc i ={sc1,sc2,sc3} represents; The reputation value is calculated as follows: The reputation management contract sc2 extracts the edge node reputation information and calculates the reputation value R (Eg i ,t) value, R(Eg i ,t) represents the edge node Eg i The reputation value at time t is expressed as follows: Among them, k represents a fixed value, which is 1; e -0.01t represents the decay function; Indicates the consensus success rate, cs t represents the number of times the consensus of node i succeeds at time t, c t represents the total number of consensuses at time t, and c represents the total number of consensuses; Indicates the registration success rate, rs t Indicates the number of successful registrations, r t represents the total number of registrations at time t, and r represents the total number of registrations; Indicates that the node consensus time is less than the average consensus time T of all nodes at a certain time e The number of times, Indicates that the node consensus time T is greater than the average consensus time T of all nodes at a certain time e The number of times; represents the impact factor of malicious consensus behavior, M c Indicates the influence factor of malicious behavior during consensus, represents the impact weight when the a-th consensus is malicious, n represents the total weight of the impact when the consensus is malicious, M represents the impact factor of the total malicious behavior, and a represents the impact weight when the a-th consensus is malicious; represents the malicious registration impact factor, M r Indicates malicious behavior when registering a logo, represents the impact weight when the bth registration is malicious; The reputation value calculation also includes the non-restricted device identification I s The reputation value is calculated as follows: Among them, R(Is i ,t) indicates non-restricted device Is i The reputation value at time t, α and β represent optimization factors, cs t represents the number of times the consensus of node i succeeds at time t, c t Represents the total number of consensuses at time t.
2. According to claim 1, a blockchain reputation management system for IoT identity resolution is characterized in that: The restricted device I w According to the geographical location, the nearest edge node Eg is selected for identity resolution. w Communication with the edge node Eg is also based on the IP address.
3. According to a blockchain reputation management system for IoT identity resolution according to claim 1, it is characterized in that: Since the two node reputation calculation formulas are different, the reputation values are normalized as follows: Among them, R(Eg i ,Is i ,t) norm represents the normalized reputation value of the edge node or non-restricted device node at time t, and R represents the reputation value; The behavior of all nodes is managed by the reputation management contract sc2, which regularly calculates the node reputation value within t time intervals. when , the node will be removed from the blockchain network and will not be able to participate in identity resolution or exchange data with other devices. When consensus begins, the reputation management contract sc2 will compare the node's most recently updated reputation value with the preset threshold. , the current node cannot participate in the consensus.
4. According to a blockchain reputation management system for IoT identity resolution according to claim 1, it is characterized in that: The automatic allocation and registration contract includes transaction initialization implemented by three smart contracts and consensus completed by the blockchain network.
5. According to claim 4, a blockchain reputation management system for IoT identity resolution is characterized in that: The transaction initialization specifically includes: The node first submits a request containing<Deviceinformation,SensitiveInformation,Publickey,Others> Request package, and mark it as Deviceinformation registered as internal identification and Others registered as external identification, then automatically assign and register contract sc1 to process the request information, conduct a preliminary compliance review, and after confirming that the request information is compliant, automatically assign and register contract sc1 to generate an internal identification for uniquely identifying the device according to the established rules. The format is <deviceinformation>*<unique_id> , where unique_id is composed of node ID and timestamp. The contract checks whether there is any marked sensitive information in the user registration request. If there is such information, the requester's public key signature generates a sign (sensitiveinformation) Then the system assigns an IPv6 address to it and sets IPv6, others, and sign (sensitiveinformation) Aggregated into an external identifier, the external identifier is bound to the corresponding internal identifier as a transaction, ready to enter the transaction sorting stage;< / deviceinformation> The reputation management smart contract sc2 monitors and records node transactions, including consensus success rate, registration success rate, consensus time, and compliance verification results. When a node submits a registration request, the reputation management smart contract sc2 calculates the node's reputation value at the current moment; The transaction priority management contract sc3 obtains the node reputation value from the reputation management smart contract sc2, and then prioritizes the transactions within a certain time window according to the size of the node reputation value, and finally adds them to the transaction pool in an orderly manner to wait for processing.
6. According to claim 5, a blockchain reputation management system for IoT identity resolution is characterized in that: The consensus specifically includes: the PBFT packaging thread is responsible for taking transactions from the transaction pool, encapsulating the transactions into PBFTPrepare packages and handing them over to the consensus thread for processing; PBFT Engine receives PBFT consensus message packages through PBFTSealer or P2P network, starts the consensus process, and finally writes the consensus blocks into the blockchain, and deletes the transactions that have been on the chain from the transaction pool.
7. A blockchain reputation management system for IoT identity resolution according to claim 1, characterized in that: The identification resolution specifically includes: non-restricted device node I s By initiating a resolution request to the nearby edge node Eg, the IP address of the target device is obtained. w The local account book can be directly queried to obtain the edge node Eg, which maintains a managed restricted device node I s list, and avoid a restricted device node I by detecting the data traffic frequency s Request overload.
8. According to claim 1, a blockchain reputation management system for IoT identity resolution is characterized in that: The four trends of the reputation value include gradually increasing, first increasing and then decreasing, gradually decreasing, and first decreasing and then increasing.
Citation Information
Patent Citations
Safe data sharing method based on reputation consensus mechanism
CN115412374A
PBFT consensus mechanism based on reputation model
CN116015672A