A method for aggregating data of intelligent IoT without a trusted third party

By setting up a resource node management center and multiple resource nodes in the Internet of Things system, using the multi-classification fusion method of fuzzy measurement and the encryption technology that independently generates public and private keys, the security vulnerabilities caused by the difficulty in aggregating multiple types of IoT data in real time and relying on trusted third parties in the existing technology is solved, and efficient data aggregation and enhanced security are achieved.

CN119484156BActive Publication Date: 2025-05-13KUNSHAN ZHONGYIFENG PHOTOELECTRIC TECH CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510041031.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-13
Estimated Expiration
2045-01-10

AI Technical Summary

Technical Problem

Existing IoT technologies are difficult to aggregate multiple types of IoT data in real time, and rely on trusted third parties to have security vulnerabilities such as external attacks and internal conspiracy to leak secrets.

Method used

By setting up a resource node management center, the IoT data types collected by resource nodes are distinguished using a multi-classification fusion method based on fuzzy measurements, and an incremental sequence is generated in the operation center. Each resource node independently generates a public and private key for encryption, realizing the distinction and aggregation of multi-type IoT data without trusted third parties.

Benefits of technology

The distinction and aggregation of multiple types of IoT data has been realized, the transmission and processing efficiency between resource nodes and business nodes has been improved, security problems caused by external attacks and internal conspiracy attacks have been avoided, and the reliability of IoT data transmission protection has been improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484156B_ABST
    Figure CN119484156B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for aggregating intelligent IoT data without a trusted third party, and relates to the technical field of IoT. A plurality of resource nodes and a resource node management center are set, and the types of IoT data collected by the resource nodes are distinguished by a multi-classification fusion method based on fuzzy measurement. Each resource node autonomously generates a public and private key and encrypts the IoT data to generate a ciphertext. A plurality of aggregation nodes are set to aggregate different types of ciphertexts. An operation center identifies the type of the aggregated ciphertext and selects a port to a corresponding business node. The business node decrypts the aggregated ciphertext to obtain aggregated data, thereby achieving the distinction and aggregation of multiple types of IoT data without a trusted third party, improving the data transmission efficiency, avoiding the security problems caused by external attacks and internal collusion attacks, and improving the reliability of IoT data transmission protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things, and in particular to a method for aggregating intelligent Internet of Things data without a trusted third party. Background Art

[0002] The Internet of Things (IoT) technology has developed rapidly and has become one of the most important technologies at present. Its related applications include smart lighting, smart parking and energy management. Taking smart lighting as an example, smart devices are needed to collect the operating data, energy consumption data and even the surrounding environmental data of lighting equipment, and the control center will learn and analyze them to realize the intelligent control of lighting equipment. The data collected by a single smart device often involves the privacy of enterprises or users, and the control center generally only needs statistical data for overall allocation. Therefore, data aggregation technology that can hide the detailed data of a single device is widely used in the Internet of Things. However, during the data aggregation process, all data is transmitted on an insecure public channel, so an effective cryptographic solution is also needed to ensure the integrity and authenticity of the data and prevent the data from being tampered with and destroyed during transmission.

[0003] The existing Chinese patent application with publication number CN116318901A proposes a privacy-integrated blockchain and verifiable IoT data aggregation method. It uses homomorphic encryption technology to encrypt the IoT data of multiple parties involved in the aggregation and transmit it to a trusted third party. The trusted third party aggregates the data based on the ciphertext, effectively protecting the privacy of the data during the calculation process.

[0004] The existing Chinese patent application with publication number CN113489697A proposes a decentralized key distribution method in the Internet of Things. By improving the lightweight calculation process of the ECC encryption algorithm and using the PBFT consensus algorithm to reach a consensus between nodes, the master node stores the public key information of all nodes in the blockchain. Then, the communication between nodes can confirm the credibility of the public key through the blockchain, so that the Internet of Things devices can automatically generate public and private keys without a third party, thereby improving security.

[0005] However, the prior art has the following disadvantages:

[0006] 1. There are multiple related businesses in the Internet of Things, such as smart lighting, smart parking, energy management, etc. Taking smart lighting as an example, the IoT data it collects can be divided into at least three categories, including operation data, energy consumption data and environmental data. The data aggregation solutions in the existing technology only aggregate a single data type and cannot aggregate multiple types of IoT data in real time;

[0007] 2. Existing technologies partially rely on trusted third parties, but trusted third parties are vulnerable to attacks by adversaries. Adversaries can obtain IoT data and paralyze the entire IoT by intercepting or tampering with the encryption parameters provided by the trusted third party. Therefore, existing technologies that rely on trusted third parties have security vulnerabilities that can be attacked from outside.

[0008] 3. Another part of the existing technology does not need to rely on a trusted third party. The public and private keys are generated autonomously by the master node or the central device. The data encryption and aggregation process depends on the master node or the central device. If the master node or the central device launches a collusion attack with other nodes, the data of the attacked node can be easily obtained. Therefore, the existing technology that does not need to rely on a trusted third party has a security vulnerability of internal collusion leakage. Summary of the invention

[0009] In view of the shortcomings of the prior art, the present invention proposes a method for aggregating intelligent IoT data without a trusted third party.

[0010] To achieve the above object, the present invention provides the following technical solution: a method for aggregating intelligent IoT data without a trusted third party, comprising the following steps:

[0011] Get the number of IoT data classes and number of users ,set up Aggregation nodes and business nodes and assign labels to them. Set resource nodes, the resource node management center uses a multi-classification fusion method based on fuzzy measurement to assign labels to resource nodes;

[0012] The operation center generates and publishes system parameters, confirms service nodes and connected ports, establishes a search relationship between service node labels and port numbers of connected ports, and constructs a label forwarding table;

[0013] resource nodes and Each aggregation node registers with the operation center to obtain a certificate;

[0014] The resource node broadcasts the public key, Resource nodes are based on labels Identify and classify Other resource nodes of the construction class The group public key ;

[0015] No. Resource nodes collect additional tags IoT data , determine the IoT data and The data scope, obtain security parameters, and encrypt IoT data Generating Classes The ciphertext ,in, ;

[0016] kind The aggregation node receives and verifies the Ciphertext packets sent by resource nodes , aggregate the classes that pass the validation The ciphertext , generate class Aggregate ciphertext , additional resource node identity , Aggregation time Encrypted signature with aggregation node Generate aggregate ciphertext package ;

[0017] The operation center receives the aggregated ciphertext package , query the tag forwarding table to select a port to transmit the aggregated ciphertext packet ;

[0018] No. Business nodes include tags , receive and verify the aggregated ciphertext packet , verified by the backward class The resource node asks for a partial key and gets the key from the class Aggregate ciphertext Decryption acquisition class Aggregate data , obtain the dimension through the data separation algorithm Class Total IoT data .

[0019] Furthermore, setting Aggregation nodes and business nodes and assign labels including: sorting The aggregation node is Aggregate nodes are given labels , defined as class Aggregation nodes of type The aggregation node is used to process the The ciphertext packet sent by the resource node, , get the The class of IoT data processed by the business node is assigned the label corresponding to the class. business nodes, a single business node can be assigned multiple different labels. .

[0020] Furthermore, the multi-classification fusion method based on fuzzy integral includes the following steps:

[0021] Get The test IoT data sent by resource nodes is used to construct a sample set , select the sample set A small number of samples are used to generate new sample sets through GAN network and data enhancement technology. , and divided into training set and test set according to the proportion;

[0022] set up A graph convolution classifier with the same structure , trained using the training set Graph Convolution Classifier After the training is completed, the hyperparameters are fixed and verified by the test set. The graph convolution classifier can be implemented by the existing graph convolutional network, and the output is dimensional probability vector;

[0023] Calculate the Graph Convolution Classifier In the new sample set The classification accuracy in For class Clarity and for class Descriptive quality , get the Graph Convolution Classifier Pair Fuzzy measure ;

[0024] The sample set Middle Test IoT data sent by resource nodes Enter separately A graph convolution classifier is used, and the fuzzy measure is used to classify The outputs of the graph convolution classifiers are superimposed to obtain the fusion probability vector , and select the label corresponding to the maximum probability in the fusion probability vector and assign it to the resource nodes.

[0025] Furthermore, the operation center generates and publishes system parameters including the following steps:

[0026] The operation center is based on The first elliptic curve cyclic group of order Constructing integer fields , where the first elliptic curve cyclic group The generating factor is , is a large prime number;

[0027] The operation center randomly generates the operation center private key , combined with the generation factor Generate the Operation Center public key ;

[0028] The operation center uses bilinear mapping Get the second elliptic curve cyclic group , and construct a one-way hash function ;

[0029] The operation center is a class choose Continuous data range ,in, , , and class The maximum value of IoT data Much smaller than large prime numbers , ;

[0030] Operation Center Generation Class The first increasing sequence and Class The second increasing sequence ;

[0031] The operation center publishes system parameters within the Internet of Things, including the first elliptic curve cycle group 、The second elliptic curve cyclic group , Generative Factors , integer domain , bilinear mapping , one-way hash function , Operation Center Public Key ,kind The first increasing sequence ,kind The second increasing sequence and Class Data range .

[0032] Further, The registration of a resource node includes the following steps:

[0033] No. Resource nodes randomly generate private keys , combined with the generation factor Calculate the public key , combined with the resource node identity and registration time Generate resource node signature ;

[0034] No. Resource nodes are combined to generate a resource node registration package , and sent to the operation center;

[0035] The operation center receives the resource node registration package , verify the The identity of the resource node, after verification, Resource nodes issue certificates .

[0036] Furthermore, class The registration of an aggregation node includes the following steps:

[0037] kind The aggregation node selects a random number As a private key, combined with the generated factor Calculate the public key , combined with the aggregation node identity and registration time Generate aggregation node signature ;

[0038] Aggregate node combination generates aggregate node registration package , and sent to the operation center;

[0039] The operation center receives the aggregation node registration package , Validation Class The identity of the aggregation node is verified as The aggregation node issues the certificate .

[0040] Furthermore, construct the class The group public key The following steps are involved:

[0041] No. Resource nodes generate and broadcast class verification packets ;

[0042] No. The resource node receives Class verification package broadcast by resource nodes , verify the The class and identity of the resource node. If the verification is successful, obtain the The public key of each resource node;

[0043] After broadcasting, the Each resource node in the The public key of the resource node will be middle The public key summation calculation class for resource nodes The group public key .

[0044] Further, Resource node generation class Ciphertext The following steps are involved:

[0045] No. A resource node selects a random number , based on random numbers Generating Classes The first ciphertext ;

[0046] No. Resource node query class middle Data range , determine the IoT data of resource nodes and The data range , based on class The second increasing sequence Middle Safety value Generate security parameters ;

[0047] No. Resource nodes are based on classes The first increasing sequence , Safety parameters and random numbers Generating Classes The second ciphertext , and combined into classes The ciphertext ;

[0048] No. Resource nodes record encryption time , using the private key Computing resource node encryption signature , combined to generate a ciphertext packet , and forwarded to the class The aggregation node.

[0049] Furthermore, the generated class Aggregate ciphertext The specific steps include:

[0050] kind The aggregation node receives the ciphertext packet , record the aggregation time ;

[0051] kind Aggregation node verifies ciphertext packet The identity and timeliness of the class that has been verified The ciphertext Computing Aggregate ciphertext ;

[0052] kind The aggregation node uses the aggregation node private key Calculate the encrypted signature of the aggregation node , combined to generate an aggregated ciphertext package , and transmitted to the operation center.

[0053] Furthermore, the operation center queries the tag forwarding table to select a port to forward the aggregated ciphertext packet. The following steps are involved:

[0054] Get the aggregated ciphertext package Tags in ;

[0055] Traversal and The port number of the port connected to the service node is searched for the field corresponding to the port number in the label forwarding table;

[0056] Send aggregated ciphertext packet The to field contains the label port.

[0057] Further, Business nodes The resource node requests a partial key The following steps are involved:

[0058] No. Business nodes obtain aggregated ciphertext packets , record the first receiving time ;

[0059] No. Business nodes verify the aggregated ciphertext package The identity and timeliness of the The first aggregate ciphertext , requiring classification into the category The resource node provides part of the key;

[0060] No. Resource Node Identification Class The first aggregate ciphertext Tags in , using the private key Calculate partial keys , and based on the resource node identity and partial decryption time Generate partial decryption signature ;

[0061] No. Resource nodes are combined to generate a partial decryption package , and forwarded to business nodes.

[0062] Further, Business node decryption acquisition class Aggregate data The specific steps include:

[0063] No. Business nodes receive some decrypted packets , record the second receiving time ;

[0064] No. Business nodes verify partial decryption packets identity and timeliness, obtain partial keys ;

[0065] When the class middle After all partial decryption packages of resource nodes are verified, Business node elimination class The second aggregate ciphertext middle The sum of the partial keys of the resource nodes, based on the generation factor Get Class Aggregate data .

[0066] Further, Business nodes obtain dimensions through data separation algorithm Class Total IoT data The following steps are involved:

[0067] Get Class Aggregate data ,kind The first increasing sequence ,kind The second increasing sequence and Data range ;

[0068] in accordance with Traverse the data range in descending order ;

[0069] When traversing to the A single range Calculate the safety value The number of occurrences, from the class Aggregate data Minus Secondary safety value ;

[0070] Data range Class after traversal The remaining aggregate data is recorded as ;

[0071] No. Business nodes based on Descending from class The remaining aggregate data Separate the dimensions Class Total IoT data , traverse After dimensions, get Dimensional classes Total IoT data .

[0072] Compared with the prior art, the present invention has the following significant advantages:

[0073] 1. Set up a resource node management center, distinguish the types of IoT data collected by resource nodes through a multi-classification fusion method based on fuzzy measurement, set up multiple aggregation nodes to aggregate different types of ciphertexts, and the operation center autonomously sends the aggregated ciphertexts to the corresponding business nodes, which perform decryption analysis, thus achieving the distinction and aggregation of multiple types of IoT data and improving the transmission and processing efficiency from resource nodes to business nodes;

[0074] 2. The operation center generates an ascending sequence, and each resource node independently generates public and private keys. The data encryption process is implemented by the resource node's own private key and ascending sequence, without relying on a trusted third party, avoiding security issues caused by external attacks. At the same time, since the aggregation center and the operation center are only responsible for ciphertext aggregation and forwarding of aggregated ciphertext, and data encryption is implemented by the resource node's own private key, it avoids security issues caused by internal collusion attacks and improves the reliability of IoT data transmission protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0075] Figure 1 It is a flow chart of a method for aggregating data of intelligent IoT without a trusted third party;

[0076] Figure 2Register a flow chart for a resource node or aggregation center in the operation center;

[0077] Figure 3 Generate ciphertext for resource nodes and generate aggregate ciphertext flow chart through aggregation nodes;

[0078] Figure 4 Decrypt and obtain the aggregated data flow chart for the business node. DETAILED DESCRIPTION

[0079] The present invention is further described in detail below in conjunction with the accompanying drawings and embodiments.

[0080] like Figure 1 As shown, the embodiment provided by the present invention: a method for aggregating data of intelligent IoT without a trusted third party, comprising the following steps:

[0081] Get the number of IoT data classes ,set up Aggregation nodes and business nodes and assign labels. For example, in smart lighting, the status monitoring of lighting equipment requires operation data and environmental data, and the power distribution of lighting equipment requires real-time power consumption. , the number of business nodes ;

[0082] Get the number of users ,set up resource nodes, Resource nodes collect and test IoT data for the first time The resource node management center uses a multi-classification fusion method based on fuzzy measurement to analyze and test IoT data. , giving the Resource node labels , For example, in smart lighting, there are Each user has lighting equipment and needs monitoring equipment, sensors and smart meters as resource nodes to collect operation data, environmental data and real-time power consumption respectively. resource nodes, and assign labels 1, 2, or 3 to represent monitoring devices, sensors, or smart meters;

[0083] The operation center generates and publishes system parameters, confirms the connected port, and the port number is The port connection business node, obtain the Labels for business nodes, create labels and port numbers The retrieval relationship is used to construct the label transfer table. For example, in smart lighting, the lighting equipment status monitoring is set as the first business node, with labels 1 and 2, indicating that operation data and environmental data are required, and the port number is , the lighting equipment power supply distribution is set to the second business node, the label is 3, indicating that real-time power consumption is required, and the port number is ;

[0084] resource nodes and Each aggregation node registers with the operation center to obtain a certificate;

[0085] The resource node broadcasts the public key, Resource nodes are based on labels Identify and classify Other resource nodes of the construction class Group public key For example, in smart lighting, assuming the label , at this time class The resource node is a smart meter, and the public keys of other smart meters are obtained by broadcasting the public key to construct the group public key ;

[0086] No. Resource nodes collect IoT data And attach the label , denoted as , For the The resource node Dimension IoT data to meet For Class The maximum value of IoT data, For example, in smart lighting, assuming the label , a single user is configured with lighting equipment, so the real-time power consumption collected by the resource node, i.e., the smart meter, is a Vector of dimensions ,at this time, Essentially, it refers to the maximum real-time power consumption;

[0087] Determine IoT data of resource nodes and The data range to which it belongs, obtain the security parameters corresponding to the data range ,in, For the system parameters The second increasing sequence Middle A safety value, For Class The number of corresponding continuous data ranges, is the generation factor in the system parameters, encrypting the IoT data of resource nodes Generating Classes The ciphertext For example, in smart lighting, assuming the label , based on the maximum real-time power consumption Divide into A continuous range of electricity consumption, calculating the power consumption of a single user Total electricity consumption of lighting equipment And determine the power consumption range as Get the second increasing sequence Middle Safety value And by generating factors Get security parameters , and encrypt to generate the ciphertext about the total power consumption ;

[0088] kind The aggregation node receives and verifies the Ciphertext packets sent by resource nodes , aggregate the classes that pass the validation The ciphertext , generate class Aggregate ciphertext For example, in smart lighting, assuming the label ,kind The aggregation node is used to verify whether the ciphertext packet is sent by the smart meter and whether the content has been tampered with. Aggregation generates aggregate ciphertext ;

[0089] The operation center receives the aggregated ciphertext package , query the tag forwarding table to select a port to transmit the aggregated ciphertext packet To all including tags For example, in smart lighting, the operation center receives the aggregated ciphertext packet and obtains the label , determine that the data type is real-time power consumption, query the label forwarding table, and find that the second business node requires a label , select the corresponding port number to make a transmission;

[0090] No. Business nodes include tags , receive and verify the aggregated ciphertext packet , verified by the backward class The resource node of the smart lighting system requests partial keys. For example, in smart lighting, the second business node obtains the aggregated ciphertext package, verifies again whether the data type of the aggregated ciphertext package is real-time power consumption, and whether the content has been tampered with. After the verification is passed, it requests partial keys from the smart meter.

[0091] No. Business node acquisition class Partial keys of all resource nodes in the class Aggregate ciphertext Decryption acquisition class Aggregate data , and obtain the dimension through the data separation algorithm Class Total IoT data For example, in smart lighting, the second business node obtains partial keys of all smart meters and can decrypt and obtain the aggregated power consumption. , and obtained through the data separation algorithm User's The total real-time power consumption of lighting equipment .

[0092] Furthermore, setting Aggregation nodes and The tags of business nodes include: The aggregation node is Aggregate nodes are given labels , defined as class Aggregation nodes of type The aggregation node is used to process the The ciphertext packet sent by the resource node, , get the The class of IoT data processed by the business node is assigned the label corresponding to the class. business nodes, a single business node can be assigned multiple labels. .

[0093] Furthermore, the multi-classification fusion method based on fuzzy measurement includes the following steps:

[0094] Get The test IoT data sent by resource nodes is used to construct a sample set , select the sample set A small number of samples, which must contain at least one piece of each type of IoT data;

[0095] Generate a new sample set by processing a small number of samples through GAN network and data enhancement technology , and divide the new sample set proportionally For training set and test set;

[0096] set up The same structure of graph convolution classifier is denoted as , using the training set to train simultaneously Graph Convolution Classifier After training, fix Graph Convolution Classifier The hyperparameters are verified by the test set. The graph convolution classifier can be implemented by the existing graph convolution network, and the output is dimensional probability vector;

[0097] Calculate the Graph Convolution Classifier In the new sample set The classification accuracy of ,in, Represents a new sample set The number of new samples with correct labels assigned to them;

[0098] Calculate the Graph Convolution Classifier For Class Clarity , the specific calculation formula is as follows:

[0099] ,

[0100] in, for The labels are correctly assigned The number of new samples, Indicates Correctly assigned labels The new sample is Graph Convolution Classifier Predicted distribution labels The probability of

[0101] Calculate the Graph Convolution Classifier For Class Descriptive quality , the specific calculation formula is as follows:

[0102] ,

[0103] Because the Graph Convolution Classifier The output is essentially a dimensional probability vector Therefore, the closer the value distribution of the probability vector is to binary, the more accurate the label prediction for the new sample is, and the better the quality of the description is. The larger the value of ;

[0104] Calculate the Graph Convolution Classifier Pair Fuzzy measure ;

[0105] The sample set Middle Test IoT data sent by resource nodes Enter separately A graph convolution classifier is used, and the fuzzy measure is used to classify The outputs of the graph convolution classifiers are superimposed to obtain the fusion probability vector ,kind The corresponding probability ,in, Indicates test IoT data After Graph Convolution Classifier Class The fuzzy measure of Indicates test IoT data After Graph Convolution Classifier Predicted distribution labels The probability of , and select the label corresponding to the maximum probability in the fusion probability vector to assign to the resource nodes.

[0106] Furthermore, the operation center generates and publishes system parameters including the following steps:

[0107] The operation center is based on The first elliptic curve cyclic group of order Constructing integer fields , where the first elliptic curve cyclic group The generating factor is , is a large prime number;

[0108] The operation center selects a random number As the operation center private key, calculate the operation center public key ;

[0109] The operation center uses bilinear mapping Get the second elliptic curve cyclic group , and construct the range as One-way hash function ;

[0110] The operation center is a class choose Continuous data range ,in, , and class The maximum value of IoT data Much smaller than large prime numbers , ;

[0111] Operation Center Generation Class The first increasing sequence and Class The second increasing sequence , where class The first increasing sequence middle are all prime numbers, satisfying and Respectively The dimensions and number of users of IoT data, ,kind The second increasing sequence Middle Safety value satisfy is the preset value, satisfying ;

[0112] The operation center publishes system parameters within the Internet of Things, including the first elliptic curve cycle group 、The second elliptic curve cyclic group , Generative Factors , integer domain , bilinear mapping , one-way hash function , Operation Center Public Key ,kind The first increasing sequence ,kind The second increasing sequence and Class middle Continuous data range .

[0113] like Figure 2 As shown, further, The registration of a resource node includes the following steps:

[0114] No. Resource nodes with labels , in the integer domain Randomly generate a private key , ensure the security of private keys;

[0115] Calculate the The public key of each resource node and resource node signature , , ,in, is the resource node identity, The registration time;

[0116] No. Resource node combination resource node identity , Registration time , Resource Node Signature and the public key Generate resource node registration package , and send the resource node registration package To the Operations Center;

[0117] The operation center receives the resource node registration package , verify the equation Is it true? If true, it proves the resource node registration package Has not been tampered with during transmission. The identity of the resource node is compliant, and the operation center is Resource nodes issue certificates ,in, The private key of the operation center.

[0118] like Figure 2 As shown, further, class The registration of an aggregation node includes the following steps:

[0119] To improve safety, The aggregation node is from the integer domain Choose a random number from As a private key;

[0120] Computing The public key of the aggregation node and the aggregation node signature , , ,in, is the aggregation node identity, The registration time;

[0121] Aggregation Node Group Aggregation Node Identity , Registration time , Aggregation Node Signature and the public key Generate aggregation node registration package , and send the aggregation node registration package To the Operations Center;

[0122] The operation center receives the aggregation node registration package , verify the equation Is it true? If true, it proves that the aggregation node registration package Has not been tampered with during transmission, The aggregation node identity is compliant, and the operation center is The aggregation node issues the certificate ,in, The private key of the operation center.

[0123] Furthermore, construct the class The group public key The following steps are involved:

[0124] No. Resource node combination resource node identity , Registration time , public key and Certificate Generate class verification package , and broadcast class verification package ;

[0125] No. The resource node receives Class verification package broadcast by resource nodes , Resource nodes are also classified into categories , verify the equation Is it established? If established, Resource nodes get the The public key of each resource node;

[0126] After broadcasting, the Each resource node in the The public key of the resource node will be middle The public key summation calculation class for resource nodes The group public key .

[0127] like Figure 3 As shown, further, Resource node generation class The ciphertext The following steps are involved:

[0128] No. resource nodes in the integer domain Choose a random number from , Computing The first ciphertext ;

[0129] No. Resource node query class middle Data range , determine the IoT data of resource nodes and The data scope to which it belongs;

[0130] Assume IoT data of resources and satisfy , then IoT data of resource nodes and Belongs to the data range , select class The second increasing sequence Middle Elements , get the data range Corresponding safety parameters ;

[0131] No. Resource node computing class The second ciphertext , the specific formula is as follows:

[0132] ,

[0133] in, For Class The first increasing sequence Middle elements, For the The resource node Dimension IoT data, is the first elliptic curve cyclic group The generating factor, For Class The group public key of

[0134] No. Resource node combination class The first ciphertext and Class The second ciphertext Generating Classes The ciphertext , using the private key Computing resource node encryption signature ,in, is the resource node identity, For the The encryption time of each resource node;

[0135] No. Resource node combination resource node identity , encryption time , Resource node encryption signature and Class The ciphertext Generate ciphertext package , and forward it to the class The aggregation node.

[0136] like Figure 3 As shown, further, the generated class Aggregate ciphertext The following steps are involved:

[0137] kind The aggregation node receives the ciphertext packet , record the aggregation time ;

[0138] kind Aggregation node judgment Is it established, among which, The allowed transmission duration;

[0139] If not, it indicates that the transmission has timed out, the ciphertext packet, Invalid, no processing;

[0140] If established, the class The aggregation node verifies the equation , cumulatively verify the passed class The ciphertext Computing Aggregate ciphertext ;

[0141] kind The aggregation node calculates the aggregation node encryption signature ,in, For Class The aggregation node private key;

[0142] kind Aggregation node combination resource node identity , Aggregation time , Aggregation node encryption signature and Class Aggregate ciphertext Generate aggregate ciphertext package , and transmitted to the operation center.

[0143] Furthermore, the operation center queries the tag forwarding table to select a port to forward the aggregated ciphertext packet. The following steps are involved:

[0144] Get the aggregated ciphertext package Tags in ;

[0145] The port number As an index, query the tag forwarding table to obtain the port number The corresponding fields;

[0146] Determine whether the field contains a label , if included, select the port number Send aggregated ciphertext packet ;

[0147] The port number As an index, continue to query and judge until it matches All ports connected to the business nodes are queried.

[0148] Further, Business nodes The resource node requests a partial key The specific steps include:

[0149] No. Business node acquisition class Aggregation ciphertext packet sent by the aggregation node , record the first receiving time ;

[0150] No. Business node inspection Is it established, among which, is the allowed transmission duration;

[0151] If it is not true, it means that the transmission has timed out, and the ciphertext packet is aggregated. Invalid, no processing;

[0152] If established, no. Business node verification equation ,in, For Class The public key of the aggregation node, after verification Business node broadcast class The first aggregate ciphertext , requiring classification into the category The resource node provides part of the key;

[0153] No. Resource Node Identification Class The first aggregate ciphertext Labels carried in , using the private key Calculate partial keys , and generate a partial decryption signature ,in, is the resource node identity, For partial decryption time;

[0154] No. Resource node combination resource node identity , Partial decryption time , Partial decryption signature and partial keys Generate partial decryption package , and forwarded to business nodes.

[0155] like Figure 4 As shown, further, Business node decryption acquisition class Aggregate data The specific steps include:

[0156] No. Business nodes receive some decrypted packets , record the second receiving time ;

[0157] No. Business node inspection Is it established, among which, is the allowed transmission duration;

[0158] If not, it means the transmission has timed out and some decrypted packets Invalid, no processing;

[0159] If established, no. Business node verification equation ,in, For the The public key of each resource node;

[0160] When the class middle After all partial decryption packages of resource nodes are verified, Business node acquisition class Aggregate data .

[0161] Further, Business nodes obtain dimensions through data separation algorithm Class Total IoT data The following steps are involved:

[0162] Get Class Aggregate data ,kind The first increasing sequence ,kind The second increasing sequence and Data range ;

[0163] Record Class Aggregate data for ,in accordance with Descending traversal Data range , when traversing to the A single range When, class The aggregated data is times removed, recorded as ;

[0164] No. A single range The corresponding safety parameters are , due to the class Aggregate data Divided by the generating factor , so the category Aggregate data Include safety value , calculate the safety value Number of occurrences , where mod represents the remainder operation, from The class that was removed Aggregate data Eliminate Safety value The specific formula is ;

[0165] Data range Class after traversal The remaining aggregate data is ;

[0166] in accordance with Get dimensions in descending order Class Total IoT data , the specific formula is as follows:

[0167] ;

[0168] Traversal After the dimension, Business nodes can obtain Dimensional classes Total IoT data .

[0169] The present invention sets up a resource node management center and multiple resource nodes, distinguishes the types of IoT data collected by resource nodes through a multi-classification fusion method based on fuzzy measurement, each resource node autonomously generates public and private keys and encrypts IoT data to generate ciphertext, sets up multiple aggregation nodes for aggregating different types of ciphertexts, an operation center identifies the type of aggregated ciphertext and selects a port to a corresponding business node, and the business node decrypts the aggregated ciphertext to obtain aggregated data, thereby achieving the distinction and aggregation of multiple types of IoT data without a trusted third party, improving data transmission efficiency, avoiding security issues caused by external attacks and internal collusion attacks, and improving the reliability of IoT data transmission protection.

[0170] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiment. All kinds of IoT data aggregation technologies under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technicians in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. A method for aggregating intelligent IoT data without a trusted third party, characterized in that: The following steps are involved: Set up aggregation nodes and business nodes and assign labels, set up resource nodes and assign labels through a multi-classification fusion method based on fuzzy measurement; The operation center generates and publishes system parameters and builds a label forwarding table; The resource node and the aggregation node register with the operation center to obtain a certificate; The resource node broadcasts a public key, identifies other resource nodes with the same label, and generates a group public key; The resource node collects IoT data and adds tags, obtains security parameters based on the IoT data and the data range to which it belongs, and encrypts and generates ciphertext; The aggregation node receives and verifies the ciphertext packet and generates an aggregated ciphertext; The operation center queries the label forwarding table to select a port to forward the aggregated ciphertext packet; The business node receives and verifies the aggregated ciphertext package, requests a partial key, decrypts to obtain aggregated data, and obtains total IoT data of a single dimension through a data separation algorithm; Wherein, the service node requests a partial key from the resource node; The business node obtains the total IoT data of a single dimension through a data separation algorithm, including: Acquire the aggregated data, a first increasing sequence of the same label, a second increasing sequence of the same label, and a continuous data range of the same label; Traversing the continuous data range in descending order; When traversing to a single range, the number of occurrences of the corresponding safety value of the single range is calculated; The safety value is subtracted from the aggregated data the same number of times, and after the continuous data range is completely traversed, the remaining aggregated data is obtained, and the total IoT data of a single dimension is separated out in sequence.

2. A method for aggregating smart IoT data without a trusted third party as claimed in claim 1, characterized in that: The multi-classification fusion method based on fuzzy measurement includes the following steps: Constructing a sample set, generating a new sample set based on a small number of samples in the sample set, and dividing the new sample set into a training set and a test set; Setting a plurality of graph convolution classifiers, training them with the training set, and verifying them with the test set; Calculating the classification accuracy, clarity for a single class, and description quality for a single class of a single graph convolution classifier in the new sample set, and obtaining a fuzzy measure of the single graph convolution classifier for a single class; The samples in the sample set are respectively input into the multiple graph convolution classifiers, and the outputs of the multiple graph convolution classifiers are superimposed by using fuzzy measurement to select labels to assign to resource nodes.

3. A method for aggregating smart IoT data without a trusted third party as claimed in claim 1, characterized in that: The operation center generates and publishes system parameters including the following steps: The operation center constructs an integer field based on the first elliptic curve cyclic group, and publishes the first elliptic curve cyclic group, a generating factor of the first elliptic curve cyclic group, and the integer field; The operation center generates an operation center private key and an operation center public key and publishes them; The operation center uses bilinear mapping to obtain the second elliptic curve cyclic group, constructs a one-way hash function, and publishes the second elliptic curve cyclic group, bilinear mapping, and one-way hash function; The operation center selects a continuous data range for the class corresponding to each label, generates a first increasing sequence and a second increasing sequence for the class corresponding to each label, and publishes the data range, the first increasing sequence and the second increasing sequence.

4. A method for aggregating smart IoT data without a trusted third party as described in any one of claims 1 to 3, characterized in that: The resource node generates a group public key comprising the following steps: The resource node generates and broadcasts a class verification package; The resource node receives the class verification package broadcasted by other resource nodes, verifies the class and identity assigned to other resource nodes, and obtains the public key of other resource nodes that have passed the verification; After broadcasting, the resource node obtains the public keys of other resource nodes with the same label, and calculates the group public key by summing them up.

5. A method for aggregating smart IoT data without a trusted third party as described in any one of claims 1 to 3, characterized in that: The resource node generates ciphertext including the following steps: The resource node selects a random number in the integer domain and generates a first ciphertext; The resource node queries multiple data ranges of the same tag, determines the IoT data and the single data range to which it belongs, and generates security parameters; The resource node generates a second ciphertext based on a first increasing sequence of the same tag, a security parameter and a random number, and combines the first ciphertext and the second ciphertext to generate a ciphertext; The resource node records the encryption time, uses the private key to calculate the resource node encryption signature, combines the generated ciphertext package and forwards it to the aggregation node with the same label.

6. A method for aggregating smart IoT data without a trusted third party as described in any one of claims 1 to 3, characterized in that: The aggregation node generates the aggregation ciphertext including the following specific steps: The aggregation node receives the ciphertext packet, records the aggregation time, and verifies the identity and timeliness of the ciphertext packet; The aggregation node accumulates and verifies the ciphertexts passed by the verification to calculate the aggregated ciphertext; The aggregation node uses the aggregation node private key to calculate the aggregation node encryption signature, combines to generate an aggregation ciphertext package, and transmits it to the operation center.

7. A method for aggregating smart IoT data without a trusted third party as described in any one of claims 1 to 3, characterized in that: The service node requests a partial key from the resource node, comprising the following steps: The service node obtains the aggregated ciphertext package, records the first receiving time and verifies the identity and timeliness of the aggregated ciphertext package; The service node broadcasts the first aggregated ciphertext in the verified aggregated ciphertext package, and requires the resource nodes with the same label to provide partial keys; The resource node with the same label uses a private key to calculate a partial key, generates a partial decryption signature based on the partial decryption time, combines to generate a partial decryption package, and forwards it to the service node.

8. A method for aggregating smart IoT data without a trusted third party as described in any one of claims 1 to 3, characterized in that: The business node decrypts and obtains the aggregated data, including the following steps: The service node receives a portion of the decrypted packets and records a second receiving time; The service node verifies the identity and timeliness of the partial decryption package and obtains the partial key; The service node removes the sum of partial keys of resource nodes with the same label in the second aggregated ciphertext, and obtains aggregated data based on the generation factor.

9. The method for aggregating smart IoT data without a trusted third party as claimed in claim 3, characterized in that: The registration of the resource node or aggregation node comprises the following steps: The resource node or aggregation node randomly generates a private key in the integer domain, and calculates a public key and a signature; The resource nodes or aggregation nodes combine to generate a registration package and send it to the operation center; The operation center verifies the identity of the registration package, and after the verification is passed, uses the operation center private key to issue a certificate to the resource node or aggregation node.

Citation Information

Patent Citations

  • Center-free key distribution method in Internet of Things

    CN113489697A

  • Privacy and verifiable Internet of Things data aggregation method fusing block chain

    CN116318901A

  • Heterogeneous polymerization signcryption method in Internet-of-things environment

    CN107707360A

  • Industrial Internet of Things platform monitoring data transmission and exchange method and system

    CN114466090A