Trusted Asymmetric Encryption Communication Method for Edge Computing Gateways Driven by Certificate Chains

Through the combination of dynamic certificate chain, chaotic mapping algorithm and quantum initialization vector data, the problem of insufficient trust root limitations and flexibility in edge computing is solved, and efficient and secure encrypted communication is achieved to adapt to complex network environments.

CN119628841BActive Publication Date: 2025-07-22ZHEJIANG ZHUOYI NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411812329.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-10
Publication Date
2025-07-22
Estimated Expiration
2044-12-10

AI Technical Summary

Technical Problem

The prior art has limitations in edge computing, insufficient flexibility in complex network environments, inefficient verification efficiency and vulnerability in attacks, especially in multi-node distributed environments, which are difficult to dynamically adapt to network changes and interoperability between complex devices.

Method used

Global random number data is generated through dynamic certificate chain data and chaotic mapping algorithm, combined with quantum initialization vector data for block encryption, and used secret sharing algorithm to distribute dynamic session keys to realize a highly secure encrypted communication process, and dynamically adjust communication parameters in combination with feedback optimization mechanism.

Benefits of technology

It significantly improves the robustness and communication efficiency of edge computing networks, enhances the security and attack resistance of data transmission, and adapts to the needs of complex edge computing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119628841B_ABST
    Figure CN119628841B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical fields of network security and edge computing, and particularly to a trusted asymmetric encryption communication method for an edge computing gateway driven by a certificate chain, including: generating node feature data based on the hardware characteristics of edge nodes, generating dynamic certificate chain data through the cooperation of edge nodes, and recording it in a blockchain to form global trust data; combining the dynamic certificate chain data and a chaotic mapping algorithm to generate global random number data and verifying its integrity; combining the global random number data and hardware noise data to generate quantum initialization vector data, and encrypting the original communication data in blocks to generate block-encrypted data; using a secret sharing algorithm to distribute a dynamic session key to highly trusted nodes to ensure the security of the key; dynamically optimizing subsequent communication parameters according to the result of decrypting the communication data. By introducing a dynamic certificate chain, a chaotic mapping algorithm, block encryption, and a feedback optimization mechanism, the present invention improves the security, robustness, and adaptability of data transmission in edge computing scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of network security and edge computing, and particularly to a trusted asymmetric encryption communication method for an edge computing gateway driven by a certificate chain. Background Art

[0002] With the rapid development of the Internet of Things and edge computing, edge devices need to efficiently and reliably perform data interaction in a dynamic and complex network environment, while traditional security communication solutions have limitations in dealing with data integrity, authentication, and privacy protection. Trusted communication based on a certificate chain can provide a distributed trust mechanism, which significantly improves the security, authenticity, and anti-attack ability of data during transmission by combining dynamic certificate chains with asymmetric encryption algorithms.

[0003] The prior art (Chinese invention patent, publication number: CN113591109B, title: Method and system for communicating between a trusted execution environment and the cloud) based on the transmission method of a trusted execution environment (TEE) and a root of trust has solved the communication security problem between the device side and the cloud to a certain extent, but still has the following defects:

[0004] The existing method uses the device's inherent root of trust or pre-injected key pairs for data protection, which is difficult to dynamically adapt to changes in the network environment and interoperability between complex devices, and is easily targeted by attacks; most adopt fixed encryption key generation and transmission strategies, such as a single symmetric or asymmetric encryption method, lacking flexibility in dealing with complex attack scenarios; the prior art relies on a centralized key management and verification mechanism, resulting in low verification efficiency in a multi-node distributed environment and being vulnerable to man-in-the-middle attacks and data tampering threats. Summary of the Invention

[0005] In view of the many problems existing in the above prior art, the present invention provides a trusted asymmetric encryption communication method for an edge computing gateway driven by a certificate chain. The present invention generates global random number data through dynamic certificate chain data and a chaotic mapping algorithm, encrypts the original communication data in blocks by combining quantum initialization vector data, and distributes dynamic key fragments to highly trusted nodes using a secret sharing algorithm, realizing a highly secure encryption communication process. By integrating dynamic trust management, randomness enhancement, and feedback optimization mechanisms into the communication method, the security and robustness of data transmission are significantly improved.

[0006] A trusted asymmetric encryption communication method for an edge computing gateway driven by a certificate chain includes the following steps:

[0007] Generate node feature data based on the hardware characteristics of edge nodes, generate dynamic certificate chain data through the cooperation between edge nodes, and record the dynamic certificate chain data in a blockchain to form global trust data;

[0008] Generate global random number data based on dynamic certificate chain data and chaotic mapping algorithm, and perform integrity verification on the global random number data;

[0009] Combine the global random number data to perform block encryption on the original communication data, generate block encrypted data, and append the signature of the block encrypted data and the check value of the block encrypted data to form signature encrypted data;

[0010] Verify the integrity of the signature encrypted data based on the dynamic certificate chain data, decrypt the block encrypted data to generate decrypted communication data, and adjust subsequent communication parameters according to the result of the decrypted communication data.

[0011] Preferably, the process of generating global random number data based on dynamic certificate chain data and chaotic mapping algorithm includes: processing the initial random number fragment data of high-trust nodes through an enhanced chaotic mapping algorithm, performing multiple iterative mixing processes on the initial random number fragment data combined with random number cooperation path data to generate mixed random number data, and finally generating global random number data by combining the mixed random number data with the path hash of the dynamic certificate chain data; wherein, the enhanced chaotic mapping algorithm generates random number fragment data through the following formula:

[0012]

[0013]

[0014] Wherein, represents the random number fragment value of the current iteration; represents the cooperation path status value of the current iteration; represents the node status value of the current iteration; represents a parameter dynamically generated based on node feature data, used to control the dynamic change of the mapping function.

[0015] Preferably, the process of the enhanced chaotic mapping algorithm processing high-trust nodes includes: sorting high-trust nodes using the trust weight in the dynamic certificate chain data, and adjusting the initial state parameters of the enhanced chaotic mapping algorithm based on the sorting result.

[0016] Preferably, the process of combining the global random number data to perform block encryption on the original communication data includes: dividing the original communication data into blocks according to a fixed size to generate block data, and combining the global random number data and hardware noise data to generate quantum initialization vector data, wherein the quantum initialization vector data is generated through the following formula:

[0017]

[0018] Wherein, represents the quantum initialization vector data; represents a quantum hash function; represents the th segment of the global random number data; represents the th sampling value of the hardware noise data; represents the total number of segments of the global random number data and the hardware noise data.

[0019] Preferably, the generation process of the quantum initialization vector data further includes: preprocessing the hardware noise data, and the preprocessing includes denoising and quantization processing.

[0020] Preferably, the block encryption process includes: encrypting each block of data by combining the AES-256-GCM algorithm with the quantum initialization vector data to generate block encrypted data, and storing the dynamic session key data in fragments to multiple edge nodes through the secret sharing algorithm, where the dynamic session key data is generated by the following formula:

[0021]

[0022] where, represents the dynamic session key data; represents the th segment of the global random number data; represents the th segment of the quantum initialization vector data; represents the total number of segments of the global random number data and the quantum initialization vector data.

[0023] Preferably, the process of storing the dynamic session key data in fragments through the secret sharing algorithm includes: splitting the dynamic session key data into multiple key fragments, each key fragment is distributed and stored to highly trusted nodes according to a predetermined distribution rule, and at least part of the key fragments can be used to recover the complete dynamic session key data based on the recovery threshold.

[0024] Preferably, the process of verifying the integrity of the signature encrypted data based on the dynamic certificate chain data includes: extracting the signature verification information and the public key data from the dynamic certificate chain data, verifying the signature encrypted data by using the extracted public key data, and verifying the integrity of the block encrypted data through the HMAC check value.

[0025] Preferably, the process of adjusting the subsequent communication parameters according to the result of decrypting the communication data includes: generating optimization feedback data by analyzing the packet loss rate, communication delay and decryption success rate of the decrypted communication data, and dynamically adjusting the block data size, the global random number generation path and the dynamic key generation strategy based on the optimization feedback data.

[0026] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows:

[0027] By introducing dynamic certificate chain data, the present invention achieves stronger flexibility and adaptability, overcomes the limitations of static trust roots, supports dynamic trust management of multiple nodes, and significantly improves the robustness of the edge computing network;

[0028] By combining the chaotic mapping algorithm and the distributed random number generation technology, the present invention realizes the high randomness and unpredictability of global random number data, effectively preventing pseudo-random number attacks and replay attacks;

[0029] Through the innovative encryption method of combining the block encryption strategy with quantum initialization vector data, the present invention improves the security and anti-attack ability of data encryption, ensuring the integrity and confidentiality of the block-encrypted data during transmission;

[0030] By optimizing communication parameters based on feedback, the present invention realizes dynamic adjustment of the communication process, significantly improving communication efficiency and reliability, and meeting the requirements of complex edge computing scenarios. Brief Description of the Drawings

[0031] Figure 1 is a schematic flow chart of the present invention;

[0032] Figure 2 is a schematic diagram of dynamic certificate chain generation in the present invention;

[0033] Figure 3 is a schematic diagram of global random number generation in the present invention;

[0034] Figure 4 is a schematic diagram of block encryption and dynamic key distribution in the present invention;

[0035] Figure 5 is a schematic diagram of communication optimization feedback in the present invention. Detailed Embodiments

[0036] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0037] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0038] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0039] A trusted asymmetric encryption communication method for a certificate chain-driven edge computing gateway, comprising the following steps:

[0040] Generating node feature data based on the hardware characteristics of edge nodes, generating dynamic certificate chain data through the collaboration between edge nodes, and recording the dynamic certificate chain data in a blockchain to form global trust data;

[0041] The present invention analyzes the hardware characteristics of edge nodes and generates node feature data, thereby realizing the generation of a dynamic certificate chain and the construction of global trust data. The core of this process is a dynamic trust mechanism and a certificate chain generation mechanism based on the collaboration between edge nodes, and its main principle is as follows:

[0042] The node feature data is a unique identifier generated based on the hardware characteristics of edge nodes (such as MAC address, hardware serial number, device timestamp, etc.). This identifier is encrypted using a hash algorithm (such as SHA-256) to ensure its uniqueness and irreversibility. For example, for an edge node with a MAC address of A1:B2:C3:D4:E5:F6, a timestamp of 1672531200, and a hardware serial number of SN12345, the generation formula for the node feature data is:

[0043]

[0044] where represents the node feature data; represents the MAC address; represents the timestamp; represents the hardware serial number; represents the hash function (such as SHA-256). The node feature data generated in this way not only ensures uniqueness but also can resist conventional data tampering attacks.

[0045] such as Figure 2As shown, the generation of the dynamic certificate chain is based on the collaboration between edge nodes, and the main basis for collaboration is the degree of trust between nodes. The calculation of the trust degree comprehensively considers parameters such as the communication behavior, response time, and data integrity of nodes. For example, by analyzing the historical behavior data of edge nodes, a trust scoring model for nodes is constructed:

[0046]

[0047] Among them, represents the trust score; represents the node response time; represents the data integrity index; represents the communication success rate; represents the weight coefficient dynamically adjusted according to different scenarios.

[0048] On this basis, nodes with a trust score higher than the preset threshold are selected as highly trusted nodes, and the certificate chain data is generated through the public key signatures between these nodes. The public key signature process uses asymmetric encryption technology. The private key of the highly trusted node is used to sign the node feature data of other nodes to ensure the credibility of their identities.

[0049] The generated dynamic certificate chain data is written into the blockchain through distributed storage technology. As a decentralized distributed ledger, the blockchain can ensure the immutability and traceability of the certificate chain data. For example, each block in the blockchain contains information such as certificate chain data, the hash value of the previous block, and the timestamp:

[0050]

[0051] Among them, represents the dynamic certificate chain data; represents the hash value of the previous block; represents the timestamp of the generated block.

[0052] The introduction of the blockchain not only enhances the security of data but also provides a reliable basis for future node trust auditing and historical tracking.

[0053] By generating node feature data and combining it with the dynamic certificate chain, the identity of edge nodes can be accurately identified and authenticated, avoiding the addition of fake nodes. In addition, the combination of the trust scoring model and the dynamic certificate chain can dynamically reflect the behavior changes of nodes, improving the flexibility and anti-attack ability of the system.

[0054] After the dynamic certificate chain data is recorded in the blockchain, by utilizing the immutability and distributed storage characteristics of the blockchain, the integrity of the certificate chain data is ensured, and at the same time, it supports the tracing of the node trust history, which helps to achieve secure global trust management.

[0055] The trust scoring mechanism can dynamically adjust the trust level according to the actual performance of nodes. When the behavior of certain nodes is abnormal, the system can promptly reduce their trust level or even remove them from the list of highly trusted nodes, thereby enhancing the overall security of the network.

[0056] Example, assume there are five edge nodes The trust scores of each node are respectively , , , , , and the preset trust score threshold is 80. Through trust score calculation, the list of highly trusted nodes is . The system uses these three nodes to generate dynamic certificate chain data and records it through the blockchain.

[0057] When the behavior of node improves and its trust score rises to 82, the system will dynamically update the list of highly trusted nodes to , and generate new certificate chain data. This dynamic adjustment mechanism ensures the sensitivity of the network to changes in node behavior.

[0058] Generate global random number data based on the dynamic certificate chain data and the chaotic mapping algorithm, and perform integrity verification on the global random number data;

[0059] Preferably, as Figure 3 shown, the process of generating global random number data based on the dynamic certificate chain data and the chaotic mapping algorithm includes: processing the initial random number segment data of highly trusted nodes through an enhanced chaotic mapping algorithm, performing multiple iterative mixing processes on the initial random number segment data combined with random number cooperation path data to generate mixed random number data, and finally generating global random number data by combining the mixed random number data with the path hash of the dynamic certificate chain data; wherein, the enhanced chaotic mapping algorithm generates random number segment data through the following formula:

[0060]

[0061]

[0062] wherein, represents the random number segment value of the current iteration; represents the cooperation path state value of the current iteration; represents the node state value of the current iteration; represents a parameter dynamically generated based on node feature data, used to control the dynamic change of the mapping function.

[0063] Each highly trusted node generates initial random number fragment data based on its own state variables, which include the node's hardware feature data, timestamp, dynamic certificate chain related information, etc. These state variables are iteratively calculated through an enhanced chaotic mapping algorithm to generate random number fragments after initialization.

[0064] The enhanced chaotic mapping algorithm is calculated based on the above formulas. These formulas generate initial random number fragments through non-linear iteration and ensure the unpredictability and high sensitivity of the random numbers generated each time.

[0065] The generated initial random number fragment data needs to be mixed through the cooperation path among nodes. The cooperation path data is determined by the trust weights in the dynamic certificate chain. The higher the trust weight of a node, the greater the weight assigned to its data. For example, for three nodes in the path, the weights are , , , then the path mixing process passes through the weighted processing formula:

[0066]

[0067] where, represents the path mixed random number fragment; represents the th initial random number fragment of the node; represents the th trust weight of the node; represents the total number of nodes participating in the path mixing.

[0068] The random number cooperation path data generates mixed random number data after multiple rounds of iterative mixing. To ensure the uniqueness and security of the global random number data, the mixed random number data is combined with the path hash of the dynamic certificate chain data to finally generate the global random number data. The path hash combines the signatures and timestamps of all highly trusted nodes in the dynamic certificate chain and is implemented through the following formula:

[0069]

[0070] where, represents the global random number data; represents the hash function (such as SHA-256); represents the path hash of the dynamic certificate chain data; || represents the concatenation operation.

[0071] The chaotic mapping algorithm is characterized by the sensitivity of its initial value and the unpredictability of its trajectory, enhancing the complexity of random number generation. At the same time, it further improves the uniqueness and security of random numbers by combining dynamic certificate chain data.

[0072] The random number generation process is dynamically dependent on the trust weights of highly trusted nodes and can reflect the dynamic changes in trust among nodes. This collaboration mechanism ensures that the random number generation process not only has a distributed nature but also has self - adaptability.

[0073] By integrating dynamic certificate chain data through path hashing, the generated global random number data has global uniqueness. Even if an attacker can obtain some initial random number fragments of nodes, they cannot predict or reconstruct the complete global random number data.

[0074] In an embodiment, assume that in an edge computing environment, there are three highly trusted nodes Their trust weights are respectively , , . Each node generates initial random number fragment data based on its own state variables and the chaotic mapping algorithm:

[0075] Node 's initial random number fragment is ;

[0076] Node 's initial random number fragment is ;

[0077] Node 's initial random number fragment is .

[0078] Through weighted fusion of the random number collaboration path:

[0079]

[0080] Combined with the path hashing of dynamic certificate chain data , finally, global random number data is generated through global hashing:

[0081]

[0082] Assume that the hash function is SHA - 256, then the generated global random number data is a random value of a fixed length, such as .

[0083] Preferably, the enhanced chaotic mapping algorithm for processing highly trusted nodes includes: sorting the highly trusted nodes using the trust weights in the dynamic certificate chain data and adjusting the initial state parameters of the enhanced chaotic mapping algorithm based on the sorting results.

[0084] The dynamic certificate chain data records the trust scores of each node, which are comprehensively calculated from parameters such as the node's historical behavior data, communication response time, and data integrity (for example, through the formula ). Based on the trust score, the system sorts the highly trusted nodes in descending order to form a list of highly trusted nodes.

[0085] The purpose of sorting is to determine the priority and influence weight of each node in the random number generation process. For example, nodes with a high trust score will have a greater impact on the initial state parameters of the chaotic mapping algorithm.

[0086] The initial state parameters of the chaotic mapping algorithm (such as ) are the key to generating random number segments. According to the sorting results of the highly trusted nodes, the initial values of these parameters are dynamically adjusted to ensure that the random number generation process has higher dynamics and security. For example:

[0087]

[0088]

[0089]

[0090] Among them, represents the initial state parameters of the chaotic mapping algorithm; represents the weight of the highly trusted nodes after sorting by trust score; represents the characteristic data of the corresponding node; represents the hash function, which is used to map the input data to an initial value of a fixed length.

[0091] After the initial state parameters are determined, the chaotic mapping algorithm starts iterative operations to generate unpredictable random number segments. The iterative formula is:

[0092]

[0093]

[0094] This enhanced dynamic adjustment mechanism not only ensures that the generation of random number segments is highly randomized but also enhances the anti-attack ability of the generation process.

[0095] By dynamically adjusting the initial state parameters in combination with the sorting results of the highly trusted nodes, the enhanced chaotic mapping algorithm can generate more secure and unpredictable random numbers, avoiding security risks caused by fixed initial parameters.

[0096] The present invention dynamically updates the sorting of highly trusted nodes through dynamic certificate chain data, thereby dynamically adjusting the initial state parameters of the chaotic mapping algorithm. This dynamic nature enables the random number generation process to adapt to changes in node behavior, significantly enhancing the flexibility of the system.

[0097] Traditional random number generation algorithms usually have security risks due to the leakage or fixation of initial parameters. The present invention dynamically adjusts the initial state parameters by using the sorting results of highly trusted nodes in the dynamic certificate chain data, so that even if an attacker masters partial node information, it is difficult to predict the final result of random number generation.

[0098] Example, assume that three highly trusted nodes are recorded in the dynamic certificate chain , and their trust scores are respectively . The system sorts the nodes according to the scores, and the result is . According to the sorting result, the system assigns weights to each node: , , .

[0099] Then, these weights are used to generate the initial state parameters of the chaotic mapping algorithm:

[0100]

[0101]

[0102]

[0103] Where , , is the characteristic data of node (such as MAC address and hardware serial number).

[0104] After determining the initial parameters, the chaotic mapping algorithm starts to run and generates random number segments after multiple iterations. Assume that after five iterations, the obtained random number segments are:

[0105] Node : ;

[0106] Node : ;

[0107] Node : .

[0108] These random number segments then participate in the generation of the global random number to ensure the security and flexibility of the entire system.

[0109] Combined with the global random number data, the original communication data is block-encrypted to generate block-encrypted data, and the signature of the block-encrypted data and the check value of the block-encrypted data are attached to form signature-encrypted data;

[0110] Preferably, the process of encrypting the original communication data by combining the global random number data includes: generating block data by dividing the original communication data into blocks of a fixed size, and generating quantum initialization vector data by combining the global random number data and the hardware noise data, where the quantum initialization vector data is generated by the following formula:

[0111]

[0112] where, represents the quantum initialization vector data; represents the quantum hash function; represents the th segment of the global random number data; represents the th sampling value of the hardware noise data; represents the total number of segments of the global random number data and the hardware noise data.

[0113] As Figure 4 shown, the original communication data is divided into multiple block data according to a fixed block size. This block operation not only facilitates subsequent encryption processing, but also makes data encryption and transmission more flexible.

[0114] Assume that the original communication data is a byte stream of length , and the fixed block size is , then the total number of block data is , and the size of each block data is or the remaining number of bytes.

[0115] The quantum initialization vector data (Quantum Initialization Vector, IV) is a key component of block encryption. Its generation combines the global random number data and the hardware noise data to ensure the uniqueness and security of the encryption process for each block of data. The specific generation formula is: .

[0116] The quantum hash function is an improved hash function that can efficiently process the input data and output a hash value of a fixed length, which is used to initialize the state of the encryption algorithm.

[0117] After the quantum initialization vector data is generated, each block of data is encrypted in combination with a symmetric encryption algorithm (such as AES-256-GCM). The encryption process uses the quantum initialization vector as part of the encryption key to ensure the uniqueness and security of the encryption result for each block.

[0118] ​By combining global random number data and hardware noise data to generate quantum initialization vector data, the present invention ensures the unpredictability of the block encryption process and effectively prevents known plaintext attacks and repeated attacks.

[0119] The block encryption design ensures that even if some blocks are lost or damaged during transmission, it will not affect the encryption and decryption operations of other blocks, enhancing the reliability of the communication system.

[0120] The dynamic generation of quantum initialization vector data makes the result of each encryption completely different. Even if the original encrypted data is the same, this feature further enhances the security of encrypted communication.

[0121] Embodiment, assuming the original communication data has a length of 1024 bytes and a block size of 256 bytes, then the total number of blocks is . The global random number data and the hardware noise data are sampled respectively as:

[0122] Global random number data ;

[0123] Hardware noise data .

[0124] The generation process of the quantum initialization vector data is as follows:

[0125] Calculate the input value of the quantum initialization vector data according to the formula:

[0126]

[0127] Apply the quantum hash function :

[0128]

[0129] Assume that the quantum hash function outputs a vector of a fixed length .

[0130] Use and the AES-256-GCM algorithm to encrypt each block of data: The block data is encrypted into ciphertext respectively. Finally, the ciphertext of each block is generated independently, ensuring the security isolation between blocks and the uniqueness of the encryption result.

[0131] Preferably, the generation process of the quantum initialization vector data further includes: preprocessing the hardware noise data, and the preprocessing includes denoising and quantization processing.

[0132] The hardware noise data is sourced from the hardware devices of edge nodes (such as sensors, oscillators, or other physical noise sources). Due to hardware characteristics, different devices generate non-uniform noise signals, which may be mixed with environmental noise or systematic biases. The core of the denoising process lies in preserving the randomness of the hardware noise data while removing the interference signals that may affect randomness or introduce biases.

[0133] A high-pass filter is used to remove low-frequency system noise and retain high-frequency random noise signals. The specific process includes performing a Fourier transform on the hardware noise data to separate the noise frequency components.

[0134] After frequency-domain analysis, by designing a band-pass filter, only the random signal components within the frequency range are retained, and the denoised signal is inverse Fourier transformed back to the time domain to obtain the purified hardware noise data.

[0135] To ensure that the hardware noise data can be adapted to the digital computing environment, quantization processing is required. The quantization process converts the continuous analog signal into a discrete digital signal while maintaining its randomness and unpredictability. The hardware noise signal is divided into multiple fixed intervals, and each interval corresponds to a discrete value. The hardware noise data after denoising and quantization is combined with the global random number data to generate quantum initialization vector data.

[0136] The denoising process removes the interference components in the hardware noise signal and retains the high-frequency randomness characteristics, ensuring that the generated quantum initialization vector data has a high degree of randomness and unpredictability.

[0137] The quantization process discretizes the continuous hardware noise signal, enabling it to be effectively combined with the global random number data in the same digital computing environment, ensuring that the generated initialization vector data has consistency and accuracy.

[0138] The preprocessed hardware noise data introduces more sources of randomness in the initialization vector generation, further enhancing the uniqueness and anti-attack ability of block encryption and preventing pattern-based attacks.

[0139] Preferably, the block encryption process includes: encrypting each block of data through the AES-256-GCM algorithm in combination with the quantum initialization vector data to generate block-encrypted data, and storing the dynamic session key data in fragments to multiple edge nodes through the secret sharing algorithm, where the dynamic session key data is generated by the following formula:

[0140]

[0141] where, represents the dynamic session key data; represents the th fragment of the global random number data; Represents the th segment of the quantum initialization vector data; Represents the total number of segments of the global random number data and the quantum initialization vector data.

[0142] In the present invention, the block encryption process encrypts the block data by combining the AES-256-GCM algorithm with the quantum initialization vector data, and at the same time uses the dynamic session key data as an auxiliary key management mechanism to further enhance the security and flexibility of the system. The dynamic session key data is jointly generated by the global random number data and the quantum initialization vector data, and after being fragmented, it is distributed and stored in multiple edge nodes through the secret sharing algorithm to ensure the security and recoverability of the key.

[0143] Block encryption is a process of encrypting each block after splitting the original communication data according to a fixed block size. Each block of data is processed separately, and the AES-256-GCM algorithm is used in combination with the quantum initialization vector data for encryption, where the quantum initialization vector data is used as part of the encryption key to ensure the independence and randomness of the encryption result of each block. The AES-256-GCM algorithm has the following characteristics:

[0144] Symmetric encryption: The same key is used for encryption and decryption;

[0145] Authenticated encryption: The GCM mode supports integrity verification to ensure that the block data has not been tampered with;

[0146] High performance: Suitable for the efficient processing requirements of the edge computing environment.

[0147] For each block of data , the encryption formula is:

[0148]

[0149] where represents the block encrypted data; represents the block data; represents the dynamic session key data; represents the quantum initialization vector data.

[0150] The dynamic session key data is an important key generated during the block encryption process, which is jointly calculated by the global random number data and the quantum initialization vector data. The specific generation formula is: , this generation process ensures the uniqueness of the dynamic session key data, and at the same time makes its association with the global random number and the quantum initialization vector data closer, improving the anti-attack ability of the key.

[0151] The generated dynamic session key data is fragmented and stored through a secret sharing algorithm. The secret sharing algorithm is a secure distribution method that can split the key into shards, and each shard is independently stored in different edge nodes. At the same time, a recovery threshold is set, and only any key shards are required to recover the complete key. This fragmented storage mechanism has the following advantages:

[0152] Security: Even if some nodes are compromised, the attacker still cannot obtain the complete key;

[0153] Redundancy: When a node fails, the complete key can be recovered through the key shards of other nodes. The fragmentation formula of the secret sharing algorithm is:

[0154]

[0155] Among them, represents the key fragmentation function; represents the complete dynamic session key data; represents the randomly generated polynomial coefficients; represents the key recovery threshold. Each node stores the key shard , where is the node number.

[0156] Block encryption combines the quantum initialization vector data and the dynamic session key data to ensure that the encryption result has high randomness and can effectively resist known plaintext attacks and pattern analysis attacks.

[0157] The dynamic session key data is dynamically generated through the global random number data and the quantum initialization vector data and is fragmented and stored through the secret sharing algorithm, effectively preventing key leakage and enhancing the security of key management.

[0158] The block encryption design makes the encryption results of individual blocks independent. Even if some block data is damaged or lost, other blocks can still be normally decrypted. Combined with the fragmented and stored dynamic session key data, the system has strong fault tolerance for node failures or partial fragment losses.

[0159] Example, assume that the original communication data is divided into , the quantum initialization vector data is , the global random number data is , and the size of each block of data is 256 bytes.

[0160] Generation of dynamic session key data, according to the formula:

[0161]

[0162] Assume Then:

[0163]

[0164] Use the AES-256-GCM algorithm to encrypt each block of data:

[0165]

[0166]

[0167]

[0168] Dynamic session key Is divided into three fragments and stored in nodes through the secret sharing algorithm . For example:

[0169] Node Stores ;

[0170] Node Stores ;

[0171] Node Stores .

[0172] Set the threshold , and any two pieces can recover the complete key.

[0173] Preferably, the process of storing the dynamic session key data in fragments through the secret sharing algorithm includes: dividing the dynamic session key data into multiple key fragments, distributing and storing each key fragment to highly trusted nodes according to a predetermined distribution rule, and limiting that at least some key fragments can recover the complete dynamic session key data based on the recovery threshold.

[0174] In the present invention, the dynamic session key data is the core key information in the block encryption process. To ensure the security of the key and the fault tolerance of the system, the present invention uses the secret sharing algorithm to divide the dynamic session key data into multiple key fragments, and distributes and stores these fragments to different highly trusted nodes according to a predetermined distribution rule. At the same time, a recovery threshold is set to ensure that the complete dynamic session key data can still be recovered in the case of loss of some key fragments. The following is the specific principle:

[0175] The secret sharing algorithm is a method of dividing a complete key into multiple parts, where each part is stored separately in different nodes. By setting the recovery threshold , the complete key can be recovered when at least pieces of key fragments are obtained. This process is based on the principle of polynomial interpolation in mathematics.

[0176] Let the complete dynamic session key data be , and use a randomly generated -degree polynomial :

[0177]

[0178] where represents the complete dynamic session key data; represents the randomly generated polynomial coefficients; represents the recovery threshold.

[0179] For highly trusted nodes, the key fragment stored by each node is , where is the unique identifier of the node.

[0180] The storage process of the dynamic session key fragments is based on the trust weights of the highly trusted nodes in the dynamic certificate chain data. Nodes with higher trust weights preferentially store more important key fragments to reduce the risk of key leakage. For example, nodes with a trust weight of respectively store . This allocation rule ensures the security of fragment storage.

[0181] If it is necessary to recover the complete dynamic session key data, only at least pieces of key fragments are required, and the Lagrange interpolation method can be used to recover:

[0182]

[0183] where represents the key fragment stored by node ; represents the identifier of node .

[0184] After the key is fragmented and stored in multiple highly trusted nodes, even if an attacker compromises some nodes, the complete key cannot be directly obtained, improving the overall security.

[0185] The secret sharing algorithm ensures that the system can still recover the complete key when some nodes fail or key fragments are lost by setting the recovery threshold , enhancing the fault tolerance.

[0186] The dynamic session key fragments can be dynamically allocated to different nodes, and the introduction of trust weights makes the key storage strategy more intelligent, adapting to the dynamic network environment of the edge computing gateway.

[0187] Example, assume the dynamic session key data is , set the recovery threshold , the number of participating nodes . The randomly generated quadratic polynomial is:

[0188]

[0189] For nodes, calculate the key fragments:

[0190] Node 1:

[0191] Node 2:

[0192] Node 3:

[0193] Node 4:

[0194] Node 5:

[0195] Allocate the above key fragments to Nodes 1 - 5 and store their respective key fragments.

[0196] If Nodes 2, 4, and 5 encounter failures, only the key fragments of Nodes 1, 3, and 5 are still available. Recover the complete key through Lagrange interpolation:

[0197]

[0198] The final recovery result is .

[0199] Verify the integrity of the signature - encrypted data based on the dynamic certificate chain data, decrypt the block - encrypted data to generate decrypted communication data, and adjust the subsequent communication parameters according to the result of the decrypted communication data.

[0200] Preferably, the verification of the integrity of the signature - encrypted data based on the dynamic certificate chain data includes: extracting signature verification information and public key data from the dynamic certificate chain data, verifying the signature - encrypted data using the extracted public key data, and verifying the integrity of the block - encrypted data through the HMAC check value.

[0201] The dynamic certificate chain data is a trusted data chain jointly generated by multiple highly trusted nodes, recording the signature information, public key data, trust relationship, etc. of each node. During the verification process, first extract the signature verification information and public key data of the corresponding node from the dynamic certificate chain data.

[0202] Signature verification information: Records the hash digest used when generating the signature;

[0203] Public key data: Generated from the asymmetric key pair of highly trusted nodes and used for signature verification.

[0204] The structured design of the dynamic certificate chain data allows for fast indexing and efficient parsing. For example, the format of each block record is as follows:

[0205]

[0206] Among them, represents the node identifier; represents the public key data of the node; represents the node signature information; represents the generated timestamp; represents the hash value of the previous block.

[0207] The first step in verifying the signed encrypted data is to verify the signature using the extracted public key data. The signed encrypted data contains the encrypted chunk data and its signature. By decrypting the signature and comparing the hash values, the authenticity of the data source and the non-tampering of the data are confirmed. The verification process includes the following steps:

[0208] Calculate the hash digest of the signed encrypted data: Among them is the signed encrypted data, is the calculated hash value.

[0209] Decrypt the signature using the extracted public key: , where is the decrypted hash value.

[0210] Compare the two hash values and : If they are the same, the signature verification passes.

[0211] To further ensure the integrity of the chunk encrypted data, the present invention introduces an integrity verification mechanism based on the Hash Message Authentication Code (HMAC). The HMAC check value is pre-generated during the encryption process and attached to the signed encrypted data. During verification, the HMAC value of the chunk data is recalculated and compared with the attached HMAC value. The HMAC calculation formula is:

[0212]

[0213] Among them, represents the dynamic session key data; represents the chunk encrypted data.

[0214] Verifying the signed encrypted data through the dynamic certificate chain data ensures that the data source is trustworthy and has not been tampered with, guaranteeing the security of the communication process.

[0215] The real-time nature and updatability of dynamic certificate chain data enable the system to quickly adapt to node changes, enhancing the flexibility and robustness of the verification process.

[0216] Combined with the HMAC verification mechanism, it further ensures the integrity of the chunk-encrypted data, effectively resisting data tampering and forgery attacks.

[0217] In an embodiment, assuming in an edge computing environment, the latest block record of the dynamic certificate chain data is:

[0218]

[0219] The signed and encrypted data has the following structure:

[0220]

[0221] The verification process includes the following steps:

[0222] (1) Extract the public key and the signature .

[0223] (2) Calculate the hash digest of the signed and encrypted data .

[0224] (3) Decrypt the signature using the extracted public key:

[0225] (4) Compare and : If they are the same, the signature verification passes.

[0226] (5) Calculate the HMAC value of the chunk-encrypted data:

[0227] (6) Compare and the attached : If they are the same, the integrity verification of the chunk-encrypted data passes.

[0228] Preferably, as Figure 5 shown, the process of adjusting subsequent communication parameters according to the result of decrypting communication data includes: generating optimization feedback data by analyzing the packet loss rate, communication delay, and decryption success rate of the decrypted communication data, and dynamically adjusting the chunk data size, global random number generation path, and dynamic key generation strategy based on the optimization feedback data.

[0229] The analysis of the decrypted communication data is the basis for generating optimization feedback data. The following is the specific analysis process:

[0230] Packet loss rate: The packet loss rate is calculated by counting the difference between the number of received data packets and the number of sent data packets:

[0231]

[0232] where, is the number of sent data packets, is the number of received data packets. A higher packet loss rate may indicate that the current communication parameters need to be adjusted, such as reducing the block size to reduce the risk of loss.

[0233] Communication latency: Analyze the time required for each block of data from being sent to successful decryption (including transmission time and decryption time). A higher latency may indicate that the global random number generation path or the dynamic key generation strategy needs to be optimized.

[0234] Decryption success rate: The decryption success rate is calculated by comparing the number of successfully decrypted data packets with the number of received data packets:

[0235]

[0236] A lower decryption success rate may indicate problems with the current dynamic key generation strategy and need to be improved.

[0237] Based on the above performance metrics, optimize the feedback data through a weighted model:

[0238]

[0239] where, represents the optimized feedback data; represents the packet loss rate; represents the communication latency; represents the decryption success rate; represents the weight parameter dynamically adjusted according to different scenarios.

[0240] After the optimized feedback data is generated, the system dynamically adjusts the following communication parameters according to the feedback results:

[0241] Block data size: Reduce the probability of data loss by reducing the block size, while taking into account the transmission efficiency. For example, if the packet loss rate exceeds a preset threshold (such as 10%), the block size is reduced from 256 bytes to 128 bytes.

[0242] Global random number generation path: Optimize the collaborative path of global random number generation by adjusting the priorities of highly trusted nodes to reduce latency. For example, nodes with shorter response times are preferentially used for global random number generation.

[0243] Dynamic Key Generation Strategy: By adjusting the parameter weights of the dynamic session key generation formula, the key generation process can be made more efficient. For example, increasing the weight related to quantum initialization vector data can enhance the dynamics and randomness of key generation.

[0244] Dynamically adjusting the block size can effectively reduce data loss, and optimizing the global random number generation path can reduce communication latency and improve the overall efficiency of the system.

[0245] Improving the dynamic key generation strategy makes the key generation process more efficient and random, enhances the system's resistance to various attacks, and ensures the security of communication data.

[0246] The feedback-based dynamic adjustment mechanism can respond in real time to changes in the communication environment (such as network fluctuations or node state changes), ensuring that the system is always in an optimized state and adapting to complex edge computing environments.

[0247] Example: Assume that in an edge computing environment, the statistical results of decrypting data during communication are as follows:

[0248] Number of sent data packets ;

[0249] Number of received data packets ;

[0250] Number of successfully decrypted data packets ;

[0251] Average packet delay .

[0252] Calculate performance metrics based on the above data:

[0253] Packet loss rate:

[0254] Decryption success rate:

[0255] Optimize feedback data: Assume the weight parameter is :

[0256]

[0257] According to the optimized feedback data , the system adjusts communication parameters:

[0258] (1) Block data size: Reduce the block size from 256 bytes to 128 bytes to reduce the packet loss rate.

[0259] (2) Global random number generation path: Reorder highly trusted nodes and preferentially select nodes with a response time lower than 50 ms to participate in random number generation.

[0260] (3) Dynamic key generation strategy: Increase the weight of quantum initialization vector data to make the key generation process more dynamic.

[0261] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects.

[0262] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A certificate chain-driven trusted asymmetric encryption communication method for edge computing gateways, characterized in that It includes the following steps: Generate node feature data based on the hardware characteristics of edge nodes, statistically analyze the historical communication behaviors of each edge node, obtain the node response time, data integrity metrics, and communication success rate, and calculate the trust score through dynamically adjusted weight coefficients; Select nodes with trust scores higher than the preset threshold as highly trusted nodes, use the private keys of the highly trusted nodes to perform public key signatures on the node feature data of other nodes to generate dynamic certificate chain data, and record the dynamic certificate chain data into the blockchain to form global trust data; Process the initial random number fragment data of highly trusted nodes through an enhanced chaotic mapping algorithm, perform multiple iterative mixing processes on the initial random number fragment data combined with random number cooperation path data to generate mixed random number data, and combine the path hashes of the mixed random number data and the dynamic certificate chain data to finally generate global random number data, and perform integrity verification on the global random number data; Perform block encryption on the original communication data in combination with the global random number data. The process includes: generating block data by dividing the original communication data into fixed-size blocks, and generating quantum initialization vector data in combination with the global random number data and hardware noise data; based on the quantum initialization vector data and combined with the symmetric encryption algorithm, encrypt each block of data to generate block encrypted data; and append the signature of the block encrypted data and the check value of the block encrypted data to form signature encrypted data; Verify the integrity of the signature encrypted data based on the dynamic certificate chain data, decrypt the block encrypted data to generate decrypted communication data, and adjust subsequent communication parameters according to the result of the decrypted communication data.

2. The certificate chain-driven trusted asymmetric encryption communication method for the edge computing gateway according to claim 1, wherein The enhanced chaotic mapping algorithm for processing highly trusted nodes includes: sorting the highly trusted nodes using the trust weights in the dynamic certificate chain data, and adjusting the initial state parameters of the enhanced chaotic mapping algorithm based on the sorting results.

3. The certificate chain-driven trusted asymmetric encryption communication method for the edge computing gateway according to claim 1, wherein The generation process of the quantum initialization vector data further includes: preprocessing the hardware noise data, and the preprocessing includes denoising and quantization processing.

4. The certificate chain-driven trusted asymmetric encryption communication method for the edge computing gateway according to claim 1, wherein The block encryption process includes: encrypting each block of data through the AES-256-GCM algorithm in combination with the quantum initialization vector data to generate block encrypted data, and storing the dynamic session key data in fragments to multiple edge nodes through the secret sharing algorithm.

5. The method for trusted asymmetric encryption communication of a certificate chain-driven edge computing gateway according to claim 4, characterized in that, The process of storing the dynamic session key data in fragments through the secret sharing algorithm includes: dividing the dynamic session key data into multiple key fragments, distributing and storing each key fragment to highly trusted nodes through a predetermined distribution rule, and restricting at least some key fragments to be able to recover the complete dynamic session key data based on the recovery threshold.

6. The certificate chain-driven trusted asymmetric encryption communication method for an edge computing gateway according to claim 1, characterized in that, The verification of the integrity of the signature encrypted data based on the dynamic certificate chain data includes: extracting signature verification information and public key data from the dynamic certificate chain data, verifying the signature encrypted data using the extracted public key data, and verifying the integrity of the block encrypted data through the HMAC check value.

7. The certificate chain-driven trusted asymmetric encryption communication method for an edge computing gateway according to claim 1, wherein The process of adjusting subsequent communication parameters according to the result of decrypting communication data includes: generating optimization feedback data by analyzing the packet loss rate, communication latency, and decryption success rate of the decrypted communication data, and dynamically adjusting the block data size, global random number generation path, and dynamic key generation strategy based on the optimization feedback data.

Citation Information

Patent Citations

  • Methods and systems for communication between trusted execution environments and the cloud.

    CN113591109B

  • Block chain intelligent cooperative authentication method for multi-user common management

    CN115987519A

  • Power distribution network safety protection method based on trusted computing and privacy computing

    CN116418478A