Trust evaluation method and system based on credit dynamic access control
By dynamically updating the credit scores of medical IoT devices in the consortium chain network, BTRM's challenges in detecting intermittent attacks and evaluating global user behaviors are solved, and efficient trust assessment and security guarantees for medical IoT devices are achieved.
Patent Information
- Application Number
- CN202510029826.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-13
AI Technical Summary
Existing blockchain-based trust and reputation model (BTRM) has challenges in detecting intermittent attacks and evaluating global user behavior, and it is difficult to obtain credit scores that fully represent user behavior.
The trust evaluation method based on credit dynamic access control is adopted to initialize the credit score of medical IoT devices in the consortium chain network and dynamically update the credit scores according to their access behavior, and to realize the trust evaluation of nodes.
It effectively reduces the speed of credit score recovery after passive access to medical IoT devices, increases the cost of malicious behavior, ensures the accuracy and fairness of credit scores, and prevents whitewashing attacks and token forgery.
Smart Images

Figure CN119995943A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer applications, and in particular relates to a trust evaluation method and system based on credit dynamic access control. Background Art
[0002] With the development of the times, the number of Internet of Things (IoT) devices has increased dramatically around the world. Massive IoT devices have promoted the interconnection of all things, but they have also increased the risk of IoT networks being attacked by malicious users. Malicious users can launch various forms of attacks on IoT networks, such as distributed denial of service (DDoS), spoofing attacks, and switch attacks, to hinder the access of other normal users and the provision of network services. In recent years, the security of the Internet of Medical Things (IoMT) networks has become an important issue. The IoMT network is designed to connect patients with caregivers, and all reports, data, and medical signals are transmitted through these networks. Therefore, it is urgent to design some security mechanisms that can detect malicious behavior to improve the security of the Internet of Medical Things.
[0003] Trust and Reputation Model (TRM) is one of the important mechanisms to improve network security. In the Internet of Things, TRM is often used to evaluate the trust relationship between devices and networks. Specifically, TRM can be divided into three categories from the perspective of participants, including "device to device", "device to network" and "network to device". The "device to device" reputation model is mainly used to evaluate the trust between devices. The device analyzes the behavior of another device to determine whether it is trustworthy. The "device to network" reputation model is executed to evaluate the user's trust in the network. It evaluates the quality of service provided by the network to verify whether the network is trustworthy. In contrast, the "network to device" reputation model focuses on evaluating the network's trust in the user. The network identifies the user as a trustworthy user based on his or her behavior. Compared with the above two reputation models that initiate evaluation or feedback on the user side, the "network to device" TRM evaluates user behavior on the network side, which can better prevent deceptive evaluation messages initiated by malicious users. Therefore, deploying the "network to device" reputation model in the medical Internet of Things is very effective for malicious attack detection.
[0004] The reputation model of "network to device" can be roughly divided into centralized trust and reputation model (CTRM) and distributed trust and reputation model (DTRM). Compared with CTRM, DTRM can avoid single point failure and has the advantages of simplified evaluation process and fast execution, which is suitable for deployment in IoT application scenarios. However, traditional DTRM still has some shortcomings in data sharing and trusted collaboration.
[0005] The emergence of blockchain provides a new development direction for DTRM. With the characteristics of decentralization, traceability, and anonymity, blockchain can solve the problems of poor trust between evaluation nodes, unreliable data sharing, and opaque trust relationships in traditional DTRM. Therefore, organically combining blockchain with DTRM to build a blockchain-based trust and reputation model (BTRM) can solve the above problems well. However, the existing BTRM is evaluated at fixed time intervals, which makes the detection of intermittent attacks more challenging. In addition, BTRM tends to evaluate users' specific behaviors rather than global behaviors, so it is difficult to obtain a credit score that can fully represent user behavior. Summary of the invention
[0006] The purpose of the present invention is to provide a trust assessment method and system based on credit dynamic access control to resist the security risks brought by the vulnerability of Internet of Things devices.
[0007] In a first aspect, the present invention provides a trust evaluation method based on credit dynamic access control, which comprises the following steps: Step 1: Use medical IoT devices as nodes in the alliance chain network; initialize the nodes and their credit points, obtain the node's identity authentication information, and build access policies for the resources provided by the nodes; Step 2: The node that accesses the resource is regarded as the subject node, and the node that provides the resource is regarded as the object node; the access request information of the subject node to the object node is set; according to the access request information and the credit score of the subject node, whether the subject node meets the access condition is determined; if the subject node meets the access condition, the subject node can access the object node; otherwise, the object node refuses the access of the subject node; Step 3: Obtain evaluation feedback results by evaluating the access behavior of the subject node to the object node, and update the credit score of the subject node according to the evaluation feedback results; Step 4: Repeat steps 2 and 3 to continuously update the credit score of the node through dynamic access between different nodes, thereby achieving trust evaluation of the node.
[0008] Preferably, in step 3, the method for obtaining the evaluation feedback result is as follows: The access behavior of the main node is decomposed into multiple different characteristic attributes, and each characteristic attribute is split into multiple evidence types; the importance of all evidence types under the characteristic attributes corresponding to the evidence type is compared pairwise to obtain an initial judgment matrix; the initial judgment matrix is converted into a fuzzy consistency matrix and then normalized to obtain the weight vector of the characteristic attribute; according to the access behavior evidence of the main node under different characteristic attributes, the access behavior evidence is normalized, and after fusing the weight vectors for the characteristic attributes, the evaluation score of each characteristic attribute is obtained; the evaluation feedback results are confirmed according to the evaluation scores of different characteristic attributes.
[0009] Preferably, in step 3, the method for updating the credit score of the subject node is as follows: The scoring function is constructed by setting the scoring values corresponding to different evaluation feedback results. The current credit score of the main node is obtained according to the scoring function and the historical access records of the main node. The expression is as follows: Among them, T d The current credit score of the main node d; H d is the historical access record of the main node d; β is the total number of low-quality access, denied access, and malicious access that occurred in the main node; α is the starting credit score; E(x) is the scoring function; x is the evaluation feedback result.
[0010] Preferably, the evaluation feedback results include positive behavior, low-quality service behavior, access denial behavior and malicious access behavior; the absolute values of the scoring scores corresponding to positive behavior, low-quality service behavior, access denial behavior and malicious access behavior decrease in sequence.
[0011] Preferably, the node's identity authentication information includes the node's attribute set, the node's signature and the timestamp of the registration transaction; the access policy includes a set of mandatory attributes, the actions that the resource is allowed to access, the allowed context set, the real-time refresh rate of access data and the minimum credit score allowed for access; the access request information includes the object node's identifier, the action requested by the subject node, the encrypted session key and the signature of the access request information.
[0012] Preferably, in step 2, the access conditions are: the attribute set of the subject node includes a set of mandatory attributes, the action requested to be executed by the subject node is included in the actions allowed by the policy, and the current credit score of the subject node is greater than or equal to the minimum credit score allowed for access.
[0013] Preferably, the identity authentication information and access policy are stored in the blockchain.
[0014] Preferably, in step 2, before determining whether the subject node meets the access conditions, the validity of the subject node's identity is first checked; if the subject node's identity authentication information is expired or the subject node and the object node's identities are the same, the subject node's access is denied.
[0015] In the second aspect, the present invention provides a trust assessment system based on credit dynamic access control, which is used to execute the above-mentioned trust assessment method; the trust assessment system includes a device layer, a blockchain layer, a storage layer and a user layer; the device layer includes an edge server and a medical Internet of Things device; the edge server is used to provide blockchain proxy services and calculate the credibility of the medical Internet of Things device based on the trust assessment mechanism; the medical Internet of Things device is a physical device and a sensor used for data collection, transmission and interaction; the blockchain layer is composed of a consortium chain network, and the consortium chain network includes a management node and several peer nodes; the storage layer adopts a data storage server; the user layer includes an administrator node and a medical Internet of Things device node; the administrator node is used to initialize the relevant configuration of the blockchain network and deploy smart contracts on the blockchain network.
[0016] Preferably, the credit score is calculated on the edge server by calling the credit assessment contract in the blockchain layer.
[0017] The present invention has the following beneficial effects: 1. The present invention sets different scoring values for different evaluation feedback results, so that when negative access behavior occurs, the punishment is much stronger than the reward for positive access, thereby reducing the credit score recovery speed of the medical Internet of Things device after a negative access, and greatly increasing the cost of the medical Internet of Things device to do evil; at the same time, after each access behavior, the present invention also needs to update the credit score in combination with the historical access record of the current device to prevent fraudulent behavior of covering up negative access through active access in a short period of time, and ensure the accuracy and fairness of the credit score.
[0018] 2. The present invention initiates a registration transaction through a performance improvement plan to store the identity authentication information as a key-value pair on the blockchain to prevent attribute tampering; by storing the attribute set in the identity authentication information in the form of a hash value on the blockchain, it can not only protect the privacy and security of the attributes and prevent attribute forgery, but also optimize the storage space on the blockchain; at the same time, since the identity information of each node is recorded on the blockchain and its authenticity is verified through a consensus mechanism, it ensures that its identity attribute information is not tampered with or deleted, effectively preventing whitewashing attacks.
[0019] 3. The present invention generates a corresponding valid identity based on the machine code of the internal hardware of the medical Internet of Things device, so that malicious Internet of Things devices cannot create multiple identities, thereby preventing witch attacks on the Internet of Things network; at the same time, because the access control logic is completed by the smart contract, the authorization result is completely transparent and reliable, which further limits the behavior of nodes to improve their own reputation through self-promotion methods.
[0020] 4. The present invention issues access tokens to subject nodes so that they can be used to access resources multiple times without repeated authorization processes. Regardless of whether the authorization is passed, the access records will be written into the blockchain to support retrospective auditing of subsequent access records. At the same time, each token is associated with a specific object node. Even if an attacker forges an access token, it cannot be used in other sessions, thus preventing token forgery attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the structure of the trust evaluation system in the present invention.
[0022] Figure 2 Flow chart of the trust evaluation method in the present invention.
[0023] Figure 3 This is an access authorization flow chart of the trust evaluation method in the present invention.
[0024] Figure 4 The figure is a credit update flow chart of the trust evaluation method in the present invention.
[0025] Figure 5 This is an evaluation feedback flow chart of the trust evaluation method in the present invention.
[0026] Figure 6 Schematic diagram of evaluation scores at different times.
[0027] Figure 7 Schematic diagram of credit score update corresponding to four different types of access requests.
[0028] Figure 8 Schematic diagram of the change in access success rate of the present invention and the existing trust evaluation method under different malicious node proportions.
[0029] Fig. 9 The figure is a comparison diagram of the credit assessment delay and Gas consumption between the present invention and the existing trust assessment method.
[0030] Fig.10 A schematic diagram comparing the authorization delays of the present invention with and without an access token. DETAILED DESCRIPTION
[0031] The present invention will be further described below in conjunction with the accompanying drawings.
[0032] like Figure 1 As shown in the figure, a trust evaluation system based on credit dynamic access control includes device layer, blockchain layer, storage layer and user layer. Due to the high privacy and security requirements of medical Internet of Things application scenarios, a consortium blockchain network combined with a certificate authority (CA) access mechanism is used to implement the blockchain layer and the device layer. In addition, all communications between layers are carried out through the gateway.
[0033] The device layer includes edge servers and medical Internet of Things (IoMT) devices. Using edge computing technology, medical Internet of Things devices are decoupled from resource-intensive operations, such as malicious behavior detection and credit assessment. Therefore, the edge server can not only provide blockchain proxy services for medical Internet of Things devices, but also calculate the trustworthiness of IoMT devices based on the trust assessment mechanism. IoMT devices refer to physical devices and sensors that directly interact with patients and collect health data, such as electrocardiogram monitors, wearable medical devices, etc. Its main functions include data collection, transmission and interaction. Trusted IoMT devices can store their collected data resources in data storage servers within the hospital. The Message Queuing Telemetry Transport (MQTT) protocol is used for device-layer communication. MQTT is a lightweight messaging protocol optimized for IoT devices and low-bandwidth, high-latency or unreliable networks. To ensure message integrity, medical Internet of Things devices and edge servers use lightweight elliptic curve digital signatures (ECDSA) to sign messages transmitted in the network.
[0034] The blockchain layer is composed of the Quorum alliance chain network and is the core of the dynamic access control system architecture. The Quorum alliance chain network includes a management node and several peer nodes, and uses smart contracts to implement a decentralized access control mechanism based on attributes, making access authorization more reliable and efficient, thereby prohibiting malicious user nodes from illegally accessing device resources. Therefore, deploying network services in smart contracts can well achieve data security sharing and multi-domain trusted collaboration. In the blockchain layer, access control and credit evaluation services are implemented by access control contracts (ACC) and credit evaluation contracts (CEC), respectively. The access control contract (ACC) includes three contracts: PIP (Performance Improvement Plan), PDP (Data Packet Protocol) and PAP (Password Authentication Protocol), which is a collection of these three contracts. These smart contracts are deployed in the Quorum alliance chain network. Any node in the blockchain network can call the service interface provided by the smart contract to obtain access authorization. However, all users need to be authenticated by the certificate authority within the medical institution before joining the blockchain network. This is because the medical Internet of Things involves the privacy data of patients. Identity authentication can ensure that the data is only open to specific authorized users and prevent sensitive information from being accessed by unauthorized third parties.
[0035] The storage layer includes data storage servers within medical institutions. The privacy and security of its data storage is guaranteed by the medical institutions themselves. It can store a large amount of data resources of IoMT devices for a considerable period of time, and IoMT devices will regularly store and update resources to ensure the real-time access to subsequent interactive data.
[0036] The user layer consists of administrator nodes and IoMT device nodes. The administrator is mainly responsible for initializing the relevant configuration of the blockchain network and deploying smart contracts on the blockchain network. After that, other users can apply to register and join the blockchain network to access the relevant services of the blockchain network, that is, send attribute-based authorization requests to the blockchain network to request IoMT device resources. In addition, the administrator can update the access policy or smart contract by presenting the identity authentication certificate issued by the certificate authority.
[0037] like Figure 2 As shown, the working method of the trust evaluation system includes the following steps: Step 1: Node initialization 1-1. Attribute registration The trust evaluation system meets the following conditions: (1) Administrator nodes, blockchain gateways, and edge devices are secure and trustworthy; (2) There are multiple secure data storage servers within the medical institution, and they have sufficient redundancy to achieve high availability and scalability; (3) The certificate authority is safe and trustworthy.
[0038] The IoMT device node uses a secure channel to send an attribute registration request to the certificate authority and signs the request with its private key SKs for authentication. The certificate authority issues an identity certificate for the node based on its machine code identity such as the motherboard, memory, and Mac address. Since the effective identity of an IoT device is generated based on the machine code of its internal hardware, any different parameter model of any hardware in the IoMT device node will result in a different identity, so malicious IoT devices cannot create multiple identities, thereby preventing Sybil attacks on IoT networks.
[0039] Construct the attribute set A of node d d = {a1, a2,..., a M}; where a m is the mth attribute of the node, which is expressed as: a m =< key,val,type > (1) Where key, val and type are the name, value and type of the attribute respectively; m=1,2,...,M; M is the number of attributes in the node.
[0040] 1-2. Identity authentication information on the chain Get the identity authentication information TXreg of node d, which is expressed as: TXreg= {Hash(A d ),Sig s,Timestamp} (2) Among them, Hash is the hash value; Sig s It is the signature of the node; Timestamp is the timestamp of the registration transaction.
[0041] Use the credit evaluation contract to set a starting credit score for the newly added node as its initial credit status in the credit system, which is of great significance for subsequent credit evaluation and dynamic adjustment. Initiate a registration transaction through PIP to store the identity authentication information TXreg as a key-value pair on the blockchain to prevent attribute tampering; at the same time, the starting credit score corresponding to the node is also stored on the blockchain. Attribute set A d Hash value Hash (A d ) in the form of a blockchain, which can not only protect the privacy and security of attributes and prevent attribute forgery, but also optimize the storage space on the blockchain; at the same time, since the identity information of each node is recorded on the blockchain and its authenticity is verified through a consensus mechanism, it ensures that its identity attribute information is not tampered with or deleted, effectively preventing whitewashing attacks. Prevent replay attacks by setting a timestamp;
[0042] 1-3. In order to clearly define the authorization policy of the resources provided by the node, it is necessary to construct an access policy P and declare it as a Boolean rule of the required attributes. The access policy P defines a set of actions, represented as action ⊂ {read ,write}, which are executed on the target resource by the authorized node according to the rule conditions defined in the allowed context set c. Only the resource providing node has the right to construct, update and revoke the access policy P for all its resources. The access policy P is expressed as follows:
[0043] P =< A, c, action P , rate, T min > (3) Where A = {a1, ..., a n} is a set of mandatory attributes, that is, the attribute requirements that the node accessing the resource must meet; action P is the action that allows access to the resource; c is the allowed context set, c = < t, l >; t is the restricted access time; l is the restricted access throughput; rate is the real-time refresh rate of access data; T min The minimum credit score required to access.
[0044] Access control contract calls strategy management contract to initiate transaction TX pol The defined access policy P is stored in the blockchain and used as the basis for the access control contract to determine the subsequent node authorization. The transaction TXpol It is expressed as follows: TX pol = {P,Sig sp ,Timestamp} (4) Among them, Sig sp It is the signature of the node that provides resources; Timestamp is the creation time of access policy P.
[0045] Step 2: Access authorization stage The essence of access authorization is to grant corresponding resource permissions to nodes that meet the access policy P. The judgment of access authorization is completed by the access control contract, and its authorization result is completely decentralized and reliable. The access control contract evaluates the legitimacy of the incoming authorization request based on the access policy defined in the initialization phase and a specific set of Boolean attribute rules. Therefore, the entire access authorization process is completely decentralized, and the authorization result is more reliable. If the authorization is successful, an access token will be issued to the resource requester so that the token can be used to access the resource multiple times without repeating the authorization process. Regardless of whether the authorization is passed, the access record will be written to the blockchain to support the retrospective audit of subsequent access records.
[0046] 2-1. Initiate access request like Figure 3 As shown, the node that accesses the resource is taken as the subject node, and the node that provides the resource is taken as the object node; the access request information R of the subject node to the object node r is initialized to indicate a request to perform an operation on the object node r as an action, and the access request information R is expressed as: R =< r, action R , S, Sig R > (5) Among them, r is the identifier of the object node; action R is the action requested by the subject node; S is the encrypted session key, S= (k) (·) indicates encryption using the public key PKo of the object node; k is the original session key; Sig R For the signature of the request message, Sig R =SigSKs(Hash(R)); SigSKs(Hash(R)) represents the digital signature of the hash value of the access request information R.
[0047] By setting the signature Sig of the request message R ,The object node can use the public key PKs of the subject node to verify the authenticity and integrity of the signature, thereby determining whether the access request information R is sent by the corresponding subject node.
[0048] 2-2. Verify identity validity The subject node initiates a transaction to the access control contract based on the access request information R for policy verification; in order to verify the access request information R, the access control contract initiates an identity validity check to the certificate authority to prevent the identity information from expiring. At the same time, although a node can act as a service requester or a service provider, no node can request access to the node itself. Since the identity of each node is unique, after the access control contract receives the access request, it will verify whether the subject and object identity IDs of the request are consistent. If they are consistent, it is judged as a self-promotion attack and corresponding restrictive measures are taken. Since the access control logic is completed by the smart contract, the authorization result is completely transparent and reliable, which further limits the behavior of nodes to improve their reputation through self-promotion methods.
[0049] 2-3. Access authorization judgment The access control contract obtains the attribute information of the subject node; initializes the access status of the subject node and verifies the subject node. If the subject node satisfies the access policy P, that is, the attribute set A of the subject node d A contains a set of mandatory attributes. The action requested by the subject node is included in the actions allowed by the policy. The current credit score of the subject node is Rep. s Greater than or equal to the minimum credit score allowed to access T min , the verification is successful; otherwise, the object node denies the subject node’s access.
[0050] 2-4. Grant access token After verification, the access control contract issues an access rights token to the subject node. R , which is defined as: TokenR= <Reps, ExpR, l , time R , Sigsp> (6) Among them, Rep. s is the current credit score of the main node; Exp R is the expiration date of the access permission token; l is the access interval; time R The timestamp for token generation; SigspR is the digital signature for the access permission token.
[0051] Issuing access rights token RWhen issuing access tokens, the digital signature SigspR of the access token is generated to prevent access token forgery. The signature is generated by the server private key, and only the server public key can verify the signature. If the token is forged or tampered with, its signature verification will be invalid. And the issued access token is only valid for a short time and cannot be used after it expires. This can effectively reduce the chance of attackers obtaining valid tokens. In addition, each token is associated with a specific user session, so even if an attacker forges an access token, he cannot use it in other sessions, preventing token forgery attacks.
[0052] Step 3: Credit Update 3-1. After obtaining access authorization, the subject node accesses the object node through the authorization token.
[0053] 3-2. Access Interaction like Figure 4 and Figure 5 As shown in the figure, trust-based access control uses trust management technology to dynamically evaluate the reliability of the subject node by evaluating the changes in the subject node's access behavior to the object node. For example, when performing access interaction, both parties can evaluate the quality of service, the reliability and security of the network. In order to make a more detailed evaluation of the access behavior, the fuzzy hierarchical analysis method will be used to decompose the access behavior of the subject node into three different characteristic attributes, namely, the reliability attribute R, the performance attribute P, and the security attribute S. Then each characteristic attribute is refined and divided into more detailed evidence types, as shown in Table 1. In this way, the fuzzy uncertainty evaluation problem of access behavior is transformed into a simple trust evidence weighted sum problem.
[0054] Table 1 Types of evidence for credit score assessment After determining the evidence type, the importance of all evidence types under the characteristic attributes corresponding to the evidence type is compared pairwise to obtain the initial judgment matrix J0=(r ij )n×n; where r ij is the importance of the fuzzy relationship between the i-th evidence type and the j-th evidence type in the feature attribute, r ij ∈[0,1]; n is the number of evidence types in the feature attribute; The more important evidence type i is than evidence type j, the more important the degree r is. ij The bigger.
[0055] The initial judgment matrix J0 is converted into a fuzzy consistency matrix Q = (q ij )n×n; where q ij The expression is: (7) Among them, qi is the sum of the i-th row of the initial judgment matrix R; q j is the sum of the j-th column of the initial judgment matrix R.
[0056] Normalize the fuzzy consistency matrix Q to obtain the weight vector W = (w1, w2,...,w n ) T ; Among them, w i is the weight; its expression is: (8) 3-3. Credit feedback When the access ends or the authorization token expires, the main node uses the fuzzy hierarchical analysis method to analyze the multi-dimensional access behavior credentials collected by the edge gateway to determine whether there is malicious access behavior. The specific process is as follows: The reliability, performance and security attributes of access behaviors are measured. Evidence of user node access behaviors under different characteristic attributes can be obtained through network traffic detection tools (such as NetFlow, WireShark, etc.). Since various indicators may have different dimensions, the indicators with different dimensions are normalized. The normalization method is as follows:
[0057] If the evidence type is a positive indicator, that is, a benefit indicator, such as network bandwidth, the normalized processing result The expression is: (9) in, is the measurement data of the j-th evidence type of the a-th feature attribute; and are the minimum and maximum values of the measurement data of the evidence type in the ath feature attribute; a=1,2,3.
[0058] If the evidence type is a negative indicator, that is, a cost indicator, such as data transmission packet loss rate and delay jitter, the normalized processing result The expression is: (10) According to the normalization results Get the evaluation score S for each feature attribute a , whose expression is: S a = D a ×W a , 0 ≤S a ≤ 1 (11) Among them, D a = (d a1 , da2 , ..., d an );W a is the weight vector of the a-th feature attribute.
[0059] The evaluation scores S of the reliable attributes are calculated by the above method. r , the evaluation score S of the performance attribute p And the evaluation score S of the security attribute s , in order to make an overall evaluation of this access behavior. During the interaction of nodes, the network packet capture tool is used to capture relevant access behavior credentials as required, and the services provided by each other are evaluated and fed back based on various indicators such as the success rate of data transmission, response time, error rate, and violations during the interaction. The feedback content is divided into two aspects: positive access and negative access. Negative access includes low-quality access, denied access, and malicious access. Only when the evaluation scores of the three characteristic attributes meet the pre-set thresholds can this access be defined as a positive access. When the evaluation score S r When the evaluation score S is lower than the threshold, the access will be defined as a denied access type. p When the evaluation score S is lower than the threshold, it is defined as a low-quality access type; if and only if s Or when the evaluation scores of any two or more attribute features are lower than the threshold, it is a malicious access type.
[0060] 3-4. Reward and Punishment Strategy If a node detects a passive access from another node, it can submit the type of passive access and the access message M or transaction TXF through the smart contract. The transaction TXF is defined as follows:
[0061] TXF= {feed||AccNo||H(Token R )||Sig s} (12) Among them, feed is the evaluation feedback result, feed⊂{active access, low-quality access, denied access, malicious access}; AccNo is the sequence number of this access event; H(Token R ) is the hash value of the authorization token.
[0062] Although the subject node can access the object node multiple times through the authorization token, only one transaction TXF can be submitted for each token. Subsequently, CEC will dynamically update the credit score of the subject node based on the feedback results. The digital signature and serial number in the message or transaction ensure that no device can forge malicious access records from other devices. Obviously, different types of access behaviors should have different effects on device credit. Therefore, the scoring function E(x) is defined according to different categories of access behaviors as follows:
[0063] (13) Among them, v1, v2, v3 and v4 are the scoring values corresponding to different access types, v1> 0, v2, v3, v4< 0 and |v1|≪|v2|<|v3|<|v4|; x is the evaluation feedback result.
[0064] Therefore, when negative access behavior occurs, the punishment is much greater than the reward for positive access.
[0065] 3-5. Credit score update According to the interactive feedback between nodes and the rewards and punishments received, the positive and negative behaviors of the nodes are scored cumulatively and fed back to the credit evaluation contract CEC to complete the credit score update, comprehensively evaluate the credit score of the node, and dynamically adjust it. Over time, the weight of earlier feedback information is gradually reduced to ensure that the credit score reflects the latest performance of the node. Because some users cover up their bad behavior through good behavior in the short term, after each access behavior, it is necessary to dynamically update the device's credit score in combination with the current device's historical access records. Through long-term historical access records, this kind of fraud can be more effectively prevented to ensure the accuracy and fairness of the credit score. The credit score of the dth device is T d The expression is:
[0066] (14) Among them, H d is the historical access record of the dth subject node; β is the total number of low-quality access, denied access, and malicious access that have occurred on the current subject node; α is the starting credit score; is the sum of the scores corresponding to the historical access behaviors of the dth subject node; arctan(·) is the inverse tangent function.
[0067] If the credit score of the dth device is T d When the credit score is lower than the set threshold, the device is prohibited from requesting any service, thus preventing malicious devices from consuming system resources and improving the resource utilization and security of the system. d It increases slowly with the increase of normal access times, but once the device is detected to have negative access, its credit score will be significantly reduced. And the credit score growth rate decreases with the increase of bad behavior, which means that if the device has multiple malicious access behaviors, its credit score will be significantly reduced and difficult to recover, which greatly increases the cost of the device doing evil.
[0068] The main goal of using the trust evaluation mechanism is to enable the system to control access rights to resources more finely to better support dynamic and fine-grained access control. At the same time, in order to reduce the high latency and resource consumption caused by IoT devices when performing trust evaluation, the trust evaluation mechanism is implemented on the edge device. The credit score is calculated on the edge device by calling the credit evaluation contract in the blockchain network, making the trust evaluation mechanism more flexible and efficient. Since the trust evaluation mechanism collects behavioral credentials of various dimensions through the edge server within the medical institution, and then uploads them to the credit evaluation contract for credit calculation and update, and the edge server within the medical institution is honest and trustworthy. During the whole process, the IoMT device does not participate in the collection of behavioral credentials, nor is it responsible for calculating or updating credit scores. Therefore, even if some nodes are maliciously invaded, the attacker cannot use them to launch malicious feedback attacks to damage the reputation of the server, effectively preventing malicious feedback attacks.
[0069] Step 4: Repeat steps 2 and 3 to continuously update the credit score of the node through dynamic access between different nodes, thereby achieving trust evaluation of the node.
[0070] Step 5: Experimental Verification The access behavior evaluation mechanism is based on the key indicators of multiple network credentials in the access interaction process, thus overcoming the one-sidedness of a single evaluation indicator and realizing the fusion of multiple indicators. In order to verify the accuracy and scientificity of the access behavior evaluation using the fuzzy hierarchical analysis method in the credit-based access control method, an experimental analysis is conducted using the reliable attribute in the access behavior as an example. The evidence type set r = {packet loss rate, abnormal service rate, network failure rate} is selected as the judgment criterion for the reliable attribute R. According to the business needs of the medical Internet of Things, the evidence types in the evidence type set are compared pairwise, and their importance is quantitatively described to obtain the initial judgment matrix J0, as shown below:
[0071] (15) According to formula (7), the initial judgment matrix J0 is transformed into the fuzzy consistency matrix Q: (16) According to formula (8), the fuzzy consistency matrix Q is normalized to obtain the weight vector W of the reliable attribute R: W = (0.289, 0.333, 0.378)T (17) Use Ubuntu's tc (traffic control) command to simulate bad access behavior, and use the tc command to introduce a high packet loss rate on the eth0 interface to simulate the high packet loss rate that may exist in abnormal access behavior. In order to simulate abnormal service scenarios, tc is used to add a delay that exceeds the service response time on the network interface to increase the abnormal service rate. And intermittently disable the network interface to simulate network failures. Measure the network link data of normal behavior and malicious behavior at different times, as shown in Table 2:
[0072] Table 2 Link measurement data time Packet loss rate / % Abnormal service rate / % Network failure rate / % type <![CDATA[T1]]> 0.057 0.13 0.32 positive <![CDATA[T2]]> 0.048 0.35 4.6 negative <![CDATA[T3]]> 0.033 0.26 0.29 positive <![CDATA[T4]]> 5.1 4.2 0.27 negative It is necessary to normalize the measurement data of these heterogeneous quantities. Since the packet loss rate, abnormal service rate and network failure rate are all negative indicators, the data will be processed according to formula (10) to obtain the evaluation vector of each indicator at different times: (18) Use formula (11) to calculate the evaluation score S at each moment a , the scores are as follows Figure 6 As shown in the figure. As can be seen from the figure, the comprehensive scores of link access behaviors at T1 and T3 are significantly higher than those at T2 and T4. This is mainly because T2 and T4 simulate the actual medical Internet of Things application scenarios where there may be network link failures and high-latency service scenarios, while T1 and T3 measure the data of normal access links. Therefore, the network failure rate at T2 is much higher than that at other times, and the packet loss rate and abnormal service rate at T4 are also higher than those at other times. After being evaluated by the access behavior evaluation mechanism, the comprehensive score of positive access behaviors is significantly higher than that of negative behaviors, which is consistent with the actual label category and also confirms the accuracy and scientificity of the designed access behavior evaluation mechanism.
[0073] After a multi-level analysis of the reliability, performance, and security attributes of the access behavior, the evaluation mechanism will feed back the evaluation results to the credit calculation contract, which will then aggregate the trust based on the historical access behavior of the device. Four different types of access requests will be initiated to the Raspberry Pi node through a shell script, and the credit score changes of each type will be observed when different types of access requests occur. Figure 7 As shown in the figure, as the number of normal accesses increases, the credit score of the device shows an increasing trend. However, when the 50th negative access occurs, the credit score of the node decreases to varying degrees.
[0074] When a malicious intrusion device access occurs, the credit score of the current node will drop suddenly, and it will no longer be able to request access to any other device, and its credit score will be difficult to restore to normal levels. The penalty for low-quality or denied access services that may be caused by network link failures and temporary device offline is much less than that for malicious intrusions. As can be seen from the figure, it takes five consecutive low-quality services and denied access behaviors to reduce the node's credit score to a low level. After the network link is repaired or the device is online, its credit score will slowly rise with the increase in the number of active accesses. It is not difficult to see that the penalty intensity of this scheme is much greater than the reward level, which is mainly to increase the cost of passive access and curb the expansion of malicious behavior. Therefore, the credit-based access control method can well distinguish different access behaviors and subdivide these behaviors. Different rewards and punishments are given in combination with their historical behaviors, which enhances the dynamic security of access control.
[0075] The reason for introducing the credit mechanism in access control is to continuously monitor and evaluate user behavior through the credit mechanism, so as to reduce the illegal infringement of the system by malicious users or devices. Figure 8 As shown in the figure, malicious nodes with a proportion of 10%, 30%, 50%, 70%, and 90% are simulated in the experimental test network, and these nodes will initiate various types of interactive behaviors, such as low-quality access, access denial, and malicious access. On this basis, the access success rate changes of the three schemes of the present invention (TrustBased Dynamic Access Control, TDAC), Feng, and DEM-BTRM under different malicious node proportions are tested to demonstrate the identification and response capabilities of different schemes for interactive behaviors when facing various changing attack environments.
[0076] As the proportion of malicious nodes continues to increase, the access success rates of TDAC and DEM-BTRM are relatively close and both show a slow downward trend. Among them, the access interaction success rates of TDAC and DEM-BTRM are relatively close under various malicious node proportions. This is mainly because TDAC and DEM-BTRM are interactive behavior evaluation methods based on multi-index fusion. In the TDAC scheme, the access interaction behavior of the node is mainly divided into three characteristic attributes, and then each characteristic attribute is further refined and split into more measurable evidence types. Similarly, DEM-BTRM evaluates the reputation of the node based on three behavior sets: link behavior, access behavior, and communication behavior, each of which also contains multiple behavior credentials. Therefore, the two schemes are more scientific and accurate in evaluating reputation, and the access success rates are naturally similar. However, Feng's scheme has a large difference in performance from the above two schemes, and even the proportion of malicious nodes increases, and the access success rate increases year-on-year. This is because Feng's solution only relies on four indicators, namely packet loss rate, transmission delay, access success rate and node performance, to evaluate access behavior, lacking comprehensive consideration of multiple factors. Therefore, its evaluation results are relatively one-sided and prone to misjudgment. This also explains why its access success rate is inconsistent with TDAC and DEM-BTRM and fluctuates.
[0077] Next, we compare the credit assessment latency and gas consumption of these three solutions. We take the average of 1,000 credit assessment latency values and record the gas consumption of different solutions for credit assessment transactions. Fig. 9 As shown in the figure, the credit evaluation delay and Gas consumption of the DEM-BTRM scheme are significantly higher than those of the TDAC and Feng schemes. This is because the DEM-BTRM scheme designs three complex contracts for direct credit, indirect credit and credit aggregation respectively, and the calculation of a credit evaluation requires the interaction of these three contracts. TDAC and Feng are both lightweight credit evaluation methods, in which TDAC uses the fuzzy hierarchical analysis method to evaluate and analyze access behavior, and then the credit calculation contract aggregates credit based on the historical behavior records of the node. In this process, the hierarchical analysis and feedback of access behavior are performed by a trusted edge server, so there is no need to design an additional indirect credit mechanism to resist malicious evaluation. Compared with DEM-BTRM, the performance in latency and Gas consumption is greatly improved. The scheme designed by Feng mainly collects data related to packet loss rate, transmission delay, access success rate and node performance for simple verification, and then submits it to the credit contract to calculate the node's credit score, so its latency and Gas consumption are lower than the other two schemes.
[0078] Combination Figure 8 and Fig. 9It can be seen that compared with Feng and DEM-BTRM solutions, TDAC can reduce the complexity of data collection and processing and improve evaluation efficiency without sacrificing the accuracy and reliability of evaluation results. The lightweight and efficient credit evaluation mechanism has important application value and social significance in the medical Internet of Things scenario. It can not only improve the convenience and safety of medical services, reduce the operational risks of medical institutions, promote the rational allocation of medical resources and improve the overall efficiency of the medical Internet of Things system, but also promote the digital transformation and sustainable development of the medical industry.
[0079] In addition, a token mechanism is introduced into the TDAC solution. To verify the role of the token mechanism designed in TDAC in access authorization, a comparative experiment is designed to verify its effectiveness. Specifically, two groups of experiments will be conducted, one of which is the TDAC solution with a token mechanism and the other without a token. The validity period of the token is set to two minutes, and then an access request is initiated every one minute, and the access delay data of the two groups of experiments are recorded.
[0080] like Fig.10 As shown in the figure, whether or not the Token mechanism is used has little effect on access authorization during the first access, and the latency levels of the two are relatively close. In the subsequent two accesses, the authorization latency of the scheme with the Token access token is much better than that of the scheme without the Token mechanism. Then, in the third access, the two return to the same level, and so on. The main reason for this phenomenon is that, without the use of the Token access token, each access request of the node needs to be authorized by the access control system, so its latency is relatively stable. When TDAC introduces the Token mechanism, the first access request of the node needs to be authorized by the access control system, and only after the authorization is passed will the Token be issued. After the node obtains this Token, it can access the target device node multiple times within the validity period of the token without the need for authorization judgment again, so the latency of its subsequent access is greatly reduced. In the TDAC scheme, although the subsequent access after obtaining the Token does not require authorization judgment, each access needs to collect its network link credentials to monitor its access behavior in real time, so the access with the token still requires a latency of about 1.2s, but it is still a significant improvement compared with the former.
Claims
1. A trust evaluation method based on credit dynamic access control, characterized in that: The following steps are involved: Step 1: Use medical IoT devices as nodes in the alliance chain network; initialize the nodes and their credit points, obtain the node's identity authentication information, and build access policies for the resources provided by the nodes; Step 2: The node that accesses the resource is regarded as the subject node, and the node that provides the resource is regarded as the object node; Set the access request information of the subject node to the object node; Determine whether the subject node meets the access conditions based on the access request information and the credit score of the subject node; If the subject node meets the access conditions, the subject node can access the object node; On the contrary, the object node denies the access of the subject node; Step 3: Obtain evaluation feedback results by evaluating the access behavior of the subject node to the object node, and update the credit score of the subject node according to the evaluation feedback results; Step 4: Repeat steps 2 and 3 to continuously update the credit score of the node through dynamic access between different nodes, thereby achieving trust evaluation of the node.
2. A trust assessment method based on credit dynamic access control according to claim 1, characterized in that: In step 3, the method for obtaining the evaluation feedback result is as follows: The access behavior of the main node is decomposed into multiple different characteristic attributes, and each characteristic attribute is split into multiple evidence types; the importance of all evidence types under the characteristic attributes corresponding to the evidence type is compared pairwise to obtain an initial judgment matrix; the initial judgment matrix is converted into a fuzzy consistency matrix and then normalized to obtain the weight vector of the characteristic attribute; according to the access behavior evidence of the main node under different characteristic attributes, the access behavior evidence is normalized, and after fusing the weight vectors for the characteristic attributes, the evaluation score of each characteristic attribute is obtained; the evaluation feedback results are confirmed according to the evaluation scores of different characteristic attributes.
3. A trust assessment method based on credit dynamic access control according to claim 1, characterized in that: In step 3, the method for updating the credit score of the subject node is as follows: The scoring function is constructed by setting the scoring values corresponding to different evaluation feedback results. The current credit score of the main node is obtained according to the scoring function and the historical access records of the main node. The expression is as follows: Among them, T d The current credit score of the main node d; H d is the historical access record of the main node d; β is the total number of low-quality access, denied access, and malicious access that occurred in the main node; α is the starting credit score; E(x) is the scoring function; x is the evaluation feedback result.
4. A trust assessment method based on credit dynamic access control according to claim 3, characterized in that: The evaluation feedback results include positive behavior, low-quality service behavior, access denial behavior and malicious access behavior; the absolute values of the scoring scores corresponding to positive behavior, low-quality service behavior, access denial behavior and malicious access behavior decrease in sequence.
5. A trust evaluation method based on credit dynamic access control according to claim 1, characterized in that: The node's identity authentication information includes the node's attribute set, the node's signature and the timestamp of the registration transaction; the access policy includes a set of mandatory attributes, the actions allowed for resource access, a set of allowed contexts, a real-time refresh rate for access data and a minimum credit score for access; the access request information includes an identifier for the object node, the action requested by the subject node, an encrypted session key and a signature for the access request information.
6. A trust evaluation method based on credit dynamic access control according to claim 5, characterized in that: In step 2, the access conditions are: the attribute set of the subject node includes a set of mandatory attributes, the action requested by the subject node is included in the actions allowed by the policy, and the current credit score of the subject node is greater than or equal to the minimum credit score allowed for access.
7. A trust evaluation method based on credit dynamic access control according to claim 1, characterized in that: The identity authentication information and access policies are stored in the blockchain.
8. A trust evaluation method based on credit dynamic access control according to claim 1, characterized in that: In the step 2, before determining whether the subject node meets the access condition, the identity validity of the subject node is first checked; If the subject node's identity authentication information expires or the subject node and object node have the same identity, the subject node will be denied access.
9. A trust evaluation system based on credit dynamic access control, characterized in that: Used to execute the trust assessment method based on credit dynamic access control as described in claim 1; the trust assessment system includes a device layer, a blockchain layer, a storage layer and a user layer; the device layer includes an edge server and a medical Internet of Things device; The edge server is used to provide blockchain proxy services and calculate the trustworthiness of medical IoT devices based on the trust evaluation mechanism; Medical IoT devices are physical devices and sensors used for data collection, transmission and interaction; the blockchain layer consists of a consortium chain network, which includes a management node and several peer nodes; the storage layer uses a data storage server; the user layer includes administrator nodes and medical IoT device nodes; The administrator node is used to initialize the relevant configuration of the blockchain network and deploy smart contracts on the blockchain network.
10. A trust evaluation system based on credit dynamic access control according to claim 9, characterized in that: The credit score is calculated on the edge server by calling the credit assessment contract in the blockchain layer.
Citation Information
Cited By
Block chain-based lease user credit risk assessment method and system
CN120849513A
Blockchain-based lease user credit risk assessment method and system
CN120849513B
Equipment access authentication method and system of wireless communication network
CN120957136A