Lightweight Internet of Things equipment identity management system based on block chain

By adopting a lightweight blockchain-based identity management solution in the IoT device identity management system, the identity authentication problem of IoT devices in the poor network is solved, efficient and accurate identity management and verification are achieved, and the cost of identity verification is reduced.

CN119995959APending Publication Date: 2025-05-13XINJIANG DIGITAL CERTIFICATE CERTIFICATION CENT (CO LTD)
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510084572.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing identity management technology is not adaptable to IoT devices, resulting in inaccurate identity verification of IoT devices in poor network conditions, increasing the cost of identity verification and reducing the performance of judging identity status.

Method used

The blockchain-based lightweight IoT device identity management system is adopted, and the identity management and verification of IoT devices is realized through the system initialization module, identity registration module, lightweight identity verification module, identity update module, identity revocation module and light node information maintenance module. The system utilizes the decentralized and immutable characteristics of blockchain to improve the accuracy and efficiency of authentication through light node synchronization of block headers and updates of Bloom filters and cryptographic accumulators.

Benefits of technology

It solves the problem of inaccurate identity verification of IoT devices in poor network conditions, reduces the cost of identity verification of IoT devices, and improves the performance of IoT judging identity status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995959A_ABST
    Figure CN119995959A_ABST
Patent Text Reader

Abstract

The invention provides a lightweight Internet of Things equipment identity management system based on a block chain, which comprises a system initial module, an identity registration module, a lightweight identity verification module, an identity updating module, an identity revocation module and a light node information maintenance module, and realizes functions of identity registration, verification, revocation, updating and the like based on a block chain environment. The equipment identity credibility is ensured; a block chain light node is deployed on the Internet of Things node to reduce resource consumption; a revocation scheme based on a Bloom filter and a cryptographic accumulator is used to realize light weight of identity verification so as to adapt to the environment of the Internet of Things. The method has the advantages that the problem of inaccurate identity bidirectional verification of the Internet of Things equipment under the condition of poor network is solved, the cost of identity verification of the Internet of Things equipment is reduced, and the judgment performance of the Internet of Things on the identity state is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things technology, and specifically to a lightweight Internet of Things device identity management system based on blockchain. Background Art

[0002] The Internet of Things is a huge network that connects various devices in the physical world. All IoT nodes collect and share data about how they are used and the surrounding environment. It aims to connect everything from individuals, groups to the physical world. According to the Internet of Things White Paper of China Academy of Information and Communications Technology, the total number of IoT connections worldwide is expected to reach 24.6 billion by 2025, and my country is expected to reach 8.01 billion. The Internet of Things is developing rapidly and on a large scale. It has mature applications in various aspects of life such as smart grids, smart transportation, and smart cities, and has great development prospects. my country has also taken many measures to vigorously promote the construction of the Internet of Things.

[0003] Blockchain is a multi-party shared, tamper-proof distributed ledger that builds a trusted data environment. The prototype of blockchain was proposed by Satoshi Nakamoto in 2008. It uses a distributed hash chain as a ledger to save permanent records of transactions between members, and then its central idea was refined into blockchain. Blockchain records transactions between two nodes in a permanent manner without the need for third-party identity verification. It has the characteristics of decentralization, openness, autonomy, and immutability. It can eliminate trust issues and has high security. In the past decade, the idea of ​​blockchain has spread from monetary finance to many fields such as the Internet of Things, supply chain, medical care, and public services.

[0004] With the rapid development of the Internet of Things and the Industrial Internet of Things, their security risks are also increasing. Identity management is an important aspect of the security of the Internet of Things: most connected computing devices in the information network share information directly with the cloud, so they are vulnerable to security threats and attacks, and identity-based attacks are usually considered a prerequisite for other attacks, such as man-in-the-middle attacks, data modification, and denial of service attacks. Identity authentication can be said to be one of the core security mechanisms that should be used at all levels of IoT devices, and identity management is particularly important for the Internet of Things.

[0005] The development of identity management systems can be summarized into the following three stages. The first stage: centralized identity management: identity providers can fully control the identity of users and provide authentication services to users. The second stage: federated identity management: establishing a trust relationship between identity providers is an arrangement between two or more organizations, such as using WeChat to authorize the login of applications on other platforms. The third stage: distributed identity management: centralized and federated digital identity models do not allow users to be completely independent or control their own identity information, which leads to privacy issues. Blockchain technology, as a decentralized distributed ledger, has received considerable attention in the field of identity management in recent years and has also achieved many industrial results.

[0006] In general, blockchain technology is becoming a prominent perspective for developing IoT security solutions in a decentralized and trustless environment. Using blockchain structure to manage the identities of IoT devices with limited computing power and storage is of great significance at present. Summary of the invention

[0007] The present application provides a lightweight IoT device identity management system based on blockchain to solve the problem that existing identity management technologies are not sufficiently adaptable to IoT devices.

[0008] The present application provides a lightweight IoT device identity management system based on blockchain, including a system initialization module, an identity registration module, a lightweight identity authentication module, an identity revocation module, an identity update module and a light node information maintenance module.

[0009] The system initialization module is used to initialize the identity management agency and the Internet of Things device, publish the necessary information of the identity management system, and synchronize the identity authentication information of the blockchain through the Internet of Things device; the identity registration module is used to accept the identity registration request of the Internet of Things device; the lightweight identity authentication module is used to verify the identity of the Internet of Things device; the identity revocation module includes an identity revocation judgment unit and an identity revocation information management unit, the identity revocation execution unit globally declares the revoked identity through the identity revocation transaction, and the identity revocation information management unit is used to maintain the contents of the Bloom filter and the cryptographic accumulator; the identity update module is used to accept the identity update request of the Internet of Things device; the light node information maintenance module includes a block header synchronization unit and a revocation auxiliary identity information update unit, the block header synchronization unit joins the blockchain network, listens to the new block broadcast information to synchronize the block header, and the revocation auxiliary identity information update unit is used to update the Bloom filter and the cryptographic accumulator stored in the Internet of Things device when an identity is revoked.

[0010] Furthermore, the operation steps of the system initialization module specifically include an information disclosure step, a block formation step, a recording step and a hash value verification step.

[0011] The information disclosure step is used to disclose the public keys of the members of the identity management agency, disclose the multi-signature threshold, disclose the hash algorithm of the Bloom filter in the blockchain, and disclose the public key and initial value of the cryptographic accumulator used in the blockchain; the block formation step is when a node initializes itself as the first node of the blockchain network, generating a genesis block as the first block of blockchain data; when there are already nodes in the blockchain network, the newly added blockchain node communicates with any node in the blockchain network, and the newly added blockchain node can obtain the content of the blockchain and join the blockchain network; the recording step is used to record the hash algorithm of the Bloom filter in the public blockchain and the public key and initial value of the cryptographic accumulator used in the public blockchain; the hash value verification step is to pull the information of all current block headers from the blockchain node, and verify in turn whether the hash field of the previous block header of each block is the same as the hash value of the previous block header. If they are the same, the content of the block header is trusted and stored in the local device.

[0012] Furthermore, the operation steps of the identity registration module specifically include an identity information determination step, a number assignment step, an identity registration transaction verification step, and an identity information storage step.

[0013] The identity information judgment step is to query and compare the identity information requested for registration with the registered identity information, determine whether the identity information requested for registration has been registered, and determine whether the identity information requested for registration provides a true and valid unique identifier. If the identity information requested for registration is legal, execute the next step; the number assignment step is used to assign a global unique number to the identity information requested for registration, and use the identity information requested for registration as an identity registration transaction, and attach the signature of the identity information; the identity registration transaction verification step is to broadcast the identity registration transaction to the identity management agency to verify the legitimacy. When the identity registration transaction meets the multi-signature threshold, the identity registration transaction is written into the block body to participate in the consensus. After confirmation by the identity management agency, it becomes immutable data on the blockchain network; the identity information storage step is to store the identity information content to the local device.

[0014] Furthermore, the operation steps of the lightweight identity authentication module specifically include a first verification step, a second verification step, a third verification step and a fourth verification step.

[0015] The first verification step is to read the validity period field in the identity information, compare it with the current time, and determine whether the identity has expired. If not, the next step is executed, wherein the identity information includes a Merkle proof; the second verification step is to combine the Merkle proof and use the blockchain head node to verify whether the identity information has been tampered with: the identity information is hashed, and a new Merkle root is constructed along the Merkle proof, and the new Merkle root is compared with the original Merkle root of the corresponding block. If the new Merkle root is the same as the original Merkle root, the verification is passed and the next step is executed; The third verification step is used to determine whether the identity information is in the Bloom filter. If so, it is determined whether the cryptographic accumulator can provide a valid proof of the identity information. If a valid proof can be given, the identity information is deemed to be in an unrevokated state and the next step is executed. Otherwise, the identity information is deemed to be revoked. If not, the identity information is determined to be valid and the next step is executed. The fourth verification step is to use the identity information to confirm whether the identity information contains the private key corresponding to the public key it claims through a "challenge-response" mechanism. If the verification fails, communication with the device is terminated.

[0016] Furthermore, in the identity revocation module, the identity revocation execution unit generates and broadcasts a new identity revocation transaction, in which the information of the revoked identity is stored, and the information of the revoked identity is indicated in the revocation transaction field in the block header; the identity management agency adds the revoked identity identifier to the Bloom filter, checks whether the revoked identity has been mistakenly added to the Bloom filter and assigned a cryptographic accumulator certificate, and determines whether the revoked identity is in the cryptographic accumulator. If so, the information of the revoked identity is deleted from the Bloom filter and the cryptographic accumulator; when the revoked identity request is added to the cryptographic accumulator, the identity management agency checks the revocation information set to determine whether the revoked identity is in the revocation information set. If not, the revoked identity is added to the cryptographic accumulator. Otherwise, it is determined that the request is a malicious request and the revoked identity cannot be added to the cryptographic accumulator.

[0017] Furthermore, the operation steps of the identity update module specifically include a content modification step and a validity period extension step.

[0018] The content modification step is that the identity management agency revokes the old identity information, writes the new identity information into the blockchain, confirms by consensus that the old identity information is consistent with the new identity information, and returns the Merkel proof of the new identity information to the Internet of Things device; the validity extension step is that the identity management agency does not revoke the old identity information, continues to use the content in the old identity information, and modifies the start time of the validity period of the new identity information to the expiration time of the old identity information, writes the new identity information into the blockchain, and returns the Merkel proof of the new identity information to the Internet of Things device after consensus confirmation, wherein the Internet of Things device still uses the Merkel proof of the old identity information before the old identity information expires, and uses the Merkel proof of the new identity information after the old identity information expires.

[0019] Furthermore, the operation steps of the block header synchronization unit specifically include a block header linking step, a hash value determination step, and a block header information storage step.

[0020] The block header linking step is to pull the information of the block header that does not exist in the IoT device in the blockchain node, and link the new block header to the existing block header; the hash value judgment step is to pull the information of all current block headers from the blockchain node, and verify in turn whether the hash value of the previous block header of each block is the same as the hash value of the previous block header. If it is judged that all block headers have not been tampered with, the content of the new block header is trusted and stored in the IoT device; if it is judged that there is a tampered block header, the light node selects other full nodes to communicate and obtain the block header information; the block header information storage step is that when the block header information cannot be successfully updated and synchronized, the light node directly selects to synchronize qualified block header information for storage, wherein the qualified block header indicates that the number of nodes storing qualified block headers is not less than a first threshold.

[0021] Furthermore, the operation steps of the revoking auxiliary identity information update unit specifically include a transaction writing step and an update verification step.

[0022] The transaction writing step is that the identity management agency writes the updated content of the Bloom filter and the cryptographic accumulator as a transaction into the block body of the latest block; the update verification step is that the Internet of Things device checks whether there is updated content in the revocation transaction field of the block body of the latest block. If so, it requests the updated content from the identity management agency, receives the transaction information stored in the Bloom filter and the cryptographic accumulator and the Merkle proof of the updated content, verifies the authenticity of the Merkle proof of the updated content, and after confirming the authenticity of the updated content, the Internet of Things device updates the content of the Bloom filter accumulator.

[0023] The present application provides a lightweight IoT device identity management system based on blockchain, which is composed of blockchain, IoT devices, and identity management agencies, including a system initialization module, an identity registration module, a lightweight identity authentication module, an identity update module, an identity revocation module, and a light node information maintenance module. The system initialization module is used to initialize the IoT devices and the identity management agency to initialize the necessary parameters for the operation of the system. The identity registration module is used to register the unique identity identification of the IoT device and other information on the blockchain. The lightweight identity authentication module is used for two-way authentication between IoT devices. The identity update module is used to write the update information of the IoT device to the new block transaction. The identity revocation module is used to judge the validity of the identity and maintain the data structure required for such judgment. The light node information maintenance module is used to synchronize the block header and update the identity revocation information, which solves the problem of inaccurate two-way identity authentication of IoT devices in poor network conditions, reduces the cost of identity authentication of IoT devices, and improves the judgment performance of the IoT on the identity status. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0025] Figure 1 Schematic diagram of a lightweight IoT device identity management system based on blockchain according to this embodiment; Figure 2 is a flow chart of the operation steps of the system initialization module described in this embodiment; Figure 3 is a flow chart of the operation steps of the identity registration module described in this embodiment; Figure 4 is a flow chart of the operation steps of the lightweight identity authentication module described in this embodiment; Figure 5 is a flow chart of the operation steps of the identity update module described in this embodiment; Figure 6 is a flowchart of the operation steps of the block header synchronization unit described in this embodiment; Figure 7 It is a flow chart of the operation steps of the auxiliary identity information revocation updating unit described in this embodiment. DETAILED DESCRIPTION

[0026] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0027] like Figure 1 As shown, the present application provides a lightweight IoT device identity management system based on blockchain, including a system initialization module, an identity registration module, a lightweight identity authentication module, an identity revocation module, an identity update module and a light node information maintenance module.

[0028] In this embodiment, the blockchain-based lightweight IoT device identity management system consists of a blockchain, an IoT device, and an identity management agency. The blockchain participant nodes locally store identity authentication-related information in the form of a blockchain. The nodes use a consensus protocol to ensure that legal information can be stored on the blockchain and is not tampered with, while ensuring that illegal information is not stored on the chain. The blockchain is a decentralized distributed ledger that contains a growing list of records that are connected into a chain through a hash algorithm and has good security properties such as decentralization, traceability, immutability, and transparency. The IoT device is responsible for managing its own identity status and submitting identity registration, revocation, and update requests to the identity management agency; it runs a light node and synchronizes the latest blockchain; it performs two-way identity verification with other IoT devices by reading the content of the blockchain; the identity management agency can form an alliance of government departments, enterprises, etc., establish blockchain nodes and join the blockchain network, participate in the blockchain consensus, and be responsible for accepting and verifying IoT device identity registration, revocation, and update requests, and writing identity-related information into the blockchain.

[0029] The present invention regards IoT device nodes as blockchain "light nodes". They only synchronize the content of the block header, and use the principle of simple payment verification, Merkle proof and the content of the block header to confirm that a certain identity information is in a block that has been confirmed to be legal by consensus, thereby performing identity authentication. In order to check the validity of the identity, this solution records the revoked identity on the blockchain, and saves the revoked identity in the Bloom filter (BF) and accumulator (Acc). By synchronizing and querying the latest BF and Acc, it is possible to easily determine whether a certain identity has been revoked.

[0030] The blockchain is a linked list of a series of blocks linked in chronological order. The block consists of two parts: the block header and the block body. In the present invention, the block body stores information such as identity registration and revocation, and each piece of information exists as a transaction. The block header not only stores the information necessary for blockchain consensus, but also stores information about the types of transactions contained in the block, so that the light node can determine whether the block has updated BF and Acc, and then determine whether synchronization is required.

[0031] Among them, the main fields and lengths of the block header are as follows: The block height (index) increases continuously from 0 and is used to locate and find specific blocks, as well as add and synchronize blocks.

[0032] The previous block hash (previous_hash) refers to the hash value of the previous block header, which is used to verify whether a block is indeed connected to the previous block it claims to be, thereby verifying whether the block content is legal and has not been tampered with.

[0033] Merkle root (merkle_root) is the root of the Merkle tree composed of the data in this block. The node determines the integrity of the block data by calculating the Merkle root of the transaction in the block and comparing it with the value in the block header. If the values ​​are equal, it means that the data in the block has not been tampered with. At the same time, this field can be used for simple payment verification. For users who provide Merkle proofs and single transaction originals, they can calculate and compare the Merkle root to verify the existence of the transaction. Merkle tree height (merkle_height) is auxiliary information to facilitate Merkle verification.

[0034] The revo_flag indicates whether there is an update transaction of BF and Acc in the block. There are four states: 00, 01, 10, and 11. If the first bit is 1, it means that the value of BF has been updated, and if the second bit is 1, it means that the value of Acc has been updated. Otherwise, it means that there is no update.

[0035] The data required for consensus (nonce) refers to the data required for consensus algorithm to be carried out or verified. Different consensus algorithms may have different required data. In this scheme, since only all nodes are used for consensus, they have sufficient computing power and the consensus process is a mature existing technology, so the consensus process will not be described in detail.

[0036] The system initialization module is used to initialize the identity management agency and the Internet of Things device, publish the necessary information of the identity management system, and synchronize the identity authentication information of the blockchain through the Internet of Things device.

[0037] like Figure 2As shown, the operation steps of the system initialization module specifically include step S11) information disclosure step, step S12) block formation step, step S13) recording step and step S14) hash value verification step.

[0038] Step S11) Information disclosure step, disclosing the public keys of the members of the identity management agency, disclosing the multi-signature threshold, disclosing the hash algorithm of the Bloom filter in the blockchain, and disclosing the public key and initial value of the cryptographic accumulator used in the blockchain; Step S12) Block formation step: when a node initializes itself as the first node of the blockchain network, a genesis block is generated as the first block of blockchain data; when there are already nodes in the blockchain network, the newly added blockchain node communicates with any node in the blockchain network, and the newly added blockchain node can obtain the content of the blockchain and join the blockchain network; Step S13) recording step, recording the hash algorithm of the Bloom filter in the public blockchain and the public key and initial value of the cryptographic accumulator used in the public blockchain; Step S14) Hash value verification step, pull the information of all current block headers from the blockchain node, and verify in turn whether the hash field of the previous block header of each block is the same as the hash value of the previous block header. If they are the same, trust the content of the block header and store it in the local device.

[0039] In this embodiment, the hash algorithm is an algorithm that transforms an input of any length into an output of a fixed length. The value of the output is the hash value, which is also called hash, hash, etc. The hash algorithm ensures that if two hash values ​​are different, then their original inputs are also different; if two hash values ​​are the same, then their original inputs are the same if there is no hash collision (which is highly unlikely to occur).

[0040] The identity registration module is used to accept the identity registration request of the Internet of Things device. The Internet of Things device provides identity information to the identity management agency and applies for identity registration. The application includes the public key generated by the Internet of Things device, the identity certificate of the Internet of Things device and the validity period information of the application, etc. The identity registration module returns the registration result.

[0041] like Figure 3 As shown, the operation steps of the identity registration module specifically include step S21) identity information judgment step, step S22) number assignment step, step S23) identity registration transaction verification step and step S24) identity information storage step.

[0042] Step S21) Identity information determination step, querying and comparing the identity information requested for registration with the registered identity information, determining whether the identity information requested for registration has been registered, and determining whether the identity information requested for registration provides a true and valid unique identifier. If the identity information requested for registration is legal, proceed to the next step.

[0043] Step S22) A numbering step is to assign a globally unique number to the identity information requested for registration, and treat the identity information requested for registration as an identity registration transaction, while attaching a signature for the identity information.

[0044] Step S23) Identity registration transaction verification step, broadcasting the identity registration transaction to the identity management agency to verify the legitimacy. When the identity registration transaction meets the multi-signature threshold, the identity registration transaction is written into the block body to participate in the consensus. After confirmation by the identity management agency, it becomes immutable data on the blockchain network.

[0045] Step S24) Identity information storage step, storing the identity information content in a local device for use in a subsequent verification process, wherein the identity information includes a unique identity identification number, a public key, an effective date, and a Merkle proof, etc.

[0046] The lightweight identity authentication module verifies the identity of the IoT device. The two parties to be verified present their identity information and the Merkle proof of the information. The information of the block header is used to confirm whether the identity information is in the blockchain through simple payment verification. The identity revocation status is judged based on the Bloom filter and the cryptography-based accumulator.

[0047] In this embodiment, simple payment verification is the process of using Merkle proof and Merkle root to confirm whether a transaction exists on the blockchain. The hash value of the Merkle tree root is compared and checked to see if it is the same as the hash value calculated based on the Merkle proof for a transaction. If the two are the same, it means that the transaction exists on the blockchain. Otherwise, it means that the transaction may be invalid or tampered with.

[0048] like Figure 4 As shown, the operation steps of the lightweight identity authentication module specifically include step S31) a first verification step, step S32) a second verification step, step S33) a third verification step and step S34) a fourth verification step.

[0049] Step S31) The first verification step is to read the validity period field in the identity information, compare it with the current time, and determine whether the identity has expired. If it has not expired, the next step is executed, wherein the identity information includes a Merkle proof. In this embodiment, the Merkle proof means that if you want to prove that a piece of data is in a Merkle tree, you only need to hash the value to be proved with the hash value of its brother node until the Merkle root is calculated, and then compare. If the values ​​of the two Merkle roots are the same, the proof can be successfully proved. The hash value data required for the proof is the Merkle proof, including the value to be proved and the hash value required on the proof path.

[0050] Step S32) The second verification step, in combination with the Merkle proof, uses the blockchain head node to verify whether the identity information has been tampered with: the identity information is hashed, and a new Merkle root is constructed along the Merkle proof, and the new Merkle root is compared with the original Merkle root of the corresponding block. If the new Merkle root is the same as the original Merkle root, the verification is passed and the next step is executed.

[0051] In this embodiment, the Merkle tree is a binary tree structure, which is used to check the integrity of transactions in the blockchain. It divides a large amount of data into multiple small data blocks, and performs a hash operation on each block to generate a respective hash value. Subsequently, two adjacent hash values ​​are connected to form a new hash value until a unique hash value is finally obtained, that is, the hash value of the root node.

[0052] Step S33) The third verification step is to determine whether the identity information is in the Bloom filter. If so, determine whether the cryptographic accumulator can provide a valid proof of the identity information. If it can provide a valid proof, the identity information is determined to be in an unrevokated state and the next step is executed. Otherwise, the identity information is determined to be in a revoked state. If not, the identity information is determined to be valid identity information and the next step is executed.

[0053] Specifically, based on the latest BF value, calculate and determine whether the other party is in the BF. If so, continue to request Acc proof from the other party. Based on the latest Acc value, the other party provides the element unique identifier and element member proof to verify whether the identity is legal. The identity that can provide valid proof is in an unrevokated state, otherwise it is deemed to have been revoked. BF represents Bloom filter, and Acc represents cryptographic accumulator.

[0054] Step S34) The fourth verification step is to use the identity information to confirm whether the identity information contains the private key corresponding to the public key it claims through the "challenge-response" mechanism. If the verification fails, communication with the device is terminated.

[0055] like Figure 1As shown, the identity revocation module includes an identity revocation judgment unit and an identity revocation information management unit. The identity revocation execution unit globally declares the revoked identity through an identity revocation transaction. The identity revocation information management unit is used to maintain the contents of the Bloom filter and the cryptographic accumulator.

[0056] Furthermore, in the identity revocation module, the identity revocation execution unit generates and broadcasts a new identity revocation transaction, in which the information of the revoked identity is stored, and the information of the revoked identity is indicated in the revocation transaction field in the block header; the identity management agency adds the revoked identity identifier to the Bloom filter, checks whether the revoked identity has been mistakenly added to the Bloom filter and assigned a cryptographic accumulator certificate, and determines whether the revoked identity is in the cryptographic accumulator. If so, the information of the revoked identity is deleted from the Bloom filter and the cryptographic accumulator; when the revoked identity request is added to the cryptographic accumulator, the identity management agency checks the revocation information set to determine whether the revoked identity is in the revocation information set. If not, the revoked identity is added to the cryptographic accumulator. Otherwise, it is determined that the request is a malicious request and the revoked identity cannot be added to the cryptographic accumulator.

[0057] Specifically, the identity management agency adds the identity ID to the BF, performs an OR operation on the corresponding BF bit after hashing and 1, checks whether the identity has been mistakenly added to the BF and assigned an Acc certificate. If so, the identity is deleted from the Acc, and the updated BF and Acc values ​​are stored on the chain as transactions. At the same time, the block header update field revo_flag of the corresponding block is set to facilitate the synchronization of the latest value of the IoT device. The above update of BF will cause some valid identities to be mistakenly added to the BF. They will initiate an Acc joining request. The identity management agency checks their validity. If they have not been revoked, they can be added to the Acc. Otherwise, it means that the request is a malicious request and cannot be added to the Acc. The identity update module is used to accept the identity update request of the IoT device. The IoT device presents the Merkel certificate and identity information to the identity management agency, and the identity management agency accepts the request after verifying the legitimacy. In special cases, the identity management agency can directly update the request.

[0058] like Figure 5 As shown, the operation steps of the identity update module specifically include step S41) content modification step and step S42) validity period extension step.

[0059] Step S41) Content modification step: the identity management agency revokes the old identity information, writes the new identity information into the blockchain, confirms by consensus that the old identity information is consistent with the new identity information, and returns the Merkle proof of the new identity information to the IoT device.

[0060] Step S42) Validity extension step: the identity management agency does not revoke the old identity information, but continues to use the content in the old identity information, and modifies the start time of the validity period of the new identity information to the expiration time of the old identity information, writes the new identity information into the blockchain, and returns the Merkle proof of the new identity information to the IoT device after consensus confirmation, wherein the IoT device still uses the Merkle proof of the old identity information before the old identity information expires, and uses the Merkle proof of the new identity information after the old identity information expires.

[0061] like Figure 1 As shown, the light node information maintenance module includes a block header synchronization unit and a revocation auxiliary identity information update unit. The block header synchronization unit joins the blockchain network, listens to the new block broadcast information to synchronize the block header, and the revocation auxiliary identity information update unit is used to update the Bloom filter and the cryptography-based accumulator stored in the Internet of Things device when an identity is revoked.

[0062] like Figure 6 As shown, the operation steps of the block header synchronization unit specifically include step S51) a block header linking step, step S52) a hash value determination step, and step S53) a block header information storage step.

[0063] Step S51) Block header linking step, pulling the information of the block header that does not exist in the IoT device in the blockchain node, and linking the new block header to the existing block header.

[0064] Step S52) Hash value judgment step, pull the information of all current block headers from the blockchain node, and verify in turn whether the hash value of the previous block header of each block is the same as the hash value of the previous block header. If it is determined that all block headers have not been tampered with, the content of the new block header is trusted and stored in the IoT device; if it is determined that there is a tampered block header, the light node selects other full nodes to communicate and obtain the block header information.

[0065] In this embodiment, a full node refers to a node that stores a complete copy of the blockchain, including the entire blockchain from the genesis block to the latest block, and can independently verify transactions and save received legal blocks locally; a light node refers to a light node that only synchronizes block header information from a full node, rather than the entire blockchain, and does not require consensus, and verifies the existence of transactions through a simple payment verification method.

[0066] Step S53) A block header information storage step. When the block header information cannot be successfully updated and synchronized, the light node directly selects and synchronizes qualified block header information for storage, wherein the qualified block header indicates that the number of nodes storing the qualified block header is not less than a first threshold.

[0067] like Figure 7 As shown, the operation steps of the revoking auxiliary identity information update unit specifically include step S61) a transaction writing step and step S62) an update verification step.

[0068] Step S61) Transaction writing step, the identity management agency writes the updated content of the Bloom filter and the cryptographic accumulator into the block body of the latest block as a transaction.

[0069] Step S62) Update verification step, the IoT device checks whether there is updated content in the revocation transaction field of the block body of the latest block, and if so, requests the updated content from the identity management agency, receives the transaction information stored in the Bloom filter and the cryptographic accumulator and the Merkle proof of the updated content, verifies the authenticity of the Merkle proof of the updated content, and after confirming the authenticity of the updated content, the IoT device updates the content of the Bloom filter accumulator.

[0070] In this embodiment, the revocation auxiliary judgment information update unit updates the values ​​of the Bloom filter and the cryptographic accumulator locally on the IoT device after an identity is revoked. Once an identity is revoked, the values ​​of BF and Acc will be updated accordingly. At this time, the IoT device needs to be updated locally as well. Since the query of revocation information is only related to the latest BF and Acc values, the IoT device does not need to save all their historical records, but only needs to request the block transaction where the latest value is located from the identity management agency and save it.

[0071] When BF and Acc need to be updated, the identity management agency writes the updated content into the block body of the latest block as a transaction, and uses the update field revo_flag in the block header to indicate whether its value has been updated. The IoT client checks this field when synchronizing the block header. If it finds updated content, it requests this part of the content from the identity management agency, and then receives the transaction information and Merkel proof of BF and Acc. By verifying their Merkel proofs, IoT devices can confirm whether the latest information sent is true or false, and then confirm whether to accept them or not make any changes.

[0072] Since the latest Acc values ​​of the two parties may be inconsistent due to network and other reasons, the IoT client can decide whether to accept the proof corresponding to the latest Acc that is not its own based on the strictness of its security requirements: for example, if the Acc currently in its possession has been updated n + k times, and the other party provides the proof corresponding to the nth update of Acc, the IoT client decides the size of k that it can accept and saves the corresponding number of historical Acc for verification.

[0073] The present application provides a lightweight IoT device identity management system based on blockchain, which is composed of blockchain, IoT devices, and identity management agencies, including a system initialization module, an identity registration module, a lightweight identity authentication module, an identity update module, an identity revocation module, and a light node information maintenance module. The system initialization module is used to initialize the IoT devices and the identity management agency to initialize the necessary parameters for the operation of the system. The identity registration module is used to register the unique identity identification of the IoT device and other information on the blockchain. The lightweight identity authentication module is used for two-way authentication between IoT devices. The identity update module is used to write the update information of the IoT device to the new block transaction. The identity revocation module is used to judge the validity of the identity and maintain the data structure required for such judgment. The light node information maintenance module is used to synchronize the block header and update the identity revocation information, which solves the problem of inaccurate two-way identity authentication of IoT devices in poor network conditions, reduces the cost of identity authentication of IoT devices, and improves the judgment performance of the IoT on the identity status.

[0074] The above is a detailed introduction to the lightweight IoT device identity management system based on blockchain provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, according to the idea of ​​the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A lightweight IoT device identity management system based on blockchain, characterized in that: include: A system initialization module, which initializes the identity management agency and the IoT device, publishes the necessary information of the identity management system, and synchronizes the identity authentication information of the blockchain through the IoT device; An identity registration module, which accepts an identity registration request of the IoT device; A lightweight identity authentication module to authenticate the identity of the IoT device; An identity revocation module, comprising an identity revocation judgment unit and an identity revocation information management unit, wherein the identity revocation execution unit globally declares the revoked identity through an identity revocation transaction, and the identity revocation information management unit is used to maintain the contents of the Bloom filter and the cryptographic accumulator; An identity update module, which accepts the IoT device identity update request; as well as The light node information maintenance module includes a block header synchronization unit and a revocation auxiliary identity information update unit. The block header synchronization unit joins the blockchain network and listens to the new block broadcast information to synchronize the block header. The revocation auxiliary identity information update unit is used to update the Bloom filter and the cryptography-based accumulator stored in the Internet of Things device when an identity is revoked.

2. The lightweight IoT device identity management system based on blockchain as claimed in claim 1, characterized in that: The operation steps of the system initialization module specifically include the following steps: An information disclosure step, disclosing the public keys of the members of the identity management agency, disclosing the multi-signature threshold, disclosing the hash algorithm of the Bloom filter in the blockchain, and disclosing the public key and initial value of the cryptographic accumulator used in the blockchain; Block formation step: when a node initializes itself as the first node of the blockchain network, it generates a genesis block as the first block of blockchain data; when there are already nodes in the blockchain network, the newly added blockchain node communicates with any node in the blockchain network, and the newly added blockchain node can obtain the content of the blockchain and join the blockchain network; A recording step, recording a hash algorithm of a Bloom filter in the public blockchain and a public key and an initial value of a cryptographic accumulator used in the public blockchain; as well as The hash value verification step pulls the information of all current block headers from the blockchain node, and verifies in turn whether the hash field of the previous block header of each block is the same as the hash value of the previous block header. If they are the same, the content of the block header is trusted and stored in the local device.

3. The blockchain-based lightweight IoT device identity management system according to claim 1, characterized in that: The operation steps of the identity registration module specifically include the following steps: The identity information determination step is to query and compare the identity information requested for registration with the registered identity information to determine whether the identity information requested for registration has been registered, and whether the identity information requested for registration provides a true and valid unique identifier. If the identity information requested for registration is legal, proceed to the next step; A numbering step of assigning a globally unique number to the identity information of the registration request, treating the identity information of the registration request as an identity registration transaction, and attaching a signature of the identity information; The identity registration transaction verification step is to broadcast the identity registration transaction to the identity management agency for verification of legitimacy. When the identity registration transaction meets the multi-signature threshold, the identity registration transaction is written into the block body to participate in the consensus. After confirmation by the identity management agency, it becomes immutable data on the blockchain network. as well as The identity information storage step stores the identity information content in a local device.

4. The blockchain-based lightweight IoT device identity management system according to claim 1, characterized in that: The operation steps of the lightweight identity authentication module specifically include the following steps: The first verification step is to read the validity period field in the identity information and compare it with the current time to determine whether the identity has expired. If not, proceed to the next step, wherein the identity information includes a Merkle proof; The second verification step is to use the blockchain head node to verify whether the identity information has been tampered with in combination with the Merkle proof: the identity information is hashed, and a new Merkle root is constructed along the Merkle proof, and the new Merkle root is compared with the original Merkle root of the corresponding block. If the new Merkle root is the same as the original Merkle root, the verification is passed and the next step is executed; The third verification step is to determine whether the identity information is in the Bloom filter. If so, determine whether the cryptographic accumulator can provide a proof that the identity information is valid. If it can provide a valid proof, determine that the identity information is in an unrevoked state and execute the next step. Otherwise, determine that the identity information is in a revoked state. If not, determine that the identity information is valid and execute the next step. And In the fourth verification step, the identity information is confirmed through a "challenge-response" mechanism to see whether the identity information contains the private key corresponding to the public key it claims. If the verification fails, communication with the device is terminated.

5. The blockchain-based lightweight IoT device identity management system according to claim 1, characterized in that: In the identity revocation module, The identity revocation execution unit generates and broadcasts a new identity revocation transaction, in which the identity revocation information is stored, and the identity revocation information is indicated in the revocation transaction field in the block header; The identity management agency adds the revoked identity identifier to the Bloom filter, checks whether the revoked identity has been mistakenly added to the Bloom filter and assigned a cryptographic accumulator certificate, determines whether the revoked identity is in the cryptographic accumulator, and if so, deletes the revoked identity information from the Bloom filter and the cryptographic accumulator; When the revocation request is added to the cryptographic accumulator, the identity management agency checks the revocation information set to determine whether the revoked identity is in the revocation information set. If not, the revoked identity is added to the cryptographic accumulator. Otherwise, the request is determined to be a malicious request and the revoked identity cannot be added to the cryptographic accumulator.

6. The blockchain-based lightweight IoT device identity management system according to claim 1, characterized in that: The operation steps of the identity update module specifically include the following steps: In the content modification step, the identity management agency revokes the old identity information, writes the new identity information into the blockchain, confirms by consensus that the old identity information is consistent with the new identity information, and returns the Merkle proof of the new identity information to the IoT device; as well as In the validity extension step, the identity management agency does not revoke the old identity information, but continues to use the content in the old identity information, and modifies the start time of the validity period of the new identity information to the expiration time of the old identity information, writes the new identity information into the blockchain, and returns the Merkle proof of the new identity information to the IoT device after consensus confirmation, wherein the IoT device still uses the Merkle proof of the old identity information before the old identity information expires, and uses the Merkle proof of the new identity information after the old identity information expires.

7. The blockchain-based lightweight IoT device identity management system according to claim 1, characterized in that: The operation steps of the block header synchronization unit specifically include the following steps: A block header linking step, in which the information of the block header that does not exist in the IoT device is pulled out in the blockchain node, and the new block header is linked to the existing block header; A hash value judgment step, pulling information of all current block headers from the blockchain node, and verifying in turn whether the hash value of the previous block header of each block is the same as the hash value of the previous block header. If it is determined that all block headers have not been tampered with, the content of the new block header is trusted and stored in the IoT device; If it is determined that there is a tampered block header, the light node selects other full nodes to communicate with and obtain the block header information; as well as In the step of storing the block header information, if the block header information cannot be successfully updated and synchronized, the light node directly selects and synchronizes qualified block header information for storage, wherein the qualified block header indicates that the number of nodes storing the qualified block header is not less than a first threshold.

8. The blockchain-based lightweight IoT device identity management system according to claim 1, characterized in that: The operation steps of the revoking auxiliary identity information updating unit specifically include the following steps: A transaction writing step, wherein the identity management agency writes the updated contents of the Bloom filter and the cryptographic accumulator into the block body of the latest block as a transaction; and In the update verification step, the IoT device checks whether there is updated content in the revocation transaction field of the block body of the latest block. If so, it requests the updated content from the identity management agency, receives the transaction information stored in the Bloom filter and the cryptographic accumulator and the Merkle proof of the updated content, verifies the authenticity of the Merkle proof of the updated content, and after confirming the authenticity of the updated content, the IoT device updates the content of the Bloom filter accumulator.

Citation Information

Cited By

  • Block chain identity certificate revocation method in 6G heterogeneous network scene

    CN120676355A