Block chain enabled zero-trust forest and grass Internet of Things security protection method
Through blockchain technology and smart contracts, the zero-trust architecture is realized in the forest and grass IoT system, and the identity authentication and access control is used to use multi-dimensional dynamic feature fingerprints, which solves the security protection problems of forest and grass IoT system and realizes decentralization, transparency and high security protection.
Patent Information
- Application Number
- CN202510165610.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-14
AI Technical Summary
Because the terminals are located in an open natural environment, forest and grass IoT systems have problems such as difficulty in terminal protection, system maintenance, and security protection. The traditional security model has defects such as high maintenance costs and centralized risks, making it difficult to effectively resist internal attacks and long-term hidden attacks.
The blockchain-enabled zero-trust forest and grass IoT security protection method is adopted, and identity authentication, access control, data integrity detection and independent audit is realized through the forest and grass cloud platform, and smart contracts and multi-dimensional dynamic feature fingerprints are used for continuous verification and dynamic access control, ensuring the system's decentralization, transparency, tamper-free and traceable.
It realizes low-cost and decentralized security protection, can effectively resist internal attacks and long-term hidden attacks, reduces maintenance costs, and improves the transparency and security of the system.
Smart Images

Figure CN120017364A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things security technology, and specifically to a blockchain-enabled zero-trust forest and grassland Internet of Things security protection method. Background Art
[0002] Compared with the power Internet of Things, the Internet of Vehicles, and the Industrial Internet of Things, the forestry and grassland Internet of Things has the industry characteristics of "difficult terminal protection, difficult system maintenance, and difficult security protection" because the terminals are deployed in an open natural environment. It has a high probability of being attacked and hacked from the outside. At present, traditional security modes such as password-based static identity authentication, centralized authorization, and access control lists have defects such as high maintenance costs and high centralized risks in the forestry and grassland Internet of Things. In addition, since the detection process cannot be effectively monitored, the detection process is not transparent and the results cannot be traced. If internal security threats such as internal personnel being subverted and account theft are added, it will be difficult to detect long-term covert attacks after being hacked. Long-term false data injection or equipment damage will cause decision-making errors or inability to make decisions, causing huge economic and social losses.
[0003] To sum up, there is an urgent need to provide a low-cost, decentralized, transparent, tamper-proof, traceable, zero-trust forestry and grassland IoT security protection method that can effectively resist internal attacks and realize the concept of "continuous verification, never trust". Summary of the invention
[0004] The purpose of this invention is to provide a low-cost, decentralized, transparent, tamper-proof, traceable, and zero-trust forest and grassland Internet of Things security protection method that can effectively resist internal attacks and realize the concept of "continuous verification, never trust".
[0005] The above purpose is achieved through the following technical solution: a blockchain-enabled zero-trust forest and grassland IoT security protection method, which is implemented through a forest and grassland cloud platform, and the forest and grassland cloud platform includes:
[0006] Forestry and grassland IoT application system: used to receive reports and return data and requests from forestry and grassland communication relays, convert them into access sessions, store them in the blockchain, and submit them to the forestry and grassland security situation awareness system. According to the results returned by the forestry and grassland security situation awareness system, the forestry and grassland communication relays can access internal resources securely.
[0007] Forestry and grassland security situation awareness system: used to receive forestry and grassland IoT application system sessions and combine internal resources through smart contracts to decide whether to authorize the submitted request sessions, and judge the current security situation based on the current status of the forestry and grassland IoT system, and whether to conduct an independent audit;
[0008] Cloud platform: Cloud platform resources and application platform used to support the forest and grassland Internet of Things application system and forest and grassland security situation awareness system, providing system operating conditions and basic software and hardware environment;
[0009] The blockchain-enabled zero-trust forest and grassland IoT system security protection method includes the following steps:
[0010] S1, blockchain creation, smart contract definition and system initialization: complete the definition and chain code installation of identity authentication smart contract, access control smart contract, integrity detection smart contract, independent audit smart contract, security situation awareness smart contract, and initialize the equipment registration information of the Lincao Cloud Platform, and generate spatial data fingerprint and key system;
[0011] S2, periodic operation of the forest and grassland IoT system: The forest and grassland IoT system wakes up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then sleeps and waits for the next data collection cycle;
[0012] S3, the forest and grassland security situation awareness system performs identity authentication: the forest and grassland security situation awareness system calls the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay, and performs static identity authentication and continuous dynamic identity authentication on the forest and grassland communication relay; the forest and grassland communication relay generates the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal according to the periodic operation configuration strategy, and completes the static identity authentication and continuous dynamic identity authentication for the forest and grassland perception terminal. If the authentication is passed, execute step S4, if not, execute step S10;
[0013] S4, the forest and grassland security situation awareness system performs dynamic access control: the forest and grassland communication relay uses the key policy attribute-based encryption method to encrypt the forest and grassland communication relay data to form a ciphertext and initiate a data transmission attribute access request to the forest and grassland cloud platform. The forest and grassland security situation awareness system calls the dynamic access control smart contract to calculate the multi-dimensional subject attributes of the forest and grassland communication relay, decrypts and verifies whether the attributes of the forest and grassland communication relay have passed the verification, completes the dynamic access control and returns the access result. If it passes the verification, execute step S5, if it fails the verification, execute step S10;
[0014] S5, the forest and grassland safety situation awareness system performs integrity detection: the forest and grassland safety situation awareness system compares the spatial data fingerprint submitted by the forest and grassland perception terminal obtained by decryption with the spatial data fingerprint initialized and stored in the blockchain, and completes the forest and grassland IoT data integrity detection and returns the detection result. If the detection passes, step S6 is executed, if not, step S10 is executed;
[0015] S6, the forestry cloud platform submits data and returns access results: the forestry communication relay sends the collected monitoring data to the forestry cloud platform, and the forestry IoT application system connects to the internal resource database to complete the data storage, returns the periodic operation configuration and periodic operation strategy, and waits for the next data collection cycle;
[0016] S7, determine whether the monitoring is finished, if not, execute step S8, if yes, terminate the process;
[0017] S8, determine whether to trigger an independent audit: the forest and grassland safety situation awareness system determines whether the independent audit start condition is triggered by executing the independent audit smart contract. If so, execute step S9; if not, execute step S2;
[0018] S9, the forest and grassland safety situation awareness system performs independent auditing: the forest and grassland safety situation awareness system generates an independent audit notification and encrypts and broadcasts it. The audited device receives the audit notification, conducts the audit and returns the audit data. The forest and grassland safety situation awareness system verifies the returned audit data and stores the audit session and audit results on the chain. If the audit passes, step S2 is executed. If the audit fails, step S10 is executed.
[0019] S10, the forest and grassland security situation awareness system performs security situation awareness: the forest and grassland security situation awareness system stores the information record of the failed access session into the blockchain network, reads the historical access session records in the blockchain network, evaluates the number of accesses and access status of the current client and forest and grassland communication relay, determines whether it has been attacked and takes corresponding measures to prevent the attack; then executes step S7.
[0020] In view of the problems of high centralization, opaque detection process, untraceable results and difficulty in effectively resisting internal attacks in identity authentication, access control and data integrity detection of forest and grassland Internet of Things systems under internal attack threats and complex open environments, a blockchain-enabled zero-trust forest and grassland Internet of Things system security protection method is proposed. Continuous identity authentication is achieved by combining static physical fingerprints with multi-dimensional dynamic feature fingerprints, dynamic sustainable access control is achieved by combining attribute-based access control with multi-dimensional dynamic attributes, forest and grassland data integrity detection is achieved by spatial data feature extraction combined with spatial data fingerprint on-chain comparison, internal attack detection is achieved by combining attribute encryption with independent audit mode, and blockchain technology is used to store smart contracts, session processes and execution results of access, control, verification, detection and audit between forest and grassland perception terminals, policy execution points and policy decision points into the blockchain, so as to realize continuous verification, dynamic fine-grained access control, decentralization, transparency, non-tamperability, traceability and effective resistance to internal attacks of the forest and grassland Internet of Things system, and provide an effective way to solve the problem of security defense of forest and grassland Internet of Things systems.
[0021] A further technical solution is that step S1 includes the following steps:
[0022] S1.1, blockchain network creation and initialization;
[0023] S1.2, identity authentication smart contract definition and chain code installation, where the identity authentication smart contract includes the forestry perception terminal, forestry communication relay and forestry cloud platform to perform identity authentication access session chain operation strategy and identity authentication operation strategy in the blockchain network, and the chain code is installed through the forestry cloud platform server;
[0024] S1.3, access control smart contract definition and chain code installation, where the access control smart contract includes the access control access session chain operation strategy and dynamic access control operation strategy in the blockchain network by the Lincao communication relay and the Lincao cloud platform, and the chain code is installed through the Lincao cloud platform server;
[0025] S1.4, independent audit smart contract and chain code installation, where the independent audit smart contract includes the independent audit session chain operation strategy and independent audit operation strategy carried out by the Lincao Cloud Platform in the blockchain network, and the chain code is installed through the Lincao Cloud Platform server;
[0026] S1.5, data integrity detection smart contract and chain code installation, where the data integrity detection smart contract includes the data integrity detection access session chain operation strategy and integrity detection operation strategy in the blockchain network by the Lincao communication relay and the Lincao cloud platform, and the chain code is installed through the Lincao cloud platform server;
[0027] S1.6, security situation awareness smart contract definition and chain code installation, where the security situation awareness smart contract includes the data exchange operation strategy for the forest and grassland perception terminal, forest and grassland communication relay and forest and grassland cloud platform to access internal data through identity authentication, access control and integrity detection, as well as the security situation awareness operation strategy initiated in the blockchain network when it fails;
[0028] S1.7, initialization of the forest and grassland Internet of Things system, including initialization of forest and grassland Internet of Things device information registration, initialization of generation of spatial data fingerprint, initialization of key policy attribute-based encryption scheme and key generation.
[0029] A further technical solution is that the identity authentication access session chain operation strategy at least includes a login session chain strategy, an identity authentication session chain strategy, an identity authentication failure session chain strategy and a data transmission session chain strategy;
[0030] The identity authentication operation strategy includes at least a static physical fingerprint generation strategy, a static identity authentication strategy, a multi-dimensional dynamic feature fingerprint generation strategy and a continuous dynamic identity authentication strategy;
[0031] The access control access session operation policy at least includes a data transmission session chaining policy, an operation policy download access session chaining policy and an access control failure session chaining policy;
[0032] The dynamic access control strategy at least includes a forest and grassland communication relay subject attribute generation strategy, a forest and grassland communication relay subject multi-dimensional dynamic attribute calculation strategy, a forest and grassland communication relay data transmission attribute access request generation strategy, a forest and grassland cloud platform key policy attribute base encryption initialization strategy, a forest and grassland cloud platform access control tree structure key generation strategy, a forest and grassland communication relay key policy attribute base data encryption strategy, a forest and grassland cloud platform key policy attribute base data decryption strategy and a forest and grassland communication relay collected data transmission storage access control verification strategy;
[0033] The independent audit session chain operation strategy at least includes an independent audit notification session chain strategy, a forestry communication relay audit reply session chain strategy, an independent audit successful completion session chain strategy, and an independent audit failure end session chain strategy;
[0034] The independent audit operation strategy at least includes an independent audit start decision strategy, an independent audit notification attribute generation strategy, an independent audit notification attribute encryption strategy, an independent audit notification attribute broadcast strategy and an independent audit detection strategy;
[0035] The data integrity detection session chain operation strategy includes a fingerprint cloud database generation session chain strategy, a fingerprint cloud database chain session chain strategy, a client data integrity detection request session chain strategy, a data integrity detection failure session chain strategy and a data integrity detection execution result session chain strategy;
[0036] The integrity detection operation strategy at least includes a spatial data feature extraction strategy, a spatial data fingerprint generation strategy, a fingerprint cloud database generation strategy, a fingerprint cloud database chain strategy, a spatial data fingerprint comparison and detection strategy, a data integrity detection result generation strategy, and a data integrity detection result chain strategy;
[0037] The data exchange operation strategy at least includes the device registration information storage strategy, the forest and grassland communication relay periodic operation configuration download strategy, the forest and grassland communication relay collected data transmission storage strategy, the independent audit results storage strategy and the data integrity test result return strategy;
[0038] The security situation awareness operation strategy at least includes a security situation awareness strategy, a security threat emergency disposal strategy, a DOS attack monitoring strategy and an injection attack detection strategy.
[0039] A further technical solution is that the specific steps of step S1.7 are as follows:
[0040] S1.7.1, Initialize the registration of forest and grassland IoT device information: Use the static physical fingerprint generation strategy to form the static physical fingerprint of the device based on the registration information and static password, and then use the device registration information storage strategy to upload the device registration and device registration information into a new block to the blockchain network to complete the registration of forest and grassland IoT devices;
[0041] S1.7.2, Initialize and generate spatial data fingerprint: The server of the forest and grass cloud platform calls the spatial data feature strategy to extract the spatial features and attribute features of the spatial vector data in the internal resource database of the server, executes the spatial data fingerprint generation strategy to obtain the spatial data fingerprint, and after calculation through the blockchain network consensus algorithm, forms a new block storage and enters the blockchain network, so as to realize the immutability and traceability of the fingerprint cloud database chain session;
[0042] S1.7.3, Key policy attribute-based encryption scheme initialization and key generation: The Lincao Cloud Platform client calls the Lincao Cloud Platform key policy attribute-based encryption initialization strategy, generates the system public key and system master key based on the attribute-based encryption mechanism of the key policy, calls the Lincao Cloud Platform access control tree structure key generation strategy, and calculates the decryption key of the Lincao Cloud Platform client user based on the system master key and the user attribute set.
[0043] A further technical solution is that step S2 includes the following steps:
[0044] S2.1, the first deployment of forest and grassland communication relay initiates identity authentication session;
[0045] S2.2, mobile data collection terminal connection and configuration of forest and grassland communication relay;
[0046] S2.3, the forest and grassland Internet of Things system operates periodically.
[0047] A further technical solution is that step S3 includes the following steps:
[0048] S3.1, create a static physical fingerprint of the forest and grass communication relay and perform static identity authentication: the forest and grass cloud platform client calls the static physical fingerprint generation strategy, generates the static physical fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the forest and grass cloud platform client, and then obtains the static physical fingerprint of the forest and grass communication relay last accessed in the blockchain platform, and calls the static identity authentication strategy to perform static identity authentication;
[0049] S3.2, create a multi-dimensional dynamic feature fingerprint of the forest and grass communication relay and perform dynamic identity authentication: the forest and grass cloud platform client calls the multi-dimensional dynamic feature fingerprint generation strategy, generates the multi-dimensional dynamic feature fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the forest and grass cloud platform client, and then obtains the multi-dimensional dynamic feature fingerprint of the forest and grass communication relay last accessed in the blockchain platform, calls the continuous dynamic identity authentication strategy to compare the two pieces of information and returns the identity authentication result;
[0050] S3.3, Lincao communication relay identity authentication result session upload to blockchain network: Lincao cloud platform client calls the identity authentication session chain strategy, records the session information into the blockchain network, and calls the device registration information storage strategy to add and update the device access registration information of the current Lincao communication relay into the database;
[0051] S3.4, the forest-grass communication relay receives and stores the identity authentication access session information of the forest-grass perception terminal: the forest-grass communication relay receives the identity access request of the forest-grass perception terminal, obtains the identity authentication session parameters of the forest-grass perception terminal, and stores them locally in the forest-grass communication relay;
[0052] S3.5, the forest and grassland communication relay creates a static physical fingerprint of the forest and grassland perception terminal and performs static identity authentication: the forest and grassland communication relay generates a static physical fingerprint for accessing the forest and grassland perception terminal based on the static physical fingerprint generation strategy stored locally, calls the static identity authentication strategy, and compares it with the static physical fingerprint of the forest and grassland perception terminal stored locally;
[0053] S3.6, the forestry and grassland communication relay creates a multi-dimensional dynamic feature fingerprint of the forestry and grassland perception terminal and performs dynamic identity authentication: the forestry and grassland communication relay calculates and generates a multi-dimensional dynamic feature fingerprint based on the multi-dimensional dynamic feature fingerprint generation strategy stored locally, for the identity authentication session parameters of the forestry and grassland perception terminal obtained, as well as the identity authentication session parameters of the last forestry and grassland perception terminal obtained from the blockchain network when the forestry and grassland communication relay is initialized and stored locally, and uses the continuous dynamic identity authentication strategy stored locally to compare and authenticate the two multi-dimensional dynamic feature fingerprints of the forestry and grassland perception terminal.
[0054] A further technical solution is that step S4 includes the following steps:
[0055] S4.1, encryption of forest and grassland communication relay data collected by key policy attribute-based encryption mechanism: the forest and grassland communication relay uses the forest and grassland communication relay subject attributes and the forest and grassland cloud platform system public key, calls the forest and grassland communication relay key policy attribute-based data encryption strategy, and encrypts the forest and grassland perception terminal data collected in the forest and grassland communication relay to form ciphertext;
[0056] S4.2, the forest and grassland communication relay initiates a data transmission attribute access request to the forest and grassland cloud platform: the forest and grassland communication relay uses the forest and grassland communication relay data transmission attribute access request generation strategy downloaded to the local forest and grassland communication relay periodic operation configuration, combines the forest and grassland communication relay subject attributes to generate a forest and grassland communication relay data transmission attribute access request, and sends a forest and grassland communication relay data transmission attribute access request session to the forest and grassland cloud platform;
[0057] S4.3, Lincao Cloud Platform uploads the data transmission session of Lincao Communication Relay to the blockchain network: Lincao Cloud Platform calls the data transmission session chain strategy, initiates a transaction for the data transmission session access request session sent by Lincao Communication Relay, and forms a new block storage into the blockchain network after calculation through the blockchain network consensus algorithm, so as to realize the tamper-proof and traceable access behavior;
[0058] S4.4, the forestry cloud platform calculates the multi-dimensional dynamic attributes of the forestry communication relay: the forestry cloud platform calls the multi-dimensional dynamic attribute calculation strategy of the forestry communication relay subject, obtains the forestry communication relay subject attributes stored in the last access session in the blockchain network, uses the physical model to simulate and calculate the multi-dimensional dynamic attributes, and simulates and calculates the forestry communication relay subject attribute values of this access session;
[0059] S4.5, the forestry cloud platform performs access control verification on the forestry communication relay data transmission: the forestry cloud platform calls the forestry communication relay collection data transmission storage access control verification strategy, and verifies the forestry communication relay subject attributes of the current session in combination with the simulated calculated forestry communication relay subject attribute values;
[0060] S4.6, Lincao Cloud Platform Key Policy Attribute Base Data Decryption: Lincao Cloud Platform calls the Lincao Cloud Platform Key Policy Attribute Base Data Decryption Strategy, and uses the key related to the access structure assigned to the Lincao Cloud Platform client user when the Lincao Cloud Platform is initialized to perform decryption operations. The decryption is successful when the attributes in the ciphertext satisfy the access control tree.
[0061] A further technical solution is to use the sensing end of the forest and grass cloud platform to collect, process and interact with spatial data. Step S5 includes the following steps:
[0062] S5.1, forest and grassland perception terminal obtains spatial data fingerprint database generation strategy: the forest and grassland perception terminal accesses the forest and grassland cloud platform client or blockchain network to obtain spatial data feature extraction strategy, spatial data fingerprint generation strategy and fingerprint database generation strategy;
[0063] S5.2, spatial data feature extraction of forest and grassland perception terminal: For the spatial database used for data integrity detection, the forest and grassland perception terminal locally executes the spatial data feature extraction strategy to obtain the spatial features and attribute features of the spatial vector data in the perception terminal spatial database;
[0064] S5.3, spatial data fingerprint generation at the perception end: The perception end of the forest and grassland cloud platform obtains spatial data with spatial features and attribute features for data integrity detection, executes the spatial data fingerprint generation strategy, and obtains the spatial data fingerprint of the spatial database of the perception end of the forest and grassland cloud platform;
[0065] S5.4, generation of fingerprint cloud database of perception end: the perception end of the forest and grass cloud platform obtains the spatial data with spatial data fingerprint for data integrity detection, executes the fingerprint cloud database generation strategy, and obtains the fingerprint database of the perception end of the forest and grass cloud platform;
[0066] S5.5, the sensing end sends a data integrity detection request and a sensing end fingerprint database: the sensing end of the forest and grass cloud platform sends a data integrity detection request to the forest and grass cloud platform client, and submits the sensing end fingerprint database to complete the data integrity detection;
[0067] S5.6, the perception terminal data integrity detection request session is uploaded to the chain: the forest and grassland cloud platform client executes the fingerprint cloud database to generate the session on-chain strategy, and the forest and grassland cloud platform client initiates the client data integrity detection request session transaction, which is calculated through the blockchain network consensus algorithm to form a new block storage and enter the blockchain network, so as to realize the tamper-proof and traceability of the forest and grassland perception terminal data submission and data integrity detection behavior;
[0068] S5.7, server-side spatial data fingerprint comparison and detection: The server-side of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint comparison and detection strategy, takes the sensor terminal fingerprint database submitted for detection by the sensor terminal of the Forestry and Grassland Cloud Platform as input, obtains the fingerprint cloud database from the blockchain network, and compares the spatial data fingerprint of the sensor terminal fingerprint database with the spatial data fingerprint of the fingerprint cloud database through attribute query comparison, and marks the inconsistent spatial data fingerprints;
[0069] S5.8, the server side obtains the data integrity test result: the server side of the forest and grass cloud platform executes the spatial data fingerprint test result generation strategy, and stores the spatial data fingerprints marked as inconsistent separately to form a data integrity test result database;
[0070] S5.9, Data integrity test results are uploaded to the blockchain: The client of the Lincao Cloud Platform executes the data integrity test results upload strategy, initiates a transaction with all records in the data integrity test results database, and forms a new block after calculation through the blockchain network consensus algorithm to store it in the blockchain network, thus achieving the data integrity test results database data that cannot be tampered with and can be traced;
[0071] S5.10, data integrity check execution result session chaining: The Lincao Cloud Platform client executes the data integrity check execution result session chaining strategy, initiates a transaction on the server-side data integrity check execution result session, and after calculation through the blockchain network consensus algorithm, forms a new block storage and enters the blockchain network, thereby achieving the tamper-proof and traceability of data integrity detection behavior.
[0072] A further technical solution is that step S6 includes the following steps:
[0073] S6.1, the forest and grass communication relay downloads the periodic operation configuration of the forest and grass communication relay: the forest and grass communication relay uses the forest and grass communication relay periodic operation configuration download strategy to read and download the forest and grass Internet of Things periodic operation strategy configuration information in the forest and grass cloud platform database to the local forest and grass communication relay;
[0074] S6.2, the forestry and grassland communication relay stores the data collected by the forestry and grassland perception terminal and sends down the periodic operation configuration: the forestry and grassland communication relay receives the authentication parameters and collected data transmitted by the forestry and grassland perception terminal, stores them in the forestry and grassland communication relay, and sends down the periodic operation policy of the locally stored forestry and grassland perception terminal to the forestry and grassland perception terminal.
[0075] S6.3, the forest and grassland communication relay sends the collected data to the forest and grassland cloud platform: if the forest and grassland communication relay passes the identity authentication, access control, and data integrity detection, it agrees to submit the data submitted by the perception end into the internal resource database of the server. If not, it returns the data integrity detection result database to the perception end;
[0076] A further technical solution is that step S9 includes the following steps:
[0077] S9.1, Lincao Cloud Platform executes and generates audit notifications: The independent audit notification attribute generation strategy executed by Lincao Cloud Platform generates audit notifications;
[0078] S9.2, the Forestry and Grassland Cloud Platform puts the independent audit notification session on the chain: the audit notification is issued to the Forestry and Grassland Communication Relay and / or Forestry and Grassland Sensing Terminal, and the Forestry and Grassland Cloud Platform Client initiates the transaction of the audit notification issuance session, and calculates through the blockchain network consensus algorithm to form a new block storage into the blockchain network, so as to realize the tamper-proof and traceable audit notification behavior;
[0079] S9.3, Lincao Cloud Platform uses ciphertext attribute encryption to encrypt audit notifications: Lincao Cloud Platform implements independent audit notification attribute encryption strategy and uses ciphertext attribute encryption to encrypt audit notifications;
[0080] S9.4, the Lincao cloud platform broadcasts the audit notification to the Lincao communication relay: the Lincao cloud platform executes and sends the encrypted audit notification ciphertext to the Lincao communication relay in the next data collection cycle;
[0081] S9.5, the forestry communication relay decrypts the audit notice and conducts an independent audit according to the audit notice requirements: the forestry communication relay uses the forestry cloud platform system public key to obtain the current forestry communication relay attributes and private key, and decrypts the audit notice ciphertext. If the forestry communication relay attributes meet the access policy of the audit notice ciphertext, the ciphertext is decrypted and the audit notice content is obtained;
[0082] S9.6, the forest and grassland perception terminal decrypts the audit notification and conducts an independent audit according to the audit notification requirements: the forest and grassland communication relay uses the forest and grassland cloud platform system public key to obtain the attributes and private key of the current forest and grassland perception terminal, and decrypts the audit notification ciphertext. If the attributes of the forest and grassland perception terminal meet the access policy of the audit notification ciphertext, the ciphertext is decrypted and the audit notification content is obtained. The audit notification content is executed to form audit data and submitted to the forest and grassland communication relay;
[0083] S9.7, Forestry and grassland communication relay submits audit data according to the audit notice requirements: Forestry and grassland communication relay, according to the audit notice requirements, encrypts the data collected by the local forestry and grassland sensing terminals and the data stored locally and transmits it back to the forestry and grassland cloud platform for audit;
[0084] S9.8, Lincao Cloud Platform Lincao Communication Relay Audit Response Session on Chain: Lincao Cloud Platform Client Lincao Communication Relay Audit Response Session initiates a transaction, which is calculated through the blockchain network consensus algorithm to form a new block storage and enter the blockchain network, so as to achieve the immutability and traceability of the Lincao Communication Relay Audit Response behavior;
[0085] S9.9, Lincao Cloud Platform decrypts the audit return data and conducts comparative audit: The audit organization client of Lincao Cloud Platform uses a symmetric key to decrypt the return data to obtain the audit data, and then reads the historical data of the audited device from the blockchain network, and conducts comparative audit on the historical data and the audit data;
[0086] S9.10, Lincao Cloud Platform conducts independent audit and gives audit results: Lincao Cloud Platform implements independent audit and detection strategy to detect the integrity and authenticity of current and previous data. If the audit data returned by the audit device is inconsistent with the historical data in the blockchain network, then execute step S10;
[0087] S9.11, Lincao Cloud Platform independent audit successfully completes the session on-chain: The Lincao Cloud Platform client will initiate a transaction for the successful completion of the audit session, and after calculation through the blockchain network consensus algorithm, a new block will be formed and stored in the blockchain network, making the audit results and behaviors tamper-proof and traceable;
[0088] S9.12, Lincao Cloud Platform records and stores audit sessions and results: Lincao Cloud Platform calls the independent audit results storage strategy to store the audit data and audit results obtained by local audits into the database.
[0089] A further technical solution is that step S10 includes the following steps:
[0090] S10.1. Conduct security situation awareness and emergency disposal when identity authentication fails: When identity authentication fails, the client of the Lincao Cloud Platform calls the identity authentication failure session chain strategy to record the identity authentication access session failure information into the blockchain network; and calls the security situation awareness strategy to read the historical access session records in the blockchain network, evaluate the number of accesses of the current client and the Lincao communication relay to determine whether there is a DOS attack. If the access IP and / or access port exceeds the access upper limit threshold, call the security threat emergency disposal strategy to urgently close the current access IP and / or access port to prevent the DOS attack;
[0091] S10.2, conduct security situation awareness and emergency disposal when access control fails: When access control or decryption fails, the Lincao cloud platform calls the access control failure session chain strategy, initiates a transaction for the access control failure session sent by the Lincao communication relay, calculates through the blockchain network consensus algorithm, forms a new block storage into the blockchain network, and realizes the tamper-proof and traceability of access behavior; and calls the security situation awareness strategy, reads the historical access session records in the blockchain network, evaluates the number of accesses of the current client and Lincao communication relay to determine whether there is a DOS attack, and if the access IP and / or access port exceeds the access upper limit threshold, calls the security threat emergency disposal strategy of the security situation awareness smart contract to urgently close the current access IP and / or access port to prevent DOS attacks;
[0092] S10.3, conduct security situation awareness and emergency disposal when integrity detection fails: if data integrity detection fails, the client of the Lincao cloud platform calls the integrity detection failure session chain strategy, initiates a transaction with the integrity detection failure session sent by the Lincao communication relay, and calculates through the blockchain network consensus algorithm to form a new block storage into the blockchain network, so as to achieve the tamper-proof and traceable access behavior;
[0093] The server side of the Lincao Cloud Platform executes the DOS attack monitoring strategy. The Lincao Cloud Platform queries the Lincao perception terminals that failed the data integrity test in the blockchain network, obtains the number of failed accesses to the Lincao perception terminals for this request, and determines whether the number of failed accesses exceeds the specified threshold. If so, it is determined that there is a DOS attack threat, triggering the security threat emergency disposal strategy.
[0094] S10.4. If the independent audit fails, conduct security situation awareness and emergency disposal: If the independent audit result verification fails, the Lincao Cloud Platform client will end the audit failure session and initiate a transaction. Through the blockchain network consensus algorithm, a new block will be calculated and stored in the blockchain network to achieve the unalterability and traceability of the audit failure behavior. Based on the audit results, Lincao Cloud Platform will execute the security situation awareness smart contract disposal strategy and make rectifications to the audit results.
[0095] A further technical solution is that the forest and grassland safety situation awareness system includes:
[0096] Blockchain creation, smart contract definition and system initialization module: used to initialize the blockchain network, complete identity authentication, access control, independent audit, integrity detection smart contract definition and chain code installation, and complete the initialization of the forest and grassland Internet of Things system;
[0097] Forestry and Grassland Communication Relay Identity Authentication Module: It is used by the Forestry and Grassland Cloud Platform client to call the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the Forestry and Grassland Communication Relay, and perform static identity authentication and continuous dynamic identity authentication on the Forestry and Grassland Communication Relay;
[0098] Attribute-based data encryption access control request generation module: used to use the periodic operation configuration of the forest and grassland communication relay to generate the subject attributes of the forest and grassland communication relay, combine the public key of the forest and grassland cloud platform system, use the forest and grassland communication relay key policy attribute-based data encryption policy, encrypt the forest and grassland perception terminal data collected in the forest and grassland communication relay to form ciphertext, and initiate a data transmission attribute access request to the forest and grassland cloud platform;
[0099] Attribute-based data encryption access control request verification module: used to verify whether the attributes of the forest-grass communication relay have passed the verification in combination with the simulated calculated attributes of the forest-grass communication relay subject;
[0100] Server-side data integrity detection module: used by the forestry cloud platform to compare the spatial data fingerprint submitted by the forestry perception terminal obtained through decryption with the spatial data fingerprint generated and stored by initialization in the blockchain, verify that the forestry IoT has completed the data integrity detection and returned the detection result;
[0101] Triggering audit judgment module: used by the Lincao Cloud Platform to determine whether the independent audit start conditions are triggered by executing the independent audit smart contract;
[0102] Independent audit notification generation and encrypted broadcast module: used for the forestry cloud platform to generate independent audit notifications, encrypt the independent audit notifications using ciphertext attribute encryption, and broadcast the ciphertext of the independent audit notifications from the forestry cloud platform to the forestry communication relay in the next data collection cycle;
[0103] Audit device returns audit result verification module: used for the Lincao Cloud Platform to decrypt the returned audit data and compare it with the historical data stored in the blockchain network, and complete data integrity and system security detection by judging the consistency of the data;
[0104] Forestry and Grassland IoT Security Situation Awareness and Emergency Response Module: It is used by the forestry and grassland cloud platform to store the failed access session information records into the blockchain network, read the historical access session records in the blockchain network, evaluate the access times and access status of the current client and forestry and grassland communication relay, determine whether it is attacked, and take corresponding measures to prevent the attack.
[0105] A further technical solution is that the forest and grassland Internet of Things application system includes:
[0106] The periodic operation module of the forest and grassland IoT system is used for the forest and grassland IoT system to wake up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, complete data collection, aggregation and transmission, and sleep after completion to wait for the next data collection cycle;
[0107] Attribute-based encrypted data decryption module: used by the forestry cloud platform to decrypt the ciphertext transmitted by the forestry IoT using the key associated with the access structure, and transmit the successfully decrypted data through the forestry communication relay;
[0108] Forest and grassland perception terminal identity authentication module: used for forest and grassland communication relay to receive and store the identity authentication access session information of forest and grassland perception terminals according to the downloaded local periodic operation configuration policy, and then generate the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal in combination with the periodic security perception configuration policy, complete static identity authentication and continuous dynamic identity authentication, and store the data collected by the forest and grassland perception terminal locally;
[0109] The sensor-end spatial data fingerprint database generation module is used for the sensor-end of the forest and grass cloud platform to perform spatial data feature extraction and spatial data fingerprint generation, generate the sensor-end fingerprint database, and then send a data integrity detection request and the sensor-end fingerprint database to the forest and grass cloud platform server;
[0110] Forestry and grassland communication relay audit module: used for forestry and grassland communication relay to decrypt the ciphertext of independent audit notification. When the forestry and grassland communication relay attributes meet the independent audit notification access policy, the ciphertext is decrypted to obtain the content of the independent audit notification, and independent audit is carried out according to the requirements of the independent audit notification and the audit data is returned.
[0111] Extended audit module for forest and grassland perception terminals: used for forest and grassland perception terminals to receive and decrypt independent audit notifications issued by forest and grassland communication relays when independent audit notifications require extended audits. When the attributes of forest and grassland perception terminals meet the access policy of independent audit notifications, the ciphertext is decrypted to obtain the content of independent audit notifications, and independent audits are carried out and audit data is returned in accordance with the requirements of independent audit notifications.
[0112] The module for uploading access sessions to the forest and grassland cloud platform is used for the client of the forest and grassland cloud platform to upload the access request sessions and access request result sessions of the forest and grassland sensing terminal and the forest and grassland communication relay to the chain.
[0113] Data storage and download module: used by the forestry and grassland cloud platform client to submit the forestry and grassland communication relay to store the transmitted data into the internal resource database, and to send the server-side periodic operation configuration and data acquisition.
[0114] Compared with the prior art, the present invention has the following advantages:
[0115] Low management and maintenance costs: The identity authentication method in the present invention uses the static physical fingerprint of the forest and grassland Internet of Things device, and relies more on the multi-dimensional dynamic feature fingerprint of the physical properties of the device. These fingerprint information is based on the physical characteristics of the Internet of Things itself, does not require fixed memory and storage, and has low maintenance costs.
[0116] Effectively prevent internal attacks: The multi-dimensional dynamic feature fingerprint in the present invention performs continuous dynamic verification based on the characteristics of the IoT device itself. Internal managers obtain password information in a certain device or each system and cannot break into other devices or systems.
[0117] Can dynamically detect intrusion attacks: Since it is based on zero-trust architecture and multi-dimensional dynamic feature fingerprints for identity authentication, it implements the "never trust, continuous verification" approach, so the identity authentication method has been changing. If there is a forgery, impersonation, or replay attack, the system can promptly detect illegal access and register it in the blockchain network, so it can be discovered and traced in a timely manner.
[0118] Effectively prevent forgery and tampering attacks: For illegal access, the present invention records it in the blockchain network. Through the tamper-proof and traceable characteristics of the blockchain, all illegal access can be queried, effectively preventing attackers from hiding their illegal attack behaviors by tampering with or deleting access records.
[0119] Provide lightweight protection measures: The multi-dimensional dynamic feature fingerprint technology provided by the present invention is verified based on the physical characteristics of the forest and grassland Internet of Things devices. There is no need for password preservation, encrypted storage and transmission. The protection method is both "instantaneous" and fast and lightweight. It is very suitable for security protection in low-power and long-period monitoring scenarios such as forest and grassland Internet of Things where power supply and transmission are difficult.
[0120] Decentralized and distributed features: Deployed on the blockchain through smart contracts, the dynamic access control method is decentralized and distributed. There is no single central point that can control or tamper with access rights, which enhances the security and robustness of the system.
[0121] Transparency and immutability: All smart contract executions and transactions are recorded on the blockchain network, ensuring transparency and immutability, which can effectively prevent malicious actors from modifying access control rules or abusing permissions.
[0122] Dynamicity and flexibility: Smart contracts can automatically execute and adjust access rights according to preset rules and conditions. This enables access control policies to be dynamically adjusted according to the real-time status and needs of the forest and grassland IoT, increasing the flexibility and adaptability of the system. Spatial data fingerprint database generation can be automatically executed according to preset rules and conditions, and the fingerprint database is replaced by an encrypted attribute database instead of a geospatial database, which enables data integrity detection strategies to be shared in a distributed network, and forest and grassland perception terminals can obtain and calculate locally in real time, increasing the flexibility and adaptability of the system.
[0123] Fine-grained access control: KP-ABE allows fine-grained access control based on user attributes and roles, and can set different access rights for different users or user groups to meet the complex permission requirements in the forest and grassland Internet of Things.
[0124] Simplified permission management: By associating permissions with attributes and roles, KP-ABE simplifies the permission management process. Administrators do not need to set permissions for each user individually, but only need to define attributes and roles, thereby reducing management costs and complexity.
[0125] Enhanced security: KP-ABE uses encryption technology to protect the security of data and combines multi-dimensional dynamic attributes to participate in access control, so that only users with appropriate attributes can decrypt and access data. This helps prevent unauthorized access and data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0126] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0127] Figure 1 A structural block diagram of a blockchain-enabled zero-trust forest and grassland IoT system involved in one embodiment of the present invention;
[0128] Figure 2 A flowchart of a blockchain-enabled zero-trust forest and grassland IoT system security protection method according to an embodiment of the present invention;
[0129] Figure 3 A flowchart of a blockchain creation, smart contract definition, and system initialization process according to an embodiment of the present invention;
[0130] Figure 4 A schematic diagram of the process of periodic operation of a forest and grassland Internet of Things system according to an embodiment of the present invention;
[0131] Figure 5 A schematic diagram of a flow chart of an identity authentication process performed by a forest and grassland safety situation awareness system according to an embodiment of the present invention;
[0132] Figure 6 A schematic diagram of a flow chart of a dynamic access control process performed by a forest and grassland safety situation awareness system according to an embodiment of the present invention;
[0133] Figure 7 A schematic diagram of a flow chart of an integrity detection process performed by a forest and grassland safety situation awareness system according to an embodiment of the present invention;
[0134] Figure 8 A flow chart of the process of submitting data and returning access results on the forest and grassland cloud platform involved in one embodiment of the present invention;
[0135] Fig. 9 A schematic diagram of a process of executing an independent audit process by a forest and grassland safety situation awareness system according to an embodiment of the present invention;
[0136] Fig.10 A schematic diagram of a flow chart of a forest and grassland safety situation awareness process performed by a forest and grassland safety situation awareness system according to an embodiment of the present invention;
[0137] Fig.11 This is a schematic diagram of the execution flow of a blockchain-enabled zero-trust forestry and grassland Internet of Things system module involved in one embodiment of the present invention. DETAILED DESCRIPTION
[0138] The present invention is described in detail below in conjunction with the accompanying drawings. The description in this part is only exemplary and explanatory and should not have any limiting effect on the scope of protection of the present invention. In addition, those skilled in the art can make corresponding combinations of the features in the embodiments and in different embodiments in this document based on the description of this document.
[0139] In order to better understand the technical solution of the present invention, the structure of the forest and grassland Internet of Things system of the present invention is introduced as follows:
[0140] It consists of forest and grassland sensing terminals, forest and grassland communication relays, forest and grassland cloud platforms and internal resources.
[0141] Forest and grassland sensing terminals collect, perceive and monitor information on forest and grassland resources and their growth and living environment, including but not limited to forest tree (carbon) meters, infrared cameras, meteorological environment monitoring equipment, video mounts, mobile data acquisition terminals and other IoT smart devices, as well as mobile or fixed control terminals for spatial data collection, processing and interaction, which are the perception terminals of the forest and grassland cloud platform.
[0142] Forest and grassland communication relay, which receives forest and grassland sensing terminal signals and realizes the reporting, feedback and reception of collected data, including but not limited to Beidou short message gateway, 4G mobile communication gateway, industrial control gateway and other Internet of Things communication equipment.
[0143] The forestry and grassland cloud platform is deployed on the cloud platform and is a collection of software and hardware resources and systems that maintain and operate the blockchain system and realize continuous verification, dynamic evaluation, real-time perception and scientific decision-making of the forestry and grassland Internet of Things system.
[0144] The cloud platform provides platform software and hardware support, including cloud platform resources and application platforms. Cloud platform resources include but are not limited to X86 computing servers for building computing resource pools, storage servers for building storage resource pools, network servers and routers for building network resource pools, and virtualization platform software for resource virtualization management. Application platforms include but are not limited to operating systems, database platforms, GIS platforms, network middleware, blockchain, etc. deployed on virtualization platforms. This part adopts existing mature technologies and will not be elaborated on.
[0145] Internal resources are the software, hardware and data resources stored, maintained and managed by the forestry and grassland Internet of Things system.
[0146] The forestry and grassland cloud platform includes the forestry and grassland Internet of Things application system and the forestry and grassland safety situation awareness system, as well as a cloud platform equipped with the forestry and grassland Internet of Things application system and the forestry and grassland safety situation awareness system.
[0147] The blockchain-enabled zero-trust forestry and grassland IoT system consists of the forestry and grassland IoT application system and the forestry and grassland security situation awareness system.
[0148] The forestry and grassland IoT application system receives the reports and return data and requests from the forestry and grassland communication relay, converts them into access sessions, stores them in the blockchain, and submits them to the forestry and grassland security situation awareness system. According to the results returned by the forestry and grassland security situation awareness system, the forestry and grassland communication relay executes secure access to internal resources. The forestry and grassland IoT application system port is the channel for the forestry and grassland communication relay to interact with the forestry and grassland cloud platform and blockchain system, that is, the forestry and grassland cloud platform client.
[0149] The forestry and grassland security situation awareness system receives the forestry and grassland IoT application system session and combines internal resources through smart contracts to decide whether to authorize the submitted identity authentication, access control, integrity detection and other request sessions, and judges the current security situation and whether to conduct independent audits based on the current status of the forestry and grassland IoT system. The forestry and grassland security situation awareness system port is the channel for the forestry and grassland IoT application system to interact with the blockchain smart contract, that is, the server side of the forestry and grassland cloud platform.
[0150] Specifically, the embodiment of the present invention is as follows: a blockchain-enabled zero-trust forest and grassland IoT security protection method is implemented through the forest and grassland cloud platform, such as Figure 2 The blockchain-enabled zero-trust forest and grassland IoT system security protection method includes the following steps:
[0151] S1, blockchain creation, smart contract definition and system initialization: complete the definition and chain code installation of identity authentication smart contract, access control smart contract, integrity detection smart contract, independent audit smart contract, security situation awareness smart contract, and initialize the equipment registration information of the Lincao Cloud Platform, and generate spatial data fingerprint and key system;
[0152] like Figure 3 , the specific steps in step S1 are as follows:
[0153] S1.1, blockchain network creation and initialization;
[0154] Select the appropriate blockchain type and specific blockchain platform based on the application scenario, carry out organization registration, identity authentication and verification, define the alliance for the organization based on actual business and create a channel for the alliance, issue certificates to the organization's client user nodes, peer nodes, sorting nodes, and identity authentication nodes through the certificate authority, and each organization approves the chain code definition and endorsement policy definition and completes the storage on the channel ledger.
[0155] For the forest and grassland IoT application scenario, considering that the users are mainly forest and grassland management departments, the data has strong industry attributes and needs to be connected to the Internet for information exchange. It is most appropriate to use a consortium chain, and Hyperledger Fabric is one of the most widely used consortium chain platforms in the world. Therefore, the Fabric blockchain platform is recommended for the method of the present invention.
[0156] For the forestry and grassland Internet of Things system, the forestry and grassland management departments at all levels are organizations, and usually establish organizations and alliances according to administrative levels. For example, the municipal forestry and grassland management departments are organizations, and alliances are established at the provincial level. Channels are built to enable organizations to communicate with each other and maintain a common ledger.
[0157] Each organization is an organization administrator registered in the Fabric blockchain network MSP, and sends requests and obtains services to the forestry and grassland IoT application system deployed on the forestry and grassland cloud platform through the client user node.
[0158] Registered field investigators, after passing the MSP identity authentication, use mobile data collection terminals to connect to the forest and grassland communication relay and forest and grassland cloud platform to carry out initial deployment work.
[0159] Before the audit, under the supervision of the established audit team, the system administrator will establish an audit department organization in the Fabric blockchain network, register the auditors of the audit department organization through MSP, join the channel to maintain the common ledger, and conduct independent audits on the alliances, organizations and administrators of the audited forest and grassland IoT system.
[0160] S1.2, identity authentication smart contract definition and chain code installation, where the identity authentication smart contract includes the forestry perception terminal, forestry communication relay and forestry cloud platform to perform identity authentication access session chain operation strategy and identity authentication operation strategy in the blockchain network, and the chain code is installed through the forestry cloud platform server;
[0161] (1) The identity authentication access session chain operation strategy includes but is not limited to the organization administrator login session chain strategy, identity authentication session chain strategy, identity authentication failure session chain strategy, and data transmission session chain strategy. For the forest and grassland IoT system, the identity authentication access session storage content is different according to the session type, but the storage method is the same, that is, to initiate a transaction for the access session, and after calculation through the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network to achieve the tamper-proof and traceable access behavior. For example, the organization administrator login session chain strategy, the identity authentication access session storage content is but not limited to the organization administrator username, login time, login location, login IP, and a session write request is made to the blockchain network after the session is completed.
[0162] (2) Identity authentication operation strategies include but are not limited to static physical fingerprint generation strategy, static identity authentication strategy, multi-dimensional dynamic feature fingerprint generation strategy, and continuous dynamic identity authentication strategy.
[0163] Among them, the static physical fingerprint generation strategy is that the Lincao Cloud Platform generates a static physical fingerprint for the device based on the device type, device MAC, and radio frequency fingerprint in the registered device registration table. After the set combination and conversion, it uses a hash function to generate a static physical fingerprint for the device as the unique identification of the device.
[0164] The combination and conversion method in the forest and grassland Internet of Things system adopts string concatenation operation, that is, the device type, device MAC address and radio frequency fingerprint information are concatenated into a string, and then the national secret SM3 cryptographic hash algorithm is used to output summary information with a length of 256 bits as the static physical fingerprint of the device.
[0165] The static identity authentication strategy generates a static physical fingerprint of the current forestry and grassland IoT gateway based on the registration information of the currently accessed device, and then obtains the static physical fingerprint of the device's last access on the blockchain platform, and returns the identity authentication result after comparison.
[0166] Among them, the multi-dimensional dynamic feature fingerprint generation strategy is that the Lincao Cloud Platform usually builds a dynamic feature fingerprint for the device based on the dynamic change characteristics over time, space and environment in the device registration form, using its physical change characteristics to form a continuous dynamic verification model.
[0167] For the forestry and grassland Internet of Things system, the device type, device MAC, device power, registration time, and the time-battery power attenuation model can be used to build a dynamic feature fingerprint based on power; the device temperature, external humidity, and internal humidity can be used to build a dynamic feature fingerprint based on temperature and humidity using the consistency characteristics of common spatial environmental factors; the channel fingerprint and RF fingerprint can be used to build a dynamic feature fingerprint based on the network channel using the wireless signal spatial transmission attenuation model.
[0168] The continuous dynamic identity authentication strategy generates a multi-dimensional dynamic feature fingerprint of the device based on the current device’s registration information, and then obtains the multi-dimensional dynamic feature fingerprint of the forestry and grassland IoT gateway’s last visit on the blockchain platform, compares the two pieces of information and returns the identity authentication result.
[0169] For the forest and grass IoT system, the device type, device mac, device power, and registration time of the last access time node are calculated using the time-battery power attenuation model to compare the battery power result with the power in the current registration information of the forest and grass communication relay. If it is within the set threshold range, such as ±10% of the calculated result, it is considered to have passed the verification; the device temperature, external humidity, and internal humidity collected by the forest and grass communication relay are calculated using the consistency characteristics of the common spatial environmental factors. The fluctuation range of the ambient temperature and humidity of all devices is calculated. If it is within the set threshold range, such as ±10% of the average temperature and humidity, it is considered to have passed the verification; the channel fingerprint and RF fingerprint are constructed based on the network channel using the wireless signal spatial transmission attenuation model. If it is within the set threshold range, such as ±10% of the signal strength, it is considered to have passed the verification. The above multi-dimensional feature fingerprints can be used alone or in combination.
[0170] S1.3, access control smart contract definition and chain code installation, where the access control smart contract includes the access control access session chain operation strategy and dynamic access control operation strategy in the blockchain network by the Lincao communication relay and the Lincao cloud platform, and the chain code is installed through the Lincao cloud platform server;
[0171] (1) Access control access session operation policies include but are not limited to data transmission session chaining policies, operation policy download access session chaining policies, and access control failure session chaining policies.
[0172] For the forest and grassland IoT system, the access control access session stores different contents according to the session type, but the storage method is the same, that is, to initiate a transaction for the access session, and after calculation through the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network, so that the access behavior cannot be tampered with and is traceable. For example, the operation strategy downloads the access session chain strategy, and the access control access session storage content includes but is not limited to the visitor's username, login time, login location, login IP, and submits a session write request to the blockchain network after the session is completed.
[0173] (2) Dynamic access control strategies include but are not limited to forest and grassland communication relay subject attribute generation strategy, forest and grassland communication relay subject multi-dimensional dynamic attribute calculation strategy, forest and grassland communication relay data transmission attribute access request generation strategy, forest and grassland cloud platform key policy attribute base encryption initialization strategy, forest and grassland cloud platform access control tree structure key generation strategy, forest and grassland communication relay key policy attribute base data encryption (KP-ABE) strategy, forest and grassland cloud platform key policy attribute base data decryption strategy, forest and grassland communication relay collected data transmission storage access control verification strategy.
[0174] For the access control attributes of the forest and grass IoT system, the subject attribute is the data of the forest and grass communication relay, the object attribute is the client attribute of the forest and grass cloud platform, the permission attribute is the operation authority of the forest and grass communication relay on the forest and grass cloud platform, and the environment attribute is the environment information when the forest and grass communication relay accesses the forest and grass cloud platform. For example: the object attribute includes the client IP, client port number, network protocol and other forest and grass cloud platform client description information; the operation of the permission attribute includes read, write, execute, etc.; the environment attribute includes the start time, end time, initiator, etc. of the control access session.
[0175] The main attribute generation strategy of the forest and grass communication relay is that the forest and grass communication relay directly reads its own attributes and collects data information, such as device name, device type, device MAC, battery power, temperature, humidity, RSSI and other information, and stores them in the form of key-value pairs. {Device name: Getwey101, device type: forest and grass communication relay, device MAC: 23:e4:xx:xx:5f:k9, battery power: 2400, temperature: 24, humidity: 80; RSSI: -65}.
[0176] Among them, the multi-dimensional dynamic attribute generation strategy of the forestry and grassland communication relay subject is based on the forestry and grassland communication relay subject attributes stored in the last access session in the blockchain network by the forestry and grassland cloud platform. It uses the physical model to simulate and calculate the multi-dimensional dynamic attributes, and simulates and calculates the forestry and grassland communication relay subject attribute values of this access session for subsequent access control verification.
[0177] Among them, multi-dimensional dynamic attributes refer to attribute values that change over time or space, such as battery power, temperature and humidity, and wireless model strength. The physical model is determined by the physical characteristics of multi-dimensional dynamic attributes. For example, the battery power has a physical characteristic that the battery power will decay over time, and temperature and humidity are physical characteristics that wireless devices have consistent temperature and humidity in a common space environment; wireless model strength is a physical characteristic that the wireless signal strength of wireless devices in a fixed wireless signal space remains stable.
[0178] The forest and grassland communication relay data transmission attribute access request generation strategy is that the forest and grassland communication relay generates data transmission access request attributes, including subject attributes, object attributes, authority attributes and environment attributes; wherein the authority attribute is a write operation.
[0179] Among them, the key policy attribute-based encryption initialization strategy of the Lincao cloud platform is that the certificate authority (CA) generates the system public key PK and the system master key MK based on the key policy attribute-based encryption mechanism (KP-ABE).
[0180] The access control tree structure key generation strategy of the Lincao Cloud Platform is that the certificate authority (CA) calculates the decryption key S of the Lincao Cloud Platform client user based on the system master key MK and the user attribute set W'.
[0181] Among them, the forest and grassland communication relay key policy attribute-based data encryption (KP-ABE) strategy is that the forest and grassland communication relay uses the system public key PK, the forest and grassland communication relay submission data D, and the access request attribute W as input to generate the ciphertext C.
[0182] Among them, the Lincao cloud platform key policy attribute base data decryption strategy is that the Lincao cloud platform takes the ciphertext C as input. If the access request attribute W meets the threshold value requirement of the user attribute set W', the Lincao communication relay submission data D is restored.
[0183] Among them, the access control verification strategy for the storage of data collected by the forest and grassland communication relay is to perform access control verification on the attribute set of the client of the visited forest and grassland cloud platform and the attribute set of the access control request for the storage of data collected by the forest and grassland communication relay.
[0184] S1.4, independent audit smart contract and chain code installation, where the independent audit smart contract includes the independent audit session chain operation strategy and independent audit operation strategy carried out by the Lincao Cloud Platform in the blockchain network, and the chain code is installed through the Lincao Cloud Platform server;
[0185] (1) Independent audit session chain operation strategies include but are not limited to independent audit notification session chain strategy, forestry and grassland communication relay audit reply session chain strategy, independent audit successful completion session chain strategy, and independent audit failure end session chain strategy.
[0186] For the forestry and grassland Internet of Things system, the independent audit access session stores different contents depending on the session type, but the storage method is the same, which is to initiate a transaction for the access session, and then form a new block after calculation through the blockchain network consensus algorithm to store it in the blockchain network, so as to achieve the unalterability and traceability of the access behavior.
[0187] The structure of a standalone audit session is as follows:
[0188] Sessions (session ID, session type, session subject, session object, session send time, session receive time, session status) are stored in key-value pairs.
[0189] The session ID is the unique number of the session;
[0190] Session types include but are not limited to independent audit notification session, forestry and grassland communication relay audit reply session, independent audit successful completion session, and independent audit failure session;
[0191] The session subject is the attribute of the session generator and sender, which can be represented by a single attribute or a composite key value;
[0192] The session topic is the receiver and storage attributes of the session, which can be represented by a single attribute or a composite key value;
[0193] The session sending time is the time when the session subject sends the session;
[0194] The session receiving time is the time when the session object receives the session;
[0195] The session status describes the current status of the session, including but not limited to sent, received, failed to send, and failed to receive.
[0196] For example, the independent audit notification session is recorded as (session_ID:20210000001, session_Type: "Independent Audit Notification Session
[0197] ",session_subject:{"sjy_ID":SJ001,deviceID:C2300101000XXX01,MAC:48:e2:xx:xx:6f:f9},session_object:{"sjy_ID":SJ001, deviceID:C2300101000XXX01,MAC:48:e2:xx:xx:6f:f9}, createTime:202104022038, endTime:202104022039, session_result: "Sent").
[0198] (2) Independent audit operation strategies include, but are not limited to, independent audit initiation decision strategies, independent audit notification attribute generation strategies, independent audit notification attribute encryption strategies, independent audit notification attribute broadcast strategies, and independent audit detection strategies.
[0199] The independent audit initiation decision strategy is that the independent audit organization of the Lincao Cloud Platform determines whether to initiate an independent audit action based on the independent audit initiation conditions set by the Lincao IoT system. The independent audit initiation conditions here may include but are not limited to reaching a specified time node or passing a specified period of time, such as an audit once a year, or starting an audit on December 1st of each year, triggering an emergency security state or a specific business function, such as when the network situational awareness enters an emergency disposal state, and an independent audit is initiated after the emergency disposal is completed.
[0200] Among them, the independent audit notification attribute generation strategy is that the independent audit organization of the forest and grassland cloud platform generates the audit attributes. The audit notification is an attribute-based access control request, which consists of audit subject attributes, audit object attributes, permission attributes, and environmental attributes. For the forest and grassland IoT system, the audit subject attributes are the audit organization and audit client information, and the symmetric encryption algorithm and key used to encrypt the return data of the audit object are generated. The object attributes are the forest and grassland communication relay and / or forest and grassland perception terminal. The permission attributes are the operation permissions of the forest and grassland cloud platform to the forest and grassland communication relay and / or forest and grassland perception terminal. The environmental attributes are the environmental information when the independent audit is generated.
[0201] The audit subject attributes are the audit organization and audit client information, such as client IP, client port number, client account, encryption algorithm, and symmetric key. {Client IP: 192.168.8.106, client port number: 5058, client account: auditadmin, encryption algorithm: SM4, symmetric key: Sa@123456}.
[0202] The object attributes are forest and grass communication relay and / or forest and grass perception terminal, such as device name, device type, device MAC and other information, which are stored in key-value pairs. {Device type: forest and grass communication relay, forest and grass communication relay location: Luhuo County, device name: Getwey101, device MAC: 23:e4:xx:xx:5f:k9, extended audit: yes, device type: forest and grass IoT terminal, terminal location: Luhuo County, device name: ALL, device MAC: ALL}.
[0203] The operations of permission attributes include read, write, and execute;
[0204] Environmental attributes include, but are not limited to, controlling the start time, end time, and initiator of the access session.
[0205] An audit notification initiated by the client with IP address 192.168.8.106 and the auditadmin audit account to audit all forest and grassland communication relays and forest and grassland perception terminals deployed in Luhuo County from 20:38 on April 2, 2021 to 20:38 on April 3, 2021 is as follows:
[0206] {"Action":"audit","Notice":{AS:{Client IP:192.168.8.106, Client user: auditadmin, Encryption algorithm: SM4, Symmetric key: Sa@123456}}, AO:{Device type: Lincao communication relay, Device location: Luhuo County, Device name: ALL, Device MAC: ALL, Extended audit: Yes, Device type: Lincao IoT terminal, Terminal location: Luhuo County, Device name: ALL, Device MAC: ALL}, AP:"read", AE:{Start time: 202104022038, End time: 202104032038, Initiator: auditadmin}}}.
[0207] The independent audit notification attribute encryption strategy is that the independent audit organization of the Lincao Cloud Platform uses the CP-ABE encryption mechanism to initialize the generation of the Lincao Cloud Platform system public key PK, system master key MK, and the decryption key S of the audited device, and encrypts it using PK, MK and the generated independent audit access control policy.
[0208] (1) The certificate authority CA of the Lincao Cloud Platform initializes and generates the Lincao Cloud Platform system public key PK, system master key MK, and decryption key S of the audited device based on the attributes of the audited device.
[0209] (2) The independent audit organization of the Lincao Cloud Platform encrypts the audit notification using PK, MK and independent audit access control policy.
[0210] Since the ciphertext length is small, the ciphertext attribute encryption method here uses the classic linear secret sharing matrix CP-ABE scheme, which will not be described here.
[0211] The independent audit access control policy here is determined by the audit object and audit content. For example, if all IoT terminals in Luhuo County are audited, the independent audit access control policy is "Device type = forest and grass IoT terminal AND terminal location = Luhuo County AND device name = ALL".
[0212] Because of the use of ciphertext attribute encryption, the Lincao Cloud Platform can control who can access the data, ensuring that the independent audit organization of the Lincao Cloud Platform and the Lincao perception terminal can conduct encrypted communication without exposing the key.
[0213] Among them, the independent audit notification attribute broadcast strategy is that the independent audit organization of the forest and grassland cloud platform adds an extended audit decision based on the object attributes of the independent audit notification attributes, and then broadcasts the ciphertext to the forest and grassland communication relay to be audited.
[0214] Among them, the independent audit detection strategy is that the independent audit organization of the Lincao Cloud Platform obtains the audit data transmitted back by the Lincao communication relay, decrypts the data using the symmetric key generated when the independent audit notification attribute is encrypted, reads the data in the blockchain network for comparative analysis, and detects the integrity and authenticity of the current and previous data.
[0215] S1.5, data integrity detection smart contract and chain code installation, where the data integrity detection smart contract includes the data integrity detection access session chain operation strategy and integrity detection operation strategy in the blockchain network by the Lincao communication relay and the Lincao cloud platform, and the chain code is installed through the Lincao cloud platform server;
[0216] (1) Data integrity detection session chain operation strategies include but are not limited to fingerprint cloud database generation session chain strategy, fingerprint cloud database chain session chain strategy, client data integrity detection request session chain strategy, data integrity detection failure session chain strategy, and data integrity detection execution result session chain strategy.
[0217] For the forest and grassland IoT system, the data integrity detection session stores different contents according to the session type, but the storage method is the same, that is, to initiate a transaction for data integrity detection, calculate through the blockchain network consensus algorithm, form a new block storage and enter the blockchain network, so as to achieve the tamper-proof and traceable access behavior. The structure of the fingerprint cloud database generated session is as follows:
[0218] Sessions (session ID, session type, session subject, session object, session send time, session receive time, session status) are stored in key-value pairs.
[0219] The session ID is the unique number of the session;
[0220] Session types include but are not limited to fingerprint cloud database generation session, fingerprint cloud database on-chain session, client data integrity detection request session, and data integrity detection execution result session;
[0221] The session subject is the attribute of the session generator and sender, which can be represented by a single attribute or a composite key value;
[0222] The session topic is the receiver and storage attributes of the session, which can be represented by a single attribute or a composite key value;
[0223] The session sending time is the time when the session subject sends the session;
[0224] The session receiving time is the time when the session object receives the session;
[0225] The session status describes the current status of the session, including but not limited to sent, received, failed to send, and failed to receive.
[0226] For example, for a client data integrity check request session, the session record is (session_ID: 20210000001, session_Type: “Client data integrity check request session”, session_subject: {“sjy_ID”: SJ001, deviceID: C2300101000XXX01, MAC: 48:e2:xx:xx:6f:f9}, session_object: {“sjy_ID”: SJ001, deviceID: C2300101000XXX01, MAC: 48:e2:xx:xx:6f:f9}, createTime: 202104022038, endTime: 202104022039, session_result: “Sent”).
[0227] (2) Integrity detection operation strategies include but are not limited to spatial data feature extraction strategies, spatial data fingerprint generation strategies, fingerprint cloud database generation strategies, fingerprint cloud database on-chain strategies, spatial data fingerprint comparison and detection strategies, data integrity detection result generation strategies, and data integrity detection result on-chain strategies.
[0228] Among them, the spatial data feature extraction strategy, the Lincao Cloud Platform obtains the spatial features and attribute features of the spatial vector data in the server-side internal resource database by executing the spatial feature extraction algorithm and the attribute feature extraction algorithm.
[0229] The spatial specific extraction algorithm calculates the centroid X-coordinate, Y-coordinate, feature information and spatial coordinate system of the spatial vector data in the internal resource database of the server, and connects them to form a spatial feature with unique identification information. The feature information for line elements is the length of the line, and for surface elements is the area of the patch. Under the premise that the topological relationship of the spatial elements is correct, the extracted spatial features are unique.
[0230] For example, the X coordinate of the spatial vector data patch is 349087.34, the Y coordinate is 35452784.98, the feature value is the area, which is 34.557875, and the spatial coordinate system is
[0231] CGCS2000_3_Degree_GK_CM_99E, the connector is "-", then the spatial feature is "349087.34-35452784.98-34.557875-CGCS2000_3_Degree_GK_CM_99E".
[0232] The attribute feature extraction algorithm is to calculate the key attribute factors used for data integrity detection in the spatial vector data in the internal resource database of the server, and form attribute identification information through connector splicing.
[0233] For example, the attribute information of the spatial vector data map has a county code of 3327, a township code of 101, a village code of 101, a small class number of 0001, a tree species code of 601, a forest category code of 11, a jurisdiction code of 10, a forest grade code of 1, an origin code of 11, and a connector of “-”, then the attribute feature is “3327-101-101-0001-601-11-10-1-11”.
[0234] Among them, the spatial data fingerprint generation strategy is that the Lincao Cloud Platform connects the spatial features and attribute features extracted from the spatial vector data through connectors, and uses a hash algorithm to summarize the information to form a spatial data fingerprint.
[0235] For example, the spatial feature of a spatial vector data patch is "349087.34-35452784.98-34.557875-CGCS2000_3_Degree_GK_CM_99E", the attribute feature is "3327-101-101-0001-601-11-10-1-11", the connector is "-", and the connection is "349087.34-35452784.98-34.557875-CGCS2000_3_Degree_GK_CM_99E-3327-101-101-0001-601-11-10-1-11". The national secret SM3 hash algorithm is used for information summary, and the output Base64 encoded spatial data fingerprint is as follows:
[0236] "gSfb59rXqb1htCmqntJfFJ0bvQnUVwQStD4Nzu / 7tho="
[0237] Among them, the fingerprint cloud database generation strategy is that the forestry and grassland cloud platform will generate spatial data fingerprints for all elements of the spatial vector data used for data integrity detection, and export the administrative division and / or business division information describing the data area information to generate a fingerprint cloud database with pure attribute method and independent storage.
[0238] For example, administrative division information includes but is not limited to provinces, cities, counties, townships, and villages; business division information includes but is not limited to forestry bureaus, forest grasslands, operating areas, forest classes, small classes, and detailed classes.
[0239] The fingerprint cloud database chain strategy is that before the Lincao Cloud Platform conducts data integrity detection, the client of the Lincao Cloud Platform initiates a transaction with all the records of the fingerprint cloud database. After calculation through the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network, thereby achieving the immutability and traceability of the fingerprint cloud database data.
[0240] Among them, the spatial data fingerprint comparison and detection strategy is that the forestry cloud platform obtains the stored fingerprint cloud database from the blockchain network based on the perception end fingerprint database and the detection area that will be submitted for detection by the forestry perception terminal. Through the attribute query and comparison method, the spatial data fingerprint of the perception end fingerprint database of the detection area and the spatial data fingerprint in the fingerprint cloud database are compared for consistency, and inconsistent spatial data fingerprints are marked.
[0241] The strategy for generating spatial data fingerprint detection results is that the Lincao Cloud Platform stores the marked inconsistent spatial data fingerprints separately to form a data integrity detection result database.
[0242] The strategy for uploading data integrity test results to the chain is that after the Lincao Cloud Platform has tested the data integrity, the Lincao Cloud Platform client will initiate a transaction with all the records in the data integrity test result database. After calculation through the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network, thereby achieving the tamper-proof and traceable nature of the data in the data integrity test result database.
[0243] S1.6, security situation awareness smart contract definition and chain code installation, where the security situation awareness smart contract includes the data exchange operation strategy for the forest and grassland perception terminal, forest and grassland communication relay and forest and grassland cloud platform to access internal data through identity authentication, access control and integrity detection, as well as the security situation awareness operation strategy initiated in the blockchain network when it fails;
[0244] (1) Data exchange operation strategies include but are not limited to device registration information storage strategy, forest and grassland communication relay periodic operation configuration download strategy, forest and grassland communication relay collected data transmission storage strategy, independent audit results storage strategy, and data integrity test result return strategy;
[0245] The strategy for storing device registration information is that the device registrar uses the factory inspection function of the device management subsystem to detect whether the registered device has security hardening. Through the device scanning and registration function, the device barcode is scanned to form a device registration record with the device information, registration personnel information, registration operation information and device fingerprint information. This registers information other than the static physical fingerprint of the device and the multi-dimensional dynamic feature fingerprint of the device.
[0246] The logical structure of the equipment registration database is as follows:
[0247] Equipment registration (registration ID, equipment ID, equipment type, equipment mac, equipment power, equipment temperature, equipment external humidity, equipment internal humidity, channel fingerprint, radio frequency fingerprint, registration personnel number, registration batch number, registration workshop, registration time, equipment static physical fingerprint, equipment multi-dimensional dynamic feature fingerprint)
[0248] The registration ID is the unique identifier of the device registration list and the primary key in the database; the device ID is the device number of the forest and grass Internet of Things device, and the device ID within each device and between devices is unique; the device type is the forest and grass Internet of Things device type, including but not limited to forest and grass communication relays, terminals, and mobile data acquisition terminals; the device mac is the mac address of the device, which is a unique and fixed mark of the device; the device power is the device power read at registration; the device temperature is the device temperature read at registration; the device humidity is the humidity sensor data on the outside of the device shell at registration, which is equivalent to the ambient humidity; the humidity inside the device is the humidity sensor data on the inside of the device shell at registration, and the airtightness of the device shell is detected by comparing the humidity inside and outside the device; the channel fingerprint is the The signal strength of the wireless communication module. The wireless communication module can be WIFI, Bluetooth, or LORA depending on the device. The radio frequency fingerprint is the signal characteristic of the wireless communication module of the forest and grassland IoT device. The registration personnel number is the registration personnel number that has passed the MSP identity authentication of the Fabric blockchain network and uses the device registration client system. The registration batch number is the number of the registered devices in this batch, which is automatically generated according to the numbering rules. The registration workshop is the name of the venue where the registration is completed during registration. The registration time is the time of scanning and registration. The static physical fingerprint of the device is automatically generated according to the static physical fingerprint generation strategy of the identity authentication smart contract device. The multi-dimensional dynamic feature fingerprint of the device is automatically generated according to the multi-dimensional dynamic feature fingerprint generation strategy of the identity authentication smart contract device.
[0249] The download strategy of the periodic operation configuration of the forest-grass communication relay is that the forest-grass communication relay obtains the periodic operation configuration of the forest-grass communication relay configured and generated in the forest-grass cloud platform from the forest-grass cloud platform client; the periodic operation configuration of the forest-grass communication relay configured by the forest-grass cloud platform includes but is not limited to the IP address, access port, access time, and access duration of the forest-grass cloud platform client;
[0250] The data transmission storage strategy collected by the forest and grass communication relay is that the forest and grass communication relay obtains the data transmission storage configuration information and performs operations in the forest and grass cloud platform from the forest and grass cloud platform client, including but not limited to the forest and grass cloud platform client database IP address, access port, database name, and database user;
[0251] Among them, the independent audit results storage strategy is that the independent audit organization of the Lincao Cloud Platform decrypts the audit data, and the Lincao Cloud Platform client initiates a transaction with the audit results data. After calculation through the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network, so that the audit results data cannot be tampered with and can be traced;
[0252] The data integrity test result return strategy is that the forestry cloud platform returns the test results to the forestry perception terminal based on the data integrity test results. According to the business type, for one-way data integrity check business, after the data integrity test passes, True is returned to the forestry perception terminal, otherwise, False is returned; for data collection business, after the data integrity test passes, it is agreed that the data submitted by the forestry perception terminal will be submitted to the internal resource database of the server, otherwise, the data integrity test result database is returned to the forestry perception terminal.
[0253] (2) Security situation awareness operation strategies include but are not limited to security situation awareness strategies, security threat emergency response strategies, DOS attack monitoring strategies, and injection attack detection strategies.
[0254] Among them, the security situation awareness strategy is that the Lincao Cloud Platform monitors the Lincao communication relays that fail access control or decryption. When the number of failed accesses to the same Lincao communication relay exceeds the specified threshold, the security threat emergency response strategy is triggered.
[0255] The emergency response strategy for security threats is that the Lincao Cloud Platform closes access authorization to Lincao communication relays that exceed the specified access threshold, and notifies the system administrator of the information about the attacked Lincao communication relays.
[0256] Among them, the DOS attack monitoring strategy is that the Lincao Cloud Platform monitors the Lincao communication relays that have failed independent audit verification. When the number of failed accesses to the same Lincao communication relay exceeds the specified threshold, the security threat emergency response strategy is triggered.
[0257] The injection attack detection strategy is to check whether there is false data injection attack in the forest and grassland communication relay and / or forest and grassland perception terminal. The mainstream methods include Kalman filter, deep learning, and neural network, which will not be elaborated here.
[0258] S1.7, initialization of the forest and grassland IoT system, including initialization of the registration of forest and grassland IoT device information, initialization of the generation of spatial data fingerprints, initialization of the key policy attribute-based encryption scheme and key generation;
[0259] S1.7.1, Initialize the registration of forest and grassland IoT device information: The system administrator or the authorized device manager forms the static physical fingerprint of the device based on the registration information and static password through the static physical fingerprint generation strategy of the identity authentication smart contract, and then uses the device registration information storage strategy to form a new block of device registration and device registration information and upload it to the blockchain network to complete the registration of forest and grassland IoT devices;
[0260] S1.7.2, Initialize and generate spatial data fingerprint: The server of the forest and grass cloud platform calls the spatial data feature strategy to extract the spatial features and attribute features of the spatial vector data in the internal resource database of the server, executes the spatial data fingerprint generation strategy to obtain the spatial data fingerprint, and after calculation through the blockchain network consensus algorithm, forms a new block storage and enters the blockchain network, so as to realize the immutability and traceability of the fingerprint cloud database chain session;
[0261] S1.7.3, Key policy attribute-based encryption scheme initialization and key generation: The Lincao cloud platform client calls the Lincao cloud platform key policy attribute-based encryption initialization strategy of the access control smart contract, and the certificate authority (CA) generates the system public key PK and system master key MK based on the key policy attribute-based encryption mechanism (KP-ABE). Call the Lincao cloud platform access control tree structure key generation strategy of the access control smart contract, and the certificate authority (CA) generates the system public key PK and system master key MK based on the system master key MK and the user attribute set W'
[0262] Calculate the decryption key S of the client user of the Lincao Cloud Platform.
[0263] S2, periodic operation of the forest and grassland IoT system: The forest and grassland IoT system wakes up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then sleeps and waits for the next data collection cycle;
[0264] like Figure 4 , the specific steps in step S2 are as follows:
[0265] S2.1, the first deployment of forest and grassland communication relay initiates identity authentication session;
[0266] Field investigators registered by various organizations in the Fabric blockchain network MSP, after passing the MSP identity authentication, use the forest and grassland communication relay deployed on the mobile data collection terminal to connect to the forest and grassland communication relay and configure the address and port of the access client. The forest and grassland communication relay sends the locally stored device registration information to the client, and sends an identity authentication access request to the forest and grassland cloud platform through the client.
[0267] S2.2, mobile data collection terminal connection and configuration of forest and grassland communication relay;
[0268] After passing the identity authentication, the field investigators registered through the Fabric blockchain network MSP use the mobile data collection terminal to connect to the forest and grassland communication relay and the forest and grassland cloud platform, and download and store the dynamic access control policy of the access control smart contract in the forest and grassland cloud platform, the data exchange operation policy of the security situation awareness smart contract, and the periodic operation configuration of the forest and grassland communication relay to the local forest and grassland communication relay.
[0269] S2.3, periodic operation of forest and grassland IoT system;
[0270] The forest and grassland IoT system wakes up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy. The forest and grassland communication relay uses the configured address and port to send the locally collected and updated device registration information to the forest and grassland cloud platform through the client for identity authentication access request. The forest and grassland communication relay uses the forest and grassland communication relay subject attribute generation strategy to generate the subject attributes of the forest and grassland communication relay based on the locally stored smart contract strategy and the forest and grassland communication relay periodic operation configuration. Complete data collection, aggregation and transmission, and then sleep and wait for the next data collection cycle.
[0271] The static attribute generation strategy of the forest and grass communication relay is that the forest and grass communication relay directly reads its own unchanged attribute information, such as device name, device type, device MAC and other information, and stores them in the form of key-value pairs. {Device name: Getwey101, device type: forest and grass communication relay, device MAC: 23:e4:xx:xx:5f:k9}.
[0272] S3, the forest and grassland security situation awareness system performs identity authentication: the forest and grassland security situation awareness system calls the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay, and performs static identity authentication and continuous dynamic identity authentication on the forest and grassland communication relay; the forest and grassland communication relay generates the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal according to the periodic operation configuration strategy, and completes the static identity authentication and continuous dynamic identity authentication for the forest and grassland perception terminal. If the authentication is passed, execute step S4, if not, execute step S10;
[0273] like Figure 5 , the specific steps in step S3 are as follows:
[0274] S3.1, create a static physical fingerprint of the forest and grass communication relay and perform static identity authentication: the forest and grass cloud platform client calls the static physical fingerprint generation strategy, generates the static physical fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the forest and grass cloud platform client, and then obtains the static physical fingerprint of the forest and grass communication relay last accessed in the blockchain platform, and calls the static identity authentication strategy to perform static identity authentication;
[0275] S3.2, create a multi-dimensional dynamic feature fingerprint of the forest and grass communication relay and perform dynamic identity authentication: the forest and grass cloud platform client calls the multi-dimensional dynamic feature fingerprint generation strategy, generates the multi-dimensional dynamic feature fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the forest and grass cloud platform client, and then obtains the multi-dimensional dynamic feature fingerprint of the forest and grass communication relay last accessed in the blockchain platform, calls the continuous dynamic identity authentication strategy to compare the two pieces of information and returns the identity authentication result;
[0276] S3.3, Lincao communication relay identity authentication result session upload to blockchain network: Lincao cloud platform client calls the identity authentication session chain strategy, records the session information into the blockchain network, and calls the device registration information storage strategy to add and update the device access registration information of the current Lincao communication relay into the database;
[0277] S3.4, the forest-grass communication relay receives and stores the identity authentication access session information of the forest-grass perception terminal: the forest-grass communication relay receives the identity access request of the forest-grass perception terminal, obtains the identity authentication session parameters of the forest-grass perception terminal, and stores them locally in the forest-grass communication relay;
[0278] S3.5, the forest and grassland communication relay creates a static physical fingerprint of the forest and grassland perception terminal and performs static identity authentication: the forest and grassland communication relay generates a static physical fingerprint for accessing the forest and grassland perception terminal based on the static physical fingerprint generation strategy stored locally, calls the static identity authentication strategy, and compares it with the static physical fingerprint of the forest and grassland perception terminal stored locally;
[0279] S3.6, the forestry and grassland communication relay creates a multi-dimensional dynamic feature fingerprint of the forestry and grassland perception terminal and performs dynamic identity authentication: the forestry and grassland communication relay calculates and generates a multi-dimensional dynamic feature fingerprint based on the multi-dimensional dynamic feature fingerprint generation strategy stored locally, for the identity authentication session parameters of the forestry and grassland perception terminal obtained, as well as the identity authentication session parameters of the last forestry and grassland perception terminal obtained from the blockchain network when the forestry and grassland communication relay is initialized and stored locally, and uses the continuous dynamic identity authentication strategy stored locally to compare and authenticate the two multi-dimensional dynamic feature fingerprints of the forestry and grassland perception terminal.
[0280] S4, the forest and grassland security situation awareness system performs dynamic access control: the forest and grassland communication relay uses the key policy attribute-based encryption method to encrypt the forest and grassland communication relay data to form a ciphertext and initiate a data transmission attribute access request to the forest and grassland cloud platform. The forest and grassland security situation awareness system calls the dynamic access control smart contract to calculate the multi-dimensional subject attributes of the forest and grassland communication relay, decrypts and verifies whether the attributes of the forest and grassland communication relay have passed the verification, completes the dynamic access control and returns the access result. If it passes the verification, execute step S5, if it fails the verification, execute step S10;
[0281] like Figure 6 , the specific steps in step S4 are as follows:
[0282] S4.1, encryption of forest and grassland communication relay data collected by key policy attribute-based encryption mechanism: the forest and grassland communication relay uses the forest and grassland communication relay subject attributes and the forest and grassland cloud platform system public key, calls the forest and grassland communication relay key policy attribute-based data encryption strategy, and encrypts the forest and grassland perception terminal data collected in the forest and grassland communication relay to form ciphertext;
[0283] S4.2, the forest and grassland communication relay initiates a data transmission attribute access request to the forest and grassland cloud platform: the forest and grassland communication relay uses the forest and grassland communication relay data transmission attribute access request generation strategy downloaded to the local forest and grassland communication relay periodic operation configuration, combines the forest and grassland communication relay subject attributes to generate a forest and grassland communication relay data transmission attribute access request, and sends a forest and grassland communication relay data transmission attribute access request session to the forest and grassland cloud platform;
[0284] For the forest and grassland communication relay, data transmission access request attributes are generated, including subject, object attributes, authority attributes and environment attributes; among them, the authority attribute is a write operation, that is, the perception data collected by the forest and grassland communication relay is written into the database of the forest and grassland cloud platform.
[0285] S4.3, Lincao Cloud Platform uploads the data transmission session of Lincao Communication Relay to the blockchain network: Lincao Cloud Platform calls the data transmission session chain strategy, initiates a transaction for the data transmission session access request session sent by Lincao Communication Relay, and forms a new block storage into the blockchain network after calculation through the blockchain network consensus algorithm, so as to realize the tamper-proof and traceable access behavior;
[0286] S4.4, the forestry cloud platform calculates the multi-dimensional dynamic attributes of the forestry communication relay: the forestry cloud platform calls the multi-dimensional dynamic attribute calculation strategy of the forestry communication relay subject, obtains the forestry communication relay subject attributes stored in the last access session in the blockchain network, uses the physical model to simulate and calculate the multi-dimensional dynamic attributes, and simulates and calculates the forestry communication relay subject attribute values of this access session;
[0287] S4.5, the forestry cloud platform performs access control verification on the forestry communication relay data transmission: the forestry cloud platform calls the forestry communication relay collection data transmission storage access control verification strategy, and verifies the forestry communication relay subject attributes of the current session in combination with the simulated calculated forestry communication relay subject attribute values;
[0288] S4.6, Lincao Cloud Platform Key Policy Attribute Base Data Decryption: Lincao Cloud Platform calls the Lincao Cloud Platform Key Policy Attribute Base Data Decryption Strategy, and uses the key S related to the access structure allocated to the Lincao Cloud Platform client user when the Lincao Cloud Platform is initialized to perform decryption operations. The decryption is successful when the attributes in the ciphertext satisfy the access control tree.
[0289] S5, the forest and grassland safety situation awareness system performs integrity detection: the forest and grassland safety situation awareness system compares the spatial data fingerprint submitted by the forest and grassland perception terminal obtained by decryption with the spatial data fingerprint initialized and stored in the blockchain, and completes the forest and grassland IoT data integrity detection and returns the detection result. If the detection passes, step S6 is executed, if not, step S10 is executed;
[0290] like Figure 7 , the step S5 includes the following steps:
[0291] S5.1, forest and grassland perception terminal obtains spatial data fingerprint database generation strategy: the forest and grassland perception terminal accesses the forest and grassland cloud platform client or blockchain network to obtain spatial data feature extraction strategy, spatial data fingerprint generation strategy and fingerprint database generation strategy;
[0292] The above-mentioned forest and grassland cloud platform is open to all forest and grassland sensing terminals and can be freely accessed to ensure the accuracy and timeliness of data integrity detection.
[0293] S5.2, spatial data feature extraction of forest and grassland perception terminal: For the spatial database used for data integrity detection, the forest and grassland perception terminal locally executes the spatial data feature extraction strategy to obtain the spatial features and attribute features of the spatial vector data in the perception terminal spatial database;
[0294] As with the server side of the forest and grass cloud platform, two text fields, spatial features and attribute features, are usually added to the spatial database used for data integrity detection. The calculated spatial features and attribute features are stored.
[0295] S5.3, spatial data fingerprint generation at the perception end: The perception end of the forest and grassland cloud platform obtains spatial data with spatial features and attribute features for data integrity detection, executes the spatial data fingerprint generation strategy, and obtains the spatial data fingerprint of the spatial database of the perception end of the forest and grassland cloud platform;
[0296] As with the server side, a text field of data fingerprint is usually added to the spatial database used for data integrity detection to store the spatial data fingerprint obtained by calculation in Base64 encoding format.
[0297] S5.4, generation of fingerprint cloud database of perception end: the perception end of the forest and grass cloud platform obtains the spatial data with spatial data fingerprint for data integrity detection, executes the fingerprint cloud database generation strategy, and obtains the fingerprint database of the perception end of the forest and grass cloud platform;
[0298] S5.5, the sensing end sends a data integrity detection request and a sensing end fingerprint database: the sensing end of the forest and grass cloud platform sends a data integrity detection request to the forest and grass cloud platform client, and submits the sensing end fingerprint database to complete the data integrity detection;
[0299] S5.6, the perception terminal data integrity detection request session is uploaded to the chain: the forest and grassland cloud platform client executes the fingerprint cloud database to generate the session on-chain strategy, and the forest and grassland cloud platform client initiates the client data integrity detection request session transaction, which is calculated through the blockchain network consensus algorithm to form a new block storage and enter the blockchain network, so as to realize the tamper-proof and traceability of the forest and grassland perception terminal data submission and data integrity detection behavior;
[0300] S5.7, server-side spatial data fingerprint comparison and detection: The server-side of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint comparison and detection strategy, takes the sensor terminal fingerprint database submitted for detection by the sensor terminal of the Forestry and Grassland Cloud Platform as input, obtains the fingerprint cloud database from the blockchain network, and compares the spatial data fingerprint of the sensor terminal fingerprint database with the spatial data fingerprint of the fingerprint cloud database through attribute query comparison, and marks the inconsistent spatial data fingerprints;
[0301] S5.8, the server side obtains the data integrity test result: the server side of the forest and grass cloud platform executes the spatial data fingerprint test result generation strategy, and stores the spatial data fingerprints marked as inconsistent separately to form a data integrity test result database;
[0302] S5.9, Data integrity test results are uploaded to the blockchain: The client of the Lincao Cloud Platform executes the data integrity test results upload strategy, initiates a transaction with all records in the data integrity test results database, and forms a new block after calculation through the blockchain network consensus algorithm to store it in the blockchain network, thus achieving the data integrity test results database data that cannot be tampered with and can be traced;
[0303] S5.10, data integrity check execution result session chaining: The Lincao Cloud Platform client executes the data integrity check execution result session chaining strategy, initiates a transaction on the server-side data integrity check execution result session, and after calculation through the blockchain network consensus algorithm, forms a new block storage and enters the blockchain network, thereby achieving the tamper-proof and traceability of data integrity detection behavior.
[0304] S6, the forestry cloud platform submits data and returns access results: the forestry communication relay sends the collected monitoring data to the forestry cloud platform, and the forestry IoT application system connects to the internal resource database to complete the data storage, returns the periodic operation configuration and periodic operation strategy, and waits for the next data collection cycle;
[0305] like Figure 8, the step S6 includes the following steps:
[0306] S6.1, Forestry and Grassland Communication Relay downloads the periodic operation configuration of Forestry and Grassland Communication Relay: Forestry and Grassland Communication Relay uses the periodic operation configuration download strategy of Forestry and Grassland Communication Relay to read and download the forestry and grassland Internet of Things periodic operation strategy configuration information in the Forestry and Grassland Cloud Platform database to the local Forestry and Grassland Communication Relay for use in periodic operation after the Forestry and Grassland Communication Relay wakes up from sleep mode next time.
[0307] S6.2, the forestry and grassland communication relay stores the data collected by the forestry and grassland perception terminal and sends down the periodic operation configuration: the forestry and grassland communication relay receives the authentication parameters and collected data transmitted by the forestry and grassland perception terminal, stores them in the forestry and grassland communication relay, and sends the locally stored forestry and grassland perception terminal periodic operation policy to the forestry and grassland perception terminal to ensure the next operation.
[0308] For the forest and grassland IoT system, the authentication parameter information is consistent with the device registration format. For the collected data, the transmission and storage strategy data formats vary depending on the type of sensor. For forest tree (carbon) meter devices, it includes but is not limited to tree species, standing tree type, breast diameter, tree height, hourly temperature sequence, and hourly humidity sequence. The periodic operation strategy of the forest and grassland sensing terminal includes but is not limited to the address and port of the forest and grassland sensing terminal's next visit to the forest and grassland communication relay, as well as periodic monitoring configuration information such as wake-up time and wake-up duration.
[0309] S6.3, the forest and grassland communication relay sends the collected data to the forest and grassland cloud platform: if the forest and grassland communication relay passes the identity authentication, access control, and data integrity detection, it agrees to submit the data submitted by the perception end into the internal resource database of the server. If not, it returns the data integrity detection result database to the perception end;
[0310] S7, determine whether the monitoring is finished, if not, execute step S8, if yes, terminate the process;
[0311] Due to project requirements or force majeure, the forest and grassland sensing terminals, forest and grassland communication relays, and forest and grassland cloud platforms all stop operating at the same time or in part, and the monitoring is deemed to have ended.
[0312] S8, determine whether to trigger an independent audit: the forest and grassland safety situation awareness system determines whether the independent audit start condition is triggered by executing the independent audit smart contract. If so, execute step S9; if not, execute step S2;
[0313] The forestry and grassland Internet of Things system executes the independent audit startup strategy of the independent security audit smart contract to determine whether an independent audit is triggered. If the independent audit startup conditions are met, the auditor account organized by the MSP registration and audit department in the blockchain network will conduct an independent audit of the alliance, organization and administrator of the audited forestry and grassland Internet of Things system.
[0314] The conditions for initiating an independent audit here may include but are not limited to reaching a specified time node or passing a specified period of time, such as an audit once a year, or starting an audit on December 1st of each year, triggering an emergency security status or a fixed business function, such as network situation awareness entering an emergency disposal state, and automatically initiating an independent audit after the disposal.
[0315] S9, the forest and grassland safety situation awareness system performs independent auditing: the forest and grassland safety situation awareness system generates an independent audit notification and encrypts and broadcasts it. The audited device receives the audit notification, conducts the audit and returns the audit data. The forest and grassland safety situation awareness system verifies the returned audit data and stores the audit session and audit results on the chain. If the audit passes, step S2 is executed. If the audit fails, step S10 is executed.
[0316] like Fig. 9 , the step S9 includes the following steps:
[0317] S9.1, Lincao Cloud Platform executes and generates audit notifications: The independent audit notification attribute generation strategy executed by Lincao Cloud Platform generates audit notifications;
[0318] Audit notification is an attribute-based access control request, which consists of audit subject attributes, audit object attributes, permission attributes, and environment attributes. For the forest and grassland IoT system, the audit subject attributes are the audit organization and audit client information, and the symmetric encryption algorithm and key used to encrypt the return data of the audit object are generated. The object attributes are the forest and grassland communication relay and / or forest and grassland perception terminal. The permission attributes are the operation permissions of the forest and grassland cloud platform to the forest and grassland communication relay and / or forest and grassland perception terminal. The environment attributes are the environment information when the independent audit is generated.
[0319] The audit subject attributes are the audit organization and audit client information, such as client IP, client port number, client account, encryption algorithm, and symmetric key. {Client IP: 192.168.8.106, client port number: 5058, client account: auditadmin, encryption algorithm: SM4, symmetric key: Sa@123456}.
[0320] The object attributes are forest and grass communication relay and / or forest and grass perception terminal, such as device name, device type, device MAC and other information, which are stored in key-value pairs. {Device type: forest and grass communication relay, forest and grass communication relay location: Luhuo County, device name: Getwey101, device MAC: 23:e4:xx:xx:5f:k9, extended audit: yes, device type: forest and grass IoT terminal, terminal location: Luhuo County, device name: ALL, device MAC: ALL}.
[0321] The operations of permission attributes include read, write, and execute;
[0322] Environmental attributes include, but are not limited to, controlling the start time, end time, and initiator of the access session.
[0323] An audit notification initiated by the client with IP address 192.168.8.106 and the auditadmin audit account to audit all forest and grassland communication relays and forest and grassland perception terminals deployed in Luhuo County from 20:38 on April 2, 2021 to 20:38 on April 3, 2021 is as follows:
[0324] {"Action":"audit","Notice":{AS:{Client IP:192.168.8.106, Client user: auditadmin, Encryption algorithm: SM4, Symmetric key: Sa@123456}}, AO:{Device type: Lincao communication relay, Device location: Luhuo County, Device name: ALL, Device MAC: ALL, Extended audit: Yes, Device type: Lincao IoT terminal, Terminal location: Luhuo County, Device name: ALL, Device MAC: ALL}, AP:"read", AE:{Start time: 202104022038, End time: 202104032038, Initiator: auditadmin}}}.
[0325] S9.2, the Lincao Cloud Platform puts independent audit notification sessions on the chain: After the audit triggering conditions are met, the Lincao Cloud Platform generates an audit notification and distributes the audit notification to the Lincao communication relay and / or the Lincao perception terminal. The Lincao Cloud Platform client initiates a transaction for the audit notification distribution session, which is calculated through the blockchain network consensus algorithm to form a new block storage into the blockchain network, so as to achieve the immutability and traceability of the audit notification behavior;
[0326] S9.3, Lincao Cloud Platform uses ciphertext attribute encryption to encrypt audit notifications: Lincao Cloud Platform implements independent audit notification attribute encryption strategy and uses ciphertext attribute encryption to encrypt audit notifications;
[0327] Before encryption, (1) the certificate authority CA of the Lincao Cloud Platform initializes and generates the Lincao Cloud Platform system public key PK, system master key MK, and decryption key S of the audited device based on the attributes of the audited device.
[0328] (2) The independent audit organization of the Lincao Cloud Platform uses PK, MK and independent audit access control policy to encrypt the audit notification. Due to the small length of the ciphertext, the ciphertext attribute encryption method here uses the classic linear secret sharing matrix CP-ABE scheme, which is not described here. The independent audit access control policy here is determined by the audit object and the audit content. For example, if all IoT terminals in Luhuo County are audited, then the independent audit access control policy is "Device Type = Lincao IoT Terminal AND Terminal Location = Luhuo County AND Device Name = ALL". Due to the use of ciphertext attribute encryption, the Lincao Cloud Platform can control who can access the data and ensure that the independent audit organization of the Lincao Cloud Platform and the Lincao perception terminal can communicate encrypted without exposing the key.
[0329] S9.4, the Lincao cloud platform broadcasts the audit notification to the Lincao communication relay: the Lincao cloud platform executes and sends the encrypted audit notification ciphertext to the Lincao communication relay in the next data collection cycle;
[0330] The audit notification here is encrypted using the CP-ABE scheme. The audit notification content can only be decrypted and obtained when the attributes of the audited device meet the access policy of CP-ABE.
[0331] S9.5, the forestry communication relay decrypts the audit notice and conducts an independent audit according to the audit notice requirements: the forestry communication relay uses the forestry cloud platform system public key to obtain the current forestry communication relay attributes and private key, and decrypts the audit notice ciphertext. If the forestry communication relay attributes meet the access policy of the audit notice ciphertext, the ciphertext is decrypted and the audit notice content is obtained;
[0332] S9.6, the forest and grassland perception terminal decrypts the audit notification and conducts an independent audit according to the audit notification requirements: the forest and grassland communication relay uses the forest and grassland cloud platform system public key to obtain the attributes and private key of the current forest and grassland perception terminal, and decrypts the audit notification ciphertext. If the attributes of the forest and grassland perception terminal meet the access policy of the audit notification ciphertext, the ciphertext is decrypted and the audit notification content is obtained. The audit notification content is executed to form audit data and submitted to the forest and grassland communication relay;
[0333] S9.7, Forestry and grassland communication relay submits audit data according to the audit notice requirements: Forestry and grassland communication relay, according to the audit notice requirements, encrypts the data collected by the local forestry and grassland sensing terminals and the data stored locally and transmits it back to the forestry and grassland cloud platform for audit;
[0334] S9.8, Lincao Cloud Platform Lincao Communication Relay Audit Response Session on Chain: Lincao Cloud Platform Client Lincao Communication Relay Audit Response Session initiates a transaction, which is calculated through the blockchain network consensus algorithm to form a new block storage and enter the blockchain network, so as to achieve the immutability and traceability of the Lincao Communication Relay Audit Response behavior;
[0335] S9.9, Lincao Cloud Platform decrypts the audit return data and conducts comparative audit: The audit organization client of Lincao Cloud Platform uses a symmetric key to decrypt the return data to obtain the audit data, and then reads the historical data of the audited device from the blockchain network, and conducts comparative audit on the historical data and the audit data;
[0336] S9.10, Lincao Cloud Platform conducts independent audit and gives audit results: Lincao Cloud Platform implements independent audit and detection strategy to detect the integrity and authenticity of current and previous data. If the audit data returned by the audit device is inconsistent with the historical data in the blockchain network, then execute step S10;
[0337] S9.11, Lincao Cloud Platform independent audit successfully completes the session on-chain: The Lincao Cloud Platform client will initiate a transaction for the successful completion of the audit session, and after calculation through the blockchain network consensus algorithm, a new block will be formed and stored in the blockchain network, making the audit results and behaviors tamper-proof and traceable;
[0338] S9.12, Lincao Cloud Platform records and stores audit sessions and results: Lincao Cloud Platform calls the independent audit results storage strategy to store the audit data and audit results obtained by local audits into the database.
[0339] S10, the forest and grassland security situation awareness system performs security situation awareness: the forest and grassland security situation awareness system stores the information record of the failed access session into the blockchain network, reads the historical access session records in the blockchain network, evaluates the number of accesses and access status of the current client and forest and grassland communication relay, determines whether it has been attacked and takes corresponding measures to prevent the attack; then executes step S7.
[0340] like Fig.10 , the step S10 includes the following steps:
[0341] S10.1. Conduct security situation awareness and emergency disposal when identity authentication fails: When identity authentication fails, the client of the Lincao Cloud Platform calls the identity authentication failure session chain strategy to record the identity authentication access session failure information into the blockchain network; and calls the security situation awareness strategy to read the historical access session records in the blockchain network, evaluate the number of accesses of the current client and the Lincao communication relay to determine whether there is a DOS attack. If the access IP and / or access port exceeds the access upper limit threshold, call the security threat emergency disposal strategy to urgently close the current access IP and / or access port to prevent the DOS attack;
[0342] S10.2, conduct security situation awareness and emergency disposal when access control fails: When access control or decryption fails, the Lincao cloud platform calls the access control failure session chain strategy, initiates a transaction for the access control failure session sent by the Lincao communication relay, calculates through the blockchain network consensus algorithm, forms a new block storage into the blockchain network, and realizes the tamper-proof and traceability of access behavior; and calls the security situation awareness strategy, reads the historical access session records in the blockchain network, evaluates the number of accesses of the current client and Lincao communication relay to determine whether there is a DOS attack, and if the access IP and / or access port exceeds the access upper limit threshold, calls the security threat emergency disposal strategy of the security situation awareness smart contract to urgently close the current access IP and / or access port to prevent DOS attacks;
[0343] S10.3, conduct security situation awareness and emergency disposal when integrity detection fails: if data integrity detection fails, the client of the Lincao cloud platform calls the integrity detection failure session chain strategy, initiates a transaction with the integrity detection failure session sent by the Lincao communication relay, and calculates through the blockchain network consensus algorithm to form a new block storage into the blockchain network, so as to achieve the tamper-proof and traceable access behavior;
[0344] The server side of the Lincao Cloud Platform executes the DOS attack monitoring strategy. The Lincao Cloud Platform queries the Lincao perception terminals that failed the data integrity test in the blockchain network, obtains the number of failed accesses to the Lincao perception terminals for this request, and determines whether the number of failed accesses exceeds the specified threshold. If so, it is determined that there is a DOS attack threat, triggering the security threat emergency disposal strategy.
[0345] S10.4. If the independent audit fails, conduct security situation awareness and emergency disposal: If the independent audit result verification fails, the Lincao Cloud Platform client will end the audit failure session and initiate a transaction. Through the blockchain network consensus algorithm, a new block will be calculated and stored in the blockchain network to achieve the unalterability and traceability of the audit failure behavior. Based on the audit results, Lincao Cloud Platform will execute the security situation awareness smart contract disposal strategy and make rectifications to the audit results.
[0346] When the audit result is: the audit fails, it is suspected that the Lincao Cloud platform has been attacked, and the focus is on denial of service attacks and internal attacks. Execute the DOS attack monitoring strategy of the security situation awareness smart contract to check whether the access IP and / or access port exceeds the access upper limit threshold. If not, focus on screening internal attacks.
[0347] When the audit result is: the audit fails, it is suspected that the Lincao cloud platform has been attacked, and the focus is on injection attacks and internal attacks. Execute the injection attack detection strategy of the security situation awareness smart contract to check whether there is false data injection attack in the Lincao communication relay and / or Lincao perception terminal. The mainstream methods include Kalman filter, deep learning, and neural network, which are not described here. No, focus on screening internal attacks.
[0348] When the audit result is: audit failed, it is suspected that the forestry and grassland IoT device has been attacked, and the focus is on device hijacking. Investigators will check on-site whether the forestry and grassland IoT device is currently lost or damaged.
[0349] When the audit result is: audit failed, suspected physical attack on forestry and grassland IoT devices, focus on physical damage attack and equipment failure. Investigators will check on-site whether the forestry and grassland IoT devices are currently lost or damaged.
[0350] like Figure 1 , the forest and grassland safety situation awareness system includes:
[0351] Blockchain creation, smart contract definition and system initialization module: used to initialize the blockchain network, complete identity authentication, access control, independent audit, integrity detection smart contract definition and chain code installation, and complete the initialization of the forest and grassland Internet of Things system;
[0352] Forestry and Grassland Communication Relay Identity Authentication Module: It is used by the Forestry and Grassland Cloud Platform client to call the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the Forestry and Grassland Communication Relay, and perform static identity authentication and continuous dynamic identity authentication on the Forestry and Grassland Communication Relay;
[0353] Attribute-based data encryption access control request generation module: used to use the periodic operation configuration of the forest and grassland communication relay to generate the subject attributes of the forest and grassland communication relay, combine the public key of the forest and grassland cloud platform system, use the forest and grassland communication relay key policy attribute-based data encryption policy, encrypt the forest and grassland perception terminal data collected in the forest and grassland communication relay to form ciphertext, and initiate a data transmission attribute access request to the forest and grassland cloud platform;
[0354] Attribute-based data encryption access control request verification module: used to verify whether the attributes of the forest-grass communication relay have passed the verification in combination with the simulated calculated attributes of the forest-grass communication relay subject;
[0355] Server-side data integrity detection module: used by the forestry and grassland cloud platform to decrypt and obtain the spatial data fingerprint submitted by the forestry and grassland perception terminal, and compare it with the spatial data fingerprint initialized and stored in the blockchain, to verify that the forestry and grassland Internet of Things has completed the data integrity detection and returned the detection results.
[0356] Triggering audit judgment module: used by the Lincao Cloud Platform to determine whether the independent audit start conditions are triggered by executing the independent audit smart contract;
[0357] Independent audit notification generation and encrypted broadcast module: used for the forestry cloud platform to generate independent audit notifications, encrypt the independent audit notifications using ciphertext attribute encryption, and broadcast the ciphertext of the independent audit notifications from the forestry cloud platform to the forestry communication relay in the next data collection cycle;
[0358] Audit device returns audit result verification module: used for the Lincao Cloud Platform to decrypt the returned audit data and compare it with the historical data stored in the blockchain network, and complete data integrity and system security detection by judging the consistency of the data;
[0359] Forestry and Grassland IoT Security Situation Awareness and Emergency Response Module: It is used by the forestry and grassland cloud platform to store the failed access session information records into the blockchain network, read the historical access session records in the blockchain network, evaluate the access times and access status of the current client and forestry and grassland communication relay, determine whether it is attacked, and take corresponding measures to prevent the attack.
[0360] like Figure 1 , the forest and grassland Internet of Things application system includes:
[0361] The periodic operation module of the forest and grassland IoT system is used for the forest and grassland IoT system to wake up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, complete data collection, aggregation and transmission, and sleep after completion to wait for the next data collection cycle;
[0362] Attribute-based encrypted data decryption module: used by the forestry cloud platform to decrypt the ciphertext transmitted by the forestry IoT using the key associated with the access structure, and transmit the successfully decrypted data through the forestry communication relay;
[0363] Forest and grassland perception terminal identity authentication module: used for forest and grassland communication relay to receive and store the identity authentication access session information of forest and grassland perception terminals according to the downloaded local periodic operation configuration policy, and then generate the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal in combination with the periodic security perception configuration policy, complete static identity authentication and continuous dynamic identity authentication, and store the data collected by the forest and grassland perception terminal locally;
[0364] The sensor-end spatial data fingerprint database generation module is used for the sensor-end of the forest and grass cloud platform to perform spatial data feature extraction and spatial data fingerprint generation, generate the sensor-end fingerprint database, and then send a data integrity detection request and the sensor-end fingerprint database to the forest and grass cloud platform server;
[0365] Forestry and grassland communication relay audit module: used for forestry and grassland communication relay to decrypt the ciphertext of independent audit notification. When the forestry and grassland communication relay attributes meet the independent audit notification access policy, the ciphertext is decrypted to obtain the content of the independent audit notification, and independent audit is carried out according to the requirements of the independent audit notification and the audit data is returned.
[0366] Extended audit module for forest and grassland perception terminals: used for forest and grassland perception terminals to receive and decrypt independent audit notifications issued by forest and grassland communication relays when independent audit notifications require extended audits. When the attributes of forest and grassland perception terminals meet the access policy of independent audit notifications, the ciphertext is decrypted to obtain the content of independent audit notifications, and independent audits are carried out and audit data is returned in accordance with the requirements of independent audit notifications.
[0367] The module for uploading access sessions to the forest and grassland cloud platform is used for the client of the forest and grassland cloud platform to upload the access request sessions and access request result sessions of the forest and grassland sensing terminal and the forest and grassland communication relay to the chain.
[0368] Data storage and download module: used by the forestry and grassland cloud platform client to submit the forestry and grassland communication relay to store the transmitted data into the internal resource database, and to send the server-side periodic operation configuration and data acquisition.
[0369] In order to better understand the technical solution of the present invention, an embodiment of the execution process of the zero-trust forest and grassland Internet of Things system based on blockchain of the present invention is provided as follows: Fig.11 :
[0370] (1) The system administrator executes the blockchain creation, smart contract definition and system initialization modules, creates a blockchain network in the forestry and grassland cloud platform, completes the smart contract definition and chain code installation, and completes the initialization of the forestry and grassland Internet of Things system.
[0371] (2) The forest and grassland Internet of Things system executes the periodic operation module of the forest and grassland Internet of Things system. According to the configured periodic operation strategy, it wakes up the forest and grassland communication relay and forest and grassland perception terminal at fixed intervals to complete data collection, aggregation and transmission. After completion, it goes into sleep mode and waits for the next data collection cycle.
[0372] (3) After the forestry and grassland communication relay is awakened according to the periodic operation configuration, the forestry and grassland communication relay executes the forestry and grassland communication relay identity authentication module and initiates an identity authentication session to the forestry and grassland cloud platform.
[0373] (4) After the forest-grassland communication relay is awakened according to the periodic operation configuration, the forest-grassland perception terminal executes the forest-grassland perception terminal identity authentication module and initiates an identity authentication session to the forest-grassland communication relay.
[0374] (5) The forest and grassland perception terminal executes the perception terminal spatial data fingerprint database generation strategy to generate the perception terminal fingerprint database.
[0375] (6) The forestry and grassland communication relay executes the attribute-based data encryption access control request generation module and initiates a data transmission attribute-based data encryption access control request to the forestry and grassland cloud platform.
[0376] (7) The forestry and grassland cloud platform executes the attribute-based data encryption access control request verification module to verify whether the attributes of the forestry and grassland communication relay have passed the verification.
[0377] (8) The forestry and grassland cloud platform executes the attribute-based encrypted data decryption module to decrypt the ciphertext transmitted by the forestry and grassland Internet of Things.
[0378] (9) The Lincao Cloud Platform executes the server-side data integrity detection module to obtain the data integrity detection results.
[0379] (10) The Lincao Cloud Platform executes the Lincao Cloud Platform access session chain module to chain the client access request session and access request result session.
[0380] (11) The forestry and grassland cloud platform executes the data storage and download module, stores the submitted transmission data into the internal resource database, and sends the server-side periodic operation configuration and data acquisition.
[0381] (12) The Lincao Cloud Platform executes the trigger audit judgment module to determine whether the independent audit start condition is triggered. If yes, proceed to step (13); if no, proceed to step (2)
[0382] (13) The Lincao Cloud Platform executes the independent audit notification generation and encryption broadcast module to generate, encrypt and broadcast independent audit notifications to the audited devices.
[0383] (14) Forestry and grassland communication relays shall implement the forestry and grassland communication relay audit module and conduct forestry and grassland communication relay audits in accordance with the requirements of the independent audit notice.
[0384] (15) The forest and grassland perception terminal implements the extended audit module of the forest and grassland perception terminal and conducts the audit of the forest and grassland perception terminal in accordance with the requirements of the independent audit notice.
[0385] (16) The Lincao Cloud Platform executes the verification of the audited device returning the audit result module to verify the data integrity and system security.
[0386] (17) The Forestry and Grassland Cloud Platform executes the security situation awareness and emergency response module, and performs security situation awareness and emergency response according to the type of access results.
[0387] (18) Determine whether the monitoring is finished. If not, execute step (2); if yes, terminate the process.
[0388] For ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention, and these improvements and modifications should also be considered as the scope of protection of the present invention.
Claims
1. A blockchain-enabled zero-trust forest and grassland IoT security protection method, characterized in that: This is achieved through the forest and grass cloud platform, which includes: Forestry and grassland IoT application system: used to receive reports and return data and requests from forestry and grassland communication relays, convert them into access sessions, store them in the blockchain, and submit them to the forestry and grassland security situation awareness system. According to the results returned by the forestry and grassland security situation awareness system, the forestry and grassland communication relays can access internal resources securely. Forestry and grassland security situation awareness system: used to receive forestry and grassland IoT application system sessions and combine internal resources through smart contracts to decide whether to authorize the submitted request sessions, and judge the current security situation based on the current status of the forestry and grassland IoT system, and whether to conduct an independent audit; Cloud platform: Cloud platform resources and application platform used to support the forest and grassland Internet of Things application system and forest and grassland security situation awareness system, providing system operating conditions and basic software and hardware environment; The blockchain-enabled zero-trust forest and grassland IoT system security protection method includes the following steps: S1, blockchain creation, smart contract definition and system initialization: complete the definition and chain code installation of identity authentication smart contract, access control smart contract, integrity detection smart contract, independent audit smart contract, security situation awareness smart contract, and initialize the equipment registration information of the Lincao Cloud Platform, and generate spatial data fingerprint and key system; S2, periodic operation of the forest and grassland IoT system: The forest and grassland IoT system wakes up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then sleeps and waits for the next data collection cycle; S3, the forest and grassland security situation awareness system performs identity authentication: the forest and grassland security situation awareness system calls the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay, and performs static identity authentication and continuous dynamic identity authentication on the forest and grassland communication relay; the forest and grassland communication relay generates the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal according to the periodic operation configuration strategy, and completes the static identity authentication and continuous dynamic identity authentication for the forest and grassland perception terminal. If the authentication is passed, execute step S4, if not, execute step S10; S4, the forest and grassland security situation awareness system performs dynamic access control: the forest and grassland communication relay uses the key policy attribute-based encryption method to encrypt the forest and grassland communication relay data to form a ciphertext and initiate a data transmission attribute access request to the forest and grassland cloud platform. The forest and grassland security situation awareness system calls the dynamic access control smart contract to calculate the multi-dimensional subject attributes of the forest and grassland communication relay, decrypts and verifies whether the attributes of the forest and grassland communication relay have passed the verification, completes the dynamic access control and returns the access result. If it passes the verification, execute step S5, if it fails the verification, execute step S10; S5, the forest and grassland safety situation awareness system performs integrity detection: the forest and grassland safety situation awareness system compares the spatial data fingerprint submitted by the forest and grassland perception terminal obtained by decryption with the spatial data fingerprint initialized and stored in the blockchain, and completes the forest and grassland IoT data integrity detection and returns the detection result. If the detection passes, step S6 is executed, if not, step S10 is executed; S6, the forestry cloud platform submits data and returns access results: the forestry communication relay sends the collected monitoring data to the forestry cloud platform, and the forestry IoT application system connects to the internal resource database to complete the data storage, returns the periodic operation configuration and periodic operation strategy, and waits for the next data collection cycle; S7, determine whether the monitoring is finished, if not, execute step S8, if yes, terminate the process; S8, determine whether to trigger an independent audit: the forest and grassland safety situation awareness system determines whether the independent audit start condition is triggered by executing the independent audit smart contract. If so, execute step S9; if not, execute step S2; S9, the forest and grassland safety situation awareness system performs independent auditing: the forest and grassland safety situation awareness system generates an independent audit notification and encrypts and broadcasts it. The audited device receives the audit notification, conducts the audit and returns the audit data. The forest and grassland safety situation awareness system verifies the returned audit data and stores the audit session and audit results on the chain. If the audit passes, step S2 is executed. If the audit fails, step S10 is executed. S10, the forest and grassland security situation awareness system performs security situation awareness: the forest and grassland security situation awareness system stores the information record of the failed access session into the blockchain network, reads the historical access session records in the blockchain network, evaluates the number of accesses and access status of the current client and forest and grassland communication relay, determines whether it has been attacked and takes corresponding measures to prevent the attack; then executes step S7.
2. According to claim 1, the blockchain-enabled zero-trust forest and grassland IoT system security protection method is characterized in that: The step S1 includes the following steps: S1.1, blockchain network creation and initialization; S1.2, identity authentication smart contract definition and chain code installation, where the identity authentication smart contract includes the forestry perception terminal, forestry communication relay and forestry cloud platform to perform identity authentication access session chain operation strategy and identity authentication operation strategy in the blockchain network, and the chain code is installed through the forestry cloud platform server; S1.3, access control smart contract definition and chain code installation, where the access control smart contract includes the access control access session chain operation strategy and dynamic access control operation strategy in the blockchain network by the Lincao communication relay and the Lincao cloud platform, and the chain code is installed through the Lincao cloud platform server; S1.4, independent audit smart contract and chain code installation, where the independent audit smart contract includes the independent audit session chain operation strategy and independent audit operation strategy carried out by the Lincao Cloud Platform in the blockchain network, and the chain code is installed through the Lincao Cloud Platform server; S1.5, data integrity detection smart contract and chain code installation, where the data integrity detection smart contract includes the data integrity detection access session chain operation strategy and integrity detection operation strategy in the blockchain network by the Lincao communication relay and the Lincao cloud platform, and the chain code is installed through the Lincao cloud platform server; S1.6, security situation awareness smart contract definition and chain code installation, where the security situation awareness smart contract includes the data exchange operation strategy for the forest and grassland perception terminal, forest and grassland communication relay and forest and grassland cloud platform to access internal data through identity authentication, access control and integrity detection, as well as the security situation awareness operation strategy initiated in the blockchain network when it fails; S1.7, initialization of the forest and grassland Internet of Things system, including initialization of forest and grassland Internet of Things device information registration, initialization of generation of spatial data fingerprint, initialization of key policy attribute-based encryption scheme and key generation.
3. According to claim 2, the blockchain-enabled zero-trust forest and grassland IoT system security protection method is characterized in that: The identity authentication access session chain operation strategy at least includes a login session chain strategy, an identity authentication session chain strategy, an identity authentication failure session chain strategy and a data transmission session chain strategy; The identity authentication operation strategy includes at least a static physical fingerprint generation strategy, a static identity authentication strategy, a multi-dimensional dynamic feature fingerprint generation strategy and a continuous dynamic identity authentication strategy; The access control access session operation policy at least includes a data transmission session chaining policy, an operation policy download access session chaining policy and an access control failure session chaining policy; The dynamic access control strategy at least includes a forest and grassland communication relay subject attribute generation strategy, a forest and grassland communication relay subject multi-dimensional dynamic attribute calculation strategy, a forest and grassland communication relay data transmission attribute access request generation strategy, a forest and grassland cloud platform key policy attribute base encryption initialization strategy, a forest and grassland cloud platform access control tree structure key generation strategy, a forest and grassland communication relay key policy attribute base data encryption strategy, a forest and grassland cloud platform key policy attribute base data decryption strategy and a forest and grassland communication relay collected data transmission storage access control verification strategy; The independent audit session chain operation strategy at least includes an independent audit notification session chain strategy, a forestry communication relay audit reply session chain strategy, an independent audit successful completion session chain strategy, and an independent audit failure end session chain strategy; The independent audit operation strategy at least includes an independent audit start decision strategy, an independent audit notification attribute generation strategy, an independent audit notification attribute encryption strategy, an independent audit notification attribute broadcast strategy and an independent audit detection strategy; The data integrity detection session chain operation strategy includes a fingerprint cloud database generation session chain strategy, a fingerprint cloud database chain session chain strategy, a client data integrity detection request session chain strategy, a data integrity detection failure session chain strategy and a data integrity detection execution result session chain strategy; The integrity detection operation strategy at least includes a spatial data feature extraction strategy, a spatial data fingerprint generation strategy, a fingerprint cloud database generation strategy, a fingerprint cloud database chain strategy, a spatial data fingerprint comparison and detection strategy, a data integrity detection result generation strategy, and a data integrity detection result chain strategy; The data exchange operation strategy at least includes the device registration information storage strategy, the forest and grassland communication relay periodic operation configuration download strategy, the forest and grassland communication relay collected data transmission storage strategy, the independent audit results storage strategy and the data integrity test result return strategy; The security situation awareness operation strategy at least includes a security situation awareness strategy, a security threat emergency disposal strategy, a DOS attack monitoring strategy and an injection attack detection strategy.
4. According to claim 3, the blockchain-enabled zero-trust forest and grassland IoT system security protection method is characterized in that: The specific steps of step S1.7 are as follows: S1.7.1, Initialize the registration of forest and grassland IoT device information: Use the static physical fingerprint generation strategy to form the static physical fingerprint of the device based on the registration information and static password, and then use the device registration information storage strategy to upload the device registration and device registration information into a new block to the blockchain network to complete the registration of forest and grassland IoT devices; S1.7.2, Initialize and generate spatial data fingerprint: The server of the forest and grass cloud platform calls the spatial data feature strategy to extract the spatial features and attribute features of the spatial vector data in the internal resource database of the server, executes the spatial data fingerprint generation strategy to obtain the spatial data fingerprint, and after calculation through the blockchain network consensus algorithm, forms a new block storage and enters the blockchain network, so as to realize the immutability and traceability of the fingerprint cloud database chain session; S1.7.3, Key policy attribute-based encryption scheme initialization and key generation: The Lincao Cloud Platform client calls the Lincao Cloud Platform key policy attribute-based encryption initialization strategy, generates the system public key and system master key based on the attribute-based encryption mechanism of the key policy, calls the Lincao Cloud Platform access control tree structure key generation strategy, and calculates the decryption key of the Lincao Cloud Platform client user based on the system master key and the user attribute set.
5. According to claim 1, the blockchain-enabled zero-trust forest and grassland IoT system security protection method is characterized in that: The step S2 includes the following steps: S2.1, the first deployment of forest and grassland communication relay initiates identity authentication session; S2.2, mobile data collection terminal connection and configuration of forest and grassland communication relay; S2.3, the forest and grassland Internet of Things system operates periodically.
6. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 3 is characterized in that: The step S3 includes the following steps: S3.1, create a static physical fingerprint of the forest and grass communication relay and perform static identity authentication: the forest and grass cloud platform client calls the static physical fingerprint generation strategy, generates the static physical fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the forest and grass cloud platform client, and then obtains the static physical fingerprint of the forest and grass communication relay last accessed in the blockchain platform, and calls the static identity authentication strategy to perform static identity authentication; S3.2, create a multi-dimensional dynamic feature fingerprint of the forest and grass communication relay and perform dynamic identity authentication: the forest and grass cloud platform client calls the multi-dimensional dynamic feature fingerprint generation strategy, generates the multi-dimensional dynamic feature fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the forest and grass cloud platform client, and then obtains the multi-dimensional dynamic feature fingerprint of the forest and grass communication relay last accessed in the blockchain platform, calls the continuous dynamic identity authentication strategy to compare the two pieces of information and returns the identity authentication result; S3.3, Lincao communication relay identity authentication result session upload to blockchain network: Lincao cloud platform client calls the identity authentication session chain strategy, records the session information into the blockchain network, and calls the device registration information storage strategy to add and update the device access registration information of the current Lincao communication relay into the database; S3.4, the forest-grass communication relay receives and stores the identity authentication access session information of the forest-grass perception terminal: the forest-grass communication relay receives the identity access request of the forest-grass perception terminal, obtains the identity authentication session parameters of the forest-grass perception terminal, and stores them locally in the forest-grass communication relay; S3.5, the forest and grassland communication relay creates a static physical fingerprint of the forest and grassland perception terminal and performs static identity authentication: the forest and grassland communication relay generates a static physical fingerprint for accessing the forest and grassland perception terminal based on the static physical fingerprint generation strategy stored locally, calls the static identity authentication strategy, and compares it with the static physical fingerprint of the forest and grassland perception terminal stored locally; S3.6, the forestry and grassland communication relay creates a multi-dimensional dynamic feature fingerprint of the forestry and grassland perception terminal and performs dynamic identity authentication: the forestry and grassland communication relay calculates and generates a multi-dimensional dynamic feature fingerprint based on the multi-dimensional dynamic feature fingerprint generation strategy stored locally, for the identity authentication session parameters of the forestry and grassland perception terminal obtained, as well as the identity authentication session parameters of the last forestry and grassland perception terminal obtained from the blockchain network when the forestry and grassland communication relay is initialized and stored locally, and uses the continuous dynamic identity authentication strategy stored locally to compare and authenticate the two multi-dimensional dynamic feature fingerprints of the forestry and grassland perception terminal.
7. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 6 is characterized in that: The step S4 includes the following steps: S4.1, encryption of forest and grassland communication relay data collected by key policy attribute-based encryption mechanism: the forest and grassland communication relay uses the forest and grassland communication relay subject attributes and the forest and grassland cloud platform system public key, calls the forest and grassland communication relay key policy attribute-based data encryption strategy, and encrypts the forest and grassland perception terminal data collected in the forest and grassland communication relay to form ciphertext; S4.2, the forest and grassland communication relay initiates a data transmission attribute access request to the forest and grassland cloud platform: the forest and grassland communication relay uses the forest and grassland communication relay data transmission attribute access request generation strategy downloaded to the local forest and grassland communication relay periodic operation configuration, combines the forest and grassland communication relay subject attributes to generate a forest and grassland communication relay data transmission attribute access request, and sends a forest and grassland communication relay data transmission attribute access request session to the forest and grassland cloud platform; S4.3, Lincao Cloud Platform uploads the data transmission session of Lincao Communication Relay to the blockchain network: Lincao Cloud Platform calls the data transmission session chain strategy, initiates a transaction for the data transmission session access request session sent by Lincao Communication Relay, and forms a new block storage into the blockchain network after calculation through the blockchain network consensus algorithm, so as to realize the tamper-proof and traceable access behavior; S4.4, the forestry cloud platform calculates the multi-dimensional dynamic attributes of the forestry communication relay: the forestry cloud platform calls the multi-dimensional dynamic attribute calculation strategy of the forestry communication relay subject, obtains the forestry communication relay subject attributes stored in the last access session in the blockchain network, uses the physical model to simulate and calculate the multi-dimensional dynamic attributes, and simulates and calculates the forestry communication relay subject attribute values of this access session; S4.5, the forestry cloud platform performs access control verification on the forestry communication relay data transmission: the forestry cloud platform calls the forestry communication relay collection data transmission storage access control verification strategy, and verifies the forestry communication relay subject attributes of the current session in combination with the simulated calculated forestry communication relay subject attribute values; S4.6, Lincao Cloud Platform Key Policy Attribute Base Data Decryption: Lincao Cloud Platform calls the Lincao Cloud Platform Key Policy Attribute Base Data Decryption Strategy, and uses the key related to the access structure assigned to the Lincao Cloud Platform client user when the Lincao Cloud Platform is initialized to perform decryption operations. The decryption is successful when the attributes in the ciphertext satisfy the access control tree.
8. According to claim 7, the blockchain-enabled zero-trust forest and grassland IoT system security protection method is characterized in that: The sensing end of the forest and grass cloud platform is used to collect, process and interact with spatial data. Step S5 includes the following steps: S5.1, forest and grassland perception terminal obtains spatial data fingerprint database generation strategy: the forest and grassland perception terminal accesses the forest and grassland cloud platform client or blockchain network to obtain spatial data feature extraction strategy, spatial data fingerprint generation strategy and fingerprint database generation strategy; S5.2, spatial data feature extraction of forest and grassland perception terminal: For the spatial database used for data integrity detection, the forest and grassland perception terminal locally executes the spatial data feature extraction strategy to obtain the spatial features and attribute features of the spatial vector data in the perception terminal spatial database; S5.3, spatial data fingerprint generation at the perception end: The perception end of the forest and grassland cloud platform obtains spatial data with spatial features and attribute features for data integrity detection, executes the spatial data fingerprint generation strategy, and obtains the spatial data fingerprint of the spatial database of the perception end of the forest and grassland cloud platform; S5.4, generation of fingerprint cloud database of perception end: the perception end of the forest and grass cloud platform obtains the spatial data with spatial data fingerprint for data integrity detection, executes the fingerprint cloud database generation strategy, and obtains the fingerprint database of the perception end of the forest and grass cloud platform; S5.5, the sensing end sends a data integrity detection request and a sensing end fingerprint database: the sensing end of the forest and grass cloud platform sends a data integrity detection request to the forest and grass cloud platform client, and submits the sensing end fingerprint database to complete the data integrity detection; S5.6, the perception terminal data integrity detection request session is uploaded to the chain: the forest and grassland cloud platform client executes the fingerprint cloud database to generate the session on-chain strategy, and the forest and grassland cloud platform client initiates the client data integrity detection request session transaction, which is calculated through the blockchain network consensus algorithm to form a new block storage and enter the blockchain network, so as to realize the tamper-proof and traceability of the forest and grassland perception terminal data submission and data integrity detection behavior; S5.7, server-side spatial data fingerprint comparison and detection: The server-side of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint comparison and detection strategy, takes the sensor terminal fingerprint database submitted for detection by the sensor terminal of the Forestry and Grassland Cloud Platform as input, obtains the fingerprint cloud database from the blockchain network, and compares the spatial data fingerprint of the sensor terminal fingerprint database with the spatial data fingerprint of the fingerprint cloud database through attribute query comparison, and marks the inconsistent spatial data fingerprints; S5.8, the server side obtains the data integrity test result: the server side of the forest and grass cloud platform executes the spatial data fingerprint test result generation strategy, and stores the spatial data fingerprints marked as inconsistent separately to form a data integrity test result database; S5.9, Data integrity test results are uploaded to the blockchain: The client of the Lincao Cloud Platform executes the data integrity test results upload strategy, initiates a transaction with all records in the data integrity test results database, and forms a new block after calculation through the blockchain network consensus algorithm to store it in the blockchain network, thus achieving the data integrity test results database data that cannot be tampered with and can be traced; S5.10, data integrity check execution result session chaining: The Lincao Cloud Platform client executes the data integrity check execution result session chaining strategy, initiates a transaction on the server-side data integrity check execution result session, and after calculation through the blockchain network consensus algorithm, forms a new block storage and enters the blockchain network, thereby achieving the tamper-proof and traceability of data integrity detection behavior.
9. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 8 is characterized in that: The step S6 includes the following steps: S6.1, the forest and grass communication relay downloads the periodic operation configuration of the forest and grass communication relay: the forest and grass communication relay uses the forest and grass communication relay periodic operation configuration download strategy to read and download the forest and grass Internet of Things periodic operation strategy configuration information in the forest and grass cloud platform database to the local forest and grass communication relay; S6.2, the forestry and grassland communication relay stores the data collected by the forestry and grassland perception terminal and sends down the periodic operation configuration: the forestry and grassland communication relay receives the authentication parameters and collected data transmitted by the forestry and grassland perception terminal, stores them in the forestry and grassland communication relay, and sends down the periodic operation policy of the locally stored forestry and grassland perception terminal to the forestry and grassland perception terminal. S6.3, the forest and grassland communication relay sends the collected data to the forest and grassland cloud platform: if the forest and grassland communication relay passes the identity authentication, access control, and data integrity test, it agrees to submit the data submitted by the perception end into the internal resource database of the server. If not, the data integrity test result database is returned to the perception end.
10. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 9 is characterized in that: The step S9 includes the following steps: S9.1, Lincao Cloud Platform executes and generates audit notifications: The independent audit notification attribute generation strategy executed by Lincao Cloud Platform generates audit notifications; S9.2, the Forestry and Grassland Cloud Platform puts the independent audit notification session on the chain: the audit notification is issued to the Forestry and Grassland Communication Relay and / or Forestry and Grassland Sensing Terminal, and the Forestry and Grassland Cloud Platform Client initiates the transaction of the audit notification issuance session, and calculates through the blockchain network consensus algorithm to form a new block storage into the blockchain network, so as to realize the tamper-proof and traceable audit notification behavior; S9.3, Lincao Cloud Platform uses ciphertext attribute encryption to encrypt audit notifications: Lincao Cloud Platform implements independent audit notification attribute encryption strategy and uses ciphertext attribute encryption to encrypt audit notifications; S9.4, the Lincao cloud platform broadcasts the audit notification to the Lincao communication relay: the Lincao cloud platform executes and sends the encrypted audit notification ciphertext to the Lincao communication relay in the next data collection cycle; S9.5, the forestry communication relay decrypts the audit notice and conducts an independent audit according to the audit notice requirements: the forestry communication relay uses the forestry cloud platform system public key to obtain the current forestry communication relay attributes and private key, and decrypts the audit notice ciphertext. If the forestry communication relay attributes meet the access policy of the audit notice ciphertext, the ciphertext is decrypted and the audit notice content is obtained; S9.6, the forest and grassland perception terminal decrypts the audit notification and conducts an independent audit according to the audit notification requirements: the forest and grassland communication relay uses the forest and grassland cloud platform system public key to obtain the attributes and private key of the current forest and grassland perception terminal, and decrypts the audit notification ciphertext. If the attributes of the forest and grassland perception terminal meet the access policy of the audit notification ciphertext, the ciphertext is decrypted and the audit notification content is obtained. The audit notification content is executed to form audit data and submitted to the forest and grassland communication relay; S9.7, Forestry and grassland communication relay submits audit data according to the audit notice requirements: Forestry and grassland communication relay, according to the audit notice requirements, encrypts the data collected by the local forestry and grassland sensing terminals and the data stored locally and transmits it back to the forestry and grassland cloud platform for audit; S9.8, Lincao Cloud Platform Lincao Communication Relay Audit Response Session on Chain: Lincao Cloud Platform Client Lincao Communication Relay Audit Response Session initiates a transaction, which is calculated through the blockchain network consensus algorithm to form a new block storage and enter the blockchain network, so as to achieve the immutability and traceability of the Lincao Communication Relay Audit Response behavior; S9.9, Lincao Cloud Platform decrypts the audit return data and conducts comparative audit: The audit organization client of Lincao Cloud Platform uses a symmetric key to decrypt the return data to obtain the audit data, and then reads the historical data of the audited device from the blockchain network, and conducts comparative audit on the historical data and the audit data; S9.10, Lincao Cloud Platform conducts independent audit and gives audit results: Lincao Cloud Platform implements independent audit and detection strategy to detect the integrity and authenticity of current and previous data. If the audit data returned by the audit device is inconsistent with the historical data in the blockchain network, then execute step S10; S9.11, Lincao Cloud Platform independent audit successfully completes the session on-chain: The Lincao Cloud Platform client will initiate a transaction for the successful completion of the audit session, and after calculation through the blockchain network consensus algorithm, a new block will be formed and stored in the blockchain network, making the audit results and behaviors tamper-proof and traceable; S9.12, Lincao Cloud Platform records and stores audit sessions and results: Lincao Cloud Platform calls the independent audit results storage strategy to store the audit data and audit results obtained by local audits into the database.
11. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 10 is characterized in that: The step S10 includes the following steps: S10.1, conduct security situation awareness and emergency disposal when identity authentication fails: when identity authentication fails, the client of the Lincao Cloud Platform calls the identity authentication failure session chain strategy to record the identity authentication access session failure information into the blockchain network; And call the security situation awareness strategy, read the historical access session records in the blockchain network, evaluate the access times of the current client and forest and grass communication relay to determine whether there is a DOS attack. If the access IP and / or access port exceeds the access upper limit threshold, call the security threat emergency disposal strategy to urgently close the current access IP and / or access port to prevent the DOS attack; S10.2, conduct security situation awareness and emergency disposal when access control fails: When access control or decryption fails, the Lincao cloud platform calls the access control failure session chain strategy, initiates a transaction for the access control failure session sent by the Lincao communication relay, calculates through the blockchain network consensus algorithm, forms a new block storage into the blockchain network, and realizes the tamper-proof and traceability of access behavior; and calls the security situation awareness strategy, reads the historical access session records in the blockchain network, evaluates the number of accesses of the current client and Lincao communication relay to determine whether there is a DOS attack, and if the access IP and / or access port exceeds the access upper limit threshold, calls the security threat emergency disposal strategy of the security situation awareness smart contract to urgently close the current access IP and / or access port to prevent DOS attacks; S10.3, conduct security situation awareness and emergency disposal when integrity detection fails: if data integrity detection fails, the client of the Lincao cloud platform calls the integrity detection failure session chain strategy, initiates a transaction with the integrity detection failure session sent by the Lincao communication relay, and calculates through the blockchain network consensus algorithm to form a new block storage into the blockchain network, so as to achieve the tamper-proof and traceable access behavior; The server side of the Lincao Cloud Platform executes the DOS attack monitoring strategy. The Lincao Cloud Platform queries the Lincao perception terminals that failed the data integrity test in the blockchain network, obtains the number of failed accesses to the Lincao perception terminals for this request, and determines whether the number of failed accesses exceeds the specified threshold. If so, it is determined that there is a DOS attack threat, triggering the security threat emergency disposal strategy. S10.
4. If the independent audit fails, conduct security situation awareness and emergency disposal: If the independent audit result verification fails, the Lincao Cloud Platform client will end the audit failure session and initiate a transaction. Through the blockchain network consensus algorithm, a new block will be calculated and stored in the blockchain network to achieve the unalterability and traceability of the audit failure behavior. Based on the audit results, Lincao Cloud Platform will execute the security situation awareness smart contract disposal strategy and make rectifications to the audit results.
12. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 11 is characterized in that: The forest and grassland safety situation awareness system includes: Blockchain creation, smart contract definition and system initialization module: used to initialize the blockchain network, complete identity authentication, access control, independent audit, integrity detection smart contract definition and chain code installation, and complete the initialization of the forest and grassland Internet of Things system; Forestry and Grassland Communication Relay Identity Authentication Module: It is used by the Forestry and Grassland Cloud Platform client to call the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the Forestry and Grassland Communication Relay, and perform static identity authentication and continuous dynamic identity authentication on the Forestry and Grassland Communication Relay; Attribute-based data encryption access control request generation module: used to use the periodic operation configuration of the forest and grassland communication relay to generate the subject attributes of the forest and grassland communication relay, combine the public key of the forest and grassland cloud platform system, use the forest and grassland communication relay key policy attribute-based data encryption policy, encrypt the forest and grassland perception terminal data collected in the forest and grassland communication relay to form ciphertext, and initiate a data transmission attribute access request to the forest and grassland cloud platform; Attribute-based data encryption access control request verification module: used to verify whether the attributes of the forest-grass communication relay have passed the verification in combination with the simulated calculated attributes of the forest-grass communication relay subject; Server-side data integrity detection module: used by the forestry and grassland cloud platform to decrypt and obtain the spatial data fingerprint submitted by the forestry and grassland perception terminal, and compare it with the spatial data fingerprint initialized and stored in the blockchain, to verify that the forestry and grassland Internet of Things has completed the data integrity detection and returned the detection results. Triggering audit judgment module: used by the Lincao Cloud Platform to determine whether the independent audit start conditions are triggered by executing the independent audit smart contract; Independent audit notification generation and encrypted broadcast module: used for the forestry cloud platform to generate independent audit notifications, encrypt the independent audit notifications using ciphertext attribute encryption, and broadcast the ciphertext of the independent audit notifications from the forestry cloud platform to the forestry communication relay in the next data collection cycle; Audit device returns audit result verification module: used for the Lincao Cloud Platform to decrypt the returned audit data and compare it with the historical data stored in the blockchain network, and complete data integrity and system security detection by judging the consistency of the data; Forestry and Grassland IoT Security Situation Awareness and Emergency Response Module: It is used by the forestry and grassland cloud platform to store the failed access session information records into the blockchain network, read the historical access session records in the blockchain network, evaluate the access times and access status of the current client and forestry and grassland communication relay, determine whether it is attacked, and take corresponding measures to prevent the attack.
13. The blockchain-enabled zero-trust forest and grassland IoT system security protection method according to claim 12 is characterized in that: The forest and grassland Internet of Things application system includes: The periodic operation module of the forest and grassland IoT system is used for the forest and grassland IoT system to wake up the forest and grassland communication relay and forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, complete data collection, aggregation and transmission, and sleep after completion to wait for the next data collection cycle; Attribute-based encrypted data decryption module: used by the forestry cloud platform to decrypt the ciphertext transmitted by the forestry IoT using the key associated with the access structure, and transmit the successfully decrypted data through the forestry communication relay; Forest and grassland perception terminal identity authentication module: used for forest and grassland communication relay to receive and store the identity authentication access session information of forest and grassland perception terminals according to the downloaded local periodic operation configuration policy, and then generate the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal in combination with the periodic security perception configuration policy, complete static identity authentication and continuous dynamic identity authentication, and store the data collected by the forest and grassland perception terminal locally; The sensor-end spatial data fingerprint database generation module is used for the sensor-end of the forest and grass cloud platform to perform spatial data feature extraction and spatial data fingerprint generation, generate the sensor-end fingerprint database, and then send a data integrity detection request and the sensor-end fingerprint database to the forest and grass cloud platform server; Forestry and grassland communication relay audit module: used for forestry and grassland communication relay to decrypt the ciphertext of independent audit notification. When the forestry and grassland communication relay attributes meet the independent audit notification access policy, the ciphertext is decrypted to obtain the content of the independent audit notification, and independent audit is carried out according to the requirements of the independent audit notification and the audit data is returned. Extended audit module for forest and grassland perception terminals: used for forest and grassland perception terminals to receive and decrypt independent audit notifications issued by forest and grassland communication relays when independent audit notifications require extended audits. When the attributes of forest and grassland perception terminals meet the access policy of independent audit notifications, the ciphertext is decrypted to obtain the content of independent audit notifications, and independent audits are carried out and audit data is returned in accordance with the requirements of independent audit notifications. The module for uploading access sessions to the forest and grassland cloud platform is used for the client of the forest and grassland cloud platform to upload the access request sessions and access request result sessions of the forest and grassland sensing terminal and the forest and grassland communication relay to the chain. Data storage and download module: used by the forestry and grassland cloud platform client to submit the forestry and grassland communication relay to store the transmitted data into the internal resource database, and to send the server-side periodic operation configuration and data acquisition.
Citation Information
Patent Citations
Internet of Things zero-trust system based on block chain and access method
CN114338701A
Zero-trust forestry Internet of Things management platform system and security protection method
CN117749533A
Cloud-side collaborative multi-mode private data circulation method based on smart contract
US20230041862A1