A Blockchain-Enabled Zero-Trust Security Protection Method for Forestry and Grassland Internet of Things
Through blockchain technology, static physical fingerprints and multi-dimensional dynamic feature fingerprints combined with attribute-based access control are implemented in forest and grass IoT systems, which solves the centralized risk and detection of untraceable problems of forest and grass IoT systems, and realizes low-cost, transparency and traceability security protection, and is suitable for forest and grass IoT systems in complex open environments.
Patent Information
- Application Number
- CN202510165610.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-02-14
AI Technical Summary
The forest and grass IoT system has high centralization risks, opaque detection processes, unretrospective results, difficult to effectively resist internal attacks, and high maintenance costs. It is difficult to detect long-term hidden attacks and false data injection in existing security models, resulting in decision-making errors or economic losses.
The zero-trust forest and grass IoT security protection method empowered by blockchain is adopted, and continuous authentication is carried out through static physical fingerprints and multi-dimensional dynamic feature fingerprints, combining attribute-based access control and independent audit mode to achieve dynamic fine-grained access control, data integrity detection and untampered transparency and traceability.
It realizes low-cost, decentralized, transparent and traceable security protection, effectively resists internal attacks, dynamically adjusts access control, reduces management complexity, improves system security and robustness, and is suitable for forest and grass Internet of Things systems in complex open environments.
Smart Images

Figure CN120017364B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things security, and particularly to a zero-trust forestry and grassland Internet of Things security protection method empowered by blockchain. Background Art
[0002] Compared with the power Internet of Things, vehicle Internet of Things, and industrial Internet of Things, the forestry and grassland Internet of Things has the industry particularity of "difficult terminal protection, difficult system maintenance, and difficult security protection" because the terminals are deployed in an open natural environment, and the probability of being attacked externally and breached is relatively high. At present, traditional security models such as static identity authentication based on passwords, centralized authorization, and access control lists have defects such as high maintenance costs and high centralized risks in the forestry and grassland Internet of Things. Moreover, due to the inability to effectively monitor the detection process, the detection process is opaque and the results are not traceable. If internal security threats such as internal personnel being turned against or account theft are superimposed, it will be very difficult to detect long-term covert attacks after being breached, and long-term false data injection or equipment damage will cause decision-making errors or inability to make decisions, resulting in huge economic and social losses.
[0003] In summary, there is an urgent need to provide a zero-trust forestry and grassland Internet of Things security protection method that is low-cost, decentralized, transparent, tamper-proof, traceable, can effectively resist internal attacks, and realizes the concept of "continuous verification, never trust". Summary of the Invention
[0004] The purpose of the present invention is to provide a zero-trust forestry and grassland Internet of Things security protection method that is low-cost, decentralized, transparent, tamper-proof, traceable, can effectively resist internal attacks, and realizes the concept of "continuous verification, never trust".
[0005] The above purpose is achieved through the following technical solutions: A zero-trust forestry and grassland Internet of Things security protection method empowered by blockchain, which is implemented through a forestry and grassland cloud platform. The forestry and grassland cloud platform includes:
[0006] Forestry and grassland Internet of Things application system: used to receive reports, return data, and requests from the forestry and grassland communication relay, convert them into access sessions, store them in the blockchain, and submit them to the forestry and grassland security situation awareness system, and execute the secure access of the forestry and grassland communication relay to internal resources according to the results returned by the forestry and grassland security situation awareness system;
[0007] Forestry and grassland security situation awareness system: used to receive sessions from the forestry and grassland Internet of Things application system, combine with internal resources through smart contracts, make decisions on whether to authorize the submitted request sessions, judge the current security situation based on the current state of the forestry and grassland Internet of Things system, and whether to conduct independent audits;
[0008] Cloud platform: a cloud platform resource and application platform that supports the forestry and grassland Internet of Things application system and the forestry and grassland security situation awareness system, providing system operation conditions and basic software and hardware environments;
[0009] The blockchain-enabled zero-trust forest and grassland IoT system security protection method includes the following steps:
[0010] S1, blockchain creation, smart contract definition and system initialization: complete the definition and chain code installation of the identity authentication smart contract, access control smart contract, integrity detection smart contract, independent audit smart contract, and security situation awareness smart contract, initialize the device registration information of the Lincao Cloud Platform, and generate the spatial data fingerprint and key system;
[0011] S2, periodic operation of the forest and grassland IoT system: The forest and grassland IoT system wakes up the forest and grassland communication relay and forest and grassland perception terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then sleeps and waits for the next data collection cycle;
[0012] S3, the forest and grassland security situation awareness system performs identity authentication: the forest and grassland security situation awareness system calls the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay, and performs static identity authentication and continuous dynamic identity authentication on the forest and grassland communication relay; the forest and grassland communication relay generates the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal according to the periodic operation configuration strategy, and completes static identity authentication and continuous dynamic identity authentication for the forest and grassland perception terminal. If the authentication is passed, step S4 is executed; if the authentication is not passed, step S10 is executed;
[0013] S4, the forest and grassland security situation awareness system performs dynamic access control: the forest and grassland communication relay uses the key policy attribute-based encryption method to encrypt the forest and grassland communication relay data to form a ciphertext and initiates a data transmission attribute access request to the forest and grassland cloud platform. The forest and grassland security situation awareness system calls the dynamic access control smart contract to calculate the multi-dimensional subject attributes of the forest and grassland communication relay, decrypts and verifies whether the attributes of the forest and grassland communication relay pass the verification, completes the dynamic access control and returns the access result. If it passes the verification, execute step S5, if it fails the verification, execute step S10;
[0014] S5, the forest and grassland security situation awareness system performs integrity testing: The forest and grassland security situation awareness system compares the spatial data fingerprint submitted by the forest and grassland perception terminal obtained through decryption with the spatial data fingerprint initialized and stored in the blockchain, completes the forest and grassland IoT data integrity test and returns the test result. If the test passes, step S6 is executed; if not, step S10 is executed;
[0015] S6. The Forestry and Grassland Cloud Platform submits data and returns access results: The Forestry and Grassland Communication Relay sends the collected monitoring data to the Forestry and Grassland Cloud Platform. The Forestry and Grassland Internet of Things application system connects to the internal resource database to complete data storage, returns the periodic operation configuration and periodic operation strategy, and waits for the next data collection cycle;
[0016] S7. Determine whether the monitoring is completed. If not, execute step S8. If so, terminate the process;
[0017] S8. Determine whether to trigger an independent audit: The Forestry and Grassland Security Situation Awareness System determines whether to trigger the independent audit start condition by executing the independent audit smart contract. If so, execute step S9. If not, execute step S2;
[0018] S9. The Forestry and Grassland Security Situation Awareness System performs an independent audit: The Forestry and Grassland Security Situation Awareness System generates an independent audit notice and encrypts and broadcasts it. The audited device receives the audit notice, conducts the audit and returns the audit data. The Forestry and Grassland Security Situation Awareness System verifies the returned audit data and stores the audit session and audit results on the chain. If the audit passes, execute step S2. If the audit fails, execute step S10;
[0019] S10. The Forestry and Grassland Security Situation Awareness System performs security situation awareness: The Forestry and Grassland Security Situation Awareness System stores the failure information record of this access session into the blockchain network, reads the historical access session records in the blockchain network, evaluates the access times and access situations of the current client and the Forestry and Grassland Communication Relay, determines whether it is attacked and takes corresponding measures to prevent the attack; then execute step S7.
[0020] In view of the problems existing in the identity authentication, access control, and data integrity detection of the Forestry and Grassland Internet of Things system in the face of internal attack threats and complex open environments, such as high centralization, opaque detection processes, untraceable results, and difficulty in effectively resisting internal attacks, a security protection method for the blockchain-enabled zero-trust Forestry and Grassland Internet of Things system is proposed. Continuous identity authentication is realized through static physical fingerprints combined with multi-dimensional dynamic feature fingerprints. Dynamic sustainable access control is realized through attribute-based access control combined with multi-dimensional dynamic attributes. Forestry and Grassland data integrity detection is realized through spatial data feature extraction combined with spatial data fingerprint comparison on the chain. Internal attack detection is realized through attribute encryption combined with an independent audit mode. The access, control, verification, detection, and audit smart contracts, session processes, and execution results between the Forestry and Grassland perception terminals, policy enforcement points, and policy decision points are stored in the blockchain using blockchain technology, realizing continuous verification, dynamic fine-grained access control, decentralization, transparency, immutability, traceability, and effective resistance to internal attacks of the Forestry and Grassland Internet of Things system, providing an effective way to solve the security defense problems of the Forestry and Grassland Internet of Things system.
[0021] A further technical solution is that the following steps are included in step S1:
[0022] S1.1, Creation and initialization of the blockchain network;
[0023] S1.2, Definition of the identity authentication smart contract and installation of the chain code. Among them, the identity authentication smart contract includes the operation policies for the forest and grass perception terminal, forest and grass communication relay, and forest and grass cloud platform to conduct identity authentication access session chain - up operations and identity authentication operation policies in the blockchain network, and the chain code is installed through the server - side of the forest and grass cloud platform;
[0024] S1.3, Definition of the access control smart contract and installation of the chain code. Among them, the access control smart contract includes the operation policies for the forest and grass communication relay and forest and grass cloud platform to conduct access control access session chain - up operations and dynamic access control operation policies in the blockchain network, and the chain code is installed through the server - side of the forest and grass cloud platform;
[0025] S1.4, Installation of the independent audit smart contract and chain code. Among them, the independent audit smart contract includes the operation policies for the forest and grass cloud platform to conduct independent audit session chain - up operations and independent audit operation policies in the blockchain network, and the chain code is installed through the server - side of the forest and grass cloud platform;
[0026] S1.5, Installation of the data integrity detection smart contract and chain code. Among them, the data integrity detection smart contract includes the operation policies for the forest and grass communication relay and forest and grass cloud platform to conduct data integrity detection access session chain - up operations and integrity detection operation policies in the blockchain network, and the chain code is installed through the server - side of the forest and grass cloud platform;
[0027] S1.6, Definition of the security situation awareness smart contract and installation of the chain code. Among them, the security situation awareness smart contract includes the data exchange operation policies for the forest and grass perception terminal, forest and grass communication relay, and forest and grass cloud platform to access internal data through identity authentication, access control, and integrity detection, and the security situation awareness operation policies launched in the blockchain network when the access fails;
[0028] S1.7, Initialization of the forest and grass Internet of Things system, including initializing the registration of forest and grass Internet of Things device information, initializing the generation of spatial data fingerprints, initializing the key - policy attribute - based encryption scheme, and generating keys.
[0029] Furthermore, the operation policy for the identity authentication access session chain - up at least includes the login session chain - up policy, identity authentication session chain - up policy, identity authentication failure session chain - up policy, and data transmission session chain - up policy;
[0030] The identity authentication operation policy at least includes the static physical fingerprint generation policy, static identity authentication policy, multi - dimensional dynamic feature fingerprint generation policy, and continuous dynamic identity authentication policy;
[0031] The access control access session operation policy at least includes a data transmission session blockchain policy, an operation policy download access session blockchain policy, and an access control failure session blockchain policy;
[0032] The dynamic access control policy at least includes a forest and grass communication relay subject attribute generation policy, a forest and grass communication relay subject multi-dimensional dynamic attribute calculation policy, a forest and grass communication relay data transmission attribute access request generation policy, a forest and grass cloud platform key policy attribute-based encryption initialization policy, a forest and grass cloud platform access control tree structure key generation policy, a forest and grass communication relay key policy attribute-based data encryption policy, a forest and grass cloud platform key policy attribute-based data decryption policy, and a forest and grass communication relay collected data transmission into the library access control verification policy;
[0033] The independent audit session blockchain operation policy at least includes an independent audit notification session blockchain policy, a forest and grass communication relay audit reply session blockchain policy, an independent audit successful completion session blockchain policy, and an independent audit failure end session blockchain policy;
[0034] The independent audit operation policy at least includes an independent audit start decision policy, an independent audit notification attribute generation policy, an independent audit notification attribute encryption policy, an independent audit notification attribute broadcast policy, and an independent audit detection policy;
[0035] The data integrity detection session blockchain operation policy includes a fingerprint cloud database generation session blockchain policy, a fingerprint cloud database blockchain session blockchain policy, a client data integrity detection request session blockchain policy, a data integrity detection failure session blockchain policy, and a data integrity detection execution result session blockchain policy;
[0036] The integrity detection operation policy at least includes a spatial data feature extraction policy, a spatial data fingerprint generation policy, a fingerprint cloud database generation policy, a fingerprint cloud database blockchain policy, a spatial data fingerprint comparison and detection policy, a data integrity detection result generation policy, and a data integrity detection result blockchain policy;
[0037] The data exchange operation policy at least includes a device registration information storage policy, a forest and grass communication relay periodic operation configuration download policy, a forest and grass communication relay collected data transmission into the library policy, an independent audit result storage policy, and a data integrity detection result return policy;
[0038] The security situation awareness operation policy at least includes a security situation awareness policy, a security threat emergency handling policy, a DOS attack monitoring policy, and an injection attack detection policy.
[0039] A further technical solution is that the specific steps of step S1.7 are as follows:
[0040] S1.7.1, Initialize the registration of forestry and grassland IoT device information: Through the static physical fingerprint generation strategy, form the device static physical fingerprint based on the registration information and the static password, and then use the device registration information storage strategy to form a new block with the device registration and device registration information and upload it to the blockchain network to complete the registration of forestry and grassland IoT devices;
[0041] S1.7.2, Initialize the generation of spatial data fingerprints: The forestry and grassland cloud platform server calls the spatial data feature strategy to extract and obtain the spatial vector data spatial features and attribute features in the server's internal resource database, execute the spatial data fingerprint generation strategy to obtain the spatial data fingerprint, and after calculation by the blockchain network consensus algorithm, form a new block and store it in the blockchain network to achieve the immutability and traceability of the fingerprint cloud database on-chain session;
[0042] S1.7.3, Initialize the key policy attribute-based encryption scheme and generate keys: The forestry and grassland cloud platform client calls the forestry and grassland cloud platform key policy attribute-based encryption initialization strategy, generates the system public key and the system master key based on the key policy attribute-based encryption mechanism, and calls the forestry and grassland cloud platform access control tree structure key generation strategy to calculate the decryption key of the forestry and grassland cloud platform client user based on the system master key and the user attribute set.
[0043] A further technical solution is that the following steps are included in the step S2:
[0044] S2.1, The forestry and grassland communication relay initiates an identity authentication session for the first layout;
[0045] S2.2, The mobile data collection terminal connects to and configures the forestry and grassland communication relay;
[0046] S2.3, The forestry and grassland IoT system runs periodically.
[0047] A further technical solution is that the following steps are included in the step S3:
[0048] S3.1, Create the static physical fingerprint of the forestry and grassland communication relay and perform static authentication: The forestry and grassland cloud platform client calls the static physical fingerprint generation strategy to generate the static physical fingerprint of the current forestry and grassland communication relay based on the registration information of the forestry and grassland communication relay sent by the forestry and grassland cloud platform client, and then obtain the static physical fingerprint of the forestry and grassland communication relay's last access on the blockchain platform, and call the static authentication strategy to perform static authentication;
[0049] S3.2. Create the multi-dimensional dynamic feature fingerprint of the forest and grass communication relay and conduct dynamic identity authentication: The client of the forest and grass cloud platform calls the multi-dimensional dynamic feature fingerprint generation strategy, generates the multi-dimensional dynamic feature fingerprint of the current forest and grass communication relay according to the registration information of the forest and grass communication relay sent by the client of the forest and grass cloud platform, then obtains the multi-dimensional dynamic feature fingerprint of the previous access of the forest and grass communication relay on the blockchain platform, and calls the continuous dynamic identity authentication strategy to compare the two pieces of information and return the identity authentication result;
[0050] S3.3. Upload the session of the identity authentication result of the forest and grass communication relay to the blockchain network: The client of the forest and grass cloud platform calls the identity authentication session on-chain strategy, records the information of this session into the blockchain network, and calls the device registration information warehousing strategy to add and update the device access registration information of the current forest and grass communication relay into the database;
[0051] S3.4. The forest and grass communication relay receives and stores the identity authentication access session information of the forest and grass sensing terminal: The forest and grass communication relay receives the identity access request of the forest and grass sensing terminal, obtains the identity authentication session parameters of the forest and grass sensing terminal, and stores them locally on the forest and grass communication relay;
[0052] S3.5. The forest and grass communication relay creates the static physical fingerprint of the forest and grass sensing terminal and conducts static identity authentication: The forest and grass communication relay generates the static physical fingerprint for accessing the forest and grass sensing terminal according to the static physical fingerprint generation strategy stored locally, and calls the static identity authentication strategy to compare it with the static physical fingerprint of the forest and grass sensing terminal stored locally;
[0053] S3.6. The forest and grass communication relay creates the multi-dimensional dynamic feature fingerprint of the forest and grass sensing terminal and conducts dynamic identity authentication: The forest and grass communication relay respectively calculates and generates the multi-dimensional dynamic feature fingerprint based on the identity authentication session parameters of the forest and grass sensing terminal obtained, and the identity authentication session parameters of the previous forest and grass sensing terminal obtained from the blockchain network and stored locally when the forest and grass communication relay is initialized, according to the multi-dimensional dynamic feature fingerprint generation strategy stored locally, and uses the continuous dynamic identity verification strategy stored locally to compare and authenticate the two multi-dimensional dynamic feature fingerprints of the forest and grass sensing terminal.
[0054] A further technical solution is that the step S4 includes the following steps:
[0055] S4.1. Encrypt the aggregated data of the forest and grass communication relay by the key-policy attribute-based encryption mechanism: The forest and grass communication relay uses the main body attributes of the forest and grass communication relay and the public key of the forest and grass cloud platform system, and calls the key-policy attribute-based data encryption strategy of the forest and grass communication relay to encrypt the data of the forest and grass sensing terminal aggregated in the forest and grass communication relay to form ciphertext;
[0056] S4.2, The forestry and grassland communication relay initiates a data transmission attribute access request to the forestry and grassland cloud platform: The forestry and grassland communication relay uses the data transmission attribute access request generation strategy in the periodically running configuration of the forestry and grassland communication relay downloaded locally, combines it with the main body attributes of the forestry and grassland communication relay to generate a data transmission attribute access request for the forestry and grassland communication relay, and sends a data transmission attribute access request session for the forestry and grassland communication relay to the forestry and grassland cloud platform;
[0057] S4.3, The forestry and grassland cloud platform uploads the data transmission session of the forestry and grassland communication relay to the blockchain network: The forestry and grassland cloud platform calls the data transmission session on-chain strategy, initiates a transaction for the data transmission session access request session sent by the forestry and grassland communication relay, and after calculation by the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network to achieve the immutability and traceability of access behaviors;
[0058] S4.4, The forestry and grassland cloud platform calculates the multi-dimensional dynamic attributes of the forestry and grassland communication relay: The forestry and grassland cloud platform calls the multi-dimensional dynamic attribute calculation strategy of the forestry and grassland communication relay main body, obtains the main body attributes of the forestry and grassland communication relay stored in the previous access session in the blockchain network, uses the physical model to perform simulation calculations on the multi-dimensional dynamic attributes, and simulates and calculates the main body attribute values of the forestry and grassland communication relay in this access session;
[0059] S4.5, The forestry and grassland cloud platform conducts access control verification on the data transmission of the forestry and grassland communication relay: The forestry and grassland cloud platform calls the access control verification strategy for the data transmission of the forestry and grassland communication relay to the library, combines it with the main body attribute values of the forestry and grassland communication relay obtained by simulation calculation, and verifies the main body attributes of the forestry and grassland communication relay in the current session;
[0060] S4.6, The forestry and grassland cloud platform decrypts the key policy attribute-based data: The forestry and grassland cloud platform calls the key policy attribute-based data decryption strategy of the forestry and grassland cloud platform, uses the key related to the access structure assigned to the forestry and grassland cloud platform client user during the initialization of the forestry and grassland cloud platform to perform decryption operations, and the decryption is successful when the attributes in the ciphertext satisfy the access control tree.
[0061] A further technical solution is to use the forestry and grassland cloud platform sensing terminal to collect, process and interact with spatial data. The following steps are included in step S5:
[0062] S5.1, The forestry and grassland sensing terminal obtains the spatial data fingerprint database generation strategy: The forestry and grassland sensing terminal accesses the forestry and grassland cloud platform client or the blockchain network to obtain the spatial data feature extraction strategy, the spatial data fingerprint generation strategy and the fingerprint database generation strategy;
[0063] S5.2, The forestry and grassland sensing terminal extracts spatial data features: For the spatial database used for data integrity detection, the forestry and grassland sensing terminal locally executes the spatial data feature extraction strategy to obtain the spatial vector data spatial features and attribute features of the sensing terminal spatial database;
[0064] S5.3, Generation of Spatial Data Fingerprints at the Sensing End: The sensing end of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint generation strategy on the spatial data that has obtained spatial features and attribute features for data integrity detection, and obtains the spatial data fingerprints of the spatial database at the sensing end of the Forestry and Grassland Cloud Platform;
[0065] S5.4, Generation of Fingerprint Cloud Database at the Sensing End: The sensing end of the Forestry and Grassland Cloud Platform executes the fingerprint cloud database generation strategy on the spatial data that has obtained spatial data fingerprints for data integrity detection, and obtains the fingerprint database at the sensing end of the Forestry and Grassland Cloud Platform;
[0066] S5.5, Sending Data Integrity Detection Request and Sensing End Fingerprint Database: The sensing end of the Forestry and Grassland Cloud Platform sends a data integrity detection request to the client of the Forestry and Grassland Cloud Platform, and submits the sensing end fingerprint database to complete the data integrity detection;
[0067] S5.6, Linking the Data Integrity Detection Request Session of the Sensing End to the Chain: The client of the Forestry and Grassland Cloud Platform executes the fingerprint cloud database generation session linking strategy. The client of the Forestry and Grassland Cloud Platform initiates a transaction for the client data integrity detection request session. After being calculated by the blockchain network consensus algorithm, a new block is stored in the blockchain network, realizing the immutability and traceability of the data collection and data integrity detection behaviors of the forestry sensing terminal;
[0068] S5.7, Comparison and Detection of Spatial Data Fingerprints at the Server End: The server end of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint comparison and detection strategy. Taking the sensing end fingerprint database submitted for detection by the sensing end of the Forestry and Grassland Cloud Platform as the input, it obtains the fingerprint cloud database from the blockchain network. Through the attribute query and comparison method, it compares the spatial data fingerprints of the sensing end fingerprint database with the spatial data fingerprints in the fingerprint cloud database, and marks the inconsistent spatial data fingerprints;
[0069] S5.8, Obtaining the Data Integrity Detection Results at the Server End: The server end of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint detection result generation strategy, and stores the marked inconsistent spatial data fingerprints separately to form a data integrity detection result database;
[0070] S5.9, Linking the Data Integrity Detection Results to the Chain: The client of the Forestry and Grassland Cloud Platform executes the data integrity detection result linking strategy. It initiates a transaction for all the records in the data integrity detection result database. After being calculated by the blockchain network consensus algorithm, a new block is stored in the blockchain network, realizing the immutability and traceability of the data in the data integrity detection result database;
[0071] S5.10, Upload the Execution Result Session of Data Integrity Detection to the Blockchain: The client of the Forestry and Grassland Cloud Platform executes the policy of uploading the execution result session of data integrity detection. Initiate a transaction for the execution result session of data integrity detection on the server side. After being calculated by the consensus algorithm of the blockchain network, a new block is stored in the blockchain network, realizing the non-tampering and traceability of data integrity detection behavior.
[0072] A further technical solution is that the step S6 includes the following steps:
[0073] S6.1, The Forestry and Grassland Communication Relay Downloads the Periodic Operation Configuration of the Forestry and Grassland Communication Relay: The Forestry and Grassland Communication Relay uses the periodic operation configuration download policy of the Forestry and Grassland Communication Relay to read and download the periodic operation policy configuration information of the Forestry and Grassland Internet of Things in the Forestry and Grassland Cloud Platform database to the local of the Forestry and Grassland Communication Relay;
[0074] S6.2, The Forestry and Grassland Communication Relay Stores the Data Collected by the Forestry and Grassland Sensing Terminal and Sends the Periodic Operation Configuration: The Forestry and Grassland Communication Relay receives the identity authentication parameters and the collected data transmitted by the Forestry and Grassland Sensing Terminal, stores them in the Forestry and Grassland Communication Relay, and sends the periodic operation policy of the Forestry and Grassland Sensing Terminal stored locally to the Forestry and Grassland Sensing Terminal.
[0075] S6.3, The Forestry and Grassland Communication Relay Sends the Collected Data to the Forestry and Grassland Cloud Platform: If the identity authentication, access control, and data integrity detection of the Forestry and Grassland Communication Relay are passed, it agrees to submit the data from the sensing end to the internal resource database of the server side. Otherwise, it returns the data integrity detection result database to the sensing end;
[0076] A further technical solution is that the step S9 includes the following steps:
[0077] S9.1, The Forestry and Grassland Cloud Platform Executes the Generation of Audit Notifications: The Forestry and Grassland Cloud Platform executes an independent audit notification attribute generation policy to generate audit notifications;
[0078] S9.2, The Forestry and Grassland Cloud Platform Uploads the Independent Audit Notification Session to the Blockchain: The audit notification is sent to the Forestry and Grassland Communication Relay and / or the Forestry and Grassland Sensing Terminal. The client of the Forestry and Grassland Cloud Platform initiates a transaction for the audit notification distribution session. After being calculated by the consensus algorithm of the blockchain network, a new block is stored in the blockchain network, realizing the non-tampering and traceability of the audit notification behavior;
[0079] S9.3, The Forestry and Grassland Cloud Platform Encrypts the Audit Notification Using the Ciphertext Attribute Encryption Method: The Forestry and Grassland Cloud Platform executes an independent audit notification attribute encryption policy to encrypt the audit notification using the ciphertext attribute encryption method;
[0080] S9.4, The Forestry and Grassland Cloud Platform broadcasts an audit notice to the Forestry and Grassland Communication Relay: The Forestry and Grassland Cloud Platform executes and sends the encrypted audit notice ciphertext to the Forestry and Grassland Communication Relay in the next data collection cycle;
[0081] S9.5, The Forestry and Grassland Communication Relay decrypts the audit notice and conducts an independent audit according to the requirements of the audit notice: The Forestry and Grassland Communication Relay uses the public key of the Forestry and Grassland Cloud Platform system to obtain the attributes and private key of the current Forestry and Grassland Communication Relay, decrypts the audit notice ciphertext. If the attributes of the Forestry and Grassland Communication Relay meet the access policy of the audit notice ciphertext, then decrypt the ciphertext and obtain the audit notice content;
[0082] S9.6, The Forestry and Grassland Sensing Terminal decrypts the audit notice and conducts an independent audit according to the requirements of the audit notice: The Forestry and Grassland Communication Relay uses the public key of the Forestry and Grassland Cloud Platform system to obtain the attributes and private key of the current Forestry and Grassland Sensing Terminal, decrypts the audit notice ciphertext. If the attributes of the Forestry and Grassland Sensing Terminal meet the access policy of the audit notice ciphertext, then decrypt the ciphertext and obtain the audit notice content, execute the audit notice content to form audit data and submit it to the Forestry and Grassland Communication Relay;
[0083] S9.7, The Forestry and Grassland Communication Relay submits audit data according to the requirements of the audit notice: The Forestry and Grassland Communication Relay encrypts and uploads the locally aggregated Forestry and Grassland Sensing Terminals and locally stored data back to the Forestry and Grassland Cloud Platform for auditing according to the requirements of the audit notice;
[0084] S9.8, The Forestry and Grassland Cloud Platform chains the audit reply session of the Forestry and Grassland Communication Relay: The client of the Forestry and Grassland Cloud Platform initiates a transaction for the audit reply session of the Forestry and Grassland Communication Relay, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of the audit reply behavior of the Forestry and Grassland Communication Relay;
[0085] S9.9, The Forestry and Grassland Cloud Platform decrypts the audit upload data and conducts a comparison audit: The audit organization client of the Forestry and Grassland Cloud Platform decrypts the upload data using the symmetric key to obtain the audit data, then reads the historical data of the audited device from the blockchain network, and conducts a comparison audit between the historical data and the audit data;
[0086] S9.10, The Forestry and Grassland Cloud Platform conducts an independent audit detection and gives an audit result: The Forestry and Grassland Cloud Platform executes the independent audit detection strategy to detect the integrity and authenticity of the current and previous data. If the audit device replies with audit data that is inconsistent with the historical data in the blockchain network, then execute step S10;
[0087] S9.11, The Forestry and Grassland Cloud Platform chains the successful completion session of the independent audit: The client of the Forestry and Grassland Cloud Platform initiates a transaction for the successful completion session of the independent audit. After calculating through the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network, realizing the immutability and traceability of the audit result behavior;
[0088] S9.12, The forestry and grassland cloud platform records and stores audit sessions and results: The forestry and grassland cloud platform invokes an independent audit result storage strategy to store the audit data and results obtained from local audits into the database.
[0089] A further technical solution is that the step S10 includes the following steps:
[0090] S10.1, Conduct security situation awareness and emergency response when identity authentication fails: When identity authentication fails, the identity authentication failure session on-chain strategy invoked by the forestry and grassland cloud platform client records the identity authentication access session failure information into the blockchain network; and invokes the security situation awareness strategy to read the historical access session records in the blockchain network, evaluate the access times of the current client and the forestry and grassland communication relay to determine whether there is a DOS attack. If the access IP and / or access port exceeds the access upper limit threshold, the security threat emergency response strategy is invoked to urgently close the current access IP and / or access port to prevent the DOS attack;
[0091] S10.2, Conduct security situation awareness and emergency response when access control fails: When access control or decryption fails, the forestry and grassland cloud platform invokes the access control failure session on-chain strategy to initiate a transaction for the access control failure session sent by the forestry and grassland communication relay. Through the blockchain network consensus algorithm calculation, a new block is formed and stored in the blockchain network to achieve the non-tamperability and traceability of access behaviors; and invokes the security situation awareness strategy to read the historical access session records in the blockchain network, evaluate the access times of the current client and the forestry and grassland communication relay to determine whether there is a DOS attack. If the access IP and / or access port exceeds the access upper limit threshold, the security threat emergency response strategy of the security situation awareness smart contract is invoked to urgently close the current access IP and / or access port to prevent the DOS attack;
[0092] S10.3, Conduct security situation awareness and emergency response when integrity detection fails: When the data integrity detection fails, the integrity detection failure session on-chain strategy invoked by the forestry and grassland cloud platform client initiates a transaction for the integrity detection failure session sent by the forestry and grassland communication relay. Through the blockchain network consensus algorithm calculation, a new block is formed and stored in the blockchain network to achieve the non-tamperability and traceability of access behaviors;
[0093] The forestry and grassland cloud platform server executes the DOS attack monitoring strategy. The forestry and grassland cloud platform queries the blockchain network for the forestry perception terminal with failed data integrity detection, obtains the failed access times of the forestry perception terminal for this request detection, and determines whether the failed access times exceed the defined threshold. If so, it is determined that there is a DOS attack threat, and the security threat emergency response strategy is triggered.
[0094] S10.4. Conduct security situation awareness and emergency response in case of independent audit failure: If the verification of the independent audit result fails, the client of the forestry and grassland cloud platform will initiate a transaction to end the session due to the audit failure. Through the consensus algorithm of the blockchain network, a new block is calculated and stored in the blockchain network to achieve the immutability and traceability of the audit failure behavior. The forestry and grassland cloud platform will execute the security situation awareness intelligent contract disposal strategy based on the audit result and rectify the audit result.
[0095] A further technical solution is that the forestry and grassland security situation awareness system includes:
[0096] Blockchain creation, smart contract definition, and system initialization module: Used for initializing the blockchain network, completing identity authentication, access control, independent audit, integrity detection smart contract definition, and chain code installation, and completing the initialization of the forestry and grassland Internet of Things system;
[0097] Forestry and grassland communication relay identity authentication module: Used for the client of the forestry and grassland cloud platform to separately call the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forestry and grassland communication relay, and conduct static identity verification and continuous dynamic identity authentication on the forestry and grassland communication relay;
[0098] Attribute-based data encryption access control request generation module: Used for using the periodic operation configuration of the forestry and grassland communication relay to generate the subject attributes of the forestry and grassland communication relay, combining with the public key of the forestry and grassland cloud platform system, and using the forestry and grassland communication relay key policy attribute-based data encryption policy to encrypt the forestry and grassland perception terminal data collected in the forestry and grassland communication relay into ciphertext, and initiate a data transmission attribute access request to the forestry and grassland cloud platform;
[0099] Attribute-based data encryption access control request verification module: Used for combining the subject attributes of the forestry and grassland communication relay calculated by simulation to verify whether the attributes of the forestry and grassland communication relay pass the verification;
[0100] Server-side data integrity detection module: Used for the forestry and grassland cloud platform to compare the spatial data fingerprint submitted by the forestry and grassland perception terminal obtained by decryption with the spatial data fingerprint initially generated and stored in the blockchain to verify the completion of data integrity detection of the forestry and grassland Internet of Things and return the detection result;
[0101] Trigger audit judgment module: Used for the forestry and grassland cloud platform to judge whether to trigger the independent audit start condition by executing the independent audit smart contract;
[0102] Independent audit notice generation and encrypted broadcast module: Used for the forestry and grassland cloud platform to generate an independent audit notice, encrypt the independent audit notice using the ciphertext attribute encryption method, and broadcast the independent audit notice ciphertext from the forestry and grassland cloud platform to the forestry and grassland communication relay in the next data collection cycle;
[0103] Audit device returns an audit result verification module: It is used for the forestry and grassland cloud platform to decrypt the transmitted audit data and compare it with the historical data stored in the blockchain network, and complete the detection of data integrity and system security by judging the data consistency;
[0104] Forestry and grassland Internet of Things security situation awareness and emergency disposal module: It is used for the forestry and grassland cloud platform to store the record of the current access session failure information into the blockchain network, read the historical access session records in the blockchain network, evaluate the access times and access situations of the current client and the forestry and grassland communication relay, judge whether it is attacked, and take corresponding measures to prevent the attack.
[0105] A further technical solution is that the forestry and grassland Internet of Things application system includes:
[0106] Forestry and grassland Internet of Things system periodic operation module: It is used for the forestry and grassland Internet of Things system to wake up the forestry and grassland communication relay and the forestry and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, complete data collection, aggregation and transmission, and then go into dormancy waiting for the next data collection cycle;
[0107] Attribute-based encryption data decryption module: It is used for the forestry and grassland cloud platform to decrypt the ciphertext transmitted by the forestry and grassland Internet of Things with the key related to the access structure, and transmit the successfully decrypted data through the forestry and grassland communication relay;
[0108] Forestry and grassland sensing terminal identity authentication module: It is used for the forestry and grassland communication relay to receive and store the identity authentication access session information of the forestry and grassland sensing terminal according to the locally downloaded periodic operation configuration strategy, and then generate the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forestry and grassland sensing terminal in combination with the periodic security awareness configuration strategy, complete the static identity authentication and continuous dynamic identity authentication, and store the data collected by the forestry and grassland sensing terminal locally;
[0109] Perception end spatial data fingerprint database generation module: It is used for the forestry and grassland cloud platform perception end to perform spatial data feature extraction and spatial data fingerprint generation, generate the perception end fingerprint database, and then send a data integrity detection request and the perception end fingerprint database to the forestry and grassland cloud platform server;
[0110] Forestry and grassland communication relay audit module: It is used for the forestry and grassland communication relay to decrypt the independent audit notice ciphertext. When the attributes of the forestry and grassland communication relay meet the independent audit notice access policy, decrypt the ciphertext to obtain the independent audit notice content, and conduct an independent audit according to the requirements of the independent audit notice and transmit the audit data;
[0111] Forest and Grass Sensing Terminal Extension Audit Module: When the forest and grass sensing terminal is required to conduct an extended audit according to the independent audit notice, it receives the independent audit notice sent by the forest and grass communication relay and decrypts it. When the attributes of the forest and grass sensing terminal meet the access policy of the independent audit notice, it decrypts the ciphertext to obtain the content of the independent audit notice, conducts an independent audit according to the requirements of the independent audit notice, and transmits the audit data back.
[0112] Forest and Grass Cloud Platform Access Session Blockchain Module: It is used for the forest and grass cloud platform client to blockchain the access request sessions and access request result sessions of the forest and grass sensing terminal and the forest and grass communication relay.
[0113] Data Storage and Download Module: It is used for the forest and grass cloud platform client to store the transmission data submitted by the forest and grass communication relay into the internal resource database and distribute the periodic operation configuration and acquired data of the server side.
[0114] Compared with the prior art, the present invention has the following advantages:
[0115] Low management and maintenance cost: The identity authentication method in the present invention uses the static physical fingerprints of forest and grass Internet of Things devices and relies more on the multi-dimensional dynamic feature fingerprints of device physical attributes. These fingerprint information is based on the physical characteristics of the Internet of Things itself, without the need for fixed memorization and storage, and the maintenance cost is low.
[0116] Effectively prevent internal attacks: The multi-dimensional dynamic feature fingerprints in the present invention are continuously and dynamically verified based on the characteristics of Internet of Things devices themselves. Even if internal management personnel obtain the password information of a certain device or within each system, they cannot break into other devices or systems.
[0117] Can dynamically detect intrusion attacks: Since the identity authentication is based on the zero-trust architecture and multi-dimensional dynamic feature fingerprints, realizing the method of "never trust, continuously verify", the identity authentication method is constantly changing. If there are forgery, impersonation, and replay attacks, the system can promptly detect illegal access and register it in the blockchain network, and can be promptly detected and traced.
[0118] Effectively prevent forgery and tampering attacks: For illegal access, the present invention records all in the blockchain network. Through the anti-tampering and traceable characteristics of the blockchain, all illegal access can be queried, effectively preventing attackers from hiding attack behaviors by tampering with or deleting access records.
[0119] Provide lightweight protection measures: The multi-dimensional dynamic feature fingerprint technology provided by the present invention is verified based on the physical characteristics of forest and grass Internet of Things devices, without the need for password storage, encrypted storage, and transmission. The protection method is both "obtainable immediately" and fast and lightweight, which is very suitable for the security protection in the low-power long-cycle monitoring scenarios with difficult power supply and transmission in forest and grass Internet of Things.
[0120] Decentralization and Distributed Features: Deployed on the blockchain through smart contracts, the dynamic access control method has decentralization and distributed features. There is no single central point that can control or tamper with access rights, enhancing the security and robustness of the system.
[0121] Transparency and Immutability: The execution and transactions of all smart contracts are recorded on the blockchain network, ensuring transparency and immutability, and effectively preventing malicious actors from modifying access control rules or abusing permissions.
[0122] Dynamicity and Flexibility: Smart contracts can automatically execute and adjust access rights according to preset rules and conditions. This enables access control policies to be dynamically adjusted according to the real-time status and requirements of the forestry and grassland IoT, increasing the flexibility and adaptability of the system. The generation of the spatial data fingerprint database can be automatically executed according to preset rules and conditions, and the fingerprint database is replaced by an encrypted attribute database instead of a geospatial database. This allows data integrity detection policies to be shared in a distributed network, and forestry and grassland sensing terminals can obtain and calculate locally in real time, increasing the flexibility and adaptability of the system.
[0123] Fine-grained Access Control: KP-ABE allows for fine-grained access control based on the attributes and roles of users. Different access rights can be set for different users or user groups to meet the complex permission requirements in the forestry and grassland IoT.
[0124] Simplified Permission Management: By associating permissions with attributes and roles, KP-ABE simplifies the permission management process. Administrators do not need to set permissions for each user individually, but only need to define attributes and roles, thus reducing management costs and complexity.
[0125] Enhanced Security: KP-ABE uses encryption technology to protect data security and combines multi-dimensional dynamic attributes to participate in access control. Only users with appropriate attributes can decrypt and access data. This helps prevent unauthorized access and data leakage. Brief Description of the Drawings
[0126] The drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments and descriptions of the present invention are used to explain the present invention and do not constitute an improper limitation of the present invention.
[0127] Figure 1 It is a structural block diagram of a blockchain-enabled zero-trust forestry and grassland IoT system according to an embodiment of the present invention;
[0128] Figure 2 It is a flow schematic diagram of a security protection method for a blockchain-enabled zero-trust forestry and grassland IoT system according to an embodiment of the present invention;
[0129] Figure 3 Schematic diagram of the process of blockchain creation, smart contract definition, and system initialization involved in an embodiment of the present invention;
[0130] Figure 4 Schematic diagram of the process of periodic operation of the forest and grassland Internet of Things system involved in an embodiment of the present invention;
[0131] Figure 5 Schematic diagram of the process of identity authentication executed by the forest and grassland security situation awareness system involved in an embodiment of the present invention;
[0132] Figure 6 Schematic diagram of the process of dynamic access control executed by the forest and grassland security situation awareness system involved in an embodiment of the present invention;
[0133] Figure 7 Schematic diagram of the process of integrity detection executed by the forest and grassland security situation awareness system involved in an embodiment of the present invention;
[0134] Figure 8 Schematic diagram of the process of the forest and grassland cloud platform submitting data and returning access results involved in an embodiment of the present invention;
[0135] Figure 9 Schematic diagram of the process of independent audit executed by the forest and grassland security situation awareness system involved in an embodiment of the present invention;
[0136] Figure 10 Schematic diagram of the process of security situation awareness executed by the forest and grassland security situation awareness system involved in an embodiment of the present invention;
[0137] Figure 11 Schematic diagram of the execution process of the blockchain - empowered zero - trust forest and grassland Internet of Things system module involved in an embodiment of the present invention. Detailed implementation manners
[0138] The present invention will be described in detail below with reference to the accompanying drawings. The description in this part is only exemplary and explanatory, and shall not have any restrictive effect on the protection scope of the present invention. In addition, those skilled in the art can make corresponding combinations of the features in the embodiments and different embodiments according to the description of this document.
[0139] To better understand the technical solution of the present invention, the structure of the forest and grassland Internet of Things system of the present invention is introduced as follows:
[0140] It consists of forest and grassland sensing terminals, forest and grassland communication relays, forest and grassland cloud platforms, and internal resources.
[0141] Forest and grass perception terminal, which realizes the collection, perception and monitoring of forest and grass resources and their growth and living environment information, including but not limited to Internet of Things intelligent devices such as forest tree (carbon) tables, infrared cameras, meteorological environment monitoring devices, video checkpoints, mobile data collection terminals, etc., and also includes mobile or fixed control terminals for spatial data collection, processing and interaction, that is, the perception end of the forest and grass cloud platform.
[0142] Forest and grass communication relay, which receives the signals of the forest and grass perception terminal and realizes the reporting, backhaul and reception of the collected data, including but not limited to Internet of Things communication devices such as Beidou short message gateways, 4G mobile communication gateways, industrial control gateways, etc.
[0143] Forest and grass cloud platform, which is deployed on the cloud platform and is a collection of software and hardware resources and systems that maintain and operate the blockchain system and realize the continuous verification, dynamic evaluation, real-time perception and scientific decision-making of the forest and grass Internet of Things system.
[0144] Among them, the cloud platform provides platform software and hardware support, including cloud platform resources and application platforms. Cloud platform resources include but are not limited to X86 computing servers for building computing resource pools, storage servers for building storage resource pools, network servers and routers for building network resource pools, etc., as well as virtualization platform software for resource virtualization management. The application platform includes but is not limited to operating systems, database platforms, GIS platforms, network middleware, blockchains, etc. deployed on the virtualization platform. This part adopts existing mature technologies and will not be elaborated here.
[0145] Internal resources are the software, hardware and data resources stored, maintained and managed by the forest and grass Internet of Things system.
[0146] The forest and grass cloud platform includes the forest and grass Internet of Things application system and the forest and grass security situation perception system, as well as the cloud platform carrying the forest and grass Internet of Things application system and the forest and grass security situation perception system.
[0147] The blockchain-enabled zero-trust forest and grass Internet of Things system is jointly composed of the forest and grass Internet of Things application system and the forest and grass security situation perception system.
[0148] The forest and grass Internet of Things application system receives the data and requests reported and backhauled by the forest and grass communication relay, converts them into access sessions, stores them in the blockchain and submits them to the forest and grass security situation perception system, and executes the secure access of the forest and grass communication relay to the internal resources according to the results returned by the forest and grass security situation perception system. The port of the forest and grass Internet of Things application system is the channel for the forest and grass communication relay to interact with the forest and grass cloud platform and the blockchain system, that is, the client of the forest and grass cloud platform.
[0149] The forest and grass security situation awareness system receives sessions from the forest and grass IoT application system and combines internal resources through smart contracts to make decisions on whether to authorize requests for identity authentication, access control, integrity detection, etc. submitted in the session, and determines the current security situation based on the status of the current forest and grass IoT system, as well as whether to conduct an independent audit. The port of the forest and grass security situation awareness system is the channel for the forest and grass IoT application system to interact with the blockchain smart contract, that is, the server side of the forest and grass cloud platform.
[0150] Specifically, the embodiments of the present invention are as follows. A zero-trust forest and grass IoT security protection method empowered by blockchain is implemented through the forest and grass cloud platform, as Figure 2 , the zero-trust forest and grass IoT system security protection method empowered by blockchain includes the following steps:
[0151] S1. Creation of blockchain, definition of smart contracts, and system initialization: Complete the definition of identity authentication smart contracts, access control smart contracts, integrity detection smart contracts, independent audit smart contracts, and security situation awareness smart contracts, and install chain codes, and initialize the device registration information of the forest and grass cloud platform to generate spatial data fingerprints and key systems;
[0152] As Figure 3 , the specific steps in step S1 are as follows:
[0153] S1.1. Creation and initialization of the blockchain network;
[0154] Select a suitable blockchain type and specific blockchain platform according to the application scenario, conduct organization registration, identity authentication and verification, define alliances for organizations according to actual business and create channels for the alliances, issue certificates for the client user nodes, peer nodes, ordering nodes, and identity authentication nodes of the organizations through the certificate authority, and each organization approves the chain code definition and endorsement policy definition and stores them on the channel ledger.
[0155] For the forest and grass IoT application scenario, considering that the users are mainly forest and grass competent departments, the data has strong industry attributes and needs to connect to the Internet for information interaction. It is most suitable to use a consortium blockchain, and Hyperledger Fabric is one of the most widely used consortium blockchain platforms in the world. Therefore, the Fabric blockchain platform is recommended for use in the method of the present invention.
[0156] For the forest and grass IoT system, forest and grass competent departments at all levels are organizations. Usually, organizations and alliances are established according to administrative levels. For example, the municipal forest and grass competent department is an organization, and alliances are established at the provincial level, and channels are constructed to enable organizations to communicate with each other and maintain a common ledger.
[0157] The organization administrators registered in the MSP of the Fabric blockchain network send requests and obtain services from the forestry and grassland Internet of Things application system deployed on the forestry and grassland cloud platform through the client user nodes.
[0158] The registered field surveyors, after passing the identity authentication of the MSP, use the mobile data collection terminal to connect to the forestry and grassland communication relay and the forestry and grassland cloud platform to carry out the initial layout work.
[0159] Before the audit, under the supervision of the established audit team, the system administrator establishes an audit department organization in the Fabric blockchain network, registers the reviewers of the audit department organization through the MSP, joins the channel to maintain the common ledger, and conducts independent audits on the alliances, organizations, and administrators of the audited forestry and grassland Internet of Things system.
[0160] S1.2, Identity authentication smart contract definition and chain code installation. Among them, the identity authentication smart contract includes the identity authentication access session on-chain operation policy and the identity authentication operation policy for the forestry and grassland perception terminal, the forestry and grassland communication relay, and the forestry and grassland cloud platform in the blockchain network. The chain code is installed through the forestry and grassland cloud platform server side;
[0161] (1) The identity authentication access session on-chain operation policy includes, but is not limited to, the organization administrator login session on-chain policy, the identity authentication session on-chain policy, the identity authentication failure session on-chain policy, and the data transmission session on-chain policy. For the forestry and grassland Internet of Things system, the content stored in the identity authentication access session varies according to the session type, but the storage method is the same. That is, the access session initiation transaction is to be calculated through the blockchain network consensus algorithm, and then a new block is stored and entered into the blockchain network to achieve the immutability and traceability of access behaviors. For example, in the organization administrator login session on-chain policy, the content stored in the identity authentication access session includes, but is not limited to, the organization administrator username, login time, login location, and login IP, and a session write request is sent to the blockchain network after the session is completed.
[0162] (2) The identity authentication operation policy includes, but is not limited to, the static physical fingerprint generation policy, the static identity authentication policy, the multi-dimensional dynamic feature fingerprint generation policy, and the continuous dynamic identity authentication policy.
[0163] Among them, the static physical fingerprint generation policy is that the forestry and grassland cloud platform generates the device static physical fingerprint for the device by using the hash function according to the device type, device mac, and radio frequency fingerprint in the registered device registration form after setting the combination and conversion, as the unique identifier of the device.
[0164] For the combination and conversion methods in the forestry and grassland Internet of Things system, string concatenation operations are used. That is, the device type, device MAC address, and radio frequency fingerprint information are concatenated into a single string, and then the national cryptography SM3 cryptographic hashing algorithm is used to output a digest information with a length of 256 bits as the static physical fingerprint of the device.
[0165] Among them, the static identity authentication strategy is to generate the static physical fingerprint of the current forestry and grassland Internet of Things gateway based on the registration information of the currently accessed device, and then obtain the static physical fingerprint of the device's last access on the blockchain platform. After comparison, the identity authentication result is returned.
[0166] Among them, the multi-dimensional dynamic feature fingerprint generation strategy is that the forestry and grassland cloud platform usually constructs dynamic feature fingerprints for devices based on the dynamic change characteristics of time, space, and environment in the device registration form, and uses its physical change characteristics to form a continuous dynamic verification model.
[0167] For the forestry and grassland Internet of Things system, a dynamic feature fingerprint based on battery power can be constructed by the device type, device MAC, device battery power, and registration time using the time-battery power attenuation model; a dynamic feature fingerprint based on temperature and humidity can be constructed by the device temperature, external humidity of the device, and internal humidity of the device using the consistency characteristic of common space environment factors; a dynamic feature fingerprint based on the network channel can be constructed by the channel fingerprint and radio frequency fingerprint using the wireless signal space transmission attenuation model.
[0168] Among them, the continuous dynamic identity authentication strategy is to generate the multi-dimensional dynamic feature fingerprint of the current device based on the registration information of the current device, and then obtain the multi-dimensional dynamic feature fingerprint of the last access of the forestry and grassland Internet of Things gateway on the blockchain platform. The two pieces of information are compared and the identity authentication result is returned.
[0169] For the forestry and grassland Internet of Things system, that is, the device type, device MAC, device battery power, and registration time at the last access time node are used to calculate the battery power result of this time using the time-battery power attenuation model and compare it with the battery power in the current registration information of the forestry and grassland communication relay. If it is within the set threshold range, for example, within ±10% of the calculation result, it is considered to pass the verification; the device temperature, external humidity of the device, and internal humidity of the device collected by the forestry and grassland communication relay this time are used to calculate the fluctuation range of the environmental temperature and humidity of all devices using the consistency characteristic of common space environment factors. If it is within the set threshold range, for example, within ±10% of the average temperature and humidity, it is considered to pass the verification; the channel fingerprint and radio frequency fingerprint are used to construct a network signal feature fingerprint based on the network channel using the wireless signal space transmission attenuation model. If it is within the set threshold range, for example, within ±10% of the signal strength, it is considered to pass the verification. The above multi-dimensional feature fingerprints can be used alone or in combination.
[0170] S1.3, Definition of access control smart contract and installation of chain code. Among them, the access control smart contract includes the operation policies for the forestry and grassland communication relay and the forestry and grassland cloud platform to conduct access control access session on-chain operations and dynamic access control operation policies, and the chain code is installed through the forestry and grassland cloud platform server side;
[0171] (1) The access control access session operation policies include but are not limited to the data transmission session on-chain policy, the operation policy download access session on-chain policy, and the access control failure session on-chain policy.
[0172] For the forestry and grassland Internet of Things system, the content stored by the access control access session varies according to the session type, but the storage method is the same. That is, the access session initiation transaction is to be calculated through the blockchain network consensus algorithm, and then a new block is stored and entered into the blockchain network to achieve the immutability and traceability of access behaviors. For example, for the operation policy download access session on-chain policy, the content stored by the access control access session includes but is not limited to the username, login time, login location, and login IP of the visitor, and a session write request is sent to the blockchain network after the session is completed.
[0173] (2) The dynamic access control policies include but are not limited to the forestry and grassland communication relay subject attribute generation policy, the forestry and grassland communication relay subject multi-dimensional dynamic attribute calculation policy, the forestry and grassland communication relay data transmission attribute access request generation policy, the forestry and grassland cloud platform key policy attribute-based encryption initialization policy, the forestry and grassland cloud platform access control tree structure key generation policy, the forestry and grassland communication relay key policy attribute-based data encryption (KP-ABE) policy, the forestry and grassland cloud platform key policy attribute-based data decryption policy, and the forestry and grassland communication relay collected data transmission into the library access control verification policy.
[0174] For the access control attributes of the forestry and grassland Internet of Things system, the subject attribute is the data of the forestry and grassland communication relay, the object attribute is the forestry and grassland cloud platform client attribute, the permission attribute is the operation permission of the forestry and grassland communication relay to the forestry and grassland cloud platform, and the environment attribute is the environment information when the forestry and grassland communication relay accesses the forestry and grassland cloud platform. For example: The object attributes include the client IP, client port number, network protocol and other forestry and grassland cloud platform client description information; The operations of the permission attributes include read, write, execute, etc.; The environment attributes include the start time, end time, initiator, etc. of the control access session.
[0175] Among them, the generation strategy of the main body attributes of the forest and grass communication relay is that the forest and grass communication relay directly reads its own attributes and collects data information, such as device name, device type, device MAC, battery power, temperature, humidity, RSSI, etc., and stores them in the form of key-value pairs. {Device name: Getwey101, Device type: Forest and grass communication relay, Device MAC: 23:e4:xx:xx:5f:k9, Battery power: 2400, Temperature: 24, Humidity: 80; RSSI: -65}.
[0176] Among them, the generation strategy of the multi-dimensional dynamic attributes of the forest and grass communication relay main body is that the forest and grass cloud platform is based on the attributes of the forest and grass communication relay main body stored in the previous access session in the blockchain network, uses a physical model to simulate and calculate the multi-dimensional dynamic attributes, and simulates and calculates the attribute values of the forest and grass communication relay main body in this access session for later access control verification.
[0177] Among them, the multi-dimensional dynamic attributes refer to the attribute values that change over time or space, such as battery power, temperature and humidity, and wireless signal strength. The physical model is determined by the physical characteristics of the multi-dimensional dynamic attributes. For example, the battery power has the physical characteristic that the battery power will decay over time, the temperature and humidity have the physical characteristic that the temperature and humidity are the same in the common space environment of wireless devices; the wireless signal strength has the physical characteristic that the wireless signal strength remains stable in the fixed wireless signal space of wireless devices.
[0178] Among them, the generation strategy of the access request for the data transmission attributes of the forest and grass communication relay is that the forest and grass communication relay generates the access request attributes for data transmission, including main body attributes, object attributes, permission attributes and environmental attributes; among them, the permission attribute is a write operation.
[0179] Among them, the initialization strategy of the key-policy attribute-based encryption of the forest and grass cloud platform is that the certificate authority (CA) generates the system public key PK and the system master key MK based on the key-policy attribute-based encryption mechanism (KP-ABE).
[0180] Among them, the generation strategy of the access control tree structure key of the forest and grass cloud platform is that the certificate authority (CA) calculates the decryption key S of the client user of the forest and grass cloud platform based on the system master key MK and the user attribute set W'.
[0181] Among them, the key-policy attribute-based data encryption (KP-ABE) strategy of the forest and grass communication relay is that the forest and grass communication relay uses the system public key PK, takes the data D submitted by the forest and grass communication relay and the access request attribute W as inputs, and generates the ciphertext C.
[0182] Among them, the key-policy attribute-based data decryption strategy of the forest and grass cloud platform is that the forest and grass cloud platform takes the ciphertext C as the input. If the access request attribute W meets the threshold requirements of the user attribute set W', the data D submitted by the forest and grass communication relay is restored.
[0183] Among them, the access control verification policy for the data transmission and input library of forest and grass communication relays is to perform access control verification on the set of client attributes of the forest and grass cloud platform to be accessed and the set of access control request attributes for the data transmission and input library of forest and grass communication relays.
[0184] S1.4, Install independent audit smart contracts and chain codes. Among them, the independent audit smart contracts include the chain operation strategy for independent audit sessions carried out by the forest and grass cloud platform in the blockchain network and the independent audit operation strategy, and the chain codes are installed through the server side of the forest and grass cloud platform;
[0185] (1) The chain operation strategy for independent audit sessions includes, but is not limited to, the chain strategy for independent audit notice sessions, the chain strategy for forest and grass communication relay audit reply sessions, the chain strategy for successful completion of independent audit sessions, and the chain strategy for ending independent audit failure sessions.
[0186] For the forest and grass IoT system, the content stored in the independent audit access session varies according to the session type, but the storage method is the same. That is, the access session initiation transaction needs to be calculated through the blockchain network consensus algorithm and then stored as a new block in the blockchain network to achieve the immutability and traceability of access behaviors.
[0187] The structure of the independent audit session is as follows:
[0188] Session (session ID, session type, session subject, session object, session sending time, session receiving time, session status), which is stored in the form of key-value pairs
[0189] Among them, the session ID is the unique number of the session;
[0190] The session type includes, but is not limited to, independent audit notice sessions, forest and grass communication relay audit reply sessions, successful completion of independent audit sessions, and independent audit failure sessions;
[0191] The session subject is the attribute of the session generator and sender, which can be represented by a single attribute or a composite key-value;
[0192] The session object is the attribute of the session receiver and storage party, which can be represented by a single attribute or a composite key-value;
[0193] The session sending time is the time when the session subject sends the session;
[0194] The session receiving time is the time when the session object receives the session;
[0195] The session status represents the current status of the session, including, but is not limited to, sent, received, send failed, receive failed.
[0196] For example, in an independent audit notice session, the session record is (session_ID: 20210000001, session_Type: "Independent Audit Notice Session", session_subject: {"sjy_ID": SJ001, deviceID: C2300101000XXX01, MAC: 48:e2:xx:xx:6f:f9}, session_object: {"sjy_ID": SJ001, deviceID: C2300101000XXX01, MAC: 48:e2:xx:xx:6f:f9}, createTime: 202104022038, endTime: 202104022039, session_result: "Sent").
[0197] The independent audit operation strategies include, but are not limited to, independent audit start decision-making strategy, independent audit notice attribute generation strategy, independent audit notice attribute encryption strategy, independent audit notice attribute broadcasting strategy, and independent audit detection strategy.
[0198] Among them, the independent audit start decision-making strategy is that the independent audit organization of the Forestry and Grassland Cloud Platform determines whether to initiate an independent audit action based on the independent audit start conditions set by the Forestry and Grassland Internet of Things system. Here, the independent audit start conditions can include, but are not limited to, reaching a specified time node or passing a specified time duration, such as auditing once a year, or starting an audit on December 1st every year, touching an emergency security state or a specific business function. For example, when the network situation awareness enters an emergency response state, an independent audit is initiated after the emergency situation is resolved.
[0199] Among them, the independent audit notice attribute generation strategy is that the independent audit organization of the Forestry and Grassland Cloud Platform generates the attributes of this audit. The audit notice is an attribute-based access control request, which consists of audit subject attributes, audit object attributes, permission attributes, and environmental attributes. For the Forestry and Grassland Internet of Things system, the audit subject attributes are the audit organization and audit client information, and a symmetric encryption algorithm and key for encrypting and transmitting data back to the audit object are generated. The object attributes are the forestry and grass communication relay and / or forestry and grass sensing terminals. The permission attributes are the operation permissions of the Forestry and Grassland Cloud Platform for the forestry and grass communication relay and / or forestry and grass sensing terminals. The environmental attributes are the environmental information at the time of independent audit generation.
[0200]
[0201] The audit subject attributes are the information of the audit organization and the audit client, such as: client IP, client port number, client account, encryption algorithm, symmetric key. {Client IP: 192.168.8.106, Client port number: 5058, Client account: auditadmin, Encryption algorithm: SM4, Symmetric key: Sa@123456}.
[0202] The object attributes are the forestry and grassland communication relay and / or forestry and grassland perception terminal, such as information like device name, device type, device MAC, etc., which are stored in the form of key-value pairs. {Device type: Forestry and grassland communication relay, Location of forestry and grassland communication relay: Luhuo County, Device name: Getwey101, Device MAC: 23:e4:xx:xx:5f:k9, Extended audit: Yes, Device type: Forestry and grassland Internet of Things terminal, Terminal location: Luhuo County, Device name: ALL, Device MAC: ALL}.
[0203] The operations of the permission attributes include read, write, and execute;
[0204] The environment attributes include but are not limited to the start time, end time, and initiator of the control access session.
[0205] A schematic of the audit notice for all forestry and grassland communication relays and forestry and grassland perception terminals deployed in Luhuo County, initiated by the client with the IP address 192.168.8.106 and the audit account auditadmin, from 20:38 on April 2, 2021 to 20:38 on April 3, 2021 is as follows:
[0206] {"Action": "audit", "Notice": {"AS": {"Client IP": "192.168.8.106", "Client user": "auditadmin", "Encryption algorithm": "SM4", "Symmetric key": "Sa@123456"}}, "AO": {"Device type": "Forestry and grassland communication relay", "Device location": "Luhuo County", "Device name": "ALL", "Device MAC": "ALL", "Extended audit": "Yes", "Device type": "Forestry and grassland Internet of Things terminal", "Terminal location": "Luhuo County", "Device name": "ALL", "Device MAC": "ALL"}, "AP": "read", "AE": {"Start time": "202104022038", "End time": "202104032038", "Initiator": "auditadmin"}}.
[0207] Among them, the encryption policy of the independent audit notice attribute is that the independent audit organization of the forestry and grassland cloud platform uses the CP-ABE encryption mechanism to initialize and generate the system public key PK, the system master key MK of the forestry and grassland cloud platform, and the decryption key S of the audited device, and encrypts it using PK, MK, and the generated independent audit access control policy.
[0208] (1) The Certificate Authority (CA) of the Forestry and Grassland Cloud Platform initializes and generates the system public key PK, the system master key MK of the Forestry and Grassland Cloud Platform, and the decryption key S of the audited device according to the attributes of the audited device.
[0209] (2) The independent audit organization of the Forestry and Grassland Cloud Platform encrypts the audit notice using PK, MK, and the independent audit access control policy.
[0210] Since the ciphertext length is small, the classical linear secret sharing matrix CP-ABE scheme is used for the ciphertext attribute encryption method here, which will not be elaborated here.
[0211] The independent audit access control policy here is determined by the audit object and the audit content. For example, when auditing all Internet of Things terminals in Luhuo County, the independent audit access control policy is "device type = Forestry and Grassland Internet of Things terminal AND terminal location = Luhuo County AND device name = ALL".
[0212] Due to the use of the ciphertext attribute encryption method, the Forestry and Grassland Cloud Platform can control who can access the data, ensuring encrypted communication between the independent audit organization of the Forestry and Grassland Cloud Platform and the Forestry and Grassland perception terminals without exposing the keys.
[0213] Among them, the independent audit notice attribute broadcast policy is that the independent audit organization of the Forestry and Grassland Cloud Platform makes an additional extended audit decision based on the object attribute of the independent audit notice attribute, and then broadcasts the ciphertext to the Forestry and Grassland communication relay to be audited.
[0214] Among them, the independent audit detection policy is that the independent audit organization of the Forestry and Grassland Cloud Platform obtains the audit data returned by the Forestry and Grassland communication relay, decrypts the data using the symmetric key generated during the encryption of the independent audit notice attribute, reads the data in the blockchain network for comparison and analysis, and detects the integrity and authenticity of the current and previous data.
[0215] S1.5, Installation of the data integrity detection smart contract and chain code. Among them, the data integrity detection smart contract includes the chain operation strategy and the integrity detection operation strategy for the data integrity detection access session between the Forestry and Grassland communication relay and the Forestry and Grassland Cloud Platform in the blockchain network, and the chain code is installed through the server side of the Forestry and Grassland Cloud Platform;
[0216] (1) The data integrity detection session chain operation strategy includes, but is not limited to, the session chain strategy generated by the fingerprint cloud database, the session chain strategy for the fingerprint cloud database chain, the session chain strategy for the client data integrity detection request, the session chain strategy for the data integrity detection failure, and the session chain strategy for the data integrity detection execution result.
[0217] For the forestry and grassland Internet of Things system, the content stored in the data integrity detection session varies according to the session type, but the storage method is the same. That is, the data integrity detection initiation transaction is to be calculated through the blockchain network consensus algorithm and then form a new block to be stored in the blockchain network to achieve the immutability and traceability of access behavior. The structure of the session generated by the fingerprint cloud database is as follows:
[0218] Session (session ID, session type, session subject, session object, session sending time, session receiving time, session status), stored in the form of key-value pairs
[0219] Among them, the session ID is the unique number of the session;
[0220] Session types include but are not limited to fingerprint cloud database generation session, fingerprint cloud database on-chain session, client data integrity detection request session, data integrity detection execution result session;
[0221] The session subject is the attribute of the session generator and sender, which can be represented by a single attribute or a composite key-value;
[0222] The session topic is the attribute of the session receiver and storage party, which can be represented by a single attribute or a composite key-value;
[0223] The session sending time is the time when the session subject sends the session;
[0224] The session receiving time is the time when the session object receives the session;
[0225] The session status represents the current status of the session, including but not limited to sent, received, send failed, receive failed.
[0226] For example, in the client data integrity detection request session, the session record is (session_ID: 20210000001, session_Type: "client data integrity detection request session", session_subject: {"sjy_ID": SJ001, deviceID: C2300101000XXX01, MAC: 48:e2:xx:xx:6f:f9}, session_object: {"sjy_ID": SJ001, deviceID: C2300101000XXX01, MAC: 48:e2:xx:xx:6f:f9}, createTime: 202104022038, endTime: 202104022039, session_result: "sent").
[0227] (2) The integrity detection operation strategy includes, but is not limited to, spatial data feature extraction strategy, spatial data fingerprint generation strategy, fingerprint cloud database generation strategy, fingerprint cloud database on-chain strategy, spatial data fingerprint comparison and detection strategy, data integrity detection result generation strategy, and data integrity detection result on-chain strategy.
[0228] Among them, for the spatial data feature extraction strategy, the forest and grass cloud platform obtains the spatial features and attribute features of the spatial vector data in the server-side internal resource database by executing the spatial feature extraction algorithm and the attribute feature extraction algorithm.
[0229] Among them, the spatial specific extraction algorithm calculates the centroid X coordinate, Y coordinate, element feature information, and spatial coordinate system of the spatial vector data in the server-side internal resource database, and forms a spatial feature with unique identification information through a connector. Among them, the element feature information is the length of the line for line elements and the area of the patch for polygon elements. On the premise that the topological relationship of spatial elements is correct, the extracted spatial features are unique.
[0230] For example, for the spatial vector data patch, the calculated X coordinate is 349087.34, the Y coordinate is 35452784.98, the element feature value is the area, which is 34.557875, and the spatial coordinate system is
[0231] CGCS2000_3_Degree_GK_CM_99E, and the connector is "-", then the spatial feature is "349087.34-35452784.98-34.557875-CGCS2000_3_Degree_GK_CM_99E".
[0232] Among them, the attribute feature extraction algorithm calculates the key attribute factors for data integrity detection in the spatial vector data in the server-side internal resource database, and forms attribute identification information through a connector.
[0233] For example, for the attribute information of the spatial vector data patch, the county code is 3327, the township code is 101, the village code is 101, the sub-compartment number is 0001, the tree species code is 601, the forest category code is 11, the administrative power code is 10, the forest land grade code is 1, and the origin code is 11. The connector is "-", then the attribute feature is "3327-101-101-0001-601-11-10-1-11".
[0234] Among them, for the spatial data fingerprint generation strategy, the forest and grass cloud platform connects the spatial features and attribute features extracted from the spatial vector data through a connector, and uses a hashing algorithm to perform information digest to form a spatial data fingerprint.
[0235] For example, the spatial characteristics of a certain spatial vector data patch are "349087.34-35452784.98-34.557875-CGCS2000_3_Degree_GK_CM_99E", the attribute characteristics are "3327-101-101-0001-601-11-10-1-11", the separator is "-", and after connection, it is "349087.34-35452784.98-34.557875-CGCS2000_3_Degree_GK_CM_99E-3327-101-101-0001-601-11-10-1-11". The national secret SM3 hashing algorithm is used for information digest, and the spatial data fingerprint in Base64 encoding format output is
[0236] "gSfb59rXqb1htCmqntJfFJ0bvQnUVwQStD4Nzu / 7tho="
[0237] Among them, for the fingerprint cloud database generation strategy, the Forestry and Grassland Cloud Platform generates spatial data fingerprints for all elements of the spatial vector data used for data integrity detection, and exports the administrative division and / or management division information describing the data area information together to generate a fingerprint cloud database in a pure attribute manner and stored independently.
[0238] For example, administrative division information includes, but is not limited to, provinces, cities, counties, townships, and villages; management division information includes, but is not limited to, forestry bureaus, forestry and grasslands, working areas, forest compartments, sub-compartments, and fine compartments.
[0239] Among them, for the fingerprint cloud database on-chain strategy, before the Forestry and Grassland Cloud Platform conducts data integrity detection, the client of the Forestry and Grassland Cloud Platform initiates a transaction for all records of the fingerprint cloud database. After calculation by the blockchain network consensus algorithm, a new block is formed and stored in the blockchain network to achieve the immutability and traceability of the fingerprint cloud database data.
[0240] Among them, for the spatial data fingerprint comparison and detection strategy, the Forestry and Grassland Cloud Platform obtains the stored fingerprint cloud database from the blockchain network according to the perception end fingerprint database and the detection area submitted by the forestry and grassland perception terminal for detection. Through the attribute query and comparison method, the spatial data fingerprints of the perception end fingerprint database in the detection area are compared with the spatial data fingerprints in the fingerprint cloud database, and the inconsistent spatial data fingerprints are marked.
[0241] Among them, for the spatial data fingerprint detection result generation strategy, the Forestry and Grassland Cloud Platform stores the marked inconsistent spatial data fingerprints separately to form a data integrity detection result database.
[0242] Among them, the data integrity detection result uploading strategy means that after the Forestry and Grassland Cloud Platform conducts data integrity detection, the client of the Forestry and Grassland Cloud Platform initiates a transaction for all records in the data integrity detection result database. After being calculated by the consensus algorithm of the blockchain network, a new block is formed and stored in the blockchain network, realizing the immutability and traceability of the data in the data integrity detection result database.
[0243] S1.6, Definition and chain code installation of the security situation awareness smart contract. Among them, the security situation awareness smart contract includes the data exchange operation strategy for the forestry and grassland perception terminal, forestry and grassland communication relay, and forestry and grassland cloud platform to access internal data through identity authentication, access control, and integrity detection, as well as the security situation awareness operation strategy initiated in the blockchain network when it fails.
[0244] (1) The data exchange operation strategy includes, but is not limited to, the device registration information warehousing strategy, the periodic operation configuration download strategy for the forestry and grassland communication relay, the data collection and transmission warehousing strategy for the forestry and grassland communication relay, the independent audit result warehousing strategy, and the data integrity detection result return strategy.
[0245] Among them, the device registration information warehousing strategy means that the device registrar uses the factory inspection function of the device management subsystem to detect that the registered device has no security hardening. Through the device scanning and registration function, the device barcode is scanned, and the device information, registration personnel information, registration operation information, and device fingerprint information background are formed into a device registration record, registering information other than the device static physical fingerprint and the device multi-dimensional dynamic feature fingerprint.
[0246] The database logical structure of the device registration is as follows:
[0247] Device registration (registration ID, device ID, device type, device mac, device power, device temperature, external humidity of the device, internal humidity of the device, channel fingerprint, radio frequency fingerprint, registration personnel number, registration batch number, registration workshop, registration time, device static physical fingerprint, device multi-dimensional dynamic feature fingerprint)
[0248] Among them, the registration ID is the unique identifier of the device registration list and is the primary key in the database; the device ID is the device number of the forestry and grassland Internet of Things device, and the device IDs within and between devices are all unique; the device type is the forestry and grassland Internet of Things device type, including but not limited to forestry and grassland communication relays, terminals, and mobile data collection terminals; the device mac is the mac address of the device, which is a unique and fixed mark of the device; the device power is the device power read during registration; the device temperature is the device temperature read during registration; the device humidity is the humidity sensor data on the outside of the device shell during registration, which is equivalent to the ambient humidity; the humidity inside the device is the humidity sensor data on the inside of the device shell during registration, and the airtightness of the device shell is detected by comparing the humidity inside and outside the device; the channel fingerprint is the signal strength of the wireless communication module of the forestry and grassland Internet of Things device, and the wireless communication module can be WIFI, Bluetooth, or LORA according to the different devices; the radio frequency fingerprint is the signal characteristic of the wireless communication module of the forestry and grassland Internet of Things device; the registered person number is the registered person number using the device registration client system after being authenticated by the MSP of the Fabric blockchain network; the registration batch number is the device number registered in this batch and is automatically generated according to the numbering rule; the registration workshop is the site name where the registration is completed during registration; the registration time is the time when the registration is scanned; the device static physical fingerprint is automatically generated according to the device static physical fingerprint generation strategy of the identity authentication smart contract; the device multi-dimensional dynamic feature fingerprint is automatically generated according to the device multi-dimensional dynamic feature fingerprint generation strategy of the identity authentication smart contract;
[0249] Among them, the periodic operation configuration download strategy of the forestry and grassland communication relay is that the forestry and grassland communication relay obtains the configured and generated periodic operation configuration of the forestry and grassland communication relay in the forestry and grassland cloud platform client from the forestry and grassland cloud platform; the periodic operation configuration of the forestry and grassland communication relay configured by the forestry and grassland cloud platform includes but not limited to the IP address, access port, access time, and access duration of the forestry and grassland cloud platform client;
[0250] Among them, the data collection and transmission into the database strategy of the forestry and grassland communication relay is that the forestry and grassland communication relay obtains the data transmission and storage configuration information and executes operations in the forestry and grassland cloud platform client from the forestry and grassland cloud platform, including but not limited to the database IP address, access port, database name, and database user of the forestry and grassland cloud platform client;
[0251] Among them, for the independent audit result storage strategy in the blockchain, the independent audit organization of the forestry and grassland cloud platform decrypts the audit data, and the forestry and grassland cloud platform client initiates a transaction for the audit result data. After being calculated by the consensus algorithm of the blockchain network, a new block is formed and stored in the blockchain network to achieve the immutability and traceability of the audit result data;
[0252] Among them, the data integrity detection result return policy is that the forestry and grassland cloud platform returns the detection result to the forestry and grassland perception terminal according to the data integrity detection result. According to the business type, for the unidirectional data integrity check business, after the data integrity detection passes, return True to the forestry and grassland perception terminal; otherwise, return False. For the data aggregation business, after the data integrity detection passes, agree to submit the data submitted by the forestry and grassland perception terminal to the server-side internal resource database; otherwise, return the data integrity detection result database to the forestry and grassland perception terminal.
[0253] (2) The security situation awareness operation policies include but are not limited to security situation awareness policies, security threat emergency response policies, DOS attack monitoring policies, and injection attack detection policies.
[0254] Among them, the security situation awareness policy is that the forestry and grassland cloud platform monitors the forestry and grassland communication relay with access control or decryption failure. When the number of failed accesses of the same forestry and grassland communication relay exceeds the specified threshold, the security threat emergency response policy is triggered.
[0255] Among them, the security threat emergency response policy is that the forestry and grassland cloud platform closes the access authorization of the forestry and grassland communication relay that exceeds the specified access threshold and notifies the system administrator of the information of the attacked forestry and grassland communication relay.
[0256] Among them, the DOS attack monitoring policy is that the forestry and grassland cloud platform monitors the forestry and grassland communication relay with failed independent audit result verification. When the number of failed accesses of the same forestry and grassland communication relay exceeds the specified threshold, the security threat emergency response policy is triggered.
[0257] Among them, the injection attack detection policy is to check whether there is false data injection attack in the forestry and grassland communication relay and / or forestry and grassland perception terminal. The mainstream methods include Kalman-type filters, deep learning, and neural networks, which will not be elaborated here.
[0258] S1.7, Initialize the forestry and grassland Internet of Things system, including initializing the registration of forestry and grassland Internet of Things device information, initializing the generation of spatial data fingerprints, initializing the key policy attribute-based encryption scheme, and key generation;
[0259] S1.7.1, Initialize the registration of forestry and grassland Internet of Things device information: The system administrator or authorized device management personnel use the static physical fingerprint generation policy of the identity authentication smart contract to form the device static physical fingerprint based on the registration information and static password, and then use the device registration information warehousing policy to form a new block of the device registration and device registration information and upload it to the blockchain network to complete the registration of the forestry and grassland Internet of Things device;
[0260] S1.7.2, Initialize and generate spatial data fingerprints: The server side of the forestry and grassland cloud platform calls the spatial data feature strategy to extract the spatial feature and attribute feature of the spatial vector data in the internal resource database of the server side, executes the spatial data fingerprint generation strategy to obtain the spatial data fingerprint, and after calculating through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of the fingerprint cloud database on-chain session;
[0261] S1.7.3, Initialize the key-policy attribute-based encryption scheme and generate keys: The client side of the forestry and grassland cloud platform calls the forestry and grassland cloud platform key-policy attribute-based encryption initialization strategy of the access control smart contract. The certificate authority (CA) generates the system public key PK and the system master key MK based on the key-policy attribute-based encryption mechanism (KP-ABE). Call the forestry and grassland cloud platform access control tree structure key generation strategy of the access control smart contract. The certificate authority (CA) calculates the decryption key S of the client user of the forestry and grassland cloud platform based on the system master key MK and the user attribute set W’
[0262] Calculate the decryption key S of the client user of the forestry and grassland cloud platform.
[0263] S2, The forestry and grassland IoT system runs periodically: The forestry and grassland IoT system wakes up the forestry and grassland communication relay and the forestry and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then goes into dormancy waiting for the next data collection cycle;
[0264] Such as Figure 4 , The specific steps in step S2 are as follows:
[0265] S2.1, The forestry and grassland communication relay initiates an identity authentication session for the first deployment;
[0266] The field investigators registered in the MSP of the Fabric blockchain network by each organization, after passing the identity authentication of the MSP, use the mobile data collection terminal connected to the forestry and grassland communication relay and configure the address and port of the access client. Then, the forestry and grassland communication relay sends the device registration information stored locally to the client, and sends an identity authentication access request to the forestry and grassland cloud platform through the client.
[0267] S2.2, The mobile data collection terminal connects and configures the forestry and grassland communication relay;
[0268] The field investigators registered in the MSP of the Fabric blockchain network, after passing the identity authentication, use the mobile data collection terminal to connect to the forestry and grassland communication relay and the forestry and grassland cloud platform, and download and store the dynamic access control policy of the access control smart contract in the forestry and grassland cloud platform, the data exchange operation policy of the security situation awareness smart contract, and the periodic operation configuration of the forestry and grassland communication relay locally to the forestry and grassland communication relay.
[0269] S2.3, The forest and grassland Internet of Things system operates periodically;
[0270] According to the configured periodic operation strategy, the forest and grassland Internet of Things system wakes up the forest and grassland communication relay and the forest and grassland sensing terminal at fixed intervals. The forest and grassland communication relay uses the configured address and port to send an identity authentication access request to the forest and grassland cloud platform through the client for the device registration information collected and updated locally. Based on the smart contract policy stored locally and the periodic operation configuration of the forest and grassland communication relay, the forest and grassland communication relay generates the main body attributes of the forest and grassland communication relay using the main body attribute generation strategy of the forest and grassland communication relay. After completing data collection, aggregation, and transmission, it enters a dormant state waiting for the next data collection cycle.
[0271] Among them, the main body static attribute generation strategy of the forest and grassland communication relay is that the forest and grassland communication relay directly reads its own unchanging attribute information, such as device name, device type, device MAC, etc., and stores it in the form of key-value pairs. {Device name: Getwey101, Device type: Forest and grassland communication relay, Device MAC: 23:e4:xx:xx:5f:k9}.
[0272] S3, The forest and grassland security situation awareness system performs identity authentication: The forest and grassland security situation awareness system calls the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay, and conducts static identity verification and continuous dynamic identity authentication on the forest and grassland communication relay; The forest and grassland communication relay generates the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland sensing terminal according to the periodic operation configuration strategy, and completes static identity verification and continuous dynamic identity authentication on the forest and grassland sensing terminal. If the authentication is passed, step S4 is executed; if the authentication fails, step S10 is executed;
[0273] Such as Figure 5 , The specific steps in step S3 are as follows:
[0274] S3.1, Create the static physical fingerprint of the forest and grassland communication relay and conduct static identity verification: The forest and grassland cloud platform client calls the static physical fingerprint generation strategy to generate the current static physical fingerprint of the forest and grassland communication relay based on the registration information of the forest and grassland communication relay sent by the forest and grassland cloud platform client, and then obtains the static physical fingerprint of the forest and grassland communication relay's last access on the blockchain platform, and calls the static identity authentication strategy to conduct static identity verification;
[0275] S3.2. Create a multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay and perform dynamic identity authentication: The forest and grassland cloud platform client calls the multi-dimensional dynamic feature fingerprint generation strategy, generates the multi-dimensional dynamic feature fingerprint of the current forest and grassland communication relay based on the registration information of the forest and grassland communication relay sent by the forest and grassland cloud platform client, then obtains the multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay when it was last accessed on the blockchain platform, calls the continuous dynamic identity authentication strategy to compare the two pieces of information and returns the identity authentication result;
[0276] S3.3, Lincao Communication Relay identity authentication result session upload to the blockchain network: The Lincao Cloud Platform client invokes the identity authentication session chain strategy to record the session information into the blockchain network, and invokes the device registration information storage strategy to add and update the current Lincao Communication Relay device access registration information into the database;
[0277] S3.4, the forest-grassland communication relay receives and stores the identity authentication access session information of the forest-grassland perception terminal: the forest-grassland communication relay receives the identity access request of the forest-grassland perception terminal, obtains the identity authentication session parameters of the forest-grassland perception terminal, and stores them locally in the forest-grassland communication relay;
[0278] S3.5. The forest-grassland communication relay creates a static physical fingerprint of the forest-grassland perception terminal and performs static identity authentication: The forest-grassland communication relay generates a static physical fingerprint for accessing the forest-grassland perception terminal based on the static physical fingerprint generation strategy stored locally, invokes the static identity authentication strategy, and compares the fingerprint with the static physical fingerprint of the forest-grassland perception terminal stored locally.
[0279] S3.6, the forest and grassland communication relay creates a multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal and performs dynamic identity authentication: the forest and grassland communication relay calculates and generates a multi-dimensional dynamic feature fingerprint based on the multi-dimensional dynamic feature fingerprint generation strategy stored locally, for the identity authentication session parameters of the forest and grassland perception terminal obtained, and the identity authentication session parameters of the last forest and grassland perception terminal obtained from the blockchain network when the forest and grassland communication relay is initialized and stored locally, and uses the continuous dynamic identity authentication strategy stored locally to compare and authenticate the two multi-dimensional dynamic feature fingerprints of the forest and grassland perception terminal.
[0280] S4, the forest and grassland security situation awareness system performs dynamic access control: the forest and grassland communication relay uses the key policy attribute-based encryption method to encrypt the forest and grassland communication relay data to form a ciphertext and initiates a data transmission attribute access request to the forest and grassland cloud platform. The forest and grassland security situation awareness system calls the dynamic access control smart contract to calculate the multi-dimensional subject attributes of the forest and grassland communication relay, decrypts and verifies whether the attributes of the forest and grassland communication relay pass the verification, completes the dynamic access control and returns the access result. If it passes the verification, execute step S5, if it fails the verification, execute step S10;
[0281] As Figure 6 , the specific steps in step S4 are as follows:
[0282] S4.1, Encryption of the forestry and grassland communication relay aggregated data by the key-policy attribute-based encryption mechanism: The forestry and grassland communication relay uses the forestry and grassland communication relay entity attributes and the public key of the forestry and grassland cloud platform system, and calls the forestry and grassland communication relay key-policy attribute-based data encryption policy to encrypt the forestry and grassland perception terminal data aggregated in the forestry and grassland communication relay to form ciphertext;
[0283] S4.2, The forestry and grassland communication relay initiates a data transmission attribute access request to the forestry and grassland cloud platform: The forestry and grassland communication relay uses the forestry and grassland communication relay data transmission attribute access request generation policy in the periodically running configuration downloaded to the local, and combines the forestry and grassland communication relay entity attributes to generate a forestry and grassland communication relay data transmission attribute access request, and sends a forestry and grassland communication relay data transmission attribute access request session to the forestry and grassland cloud platform;
[0284] For the forestry and grassland communication relay to generate data transmission access request attributes, it includes entity, object attributes, permission attributes, and environmental attributes; among them, the permission attribute is a write operation, that is, writing the perception data aggregated by the forestry and grassland communication relay into the database of the forestry and grassland cloud platform.
[0285] S4.3, The forestry and grassland cloud platform uploads the data transmission session of the forestry and grassland communication relay to the blockchain network: The forestry and grassland cloud platform calls the data transmission session on-chain policy, initiates a transaction for the data transmission session access request session sent by the forestry and grassland communication relay, and after calculation by the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network to achieve the immutability and traceability of the access behavior;
[0286] S4.4, The forestry and grassland cloud platform calculates the multi-dimensional dynamic attributes of the forestry and grassland communication relay: The forestry and grassland cloud platform calls the forestry and grassland communication relay entity multi-dimensional dynamic attribute calculation policy, obtains the forestry and grassland communication relay entity attributes stored in the previous access session in the blockchain network, uses the physical model to perform simulation calculations on the multi-dimensional dynamic attributes, and simulates and calculates the forestry and grassland communication relay entity attribute values of this access session;
[0287] S4.5, The forestry and grassland cloud platform performs access control verification on the forestry and grassland communication relay data transmission: The forestry and grassland cloud platform calls the forestry and grassland communication relay data collection and transmission into the library access control verification policy, and combines the simulated forestry and grassland communication relay entity attribute values to verify the forestry and grassland communication relay entity attributes of the current session;
[0288] S4.6, Key-policy attribute-based data decryption of the forestry and grassland cloud platform: The forestry and grassland cloud platform calls the forestry and grassland cloud platform key-policy attribute-based data decryption policy, and uses the key S related to the access structure assigned to the forestry and grassland cloud platform client user during the initialization of the forestry and grassland cloud platform to perform decryption operations. When the attributes in the ciphertext satisfy the access control tree, the decryption is successful.
[0289] S5. The forest and grass security situation awareness system performs integrity detection: The forest and grass security situation awareness system compares the spatial data fingerprints submitted by the forest and grass perception terminals obtained by decryption with the spatial data fingerprints initially generated and stored in the blockchain, completes the integrity detection of the forest and grass Internet of Things data and returns the detection results. If the detection is passed, step S6 is executed; if not, step S10 is executed.
[0290] Such as Figure 7 , the steps in step S5 include the following steps:
[0291] S5.1. The forest and grass perception terminal obtains the spatial data fingerprint database generation strategy: The forest and grass perception terminal accesses the forest and grass cloud platform client or the blockchain network to obtain the spatial data feature extraction strategy, the spatial data fingerprint generation strategy, and the fingerprint database generation strategy.
[0292] The above strategies are open to and freely accessible by each forest and grass perception terminal on the forest and grass cloud platform to ensure the accuracy and timeliness of data integrity detection.
[0293] S5.2. The forest and grass perception terminal performs spatial data feature extraction: For the spatial database used for data integrity detection, the forest and grass perception terminal locally executes the spatial data feature extraction strategy to obtain the spatial vector data spatial features and attribute features of the perception-side spatial database.
[0294] Similar to the server side of the forest and grass cloud platform, usually two text fields of spatial features and attribute features are added to the spatial database used for data integrity detection. The calculated spatial features and attribute features are stored.
[0295] S5.3. The perception-side spatial data fingerprint generation: The forest and grass cloud platform perception terminal executes the spatial data fingerprint generation strategy for the spatial data that has obtained spatial features and attribute features for data integrity detection to obtain the spatial data fingerprint of the forest and grass cloud platform perception terminal's spatial database.
[0296] Similar to the server side, usually one text field of data fingerprint is added to the spatial database used for data integrity detection, and the calculated spatial data fingerprint in Base64 encoding format is stored.
[0297] S5.4. The perception-side fingerprint cloud database generation: The forest and grass cloud platform perception terminal executes the fingerprint cloud database generation strategy for the spatial data that has obtained the spatial data fingerprint for data integrity detection to obtain the forest and grass cloud platform perception terminal's fingerprint database.
[0298] S5.5, The sensing end sends a data integrity detection request and the sensing end fingerprint database: The sensing end of the Forestry and Grassland Cloud Platform sends a data integrity detection request to the client of the Forestry and Grassland Cloud Platform and submits the sensing end fingerprint database to complete the data integrity detection;
[0299] S5.6, The data integrity detection request session of the sensing end is chained to the blockchain: The client of the Forestry and Grassland Cloud Platform executes the session chaining strategy for generating the fingerprint cloud database. The client of the Forestry and Grassland Cloud Platform initiates a transaction for the client data integrity detection request session. After being calculated by the blockchain network consensus algorithm, a new block is stored in the blockchain network, realizing the immutability and traceability of the data collection and data integrity detection behaviors of the forestry and grassland sensing terminals;
[0300] S5.7, The server-side spatial data fingerprint comparison and detection: The server side of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint comparison and detection strategy. Taking the sensing end fingerprint database submitted for detection by the sensing end of the Forestry and Grassland Cloud Platform as the input, it obtains the fingerprint cloud database from the blockchain network. Through the attribute query and comparison method, it compares the spatial data fingerprints of the sensing end fingerprint database with the spatial data fingerprints in the fingerprint cloud database and marks the inconsistent spatial data fingerprints;
[0301] S5.8, The server side obtains the data integrity detection result: The server side of the Forestry and Grassland Cloud Platform executes the strategy for generating the spatial data fingerprint detection result. The inconsistent spatial data fingerprints are separately stored to form the data integrity detection result database;
[0302] S5.9, The data integrity detection result is chained to the blockchain: The client of the Forestry and Grassland Cloud Platform executes the data integrity detection result chaining strategy. All records of the data integrity detection result database are initiated for transactions. After being calculated by the blockchain network consensus algorithm, a new block is stored in the blockchain network, realizing the immutability and traceability of the data in the data integrity detection result database;
[0303] S5.10, The data integrity detection execution result session is chained to the blockchain: The client of the Forestry and Grassland Cloud Platform executes the data integrity detection execution result session chaining strategy. The server-side data integrity detection execution result session is initiated for transactions. After being calculated by the blockchain network consensus algorithm, a new block is stored in the blockchain network, realizing the immutability and traceability of the data integrity detection behavior.
[0304] S6, The Forestry and Grassland Cloud Platform submits data and returns the access result: The forestry and grassland communication relay sends the collected monitoring data to the Forestry and Grassland Cloud Platform. The forestry and grassland Internet of Things application system connects to the internal resource database to complete data warehousing, returns the periodic operation configuration and periodic operation strategy, and waits for the next data collection cycle;
[0305] Such as Figure 8, the steps in step S6 include the following steps:
[0306] S6.1, The forestry and grassland communication relay downloads the periodic operation configuration of the forestry and grassland communication relay: The forestry and grassland communication relay uses the periodic operation configuration download policy of the forestry and grassland communication relay to read and download the forestry and grassland IoT periodic operation policy configuration information in the forestry and grassland cloud platform database to the local of the forestry and grassland communication relay for periodic operation after the next sleep wake-up of the forestry and grassland communication relay.
[0307] S6.2, The forestry and grassland communication relay stores the data collected by the forestry and grassland sensing terminal and issues the periodic operation configuration: The forestry and grassland communication relay receives the identity authentication parameters and the collected data transmitted by the forestry and grassland sensing terminal, stores them in the forestry and grassland communication relay, and issues the periodic operation policy of the forestry and grassland sensing terminal stored locally to the forestry and grassland sensing terminal to ensure the next operation.
[0308] For the forestry and grassland IoT system, the identity authentication parameter information is the same as the device registration and registration format. For the collected data, according to the different types of sensors, the transmission and storage policy data formats are different. For the forest tree (carbon) table device, it includes but is not limited to tree species, standing tree types, diameter at breast height, tree height, hourly temperature sequence, and hourly humidity sequence. The periodic operation policy of the forestry and grassland sensing terminal includes but is not limited to the address and port of the forestry and grassland sensing terminal to access the forestry and grassland communication relay next time, as well as periodic monitoring configuration information such as wake-up time and wake-up duration.
[0309] S6.3, The forestry and grassland communication relay sends the collected data to the forestry and grassland cloud platform: If the identity authentication, access control, and data integrity detection of the forestry and grassland communication relay pass, it agrees to submit the data submitted by the sensing end to the internal resource database of the server end. If not, it returns the data integrity detection result database to the sensing end;
[0310] S7, Determine whether the monitoring ends. If not, execute step S8. If so, terminate the process;
[0311] Due to project requirements or force majeure, if the forestry and grassland sensing terminal, the forestry and grassland communication relay, and the forestry and grassland cloud platform stop running simultaneously or partially, it is considered that the monitoring ends.
[0312] S8, Determine whether to trigger an independent audit: The forestry and grassland security situation awareness system determines whether to trigger the independent audit start condition by executing the independent audit smart contract. If so, execute step S9. If not, execute step S2;
[0313] The forestry and grassland IoT system executes the independent audit start strategy of the independent security audit smart contract to determine whether to trigger an independent audit. If the independent audit start condition is reached, the reviewers' accounts organized by the audit department registered through MSP in the blockchain network conduct an independent audit on the alliances, organizations, and administrators of the forestry and grassland IoT system to be audited.
[0314] The independent audit start conditions here can include but are not limited to reaching a specified time node or passing a specified time duration. For example, an audit is conducted once a year, or the audit starts on December 1st every year. It also includes touching an emergency security state or a fixed business function. For example, when the network situation awareness enters an emergency handling state, an independent audit is automatically started after the handling.
[0315] S9. The forest and grassland security situation awareness system conducts an independent audit: The forest and grassland security situation awareness system generates an independent audit notice and broadcasts it encrypted. The audited device receives the audit notice, conducts the audit, and returns the audit data. The forest and grassland security situation awareness system verifies the returned audit data, and stores the audit session and audit results on the chain. If the audit passes, step S2 is executed; if the audit fails, step S10 is executed.
[0316] Such as Figure 9 , the steps in step S9 include the following steps:
[0317] S9.1. The forest and grassland cloud platform generates an audit notice: The independent audit notice attribute generation policy executed by the forest and grassland cloud platform generates an audit notice.
[0318] The audit notice is an attribute-based access control request, which consists of an audit subject attribute, an audit object attribute, a permission attribute, and an environment attribute. For the forest and grassland Internet of Things system, the audit subject attribute is the audit organization and audit client information, and a symmetric encryption algorithm and key for encrypting and transmitting data back for the audit object are generated. The object attribute is the forest and grassland communication relay and / or forest and grassland sensing terminal. The permission attribute is the operation permission of the forest and grassland cloud platform for the forest and grassland communication relay and / or forest and grassland sensing terminal. The environment attribute is the environment information when the independent audit is generated.
[0319] The audit subject attribute is the audit organization and audit client information. For example: client IP, client port number, client account, encryption algorithm, symmetric key. {Client IP: 192.168.8.106, Client port number: 5058, Client account: auditadmin, Encryption algorithm: SM4, Symmetric key: Sa@123456}.
[0320] The object attribute is the forest and grassland communication relay and / or forest and grassland sensing terminal. For example, information such as device name, device type, and device MAC is stored in a key-value pair manner. {Device type: Forest and grassland communication relay, Location of forest and grassland communication relay: Luhuo County, Device name: Getwey101, Device MAC: 23:e4:xx:xx:5f:k9, Extended audit: Yes, Device type: Forest and grassland Internet of Things terminal, Terminal location: Luhuo County, Device name: ALL, Device MAC: ALL}.
[0321] Operations on permission attributes include read, write, and execute;
[0322] Environmental attributes include, but are not limited to, the start time, end time, and initiator of the control access session.
[0323] The following is a schematic of an audit notice for all forestry and grassland communication relays and forestry and grassland sensing terminals deployed in Luhuo County, initiated by the audit account auditadmin of the client with the IP address 192.168.8.106, and conducted from 20:38 on April 2, 2021 to 20:38 on April 3, 2021:
[0324] {"Action": "audit", "Notice": {"AS": {"Client IP": "192.168.8.106", "Client User": "auditadmin", "Encryption Algorithm": "SM4", "Symmetric Key": "Sa@123456"}}, "AO": {"Device Type": "Forestry and Grassland Communication Relay", "Device Location": "Luhuo County", "Device Name": "ALL", "Device MAC": "ALL", "Extended Audit": "Yes", "Device Type": "Forestry and Grassland Internet of Things Terminal", "Terminal Location": "Luhuo County", "Device Name": "ALL", "Device MAC": "ALL"}, "AP": "read", "AE": {"Start Time": "202104022038", "End Time": "202104032038", "Initiator": "auditadmin"}}}
[0325] S9.2, The forestry and grassland cloud platform chains the independent audit notice session: After the forestry and grassland cloud platform triggers the audit condition to be met, the forestry and grassland cloud platform generates an audit notice, distributes the audit notice to the forestry and grassland communication relay and / or the forestry and grassland sensing terminal. The forestry and grassland cloud platform client initiates a transaction for distributing the audit notice session, and through the blockchain network consensus algorithm calculation, forms a new block and stores it into the blockchain network, realizing the non-tampering and traceability of the audit notice behavior;
[0326] S9.3, The forestry and grassland cloud platform encrypts the audit notice using the ciphertext attribute encryption method: The forestry and grassland cloud platform executes the independent audit notice attribute encryption policy and encrypts the audit notice using the ciphertext attribute encryption method;
[0327] Before encryption, (1) The certificate authority CA of the forestry and grassland cloud platform initializes and generates the system public key PK, the system master key MK, and the decryption key S of the audited device according to the attributes of the audited device.
[0328] (2) The independent audit organization of the forest and grass cloud platform uses PK, MK, and the independent audit access control policy to encrypt the audit notice. Since the length of the ciphertext is small, the classical linear secret sharing matrix CP-ABE scheme is used for the ciphertext attribute encryption method here, which will not be elaborated here. The independent audit access control policy here is determined by the audit object and the audit content. For example, when auditing all Internet of Things terminals in Luhuo County, the independent audit access control policy is "device type = forest and grass Internet of Things terminal AND terminal location = Luhuo County AND device name = ALL". Due to the use of the ciphertext attribute encryption method, the forest and grass cloud platform can control who can access the data, ensuring that the independent audit organization of the forest and grass cloud platform and the forest and grass perception terminals can conduct encrypted communication without exposing the keys.
[0329] S9.4, The forest and grass cloud platform broadcasts the audit notice to the forest and grass communication relay: The forest and grass cloud platform executes and sends the encrypted audit notice ciphertext to the forest and grass communication relay in the next data collection cycle;
[0330] Here, the audit notice is encrypted by the CP-ABE scheme. Only when the attributes of the audited device meet the access policy of CP-ABE can the audit notice content be decrypted.
[0331] S9.5, The forest and grass communication relay decrypts the audit notice and conducts an independent audit according to the requirements of the audit notice: The forest and grass communication relay uses the system public key of the forest and grass cloud platform to obtain the attributes and private key of the current forest and grass communication relay, decrypts the audit notice ciphertext. If the attributes of the forest and grass communication relay meet the access policy of the audit notice ciphertext, then decrypt the ciphertext and obtain the audit notice content;
[0332] S9.6, The forest and grass perception terminal decrypts the audit notice and conducts an independent audit according to the requirements of the audit notice: The forest and grass communication relay uses the system public key of the forest and grass cloud platform to obtain the attributes and private key of the current forest and grass perception terminal, decrypts the audit notice ciphertext. If the attributes of the forest and grass perception terminal meet the access policy of the audit notice ciphertext, then decrypt the ciphertext and obtain the audit notice content, execute the audit notice content to form audit data and submit it to the forest and grass communication relay;
[0333] S9.7, The forest and grass communication relay submits the audit data according to the requirements of the audit notice: The forest and grass communication relay encrypts and uploads the forest and grass perception terminals and the data stored locally collected according to the requirements of the audit notice, and returns them to the forest and grass cloud platform for auditing;
[0334] S9.8, The forest and grass cloud platform chains the audit reply session of the forest and grass communication relay: The forest and grass cloud platform client initiates a transaction for the audit reply session of the forest and grass communication relay, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of the audit reply behavior of the forest and grass communication relay;
[0335] S9.9, The Forestry and Grassland Cloud Platform decrypts the audit feedback data and conducts a comparison audit: The audit organization client of the Forestry and Grassland Cloud Platform decrypts the feedback data using a symmetric key to obtain the audit data, then reads the historical data of the audited device from the blockchain network, and conducts a comparison audit on the historical data and the audit data;
[0336] S9.10, The Forestry and Grassland Cloud Platform conducts an independent audit detection and gives an audit result: The Forestry and Grassland Cloud Platform executes an independent audit detection strategy to detect the integrity and authenticity of the current and previous data. If the audited device replies with audit data that is inconsistent with the historical data in the blockchain network, then execute step S10;
[0337] S9.11, The Forestry and Grassland Cloud Platform successfully completes the session of the independent audit and uploads it to the blockchain: The client of the Forestry and Grassland Cloud Platform initiates a transaction for the successfully completed audit session. After being calculated by the consensus algorithm of the blockchain network, a new block is formed and stored in the blockchain network, realizing the immutability and traceability of the audit result behavior;
[0338] S9.12, The Forestry and Grassland Cloud Platform records and stores the audit session and result: The Forestry and Grassland Cloud Platform calls the strategy for storing the independent audit results in the repository, and stores the audit data and audit results obtained from the local audit into the database.
[0339] S10, The Forestry and Grassland Security Situation Awareness System executes security situation awareness: The Forestry and Grassland Security Situation Awareness System stores the information record of the failed access session of this time into the blockchain network, reads the historical access session records in the blockchain network, evaluates the access times and access situations of the current client and the Forestry and Grassland communication relay, determines whether it is under attack and takes corresponding measures to prevent the attack; then execute step S7.
[0340] Such as Figure 10 , the steps in step S10 include the following steps:
[0341] S10.1, When the identity authentication fails, conduct security situation awareness and emergency handling: When the identity authentication fails, the identity authentication failure session upload strategy called by the client of the Forestry and Grassland Cloud Platform records the information of the failed access session of this identity authentication into the blockchain network; and calls the security situation awareness strategy, reads the historical access session records in the blockchain network, evaluates the access times of the current client and the Forestry and Grassland communication relay to determine whether there is a DOS attack. If the access IP and / or access port has an access exceeding the upper limit threshold, call the security threat emergency handling strategy to urgently close the current access IP and / or access port to prevent the DOS attack;
[0342] S10.2, Conduct security situation awareness and emergency response in case of access control failure: When access control or decryption fails, the Forestry and Grassland Cloud Platform invokes the access control failure session chain-up strategy, sends the access control failure session initiation transaction sent by the Forestry and Grassland Communication Relay, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of access behaviors; and invokes the security situation awareness strategy, reads the historical access session records in the blockchain network, evaluates the access times of the current client and the Forestry and Grassland Communication Relay to determine whether there is a DOS attack. If the access to the access IP and / or access port exceeds the access upper limit threshold, the security threat emergency response strategy of the security situation awareness smart contract is invoked to urgently close the current access IP and / or access port to prevent the DOS attack;
[0343] S10.3, Conduct security situation awareness and emergency response in case of integrity detection failure: When the data integrity detection fails, the Forestry and Grassland Cloud Platform client invokes the integrity detection failure session chain-up strategy, sends the integrity detection failure session initiation transaction sent by the Forestry and Grassland Communication Relay, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of access behaviors;
[0344] The Forestry and Grassland Cloud Platform server executes the DOS attack monitoring strategy. The Forestry and Grassland Cloud Platform queries the Forestry and Grassland perception terminal with failed data integrity detection in the blockchain network, obtains the failed access times of the Forestry and Grassland perception terminal for this request detection, and determines whether the failed access times exceed the defined threshold. If so, it is determined that there is a DOS attack threat and the security threat emergency response strategy is triggered.
[0345] S10.4, Conduct security situation awareness and emergency response in case of independent audit failure: When the independent audit result verification fails, the Forestry and Grassland Cloud Platform client sends the audit failure end session transaction, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of audit failure behaviors; the Forestry and Grassland Cloud Platform executes the security situation awareness smart contract response strategy based on the audit result and rectifies the audit result.
[0346] When the audit result is: the audit fails and the Forestry and Grassland Cloud Platform is suspected of being attacked, pay attention to denial-of-service attacks and internal attacks. Execute the DOS attack monitoring strategy of the security situation awareness smart contract to check whether the access to the access IP and / or access port exceeds the access upper limit threshold. If not, focus on screening for internal attacks.
[0347] When the audit result is: the audit fails, and it is suspected that the forestry and grassland cloud platform has been attacked. Pay attention to injection attacks and internal attacks. Execute the injection attack detection strategy of the security situation awareness smart contract to check whether there are false data injection attacks on the forestry and grassland communication relay and / or forestry and grassland perception terminals. The mainstream methods include Kalman filters, deep learning, and neural networks, which will not be elaborated here. Otherwise, focus on screening internal attacks.
[0348] When the audit result is: the audit fails, and it is suspected that the forestry and grassland Internet of Things devices have been attacked. Pay attention to device hijacking. The investigators should go to the site to check whether the forestry and grassland Internet of Things devices are currently lost or damaged.
[0349] When the audit result is: the audit fails, and it is suspected that the forestry and grassland Internet of Things devices have been physically attacked. Pay attention to physical damage attacks and device failures. The investigators should go to the site to check whether the forestry and grassland Internet of Things devices are currently lost or damaged.
[0350] Such as Figure 1 , the forestry and grassland security situation awareness system includes:
[0351] Blockchain creation, smart contract definition, and system initialization module: used for initializing the blockchain network, completing identity authentication, access control, independent audit, integrity detection smart contract definition, and chain code installation, and completing the initialization of the forestry and grassland Internet of Things system;
[0352] Forestry and grassland communication relay identity authentication module: used for the forestry and grassland cloud platform client to respectively call the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forestry and grassland communication relay, and perform static identity verification and continuous dynamic identity authentication on the forestry and grassland communication relay;
[0353] Attribute-based data encryption access control request generation module: used for using the periodic operation configuration of the forestry and grassland communication relay to generate the subject attributes of the forestry and grassland communication relay, combining with the public key of the forestry and grassland cloud platform system, and using the forestry and grassland communication relay key policy attribute-based data encryption policy to encrypt the forestry and grassland perception terminal data collected in the forestry and grassland communication relay to form ciphertext, and initiate a data transmission attribute access request to the forestry and grassland cloud platform;
[0354] Attribute-based data encryption access control request verification module: used for combining the subject attributes of the simulated forestry and grassland communication relay to verify whether the attributes of the forestry and grassland communication relay pass the verification;
[0355] Server-side data integrity detection module: used for the forestry and grassland cloud platform to compare the spatial data fingerprints submitted by the forestry and grassland perception terminals obtained by decryption with the spatial data fingerprints initially generated and stored in the blockchain to verify the data integrity detection of the forestry and grassland Internet of Things and return the detection results.
[0356] Trigger Audit Judgment Module: Used by the Forestry and Grassland Cloud Platform to determine whether to trigger the independent audit start condition by executing an independent audit smart contract;
[0357] Independent Audit Notification Generation and Encrypted Broadcast Module: Used by the Forestry and Grassland Cloud Platform to generate an independent audit notification, encrypt the independent audit notification using the ciphertext attribute encryption method, and broadcast the independent audit notification ciphertext to the Forestry and Grassland Communication Relay by the Forestry and Grassland Cloud Platform in the next data collection cycle;
[0358] Audit Device Returned Audit Result Verification Module: Used by the Forestry and Grassland Cloud Platform to decrypt the returned audit data and compare it with the historical data stored in the blockchain network, and complete the data integrity and system security detection by judging the data consistency;
[0359] Forestry and Grassland Internet of Things Security Situation Awareness and Emergency Disposal Module: Used by the Forestry and Grassland Cloud Platform to store the failure information record of the current access session into the blockchain network, read the historical access session records in the blockchain network, evaluate the access times and access situations of the current client and the Forestry and Grassland Communication Relay to determine whether it is attacked and take corresponding measures to prevent the attack.
[0360] Such as Figure 1 , the Forestry and Grassland Internet of Things application system includes:
[0361] Forestry and Grassland Internet of Things System Periodic Operation Module: Used by the Forestry and Grassland Internet of Things system to wake up the Forestry and Grassland Communication Relay and the Forestry and Grassland Sensing Terminal at fixed intervals according to the configured periodic operation strategy, complete data collection, aggregation and transmission, and then go into dormancy waiting for the next data collection cycle;
[0362] Attribute-based Encryption Data Decryption Module: Used by the Forestry and Grassland Cloud Platform to decrypt the ciphertext transmitted by the Forestry and Grassland Internet of Things using the key related to the access structure, and transmit the successfully decrypted data through the Forestry and Grassland Communication Relay;
[0363] Forestry and Grassland Sensing Terminal Identity Authentication Module: Used by the Forestry and Grassland Communication Relay to receive and store the identity authentication access session information of the Forestry and Grassland Sensing Terminal according to the locally downloaded periodic operation configuration strategy, and then combine the periodic security awareness configuration strategy to generate the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the Forestry and Grassland Sensing Terminal, complete the static identity authentication and continuous dynamic identity authentication, and store the data collected by the Forestry and Grassland Sensing Terminal locally;
[0364] Perception End Space Data Fingerprint Database Generation Module: Used by the Forestry and Grassland Cloud Platform perception end to perform space data feature extraction and space data fingerprint generation, generate the perception end fingerprint database, and then send a data integrity detection request and the perception end fingerprint database to the Forestry and Grassland Cloud Platform server;
[0365] Forest and Grassland Communication Relay Audit Module: It is used for the forest and grassland communication relay to decrypt the independent audit notice ciphertext. When the attributes of the forest and grassland communication relay conform to the access policy of the independent audit notice, the ciphertext is decrypted to obtain the content of the independent audit notice, and the independent audit is carried out according to the requirements of the independent audit notice and the audit data is transmitted back;
[0366] Forest and Grassland Sensing Terminal Extended Audit Module: It is used for the forest and grassland sensing terminal to receive the independent audit notice sent by the forest and grassland communication relay and decrypt it when the independent audit notice requires extended audit. When the attributes of the forest and grassland sensing terminal conform to the access policy of the independent audit notice, the ciphertext is decrypted to obtain the content of the independent audit notice, and the independent audit is carried out according to the requirements of the independent audit notice and the audit data is transmitted back;
[0367] Forest and Grassland Cloud Platform Access Session Blockchain Module: It is used for the forest and grassland cloud platform client to blockchain the access request session and access request result session of the forest and grassland sensing terminal and the forest and grassland communication relay;
[0368] Data Storage and Download Module: It is used for the forest and grassland cloud platform client to store the transmission data submitted by the forest and grassland communication relay into the internal resource database and issue the periodic operation configuration and acquired data of the server side.
[0369] To better understand the technical solution of the present invention, the following is an embodiment of the execution process of the zero-trust forest and grassland Internet of Things system based on blockchain of the present invention, as Figure 11 :
[0370] (1) The system administrator executes the blockchain creation, smart contract definition and system initialization module, creates a blockchain network in the forest and grassland cloud platform, completes the smart contract definition and chain code installation, and completes the initialization of the forest and grassland Internet of Things system.
[0371] (2) The forest and grassland Internet of Things system executes the forest and grassland Internet of Things system periodic operation module, wakes up the forest and grassland communication relay and the forest and grassland sensing terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then goes to sleep waiting for the next data collection cycle.
[0372] (3) After the forest and grassland communication relay is woken up according to the periodic operation configuration, the forest and grassland communication relay executes the forest and grassland communication relay identity authentication module and initiates an identity authentication session to the forest and grassland cloud platform.
[0373] (4) After the forest and grassland sensing terminal is woken up according to the periodic operation configuration, the forest and grassland sensing terminal executes the forest and grassland sensing terminal identity authentication module and initiates an identity authentication session to the forest and grassland communication relay.
[0374] (5) The forest and grassland sensing terminal executes the sensing terminal spatial data fingerprint database generation strategy to generate the sensing terminal fingerprint database.
[0375] (6) The forestry and grassland communication relay executes the attribute-based data encryption access control request generation module to initiate an attribute-based data encryption access control request to the forestry and grassland cloud platform.
[0376] (7) The forestry and grassland cloud platform executes the attribute-based data encryption access control request verification module to verify whether the attributes of the forestry and grassland communication relay pass the verification.
[0377] (8) The forestry and grassland cloud platform executes the attribute-based encrypted data decryption module to decrypt the ciphertext transmitted by the forestry and grassland Internet of Things.
[0378] (9) The forestry and grassland cloud platform executes the server-side data integrity detection module to obtain the data integrity detection result.
[0379] (10) The forestry and grassland cloud platform executes the forestry and grassland cloud platform access session on-chain module to chain the client access request session and the access request result session.
[0380] (11) The forestry and grassland cloud platform executes the data storage and download module to store the submitted transmission data into the internal resource database and distribute the server-side periodic operation configuration and the obtained data.
[0381] (12) The forestry and grassland cloud platform executes the trigger audit judgment module to judge whether the independent audit start condition is triggered. If yes, execute step (13); if no, execute step (2).
[0382] (13) The forestry and grassland cloud platform executes the independent audit notification generation and encryption broadcast module to generate, encrypt, and broadcast an independent audit notification to the audited devices.
[0383] (14) The forestry and grassland communication relay executes the forestry and grassland communication relay audit module to conduct the forestry and grassland communication relay audit according to the requirements of the independent audit notification.
[0384] (15) The forestry and grassland sensing terminal executes the forestry and grassland sensing terminal extended audit module to conduct the forestry and grassland sensing terminal audit according to the requirements of the independent audit notification.
[0385] (16) The forestry and grassland cloud platform executes the module for verifying the audit results returned by the audited devices to verify data integrity and system security.
[0386] (17) The forestry and grassland cloud platform executes the security situation awareness and emergency response module to perform security situation awareness and emergency response according to the access results by type.
[0387] (18) Judge whether the monitoring is over. If no, execute step (2); if yes, the process terminates.
[0388] For those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can also be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A blockchain-enabled zero-trust security protection method for forestry and grassland Internet of Things, characterized in that, This is achieved through the Forestry and Grassland Cloud Platform, which includes: Forestry and grassland IoT application system: used to receive reports and return data and requests from forestry and grassland communication relays, convert them into access sessions, store them in the blockchain, and submit them to the forestry and grassland security situation awareness system. Based on the results returned by the forestry and grassland security situation awareness system, it executes secure access to internal resources by the forestry and grassland communication relays. Forestry and grassland security situation awareness system: used to receive forestry and grassland IoT application system sessions and, through smart contracts and combined with internal resources, decide whether to authorize submitted request sessions. It also determines the current security situation based on the current status of the forestry and grassland IoT system and whether to conduct an independent audit. Cloud platform: Cloud platform resources and application platforms used to support the forest and grassland Internet of Things application system and the forest and grassland security situation awareness system, providing system operating conditions and basic software and hardware environment; The blockchain-enabled zero-trust forest and grassland IoT system security protection method includes the following steps: S1, blockchain creation, smart contract definition and system initialization: complete the definition and chain code installation of the identity authentication smart contract, access control smart contract, integrity detection smart contract, independent audit smart contract, and security situation awareness smart contract, initialize the device registration information of the Lincao Cloud Platform, and generate the spatial data fingerprint and key system; S2, periodic operation of the forest and grassland IoT system: The forest and grassland IoT system wakes up the forest and grassland communication relay and forest and grassland perception terminal at fixed intervals according to the configured periodic operation strategy, completes data collection, aggregation and transmission, and then sleeps and waits for the next data collection cycle; S3, the forest and grassland security situation awareness system performs identity authentication: the forest and grassland security situation awareness system calls the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay, and performs static identity authentication and continuous dynamic identity authentication on the forest and grassland communication relay; the forest and grassland communication relay generates the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forest and grassland perception terminal according to the periodic operation configuration strategy, and completes static identity authentication and continuous dynamic identity authentication for the forest and grassland perception terminal. If the authentication is passed, step S4 is executed; if the authentication is not passed, step S10 is executed; S4, the forest and grassland security situation awareness system performs dynamic access control: the forest and grassland communication relay uses the key policy attribute-based encryption method to encrypt the forest and grassland communication relay data to form a ciphertext and initiates a data transmission attribute access request to the forest and grassland cloud platform. The forest and grassland security situation awareness system calls the dynamic access control smart contract to calculate the multi-dimensional subject attributes of the forest and grassland communication relay, decrypts and verifies whether the attributes of the forest and grassland communication relay pass the verification, completes the dynamic access control and returns the access result. If it passes the verification, execute step S5, if it fails the verification, execute step S10; S5, the forest and grassland security situation awareness system performs integrity testing: The forest and grassland security situation awareness system compares the spatial data fingerprint submitted by the forest and grassland perception terminal obtained through decryption with the spatial data fingerprint initialized and stored in the blockchain, completes the forest and grassland IoT data integrity test and returns the test result. If the test passes, step S6 is executed; if not, step S10 is executed; S6. The forestry and grassland cloud platform submits data and returns access results: The forestry and grassland communication relay sends the aggregated monitoring data to the forestry and grassland cloud platform. The forestry and grassland Internet of Things application system connects to the internal resource database to complete data warehousing, returns the periodic operation configuration and periodic operation strategy, and waits for the next data collection cycle; S7. Determine whether the monitoring is completed. If not, execute step S8. If so, terminate the process; S8. Determine whether to trigger an independent audit: The forestry and grassland security situation awareness system determines whether to trigger the independent audit start condition by executing the independent audit smart contract. If so, execute step S9. If not, execute step S2; S9. The forestry and grassland security situation awareness system performs an independent audit: The forestry and grassland security situation awareness system generates an independent audit notice and encrypts and broadcasts it. The audited device receives the audit notice, conducts the audit and returns the audit data. The forestry and grassland security situation awareness system verifies the returned audit data and stores the audit session and audit results on the chain. If the audit passes, execute step S2. If the audit fails, execute step S10; S10. The forestry and grassland security situation awareness system performs security situation awareness: The forestry and grassland security situation awareness system stores the failure information record of the current access session in the blockchain network, reads the historical access session records in the blockchain network, evaluates the access times and access situations of the current client and the forestry and grassland communication relay, determines whether it is under attack and takes corresponding measures to prevent the attack; then execute step S7.
2. The security protection method for the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 1, wherein The steps in step S1 include the following steps: S1.
1. Create and initialize the blockchain network; S1.
2. Define the identity authentication smart contract and install the chain code. Among them, the identity authentication smart contract includes the operation strategies for identity authentication access sessions and identity authentication operations of the forestry and grassland sensing terminal, forestry and grassland communication relay, and forestry and grassland cloud platform in the blockchain network, and the chain code is installed through the forestry and grassland cloud platform server; S1.
3. Define the access control smart contract and install the chain code. Among them, the access control smart contract includes the operation strategies for access control access sessions and dynamic access control operations of the forestry and grassland communication relay and forestry and grassland cloud platform in the blockchain network, and the chain code is installed through the forestry and grassland cloud platform server; S1.
4. Install the independent audit smart contract and chain code. Among them, the independent audit smart contract includes the operation strategies for independent audit sessions and independent audit operations of the forestry and grassland cloud platform in the blockchain network, and the chain code is installed through the forestry and grassland cloud platform server; S1.
5. Install the data integrity detection smart contract and chain code. Among them, the data integrity detection smart contract includes the operation strategies for data integrity detection access sessions and integrity detection operations of the forestry and grassland communication relay and forestry and grassland cloud platform in the blockchain network, and the chain code is installed through the forestry and grassland cloud platform server; S1.6, Definition of security situation awareness smart contract and installation of chain code. The security situation awareness smart contract includes data exchange operation policies for the forest and grassland perception terminals, forest and grassland communication relays, and forest and grassland cloud platforms to access internal data through identity authentication, access control, and integrity detection, as well as security situation awareness operation policies initiated in the blockchain network when the above fails. S1.7, Initialization of the forest and grassland Internet of Things system, including initialization of forest and grassland Internet of Things device information registration, initialization of generating spatial data fingerprints, initialization of key-policy attribute-based encryption scheme, and key generation.
3. The security protection method of the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 2, wherein, The chain operation policy for the identity authentication access session at least includes the login session chain policy, the identity authentication session chain policy, the identity authentication failure session chain policy, and the data transmission session chain policy. The identity authentication operation policy at least includes the static physical fingerprint generation policy, the static identity authentication policy, the multi-dimensional dynamic feature fingerprint generation policy, and the continuous dynamic identity authentication policy. The access session operation policy for access control at least includes the data transmission session chain policy, the operation policy download access session chain policy, and the access control failure session chain policy. The dynamic access control policy at least includes the forest and grassland communication relay subject attribute generation policy, the forest and grassland communication relay subject multi-dimensional dynamic attribute calculation policy, the forest and grassland communication relay data transmission attribute access request generation policy, the forest and grassland cloud platform key-policy attribute-based encryption initialization policy, the forest and grassland cloud platform access control tree structure key generation policy, the forest and grassland communication relay key-policy attribute-based data encryption policy, the forest and grassland cloud platform key-policy attribute-based data decryption policy, and the forest and grassland communication relay collected data transmission into the library access control verification policy. The chain operation policy for the independent audit session at least includes the independent audit notification session chain policy, the forest and grassland communication relay audit reply session chain policy, the independent audit successful completion session chain policy, and the independent audit failure end session chain policy. The independent audit operation policy at least includes the independent audit start decision policy, the independent audit notification attribute generation policy, the independent audit notification attribute encryption policy, the independent audit notification attribute broadcast policy, and the independent audit detection policy. The chain operation policy for the data integrity detection session includes the fingerprint cloud database generation session chain policy, the fingerprint cloud database chain session chain policy, the client data integrity detection request session chain policy, the data integrity detection failure session chain policy, and the data integrity detection execution result session chain policy. The integrity detection operation policy at least includes the spatial data feature extraction policy, the spatial data fingerprint generation policy, the fingerprint cloud database generation policy, the fingerprint cloud database chain policy, the spatial data fingerprint comparison and detection policy, the data integrity detection result generation policy, and the data integrity detection result chain policy. The data exchange operation policy at least includes the device registration information into the library policy, the forest and grassland communication relay periodic operation configuration download policy, the forest and grassland communication relay collected data transmission into the library policy, the independent audit result into the library policy, and the data integrity detection result return policy. The security situation awareness operation strategy at least includes a security situation awareness strategy, a security threat emergency disposal strategy, a DOS attack monitoring strategy, and an injection attack detection strategy.
4. The security protection method of the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 3, wherein, The specific steps of step S1.7 are as follows: S1.7.1, Initialize the registration of forest and grassland Internet of Things device information: Through the static physical fingerprint generation strategy, form the device static physical fingerprint based on the registration information and the static password, and then use the device registration information warehousing strategy to form a new block with the device registration and device registration information and upload it to the blockchain network to complete the registration of forest and grassland Internet of Things devices; S1.7.2, Initialize the generation of spatial data fingerprints: The forest and grassland cloud platform server calls the spatial data feature strategy to extract and obtain the spatial vector data spatial features and attribute features in the server-side internal resource database, execute the spatial data fingerprint generation strategy to obtain the spatial data fingerprint, and after calculation by the blockchain network consensus algorithm, form a new block and store it in the blockchain network to achieve the immutability and traceability of the fingerprint cloud database on-chain session; S1.7.3, Initialize the key policy attribute-based encryption scheme and generate keys: The forest and grassland cloud platform client calls the forest and grassland cloud platform key policy attribute-based encryption initialization strategy, generates the system public key and the system master key based on the key policy attribute-based encryption mechanism, and calls the forest and grassland cloud platform access control tree structure key generation strategy to calculate the decryption key of the forest and grassland cloud platform client user based on the system master key and the user attribute set.
5. The security protection method for the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 1, wherein, The following steps are included in step S2: S2.1, The forest and grassland communication relay initiates an identity authentication session for the first deployment; S2.2, The mobile data collection terminal connects to and configures the forest and grassland communication relay; S2.3, The forest and grassland Internet of Things system runs periodically.
6. The security protection method of the blockchain-empowered zero-trust forestry and grassland Internet of Things system according to claim 3, wherein, The following steps are included in step S3: S3.1, Create the static physical fingerprint of the forest and grassland communication relay and perform static identity verification: The forest and grassland cloud platform client calls the static physical fingerprint generation strategy to generate the static physical fingerprint of the current forest and grassland communication relay based on the registration information of the forest and grassland communication relay sent by the forest and grassland cloud platform client, then obtain the static physical fingerprint of the forest and grassland communication relay during the previous access on the blockchain platform, and call the static identity authentication strategy to perform static identity verification; S3.2, Create the multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay and perform dynamic identity verification: The forest and grassland cloud platform client calls the multi-dimensional dynamic feature fingerprint generation strategy to generate the multi-dimensional dynamic feature fingerprint of the current forest and grassland communication relay based on the registration information of the forest and grassland communication relay sent by the forest and grassland cloud platform client, then obtain the multi-dimensional dynamic feature fingerprint of the forest and grassland communication relay during the previous access on the blockchain platform, and call the continuous dynamic identity authentication strategy to compare the two pieces of information and return the identity authentication result; S3.3, Upload the identity authentication result session of the forest and grassland communication relay to the blockchain network: The forest and grassland cloud platform client calls the identity authentication session on-chain strategy to record the session information of this time into the blockchain network, and calls the device registration information warehousing strategy to add and update the device access registration information of the current forest and grassland communication relay into the database; S3.
4. The forestry and grassland communication relay receives and stores the identity authentication access session information of the forestry and grassland sensing terminal: The forestry and grassland communication relay receives the identity access request of the forestry and grassland sensing terminal, obtains the identity authentication session parameters of the forestry and grassland sensing terminal, and stores them locally in the forestry and grassland communication relay; S3.
5. The forestry and grassland communication relay creates a static physical fingerprint of the forestry and grassland sensing terminal and conducts static identity authentication: The forestry and grassland communication relay generates a static physical fingerprint for accessing the forestry and grassland sensing terminal according to the static physical fingerprint generation strategy stored locally, and calls the static identity authentication strategy to compare it with the static physical fingerprint of the forestry and grassland sensing terminal stored locally; S3.
6. The forestry and grassland communication relay creates a multi-dimensional dynamic feature fingerprint of the forestry and grassland sensing terminal and conducts dynamic identity authentication: The forestry and grassland communication relay respectively calculates and generates a multi-dimensional dynamic feature fingerprint based on the identity authentication session parameters of the forestry and grassland sensing terminal obtained and the identity authentication session parameters of the previous forestry and grassland sensing terminal obtained from the blockchain network and stored locally during the initialization of the forestry and grassland communication relay according to the multi-dimensional dynamic feature fingerprint generation strategy stored locally, and uses the continuous dynamic authentication strategy stored locally to compare and authenticate the two multi-dimensional dynamic feature fingerprints of the forestry and grassland sensing terminal.
7. The security protection method of the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 6, wherein, The steps in step S4 include the following steps: S4.
1. The forestry and grassland communication relay of the key-policy attribute-based encryption mechanism aggregates data encryption: The forestry and grassland communication relay uses the forestry and grassland communication relay main body attributes and the public key of the forestry and grassland cloud platform system, and calls the forestry and grassland communication relay key-policy attribute-based data encryption strategy to encrypt the forestry and grassland sensing terminal data aggregated in the forestry and grassland communication relay to form ciphertext; S4.
2. The forestry and grassland communication relay initiates a data transmission attribute access request to the forestry and grassland cloud platform: The forestry and grassland communication relay uses the forestry and grassland communication relay data transmission attribute access request generation strategy in the forestry and grassland communication relay periodic operation configuration downloaded locally, combines the forestry and grassland communication relay main body attributes to generate a forestry and grassland communication relay data transmission attribute access request, and sends a forestry and grassland communication relay data transmission attribute access request session to the forestry and grassland cloud platform; S4.
3. The forestry and grassland cloud platform uploads the data transmission session of the forestry and grassland communication relay to the blockchain network: The forestry and grassland cloud platform calls the data transmission session on-chain strategy, initiates a transaction for the data transmission session access request session sent by the forestry and grassland communication relay, and after being calculated by the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network to achieve the non-tampering and traceability of the access behavior; S4.
4. The forestry and grassland cloud platform calculates the multi-dimensional dynamic attributes of the forestry and grassland communication relay: The forestry and grassland cloud platform calls the forestry and grassland communication relay main body multi-dimensional dynamic attribute calculation strategy, obtains the forestry and grassland communication relay main body attributes stored in the previous access session in the blockchain network, uses the physical model to simulate and calculate the multi-dimensional dynamic attributes, and simulates and calculates the forestry and grassland communication relay main body attribute value of this access session; S4.
5. The forestry and grassland cloud platform conducts access control verification on the data transmission of the forestry and grassland communication relay: The forestry and grassland cloud platform calls the forestry and grassland communication relay data collection and transmission into the library access control verification strategy, combines the simulated forestry and grassland communication relay main body attribute value, and verifies the forestry and grassland communication relay main body attributes of the current session; S4.6, Decryption of Key-Policy Attribute-Based Data on the Forestry and Grassland Cloud Platform: The Forestry and Grassland Cloud Platform invokes the key-policy attribute-based data decryption policy on the Forestry and Grassland Cloud Platform and uses the key related to the access structure assigned to the client users of the Forestry and Grassland Cloud Platform during the initialization of the Forestry and Grassland Cloud Platform for decryption operations. Decryption is successful when the attributes in the ciphertext satisfy the access control tree.
8. The blockchain-enabled zero-trust forestry and grassland IoT system security protection method according to claim 7, wherein, The Forestry and Grassland Cloud Platform's sensing terminal is used for spatial data collection, processing, and interaction. The following steps are included in step S5: S5.1, Obtaining the Generation Strategy of the Spatial Data Fingerprint Database by the Forestry and Grassland Sensing Terminal: The Forestry and Grassland sensing terminal accesses the client of the Forestry and Grassland Cloud Platform or the blockchain network to obtain the spatial data feature extraction strategy, the spatial data fingerprint generation strategy, and the fingerprint database generation strategy. S5.2, Spatial Data Feature Extraction by the Forestry and Grassland Sensing Terminal: For the spatial database used for data integrity detection, the Forestry and Grassland sensing terminal locally executes the spatial data feature extraction strategy to obtain the spatial vector data spatial features and attribute features of the sensing terminal's spatial database. S5.3, Generation of Spatial Data Fingerprints at the Sensing Terminal: The Forestry and Grassland Cloud Platform's sensing terminal executes the spatial data fingerprint generation strategy on the spatial data for which spatial features and attribute features have been obtained for data integrity detection, and obtains the spatial data fingerprints of the Forestry and Grassland Cloud Platform's sensing terminal's spatial database. S5.4, Generation of the Fingerprint Cloud Database at the Sensing Terminal: The Forestry and Grassland Cloud Platform's sensing terminal executes the fingerprint cloud database generation strategy on the spatial data for which spatial data fingerprints have been obtained for data integrity detection, and obtains the Forestry and Grassland Cloud Platform's sensing terminal's fingerprint database. S5.5, Sending a Data Integrity Detection Request and the Sensing Terminal's Fingerprint Database: The Forestry and Grassland Cloud Platform's sensing terminal sends a data integrity detection request to the client of the Forestry and Grassland Cloud Platform and submits the sensing terminal's fingerprint database to complete the data integrity detection. S5.6, Linking the Data Integrity Detection Request Session of the Sensing Terminal to the Blockchain: The client of the Forestry and Grassland Cloud Platform executes the fingerprint cloud database generation session linking strategy to initiate a transaction for the client data integrity detection request session by the client of the Forestry and Grassland Cloud Platform. After being calculated by the blockchain network consensus algorithm, a new block is stored in the blockchain network, realizing the immutability and traceability of the data collection and data integrity detection behaviors of the Forestry and Grassland sensing terminal. S5.7, Comparison and Detection of Spatial Data Fingerprints on the Server Side: The server side of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint comparison and detection strategy, takes the sensing terminal's fingerprint database submitted for detection by the Forestry and Grassland Cloud Platform's sensing terminal as input, obtains the fingerprint cloud database from the blockchain network, and compares the spatial data fingerprints in the sensing terminal's fingerprint database and the spatial data fingerprints in the fingerprint cloud database for consistency by means of attribute query comparison, and marks the inconsistent spatial data fingerprints. S5.8, Obtaining the Data Integrity Detection Results on the Server Side: The server side of the Forestry and Grassland Cloud Platform executes the spatial data fingerprint detection result generation strategy, separately stores the marked inconsistent spatial data fingerprints to form a data integrity detection result database. S5.9, Uploading the data integrity detection results to the blockchain: The client of the Forestry and Grassland Cloud Platform executes the policy of uploading the data integrity detection results to the blockchain, initiates a transaction for all records in the data integrity detection results database, and after being calculated by the consensus algorithm of the blockchain network, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of the data in the data integrity detection results database; S5.10, Uploading the session of the data integrity detection execution results to the blockchain: The client of the Forestry and Grassland Cloud Platform executes the policy of uploading the session of the data integrity detection execution results to the blockchain, initiates a transaction for the session of the data integrity detection execution results on the server side, and after being calculated by the consensus algorithm of the blockchain network, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of the data integrity detection behavior.
9. The blockchain-empowered zero-trust forestry and grassland IoT system security protection method according to claim 8, wherein, The steps in step S6 include the following steps: S6.1, The Forestry and Grassland Communication Relay downloads the periodic operation configuration of the Forestry and Grassland Communication Relay: The Forestry and Grassland Communication Relay uses the periodic operation configuration download policy of the Forestry and Grassland Communication Relay to read and download the periodic operation policy configuration information of the Forestry and Grassland Internet of Things in the Forestry and Grassland Cloud Platform database to the local of the Forestry and Grassland Communication Relay; S6.2, The Forestry and Grassland Communication Relay stores the data collected by the Forestry and Grassland Sensing Terminal and distributes the periodic operation configuration: The Forestry and Grassland Communication Relay receives the identity authentication parameters and the collected data transmitted by the Forestry and Grassland Sensing Terminal, stores them in the Forestry and Grassland Communication Relay, and distributes the periodic operation policy of the Forestry and Grassland Sensing Terminal stored locally to the Forestry and Grassland Sensing Terminal; S6.3, The Forestry and Grassland Communication Relay sends the collected data to the Forestry and Grassland Cloud Platform: If the identity authentication, access control, and data integrity detection of the Forestry and Grassland Communication Relay are passed, it agrees to submit the data from the sensing end to the internal resource database of the server side. Otherwise, it returns the data integrity detection results database to the sensing end.
10. The security protection method for the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 9, characterized in that, The steps in step S9 include the following steps: S9.1, The Forestry and Grassland Cloud Platform executes the generation of the audit notice: The Forestry and Grassland Cloud Platform executes the independent audit notice attribute generation policy to generate the audit notice; S9.2, The Forestry and Grassland Cloud Platform uploads the independent audit notice session to the blockchain: The audit notice is sent to the Forestry and Grassland Communication Relay and / or the Forestry and Grassland Sensing Terminal. The client of the Forestry and Grassland Cloud Platform initiates a transaction for the audit notice distribution session, and after being calculated by the consensus algorithm of the blockchain network, forms a new block and stores it in the blockchain network, realizing the immutability and traceability of the audit notice behavior; S9.3, The Forestry and Grassland Cloud Platform encrypts the audit notice using the ciphertext attribute encryption method: The Forestry and Grassland Cloud Platform executes the independent audit notice attribute encryption policy to encrypt the audit notice using the ciphertext attribute encryption method; S9.4, The Forestry and Grassland Cloud Platform broadcasts the audit notice to the Forestry and Grassland Communication Relay: The Forestry and Grassland Cloud Platform executes and sends the encrypted audit notice ciphertext to the Forestry and Grassland Communication Relay in the next data collection cycle; S9.5, The Forestry and Grassland Communication Relay decrypts the audit notice and conducts an independent audit according to the requirements of the audit notice: The Forestry and Grassland Communication Relay uses the public key of the Forestry and Grassland Cloud Platform system to obtain the attributes and private key of the current Forestry and Grassland Communication Relay, decrypts the audit notice ciphertext. If the attributes of the Forestry and Grassland Communication Relay meet the access policy of the audit notice ciphertext, it decrypts the ciphertext and obtains the content of the audit notice; S9.
6. The forestry and grassland perception terminal decrypts the audit notice and conducts an independent audit according to the requirements of the audit notice: The forestry and grassland communication relay uses the public key of the forestry and grassland cloud platform system to obtain the attributes and private key of the current forestry and grassland perception terminal, decrypts the audit notice ciphertext. If the attributes of the forestry and grassland perception terminal conform to the access policy of the audit notice ciphertext, the ciphertext is decrypted to obtain the audit notice content, and the audit notice content is executed to form audit data and submitted to the forestry and grassland communication relay; S9.
7. The forestry and grassland communication relay submits audit data according to the requirements of the audit notice: The forestry and grassland communication relay encrypts the forestry and grassland perception terminals and the data stored locally collected according to the requirements of the audit notice, and then uploads them back to the forestry and grassland cloud platform for auditing; S9.
8. The forestry and grassland cloud platform chains the audit reply session of the forestry and grassland communication relay: The forestry and grassland cloud platform client initiates a transaction for the audit reply session of the forestry and grassland communication relay. Through the consensus algorithm calculation of the blockchain network, a new block is formed and stored in the blockchain network, realizing the immutability and traceability of the audit reply behavior of the forestry and grassland communication relay; S9.
9. The forestry and grassland cloud platform decrypts the audit upload data and conducts a comparison audit: The audit organization client of the forestry and grassland cloud platform decrypts the upload data using the symmetric key to obtain the audit data, then reads the historical data of the audited device from the blockchain network, and conducts a comparison audit on the historical data and the audit data; S9.
10. The forestry and grassland cloud platform conducts an independent audit detection and gives an audit result: The forestry and grassland cloud platform executes the independent audit detection strategy to detect the integrity and authenticity of the current and previous data. If the audited device replies with audit data that is inconsistent with the historical data in the blockchain network, then step S10 is executed; S9.
11. The forestry and grassland cloud platform successfully completes the independent audit and chains the session: The forestry and grassland cloud platform client initiates a transaction for the successful completion of the independent audit session. After calculation by the consensus algorithm of the blockchain network, a new block is formed and stored in the blockchain network, realizing the immutability and traceability of the audit result behavior; S9.
12. The forestry and grassland cloud platform records and stores the audit session and result: The forestry and grassland cloud platform calls the independent audit result storage strategy to store the audit data and audit results obtained from the local audit into the database.
11. The blockchain-enabled zero-trust security protection method for forestry and grassland Internet of Things systems according to claim 10, characterized in that, The steps in the said step S10 include the following steps: S10.
1. When the identity authentication fails, conduct security situation awareness and emergency disposal: When the identity authentication fails, the forestry and grassland cloud platform client calls the strategy of chaining the identity authentication failure session, and records the failure information of the current identity authentication access session into the blockchain network; And call the security situation awareness strategy, read the historical access session records in the blockchain network, evaluate the access times of the current client and the forestry and grassland communication relay to determine whether there is a DOS attack. If the access IP and / or access port has an access exceeding the access upper limit threshold, call the security threat emergency disposal strategy to urgently close the current access IP and / or access port to prevent the DOS attack; S10.2, Conduct security situation awareness and emergency response in case of access control failure: When access control or decryption fails, the Forestry and Grassland Cloud Platform invokes the access control failure session chaining policy, initiates a transaction for the access control failure session sent by the Forestry and Grassland Communication Relay, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network to achieve the non-tampering and traceability of access behaviors; and invokes the security situation awareness policy, reads the historical access session records in the blockchain network, evaluates the access times of the current client and the Forestry and Grassland Communication Relay to determine whether there is a DOS attack. If the access to the access IP and / or access port exceeds the access upper limit threshold, the security threat emergency response policy of the security situation awareness smart contract is invoked to urgently close the current access IP and / or access port to prevent DOS attacks; S10.3, Conduct security situation awareness and emergency response in case of integrity detection failure: When the data integrity detection fails, the Forestry and Grassland Cloud Platform client invokes the integrity detection failure session chaining policy, initiates a transaction for the integrity detection failure session sent by the Forestry and Grassland Communication Relay, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network to achieve the non-tampering and traceability of access behaviors; The Forestry and Grassland Cloud Platform server executes the DOS attack monitoring policy. The Forestry and Grassland Cloud Platform queries the Forestry and Grassland perception terminal with failed data integrity detection in the blockchain network, obtains the failed access times of the Forestry and Grassland perception terminal for this request detection, and determines whether the failed access times exceed the defined threshold. If so, it is determined that there is a DOS attack threat and the security threat emergency response policy is triggered; S10.4, Conduct security situation awareness and emergency response in case of independent audit failure: When the independent audit result verification fails, the Forestry and Grassland Cloud Platform client initiates a transaction for the audit failure end session, calculates through the blockchain network consensus algorithm, forms a new block and stores it in the blockchain network to achieve the non-tampering and traceability of audit failure behaviors; the Forestry and Grassland Cloud Platform executes the security situation awareness smart contract response policy based on the audit result and rectifies the audit result.
12. The security protection method for the blockchain-enabled zero-trust forestry and grassland Internet of Things system according to claim 11, wherein, The Forestry and Grassland security situation awareness system includes: Blockchain creation, smart contract definition and system initialization module: Used for initializing the blockchain network, completing the definition of identity authentication, access control, independent audit, integrity detection smart contracts and chain code installation, and completing the initialization of the Forestry and Grassland Internet of Things system; Forestry and Grassland Communication Relay identity authentication module: Used for the Forestry and Grassland Cloud Platform client to respectively invoke the identity authentication smart contract to create the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the Forestry and Grassland Communication Relay, and conduct static identity verification and continuous dynamic identity authentication on the Forestry and Grassland Communication Relay; Attribute-based data encryption access control request generation module: Used for using the periodic operation configuration of the Forestry and Grassland Communication Relay to generate the subject attributes of the Forestry and Grassland Communication Relay, combining with the public key of the Forestry and Grassland Cloud Platform system, using the attribute-based data encryption policy of the Forestry and Grassland Communication Relay key strategy to encrypt the data of the Forestry and Grassland perception terminal collected in the Forestry and Grassland Communication Relay into ciphertext, and initiating a data transmission attribute access request to the Forestry and Grassland Cloud Platform; Attribute-based Data Encryption Access Control Request Verification Module: It is used to verify whether the attributes of the forestry and grassland communication relay pass the verification by combining the attributes of the forestry and grassland communication relay subject calculated by simulation; Server-side Data Integrity Detection Module: It is used for the forestry and grassland cloud platform to compare the spatial data fingerprints submitted by the forestry and grassland perception terminals obtained by decryption with the spatial data fingerprints initially generated and stored in the blockchain, verify that the forestry and grassland Internet of Things has completed the data integrity detection and return the detection results; Trigger Audit Judgment Module: It is used for the forestry and grassland cloud platform to judge whether to trigger the independent audit start condition by executing the independent audit smart contract; Independent Audit Notification Generation and Encrypted Broadcast Module: It is used for the forestry and grassland cloud platform to generate an independent audit notification, encrypt the independent audit notification using the ciphertext attribute encryption method, and broadcast the independent audit notification ciphertext from the forestry and grassland cloud platform to the forestry and grassland communication relay in the next data collection cycle; Audit Device Returned Audit Result Verification Module: It is used for the forestry and grassland cloud platform to decrypt the returned audit data and compare it with the historical data stored in the blockchain network, and complete the data integrity and system security detection by judging the data consistency; Forestry and Grassland Internet of Things Security Situation Awareness and Emergency Disposal Module: It is used for the forestry and grassland cloud platform to store the record of the current access session failure information into the blockchain network, read the historical access session records in the blockchain network, evaluate the access times and access situations of the current client and the forestry and grassland communication relay to judge whether it is attacked and take corresponding measures to prevent the attack.
13. The blockchain-empowered zero-trust forestry and grassland Internet of Things system security protection method according to claim 12, characterized in that, The forestry and grassland Internet of Things application system includes: Forestry and Grassland Internet of Things System Periodic Operation Module: It is used for the forestry and grassland Internet of Things system to wake up the forestry and grassland communication relay and the forestry and grassland perception terminal at fixed intervals according to the configured periodic operation strategy, complete data collection, aggregation and transmission, and then go into dormancy waiting for the next data collection cycle; Attribute-based Encryption Data Decryption Module: It is used for the forestry and grassland cloud platform to decrypt the ciphertext transmitted by the forestry and grassland Internet of Things using the key related to the access structure, and transmit the successfully decrypted data through the forestry and grassland communication relay; Forestry and Grassland Perception Terminal Identity Authentication Module: It is used for the forestry and grassland communication relay to receive and store the identity authentication access session information of the forestry and grassland perception terminal according to the locally downloaded periodic operation configuration strategy, and then combine the periodic security perception configuration strategy to generate the static physical fingerprint and multi-dimensional dynamic feature fingerprint of the forestry and grassland perception terminal, complete the static identity authentication and continuous dynamic identity authentication, and store the data collected by the forestry and grassland perception terminal locally; Perception End Spatial Data Fingerprint Database Generation Module: It is used for the forestry and grassland cloud platform perception end to perform spatial data feature extraction and spatial data fingerprint generation, generate the perception end fingerprint database, and then send a data integrity detection request and the perception end fingerprint database to the forestry and grassland cloud platform server; Forestry and Grassland Communication Relay Audit Module: It is used for the forestry and grassland communication relay to decrypt the independent audit notification ciphertext. When the attributes of the forestry and grassland communication relay meet the independent audit notification access policy, decrypt the ciphertext to obtain the independent audit notification content, conduct an independent audit according to the requirements of the independent audit notification and return the audit data; Forest and Grass Sensing Terminal Extended Audit Module: When the forest and grass sensing terminal is required to conduct an extended audit according to the independent audit notice, it receives the independent audit notice sent by the forest and grass communication relay and decrypts it. When the attributes of the forest and grass sensing terminal comply with the access policy of the independent audit notice, it decrypts the ciphertext to obtain the content of the independent audit notice, conducts an independent audit according to the requirements of the independent audit notice, and transmits the audit data back; Forest and Grass Cloud Platform Access Session Blockchain Module: It is used for the forest and grass cloud platform client to blockchain the access request session and access request result session of the forest and grass sensing terminal and the forest and grass communication relay; Data Storage and Download Module: It is used for the forest and grass cloud platform client to store the transmission data submitted by the forest and grass communication relay into the internal resource database and distribute the periodic operation configuration and acquired data of the server side.
Citation Information
Patent Citations
Zero-trust forestry Internet of Things management platform system and security protection method
CN117749533A
Cloud-side collaborative multi-mode private data circulation method based on smart contract
US20230041862A1