Internet of Things equipment identity authentication method based on block chain

By adopting lightweight consensus mechanism, encryption algorithm and sharding technology in the blockchain network, combined with multi-level node architecture and timestamp update mechanism, the problem of synchronization and consistency of identity information in IoT devices is solved, and efficient and real-time identity information management is achieved to meet the needs of IoT scenarios.

CN120090857APending Publication Date: 2025-06-03LUSHAN COLLEGE OF GUANGXI UNIV OF SCI & TECH

Patent Information

Application Number
CN202510307802.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

In the distributed network of blockchain, how to achieve real-time synchronization and consistency of identity information of IoT devices, especially when the number of devices is huge, widely distributed and limited computing and storage capabilities.

Method used

The lightweight consensus mechanism and encryption algorithm are used to perform preliminary verification and encryption processing on identity information changes. The network is divided into multiple regions through sharding technology, and combined with a multi-level node architecture to achieve efficient local synchronization and global consistency. Design a time stamp-based identity status update mechanism to handle dynamic joining and exiting scenarios of devices, and introduce conflict resolution mechanisms and retransmission mechanisms to ensure the reliability of data transmission.

Benefits of technology

It significantly improves the synchronization efficiency and consistency maintenance of identity information of IoT devices in blockchain networks, and meets the real-time and scalability needs in IoT scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090857A_ABST
    Figure CN120090857A_ABST
Patent Text Reader

Abstract

The invention provides an Internet of Things device identity authentication method based on a block chain, and relates to the technical field of Internet of Things, and the method comprises the steps: obtaining an identity information change request of an Internet of Things device, and carrying out the preliminary verification of the change request through employing a lightweight consensus mechanism according to the characteristics of a large number of devices and wide distribution; performing encryption processing on the identity information change request passing verification through a lightweight encryption algorithm, generating block data containing encrypted equipment identity information, and broadcasting the block data to other nodes in the block chain network; and after the local identity information is synchronized, changing and spreading the identity information to other fragments by adopting a cross-fragment communication protocol. The method comprises a retransmission mechanism and alarm triggering under an abnormal condition, so that the reliability of data transmission is ensured. According to the method, the synchronization efficiency and consistency maintenance of the identity information of the Internet of Things equipment in the block chain network are remarkably improved, and the real-time performance and expandability requirements in an Internet of Things scene are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the Internet of Things, and in particular to an Internet of Things device identity authentication method based on blockchain. Background Art

[0002] In the Internet of Things device identity authentication method based on blockchain, the consistency of identities faces a key technical problem. Due to the large number and wide distribution of Internet of Things devices, and the limited computing and storage capabilities of the devices, how to achieve real-time synchronization and consistency of device identity information on all nodes in the distributed network of blockchain is a difficult problem to be solved urgently.

[0003] Specifically, when the identity information of an Internet of Things device changes on a certain node, how to quickly and reliably spread this change to other nodes in the blockchain network and ensure that the identity information on all nodes can be updated in time to reach a consistent state requires an efficient consensus mechanism and synchronization strategy. However, traditional consensus algorithms often have problems such as low efficiency and high latency, and it is difficult to meet the requirements of real-time and scalability in the Internet of Things scenario.

[0004] In addition, in the dynamic environment where Internet of Things devices frequently join and leave the network, how to ensure that the identity information of newly joined devices can be quickly synchronized to all nodes, and when the device is offline or fails, update its identity status in time is also a thorny problem. At the same time, due to the resource limitations of Internet of Things devices themselves, how to achieve efficient synchronization and verification of identity information without increasing the device burden also requires careful design and trade-off.

[0005] In summary, how to achieve the consistency of Internet of Things device identity information in the distributed network of blockchain, ensure that the identity status on all nodes can be synchronized and maintained in real time, is a key technical problem to be solved urgently in the Internet of Things device identity authentication method based on blockchain. This requires in-depth research and innovative design in aspects such as consensus mechanism, synchronization strategy, identity management, etc. to meet the special needs in the Internet of Things scenario. Summary of the Invention

[0006] The present invention provides Internet of Things device identity authentication based on blockchain, mainly including: Obtain the identity information change request of the Internet of Things device. For the characteristics of a large number of devices and wide distribution, adopt a lightweight consensus mechanism to initially verify the change request; encrypt the verified identity information change request through a lightweight encryption algorithm to generate block data containing the encrypted device identity information, and broadcast the block data to other nodes in the blockchain network; according to the requirements of resource limitation and real-time synchronization, design a synchronization strategy based on the sharding technology, divide the network into multiple shards, each shard is responsible for processing the device identity information within a specific range, and through the efficient consensus mechanism within the shard, quickly complete the local synchronization of the identity information; after the local identity information is synchronized, use the cross-shard communication protocol to spread the identity information change to other shards. When an abnormality occurs in the inter-shard communication, start the retry mechanism or trigger an alarm to ensure that the consistency requirement of the identity information is met.

[0007] Further, the initial verification of the change request by adopting the lightweight consensus mechanism includes: judging the legality and integrity of the request according to the preset rules. For the change request that passes the initial judgment, use the PBFT consensus algorithm for voting verification, and adopt the principle of more than two-thirds of the nodes' recognition to determine the validity of the request.

[0008] Further, the encryption process through the lightweight encryption algorithm includes: using the AES encryption algorithm to encrypt the changed identity information. To ensure the security and reliability of the encryption process, adopt the key rotation mechanism, and update the encryption key through the key management system at regular intervals.

[0009] Further, the design of the synchronization strategy based on the sharding technology includes: dividing the network into multiple shards by using the consistent hashing algorithm according to the specific range of the identity information; after the shard division is completed, design a consensus mechanism based on the Raft protocol for the identity information within each shard, and quickly reach a consensus through the distributed consistency algorithm to achieve local synchronization within the shard.

[0010] Further, after the local identity information is synchronized, using the cross-shard communication protocol to spread the identity information change to other shards includes: obtaining the synchronized identity information of each shard, and integrating the results of local synchronization into a globally consistent identity information view through the MerkleTree data aggregation algorithm and the conflict resolution algorithm of the longest chain principle.

[0011] Further, the design of the synchronization strategy based on the sharding technology according to the requirements of resource limitation and real-time synchronization also includes: dynamically adjusting the number and range of shards according to the real-time monitoring results of the system load and response time, and balancing the processing pressure of each shard through the load balancing algorithm to ensure efficient identity information synchronization under limited resources.

[0012] Further, when communication between shards is abnormal, a retry mechanism is started or an alarm is triggered, including: setting up a message retry mechanism, using an exponential backoff algorithm, with an initial retry interval of 1 second, multiplying the interval time by 2 after each retry failure, and retrying at most 5 times; when consecutive retries still fail, trigger the alarm mechanism, notify the operation and maintenance personnel by means of SMS, email, enterprise WeChat, etc., and provide detailed error information and logs to facilitate problem troubleshooting.

[0013] Further, obtaining the identity information change request of the IoT device further includes: according to the identity information of the IoT device, assigning a unique identifier to each device in the blockchain network, and storing the identifier together with other attribute information of the device on the blockchain to form a distributed storage of the device identity information; adopting a smart contract-based method to manage and synchronize the identity information of the IoT device. The smart contract defines the data structure and operation functions of the device identity information, including device registration, attribute update, permission management, etc.

[0014] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: The present invention discloses an IoT device identity authentication method based on blockchain. In view of the characteristics of a large number, wide distribution, and frequent changes of IoT devices, a lightweight consensus mechanism and encryption algorithm are adopted to ensure the security of identity information changes. The network is divided into multiple regions through sharding technology, combined with a multi-level node architecture, to achieve efficient local synchronization and global consistency. A timestamp-based identity status update mechanism is designed to effectively handle scenarios where devices dynamically join and leave. During the synchronization process, a conflict resolution mechanism is introduced to determine the valid identity information by comparing timestamps and node credibility. The present invention also includes a retransmission mechanism and alarm trigger in case of abnormalities to ensure the reliability of data transmission. This method significantly improves the synchronization efficiency and consistency maintenance of IoT device identity information in the blockchain network, meeting the real-time and scalability requirements in the IoT scenario. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a flowchart of an IoT device identity authentication method based on blockchain of the present invention. DETAILED DESCRIPTION

[0016] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.

[0017] As Figure 1 , a method for authenticating the identity of Internet of Things devices based on blockchain in this embodiment may specifically include: S101. Obtain the identity information change request of the Internet of Things device from the blockchain network. In view of the characteristics of a large number of devices and wide distribution, a lightweight consensus mechanism is used to preliminarily verify the change request. After passing the verification, the device identity information is encrypted by a lightweight encryption algorithm to ensure the security of the identity information change. Generate block data containing the encrypted device identity information and broadcast the block data to other nodes in the network.

[0018] When the blockchain network receives the identity information change request of the Internet of Things device, obtain information such as the device identifier and change content included in the request, and judge the legality and integrity of the request according to the preset rules. If the requirements are not met, reject the request; otherwise, proceed to the next step. For the change request that passes the preliminary judgment, the blockchain network nodes use the PBFT consensus algorithm for voting verification, and determine the validity of the request based on the principle that more than two-thirds of the nodes approve. If the verification fails, reject the request and notify the request initiator; if the verification passes, send the request to the next processing link. For the device identity information change request that passes the verification, use the AES encryption algorithm to encrypt the changed identity information to generate encrypted identity information data. To ensure the security and reliability of the encryption process, a key rotation mechanism is adopted, and the encryption key is updated through the key management system at regular intervals. According to the encrypted device identity information, write it into the newly generated block data through a smart contract, and submit the block data to the blockchain network for consensus verification. After receiving the new block data, the nodes in the blockchain network verify and confirm it according to the PBFT consensus mechanism, and judge the validity of the block based on the voting result. If the block fails to pass the verification, reject the block; if the block passes the verification, add it to the local blockchain and synchronously broadcast the block data to other nodes in the network through the P2P network protocol. The Internet of Things device queries the latest identity information according to the device identifier by accessing the API interface provided by the blockchain network. After the device obtains the encrypted identity information, it decrypts it using the preset key to obtain the real identity information, and compares and verifies it with the identity information stored locally to complete the identity authentication process. To improve the identity authentication efficiency, the device can regularly synchronize the identity information from the blockchain to the local database through the API for caching.

[0019] Specifically, when the blockchain network receives an identity information change request from an IoT device, it first obtains the device identifier and the change content. For example, a thermostat in a smart home system may request an update to its firmware version number. The system checks the legality and integrity of the request, such as verifying whether the digital signature is valid and whether the message format is correct. After a preliminary judgment, the network nodes use the PBFT (Practical Byzantine Fault Tolerance) consensus algorithm for voting verification. Suppose there are 100 nodes participating in the consensus. At least 67 nodes (more than two-thirds) need to approve to determine that the request is valid. This mechanism can effectively prevent malicious nodes from tampering with data and improve the system security. For the requests that pass the verification, the updated identity information is encrypted using the AES (Advanced Encryption Standard) algorithm. For example, the new firmware version number "2.0.1" of the thermostat is encrypted as "X7f9Q2pL". To enhance security, the system updates the encryption key at regular intervals (such as weekly). In this way, even if a certain key is leaked, the impact is limited to the data in the short term. The encrypted identity information is written into a new block through a smart contract. The smart contract can automatically execute predefined rules, such as checking whether the device has the permission to update specific information and recording the update history. The new block undergoes PBFT consensus verification again to ensure data consistency and immutability. The verified block is added to the local blockchain and synchronized to other nodes through the P2P network. This distributed storage method improves the reliability and anti-attack ability of the data. Even if some nodes fail or are attacked, the system can still run normally. IoT devices can query the latest identity information through the API interface. The thermostat may synchronize data from the blockchain at a fixed time every day at midnight, decrypt the encrypted identity information and compare it with the information stored locally. This regular synchronization mechanism can not only ensure that the device obtains the latest information in a timely manner but also reduce the pressure on the network caused by real-time queries. The whole process reflects the advantages of blockchain technology in IoT identity management: decentralization, transparency, immutability, and high security. Through multi-level verification and encryption mechanisms, it effectively prevents the device identity from being misused or tampered with, providing a reliable identity authentication foundation for the IoT ecosystem.

[0020] S102. According to the requirements of resource limitation and real-time synchronization, design a synchronization strategy based on the sharding technology, divide the network into multiple shards, and each shard is responsible for processing the device identity information within a specific range. Through the efficient consensus mechanism within the shard, quickly complete the local synchronization of the identity information.

[0021] According to a specific range of identity information, the network is divided into multiple shards using the consistent hashing algorithm, and each shard is responsible for processing the identity information within its respective range. After the shard division is completed, for the identity information within each shard, a consensus mechanism based on the Raft protocol is designed to quickly reach a consensus through a distributed consistency algorithm, achieving local synchronization within the shard. After synchronizing the local identity information, the synchronized identity information of each shard is obtained, and through the MerkleTree data aggregation algorithm and the conflict resolution algorithm based on the longest chain principle, the results of local synchronization are integrated into a globally consistent identity information view. According to the real-time monitoring results of system load and response time, the number and range of shards are dynamically adjusted, and the processing pressure of each shard is balanced through a load balancing algorithm to ensure efficient identity information synchronization under limited resources. To ensure the fault tolerance and availability of the system, a data backup and failover mechanism based on the Paxos protocol is designed. By maintaining multiple replicas within the shard and automatically forwarding requests to available replicas when a node fails, the integrity and accessibility of identity information are ensured. The AES symmetric encryption algorithm is used to encrypt and protect the identity information, and fine-grained access control is implemented based on the RBAC model to prevent unauthorized access and tampering, ensuring the confidentiality and integrity of identity information. Continuously monitor system performance metrics and synchronization quality, collect and analyze system logs in real time through the ELK log analysis platform, use machine learning algorithms for anomaly detection and root cause analysis, timely discover and locate problems in the synchronization process, and continuously improve the reliability and efficiency of the synchronization strategy through measures such as parameter tuning and algorithm optimization.

[0022] Specifically, the application of the consistent hashing algorithm in IoT identity management can effectively solve the problem of uneven distribution of a large number of devices. For example, suppose there are one million smart home devices to be managed. The hash space can be divided into 1024 virtual nodes. The unique identifier of each device is mapped into this circular space through a hash function and then divided into different shards according to the range of the hash value. In this way, even if some shards are overloaded, the load can be dynamically adjusted by increasing or decreasing the number of virtual nodes to ensure load balance. Inside the shard, the application of the Raft protocol can quickly reach a consensus. Taking smart meters as an example, suppose a shard contains 100,000 meter devices. When the electricity price information needs to be updated, the primary node in the shard will broadcast the update request to other nodes. As long as more than half of the nodes (such as at least 3 nodes) confirm receipt, the update is considered valid. This mechanism not only ensures data consistency but also avoids the performance overhead caused by network-wide broadcasts. The MerkleTree data aggregation algorithm plays an important role in integrating the results of each shard. For example, there are 8 shards each maintaining the identity information of 125,000 devices. Each shard constructs a Merkle tree from the device information it manages, and the root hash value represents the data summary of the shard. Then, the root hashes of the 8 shards are used to construct a higher-level Merkle tree, finally obtaining a globally consistent view. This method not only greatly reduces the amount of data transmission but also can quickly verify data integrity. Dynamic load balancing is the key to ensuring the efficient operation of the system. Suppose it is monitored that the CPU usage rate of a certain shard continuously exceeds 80%, while other shards are only about 40%. The system will automatically trigger a rebalancing mechanism to migrate some devices from the high-load shard to the low-load shard. This process may involve recalculating the consistent hash, updating the routing table, etc., but can significantly improve the overall performance. The Paxos protocol plays a key role in ensuring data availability. For example, when managing an intelligent transportation system, the status information of each traffic light is stored in 3 copies within the shard. When the node where the primary copy is located fails, the system will immediately elect a new primary node from other copies to ensure that the service is not interrupted. This mechanism is particularly suitable for the high-reliability requirements in a distributed environment. In terms of security, AES encryption combined with the RBAC access control model can effectively protect sensitive information. For example, the switch records of smart locks are highly sensitive data. The system will use a 256-bit AES key to encrypt this data and set different access permissions based on user roles (such as ordinary users, administrators, emergency service personnel). This not only ensures the confidentiality of the data but also realizes flexible authorization management. The application of the ELK log analysis platform makes system operation and maintenance more intelligent. By collecting the log information of each node in real time, the system can quickly discover abnormal patterns. For example, if the synchronization delay of a certain shard suddenly increases, machine learning algorithms may identify that this is caused by network congestion.Based on this analysis, the system can automatically adjust the load of the shard or activate a backup network link to maintain overall performance.

[0023] S103. Optimize the topology of the blockchain network according to the scalable requirements and network latency, and adopt a multi-level node architecture. High-level nodes are responsible for the synchronization of global identity information, and low-level nodes are responsible for the processing of local identity information, reducing network load.

[0024] Design a multi-level node architecture according to the scale and performance requirements of the blockchain network, and divide high-level nodes and low-level nodes. By analyzing parameters such as the computing power, storage capacity, and network bandwidth of the nodes, determine the number and distribution of high- and low-level nodes. The number of high-level nodes is relatively small, mainly responsible for the tasks of global consensus and identity information synchronization, and requires strong computing and storage capabilities. The number of low-level nodes is large, distributed in different geographical locations, close to users, and mainly responsible for the task of local identity information verification. Use the minimum spanning tree algorithm to optimize the network topology, with high-level nodes as the root nodes and low-level nodes as the leaf nodes, to construct the optimal connection topology between nodes. Through the minimum spanning tree algorithm, while ensuring network connectivity, the communication overhead and latency between nodes can be minimized. Establish dedicated high-speed links between high-level nodes, such as fiber optic dedicated lines or intranet dedicated lines, to ensure the communication quality and speed between high-level nodes. High-level nodes use the Byzantine fault-tolerant consensus algorithm to achieve the fast synchronization and consensus of global identity information, ensuring the consistency and anti-tampering of the identity information of the entire network. Low-level nodes perform K-Means clustering according to geographical location and business relevance to form multiple subnets for local identity information processing. Low-level nodes within each subnet use the Gossip protocol for P2P communication to achieve the efficient verification and update of local identity information. Low-level nodes receive identity authentication requests from end users and quickly respond by querying the local identity information database to improve the user experience. During the operation of the system, monitor indicators such as the CPU occupancy rate, memory occupancy rate, and network throughput of each node in real time. When the load of a certain node continuously exceeds the preset threshold, trigger the node role dynamic adjustment process. Through the load balancing algorithm between nodes, dynamically promote some low-level nodes to high-level nodes to share the tasks of high-level nodes, or demote some high-level nodes to low-level nodes to relieve their load pressure. At the same time, adjust the division of subnets, further split the subnets with high load, and merge the subnets with low load to achieve the adaptive optimization of the network topology and ensure the scalability and robustness of the system.

[0025] Specifically, the multi-level node architecture is a key strategy for optimizing large-scale Internet of Things (IoT) identity management systems. Take a smart city as an example. Suppose a city with a population of 10 million needs to manage 50 million IoT devices. A two-layer architecture can be designed, with 100 high-level nodes and 10,000 low-level nodes. The high-level nodes can be high-performance servers deployed in the city's data center, each equipped with a 64-core CPU, 256GB of memory, and 10TB of storage space. The low-level nodes can be edge computing devices distributed in various communities, such as smart routers, equipped with a 4-core CPU, 8GB of memory, and 1TB of storage space. The minimum spanning tree algorithm plays an important role in optimizing the network topology. Assume the city is divided into 100 regions, each responsible for by a high-level node. Using the Kruskal algorithm to construct the minimum spanning tree, these 100 high-level nodes can be connected in an optimal way. For example, high-level nodes in two adjacent regions may be directly connected by 10Gbps optical fibers, while nodes farther apart forward data through intermediate nodes, thus minimizing the overall communication cost while ensuring network connectivity. The Byzantine fault-tolerant consensus algorithm ensures global consistency among high-level nodes. Suppose when updating the traffic signal configuration of the intelligent transportation system, even if a few nodes fail or are maliciously attacked, the system can still reach an agreement. For example, among 100 high-level nodes, even if 33 nodes fail or are controlled, as long as the remaining 67 nodes are operating normally and reach an agreement, the entire system can maintain correct operation. The K-Means clustering of low-level nodes can be based on geographical location and business type. For example, divide 10,000 low-level nodes into 500 subnets, with each subnet containing 20 nodes. In a subnet mainly covering residential areas, these 20 nodes may mainly handle the identity authentication of smart home devices. In a subnet in the business district, the nodes may handle more identity verification of payment terminals and security devices. The Gossip protocol enables efficient information dissemination within the subnet. Suppose a new device is connected to a smart home subnet. This information will spread to all 20 nodes in the subnet within a few seconds through the Gossip protocol, without the need for a centralized broadcast mechanism. This decentralized approach greatly improves the scalability and fault tolerance of the system. Dynamic load balancing is the key to ensuring the long-term stable operation of the system. For example, when it is monitored that the load of a business district subnet continuously exceeds 80% on weekdays, while the load of the adjacent residential area subnet is only 30%, the system will automatically transfer the identity verification tasks of some devices from the business district subnet to the residential area subnet. This dynamic adjustment not only balances the load but also improves the overall resource utilization of the system. Through this multi-level and dynamically adjustable architecture design, the IoT identity management system can efficiently handle the identity verification requests of a large number of devices while maintaining good scalability and robustness. This is crucial for the stable operation and future development of smart cities.

[0026] S104. After synchronizing the local identity information, use the cross-shard communication protocol to propagate the identity information change to other shards. When communication between shards encounters an exception, start the retry mechanism or trigger an alarm to ensure that the consistency requirements of the identity information are met.

[0027] According to the preset sharding rules, divide the identity information into different shards, and maintain a complete copy of the identity information within each shard. Within each shard, use the consistent hashing algorithm to map the identity information to the corresponding nodes. The nodes are synchronized in real time through a distributed cache such as Redis to ensure the consistency of the data within the shard. When the identity information within a certain shard changes, encapsulate the change information into a message through the cross-shard communication protocol and propagate it to other shards. During the cross-shard communication process, use a message queue middleware such as Kafka and the publish-subscribe mode to ensure that the change message can be reliably delivered to the target shard. For possible network exceptions in cross-shard communication, set a message retry mechanism. Use the exponential backoff algorithm, with the initial retry interval being 1 second. Multiply the interval time by 2 after each retry failure, and retry at most 5 times. When consecutive retries still fail, trigger the alarm mechanism, and notify the operation and maintenance personnel by means such as text messages, emails, and enterprise WeChat, and provide detailed error information and logs to facilitate problem troubleshooting. After receiving the change message from other shards, judge whether to update the local copy according to the identity information identifier and timestamp carried in the message. If the timestamp of the message is newer than the timestamp of the local copy, perform the update operation; otherwise, ignore the message to avoid data backtracking and inconsistency problems. During the update process, use the optimistic lock mechanism to prevent data conflicts through version number comparison to ensure the ultimate consistency between shards.

[0028] Specifically, the sharding rule is one of the core designs of the identity information management system. For example, sharding can be performed based on geographical location. The whole country can be divided into five major regions: east, south, west, north, and central. Each major region serves as a shard. Within each shard, the consistent hashing algorithm is used to map the identity information to nodes. Suppose there are 100 nodes in the eastern major region. The SHA-256 hash function is used to map the ID number to the hash ring from 0 to 2^256 - 1, and then this range is evenly distributed among 100 nodes. This can achieve load balancing and minimize data migration when nodes are added or removed. Real-time synchronization within the shard is crucial for ensuring data consistency. Taking Redis as an example, the master-slave replication mechanism can be used. One master node and multiple slave nodes are set up within each shard. The master node is responsible for write operations, and the slave nodes are responsible for read operations. When the data on the master node changes, the changes will be automatically synchronized to the slave nodes. This mechanism not only ensures data consistency but also improves the reading performance and availability of the system. Cross-shard communication is the key to ensuring data consistency across the entire system. Using Kafka as the message queue middleware can achieve high-throughput and low-latency message delivery. For example, when an identity information change occurs in the eastern major region, the system will encapsulate this change into a message and publish it to the "identity_update" topic of Kafka. The shards in the other four major regions subscribe to this topic and can receive the change information in a timely manner. This publish-subscribe mode enables the system to flexibly handle large-scale data synchronization requirements. Network anomalies are inevitable problems in distributed systems. The exponential backoff algorithm can effectively handle this situation. Suppose a message sent from the eastern major region to the southern major region fails. The system will perform the first retry after 1 second. If it still fails, the second retry will be performed after 2 seconds, the third after 4 seconds, and so on. This strategy can solve temporary network problems in a short time and avoid the additional burden on the system caused by frequent retries. The alarm mechanism is an important means to ensure the stable operation of the system. When the message retry fails 5 times, the system will trigger multi-channel alarms. For example, send a message containing error details to the enterprise WeChat group of the operation and maintenance team, send an email to the technical person in charge at the same time, and send a text message to the on-duty personnel. This multi-channel alarm strategy ensures that problems can be discovered and handled in a timely manner. Timestamp comparison is an effective method to solve data conflicts. Suppose the southern major region receives an identity information update message from the eastern major region with a timestamp of 2024-06-22 10:30:00, while the timestamp of the local copy in the southern major region is 2024-06-22 10:29:55. In this case, the system will accept this update message because it contains updated information. This mechanism effectively avoids data inconsistency problems caused by network latency or message disorder. The optimistic lock mechanism is the last line of defense to ensure data consistency. Each piece of identity information will have a version number, initially 1.When a shard needs to update a piece of information, it will first check whether the local version number is the same as the version number in the received message. If they are the same, the update is executed and the version number is incremented by 1. If they are different, it means the data has been modified by other processes. In this case, the latest data needs to be retrieved again and the update attempt is made. This mechanism effectively prevents data overwrite problems caused by concurrent updates and ensures eventual consistency among shards.

[0029] S105. For the dynamic update nature of frequent device joining and leaving, design a timestamp-based identity status update mechanism. When a device joins the network, obtain its identity information and generate a timestamp marker. When a device goes offline or fails, compare the difference between the current time and the last update timestamp. If it exceeds a preset threshold, it is determined that the device is offline or has failed, and the identity status in the blockchain is updated.

[0030] Obtain the identity information of the device when it joins the network, including the device unique identifier, device type, device status, etc. Generate a timestamp marker based on the obtained identity information and store the identity information and timestamp marker in the database in an associated manner. Regularly monitor the timestamp markers of devices in the database. If it is found that the timestamp of a certain device has not been updated for a long time, exceeding the preset heartbeat threshold time, it is determined that the device is offline or has failed. The heartbeat threshold can be reasonably set according to the device type and network environment. For the device determined to be offline or failed, update its identity status in the database to the offline or failed state, and synchronously write the updated device identity information into the block data corresponding to the device in the blockchain. Nodes in the blockchain network verify and confirm the update transaction of the device identity status through consensus algorithms such as PBFT to ensure the consistency of the device identity status information in each node. Use a smart contract to automatically trigger the update of the device identity status. The smart contract sets the rule: when the offline time of the device in the database exceeds the threshold, automatically update the identity status of the device to offline and write it into a new block. Query the device identity status information in the blockchain through a blockchain browser or API interface, and visually display and analyze the queried information to provide data support for device management. The analysis content includes statistical information such as the online rate and offline frequency of the device. According to the historical online status of the device recorded in the blockchain, analyze the usage patterns and behavior models of the device, construct a device profile, and provide a reference basis for detecting abnormal devices. For example, a device with frequent offline may have a failure risk and needs to be focused on.

[0031] Specifically, the device identity management system is an important foundation for IoT security. Obtaining the identity information of a device when it joins the network is the first step, which includes the device's unique identifier (such as MAC address or serial number), device type (such as smart camera, temperature sensor), and device status (such as online, offline). The system generates a timestamp for each piece of identity information, such as "2024-06-22 10:30:00", and stores it in the database together with the identity information. This associated storage method facilitates subsequent status monitoring and updates. Regular monitoring is the key to ensuring the real-time nature of device status. The system checks the latest timestamp of each device in the database. If it is found that the timestamp of a certain device has not been updated for a long time, such as exceeding the preset heartbeat threshold time (for example, 5 minutes for a smart camera and 30 minutes for a temperature sensor), then it is determined that the device is offline or malfunctioning. This differential heartbeat threshold setting takes into account the characteristics of different devices and network environments, improving the accuracy of judgment. When the system determines that a device is offline or malfunctioning, it updates the status of the device in the database and synchronizes this update to the blockchain network. The use of blockchain brings advantages such as decentralization, immutability, and traceability to device identity management. For example, when a smart door lock is determined to be offline, the system generates a transaction containing the device ID, status update (online → offline), and timestamp, and broadcasts it to the blockchain network. Nodes in the blockchain network use consensus algorithms such as Practical Byzantine Fault Tolerance (PBFT) to verify this transaction. The PBFT algorithm can still ensure the consistency of the system in the presence of a small number of malicious nodes, which is crucial for IoT device management. After verification, the transaction is packaged into a new block, ensuring the consistency of device identity status information among all nodes. The introduction of smart contracts makes the device status update process more automated and intelligent. For example, a smart contract can be written to stipulate that when it is detected that a device has been offline for more than 24 hours, its status is automatically updated to "needs maintenance", and a maintenance notice is triggered. This automated mechanism greatly improves the efficiency of device management. Through the blockchain browser or API interface, administrators can query and analyze the identity status information of devices in real time. For example, a dashboard can be generated to display key metrics such as the online rate and average offline duration of all devices. These visual data provide strong support for device management decisions. Based on the historical data recorded by the blockchain, the system can analyze the usage patterns and behavior models of devices and construct device profiles. For example, if a temperature sensor is frequently offline between 2 am and 4 am every day, this may imply that the system load is too high due to scheduled tasks. Through this analysis, administrators can optimize the system configuration and improve the stability of the device. This blockchain-based device identity management solution not only improves the credibility of data but also provides a solid technical foundation for the full life cycle management of devices. It can effectively address the management challenges brought about by the rapid increase in the number of IoT devices and make an important contribution to building a secure and reliable IoT ecosystem.

[0032] When an exception occurs during the transmission of the encrypted information, the retransmission mechanism is triggered until the information completely reaches the target node.

[0033] The original information is encrypted according to the preset AES encryption algorithm to obtain an encrypted information data packet. The encrypted information data packet is divided into several transmission units according to the preset maximum transmission unit size, and a unique sequence number is assigned to each transmission unit. The transmission units are sequentially sent to the target node through the TCP protocol, and a timer is started to monitor the transmission time of each transmission unit. If the ACK confirmation for a certain transmission unit is not received within the preset RTT time threshold, it is determined that a packet loss exception occurs during the transmission of this transmission unit. According to the sequence number of the unconfirmed transmission unit, the corresponding encrypted information data packet is obtained from the local HashMap cache, and the transmission unit is re-divided according to the maximum transmission unit size. The retransmitted transmission unit is sent to the target node through the TCP protocol, and the timer is updated to continue monitoring the transmission status of the transmission unit. The retransmission of the unconfirmed transmission unit is repeatedly executed until the ACK confirmation for all transmission units is received from the target node to ensure the integrity and reliability of the encrypted information.

[0034] Specifically, in the secure communication of the Internet of Things, encryption and reliable transmission are crucial. First, the AES encryption algorithm is used to encrypt the original information. AES is a symmetric encryption algorithm, featuring high efficiency and security. For example, the temperature sensor in a smart home system collects the room temperature data "25°C", which may become ciphertext such as "7Fh8J2pL9x" after being encrypted by AES. The encrypted data packet needs to be divided according to the maximum transmission unit (MTU). MTU is the maximum length of a data packet in the network, usually 1500 bytes. Suppose the size of the encrypted data packet is 4500 bytes and the MTU is 1500 bytes, then it needs to be divided into 3 transmission units. Each unit is assigned a unique sequence number, such as 1, 2, 3, which is convenient for the receiving party to reassemble and the sending party to retransmit. The TCP protocol is used to transmit the data unit to ensure reliability. The three-way handshake and four-way handshake mechanisms of TCP guarantee the establishment and disconnection of the connection. The sending party starts a timer to monitor the transmission time, and sets a threshold for the round-trip time (RTT), such as 200 milliseconds. If the ACK confirmation from the target node is not received after exceeding the threshold, it is determined that a packet loss has occurred. For example, in a smart grid system, the control center sends a control instruction to a substation. Suppose the second transmission unit does not receive the ACK within 200 milliseconds, and the system determines that this unit is lost. At this time, the sending party obtains the corresponding encrypted data packet from the local HashMap cache. HashMap provides fast key-value pair lookup, which is beneficial to improving the retransmission efficiency. Redividing the transmission unit and retransmitting it are key steps to ensure data integrity. Continuing with the example of the smart grid, the control center resends the lost second transmission unit. At the same time, the timer is updated to continue monitoring the transmission status. This process may be repeated multiple times until the ACK confirmations of all transmission units are received. This mechanism plays an important role in various Internet of Things applications. For example, in a smart transportation system, the communication between in-vehicle units and roadside units requires a high degree of reliability and real-time performance. When transmitting key information such as vehicle location and speed, even in a complex electromagnetic environment, this mechanism can ensure the complete delivery of data. The whole process embodies the idea of "divide and conquer", dividing large encrypted data packets into small units for easy transmission and management. At the same time, through the sequence number and ACK mechanism, the orderly transmission of data and packet loss detection are realized. This not only improves the transmission efficiency but also enhances the fault tolerance of the system, providing a reliable guarantee for the secure communication between Internet of Things devices.

[0035] S107. During the identity information synchronization process, when a device identity information conflict is detected, start the conflict resolution mechanism. By comparing the timestamps and node credibility, determine the final valid identity information and update it to the blockchain network. The node credibility is comprehensively calculated based on the node's historical synchronization accuracy, network stability, and computing power.

[0036] During the identity information synchronization process, the consistency of device identity information is monitored in real time. By comparing the existing identity information in the blockchain network, it is determined whether there are information conflicts. If it is detected that the device identity information is inconsistent with the existing information in the blockchain network, the conflict resolution mechanism is triggered. Extract the identity information of the conflicting device, including key information such as device ID and timestamp, and determine the corresponding conflict node. Obtain the credibility information of the conflict node from the blockchain network, including indicators such as historical synchronization accuracy, network stability, and computing power, and calculate the comprehensive credibility score according to the preset weight coefficient. Compare the timestamp of the conflicting device and the credibility score of the corresponding node, and determine the final valid identity information according to the principle of timestamp first and credibility second. Update the determined valid identity information to the blockchain network, and verify and confirm it through the Raft consensus algorithm to ensure the consistency and credibility of the identity information. The Raft algorithm elects a leader node, and the leader node synchronizes the latest identity information to all nodes. After more than half of the nodes confirm, the update can be submitted. After the identity information update is completed, the update result is synchronized to the relevant devices and application systems to ensure the consistency of the identity information of each node. Continuously monitor the identity information status in the blockchain network, analyze the node behavior patterns through the K-means clustering algorithm, dynamically adjust the node credibility evaluation model, and improve the accuracy and efficiency of identity conflict resolution. Group the nodes according to the clustering results, set different evaluation weights for different groups of nodes, and realize the dynamic optimization of node credibility evaluation.

[0037] Specifically, in the Internet of Things (IoT) environment, the consistency of device identity information is of utmost importance. Real-time monitoring and comparison of identity information in the blockchain network can promptly detect potential conflicts. For example, in the traffic management system of a smart city, each traffic signal has a unique device ID. Suppose the position coordinates recorded for traffic signal A at an intersection in the blockchain network are (116.3, 39.9), but due to GPS positioning errors, the coordinates reported by the device are (116.31, 39.91). In this case, the system will trigger a conflict resolution mechanism. The conflict resolution mechanism first extracts the key information of the conflicting device. In the case of traffic signal A, in addition to the device ID and position coordinates, it also includes the last update timestamp, device model, etc. Then, the system obtains the credibility information of relevant nodes from the blockchain network. Node credibility assessment involves multiple metrics, such as historical synchronization accuracy, network stability, and computing power. Suppose the synchronization accuracy of the edge computing node where traffic signal A is located has been 99.9% in the past month, the network stability is 98%, and the computing power score is 95 out of 100. The system calculates the comprehensive credibility score of this node as 98.45 based on preset weights (such as accuracy weight 0.5, stability weight 0.3, and computing power weight 0.2). When determining the final valid identity information, the system gives priority to the timestamp and then the node credibility. If the timestamp of the new coordinate information of traffic signal A is later than the record in the blockchain network, and the node providing the new information has a high credibility, the system will tend to adopt the new coordinate information. This mechanism can effectively handle situations such as device location changes or improved accuracy. The updated identity information needs to be verified and confirmed through the Raft consensus algorithm. In the intelligent transportation system, there may be multiple edge computing nodes responsible for traffic devices in different regions. The Raft algorithm first elects a leader node, such as the edge node responsible for the downtown area. This node sends the new coordinate information of traffic signal A to other nodes for confirmation. When more than half of the nodes (e.g., 3 out of 5 nodes) confirm, the new identity information is submitted and updated to the blockchain network. To continuously optimize the efficiency of identity conflict resolution, the system uses the K-means clustering algorithm to analyze the node behavior patterns. For example, the edge computing nodes in the urban traffic system are clustered according to characteristics such as geographical location, load conditions, and historical performance. Suppose the clustering results divide the nodes into three groups: high-density urban area group, suburban group, and industrial park group. The system may assign a higher credibility assessment weight to the nodes in the high-density urban area group because these nodes handle a large amount of data and are updated frequently, which can better reflect the real-time situation. Through this dynamic adjustment, the system can more accurately resolve identity conflicts and improve the overall efficiency. This identity information synchronization and conflict resolution mechanism is not only applicable to intelligent transportation but also widely used in other IoT applications. For example, in the smart grid system, the accuracy of the identity information of power equipment is directly related to the safe operation of the power grid.Through real-time monitoring and an efficient conflict resolution mechanism, the identity information of power grid devices can be ensured to always remain consistent and reliable, providing an important guarantee for the stable operation of the power system.

[0038] S108. Achieve efficient synchronization and consistency maintenance of the identity information of Internet of Things devices in the blockchain network, meeting the real-time and scalability requirements in Internet of Things scenarios.

[0039] According to the identity information of IoT devices, assign a unique identifier to each device in the blockchain network, and store this identifier together with other attribute information of the device on the blockchain, forming a distributed storage of device identity information. Adopt a smart contract-based approach to manage and synchronize the identity information of IoT devices. The smart contract defines the data structure and operation functions of device identity information, including device registration, attribute update, permission management, etc. When a new IoT device accesses the network, the unique identifier and initial attribute information of the device are written into the blockchain by calling the registration function of the smart contract. When the attribute information of the device changes, the device interacts with the nodes in the blockchain network, calls the update function of the smart contract, triggers the update operation of the attribute information, and synchronizes it to other nodes in the blockchain network to ensure the consistency of device identity information on each node. To improve the processing efficiency and scalability of the blockchain network, a sharding-based consensus mechanism is designed. Divide IoT devices into different shards according to certain rules. Inside each shard, the PBFT consensus algorithm is used to generate and verify blocks. Each shard processes in parallel, improving the concurrency of the network. At the same time, through the data synchronization and interaction mechanism between shards, the data consistency between shards is ensured. When a device accesses the blockchain network, a device identity authentication mechanism is introduced. The device needs to apply for a digital certificate from the authentication center. The certificate contains the public key and other identity information of the device. When the device communicates with the blockchain node, it uses the private key to digitally sign the message. The node verifies the validity of the signature and the certificate to ensure that only legitimate devices that have passed the authentication can participate in the synchronization and maintenance of identity information. To facilitate relevant parties to query the identity information and historical records of devices, a blockchain-based information query and traceability function is provided. Through tools such as Webjs, interact with the blockchain network, and query its attribute information and historical change records according to the unique identifier of the device. Utilize the immutability and traceability of the blockchain to ensure the authenticity and credibility of the query results. At the same time, by embedding access control logic in the smart contract, fine-grained management of the access permissions to the identity information of different devices is carried out. According to factors such as the type, ownership, and sensitivity of the device, set differentiated access policies to prevent unauthorized access and leakage of identity information. In terms of the communication between IoT devices and the blockchain network, an asynchronous communication mechanism based on message queues is adopted. The device sends messages to a specified message queue, and the blockchain node retrieves the messages from the queue and processes them, realizing reliable communication and data transmission between the device and the blockchain.

[0040] Specifically, in the identity management of Internet of Things (IoT) devices, the application of blockchain technology provides unique and immutable identity identifiers for devices. Taking the smart home system as an example, when each smart device (such as a smart lock, thermostat, security camera, etc.) connects to the network, it is assigned a unique blockchain address. This address serves not only as the device identifier but also stores other attribute information of the device (such as device type, manufacturer, installation location, etc.) on the blockchain, forming a complete device identity profile. Smart contracts play a key role in this process. Taking the smart lock as an example, when a new lock is installed, the installer writes information such as the unique identifier (such as serial number), model, and installation location of the lock into the blockchain by calling the registration function of the smart contract. If the user later replaces the battery of the lock, the device will automatically call the update function to synchronize the new battery status information to the blockchain network. This mechanism ensures that all relevant parties (such as users, property management companies, maintenance service providers) can obtain the latest status information of the device in real time. To improve the processing efficiency of the system, a sharding-based consensus mechanism is adopted. In a large residential community, devices can be divided into different shards according to buildings or functional areas. For example, all devices in Building A form one shard, and devices in Building B form another shard. The Practical Byzantine Fault Tolerance (PBFT) algorithm is used for consensus within each shard. In this way, even if there are thousands of devices in the entire community, the system can still operate efficiently. The device identity authentication mechanism ensures that only legitimate devices can access the network. Taking the smart meter as an example, the power company, as the certification center, issues digital certificates to each smart meter. When the meter needs to report electricity consumption data, it signs the data using its private key. The blockchain nodes verify the signature and certificate to ensure the authenticity of the data source, effectively preventing the meter data from being tampered with or forged. The query and traceability functions of the blockchain provide convenience for device management. For example, in a smart factory, the administrator can query the complete maintenance record of a certain robot on the production line through its unique identifier. This includes not only regular maintenance information but also historical records such as component replacements and software upgrades. Such transparent and immutable records help improve the efficiency of device management and quickly locate the cause of problems in case of failures. The access control mechanism ensures the security of device information. In the medical Internet of Things, a patient's vital sign monitoring device may contain sensitive health data. Through the access control logic in the smart contract, different levels of access permissions can be set. For example, the patient himself and the attending doctor can access all data, nurses can only view some necessary information, and hospital administrators can only see anonymized statistical data. The asynchronous communication mechanism based on message queues improves the reliability and efficiency of the system. In smart agriculture applications, sensors distributed in vast farmlands may not be able to communicate with the blockchain network in real time due to unstable network conditions. Through the message queue, the sensors can first send the collected data (such as soil humidity, temperature, etc.) to the local message queue.When network conditions permit, the blockchain nodes batch obtain and process this data from the queue, ensuring data integrity and system stability.

[0041] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A blockchain-based IoT device identity authentication method, characterized in that: include: Obtain identity information change requests from IoT devices, and use a lightweight consensus mechanism to perform preliminary verification of change requests in view of the large number and wide distribution of devices; Encrypt the verified identity information change request using a lightweight encryption algorithm, generate block data containing the encrypted device identity information, and broadcast the block data to other nodes in the blockchain network; According to the requirements of limited resources and real-time synchronization, a synchronization strategy based on sharding technology is designed to divide the network into multiple shards. The local synchronization of identity information is completed through an efficient consensus mechanism within the shards. After synchronizing the local identity information, the cross-shard communication protocol is used to propagate the identity information changes to other shards. When an abnormality occurs in the communication between shards, a retry mechanism is started or an alarm is triggered.

2. The method according to claim 1, characterized in that The lightweight consensus mechanism is used to conduct preliminary verification of the change request, including: The legitimacy and integrity of the request are determined according to preset rules. For change requests that pass the preliminary judgment, the PBFT consensus algorithm is used for voting verification, and the validity of the request is determined by the principle of approval by more than two-thirds of the nodes.

3. The method according to claim 1, characterized in that The encryption process using a lightweight encryption algorithm includes: The changed identity information is encrypted using the AES encryption algorithm. To ensure the security and reliability of the encryption process, a key rotation mechanism is adopted to update the encryption key through the key management system at regular intervals.

4. The method according to claim 1, characterized in that The design is based on the synchronization strategy of sharding technology, including: According to the specific range of identity information, the consistent hashing algorithm is used to divide the network into multiple shards. After the sharding is completed, a consensus mechanism based on the Raft protocol is designed for the identity information in each shard, and consensus is reached through a distributed consistency algorithm to achieve local synchronization within the shard.

5. The method according to claim 4, characterized in that After synchronizing the local identity information, the cross-shard communication protocol is used to propagate the identity information changes to other shards, including: Obtain the identity information of each shard after synchronization, and integrate the results of local synchronization into a globally consistent identity information view through the MerkleTree data aggregation algorithm and the longest chain principle conflict resolution algorithm.

6. The method according to claim 1, characterized in that The synchronization strategy based on sharding technology is designed according to the requirements of limited resources and real-time synchronization, and also includes: According to the real-time monitoring results of system load and response time, the number and range of shards are dynamically adjusted, and the processing pressure of each shard is balanced through the load balancing algorithm to ensure efficient identity information synchronization with limited resources.

7. The method according to claim 1, characterized in that When an abnormality occurs in the communication between shards, a retry mechanism is started or an alarm is triggered, including: Set up a message retry mechanism, use an exponential backoff algorithm, an initial retry interval, multiply the interval by 2 after each retry failure, and set a maximum number of retries; If multiple consecutive retries still fail, the alarm mechanism is triggered, and the operation and maintenance personnel are notified via SMS, email, and enterprise WeChat, and detailed error information and logs are provided.

8. The method according to claim 1, characterized in that The obtaining of the identity information change request of the IoT device also includes: According to the identity information of IoT devices, a unique identifier is assigned to each device in the blockchain network, and the identifier is stored on the blockchain together with other attribute information of the device, forming a distributed storage of device identity information; Manage and synchronize the identity information of IoT devices using a smart contract-based approach; The smart contract defines the data structure and operation functions of device identity information, including device registration, attribute update and permission management.

Citation Information

Patent Citations

  • Edge computing node dynamic election method based on blockchain

    CN109617992A

  • Sensor data processing method and device based on Blockchain fragmentation storage

    CN113411376A

  • Pump station safety control environment establishment method and device based on block chain

    CN117997548A

  • Security storage system of electronic information system

    CN118827232A

  • Intelligent networking distributed storage interaction system and method based on multi-cabin cooperation

    CN119292112A

Cited By

  • A method and system for large-scale meeting voting under a trusted mechanism

    CN122528126A