Edge device verification method and system based on zero-knowledge proof
By adopting the edge device verification method based on zero-knowledge proof in edge computing, the problems of high data transmission delay and poor security in traditional centralized systems are solved, and the data verification services with fast, secure and privacy protection on edge devices are realized, which significantly improves processing efficiency and security.
Patent Information
- Application Number
- CN202311849506.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-01
AI Technical Summary
In edge computing, traditional centralized systems are difficult to effectively protect data privacy and security due to high latency, low processing speed and data exposure to security threats.
Using the edge device verification method based on zero-knowledge proof, we realize the fast, secure and privacy verification service of data on edge devices by generating and verifying zero-knowledge proofs on edge devices. The method includes obtaining the information to be verified to generate a zero-knowledge proof, transmitting it to the edge device through a server, and verifying it through a combination of asymmetric encryption and dynamic parameters.
It significantly reduces the amount of data transmission, saves network bandwidth and transmission time, improves data processing efficiency, reduces the load pressure of cloud servers, and effectively protects data privacy and security.
Smart Images

Figure CN120238310A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular, to a method and system for verifying edge devices based on zero-knowledge proof. Background Art
[0002] With the rapid development of the Internet and the continuous growth of data processing requirements, edge computing has gradually become an important technological trend. In edge computing, data no longer needs to be transmitted to a remote cloud for processing, but is processed and analyzed on edge devices closer to the device. This brings faster speed and lower latency for data processing, but also brings challenges in security and privacy protection.
[0003] Zero-Knowledge Proof (ZKP) is a cryptographic technology that can verify the authenticity of a statement without revealing any useful information. In recent years, zero-knowledge proof has been widely used in security and privacy protection, especially on edge devices.
[0004] In traditional centralized systems, data needs to be transmitted to a central server for verification and processing, which not only brings high latency and low processing speed, but also exposes the data to potential security threats and privacy leaks.
[0005] To overcome these defects, the present application proposes a method and system for verifying edge devices based on zero-knowledge proof, where data can be verified and processed on edge devices, providing fast, secure and privacy-protected data verification services for edge devices. Summary of the Invention
[0006] The purpose of the present application is to provide a method and system for verifying edge devices based on zero-knowledge proof, aiming to solve the above problems.
[0007] To achieve the above purpose, the present application provides the following technical solutions:
[0008] The present application provides a method for verifying edge devices based on zero-knowledge proof, including:
[0009] Generating a zero-knowledge proof after obtaining the information to be verified;
[0010] Transmitting the zero-knowledge proof to the edge device through a server;
[0011] The edge device verifies the zero-knowledge proof by combining asymmetric encryption and dynamic parameters; where the edge device has its own public key and private key, and the dynamic parameters are introduced; when the dynamic parameters are verified to be consistent by both communicating edge devices, it is encrypted with the public key of the other party and sent to the terminal;
[0012] After receiving the zero - knowledge proof, the terminal decrypts it using the private key to obtain the information to be verified.
[0013] Further, in the step of generating a zero - knowledge proof after obtaining the information to be verified, the specific steps include:
[0014] Generate a zero - knowledge proof using cryptographic tools and parameters, including but not limited to hash functions, encryption algorithms, and random number generators;
[0015] Based on the information to be verified, construct one or more statements;
[0016] Use cryptographic tools and the generated random number to perform the zero - knowledge proof process.
[0017] Further, in the step of transmitting the zero - knowledge proof to the edge device through the server, the specific steps include:
[0018] Determine the first blockchain address, the first private key, and the first public key of the server; determine the second blockchain address and the second public key of the edge device; the edge device stores the second private key; the edge device sends a data covert transmission request to the server;
[0019] The server receives the data covert transmission request sent by the edge device and protects the first blockchain address of the server, the second blockchain address of the edge device, and the information to be verified through zero - knowledge proof technology;
[0020] The server divides the information to be verified into several subsets of data to be transmitted, performs hash operations on each subset of data to be transmitted respectively, obtains the digest information of several subsets of data to be transmitted, and re - sorts the digest information according to a preset disorder rule;
[0021] Encrypt the re - sorted digest information and the disorder rule using the second public key with an encryption algorithm and transmit them to the edge device.
[0022] Further, before the information to be verified is transmitted, compress the information to be verified to reduce the storage capacity;
[0023] A firewall is provided on the communication channel between the server and the edge device to detect malicious nodes.
[0024] Further, in the step where the edge device verifies the zero - knowledge proof by combining asymmetric encryption and dynamic parameters; where the edge device has its own public key and private key, and introduces the dynamic parameters; when the dynamic parameters verified by both communicating edge devices are consistent, encrypt them using the public key of the other party and send them to the terminal, the specific steps include:
[0025] The edge device is used to perform a hash operation after obtaining the information to be verified, send the information to be verified to the edge server, broadcast the hash value generated by itself in the blockchain network after verification, and generate an authentication block by the accounting node; the accounting node is in the edge device, and after sorting the edge devices according to the running state of the edge device, the edge device with the highest sequence is selected as the accounting node for the next consensus.
[0026] The edge server is used to perform a hash operation on the information to be verified after receiving the information to be verified sent by the edge device, broadcast the obtained hash value, and after verification by the edge device in the blockchain network, the edge server generates an information block for the information to be verified; and compare the hash value of the authentication chain with the hash value sent by the edge device, and write the comparison conclusion into the information blockchain.
[0027] When the number of nodes that have determined that the source data has not been tampered with after the hash value comparison between the edge server and the edge device reaches the preset consensus node number according to the consensus mechanism, the edge server generates an information block on the information chain for the information to be verified.
[0028] Adopt a consensus algorithm based on the practical Byzantine fault tolerance consensus algorithm. The edge server generates an information block on the information chain by the consensus mechanism, including: taking the edge server as the node with the accounting right. When more than (2*n + 1) / 3 edge devices receive the conclusion of no tampering from the preset edge devices or edge servers, a consensus is formed, and the edge server packages the information to be verified and generates a block of the information chain, where n is the number of edge devices.
[0029] If no node receives more than (2*n + 1) / 3 consent conclusions within the specified time, it is determined that the data has been tampered with, the qualification of the accounting node of the edge server is cancelled, and the current authentication chain accounting node acts as it. Write this conclusion into the data block, do not upload the data to the chain, and the edge devices temporarily store the information to be verified collected by themselves until the edge server returns to normal for the next authentication.
[0030] Furthermore, the method of combining asymmetric encryption and dynamic parameters includes:
[0031] Each edge device has its own public key and private key, and a dynamic parameter is introduced;
[0032] After the two communicating edge devices verify that the dynamic parameters are consistent, after adding the hash value of the dynamic parameter to the transmitted data, it is encrypted with the public key of the other party and then sent;
[0033] After receiving the data, use the private key to decrypt to obtain the information to be verified. In the P2P network of the edge device, every two edge devices interact once, and the value of this dynamic parameter increases by 1. When it increases to the predetermined value, it starts counting again;
[0034] Each edge device verifies the data hash value from the edge server, and based on whether the fields corresponding to the data of the edge server collected by itself are consistent, draws a conclusion on whether its own data has been tampered with;
[0035] The conclusion drawn by the edge device is sent to all other edge devices with its own identity signature attached;
[0036] The edge server compares the hash value in the authentication chain block with the data on the information chain. If different fields are found, it locates the ID of the edge device and records it in the next block of the information chain.
[0037] This application provides an edge device verification system based on zero-knowledge proof, including:
[0038] Acquisition module: Generates a zero-knowledge proof after acquiring the information to be verified;
[0039] Transmission module: Transmits the zero-knowledge proof to the edge device through the server;
[0040] Verification module: The edge device verifies the zero-knowledge proof by combining asymmetric encryption and dynamic parameters; where the edge device has its own public key and private key, and the dynamic parameters are introduced; when the two communicating edge devices verify that the dynamic parameters are consistent, they encrypt and send it to the terminal using the public key of the other party; after receiving the zero-knowledge proof, the terminal decrypts it using the private key to obtain the information to be verified.
[0041] This application provides a device, which includes a processor and a memory coupled to the processor. Among them, the memory stores program instructions for implementing an edge device verification method based on zero-knowledge proof; the processor is used to execute the program instructions stored in the memory to implement an edge device verification based on zero-knowledge proof.
[0042] This application provides a storage medium, which stores program instructions that can be run by a processor, and the program instructions are used to execute an edge device verification method based on zero-knowledge proof.
[0043] This application provides an edge device verification method and system based on zero-knowledge proof, having the following
[0044] Beneficial effects:
[0045] (1) Protect the first blockchain address of the server, the second blockchain address of the edge device, and the information to be verified through zero-knowledge proof technology, so as to detect and prevent attacks by malicious nodes before the information to be verified is transmitted;
[0046] (2) Since the data volume of zero - knowledge proofs themselves is usually small, compared with transmitting the information to be verified, transmitting zero - knowledge proofs can significantly reduce the data transmission volume, thereby saving network bandwidth and transmission time;
[0047] (3) Edge devices can process zero - knowledge proofs locally without transmitting them to the cloud for processing, improving data processing efficiency and reducing the load pressure on cloud servers. Description of the Drawings
[0048] Figure 1 It is a schematic flowchart of a method for verifying edge devices based on zero - knowledge proofs according to Embodiment 1 of the present application;
[0049] Figure 2 It is a schematic structural diagram of a system for verifying edge devices based on zero - knowledge proofs according to Embodiment 2 of the present application;
[0050] Figure 3 It is a schematic structural diagram of the device according to Embodiment 3 of the present application;
[0051] Figure 4 It is a schematic structural diagram of the storage medium according to Embodiment 4 of the present application. Detailed Embodiments
[0052] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0053] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0054] Embodiment 1
[0055] Please refer to Figure 1 , which is a schematic flowchart of a method for verifying edge devices based on zero - knowledge proofs according to Embodiment 1 of the present application; the steps include:
[0056] S1: Generate a zero - knowledge proof after obtaining the information to be verified.
[0057] In this embodiment, first, appropriate cryptographic tools and parameters need to be selected to generate zero - knowledge proofs. These tools and parameters may include hash functions, encryption algorithms, random number generators, etc.
[0058] Based on the information to be verified, construct one or more claims. These claims can be assertions about the authenticity and integrity of the data, or claims about a certain calculation result.
[0059] To increase the anonymity and security of the proof, some random numbers need to be generated. These random numbers will be used in the subsequent proof process.
[0060] Using cryptographic tools and the previously generated random numbers, perform the zero - knowledge proof process. This process may involve some complex mathematical operations and logical reasoning to ensure the authenticity and validity of the proof.
[0061] It can be understood that zero - knowledge proof allows the authenticity of information to be proven without revealing the information itself to be verified. This is particularly important for sensitive information such as personal identities, transaction details, etc. Through zero - knowledge proof, information verification can be completed while ensuring privacy. Zero - knowledge proof can be an effective tool for enhancing system security. For example, it can be used to implement more secure authentication or to verify the source and integrity of information in a distributed system.
[0062] S2: Transmit the zero - knowledge proof to the edge device through the server.
[0063] In this embodiment, determine the first blockchain address, the first private key, and the first public key of the server; determine the second blockchain address and the second public key of the edge device; the edge device stores the second private key; the edge device sends a data covert transmission request to the server;
[0064] The server receives the data covert transmission request sent by the edge device and protects the first blockchain address of the server, the second blockchain address of the edge device, and the information to be verified through zero - knowledge proof technology;
[0065] The server divides the information to be verified into several subsets of data to be transmitted, performs hash operations on the several subsets of data to be transmitted respectively to obtain the digest information of the several subsets of data to be transmitted, and re - sorts the digest information according to a preset disorder rule;
[0066] Encrypt the re - sorted digest information and the disorder rule using the second public key with an encryption algorithm and transmit them to the edge device.
[0067] Before the information to be verified is transmitted, compress the information to be verified to reduce the storage capacity; a firewall is provided on the communication channel between the server and the edge device to detect malicious nodes.
[0068] It can be understood that since the data volume of zero - knowledge proofs is usually small, compared with transmitting the information to be verified, transmitting zero - knowledge proofs can significantly reduce the data transmission volume, thereby saving network bandwidth and transmission time. At the same time, edge devices can process zero - knowledge proofs locally without transmitting them to the cloud for processing, improving data processing efficiency and reducing the load pressure on cloud servers.
[0069] S3: The edge device verifies the zero - knowledge proof by combining asymmetric encryption and dynamic parameters; where the edge device has its own public key and private key, and the dynamic parameters are introduced; when both communicating edge devices verify that the dynamic parameters are consistent, they encrypt it with the other party's public key and send it to the terminal.
[0070] In this embodiment, the edge device is used to perform a hash operation after obtaining the information to be verified, send the information to be verified to the edge server, broadcast the hash value generated by itself after verification in the blockchain network, and the accounting node generates an authentication block; the accounting node is in the edge device, and after sorting the edge devices according to the running state of the edge device, the edge device with the highest sequence is selected as the accounting node for the next consensus.
[0071] The edge server is used to perform a hash operation on the information to be verified after receiving it from the edge device, broadcast the obtained hash value, and after verification by the edge device in the blockchain network, the edge server generates an information block for the information to be verified; and compare the hash value of the authentication chain with the hash value sent by the edge device, and write the comparison conclusion into the information blockchain.
[0072] When the number of nodes that have determined through hash value comparison that the source data has not been tampered with reaches the preset number of consensus nodes between the edge server and the edge device according to the consensus mechanism, the edge server generates an information block on the information chain for the information to be verified.
[0073] Adopting a consensus algorithm based on the practical Byzantine fault - tolerant consensus algorithm, the edge server generates an information block on the information chain by the consensus mechanism, including: taking the edge server as the node with the right to keep accounts, when more than (2*n + 1) / 3 edge devices receive the conclusion of no tampering from the preset edge devices or edge servers, a consensus is formed, and the edge server packages the information to be verified and generates a block of the information chain, where n is the number of edge devices.
[0074] If no node receives more than (2*n + 1) / 3 consent conclusions within the specified time, it is determined that the data has been tampered with, the qualification of the accounting node of the edge server is cancelled, and the current authentication chain accounting node acts as it, writes this conclusion into the data block, does not put the data on the chain, and the edge devices temporarily store the information to be verified collected by themselves until the edge server returns to normal for the next authentication.
[0075] The method of combining asymmetric encryption and dynamic parameters includes:
[0076] Each edge device has its own public key and private key, and dynamic parameters are introduced;
[0077] After the two communicating edge devices verify that the dynamic parameters are consistent, they add the hash value of the dynamic parameters to the transmitted data and then encrypt it with the public key of the other party before sending;
[0078] After receiving the data, use the private key to decrypt to obtain the information to be verified. In the P2P network of edge devices, every two edge devices interact once, and the value of the dynamic parameter increases by 1. When it increases to a predetermined value, it is recounted;
[0079] Each edge device verifies the hash value of the data from the edge server, and based on whether the fields corresponding to the data collected by itself and the edge server data are consistent, it draws a conclusion on whether its own data has been tampered with;
[0080] The conclusion drawn by the edge device is attached with its own identification signature and sent to all other edge devices.
[0081] The edge server compares the hash value in the authentication chain block with the data on the information chain. If different fields are found, it locates the ID of the edge device and records it in the next block of the information chain.
[0082] S4: After receiving the zero-knowledge proof, the terminal uses the private key to decrypt to obtain the information to be verified.
[0083] Embodiment 2
[0084] Please refer to Figure 2 , which is a schematic structural diagram of an edge device verification system based on zero-knowledge proof according to Embodiment 2 of the present application; the specific content includes:
[0085] Acquisition module: After acquiring the information to be verified, generate a zero-knowledge proof;
[0086] Transmission module: Transmit the zero-knowledge proof to the edge device through the server;
[0087] Verification module: The edge device verifies the zero-knowledge proof by combining asymmetric encryption and dynamic parameters; among them, the edge device has its own public key and private key, and the dynamic parameters are introduced; when the two communicating edge devices verify that the dynamic parameters are consistent, they encrypt with the public key of the other party and send it to the terminal; after receiving the zero-knowledge proof, the terminal uses the private key to decrypt to obtain the information to be verified.
[0088] In this embodiment, a P2P (peer to peer) network is established between each edge device in the system architecture, and an edge server is set up on the end side. In the case of limited external network communication, the authenticity of the edge device data before and after transmission to the central server is guaranteed based on the verification of blockchain technology. Two blockchains are established, namely "Authentication Chain" and "Information Chain", and their blocks are named CB and IB respectively.
[0089] A five-layer logical architecture is used to represent the data authenticity verification architecture of edge scenarios based on blockchain. The bottom data layer is the information to be verified and the hash operation of the information to be verified by the edge device and the edge server. The information to be verified is sent to the edge device, and then the edge device and the edge server perform hash operations on the source data to verify whether the information to be verified has been maliciously tampered with or lost due to device failure before being written into the block. The hash value in the block structure is used to verify the integrity and availability of historical data, and to maintain the continuation of the chain structure. The network layer represents the network structure of edge devices and edge servers as blockchain nodes, which are P2P and fully interconnected networks (i.e., mesh networks), respectively, for different consensus situations.
[0090] In the authentication chain, the edge device is the accounting node. The edge devices are sorted based on the amount of data collected by the edge devices and the operating status of the edge devices, and the edge device with the highest sequence is selected as the accounting node for the next consensus. The edge device will upload the hash value of the information to be verified to the chain. At the same time, if the current accounting edge device is not executed, the edge device with the highest sequence will generate the block. At the same time, the behavior of the unexecuted edge device will be recorded and displayed through the corresponding application of the application layer for inspection and maintenance.
[0091] In the information chain, the practical Byzantine fault-tolerant consensus algorithm is used to make improvements based on this scenario. Drawing on the PBFT's tolerance for "traitors" of less than 1 / 3 of the consensus nodes, the edge server is set up as a fixed master node, responsible for the packaging of the information chain blocks. At the same time, the scheme can also include verification of the master node. If the current master node does not perform block production or is verified as a malicious node, based on the number of edge servers, if there is only one edge server, the master node will not be replaced, and only the accounting rights will be transferred.
[0092] Example 3
[0093] See also Figure 3 , is a schematic diagram of the device structure of Embodiment 3 of the present application. The device 50 includes a processor 51 and a memory 52 coupled to the processor 51 .
[0094] The memory 52 stores program instructions for implementing the above-mentioned edge device verification method based on zero-knowledge proof.
[0095] The processor 51 is used to execute the program instructions stored in the memory 52 to implement an edge device verification based on zero-knowledge proof.
[0096] Among them, the processor 51 can also be called a CPU (Central Processing Unit).
[0097] The processor 51 may be an integrated circuit chip with signal processing capabilities. The processor 51 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0098] Embodiment 4
[0099] Please refer to Figure 4 , which is a schematic structural diagram of the storage medium according to Embodiment 4 of the present application. The storage medium of the embodiment of the present application stores a program file 61 that can implement all the above methods. Among them, the program file 61 can be stored in the above storage medium in the form of a software product, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, or devices such as computers, servers, mobile phones, and tablets.
[0100] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, apparatus, article or method including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, apparatus, article or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, apparatus, article or method including that element.
[0101] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
[0102] Although embodiments of the present application have been shown and described, those of ordinary skill in the art will appreciate that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present application. The scope of the present application is defined by the appended claims and their equivalents.
[0103] Of course, the present invention can also have many other embodiments. Based on this embodiment, other embodiments obtained by those of ordinary skill in the art without any creative work fall within the scope of protection of the present invention.
Claims
1. An edge device verification method based on zero-knowledge proof, characterized in that, Including: Generate a zero-knowledge proof after obtaining the information to be verified; Transmit the zero-knowledge proof to the edge device through the server; The edge device verifies the zero-knowledge proof by combining asymmetric encryption and dynamic parameters; Among them, the edge device has its own public key and private key, and introduces the dynamic parameters; when the two communicating edge devices verify that the dynamic parameters are consistent, they encrypt with the public key of the other party and send it to the terminal; After receiving the zero-knowledge proof, the terminal decrypts it with the private key to obtain the information to be verified.
2. The edge device verification method based on zero-knowledge proof according to claim 1, wherein In the step of generating a zero-knowledge proof after obtaining the information to be verified, the specific steps include: Generate a zero-knowledge proof using cryptographic tools and parameters, including but not limited to hash functions, encryption algorithms, and random number generators; Based on the information to be verified, construct one or more statements; Use cryptographic tools and the generated random numbers to execute the zero-knowledge proof process.
3. The edge device verification method based on zero-knowledge proof according to claim 1, wherein, In the step of transmitting the zero-knowledge proof to the edge device through the server, the specific steps include: Determine the first blockchain address, first private key, and first public key of the server; determine the second blockchain address and second public key of the edge device; the edge device stores the second private key; the edge device sends a data covert transmission request to the server; After receiving the data covert transmission request sent by the edge device, the server protects the first blockchain address of the server, the second blockchain address of the edge device, and the information to be verified through zero-knowledge proof technology; The server divides the information to be verified into several data subsets to be transmitted, performs a hash operation on each of the several data subsets to be transmitted to obtain the digest information of the several data subsets to be transmitted, and reorders the digest information according to a preset disorder rule; Encrypt the reordered digest information and the disorder rule through the second public key using an encryption algorithm and transmit it to the edge device.
4. A method for verifying edge devices based on zero - knowledge proof according to claim 1, characterized in that, Before the information to be verified is transmitted, compress the information to be verified to reduce the storage capacity; A firewall is provided on the communication channel between the server and the edge device for detecting malicious nodes.
5. The edge device verification method based on zero-knowledge proof according to claim 1, characterized in that, In the edge device, verify the zero-knowledge proof by combining asymmetric encryption and dynamic parameters; Among them, the edge device has its own public key and private key, and introduces the dynamic parameters; when the two communicating edge devices verify that the dynamic parameters are consistent, the specific steps in the step of encrypting with the public key of the other party and sending it to the terminal include: The edge device is used to perform a hash operation after obtaining the information to be verified, send the information to be verified to the edge server, broadcast the hash value generated by itself in the blockchain network after verification, and the accounting node generates an authentication block; the accounting node is in the edge device, and after sorting the edge devices according to the running state of the edge device, the edge device with the highest sequence is selected as the accounting node for the next consensus; The edge server is used to perform a hash operation on the information to be verified after receiving the information to be verified sent by the edge device, broadcast the obtained hash value, and after verification by the edge device within the blockchain network, the edge server generates an information block for the information to be verified; and compares the hash value of the authentication chain with the hash value sent by the edge device, and writes the comparison conclusion into the information blockchain; When the number of nodes that have determined through hash value comparison that the source data has not been tampered with between the edge server and the edge device reaches the preset consensus node number according to the consensus mechanism, the edge server generates an information block on the information chain for the information to be verified; Adopt a consensus algorithm based on the practical Byzantine fault tolerance consensus algorithm. The edge server generates an information block on the information chain by the consensus mechanism, including: using the edge server as the node with the bookkeeping right. When more than (2*n + 1) / 3 edge devices receive the conclusion that the data has not been tampered with, a consensus is formed. The edge server packages the information to be verified and generates a block of the information chain, where n is the number of edge devices; If no node receives more than (2*n + 1) / 3 consent conclusions within the specified time, it is determined that the data has been tampered with, the qualification of the bookkeeping node of the edge server is cancelled, and the current authentication chain bookkeeping node acts as such, writes this conclusion into the data block, does not upload the data to the chain, and the edge devices temporarily store the information to be verified collected by themselves until the edge server returns to normal and conducts the next authentication.
6. The edge device verification method based on zero-knowledge proof according to claim 1, characterized in that The method of combining asymmetric encryption and dynamic parameters mentioned above includes: Each edge device has its own public key and private key, and a dynamic parameter is introduced; After the two communicating edge devices verify that the dynamic parameters are consistent, they add the hash value of the dynamic parameter to the transmitted data and then encrypt it with the public key of the other party before sending; After receiving the data, use the private key to decrypt to obtain the information to be verified. In the P2P network of edge devices, every two edge devices interact once, and the value of this dynamic parameter increases by 1. When it increases to a predetermined value, it starts counting again; Each edge device verifies the data hash value from the edge server, and based on whether the part collected by itself is consistent with the fields corresponding to the edge server data, draws a conclusion on whether its own data has been tampered with; The conclusion drawn by the edge device is sent to all other edge devices with its own identity signature attached; The edge server compares the hash value in the authentication chain block with the data on the information chain. If different fields are found, it locates the ID of the edge device and records it in the next block of the information chain.
7. A system for an edge device verification method based on zero-knowledge proof according to claim 1, characterized in that, It includes: Acquisition module: Generate a zero-knowledge proof after acquiring the information to be verified; Transmission module: Transmit the zero-knowledge proof to the edge device through the server; Verification module: The edge device verifies the zero-knowledge proof by combining asymmetric encryption and dynamic parameters; Among them, the edge device has its own public key and private key, and the dynamic parameter is introduced; when the two communicating edge devices verify that the dynamic parameters are consistent, they encrypt it with the public key of the other party and send it to the terminal; after receiving the zero-knowledge proof, the terminal uses the private key to decrypt to obtain the information to be verified.
8. A device, characterized in that, The device includes a processor and a memory coupled to the processor. Among them, the memory stores program instructions for implementing a zero-knowledge-proof-based edge device verification method according to any one of claims 1-6; the processor is configured to execute the program instructions stored in the memory to implement a zero-knowledge-proof-based edge device verification.
9. A storage medium, characterized in that, There are program instructions that can be run by the processor stored, and the program instructions are used to execute a zero-knowledge-proof-based edge device verification method according to any one of claims 1-6.
Citation Information
Cited By
Equipment access method and device, electronic equipment and storage medium
CN121508815A