Efficient, safe and extensible Internet of Things node management network and construction method thereof

Through node classification, registration, cluster structure and pyramid network topology, resource utilization, coordination and security issues in IoT node management are solved, and an efficient, secure and scalable IoT node management network is achieved.

CN120281538APending Publication Date: 2025-07-08BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510445686.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing IoT technology faces the problems of numerous nodes, dispersed deployment, limited storage and computing resources, poor controllable dynamic coordination, and insufficient data security and privacy protection, resulting in low management efficiency, poor security and difficulty in scaling.

Method used

Node classification and evaluation, registration and identity authentication, formation of underlying and second-layer clusters, pyramid-type network topology construction, identity access control and security management measures are adopted to form an efficient, secure and scalable IoT node management network.

Benefits of technology

It improves resource utilization, enhances the coordination between nodes and the scalability of the network, ensures data security and privacy protection, and solves the management and security challenges existing in the existing technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281538A_ABST
    Figure CN120281538A_ABST
Patent Text Reader

Abstract

The invention discloses an efficient, safe and extensible Internet of Things node management network and a construction method thereof, belongs to the field of Internet of Things and block chain technology fusion, and aims at solving the problems that the number of Internet of Things nodes is large, deployment is scattered, storage and computing resources are limited, and controllable dynamic collaboration is poor. According to the invention, the nodes are divided into the limited nodes, the common nodes and the switching nodes, and a pyramid-shaped network topology structure is constructed, so that the safe access, dynamic management and data hierarchical management of the nodes are realized; wherein the limited node is responsible for data acquisition and indirect interaction, the common node operates a block chain lightweight client and forms a bottom layer cluster, and the exchange node operates a complete block chain node and serves as a cluster head to manage a second layer cluster. According to the invention, the data security and the network reliability are ensured through identity access control and node security management measures. According to the invention, the expandability, efficiency and security of the Internet of Things system can be improved, and the security access and dynamic management and control of large-scale Internet of Things nodes are supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of the integration of Internet of Things and blockchain technologies, and particularly relates to an efficient, secure and scalable Internet of Things node management network and a method for constructing the same. Background Art

[0002] In today's digital age, the Internet of Things (IoT) technology is developing at an unprecedented speed. IoT nodes, as the basic building blocks of the IoT, are responsible for collecting, processing and transmitting data, and their number is rapidly increasing to the billions level. However, with the rapid increase in the number of IoT nodes and their wide and scattered deployment, existing IoT technologies are facing a series of challenges that limit the scalability, efficiency and security of IoT systems.

[0003] The following are several challenges faced by existing IoT technologies:

[0004] (1) Large number of IoT nodes and scattered deployment: IoT nodes are distributed in every corner, from urban infrastructure to environmental monitoring stations in remote areas. This extensive geographical distribution has led to difficulties in management and maintenance;

[0005] (2) Limited storage and computing resources: IoT nodes usually have limited storage and computing capabilities, which restricts their ability to process complex algorithms and large-scale data sets;

[0006] (3) Poor controllable dynamic coordination: IoT nodes need to work together to complete complex tasks, such as environmental monitoring, intelligent traffic management and industrial automation. However, due to the autonomy and dynamics of the nodes, it is difficult to achieve effective coordinated control;

[0007] (4) Data security and privacy protection: As more and more sensitive data is collected and transmitted through IoT nodes, data security and privacy protection have become important issues. Nodes may become targets of attackers, resulting in data leakage or tampering.

[0008] Currently, there are still a large number of defects in the existing solutions. For the problems of a large number of nodes and wide distribution, the existing solutions lack unified management. The management systems for nodes in different regions or types are different, resulting in low overall coordination and resource allocation efficiency, and lagging maintenance of nodes in remote areas. Regarding the problem of limited storage and computing resources, most existing solutions optimize within limited resources, such as using lightweight algorithms, but they cannot meet the growing demand for complex data processing, and the limitations are more obvious as the application scenarios expand. For the problem of poor coordination, the existing collaborative control solutions are based on preset rules, which are easily broken by the autonomy and dynamic changes of nodes, and lack an adaptive adjustment mechanism when nodes are abnormal, making it impossible to quickly reconstruct the collaborative relationship. In terms of data security and privacy protection, the existing solutions focus on encryption technologies, but they cannot completely solve the problems. For example, new attack methods may render encryption ineffective, and the access control mechanisms during data transmission and storage are imperfect, posing a risk of data leakage by insiders.

[0009] In summary, currently, the research on Internet of Things technology mainly focuses on how to overcome these challenges and defects to achieve a more efficient, secure, and reliable Internet of Things system. This requires not only technological innovation but also interdisciplinary cooperation and policy support to promote the sustainable development of Internet of Things technology. Summary of the Invention

[0010] In view of the problems existing in the existing Internet of Things technology, such as a large number of Internet of Things nodes and scattered deployment, limited storage / computing resources, and poor controllable dynamic coordination, the present invention proposes an efficient, secure, and scalable Internet of Things node management network and its construction method. The present invention breaks through key technologies such as secure node access, node dynamic management, and data hierarchical management, and supports the secure access and dynamic control of a large number of Internet of Things nodes.

[0011] The technical solutions adopted by the present invention to solve the technical problems are as follows:

[0012] A construction method of an efficient, secure, and scalable Internet of Things node management network provided by the present invention includes the following steps:

[0013] Step 1: Node classification and evaluation;

[0014] Evaluate the computing capabilities of all nodes in the Internet of Things network. According to the differences in node computing capabilities, all nodes are divided into restricted nodes, ordinary nodes, and switching nodes; the restricted nodes have data collection and communication functions and cannot independently run blockchain-related codes; the ordinary nodes can independently run blockchain-related codes and can form a bottommost cluster with the restricted node group; the switching nodes can independently run blockchain-related codes and can perform on-chain data analysis and business processing.

[0015] Step 2: Node registration and identity authentication;

[0016] All nodes register before joining the network to obtain a unique identity; the authoritative agency distributes a pair of public and private keys to each node; each node maintains an access control list that details the node identities and permission levels allowed or denied access.

[0017] Step 3: Formation of the underlying clusters;

[0018] The underlying clusters consist of ordinary nodes and restricted nodes; the ordinary nodes become cluster heads through an election mechanism and are responsible for coordinating the operation of all restricted nodes within the cluster; the restricted nodes need to register with the ordinary nodes when joining the underlying cluster and perform identity authentication and security key exchange.

[0019] Step 4: Organization of the second-layer clusters;

[0020] Above the underlying clusters, the switching nodes form the second-layer clusters as cluster heads, responsible for managing and coordinating the operation of the underlying clusters; the switching nodes within the second-layer clusters perform data exchange and information synchronization through communication protocols; the switching nodes are responsible for monitoring and managing the security status of the nodes within the cluster and detecting and responding to security threats in a timely manner through real-time monitoring and anomaly detection mechanisms.

[0021] Step 5: Construction of the pyramid-shaped network topology;

[0022] The pyramid-shaped network consists of multiple levels of clusters, including the underlying clusters and the second-layer clusters. Data flows from the nodes in the underlying clusters to the nodes in the second-layer clusters, and each layer processes and analyzes the data to optimize the data flow.

[0023] Step 6: Identity access control and node security management;

[0024] Identity authentication for node interaction is achieved through node registration, key distribution, and identity authentication steps; node security management is achieved through access control, data encryption, node monitoring, and anomaly detection steps.

[0025] Step 7: Testing and optimization;

[0026] Before actual deployment, system testing and performance monitoring are carried out, and based on the test results and performance monitoring data, the pyramid-shaped network topology structure and node security management strategies are optimized and adjusted, thereby constructing an efficient, secure, and scalable IoT node management network.

[0027] Furthermore, the energy consumption calculation formula for the restricted node is: E = k1×t + k2×f(d), where E represents the energy consumption of the restricted node, t represents the running time, k1 represents the coefficient related to the basic running energy consumption, d represents the function related to the data acquisition volume, and k2 represents the coefficient of the function related to the data acquisition volume;

[0028] The data transmission volume formula for the restricted node is: Dtx = v × t × r, where D tx represents the data transmission volume of the restricted node, v represents the data generation rate, t represents the running time, and r represents the transmission efficiency.

[0029] Furthermore, the storage utilization rate formula of the ordinary node is: where U s represents the storage utilization rate, S u represents the used storage volume, S u represents the total storage capacity;

[0030] The transaction verification efficiency formula of the ordinary node is: where V e represents the transaction verification efficiency, N v represents the number of transactions verified within time t v .

[0031] Furthermore, the data processing load formula of the switching node is: where L d represents the data processing load, d i represents the data volume of different types, w i represents the corresponding data processing weight coefficient, and n represents the number of data types;

[0032] The cluster management complexity formula of the switching node is: C = m × log(n), where C represents the cluster management complexity, m represents the change frequency of nodes within the cluster, and n represents the number of nodes within the cluster.

[0033] Furthermore, in step three, the cluster head is responsible for assigning tasks to the restricted nodes within the cluster and coordinating the execution of tasks to achieve efficient utilization of resources within the cluster and a quick response to tasks.

[0034] Furthermore, in step three, the data interaction between the nodes within the underlying cluster will follow a preset communication protocol to support efficient transmission and processing of data and ensure the integrity and privacy of data.

[0035] Furthermore, in step six, the identity authentication strength formula is: I a = α × N t + β × E s + γ × T a where I a represents the identity authentication strength, N t represents the number of authentication technologies adopted, E s represents the encryption algorithm strength, α, β, and γ all represent weight coefficients, and T a represents the authentication time;

[0036] The effectiveness formula of the identity access control is: Among them, A e represents the access control effectiveness, and N a represents the number of illegal accesses successfully blocked, and N i represents the total number of illegal access attempts.

[0037] Furthermore, in step six, a cryptographic hash function, digital signature, and hardware security module are used for identity authentication.

[0038] Furthermore, in step six, the specific implementation process of the node security management is as follows:

[0039] (1) Access control;

[0040] By subdividing the node access permissions and regularly updating the access control list to adapt to the changes in the node status, it is ensured that only authorized nodes can access network resources;

[0041] (2) Data encryption;

[0042] Symmetric encryption and asymmetric encryption methods are used for data encryption to balance security and computing efficiency;

[0043] (3) Node monitoring;

[0044] The switching node monitors network activities in real time, including abnormal traffic detection, suspicious behavior alarm, recording, and analysis of security events;

[0045] (4) Anomaly detection;

[0046] Machine learning algorithms are deployed for abnormal behavior detection, and an alarm is issued when abnormal behavior is detected; at the same time, all nodes in the Internet of Things network need to receive security updates and patches regularly;

[0047] (5) Security audit;

[0048] Regular security audits are conducted to evaluate the security status of the network and identify potential security vulnerabilities.

[0049] An efficient, secure, and scalable Internet of Things (IoT) node management network provided by the present invention includes: a pyramid-shaped network, which consists of clusters at multiple levels, including a bottom layer cluster and a second layer cluster; the bottom layer cluster is composed of ordinary nodes and restricted nodes; the ordinary nodes become cluster heads through an election mechanism and are responsible for coordinating the operations of all restricted nodes within the cluster; when joining the bottom layer cluster, the restricted nodes need to register with the ordinary nodes and perform identity authentication and secure key exchange; the second layer cluster is composed of switching nodes, and the switching nodes, as cluster heads, are responsible for managing and coordinating the operations of the bottom layer clusters; the switching nodes exchange data and synchronize information through a communication protocol; the switching nodes are responsible for monitoring and managing the security status of the nodes within the cluster, and promptly detect and respond to security threats through real-time monitoring and anomaly detection mechanisms.

[0050] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0051] (1) In terms of resource utilization and management: Through the node classification strategy of the present invention, nodes with different computing capabilities perform their respective duties. Restricted nodes focus on data collection, ordinary nodes handle basic blockchain transactions, and switching nodes perform advanced operations, avoiding resource waste. At the same time, the pyramid-shaped network topology and cluster structure optimize the data flow direction, reducing unnecessary consumption of computing and storage resources, thereby improving the overall resource utilization rate and enabling limited resources to serve the IoT system more efficiently.

[0052] (2) In terms of network performance and coordination: The present invention improves the scalability of the IoT system. The level of clusters can be expanded according to business scenarios, and new nodes can easily join the appropriate clusters, thus adapting to application scenarios of different scales and complexities. Moreover, through the hierarchical management structure from the bottom layer to the top layer and the clear and definite division of node functions, the coordination among nodes is greatly enhanced, making the collaborative work of nodes more orderly and efficient, and effectively solving the problem of poor coordination in the prior art.

[0053] (3) In terms of security guarantee: The identity access control and security management measures adopted by the present invention are comprehensive and refined, covering links from node registration, key distribution, identity authentication to access control, data encryption, node monitoring, and anomaly detection, protecting network security in all aspects, greatly reducing the risk of data leakage and tampering, and making up for the deficiencies in security in the prior art; at the same time, different authentication methods are set for nodes with different computing capabilities, which not only ensures security but also takes into account performance, and effectively balances the relationship between security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 It is an architecture diagram of an efficient, secure, and scalable IoT node management network of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The present invention will be further described in detail below with reference to the accompanying drawings.

[0056] As Figure 1 shown, since the performance of each node in the Internet of Things varies, and the blockchain requires a certain amount of computing resources from the nodes, the deployment and implementation of the blockchain on nodes with weak computing power will be greatly restricted. Therefore, based on the computing power differences of each node, the nodes are initially divided into restricted nodes, ordinary nodes, and exchange nodes. Restricted nodes do not have the ability to run blockchain-related code independently and rely on ordinary nodes to interact indirectly with the blockchain. Ordinary nodes have the ability to run blockchain-related code. It forms a bottommost cluster with a group of restricted nodes, forming a most basic interaction unit of the blockchain. The exchange node is a node with relatively strong computing power. While it can run blockchain code, it can also perform operations such as analysis of on-chain data and business processing. As the cluster head, it forms a second-layer cluster with several bottommost clusters. According to different business scenarios, the level of the cluster can also be extended to form a pyramid-shaped Internet of Things node network. At the same time, identity access control operations need to be carried out on the interaction of each node to ensure node security management while realizing the cluster management of nodes.

[0057] A method for constructing an efficient, secure, and scalable Internet of Things node management network provided by the present invention has the following specific implementation process:

[0058] Step 1: Node classification and evaluation;

[0059] First, it is necessary to evaluate the computing power of all nodes in the Internet of Things network, mainly including processing power, storage capacity, and network connectivity, etc. After the evaluation, according to the performance indicators of each node, they are classified into restricted nodes, ordinary nodes, and exchange nodes.

[0060] Among them, restricted nodes usually have basic data collection and communication functions, but lack the ability to run blockchain-related code; ordinary nodes have the ability to run blockchain-related code and can form a bottommost cluster with a group of restricted nodes; while the exchange node, as a node with relatively strong computing power, can not only run blockchain-related code but also perform analysis of on-chain data and business processing.

[0061] The specific implementation process of the node classification strategy is as follows:

[0062] (1) Definition and functions of restricted nodes;

[0063] Restricted nodes refer to nodes with weak computing power in the Internet of Things network that cannot independently run blockchain-related code. Such nodes usually have basic data collection and communication functions but lack sufficient computing resources to execute complex encryption operations and consensus mechanisms.

[0064] The main functions of restricted nodes include data collection, that is, being responsible for collecting data from the surrounding environment or performing some simple preprocessing tasks. Since the computing power of these nodes is relatively weak, they cannot directly interact with the blockchain network. Therefore, they need to indirectly upload the collected data and receive instructions from the blockchain network through communication with ordinary nodes. During the communication with ordinary nodes, restricted nodes will authenticate through an access control list (ACL), which is an important step to ensure the security of data transmission. In addition, in order to adapt to the limited computing power of restricted nodes, they usually adopt a low-power design, which helps to extend the service life of the device and reduce maintenance costs, thereby optimizing energy consumption while maintaining network performance.

[0065] The energy consumption calculation formula for restricted nodes is: E = k1×t + k2×f(d), where E represents the energy consumption of restricted nodes, t represents the running time, k1 represents the coefficient related to the basic running energy consumption, d represents the function related to the data collection volume, and k2 represents the coefficient of the function related to the data collection volume.

[0066] The data transmission volume formula for restricted nodes is: D tx = v×t×r, where D tx represents the data transmission volume of restricted nodes, v represents the data generation rate, t represents the running time, and r represents the transmission efficiency.

[0067] (2) Definition and functions of ordinary nodes;

[0068] Ordinary nodes are nodes in the Internet of Things network that have the ability to run blockchain-related code. They usually have relatively high computing power and a certain amount of storage capacity, and can perform lightweight operations of the blockchain, such as transaction verification and data storage.

[0069] Ordinary nodes have sufficient computing power to run a lightweight client of the blockchain and participate in the process of transaction verification and data storage. In addition, ordinary nodes are also responsible for combining with groups of restricted nodes to form the bottommost cluster, which is the basic interaction unit in the blockchain network. In terms of data transmission, ordinary nodes act as data relay stations, passing the data collected by restricted nodes to the blockchain network and transmitting instructions from the blockchain network to restricted nodes. In some lightweight blockchain networks, ordinary nodes may also participate in the consensus mechanism to help maintain the stability and security of the entire blockchain network. Through these functions, ordinary nodes not only support the basic operations of the blockchain network but also contribute to the efficient operation and security guarantee of the blockchain network.

[0070] The storage utilization rate formula for ordinary nodes is: where U s represents the storage utilization rate, S u represents the used storage amount, Su Represents the total storage capacity.

[0071] The formula for the transaction verification efficiency of ordinary nodes is: Where V e Represents the transaction verification efficiency, and N v Represents the number of transactions verified within time t v within.

[0072] (3) Definition and functions of switching nodes;

[0073] Switching nodes are nodes with relatively strong computing power in the Internet of Things network. They can not only run blockchain-related codes but also perform analysis and business processing of on-chain data.

[0074] Switching nodes can not only run complete blockchain nodes, participate in the verification of all transactions and the storage of data, but also act as cluster heads, forming a second-layer cluster with multiple bottom-layer clusters, responsible for coordinating and managing the interactions of nodes within the cluster. Switching nodes also have powerful data analysis capabilities, can perform real-time analysis of on-chain data, and provide intelligent decision-making support for Internet of Things applications. In addition, switching nodes can execute complex business logics, including the execution of smart contracts and the processing of automated tasks. In terms of security management, switching nodes are responsible for the security management of nodes within the cluster, including identity authentication, access control, and anomaly detection, etc., to ensure the security of the network. To adapt to the requirements of different business scenarios, switching nodes can also expand the level of the cluster to form a pyramid-shaped Internet of Things node network, supporting larger-scale Internet of Things applications, thereby enhancing the scalability and flexibility of the network.

[0075] The formula for the data processing load of switching nodes is: Where L d Represents the data processing load, d i Represents different types of data volumes, w i Represents the corresponding data processing weight coefficient, and n represents the number of data types.

[0076] The formula for the cluster management complexity of switching nodes is: C = m × log(n), where C represents the cluster management complexity, m represents the change frequency of nodes within the cluster, and n represents the number of nodes within the cluster.

[0077] Step 2: Node registration and identity authentication;

[0078] Next, all nodes need to be registered before joining the network to obtain a unique identity identifier (DID). Subsequently, an authoritative institution (such as a switching node) will distribute a pair of public and private keys to each node for subsequent identity authentication. In addition, each node also needs to maintain an access control list (ACL) to record in detail the node identifiers and corresponding permission levels that are allowed or denied access, to ensure the security of node interactions.

[0079] Step 3: Formation of the underlying clusters;

[0080] During the formation stage of the underlying clusters, ordinary nodes become cluster heads through an election mechanism and are responsible for coordinating the operations of all restricted nodes within the cluster. Restricted nodes need to register with ordinary nodes when joining the underlying clusters, and perform authentication and secure key exchange. Meanwhile, data interaction among nodes within the underlying clusters will follow a preset communication protocol to support efficient data transmission and processing while ensuring data integrity and privacy.

[0081] The formation mechanism of the underlying clusters is as follows:

[0082] In the Internet of Things, the formation of the underlying clusters is crucial for achieving efficient network management and secure operation. These underlying clusters are composed of ordinary nodes and restricted nodes, where ordinary nodes act as cluster heads and are responsible for coordinating all activities of restricted nodes within the cluster. The election mechanism of the cluster heads comprehensively considers factors such as the computing power, energy status, and network connectivity of nodes to ensure optimal resource allocation and effective task coordination. When joining the cluster, restricted nodes must register with ordinary nodes, which includes authentication and secure key exchange to ensure the legitimacy and security of cluster members. Data interaction among nodes within the cluster follows a preset protocol, aiming to support efficient data transmission and processing while guaranteeing data integrity and privacy. The cluster head is also responsible for assigning tasks to restricted nodes within the cluster and coordinating the execution of tasks, thereby achieving efficient utilization of resources within the cluster and a rapid response to tasks. These mechanisms jointly ensure the effective operation of the underlying clusters and lay the foundation for the stability and security of the Internet of Things network.

[0083] Step 4: Organization of the second-layer clusters;

[0084] Above the underlying clusters, switching nodes act as cluster heads to form the second-layer clusters, which are responsible for managing and coordinating the operations of the underlying clusters. Switching nodes possess more advanced data and service processing capabilities in addition to the functions of ordinary nodes. Data exchange and information synchronization among switching nodes within the second-layer clusters are carried out through an efficient communication protocol, ensuring the coordination of cross-cluster tasks and the consistency of the global state. Meanwhile, switching nodes are responsible for monitoring and managing the security status of nodes within the cluster, and through real-time monitoring and anomaly detection mechanisms, promptly detect and respond to security threats.

[0085] Above the underlying clusters of the Internet of Things, the switching nodes assume the role of cluster heads, forming a second - layer cluster responsible for managing and coordinating the operation of the underlying clusters. This organizational structure not only improves the scalability and flexibility of the network but also expands the functions of the switching nodes. In addition to having the functions of ordinary nodes, the switching nodes can perform more advanced data processing and service processing, including executing complex data analysis and smart contracts. In the second - layer cluster, the switching nodes exchange data and synchronize information through an efficient communication protocol, ensuring the coordination of cross - cluster tasks and maintaining the consistency of the global state. Moreover, the switching nodes are responsible for monitoring and managing the security status of the nodes within the cluster, using real - time monitoring and anomaly detection mechanisms to detect and respond to security threats in a timely manner. The switching nodes can also handle more complex business logics, such as automated task scheduling and smart contract execution, thus providing richer functional support for Internet of Things applications. These capabilities make the switching nodes a key component in the Internet of Things network, providing a solid foundation for the efficient operation and security management of the network.

[0086] Step Five: Construction of the pyramid - shaped network topology;

[0087] The entire Internet of Things network forms a pyramid - shaped network topology through a multi - level cluster structure. This network topology structure not only improves the network management efficiency but also enhances the network security and scalability. The pyramid - shaped network consists of multiple levels of clusters (underlying clusters and second - layer clusters). From the bottom layer, i.e., the restricted nodes and ordinary nodes in the underlying clusters, to the top layer, i.e., the switching nodes in the second - layer clusters, each layer undertakes different responsibilities and functions. Data flows from the nodes in the bottom layer to the nodes in the top layer, and each layer processes and analyzes the data, optimizing the data flow direction and reducing network congestion and latency.

[0088] In addition, each layer of the pyramid - shaped network implements strict security policies, including authentication, access control, and data encryption, etc., ensuring the overall security of the network. The scalability of the network is also guaranteed. New nodes can be easily added to the appropriate clusters without affecting the overall stability and performance of the network. More importantly, the pyramid - shaped network can flexibly adjust the cluster levels and structures according to different business scenario requirements to adapt to diverse application requirements and environmental changes, thus achieving a high degree of adaptability and flexibility.

[0089] Step Six: Identity access control and node security management;

[0090] In the network combining the Internet of Things (IoT) and blockchain, identity authentication between nodes is crucial for ensuring data security and network reliability. The identity authentication mechanism for node - to - node interaction needs to establish an effective verification process among constrained nodes, ordinary nodes, and switching nodes to prevent unauthorized access and data tampering. Meanwhile, to ensure the security of nodes in the IoT network, a series of security management measures need to be taken, including but not limited to access control, data encryption, node monitoring, and anomaly detection.

[0091] The specific implementation process is as follows:

[0092] (1) The identity authentication mechanism for node - to - node interaction;

[0093] In the network combining the IoT and blockchain, ensuring identity authentication between nodes is the core of guaranteeing data security and network reliability. The identity authentication process mainly includes three main steps: node registration, key distribution, and identity verification. Nodes register through a decentralized identity system to obtain a unique identity identifier, and then a pair of public - private keys is distributed by an authoritative institution such as a switching node for subsequent identity verification. The interaction between nodes uses digital signatures and identity verification mechanisms to ensure the security of data transmission. To enhance security, each node maintains an access control list (ACL) that records the node identifiers and permission levels allowed or denied to control resource access permissions. In identity authentication, various technologies can be adopted, such as cryptographic hash functions, digital signatures, and hardware security modules, which can improve the security and efficiency of authentication. At the same time, considering the differences in the computing capabilities of IoT nodes, the identity authentication mechanism minimizes the consumption of computing resources while ensuring security. For example, constrained nodes can use lightweight authentication protocols, while switching nodes with stronger computing capabilities undertake more complex identity authentication tasks to achieve a balance between performance and security.

[0094] The identity authentication strength formula is: I a =α×N t +β×E s +γ×T a where I a represents the identity authentication strength, N t represents the number of authentication technologies adopted, E s represents the strength of the encryption algorithm, α, β, γ are all weight coefficients, and T a represents the authentication time.

[0095] The formula for the effectiveness of identity access control is: where A e represents the effectiveness of access control, N a represents the number of illegal access attempts successfully blocked, and N i represents the total number of illegal access attempts.

[0096] (2) Node security management measures;

[0097] To ensure the security of nodes in the Internet of Things network, a series of comprehensive security management measures must be implemented. These measures include access control, data encryption, node monitoring, and anomaly detection. First, by implementing strict access control policies, ensure that only authorized nodes can access network resources. This involves the subdivision of node access permissions and the regular update of the access control list (ACL) to adapt to changes in node status. Second, data encryption is the key to protecting data transmitted between nodes from being intercepted or tampered with. Usually, a combination of symmetric encryption and asymmetric encryption methods is used to balance security and computational efficiency. In addition, nodes in the network, especially switching nodes, need to monitor network activities in real time to detect and respond to potential security threats in a timely manner. This includes anomaly traffic detection, suspicious behavior alarms, and the recording and analysis of security events. To improve security, machine learning algorithms can also be deployed for anomaly behavior detection. These algorithms can issue alarms when detecting abnormal behaviors by learning normal behavior patterns. At the same time, to cope with emerging security threats, all nodes in the Internet of Things network need to receive security updates and patches regularly. This requires the network to have an effective software distribution mechanism to ensure that nodes can be updated to the latest security version in a timely manner. Finally, regular security audits help evaluate the security status of the network and identify potential security vulnerabilities. These audits can be carried out by an internal team or third-party security experts to ensure the objectivity and comprehensiveness of the audits. By implementing these security management measures, the security of the Internet of Things network can be significantly improved, and the nodes in the network can be effectively protected from the risks of malicious attacks and data leakage.

[0098] Step Seven: Testing and Optimization;

[0099] Before actual deployment, conduct system testing to ensure the normal functioning of all nodes and clusters, and at the same time monitor system performance to ensure efficient and expected interactions between nodes. According to the test results and performance monitoring data, optimize and adjust the pyramid-shaped network topology structure and node security management strategy to adapt to different application requirements and environmental changes. Through these steps, an efficient, secure, and scalable Internet of Things node management network can be constructed.

[0100] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for constructing an efficient, secure, and scalable Internet of Things node management network, characterized in that, It includes the following steps: Step 1: Node classification and evaluation; Evaluate the computing capabilities of all nodes in the IoT network. According to the differences in node computing capabilities, all nodes are divided into restricted nodes, ordinary nodes, and switching nodes. The restricted nodes have data collection and communication functions and cannot independently run blockchain-related code. The ordinary nodes can independently run blockchain-related code and can form a bottom-layer cluster with the restricted node group. The switching nodes can independently run blockchain-related code and can perform analysis and business processing of on-chain data. Step 2: Node registration and identity authentication; All nodes are registered before joining the network to obtain a unique identity identifier. The authoritative agency distributes a pair of public and private keys to each node. Each node maintains an access control list that details the node identifiers and permission levels allowed or denied access. Step 3: Formation of the bottom-layer cluster; The bottom-layer cluster consists of ordinary nodes and restricted nodes. The ordinary nodes become the cluster heads through an election mechanism and are responsible for coordinating the operations of all restricted nodes within the cluster. The restricted nodes need to register with the ordinary nodes when joining the bottom-layer cluster and perform identity verification and security key exchange. Step 4: Organization of the second-layer cluster; Above the bottom-layer cluster, the switching nodes form the second-layer cluster as the cluster heads and are responsible for managing and coordinating the operations of the bottom-layer cluster. The switching nodes within the second-layer cluster exchange data and synchronize information through a communication protocol. The switching nodes are responsible for monitoring and managing the security status of the nodes within the cluster and promptly detecting and responding to security threats through real-time monitoring and anomaly detection mechanisms. Step 5: Construction of the pyramid-shaped network topology; The pyramid-shaped network consists of multiple levels of clusters, including the bottom-layer cluster and the second-layer cluster. Data flows from the nodes in the bottom-layer cluster to the nodes in the second-layer cluster, and each layer processes and analyzes the data to optimize the data flow direction. Step 6: Identity access control and node security management; Implement identity authentication for node-to-node interactions through node registration, key distribution, and identity verification steps. Implement node security management through access control, data encryption, node monitoring, and anomaly detection steps. Step 7: Testing and optimization; Conduct system testing and performance monitoring before actual deployment. According to the test results and performance monitoring data, optimize and adjust the pyramid-shaped network topology structure and node security management strategy to build an efficient, secure, and scalable IoT node management network.

2. The method for constructing an efficient, secure and scalable Internet of Things node management network according to claim 1, characterized in that The energy consumption calculation formula for the restricted nodes is: E = k1×t + k2×f(d), where E represents the energy consumption of the restricted nodes, t represents the running time, k1 represents the coefficient related to the basic running energy consumption, d represents the function related to the data collection volume, and k2 represents the coefficient of the function related to the data collection volume. The data transmission volume formula of the restricted node is: D tx = v × t × r, where D tx represents the data transmission volume of the restricted node, v represents the data generation rate, t represents the running time, and r represents the transmission efficiency.

3. The method for constructing an efficient, secure and scalable Internet of Things node management network according to claim 1, characterized in that, The storage utilization formula for the ordinary node is as follows: where U s represents the storage utilization, S u represents the used storage amount, and S u represents the total storage capacity; The transaction verification efficiency formula for the ordinary node is as follows: where V e represents the transaction verification efficiency, and N v represents the number of transactions verified within time t v .

4. The method for constructing an efficient, secure and scalable Internet of Things node management network according to claim 1, wherein The point data processing load formula of the switching section is as follows: Where L d represents the data processing load, d i represents the amount of different types of data, w i represents the corresponding data processing weight coefficient, and n represents the number of data types; The cluster management complexity formula for the switching nodes is: C = m×log(n), where C represents the cluster management complexity, m represents the frequency of node changes within the cluster, and n represents the number of nodes within the cluster.

5. The method for constructing an efficient, secure and scalable Internet of Things node management network according to claim 1, characterized in that In Step 3, the cluster head is responsible for allocating tasks to the restricted nodes within the cluster and coordinating the execution of tasks to achieve efficient utilization of cluster resources and rapid response to tasks.

6. The method for constructing an efficient, secure, and scalable Internet of Things node management network according to claim 1, characterized in that In step 3, the data interaction among the nodes within the bottom layer clusters will follow a preset communication protocol, supporting efficient data transmission and processing, and ensuring data integrity and privacy.

7. The method for constructing an efficient, secure and scalable Internet of Things node management network according to claim 1, characterized in that In step six, the strength formula for the identity authentication is: I a = α × N t + β × E s + γ × T a , where I a represents the identity authentication strength, N t represents the number of authentication technologies adopted, E s represents the encryption algorithm strength, α, β, and γ all represent weight coefficients, and T a represents the authentication time; The validity formula for the identity access control is as follows: where A e represents the access control effectiveness, N a represents the number of illegal accesses successfully blocked, N i represents the total number of illegal access attempts.

8. The method for constructing an efficient, secure and scalable Internet of Things node management network according to claim 1, characterized in that, In step 6, a cryptographic hash function, digital signature, and hardware security module are used for identity authentication.

9. The method for constructing an efficient, secure, and scalable Internet of Things node management network according to claim 1, characterized in that, In step 6, the specific implementation process of the node security management is as follows: (1) Access control; By subdividing the node access permissions and regularly updating the access control list to adapt to the changes in the node status, ensuring that only authorized nodes can access network resources; (2) Data encryption; Symmetric encryption and asymmetric encryption methods are used for data encryption to balance security and computational efficiency; (3) Node monitoring; The switching nodes monitor network activities in real time, including abnormal traffic detection, suspicious behavior alarm, recording, and analysis of security events; (4) Anomaly detection; Machine learning algorithms are deployed for abnormal behavior detection, and an alarm is issued when an abnormal behavior is detected; at the same time, all nodes in the Internet of Things network need to receive security updates and patches regularly; (5) Security audit; A security audit is conducted regularly to evaluate the security status of the network and identify potential security vulnerabilities.

10. The efficient, secure and scalable Internet of Things node management network constructed by the construction method of the efficient, secure and scalable Internet of Things node management network according to any one of claims 1-9, characterized in that, It includes: A pyramid-shaped network, which is composed of multiple layers of clusters, including bottom layer clusters and second layer clusters; the bottom layer clusters are composed of ordinary nodes and restricted nodes; the ordinary nodes become cluster heads through an election mechanism and are responsible for coordinating the operations of all restricted nodes within the cluster; the restricted nodes need to register with the ordinary nodes when joining the bottom layer cluster, and conduct identity authentication and security key exchange; the second layer clusters are composed of switching nodes, and the switching nodes, as cluster heads, are responsible for managing and coordinating the operations of the bottom layer clusters; the switching nodes exchange data and synchronize information through a communication protocol; the switching nodes are responsible for monitoring and managing the security status of the nodes within the cluster, and timely discovering and responding to security threats through real-time monitoring and anomaly detection mechanisms.