Internet of Things encryption method and system combined with distributed trust mechanism

By introducing PUF authentication and trust-enhanced consensus mechanisms into the Internet of Things system, the difficulty in establishing a trust root in the cold start stage is solved, the security expansion of the trust chain and dynamic key management are realized, and the system's anti-attack capability and stability are improved.

CN120342632AActive Publication Date: 2025-07-18刘慧
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510574362.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-07-18
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

In the cold startup stage, IoT systems have difficulty in establishing trust roots, and are prone to forged node injection and trust chain failure, resulting in impairment of security and stability.

Method used

Introducing a trust initial node authentication mechanism based on physical non-cloneability (PUF), combining the trust-enhanced consensus mechanism and a trust-value-driven key dynamic distribution and update mechanism, we ensure the authenticity and security of the trust chain through physical layer security authentication, two-way identity confirmation and dynamic trust evaluation.

Benefits of technology

It significantly improves the attack resistance of the Internet of Things system during cold startup and operation, ensures the secure expansion and stability of the trust chain, prevents fake nodes and key hijacking, and improves the security, stability and traceability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342632A_ABST
    Figure CN120342632A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Things encryption method and system combined with a distributed trust mechanism, and relates to the technical field of information security, and the method comprises the following steps: building a trust initial node set, carrying out the physical layer security authentication of a core node of the Internet of Things through employing the physical unclonable characteristic, generating a unique node identity key, and carrying out the encryption of the trust initial node set; and a trusted node is registered in the distributed account book. According to the invention, by introducing a trust initial node authentication mechanism based on the PUF, the authenticity and unforgeability of the trust root in the cold start stage of the Internet of Things are ensured; a trust enhancement consensus mechanism is designed, dynamic trust evaluation and consensus confirmation of new access equipment are realized, and secure extension of a trust chain is guaranteed; a trust value-driven key dynamic distribution and updating mechanism is provided, the key permission and life cycle are flexibly controlled according to the trust value, low-trust node hiding or attacking is prevented, and the attack resistance, safety and stability of the system in the cold start and operation process are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to an Internet of Things encryption method and system combining a distributed trust mechanism. Background Art

[0002] The Internet of Things encryption combining a distributed trust mechanism refers to, in an Internet of Things (IoT) system, using decentralized, immutable, and traceable distributed trust technologies (such as blockchain, distributed ledger, consensus mechanism, etc.) to perform secure encryption and trusted management on the data transmission, storage, and identity authentication processes between IoT devices; through the distributed trust mechanism, the single-point trust problem can be avoided, and the trust vulnerability and security risks brought by the centralized trust model in the traditional Internet of Things can be solved; at the same time, in cooperation with encryption algorithms (such as symmetric encryption, asymmetric encryption, hash encryption, etc.), the confidentiality, integrity, and authenticity of the communication data between IoT terminal devices are guaranteed, ensuring that the Internet of Things system can still achieve secure and reliable end-to-end data transmission and node trust establishment in an open environment; in short, it is to use distributed technology to provide decentralized trust guarantee for the encrypted communication and identity authentication of the Internet of Things;

[0003] The existing technologies have the following deficiencies: in the existing Internet of Things encryption process combining a distributed trust mechanism, there is generally a cold start dilemma problem of the trust root; that is, when the Internet of Things system is initially deployed or a new device is connected, the device needs to establish initial trust and distribute keys through the distributed trust mechanism; however, when the system has not yet formed a large enough network of trusted nodes, if security threats such as forged node injection, replay of historical block information, or hijacking of key distribution occur during the construction of the initial trust chain, it may directly lead to the invalidation or tampering of the trust chain; even if a perfect consensus mechanism and encryption method are adopted during the subsequent system operation, it is difficult to make up for the security risks brought by the initial trust failure; once an attacker successfully forges a trusted device or lurks for a long time by this means, data can be continuously stolen and the device can be manipulated, seriously threatening the security and stability of the Internet of Things system;

[0004] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure, and thus it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The object of the present invention is to provide an Internet of Things encryption method and system combined with a distributed trust mechanism. By introducing a trust initial node authentication mechanism based on PUF, the authenticity and non-forgeability of the trust root in the cold start phase of the Internet of Things are ensured; a trust enhancement consensus mechanism is designed to achieve dynamic trust evaluation and consensus confirmation of newly connected devices, ensuring the secure extension of the trust chain; a key dynamic distribution and update mechanism driven by trust values is proposed, flexibly controlling key permissions and life cycles according to trust values to prevent low-trust nodes from lurking or attacking, significantly improving the anti-attack ability and security stability of the system during cold start and operation, so as to solve the problems in the above background technology.

[0006] To achieve the above object, the present invention provides the following technical solutions: An Internet of Things encryption method combined with a distributed trust mechanism, comprising the following steps:

[0007] Establish a set of trust initial nodes, perform physical layer security authentication on the core nodes of the Internet of Things using physical unclonable characteristics, generate a unique node identity key, and register it as a trust node in the distributed ledger;

[0008] When a new device accesses the Internet of Things network, complete the identity confirmation and trust relationship establishment of the new device through two-way identity authentication with at least one node in the set of trust initial nodes;

[0009] Based on the trust relationship established between the new device and the trust nodes, distribute the encryption key through a secure channel, and synchronously record the key distribution process and the trust chain establishment process in the distributed ledger;

[0010] Construct a trust enhancement consensus mechanism with trust initial nodes and verified devices as participants, dynamically update the trust value and key validity, and monitor node behavior anomalies in real time;

[0011] Based on the trust chain and consensus results in the distributed ledger, encrypt the communication data between Internet of Things devices to ensure the confidentiality, integrity and non-repudiation of the data during transmission;

[0012] During the operation of the device, continuously use the set of trust initial nodes to perform dynamic trust evaluation and key update on newly connected devices in the distributed trust Internet of Things security system. When it is found that the trust value of a node is lower than a preset threshold, automatically revoke its communication permission and record the abnormal information in the distributed ledger.

[0013] Preferably, the physical unclonable feature authentication process includes verifying operations through multiple rounds of challenge-response pairs. In each authentication process, the trusted initial node sends a predefined physical feature challenge signal to the device to be authenticated. The device to be authenticated responds through its internal unique PUF circuit and generates a unique response code. The trusted initial node compares the response code with the correct response code in the pre-stored original challenge response database. When the responses in multiple rounds all meet the consistency and stability thresholds, the device is confirmed as a trusted node, and the device ID, PUF signature, and authentication result are uploaded to the distributed ledger in the form of a structured transaction, ensuring that the authentication process is real, non-forgeable, and traceable.

[0014] Preferably, during the new device access, the two-way identity authentication process includes the new device and the trusted initial node respectively initiating challenge verification based on asymmetric key encryption. Specifically, the new device signs the random challenge message sent by the trusted node using its own private key, and the trusted initial node verifies the signature result through the public key of the new device. At the same time, the trusted initial node also needs to sign the challenge message of the new device using its own private key, and the new device verifies it in the same way. After both-way verification passes, the two-way confirmation of the device identity is completed, and a block with a timestamp and verification log is generated in the distributed ledger to ensure the transparency and non-deniability of the verification process.

[0015] Preferably, the establishment of the secure channel is based on the elliptic curve key agreement protocol. After the two-way identity authentication is completed, the new device and the trusted node respectively calculate the shared session key using the public key of the other party and their own private key. The obtained session key is only valid for this session, and the encrypted digest and negotiation status of the key negotiation are recorded in the distributed ledger. The negotiation process adopts a time window control mechanism, and if the timeout is not completed, the key negotiation is forcibly interrupted to prevent man-in-the-middle attacks or delayed replay attacks.

[0016] Preferably, the trust-enhanced consensus mechanism is an asynchronous consensus protocol improved based on Byzantine fault tolerance. The trusted initial node and the verified devices jointly participate in the consensus process. In each round of the consensus process, the node trust value is dynamically calculated based on the historical behavior score, data transmission reliability, and key usage frequency of the device. Devices with a node trust value lower than the consensus threshold will be automatically excluded from the consensus participating nodes, and all consensus results and the historical changes of the trust value are stored on the chain to prevent malicious nodes from participating in the consensus process and improve the security and stability of the consensus.

[0017] Preferably, the specific steps for the dynamic update of the trust value and the calculation of the consensus voting weight are as follows:

[0018] To ensure that the IoT nodes can dynamically reflect their trustworthiness during the long-term operation process, a trust evaluation mechanism is established for each node to calculate the trust value. The calculation expression is as follows:

[0019] T iT(t) = α·H(t) + β·C(t) + γ·S(t), where i T(t) is the trust value of node i at time t, which is used to measure the current credibility of the node in the system. The higher the trust value, the better the historical behavior, data quality, and security of the node. H(t) i is the historical behavior score of node i at time t, which reflects the historical behavior performance of the node in the past cycle, such as normal communication situation, task completion rate, abnormal operation rate, etc. C(t) i is the data transmission reliability score of node i within time t, which represents the reliability of the node in data interaction. Considering indicators such as packet loss rate, communication delay, and transmission success rate, it directly reflects the communication link quality and transmission stability. S(t)

[0020] , where T i (t) is the trust value of node i at time t, which is used to measure the current credibility of the node in the system. The higher the trust value, the better the historical behavior, data quality, and security of the node. H i (t) is the historical behavior score of node i at time t, which reflects the historical behavior performance of the node in the past cycle, such as normal communication situation, task completion rate, abnormal operation rate, etc. C i (t) is the data transmission reliability score of node i within time t, which represents the reliability of the node in data interaction. Considering indicators such as packet loss rate, communication delay, and transmission success rate, it directly reflects the communication link quality and transmission stability. S i (t) is the security event sensitivity factor of node i at time t, which quantifies the severity of security events encountered or participated in by the node in the system. For example, whether abnormal data packets are detected, whether communication is rejected, or whether the node has ever been included in the temporary blacklist, etc. α, β, and γ are all trust value weighting coefficients, corresponding to T i (t), C i (t), and S i (t)'s contribution to the comprehensive trust value, and satisfy: α + β + γ = 1;

[0021] In the distributed consensus process, the voting weight of each node is dynamically determined according to its trust value. The calculation expression of the voting weight is as follows:

[0022] ,

[0023] where W i is the voting weight of node i in the distributed consensus process, which reflects the proportion of the node in the consensus voting. The higher the trust value of the node, the greater the voting weight. N is the total number of nodes participating in the current consensus process. T j (t) is the data transmission reliability score of node j within time t;

[0024] When the trust value volatility of the node in k consecutive rounds of consensus process satisfies the following condition: Var(T i ) > θ, that is, the trust value variance is greater than the system - preset security threshold θ, it is determined that the node has abnormal behavior in recent behavior and automatically enters the trust anomaly review mechanism. The relevant node needs to accept additional behavior analysis and multi - dimensional trust correction to ensure the stability and anti - attack ability of the consensus system.

[0025] Preferably, the encryption process adopts a combination of symmetric encryption and immutable blockchain records. During the communication process between devices, first, the shared symmetric key confirmed by the trust-enhanced consensus mechanism is used to encrypt the transmitted data, and the data recipient decrypts it using the shared key. At the same time, both communication parties jointly record the encryption digest, timestamp, and participating device identity information of this data communication on the distributed ledger to ensure the confidentiality, integrity, and traceability of the data during transmission. Moreover, the communication records cannot be tampered with, effectively addressing replay attacks and communication hijacking issues.

[0026] Preferably, the dynamic trust evaluation and key update mechanism include a dynamic adjustment mechanism based on node trust values. The trust initial node periodically evaluates the trust values of all connected nodes in the distributed trust IoT security system, comprehensively considering the device's behavior consistency, data transmission quality, historical security events, and key usage. When the node trust value gradually decreases and is lower than the preset security threshold, it automatically broadcasts trust revocation information to the remaining trusted nodes in the distributed trust IoT security system and generates a revocation block to synchronize to the distributed ledger. At the same time, it revokes the key permissions and communication permissions of the corresponding device to ensure that only highly trusted nodes in the distributed trust IoT security system participate in communication and consensus.

[0027] Preferably, the specific steps of the dynamic key update strategy are as follows:

[0028] Dynamically adjust the update frequency of the node key based on the trust value. The calculation expression for the key update period of each node is as follows:

[0029] ,

[0030] In the formula, U i is the key update period of node i, indicating how often the node needs to update the encryption key. The lower the trust value, the shorter the update period. λ is the preset maximum allowable update period, and T max is the specified theoretical maximum trust value;

[0031] The lower the trust value, the shorter the key update period assigned to the node, forcing nodes with low trust values to update their keys frequently, thereby enhancing the control over abnormal nodes and reducing their potential security threats.

[0032] When the trust value fluctuates, the node resets the key according to the trust change amount and the current timestamp. The session key update formula is as follows:

[0033] ,

[0034] In the formula, is the newly generated session key of node i, which will replace the old key for subsequent communication. HMAC SHA256It is a message authentication code (HMAC) algorithm based on SHA256, providing high-strength encryption intensity and collision resistance, ensuring the security and unpredictability of new keys. is the session key currently used by node i and serves as the basis for key updates, ΔT i is the change in the trust value of node i at the most recent time. ts is the current timestamp, which is used to ensure the uniqueness and timeliness of each update input and prevent replay attacks.

[0035] By jointly incorporating the change in trust value and the timestamp into the key update process, the entropy and unpredictability of the key are significantly enhanced, ensuring the security of the key in a dynamic trust environment.

[0036] If the change in the trust value of the node satisfies the following conditions: ΔT i < -δ, when the change in the trust value ΔT of node i i is less than the negative security threshold -δ, where δ is the trust value decrease threshold, representing the maximum amplitude of the single decrease in the tolerated trust value, and if it has not recovered to the normal range after continuous n rounds of detection, the key revocation process is immediately triggered, directly revoking the session key and all trust credentials of the node. The node is isolated and prohibited from continuing to participate in any IoT communication and consensus processes. At the same time, the current abnormal event is synchronously written into the distributed ledger as a security audit record to form a complete event tracking record, ensuring overall security and traceability. Here, n is the round threshold for continuous detection. Only when the trust value remains below the threshold for more than n rounds will the revocation mechanism be triggered to avoid misjudging normal nodes due to short-term fluctuations.

[0037] Preferably, an IoT encryption system combined with a distributed trust mechanism includes a trust initial node authentication module, a new device trust access module, a key distribution and trust chain establishment module, a trust enhancement consensus and dynamic evaluation module, an encrypted communication and security guarantee module, and a dynamic trust management and key revocation module;

[0038] The trust initial node authentication module establishes a set of trust initial nodes, uses the physical unclonable feature to perform physical layer security authentication on the core nodes of the IoT, generates a unique node identity key, and registers it as a trusted node in the distributed ledger;

[0039] The new device trust access module, when a new device accesses the IoT network, completes the identity confirmation and trust relationship establishment of the new device through two-way authentication with at least one node in the set of trust initial nodes;

[0040] The key distribution and trust chain establishment module, based on the trust relationship established between the new device and the trusted node, distributes the encryption key through a secure channel and synchronously records the key distribution process and the trust chain establishment process in the distributed ledger;

[0041] The trust enhancement consensus and dynamic evaluation module constructs a trust enhancement consensus mechanism with trust initial nodes and verified devices as participants, dynamically updates the trust value and key validity, and monitors node behavior anomalies in real time;

[0042] The encrypted communication and security guarantee module encrypts the communication data between IoT devices based on the trust chain and consensus results in the distributed ledger to ensure the confidentiality, integrity, and non-repudiation of the data during transmission;

[0043] The dynamic trust management and key revocation module continuously conducts dynamic trust evaluation and key update on newly connected devices in the distributed trust IoT security system using the set of trust initial nodes during the device operation. When it is found that the trust value of a node is lower than the preset threshold, its communication permission is automatically revoked and the abnormal information is recorded in the distributed ledger.

[0044] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:

[0045] By introducing a trust initial node authentication mechanism based on the physical unclonable feature (PUF), the present invention effectively solves the problem of difficult establishment of the trust root commonly existing in the cold start stage of the IoT system; by integrating the PUF circuit in the core node and utilizing its natural uniqueness and non-clonability, the authenticity and non-forgery of the trust initial node identity are guaranteed, and the risk of forged nodes sneaking into the system through the initial trust authentication is eliminated; compared with the traditional trust root construction methods based on software certificates or symmetric keys, the present invention can directly establish a trustworthy trust source at the hardware level, providing a secure and reliable basic environment for subsequent IoT device access, trust chain extension, and secure communication, and significantly improving the cold start security of the trust mechanism;

[0046] By designing a trust enhancement consensus mechanism and collaborating based on trust initial nodes and verified nodes, the present invention conducts dynamic trust evaluation and consensus confirmation on new devices in the initial access stage, avoiding the security risks of the traditional IoT system being easily penetrated by forged devices and malicious nodes due to insufficient trust nodes during the cold start process; the proposed trust enhancement consensus mechanism not only considers the authenticity of the device identity, but also introduces multi-dimensional dynamic trust indicators such as device access behavior, communication stability, and consensus participation quality, effectively improving the accuracy and security of the consensus; by combining the dynamic adjustment of the trust value with the consensus voting weight and transparently recording the consensus process in the distributed ledger, it can ensure the orderly and secure extension of the trust chain during the cold start stage, laying a solid foundation for the subsequent large-scale device secure access;

[0047] The trust value-driven key dynamic distribution and update mechanism proposed by the present invention can flexibly control key permissions and validity periods according to the real-time trust value of devices, significantly improving the anti-attack ability of the Internet of Things system during cold start and operation; by directly associating the trust value with the key life cycle, key length, and communication permissions, it can effectively limit the communication capabilities of low-trust or suspicious devices, and automatically revoke their keys when the trust value drops below the security threshold, preventing malicious nodes from lurking for a long time before the trust chain is stable; combined with security update mechanisms such as HMAC-SHA256, it ensures the dynamicity and uniqueness of keys, and at the same time, all key update and revocation events are traceable and verifiable in the distributed ledger, overall enhancing the system's defense ability and security stability against attack behaviors such as forged nodes, key hijacking, and trust pollution. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.

[0049] Figure 1 It is a method flow chart of an Internet of Things encryption method combining a distributed trust mechanism according to the present invention.

[0050] Figure 2 It is a module schematic diagram of an Internet of Things encryption system combining a distributed trust mechanism according to the present invention.

[0051] Figure 3 It is a module mind map of an Internet of Things encryption system combining a distributed trust mechanism according to the present invention.

[0052] Figure 4 It is a method mind map of an Internet of Things encryption method combining a distributed trust mechanism according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] Now, the exemplary embodiments will be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these examples are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art.

[0054] The present invention provides an Internet of Things encryption method combining a distributed trust mechanism as shown in Figures 1-4 and includes the following steps:

[0055] Establish an initial set of trusted nodes, use the Physical Unclonable Function (PUF) to perform physical layer security authentication on the core nodes of the Internet of Things, generate a unique node identity key, and register it as a trusted node in the distributed ledger;

[0056] The Physical Unclonable Function (PUF) authentication process includes multiple rounds of challenge-response pair (CRP) verification operations. In each authentication process, the initial trusted node sends a predefined physical characteristic challenge signal to the device to be authenticated. The device to be authenticated responds through its internal unique PUF circuit and generates a unique response code. The initial trusted node compares the response code with the correct response code in the pre-stored original challenge-response database. When multiple rounds of responses meet the consistency and stability thresholds, the device is confirmed as a trusted node, and the device ID, PUF signature, and authentication result are uploaded to the chain in the form of a structured transaction in the distributed ledger to ensure the authenticity, non-forgery, and traceability of the authentication process.

[0057] When a new device accesses the Internet of Things network, it completes the identity confirmation and trust relationship establishment of the new device through two-way authentication with at least one node in the initial set of trusted nodes;

[0058] When a new device accesses, the two-way authentication process includes the new device and the initial trusted node respectively initiating challenge verification based on asymmetric key encryption. Specifically, the new device signs the random challenge message sent by the trusted node using its own private key, and the initial trusted node verifies the signature result through the public key of the new device; at the same time, the initial trusted node also needs to sign the challenge message of the new device using its own private key, and the new device verifies it in the same way. After both two-way verifications pass, the two-way confirmation of the device identity is completed, and a block with a timestamp and verification log is generated in the distributed ledger for this process to ensure the transparency and non-deniability of the verification process.

[0059] Based on the trust relationship established between the new device and the trusted nodes, distribute the encryption key through a secure channel, and synchronously record the key distribution process and the trust chain establishment process in the distributed ledger;

[0060] The establishment of the secure channel is based on the Elliptic Curve Diffie-Hellman (ECDH) protocol. After completing the two-way authentication, the new device and the trusted node respectively use the public key of the other party and their own private key to calculate the shared session key. The obtained session key is only valid for this session, and the encryption digest and negotiation status of the key negotiation are recorded in the distributed ledger. The negotiation process adopts a time window control mechanism. If the negotiation is not completed within the timeout period, the key negotiation is forcibly interrupted to prevent man-in-the-middle attacks or delayed replay attacks.

[0061] Construct a trust-enhanced consensus mechanism with the initial trusted nodes and the verified devices as participants, dynamically update the trust value and key validity, and real-time monitor node behavior anomalies;

[0062] The trust-enhanced consensus mechanism is an asynchronous consensus protocol improved based on Byzantine Fault Tolerance (BFT). The trusted initial nodes and the verified devices jointly participate in the consensus process. In each round of the consensus process, the node trust value is dynamically calculated based on the historical behavior score, data transmission reliability, and key usage frequency of the device. Devices with a node trust value lower than the consensus threshold will be automatically excluded from the consensus participating nodes, and all consensus results and the historical changes of the trust value are stored on the chain to prevent malicious nodes from participating in the consensus process and improve the security and stability of the consensus.

[0063] The specific steps for dynamically updating the trust value and calculating the consensus voting weight are as follows:

[0064] To ensure that the Internet of Things nodes can dynamically reflect their trustworthiness during long-term operation, a trust evaluation mechanism is established for each node to calculate the trust value. The calculation formula is as follows:

[0065] T i (t) = α·H i (t) + γ·C i (t) + γ·S i (t)

[0066] , where, T i (t) is the trust value of node i at time t, which is used to measure the current trustworthiness of the node in the system. The higher the trust value, the better the historical behavior, data quality, and security of the node. H i (t) is the historical behavior score of node i at time t, which reflects the historical behavior performance of the node in the past cycle, such as normal communication situation, task completion rate, abnormal operation rate, etc. C i (t) is the data transmission reliability score of node i within time t, which represents the reliability of the node in data interaction. Considering indicators such as packet loss rate, communication delay, and transmission success rate, it directly reflects the communication link quality and transmission stability. S i (t) is the security event sensitivity factor of node i at time t, which quantifies the severity of security events encountered or participated in by the node in the system, such as whether abnormal data packets are detected, whether communication is rejected, whether it has ever been included in the temporary blacklist, etc. α, β, and γ are all trust value weighting coefficients, corresponding to the contribution degrees of T i (t), C i (t), and S i (t) to the comprehensive trust value, and satisfy: α + β + γ = 1;

[0067] In the distributed consensus process, the voting weight of each node is dynamically determined according to its trust value. The calculation formula for the voting weight is as follows:

[0068] ,

[0069] Where, W i is the voting weight of node i in the distributed consensus process, reflecting the proportion of the node in the consensus voting. The higher the trust value of the node, the greater the voting weight. N is the total number of nodes participating in the current consensus process, and T j (t) is the data transmission reliability score of node j within time t;

[0070] When the trust value volatility of a node in consecutive k rounds of consensus processes satisfies the following condition: Var(T i ) > θ, that is, the variance of the trust value fluctuation is greater than the system - preset security threshold θ, it is determined that there are abnormalities in the recent behavior of the node, and it automatically enters the trust anomaly review mechanism. The relevant nodes need to undergo additional behavior analysis and multi - dimensional trust correction to ensure the stability and anti - attack ability of the consensus system.

[0071] Based on the trust chain and consensus results in the distributed ledger, encrypt the communication data between IoT devices to ensure the confidentiality, integrity, and non - repudiation of the data during the transmission process;

[0072] The encryption process adopts a combination of symmetric encryption and immutable blockchain records. During the communication process between devices, first, the shared symmetric key confirmed by the trust - enhanced consensus mechanism is used to encrypt the transmitted data, and the data receiver decrypts it through the shared key. At the same time, both communication parties jointly record the encryption digest, timestamp, and participating device identity information of this data communication on the distributed ledger, ensuring the confidentiality, integrity, and traceability of the data during the transmission process, and the communication record cannot be tampered with, which can effectively address replay attacks and communication hijacking problems.

[0073] During the operation of the device, continuously use the initial trust node set to conduct dynamic trust assessment and key update for newly - connected devices in the distributed - trust IoT security system. When it is found that the trust value of a node is lower than the preset threshold, automatically revoke its communication permission and record abnormal information in the distributed ledger;

[0074] The dynamic trust assessment and key update mechanism includes a dynamic adjustment mechanism based on the node trust value. The initial trust nodes periodically evaluate the trust values of all connected nodes in the distributed - trust IoT security system, comprehensively considering the device's behavior consistency, data transmission quality, historical security events, and key usage. When the node trust value gradually decreases and is lower than the preset security threshold, automatically broadcast trust revocation information to the remaining trusted nodes in the distributed - trust IoT security system, generate a revocation block and synchronize it to the distributed ledger, and at the same time revoke the key permission and communication permission of the corresponding device to ensure that only highly - trusted nodes in the distributed - trust IoT security system participate in communication and consensus.

[0075] The specific steps of the dynamic key update strategy are as follows:

[0076] Dynamically adjust the update frequency of the node key based on the trust value. The calculation expression for the key update period of each node is as follows:

[0077] ,

[0078] where U i is the key update period of node i, indicating how often the node needs to update the encryption key. The lower the trust value, the shorter the update period. λ is the preset maximum allowable update period, and T max is the specified theoretical maximum trust value;

[0079] The lower the trust value, the shorter the key update period assigned to the node, forcing nodes with low trust values to update their keys frequently, thereby enhancing the control over abnormal nodes and reducing their potential security threats.

[0080] When the trust value fluctuates, the node resets the key according to the trust change amount and the current timestamp. The session key update formula is as follows:

[0081] ,

[0082] where is the newly generated session key of node i, which will replace the old key for subsequent communication. HMAC SHA256 is the message authentication code (HMAC) algorithm based on SHA256, providing high encryption strength and collision resistance to ensure the security and unpredictability of the new key. is the session key currently used by node i, serving as the basis for key update. ΔT i is the change amount of the trust value of node i in the most recent time. ts is the current timestamp, used to ensure the uniqueness and timeliness of each update input and prevent replay attacks.

[0083] By jointly incorporating the trust change amount and the timestamp into the key update process, the entropy and unpredictability of the key are significantly enhanced, ensuring the security of the key in a dynamic trust environment.

[0084] If the trust value change of the node satisfies the following condition: ΔT i < -δ, when the trust value change amount ΔT of node i iWhen it is less than the negative security threshold -δ, where δ is the trust value decrease threshold, representing the maximum amplitude of the tolerated single - round decrease of the trust value, and the trust value has not recovered to the normal range after continuous n rounds of detection, the key revocation process is immediately triggered. The session key and all trust credentials of this node are directly revoked, the node is isolated and prohibited from continuing to participate in any IoT communication and consensus process. At the same time, the current abnormal event is synchronously written into the distributed ledger as a security audit record to form a complete event tracking record, ensuring overall security and traceability. Here, n is the threshold of the number of consecutive detection rounds. Only when the trust value remains lower than the threshold for more than n rounds will the revocation mechanism be triggered to avoid misjudging normal nodes due to short - term fluctuations.

[0085] Embodiment 1: In the IoT environment, the construction of trusted initial nodes is the key to trust chain establishment and the cold start of the trust mechanism. Especially in newly deployed IoT networks, if there is a lack of a secure initial trust source, the system will face high - risk threats such as forged node injection and initial trust chain contamination. To effectively solve this problem, the physical unclonable feature (PUF) is used as the only identity generation mechanism for trusted initial nodes. By performing hardware - level security reinforcement on core IoT devices, the authenticity and non - forgery of the trust source are guaranteed. The specific implementation process is as follows: In the initial stage of system deployment, core nodes in the IoT, such as gateways, management centers, industrial controllers, master control units, etc., are selected as trusted initial nodes, and PUF circuits are built - in during hardware design. PUF utilizes the tiny random differences in manufacturing processes to form unpredictable and unclonable physical fingerprints, serving as the unique physical identity identifier of the device.

[0086] In the system initialization stage, the trusted initial node receives multiple rounds of challenge signals (Challenge) sent by the control center or other trusted nodes. The PUF circuit generates a unique and stable response (Response) based on the input signal. The control center or trusted node compares the response result with the PUF signature information in the pre - registered database. Only after all challenge - response pairs pass the threshold tolerance test is the device confirmed as a trusted initial node. The authentication results, PUF signature summaries, device identity information, authentication timestamps, etc. of all verification processes are synchronously packaged into structured blocks and written into the distributed ledger for subsequent nodes to share securely.

[0087] During the network operation after cold start, all newly connected devices need to perform PUF authentication with at least one node in the trusted initial node set to confirm the device identity bidirectionally. On the one hand, the initial node performs PUF authentication on the connected device. On the other hand, the newly connected device also confirms its identity through the PUF signature of the trusted initial node, forming a two-way trust to ensure that both the connected device and the trusted node are real and legitimate devices that have not been forged. Compared with traditional unidirectional authentication, two-way PUF authentication can significantly reduce the risk of being injected with forged nodes during the cold start phase and avoid the destruction of the trust root. At the same time, due to the natural physical unclonability, lightweight and low-power characteristics of the PUF feature, it is particularly suitable for resource-constrained Internet of Things devices.

[0088] After the authentication is completed, the trusted initial node distributes the initial trust value and key to the new device as a voucher for it to join the trust chain, and records the authentication process completely in the distributed ledger. Through the above PUF authentication mechanism, key issues such as the generation of the trust root and the defense against forged nodes in the cold start process of the trust chain can be solved at the physical level, laying a solid foundation for subsequent secure communication, consensus and key distribution in the system.

[0089] Embodiment 2: In the cold start phase of the Internet of Things system, the expansion ability and security of the trust mechanism are often limited due to the insufficient number of trusted nodes. To solve this problem, the system designs a trust-enhanced consensus mechanism to ensure that even when the trusted initial nodes are insufficient, the trust chain can be extended safely and reliably. Specifically, in the cold start phase, the system designs an improved Byzantine fault-tolerant consensus mechanism based on the trusted initial node set. The participating nodes include the initial nodes that have passed the PUF authentication and the subsequently connected verified devices.

[0090] During the process of new device access, it first needs to complete the PUF two-way authentication, and its identity is confirmed by at least one trusted initial node. After successful authentication, the new device does not immediately become a trusted node, but enters the trust-enhanced consensus process. The consensus mechanism dynamically assigns an initial trust value to the new device by comprehensively analyzing the PUF authentication result of the new device, the behavioral characteristics during access (such as the normality of data interaction, the stability of the communication channel, transmission delay, energy consumption characteristics, etc.) and the device's historical behavior (such as the security self-check performed by the device in the local environment, communication behavior records).

[0091] The new device needs to participate in the trust-enhanced consensus multiple times during the cold start phase. The trusted initial nodes in the system and some of the existing verified nodes jointly score the behavior of the new device and initiate the consensus. The consensus adopts a weighted trust voting mechanism. The higher the trust value of the participating node, the greater its voting weight, preventing a small number of attacked nodes from destroying the system security through the consensus. During the consensus process, if the new device performs stably in multiple rounds of evaluations and meets the trust value improvement conditions, its trust value gradually increases and it is finally formally incorporated into the trust chain, obtaining complete communication, consensus and key permissions.

[0092] The trust-enhanced consensus mechanism is particularly crucial in the cold start phase. It can not only effectively screen new devices, prevent forged nodes from quickly penetrating the trust chain, but also record all the processes and results of participating in the consensus through a distributed ledger, forming a complete trust track, and enhancing the auditability and traceability of the system. Compared with the direct acceptance method of the traditional trust chain, this implementation method can significantly enhance the trust extension ability and anti-attack ability of the IoT system in the cold start phase.

[0093] Embodiment 3: In the IoT trust system during cold start, insufficient initial trust may lead to a vulnerable key distribution mechanism. If an attacker hijacks or forges participation through a small number of nodes, it is easy to cause key leakage or the trust chain to be contaminated. Therefore, the system designs a key dynamic distribution and update mechanism driven by trust values, and combines the trust-enhanced consensus mechanism and the distributed ledger to achieve refined management of the key life cycle. This mechanism effectively improves the anti-forgery and anti-long-latency attack capabilities of the trust chain by dynamically adjusting the key distribution period, key length, and key usage permissions.

[0094] Specifically, when a new device becomes a formal trust node through the trust-enhanced consensus mechanism, the session key, data encryption key, and signature key it obtains are not fixed, but are directly associated with its current trust value. Nodes with a high trust value will obtain keys with a longer period and higher permissions; nodes with a relatively low trust value will obtain keys with a short period and low permissions. The system periodically evaluates the trust values of all nodes in the network in real time. If a node's trust value decreases due to abnormal behavior, poor data consistency, communication distortion, or abnormal key usage, the system will automatically shorten the validity period of its key. Even when the trust value is lower than the security threshold, the communication key of this node will be directly revoked.

[0095] At the same time, the system supports dynamic key update. The key update process is initiated by the trust-enhanced consensus group, and a new key is generated using HMAC-SHA256 together with the current trust value change amount and timestamp to ensure the uniqueness and dynamics of the updated key. After the update is completed, the new key and the trust value change history will be written into the distributed ledger as a new block for sharing and verification by all devices in the network, preventing malicious nodes from bypassing the key update mechanism. If a node's trust value continues to decline, the system will reject its participation in subsequent key negotiations and broadcast its key revocation information to the whole network synchronously to ensure the key security of the entire trust chain.

[0096] Through this mechanism, even in the case of insufficient trust nodes and an immature trust chain during cold start, hierarchical key management based on trust values can be achieved, effectively preventing the problem of long-term latent attacks after a small number of nodes hijack the key in the initial stage. This mechanism is particularly important in the initial stage of system deployment, can dynamically restrict the communication permissions of new devices and low-trust nodes, and establish a dynamically secure, flexible and controllable trust and key management system for the system.

[0097] By introducing a trust initial node authentication mechanism based on the physical unclonable feature (PUF), the present invention effectively solves the problem of difficult establishment of the root of trust that commonly exists in the cold start phase of the Internet of Things system. By integrating the PUF circuit in the core node and utilizing its natural uniqueness and unclonability, the authenticity and non-forgeability of the trust initial node identity are guaranteed, and the risk of forged nodes sneaking into the system through the initial trust authentication is eliminated. Compared with the traditional method of constructing the root of trust based on software certificates or symmetric keys, the present invention can directly establish a trusted trust source at the hardware level, providing a secure and reliable basic environment for subsequent Internet of Things device access, trust chain extension, and secure communication, and significantly improving the cold start security of the trust mechanism.

[0098] By designing a trust enhancement consensus mechanism, based on the cooperation between the trust initial node and the verified nodes, dynamic trust evaluation and consensus confirmation are carried out on new devices in the initial access stage, avoiding the security risks of the traditional Internet of Things system being easily penetrated by forged devices and malicious nodes due to insufficient number of trust nodes during the cold start process. The proposed trust enhancement consensus mechanism not only considers the authenticity of the device identity, but also introduces multi-dimensional dynamic trust indicators such as device access behavior, communication stability, and consensus participation quality, effectively improving the accuracy and security of the consensus. By combining the dynamic adjustment of the trust value with the consensus voting weight and transparently recording the consensus process in the distributed ledger, it can ensure the orderly and secure extension of the trust chain in the cold start stage, laying a solid foundation for the subsequent large-scale device secure access.

[0099] The trust value-driven key dynamic distribution and update mechanism proposed by the present invention can flexibly control the key permissions and validity periods according to the real-time trust value of the device, significantly enhancing the anti-attack ability of the Internet of Things system during the cold start and operation processes. By directly associating the trust value with the key life cycle, key length, and communication permissions, it can effectively limit the communication capabilities of low-trust or suspicious devices and automatically revoke their keys when the trust value drops below the security threshold, preventing malicious nodes from lurking for a long time before the trust chain is stable. Combined with security update mechanisms such as HMAC-SHA256, it ensures the dynamicity and uniqueness of the keys, and at the same time, all key update and revocation events are traceable and verifiable in the distributed ledger, overall enhancing the system's defense ability and security stability against attack behaviors such as forged nodes, key hijacking, and trust pollution.

[0100] The present invention provides an Internet of Things encryption system combined with a distributed trust mechanism as Figure 2 shown, including a trust initial node authentication module, a new device trust access module, a key distribution and trust chain establishment module, a trust enhancement consensus and dynamic evaluation module, an encrypted communication and security guarantee module, and a dynamic trust management and key revocation module;

[0101] Trust the initial node authentication module, establish a set of initial trusted nodes, use the physical unclonable feature to perform physical layer security authentication on the core nodes of the Internet of Things, generate a unique node identity key, and register it as a trusted node in the distributed ledger;

[0102] New device trusted access module. When a new device accesses the Internet of Things network, it completes the identity confirmation and trust relationship establishment of the new device through two-way identity authentication with at least one node in the set of initial trusted nodes;

[0103] Key distribution and trust chain establishment module. Based on the trust relationship established between the new device and the trusted nodes, it distributes encryption keys through a secure channel and synchronously records the key distribution process and the trust chain establishment process in the distributed ledger;

[0104] Trust enhancement consensus and dynamic evaluation module. Build a trust enhancement consensus mechanism with the initial trusted nodes and the verified devices as participants, dynamically update the trust value and key validity, and monitor node behavior anomalies in real time;

[0105] Encryption communication and security guarantee module. Based on the trust chain and consensus results in the distributed ledger, it encrypts the communication data between Internet of Things devices to ensure the confidentiality, integrity, and non-repudiation of the data during the transmission process;

[0106] Dynamic trust management and key revocation module. During the operation of the device, it continuously uses the set of initial trusted nodes to perform dynamic trust evaluation and key update on the newly accessed devices in the distributed trust Internet of Things security system. When it is found that the trust value of a node is lower than the preset threshold, it automatically revokes its communication permission and records the abnormal information in the distributed ledger.

[0107] An Internet of Things encryption method combining a distributed trust mechanism provided by an embodiment of the present invention is implemented through the above-mentioned Internet of Things encryption system combining a distributed trust mechanism. The specific methods and processes of an Internet of Things encryption system combining a distributed trust mechanism are detailed in the embodiments of the above-mentioned Internet of Things encryption method combining a distributed trust mechanism, and will not be elaborated here.

[0108] As described above, only the specific implementation manners of the present application are provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claimed rights.

Claims

1. An Internet of Things encryption method combined with a distributed trust mechanism, characterized in that, It includes the following steps: Establish a set of initial trusted nodes, use the physical unclonable feature to perform physical layer security authentication on the core nodes of the Internet of Things, generate a unique node identity key, and register it as a trusted node in the distributed ledger; When a new device accesses the Internet of Things network, complete the identity confirmation of the new device and establish a trust relationship by performing two-way identity authentication with at least one node in the set of initial trusted nodes; Based on the trust relationship established between the new device and the trusted nodes, distribute the encryption key through a secure channel, and synchronously record the key distribution process and the trust chain establishment process in the distributed ledger; Construct a trust-enhanced consensus mechanism with the initial trusted nodes and the verified devices as participants, dynamically update the trust value and key validity, and monitor node behavior anomalies in real time; Based on the trust chain and consensus results in the distributed ledger, encrypt the communication data between the Internet of Things devices to ensure the confidentiality, integrity, and non-repudiation of the data during transmission; During the operation of the device, continuously use the set of initial trusted nodes to perform dynamic trust assessment and key update on the newly accessed devices in the distributed trust Internet of Things security system. When it is found that the node trust value is lower than the preset threshold, automatically revoke its communication permission and record the abnormal information in the distributed ledger.

2. The Internet of Things encryption method combining a distributed trust mechanism according to claim 1, characterized in that, The physical unclonable feature authentication process includes multiple rounds of challenge-response verification operations. In each authentication process, the initial trusted node sends a predefined physical feature challenge signal to the device to be authenticated. The device to be authenticated responds through its internal unique PUF circuit and generates a unique response code. The initial trusted node compares the response code with the correct response code in the pre-stored original challenge-response database. When multiple rounds of responses meet the consistency and stability thresholds, confirm that the device is a trusted node, and record the device ID, PUF signature, and authentication result in the distributed ledger in the form of a structured transaction to ensure the authenticity, non-forgery, and traceability of the authentication process.

3. The Internet of Things encryption method combining a distributed trust mechanism according to claim 2, characterized in that, When a new device accesses, the two-way identity authentication process includes the new device and the initial trusted node respectively initiating challenge verification based on asymmetric key encryption. Specifically, the new device uses its own private key to sign the random challenge message sent by the trusted node, and the initial trusted node verifies the signature result through the public key of the new device; at the same time, the initial trusted node also needs to sign the challenge message of the new device with its own private key, and the new device verifies it in the same way. After both two-way verifications pass, complete the two-way confirmation of the device identity, and generate a block with a timestamp and verification log in the distributed ledger to ensure the transparency and non-deniability of the verification process.

4. An Internet of Things encryption method combining a distributed trust mechanism according to claim 3, characterized in that, The establishment of the secure channel is based on the elliptic curve key agreement protocol. After completing the two-way identity authentication, the new device and the trusted node respectively use the public key of the other party and their own private key to calculate the shared session key. The obtained session key is only valid for this session, and the encrypted digest and negotiation status of the key negotiation are recorded in the distributed ledger. The negotiation process adopts a time window control mechanism, and if the timeout is not completed, the key negotiation is forced to interrupt to prevent man-in-the-middle attacks or delayed replay attacks.

5. The Internet of Things encryption method combining a distributed trust mechanism according to claim 4, characterized in that, The trust-enhanced consensus mechanism is an asynchronous consensus protocol based on Byzantine fault tolerance. The trust initial node and verified devices jointly participate in the consensus process. In each round of consensus, the node trust value is dynamically calculated based on the device's historical behavior score, data transmission reliability, and key usage frequency. Devices with node trust values below the consensus threshold will be automatically excluded from the consensus participating nodes, and all consensus results and trust value change history are stored on the chain to prevent malicious nodes from participating in the consensus process and improve the security and stability of the consensus.

6. An Internet of Things encryption method combined with a distributed trust mechanism according to claim 5, characterized in that The specific steps for dynamic update of trust value and calculation of consensus voting weight are as follows: In order to ensure that IoT nodes can dynamically reflect their trustworthiness during long-term operation, a trust evaluation mechanism is established for each node to calculate the trust value. In the distributed consensus process, the voting weight of each node is dynamically determined based on its trust value. When the volatility of the trust value of a node during consecutive rounds of consensus meets the following conditions: that is, the variance of the trust value fluctuation is greater than the system's preset safety threshold, the node is judged to have abnormal behavior in recent times and automatically enters the trust anomaly review mechanism. The relevant nodes are required to undergo additional behavior analysis and multi-dimensional trust correction to ensure the stability and anti-attack capability of the consensus system.

7. An Internet of Things encryption method combining a distributed trust mechanism according to claim 6, characterized in that, The encryption processing adopts a combination of symmetric encryption and immutable blockchain records. During the communication between devices, the shared symmetric key confirmed by the trust-enhanced consensus mechanism is first used to encrypt the transmitted data, and the data recipient decrypts it using the shared key. At the same time, the communicating parties jointly record the encrypted summary, timestamp and identity information of the participating devices of this data communication on the distributed ledger to ensure the confidentiality, integrity and traceability of the data during transmission. The communication records cannot be tampered with, which can effectively deal with replay attacks and communication hijacking problems.

8. An Internet of Things encryption method combining a distributed trust mechanism according to claim 7, characterized in that, The dynamic trust evaluation and key update mechanism includes a dynamic adjustment mechanism based on the node trust value. The trust initial node performs periodic trust value evaluation on all connected nodes in the distributed trust Internet of Things security system, comprehensively considering the behavioral consistency, data transmission quality, historical security events and key usage of the equipment. When the node trust value gradually decreases and falls below the preset security threshold, it automatically broadcasts trust revocation information to the remaining trust nodes in the distributed trust Internet of Things security system, generates a revocation block and synchronizes it to the distributed ledger, and revokes the key permissions and communication permissions of the corresponding device at the same time, ensuring that only high-trust nodes in the distributed trust Internet of Things security system participate in communication and consensus.

9. An Internet of Things encryption method combining a distributed trust mechanism according to claim 8, characterized in that, The specific steps of the dynamic key update strategy are as follows: Dynamically adjust the update frequency of node keys based on trust value When the trust value fluctuates, the node resets the key based on the trust change and the current timestamp. If the change in the trust value of a node satisfies the following conditions: when the change in the trust value of the node is less than the negative security threshold and it has not recovered to the normal range after continuous detection for n rounds, the key revocation process is immediately triggered, directly revoking the session key and all trust credentials of the node. The node is isolated and prohibited from continuing to participate in any IoT communication and consensus process. At the same time, the current abnormal event is synchronously written into the distributed ledger as a security audit record to form a complete event tracking record, ensuring overall security and traceability.

10. An Internet of Things encryption system incorporating a distributed trust mechanism, for implementing an Internet of Things encryption method incorporating a distributed trust mechanism according to any one of the above claims 1-9, characterized in that, It includes a trust initial node authentication module, a new device trust access module, a key distribution and trust chain establishment module, a trust enhancement consensus and dynamic evaluation module, an encrypted communication and security guarantee module, and a dynamic trust management and key revocation module; The trust initial node authentication module establishes a set of trust initial nodes, uses the physical unclonable feature to perform physical layer security authentication on the core nodes of the Internet of Things, generates a unique node identity key, and registers it as a trusted node in the distributed ledger; The new device trust access module, when a new device accesses the Internet of Things network, completes the identity confirmation and trust relationship establishment of the new device through two-way identity authentication with at least one node in the set of trust initial nodes; The key distribution and trust chain establishment module, based on the trust relationship established between the new device and the trusted node, distributes the encryption key through a secure channel and synchronously records the key distribution process and the trust chain establishment process in the distributed ledger; The trust enhancement consensus and dynamic evaluation module constructs a trust enhancement consensus mechanism with trust initial nodes and verified devices as participants, dynamically updates the trust value and key validity, and monitors node behavior anomalies in real time; The encrypted communication and security guarantee module, based on the trust chain and consensus results in the distributed ledger, encrypts the communication data between IoT devices to ensure the confidentiality, integrity, and non-repudiation of the data during transmission; The dynamic trust management and key revocation module, during the operation of the device, continuously uses the set of trust initial nodes to perform dynamic trust evaluation and key update on newly accessed devices in the distributed trust IoT security system. When it is found that the trust value of a node is lower than the preset threshold, its communication permission is automatically revoked and the abnormal information is recorded in the distributed ledger.

Citation Information

Patent Citations

  • Dual-master-node PBFT consensus method based on credit mechanism

    CN117595998A

  • Internet of vehicles trust management method of pre-reward and punishment mechanism based on block chain

    CN118890625A

  • Distributed device identity authentication and access control method and system based on block chain

    CN119363318A

  • Data asset transaction control method and device, decentralized PUF network and storage medium

    CN119762070A

  • IWSN sensor access authentication protocol method of TCA and PUF

    CN119767305A