An internet of things encryption method and system combined with a distributed trust mechanism
By introducing PUF circuits into the IoT system for initial trust node authentication and trust enhancement consensus mechanism, the difficulty of establishing the root of trust during the cold start phase is solved, enabling secure and reliable communication and stable expansion of the trust chain in the IoT system, and improving the anti-attack capability and data transmission security.
Patent Information
- Application Number
- CN202510574362.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2045-05-06
AI Technical Summary
IoT systems face difficulties in establishing a root of trust during the cold start phase, and the initial trust chain is vulnerable to attacks by forged nodes, resulting in compromised security and stability.
A trust-based initial node authentication mechanism based on Physically Unclonable (PUF) is introduced, combined with a trust-enhanced consensus mechanism and a trust-value-driven key dynamic distribution and update mechanism. A unique node identity is generated through the PUF circuit, and two-way identity authentication and dynamic trust evaluation are performed to dynamically adjust key permissions and lifecycle.
It effectively solves the difficulty of establishing a root of trust during the cold start phase, improves the system's resistance to attacks and security stability, and ensures the reliable expansion of the trust chain and the confidentiality, integrity, and non-repudiation of data transmission.
Smart Images

Figure CN120342632B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and particularly relates to an Internet of Things encryption method and system combined with a distributed trust mechanism. BACKGROUND
[0002] The Internet of Things encryption combined with a distributed trust mechanism refers to using a decentralized, tamper-proof, and traceable distributed trust technology (such as a block chain, a distributed ledger, a consensus mechanism, etc.) to securely encrypt and credibly manage data transmission, storage, and identity authentication processes between Internet of Things devices in an Internet of Things (IoT) system. Through the distributed trust mechanism, the single-point trust problem can be avoided, and the trust vulnerability and security risks caused by the centralized trust model in the traditional Internet of Things can be solved. At the same time, in combination with encryption algorithms (such as symmetric encryption, asymmetric encryption, and hash encryption), the confidentiality, integrity, and authenticity of the communication data between Internet of Things terminal devices can be guaranteed, and secure and reliable end-to-end data transmission and node trust establishment in the Internet of Things system in an open environment can be ensured. In short, the distributed technology is used to provide decentralized trust protection for the encrypted communication and identity authentication of the Internet of Things.
[0003] The prior art has the following disadvantages: In the existing Internet of Things encryption process combined with a distributed trust mechanism, there is generally a cold start dilemma problem of trust roots. That is, when the Internet of Things system is initially deployed or new devices are accessed, the devices need to establish initial trust and distribute keys through the distributed trust mechanism. However, when the system has not yet formed a sufficient scale of trusted node network, if the initial trust chain construction process encounters security threats such as fake node injection, replaying historical block information, or key distribution hijacking, the trust chain may be directly invalidated or tampered with. Even if a perfect consensus mechanism and encryption method are used in the subsequent system operation, it is difficult to compensate for the security risks caused by the initial trust failure. Once an attacker successfully forges a trusted device or lurks for a long time, data can be continuously stolen and devices can be controlled, which seriously threatens the security and stability of the Internet of Things system.
[0004] The above information disclosed in the BACKGROUND section merely to enhance the understanding of the background of the present disclosure, and therefore it can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0005] The application aims to provide an Internet of Things encryption method and system combined with a distributed trust mechanism, which ensures the authenticity and unforgeability of the trust root in the cold start stage of the Internet of Things by introducing a trust initial node authentication mechanism based on PUF, designs a trust-enhanced consensus mechanism to realize dynamic trust evaluation and consensus confirmation of newly connected devices, and guarantees the safe expansion of the trust chain, and proposes a trust value-driven key dynamic distribution and update mechanism to flexibly control the key permission and life cycle according to the trust value, prevent low-trust nodes from lurking or attacking, and significantly improve the anti-attack ability and security stability of the system in the cold start and running processes, so as to solve the problems in the above background technology.
[0006] In order to achieve the above-mentioned purpose, the application provides the following technical scheme: an Internet of Things encryption method combined with a distributed trust mechanism, comprising the following steps:
[0007] A set of trust initial nodes is established, the physical layer security authentication of the core nodes of the Internet of Things is performed by using the physical unclonable feature, a unique node identity key is generated, and the trust nodes are registered in the distributed ledger;
[0008] When a new device accesses the Internet of Things network, two-way identity authentication is performed with at least one node in the set of trust initial nodes, the identity confirmation of the new device and the establishment of the trust relationship are completed;
[0009] Based on the trust relationship established between the new device and the trust nodes, the encryption key is distributed through the secure channel, and the key distribution process and the trust chain establishment process are recorded in the distributed ledger;
[0010] A trust-enhanced consensus mechanism is constructed with the trust initial nodes and the verified devices as participants, the trust value and the key validity are dynamically updated, and the abnormal behavior of the nodes is monitored in real time;
[0011] Based on the trust chain and the consensus result in the distributed ledger, the communication data between the Internet of Things devices is encrypted to ensure the confidentiality, integrity and non-repudiation of the data in the transmission process;
[0012] During the running of the device, the set of trust initial nodes is continuously used to dynamically evaluate the trust of the newly connected devices in the distributed trust Internet of Things security system and update the key, and when it is found that the node trust value is lower than the preset threshold, the communication permission of the node is automatically revoked and the abnormal information is recorded in the distributed ledger.
[0013] Preferably, the physical unclonable function authentication process includes a verification operation through multiple rounds of challenge-response pairs. In each authentication process, the trust initial node sends a predefined physical property challenge signal to the device to be authenticated, the device to be authenticated responds and generates a unique response code through an internal unique PUF circuit, and the trust initial node compares the response code with the correct response code in the pre-stored original challenge response database. When the multiple rounds of responses all meet the consistency and stability thresholds, the device is confirmed as a trusted node, and the device ID, PUF signature and authentication result are chained in the distributed ledger in the form of a structured transaction, ensuring that the authentication process is real, unforgeable and traceable.
[0014] Preferably, when a new device accesses, the two-way identity authentication process includes challenge verification based on asymmetric key encryption initiated by the new device and the trust initial node. Specifically, the new device signs the random challenge message sent by the trust node using its own private key, and the trust initial node verifies the signature result through the public key of the new device. At the same time, the trust initial node also needs to sign the challenge message of the new device using its own private key, and the new device verifies in the same way. After both-way verification, the device identity is confirmed in both directions, and a block with a timestamp and verification log is generated in the distributed ledger, ensuring the transparency and non-repudiation of the verification process.
[0015] Preferably, the establishment of the secure channel is based on the elliptic curve key agreement protocol. After completing the two-way identity authentication, the new device and the trust node calculate the shared session key using the public key of the other party and their own private key. The obtained session key is only valid for this session, and the encryption digest and negotiation state of the key agreement are recorded in the distributed ledger. The negotiation process uses a time window control mechanism, and if it is not completed within the time limit, the key agreement is forcibly interrupted to prevent man-in-the-middle attacks or delay replay attacks.
[0016] Preferably, the trust-enhanced consensus mechanism is an improved asynchronous consensus protocol based on Byzantine fault tolerance. The trust initial node and the verified devices jointly participate in the consensus process. In each round of consensus process, the node trust value is dynamically calculated based on the historical behavior score of the device, the data transmission reliability and the key usage frequency. The device with a node trust value lower than the consensus threshold will be automatically excluded from the consensus participant nodes, and all consensus results and trust value change history are stored on the chain to prevent malicious nodes from participating in the consensus process and improve the consensus security and stability.
[0017] Preferably, the trust value dynamic update and consensus voting weight calculation specific steps are as follows:
[0018] To ensure that the Internet of Things nodes can dynamically reflect their trustworthiness during long-term operation, a trust evaluation mechanism is established for each node to calculate the trust value. The calculation expression is as follows:
[0019] T i(t) = a H i (t) + b C i (t) + g S i (t)
[0020] , where T i (t) is the trust value of node i at time t, which measures the trustworthiness of the node in the system at present, the higher the trust value, the better the historical behavior, data quality and security of the node, H i (t) is the historical behavior score of node i at time t, reflecting the historical behavior performance of the node in the past period, such as normal communication, task completion rate and abnormal operation rate, C i (t) is the data transmission reliability score of node i at time t, indicating the reliability of the node in data interaction, considering packet loss rate, communication delay, transmission success rate and other indicators, directly reflecting the communication link quality and transmission stability, S i (t) is the security event sensitivity factor of node i at time t, quantifying the severity of security events encountered or participated by the node in the system, such as whether abnormal data packets are detected, whether communication is rejected, whether the node has ever been listed in the temporary blacklist, etc., a, b and g are trust value weighting coefficients, corresponding to T i (t), C i (t) and S i (t) respectively, and satisfy: a + b + g = 1;
[0021] In the distributed consensus process, the voting weight of each node is dynamically determined according to its trust value, and the voting weight calculation expression is as follows:
[0022]
[0023] , where W i is the voting weight of node i in the distributed consensus process, reflecting the proportion of the node in the consensus voting, the higher the trust value of the node, the greater the voting weight, N is the total number of nodes participating in the current consensus process, T j (t) is the data transmission reliability score of node j at time t;
[0024] When the trust value fluctuation rate of the node in the continuous k rounds of consensus process satisfies the following condition: Var(T i ) > q, i.e. the trust value fluctuation variance is greater than the system preset security threshold q, it is determined that the node has abnormal behavior in recent behavior, and automatically enters the trust abnormality review mechanism, and the related node needs to accept additional behavior analysis and multi-dimensional trust correction, to ensure the stability and attack resistance of the consensus system.
[0025] Preferably, the encryption process adopts a combination of symmetric encryption and immutable blockchain recording. In the process of communication between devices, the shared symmetric key confirmed by the trust-enhanced consensus mechanism is first used to encrypt the transmitted data, and the data receiver decrypts the data through the shared key. At the same time, the communication parties jointly record the encryption digest, timestamp, and identity information of the participating devices of the data communication on the distributed ledger, ensuring the confidentiality, integrity, and traceability of the data in the transmission process, and the communication record cannot be tampered with, which can effectively deal with the problems of replay attacks and communication hijacking.
[0026] Preferably, the dynamic trust evaluation and key update mechanism includes a dynamic adjustment mechanism based on node trust value. The trust initial node periodically evaluates the trust value of all nodes connected to the distributed trust Internet of Things security system, considering the behavior consistency, data transmission quality, historical security events, and key usage of the device. When the node trust value gradually decreases and is lower than the preset security threshold, the trust revocation information is automatically broadcast to the remaining trust nodes in the distributed trust Internet of Things security system, and a revocation block is generated and synchronized to the distributed ledger, and the key permission and communication permission of the corresponding device are revoked, ensuring that only high-trust nodes participate in communication and consensus in the distributed trust Internet of Things security system.
[0027] Preferably, the dynamic key update strategy has the following specific steps:
[0028] The update frequency of the node key based on the trust value is dynamically adjusted. The key update period calculation expression of each node is as follows:
[0029]
[0030] In the formula, U i is the key update period of node i, indicating how long the node needs to update the encryption key once, the lower the trust value, the shorter the update period, λ is the preset maximum allowed update period, T max is the specified theoretical maximum trust value;
[0031] The lower the trust value, the shorter the key update period allocated to the node, forcing the low-trust value node to frequently update the key, thereby improving the control of abnormal nodes and reducing their potential security threats.
[0032] When the trust value fluctuates, the node resets the key according to the trust change amount and the current timestamp. The session key update formula is as follows:
[0033]
[0034] In the formula, is the newly generated session key of node i, which will replace the old key for the next communication, HMACSHA256 is a message authentication code (HMAC) algorithm based on SHA256, providing high encryption strength and collision resistance, ensuring the security and unpredictability of the new key, is the current session key used by node i, which is the basis for key update, ΔT i is the change in the trust value of node i, and ts is the current timestamp, which is used to ensure that the input of each update is unique and timely, preventing replay attacks;
[0035] By incorporating the trust value change and timestamp into the key update process, the entropy and unpredictability of the key are significantly enhanced, ensuring the security of the key in a dynamic trust environment.
[0036] If the trust value of the node changes meet the following conditions: ΔT i <-δ, when the trust value change ΔT i of node i is less than the negative security threshold -δ, where δ is the trust value drop threshold, representing the maximum single drop of the trust value tolerated, and the continuous n rounds of detection have not returned to the normal interval, the key revocation process is triggered immediately, directly revoking the session key and all trust credentials of the node, the node is isolated and prohibited from participating in any Internet of Things communication and consensus process, while the current abnormal event is written into the distributed ledger as a security audit record, forming a complete event tracking record, ensuring the overall security and traceability, where n is the round threshold for continuous detection, only when the trust value remains below the threshold for n rounds or more, the revocation mechanism is triggered, avoiding false positives for normal nodes due to short-term fluctuations.
[0037] Preferably, an Internet of Things encryption system combined with a distributed trust mechanism includes a trust initial node authentication module, a new device trust access module, a key distribution and trust chain establishment module, a trust-enhanced consensus and dynamic evaluation module, an encrypted communication and security guarantee module, and a dynamic trust management and key revocation module.
[0038] The trust initial node authentication module establishes a set of trust initial nodes, performs physical layer security authentication on Internet of Things core nodes using physical unclonable features, generates a unique node identity key, and registers as a trusted node in the distributed ledger.
[0039] The new device trust access module, when a new device accesses the Internet of Things network, performs two-way identity authentication with at least one node in the set of trust initial nodes, completes the identity confirmation of the new device and the establishment of trust relationship;
[0040] The key distribution and trust chain establishment module, based on the trust relationship established between the new device and the trust node, distributes encryption keys through a secure channel, and synchronously records the key distribution process and the trust chain establishment process to the distributed ledger.
[0041] The trust-enhanced consensus and dynamic evaluation module constructs a trust-enhanced consensus mechanism with trust initial nodes and verified devices as participants, dynamically updates trust values and key validity, and monitors node behavior abnormalities in real time.
[0042] The encrypted communication and security guarantee module encrypts the communication data between Internet of Things devices based on the trust chain and consensus results in the distributed ledger, ensuring the confidentiality, integrity and non-repudiation of the data in the transmission process.
[0043] The dynamic trust management and key revocation module continuously uses the trust initial node set to dynamically evaluate the trust of newly connected devices in the distributed trust Internet of Things security system and update the keys during device operation. When the node trust value is found to be lower than the preset threshold, the communication rights are automatically revoked and the abnormal information is recorded in the distributed ledger.
[0044] In the above technical solution, the technical effects and advantages provided by the application are as follows:
[0045] The application introduces a trust initial node authentication mechanism based on physical unclonable function (PUF), effectively solving the problem of difficulty in establishing a trust root in the cold start phase of the Internet of Things system. By integrating the PUF circuit in the core node, the natural uniqueness and unclonability of the PUF circuit are used to ensure the authenticity and unforgeability of the trust initial node identity, eliminating the risk of fake nodes infiltrating the system through initial trust authentication. Compared with traditional trust root construction methods based on software certificates or symmetric keys, the application can directly establish a trusted trust source from the hardware level, providing a secure and reliable foundation for subsequent Internet of Things device access, trust chain expansion and secure communication, significantly improving the cold start security of the trust mechanism.
[0046] The application designs a trust-enhanced consensus mechanism based on the cooperation of trust initial nodes and verified nodes to dynamically evaluate and confirm the trust of new devices in the initial access phase, avoiding the security risks of fake devices and malicious nodes quickly penetrating the system due to insufficient trust nodes in the cold start process of traditional Internet of Things systems. The proposed trust-enhanced consensus mechanism not only considers the authenticity of the device identity, but also introduces multi-dimensional dynamic trust indicators such as device access behavior, communication stability and consensus participation quality, effectively improving the accuracy and security of the consensus. By combining dynamic trust value adjustment with consensus voting weight and transparently recording the consensus process in the distributed ledger, the ordered and secure expansion of the trust chain in the cold start phase is guaranteed, laying a solid foundation for subsequent large-scale device security access.
[0047] The trust value driven key dynamic distribution and update mechanism can flexibly control the key permission and validity period according to the real-time trust value of the device, and significantly improves the anti-attack ability of the Internet of Things system in the cold start and running process; by directly associating the trust value with the key life cycle, the key length and the communication permission, the communication ability of the low-trust or suspicious device can be effectively limited, and the key of the device can be automatically revoked when the trust value drops below the security threshold, preventing malicious nodes from long-term lurking before the trust chain is stable; in combination with the security update mechanism such as HMAC-SHA256, the dynamic and uniqueness of the key are guaranteed, and meanwhile, all key update and revocation events can be traced and verified in the distributed ledger, thereby improving the defense ability and security stability of the system when facing attacks such as fake nodes, key hijacking and trust pollution. BRIEF DESCRIPTION OF DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present application, and other drawings can also be obtained by those skilled in the art based on these drawings.
[0049] Figure 1 The method flowchart of the Internet of Things encryption method combined with the distributed trust mechanism.
[0050] Figure 2 The module schematic diagram of the Internet of Things encryption system combined with the distributed trust mechanism.
[0051] Figure 3 The module mind map of the Internet of Things encryption system combined with the distributed trust mechanism.
[0052] Figure 4 The method mind map of the Internet of Things encryption method combined with the distributed trust mechanism. DETAILED DESCRIPTION
[0053] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations may, however, be implemented in many different forms and should not be construed as limited to the examples set forth herein; rather, these example implementations are provided so that this disclosure will be thorough and complete, and will fully convey the gist of each example to those skilled in the art.
[0054] The present application provides an Internet of Things encryption method combined with a distributed trust mechanism, as shown in Figures 1-4 The method flowchart of the Internet of Things encryption method combined with the distributed trust mechanism.
[0055] A set of trusted initial nodes is established, a physical unclonable function (PUF) is used to perform physical layer security authentication on an Internet of Things core node, a unique node identity key is generated, and the node is registered as a trusted node in a distributed ledger;
[0056] The PUF authentication process includes a multi-round challenge-response pair (CRP) verification operation. In each authentication process, the trusted initial node sends a predefined physical property challenge signal to the device to be authenticated. The device to be authenticated responds by generating a unique response code through an internal unique PUF circuit. The trusted initial node compares the response code with the correct response code in the pre-stored original challenge-response database. When the multiple rounds of responses all meet the consistency and stability thresholds, the device is confirmed as a trusted node. The device ID, PUF signature, and authentication result are chained in the distributed ledger in a structured transaction, ensuring that the authentication process is real, unforgeable, and traceable.
[0057] When a new device accesses the Internet of Things network, a two-way identity authentication is performed with at least one node in the set of trusted initial nodes to complete the identity confirmation and trust relationship establishment of the new device.
[0058] When the new device accesses, the two-way identity authentication process includes challenge verification based on asymmetric key encryption initiated by the new device and the trusted initial node. Specifically, the new device signs the random challenge message sent by the trusted node using its own private key, and the trusted initial node verifies the signature result through the public key of the new device. At the same time, the trusted initial node also needs to sign the challenge message of the new device using its own private key, and the new device verifies it in the same way. After both-way verification, the device identity is confirmed, and a block with a timestamp and verification log is generated in the distributed ledger, ensuring the transparency and non-repudiation of the verification process.
[0059] Based on the trust relationship established between the new device and the trusted node, an encryption key is distributed through a secure channel, and the key distribution process and trust chain establishment process are recorded in the distributed ledger;
[0060] The establishment of the secure channel is based on the Elliptic Curve Diffie-Hellman (ECDH) protocol. After completing the two-way identity authentication, the new device and the trusted node use each other's public key and their own private key to calculate a shared session key. The resulting session key is only valid for this session, and the encryption digest and negotiation status of the key negotiation are recorded in the distributed ledger. The negotiation process uses a time window control mechanism, and if it is not completed within the time limit, the key negotiation is forcibly interrupted to prevent man-in-the-middle attacks or delayed replay attacks.
[0061] A trust-enhanced consensus mechanism is constructed with the trusted initial nodes and verified devices as participants, the trust value and key validity are dynamically updated, and the node behavior anomalies are monitored in real time;
[0062] The trust-enhanced consensus mechanism is an improved asynchronous consensus protocol based on Byzantine Fault Tolerance (BFT). The trust initial node and the verified device jointly participate in the consensus process. In each round of the consensus process, the trust value of the node is dynamically calculated based on the historical behavior score of the device, the data transmission reliability and the key usage frequency. The device with a trust value lower than the consensus threshold will be automatically excluded from the consensus participating nodes. All consensus results and trust value change history are stored on the chain to prevent malicious nodes from participating in the consensus process and improve the consensus security and stability.
[0063] The specific steps of dynamic updating of the trust value and calculation of the consensus voting weight are as follows:
[0064] To ensure that the Internet of Things nodes can dynamically reflect their trustworthiness during long-term operation, a trust evaluation mechanism is established for each node to calculate the trust value. The calculation expression is as follows:
[0065] T i (t)=α·H i (t)+γ·C i (t)+γ·S i (t)
[0066] In the formula, T i (t) is the trust value of node i at time t, which is used to measure the trustworthiness of the node in the system. The higher the trust value, the better the historical behavior, data quality and security of the node. H i (t) is the historical behavior score of node i at time t, which reflects the historical behavior performance of the node in the past period, such as normal communication, task completion rate and abnormal operation rate. C i (t) is the data transmission reliability score of node i at time t, which represents the reliability of the node in data interaction, considering packet loss rate, communication delay, transmission success rate and other indicators, directly reflecting the communication link quality and transmission stability. S i (t) is the security event sensitivity factor of node i at time t, which quantifies the severity of security events encountered or participated by the node in the system, such as whether abnormal data packets are detected, whether communication is rejected, whether the node has ever been listed in the temporary blacklist, etc. α, β and γ are trust value weighting coefficients, corresponding to the contribution of T i (t), C i (t) and S i (t) to the comprehensive trust value, and satisfy: α+β+γ=1.
[0067] In the distributed consensus process, the voting weight of each node is dynamically determined according to its trust value. The voting weight calculation expression is as follows:
[0068]
[0069] wherein W i is the voting weight of node i in the distributed consensus process, reflecting the proportion of the node in the consensus voting, the higher the trust value of the node, the greater the voting weight, N is the total number of nodes participating in the current consensus process, T j (t) is the data transmission reliability score of node j at time t;
[0070] When the fluctuation rate of the trust value of the node in the continuous k rounds of the consensus process satisfies the following condition: Var(T i )>θ, that is, the trust value fluctuation variance is greater than the system preset safety threshold θ, it is determined that the node has abnormal behavior in recent behavior, and the related node needs to accept additional behavior analysis and multi-dimensional trust correction to ensure the stability and attack resistance of the consensus system.
[0071] Based on the trust chain and consensus result in the distributed ledger, the communication data between the Internet of Things devices is encrypted to ensure the confidentiality, integrity and non-repudiation of the data in the transmission process;
[0072] The encryption processing adopts the combination of symmetric encryption and immutable blockchain record. In the communication process between devices, the shared symmetric key confirmed by the trust-enhanced consensus mechanism is used to encrypt the transmission data, and the data receiver decrypts it through the shared key. At the same time, the communication parties jointly record the encryption digest, timestamp and participating device identity information of this data communication on the distributed ledger, ensuring the confidentiality, integrity and traceability of the data in the transmission process, and the communication record cannot be tampered with, which can effectively deal with the problems of replay attack and communication hijacking.
[0073] During the operation of the device, the trust initial node set is continuously used to dynamically evaluate the trust of newly connected devices in the distributed trust Internet of Things security system and update the key. When it is found that the node trust value is lower than the preset threshold, the communication right is automatically revoked and the abnormal information is recorded in the distributed ledger;
[0074] The dynamic trust evaluation and key update mechanism includes a dynamic adjustment mechanism based on the node trust value. The trust initial node periodically evaluates the trust value of all connected nodes in the distributed trust Internet of Things security system, considering the behavior consistency, data transmission quality, historical security events and key usage of the device. When the node trust value gradually decreases and is lower than the preset safety threshold, the trust revocation information is automatically broadcast to the remaining trust nodes in the distributed trust Internet of Things security system, and the revocation block is generated and synchronized to the distributed ledger, and the key right and communication right of the corresponding device are revoked, ensuring that only high-trust nodes participate in communication and consensus in the distributed trust Internet of Things security system.
[0075] The dynamic key update strategy has the following specific steps:
[0076] The trust value is used to dynamically adjust the frequency of node key update. The key update period of each node is calculated as follows:
[0077]
[0078] In the formula, U i is the key update period of node i, indicating how long the node needs to update the encryption key, the lower the trust value, the shorter the update period, λ is the preset maximum allowed update period, T max is the specified theoretical maximum trust value;
[0079] The lower the trust value, the shorter the key update period of the node, forcing the low-trust-value node to frequently update the key, thereby improving the control over abnormal nodes and reducing their potential security threats.
[0080] When the trust value fluctuates, the node resets the key according to the trust change amount and the current timestamp, and the session key update formula is as follows:
[0081]
[0082] In the formula, is the newly generated session key of node i, which will replace the old key for the next communication, HMAC SHA256 is the message authentication code (HMAC) algorithm based on SHA256, which provides high encryption strength and collision resistance, ensuring the security and unpredictability of the new key, is the current session key of node i, which serves as the basis for key update, ΔT i is the change amount of the trust value of node i, and ts is the current timestamp, which is used to ensure the uniqueness and timeliness of each update input and prevent replay attacks;
[0083] By incorporating the trust value change amount and the timestamp into the key update process, the entropy and unpredictability of the key are significantly enhanced, ensuring the security of the key in a dynamic trust environment.
[0084] If the trust value change of the node satisfies the following condition: ΔT i <- δ, when the trust value change amount ΔT iWhen the trust value is less than the negative security threshold - δ, where δ is a trust value drop threshold representing the maximum amplitude of a single drop of the trust value tolerated, and the trust value does not rise to the normal interval continuously for n rounds of detection, a key revocation process is triggered, the session key and all trust credentials of the node are directly revoked, the node is isolated and prohibited from continuing to participate in any Internet of Things communication and consensus process, and the current abnormal event is written into the distributed ledger as a security audit record, forming a complete event tracking record, thereby guaranteeing the overall security and traceability, where n is a round threshold of continuous detection, and the revocation mechanism is triggered only when the trust value is continuously below the threshold for more than n rounds, thereby avoiding misjudgment of normal nodes due to short-term fluctuations.
[0085] Embodiment one: In the Internet of Things environment, the construction of the trust initial node is the key to the establishment of the trust chain and the cold start of the trust mechanism. Especially in newly deployed Internet of Things networks, if there is a lack of secure initial trust source, the system will face high-risk threats such as injection of fake nodes and pollution of the initial trust chain. To effectively solve this problem, a physical unclonable feature (PUF) is used as the unique identity generation mechanism of the trust initial node, and the authenticity and unforgeability of the trust source are guaranteed by performing hardware-level security reinforcement on the core Internet of Things device. The specific implementation process is as follows: In the initial deployment stage, the system selects core nodes in the Internet of Things, such as gateways, management centers, industrial controllers, and master control units, as trust initial nodes, and embeds PUF circuits in the hardware design. PUF uses the small random differences in manufacturing processes to form an unpredictable and unclonable physical fingerprint as a unique physical identity of the device.
[0086] In the system initialization stage, the trust initial node accepts multiple rounds of challenge signals (Challenge) from the control center or other trust nodes, and the PUF circuit generates a unique and stable response (Response) according to the input signal. The control center or trust node compares the response result with the PUF signature information in the pre-registration database, and only when all challenge-response pairs pass the threshold tolerance test, the device is confirmed as a trust initial node. The authentication results of all verification processes, PUF signature digest, device identity information, and authentication timestamp are packaged into structured blocks and written into the distributed ledger for subsequent node security sharing.
[0087] During the network operation after the cold start, all new access devices need to be authenticated by PUF with at least one node in the initial trusted node set, and the device identity is confirmed bidirectionally. On the one hand, the initial node performs PUF authentication on the access device, and on the other hand, the new access device also confirms its identity through the PUF signature of the trusted initial node, forming a two-way trust, ensuring that both the access device and the trusted node are real, legal devices that have not been forged. Compared with the traditional one-way authentication, the two-way PUF authentication can significantly reduce the risk of being injected by a forged node in the cold start stage, and avoid the destruction of the trust root. At the same time, due to the physical unclonable nature, lightweight and low power consumption characteristics of PUF, it is particularly suitable for resource-constrained Internet of Things devices.
[0088] After completing the authentication, the trusted initial node distributes the initial trust value and the key to the new device as the credential for joining the trust chain, and records the authentication process in the distributed ledger. Through the above PUF authentication mechanism, the key problems such as trust root generation and forged node defense in the cold start process of the trust chain can be solved from the physical layer, laying a solid foundation for subsequent secure communication, consensus and key distribution of the system.
[0089] Embodiment two: The expansion ability and security of the trust mechanism are limited due to the lack of trust nodes in the cold start stage of the Internet of Things system. To solve this problem, the system designs a trust enhancement consensus mechanism to ensure that the trust chain can be safely and reliably expanded even in the case of insufficient initial trust nodes. Specifically, the system designs an improved Byzantine fault tolerance consensus mechanism based on the initial trust node set in the cold start stage, and the participating nodes include the initial nodes that pass the PUF authentication and the verified devices that subsequently access.
[0090] In the process of accessing the new device, it first needs to complete the PUF bidirectional authentication, and its identity is confirmed by at least one trusted initial node. After successful authentication, the new device does not become a trusted node immediately, but enters the trust enhancement consensus process. The consensus mechanism dynamically assigns an initial trust value to the new device by comprehensively analyzing the PUF authentication result of the new device, the behavior characteristics at the time of access (such as data interaction normality, communication channel stability, transmission delay, energy consumption characteristics, etc.), and the historical behavior of the device (such as the security self-check performed by the device in the local environment, communication behavior record).
[0091] The new device needs to participate in the trust enhancement consensus multiple times in the cold start stage, and the initial trust nodes in the system and the existing part of the verified nodes jointly score the behavior of the new device and initiate the consensus. The consensus adopts a weighted trust voting mechanism, and the higher the trust value of the participating node, the greater its voting weight, preventing a few attacked nodes from destroying the system security through consensus. In the consensus process, if the new device performs stably in multiple rounds of evaluation and meets the trust value promotion condition, its trust value is gradually increased, and finally it is formally included in the trust chain and obtains complete communication, consensus and key permissions.
[0092] The trust-enhanced consensus mechanism is particularly crucial in the cold start phase. It not only effectively filters new devices and prevents fake nodes from rapidly infiltrating the trust chain, but also records all the processes and results of participating in the consensus through a distributed ledger, forming a complete trust trajectory and improving the auditability and traceability of the system. Compared to the direct admission method of traditional trust chains, the present embodiment can significantly enhance the trust expansion capability and attack resistance of the Internet of Things system in the cold start phase.
[0093] Embodiment three: In the cold start phase of the Internet of Things trust system, the lack of initial trust may lead to a weak key distribution mechanism. If an attacker hijacks or forges a few nodes, it is easy to cause key leakage or trust chain pollution. Therefore, the system designs a trust value-driven dynamic key distribution and update mechanism, which combines the trust-enhanced consensus mechanism and the distributed ledger to achieve fine management of the key life cycle. This mechanism effectively improves the anti-forgery and anti-long-latency attack capabilities of the trust chain by dynamically adjusting the key distribution period, key length, and key usage permissions.
[0094] Specifically, when a new device becomes an official trusted node through the trust-enhanced consensus mechanism, the session key, data encryption key, and signature key it obtains are not fixed but directly related to its current trust value. Nodes with high trust values will obtain longer-period and higher-permission keys, while nodes with low trust values will obtain short-period and low-permission keys. The system periodically evaluates the trust values of all nodes in the network in real time. If a node's trust value decreases due to abnormal behavior, poor data consistency, distorted communication, or abnormal key usage, the system will automatically shorten its key validity period, or even revoke its communication key if the trust value falls below a security threshold.
[0095] At the same time, the system supports dynamic key updates. The key update process is initiated by the trust-enhanced consensus group, and a new key is generated using HMAC-SHA256 and the current trust value change and timestamp to ensure the uniqueness and dynamics of the updated key. After the update is complete, the new key and trust value change history are written as a new block into the distributed ledger for sharing and verification by all devices in the network, preventing malicious nodes from bypassing the key update mechanism. If a node's trust value continues to decline, the system will refuse its participation in subsequent key negotiation and simultaneously broadcast its key revocation information to the entire network, ensuring the security of the entire trust chain.
[0096] Through this mechanism, even in the case of insufficient trust nodes and immature trust chains during the cold start phase, layered key management based on trust values can be achieved, effectively preventing the problem of long-term latent attacks after a few nodes hijack the keys in the early stage. This mechanism is particularly important in the early stage of system deployment, dynamically restricting the communication permissions of new devices and low-trust nodes, and establishing a dynamic, secure, and flexible trust and key management system for the system.
[0097] The application effectively solves the problem of difficulty in establishing a trust root in the cold start stage of an Internet of Things system by introducing a trust initial node authentication mechanism based on a physical unclonable function (PUF). By integrating a PUF circuit in a core node, the natural uniqueness and unclonability of the PUF circuit are utilized to ensure the authenticity and unforgeability of the identity of the trust initial node, thereby eliminating the risk of a fake node infiltrating the system through initial trust authentication. Compared with a traditional trust root construction method based on software certificates or symmetric keys, the application can directly establish a trusted trust source at the hardware level, providing a secure and reliable foundation for subsequent Internet of Things device access, trust chain expansion, and secure communication, thereby significantly improving the cold start security of the trust mechanism.
[0098] The application avoids the security risks of fake devices and malicious nodes rapidly penetrating the system due to insufficient trust nodes in the cold start process of a traditional Internet of Things system by designing a trust-enhanced consensus mechanism based on the cooperation of trust initial nodes and verified nodes to dynamically evaluate and confirm the consensus of new devices in the early stage of access. The proposed trust-enhanced consensus mechanism not only considers the authenticity of the device's identity but also introduces dynamic trust indicators such as device access behavior, communication stability, and consensus participation quality, effectively improving the accuracy and security of the consensus. By combining dynamic trust value adjustment with consensus voting weight and transparently recording the consensus process in a distributed ledger, the ordered and secure expansion of the trust chain in the cold start stage is ensured, laying a solid foundation for subsequent large-scale device secure access.
[0099] The trust value-driven key dynamic distribution and update mechanism proposed by the application can flexibly control the key permissions and validity period based on the real-time trust value of the device, significantly improving the anti-attack capability of the Internet of Things system in the cold start and running processes. By directly associating the trust value with the key life cycle, key length, and communication permissions, the communication capability of low-trust or suspicious devices can be effectively limited, and the key of a malicious node can be automatically revoked when the trust value drops below a security threshold, preventing the malicious node from lingering for a long time before the trust chain stabilizes. Combined with security update mechanisms such as HMAC-SHA256, the dynamic and unique nature of the key is ensured, and all key update and revocation events can be traced and verified in the distributed ledger, thereby improving the defense capability and security stability of the system when facing attacks such as fake nodes, key hijacking, and trust pollution.
[0100] The application provides an Internet of Things encryption system combined with a distributed trust mechanism, as shown in Figure 2 The application provides an Internet of Things encryption system combined with a distributed trust mechanism, as shown in The application provides an Internet of Things encryption system combined with a distributed trust mechanism, as shown in
[0101] Trust initial node authentication module, establish a set of trusted initial nodes, use physical unclonable features to conduct physical layer security authentication on the core nodes of the Internet of Things, generate a unique node identity key, and register as a trusted node in the distributed ledger;
[0102] New device trust access module, when a new device accesses the Internet of Things network, complete the identity confirmation and trust relationship establishment of the new device through bidirectional identity authentication with at least one node in the set of trusted initial nodes;
[0103] Key distribution and trust chain establishment module, based on the trust relationship established between the new device and the trusted node, distribute encryption keys through a secure channel, and synchronize the key distribution process and the trust chain establishment process to the distributed ledger;
[0104] Trust-enhanced consensus and dynamic evaluation module, build a trust-enhanced consensus mechanism with trust initial nodes and verified devices as participants, dynamically update trust values and key validity, and real-time monitor node behavior anomalies;
[0105] Encrypted communication and security module, based on the trust chain and consensus results in the distributed ledger, encrypt the communication data between Internet of Things devices to ensure the confidentiality, integrity and non-repudiation of the data in the transmission process;
[0106] Dynamic trust management and key revocation module, during the operation of the device, continuously use the set of trust initial nodes to dynamically evaluate the trust of newly accessed devices in the distributed trust Internet of Things security system and update the keys, when the node trust value is found to be lower than the preset threshold, automatically revoke its communication rights and record the abnormal information in the distributed ledger.
[0107] The embodiment of the application provides an Internet of Things encryption method combined with a distributed trust mechanism, which is realized through the above-mentioned Internet of Things encryption system combined with a distributed trust mechanism, and the specific method and process of the Internet of Things encryption system combined with a distributed trust mechanism are described in the above-mentioned embodiment of the Internet of Things encryption method combined with a distributed trust mechanism, which will not be repeated here.
[0108] The above is only a specific embodiment of the application, but the protection scope of the application is not limited to this, any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the application, which should be covered in the protection scope of the application. Therefore, the protection scope of the application should be subject to the protection scope of the claims.
Claims
1. An Internet of Things encryption method combined with a distributed trust mechanism, characterized in that, The method comprises the following steps: Establish a set of trusted initial nodes, use physical unclonable features to perform physical layer security authentication on the core nodes of the Internet of Things, generate a unique node identity key, and register as trusted nodes in the distributed ledger; When a new device accesses the Internet of Things network, complete the identity confirmation and trust relationship establishment of the new device through bidirectional identity authentication with at least one node in the set of trusted initial nodes; Based on the trust relationship established between the new device and the trusted node, distribute the encryption key through the secure channel, and synchronize the key distribution process and the trust chain establishment process to the distributed ledger; A trust-enhanced consensus mechanism is constructed with the trusted initial nodes and verified devices as participants, which dynamically updates the trust value and key validity, and monitors the abnormal behavior of the nodes in real time; The trust-enhanced consensus mechanism is an improved asynchronous consensus protocol based on Byzantine fault tolerance. The trusted initial nodes and verified devices jointly participate in the consensus process. In each round of consensus process, the trust value of the node is dynamically calculated based on the historical behavior score of the device, the data transmission reliability and the key usage frequency. The device whose trust value is lower than the consensus threshold will be automatically excluded from the consensus participant nodes. All consensus results and trust value change history are stored on the chain to prevent malicious nodes from participating in the consensus process, and to improve the consensus security and stability; The specific steps of trust value dynamic updating and consensus voting weight calculation include: to ensure that the Internet of Things nodes can dynamically reflect their trustworthiness during long-term operation, a trust evaluation mechanism is established for each node to calculate the trust value. In the distributed consensus process, the voting weight of each node is dynamically determined according to its trust value. When the trust value fluctuation rate of the node in the continuous round consensus process meets the following conditions: that is, the trust value fluctuation variance is greater than the system preset safety threshold, it is determined that the node has abnormal behavior in recent behavior, and the related node needs to accept additional behavior analysis and multi-dimensional trust correction to ensure the stability and attack resistance of the consensus system; Based on the trust chain and consensus results in the distributed ledger, the communication data between the Internet of Things devices is encrypted to ensure the confidentiality, integrity and non-repudiation of the data in the transmission process; During the operation of the device, the set of trusted initial nodes continuously performs dynamic trust evaluation and key update on the newly accessed devices in the distributed trust Internet of Things security system. When it is found that the node trust value is lower than the preset threshold, the communication right of the node is automatically revoked and the abnormal information is recorded in the distributed ledger; The specific steps of the dynamic key update strategy are as follows: The update frequency of the node key is dynamically adjusted based on the trust value; When the trust value fluctuates, the node resets the key according to the trust change amount and the current timestamp, If the trust value of the node changes and meets the following conditions: when the amount of change of the trust value of the node is less than the negative security threshold, and the continuous If the wheel detection does not return to the normal range, the key revocation process is triggered, the session key and all trust credentials of the node are directly revoked, the node is isolated and prohibited from continuing to participate in any Internet of Things communication and consensus process, and the current abnormal event is written into the distributed ledger as a security audit record, forming a complete event tracking record, ensuring the overall security and traceability.
2. The IoT encryption method combined with a distributed trust mechanism according to claim 1, characterized in that, The physical unclonable function authentication process includes a verification operation through multiple rounds of challenge-response pairs. In each authentication process, the trust initial node sends a predefined physical property challenge signal to the device to be authenticated, the device to be authenticated responds through an internal unique PUF circuit and generates a unique response code, and the trust initial node compares the response code with the correct response code in the pre-stored original challenge response database. When the multiple rounds of responses all meet the consistency and stability thresholds, the device is confirmed as a trusted node, and the device ID, PUF signature, and authentication result are chained in the distributed ledger in the form of a structured transaction, ensuring that the authentication process is real, unforgeable, and traceable.
3. The IoT encryption method combined with a distributed trust mechanism according to claim 2, characterized in that, When a new device accesses, the two-way identity authentication process includes the new device and the trust initial node respectively initiating challenge verification based on asymmetric key encryption. Specifically, the new device signs the random challenge message sent by the trust node using its own private key, and the trust initial node verifies the signature result through the public key of the new device. At the same time, the trust initial node also needs to sign the challenge message of the new device using its own private key, and the new device verifies it in the same way. After both-way verification, the device identity is confirmed, and a block with timestamp and verification log is generated in the distributed ledger, ensuring the transparency and non-repudiation of the verification process.
4. The Internet of Things encryption method combined with a distributed trust mechanism according to claim 3, characterized in that, The establishment of a secure channel is based on the elliptic curve key agreement protocol. After completing the two-way identity authentication, the new device and the trust node respectively use the public key of the other party and their own private key to calculate the shared session key. The obtained session key is only valid for this session, and the encryption digest and negotiation state of the key negotiation are recorded in the distributed ledger. The negotiation process uses a time window control mechanism, and if it is not completed within the time limit, the key negotiation is forcibly interrupted to prevent man-in-the-middle attacks or delayed replay attacks.
5. The IoT encryption method combined with a distributed trust mechanism according to claim 4, characterized in that, The encryption process uses a combination of symmetric encryption and immutable blockchain recording. During the communication process between devices, the shared symmetric key confirmed by the trust enhancement consensus mechanism is first used to encrypt the transmitted data, and the receiving party decrypts it through the shared key. At the same time, both parties record the encryption digest, timestamp, and participating device identity information of this data communication on the distributed ledger, ensuring the confidentiality, integrity, and traceability of the data during transmission. The communication record cannot be tampered with, effectively addressing replay attacks and communication hijacking issues.
6. The Internet of Things encryption method combined with a distributed trust mechanism according to claim 5, characterized in that, The dynamic trust evaluation and key update mechanism includes a dynamic adjustment mechanism based on node trust values. The trust initial node periodically evaluates the trust values of all connected nodes in the distributed trust Internet of Things security system, considering the behavior consistency, data transmission quality, historical security events, and key usage of the devices. When the node trust value gradually decreases and falls below the preset security threshold, the trust revocation information is automatically broadcast to the remaining trust nodes in the distributed trust Internet of Things security system, and a revocation block is generated and synchronized to the distributed ledger. At the same time, the key permissions and communication permissions of the corresponding device are revoked, ensuring that only high-trust nodes participate in communication and consensus in the distributed trust Internet of Things security system.
7. An IoT encryption system incorporating a distributed trust mechanism for implementing the IoT encryption method of any one of claims 1-6, characterized by, The trust initial node authentication module, the new device trust access module, the key distribution and trust chain establishment module, the trust enhanced consensus and dynamic evaluation module, the encrypted communication and security guarantee module, and the dynamic trust management and key revocation module are included. The trust initial node authentication module establishes a set of trust initial nodes, performs physical layer security authentication on the Internet of Things core nodes by using physical unclonable features, generates a unique node identity key, and registers as a trusted node in a distributed ledger. The new device trust access module performs two-way identity authentication with at least one node in the set of trust initial nodes when a new device accesses the Internet of Things network, completes identity confirmation and trust relationship establishment of the new device. The key distribution and trust chain establishment module distributes encryption keys through a secure channel based on the trust relationship established between the new device and the trusted node, and synchronously records the key distribution process and the trust chain establishment process to the distributed ledger. The trust enhanced consensus and dynamic evaluation module constructs a trust enhanced consensus mechanism with trust initial nodes and verified devices as participants, dynamically updates trust values and key validity, and monitors node behavior abnormalities in real time. The encrypted communication and security guarantee module encrypts communication data between Internet of Things devices based on the trust chain and consensus results in the distributed ledger, ensuring the confidentiality, integrity, and non-repudiation of data during transmission. The dynamic trust management and key revocation module continuously evaluates the trust of newly accessed devices in the distributed trust Internet of Things security system and updates the keys using the set of trust initial nodes during device operation. When the node trust value is found to be lower than the preset threshold, the communication rights are automatically revoked and the abnormal information is recorded in the distributed ledger.
Citation Information
Patent Citations
Dual-master-node PBFT consensus method based on credit mechanism
CN117595998A
Distributed device identity authentication and access control method and system based on block chain
CN119363318A
Data asset transaction control method and device, decentralized PUF network and storage medium
CN119762070A