A cloud database key management method based on the Internet of Things
By leveraging the collaborative efforts of IoT device terminals, edge computing nodes, cloud databases, and blockchain networks, this approach addresses the shortcomings of traditional cloud database key management methods, such as insufficient real-time performance, inadequate privacy management, and insufficient security. It enables real-time data management and refined data protection for IoT devices, thereby improving the collaborative, real-time, and security aspects of key management.
Patent Information
- Application Number
- CN202510475567.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-04-16
AI Technical Summary
Traditional cloud database key management methods lack real-time performance, have insufficiently refined data privacy management, and are inadequate in terms of security and traceability. They are difficult to effectively manage the diversity of IoT devices and the real-time data collection needs, and there are security vulnerabilities in the key management process.
By working together with IoT device terminals, edge computing nodes, cloud databases, blockchain networks, and management consoles, data is collected in real time, data privacy assessment indicators are defined, key policies for different levels of privacy are generated, and the security and traceability of key management are ensured through the immutability of blockchain and smart contract technology.
It enables real-time data management and refined data protection for IoT devices, improves the collaboration, real-time performance, security and traceability of key management, and ensures the security and privacy of data throughout the entire process.
Smart Images

Figure CN120408662B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology, and more specifically, to a cloud database key management method based on IoT. Background Technology
[0002] With the rapid development of the Internet of Things (IoT) and cloud computing technologies, IoT connects various devices via the internet to achieve data collection and sharing, and is widely used in smart homes and smart cities. However, the sheer number and wide distribution of these devices make data security and privacy protection critical issues. Cloud computing provides powerful computing and storage capabilities, supporting the processing and analysis of large-scale data. However, data stored in the cloud faces security threats; therefore, key management is an effective technical means to protect data security. Key management includes the generation, storage, distribution, updating, and destruction of keys, and is the foundation of data encryption.
[0003] However, it still has some shortcomings in actual use. First, it lacks device collaboration and real-time performance. Traditional cloud database key management methods do not fully consider the diversity of IoT devices and the need for real-time data collection. The amount of data generated by IoT device terminals is huge and has strong real-time requirements. Traditional methods are difficult to effectively manage and control these devices and lack real-time performance.
[0004] Second, data privacy management is not refined enough. Traditional cloud database key management methods often consider data privacy in a relatively simple way, and may only classify data based on a few factors such as data type or access permissions, making it difficult to comprehensively and accurately assess the degree of data privacy.
[0005] Third, key management suffers from insufficient security and traceability. Traditional methods lack effective security guarantees and traceability mechanisms in the key management process. Security vulnerabilities may exist in the generation, distribution, and storage of keys, and once keys are leaked, it is difficult to quickly locate and trace the root cause of the problem. Summary of the Invention
[0006] In view of this, embodiments of the present invention provide a cloud database key management method based on the Internet of Things. By classifying the sensitivity of data, the privacy level of the data is determined, and corresponding key management strategies are adopted according to the privacy level of the data. Furthermore, by monitoring the running status of the key management process in real time, effective solutions are taken to effectively address the problems of lack of real-time performance, insufficient precision in data privacy management, and inadequate security raised in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a cloud database key management method based on the Internet of Things (IoT), comprising an IoT device terminal, an edge computing node, a cloud database, a blockchain network, and a management console, connected via the Internet, specifically including the following steps:
[0008] S1: System Initialization and Definition: Initialize the system, define data privacy assessment metrics, configure the blockchain network, deploy smart contracts, and assign identifiers;
[0009] S2: Data Collection and Evaluation: Collect data through IoT device terminals, classify the data according to privacy evaluation indicators, and attach privacy labels to the data;
[0010] S3: Key generation and distribution: Edge computing nodes generate key policies based on data privacy, securely distribute keys to IoT device terminals, and upload key metadata to the blockchain network;
[0011] S4: Data Encryption and Upload: The IoT device terminal uses the received key to encrypt the data and uploads the encrypted data to the edge computing node. The edge computing node processes the data and uploads it to the cloud database.
[0012] S5: Data Query and Recovery: The management console queries encrypted data through the cloud database, the edge computing node obtains key metadata from the blockchain network, decrypts the key, and uses the decryption key to decrypt the encrypted data;
[0013] S6: Audit Monitoring and Fault Tolerance: Real-time monitoring of key management operation status, calculation of key management comprehensive evaluation index, recovery of damaged keys, and recovery and encryption of lost data.
[0014] The technical effects and advantages of this invention are as follows:
[0015] 1. This invention employs the collaborative work of IoT device terminals and edge computing nodes to collect data from the device in real time, thereby tightly connecting the entire IoT device terminal with the key management system. This enables real-time data collection and participation in data privacy assessment, encryption, and other processes, achieving full-process secure management of data from generation to storage and improving device collaboration and real-time performance.
[0016] 2. This invention defines data privacy assessment indicators and divides data sensitivity into low sensitivity, medium sensitivity, and high sensitivity. It determines the scoring range and weight for different assessment indicators, generates different key strategies for data with different levels of privacy, and comprehensively considers multiple dimensions such as data source, purpose, and privacy to evaluate and generate more suitable key strategies, thus providing more refined data protection.
[0017] 3. This invention comprehensively and effectively reflects whether there are any abnormalities in the key management process by monitoring the key management operation status in real time and calculating the key management comprehensive evaluation index. By uploading the key metadata to the blockchain network, the distributed ledger and smart contract technology of the blockchain ensure the immutability and traceability of the key metadata. Through real-time monitoring of the key management operation status and uploading and processing of key metadata, the security and traceability of key management are improved. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the method steps of the present invention.
[0019] Figure 2 This is a schematic diagram of the system structure of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] As attached Figure 1 The method for managing cloud database keys based on the Internet of Things (IoT) includes IoT device terminals, edge computing nodes, cloud databases, blockchain networks, and management consoles, all connected via the Internet.
[0022] This embodiment specifically describes how the IoT device terminal connects to the edge computing node via wireless communication, and is responsible for data acquisition, data encryption, key reception and updating, and lightweight computing. Data acquisition refers to collecting data from sensors or actuators; data encryption refers to encrypting data using a locally stored symmetric key; key reception and updating refers to receiving and updating the encryption key from the edge computing node; and lightweight computing refers to performing simple encryption / decryption operations and communication protocol processing.
[0023] Edge computing nodes connect to IoT devices wirelessly, receiving device data and distributing keys. They also connect to cloud databases via the internet, uploading encrypted data, and connect to blockchain networks via the internet, uploading key metadata and operation logs. These nodes are responsible for key management, data processing, local storage and caching, blockchain interaction, and security authentication. Key management involves generating, distributing, and updating symmetric keys, as well as encapsulating and decapsulating them. Data processing involves verifying, indexing, and hashing the encrypted data uploaded by IoT devices. Local storage and caching temporarily stores keys and data to reduce cloud load. Blockchain interaction involves uploading key metadata and operation logs to the blockchain. Security authentication involves authenticating and controlling access to IoT devices.
[0024] The cloud database connects to edge computing nodes via the internet to receive encrypted data and connects to the management console via the internet to provide data query and management interfaces. It is primarily responsible for data storage, data querying, data backup and recovery, and access control. Data storage refers to storing encrypted data. Data querying refers to quickly retrieving data based on indexes and key identifiers. Data backup and recovery refers to regularly backing up data and supporting disaster recovery. Access control refers to authenticating permissions for the management console and data requests.
[0025] The blockchain network connects to edge computing nodes via the internet to receive key metadata and operation logs. It also connects to a management console via the internet to provide auditing and verification interfaces. Its main responsibilities include key metadata storage, operation log recording, decentralization and immutability, and audit support. Key metadata storage refers to storing the metadata and lifecycle information of the keys. Operation log recording refers to recording the operations of key generation, distribution, updating, and destruction. Decentralization and immutability refer to ensuring data transparency and security through a consensus mechanism. Audit support refers to providing immutable operation records to support security auditing.
[0026] The management console connects to the cloud database via the internet for querying and managing data, to the blockchain network via the internet for viewing operation logs and audit information, and to edge computing nodes via the internet for monitoring and managing key lifecycles. Its main responsibilities include key management, data management, auditing and monitoring, and user management. Key management involves monitoring the key lifecycle and manually triggering key updates or recovery operations. Data management involves querying and retrieving encrypted data stored in the cloud database, managing data backups and recovery. Auditing and monitoring involves viewing operation logs in the blockchain to ensure system security and monitor system operating status and performance metrics. User management involves managing administrator and user permissions and access controls.
[0027] For connection methods of the aforementioned IoT device terminals, edge computing nodes, cloud databases, blockchain networks, and management console, please refer to [link / reference]. Figure 2 .
[0028] The specific embodiments of the present invention include the following steps:
[0029] S1: System Initialization and Definition: Initialize the system, define data privacy assessment metrics, configure the blockchain network, deploy smart contracts, and assign identifiers.
[0030] Furthermore, the initialization process specifically includes component deployment and configuration, establishing secure channels, initializing the blockchain network, and configuring the management console.
[0031] This embodiment specifically describes the component deployment and configuration, which involves deploying IoT device terminals, edge computing nodes, a cloud database, a blockchain network, and a management console; configuring the communication protocols between these components; and assigning unique identifiers to all IoT devices and edge computing nodes within the IoT device terminal. Establishing a secure channel specifically refers to establishing a secure communication channel between IoT devices and edge computing nodes, and establishing secure connections between edge computing nodes and the cloud database and blockchain network. Blockchain network initialization specifically involves deploying smart contracts, storing key metadata and operation logs, and configuring the blockchain network's consensus mechanism and node permissions. Management console configuration specifically involves configuring user permissions and access control policies for the management console, setting up auditing and monitoring functions to ensure the system's visibility and transparency.
[0032] Furthermore, defining data privacy assessment metrics includes the following steps:
[0033] A1: Determine data privacy assessment indicators and determine data sensitivity classification;
[0034] This embodiment specifically explains that the data privacy assessment indicators are based on data type, data purpose, privacy, data risk, and legal compliance. Data type refers to the nature and content of the data; for example, environmental data is low-sensitivity data, device status data is medium-sensitivity data, and personal privacy data is high-sensitivity data. Data purpose refers to the scenario and purpose of data use; for example, internal monitoring and analysis is low-sensitivity data, and commercial use is medium-sensitivity data. Privacy refers to whether the data contains personally identifiable information or sensitive personal information; for example, data without personally identifiable information is low-sensitivity data, data containing personally identifiable information is medium-sensitivity data, and data containing sensitive personal information is high-sensitivity data. Data risk refers to the losses caused by data leakage or tampering; for example, low-risk data corresponds to low sensitivity, medium-risk data corresponds to medium sensitivity, and high-risk data corresponds to high sensitivity. Legal compliance refers to whether the data complies with relevant laws and regulations; for example, data that does not require special protection is low-sensitivity, data that requires general protection is medium-sensitivity, and data that requires strict protection is high-sensitivity.
[0035] A2: Set scoring criteria and define the scoring range and weight for different evaluation indicators;
[0036] This embodiment requires a specific explanation of the scoring criteria used to quantify data privacy. The scoring range for different evaluation indicators is determined to be 1-5, with low to high representing the level of data sensitivity. Weights are assigned to each evaluation indicator based on its importance, with a total weight of 1. For example, the weight coefficient for data type is 0.2, the weight coefficient for data usage is 0.2, the weight coefficient for privacy is 0.4, the weight coefficient for data risk is 0.1, and the weight coefficient for legal compliance is 0.1.
[0037] A3: Data privacy levels are determined based on weighted scoring results;
[0038] In this embodiment, it is necessary to specifically explain that the weighted score of the data to be rated is calculated according to the above scoring criteria, and the data privacy is divided into low privacy (1-2 points), medium privacy (2.1-3.5 points) and high privacy (3.6-5 points).
[0039] A4: Assign labels to privacy levels to facilitate system identification and processing.
[0040] This embodiment specifically explains the assignment of labels to privacy levels: "Low" for low privacy, "Medium" for medium privacy, and "High" for high privacy. This simplifies the data classification and management process, providing fundamental support for the system's security, efficiency, and scalability. Privacy labels also provide a basis for automated processing, allowing the system to automatically perform corresponding operations based on the labels, reducing manual intervention and improving efficiency.
[0041] S2: Data Collection and Evaluation: Collect data through IoT device terminals, classify the data according to privacy evaluation indicators, and attach privacy labels to the data.
[0042] Furthermore, data collection and evaluation specifically include collecting data through IoT devices in IoT device terminals, classifying the collected data according to predefined data privacy evaluation indicators, attaching corresponding privacy labels to the data according to data privacy, transmitting the data and privacy labels to edge computing nodes, and verifying the privacy labels.
[0043] This embodiment specifically illustrates that before data classification, the IoT device terminal needs to preprocess the collected data to ensure its integrity and consistency. This preprocessing includes data cleaning, data formatting, and data labeling. Verifying the privacy label involves the edge computing node receiving data from the IoT device terminal, which contains privacy labels. The edge computing node extracts the privacy labels from the received data and verifies their accuracy based on predefined privacy assessment metrics. The calculated privacy level is compared with the privacy label; if they match, the verification is successful; otherwise, it fails. Based on the verification result, the edge computing node takes corresponding corrective measures. If verification is successful, the edge computing node continues processing the data; if verification fails, the edge computing node records the failed data and the reason in a log, recalculates the privacy score based on the data attributes, and updates the privacy label.
[0044] S3: Key Generation and Distribution: Edge computing nodes generate key policies based on data privacy, securely distribute keys to IoT device terminals, and upload key metadata to the blockchain network.
[0045] Furthermore, the generation of key policies specifically refers to generating different key policies for data with different levels of privacy. For low-privacy data, a unified symmetric key is used to encrypt the low-privacy data, and the key is updated monthly. For medium-privacy data, an independent symmetric key is assigned to each device, and the key is updated weekly. For high-privacy data, an independent symmetric key is assigned to each piece of data, the key is updated once per session, and the symmetric key is encapsulated and distributed in combination with asymmetric encryption.
[0046] This embodiment specifically describes how to generate symmetric keys, such as AES-128, for low-privacy data, distribute these keys to all relevant IoT devices, and upload the key metadata to the blockchain network. For medium-privacy data, a unique symmetric key, such as AES-192, is generated for each group of devices. This symmetric key is encapsulated using the device's public key and securely distributed to the devices, with the key metadata uploaded to the blockchain network. For high-privacy data, a unique symmetric key, such as AES-256, is generated for each data entry. This symmetric key is encapsulated using the device's public key and securely distributed to the devices, with the key metadata uploaded to the blockchain network. This facilitates refined security control, optimizes resource allocation efficiency, and reduces storage costs.
[0047] S4: Data Encryption and Upload: The IoT device terminal uses the received key to encrypt the data and uploads the encrypted data to the edge computing node. The edge computing node processes the data and uploads it to the cloud database.
[0048] Furthermore, data encryption and uploading include IoT device terminals receiving and storing keys, continuously collecting data, encrypting the data, and uploading it to edge computing nodes. Edge computing nodes receive encrypted data from IoT device terminals, generate an index for the encrypted data based on the received data metadata, and calculate a hash value for the encrypted data. The edge computing nodes then upload the encrypted data, the generated index, and the calculated hash value to the cloud database. The cloud database receives the data uploaded by the edge computing nodes via the internet, verifies the data, checks the data format to ensure the data originates from a legitimate edge computing node, and stores the verified data in the cloud database.
[0049] This embodiment specifically describes how the IoT device terminal securely stores the received key in its internal secure storage area, such as a chip with encryption capabilities, to prevent unauthorized access. The encrypted data is then uploaded to the edge computing node. During the upload process, to ensure the integrity and reliability of data transmission, the device encapsulates the encrypted data, adding necessary metadata such as device identifier, data type, and timestamp. The edge computing node parses the received message, extracting the encrypted data and related metadata. A data index is used for quick data location and retrieval in the cloud database. Storing the verified data in the cloud database facilitates subsequent queries and use.
[0050] S5: Data Query and Recovery: The management console queries encrypted data through the cloud database, the edge computing node obtains key metadata from the blockchain network, decrypts the key, and uses the decryption key to decrypt the encrypted data.
[0051] Furthermore, data querying and recovery specifically includes the following steps:
[0052] B1: Based on business needs, the operator of the management console enters the query conditions in the management console. The management console encapsulates the query conditions and sends the query request to the cloud database through a secure communication protocol. The cloud database receives the query request from the management console, verifies the request, and after successful verification, the cloud database retrieves data according to the query conditions, encapsulates the retrieved encrypted data and related cloud data, and returns it to the management console.
[0053] In this embodiment, it should be specifically noted that the query conditions in the above steps can be device ID, data time range, and data type information. For example, in factory management, if an employee wants to query the encrypted operating status data of a certain device for the past week, they would enter the device ID "DEVICE1" and the time range "2025-02-01 to 2025-02-07" in the management console, and then click the query button. The query request in the above steps should include the authentication information of the management console, such as data certificates and API keys, to ensure the legitimacy of the query request.
[0054] B2: After receiving the encrypted data returned by the cloud database, the management console sends instructions to the edge computing node to decrypt the data and unblock the key. The instructions should contain key information related to the encrypted data. After receiving the instructions from the management console, the edge computing node constructs a query request to the blockchain network based on the instruction information. The blockchain network finds the corresponding key metadata based on the request and passes it to the edge computing node.
[0055] In this embodiment, it should be specifically noted that the key information included in the instructions in the above steps can be the device ID and data timestamp, which facilitates the edge computing node to accurately obtain the corresponding key metadata. The blockchain network stores metadata related to the key, such as the key's generation time, update records, key version number, and encryption algorithm.
[0056] B3: The edge computing node determines the key version and corresponding encryption algorithm based on the received key metadata, retrieves the encrypted key block from local and other secure storage locations, and decrypts the encrypted key.
[0057] In this embodiment, it should be specifically noted that the key metadata in the above steps can use the AES-256 encryption algorithm, and the key is stored in blocks using a specific encryption algorithm. The key blocks may be stored in the secure hard disk partition of the edge computing node, and each key block has a corresponding identifier. For example, the meta-computing node reads the corresponding encrypted key block based on the key block identifier in the key metadata.
[0058] S6: Audit Monitoring and Fault Tolerance: Real-time monitoring of key management operation status, calculation of key management comprehensive evaluation index, recovery of damaged keys, and recovery and encryption of lost data.
[0059] Furthermore, obtaining the key management operation status requires real-time monitoring of operation status parameters, specifically including the key usage frequency f1 of IoT device terminals, the key decryption efficiency η1, data processing latency t, and node load rate η2 of edge computing nodes, the data access frequency f2 of cloud databases, and the number of database connections X. The comprehensive evaluation index of key management is obtained by processing the operation status parameters.
[0060] In this embodiment, it is necessary to specifically explain the following: Key usage frequency refers to the number of times IoT devices use a key to encrypt or decrypt data per unit time, reflecting the actual usage of the key; Key decryption efficiency refers to the average time for edge computing nodes to obtain key metadata from the blockchain network and decrypt the key, measuring the node's key processing capability; Data processing latency refers to the time recorded for edge computing nodes to process encrypted data; excessive latency may affect the overall system performance; Node load rate refers to the usage of resources including CPU, memory, and storage, obtained through the node's system monitoring tools; excessive load may cause the node to run slowly or even malfunction; Data access frequency refers to the number of times encrypted data is queried or read from the cloud database per unit time, reflecting the data usage frequency; excessive access frequency may affect database performance; Database connection count refers to the number of current connections established with the cloud database; too many connections may lead to a decrease in database performance, which can be obtained through database management tools.
[0061] Furthermore, obtaining the key management comprehensive evaluation index requires setting a time interval and dividing it into unit sub-time intervals according to the same time interval division method, labeled as 1, 2, ..., i, ..., n respectively, and collecting the key usage frequency f in any sub-time interval. 1i The IoT device terminal management evaluation index K is obtained by summing the key usage frequencies in any sub-time region and dividing by n, and then dividing by the maximum key usage frequency. I The key decryption efficiency η within any sub-time region is collected. 1i Data processing delay time t i and node load rate η 2i The average key decryption efficiency, average data processing latency, and average node load rate are calculated, along with their corresponding maximum values η. 1max t max and η 2max Using the formula
[0062] The edge computing node management evaluation index K was calculated. e Where ω1, ω2, and ω3 represent the weighting coefficients of key decryption efficiency, data processing latency, and node load rate, respectively, and their sum is 1; and the data access frequency f within any sub-time region is collected. 2i Number of database connections X i The average data access frequency and the average number of database connections were calculated, along with the corresponding maximum data access frequency f. 2max Maximum number of database connections X max and using the formula
[0063] The cloud database management evaluation index K was calculated. c Where ρ1 and ρ2 represent the weighting coefficients of data access frequency and database connection quantity, respectively, and their sum is 1. The IoT device terminal management evaluation index, edge computing node management evaluation index, and cloud database management evaluation index are substituted into the formula.
[0064] The key management comprehensive evaluation index RSI is calculated, where μ1, μ2, and μ3 represent the weight coefficients of the IoT device terminal management evaluation index, the edge computing node management evaluation index, and the cloud database management evaluation index, respectively, and the sum is 1.
[0065] This embodiment requires specific explanation regarding the setting of the aforementioned weighting coefficients. These coefficients should be set by staff during operation and should be considered in relation to the impact of various parameters from IoT device terminals, edge computing nodes, and cloud databases on key management performance. A comprehensive key management evaluation index is used to determine if problems have occurred in the key management process and to collect corresponding solutions. For example, a low key decryption efficiency parameter value may indicate a problem in the key decryption process, requiring further investigation of the connection between the edge computing node and the blockchain network.
[0066] This embodiment requires a detailed explanation of how determining the location of the corrupted key involves analyzing log information and monitoring data from relevant components such as IoT device terminals, edge computing nodes, and blockchain networks. This determines whether the corrupted key was lost or damaged during storage, transmission, or due to a problem during transmission. Based on the monitoring parameters of the cloud database, it is determined whether the lost data was lost during the upload to the cloud database or due to a problem during storage. Data is then restored from backups, and the lost data is regenerated using data redundancy and reconstruction mechanisms.
[0067] Secondly: The accompanying drawings of the embodiments disclosed in this invention only involve the structures involved in the embodiments disclosed in this invention. Other structures can refer to the general design. In the absence of conflict, the same embodiment and different embodiments of this invention can be combined with each other.
[0068] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A cloud database key management method based on the Internet of Things, characterized in that, This includes IoT device terminals, edge computing nodes, cloud databases, blockchain networks, and management consoles, connected via the internet, specifically including the following steps: S1: System Initialization and Definition: Initialize the system, define data privacy assessment metrics, configure the blockchain network, deploy smart contracts, and assign identifiers; S2: Data Collection and Evaluation: Collect data through IoT device terminals, classify the data according to privacy evaluation indicators, and attach privacy labels to the data; S3: Key generation and distribution: Edge computing nodes generate key policies based on data privacy, securely distribute keys to IoT device terminals, and upload key metadata to the blockchain network; S4: Data Encryption and Upload: The IoT device terminal uses the received key to encrypt the data and uploads the encrypted data to the edge computing node. The edge computing node processes the data and uploads it to the cloud database. S5: Data Query and Recovery: The management console queries encrypted data through the cloud database, the edge computing node obtains key metadata from the blockchain network, decrypts the key, and uses the decryption key to decrypt the encrypted data; S6: Audit Monitoring and Fault Tolerance: Real-time monitoring of key management operation status, calculation of key management comprehensive evaluation index, recovery of damaged keys, and recovery and encryption of lost data; The acquisition of the key management comprehensive evaluation index requires setting a time interval and dividing it into unit sub-time regions according to the method of dividing time regions equally, labeled as 1, 2, ..., i, ..., n respectively, and collecting the key usage frequency f in any sub-time region. 1i The IoT device terminal management evaluation index K is obtained by summing the key usage frequencies in any sub-time region and dividing by n, and then dividing by the maximum key usage frequency. I The key decryption efficiency η within any sub-time region is collected. 1i Data processing delay time t i and node load rate η 2i The average key decryption efficiency, average data processing latency, and average node load rate are calculated, along with their corresponding maximum values η. 1max t max and η 2max Using the formula The edge computing node management evaluation index K was calculated. e Where ω1, ω2, and ω3 represent the weighting coefficients of key decryption efficiency, data processing latency, and node load rate, respectively, and their sum is 1; and the data access frequency f within any sub-time region is collected. 2i Number of database connections X i The average data access frequency and the average number of database connections were calculated, along with the corresponding maximum data access frequency f. 2max Maximum number of database connections X max and using the formula The cloud database management evaluation index K was calculated. c Where ρ1 and ρ2 represent the weighting coefficients of data access frequency and database connection quantity, respectively, and their sum is 1. The IoT device terminal management evaluation index, edge computing node management evaluation index, and cloud database management evaluation index are substituted into the formula. The key management comprehensive evaluation index RSI is calculated, where μ1, μ2, and μ3 represent the weight coefficients of the IoT device terminal management evaluation index, the edge computing node management evaluation index, and the cloud database management evaluation index, respectively, and the sum is 1.
2. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The initialization system specifically includes component deployment and configuration, establishment of secure channels, blockchain network initialization, and management console configuration.
3. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The definition of data privacy assessment metrics includes the following steps: A1: Determine data privacy assessment indicators and determine data sensitivity classification; A2: Set scoring criteria and define the scoring range and weight for different evaluation indicators; A3: Data privacy levels are determined based on weighted scoring results; A4: Assign labels to privacy levels to facilitate system identification and processing.
4. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The data collection and evaluation specifically includes collecting data through IoT devices in IoT device terminals, classifying the collected data according to predefined data privacy evaluation indicators, attaching corresponding privacy labels to the data according to data privacy, transmitting the data and privacy labels to edge computing nodes, and verifying the privacy labels.
5. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The generation of the key policy specifically refers to generating different key policies for data with different levels of privacy. For low-privacy data, a unified symmetric key is used to encrypt the low-privacy data, and the key is updated monthly. For medium-privacy data, an independent symmetric key is assigned to each device, and the key is updated weekly. For high-privacy data, an independent symmetric key is assigned to each piece of data, the key is updated once per session, and the symmetric key is encapsulated and distributed in combination with asymmetric encryption.
6. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The data encryption and uploading process includes the IoT device terminal receiving and storing keys, continuously collecting data, encrypting the data, and uploading the data to the edge computing node; the edge computing node receives the encrypted data from the IoT device terminal, generates an index for the encrypted data based on the received data metadata, calculates the hash value of the encrypted data, and uploads the encrypted data, the generated index, and the calculated hash value to the cloud database. The cloud database receives data uploaded by edge computing nodes via the Internet, verifies and checks the data format to ensure that the data comes from legitimate edge computing nodes, and stores the verified data in the cloud database.
7. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The data query and recovery process specifically includes the following steps: B1: According to business needs, the operator of the management console enters the query conditions in the management console. The management console encapsulates the query conditions and sends the query request to the cloud database through a secure communication protocol. The cloud database receives the query request from the management console, verifies the request, and after successful verification, the cloud database retrieves data according to the query conditions, encapsulates the queried encrypted data and related cloud data, and returns it to the management console. B2: After receiving the encrypted data returned by the cloud database, the management console sends instructions to the edge computing node to decrypt the data and unblock the key. The instructions should contain key information related to the encrypted data. After receiving the instructions from the management console, the edge computing node constructs a query request to the blockchain network based on the instruction information. The blockchain network finds the corresponding key metadata based on the request and passes it to the edge computing node. B3: The edge computing node determines the key version and corresponding encryption algorithm based on the received key metadata, retrieves the encrypted key block from local and other secure storage locations, and decrypts the encrypted key.
8. The cloud database key management method based on the Internet of Things according to claim 1, characterized in that: The acquisition of the key management operation status requires real-time monitoring of operation status parameters, specifically including the key usage frequency f1 of IoT device terminals, the key decryption efficiency η1, data processing latency t, and node load rate η2 of edge computing nodes, the data access frequency f2 of cloud databases, and the number of database connections X. The comprehensive evaluation index of key management is obtained by processing the operation status parameters.
Citation Information
Patent Citations
Internet-of-things-oriented edge duplicate removal and privacy protection entrusted audit management method and system
CN119814304A