Internet of Things equipment authentication method and device, electronic equipment and storage medium
Through the dynamic pseudonym and Pederson commitment mechanism combined with blockchain, the problem of privacy exposure in the IoT device collaboration training model is solved, device identity anonymization and data privacy protection are realized, and device identity authentication is not directly exposed.
Patent Information
- Application Number
- CN202510723297.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-01
AI Technical Summary
IoT devices have privacy exposure problems when collaboratively training models, especially under centralized architecture, heterogeneity and unreliable wireless communications, single point of failure and identity privacy leakage are at high risk, affecting the performance of the global model.
Dynamic pseudonym technology is used to combine Pederson's commitment and blockchain to generate pseudonyms through trusted central institutions, realize the anonymization of IoT device identity, and verified binding of data ownership to ensure that the authentication of device identity and permissions does not directly expose the data.
The identity anonymization of IoT devices is realized, ensuring that devices perform identity and permission authentication without directly exposing data, and improving privacy and security.
Smart Images

Figure CN120415869A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and in particular, to an authentication method, device, electronic device, and storage medium for Internet of Things devices. Background Art
[0002] The development of the Internet of Things (IoT) has made human life more intelligent, and the interconnection of all things has become a reality. Federated learning enables IoT devices to collaboratively train models without sharing local data. However, due to the centralized architecture, heterogeneity of IoT devices, and unreliable wireless communication, risks such as single-point failures, identity privacy leakage, and model parameter inference attacks may occur, which damage the performance of the global model. The decentralization and verifiability of blockchain provide a solution idea for secure federated learning, but its transparency still leads to the problem of privacy exposure. Summary of the Invention
[0003] The present invention provides an authentication method, device, electronic device, and storage medium for Internet of Things devices, which are used to solve the defect of privacy exposure caused by collaborative training of IoT devices in the prior art, realize dynamic pseudonyms to anonymize the identities of IoT devices, and combine Pedersen commitments and blockchain to perform verifiable binding of data ownership, ensuring the authentication of device identities and permissions without directly exposing the data.
[0004] The present invention provides an authentication method for Internet of Things devices, which is applied to an authentication system. The authentication system includes a trusted central authority, Internet of Things devices, edge servers, and a blockchain. The method includes: When a target edge server receives a shared data request sent by a target Internet of Things device, the target edge server transmits the first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things devices; the target Internet of Things device is a device that initiates a model training request in the Internet of Things devices, and the target edge server is an edge server associated with the target Internet of Things device; When the candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, the candidate Internet of Things device encrypts the pseudonym of the candidate Internet of Things device based on a first secure hash function, the first data set type, a first public key corresponding to a candidate edge server, and a first random number to obtain a first ciphertext; the first random number and the first public key are determined based on a multiplicative group determined by the trusted central authority; The candidate Internet of Things device sends the first random number, the first ciphertext, the first signature of the first authentication information, and the first moment to the corresponding candidate edge server; the first authentication information includes the first random number, the pseudonym of the candidate Internet of Things device, and the first moment, and the first moment is the moment when the candidate Internet of Things device sends the first ciphertext, the first random number, and the first signature. When the difference between the first moment and the second moment is less than a threshold, the candidate edge server decrypts the first ciphertext based on the first secure hash function, the first random number, and the first private key corresponding to the edge server to obtain the decrypted pseudonym of the candidate Internet of Things device; the second moment is the moment when the candidate edge server receives the first random number, the first ciphertext, the first signature, and the first moment; the first private key is determined based on the multiplicative group. The candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the Internet of Things device parameters in the blockchain.
[0005] The present invention also provides an Internet of Things device authentication apparatus, including the following modules: The first transmission module is configured to, when a target edge server sends a shared data request to a target Internet of Things device, transmit the first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things device; the target Internet of Things device is the device that initiates a model training request in the Internet of Things device, and the target edge server is the edge server associated with the target Internet of Things device. The encryption module is configured to, when the candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, encrypt the pseudonym of the candidate Internet of Things device based on a first secure hash function, the first data set type, the first public key corresponding to the candidate edge server, and a first random number to obtain a first ciphertext; the first random number and the first public key are determined based on a multiplicative group determined by a trusted central authority. The second transmission module is configured to, when the candidate Internet of Things device sends the first random number, the first ciphertext, the first signature of the first authentication information, and the first moment to the corresponding candidate edge server; the first authentication information includes the first random number, the pseudonym of the candidate Internet of Things device, and the first moment, and the first moment is the moment when the candidate Internet of Things device sends the first ciphertext, the first random number, and the first signature. A decryption module, configured to decrypt the first ciphertext based on the first secure hash function, the first random number, and the first private key corresponding to the edge server when the difference between the first moment and the second moment of the candidate edge server is less than a threshold, so as to obtain the decrypted pseudonym of the candidate Internet of Things device; the second moment is the moment when the candidate edge server receives the first random number, the first ciphertext, the first signature, and the first moment; the first private key is determined based on the multiplicative group; An authentication module, configured to authenticate the candidate Internet of Things device by the candidate edge server based on the decrypted pseudonym, the Pedersen commitment mechanism, and the Internet of Things device parameters in the blockchain.
[0006] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, the Internet of Things device authentication method described in any one of the above is implemented.
[0007] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the Internet of Things device authentication method described in any one of the above is implemented.
[0008] The present invention further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the Internet of Things device authentication method described in any one of the above is implemented.
[0009] The Internet of Things device authentication method, device, electronic device and storage medium provided by the present invention, when a target edge server sends a shared data request to the target edge server, transmits the first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things device; when the candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, encrypts the pseudonym of the candidate Internet of Things device based on the first secure hash function, the first data set type, the first public key corresponding to the candidate edge server and the first random number to obtain a first ciphertext; the candidate Internet of Things device sends the first random number, the first ciphertext, the first signature of the first authentication information and the first moment to the corresponding candidate edge server; when the difference between the first moment and the second moment is less than a threshold, the candidate edge server decrypts the first ciphertext based on the first secure hash function, the first random number and the first private key corresponding to the edge server to obtain the decrypted pseudonym of the candidate Internet of Things device, and the candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, the Pedersen commitment mechanism and the Internet of Things device parameters in the blockchain. In this way, the identity anonymization of Internet of Things devices is achieved through dynamic pseudonyms, and the data ownership is verifiably bound by combining Pedersen commitments and blockchains, ensuring that devices do not directly expose data and realizing the privacy of device identity and permission authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0011] Figure 1 It is a schematic flowchart of the Internet of Things device authentication method provided by the present invention.
[0012] Figure 2 It is a schematic structural diagram of the Internet of Things device authentication device provided by the present invention.
[0013] Figure 3 It is a schematic structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0014] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.
[0015] First, the following terms are explained: Trusted Central Authority (TCA): The TCA is a trusted entity responsible for registering entities within the system. It generates pseudonyms for Internet of Things devices and ensures the traceability of malicious behaviors simultaneously.
[0016] Target Internet of Things device, i.e., data user: The data user is an individual with specific data sharing requirements. They often initiate requests through Internet of Things devices and select corresponding devices to participate in model training according to the type and quality of the data.
[0017] Candidate Internet of Things device, i.e., data owner: The data owner is an Internet of Things device with data collection capabilities. They can submit data sharing requests to nearby edge servers to participate in collaborative model training. During the node selection phase, the data owner can use a part of the local dataset for preliminary local training and send the training status to the edge server.
[0018] Edge Server (ES): As a key component of edge computing, the ES has greater computing and storage capabilities than Internet of Things devices. After receiving a data sharing request, the ESs authenticate the set of data owners having relevant data. Then, the ES near the data user selects entities for model training using a node selection method. Finally, it aggregates the model parameters and returns the result to the data user.
[0019] Blockchain: The blockchain is responsible for recording data, completing model interaction and device identity information query through smart contracts, and ensuring that the data is not tampered with.
[0020] Figure 1 is a schematic flowchart of the authentication method for Internet of Things devices provided by the present invention. As Figure 1 shown, this method is applied to an authentication system, and the authentication system includes a trusted central authority, Internet of Things devices, edge servers, and a blockchain, and includes: Step 101: When the target edge server receives a shared data request from the target Internet of Things device, the target edge server transmits the first dataset type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things device.
[0021] Among them, the target Internet of Things device is the device that initiates a model training request among the Internet of Things devices, and the target edge server is the edge server associated with the target Internet of Things device.
[0022] Here, the first dataset type includes, but is not limited to, weather datasets, temperature datasets, road datasets, etc.
[0023] It should be noted that the method by which the target Internet of Things device transmits the first dataset type to the candidate Internet of Things device can be that the target Internet of Things device transmits the type to the nearby edge server, the edge server uploads it to the blockchain, and after the candidate edge server queries the data type, it sends it to the candidate Internet of Things device.
[0024] Here, the candidate Internet of Things device refers to an Internet of Things device that may participate in model training. It should be understood that an Internet of Things device participating in model training needs to have data of the dataset type required by the target Internet of Things device.
[0025] In another embodiment of the invention, when the target Internet of Things device wants to share data, it sends a data sharing request to the target edge server in the attachment In addition to the first dataset type, the data sharing request may also send a request flag, a pseudonym of the target Internet of Things device, and an initial global model.
[0026] Exemplarily, the data sharing request , where , and are the sharing request flag, the data type, and the initial global model respectively. After receiving the request, the public key of the target Internet of Things device is obtained by querying in the blockchain according to the pseudonym of the target Internet of Things device , and the target edge server publishes a data sharing message . Other edge servers ES will broadcast it to nearby Internet of Things devices. Broadcast to nearby Internet of Things devices.
[0027] Step 102: When the candidate Internet of Things device receives the model training request sent by the target edge server and has data corresponding to the first dataset type, it encrypts the pseudonym of the candidate Internet of Things device based on the first secure hash function, the first dataset type, the first public key corresponding to the candidate edge server, and the first random number to obtain the first ciphertext.
[0028] Among them, the first random number and the first public key are determined based on the multiplicative group determined by the trusted central authority.
[0029] It should be noted that the first secure hash function can be selected by the TCA, and the first secure hash function can be , where represents the number of cycles of prime order , represents the multiplicative group modulo .
[0030] The method for determining the first random number can be randomly selected by the candidate IoT device , or can be calculated according to obtained .
[0031] It should be noted that the first public key and the first private key corresponding to the candidate edge server can be pre-determined by the trusted central authority based on the multiplicative group .
[0032] Exemplarily, before transmitting the first data set type required by the target IoT device to the candidate IoT devices other than the target IoT device, the method further includes: the trusted central authority selects at least one fourth random number from the multiplicative group as the private key of each edge server; the private key of each edge server includes the first private key of the candidate edge server; the trusted central authority determines the public key corresponding to each edge server based on the private key of the edge server and the first generator; the public key corresponding to each edge server includes the first public key of the candidate edge server; the trusted central authority sends the private key of each edge server and the public key corresponding to each edge server to the corresponding edge server; the trusted central authority determines the first secure hash function, the second secure hash function, the third secure hash function, the fourth secure hash function, and the fifth secure hash function.
[0033] It should be noted that before authenticating the IoT device, the trusted central authority needs to initialize the system, that is, determine the system parameters , where and are two generators of G, are 5 secure hash functions, is the public key of the trusted central authority, and is equal to , is the private key selected by the trusted central authority from the multiplicative group, that is . The trusted central authority selects random numbers as the private key of the edge server that is i.e. , calculate to obtain the public key of the edge server , the trusted central authority randomly generates as an identifier. Finally, will be sent to the corresponding , will be made public.
[0034] Exemplarily, the second secure hash function is , the third secure hash function function is , the fourth secure hash function is , the fifth secure hash function is .
[0035] Here, the method for determining the first ciphertext can be any suitable method. For example, it can be obtained through a preset mapping relationship, or through a calculation formula.
[0036] Exemplarily, encrypting the pseudonym of the candidate Internet of Things device can be as follows in formula (1): (1) Wherein, represents the first ciphertext, represents the first secure hash function, represents the first random power of the public key of the edge server, represents the first random number, represents the data set type, represents the concatenation symbol, represents the addition symbol.
[0037] In the embodiments of the present invention, by pre-initializing parameters such as keys and secure hash functions for the trusted central authority, it is ensured that the device does not directly expose data, and the privacy of the authentication of the device identity and permissions is realized.
[0038] Further, after the trusted central authority initializes the system, it is also necessary to register the Internet of Things devices. The following is the method for the trusted central authority to register the Internet of Things devices: After the trusted central authority sends the private key of each edge server and the public key corresponding to each edge server to the corresponding edge server, the method further includes: The Internet of Things device selects at least one fifth random number from the multiplicative group, and respectively determines the private key of each Internet of Things device and the public key of each Internet of Things device based on each fifth random number and the first generator; The public key of each Internet of Things device includes the second public key; The Internet of Things device determines a type-binding random factor corresponding to the data set type based on the fourth secure hash function, the identity identifier of the Internet of Things device, the first random number array, and the data set type; The first random number array is randomly selected from the multiplicative group, and the number of the first random number array is the number of types of the data set type; The Internet of Things device determines a first Pedersen commitment result based on the Pedersen commitment, the first generator, the second generator, the type-binding random factor, and the data set type identifier; The Internet of Things device encrypts the type-binding random factor and the data set type identifier based on the first secure hash function, the public key of the edge server, the second random number array, and the data set type, to obtain a seventh random number and a fifth ciphertext; And sends the real identity of the Internet of Things device, the public key of the Internet of Things device, the seventh random number, the fifth ciphertext, a proof representing the data set type of the Internet of Things device, and a registration request to the trusted central authority; In the case where the Internet of Things device is not registered, the trusted central authority decrypts the fifth ciphertext based on the first secure hash function, the private key of the edge server, the seventh random number, and the data set type, to obtain the decrypted data set type identifier and the decrypted type-binding random factor; The trusted central authority verifies and registers the Internet of Things device based on the decrypted data set type identifier, the decrypted type-binding random factor, the Pedersen commitment mechanism, and the fifth secure hash function.
[0039] It should be noted that the Internet of Things device is registered through the TCA. Due to the heterogeneity of the Internet of Things devices, the data collected by different devices may belong to different fields, different distributions, and even have different labels or feature dimensions. Therefore, the type of the data set is divided into types. Let the data set type identifier become whether there is a data set of a specific data type (0 means no, 1 means yes), where . Before the Internet of Things device is registered, the TCA selects a session key between devices from the selected multiplicative group, that is .
[0040] Randomly select the fifth random number as the private key of the Internet of Things device That is , according to Calculate the public key of the Internet of Things device, that is , and randomly generate random numbers , denote the first random number array, denote the second random number array. Then, for each data set type , Calculate the type-bound random factor as the following formula (2): (2) Where denotes the fourth secure hash function, denotes the identity identifier of the Internet of Things device, denotes the first random number array.
[0041] Furthermore, calculate the first Pedersen commitment result as follows formula (3): (3) For , The encryption method is as follows formula (4): (4) Where denotes the seventh random number, denotes the fifth ciphertext, denotes the second random number, denotes the second random number array to the power of the public key of the edge server. Let the first set . Send to the TCA through a secure channel, where is 's real identity, is 's proof of having the data type , is the registration request.
[0042] When the TCA receives the registration request, perform the following verification: First, the TCA checks whether it has been registered. If not registered, for each data set type , the TCA decrypts the seventh random number and the fifth ciphertext, and the decryption formula is as follows (5): (5) Where Indicates the decrypted dataset type identifier, Indicates the type-bound random factor after decryption. According to the Pedersen commitment mechanism Calculate the Pedersen commitment result after decryption If the Pedersen commitment result after decryption is equal to the first Pedersen commitment result, TCA checks according to Check Whether it is correct. After verifying the identity, TCA randomly selects as the pseudonym of and generates the homomorphic (Paillier) public key and Paillier private key . Then, TCA selects a random number , calculates the random number , and encrypts as the following formula (6): (6) where represents the decryption result, represents the fifth secure hash function, and TCA sends to through a secure channel.
[0043] Next, verifies whether holds. If it holds, locally saves . Otherwise, will send the registration application again.
[0044] TCA sends the message to , where is the signature of the message by TCA, and the fifth moment represents the moment when TCA sends the message. At the sixth moment receives the message. After verifying the signature according to , when checking that is less than the threshold and holds, submits to the blockchain through the AddDevice() method. Among them, is the registration time of the device. After the registration information is successfully added, returns a notification of successful transaction to .
[0045] In the embodiment of the present invention, the identity anonymization of Internet of Things devices is achieved through dynamic pseudonyms, and the verifiable binding of data ownership is realized by combining Pedersen commitments and blockchain, ensuring that devices do not directly expose data and realizing the privacy of the authentication of device identities and permissions.
[0046] Step 103: The candidate Internet of Things device sends the first random number, the first ciphertext, the first signature of the first authentication information, and the first moment to the corresponding candidate edge server.
[0047] Wherein, the first authentication information includes the first random number, the pseudonym of the candidate Internet of Things device, and the first moment, and the first moment is the moment when the candidate Internet of Things device sends the first ciphertext, the first random number, and the first signature.
[0048] Exemplarily, the first signature , wherein, represents the first random number, represents the first moment.
[0049] Step 104: When the difference between the first moment and the second moment is less than the threshold, the candidate edge server decrypts the first ciphertext based on the first secure hash function, the first random number, and the first private key corresponding to the edge server to obtain the decrypted pseudonym of the candidate Internet of Things device.
[0050] Wherein, the second moment is the moment when the candidate edge server receives the first random number, the first ciphertext, the first signature, and the first moment; the first private key is determined based on the multiplicative group.
[0051] Here, the candidate edge server after receiving at the second moment , checks whether the difference between the second moment and the first moment is less than the threshold. If it is less, it decrypts the first ciphertext to obtain the decrypted pseudonym of the candidate Internet of Things device.
[0052] Exemplarily, decrypting the first ciphertext can be done using the following formula (7): (7) Wherein, represents the decrypted pseudonym of the candidate Internet of Things device, represents the first private key corresponding to the edge server , represents the dataset type in the candidate Internet of Things device, represents the second secure hash function.
[0053] Step 105: The candidate edge server authenticates the candidate IoT device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the IoT device parameters in the blockchain.
[0054] It should be noted that the IoT device needs to be verified before participating in model training.
[0055] Here, authentication can be performed based on the comparison value between the decrypted Pedersen commitment mechanism and the encrypted Pedersen commitment mechanism.
[0056] Exemplarily, the candidate edge server authenticates the candidate IoT device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the IoT device parameters in the blockchain, including: the candidate edge server queries the second public key, the first Pedersen commitment result, the second random number, and the second ciphertext of the candidate IoT device from the IoT device parameters in the blockchain based on the decrypted pseudonym; the second random number is determined by the trusted central authority based on the multiplicative group and the first generator; the candidate edge server verifies the first signature based on the second public key to obtain a first verification result; when the first verification result passes, the candidate edge server decrypts the second ciphertext based on the first secure hash function, the first dataset type, the second random number, and the first private key to obtain the decrypted dataset type identifier and the decrypted type-binding random factor; the candidate edge server determines a second Pedersen commitment result based on the Pedersen commitment mechanism, the decrypted dataset type identifier, the decrypted type-binding random factor, the first generator, and the second generator; the second generator is determined by the trusted central authority; when the first Pedersen commitment result is equal to the second Pedersen commitment result, the candidate edge server authenticates the candidate IoT device based on the decrypted dataset type identifier.
[0057] It should be noted that the candidate edge server calls the QueryDevice() method in the blockchain to query and obtain and verifies the first signature to check if it is correct. If it holds, signature is correct. If so, through obtain where can be the second random number or obtained from the second random number, and judge the equation Whether it holds. If it holds, the IoT device is authenticated according to the decrypted dataset type identifier and the proof. Among them, the authentication method can be to authenticate the IoT device using a neural network or to authenticate by decrypting the ciphertext.
[0058] Exemplarily, the authenticating the candidate IoT device based on the decrypted dataset type identifier includes: when the decrypted dataset type identifier indicates that the candidate IoT device has data corresponding to the first dataset type, the candidate edge server determines a third random number based on the multiplicative group and the first generator; the candidate edge server encrypts the pseudonym of the candidate IoT device based on a second secure hash function, the third random number, and the first private key to obtain a first temporary pseudonym of the candidate IoT device; the candidate edge server determines a third ciphertext based on a third secure hash function, the first temporary pseudonym, and the dataset type of the candidate IoT device; and sends the third random number, the third ciphertext, and a third time to the candidate IoT device; the third time is the time when the candidate edge server sends the third random number and the third ciphertext; when the difference between the third time and a fourth time is less than a threshold, the candidate IoT device decrypts the pseudonym of the candidate IoT device based on the second secure hash function, the first public key of the candidate edge server, and the third random number to determine a fourth ciphertext; when the third ciphertext is equal to the fourth ciphertext, it is determined that the candidate IoT device is successfully authenticated.
[0059] It should be noted that for the data type , if , then it proves has the permission to train with the data. Then, select a random number from the multiplicative group i.e., , calculate to obtain the third random number. The method of encrypting the pseudonym of the candidate IoT device is as follows in formula (8): (8) where, is the virtual identity providing this data sharing, is the second secure hash function. In addition, the calculation formula of the third ciphertext is as follows in formula (9): (9) where, is the third secure hash function, and is sent to , represents the third time. At the fourth moment A message is received. When the difference between the verification and is less than the threshold , The following formula (10) for decrypting the pseudonym of the candidate Internet of Things device: (10) Calculate the fourth ciphertext using the following formula (11): (11) Verify the equation to check if it holds. If it holds, it proves that the identity authentication has passed In the embodiments of the present invention, the identity anonymization of Internet of Things devices is achieved through dynamic pseudonyms, and combined with Pedersen commitments, it ensures the authentication of device identities and permissions without directly exposing data.
[0060] Furthermore, after the candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the Internet of Things device parameters in the blockchain, the method further includes: the candidate edge server encrypts the initial global model of the target Internet of Things device and the second public key based on the first session key, and sends the encrypted initial global model to the candidate Internet of Things device; the first session key is a key for data sharing negotiated and determined by the candidate edge server and the candidate Internet of Things device; the candidate Internet of Things device decrypts the encrypted initial global model based on the second session key and the private key of the candidate Internet of Things device to obtain the initial global model; the second session key is a key between each Internet of Things device determined by the trusted central authority; the candidate Internet of Things device trains the initial global model, obtains the model accuracy rate and the sample number of training data, and sends them to the candidate edge server; the candidate edge server uploads the first temporary pseudonym, the model accuracy rate, and the sample number of training data to the alternative list participating in training in the blockchain; the target edge server clusters each candidate Internet of Things device based on the model accuracy rate and the sample number of training data to obtain at least one set of clustering sets; the target edge server determines the target Internet of Things devices participating in training from each candidate Internet of Things device based on the comprehensive scores of the clustering centers in each clustering set.
[0061] It should be noted that after the identity authentication is completed, will be encrypted and sent using the first session key to 。 Use respectively and the second session key to decrypt and obtain the initial global model , and select some data to participate in model training. After the round of local training, obtain the local model accuracy , the sample number of the local training data and the proportion of the node's historical participation in training , and send the to . Finally, upload the to the alternative list participating in training in the blockchain through the AddList() method.
[0062] It should be noted that in federated learning, the contributions of IoT devices to the global model may vary due to different data qualities and model performances. Therefore, it is necessary to select IoT devices.
[0063] Exemplarily, the target edge server screens the nodes with the highest scores based on the clustering algorithm. The specific steps are as follows: (1) Data preprocessing, Standardize the feature vectors through . Among them, is the mean of the features, is the standard deviation of the features.
[0064] (2) Clustering and grouping, Iteratively assign nodes to the nearest cluster center according to the number of clusters: , where, is the th cluster center, is the node that is not a cluster center. Finally, update the cluster center through until convergence.
[0065] (3) Node selection, Calculate the comprehensive score of each cluster center, and select the group of strong nodes with the highest comprehensive score . Finally, select the top nodes from the according to the comprehensive score: . If the number of strong node groups is less than , supplement devices from other node groups in descending order according to the weighted eigenvalue, that is, reassign weights, until requirements of the nodes. Finally, the finally selected set of IoT devices is uploaded to the blockchain through the AddList() method, and this set is marked as the finally selected device list.
[0066] In the embodiment of the present invention, by mapping the IoT device features to the clustering space and adaptively selecting a high - contribution device group to participate in training based on the clustering and feature ranking fusion algorithm, the efficiency and reliability of federated learning in the IoT environment are ensured.
[0067] Further, after the target edge server determines the IoT devices participating in training from each of the candidate IoT devices based on the comprehensive scores of the cluster centers in each of the clustering sets, the method further includes: the IoT devices participating in training encrypt the local model and the local data volume corresponding to the local model based on the homomorphic encryption algorithm and the first session key to obtain a sixth ciphertext and send it to the target edge server corresponding to the IoT devices participating in training; the local model is obtained by the IoT devices participating in training training the initial global model using the local data set; the target edge server decrypts the sixth ciphertext based on the first session key to obtain a seventh ciphertext corresponding to the local model; the target edge server aggregates the IoT devices near the target edge server based on the seventh ciphertext and the local data volume corresponding to the seventh ciphertext to obtain a first aggregation result and upload it to the blockchain; the target edge server aggregates each of the first aggregation results to obtain a second aggregation result and sends it to the target IoT device; the target IoT device decrypts the second aggregation result based on the homomorphic decryption algorithm to obtain a global updated model and sends it to the IoT devices participating in training for training until the global updated model converges to obtain a target global model.
[0068] It should be noted that the IoT devices will iteratively train the model until the global model converges, that is, the global target loss function is minimized. Among them, the aggregation method during training is as follows: (1) Local training: Use its local data set to train and thus obtain an updated local model . (2) Upload model update: After training is completed, use the Paillier encryption algorithm to encrypt to obtain a seventh ciphertext . Then, use to The symmetric encryption is the sixth ciphertext and send it to . Suppose There are devices that meet the conditions nearby Use to After decryption, directly aggregate the seventh ciphertext to obtain the first aggregation result , that is, formula (12): (12) Among them, is the local data volume used by device . Finally, Upload and to the blockchain through the AddPara() method. (3) Model aggregation and global update: Retrieve the local model update ciphertexts uploaded by all participating devices through QueryPara() . Then, Aggregate all according to the following formula (13) to obtain the second aggregation result : (13) Among them, is the total amount of data for all participating global model training. Finally, Send to . (4) Global model feedback and update: Use the Paillier decryption algorithm to decrypt to obtain the global update model plaintext . Upload the global updated model ciphertext to the blockchain through . Then, other ESs encrypt and feedback the global updated model to all participating IoT devices through the session key. The devices perform the next round of local training based on the new global model until the global model converges, that is, the global loss function converges or reaches the desired training accuracy, to obtain the target global model
[0069] In the embodiment of the present invention, the Paillier homomorphic encryption algorithm is used to offload the model aggregation task to multiple edge nodes, greatly reducing the cost of privacy protection. In addition, the smart contract provides automated management for data sharing and model update among devices
[0070] The following describes the Internet of Things device authentication apparatus provided by the present invention. The Internet of Things device authentication apparatus described below can be correspondingly referred to the Internet of Things device authentication method described above.
[0071] Figure 2 FIG. is a schematic structural diagram of the Internet of Things device authentication apparatus provided by the present invention. As Figure 2 shown, the Internet of Things device authentication apparatus 200 includes: A first transmission module 210, configured to, when a target edge server receives a shared data request sent by a target Internet of Things device, transmit a first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things devices; the target Internet of Things device is a device that initiates a model training request among the Internet of Things devices, and the target edge server is an edge server associated with the target Internet of Things device; An encryption module 220, configured to, when a candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, encrypt a pseudonym of the candidate Internet of Things device based on a first secure hash function, the first data set type, a first public key corresponding to a candidate edge server, and a first random number to obtain a first ciphertext; the first random number and the first public key are determined based on a multiplicative group determined by a trusted central authority; A second transmission module 230, configured to the candidate Internet of Things device send the first random number, the first ciphertext, a first signature of first authentication information, and a first moment to a corresponding candidate edge server; the first authentication information includes the first random number, the pseudonym of the candidate Internet of Things device, and the first moment, and the first moment is the moment when the candidate Internet of Things device sends the first ciphertext, the first random number, and the first signature; A decryption module 240, configured to, when a difference between the first moment and a second moment is less than a threshold, decrypt the first ciphertext based on the first secure hash function, the first random number, and a first private key corresponding to the edge server to obtain a decrypted pseudonym of the candidate Internet of Things device; the second moment is the moment when the candidate edge server receives the first random number, the first ciphertext, the first signature, and the first moment; the first private key is determined based on the multiplicative group; An authentication module 250, configured to the candidate edge server authenticate the candidate Internet of Things device based on the decrypted pseudonym, a Pedersen commitment mechanism, and Internet of Things device parameters in a blockchain.
[0072] In another embodiment, the authentication module 250 is specifically configured to: the candidate edge server queries the second public key, the first Pedersen commitment result, the second random number, and the second ciphertext of the candidate Internet of Things device from the Internet of Things device parameters in the blockchain based on the decrypted pseudonym; the second random number is determined by the trusted central institution based on the multiplicative group and the first generator; the candidate edge server verifies the first signature based on the second public key to obtain a first verification result; when the first verification result passes, the candidate edge server decrypts the second ciphertext based on the first secure hash function, the first data set type, the second random number, and the first private key to obtain a decrypted data set type identifier and a decrypted type-bound random factor; the candidate edge server determines a second Pedersen commitment result based on the Pedersen commitment mechanism, the decrypted data set type identifier, the decrypted type-bound random factor, the first generator, and the second generator; the second generator is determined by the trusted central institution; when the first Pedersen commitment result is equal to the second Pedersen commitment result, the candidate edge server authenticates the candidate Internet of Things device based on the decrypted data set type identifier.
[0073] In another embodiment, the authentication module 250 is further specifically configured to: when the decrypted data set type identifier indicates that the candidate Internet of Things device has data corresponding to the first data set type, the candidate edge server determines a third random number based on the multiplicative group and the first generator; the candidate edge server encrypts the pseudonym of the candidate Internet of Things device based on a second secure hash function, the third random number, and the first private key to obtain a first temporary pseudonym of the candidate Internet of Things device; the candidate edge server determines a third ciphertext based on a third secure hash function, the first temporary pseudonym, and the data set type of the candidate Internet of Things device; and sends the third random number, the third ciphertext, and a third time to the candidate Internet of Things device; the third time is the time when the candidate edge server sends the third random number and the third ciphertext; when the difference between the third time and a fourth time is less than a threshold, the candidate Internet of Things device decrypts the pseudonym of the candidate Internet of Things device based on the second secure hash function, the first public key of the candidate edge server, and the third random number to determine a fourth ciphertext; when the third ciphertext is equal to the fourth ciphertext, it is determined that the candidate Internet of Things device authentication is successful.
[0074] In another embodiment, before transmitting the first data set type required by the target Internet of Things device to the candidate Internet of Things devices other than the target Internet of Things device among the Internet of Things devices, the Internet of Things device authentication apparatus further includes an initialization module, specifically configured to: the trusted central authority selects at least one fourth random number from the multiplicative group as the private key of each of the edge servers; the private key of each of the edge servers includes the first private key of the candidate edge server; the trusted central authority determines the public key corresponding to each of the edge servers based on the private key of the edge server and the first generator; the public key corresponding to each of the edge servers includes the first public key of the candidate edge server; the trusted central authority sends the private key of each of the edge servers and the public key corresponding to each of the edge servers to the corresponding edge server; the trusted central authority determines the first secure hash function, the second secure hash function, the third secure hash function, the fourth secure hash function, and the fifth secure hash function.
[0075] In another embodiment, after the trusted central authority sends the private key of each edge server and the public key corresponding to each edge server to the corresponding edge server, the IoT device authentication device further includes a registration module, which is specifically used for: the IoT device selects at least one fifth random number from the multiplicative group, and respectively determines the private key of each IoT device and the public key of each IoT device based on each fifth random number and the first generator; the public key of each IoT device includes the second public key; the IoT device determines the type-binding random factor corresponding to the dataset type based on the fourth secure hash function, the identity identifier of the IoT device, the first random number array, and the dataset type; the first random number array is randomly selected from the multiplicative group, and the number of the first random number array is the number of types of the dataset type; the IoT device determines the first Pedersen commitment result based on the Pedersen commitment, the first generator, the second generator, the type-binding random factor, and the dataset type identifier; the IoT device encrypts the type-binding random factor and the dataset type identifier based on the first secure hash function, the public key of the edge server, the second random number array, and the dataset type to obtain a seventh random number and a fifth ciphertext; and sends the true identity of the IoT device, the public key of the IoT device, the seventh random number, the fifth ciphertext, the proof representing the dataset type of the IoT device, and a registration request to the trusted central authority; when the IoT device is not registered, the trusted central authority decrypts the fifth ciphertext based on the first secure hash function, the private key of the edge server, the seventh random number, and the dataset type to obtain the decrypted dataset type identifier and the decrypted type-binding random factor; the trusted central authority verifies and registers the IoT device based on the decrypted dataset type identifier, the decrypted type-binding random factor, the Pedersen commitment mechanism, and the fifth secure hash function.
[0076] In another embodiment, after the candidate edge server authenticates the candidate Internet of Things (IoT) device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the IoT device parameters in the blockchain, the IoT device authentication apparatus further includes a clustering module, which is configured to: the candidate edge server encrypts the initial global model and the second public key of the target IoT device based on a first session key, obtains an encrypted initial global model, and sends it to the candidate IoT device; the first session key is a key for data sharing negotiated and determined by the candidate edge server and the candidate IoT device; the candidate IoT device decrypts the encrypted initial global model based on a second session key and the private key of the candidate IoT device to obtain the initial global model; the second session key is a key between IoT devices determined by the trusted central authority; the candidate IoT device trains the initial global model, obtains the model accuracy rate and the number of samples of the training data, and sends them to the candidate edge server; the candidate edge server uploads the first temporary pseudonym, the model accuracy rate, and the number of samples of the training data to the alternative list participating in the training in the blockchain; the target edge server clusters the candidate IoT devices based on the model accuracy rate and the number of samples of the training data to obtain at least one set of clustering sets; the target edge server determines the target IoT devices participating in the training from the candidate IoT devices based on the comprehensive scores of the clustering centers in each clustering set.
[0077] In another embodiment, after the target edge server determines the target Internet of Things (IoT) devices participating in training from each of the candidate IoT devices based on the comprehensive scores of the cluster centers in each of the clustering sets, the IoT device authentication apparatus further includes an aggregation module, which is specifically configured to: the target IoT devices participating in training encrypt the local model and the local data volume corresponding to the local model based on the homomorphic encryption algorithm and the first session key to obtain a sixth ciphertext and send it to the target edge server participating in training corresponding to the target IoT devices participating in training; the local model is obtained by the target IoT devices participating in training training the initial global model using the local data set; the target edge server participating in training decrypts the sixth ciphertext based on the first session key to obtain a seventh ciphertext corresponding to the local model; the target edge server participating in training aggregates the IoT devices near the target edge server participating in training based on the seventh ciphertext and the local data volume corresponding to the seventh ciphertext to obtain a first aggregation result and upload it to the blockchain; the target edge server aggregates each of the first aggregation results to obtain a second aggregation result and sends it to the target IoT device; the target IoT device decrypts the second aggregation result based on the homomorphic decryption algorithm to obtain a global updated model and sends it to the target IoT devices participating in training for training until the global updated model converges to obtain a target global model.
[0078] Figure 3 is a schematic structural diagram of the electronic device provided by the present invention, as Figure 3As shown, the electronic device may include: a processor 810, a communications interface 820, a memory 830, and a communication bus 840. Among them, the processor 810, the communications interface 820, and the memory 830 complete communication with each other through the communication bus 840. The processor 810 may call logic instructions in the memory 830 to execute an Internet of Things device authentication method, which is applied to an authentication system. The authentication system includes a trusted central authority, an Internet of Things device, an edge server, and a blockchain, and includes: when a target edge server receives a shared data request sent by a target Internet of Things device, the target edge server transmits a first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things device; when the candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, the candidate Internet of Things device encrypts the pseudonym of the candidate Internet of Things device based on a first secure hash function, the first data set type, a first public key corresponding to a candidate edge server, and a first random number to obtain a first ciphertext; the candidate Internet of Things device sends the first random number, the first ciphertext, a first signature of a first authentication information, and a first moment to a corresponding candidate edge server; when a difference between the first moment and a second moment is less than a threshold, the candidate edge server decrypts the first ciphertext based on the first secure hash function, the first random number, and a first private key corresponding to the edge server to obtain a decrypted pseudonym of the candidate Internet of Things device; the candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, a Pedersen commitment mechanism, and Internet of Things device parameters in the blockchain.
[0079] In addition, when the logic instructions in the above-mentioned memory 830 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.
[0080] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the Internet of Things device authentication method provided by each of the above methods. This method is applied to an authentication system, and the authentication system includes a trusted central authority, Internet of Things devices, edge servers, and a blockchain, and includes: when a target edge server receives a shared data request sent by a target Internet of Things device, the target edge server transmits the first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things device; when a candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, based on a first secure hash function, the first data set type, a first public key corresponding to a candidate edge server, and a first random number, the candidate Internet of Things device encrypts the pseudonym of the candidate Internet of Things device to obtain a first ciphertext; the candidate Internet of Things device sends the first random number, the first ciphertext, a first signature of the first authentication information, and a first time to the corresponding candidate edge server; when the difference between the first time and a second time is less than a threshold, based on the first secure hash function, the first random number, and a first private key corresponding to the edge server, the candidate edge server decrypts the first ciphertext to obtain the decrypted pseudonym of the candidate Internet of Things device; the candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the Internet of Things device parameters in the blockchain.
[0081] In another aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the Internet of Things device authentication method provided by the above-mentioned various methods. The method is applied to an authentication system, and the authentication system includes a trusted central authority, Internet of Things devices, edge servers, and a blockchain, including: when a target edge server receives a shared data request sent by a target Internet of Things device, the target edge server transmits the first data set type required by the target Internet of Things device to candidate Internet of Things devices other than the target Internet of Things device in the Internet of Things device; when the candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first data set type, the candidate Internet of Things device encrypts the pseudonym of the candidate Internet of Things device based on a first secure hash function, the first data set type, a first public key corresponding to the candidate edge server, and a first random number to obtain a first ciphertext; the candidate Internet of Things device sends the first random number, the first ciphertext, a first signature of the first authentication information, and a first time to the corresponding candidate edge server; when the difference between the first time and a second time is less than a threshold, the candidate edge server decrypts the first ciphertext based on the first secure hash function, the first random number, and a first private key corresponding to the edge server to obtain the decrypted pseudonym of the candidate Internet of Things device; the candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the Internet of Things device parameters in the blockchain.
[0082] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0083] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solutions, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An Internet of Things device authentication method, characterized in that, Applied to an authentication system, the authentication system includes a trusted central authority, Internet of Things (IoT) devices, edge servers, and a blockchain. The method includes: When a target edge server receives a shared data request from a target IoT device, the target edge server transmits the first data set type required by the target IoT device to candidate IoT devices in the IoT devices except the target IoT device. The target IoT device is the device that initiates a model training request among the IoT devices, and the target edge server is the edge server associated with the target IoT device. When the candidate IoT device receives the model training request sent by the target edge server and has data corresponding to the first data set type, based on a first secure hash function, the first data set type, the first public key corresponding to the candidate edge server, and a first random number, the candidate IoT device encrypts its pseudonym to obtain a first ciphertext. The first random number and the first public key are determined based on a multiplicative group determined by the trusted central authority. The candidate IoT device sends the first random number, the first ciphertext, a first signature of the first authentication information, and a first time to the corresponding candidate edge server. The first authentication information includes the first random number, the pseudonym of the candidate IoT device, and the first time, and the first time is the time when the candidate IoT device sends the first ciphertext, the first random number, and the first signature. When the difference between the first time and a second time is less than a threshold, based on the first secure hash function, the first random number, and the first private key corresponding to the edge server, the candidate edge server decrypts the first ciphertext to obtain the decrypted pseudonym of the candidate IoT device. The second time is the time when the candidate edge server receives the first random number, the first ciphertext, the first signature, and the first time. The first private key is determined based on the multiplicative group. The candidate edge server authenticates the candidate IoT device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the IoT device parameters in the blockchain.
2. The method for authenticating an Internet of Things device according to claim 1, wherein The candidate edge server authenticating the candidate IoT device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the IoT device parameters in the blockchain includes: Based on the decrypted pseudonym, the candidate edge server queries the second public key, the first Pedersen commitment result, the second random number, and the second ciphertext of the candidate IoT device from the IoT device parameters in the blockchain. The second random number is determined by the trusted central authority based on the multiplicative group and a first generator. The candidate edge server verifies the first signature based on the second public key to obtain a first verification result. When the first verification result passes, the candidate edge server decrypts the second ciphertext based on the first secure hash function, the first dataset type, the second random number, and the first private key to obtain the decrypted dataset type identifier and the decrypted type-bound random factor; The candidate edge server determines a second Pedersen commitment result based on the Pedersen commitment mechanism, the decrypted dataset type identifier, the decrypted type-bound random factor, the first generator, and the second generator; the second generator is determined by the trusted central authority; When the first Pedersen commitment result is equal to the second Pedersen commitment result, the candidate edge server authenticates the candidate Internet of Things device based on the decrypted dataset type identifier; 3. The method for authenticating an Internet of Things device according to claim 2, wherein The authenticating the candidate Internet of Things device based on the decrypted dataset type identifier includes: When the decrypted dataset type identifier indicates that the candidate Internet of Things device has data corresponding to the first dataset type, the candidate edge server determines a third random number based on the multiplicative group and the first generator; The candidate edge server encrypts the pseudonym of the candidate Internet of Things device based on a second secure hash function, the third random number, and the first private key to obtain the first temporary pseudonym of the candidate Internet of Things device; The candidate edge server determines a third ciphertext based on a third secure hash function, the first temporary pseudonym, and the dataset type of the candidate Internet of Things device; and sends the third random number, the third ciphertext, and a third time to the candidate Internet of Things device; the third time is the time when the candidate edge server sends the third random number and the third ciphertext; When the difference between the third time and a fourth time is less than a threshold, the candidate Internet of Things device decrypts the pseudonym of the candidate Internet of Things device based on the second secure hash function, the first public key of the candidate edge server, and the third random number to determine a fourth ciphertext; When the third ciphertext is equal to the fourth ciphertext, it is determined that the authentication of the candidate Internet of Things device is successful; 4. The method for authenticating an Internet of Things device according to claim 3, wherein Before transmitting the first dataset type required by the target Internet of Things device to the candidate Internet of Things devices other than the target Internet of Things device, the method further includes: The trusted central authority selects at least one fourth random number from the multiplicative group as the private key of each edge server; the private key of each edge server includes the first private key of the candidate edge server; The trusted central authority determines the public key corresponding to each edge server based on the private key of the edge server and the first generator; the public key corresponding to each edge server includes the first public key of the candidate edge server; The trusted central authority sends the private key of each edge server and the public key corresponding to each edge server to the corresponding edge server; The trusted central authority determines the first secure hash function, the second secure hash function, the third secure hash function, the fourth secure hash function, and the fifth secure hash function.
5. The method for authenticating an Internet of Things device according to claim 4, wherein After the trusted central authority sends the private key of each edge server and the public key corresponding to each edge server to the corresponding edge server, the method further includes: The Internet of Things device selects at least one fifth random number from the multiplicative group, and respectively determines the private key of each Internet of Things device and the public key of each Internet of Things device based on each fifth random number and the first generator; the second public key is included in the public key of each Internet of Things device; The Internet of Things device determines the type-binding random factor corresponding to the dataset type based on the fourth secure hash function, the identity identifier of the Internet of Things device, the first random number array, and the dataset type; the first random number array is randomly selected from the multiplicative group, and the number of the first random number array is the number of types of the dataset type; The Internet of Things device determines the first Pedersen commitment result based on the Pedersen commitment, the first generator, the second generator, the type-binding random factor, and the dataset type identifier; The Internet of Things device encrypts the type-binding random factor and the dataset type identifier based on the first secure hash function, the public key of the edge server, the second random number array, and the dataset type to obtain a seventh random number and a fifth ciphertext; and sends the true identity of the Internet of Things device, the public key of the Internet of Things device, the seventh random number, the fifth ciphertext, the proof representing the dataset type of the Internet of Things device, and a registration request to the trusted central authority; When the Internet of Things device is not registered, the trusted central authority decrypts the fifth ciphertext based on the first secure hash function, the private key of the edge server, the seventh random number, and the dataset type to obtain the decrypted dataset type identifier and the decrypted type-binding random factor; The trusted central authority verifies and registers the Internet of Things device based on the decrypted dataset type identifier, the decrypted type-binding random factor, the Pedersen commitment mechanism, and the fifth secure hash function.
6. The method for authenticating an Internet of Things device according to claim 5, wherein After the candidate edge server authenticates the candidate Internet of Things device based on the decrypted pseudonym, the Pedersen commitment mechanism, and the Internet of Things device parameters in the blockchain, the method further includes: The candidate edge server encrypts the initial global model of the target Internet of Things device and the second public key based on the first session key, and sends the encrypted initial global model to the candidate Internet of Things device; the first session key is a key for data sharing negotiated by the candidate edge server and the candidate Internet of Things device; The candidate Internet of Things device decrypts the encrypted initial global model based on the second session key and the private key of the candidate Internet of Things device to obtain the initial global model; the second session key is a key between Internet of Things devices determined by the trusted central authority. The candidate IoT device trains the initial global model, obtains the model accuracy rate and the number of samples of the training data, and sends them to the candidate edge server; The candidate edge server uploads the first temporary pseudonym, the model accuracy rate, and the number of samples of the training data to the alternative list participating in the training in the blockchain; The target edge server clusters each candidate IoT device based on the model accuracy rate and the number of samples of the training data, and obtains at least one set of clustering sets; The target edge server determines the IoT devices that are target participants in training from each candidate IoT device based on the comprehensive scores of the clustering centers in each clustering set.
7. The method for authenticating an Internet of Things device according to claim 6, wherein After the target edge server determines the IoT devices that are target participants in training from each candidate IoT device based on the comprehensive scores of the clustering centers in each clustering set, the method further includes: The IoT device that is the target participant in training encrypts the local model and the local data volume corresponding to the local model based on the homomorphic encryption algorithm and the first session key, obtains the sixth ciphertext, and sends it to the target edge server corresponding to the IoT device that is the target participant in training; the local model is obtained by the IoT device that is the target participant in training using the local data set to train the initial global model; The target edge server that is the target participant in training decrypts the sixth ciphertext based on the first session key to obtain the seventh ciphertext corresponding to the local model; The target edge server that is the target participant in training aggregates the IoT devices near the target edge server that is the target participant in training based on the seventh ciphertext and the local data volume corresponding to the seventh ciphertext, obtains the first aggregation result, and uploads it to the blockchain; The target edge server aggregates each of the first aggregation results to obtain a second aggregation result and sends it to the target IoT device; The target IoT device decrypts the second aggregation result based on the homomorphic decryption algorithm to obtain a globally updated model, and sends it to the IoT device that is the target participant in training for training until the globally updated model converges to obtain a target global model.
8. An Internet of Things device authentication device, characterized in that, Including: A first transmission module, configured to, when the target edge server receives a shared data request from the target IoT device, transmit the first data set type required by the target IoT device to the candidate IoT devices other than the target IoT device in the IoT devices; the target IoT device is the device that initiates the model training request in the IoT devices, and the target edge server is the edge server associated with the target IoT device; An encryption module, configured to, when the candidate Internet of Things device receives a model training request sent by the target edge server and has data corresponding to the first dataset type, encrypt the pseudonym of the candidate Internet of Things device based on a first secure hash function, the first dataset type, a first public key corresponding to the candidate edge server, and a first random number, to obtain a first ciphertext; the first random number and the first public key are determined based on a multiplicative group determined by a trusted central authority; A second transmission module, configured to enable the candidate Internet of Things device to send the first random number, the first ciphertext, a first signature of the first authentication information, and a first time to a corresponding candidate edge server; the first authentication information includes the first random number, the pseudonym of the candidate Internet of Things device, and the first time, and the first time is the time when the candidate Internet of Things device sends the first ciphertext, the first random number, and the first signature; A decryption module, configured to, when the difference between the first time and a second time is less than a threshold, decrypt the first ciphertext based on the first secure hash function, the first random number, and a first private key corresponding to the edge server, to obtain the decrypted pseudonym of the candidate Internet of Things device; the second time is the time when the candidate edge server receives the first random number, the first ciphertext, the first signature, and the first time; the first private key is determined based on the multiplicative group; An authentication module, configured to enable the candidate edge server to authenticate the candidate Internet of Things device based on the decrypted pseudonym, a Pedersen commitment mechanism, and Internet of Things device parameters in a blockchain.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the Internet of Things device authentication method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the Internet of Things device authentication method according to any one of claims 1 to 7.