Supply chain data encryption storage method based on edge calculation

By monitoring the key indicators and available computing power of edge nodes and cloud network communication, dynamically adjusting the ratchet step cycle of the dual ratchet algorithm, solving the problem of excessive consumption of computing resources and security in edge computing, and achieving a balance of security and efficiency.

CN120474839AActive Publication Date: 2025-08-12HANGZHOU LOONXI NETWORK TECH CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510958120.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-08-12
Estimated Expiration
2045-07-11

AI Technical Summary

Technical Problem

In edge computing scenarios, the double ratchet algorithm has a contradiction between excessive computing resource consumption, security and efficiency, especially in the case of limited computing power and complex network environment, it is difficult for the existing technology to achieve a balance between security and efficiency.

Method used

By monitoring the key network communication indicators between edge nodes and the cloud, dynamically adjust the ratchet step cycle of the dual ratchet algorithm, combined with the available computing power of edge nodes, adjust the key update frequency in real time to cope with the needs of different attack risks and computing power scenarios, and achieve a balance of security and efficiency.

Benefits of technology

It effectively resolves the contradiction between security and efficiency in the edge computing scenarios in security and complex network environments, and realizes resource optimization and security guarantee in different risk scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474839A_ABST
    Figure CN120474839A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data encryption storage, and particularly relates to an edge computing-based supply chain data encryption storage method, which comprises the following steps of: encrypting preprocessed supply chain data of an edge node according to a secret key generated by a dual-ratchet algorithm, grouping and packaging the encrypted supply chain data of the edge node, and storing the grouped and packaged supply chain data of the edge node. Forming a plurality of data packets of the edge node and transmitting the data packets to the cloud; wherein in the key generation process of the double-ratchet algorithm, the ratchet stepping period of the double-ratchet algorithm is determined according to the attack degree of network communication between the edge node and the cloud and the available computing power of the edge node, and ratchet stepping is carried out according to the period, so that updating of the key is realized. According to the method, challenges caused by limited computing power and a complex network environment in an edge computing scene can be effectively handled, and the balance of safety and efficiency is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption storage. More specifically, the present invention relates to a supply chain data encryption storage method based on edge computing. Background Art

[0002] With the rapid development of the Internet of Things and edge computing technologies, supply chain management is gradually evolving towards digitalization and intelligence. In modern supply chain systems, large amounts of data (such as data from logistics, warehousing, and production) are collected through edge devices and transmitted to the cloud for storage and analysis.

[0003] However, these data often contain sensitive information, which places extremely high demands on data security. Although traditional centralized encryption storage methods can provide a certain degree of security, they face many challenges in edge computing scenarios. In order to meet the above challenges, researchers have proposed some encryption schemes based on the Double Ratchet Algorithm in recent years.

[0004] The double ratchet algorithm is an efficient key agreement protocol that can dynamically generate new session keys between communicating parties, thereby improving the security of data transmission. The core idea of the double ratchet algorithm is to use two independent ratchets to manage long-term keys and temporary session keys. These two independent ratchets are the symmetric key ratchet and the DH (Diffie-Hellman) ratchet. During the communication process, the double ratchet algorithm can ensure that the keys of the communicating parties are always synchronized and updated by ratcheting these two independent ratchets.

[0005] Although the double ratchet algorithm has high security, in edge computing scenarios with limited computing power and complex network environments, there are still problems such as excessive consumption of computing resources and the contradiction between security and efficiency. Summary of the Invention

[0006] In order to solve the technical problems of excessive computing resource consumption and contradiction between security and efficiency in the above-mentioned double ratchet algorithm in edge computing scenarios with limited computing power and complex network environment, the present invention provides a supply chain data encryption and storage method based on edge computing, including: collecting supply chain data through edge devices, and combining the supply chain data collected by multiple edge devices connected to the edge node to form the supply chain data of the edge node; encrypting the pre-processed supply chain data of the edge node according to the key generated by the double ratchet algorithm, grouping and packaging the encrypted supply chain data of the edge node to form multiple data packets of the edge node and transmitting them to the cloud; wherein, in the process of generating the key by the double ratchet algorithm, ratchet stepping is performed according to a period to realize the update of the key, and ratchet stepping is performed according to a period. The method for obtaining the cycle is as follows: real-time monitoring of key indicators in the network communication between the edge node and the cloud; determining the relative risk value of each attack type based on each key indicator; weighted summing the relative risk value of each attack type by the weight of the attack type to obtain the attack degree of the network communication between the edge node and the cloud; calculating the maximum theoretical computing power of the edge node according to the hardware configuration of the edge node; calculating the real-time load availability of the edge node according to the current load of the edge node; calculating the product of the maximum theoretical computing power of the edge node and the real-time load availability of the edge node to obtain the available computing power of the edge node; determining the cycle of the ratchet stepping of the double ratchet algorithm according to the attack degree of the network communication between the edge node and the cloud, and the available computing power of the edge node.

[0007] The present invention determines the ratchet stepping cycle of the double ratchet algorithm based on the attack level of the network communication between the edge node and the cloud, as well as the available computing power of the edge node. It dynamically adjusts the key update frequency according to the needs of scenarios with different attack risks and computing power. It can effectively cope with the challenges brought by limited computing power and complex network environment in edge computing scenarios, and achieve a balance between security and efficiency.

[0008] Preferably, the key indicators in the network communication include delay anomaly ratio, packet loss rate and encrypted message repetition rate, which are respectively used to monitor the three attack types of man-in-the-middle attack, packet loss attack and re-entry attack; the delay anomaly ratio, packet loss rate and encrypted message repetition rate are recorded as the first, second and third key indicators respectively, and the monitoring of man-in-the-middle attack, packet loss attack and re-entry attack is recorded as the first, second and third attack types respectively.

[0009] Preferably, the relative risk value of each attack type is determined based on each key indicator, including: setting the maximum tolerance value of the delay anomaly ratio, the packet loss rate and the encrypted message repetition rate; Key indicators, , calculate the Key indicators and The maximum tolerance value difference of the key indicators. If the difference is greater than 0, the The relative risk value of the attack type is equal to the difference between the The ratio of the maximum tolerance values of the key indicators is 0. If the difference is not greater than 0, then The relative risk value of this attack type is equal to 0.

[0010] The present invention sets a maximum tolerance value for each key indicator and calculates a relative risk value based on the difference between the actual value and the maximum tolerance value, thereby accurately quantifying the risk level of each attack type and providing a real-time security assessment basis.

[0011] Preferably, the weights of the attack types are all greater than 0, and the sum of the weights of all attack types is equal to 1, and the weights of the first, second, and third attack types decrease in sequence.

[0012] Preferably, the hardware configuration of the edge node is reported by the edge node when registering, including CPU main frequency, number of cores, memory capacity and GPU capability, and is recorded as the first computing power influencing factor, the second computing power influencing factor, the third computing power influencing factor and the fourth computing power influencing factor of the edge node respectively.

[0013] Preferably, the calculation of the maximum theoretical computing power of the edge node based on the hardware configuration of the edge node includes: weighted summation of the computing power scores of the first computing power influencing factor, the second computing power influencing factor, the third computing power influencing factor, and the fourth computing power influencing factor of the edge node according to the first weight, the second weight, the third weight, and the fourth weight to obtain the maximum theoretical computing power of the edge node; the first weight, the second weight, the third weight, and the fourth weight are all greater than 0, and the sum of all weights is equal to 1.

[0014] The present invention obtains the maximum theoretical computing power of edge nodes by performing score mapping and weight setting on multiple computing power influencing factors, which can accurately evaluate the hardware performance of edge nodes and provide a basis for subsequent calculations.

[0015] Preferably, the mapping function of the computing power score is: for the first computing power influencing factor, i.e., the CPU main frequency, the score corresponding to 1 GHz is 100 points; for the second computing power influencing factor, i.e., the number of cores, the score corresponding to each core is 100 points; for the third computing power influencing factor, i.e., the memory capacity, the score corresponding to each 1 GB is 100 points; the fourth computing power influencing factor is the GPU capability. When the hardware configuration of the edge node has GPU capability, the corresponding score is 100 points; when the hardware configuration of the edge node does not have GPU capability, the corresponding score is 0 points.

[0016] Preferably, the real-time load availability of the edge node is calculated based on the current load of the edge node, including: each edge node periodically sends its current load to the cloud, and the current load includes CPU usage and memory usage, and the CPU usage and memory usage are both percentages; the average value of the CPU usage and memory usage of the edge node is calculated, and the difference between 1 and the average value is used as the real-time load availability of the edge node.

[0017] Preferably, the method of determining the ratchet stepping cycle of the double ratchet algorithm based on the attack level of the network communication between the edge node and the cloud, and the available computing power of the edge node, includes: calculating the longest acceptable cycle of the edge node based on the available computing power of the edge node; taking the negative of the attack level of the network communication between the edge node and the cloud, and inputting it into the Sigmoid function, multiplying the output result of the Sigmoid function by 2 and then multiplying it by the longest acceptable cycle of the edge node, rounding up the obtained product, and using the rounded result as the ratchet stepping cycle of the double ratchet algorithm.

[0018] The present invention combines the attack degree and the longest acceptable period to ultimately determine the ratchet stepping period, thereby shortening the period in high-attack risk scenarios to improve security, and extending the period in low-attack risk scenarios to save resources.

[0019] Preferably, the method of calculating the longest acceptable period of the edge node based on the available computing power of the edge node includes: calculating the difference between the available computing power of the edge node and the average of the available computing power of all edge nodes, calculating the ratio of the difference to the average of the available computing power of all edge nodes, taking the negative of the ratio, and inputting it into a natural exponential function, multiplying the output result of the natural exponential function by a preset length to obtain the longest acceptable period of the edge node.

[0020] The present invention calculates the longest acceptable cycle of the edge node by the deviation degree of the available computing power of the edge node relative to the average computing power of all edge nodes and the preset length, dynamically adjusts the cycle according to the computing power difference, reasonably allocates resources, avoids low-computing-power nodes from updating keys too early, and realizes the optimization of resource utilization.

[0021] The beneficial effects of the present invention are: The present invention determines the ratchet stepping cycle of the double ratchet algorithm based on the attack level of the network communication between the edge node and the cloud, as well as the available computing power of the edge node. It dynamically adjusts the key update frequency according to the needs of scenarios with different attack risks and computing power. It can effectively cope with the challenges brought by limited computing power and complex network environment in edge computing scenarios, and achieve a balance between security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1It is a flowchart schematically illustrating the supply chain data encryption storage method based on edge computing in the present invention. DETAILED DESCRIPTION

[0023] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work shall fall within the scope of protection of the present invention.

[0024] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0025] The embodiment of the present invention discloses a supply chain data encryption storage method based on edge computing, referring to Figure 1 , including steps S1 to S4: S1. Collect supply chain data through edge devices, and combine the supply chain data collected by multiple edge devices connected to the edge node into the supply chain data of the edge node; encrypt the pre-processed supply chain data of the edge node according to the key generated by the double ratchet algorithm, group and package the encrypted supply chain data of the edge node to form multiple data packets of the edge node and transmit them to the cloud.

[0026] Edge computing is a distributed computing paradigm that shifts data processing and analysis from a centralized cloud to edge devices or nodes close to the data source. In this way, edge computing can significantly reduce data transmission latency, lower bandwidth consumption, and improve the real-time performance and reliability of the system.

[0027] The key components of edge computing include edge devices, edge nodes, cloud, and network infrastructure. Edge devices, such as sensors, cameras, and mobile devices, are located at the source of data generation and are responsible for collecting raw data and transmitting it to edge nodes. Edge nodes, as the middle layer between edge devices and the cloud, are responsible for data aggregation, preprocessing, and preliminary analysis. The cloud can provide global data storage, in-depth analysis, and model training capabilities. Network infrastructure includes communication technologies such as 5G, Wi-Fi, and LoRa, which are used to connect edge devices, edge nodes, and the cloud for data transmission.

[0028] Specifically, supply chain data is collected through edge devices, and the supply chain data collected by multiple edge devices connected to the edge node are combined to form the supply chain data of the edge node; the supply chain data of the edge node are preprocessed, encrypted and grouped to form multiple data packets of the edge node.

[0029] Among them, the supply chain data includes but is not limited to data from the logistics link, data from the warehousing link, and data from the production link; the data from the logistics link includes the location of the transport vehicle (GPS), cargo status (temperature, humidity, vibration, etc.), etc.; the data from the warehousing link includes inventory quantity, shelf location, environmental conditions (such as temperature, humidity), etc.; the data from the production link includes production equipment status, raw material consumption, etc.

[0030] The edge devices include but are not limited to various sensors, such as temperature sensors, humidity sensors, vibration sensors, RFID tags, etc.

[0031] The preprocessing includes data cleaning, which can remove invalid data; then, the preprocessed supply chain data is encrypted according to the key generated by the double ratchet algorithm to ensure data security; the grouping and packaging is to package the supply chain data within the same time period into a data packet according to the timestamp of the supply chain data, so as to facilitate subsequent transmission and processing.

[0032] The obtained data packet contains header information, payload and verification information. The header information includes data packet identifier, sending time, destination address, etc. The payload refers to the actual supply chain data, and the verification information refers to the hash value or CRC code used to verify data integrity.

[0033] It should be noted that collecting supply chain data through edge devices and integrating data from multiple devices into an overall data set can reduce data redundancy and facilitate subsequent processing and analysis; encrypting data with keys generated by the double ratchet algorithm ensures data security during transmission; and grouping the encrypted data into multiple data packets for transmission can reduce the amount of data transmitted in a single transmission, reduce network load, and improve transmission efficiency.

[0034] The core idea of the double ratchet algorithm is to use two independent ratchets to manage long-term keys and temporary session keys. These two independent ratchets are the symmetric key ratchet and the DH (Diffie-Hellman) ratchet. During the communication process, the double ratchet algorithm can ensure that the keys of the communicating parties are always synchronized and updated by ratcheting these two independent ratchets.

[0035] Before the symmetric key ratchet step, a DH ratchet step is performed to update the chain key; when a message is sent or received, a symmetric key ratchet step of the chain key is performed to derive a new key.

[0036] Although the double ratchet algorithm has high security, each ratchet step requires updating the chain key and re-deriving a new key, which involves complex encryption operations. In edge computing scenarios, the computing power of edge nodes is limited, and frequent key derivation will occupy a large amount of computing resources, resulting in performance degradation. In addition, although frequent ratchet steps improve security, in some low-risk scenarios (such as low attack levels), this strategy is too conservative and leads to waste of resources. Conversely, in high-risk scenarios (such as high attack levels), a fixed stepping period may not be sufficient to cope with rapidly changing security threats.

[0037] To address the problems of excessive computing resource consumption and the contradiction between security and efficiency in the double ratchet algorithm, a method is proposed to dynamically adjust the ratchet step period based on the attack level of network communication between edge nodes and the cloud and the available computing power of edge nodes.

[0038] S2. Real-time monitoring of key indicators in the network communication between the edge node and the cloud; determining the relative risk value of each attack type based on each key indicator; and weighted summing the relative risk values of each attack type to obtain the attack level of the network communication between the edge node and the cloud.

[0039] It should be noted that in network communications, network delay anomalies, packet loss rate, and encrypted message repetition rate are important indicators for measuring communication quality, and can reflect the risk level of network communications being subject to man-in-the-middle attacks, packet loss attacks, and replay attacks. Therefore, this embodiment evaluates the security of network communications by monitoring the delay anomaly ratio, packet loss rate, and encrypted message repetition rate, quantifies the risk level of each attack type, and comprehensively considers the impact of multiple attack types to obtain a more accurate attack level assessment.

[0040] 1. Real-time monitoring of key indicators in network communication between edge nodes and the cloud.

[0041] Specifically, the key indicators in the network communication include delay anomaly ratio, packet loss rate and encrypted message repetition rate, which are used to monitor three types of attacks: man-in-the-middle attack, packet loss attack and replay attack.

[0042] The method for obtaining the abnormal delay ratio and packet loss rate in network communication is as follows: Specifically, a normal delay range is set based on historical data or empirical values. For example, in historical data, the average value of network delay time is 50ms, and the standard deviation of network delay time is 10ms, then the normal delay range is defined as [40, 60], in ms (milliseconds).

[0043] Furthermore, each network communication transmits at least one data packet. The network monitoring tool is used to measure the number of all data packets sent, all data packets received, and all data packets lost in each network communication. The network delay time for receiving each data packet is also monitored in milliseconds.

[0044] The network monitoring tool is a Ping statistics tool. The Ping statistics tool can help users evaluate the strength and stability of network connections by sending ICMP (Internet Control Message Protocol) requests and recording response time.

[0045] Furthermore, if the network delay time of a data packet exceeds the normal delay range, there is a delay anomaly in the transmission of the data packet; the number of all data packets with delay anomalies is counted, and the ratio of the number of all data packets with delay anomalies to the number of all received data packets is used as the delay anomaly ratio in network communication.

[0046] Furthermore, the packet loss rate in network communication is equal to the ratio of the number of lost packets to the number of sent packets.

[0047] The method for obtaining the repetition rate of encrypted messages in network communication is as follows: Specifically, for the data in the data packet, the unique identifier of the data (including but not limited to the timestamp) is used to check whether there is duplicate data in all the received data; the ratio of the number of duplicate data to the number of all received data is used as the repetition rate of the encrypted message in the network communication.

[0048] 2. Set the maximum tolerance values for delay anomaly ratio, packet loss rate, and encrypted message repetition rate.

[0049] The maximum tolerance values of delay anomaly ratio, packet loss rate and encrypted message repetition rate are used to measure network quality.

[0050] Among them, regarding the delay anomaly ratio, since the supply chain data has relatively low requirements for real-time performance, a slightly higher delay anomaly ratio can be accepted, so the maximum tolerance value of the delay anomaly ratio is set to 10%; in other embodiments, the maximum tolerance value of the delay anomaly ratio can be set according to actual application scenarios and requirements, and the maximum tolerance value of the delay anomaly ratio is in the range of [1%, 15%].

[0051] Among them, for the maximum tolerance value of the packet loss rate, the maximum tolerance value of the packet loss rate is set to 1%; in other embodiments, the maximum tolerance value of the packet loss rate can be set according to actual application scenarios and requirements, and the maximum tolerance value of the packet loss rate is in the range of (0, 2%].

[0052] Among them, since repeated messages will lead to resource waste and security risks, the maximum tolerance value of the encrypted message repetition rate should be as low as possible, so the maximum tolerance value of the encrypted message repetition rate is set to 0.1%; in other embodiments, the maximum tolerance value of the encrypted message repetition rate can be set according to actual application scenarios and requirements, and the maximum tolerance value of the encrypted message repetition rate is in the range of (0, 0.5%].

[0053] 3. Determine the relative risk value of each attack type based on each key indicator.

[0054] Specifically, the key indicators in network communication include delay anomaly ratio, packet loss rate and encrypted message repetition rate, which are used to monitor man-in-the-middle attacks, packet loss attacks and re-entry attacks, respectively. Therefore, the delay anomaly ratio, packet loss rate and encrypted message repetition rate are recorded as the first, second and third key indicators, respectively, and the monitoring of man-in-the-middle attacks, packet loss attacks and re-entry attacks are recorded as the first, second and third attack types, respectively.

[0055] Furthermore, based on each key indicator and its maximum tolerance value, the relative risk value of each attack type is calculated. The specific calculation formula is: ; Where, Indicates the The relative risk value of the attack type, Indicates the Key indicators, Indicates the The maximum tolerance value of the key indicators, Indicates taking the maximum value.

[0056] It should be noted that when the key indicator does not exceed the maximum tolerance value of the key indicator, ,but =0, that is, when the key indicator does not exceed the maximum tolerance value of the key indicator, the relative risk value of the attack type corresponding to the key indicator is always equal to 0; when the key indicator exceeds the maximum tolerance value of the key indicator, ,but ,At this time, the larger the key indicator is, the greater the relative risk value of the ,attack type corresponding to the key indicator is.

[0057] 4. Take the weighted sum of the relative risk values of each attack type to obtain the attack level of the network communication between the edge node and the cloud.

[0058] Since different types of attacks pose different threats to security, it is necessary to define weights for different attack types to indicate the severity of different attack types. The sum of the weights of all attack types is equal to 1, i.e. ,and 、 、 are greater than 0, 、 、 Represents the weights of the first, second, and third attack types respectively; since the severity of the first, second, and third attack types, namely, man-in-the-middle attack, packet loss attack, and re-entry attack, decreases in turn, In this embodiment, the weights of the first, second, and third attack types are 、 、 They are set to 0.43, 0.35, and 0.22 respectively; in other embodiments, the weights of the first, second, and third attack types can be set according to actual application scenarios and requirements.

[0059] S3. Calculate the maximum theoretical computing power of the edge node based on the hardware configuration of the edge node, calculate the real-time load availability of the edge node based on the current load of the edge node, and obtain the available computing power of the edge node based on the maximum theoretical computing power and current load of the edge node.

[0060] 1. Calculate the maximum theoretical computing power of the edge node based on the hardware configuration of the edge node.

[0061] Specifically, each edge node reports its hardware configuration when registering; the hardware configuration includes CPU main frequency, number of cores, memory capacity and GPU capability.

[0062] Furthermore, the cloud calculates the maximum theoretical computing power of the edge node based on the hardware configuration of the edge node, and then establishes a file of the maximum theoretical computing power of the edge node; the maximum theoretical computing power of the edge node represents the maximum theoretical computing power of the edge node when running at full load, which is related to the hardware performance.

[0063] Among them, the CPU main frequency, core number, memory capacity and GPU capability are recorded as the first computing power influencing factor, the second computing power influencing factor, the third computing power influencing factor and the fourth computing power influencing factor of the edge node respectively.

[0064] Therefore, the calculation formula for the maximum theoretical computing power of the edge node is: ; Where, is the maximum theoretical computing power of the edge node, 、 、 、 They are the first computing power influencing factor, the second computing power influencing factor, the third computing power influencing factor, and the fourth computing power influencing factor of the edge node, is the mapping function of computing power score, 、 、 、 are the first weight, the second weight, the third weight and the fourth weight respectively, 、 、 、 are greater than 0, and .

[0065] In this embodiment, the first weight, the second weight, the third weight and the fourth weight are 、 、 、 They are set to 0.35, 0.3, 0.25, and 0.1 respectively; in other embodiments, the first weight, the second weight, the third weight, and the fourth weight may be set according to actual application scenarios and requirements.

[0066] Mapping function for computing power score : For the first factor affecting computing power, namely the CPU main frequency, each 1GHz corresponds to a score of 100 points; for the second factor affecting computing power, namely the number of cores, each core corresponds to a score of 100 points; for the third factor affecting computing power, namely the memory capacity, each 1GB corresponds to a score of 100 points; for the fourth factor affecting computing power, namely the GPU capability, when the hardware configuration of the edge node has GPU capability, the corresponding score is 100 points; when the hardware configuration of the edge node does not have GPU capability, the corresponding score is 0 points.

[0067] 2. Calculate the real-time load availability of the edge node based on the current load of the edge node.

[0068] Specifically, each edge node periodically sends its current load to the cloud. The current load includes CPU usage and memory usage, both of which are percentages. The cloud calculates the real-time load availability of the edge node based on the current load of the edge node. The real-time load availability indicates the proportion of the edge node's current remaining resources to its maximum resources, which is used to reflect the load status.

[0069] Therefore, the calculation formula for the real-time load availability of edge nodes is: ; Where, is the real-time load availability of the edge node, 、 Indicates the CPU usage and memory usage of the edge node.

[0070] It should be noted that calculating the real-time load availability through the average value of CPU usage and memory usage can dynamically reflect the current load situation of the edge node and provide a basis for calculating the available computing power.

[0071] 3. The cloud calculates the available computing power of the edge node based on the maximum theoretical computing power and real-time load availability of the edge node.

[0072] Specifically, calculate the maximum theoretical computing power of the edge node and real-time load availability of edge nodes The product of and is used to obtain the available computing power of the edge node.

[0073] It should be noted that the actual available computing resources are obtained by comprehensively considering the hardware performance and current load and multiplying the maximum theoretical computing power by the real-time load availability.

[0074] S4. Determine the ratchet stepping cycle of the double ratchet algorithm based on the attack level of the network communication between the edge node and the cloud and the available computing power of the edge node; in the process of generating the key by the double ratchet algorithm, ratchet stepping is performed according to the cycle to achieve the update of the key.

[0075] It should be noted that in high computing power scenarios, frequent key updates can be allowed; in high attack risk scenarios, the frequency of key updates needs to be increased to enhance data security; in low attack risk or low computing power scenarios, the frequency of key updates needs to be reduced to reduce computing overhead; and the greater the frequency of key updates, the shorter the corresponding maximum acceptable period of the edge node; therefore, this embodiment determines the period of ratchet stepping of the double ratchet algorithm based on the attack level of network communication between the edge node and the cloud and the available computing power of the edge node, and dynamically adjusts the period of ratchet stepping based on actual needs to achieve a balance between security and efficiency.

[0076] Specifically, the ratchet stepping cycle of the double ratchet algorithm is determined based on the attack level of the network communication between the edge node and the cloud, as well as the available computing power of the edge node. The calculation formula is: ; Where, Represents the period of ratchet stepping of the double ratchet algorithm, Indicates the attack level of the network communication between the edge node and the cloud. represents the Sigmoid function, Indicates the longest acceptable period of the edge node, Indicates the available computing power of the edge node, Represents the average available computing power of all edge nodes, Indicates the preset length, represents the natural exponential function, Indicates rounding up.

[0077] Among them, all edge nodes refer to all edge nodes communicating with the same cloud, and the average of the available computing power of all edge nodes represents the overall level of available computing power of all edge nodes communicating with the same cloud. It is used to measure the deviation of the available computing power of the current edge node relative to the average computing power of all edge nodes, and then determine the longest acceptable cycle of the edge node, and the available computing power of the edge node The larger the overall level of available computing power, the shorter the maximum acceptable cycle of the edge node, and the greater the frequency of key updates.

[0078] In addition, the frequency of key updates is proportional to the severity of the attack. That is, the higher the attack severity, the more frequently the key needs to be updated to ensure security. Therefore, the greater the attack severity of the network communication between the edge node and the cloud, the shorter the ratchet stepping cycle of the double ratchet algorithm.

[0079] It should be noted that the longest acceptable cycle of the edge node is calculated by the degree of deviation of the available computing power of the edge node relative to the average computing power of all edge nodes and the preset length, so as to reasonably allocate resources according to the computing power differences of the edge nodes and avoid premature key updates of low-computing-power nodes.

[0080] The specific value of the preset length can be set according to the actual application scenario and requirements, and the value range of the preset length is [1,10]. The present invention sets the preset length to 6.

Claims

1. A supply chain data encryption storage method based on edge computing, characterized in that: include: Collect supply chain data through edge devices, and combine the supply chain data collected by multiple edge devices connected to the edge node to form the supply chain data of the edge node; The pre-processed supply chain data of the edge node is encrypted using the key generated by the double ratchet algorithm. The encrypted supply chain data of the edge node is grouped and packaged to form multiple data packets of the edge node and transmitted to the cloud. In the process of generating keys using the double ratchet algorithm, ratchet steps are performed periodically to update the keys. The method for obtaining the ratchet stepping period is as follows: Real-time monitoring of key indicators in the network communication between edge nodes and the cloud. Determine the relative risk value of each attack type based on each key indicator. By weighting the attack type, sum the relative risk values of each attack type to obtain the attack severity of the network communication between the edge node and the cloud. Calculate the maximum theoretical computing power of the edge node based on its hardware configuration; calculate the real-time load availability of the edge node based on its current load; and calculate the product of the maximum theoretical computing power of the edge node and the real-time load availability of the edge node to obtain the available computing power of the edge node. The ratchet stepping cycle of the double ratchet algorithm is determined based on the attack level of the network communication between the edge node and the cloud, as well as the available computing power of the edge node.

2. The supply chain data encryption storage method based on edge computing according to claim 1 is characterized in that: The key indicators in the network communication include delay anomaly ratio, packet loss rate and encrypted message repetition rate, which are respectively used to monitor three types of attacks: man-in-the-middle attack, packet loss attack and re-entry attack; the delay anomaly ratio, packet loss rate and encrypted message repetition rate are recorded as the first, second and third key indicators respectively, and the monitoring of man-in-the-middle attack, packet loss attack and re-entry attack is recorded as the first, second and third attack types respectively.

3. The supply chain data encryption storage method based on edge computing according to claim 2 is characterized in that: Determining the relative risk value of each attack type based on each key indicator includes: Set the maximum tolerance for delay anomaly ratio, packet loss rate, and encrypted message repetition rate; For the Key indicators, , calculate the Key indicators and The difference between the maximum tolerance values of the key indicators is greater than 0, then the The relative risk value of the attack type is equal to the difference between the The ratio of the maximum tolerance values of the key indicators is 0. If the difference is not greater than 0, then The relative risk value of this attack type is equal to 0.

4. The supply chain data encryption storage method based on edge computing according to claim 2 is characterized in that: The weights of the attack types are all greater than 0, and the sum of the weights of all attack types is equal to 1. The weights of the first, second, and third attack types decrease in sequence.

5. The supply chain data encryption storage method based on edge computing according to claim 1 is characterized in that: The hardware configuration of the edge node is reported by the edge node when registering, including CPU main frequency, number of cores, memory capacity and GPU capability, and is recorded as the first computing power influencing factor, second computing power influencing factor, third computing power influencing factor and fourth computing power influencing factor of the edge node respectively.

6. The supply chain data encryption storage method based on edge computing according to claim 5 is characterized in that: Calculating the maximum theoretical computing power of the edge node based on the hardware configuration of the edge node includes: According to the first weight, the second weight, the third weight, and the fourth weight, the computing power scores of the first computing power influencing factor, the second computing power influencing factor, the third computing power influencing factor, and the fourth computing power influencing factor of the edge node are weighted and summed to obtain the maximum theoretical computing power of the edge node; Among them, the first weight, the second weight, the third weight and the fourth weight are all greater than 0, and the sum of all weights is equal to 1.

7. The supply chain data encryption storage method based on edge computing according to claim 5 is characterized in that: The mapping function of the computing power score is: For the first factor affecting computing power, namely the CPU main frequency, the score for each 1GHz is 100 points; for the second factor affecting computing power, namely the number of cores, the score for each core is 100 points; for the third factor affecting computing power, namely the memory capacity, the score for each 1GB is 100 points; for the fourth factor affecting computing power, namely the GPU capability, when the hardware configuration of the edge node has GPU capability, the corresponding score is 100 points; when the hardware configuration of the edge node does not have GPU capability, the corresponding score is 0 points.

8. The supply chain data encryption storage method based on edge computing according to claim 1 is characterized in that: Calculating the real-time load availability of the edge node based on the current load of the edge node includes: Each edge node periodically sends its current load to the cloud, which includes CPU usage and memory usage, both of which are percentages; Calculate the average CPU usage and memory usage of the edge node, and use the difference between 1 and the average value as the real-time load availability of the edge node.

9. The supply chain data encryption storage method based on edge computing according to claim 1 is characterized in that: The step of determining the ratchet stepping cycle of the double ratchet algorithm based on the attack level of the network communication between the edge node and the cloud and the available computing power of the edge node includes: Calculate the longest acceptable cycle of the edge node based on the available computing power of the edge node; Take the negative of the attack level of the network communication between the edge node and the cloud and input it into the Sigmoid function. Multiply the output of the Sigmoid function by 2 and then multiply it by the longest acceptable cycle of the edge node. Round the product up and use the rounded result as the ratchet stepping cycle of the double ratchet algorithm.

10. The supply chain data encryption storage method based on edge computing according to claim 9 is characterized in that: Calculating the longest acceptable period of the edge node based on the available computing power of the edge node includes: Calculate the difference between the available computing power of the edge node and the average of the available computing power of all edge nodes, calculate the ratio of this difference to the average of the available computing power of all edge nodes, take the negative of this ratio, and input it into the natural exponential function. Multiply the output of the natural exponential function by the preset length to obtain the longest acceptable period of the edge node.

Citation Information

Patent Citations

  • Inter-satellite key negotiation method based on cloud network end architecture in space-air-ground integrated network

    CN117221885A

  • Encryption optimization method for data communication

    CN118944952A

  • Double-ratchet password communication method and system based on mixed quantum and asymmetric password

    CN118972049A

  • Medicine supply chain data security method based on multi-mode sensor design

    CN119047685A

  • Group key negotiation method, communication method and device based on dual-ratchet algorithm

    CN119276468A