Smart home equipment security login method and system based on NDN (Named Data Networking)
By generating key pairs through the NTRU algorithm and embedding them in the certificate chain, and combining the hybrid verification path of blockchain and lightweight proof, the problems of low certificate verification efficiency and inaccurate trust assessment in smart home device login are solved, and an efficient and secure device login and migration process is achieved.
Patent Information
- Application Number
- CN202511083780.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-08-04
AI Technical Summary
In the existing NDN-based smart home device login method, the certificate verification mechanism is inefficient and the device trust assessment is inaccurate, which cannot meet the strict security and reliability requirements of smart home devices.
The NTRU algorithm is used to generate key pairs, private keys are securely stored, and public keys are embedded in the device certificate chain. After verification, the home gateway synchronizes the certificate chain hash to the blockchain. The edge NDN router adopts a hybrid verification path, combining Bloom filters and MerklePatriciaTrie lightweight proofs for certificate verification, and calculates real-time trust values based on device behavior time series data. When migrating devices, historical trust values are combined for weighted evaluation.
It greatly improves the efficiency of certificate verification and the accuracy of device trust assessment, ensures the security and reliability of device login and migration, adapts to different security demand scenarios, and improves the security, efficiency and reliability of smart home devices.
Smart Images

Figure CN120811713A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of smart home network security, and particularly relates to a smart home device security login method and system based on NDN. BACKGROUND
[0002] With the rapid development of the Internet of Things technology, the number of smart home devices is rapidly increasing, and the home network environment is becoming increasingly complex. The traditional network architecture based on the TCP / IP protocol exposes many security problems in the smart home scenario, such as vulnerable device identity authentication, easy eavesdropping and tampering of data transmission, and the like. Meanwhile, when the smart home device migrates between different gateways, how to quickly and safely complete the authentication is also a difficult problem to be solved.
[0003] NDN (Named Data Networking, named data networking) is a new emerging future network architecture, which is content-centric and can effectively improve the content retrieval efficiency and transmission performance by naming and routing content data. Applying NDN to the smart home field provides a new idea for solving the above problems. However, the current smart home device login method based on NDN still has some deficiencies, such as an inefficient certificate verification mechanism, an inaccurate device trust evaluation, and the like, which cannot fully meet the strict requirements of smart home devices for security and reliability. SUMMARY
[0004] The application provides a smart home device security login method and system based on NDN to solve the problems of inefficient certificate verification mechanism and inaccurate device trust evaluation in the prior art.
[0005] The first aspect of the application provides a smart home device security login method based on NDN, which comprises the following steps: a smart home device generates a key pair based on an NTRU algorithm, a private key is securely stored by the device, a public key is embedded in a device certificate chain, and the device certificate chain is submitted to a home gateway; after the home gateway verifies the validity of the device certificate chain, a dynamic naming prefix is generated, the certificate chain is stored, and the certificate chain hash is synchronized to a blockchain network; the device uses the dynamic naming prefix to construct an interest packet with a digital signature, after an edge NDN router receives the interest packet, the certificate chain is verified through a hybrid verification path; the router calculates a real-time trust value based on device behavior time series data, if the real-time trust value is greater than a preset threshold, a quantum hybrid encrypted data packet is returned, otherwise, infrared light encoding secondary authentication is triggered; when the device migrates to a new gateway, the new gateway obtains the historical trust value and the certificate chain of the device through the blockchain network, the historical trust value is combined with the real-time trust value for weighted evaluation, if the evaluation result is higher than a migration trust threshold, the authentication is quickly completed, otherwise, infrared light encoding secondary authentication is triggered.
[0006] Preferably, the weighted evaluation of the historical trust value combined with the real-time trust value comprises:
[0007] The historical trust value and the real-time trust value are weighted and calculated, and the formula of the weighted calculation is:
[0008] T 综合 = 0.6T 历史 + 0.4T 实时
[0009] Wherein, T 历史 is the historical trust value mean recorded by the block chain, and T 实时 is the real-time trust value calculated by the current gateway;
[0010] If the weighted calculation result is higher than the preset migration trust threshold of the new gateway, the part of the authentication permission level of the original network is used;Otherwise, the infrared light coding secondary authentication is triggered.
[0011] Preferably, the infrared light coding secondary authentication specifically includes that the gateway generates a random number sequence, sends the coded infrared light signal through the infrared transmitter at a specific frequency;The device receives and decodes the infrared light signal to obtain the random number sequence, and uses the private key to encrypt and sign;The device returns the encrypted signature through the NDN interest package, and the gateway uses the device public key to verify the signature, and the secondary authentication is completed if the verification is passed.
[0012] Preferably, the device migration includes that the new gateway requires the device to submit a migration request interest package with digital signature;The migration request interest package is verified, the device certificate chain public key stored in the block chain is called for matching, and if the device identity is consistent with the original network registration information, the weighted evaluation authentication is executed.
[0013] Preferably, the mixed verification path includes: preferentially querying the local certificate cache of the edge NDN router, and the local certificate cache adopts SRAM storage;If the local certificate cache is not hit, a certificate query request is initiated to the preconfigured light node of the block chain, and the certificate query of the light node of the block chain uses the lightweight proof of MerklePatriciaTrie;It is verified whether the root certificate of the certificate chain matches the main certificate public key pre-stored by the home gateway.
[0014] Preferably, the capacity of the local certificate cache is ≤15KB, the size of the lightweight proof of MerklePatriciaTrie is ≤600 bytes, and the cache of the light node of the block chain adopts a bloom filter for the certificate revocation status, and the false negative rate is ≤0.05%.
[0015] Preferably, the router calculates the real-time trust value based on the device behavior time sequence data, and the formula of the real-time trust value is:
[0016]
[0017] Wherein, α is the attenuation factor, N successfor the number of successful interactions, F abnormal for the frequency of abnormal requests, for the historical trust value, β is a coefficient of successful interactions, γ is a coefficient of abnormal requests, δ is a coefficient of environmental risks, R env for the environmental risk factor.
[0018] Preferably, the dynamic naming prefix is periodically updated by the home gateway, and the update period is 15-30 minutes, wherein the dynamic naming prefix comprises a spatial domain, a device type and exclusive identification information.
[0019] The second aspect of the application provides a kind of based on NDN's smart home equipment security login system, comprising: generation module, for smart home equipment based on NTRU algorithm generates key pair, private key is securely stored by equipment, public key is embedded in device certificate chain, submits device certificate chain to home gateway;Storage module, for home gateway after verifying the validity of device certificate chain, generates dynamic naming prefix, stores certificate chain and synchronizes certificate chain hash to blockchain network;Verification module, for device using dynamic naming prefix constructs interest package with digital signature, after edge NDN router receives interest package, certificate chain is verified by hybrid verification path;Computing module, for router based on equipment behavior time series data calculates real-time trust value, if real-time trust value is greater than preset threshold, then return quantum hybrid encryption data packet, otherwise, trigger infrared light coding secondary authentication;Authentication module, for when device migrates to new gateway, new gateway obtains the historical trust value of equipment and certificate chain through blockchain network, historical trust value is combined with real-time trust value to carry out weighted evaluation, if evaluation result is higher than migration trust threshold then fast complete authentication, otherwise trigger infrared light coding secondary authentication.
[0020] The third aspect of the application provides an electronic device, comprising: a memory, a processor and a computer program stored in the memory and executable on the processor, the processor executes the program to perform a kind of based on NDN's smart home equipment security login method as described in the above embodiment.
[0021] Therefore, the application includes the following beneficial effects:
[0022] The key pair is generated by means of the NTRU algorithm in the embodiments of the present application, and the public key is embedded in the device certificate chain, the home gateway synchronizes the certificate chain hash to the blockchain after verification, provides a reliable basis for verification, the edge NDN router adopts a hybrid verification path, preferentially queries the local SRAM certificate cache, obtains information by using the lightweight proof of the blockchain light node when a hit is not made, combines the certificate revocation status of the Bloom filter cache and has a low false positive rate, and the certificate verification efficiency is greatly improved; in device trust evaluation, the router calculates real-time trust values based on device behavior time series data, and comprehensively considers multiple factors such as attenuation factor and successful interaction times, the new gateway performs weighted evaluation on the historical trust value and the real-time trust value obtained by the blockchain when the device migrates, so that the evaluation is more accurate and comprehensive. At the same time, the dynamic name prefix is periodically updated, the interest packet with a digital signature is constructed, and the like, which ensures the security of device login and migration, different authentication strategies are adopted according to the real-time trust value, different security requirement scenarios are flexibly adapted, and the security, efficiency and reliability of the smart home device login are comprehensively improved. Thus, the problems of inefficient certificate verification mechanism and inaccurate device trust evaluation in the prior art are solved.
[0023] Additional aspects and advantages of the present application will be made apparent by the following description and the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS
[0024] The above and / or additional aspects and advantages of the present application will become apparent and be more readily understood through consideration of the following description, taken in conjunction with the accompanying drawings, in which:
[0025] Figure 1 A flowchart of a smart home device security login method based on NDN provided according to an embodiment of the present application;
[0026] Figure 2 A structural schematic diagram of a smart home device security login system based on NDN provided according to an embodiment of the present application;
[0027] Figure 3 A structural schematic diagram of an electronic device provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0028] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0029] A method and system for secure login of smart home devices based on NDN are described below with reference to the accompanying drawings. In view of the low efficiency of the certificate verification mechanism mentioned in the background art, the present application provides a method for secure login of smart home devices based on NDN. In this method, a key pair is generated by means of the NTRU algorithm, and the public key is embedded in the device certificate chain. After verification by the home gateway, the certificate chain hash is synchronized to the blockchain, providing a reliable basis for verification. The edge NDN router uses a hybrid verification path, preferentially querying the local SRAM certificate cache, and when a hit is not found, using the lightweight proof of the blockchain light node to obtain information. Combining the Bloom filter cache certificate revocation status and low false positive rate, the certificate verification efficiency is greatly improved. In terms of device trust evaluation, the router calculates the real-time trust value based on device behavior timing data, taking into account factors such as decay factor and number of successful interactions. When the device is migrated, the new gateway combines the historical trust value obtained from the blockchain with the real-time trust value for weighted evaluation, making the evaluation more accurate and comprehensive. At the same time, dynamic naming prefixes are periodically updated, and interest packets with digital signatures are constructed to ensure the security of device login and migration. Different authentication strategies are adopted according to the real-time trust value, flexibly adapting to different security requirement scenarios, and the security, efficiency and reliability of smart home device login are comprehensively improved. Thus, the problems of low efficiency of certificate verification mechanism and inaccurate device trust evaluation in the prior art are solved.
[0030] Figure 1 A flowchart of a method for secure login of smart home devices based on NDN is provided for the embodiments of the present application.
[0031] As shown in Figure 1 , the method for secure login of smart home devices based on NDN includes the following steps:
[0032] In step S101, the smart home device generates a key pair based on the NTRU algorithm, the private key is securely stored by the device, and the public key is embedded in the device certificate chain, which is submitted to the home gateway.
[0033] The NTRU algorithm is a lattice-based public key encryption algorithm, and the key pair is composed of a private key and a public key. The private key is securely stored by the device and used for operations such as data encryption and signature. The public key is embedded in the device certificate chain and can be publicly used to verify signed and encrypted data. The device certificate chain is a chain composed of multiple certificates, containing device-related information and the signature of each level of certificate, used to prove the legitimacy of the device identity, and the public key embedded therein ensures the authenticity and relevance of the public key.
[0034] It can be understood that the key pair generated by the NTRU algorithm in the embodiments of the present application is adapted to the characteristics of the limited resources of the smart home device by using the efficient encryption characteristics thereof, the private key is securely stored to ensure that the device identity is unique and cannot be forged, and the public key is embedded in the certificate chain to bind the key and the device identity; the process of submitting the certificate chain to the home gateway is the first declaration of the legality of the device identity, and also provides the original basis for subsequent gateway verification, dynamic naming allocation and blockchain storage.
[0035] In step S102, after the home gateway verifies the validity of the device certificate chain, a dynamic naming prefix is generated, the certificate chain is stored, and the certificate chain hash is synchronized to the blockchain network.
[0036] The dynamic naming prefix is periodically updated by the home gateway, and the update period is 15-30 minutes. The dynamic naming prefix includes a spatial domain, a device type and exclusive identification information.
[0037] It can be understood that in the embodiments of the present application, the home gateway verifies the validity of the device certificate chain, which can ensure that the access device identity is legal and intercepts illegal devices from the source; the dynamic naming prefix is generated, which can provide a unique and dynamically updated network identifier for the device, and enhance the security of the identity identifier; the certificate chain is stored for local quick query and verification, and the certificate chain hash is synchronized to the blockchain network, which can permanently retain the integrity and authenticity proof of the certificate chain by using the tamper-proof characteristics of the blockchain, and provide trusted data support for subsequent cross-gateway verification, device migration and other scenarios, while realizing distributed storage and traceability of the certificate chain, and improving the security and reliability of the entire login system.
[0038] It should be noted that the dynamic naming prefix has clear hierarchy and identification, wherein the spatial domain (such as / livingroom / bedroom) accurately locates the physical position of the device, the device type (such as / camera / lock) clearly distinguishes the functional attribute of the device, and the exclusive identification information (such as the hash value of the unique serial number of the device) ensures the uniqueness of each device in the network. This structured naming method not only facilitates the NDN network to quickly identify and route the device, but also enables intuitive judgment of the basic information of the device during device interaction through the naming prefix, thereby providing a basis for the formulation of access control policies. The periodic update of 15-30 minutes further significantly reduces the risk of prefix information being maliciously intercepted and reused. Even if the prefix information is accidentally leaked, the automatic update within a short period of time can also cut off the impersonation path of illegal devices, further reinforcing the security of the device identity from the identification layer, forming a synergistic effect with the certificate chain verification, blockchain storage and other mechanisms, and building a multi-level security protection system.
[0039] In step S103, the device constructs a digitally signed interest packet using a dynamic naming prefix, and the edge NDN router receives the interest packet and verifies the certificate chain through a hybrid verification path.
[0040] The interest packet can be a data packet used for requesting data in an NDN network, and the device constructs a digitally signed interest packet using a dynamic naming prefix, which contains relevant identification information of the device and is used for requesting services or data from the network. The digital signature can ensure the authenticity and integrity of the interest packet.
[0041] It can be understood that, in the embodiment of the application, the device constructs a digitally signed interest packet using a dynamic naming prefix, which can ensure the timeliness and security of the device identity based on the uniqueness and periodic updating characteristics of the dynamic naming prefix, and can ensure the authenticity and integrity of the interest packet through the digital signature to prevent tampering or forgery. After receiving the interest packet, the edge NDN router verifies the certificate chain through a hybrid verification path, preferentially queries the local SRAM cache to improve the verification efficiency, and obtains information by means of the lightweight proof of the blockchain light node when the cache is not hit, and combines the tamper-proof nature of the blockchain to ensure the validity of the certificate chain. This method not only reduces the network transmission overhead, but also guarantees the accuracy of the verification, thereby building a security barrier at the request initiation stage of the device, laying a reliable foundation for subsequent trust evaluation and authentication decision, and effectively improving the security and efficiency of the entire login process.
[0042] Specifically, the interest packet is named as / {space domain} / {device type} / auth / {device fingerprint} / {timestamp}. The {device fingerprint} is generated by SHA-384 hash processing of hardware identifiers such as IMEI and MAC address, which not only preserves the uniqueness but also does not expose the original information. The {timestamp} is accurate to milliseconds and has a validity period of ±3 seconds, which can prevent replay attacks and avoid repeated use of the interest packet after being maliciously intercepted. The digital signature is generated by encrypting the interest packet naming and payload using the device private key, and the edge NDN router decrypts and verifies it using the device certificate chain public key to ensure that the interest packet has not been tampered with and is from a real source through matching verification.
[0043] In the embodiment of the application, the hybrid verification path includes: preferentially querying the local certificate cache of the edge NDN router, and the local certificate cache uses SRAM storage; if the local certificate cache is not hit, a certificate query request is initiated to the preconfigured blockchain light node, the certificate query of the blockchain light node uses the lightweight proof of MerklePatriciaTrie; and it is verified whether the certificate chain root certificate matches the master certificate public key pre-stored by the home gateway.
[0044] The capacity of the local certificate cache is less than or equal to 15KB, the lightweight proof size of the Merkle Patricia Trie is less than or equal to 600 bytes, and the certificate revocation state of the blockchain light node is cached by using a Bloom filter, and the error rate is less than or equal to 0.05%.
[0045] It can be understood that, by preferentially querying the certificate cache stored in the SRAM of the edge NDN router, the application embodiment realizes the rapid retrieval of the certificate by using the high-speed read-write characteristics of the SRAM, and significantly improves the verification efficiency of the high-frequency access device; when the local cache is not hit, the query is initiated to the blockchain light node, and the Merkle Patricia Trie lightweight proof is used, so that the data transmission amount is reduced, and the certificate chain authenticity is ensured by means of the tamper-proof property of the blockchain; finally, the matching of the certificate chain root certificate and the pre-stored master certificate public key of the home gateway is verified, and a three-layer verification mechanism of “local efficient query+distributed storage of the blockchain+root certificate authority verification” is formed, which not only reduces the network load and response delay, but also eliminates the risk of forged certificates passing the verification through multi-layer verification, and provides an efficient and reliable proof for the legality of the device identity.
[0046] Specifically, the capacity of the local certificate cache is limited to less than or equal to 15KB, which can meet the needs of storing the certificates of high-frequency access devices, avoid occupying too many edge router resources due to too large cache, and ensure the rapid retrieval of frequently used certificates through accurate cache strategy, thereby further optimizing the verification response speed; the lightweight proof size of the Merkle Patricia Trie is less than or equal to 600 bytes, which greatly reduces the data transmission amount in the certificate query process, reduces the network bandwidth occupation, makes the cross-node verification more efficient, and is especially suitable for low-bandwidth communication scenarios between devices and edge nodes, and between devices and blockchain light nodes in the smart home network; and the certificate revocation state of the blockchain light node is cached by using a Bloom filter and the error rate is less than or equal to 0.05%, which controls the probability of false judgment at a very low level while quickly screening the revoked certificates and reducing invalid verification operations, thereby ensuring the accuracy of the verification and avoiding the efficiency loss caused by frequent query of the complete revocation list. The fine setting of these parameters achieves an optimal balance between efficiency, resource occupation and security, and makes the advantages of the three-layer verification mechanism more fully exerted.
[0047] In step S104, the router calculates a real-time trust value based on the device behavior time sequence data, and returns the quantum hybrid encryption data packet if the real-time trust value is greater than a preset threshold, otherwise, triggers infrared light coding secondary authentication.
[0048] The real-time trust value reflects the current trust degree of the device, and is used to determine which authentication strategy to use. The preset threshold can be specifically set, for example, 70.
[0049] It can be understood that the router in the embodiment of the application calculates a real-time trust value based on device behavior time sequence data, comprehensively reflects the current trust degree of the device, and takes this as a basis for authentication strategy selection: when the real-time trust value is greater than a preset threshold, a quantum hybrid encryption data packet is returned, and data transmission is guaranteed by relying on high security encryption technology; otherwise, infrared light coding secondary authentication is triggered, and security is enhanced through additional verification. This dynamically adaptive authentication mechanism not only adopts differentiated protection strategies for devices of different trust degrees to ensure efficient communication of high-trust devices and intensifies verification for low-trust devices, balances the security and convenience requirements in the smart home scene while improving the efficiency of the login process, and can also adjust the protection level in real time through the change of the trust value, forming a dynamic security barrier to effectively balance the security and convenience requirements in the smart home scene.
[0050] In the embodiment of the application, the router calculates a real-time trust value based on device behavior time sequence data, and the formula of the real-time trust value is:
[0051]
[0052] wherein, a is a decay factor, N success is the number of successful interactions, F abnormal is the abnormal request frequency, is a historical trust value, β is a successful interaction coefficient, γ is an abnormal request coefficient, δ is an environmental risk coefficient, R env is an environmental risk factor.
[0053] Specifically, assuming that there is a smart camera in the home network, the gateway (router) needs to calculate the real-time trust value of the smart camera and determine whether to open the "cloud video upload" permission for it.
[0054] Set the initial values: a = 0.6, β = 2, γ = 3, δ = 1.5
[0055] Stable improvement of device trust value: N success = 10, F abnormal = 0, R env = 1
[0056] Substitute the formula to calculate:
[0057] Therefore, the trust value 42.5 is high (assuming that the threshold value 30 is opened), and the gateway directly allows the camera to upload the video, because it is "historically clean + current behavior rules + environmental safety", and is judged as a "trusted device".
[0058] In the embodiment of the present application, the infrared light coding secondary authentication specifically includes: the gateway generates a random number sequence, and sends the coded infrared light signal at a specific frequency through an infrared transmitter; the device receives and decodes the infrared light signal to obtain the random number sequence, and uses a private key to encrypt and sign; the device returns the encrypted signature through an NDN interest packet, and the gateway verifies the signature using the public key of the device, and completes the secondary authentication if the verification is passed.
[0059] It can be understood that, in the embodiment of the present application, the infrared light coding secondary authentication forms a secure closed loop through the infrared signal interaction between the gateway and the device and the encrypted signature verification, reduces the interception risk by using the physical characteristics of the infrared signal, provides additional verification for low-trust devices or migration substandard devices by combining the one-time use of random numbers and the non-forgery of asymmetric encryption, effectively prevents counterfeiting and illegal access, and strengthens the login security level.
[0060] Specifically, the random number sequence generated by the gateway has a length of 128 bits, and is sent at an industrial standard frequency of 38 kHz through an infrared transmitter. The frequency is in the commonly used frequency band of infrared communication, which not only ensures the stability of signal transmission, but also reduces interference with other household appliance infrared signals. The infrared light signal adopts Manchester coding mode to convert binary random numbers into optical pulse sequences, each data bit corresponds to 2 pulse periods, and the jump of high and low levels ensures the accuracy of device decoding and avoids misreading caused by signal attenuation or noise. After receiving, the device not only needs to correctly decode the random number sequence, but also needs to complete the private key encryption signature within 5 seconds. The encryption process of the private key adopts the combination of NTRU algorithm and SHA-256 hash, to generate a 1024-bit digital signature, which not only retains the lightweight characteristics of the key, but also prevents the signature from being tampered through hash operation. The signature information in the NDN interest packet returned by the device is encapsulated in a special signature field, and is associated with the prefix of the interest packet name for association verification. When the gateway verifies, it first matches the legality of the prefix, and then decrypts the signature using the public key in the device certificate chain, and compares the consistency of the decryption result with the original random number sequence.
[0061] In step S105, when the device is migrated to a new gateway, the new gateway obtains the historical trust value and the certificate chain of the device through the blockchain network, the historical trust value is combined with the real-time trust value for weighted evaluation, and if the evaluation result is higher than the migration trust threshold, the authentication is completed quickly, otherwise the infrared light coding secondary authentication is triggered.
[0062] The migration trust threshold can be a critical value preset by the new gateway for judging whether the device migration is completed quickly or not.
[0063] It can be understood that when the device migrates to a new gateway, the new gateway obtains the historical trust value and the certificate chain of the device by means of the tamper-proofing feature of the blockchain, and performs weighted evaluation on the historical trust value and the real-time trust value to form a comprehensive judgment on the trustworthiness of the device. If the evaluation result is higher than the migration trust threshold, the authentication can be quickly completed to reduce the repeated verification steps and improve the convenience of the device in the cross-gateway use; if the threshold is not reached, the infrared light coding secondary authentication is triggered to prevent potential risks through additional security checks. This mechanism not only realizes reliable traceability and sharing of device trust information through the blockchain, but also balances the security and efficiency in the migration scenario through dynamic evaluation, ensuring that the trusted device can quickly access the new network, while the risk device is strengthened for control, and the overall security of the smart home cross-gateway environment is ensured.
[0064] In the embodiments of the present application, the device migration includes: the new gateway requiring the device to submit a migration request interest package with a digital signature; verifying the migration request interest package, calling the device certificate chain public key stored in the blockchain for matching, and if the device identity is consistent with the original network registration information, performing weighted evaluation authentication.
[0065] It can be understood that the embodiments of the present application ensure the authenticity and integrity of the migration request through digital signature, and realize cross-gateway trusted verification of the device identity by means of the public key stored in the blockchain, thereby eliminating the risk of fake migration request from the source; only after the identity is confirmed to be consistent, the weighted evaluation is performed, which not only ensures the accuracy of the evaluation object, but also avoids invalid processing of illegal devices, further improving the security and efficiency of the device migration authentication, and providing rigorous pre-checking protection for the trusted migration of cross-gateway devices.
[0066] In the embodiments of the present application, the historical trust value is combined with the real-time trust value for weighted evaluation, including: performing weighted calculation on the historical trust value and the real-time trust value, wherein the formula of the weighted calculation is:
[0067] T 综合 = 0.6T 历史 + 0.4T 实时
[0068] Wherein, T 历史 is the historical trust value mean recorded in the blockchain, and T 实时 is the real-time trust value calculated by the current gateway.
[0069] If the weighted calculation result is higher than the migration trust threshold preset by the new gateway, the authentication permission level of the original network is followed; otherwise, the infrared light coding secondary authentication is triggered.
[0070] Wherein, the migration trust threshold can be a critical value preset by the new gateway for judging whether the authentication is quickly completed when the device migrates.
[0071] It can be understood that the historical trust value and the real-time trust value are weighted and calculated in the embodiments of the present application, which can comprehensively evaluate the trustworthiness of the device based on the past performance and the current state. If the result is higher than the migration trust threshold, the original network part authentication permission level is followed, the fast login after device migration is realized, and the convenience is improved. If the threshold is not reached, the infrared light coding secondary authentication is triggered, the security is strengthened through additional verification, the potential risks are prevented through the secondary authentication, the security and efficiency in the device migration scene are balanced, and the reliability and flexibility of cross-gateway login are ensured.
[0072] The present application provides a smart home device security login method based on NDN, generates a key pair by means of NTRU algorithm and embeds the public key into a device certificate chain, synchronizes the certificate chain hash to the blockchain after the home gateway verification, provides a reliable basis for verification, and adopts a hybrid verification path for the edge NDN router, preferentially queries the local SRAM certificate cache, obtains information by means of the lightweight proof of the blockchain light node when the cache is not hit, combines the certificate revocation state and the low misjudgment rate of the Bloom filter, and greatly improves the certificate verification efficiency. In the device trust evaluation, the router calculates the real-time trust value based on the device behavior time sequence data, comprehensively calculates the real-time trust value based on multiple factors such as the decay factor and the number of successful interactions, and makes a weighted evaluation of the historical trust value and the real-time trust value obtained by the new gateway when the device is migrated, so that the evaluation is more accurate and comprehensive. At the same time, the dynamic name prefix is periodically updated, the interest packet with digital signature is constructed, and the like, which ensures the security of device login and migration, adopts different authentication strategies according to the real-time trust value, flexibly adapts to different security demand scenes, and comprehensively improves the security, efficiency and reliability of smart home device login. Thus, the problems of inefficient certificate verification mechanism and inaccurate device trust evaluation in the prior art are solved.
[0073] The smart home device security login method based on NDN will be described below through a specific embodiment, taking the process of a certain brand of smart camera accessing the home network and migrating to a new gateway as an example, and specifically describing the practical application of the smart home device security login method based on NDN:
[0074] Device initial login process:
[0075] Key generation and certificate submission (step S101): the smart camera generates a key pair based on the NTRU algorithm, the private key is stored in the built-in security chip of the device, and the public key is embedded in the certificate chain composed of the manufacturer root certificate, the device model certificate and the device individual certificate. After the device is started, the certificate chain is submitted to the home gateway, and the certificate chain contains the MAC address, the factory number and other identification information of the camera.
[0076] Gateway verification and information synchronization (step S102): After receiving the certificate chain, the home gateway verifies the signature validity of each level of the certificate, and generates a dynamic name prefix / livingroom / camera / auth / 8f7d3e... / 1620000000000 (where 8f7d3e... is the device fingerprint after the device MAC address is hashed by SHA-384, and 1620000000000 is the timestamp) after confirming that there is no error, and updates it every 20 minutes. At the same time, the gateway stores the certificate chain and synchronizes its hash value a1b2c3... to the blockchain network.
[0077] Interest packet construction and certificate verification (step S103): The camera uses the dynamic name prefix to construct an interest packet with a digital signature, requesting the "cloud video upload" service. The digital signature of the interest packet is encrypted by the device private key for the name and payload parts. After receiving, the edge NDN router queries the local 15KB SRAM certificate cache first, and since it is the first access and does not hit, it initiates a query to the blockchain light node, obtains the certificate chain information through the MerklePatriciaTrie lightweight proof within 600 bytes, and finally verifies that the certificate chain root certificate matches the manufacturer's master certificate public key pre-stored by the gateway, completing the certificate verification.
[0078] Trust evaluation and authentication response (step S104): The router calculates the real-time trust value based on the behavior time series data of the camera, and gets a real-time trust value of 29.5. Since the preset threshold is 30, the real-time trust value is slightly low, triggering the infrared light coding secondary authentication. The gateway generates a 128-bit random number sequence and sends it through a 38kHz infrared transmitter in Manchester coding. After decoding by the camera, a 1024-bit digital signature is generated within 5 seconds using the private key (NTRU algorithm combined with SHA-256 hash), which is returned through the NDN interest packet. The gateway verifies that the signature and the original random number are consistent using the device public key, completes the secondary authentication, and allows the camera to upload the video.
[0079] Device migration process
[0080] When the camera is taken to a new home and connected to a new gateway:
[0081] Migration request and identity verification: The new gateway requires the camera to submit a migration request interest packet with a digital signature, and verifies the certificate chain public key stored in the blockchain to confirm that the device identity and original network registration information are consistent.
[0082] Trust weighted evaluation and authentication: The new gateway obtains the historical trust value mean T historγ = 75 of the camera from the blockchain, and combines it with the real-time trust value T realtime= 65, calculated according to the weighted formula T = 0.4 * 75 + 0.6 * 65 = 30 + 39 = 69. If the preset migration trust threshold of the new gateway is 60, the evaluation result 69 is higher than the threshold, the authentication is quickly completed, and the "720P video upload" permission of the original network is used; if the threshold is set to 70, the infrared light coding secondary authentication is triggered, and the device is allowed to access only after passing the secondary authentication.
[0083] In summary, by generating a key pair through the NTRU algorithm and submitting a certificate chain containing the public key, a dynamic name prefix is generated after verification by the home gateway, and the certificate chain hash is synchronized to the blockchain. The certificate verification is completed by means of the hybrid verification path of the edge NDN router, and then it is decided whether to trigger the infrared light coding secondary authentication through real-time trust value evaluation, forming a multi-link cooperative secure login mechanism. When migrating to a new gateway, the new gateway verifies the device identity through the blockchain, and determines the authentication mode by combining the weighted evaluation of the historical and real-time trust values.
[0084] Next, the NDN-based smart home device secure login system according to the embodiments of the present application is described with reference to the accompanying drawings.
[0085] The embodiments of the present application provide an NDN-based smart home device secure login system, as shown in Figure 2 The NDN-based smart home device secure login system 10 includes a generation module 100, a storage module 200, a verification module 300, a calculation module 400, and an authentication module 500.
[0086] The generation module 100 is configured to generate a key pair based on the NTRU algorithm for the smart home device, store the private key securely, embed the public key in the device certificate chain, and submit the device certificate chain to the home gateway. The storage module 200 is configured to generate a dynamic name prefix after the home gateway verifies the validity of the device certificate chain, store the certificate chain, and synchronize the certificate chain hash to the blockchain network. The verification module 300 is configured to use the dynamic name prefix to construct an interest packet with digital signature for the device, and the edge NDN router receives the interest packet and verifies the certificate chain through a hybrid verification path. The calculation module 400 is configured to calculate the real-time trust value based on the device behavior time series data, and if the real-time trust value is greater than the preset threshold, return the quantum hybrid encrypted data packet, otherwise trigger the infrared light coding secondary authentication. The authentication module 500 is configured to obtain the historical trust value and the certificate chain of the device through the blockchain network when the device migrates to a new gateway, perform weighted evaluation on the historical trust value and the real-time trust value, and if the evaluation result is higher than the migration trust threshold, quickly complete the authentication, otherwise trigger the infrared light coding secondary authentication.
[0087] It should be noted that the aforementioned explanation and description of the NDN-based smart home device secure login method embodiments also apply to the NDN-based smart home device secure login system of this embodiment, which will not be described here.
[0088] The application embodiment provides a smart home device security login system based on NDN. A key pair is generated by means of an NTRU algorithm, and a public key is embedded in a device certificate chain. After verification by a home gateway, the certificate chain is synchronized to a block chain, providing a reliable basis for verification. An edge NDN router adopts a hybrid verification path, preferentially queries a local SRAM certificate cache, and obtains information by means of a lightweight proof of a block chain light node when a hit is not obtained. In combination with a Bloom filter, a certificate revocation state is cached, and a false rejection rate is low, so that the certificate verification efficiency is greatly improved. In device trust evaluation, the router calculates a real-time trust value based on device behavior time sequence data, in combination with multiple factors such as a decay factor and a successful interaction number. When a device is migrated, a new gateway performs weighted evaluation on a real-time trust value and a historical trust value obtained by means of the block chain, so that the evaluation is more accurate and comprehensive. Meanwhile, dynamic naming prefixes are periodically updated, and an interest packet is constructed with a digital signature, so as to guarantee device login and migration security. Different authentication strategies are adopted according to a real-time trust value, so as to flexibly adapt to different security requirement scenes, and the security, efficiency and reliability of smart home device login are comprehensively improved. Thus, the problems of an inefficient certificate verification mechanism and inaccurate device trust evaluation in the prior art are solved.
[0089] Figure 3 A structural schematic diagram of an electronic device is provided for the application embodiment. The electronic device can include:
[0090] The memory 301, the processor 302 and the computer program stored in the memory 301 and executable on the processor 302.
[0091] The processor 302 implements the smart home device security login method based on NDN provided in the above embodiment when executing the program.
[0092] Further, the electronic device further includes:
[0093] The communication interface 303 is used for communication between the memory 301 and the processor 302.
[0094] The memory 301 is used for storing the computer program executable on the processor 302.
[0095] The memory 301 can include a high-speed RAM (Random Access Memory, random access memory) memory, and can also include a non-volatile memory, for example, at least one disk memory.
[0096] If the memory 301, the processor 302 and the communication interface 303 are implemented independently, the communication interface 303, the memory 301 and the processor 302 can be connected with each other through a bus and complete communication between each other. The bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 3 Only one thick line is used in the figure to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0097] Optionally, in a specific implementation, if the memory 301, the processor 302 and the communication interface 303 are integrated on a chip, the memory 301, the processor 302 and the communication interface 303 can complete communication between each other through an internal interface.
[0098] The processor 302 can be a CPU (Central Processing Unit), or an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present application.
[0099] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example" or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms is not necessarily for the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples without contradiction.
[0100] In addition, the terms "first", "second" are only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, for example, two, three, etc., unless otherwise specifically limited.
[0101] Any process or method described in a flowchart or otherwise described herein can be understood as representing code modules, segments, or portions of code that include one or more executable instructions for implementing the specified logical functions or steps, and the various embodiments of the application include alternative implementations of the described processes or methods, in which the order of steps can be changed, including substantially simultaneously or in reverse order, depending on the functionality involved, which should be understood by those having ordinary skill in the art.
[0102] It should be understood that portions of the present application can be realized with hardware, software, firmware or a combination thereof. In the above embodiments, a plurality of steps or methods can be realized with software or firmware stored in a memory and executed by a suitable instruction execution system. As such, if realized with hardware, as in another embodiment, any one or a combination of the following technologies known in the art can be used: discrete logic circuitry having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.
[0103] Those skilled in the art of the present technology can understand that all or part of the steps carried out by the above-mentioned embodiment method can be completed by a program instructing the relevant hardware, and the program can be stored in a computer readable storage medium, and the program includes one or a combination of the steps of the method embodiment when executed.
[0104] Although the above has shown and described the embodiments of the present application, it should be understood that the above-mentioned embodiments are exemplary and cannot be understood as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above-mentioned embodiments within the scope of the present application.
Claims
1. A secure login method for smart home devices based on NDN, characterized in that: The following steps are involved: Smart home devices generate key pairs based on the NTRU algorithm. The private key is securely stored by the device, and the public key is embedded in the device certificate chain, which is then submitted to the home gateway. After verifying the validity of the device certificate chain, the home gateway generates a dynamic naming prefix, stores the certificate chain, and synchronizes the certificate chain hash to the blockchain network; The device uses the dynamic naming prefix to construct a digitally signed Interest packet. After receiving the Interest packet, the edge NDN router verifies the certificate chain through the hybrid verification path. The router calculates a real-time trust value based on the device's behavior time series data. If the real-time trust value is greater than the preset threshold, it returns a quantum hybrid encrypted data packet. Otherwise, it triggers infrared light coding secondary authentication. When a device is migrated to a new gateway, the new gateway obtains the device's historical trust value and certificate chain through the blockchain network. The historical trust value is combined with the real-time trust value for weighted evaluation. If the evaluation result is higher than the migration trust threshold, the authentication is completed quickly. Otherwise, infrared light coding secondary authentication is triggered.
2. The NDN-based smart home device secure login method according to claim 1, characterized in that: The historical trust value is combined with the real-time trust value for weighted evaluation, including: The historical trust value and the real-time trust value are weighted and calculated, where the weighted calculation formula is: T 综合 =0.6T 历史 +0.4T 实时 Among them, T 历史 is the historical trust value average of blockchain records, T 实时 The real-time trust value calculated for the current gateway; If the weighted calculation result is higher than the migration trust threshold preset by the new gateway, part of the authentication authority level of the original network will be used; otherwise, infrared light coding secondary authentication will be triggered.
3. The NDN-based smart home device secure login method according to claim 1, characterized in that: Infrared light coding secondary authentication specifically includes: The gateway generates a random number sequence and sends a coded infrared light signal at a specific frequency through an infrared transmitter; The device receives and decodes the infrared light signal to obtain a random number sequence and encrypts the signature using the private key; The device returns an encrypted signature through the NDN Interest packet, and the gateway verifies the signature using the device's public key. If the verification is successful, the secondary authentication is completed.
4. The NDN-based smart home device secure login method according to claim 1, characterized in that: Equipment migration includes: The new gateway requires the device to submit a migration request interest packet with a digital signature; The migration request interest packet is verified and the public key of the device certificate chain stored in the blockchain is called for matching. If the device identity is consistent with the original network registration information, weighted evaluation authentication is performed.
5. The NDN-based smart home device secure login method according to claim 1, characterized in that: The hybrid verification path includes: Prioritize querying the local certificate cache of the edge NDN router, which is stored in SRAM. If the local certificate cache does not hit, a certificate query request is sent to the pre-configured blockchain light node. The certificate query of the blockchain light node uses the lightweight proof of MerklePatriciaTrie; Verify that the root certificate in the certificate chain matches the public key of the primary certificate stored in the home gateway.
6. The NDN-based smart home device secure login method according to claim 5, characterized in that: The capacity of the local certificate cache is ≤15KB, the lightweight proof size of MerklePatriciaTrie is ≤600 bytes, and the blockchain light node uses a Bloom filter to cache the certificate revocation status, with a false positive rate of ≤0.05%.
7. The NDN-based smart home device secure login method according to claim 1, characterized in that: The router calculates the real-time trust value based on the device behavior time series data. The formula for the real-time trust value is: Among them, α is the attenuation factor, N success is the number of successful interactions, F abnormal is the abnormal request frequency, is the historical trust value, β is the successful interaction coefficient, γ is the abnormal request coefficient, δ is the environmental risk coefficient, R env Environmental risk factors.
8. The NDN-based smart home device secure login method according to claim 1, characterized in that: The dynamic naming prefix is periodically updated by the home gateway with an update cycle of 15-30 minutes. The dynamic naming prefix includes the spatial domain, device type and unique identification information.
9. A system for a secure login method for smart home devices based on NDN according to any one of claims 1 to 8, characterized in that: include: The generation module is used for smart home devices to generate key pairs based on the NTRU algorithm. The private key is securely stored by the device, and the public key is embedded in the device certificate chain, which is then submitted to the home gateway. The storage module is used by the home gateway to verify the validity of the device certificate chain, generate a dynamic naming prefix, store the certificate chain, and synchronize the certificate chain hash to the blockchain network; The verification module is used by devices to construct digitally signed Interest packets using dynamic naming prefixes. After receiving the Interest packets, the edge NDN router verifies the certificate chain through the hybrid verification path. The calculation module is used by the router to calculate the real-time trust value based on the device behavior time series data. If the real-time trust value is greater than the preset threshold, the quantum hybrid encryption data packet is returned; otherwise, the infrared light coding secondary authentication is triggered; The authentication module is used when a device is migrated to a new gateway. The new gateway obtains the device's historical trust value and certificate chain through the blockchain network. The historical trust value is combined with the real-time trust value for weighted evaluation. If the evaluation result is higher than the migration trust threshold, the authentication is completed quickly. Otherwise, infrared light coding secondary authentication is triggered.
10. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement a secure login method for a smart home device based on NDN as claimed in any one of claims 1 to 8.
Citation Information
Patent Citations
Low earth orbit satellite Internet of Things access authentication method based on NTRU algorithm
CN111416656A
Cross-domain authentication bridging method and system oriented to industrial Internet of Things interconnection
CN120050088A
Vehicle-mounted ad hoc network security communication system and method based on NTRU lattice cryptosystem
CN120200750A
Multi-factor authentication system
WO2003032126A2