Distributed key management method based on polynomial pool and trust chain mechanism
By constructing a hierarchical key management architecture based on polynomial pools and trust chains, the problem of inconsistent key management in heterogeneous IoT environments is solved, enabling efficient and secure cross-domain communication and reducing the computing and communication burden on terminal devices.
Patent Information
- Application Number
- CN202511565898.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2025-12-23
AI Technical Summary
Existing technologies lack a unified key management strategy in heterogeneous IoT environments, resulting in inconsistent key generation and management, making it difficult to achieve global collaboration and unified management, and failing to effectively address the differences in encryption requirements under different security domains and cross-domain communication needs.
A distributed key management method based on polynomial pooling and trust chain mechanisms is adopted to construct a layered architecture, including a trust root layer, a domain management layer, and a terminal layer. Key negotiation and management are realized through polynomial pooling and dynamic trust chains, and trust values are dynamically updated. Terminal devices reconstruct session keys through local computation.
It reduces the computing and communication burden on terminal devices, provides a reliable cross-domain authentication mechanism, has good scalability and adaptability, and is suitable for resource-constrained IoT devices.
Smart Images

Figure CN121193533A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of key management, specifically a distributed key management method based on a polynomial pool and trust chain mechanism. Background Technology
[0002] With the rapid development of IoT technology, its applications have permeated various fields such as smart cities, industrial internet, and vehicle networking, forming a complex network ecosystem containing a massive number of heterogeneous devices. In this ecosystem, data is the foundation of network operation, and massive amounts of heterogeneous data are constantly flowing between devices. However, IoT devices usually lack computing and storage resources, so they generally cannot perform complex encryption operations. This inherent resource limitation makes data extremely vulnerable to attacks during transmission, resulting in severe communication security challenges for heterogeneous IoT environments.
[0003] Existing technologies employ a hybrid architecture scheme combining distributed trust mechanisms and key negotiation protocols. This scheme ensures key security and transparency, preventing tampering and abuse, and establishes shared session keys while reducing computational and communication overhead. However, existing technologies still reveal several fundamental shortcomings in complex heterogeneous IoT environments. Due to the lack of unified standards, different device domains often adopt their own independent key management mechanisms, leading to inconsistent key generation and management strategies and making it difficult to achieve global collaboration and unified management. Furthermore, the differences in encryption requirements of IoT devices in different security domains are not considered, and the widespread use of a unified key management strategy fails to achieve the optimal balance between security and resource overhead. Finally, existing technologies often neglect cross-domain communication needs. When two device domains that are unfamiliar with each other and belong to different protocols need to communicate, they lack a trusted and efficient mechanism to establish mutual trust and securely negotiate session keys. Summary of the Invention
[0004] To address the technical problems mentioned in the background section, this invention proposes a distributed key management method based on a polynomial pool and trust chain mechanism.
[0005] Therefore, the technical solution adopted by the present invention is as follows:
[0006] A distributed key management method based on a polynomial pool and trust chain mechanism, the method comprising:
[0007] S1: Construct a hierarchical distributed key management architecture, including a trusted institution in the trust root layer, a domain manager in the domain management layer, and a device domain in the terminal layer. One domain manager manages one device domain. The trusted institution creates a polynomial pool based on a preset key set and simultaneously performs initial trust value rating and key material allocation for the domain managers.
[0008] S2: Establish a dynamic trust chain, periodically update the trust value of the domain manager based on the network behavior of the domain manager, dynamically update the global trust view, and monitor the domain manager.
[0009] S3: The device domain contains several terminal devices. When communication needs arise between the terminal devices, including intra-domain communication and cross-domain communication, the domain manager allocates polynomial shares to the corresponding terminal devices through a key negotiation mechanism based on a bivariate polynomial pool. The terminal devices reconstruct the session key locally by exchanging polynomial shares to establish secure communication. For cross-domain communication, the dynamic trust chain determines whether to establish secure communication.
[0010] Furthermore, the preset key set Represented as:
[0011]
[0012] in, Indicates the first One key; This indicates the number of keys; the trusted authority assigns a unique identifier to each key. A polynomial pool is created based on the preset key set and identifiers.
[0013] The polynomial pool contains a product of a pair of polynomials, the value of which under an identifier is equal to the key corresponding to that identifier.
[0014] Furthermore, the initial trust value rating is the initial trust value assigned to the domain manager by the trusted authority, expressed as:
[0015]
[0016] in, Indicates the initial trust value; This indicates the domain manager's basic security configuration score; This indicates the credibility score of the deployment environment; and These represent the weighting coefficients;
[0017] The key material is allocated as follows: the trusted authority allocates polynomial shares corresponding to the permission level to the domain manager from the polynomial pool, and the key material received by the domain manager is denoted as the polynomial share set. ;
[0018] The trusted institution will temporarily go offline after completing the initial trust value rating and key material allocation.
[0019] Furthermore, the network behaviors of the domain manager are the number of successful interactions, protocol compliance, and network contribution within the evaluation period.
[0020] The number of successful interactions was normalized and converted into a successful interaction score. , represented as:
[0021]
[0022] in, Indicates the number of failed interactions; Indicates the number of successful interactions; Represents positive integers;
[0023] The degree of compliance with the protocol is calculated by counting the number of protocol violations, and is expressed as follows:
[0024]
[0025] in, Indicates agreement compliance score; Indicates the number of times the agreement was violated; Indicates the number of times the agreement has been complied with; Indicates the smoothing parameter;
[0026] The network contribution score, which integrates network contribution behavior, is expressed as follows:
[0027]
[0028] in, Indicates network contribution score; Indicates the first Weighting coefficients for class-specific contribution behaviors; The domain manager is in the Performance score based on contribution behavior;
[0029] Based on the domain manager's network behavior score, obtain the updated trust value of the domain manager at the end of the evaluation period, expressed as:
[0030]
[0031] in, , and These represent the weight coefficients for the three behavioral dimensions;
[0032] The global trust view is composed of the trust values of all domain managers, and is dynamically updated based on the updated trust values of the domain managers.
[0033] The monitoring is referred to as monitoring the network behavior of the domain manager through a dynamic trust chain.
[0034] Furthermore, the intra-domain communication is conducted through a key negotiation mechanism based on a bivariate polynomial pool, specifically,
[0035] 1) Configure terminal devices and Both belong to the domain manager When the terminal device is managed in the same device domain Requires connection to terminal devices When establishing secure communication, the terminal device To the domain manager Initiate a communication request;
[0036] 2) Domain Manager The domain manager verifies the validity of the communication request; if this fails, the domain manager... The domain manager rejects the request and returns an error message to the initiator; if successful, the domain manager... Entering the key material allocation stage;
[0037] 3) Domain Manager For the terminal device from the polynomial share set and Send a pair of single-variable polynomials and ;
[0038] 4) Terminal equipment and exchange and The product of the two polynomials is calculated locally to obtain the key restoration polynomial. , represented as:
[0039]
[0040] Calculate the session key using the key recovery polynomial and identifier. The session key is a key in the preset key set corresponding to the identifier, expressed as:
[0041]
[0042] 5) Terminal equipment and Secure communication is established through symmetric encryption using session keys.
[0043] Furthermore, the cross-domain communication is conducted through a key negotiation mechanism based on a bivariate polynomial pool and a dynamic trust chain, specifically,
[0044] 1) Configure terminal devices By Domain Manager Management, terminal equipment By Domain Manager Management, when terminal devices Requires connection to terminal devices When establishing communication, the terminal device To the domain manager Initiate a communication request;
[0045] 2) Domain Manager The communication request is validated for legitimacy. If it passes the validation, a local query is performed first. If no terminal device is found... Then, a discovery request is sent to other domain managers. After confirming the terminal device After management responds to this request, it sends a message to the domain manager. Send a discovery response message;
[0046] 3) After completing device discovery, the domain manager... Domain Manager The trust verification process is based on a dynamic trust chain and a global trust view. Once verification is successful, the domain manager... and A temporary secure channel will be established, and the terminal device will be provided with access through this temporary secure channel. and Send a pair of univariate polynomials, and the terminal device executes a key negotiation mechanism based on a bivariate polynomial pool to generate a session key for cross-domain communication.
[0047] Compared with the prior art, the advantages of the present invention are as follows:
[0048] 1. This invention constructs a key establishment mechanism based on a bivariate polynomial pool, transforming the complex key negotiation process into efficient computation on the local terminal device. This avoids the use of high-overhead technologies such as blockchain and complex encryption algorithms, thereby greatly reducing the computational and communication burden on the terminal device and making it suitable for various resource-constrained IoT devices.
[0049] 2. This invention designs an access control mechanism based on a dynamic trust chain. By continuously quantifying and evaluating the network behavior of each domain manager in the network, a global and dynamically updated trust view is constructed. This provides a reliable and flexible decision-making basis for authentication and communication between different device domains, effectively solving the cross-domain authentication problem in heterogeneous environments.
[0050] 3. This invention constructs a decoupled, layered distributed key management architecture, which decentralizes core functions such as key distribution and trust management to a collaborative domain manager. This architecture not only avoids single points of failure but also has good scalability and can efficiently adapt to the dynamic changes of IoT devices. Attached Figure Description
[0051] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0052] Figure 1 This is a diagram of the distributed key management architecture of the present invention;
[0053] Figure 2 This is a flowchart of the distributed key management process of the present invention;
[0054] Figure 3 This is a flowchart of the key negotiation mechanism based on a bivariate polynomial pool according to the present invention. Detailed Implementation
[0055] To achieve the above objectives, this invention provides a distributed key management method based on a polynomial pool and trust chain mechanism. Please refer to [link to relevant documentation]. Figures 1-3 The method includes:
[0056] S1: Construct a layered distributed key management architecture, including a trusted authority in the trust root layer, a domain manager in the domain management layer, and device domains in the endpoint layer; the trusted authority creates a polynomial pool based on a preset key set, and simultaneously performs initial trust value rating and key material allocation for the domain manager.
[0057] During the initialization phase, a layered distributed key management architecture is first constructed to ensure the scalability, reliability, and security of key management through a hierarchical management approach. This architecture consists of three layers: from top to bottom, the trusted authority in the root trust layer, the domain manager in the domain management layer, and the device domain in the endpoint layer.
[0058] The trust root layer is composed of trusted institutions, which play a key role in the initial stage of deployment, including creating a bivariate multinomial pool, initializing the trust system, and guiding the establishment of the distributed network. The trusted institutions are only active in the initial stage. After completing the guidance task, the trusted institutions will temporarily go offline, thus avoiding the drawbacks of continuous reliance on trusted third parties in traditional centralized architectures and truly realizing distributed management.
[0059] The domain management layer consists of domain managers, each responsible for managing a device domain. Domain managers are the core entities for network operation, undertaking multiple key functions such as key distribution, trust assessment, and cross-domain coordination. Domain managers cooperate with each other and synchronize information to jointly maintain the secure operation of the entire network. Different domain managers are assigned different levels of permissions and key materials according to the functional positioning and security requirements of the device domains they manage.
[0060] The terminal layer consists of device domains, which contain several terminal devices. Under the management of their respective domain managers, these terminal devices establish secure communication through a lightweight key negotiation mechanism. Terminal devices do not need to maintain complex key management logic; they only need to perform simple local calculations to complete key establishment, thus adapting to resource-constrained IoT environments.
[0061] The first step in the initial phase is to construct a bivariate polynomial pool based on a preset key set. Include Each key is represented as:
[0062]
[0063] For each key in the set A trusted organization assigns it a unique identifier. These identifiers remain unchanged throughout the entire network lifecycle, serving as key parameters in subsequent key recovery processes;
[0064] After defining the key set and identifiers, the trusted institution begins to build a bivariate polynomial pool. The core of the construction process is to design the polynomial pool, which contains several bivariate polynomials. Through appropriate algebraic operations, any key in the preset key set can be recovered from these polynomials.
[0065] To ensure secure distribution and recovery of key materials, the polynomial pool design must satisfy the following requirement: for any key and its corresponding identifier, there exists a pair of single-variable polynomials whose product, under that identifier, equals the key. This requirement ensures that the key can be correctly recovered through polynomial operations.
[0066] Meanwhile, the allocation of polynomials must be exclusive and confidential. Each terminal device obtains a unique share of the univariate polynomial, and without knowing the shares of other univariate polynomials, a single terminal device cannot independently recover any key. Only when two legitimate terminal devices cooperate and exchange their respective polynomial shares can the shared key be recovered through joint computation. This design fundamentally guarantees the security of key management and prevents systemic risks caused by single-point leakage.
[0067] After the trusted authority completes the construction of the polynomial pool, it enters the domain manager initialization phase. The trusted authority establishes secure communication links with all domain managers in the network and performs initial trust value ratings and key material distribution for the domain managers.
[0068] Initial trust rating is the foundation for establishing a dynamic trust chain. Trusted organizations assign trust values to domain managers based on factors such as the domain manager's deployment environment, functional positioning, and hardware security level. An initial trust value is assigned, following the principle of least privilege. This means that a newly joined domain manager receives a lower initial trust value and needs to gradually increase it through subsequent good network behavior. The initial trust value is represented as:
[0069]
[0070] in, Indicates the initial trust value; This indicates the domain manager's basic security configuration score; This indicates the credibility score of the deployment environment; and These represent the weighting coefficients; this formula comprehensively considers the domain manager's own security capabilities and external environmental factors, providing a scientific quantitative starting point for the initial trust value rating.
[0071] The allocation of key materials is a core step. Trusted organizations allocate polynomial shares, i.e., key materials, from the polynomial pool to domain managers based on their functional partitions and security levels. In this embodiment, for a domain manager that manages a critical infrastructure domain, the trusted organization allocates high-order polynomial shares or polynomial shares associated with high-security-level keys; for a domain manager that manages a general sensor domain, relatively simple polynomial shares are allocated. This differentiated allocation strategy ensures that adaptable key management services can be provided in scenarios with different security requirements.
[0072] The key material received by the domain manager is denoted as the polynomial share set. Each polynomial share corresponds to a specific key recovery path, enabling the domain manager to negotiate the corresponding session key for the managed terminal devices. The exponent and coefficient information of the polynomial share constitute the core key material of the domain manager and must be securely stored and prevented from being leaked.
[0073] After completing the initialization configuration of all domain managers, the trusted authority broadcasts an initialization completion message to the entire network and then goes offline temporarily. At this point, the operation of the network depends entirely on the collaboration between domain managers and no longer requires the participation of the trusted authority. This design significantly improves the robustness and scalability of key management and avoids the risk of single point of failure.
[0074] S2: Establish a dynamic trust chain, periodically update the domain manager's trust value based on the domain manager's network behavior, dynamically update the global trust view, and monitor the domain manager.
[0075] Dynamic trust chain is a core innovation in solving cross-domain authentication problems. This trust chain builds a global, dynamically evolving trust view by continuously monitoring and quantifying the network behavior of domain managers, providing a reliable basis for decision-making in cross-domain communication.
[0076] The dynamic updating of trust values is based on the actual behavior of the domain manager during network operation. Three key behavioral dimensions are defined as quantitative indicators for trust value evaluation: number of successful interactions, protocol compliance, and network contribution.
[0077] The number of successful interactions reflects the activity and reliability of the domain manager in network collaboration. The interaction counter increments when a domain manager successfully completes a key negotiation, trust information synchronization, or other collaborative task with another domain manager. During the evaluation period, the number of successful interactions by the domain manager is recorded as follows: To avoid the infinite growth of ratings caused by simple accumulation, a normalization process is adopted, converting the number of interactions into standardized ratings, and assigning ratings to successful interactions. Represented as:
[0078]
[0079] in, Indicates the number of failed interactions; This represents a very small positive number; the range of values for this score is... A higher value indicates a higher success rate and greater reliability in the interaction with the domain manager.
[0080] Protocol compliance measures how well the domain manager adheres to network protocol specifications during communication within the evaluation period. In this embodiment, the network defines a set of standard protocol behaviors, including the correctness of message format, the timeliness of response time, and the initiative in key updates. During each interaction, the network monitors whether the domain manager strictly follows the protocol requirements, and a protocol compliance score is assigned. Calculated by counting the number of protocol violations, expressed as:
[0081]
[0082] in, Indicates the number of times the agreement was violated; Indicates the number of times the agreement has been complied with; Indicates the smoothing parameter;
[0083] The network contribution assessment evaluates the domain manager's positive contribution to the overall network ecosystem. In this embodiment, contribution behaviors include actively participating in key update propagation, assisting other domain managers in completing cross-domain authentication, and providing network topology information; network contribution scoring is also included. The calculation takes into account a weighted sum of multiple contribution behaviors, and is expressed as:
[0084]
[0085] in, Indicates the first Weighting coefficients for class-specific contribution behaviors; The domain manager is in the Performance scores for contribution behaviors; in this embodiment, the behavior of actively initiating key updates is given a higher weight, while the behavior of passively responding to requests is given a relatively lower weight;
[0086] Based on the scores from three behavioral dimensions, a weighted summation method is used to merge the scores from the three dimensions to obtain the trust value updated by the domain manager at the end of the evaluation period. , represented as:
[0087]
[0088] in, , and These represent the weight coefficients for the three behavioral dimensions. In this embodiment, the specific values of the weight coefficients can be adjusted according to the security requirements of the application scenario. For example, in scenarios with high security requirements, the weight of protocol compliance can be adjusted. This can be set to a higher value, which increases the weight of network contribution in scenarios that emphasize network collaboration. Then it should be improved.
[0089] The global trust view is composed of the trust values of all domain managers. Through continuous trust assessment and information synchronization, the entire network maintains a dynamically evolving global trust view. This view accurately reflects the real-time trust status of each domain manager, providing a scientific basis for access control of cross-domain communication. When the network topology changes, a new domain manager is added, or the behavior pattern of an existing domain manager changes, the global trust view can be updated in a timely manner to ensure that access control decisions are always based on the latest trust information.
[0090] The entire network monitors the behavior of domain managers through a dynamic trust chain. Once any malicious behavior (such as message replay or authentication failure) or security vulnerability is detected, the corresponding domain manager will be punished. Punishment measures include immediately lowering the trust value or even temporarily or permanently removing the domain manager from the trust chain. If a domain manager is removed from the trust chain, the domain manager's key materials will be declared invalid and revoked. This revocation information will be quickly propagated throughout the network through the trust chain to ensure that malicious domain managers are effectively isolated and prevent further harm to the network.
[0091] S3: The device domain contains several terminal devices. When communication needs arise between the terminal devices, including intra-domain communication and cross-domain communication, the domain manager allocates polynomial shares to the corresponding terminal devices through a key negotiation mechanism based on a bivariate polynomial pool. The terminal devices reconstruct the session key locally by exchanging polynomial shares to establish secure communication. For cross-domain communication, the dynamic trust chain determines whether to establish secure communication.
[0092] Each device domain contains several terminal devices, and each device domain is managed by a domain manager. The domain manager is responsible for allocating polynomial shares to the terminal devices within the device domain. When there is a communication requirement between terminal devices in the device domain, whether it is intra-domain communication or cross-domain communication, a key negotiation mechanism based on a bivariate polynomial pool is required to achieve secure communication.
[0093] When both communicating parties are located within the same device domain, it is called intra-domain communication. The key negotiation process is relatively straightforward, with the domain manager of that device domain responsible for coordinating and distributing key materials. In this embodiment, typical applications of intra-domain communication scenarios include device communication within the same smart home network and sensor data exchange on the same industrial production line.
[0094] Configure terminal devices and Both belong to the domain manager When the terminal device is managed in the same device domain Requires connection to terminal devices When establishing secure communication, the terminal device First, communicate with the domain manager. Initiate a communication request. The request information includes the identifiers of both communicating parties and relevant parameters of the communication session, such as session type and expected communication duration.
[0095] Domain Manager Upon receiving a communication request, a legitimacy verification is first performed. This verification process includes checking whether both the initiator and the target are legitimate members of the device domain, whether the initiator has permission to communicate with the target, and whether the session parameters comply with the domain security policy. If verification fails, the domain manager... The domain manager rejects the request and returns an error message to the initiator; if authentication succeeds, the domain manager... Entering the key material distribution phase,
[0096] Key material allocation generates unique single-variable polynomial shares for each communicating party, and the domain manager... From the set of multinomial sum-based shares held, select or derive two univariate polynomials. and These two univariate polynomials must correspond to the same session key recovery path; that is, there exists a key identifier that allows the product of the two polynomials to recover the preset key. Furthermore, these two univariate polynomials must be dedicated to this session and cannot be reused with polynomial shares from other sessions to ensure the independence and forward security of the session key.
[0097] After generating polynomial shares, the domain manager Send secure channels to terminal devices respectively and terminal equipment Each terminal device sends its own polynomial share. In this embodiment, the secure channel can be a symmetric encryption channel based on a pre-shared key or an asymmetric encryption channel based on the domain manager's public key. To prevent replay attacks and man-in-the-middle attacks, the domain manager includes a timestamp and session identifier when sending the polynomial share. The terminal device verifies the validity of this information upon receiving it.
[0098] The terminal devices receive their respective polynomial shares and store them in a secure storage area. At this point, each communicating party holds a single-variable polynomial but neither knows the other's polynomial content nor can they independently calculate the session key. The key recovery process requires cooperation between the two communicating parties. The terminal devices exchange their respective polynomial shares through an end-to-end secure channel. The exchange process can use anonymous or encrypted channels to prevent third-party eavesdropping on the polynomial content.
[0099] After completing the polynomial exchange, the terminal device calculates the product of the two polynomials locally to obtain the key recovery polynomial. , represented as:
[0100]
[0101] The key restoration polynomial is not the final session key, but an intermediate product. This polynomial encodes information about the session key, but further evaluation is required to extract the actual key value. According to the design principle of the polynomial pool, there exists a preset key identifier such that the value of the key restoration polynomial under this identifier equals a key in the preset key set, expressed as:
[0102]
[0103] Since both communicating parties perform the exact same computation process, using the same polynomial and the same key identifier, the session key is calculated independently by both parties. The fact that the keys must be identical ensures the consistency of key negotiation, allowing communicating parties to establish a shared key without additional key transmission or verification.
[0104] After obtaining the session key, the terminal device can use it for symmetric encrypted communication. In this embodiment, the session key can be directly used as the key for a symmetric encryption algorithm, such as AES, or it can be used as a seed key to generate a set of subkeys through a key derivation function, which are used for different purposes such as encryption, message authentication, and integrity protection.
[0105] The entire intra-domain key negotiation process is remarkably lightweight. The terminal device only needs to perform one polynomial multiplication and one polynomial evaluation, which has a computational complexity far lower than that of traditional public-key cryptography algorithms. The degree of the polynomial is usually set to a small value, such as 5 to 10, so that the multiplication and evaluation operations can be completed efficiently on resource-constrained IoT devices. In addition, the terminal device does not need to maintain a complex key management state, and the polynomial share can be deleted after use, reducing storage overhead and the risk of key leakage.
[0106] When the communicating parties belong to different device domains, it is called cross-domain communication. The key negotiation process requires coordination from their respective domain managers and must be conducted under the constraints of a dynamic trust chain. In this embodiment, cross-domain communication scenarios are widely found in large-scale Internet of Things (IoT) applications, such as energy management coordination between different smart buildings and traffic information sharing between different vehicle network subnets.
[0107] Configure terminal devices By Domain Manager Management, terminal equipment By Domain Manager Management, when terminal devices Requires connection to terminal devices When establishing communication, the terminal device First, communicate with the domain manager. Initiate a communication request. The request information includes the identifiers of both communicating parties and relevant parameters of the communication session.
[0108] Domain Manager Upon receiving a communication request, its validity is verified. If successful, a local query is performed first. If no terminal device is found... Then, a discovery request will be sent to other domain managers on the network. After confirming the terminal device After management responds to this request, it sends a message to the domain manager. Send a discovery response message.
[0109] After completing device discovery, the domain manager Domain Manager The process then enters the mutual authentication and trust verification phase, a crucial step in cross-domain communication that directly determines whether a secure cross-domain channel can be established. Trust verification is based on a dynamic trust chain and a global trust view; only after successful verification can the domain manager proceed. and Only then will a temporary secure channel be established, and a set of polynomials be negotiated for the terminal devices of both parties. Finally, each party sends its share of the polynomials to the terminal device, which can then execute a key negotiation mechanism based on a bivariate polynomial pool to generate a session key for secure cross-domain communication.
[0110] This invention proposes a distributed key management method based on a polynomial pool and trust chain mechanism. By constructing a hierarchical distributed key management architecture, it leverages the collaboration of trusted institutions, domain managers, and terminal devices to improve the security and efficiency of key management. Specifically, firstly, a polynomial pool is created at the root trust layer and key materials are allocated to the domain manager; next, a dynamic trust chain is established, and its trust value is periodically updated based on the domain manager's network behavior; finally, a key negotiation mechanism based on a bivariate polynomial pool is used to generate secure keys for intra-domain and cross-domain communication.
[0111] In summary, this invention optimizes distributed key management through a layered structure and dynamic trust mechanism, ensuring the security of cross-domain communication while reducing the computational and communication burden on terminal devices. It also offers enhanced scalability and configurability. The layered architecture decouples trust management from key distribution and allows trusted institutions to create and distribute polynomial pools with different security levels based on the security requirements of different device domains. Due to the simplicity of its mechanism, it can be easily deployed on various heterogeneous terminal devices. This design is not only easily scalable but also enables differentiated security services to meet the specific needs of different IoT scenarios, which is unmatched by existing single-architecture solutions.
[0112] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A distributed key management method based on a polynomial pool and trust chain mechanism, characterized in that, The method includes: S1: Construct a hierarchical distributed key management architecture, including a trusted institution in the trust root layer, a domain manager in the domain management layer, and a device domain in the terminal layer. One domain manager manages one device domain. The trusted institution creates a polynomial pool based on a preset key set and simultaneously performs initial trust value rating and key material allocation for the domain managers. S2: Establish a dynamic trust chain, periodically update the trust value of the domain manager based on the network behavior of the domain manager, dynamically update the global trust view, and monitor the domain manager. S3: The device domain contains several terminal devices. When communication needs arise between the terminal devices, including intra-domain communication and cross-domain communication, the domain manager allocates polynomial shares to the corresponding terminal devices through a key negotiation mechanism based on a bivariate polynomial pool. The terminal devices reconstruct the session key locally by exchanging polynomial shares to establish secure communication. For cross-domain communication, the dynamic trust chain determines whether to establish secure communication.
2. The distributed key management method based on polynomial pooling and trust chain mechanism according to claim 1, characterized in that, The preset key set Represented as: in, Indicates the first One key; This indicates the number of keys; the trusted authority assigns a unique identifier to each key. A polynomial pool is created based on the preset key set and identifiers. The polynomial pool contains a product of a pair of polynomials, the value of which under an identifier is equal to the key corresponding to that identifier.
3. The distributed key management method based on polynomial pooling and trust chain mechanism according to claim 2, characterized in that, The initial trust value rating is the initial trust value assigned to the domain manager by the trusted authority, expressed as: in, Indicates the initial trust value; This indicates the domain manager's basic security configuration score; This indicates the credibility score of the deployment environment; and These represent the weighting coefficients; The key material is allocated as follows: the trusted authority allocates polynomial shares corresponding to the permission level to the domain manager from the polynomial pool, and the key material received by the domain manager is denoted as the polynomial share set. ; The trusted institution will temporarily go offline after completing the initial trust value rating and key material allocation.
4. The distributed key management method based on polynomial pooling and trust chain mechanism according to claim 1, characterized in that, The network behaviors of the domain manager are the number of successful interactions, protocol compliance, and network contribution within the evaluation period. The number of successful interactions was normalized and converted into a successful interaction score. , is represented as: in, Indicates the number of failed interactions; Indicates the number of successful interactions; Represents positive numbers; The degree of compliance with the protocol is calculated by counting the number of protocol violations, and is expressed as follows: in, Indicates agreement compliance score; Indicates the number of times the agreement was violated; Indicates the number of times the agreement has been complied with; Indicates the smoothing parameter; The network contribution score, which integrates network contribution behavior, is expressed as follows: in, Indicates network contribution score; Indicates the first Weighting coefficients for class-specific contribution behaviors; The domain manager is in the Performance score based on contribution behavior; Based on the domain manager's network behavior score, obtain the updated trust value of the domain manager at the end of the evaluation period, expressed as: in, , and These represent the weight coefficients for the three behavioral dimensions; The global trust view is composed of the trust values of all domain managers, and is dynamically updated based on the updated trust values of the domain managers. The monitoring is referred to as monitoring the network behavior of the domain manager through a dynamic trust chain.
5. A distributed key management method based on a polynomial pool and trust chain mechanism according to claim 3, characterized in that, The intra-domain communication is conducted through a key negotiation mechanism based on a bivariate polynomial pool, specifically, 1) Configure terminal devices and Both belong to the domain manager When the terminal device is managed in the same device domain Requires connection to terminal devices When establishing secure communication, the terminal device To the domain manager Initiate a communication request; 2) Domain Manager The domain manager verifies the validity of the communication request; if this fails, the domain manager... Reject and return an error message to the initiator; If successful, the domain manager Entering the key material allocation stage; 3) Domain Manager For the terminal device from the polynomial share set and Send a pair of single-variable polynomials and ; 4) Terminal equipment and exchange and The product of the two polynomials is calculated locally to obtain the key restoration polynomial. , is represented as: Calculate the session key using the key recovery polynomial and identifier. The session key is a key in the preset key set corresponding to the identifier, represented as: 5) Terminal equipment and Secure communication is established through symmetric encryption using session keys.
6. A distributed key management method based on a polynomial pool and trust chain mechanism according to claim 4 or 5, characterized in that, The cross-domain communication is conducted through a key negotiation mechanism based on a bivariate polynomial pool and a dynamic trust chain, specifically, 1) Configure terminal devices By Domain Manager Management, terminal equipment By Domain Manager Management, when terminal devices Requires connection to terminal devices When establishing communication, the terminal device To the domain manager Initiate a communication request; 2) Domain Manager The communication request is validated for legitimacy. If it passes the validation, a local query is performed first. If no terminal device is found... Then, a discovery request is sent to other domain managers. After confirming the terminal device After management responds to this request, it sends a message to the domain manager. Send a discovery response message; 3) After completing device discovery, the domain manager... and Domain Manager The trust verification process is based on a dynamic trust chain and a global trust view. Once verification is successful, the domain manager... and A temporary secure channel will be established, and the terminal device will be provided with access through this temporary secure channel. and Send a pair of univariate polynomials, and the terminal device executes a key negotiation mechanism based on a bivariate polynomial pool to generate a session key for cross-domain communication.