An in-nas safety method and system for controlling marine internet of things
Patent Information
- Application Number
- CN202610328583.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-18
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2046-03-18
AI Technical Summary
[0003]然而,现有解决方案存在显著局限:
针对资源管理割裂问题:通过协同优化引擎对任务完成时间、资源能耗与系统安全风险进行联合建模,并引入物理运动状态作为调节维度,实现通、感、算、控的深度耦合,解决了协同效能低下的问题。针对安全机制外挂问题:硬件层面构建基于PUF的内生安全架构,软件层面将动态可信度评分引入安全风险量化值的计算,进而引入控制策略的生成,使安全能力从外挂式变为原生属性,解决了安全机制外挂与业务任务流深度脱节的问题。针对环境适应性差问题:利用动态可信度评分实时感知安全态势,并通过轻量级区块链记录全过程关键决策,确保系统在动态复杂环境下具备闭环规避与审计溯源能力,解决了在动态极端环境下鲁棒性不足的问题。
Smart Images

Figure CN121887537B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of marine Internet of Things (IoT) technology, and in particular to an intrinsically safe marine IoT control method and system. Background Technology
[0002] As the core carrier of the marine information sensing and processing system, the marine Internet of Things (IoT) forms an integrated "air, space, sea, and shore" network by deploying heterogeneous nodes such as smart buoys, autonomous underwater vehicles, shipborne mobile platforms, offshore fixed facilities, and shore-based data centers in a vast sea area. It aims to achieve real-time, continuous, and intelligent sensing and control of marine environmental parameters, target activity status, and equipment operation status.
[0003] However, existing solutions have significant limitations: (1) Fragmented resource management and low system coordination efficiency: Existing marine monitoring systems usually adopt a "chimney" design, with communication, sensing, computing and control subsystems operating independently and lacking a unified "brain". Especially in the physical control dimension, existing systems often lack real-time closed-loop feedback based on perception and security situation, which makes it impossible for the system to optimize its operational performance through physical displacement or attitude adjustment when the environment changes suddenly.
[0004] (2) The security mechanism is external and vulnerable, making it difficult to cope with special threats in the ocean: Existing security solutions are usually added as "add-on modules" in the later stages of system design. This external security is not only statically configured, but also deeply decoupled from the business task flow. The security mechanism cannot perceive the fluctuations of underlying communication and computing resources, making it difficult to achieve a balance between security strength and system energy efficiency, resulting in unnecessary protocol overhead.
[0005] (3) Poor adaptability to dynamic extreme environments and insufficient system robustness: The topology of marine networks changes dynamically due to node movement and ship navigation. Most existing resource management and task scheduling algorithms are based on simplified or static model assumptions, which are difficult to cope with such multidimensional and time-varying constraints. This leads to: ① the predetermined task offloading or communication path quickly failing in dynamic environments; ② a lack of effective online monitoring and replanning capabilities, resulting in high task failure rates and poor auditing and tracing capabilities.
[0006] In view of this, this invention is hereby proposed. Summary of the Invention
[0007] The purpose of this invention is to address the shortcomings of existing technologies by proposing an intrinsically safe marine Internet of Things (IoT) control method and system. This method considers safety as an intrinsic attribute and deeply integrates and intelligently links communication, sensing, computing, and control resources, resulting in high efficiency, reliability, and safety.
[0008] To achieve the above objectives, the present invention adopts the following technical solution: An intrinsically safe marine Internet of Things (IoT) control method includes the following steps: Step 1: Edge computing nodes or management platforms perform key binding and sensing data integrity verification based on PUF and hash algorithms; edge computing nodes analyze the verified sensing data, generate task intents when trusted events are identified, and digitally sign the task intents; Step 2: After verifying the digital signature, the management platform receives the task intent and performs security and resource situation assessments, constructing a dual situation assessment result that includes both security and resources. Specifically, a dynamic credibility score T for security situation assessment is generated based on the node's historical behavior audit results, security configuration compliance, and responses to periodic remote authentication challenges. i (t); Step 3: Optimize based on task completion time, resource consumption, and system security risk quantification, where the system security risk quantification includes a dynamic reliability score T. i (t); and under the premise of satisfying safety constraints, solve the control strategy, which includes the safety configuration strategy, as well as one or more of the node's perception sampling parameters, communication protocol configuration and physical motion state; Step 4: The control policy generated in Step 3 is sent to the corresponding nodes. After the nodes establish a secure channel and configure the computing environment according to the security configuration policy, they execute the task. The key decisions and data flow information of the whole process are recorded in a distributed ledger based on a lightweight blockchain for auditing and traceability.
[0009] Furthermore, in step 1, key binding and perceived data integrity verification are completed through the following steps: Step 1.1: Before system deployment, write the initial challenge C0, call PUF to output a unique response R0, use BCH error correction code to correct R0, and use SHA... 256 The hash algorithm processes the error-corrected R0, derives the binding key Key, and stores C0 and the error-correction parameter P. HD ; Step 1.2: When the aircraft stores data locally, the original data D is split into several data blocks D. n Calculate the hash value H of each data block. n =SHA 256 (D n The integrity tag Tag=AES is generated using the key Key for encryption. Encrypt (Key,H n ), of which AES Encrypt The symmetric encryption algorithm ultimately stores the data according to the following storage structure: (D n +Tag+C0); Step 1.3: When the aircraft is powered on, it is determined whether each hardware module is valid; when the aircraft is running, the data blocks stored locally are sampled and verified periodically. If a tag mismatch is found, the data block with the mismatched tag is marked and isolated. Step 1.4: When the aircraft sends data D to the mother ship, extract the data stored in Step 1.2 (D) sequentially. n +Tag+C0), compressed using a compression algorithm, and finally transmitted to the mother ship after adding a CRC32 check code; Step 1.5: After receiving the compressed package, the mother ship verifies the legality of the data and the aircraft; Step 1.6: After each voyage mission is completed, the mother ship sends a new challenge C1 to the spacecraft, and the old challenge C0 becomes invalid, reducing the risk of leakage of the old challenge C0.
[0010] Furthermore, in step 1.3, when the aircraft is powered on, the following steps are used to determine whether each hardware module is valid: Step A.1: Call the PUF of each hardware module, input C0, regenerate the response R0', and derive the key Key' after error correction; Step A.2: Determine whether the key Key' can successfully decrypt the Tag. If it can, the hardware module is valid. In step 1.3, during the operation of the aircraft, when periodically sampling and verifying the data blocks stored locally, the following steps are used to determine whether the tag matches: Step B.1: Call the PUF of each hardware module, input C0, regenerate the response R0', and derive the key Key' after error correction; Step B.2: For D n Recalculate hash value H n '=SHA 256 (D n ); Use the key Key' to encrypt and generate an integrity tag Tag'=AES Encrypt (Key',H n Step B.3: Determine if Tag' and Tag are equal; if so, match.
[0011] Furthermore, step 1.5 includes the following steps: Step C.1: Decompress to obtain D n Tag and C0 are used to filter transmission errors using CRC32 checksum. Step C.2: The mother ship invokes the PUF of the aircraft, inputs C0, regenerates the response R0', and derives the key Key' after error correction; Step C.3: Decompress the obtained D n Recalculate hash value H n '=SHA 256 (D n ); Use the key Key' to decrypt the decompressed Tag to obtain the original hash value H. origin =AES Decrypt(Key',Tag); Step C.4: Determine H n 'with H origin Check if they are equal; if so, the data is valid. Step C.5: Determine if the key Key' can be generated normally. If the key Key' can be generated normally, then the aircraft is a legitimate device.
[0012] Furthermore, in step 2, the dynamic credibility score T is generated through the following steps. i (t): Step 2.1: Calculate the historical behavior audit score H of node i. i (t), the formula is as follows: ; In the formula, λ represents the forgetting factor, and R0 i (τ) represents the execution result of a single task at time τ. Represents a nonlinear mapping function; Step 2.2: Calculate the security configuration compliance score C for node i. i (t), the formula is as follows: ; In the formula, M represents the number of types of security problems. This indicates the current severity of the k-th type of security problem. This represents the tolerance threshold for the k-th type of security problem. Represents the ReLU operator. Indicates the basic configuration compliance rate; Step 2.3: Calculate the delay score S latency Cryptographic Response Score crypto The formula is as follows: ; ; In the formula, This represents the response delay at the q-th iteration. This represents the historical baseline delay (sliding window mean). Indicates network jitter variance. Indicates the number of challenges. This shows the actual response to the j-th challenge. This represents the expected correct response to the j-th challenge. Indicates the correctness of the response, denoted by 0 or 1. and The value is 1 when they are completely identical, and 0 in all other cases. Energy consumption / electromagnetic characteristics during response. for Reference value, Indicates the normalization factor; Step 2.4: Compute node i's remote authentication response score A i (t), the formula is as follows: ; In the formula, β is the weighting coefficient; Step 2.5: Calculate the dynamic credibility score T of node i. i (t), T i (t)∈[0,1], the calculation formula is as follows: ; In the formula, , , These are the weighting coefficients.
[0013] Furthermore, in step 3, the optimization objective is constructed through the following steps: Step 3.1: Calculate the task completion time C eff The formula is as follows: ; In the formula, Indicates the travel time of an underwater vehicle. Indicates the sending time. Indicates transmission time; Step 3.2: Calculate resource consumption C res The formula is as follows: ; In the formula, Indicates the propulsion power of an underwater vehicle. Indicates transmission power. Indicates the remaining battery power; Step 3.3: Calculate the system security risk quantification value Rsec, using the following formula: ; In the formula, This represents the value of the y-th task. Let represent the threat probability of the y-th task; Step 3.4: Calculate the optimization objective, using the following formula: ; In the formula, , , , , , , They are respectively , , The maximum and minimum values.
[0014] Furthermore, in step 3, security constraints include privacy constraints, integrity constraints, and authentication constraints. Privacy constraints: Data transmission or computation involving sensitive information must be processed using privacy computing techniques based on cryptography or trusted hardware, i.e., restricting sensitive information from appearing in plaintext form in untrusted memory or channels. Integrity constraints: Critical computation tasks must be assigned to nodes with trusted execution environments or hardware roots of trust to ensure that critical tasks such as seismic source location are not maliciously tampered with or injected with false data during execution. Authentication constraints: All nodes through which the task flows must undergo two-way authentication based on the unique identity generated by their PUF, i.e., ensuring that policy instructions are issued from a legitimate management platform and that the execution node is a verified legitimate device. In step 3, the security configuration strategy includes: assigning a lightweight encryption algorithm suite and session key of corresponding strength to the specified data transmission link; assigning a privacy computing technology type to the specified computing task, including secure multi-party computation, federated learning, or trusted execution environment; and adding a dynamic access control policy based on attribute-based encryption to the task data.
[0015] Furthermore, step 4 completes the distribution and execution of the control policy through the following steps: Step 4.1 Policy Distribution Phase: The control policy generated in Step 3 is distributed to the corresponding nodes, and the nodes use the policy security compiler to convert the control policy into specific physical drive instructions; Step 4.2 Environment Construction Phase: The local policy execution engine of the node device instantiates the intrinsic security environment according to the compiled security configuration policy, that is, delineates the TEE and establishes the security channel; Step 4.3 Synchronous Sensing and Control Linkage Stage: The local policy execution engine of the node device calls its external drive module to drive the vehicle to dive 5-10 meters to avoid the surface noise interference zone. Within the constructed TEE environment, the data compression ratio is increased. The lightweight encryption suite and session key allocated by the policy are used to ensure that the critical seismic wave alarm data can still maintain high reliability of transmission under narrow bandwidth. Step 4.4 Audit and Traceability Stage: Record key decisions and data flow information throughout the process in a distributed ledger based on a lightweight blockchain for audit and traceability purposes.
[0016] Furthermore, step 4 completes information recording and audit tracing through the following steps: Step D.1 Policy Distribution Phase: Record the hash digest H(P) of the control policy content P to establish the source of audit legitimacy. Its evidence entry in the ledger is... , ,in, Indicates the policy identifier. The digital signature representing the central decision-making node, , This represents the warning threshold, and f represents the sampling frequency. Represents geographic coordinates; Step D.2 Environment Construction Phase: Record the metric metadata generated by the TEE; specifically, record the remote metric proof M of node i. i , ,in, This indicates the code segment running within the TEE security zone. This indicates system configuration information. Represents the value of the hardware root register; records the temporary public key fingerprint generated when node A and node B negotiate to establish a secure channel. , ,in, This represents the public key of node A. This represents the public key of node B. This represents a random number, which is signed and stored using the TEE's internal private key. The stored item is... ,in, This represents the digital signature of the TEE; Step D.3 Sensor-Control Linkage Stage: Event-driven summary recording is adopted; specifically, nodes use Merkle tree technology to record sensor data blocks over a period of time. Compressed into root hash Decision record as , ,in, The timestamp indicating the exception capture. Indicates the logical number that triggered it. Represents the hash of the calculation result; Step D.4 Audit and Source Tracing Phase: Extract the original data of the affected nodes and reconstruct the Merkle tree. Verify whether the data has been tampered with by matching the ledger hash with the original local seismic wave data of the nodes. ,in, This represents the node's local data. If the recalculated root hash matches the ledger, output 1, proving the distributed ledger data is authentic; if the recalculated root hash does not match the ledger, output 0, proving the distributed ledger data has been tampered with or the local record is corrupted. Responsibility is determined by tracing the causal timeline in the ledger; if the distributed ledger records an early warning decision entry... If the cloud does not receive the data, it is determined to be a communication link failure; if the data meets the standard but the distributed ledger has no record, it is determined to be a failure of the perception strategy or hardware environment, thereby achieving accurate accountability and review.
[0017] To achieve the above objectives, the present invention also employs the following technical solution: An intrinsically secure marine Internet of Things (IoT) control system, deployed on a management platform, includes: Trusted Intent Module: Used to receive task intents from edge computing nodes that are digitally signed by them, and to verify the validity of the digital signature; Security Resource Monitoring Module: Used to dynamically maintain and update the dynamic trustworthiness scores of all nodes in the network, as well as resource status assessment; Collaborative optimization engine: used to run optimization algorithms based on the task intent and the resource status to generate control strategies that include perception, communication, computation and control dimensions; Policy security compiler: Used to compile control policies into executable policy packages containing specific workflow instructions, physical control parameters, and security configuration parameters, which are then sent to the corresponding nodes. Distributed audit and traceability module: Based on lightweight blockchain consensus nodes, it records and stores verifiable logs generated during policy execution and performs audit and traceability.
[0018] Compared with the prior art, the beneficial effects of this invention are as follows: To address the fragmented resource management issue: A collaborative optimization engine jointly models task completion time, resource consumption, and system security risks, introducing physical motion states as a regulation dimension to achieve deep coupling of communication, sensing, computing, and control, thus resolving the problem of low collaborative efficiency. To address the issue of external security mechanisms: At the hardware level, a PUF-based intrinsic security architecture is constructed. At the software level, dynamic trust scores are incorporated into the calculation of security risk quantification values, thereby generating control strategies. This transforms security capabilities from external to native attributes, resolving the deep disconnect between external security mechanisms and business task flows. To address the issue of poor environmental adaptability: Dynamic trust scores are used to perceive the security situation in real time, and a lightweight blockchain records key decisions throughout the process, ensuring the system has closed-loop avoidance and audit traceability capabilities in dynamic and complex environments, thus resolving the problem of insufficient robustness in dynamic and extreme environments. Attached Figure Description
[0019] Figure 1 A flowchart of a marine IoT control method for intrinsically safe operation; Figure 2 This is the result of dynamic credibility scoring calculation; Figure 3 To optimize the target calculation results. Detailed Implementation
[0020] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0021] Example 1: An intrinsically secure marine IoT control method is applied to a marine IoT system, which includes a perception layer, an edge / access layer, a network / relay layer, and a decision layer. The perception layer (end), edge / access layer (edge), network / relay layer, and decision layer (cloud) constitute an "end-edge-cloud" collaborative marine IoT architecture. The perception layer includes sensors responsible for real-time data acquisition and uploading to edge computing nodes. The edge / access layer includes edge computing nodes, specifically underwater vehicles or underwater base stations, responsible for intent generation. The network / relay layer includes a mother ship or relay nodes responsible for communication relay between edge computing nodes and shore-based / satellite networks, forwarding the intents generated by edge computing nodes to the management platform. The decision layer includes a management platform, which acts as the central decision node, responsible for uniformly collecting situational information from all nodes (including devices in the perception layer, edge / access layer, and network / relay layer) and issuing commands.
[0022] like Figure 1 As shown, it includes the following steps: Step 1: Edge computing nodes or management platforms perform key binding and sensing data integrity verification based on Physically Unclonable Functions (PUF) and hash algorithms; edge computing nodes analyze the verified sensing data, generate task intents when a trusted event is identified, and digitally sign the task intents.
[0023] In this embodiment, a trusted event refers to a specific scenario-triggered signal that has been verified for integrity and is perceived and identified by the edge computing node. This event serves as the security starting point for the interconnected communication, sensing, computing, and control mechanisms of the method in this embodiment. The task intent refers to a highly abstract description of business requirements generated by the edge computing node based on the identified trusted event. The task intent is signed by a hardware security module to ensure that the request source is non-repudiable.
[0024] In this embodiment, the improvement in step 1 mainly lies in the integrity verification of the sensing data. The following uses an underwater vehicle as an example to illustrate the steps of key binding and sensing data integrity verification: Step 1.1: Before system deployment, write the initial challenge C0, call PUF to output a unique response R0, use BCH error correction code to correct R0, and use SHA... 256 The hash algorithm processes the error-corrected R0, derives the binding key Key, and stores C0 and the error-correction parameter P. HD .
[0025] In this embodiment, for the main control chip of the aircraft (such as the STM32H7 series) or a dedicated sensor module, an initial challenge C0 is written, and the PUF outputs a unique response R0; BCH error correction code is used to correct R0, compensating for response deviations caused by underwater temperature / voltage fluctuations, ensuring consistent regeneration response each time; SHA is used... 256The hash algorithm processes the error-corrected R0 to derive the binding key Key; in this embodiment, R0 and Key are not stored, only C0 and the error-correction parameter P are stored. HD Each time the key is needed, enter... Call the PUF regeneration key Key.
[0026] In this embodiment, the key is strongly bound to the hardware. If a module is damaged or replaced, the key cannot be regenerated. The key is bound to hardware modules such as the main control module, core sensor modules (e.g., depth sensor, water quality sensor), and acoustic communication module, forming a "multi-module hardware trust chain." If any hardware module in the chain is replaced, its internal PUF cannot generate the expected key response, and the main control module will recognize that the hardware has been tampered with, refusing to unlock the system or encrypt communication. Optionally, if each hardware module has its own PUF, it is directly bound; if not, the main control module uses a dynamically generated key from the PUF to perform a challenge-response handshake with the acoustic communication module and core sensor modules.
[0027] In this embodiment, the physical characteristics of PUF are deeply integrated with the inherent security requirements of marine IoT. BCH error correction codes are used to correct R0, offsetting response deviations caused by underwater temperature / voltage fluctuations, and parameter optimization and application are performed for specific extreme environments. Compared with the easily leakable keys generated by software algorithms in the prior art, this embodiment binds the keys generated by PUF to each hardware module in hardware, realizing an interlocking mechanism of physical entities. Even if an attacker replaces one of the hardware modules, the entire vehicle will become inoperable due to the break in the trust chain, thus demonstrating the characteristics of inherent security.
[0028] Step 1.2: When the aircraft stores data locally, the original data D is split into several data blocks D. n Calculate the hash value H of each data block. n =SHA 256 (D n The integrity tag Tag=AES is generated using the key Key for encryption. Encrypt (Key,H n ), of which AES Encrypt The symmetric encryption algorithm ultimately stores the data according to the following storage structure: (D n +Tag+C0).
[0029] In this embodiment, the original data D (such as water temperature, salinity, and seabed topography data sets) is split into several data blocks D. n This avoids the loss of all data due to the failure of a single block; the final stored data is associated by block, which facilitates subsequent sampling verification.
[0030] Step 1.3: When the aircraft is powered on, determine whether each hardware module is valid; when the aircraft is running, periodically sample and verify the data blocks stored locally. If a tag mismatch is found, mark and isolate the data block with the mismatched tag to avoid errors in subsequent data analysis.
[0031] Specifically, in step 1.3, when the aircraft is powered on, the following steps are used to determine whether each hardware module is valid: Step A.1: Call the PUF of each hardware module, input C0, regenerate the response R0', and derive the key Key' after error correction.
[0032] Step A.2: Determine if the key Key' can successfully decrypt the tag. If it can, the hardware module is valid.
[0033] Specifically, in step 1.3, when the aircraft is running, during the periodic sampling and verification of locally stored data blocks, the following steps are used to determine whether the tag matches: Step B.1: Call the PUF of each hardware module, input C0, regenerate the response R0', and derive the key Key' after error correction.
[0034] Step B.2: For D n Recalculate hash value H n '=SHA 256 (D n ); Use the key Key' to encrypt and generate an integrity tag Tag'=AES Encrypt (Key',H n ').
[0035] Step B.3: Determine if Tag' is equal to Tag. If so, match.
[0036] Step 1.4: When the vehicle sends data D to the mother ship (including both cases where the vehicle actively transmits data back and cases where data is transmitted back according to the mother ship's instructions), extract the data (D) stored in Step 1.2 sequentially. n The data (+Tag+C0) is compressed using a compression algorithm (such as LZ4 algorithm) to reduce the amount of communication data and lower the underwater transmission error rate. Finally, a CRC32 checksum is added before the data is transmitted to the mother ship, giving priority to the transmission of the tag.
[0037] Step 1.5: After receiving the compressed package, the mother ship verifies the legality of the data and the aircraft.
[0038] In this embodiment, the aircraft enters normal operating mode to collect, process, and send compressed packages to the mother ship. After receiving the compressed packages, the mother ship not only verifies the legality of the data, but also verifies the legality of the hardware modules in the aircraft through the regenerated key.
[0039] Specifically, step 1.5 includes the following steps: Step C.1: Decompress to obtain D n Tag and C0 are used to filter transmission errors using CRC32 checksum.
[0040] Step C.2: The mother ship calls the PUF of the aircraft, inputs C0, regenerates the response R0', and derives the key Key' after error correction.
[0041] Step C.3: Decompress the obtained D n Recalculate hash value H n '=SHA 256 (D n ); Use the key Key' to decrypt the decompressed Tag to obtain the original hash value H. origin =AES Decrypt (Key',Tag).
[0042] Step C.4: Determine H n 'with H origin If they are equal, then the data is valid, meaning the data is complete and has not been tampered with.
[0043] Step C.5: Determine if the key Key' can be generated normally. If the key Key' can be generated normally, then the aircraft is a legitimate device.
[0044] In this embodiment, due to the uniqueness of the key Key', determining the validity of the data means determining that the key Key' can be derived normally.
[0045] In this embodiment, if either step C.4 or C.5 is not met, the mother ship will immediately terminate command execution and data reception, and trigger a warning, such as the mother ship indicating "data tampering" or "equipment malfunction".
[0046] Step 1.6: After each voyage mission is completed, the mother ship sends a new challenge C1 to the spacecraft, and the old challenge C0 becomes invalid, reducing the risk of leakage of the old challenge C0.
[0047] In this embodiment, PUF key regeneration takes only milliseconds and does not require continuous power consumption. Compared with traditional encryption chips, it can reduce the power consumption of the vehicle by 5% to 10%, thereby extending underwater endurance.
[0048] Step 2: After verifying the digital signature, the management platform receives the task intent and performs security and resource situation assessments, constructing a dual situation assessment result that includes both security and resources. Specifically, a dynamic credibility score T for security situation assessment is generated based on the node's historical behavior audit results, security configuration compliance, and responses to periodic remote authentication challenges. i (t).
[0049] In this embodiment, in step 2, the dynamic credibility score T is generated through the following steps. i (t): Step 2.1: Calculate the historical behavior audit score H of node i. i (t), the formula is as follows: ; In the formula, λ represents the forgetting factor, and R0 i (τ) represents the execution result of a single task at time τ. This represents a nonlinear mapping function.
[0050] In this embodiment, a decay-weighted time window model is used to obtain a historical behavior audit score based on the node's historical task execution records. λ represents the forgetting factor; for example, when λ=0.1, the focus is on the behavior in the most recent 10 time units; R i (τ) can be set according to specific circumstances, such as R i (τ)∈{0,0.5,1}, is 1 when the task is successfully executed, indicating that the task has fully achieved the predetermined goal; is 0.5 when the task partially fails, indicating that the task has not been completely successful but has not completely failed; is 0 when the task fails, indicating that the task has seriously failed and the core goal has not been achieved. Used to adjust the sensitivity of rewards and punishments, for example α can be 2.
[0051] Step 2.2: Calculate the security configuration compliance score C for node i. i (t), the formula is as follows: ; In the formula, M represents the number of types of security problems. This indicates the current severity of the k-th type of security problem. This represents the tolerance threshold for the k-th type of security problem. Represents the ReLU operator. This indicates the compliance rate of the basic configuration.
[0052] In this embodiment, the degree of compliance between node security configuration and policy is checked, and a multi-level compliance check and vulnerability penalty mechanism is adopted to obtain a security configuration compliance score. M can be 6, where k=1 represents node identity security (PUF uniqueness), k=2 represents communication channel security, k=3 represents data source trust security, k=4 represents computing environment security, k=5 represents physical protection security, and k=6 represents policy compliance security. This represents the ReLU operator, max(x,0), which ensures that the penalty term is non-negative. If this term is 0, then the overall C will be zero. i (t) is 0.
[0053] Step 2.3: Calculate the delay score S latency Cryptographic Response Score crypto The formula is as follows: ; ; In the formula, This represents the response delay at the q-th iteration. This represents the historical baseline delay (sliding window mean). This represents the network jitter variance; latency exceeding the baseline causes the score to decay in a Gaussian manner. Indicates the number of challenges. This shows the actual response to the j-th challenge. This represents the expected correct response to the j-th challenge. Indicates the correctness of the response, denoted by 0 or 1. and The value is 1 when they are completely identical, and 0 in all other cases. Energy consumption / electromagnetic characteristics during response. for Reference value, This represents the normalization factor.
[0054] In this embodiment, The energy consumption / electromagnetic characteristics during response are used to detect side-channel anomalies. If they differ from a reference value... If the deviation is too large, it will be judged as an abnormal simulation.
[0055] Step 2.4: Compute node i's remote authentication response score A i (t), the formula is as follows: ; In the formula, β is the weighting coefficient.
[0056] In this embodiment, a hybrid model of time decay and anomaly detection is used to obtain a remote identity authentication response score, and the authenticity of the node identity is evaluated through a periodic challenge-response protocol.
[0057] Step 2.5: Calculate the dynamic credibility score T of node i. i (t), T i (t)∈[0,1], the calculation formula is as follows: ; In the formula, , , These are the weighting coefficients.
[0058] To verify the effectiveness of the dynamic credibility scoring method in this embodiment, a node's lifecycle over 100 time steps was simulated, experiencing the process of "normal operation → network attack (increased latency) → security configuration violation → repair and recovery," visually demonstrating T i How do (t) and its sub-item scores change dynamically with the event? The verification results are as follows: Figure 2 As shown, the horizontal axis represents time steps (0-100 steps), and the vertical axis represents the score value (range 0-1). Steps 0-29 represent the stable period, during which the node trust score steadily increases. Steps 30-49 represent the first attack scenario, where increased network latency causes a sharp drop in the authentication response score, leading to the node trust score falling below the "high trust threshold." Steps 50-69 represent the second attack scenario, where security configuration violations occur, security configuration compliance and historical behavior auditing decrease, and the node trust score approaches the "warning threshold." Steps 70-100 represent the recovery period, where vulnerabilities are fixed, latency returns to normal, and the node trust score gradually recovers. Finally, a nonlinear mapping transforms the discrete results into a continuous score. Experimental results show that the dynamic node trust score model not only identifies single-dimensional faults but also reflects risk resonance. When a node experiences a serious configuration violation, its associated historical behavior audit score is simultaneously damaged. This effectively prevents attackers from using "good historical credit" as cover to perform malicious operations, enhancing the overall risk resistance of the system.
[0059] In this embodiment, the resource situation assessment item in step 2 can be completed using existing technologies, such as forming a resource situation assessment item based on the state of trusted computing resources, the state of secure communication links, and the state of controllable sensing resources. The following is a brief explanation using the state of secure communication links as an example. By monitoring indicators such as the bit error rate and signal-to-noise ratio in the secure communication link state, when strong electromagnetic interference is detected in the current sea area, the link-layer feedback mechanism captures the momentary exceedance of the preset safety threshold by the bit error rate. At this time, the resource situation assessment item marks the link state as "bit error rate exceeding the standard" or "communication environment deterioration." Finally, when aggregating the dual situation assessment results, the damaged resource component and the dynamic reliability score can be summarized.
[0060] Step 3: Optimize based on task completion time, resource consumption, and system security risk quantification, where the system security risk quantification includes a dynamic reliability score T. i (t); and under the premise of satisfying safety constraints, solve the control strategy, which includes the safety configuration strategy, as well as one or more of the node's perception sampling parameters, communication protocol configuration and physical motion state.
[0061] In this embodiment, the control strategy is an integrated control strategy that links communication, sensing, computing and control resources.
[0062] In this embodiment, in step 3, the optimization objective is constructed through the following steps: Step 3.1: Calculate the task completion time C eff The formula is as follows: ; In the formula, Indicates the travel time of an underwater vehicle. Indicates the sending time. Indicates the transmission time.
[0063] Step 3.2: Calculate resource consumption C res The formula is as follows: ; In the formula, Indicates the propulsion power of an underwater vehicle. Indicates transmission power. Indicates the remaining battery power.
[0064] Step 3.3: Calculate the system security risk quantification value Rsec, using the following formula: ; In the formula, This represents the value of the y-th task. Let y represent the threat probability of the y-th task.
[0065] In this embodiment, the value of key tasks (such as seismic source location) Value of routine tasks (such as real-time monitoring images) The value of auxiliary tasks (such as node shell temperature) .
[0066] In this embodiment, The calculation formula is as follows: ; In the formula, These are the weighting coefficients.
[0067] Step 3.4: Calculate the optimization objective, using the following formula: ; In the formula, , , , , , , They are respectively , , The maximum and minimum values.
[0068] To verify the effectiveness of the optimization objective in this embodiment, Three combinations with different weights were selected for verification, i.e., the equilibrium scheme. Safety First Plan and efficiency priority plan The verification results are as follows Figure 3 As shown in the figure, blue represents the area without the introduction of dynamic credibility score T. i The total cost of (t) (Value), green represents the introduced node dynamic credibility score T i Total cost after (t) (Value). From Figure 3 It can be seen that introducing a node dynamic credibility score T into the security risk quantification value... i After (t), the cost of the balanced solution decreased by 32.37%, the cost of the safety-first solution decreased by 63.76%, and the cost of the efficiency-first solution decreased by 27.39%.
[0069] In this embodiment, a heterogeneous optimization framework can be used to solve the control strategy, including the security configuration strategy. Specifically, a genetic optimization algorithm can be used to obtain the globally optimal path in fixed nodes with limited computing power; and a system based on high-performance edge computing modules can be deployed in underwater vehicle nodes. A reinforcement learning model for the reward function is used to achieve second-level decision response to fluctuations in the marine environment by leveraging the nonlinear mapping capability of neural networks.
[0070] In this embodiment, step 3 includes security constraints such as privacy constraints, integrity constraints, and authentication constraints. Privacy constraints: Data transmission or computation involving sensitive information must be processed using privacy computing techniques based on cryptography or trusted hardware, i.e., sensitive information (such as precise seismic waveforms and node location coordinates) is restricted from appearing in plaintext in untrusted memory or channels. Integrity constraints: Critical computation tasks must be assigned to nodes with trusted execution environments or hardware roots of trust to ensure that critical tasks such as seismic source location are not maliciously tampered with or injected with false data during execution. Authentication constraints: All nodes through which the task flows must undergo two-way authentication based on the unique identity generated by their PUF, i.e., ensuring that policy instructions are issued from a legitimate management platform and that the execution node is a verified legitimate device.
[0071] In this embodiment, step 3 includes the following security configuration strategy: assigning a lightweight encryption algorithm suite and session key of corresponding strength to the specified data transmission link; assigning a privacy computing technology type to the specified computing task, including secure multi-party computation, federated learning, or trusted execution environment; and adding a dynamic access control policy based on attribute-based encryption to the task data.
[0072] Step 4: The control policy generated in Step 3 is sent to the corresponding nodes. After the nodes establish a secure channel and configure the computing environment according to the security configuration policy, they execute the task. The key decisions and data flow information of the whole process are recorded in a distributed ledger based on a lightweight blockchain for auditing and traceability.
[0073] In this embodiment, in step 4, after the node establishes a secure channel and configures the computing environment according to the security configuration policy, it executes the task, thus completing the linkage of communication, sensing, computing, and control.
[0074] The following section explains the process of issuing and executing the control strategy in step 4 when strong electromagnetic interference is detected in the sea area during submarine geological disaster monitoring, leading to excessive bit error rate and deterioration of the communication environment: Step 4.1 Policy Distribution Phase: The control policy generated in Step 3 is distributed to the corresponding nodes, and the nodes use the policy security compiler to convert the control policy into specific physical drive instructions.
[0075] Step 4.2 Environment Construction Phase: The local policy execution engine of the node device instantiates the intrinsic security environment according to the compiled security configuration policy, that is, delineates the TEE and establishes the security channel.
[0076] Step 4.3 Synchronous Sensing and Control Linkage Stage: The local policy execution engine of the node device calls its external drive module to drive the vehicle to descend 5-10 meters (control) to avoid the surface noise interference zone. Within the constructed TEE environment, the data compression ratio is increased, and the lightweight encryption suite and session key allocated by the policy are used to ensure that the critical seismic wave alarm data can still maintain high reliability of transmission under narrow bandwidth.
[0077] Step 4.4 Audit and Traceability Stage: Record key decisions and data flow information throughout the process in a distributed ledger based on a lightweight blockchain for audit and traceability purposes.
[0078] Correspondingly, step 4 completes information recording and audit tracing through the following steps: Step D.1 Policy Distribution Phase: Record the hash digest H(P) of the control policy content P to establish the source of audit legitimacy. Its evidence entry in the ledger is... , ,in, Indicates the policy identifier. The digital signature representing the central decision-making node, , This represents the warning threshold, and f represents the sampling frequency. Represents geographic coordinates.
[0079] In this embodiment, in step D.1, An execution baseline was established. By concatenating and hashing key policy parameters, the resulting digest was recorded in the ledger as a unique identifier for the policy. The central decision node generates the policy and calculates... Digital signature The credibility of the strategy source was ensured, and the mothership will Securely forwarded to the edge computing node, the edge computing node receives the policy execution intent and compares the execution result with the ledger to determine if it meets the requirements. .
[0080] Step D.2 Environment Construction Phase: Record the metric metadata generated by the TEE to build the logical identity foundation for physical nodes; specifically, record the remote metric proof M of node i. i , ,in, This indicates the code segment running within the TEE security zone. This indicates system configuration information. Represents the value of the hardware root register; records the temporary public key fingerprint generated when node A and node B negotiate to establish a secure channel. ,here .in, This represents the public key of node A. This represents the public key of node B. This represents a random number, which is signed and stored using the TEE's internal private key. The stored item is... .in, This represents the digital signature of the TEE.
[0081] In this embodiment, in step D.2, M i These encrypted records provide a "digital identity card" for the physical environment, which auditors verify through formulas. This means proving that the hardware performing the computational task is in a safe state, undamaged by physical damage. This represents the initial state; if it is proven that the underwater vehicle's state is completely consistent with the initial state and the environment is safe, output 1; if the underwater vehicle is captured and forcibly dismantled by the enemy, attempting to read memory or modify system configuration information, output 1. Changes will occur, leading to Verification failed, output 0. This ledger-based channel notarization establishes a causal constraint relationship for data flow, ensuring that all subsequent data flows originate from a protected and trusted execution environment, rather than being maliciously forged.
[0082] Step D.3 Sensor-Control Linkage Stage: Event-driven summary recording is adopted; specifically, nodes use Merkle tree technology to record sensor data blocks over a period of time. Compressed into root hash Decision record as , ,in, The timestamp indicating the exception capture. Indicates the logical number that triggered it. This represents the hash of the calculated result.
[0083] In this embodiment, in step D.3, due to bandwidth limitations, the record exists in a very simple hash form. This transforms the complex physical sensing process into a logical closed loop. Even if the original big data is lost during seabed transmission, the encrypted decision chain in the ledger can still prove the entire process of generating the warning command. (Check) It can be confirmed that the correct algorithm was used; check. It can be confirmed that the machine was not hacked at the time (the environment is trustworthy).
[0084] Step D.4 Audit and Source Tracing Phase: Extract the original data of the affected nodes and reconstruct the Merkle tree. Verify whether the data has been tampered with by matching the ledger hash with the original local seismic wave data of the nodes. ,in, This represents the node's local data. If the recalculated root hash matches the ledger, output 1, proving the distributed ledger data is authentic; if the recalculated root hash does not match the ledger, output 0, proving the distributed ledger data has been tampered with or the local record is corrupted. Responsibility is determined by tracing the causal timeline in the ledger; if the distributed ledger records an early warning decision entry... If the cloud does not receive the data, it is determined to be a communication link failure; if the data meets the standard but the distributed ledger has no record, it is determined to be a failure of the perception strategy or hardware environment, thereby achieving accurate accountability and review.
[0085] In this embodiment, the block header in the block structure mainly includes a timestamp, index, random number, hash of the previous block, and Merkle root hash. The block header is responsible for maintaining the integrity of the chain and is the primary entry point for auditing and tracing. The block body is divided into three logical areas: a policy reference area, an environment metric area, and a decision flow record area. The policy reference area mainly records... , and This corresponds to the policy distribution phase. The environment metrics area is mainly used to record... , and This corresponds to the environment setup phase. The decision flow record area is mainly used for recording... , Addressing identifiers and This corresponds to the sensor-computer-control linkage stage, where the addressing identifier points to... The index pointer is used to tell the auditor the current record. It is calculated based on which policy in the policy reference area.
[0086] This embodiment of the intrinsically secure marine IoT control method addresses the problem of fragmented resource management by jointly modeling task completion time, resource energy consumption, and system security risks through a collaborative optimization engine, and introducing physical motion state as an adjustment dimension to achieve deep coupling of communication, sensing, computing, and control, thus solving the problem of low collaborative efficiency. It also addresses the issue of external security mechanisms by constructing an intrinsic security architecture based on PUF at the hardware level, and incorporating dynamic credibility scoring into the calculation of security risk quantification values at the software level, thereby introducing control strategy generation. This transforms security capabilities from external to native attributes, solving the problem of deep disconnect between external security mechanisms and business task flows. Finally, it addresses the problem of poor environmental adaptability by using dynamic credibility scoring to perceive the security situation in real time and recording key decisions throughout the process through a lightweight blockchain, ensuring that the system has closed-loop avoidance and audit traceability capabilities in dynamic and complex environments, thus solving the problem of insufficient robustness in dynamic extreme environments.
[0087] Example 2: An intrinsically secure marine Internet of Things (IoT) control system, deployed on a management platform, includes: Trusted Intent Module: Used to receive task intents from edge computing nodes that are digitally signed by them, and to verify the validity of the digital signature.
[0088] Security Resource Monitoring Module: Used to dynamically maintain and update the dynamic trustworthiness scores of all nodes in the network, as well as resource status assessment.
[0089] Collaborative optimization engine: Used to run optimization algorithms to generate control strategies that include perception, communication, computation and control dimensions based on the task intent and the resource status.
[0090] Policy security compiler: Used to compile control policies into executable policy packages containing specific workflow instructions, physical control parameters, and security configuration parameters, which are then sent to the corresponding nodes.
[0091] Distributed audit and traceability module: Based on lightweight blockchain consensus nodes, it records and stores verifiable logs generated during policy execution and performs audit and traceability.
[0092] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. An intrinsically safe marine Internet of Things (IoT) control method, characterized in that, Includes the following steps: Step 1: Edge computing nodes or management platforms perform key binding and sensing data integrity verification based on PUF and hash algorithms; edge computing nodes analyze the verified sensing data, generate task intents when trusted events are identified, and digitally sign the task intents; Step 2: After verifying the digital signature, the management platform receives the task intent and performs security and resource situation assessments, constructing a dual situation assessment result that includes both security and resources. Specifically, a dynamic credibility score T for security situation assessment is generated based on the node's historical behavior audit results, security configuration compliance, and responses to periodic remote authentication challenges. i (t); Step 3: Optimize based on task completion time, resource consumption, and system security risk quantification, where the system security risk quantification includes a dynamic reliability score T. i (t); and under the premise of satisfying safety constraints, solve the control strategy, which includes the safety configuration strategy, as well as one or more of the node's perception sampling parameters, communication protocol configuration and physical motion state; Step 4: The control policy generated in Step 3 is sent to the corresponding nodes. After the nodes establish a secure channel and configure the computing environment according to the security configuration policy, they execute the task. The key decisions and data flow information of the whole process are recorded in a distributed ledger based on a lightweight blockchain for auditing and traceability.
2. The intrinsically safe marine Internet of Things control method according to claim 1, characterized in that, Step 1 involves the following steps to complete key binding and perceived data integrity verification: Step 1.1: Before system deployment, write the initial challenge C0, call PUF to output a unique response R0, use BCH error correction code to correct R0, and use SHA... 256 The hash algorithm processes the error-corrected R0, derives the binding key Key, and stores C0 and the error-correction parameter P. HD ; Step 1.2: When the aircraft stores data locally, the original data D is split into several data blocks D. n Calculate the hash value H of each data block. n =SHA 256 (D n The integrity tag Tag=AES is generated using the key Key for encryption. Encrypt (Key,H n ), of which AES Encrypt The symmetric encryption algorithm ultimately stores the data according to the following storage structure: (D n +Tag+C0); Step 1.3: When the aircraft is powered on, it is determined whether each hardware module is valid; when the aircraft is running, the data blocks stored locally are sampled and verified periodically. If a tag mismatch is found, the data block with the mismatched tag is marked and isolated. Step 1.4: When the aircraft sends data D to the mother ship, extract the data stored in Step 1.2 (D) sequentially. n +Tag+C0), compressed using a compression algorithm, and finally transmitted to the mother ship after adding a CRC32 check code; Step 1.5: After receiving the compressed package, the mother ship verifies the legality of the data and the aircraft; Step 1.6: After each voyage mission is completed, the mother ship sends a new challenge C1 to the spacecraft, and the old challenge C0 becomes invalid, reducing the risk of leakage of the old challenge C0.
3. The intrinsically safe marine Internet of Things control method according to claim 2, characterized in that, In step 1.3, when the aircraft is powered on, the following steps are used to determine whether each hardware module is valid: Step A.1: Call the PUF of each hardware module, input C0, regenerate the response R0', and derive the key Key' after error correction; Step A.2: Determine whether the key Key' can successfully decrypt the Tag. If it can, the hardware module is valid. In step 1.3, when the aircraft is running, it periodically samples and verifies the data blocks stored locally. The following steps are used to determine whether the tag matches: Step B.1: Call the PUF of each hardware module, input C0, regenerate the response R0', and derive the key Key' after error correction; Step B.2: For D n Recalculate hash value H n '=SHA 256 (D n ); Use the key Key' to encrypt and generate an integrity tag Tag'=AES Encrypt (Key',H n Step B.3: Determine if Tag' and Tag are equal; if so, match.
4. The intrinsically safe marine Internet of Things control method according to claim 2, characterized in that, Step 1.5 includes the following steps: Step C.1: Decompress to obtain D n Tag and C0 are used to filter transmission errors using CRC32 checksum. Step C.2: The mother ship calls the PUF of the aircraft, inputs C0, regenerates the response R0', and derives the key Key' after error correction; Step C.3: Decompress the obtained D n Recalculate hash value H n '=SHA 256 (D n ); Decrypt the decompressed Tag using the key Key' to obtain the original hash value H. origin =AES Decrypt (Key',Tag); Step C.4: Determine H n 'with H origin Check if they are equal; if so, the data is valid. Step C.5: Determine if the key Key' can be generated normally. If the key Key' can be generated normally, then the aircraft is a legitimate device.
5. The intrinsically safe marine Internet of Things control method according to claim 1, characterized in that, In step 2, the dynamic credibility score T is generated through the following steps. i (t): Step 2.1: Calculate the historical behavior audit score H of node i. i (t), the formula is as follows: ; In the formula, λ represents the forgetting factor, and R... i (τ) represents the execution result of a single task at time τ. Represents a nonlinear mapping function; Step 2.2: Calculate the security configuration compliance score C for node i. i (t), the formula is as follows: ; In the formula, M represents the number of types of security problems. This indicates the current severity of the k-th type of security problem. This represents the tolerance threshold for the k-th type of security problem. Represents the ReLU operator. Indicates the basic configuration compliance rate; Step 2.3: Calculate the delay score S latency Cryptographic Response Score crypto The formula is as follows: ; ; In the formula, This represents the response delay at the q-th iteration. Indicates historical baseline delay, Indicates network jitter variance. Indicates the number of challenges. This shows the actual response to the j-th challenge. This represents the expected correct response to the j-th challenge. Indicates the correctness of the response, denoted by 0 or 1. and The value is 1 when they are completely identical, and 0 in all other cases. Energy consumption / electromagnetic characteristics during response. for Reference value, Indicates the normalization factor; Step 2.4: Compute node i's remote authentication response score A i (t), the formula is as follows: ; In the formula, β is the weighting coefficient; Step 2.5: Calculate the dynamic credibility score T of node i. i (t), T i (t)∈[0,1], the calculation formula is as follows: ; In the formula, , , These are the weighting coefficients.
6. The intrinsically safe marine Internet of Things control method according to claim 1, characterized in that, In step 3, the optimization objective is constructed through the following steps: Step 3.1: Calculate the task completion time C eff The formula is as follows: ; In the formula, Indicates the travel time of an underwater vehicle. Indicates the sending time. Indicates transmission time; Step 3.2: Calculate resource consumption C res The formula is as follows: ; In the formula, Indicates the propulsion power of an underwater vehicle. Indicates transmission power. Indicates the remaining battery power; Step 3.3: Calculate the system security risk quantification value Rsec, using the following formula: ; In the formula, This represents the value of the y-th task. Let represent the threat probability of the y-th task; Step 3.4: Calculate the optimization objective, using the following formula: ; In the formula, , , , , , , They are respectively , , The maximum and minimum values.
7. The intrinsically safe marine Internet of Things control method according to claim 1, characterized in that, In step 3, security constraints include privacy constraints, integrity constraints, and authentication constraints. Privacy constraints: Data transmission or computation involving sensitive information must be processed using privacy computing techniques based on cryptography or trusted hardware, i.e., restricting sensitive information from appearing in plaintext form in untrusted memory or channels. Integrity constraints: Critical computation tasks must be assigned to nodes with trusted execution environments or hardware roots of trust to ensure that the critical task of seismic source location is not maliciously tampered with or injected with false data during execution. Authentication constraints: All nodes through which the task flows must undergo two-way authentication based on the unique identity generated by their PUF, i.e., ensuring that policy instructions are issued from a legitimate management platform and that the execution node is a verified legitimate device. In step 3, the security configuration strategy includes: assigning a lightweight encryption algorithm suite and session key of corresponding strength to the specified data transmission link; Assign a privacy computing technology type to the specified computing task. The privacy computing technology type includes secure multi-party computation, federated learning, or trusted execution environment; add a dynamic access control policy based on attribute-based encryption to the task data.
8. The intrinsically safe marine Internet of Things control method according to claim 1, characterized in that, Step 4 involves the following steps to distribute and execute the control policy: Step 4.1 Policy Distribution Phase: The control policy generated in Step 3 is distributed to the corresponding nodes, and the nodes use the policy security compiler to convert the control policy into specific physical drive instructions; Step 4.2 Environment Construction Phase: The local policy execution engine of the node device instantiates the intrinsic security environment according to the compiled security configuration policy, that is, delineates the TEE and establishes the security channel; Step 4.3 Synchronous Sensing and Control Linkage Stage: The local policy execution engine of the node device calls its external drive module to drive the vehicle to dive 5-10 meters to avoid the surface noise interference zone. Within the constructed TEE environment, the data compression ratio is increased. The lightweight encryption suite and session key allocated by the policy are used to ensure that the critical seismic wave alarm data can still maintain high reliability of transmission under narrow bandwidth. Step 4.4 Audit and Traceability Stage: Record key decisions and data flow information throughout the process in a distributed ledger based on a lightweight blockchain for audit and traceability purposes.
9. A method for controlling an intrinsically safe marine Internet of Things according to claim 8, characterized in that, Step 4 involves completing information recording and audit tracing through the following steps: Step D.1 Policy Distribution Phase: Record the hash digest H(P) of the control policy content P to establish the source of audit legitimacy. Its evidence entry in the ledger is... , ,in, Indicates the policy identifier. The digital signature representing the central decision-making node, , This represents the warning threshold, and f represents the sampling frequency. Represents geographic coordinates; Step D.2 Environment Construction Phase: Record the metric metadata generated by the TEE; specifically, record the remote metric proof M of node i. i , ,in, This indicates the code segment running within the TEE security zone. This indicates system configuration information. Represents the value of the hardware root register; records the temporary public key fingerprint generated when node A and node B negotiate to establish a secure channel. , ,in, This represents the public key of node A. This represents the public key of node B. This represents a random number, which is signed and stored using the TEE's internal private key. The stored item is... ,in, This represents the digital signature of the TEE; Step D.3 Sensor-Control Linkage Stage: Event-driven summary recording is adopted; specifically, nodes use Merkle tree technology to record sensor data blocks over a period of time. Compressed into root hash Decision record as , ,in, The timestamp indicating the exception capture. Indicates the logical number that triggered it. Represents the hash of the calculation result; Step D.4 Audit and Source Tracing Phase: Extract the original data of the affected nodes and reconstruct the Merkle tree. Verify whether the data has been tampered with by matching the ledger hash with the original local seismic wave data of the nodes. ,in, This represents the node's local data. If the recalculated root hash matches the ledger, output 1, proving the distributed ledger data is authentic; if the recalculated root hash does not match the ledger, output 0, proving the distributed ledger data has been tampered with or the local record is corrupted. Responsibility is determined by tracing the causal timeline in the ledger; if the distributed ledger records an early warning decision entry... If the cloud does not receive the data, it is determined to be a communication link failure; if the data meets the standard but the distributed ledger has no record, it is determined to be a failure of the perception strategy or hardware environment, thereby achieving accurate accountability and review.
Citation Information
Patent Citations
Trusted sharing system for marine environment monitoring data
CN120915459A
KR20250136804A