Block chain wisdom medical Internet of Things authentication system and method for resisting cloud leakage attack
By leveraging blockchain technology and a multi-cloud-multi-fog-multi-device architecture, combined with PoS consensus and multinomial secret sharing, the network latency and security issues in smart healthcare IoT systems are resolved, achieving low-latency, high-security communication and intelligent protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHONGNAN UNIVERSITY OF ECONOMICS AND LAW
- Filing Date
- 2024-10-29
- Publication Date
- 2026-05-01
AI Technical Summary
Existing smart healthcare IoT systems suffer from problems such as network latency, insufficient security, and single points of failure. They are particularly vulnerable to data breaches in cloud computing and fog computing environments, and traditional authentication schemes are difficult to meet the requirements of low latency and high security.
A distributed architecture with multiple clouds, multiple fog nodes, and multiple devices is designed using blockchain technology. The PoS consensus mechanism elects and registers authorities, and elliptic curve and polynomial secret sharing technologies are used for identity authentication and key negotiation. Machine learning is combined for real-time risk assessment to ensure secure communication between medical devices, fog nodes, and cloud servers.
It achieves low-latency, high-security communication, prevents data leakage and unauthorized access, avoids single points of failure, has intelligent protection mechanisms, and improves system response efficiency and security.
Smart Images

Figure CN121967442A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to, but is not limited to, the field of smart medical IoT technology, and particularly relates to a blockchain smart medical IoT authentication system and method resistant to cloud-based data leakage attacks. Background Technology
[0002] Smart healthcare IoT is a crucial application area of IoT. Its systems are highly sensitive to network latency and security, requiring IoT medical devices to continuously, in real-time, and securely monitor patients' various physiological indicators. This enables healthcare professionals to remotely access patient data for timely and effective intervention, diagnosis, and treatment. However, cloud computing, commonly used in IoT, typically accesses servers via remote networks, leading to network latency and interruptions that impact the efficiency of healthcare services. Fog computing expands the concept of cloud computing, offering advantages such as low latency, low energy consumption, high security, high efficiency, location awareness, scalability, and mobility support. The fog layer, located between the cloud and IoT terminal devices, does not replace the cloud but extends some basic cloud services, such as computing, networking, and storage, to fog nodes at the network edge. The fog layer typically contains many fog nodes, which act as servers close to the terminal devices, capable of rapid response and maintenance of terminal data privacy within a certain physical range, while communicating with the cloud. However, while the introduction of fog significantly reduces average network latency and jitter caused by excessive distance between IoT terminal devices and the cloud, its unique computing environment also makes it susceptible to various security issues. Compared to cloud computing, fog computing needs to consider the interactions among cloud providers, fog service providers, users, and devices in an ecosystem where multiple trust domains coexist. Therefore, designing secure authentication schemes in fog computing environments presents a greater challenge. On one hand, in reality, cloud servers may be deployed or proxied by third parties and may have insecure architectural flaws, leading to data leaks or internal damage. On the other hand, many existing studies employ centralized architectures, where a single cloud service provider manages fog nodes and terminal devices. This can easily result in single points of failure, high communication overhead, and high latency, impacting the entire system's operation. Therefore, to mitigate security issues caused by cloud-fog leak attacks and meet the practical needs of low latency and high security in smart healthcare, a distributed cloud-fog architecture security authentication scheme suitable for smart healthcare IoT systems needs to be designed.
[0003] Based on the above analysis, the urgent technical problems that need to be solved in the existing technology are:
[0004] (1) Cloud computing remote access to servers can easily cause network latency and network interruption. Using the cloud alone cannot fully meet the medical Internet of Things’ requirements for low network latency and high security.
[0005] (2) Many existing solutions usually assume that cloud servers are completely trustworthy, while only considering that fog is not completely trustworthy. However, in reality, cloud servers may be deployed or proxied by third parties, or there may be insecure architectural defects, which may cause cloud servers to suffer data leakage or internal damage.
[0006] (3) Most existing studies adopt a centralized architecture of single cloud-multi-fog-multi-device, which is prone to single point of failure. Summary of the Invention
[0007] To address the problems existing in the prior art, this invention provides a blockchain-based smart healthcare IoT authentication system and method resistant to cloud leak attacks.
[0008] This invention is implemented as follows: a blockchain-based smart healthcare IoT authentication system resistant to cloud-based data leakage attacks, comprising four entity modules:
[0009] Registration authorities are a group of fully trusted entities in the network responsible for registering all deployed medical devices, fog nodes, and cloud servers in the network.
[0010] Medical device layer: Composed of smart medical devices in the smart healthcare Internet of Things, multiple medical devices can be installed or deployed in a specific application;
[0011] Fog layer: Composed of many not entirely trusted fog nodes, responsible for communicating with medical devices within its coverage area, and constructing blocks containing transactions from the data collected from the corresponding medical devices, and forwarding them to its associated cloud server;
[0012] Cloud layer: A group of cloud servers in the cloud layer form a peer-to-peer network. They are mainly responsible for receiving and verifying the blocks forwarded by their associated fog nodes and adding them to the blockchain.
[0013] Another objective of this invention is to provide a blockchain-based smart healthcare IoT authentication method that resists fogging attacks in implementing the aforementioned fogging-resistant blockchain smart healthcare IoT authentication system, specifically including:
[0014] S1: Initialization phase, the registered authorities elect a registered authority through the PoS consensus mechanism to initialize the smart medical IoT system;
[0015] S2: During the registration phase, a trusted registration authority registers all deployed medical devices, fog nodes, and cloud servers in the Internet of Things in a secure environment.
[0016] S3: Authentication phase, which implements identity authentication between medical devices and fog nodes, and between fog nodes and cloud servers, and negotiates keys to ensure secure communication between them.
[0017] Furthermore, S1 includes:
[0018] Step I1: Register an authoritative RA. First, select a non-singular elliptic curve E. q (u,v) is a large prime number q (at least 512 bits in size) with an infinity point or a zero point. An elliptic curve over a finite field (Galois field) GF(q) has the form: y 2 =x 3 +ux+v(mod q), where 4u 3 +27v 2 ≠ 0 (mod q), and u,v∈Z q ={0,1,...q-1}, RA lies on the elliptic curve E q Choose a base point P with the same order as q on (u,v), and select a unique ID for RA. RA And randomly generate a random number. As the system's private key, the corresponding public key P is also calculated. pub =s·P;
[0019] Step I2: RA selects a one-way cryptographic hash function h:{0,1} * →{0,1} l RA calculates its own pseudo-identity PID RA =h(ID) RA ||s);
[0020] Step I3: RA will use s and ID RA Add it to the blockchain, set it so that only registered authorities (RAs) can access this block, and publish the parameter {E} on the network. q (u,v),P,h(·),PID RA ,P pub}
[0021] Furthermore, the medical device registration in S2, for each deployed medical device MD i RA chooses a unique real identity for it. and the corresponding temporary identity make Calculate its pseudo-random identity Public-private key pairs In MD i Load credentials before accessing the network. RAs use the PoS algorithm to Packaged into blocks, indexed as And add it to the existing blockchain.
[0022] Furthermore, in S2, fog node registration, RA is for each fog node FN. j Select Unique Identity and a temporary identity make Calculate its pseudo-random identity Public-private key pairs RA generates a form of GF(q) as A bivariate symmetric polynomial of degree t, wherein the coefficients a ij ∈Z q The polynomial satisfies f(x,y)=f(y,x), and the value of t should not be less than the number of fog nodes deployed in the network. Calculate FN. j The polynomial share is RA in FN j China Storage Registration Certificate In addition, it stores in for The value of RAs will Publicly available on the network, using the PoS algorithm Package it into a block and add it to the blockchain.
[0023] Furthermore, in S2, cloud server registration, RA is for each cloud server CS. k Select Unique Identity Calculate its pseudo-random identity Public-private key pairs RA selects a t-degree bivariate symmetric polynomial And calculate CS k Polynomial share: RA in CS k Storage certificate In addition, it stores Will Set to public, RAs use the PoS algorithm to... Package it into a block and add it to the blockchain.
[0024] Furthermore, in S3, the medical device MD i The fog node FN that it wants to communicate with j The authentication process between them is as follows:
[0025] Step MFA1: MD i Randomly generated and current timestamp Calculate private parameters Common parameters Then MDi Generate signature Subsequently, MD i Construct message And send to FN via a public channel j ;
[0026] Step MFA2: FN j MD received at time T1 i News Then, first verify Whether the condition is met, where ΔT is the system's "maximum transmission delay". If the condition is not met, the current session is terminated directly; otherwise, FN is called. j pass Get the corresponding Then access the index in the blockchain. The block, obtained Further verification Is it true? If it is true, then FN j This successfully verified MD. i Otherwise, the session ends, followed by FN. j Generate a random and current timestamp Calculate private parameters Common parameters After that, FN j Calculate the shared key And for MD i Generate a new temporary identity And calculate Finally, FN j generate Then construct the message. And sent to MD via public channel i ;
[0027] Step MFA3: Received at time T2 After that, MD i First, verify if it exists. If the inequality holds, MD i Calculate the shared key as And verify Whether it is true or false, if the verification is successful, then MD i Also FN j As a legitimate node, MD i calculate And order Then, MD i Use the current timestamp Compute Session Key Verifier And send messages via open channels Give FN j ;
[0028] Step MFA4: FN j Received at time T3 Then, first verify If it holds true, then further verification is needed to determine if it exists. If this also holds true, then the key negotiation is successful, FN j It is also necessary to put it into its database corresponding Updated to MD i With FN j A shared session key was successfully established.
[0029] Furthermore, in S3, the fog node FN j Its associated cloud server CS k The authentication process between them is as follows:
[0030] Step FCA1: FN j Randomly generated and current timestamp calculate And calculate Subsequently, FN j Send messages via public channel To CS k ;
[0031] Step FCA2: At time T1, CS k receive Then, first verify Is it valid? If the verification passes, receive. Subsequently, CS k Through the obtained Find Then verify the existence of the index in the blockchain. If the block does not exist, authentication is terminated, and then... Restore H1, CS k Generate current timestamp and random numbers calculate Then through and its own polynomial share calculate calculate and FN jShared key After the calculation is completed, CS k For FN j Generate a new temporary identity And calculate as well as First use Update your own database to correspond to of Use again renew Finally, CS k via public channel to FN j Send message
[0032] Step FCA3: FN j Received at time T2 Then, first verify whether there is If the inequality holds, FN j calculate and Then restore Calculate the shared key Additionally, FN j Also calculate And verify Is it correct? If correct, FN j Just CS k Treat it as a legitimate node, and Finally, FN serves as the session key for their subsequent communication. j use renew Use again renew
[0033] Another object of the present invention is to provide a computer device comprising a memory and a processor, the memory storing a computer program, which, when executed by the processor, causes the processor to perform the following steps:
[0034] During the initialization phase, registration authorities elect a registration authority through a PoS consensus mechanism to initialize the smart healthcare IoT system. In the registration phase, the trusted registration authority registers all deployed medical devices, fog nodes, and cloud servers in the IoT within a secure environment. Medical devices authenticate with fog nodes, and fog nodes authenticate with cloud servers, negotiating shared session keys for subsequent secure communication. After entity registration, relevant registration information is stored in its corresponding database. When the system is in use, medical devices select nearby fog nodes for mutual authentication, and each fog node needs to authenticate with a cloud server. Upon successful authentication, shared keys are generated to ensure secure communication between the two parties.
[0035] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the following steps:
[0036] During the initialization phase, registration authorities elect a registration authority through a PoS consensus mechanism to initialize the smart healthcare IoT system. In the registration phase, the trusted registration authority registers all deployed medical devices, fog nodes, and cloud servers in the IoT within a secure environment. Medical devices authenticate with fog nodes, and fog nodes authenticate with cloud servers, negotiating shared session keys for subsequent secure communication. After entity registration, relevant registration information is stored in its corresponding database. When the system is in use, medical devices select nearby fog nodes for mutual authentication, and each fog node needs to authenticate with a cloud server. Upon successful authentication, shared keys are generated to ensure secure communication between the two parties.
[0037] Another objective of this invention is to provide an information data processing terminal for implementing the smart medical IoT secure communication system resistant to cloud and fog leakage attacks.
[0038] Based on the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solution to be protected by this invention are as follows:
[0039] First, this invention deploys fog nodes at the network edge, ensuring lower network latency and higher reliability;
[0040] This invention, while satisfying various known attacks, can also resist cloud server leakage attacks and fog server leakage attacks;
[0041] Based on blockchain technology, this invention designs a distributed architecture of multiple clouds, multiple fog, and multiple devices to avoid single point of failure.
[0042] Second, the expected benefits and commercial value of the technical solution of this invention after transformation are as follows:
[0043] The concept of the Internet of Things (IoT) has been around for over two decades. Smart healthcare IoT, as a crucial application area of IoT, utilizes IoT, computer, and other technologies to acquire, transmit, store, and process medical data. This can improve the efficiency of medical diagnosis and treatment, providing more convenient and personalized healthcare services. In a smart healthcare IoT system, IoT medical devices can continuously, in real-time, and securely monitor various physiological indicators of patients, allowing medical staff to remotely access patient data for timely and effective intervention, diagnosis, and treatment. However, as an open network, IoT is vulnerable to various attacks, including simulation attacks, replay attacks, desynchronization attacks, and data leakage attacks, leading to system failures, medical data leaks, and in severe cases, even endangering patients' lives. The authentication technology employed in this invention serves as a key threshold for ensuring system security, primarily protecting the secure communication processes within the smart healthcare IoT, particularly resisting cloud server data leakage attacks that are often overlooked in many solutions. Therefore, the technical solution of this invention, once commercialized, will generate significant expected benefits and commercial value.
[0044] Third, the anti-cloud leakage attack blockchain smart medical IoT authentication system of the present invention solves several key technical problems of existing smart medical IoT systems in industrial applications and achieves significant technological progress:
[0045] Technical problems to be solved:
[0046] 1. Insufficient security in identity authentication and data transmission: Devices in existing smart healthcare IoT systems are vulnerable to threats such as man-in-the-middle attacks and spoofing attacks during identity authentication and data transmission. This invention ensures secure communication between medical devices, fog nodes, and cloud servers through multi-step identity authentication and key negotiation technologies, preventing unauthorized access and data leakage.
[0047] 2. Device identity information is easily tampered with or leaked: Traditional centralized identity management systems are prone to single points of failure and cannot guarantee the reliability of identity information. This invention utilizes the decentralized and immutable characteristics of blockchain to record the device's pseudo-identity and encrypted parameters in the blockchain, ensuring the security and integrity of identity information and avoiding the risk of single points of failure.
[0048] 3. The system is vulnerable to cloud-based data leakage attacks: In smart healthcare systems, the data transmission process between fog nodes and cloud servers is easily targeted by attacks. Through polynomial secret sharing technology, this invention improves the resistance to identity data leakage, ensuring that even if a single node is attacked, attackers will find it difficult to obtain the true identity data, effectively preventing cloud-based data leakage attacks.
[0049] 4. Lack of dynamic risk assessment and intelligent protection: Traditional smart healthcare systems are slow to react to cyberattacks, making it difficult to quickly identify and respond to potential threats. This invention combines machine learning algorithms for real-time risk assessment, enabling dynamic adjustment of authentication and key negotiation mechanisms, rapid identification of abnormal data flows, and automatic adjustment of protection strategies to achieve intelligent protection.
[0050] Technological advancements:
[0051] 1. Decentralization and tamper-resistance of the identity authentication system: By utilizing blockchain technology, this invention permanently records the pseudo-identities and encryption parameters of each device, realizing a decentralized identity authentication system, improving data security and system reliability, and significantly reducing security vulnerabilities in traditional identity authentication.
[0052] 2. Highly efficient anti-cloud / fog leakage capability: This invention employs binary symmetric polynomials and secret sharing technology to improve the distributed protection capability of identity information, making it difficult for attackers to obtain complete identity information even if cloud or fog nodes are attacked, thus significantly improving the security of smart healthcare systems.
[0053] 3. Intelligent Security Protection Mechanism: Through real-time risk assessment and machine learning to dynamically adjust the authentication scheme, the system can proactively defend against potential threats, ensuring the communication security of smart medical devices. This intelligent design not only improves the system's response efficiency but also significantly enhances the overall security protection level.
[0054] In summary, this invention has achieved significant technological advancements in identity authentication, anti-leakage attacks, and intelligent protection, providing an efficient and reliable security solution for smart medical IoT, and effectively meeting the stringent requirements of modern medical systems for data security and communication reliability. Attached Figure Description
[0055] Figure 1 This is a structural diagram of the smart medical Internet of Things system provided in an embodiment of the present invention;
[0056] Figure 2 This is a flowchart of a blockchain-based smart healthcare IoT authentication method against cloud leakage attacks provided in an embodiment of the present invention;
[0057] Figure 3 This is an authentication flowchart between medical devices, fog nodes, and cloud servers provided in an embodiment of the present invention.
[0058] Figure 4 This is a schematic diagram comparing the communication costs of the authentication method of the present invention with other related methods, as provided in the embodiments of the present invention.
[0059] Figure 5This is a schematic diagram comparing the cost calculation of the authentication method of the present invention with other related methods, as provided in the embodiments of the present invention. Detailed Implementation
[0060] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0061] The blockchain-based smart healthcare IoT authentication system for resisting cloud leakage attacks provided in this embodiment of the invention includes:
[0062] The initialization module is configured to elect a registered authority through the PoS (Proof-of-Stake) consensus mechanism to initialize the smart healthcare IoT system.
[0063] The registration module is configured to register all deployed medical devices, fog nodes, and cloud servers in the Internet of Things (IoT) in a secure environment.
[0064] The authentication module is configured to perform identity authentication between medical devices and fog nodes, and between fog nodes and cloud servers, and to negotiate keys to ensure secure communication between them.
[0065] The initialization module includes:
[0066] The elliptic curve selection submodule is configured to select a non-singular elliptic curve defined over a finite field consisting of a large prime number (at least 512 bits).
[0067] The key generation submodule is configured to select a base point on the elliptic curve and generate a unique identity for the registration authority, a system private key, and a corresponding public key.
[0068] The hash calculation submodule is configured to select a one-way cryptographic hash function and calculate the pseudo-identity of the registered authority;
[0069] The blockchain storage submodule is configured to add the public key and pseudo-identity of the registered authority to the blockchain, set blocks that can only be accessed by the registered authority, and publish the relevant parameters on the network.
[0070] The registration module includes:
[0071] The medical device registration submodule is configured to select a unique real identity and a corresponding temporary identity for each deployed medical device, calculate its pseudo-random identity and public-private key pair, and load credentials for it and expose relevant parameters to the blockchain before entering the network.
[0072] The fog node registration submodule is configured to select a unique identity and a temporary identity for each fog node, calculate its pseudo-random identity and public-private key pair, generate a t-degree binary symmetric polynomial and calculate the polynomial share, store the registration certificate and publish the relevant parameters to the blockchain.
[0073] The cloud server registration submodule is configured to select a unique identity for each cloud server, calculate its pseudo-random identity and public-private key pair, generate a t-degree binary symmetric polynomial and calculate the polynomial share, store the registration certificate and publish the relevant parameters to the blockchain.
[0074] The blockchain-based smart healthcare IoT authentication system provided by this invention, which resists cloud and fog node leakage attacks, ensures secure communication between medical devices, fog nodes, and cloud servers in a smart healthcare IoT environment through three main modules: initialization, registration, and authentication. The system employs a PoS consensus mechanism to elect registration authorities, utilizes blockchain technology to record and manage device identity information, and combines machine learning algorithms for real-time risk assessment and dynamic adjustment, significantly improving data security and system protection capabilities.
[0075] The initialization module ensures the identity of the registration authority and the security foundation of the system by selecting a highly secure elliptic curve and generating unique key pairs. The use of a one-way hash function to generate pseudo-identities enhances the system's anonymity and resistance to tampering.
[0076] The registration module uses a layered registration method to assign unique and temporary identities to medical devices, fog nodes, and cloud servers, and leverages polynomial secret sharing technology to improve the system's fault tolerance and data security.
[0077] The authentication module ensures secure communication between nodes through multi-step identity authentication and key negotiation, preventing unauthorized access and data leakage.
[0078] This blockchain-based smart healthcare IoT authentication system, which is resistant to cloud-based data leakage attacks, consists of initialization, registration, and authentication modules. It ensures secure communication and identity authentication between medical devices, fog nodes, and cloud servers, thereby enhancing the overall security and attack resistance of the smart healthcare IoT.
[0079] First, upon system startup, the initialization module elects a registration authority using a Proof-of-Stake (PoS) consensus mechanism. This registration authority is responsible for the initialization of the smart healthcare IoT system, using a secure non-singular elliptic curve to generate unique public-private key pairs over a finite field defined by large prime numbers. A pseudo-identity is calculated using a one-way cryptographic hash function, and the registration authority's identity information is stored on the blockchain to enhance system anonymity and tamper resistance. Simultaneously, the generated public key, pseudo-identity, and encryption parameters are publicly available within the network, with access to a dedicated block limited to the registration authority.
[0080] Secondly, the system enters the registration phase. The registration module is responsible for registering unique identities for all medical devices, fog nodes, and cloud servers in the IoT within a secure environment. The medical device registration submodule generates pseudo-random identities and public-private key pairs for devices by selecting a unique real identity and a temporary identity, loads encrypted credentials, and publishes the relevant parameters to the blockchain. Fog nodes and cloud servers use multinomial secret sharing technology to generate identity and credential information, and publish pseudo-identities and encrypted parameters. In this way, the layered registration and parameter publication design significantly improves the system's fault tolerance and ensures information security.
[0081] Third, the fog node and cloud server registration submodules in the registration module utilize a binary symmetric polynomial to generate t-degree shares, which are then publicly displayed on the blockchain. The binary symmetric polynomial enhances the system's resistance to fog node leakage attacks. This polynomial encryption algorithm is used to generate distributed credentials, recording the identity authentication information of each node in the blockchain and performing pseudo-randomization processing on sensitive identity data, thereby enhancing the data's tamper resistance and confidentiality.
[0082] During the authentication phase, the authentication module ensures secure communication between devices through a multi-step authentication process. Medical devices and fog nodes, as well as fog nodes and cloud servers, complete two-way authentication and key negotiation, achieving secure communication through encryption. This authentication process prevents man-in-the-middle attacks and unauthorized access, ensuring the integrity and confidentiality of data during transmission. The negotiated key provides a guarantee for secure communication between nodes, preventing data leakage and information theft.
[0083] Furthermore, the system leverages the decentralized nature of blockchain to permanently record the pseudo-identity and encrypted parameters of registered devices, avoiding single points of failure inherent in traditional centralized storage. The pseudo-identity information of the device is immutable and permanent within the blockchain, ensuring that even if cloud or fog nodes are attacked, attackers will find it difficult to steal the device's true identity, thus enhancing the system's resistance to attacks.
[0084] Finally, to further enhance security, the system incorporates machine learning algorithms, based on real-time risk assessment and dynamic adjustment, to intelligently analyze potential risks in data transmission, automatically adjust authentication and key negotiation mechanisms, and detect and prevent malicious attacks in real time. This design not only improves the system's response efficiency and data protection capabilities but also ensures secure communication of smart healthcare IoT devices in complex network environments, achieving efficient and secure identity authentication.
[0085] The blockchain-based smart healthcare IoT authentication system of this invention has the following significant technical advantages in industrial applications:
[0086] 1. Enhance data security: Through blockchain technology and multi-layered identity authentication mechanisms, ensure secure communication between medical devices, fog nodes, and cloud servers to prevent data leakage and unauthorized access.
[0087] 2. Improve system stability and reliability: Utilize the PoS consensus mechanism to elect and register authorities, ensuring the stability and reliability of the system in the face of malicious attacks, while improving the system's fault tolerance through multinomial secret sharing technology.
[0088] 3. Real-time risk monitoring and dynamic adjustment: By combining machine learning algorithms, the system can monitor data usage behavior in real time, dynamically assess and adjust data security levels, and improve the system's response speed and protection capabilities.
[0089] 4. Simplified management process: The system's automated registration and authentication process reduces manual intervention, improves management efficiency, and adapts to the needs of a large-scale smart healthcare IoT environment.
[0090] 5. High adaptability and wide application: This system is not only suitable for smart medical IoT environments, but can also be extended to other IoT application scenarios that require high security authentication, and has broad application prospects and market value.
[0091] Through the above technical solutions, this invention effectively solves the shortcomings of data security management and identity authentication in the existing technology of smart medical Internet of Things environment, significantly improves the overall security and operating efficiency of the system, and has significant industrial application value and promotion prospects.
[0092] like Figure 1 As shown, this embodiment of the invention provides a blockchain-based smart healthcare IoT authentication system resistant to cloud-based data leakage attacks, comprising four entity modules:
[0093] Registration Authorities (RAs): RAs are a group of fully trusted entities in the network that are responsible for registering all deployed medical devices, fog nodes, and cloud servers in the network.
[0094] Medical Device Layer: The medical device layer consists of smart medical devices in the smart healthcare Internet of Things, and multiple medical devices can be installed or deployed in a specific application.
[0095] Fog Layer: The fog layer consists of many not entirely trusted fog nodes, which are responsible for communicating with medical devices within their coverage area and constructing blocks containing transactions from the data collected from the corresponding medical devices, and forwarding them to their associated cloud servers.
[0096] Cloud Layer: A group of cloud servers in the cloud layer form a peer-to-peer network. They are primarily responsible for receiving and verifying blocks forwarded by their associated fog nodes and adding them to the blockchain.
[0097] like Figure 2 , Figure 3As shown in the figure, the blockchain-based smart healthcare IoT authentication method for resisting cloud leakage attacks provided by this invention specifically includes:
[0098] S1: Initialization phase, the registered authorities elect a registered authority through the PoS consensus mechanism to initialize the smart medical IoT system;
[0099] S2: During the registration phase, a trusted registration authority registers all deployed medical devices, fog nodes, and cloud servers in the Internet of Things in a secure environment.
[0100] S3: Authentication phase, which implements identity authentication between medical devices and fog nodes, and between fog nodes and cloud servers, and negotiates keys to ensure secure communication between them.
[0101] S1 includes:
[0102] Step I1: Register an authoritative RA. First, select a non-singular elliptic curve E. q (u,v) is a large prime number q (at least 512 bits in size) with an infinity point or a zero point. An elliptic curve over a finite field (Galois field) GF(q) has the form: y 2 =x 3 +ux+v(mod q). Where 4u 3 +27v 2 ≠ 0 (mod q), and u,v∈Z q ={0,1,...q-1}. The commutative group formed by the addition of points on this elliptic curve should be an abelian group of very high order. Subsequently, RA on the elliptic curve E q Choose a base point P on (u,v) with the same order as q. RA selects a unique identity ID. RA And randomly generate a random number. As the system's private key, the corresponding public key P is also calculated. pub =s·P.
[0103] Step I2: RA selects a one-way cryptographic hash function h:{0,1} * →{0,1} l That is, it can process an input string x∈{0,1} of arbitrary length. * The mapping is to a fixed-length l-bit output string h(x)∈{0,1} l For example, h(·) can be considered as a secure hash algorithm (SHA-1) that produces a 160-bit hash value, and for greater security, it can also be SHA-256 or SHA-512
[35] . RA calculates its own pseudo-identity PID. RA=h(ID) RA ||s).
[0104] Step I3: RA will use s and ID RA Add it to the blockchain, set it so that only registered authorities (RAs) can access this block, and publish the parameter {E} on the network. q (u,v),P,h(·),PID RA ,P pub}
[0105] The medical device registration in S2, for each deployed medical device MD i RA chooses a unique real identity for it. and the corresponding temporary identity make Calculate its pseudo-random identity Public-private key pairs In MD i Load credentials before accessing the network. RAs use the PoS algorithm to Packaged into blocks, indexed as And add it to the existing blockchain.
[0106] In S2, fog node registration, RA is for each fog node FN. j Select Unique Identity and a temporary identity make Calculate its pseudo-random identity Public-private key pairs RA generates a form of GF(q) as A bivariate symmetric polynomial of degree t, wherein the coefficients a ij ∈Z q The polynomial satisfies f(x,y)=f(y,x), and the value of t should not be less than the number of fog nodes deployed in the network. And calculate FN. j The polynomial share is RA in FN j China Storage Registration Certificate In addition, it stores in for The value of RAs. Publicly available on the network, using the PoS algorithm Package it into a block and add it to the blockchain.
[0107] In S2, cloud server registration, RA is for each cloud server CS.k Select Unique Identity Calculate its pseudo-random identity Public-private key pairs RA selects a t-degree bivariate symmetric polynomial And calculate CS k Polynomial share: RA in CS k Storage certificate In addition, it stores Will Set to public. RAs uses the PoS algorithm to... Package it into a block and add it to the blockchain.
[0108] S3, medical device MD i The fog node FN that it wants to communicate with j The authentication process between them is as follows:
[0109] Step MFA1: MD i Randomly generated and current timestamp Calculate private parameters Common parameters Then MD i Generate signature Subsequently, MD i Construct message And send to FN via a public channel j .
[0110] Step MFA2: FN j MD received at time T1 i News Then, first verify The condition is checked to determine if the condition is true, where ΔT is the system's "maximum transmission delay". If the condition is false, the current session is terminated immediately. Otherwise, FN is called. j pass Get the corresponding Then access the index in the blockchain. The block, obtained Further verification Is it true? If true, FN j This successfully verified MD. i Otherwise, the session ends. Then, FN... j Generate a random and current timestamp Calculate private parameters Common parameters After that, FN jCalculate the shared key And for MD i Generate a new temporary identity And calculate Finally, FN j generate Then construct the message. And sent to MD via public channel i .
[0111] Step MFA3: Received at time T2 After that, MD i First, verify if it exists. If the inequality holds, MD i Calculate the shared key as And verify Is it true or false? If the verification is successful, then MD... i Also FN j It is considered a legitimate node. Subsequently, MD i calculate And order Then, MD i Use the current timestamp Compute Session Key Verifier And send messages via open channels Give FN j .
[0112] Step MFA4: FN j Received at time T3 Then, first verify Is it true? If true, then further verify whether it exists. If this also holds true, then the key negotiation is successful. FN j It is also necessary to put it into its database corresponding Updated to
[0113] Through the above steps, MD i With FN j A shared session key was successfully established.
[0114] S3, fog node FN j Its associated cloud server CS k The authentication process between them is as follows:
[0115] Step FCA1: FN j Randomly generated and current timestamp calculate And calculate Subsequently, FN j Send messages via public channel To CS k .
[0116] Step FCA2: At time T1, CS k receive Then, first verify Is it valid? If verification passes, receive. Subsequently, CS k Through the obtained Find Then verify the existence of the index in the blockchain. If the block does not exist, authentication is terminated. Then proceed through... Restore H1. CS k Generate current timestamp and random numbers calculate Then through and its own polynomial share calculate calculate and FN j Shared key After the calculation is completed, CS k For FN j Generate a new temporary identity And calculate as well as First use Update your own database to correspond to of Use again renew Finally, CS k via public channel to FN j Send message
[0117] Step FCA3: FN j Received at time T2 Then, first verify whether there is If the inequality holds, FN j calculate and Then restore Calculate the shared key Additionally, FN j Also calculate And verify Is it correct? If correct, FN j Just CS k Treat it as a legitimate node, and As a session key for their subsequent communication. Finally, using renew Use again renew
[0118] Through the above steps, FN j With CS k A shared session key was successfully established.
[0119] This invention provides a computer device, which includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the blockchain-based smart healthcare IoT security authentication method against cloud-based data leakage attacks.
[0120] This invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the blockchain-based smart healthcare IoT security authentication method against cloud-based data leakage attacks.
[0121] This invention provides an information data processing terminal, which is used to implement the blockchain-based smart healthcare IoT security authentication system that resists cloud leak attacks.
[0122] The technical solution of this invention can be applied to smart medical IoT systems to ensure communication security. A typical application example is remote diagnosis. Medical devices (such as blood pressure monitors) or wearable devices (such as smartwatches) in the patient's home collect the patient's physiological indicators in real time and upload them to the blockchain via fog nodes and cloud servers. Authorized doctors can remotely access the blockchain to assess the patient's health and rule out potential health problems through timely diagnosis. This saves medical resources and improves the cumbersome medical process for patients. If the communication security of the smart medical IoT system cannot be guaranteed, it may lead to incorrect or untimely diagnoses, and in severe cases, even endanger the patient's life.
[0123] In terms of security, this invention can resist various known attacks, mainly including:
[0124] It eliminates attacks such as synchronization attacks, replay attacks, man-in-the-middle attacks, impersonation attacks, smart device capture attacks, fog node leakage attacks, cloud server leakage attacks, privileged insider attacks, and transient secret leakage attacks. It also achieves characteristics such as anonymity, untraceability, and forward / backward key security.
[0125] Regarding communication costs, this invention requires relatively low communication costs. To fairly compare communication costs, the data size involved is uniformly defined. It is assumed that a 160-bit elliptic curve cryptosystem provides the same level of security as a 1024-bit RSA public-key cryptosystem, and that a point P on the elliptic curve is (160+160) = 320 bits (P's x and y coordinates are both 160 bits), and the temporary random number is also 160 bits. It is assumed that the lengths of the identity, pseudo-identity, and temporary identity are all 160 bits, the lengths of symmetric encryption / decryption and Chebyshev chaotic mapping operations are all 160 bits, and the timestamp is 32 bits. The hash digest length is 256 bits (SHA-256 algorithm). This invention requires the transmission of 5 messages, totaling 3232 bits. In other similar communication systems, the system invented by Fan et al. requires 3808 bits, the system invented by Huang et al. requires 3488 bits, and the system invented by Li et al. requires 6624 bits.
[0126] In terms of computational cost, this invention has a significant advantage. To facilitate comparison of the computational costs of different systems, the time required for one-way cryptographic hash functions, elliptic curve point addition, elliptic curve point multiplication, bilinear pairing, modular multiplication, t-degree polynomial computation, and symmetric encryption / decryption operations are defined as T, respectively. h T epa T epm T bp T m T poly and T s The computation of a polynomial of degree t requires t modular multiplications and t modular additions. The computation time of modular addition is negligible compared to modular multiplication, therefore Tt = ... poly =tT m +tT a ≈tT m (T a (This represents modular addition). The experimental measurement used is: at the IoT device end, T h ≈0.056ms, T epa ≈0.081ms, T epm ≈13.405ms, T bp ≈32.713ms, T m ≈0.008ms, T s ≈0.224ms; On the server side, T h ≈0.007ms, T epa ≈0.013ms, T epm ≈2.165ms, T bp ≈5.427ms, T m ≈0.001ms, T s≈0.028. The computational cost of this invention on the medical device side is 6T. h +4T epm +T m +T epa ≈54.045ms, server-side 20T h +4T epm +T m +2T poly ≈8.801+0.002t, when t is 1000, the total computation cost is 64.846ms. The computation cost of the system invented by Fan et al. is 123.44ms, that of Huang et al. is 93.719ms, and that of Li et al. is 77.946ms.
[0127] It should be noted that embodiments of the present invention can be implemented in hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by a suitable instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the above-described devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuitry such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., or by software executed by various types of processors, or by a combination of the above-described hardware circuitry and software, such as firmware.
[0128] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions, and improvements made by those skilled in the art within the scope of the technology disclosed in the present invention, and within the spirit and principles of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A blockchain-based smart healthcare IoT authentication system resistant to cloud-based data leakage attacks, characterized in that, The system includes: The initialization module is configured to elect a registration authority through the PoS consensus mechanism to initialize the smart healthcare IoT system. The registration module is configured to register all deployed medical devices, fog nodes, and cloud servers in the Internet of Things (IoT) in a secure environment. The authentication module is configured to perform identity authentication between medical devices and fog nodes, and Fog nodes authenticate each other with cloud servers and negotiate keys to ensure secure communication between them.
2. The blockchain-based smart healthcare IoT authentication system resistant to cloud-based data leakage attacks as described in claim 1, characterized in that, The initialization module includes: The elliptic curve selection submodule is configured to select a non-singular elliptic curve defined over a finite field consisting of a large prime number. The key generation submodule is configured to select a base point on the elliptic curve and generate a unique identity for the registration authority, a system private key, and a corresponding public key. The hash calculation submodule is configured to select a one-way cryptographic hash function and calculate the pseudo-identity of the registered authority; The blockchain storage submodule is configured to add the public key and pseudo-identity of the registered authority to the blockchain, set blocks that can only be accessed by the registered authority, and publish the relevant parameters on the network.
3. The blockchain-based smart healthcare IoT authentication system resistant to cloud-based data leakage attacks as described in claim 1, characterized in that, The registration module includes: The medical device registration submodule is configured to select a unique real identity and a corresponding temporary identity for each deployed medical device, calculate its pseudo-random identity and public-private key pair, and load credentials for it before entering the network. The fog node registration submodule is configured to select a unique identity and a temporary identity for each fog node, calculate its pseudo-random identity and public-private key pair, generate a t-degree binary symmetric polynomial and calculate the polynomial share, store the registration certificate and publish the relevant parameters to the blockchain. The cloud server registration submodule is configured to select a unique identity for each cloud server, calculate its pseudo-random identity and public-private key pair, generate a t-degree binary symmetric polynomial and calculate the polynomial share, store the registration certificate and publish the relevant parameters to the blockchain.
4. A blockchain-based smart healthcare IoT authentication method for implementing the anti-fog leakage attack blockchain smart healthcare IoT authentication system as described in any one of claims 1 to 3, characterized in that, The method specifically includes: S1: Initialization phase, the registered authorities elect a registered authority through the PoS consensus mechanism to initialize the smart medical IoT system; S2: During the registration phase, a trusted registration authority registers all deployed medical devices, fog nodes, and cloud servers in the Internet of Things in a secure environment. S3: Authentication phase, which implements identity authentication between medical devices and fog nodes, and between fog nodes and cloud servers, and negotiates keys to ensure secure communication between them.
5. The blockchain-based smart healthcare IoT authentication method against cloud leakage attacks as described in claim 4, characterized in that, S1 includes: Step I1: Register an authoritative RA. First, select a non-singular elliptic curve E. q (u,v) is a large prime number q (at least 512 bits in size) with an infinity point or a zero point. An elliptic curve over a finite field (Galois field) GF(q) has the form: y 2 =x 3 +ux+v(mod q), where 4u 3 +27v 2 ≠ 0 (mod q), and u,v∈Z q ={0,1,...q-1}, RA lies on the elliptic curve E q Choose a base point P with the same order as q on (u,v), and select a unique ID for RA. RA And randomly generate a random number. As the system's private key, the corresponding public key P is also calculated. pub =s·P; Step I2: RA selects a one-way cryptographic hash function h:{0,1} * →{0,1} l Calculate your own pseudo-identity PID RA =h(ID) RA ||s); Step I3: RA will use s and ID RA Add it to the blockchain, set it so that only registered authorities (RAs) can access this block, and publish the parameter {E} on the network. q (u,v),P,h(·),PID RA ,P pub } 6. The blockchain-based smart healthcare IoT authentication method against cloud leakage attacks as described in claim 2, characterized in that, The medical device registration in S2, for each deployed medical device MD i RA chooses a unique real identity for it. and the corresponding temporary identity make Calculate its pseudo-random identity Public-private key pairs In MD i Load credentials before accessing the network. RAs use the PoS algorithm to Packaged into blocks, indexed as And add it to the existing blockchain.
7. The blockchain-based smart healthcare IoT authentication method against cloud leakage attacks as described in claim 2, characterized in that, In S2, fog node registration, RA is for each fog node FN. j Select Unique Identity and a temporary identity make Calculate its pseudo-random identity Public-private key pairs RA generates a form of GF(q) as A bivariate symmetric polynomial of degree t, wherein the coefficients a ij ∈Z q The polynomial satisfies f(x,y)=f(y,x), and the value of t should not be less than the number of fog nodes deployed in the network. Calculate FN. j The polynomial share is RA in FN j China Storage Registration Certificate In addition, it stores in for The value of RAs will Publicly available on the network, using the PoS algorithm Package it into a block and add it to the blockchain.
8. The blockchain-based smart healthcare IoT authentication method against cloud leakage attacks as described in claim 4, characterized in that, In S2, cloud server registration, RA is for each cloud server CS. k Select Unique Identity Calculate its pseudo-random identity Public-private key pairs RA selects a t-degree bivariate symmetric polynomial And calculate CS k The polynomial share is: RA in CS k China Storage Registration Certificate In addition, it stores Will Set to public. RAs uses the PoS algorithm to... Package it into a block and add it to the blockchain.
9. The blockchain-based smart healthcare IoT authentication method against cloud leakage attacks as described in claim 4, characterized in that, S3, medical device MD i The fog node FN that it wants to communicate with j The authentication process between them is as follows: Step MFA1: MD i Randomly generated and current timestamp Calculate private parameters Common parameters Then, MD i Generate signature Subsequently, MD i Construct message And send to FN via a public channel j ; Step MFA2: FN j MD received at time T1 i News Then, first verify Whether the condition is true or false, where ΔT is the system's "maximum transmission delay". If the condition is false, the current session is terminated directly; otherwise, FN is called. j pass Get the corresponding Then access the index in the blockchain. The block, obtained Further verification Is it true? If it is true, then FN j This successfully verified MD. i Otherwise, the session ends, followed by FN. j Generate a random and current timestamp Calculate private parameters Common parameters After that, FN j Calculate the shared key And for MD i Generate a new temporary identity And calculate Finally, FN j generate Then construct the message. And sent to MD via public channel i ; Step MFA3: Received at time T2 After that, MD i First, verify if it exists. If the inequality holds, MD i Calculate the shared key as And verify Whether it is true or false, if the verification is successful, then MD i Also FN j As a legitimate node, MD i calculate And order Then, MD i Use the current timestamp Compute Session Key Verifier And send messages via open channels Give FN j ; Step MFA4: FN j Received at time T3 Then, first verify If it holds true, then further verification is needed to determine if it exists. If this also holds true, then the key negotiation is successful, FN j It is also necessary to put it into its database corresponding Updated to MD i With FN j A shared session key was successfully established.
10. The blockchain-based smart healthcare IoT authentication method against cloud leakage attacks as described in claim 4, characterized in that, S3, fog node FN j Its associated cloud server CS k The authentication process between them is as follows: Step FCA1: FN j Randomly generated and current timestamp calculate And calculate Subsequently, FN j Send messages via public channel To CS k ; Step FCA2: At time T1, CS k receive Then, first verify Is it valid? If the verification passes, receive. Subsequently, CS k Through the obtained Find Then verify the existence of the index in the blockchain. If the block does not exist, authentication is terminated, and then... Restore H1, CS k Generate current timestamp and random numbers calculate Then through and its own polynomial share calculate calculate and FN j Shared key After the calculation is completed, CS k For FN j Generate a new temporary identity And calculate as well as First use Update your own database to correspond to of Use again renew Finally, CS k via public channel to FN j Send message Step FCA3: FN j Received at time T2 Then, first verify whether there is If the inequality holds, FN j calculate and Then restore Calculate the shared key Additionally, FN j Also calculate And verify Is it correct? If correct, FN j Just CS k Treat it as a legitimate node, and Finally, FN serves as the session key for their subsequent communication. j use renew Use again renew