A multi-node high-security internet of things communication system

CN122534097APending Publication Date: 2026-08-07SHENZHEN ANZHILE TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN ANZHILE TECHNOLOGY CO LTD
Filing Date
2026-06-25
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0004]现有技术中,多节点初次握手时的公钥分发易被中间节点劫持并替换,会导致后续通信陷入虚假身份隧道,使得动态拓扑中缺乏首次身份真实性的自证机制,而且在已固化公钥的基础上,节点会话密钥协商易受历史流量分析攻击,攻击者利用时间戳相关性还原密钥片段,传统随机数无法抵抗模式预测,此外,在同时拥有固化身份和非周期密钥的条件下,节点间指令传输还可能因单节点被物理俘获而泄露全局策略,现有隔离机制难以动态阻断受控节点对上下游的污染扩散,因此,如何在物联网通信系统中解决身份首次锚定、会话密钥抗预测攻击以及被俘节点污染扩散三个安全问题,是本发明要解决的技术问题

Benefits of technology

1、该一种多节点高安全性物联网通信系统,通过果蝇算法动态寻优筛选可信临时公证人,结合哈希链的单向不可逆特性对首次通信公钥进行链式锚定,使劫持节点无法伪造连续链值或混入认证路径,实现轻量级、抗中间替换的首次身份固化,有效解决物联网动态拓扑中缺乏首次身份真实性自证机制的安全问题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122534097A_ABST
    Figure CN122534097A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of Internet of Things communication, and particularly discloses a multi-node high-security Internet of Things communication system, which comprises a cloud management center, and the cloud management center is in communication connection with the following modules: a chain anchoring identity module, which is used for dynamically optimizing trusted neighboring nodes as temporary notaries through a fruit fly algorithm in the Internet of Things communication system, combining a hash chain to chain-anchor a first public key, and realizing first-time identity solidification; and a chaos anti-analysis module, which is used for generating a high-dimensional chaotic initial vector in the cloud management center to break time sequence correlation; the application dynamically optimizes and screens trusted temporary notaries through the fruit fly algorithm, combines the one-way irreversible characteristic of the hash chain to chain-anchor the first communication public key, makes hijacked nodes unable to forge continuous chain values or mix into an authentication path, realizes lightweight and anti-intermediate replacement first-time identity solidification, and effectively solves the security problem of lacking a first-time identity authenticity self-checking mechanism in the dynamic topology of the Internet of Things.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) communication technology, and in particular to a multi-node, highly secure IoT communication system. Background Technology

[0002] With the widespread adoption of smart devices and sensors, the Internet of Things (IoT) has become a significant driver of digital transformation across various sectors of society. However, IoT devices often face challenges such as insufficient security, data privacy concerns, and cyberattacks, leading to increased risks of information leakage and system compromise during communication. In IoT communication systems, multi-node communication refers to multiple devices participating in network communication simultaneously. This mode not only improves data transmission efficiency but also enhances network reliability.

[0003] For example, in the Chinese patent publication number CN116418594A, a system and communication method for improving the security of the Internet of Things (IoT) are proposed. Since the IoT device and the front-end isolation device communicate encrypted through a private dedicated channel, the ways in which the IoT device is attacked are reduced. Even if the front-end isolation device is attacked, it is difficult for the attacker to launch an attack on the IoT device through the private dedicated channel.

[0004] In existing technologies, the distribution of public keys during the initial handshake of multiple nodes is easily intercepted and replaced by intermediate nodes, which can lead to subsequent communication being trapped in a false identity tunnel. This results in a lack of a self-verification mechanism for the authenticity of the initial identity in dynamic topologies. Moreover, based on the solidified public key, the negotiation of node session keys is vulnerable to historical traffic analysis attacks. Attackers can use timestamp correlation to reconstruct key fragments, and traditional random numbers cannot resist pattern prediction. Furthermore, under the condition of having both solidified identities and non-periodic keys, the transmission of instructions between nodes may also leak the global strategy due to the physical capture of a single node. Existing isolation mechanisms are unable to dynamically block the spread of contamination to upstream and downstream by controlled nodes. Therefore, how to solve the three security problems of initial identity anchoring, session key resistance to prediction attacks, and contamination spread by captured nodes in IoT communication systems is the technical problem that this invention aims to solve. Summary of the Invention

[0005] To overcome the shortcomings of the prior art, the present invention provides a multi-node high-security Internet of Things communication system, which can effectively solve the problems involved in the prior art.

[0006] The objective of this invention can be achieved through the following technical solution: This invention provides a multi-node, highly secure Internet of Things (IoT) communication system, including a cloud management center, wherein the cloud management center has the following communication connections: The chain-anchored identity module is used in IoT communication systems to dynamically select trusted neighbor nodes as temporary notaries through the fruit fly algorithm. Combined with the hash chain, the initial public key is chain-anchored, which forces hijacking nodes to be unable to forge continuous chain values, thus achieving lightweight and resistant to intermediate substitution of identity for initial solidification. The chaos anti-analysis module is used to generate a high-dimensional chaotic initial vector in the cloud management center to break the temporal correlation. The terminal uses the solidified public key as a perturbation factor to iteratively generate an aperiodic session key to resist historical traffic analysis attacks, making it impossible for attackers to extract repeating patterns from historical traffic and break the temporal correlation. The container truncation module is used to deploy secure containers through notary nodes selected by the fruit fly algorithm, restricting physically captured nodes to only decrypting ciphertexts unrelated to themselves, preventing them from parsing upstream and downstream communication content, cutting off the pollution propagation path, restricting the visibility of captured node information, and cutting off the path of pollution spreading outward. The strategy linkage module, based on the fixed identity and non-periodic key, combines end-cloud collaboration to generate and distribute dynamic encryption strategies in real time. This enables any node to switch its upstream and downstream communication strategies immediately after it is captured, forcibly blocking the node from continuing to pollute the instructions and data of neighboring nodes, thus preventing the pollution from spreading to neighboring nodes. The captured node becomes immediately ineffective, preventing it from spreading pollution to its neighbors. The loopback self-healing module is used to periodically verify the consistency between the solidified identity and the non-periodic key. When an anomaly is detected or a node is isolated, the reset process is automatically triggered. The notary node is re-elected through the fruit fly algorithm and the chaotic parameters are synchronized, so that the damaged topology can automatically restore the trusted communication tunnel. In case of an anomaly, the system will automatically reset and recover, ensuring that the damaged topology can quickly self-heal.

[0007] Preferably, the chain-anchored identity module includes a fruit fly neighbor selection unit and a hash chain anchor unit; The fruit fly neighbor selection unit is used to dynamically optimize the multi-dimensional trust index of neighboring nodes using the fruit fly algorithm, quickly filter out trusted temporary notary nodes, block hijackers from entering the identity authentication path, ensure the security of the first handshake, and quickly filter trusted notaries to block hijackers from entering the authentication path. The hash chain anchor unit is used to anchor the initial public key with the continuous, unidirectional, and irreversible characteristics of the hash chain, forcing hijacking nodes to be unable to forge the complete chain value, ensuring the authenticity and integrity of the initial public key distribution, and establishing a traceable identity anchor.

[0008] Preferably, the fruit fly neighbor selection unit specifically includes: In an IoT communication system, a node to be connected broadcasts a neighbor discovery request with a dynamic random number seed and collects multi-dimensional trust indicators from neighboring nodes. These multi-dimensional trust indicators include historical response entropy, online duration jitter variance, and signal phase stability coefficient, which comprehensively assess the trustworthiness of neighbors and filter out potential malicious nodes. The multidimensional trust index of each neighbor node is mapped to the odor concentration search space location of the fruit fly individual. The asymmetric odor concentration judgment function is used for iterative optimization, and a random drift suppression factor is introduced to prevent premature convergence. The candidate notary node set with the highest comprehensive trust is selected, and high-trust nodes are accurately selected to avoid the algorithm from getting trapped in local optima too early. A node is randomly selected from the candidate notary node set based on local sniffing distance weighting to serve as a temporary notary. A one-time session identifier is dynamically generated to participate in the hash chain anchoring of the public key for the first handshake. This blocks hijackers from infiltrating the authentication path through time-series replay or identity forgery, ensuring the fairness and security of notary election and preventing replay and identity forgery from infiltrating.

[0009] Preferably, the hash chain anchor unit specifically includes: The node to be connected generates the first communication public key and uses it as the tail value of the hash chain. After introducing the salt value bound to the identity of the temporary notary, it performs continuous one-way hash iteration to generate the anchor value of the chain head. The chain head, chain tail and salt value are submitted to the temporary notary to prevent the public key from being tampered with and to ensure that the chain value generation process is not forged. After the temporary notary binds the chain head value with his own digital signature, he broadcasts it to the entire network. When subsequent nodes verify, they are required to disclose the chain value in reverse order and attach timestamp proof. This causes the hijacking node to expose its tampering behavior because it lacks salt value and cannot reverse-forge the previous chain value. The forced disclosure and verification of the chain value makes it impossible for the hijacking node to hide the traces of tampering. After all nodes in the network perform joint consistency verification on the chain value and signature and pass the verification, the initial public key combined with the temporary notary identity is solidified as the non-repudiable identity anchor of that node. This achieves lightweight, non-substitution-resistant, and replay-attack-resistant initial identity anchoring, solidifying the non-repudiable identity anchor and resisting substitution and replay attacks.

[0010] Preferably, the chaos anti-analysis module includes a cloud-based chaos excitation unit and a terminal perturbation iteration unit; The cloud-based chaotic excitation unit generates an initial vector of high-dimensional chaotic mapping, i.e., a cloud-based chaotic vector, from the cloud management center. This disrupts the temporal logic of key generation, preventing attackers from extracting repeating sequences from historical traffic or predicting the next-hop key state, thus preventing sequence prediction attacks. The terminal perturbation iteration unit is used to perform nonlinear iteration on the cloud-based chaotic vector using the pre-fixed local public key as a perturbation factor on the terminal, generating a non-periodic session key that is unique in each session, blocking key restoration attacks based on pattern prediction, ensuring that each session key is unique, and blocking pattern prediction attacks.

[0011] Preferably, the cloud-based chaos excitation unit specifically includes: The cloud management center generates an initial state vector based on a five-dimensional hyperchaotic system. The five state components of this five-dimensional hyperchaotic system drive each other through nonlinear cross-coupling terms, breaking the linear predictability of a single temporal dimension, increasing the complexity of the chaotic source, and completely breaking the linear law of key temporal sequence. The initial state vector is dynamically confused and modulated with the real-time collected global network entropy value (including the characteristics of node online fluctuations and traffic bursts) to generate an irreversible cloud-based chaotic vector. This vector is then broadcast to all online terminals across the network through a quantum-resistant encryption channel, injecting real-time network entropy values ​​to make the chaotic vector dynamically irreversible and resistant to quantum cracking. The cloud updates the chaotic vector parameters at irregular session intervals (dynamically adjusted based on network load). Before each update, a random jump step size is inserted, so that there is no state transition matrix to follow between two consecutive excitation sources. Attackers cannot extract any repeating patterns or reconstruct phase space trajectories from historical traffic, disrupting the state update rhythm and blocking phase space trajectory reconstruction and pattern extraction.

[0012] Preferably, the terminal perturbation iteration unit specifically includes: The terminal extracts the locally fixed public key byte string as a perturbation seed, performs bidirectional cross-bit diffusion (exchanging the high and low bits and then XORing them) with the cloud chaos vector to generate the perturbation initial iteration value with an avalanche effect, ensuring that a single bit change triggers an avalanche, and the terminal's initial state is unique and unpredictable. The perturbed initial iteration value is used to drive the cascaded chaotic mapping function (the Logistic mapping and Tent mapping are executed alternately). In each session, a different iteration start and end round interval is dynamically selected, and the state value at the end of the interval is taken as the aperiodic key for this session. The dynamic round interval makes each session key independent and unrelated, and completely aperiodic. The terminal retains only the one-way hash pointer generated during the iteration process, pointing to the state slice required for the next round, and immediately erases all intermediate iteration variables. This prevents attackers from deriving any historical or future keys forward or backward, even if they obtain the key for this iteration. This completely blocks key recovery attacks based on time-series correlation and immediately clears intermediate variables, blocking forward and backward key derivation based on time-series correlation.

[0013] Preferably, the container truncation module specifically includes: The IoT communication system uses the fruit fly algorithm to select a notary node and dynamically instantiates a micro-container instance for each pair of adjacent communication relationships. This instance is injected with only the decryption key and policy fragment directly related to the communication pair, achieving minimum permission isolation between the key and the context, and preventing the leakage of a single container from affecting other communication pairs. Microcontainers use eBPF-based system call interception hooks to forcibly block inter-process memory sharing and network stack raw socket sniffing, so that physically captured nodes can only decrypt ciphertext data whose destination address exactly matches their own and whose session identifier is consistent. Kernel-level forced isolation restricts captured nodes to only decrypting their own ciphertext. The micro-container has a built-in real-time integrity measurement module that periodically verifies the hash value of the internal policy file. Once unauthorized memory access or key extraction is detected, the container self-destructs and communication channel is immediately triggered to prevent upstream and downstream ciphertext from being parsed across nodes or global policies from being reversed. Real-time self-destruction and circuit breaking prevent ciphertext from being leaked across nodes and policies from being reversed.

[0014] Preferably, the strategy linkage module specifically includes: Based on the fixed node identity and non-periodic session key, the cloud management center generates a dynamic encryption strategy for each pair of adjacent nodes by combining the current network topology hash snapshot. The dynamic encryption strategy includes the encryption algorithm family rotation sequence number, key derivation depth and chaotic iteration round offset. Each pair of nodes has an independent strategy, which blocks cross-communication pair key association analysis. When any node is detected as abnormal or physically captured through side channel behavior fingerprint analysis, the cloud management center immediately broadcasts a time-stamped policy switching instruction to the upstream and downstream neighbors of that node. The policy switching instruction includes a one-time update seed and the absolute time boundary for the switching to take effect. The instruction provides an immediate response to any abnormality and includes anti-replay measures and precise effective boundaries. Upon receiving the instruction, upstream and downstream nodes synchronously enter the policy conversion window. During the window period, the key materials corresponding to the old policy are completely discarded, and any instructions or data encapsulated using the old policy are refused to be processed. This causes the captured node to permanently lose the ability to decrypt communication with neighboring nodes due to the lack of a new policy seed. The old key is quickly discarded, causing the captured node to permanently lose its decryption ability.

[0015] Preferably, the loop self-healing module specifically includes: The system triggers consistency verification between identity anchors and non-periodic keys according to an adaptive cycle based on network entropy change detection. It uses a lightweight zero-knowledge challenge-response protocol to compare the current parameters of the node with the hash chain root digest and chaotic state snapshot backed up in the cloud. The dynamic adaptive verification ensures that the zero-knowledge verification does not leak key materials. When a verification failure or an isolation signal from the receiving policy linkage module is detected, a hierarchical reset process is automatically triggered: First, the communication tunnel status of the node and its upstream and downstream neighbors is temporarily stored, all local session key caches are erased, anomalies are detected and immediately isolated, and the local session key cache is completely erased. The reset process involves re-invoking the fruit fly algorithm to elect a new notary node in parallel, and synchronizing the latest high-dimensional chaotic initial vector and solidified identity parameters in the cloud. A version number mechanism is used to prevent the old parameters from rolling back, so that the damaged topology can restore the trusted communication tunnel and reconnect to the network without reusing any contaminated keys. Parallel reset and anti-rollback ensure the safe recovery of the damaged topology without reusing old keys.

[0016] Compared with the prior art, the beneficial effects of the present invention are: 1. This multi-node high-security IoT communication system uses the fruit fly algorithm to dynamically optimize and select trusted temporary notaries, and combines the one-way irreversible characteristics of hash chains to anchor the public key of the first communication in a chain, so that hijacking nodes cannot forge continuous chain values ​​or mix into the authentication path, thereby achieving lightweight and resistant to intermediate substitution for the first identity solidification, effectively solving the security problem of the lack of a self-verification mechanism for the authenticity of the first identity in the dynamic topology of IoT.

[0017] 2. This multi-node high-security IoT communication system generates high-dimensional chaotic excitation in the cloud and uses a solidified public key as a perturbation factor in the terminal for nonlinear iteration, so that each session generates a completely unique non-periodic key. Combined with the instant memory erasure and one-way hash pointer mechanism, it prevents attackers from extracting repeating patterns or restoring key fragments from historical traffic, thus blocking key prediction attacks based on time-series correlation.

[0018] 3. This multi-node high-security IoT communication system achieves minimum permission isolation of keys and policies by independently deploying micro-container instances for each pair of adjacent nodes and combining kernel-level system call interception. This ensures that physically captured nodes can only parse ciphertext directly related to themselves and cannot obtain upstream and downstream communication content or global policies, thus forcibly blocking the cross-node spread of polluting information at the kernel level.

[0019] 4. This multi-node high-security IoT communication system monitors node anomalies in real time through side-channel behavioral fingerprint analysis. Once a node is determined to be captured, it broadcasts a policy switching instruction with a one-time seed to its upstream and downstream nodes. Within the switching window, the upstream and downstream nodes completely abandon the old policy and derive a new policy with no mathematical correlation, so that the captured node permanently loses its decryption ability and completely cuts off the pollution propagation path at the protocol level. Attached Figure Description

[0020] Figure 1 This is a timing diagram of the control logic for a multi-node high-security Internet of Things communication system according to the present invention. Figure 2 This is a schematic diagram of the workflow of a multi-node high-security Internet of Things communication system according to the present invention. Detailed Implementation

[0021] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments.

[0022] Example 1, please refer to Figure 1 , Figure 2 This invention provides a technical solution: a multi-node high-security Internet of Things (IoT) communication system, including a cloud management center, the cloud management center having the following communication connections: The chain-anchored identity module is used in IoT communication systems to dynamically select trusted neighbor nodes as temporary notaries through the fruit fly algorithm. It combines the hash chain to anchor the initial public key in a chain, forcing hijacking nodes to be unable to forge continuous chain values. This achieves lightweight, resistant to intermediate replacement of identity initial solidification, ensuring that the initial identity anchor is unforgeable and resistant to intermediate node hijacking. The chain-anchored identity module includes a fruit fly neighbor selection unit and a hash chain anchor unit. The Fruit Fly Neighbor Selection Unit utilizes the Fruit Fly algorithm to dynamically optimize the multi-dimensional trust indicators of neighboring nodes, quickly selecting trusted temporary notary nodes, blocking hijackers from infiltrating the authentication path, ensuring the security of the initial handshake, and rapidly selecting trusted notaries to prevent hijackers from infiltrating the authentication path. In the IoT communication system, the node to be connected broadcasts a neighbor discovery request with a dynamic random number seed, collects multi-dimensional trust indicators from neighboring nodes, including historical response entropy, online duration jitter variance, and signal phase stability coefficient, comprehensively assesses the trustworthiness of neighbors, filters potential malicious nodes, and optimizes the multi-dimensional trust indicators of each neighboring node. The trust index is mapped to the spatial location of the odor concentration of individual fruit flies. Iterative optimization is performed through an asymmetric odor concentration judgment function, and a random drift suppression factor is introduced to prevent premature convergence. The candidate notary node set with the highest comprehensive trust is selected, and high-trust nodes are accurately selected to avoid the algorithm getting trapped in local optima too early. A node is randomly selected from the candidate notary node set based on local sniffing distance weighting as a temporary notary. A one-time session identifier is dynamically generated to participate in the hash chain anchoring of the public key of the first handshake, blocking hijackers from infiltrating the authentication path through time-series replay or identity forgery, ensuring the fairness and security of notary election, and preventing replay and identity forgery infiltration. It should be noted that when an access node powers on for the first time or during network reconfiguration, it broadcasts a neighbor discovery request message carrying a dynamic random number seed on a designated channel. This dynamic random number seed is generated by a local true random number generator, has a period of 32 bits, and a validity period of 500 milliseconds, used to prevent replay attacks. After receiving the request, surrounding neighbor nodes each extract their locally maintained three-dimensional trust indicators: the historical response entropy value is calculated by the ratio of the number of successful responses to the total number of requests in the past 24 hours, with an entropy threshold of 0.85 or higher for a node to be considered a trusted candidate; the online duration jitter variance is calculated by the standard deviation of the node's online duration over the past 7 days, with nodes having a variance exceeding 120 seconds... Points are judged to be unstable; the signal phase stability coefficient is calculated based on the average phase offset of 10 consecutive signal-to-noise ratio samples. Nodes with a coefficient lower than 0.92 are considered to have unreliable channel quality. After the access node collects the above indicators, it enters the next screening process; the access node normalizes the three-dimensional trust indicators of each neighbor node and maps them to the three-dimensional coordinate position of the fruit fly individual in the odor concentration search space. The asymmetric odor concentration judgment function assigns differentiated weights to different trust dimensions: the historical response entropy value has a weight of 0.5, the online duration jitter variance has a weight of 0.3, the signal phase stability coefficient has a weight of 0.2, and individuals with a comprehensive concentration value lower than 0.7 are directly... During the elimination and iterative optimization process, the random drift suppression factor is set to 0.1, the random drift amplitude decay coefficient is 0.95 per iteration, and the maximum number of iterations is limited to 50. The iteration terminates when the optimal concentration change rate is below 0.01% for five consecutive rounds to prevent premature convergence. The selected candidate notary node set has a capacity of no more than five nodes, and the comprehensive trust level of each node is no less than 0.85. When selecting a temporary notary from the candidate notary node set, the system uses a local sniffing distance weighted random algorithm for election. The sniffing distance of each candidate node is obtained by measuring the signal arrival time in meters, and the weight is assigned as the product of the inverse of the sniffing distance and the comprehensive trust level. The closer the node is and the higher its trust level, the greater the probability of it being selected. After the election is completed, the selected temporary notary generates a one-time session identifier. This identifier is composed of the lower 32 bits of the current Unix timestamp and the dynamic random number seed, which are XORed and then concatenated into a 12-bit cyclic redundancy check code. The total length is 44 bits, and the validity period is within 30 seconds after the start of the first handshake. This session identifier is embedded in each frame of the interaction message in the subsequent hash chain anchoring process to bind the context of this handshake. Even if the hijacker intercepts the historical messages, because it cannot obtain the precise alignment relationship between the dynamic random number seed and the real-time timestamp, it cannot replay or forge the complete session identifier to mix into the authentication path. The hash chain anchor unit is used to anchor the initial public key using the continuous, unidirectional, and irreversible nature of the hash chain. This prevents hijacking nodes from forging the complete chain value, ensuring the authenticity and integrity of the initial public key distribution and establishing a traceable identity anchor. After the access node generates its initial communication public key and uses it as the tail value of the hash chain, a salt value bound to the temporary notary's identity is introduced. Then, continuous unidirectional hashing iterations are performed to generate the head anchor value. The head, tail, and salt values ​​are submitted to the temporary notary to prevent public key tampering and ensure the chain value generation process is unforgeable. The temporary notary binds the head value to their own digital signature. Broadcast to the entire network, subsequent nodes are required to disclose the chain value in reverse order and attach timestamp proof during verification. This causes the hijacking node to expose its tampering behavior due to the lack of salt value and inability to reverse-forge the previous chain value. The forced disclosure of the verification chain value makes it impossible for the hijacking node to hide its tampering traces. After all nodes in the network perform joint consistency verification of the chain value and signature and pass the verification, the initial public key combined with the temporary notary identity is solidified as the non-repudiable identity anchor of the node. This achieves lightweight, non-intermediate substitution and non-replay attack-resistant initial identity anchoring, solidifying the non-repudiable identity anchor and resisting intermediate substitution and replay attacks. It should be noted that after the temporary notary election is completed, the node to be connected calls its local key generator to create a public key for the initial communication. This public key is 256 bits long and serves as the start and end value of the hash chain. Simultaneously, the node obtains the pre-broadcast identity code of the temporary notary and concatenates this code with a randomly generated 32-bit salt value. The salt value is generated immediately after the election by the node's local true random number generator. The node then inputs the end value, salt value, and temporary notary identity code into a one-way hash function. This hash function uses the SM3 cryptographic hash algorithm and iterates for 64 rounds, with the output of each round serving as the input for the next round, until the final chain head anchor value is generated. The header length is 256 bits, consistent with the tail length. A node combines the header, tail, and salt value into a single data packet and submits it through a pre-established secure channel by a temporary notary. The submission includes a session identifier for this handshake, ensuring contextual binding with the previous neighbor discovery process. Upon receiving the data packet from the node to be connected, the temporary notary first verifies if the salt value matches its own identity identifier. If the verification is successful, it digitally signs the header value using its private key. The signature algorithm is the SM2 elliptic curve public-key cryptography algorithm. The temporary notary then broadcasts the header value along with the signature result to all online nodes in the network. The broadcast message includes a timestamp field with a precision of [insert precision here]. At the millisecond level, subsequent nodes challenge the node to be connected during the verification phase, requiring it to disclose chain values ​​sequentially in reverse order of the hash chain, with each disclosure interval being 500 milliseconds. Each disclosed value must be accompanied by a locally generated timestamp proof. Because the hijacking node lacks the original salt value bound to the temporary notary's identity, it cannot calculate any preceding chain value from the intercepted chain head value. Furthermore, since the iteration count is fixed at 64 rounds, any forgery attempt will result in a discrepancy between the disclosed value and the hash calculation result, thus exposing the tampering behavior. After receiving the complete chain value sequence disclosed sequentially by the node to be connected, all nodes in the network independently verify the hash relationship of each hop, confirming that adjacent chain values ​​satisfy a one-way hash mapping. The system verifies the validity of the temporary notary's digital signature and compares the chain tail value with the initial communication public key declared by the node to be connected. Once more than two-thirds of the nodes in the network have completed the verification and the result is passed, the system binds the initial communication public key of the node to be connected with the node identifier of the temporary notary to form an immutable identity anchor record. This record is written to the local trust database of each node and is accompanied by a solidified timestamp. The record is valid indefinitely. In subsequent communications, any node claiming this identity must present a private key signature corresponding to the solidified public key. This achieves a lightweight, substitution-resistant, and replay-attack-resistant initial identity anchoring mechanism. The chaos anti-analysis module is used to generate a high-dimensional chaotic initial vector in the cloud management center to break the temporal correlation. The terminal uses the solidified public key as a perturbation factor to iteratively generate an aperiodic session key to resist historical traffic analysis attacks, making it impossible for attackers to extract repeating patterns from historical traffic, breaking the temporal correlation, and resisting historical traffic pattern analysis attacks. The chaos anti-analysis module includes a cloud-based chaos excitation unit and a terminal perturbation iteration unit. The cloud-based chaotic excitation unit generates an initial vector for a high-dimensional chaotic mapping, known as the cloud-based chaotic vector, from the cloud management center. This disrupts the temporal logic of key generation, preventing attackers from extracting repeating sequences from historical traffic or predicting the next-hop key state, thus preventing sequence prediction attacks. The cloud management center generates an initial state vector based on a five-dimensional hyperchaotic system. The five state components of this system are mutually driven by nonlinear cross-coupling terms, breaking the linear predictability of a single temporal dimension, increasing the complexity of the chaotic source, and completely disrupting the linear temporal law of the key. The initial state vector is then coupled with the real-time collected global entropy value of the network. (Including node online fluctuations and traffic burst characteristics) Dynamically confuse and modulate to generate an irreversible cloud-based chaotic vector, which is then broadcast to all online terminals across the network through a quantum-resistant encryption channel. Real-time network entropy values ​​are injected to make the chaotic vector dynamically irreversible and resistant to quantum cracking. The cloud updates the chaotic vector parameters according to an irregular session period (dynamically adjusted based on network load). A random jump step size is inserted before each update, so that there is no state transition matrix to follow between two consecutive excitation sources. Attackers cannot extract any repeating patterns or reconstruct the phase space trajectory from historical traffic, disrupting the state update rhythm and blocking the reconstruction of the phase space trajectory and pattern extraction. It should be noted that the cloud management center is deployed on a distributed server cluster and uses a five-dimensional hyperchaotic system to generate the initial state vector. The five state components are mapped to five physical dimensions: current, magnetic flux, voltage, phase, and coupling strength. After the system is powered on, the cloud management center reads a 128-bit true random seed from the hardware security module and iterates through five-dimensional nonlinear cross-coupling 2000 times to reach the stable state of the chaotic attractor. The initial values ​​of the five state components are set to 0.342, 0.871, 0.156, 0.623, and 0.498, respectively. The coupling coefficients between the components are fixed in the cloud-based trusted execution environment and are managed every 48 hours. Members rotate remotely via authentication. The coupling coefficient matrix is ​​stored in an encrypted configuration file, readable and writable only by privileged processes in the cloud, preventing attackers from obtaining the system's internal dynamic patterns through reverse engineering. After stabilization iterations, the five-dimensional vector value is locked as the chaotic baseline state for the current session period. A traffic probe is deployed in the cloud management center, collecting online fluctuation values ​​and traffic burst characteristics of all network nodes every 200 milliseconds. Online fluctuations are calculated as a percentage difference between the current number of online nodes and the sliding average over the past 5 seconds. Traffic bursts are quantified based on the deviation of the number of packets per second from the historical baseline. The real-time collected 32-bit entropy values ​​are SHA-enabled. The -256 hash is expanded into a 256-bit entropy mask, which is then XORed with the five-dimensional chaotic baseline state bit by bit for obfuscation. Each dimension is obfuscated independently, and the obfuscation order is randomly rearranged every 10 seconds. The resulting cloud-based chaotic vector is 1280 bits long, containing 256 bits for each of the five dimensions. This chaotic vector is encapsulated into broadcast ciphertext using a quantum-resistant encryption channel based on the NTTRU algorithm. Each broadcast message carries a sequence number and a millisecond-level timestamp to ensure that the terminal can verify the freshness of the message. The cloud sends out new chaotic vectors according to a dynamic session cycle, with the cycle length randomly varying between 15 and 90 seconds, dynamically adjusted based on the current network load rate. When the load rate is below 30%, a long period is used; when it is above 70%, it is compressed to a short period. Before each new vector is sent, a random jump step size module is inserted in the cloud. This module reads a 16-bit random integer from the local noise source and jumps each component of the current chaotic baseline state forward by the integer modulo 256 steps. The jump process uses an irreversible chaotic mapping one-way function to ensure that the state before the jump cannot be deduced from the state after the jump. There is no deterministic state transition relationship between the excitation sources sent in two consecutive times. Even if the attacker intercepts all historical chaotic vectors, he cannot construct a regression mapping of the phase space trajectory, thus completely blocking key prediction attacks based on time series analysis. The terminal perturbation iteration unit is used to perform nonlinear iteration on the cloud-based chaotic vector using a pre-set local public key as a perturbation factor. This generates a non-periodic session key that is unique for each session, blocking key decryption attacks based on pattern prediction and ensuring the uniqueness of the session key. The terminal extracts the pre-set local public key byte string as a perturbation seed and performs bidirectional cross-bit diffusion (XORing the high and low bits after swapping) with the cloud-based chaotic vector to generate a perturbed initial iteration value with an avalanche effect. This ensures that a single bit change triggers an avalanche, and the terminal's initial state is unique and unpredictable. The perturbed initial iteration value drives the cascading process. The chaotic mapping function (which alternates between Logistic mapping and Tent mapping) dynamically selects different iteration start and end intervals for each session, and extracts the state value at the end of the interval as the aperiodic key for this session. The dynamic interval makes each session key independent and unrelated, completely aperiodic. The terminal only retains the one-way hash pointer generated during the iteration process, pointing to the state slice required for the next round, and immediately erases all intermediate iteration variables. This makes it impossible for attackers to deduce any historical or future keys forward or backward even if they obtain the key for this session. It completely blocks key deduction attacks based on time-series correlation and immediately clears intermediate variables, blocking forward and backward key deduction based on time-series correlation. It should be noted that after receiving the 1280-bit chaotic vector broadcast by the cloud management center, the terminal device reads the pre-fixed 256-bit public key byte string from the local trust database as a perturbation seed. The terminal divides this public key byte string into a high half and a low half, each consisting of 128 bits, and performs cross-permutation with each of the five 256-bit components of the chaotic vector: the high half is XORed with the lower 128 bits of the chaotic component, and the low half is XORed with the higher 128 bits of the chaotic component. After the permutation, the components are reassembled to form a 256-bit diffusion result. This process is repeated for each of the five chaotic components, ultimately generating five 256-bit perturbation initial values. The initial iteration value, through bidirectional cross-bit diffusion, ensures that any single-bit change in the public key seed triggers approximately 50% of the output bits to flip, creating an avalanche effect. This ensures the uniqueness and unpredictability of the chaotic iteration start point for different terminals. The terminal uses five 256-bit initial iteration values ​​generated after perturbation to drive a cascaded chaotic mapping function. This function alternates between Logistic and Tent mappings, with each mapping outputting a 64-bit state value per iteration. The terminal synchronously obtains the iteration start and end parameters for each session from the cloud management center upon session establishment: the initial round number ranges from 1000 to 2000. The terminal selects its own iteration interval from 3000 to 5000, ensuring that iteration intervals between sessions do not overlap. The terminal iterates continuously from the starting interval until the ending interval is reached, at which point the lower 192 bits of the current state value are extracted as the aperiodic key for this session. Because the iteration interval for each session is independently and randomly selected, there is no deterministic state association between different sessions, making it impossible for attackers to deduce the iteration pattern from historical keys. To prevent key materials from remaining in the terminal's memory, the terminal maintains only a one-way hash pointer pointing to the current state slice during iteration. This pointer is obtained by performing an SM3 hash on the previous state value. The key is generated by computation and is 256 bits long. After each iteration, the terminal immediately overwrites all intermediate variables generated in the previous iteration with random data and releases the memory space, including the temporary state value of the chaotic mapping, the iteration counter and the intermediate results of bit diffusion. After the iteration is completed, the terminal only retains the 192-bit session key and the hash pointer pointing to the starting state of the next round, and erases all other iteration variables. Even if the attacker extracts the session key by physical means, because the intermediate variables have been completely cleared and the hash pointer is irreversible, it is impossible to trace back the historical key or deduce the future key, so as to completely block the time-series correlation attack. The container truncation module is used to deploy secure containers through notary nodes selected by the fruit fly algorithm, restricting physically captured nodes to only decrypting ciphertexts unrelated to themselves, preventing them from parsing upstream and downstream communication content, cutting off the pollution propagation path, restricting the visibility of captured node information, and cutting off the path of pollution spreading outward. The strategy linkage module, based on the fixed identity and non-periodic key, combines end-cloud collaboration to generate and distribute dynamic encryption strategies in real time. This enables any node to switch its upstream and downstream communication strategies immediately after it is captured, forcibly blocking the node from continuing to pollute the instructions and data of neighboring nodes, thus preventing the pollution from spreading to neighboring nodes. The captured node becomes immediately ineffective, preventing it from spreading pollution to its neighbors. The loopback self-healing module is used to periodically verify the consistency between the solidified identity and the non-periodic key. When an anomaly is detected or a node is isolated, the reset process is automatically triggered. The notary node is re-elected through the fruit fly algorithm and the chaotic parameters are synchronized, so that the damaged topology can automatically restore the trusted communication tunnel. In case of an anomaly, the system will automatically reset and recover, ensuring that the damaged topology can quickly self-heal.

[0023] Example 2, as Figure 1 , Figure 2 As shown, based on Embodiment 1, the present invention provides a technical solution: the container truncation module specifically includes: the IoT communication system dynamically instantiates a micro-container instance for each pair of adjacent communication relationships based on the notary node selected by the fruit fly algorithm. This instance only injects the decryption key and policy fragment directly related to the communication pair to achieve the minimum permission isolation of the key and context, preventing single container leakage from affecting other communication pairs. The micro-container forcibly blocks inter-process memory sharing and network stack original socket sniffing through system call interception hooks based on eBPF, so that the physically captured node can only decrypt ciphertext data whose destination address precisely matches its own and whose session identifier is consistent. Kernel-level forced isolation restricts the captured node to only decrypt its own ciphertext. The micro-container has a built-in real-time integrity measurement module that periodically verifies the hash value of the internal policy file. Once unauthorized memory access or key extraction behavior is detected, the container self-destruction and communication channel circuit breaking are immediately triggered to prevent upstream and downstream ciphertext from being parsed across nodes or global policies from being reversed. Real-time self-destruction and circuit breaking prevent ciphertext from being leaked across nodes and policies from being reversed. It should be noted that during the deployment phase of the IoT communication system, the cloud management center dynamically creates independent micro-container instances for each pair of neighboring nodes with established trust relationships, based on the notarized node election results output by the fruit fly algorithm. At creation, each instance is injected only with the decryption key material directly associated with that communication pair and the corresponding policy fragment. The decryption key is a 192-bit aperiodic session key, and the policy fragment includes the encryption algorithm family rotation sequence number and the chaotic iteration round offset. The system uses a least privilege design to ensure that each micro-container instance cannot access any key material other than its own communication pair. Even if the physical node containing the instance is subsequently captured by an attacker, the attacker cannot extract the key information used to parse other communication pairs from that instance. At the operating system kernel level, the system deploys an eBPF-based system call interception hook for each micro-container instance. This hook monitors and forcibly blocks two types of dangerous behaviors in real time: cross-container access requests for shared memory between processes and network stack sniffing operations on raw sockets. The interception hook is configured with a whitelist rule table, allowing only... Encrypted data packets whose destination address precisely matches the current container identifier and whose session identifier is consistent are allowed to pass. All other cross-container data access requests are immediately rejected by the kernel and an exception log is recorded. This forcibly isolates the data paths of different microcontainers at the kernel level, preventing physically captured nodes from parsing any upstream or downstream communication ciphertexts that do not belong to them. Each microcontainer instance integrates a real-time integrity measurement module. This module reads the current hash value of the policy file inside the container every 60 seconds and compares it with the baseline hash value saved when the container starts. When a hash value inconsistency is detected, or an unauthorized memory access alarm is reported through the eBPF hook, the integrity measurement module immediately triggers a two-stage self-destruct process: the first stage erases all key materials and policy fragments in the container memory within 5 milliseconds; the second stage broadcasts a communication channel meltdown signal to adjacent nodes, requiring upstream and downstream nodes to complete policy switching within 200 milliseconds. Container instances that have completed self-destruction will be marked as unavailable, and their physical nodes must go through a complete identity anchoring process before they can reconnect to the network. The strategy linkage module specifically includes: Based on the fixed node identity and non-periodic session key, the cloud management center generates a dynamic encryption strategy for each pair of adjacent nodes by combining the current network topology hash snapshot. The dynamic encryption strategy includes the encryption algorithm family rotation sequence number, key derivation depth and chaotic iteration round offset. Each pair of nodes has an independent strategy, blocking cross-communication pair key association analysis. When any node is detected as abnormal or physically captured through side channel behavior fingerprint analysis, the cloud management center immediately broadcasts a time-stamped strategy switching instruction to the upstream and downstream neighbors of that node. The strategy switching instruction includes a one-time update seed and the absolute time boundary for the switch to take effect. It responds immediately to abnormality detection. The instruction includes anti-replay and precise effective boundary. After receiving the instruction, the upstream and downstream nodes synchronously enter the strategy conversion window. During the window period, the key material corresponding to the old strategy is completely discarded, and any instructions or data encapsulated using the old strategy are refused to be processed. This causes the captured node to permanently lose the ability to decrypt communication with adjacent nodes due to the lack of a new strategy seed. The old key is quickly discarded, causing the captured node to permanently lose the ability to decrypt. It should be noted that the cloud management center establishes a dynamic encryption policy table for each pair of adjacent IoT nodes that have completed identity anchoring. The system uses the 256-bit public key and 192-bit aperiodic session key of each node as the basic key material, combined with the 128-bit topology digest generated by the current network topology hash snapshot, to independently calculate a set of dynamic parameters for each pair of adjacent nodes. These parameters include the encryption algorithm family rotation sequence number, key derivation depth, and chaotic iteration round offset. The encryption algorithm family rotation sequence number ranges from 0 to 7, corresponding to eight preset symmetric encryption algorithm combinations. The key derivation depth is set to 3 to 10 layers to control the number of iterations of the key material. The chaotic iteration... The round offset fluctuates within a range of ±500, used to fine-tune the start and end rounds of the cascaded chaotic mapping in the terminal perturbation iteration unit, ensuring that there is no key correlation between different communication pairs, and that policy leakage of any pair of nodes does not affect the security of other communication pairs; when the cloud management center detects abnormal characteristics of a node through side-channel behavior fingerprint analysis, such as a power consumption curve change of ≥30% for a duration of ≥3 seconds, an abnormal deviation of electromagnetic radiation of ≥30% after secondary confirmation, or a response delay deviation of ≥30% from the baseline with five consecutive abnormal probes, it is determined that the node has been physically captured. The cloud management center immediately retrieves information on all upstream and downstream neighboring nodes of the node and forwards the information to the upstream and downstream nodes. Neighboring nodes broadcast policy switching instructions with millisecond-level timestamps. Each instruction contains a 128-bit one-time update seed generated by a hardware security module, and an absolute time boundary for the switch to take effect, set at 500 milliseconds after the instruction is issued. To ensure the unforgeability of the instructions, the cloud management center signs the instruction content using its own private key. Upon receiving the instruction, the neighboring node first verifies the validity of the signature to confirm the authenticity of the instruction's source. After receiving and verifying the policy switching instruction, upstream and downstream nodes synchronously enter a 500-millisecond policy transition window. During this window, the node first completely discards all key materials corresponding to the old policy associated with the target node. The data includes a 192-bit session key, the encryption algorithm family rotation sequence number, and the offset of the chaotic iteration round. Its memory space is then randomly overwritten and erased three times. Subsequently, the node uses the one-time update seed in the instruction to derive a new dynamic encryption strategy in combination with its own fixed identity public key. The parameters of the new strategy have no mathematical relationship with the old strategy. After the window period ends, the node refuses to process any data packets encapsulated using the old strategy. The ciphertext corresponding to the old strategy will be directly discarded and an anomaly log will be recorded. The captured node, because it has not received the update seed and cannot know the new strategy parameters, permanently loses the ability to decrypt subsequent communications with neighboring nodes, thus completely blocking the path of pollution spreading to the upstream and downstream at the protocol level. The loopback self-healing module specifically includes: the system triggers consistency verification between identity anchors and non-periodic keys according to an adaptive cycle based on network entropy change detection; it uses a lightweight zero-knowledge challenge-response protocol to compare the node's current parameters with the hash chain root digest and chaotic state snapshot backed up in the cloud; dynamic adaptive verification; zero-knowledge verification does not leak key materials; when a verification failure is detected or an isolation signal is received from the policy linkage module, a hierarchical reset process is automatically triggered: first, the communication tunnel status of the node and its upstream and downstream neighbors is temporarily stored; all local session key caches are erased; anomalies are detected and immediately isolated; the local session key cache is completely erased; the reset process is carried out in parallel, and the fruit fly algorithm is called again to elect a new notary node; the latest high-dimensional chaotic initial vector and solidified identity parameters are synchronized in the cloud; a version number mechanism is used to prevent the old parameters from rolling back; the damaged topology can restore the trusted communication tunnel and reconnect to the network without reusing any contaminated keys; and the parallel reset anti-rollback ensures the safe recovery of the damaged topology without reusing old keys. It should be noted that network entropy change detection is used as an adaptive triggering mechanism to perform consistency verification on the fixed identity anchors and non-periodic session keys across the entire network. The cloud management center collects the number of online nodes and the magnitude of traffic bursts every 200 milliseconds, calculates the deviation ratio of the current network entropy value from the historical sliding window baseline, and automatically shortens the verification period to a minimum of 15 seconds when the entropy value fluctuation exceeds a preset threshold. The verification process adopts a lightweight zero-knowledge challenge-response protocol. Nodes locally hold hash chain root digests and chaotic state snapshots. The cloud only verifies the statistical characteristics of the response without obtaining the original key material to reduce communication overhead and prevent secret leakage. During each verification, the node must return a response value calculated based on the current session key within 500 milliseconds. The cloud compares its consistency with the backup parameters. If two consecutive verifications fail, the system determines that the node's identity or key has expired. When the consistency verification fails consecutively or a node isolation signal is received from the policy linkage module, the system immediately triggers a graded reset process for the target node and its upstream and downstream neighbors. The reset process first temporarily stores the status identifier of the affected communication tunnel, including the node identifier, session number, and current chaotic iteration round, and resets all session keys related to the tunnel in local memory. The key cache undergoes three rounds of random overwriting and erasure to ensure that any residual key material cannot be recovered. During this process, the cloud management center simultaneously freezes the node's adjacency relationships in the topological hash snapshot to prevent new communication tunnel establishment requests from occurring during the reset. During the temporary storage operation, upstream and downstream neighboring nodes only maintain basic keep-alive message exchange and do not process any business data ciphertext, providing a clean context environment for the reset execution. The reset process executes two tasks in parallel: notary node re-election and chaotic parameter synchronization. The fruit fly algorithm is invoked again to select a trusted temporary notary based on the latest neighboring node trust index. The target acquisition window is limited to the past 24 hours and the effective response rate is not less than 85%. The cloud management center issues the high-dimensional chaotic initial vector and fixed identity parameters for the current period. Each issued instruction is accompanied by an incrementing version number. Before updating, the node compares the version number and rejects any parameters that are lower than or equal to the current version number. This prevents attackers from rolling back and restoring the contaminated key through old parameters at the protocol layer. After the reset is completed, the upstream and downstream neighbor nodes restore the communication tunnel and re-encrypt the business data using the newly derived non-periodic key. The damaged topology reconnects to the network without reusing any contaminated keys.

[0024] The following section describes the workflow of this multi-node, high-security IoT communication system.

[0025] After the system starts, the node to be connected triggers the chain-anchored identity module by broadcasting a neighbor discovery request. This module uses the fruit fly algorithm to dynamically optimize the multi-dimensional trust indicators of neighboring nodes, selects trusted temporary notaries, and the hash chain anchoring unit anchors the node's initial public key in a chain-like manner using a unidirectional irreversible hash chain, realizing the initial identity solidification and preventing hijacking and replacement by intermediate nodes. After the identity anchoring is completed, the system enters the running phase. The cloud-based chaos excitation unit generates a high-dimensional chaotic initial vector, which is then broadcast to the entire network after dynamic obfuscation. The terminal perturbation iteration unit uses the solidified public key as a perturbation factor to perform bidirectional cross-bit diffusion on the chaotic vector and drive cascaded chaotic mapping, iteratively generating an independent and unpredictable aperiodic session key for each session to resist historical traffic analysis attacks. During communication, the container truncation module dynamically creates independent micro-containers for each pair of adjacent nodes, injecting only the keys and policy fragments required for its own communication, and forcibly isolates cross-container access through kernel-level hooks. The policy linkage module continuously monitors the node behavior fingerprint. Once a node is detected as abnormal or captured, it immediately broadcasts a policy switching instruction to upstream and downstream nodes, causing the captured node to permanently lose its decryption ability. The loopback self-healing module adaptively triggers consistency verification based on network entropy changes. Upon detecting a failure, it automatically performs a hierarchical reset, re-elects a notary node, and synchronizes the chaos parameters to ensure that the damaged topology can restore a trusted communication tunnel without reusing any contaminated keys.

[0026] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. The scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A multi-node, high-security Internet of Things (IoT) communication system, comprising a cloud management center, characterized in that, The cloud management center communication connection includes the following modules: The chain-anchored identity module is used in IoT communication systems to dynamically select trusted neighbor nodes as temporary notaries through the fruit fly algorithm, and to anchor the initial public key in a chain using a hash chain to achieve initial identity solidification. The chaos anti-analysis module is used to generate a high-dimensional chaotic initial vector in the cloud management center to break the temporal correlation. The terminal uses the solidified public key as a perturbation factor to iteratively generate an aperiodic session key to resist historical traffic analysis attacks. The container truncation module is used to deploy secure containers through notary nodes selected by the fruit fly algorithm, restricting physically captured nodes to only decrypting ciphertext unrelated to themselves, thus cutting off the path of contamination propagation. The strategy linkage module, based on the fixed identity and non-periodic key, combines end-cloud collaboration to generate and distribute dynamic encryption strategies in real time, so that when any node is captured, its upstream and downstream immediately switch communication strategies to prevent the spread of contamination to neighboring nodes. The loopback self-healing module is used to periodically verify the consistency between the solidified identity and the non-periodic key. When an anomaly is detected or a node is isolated, it automatically triggers a reset process, re-elects a notary node, and synchronizes the chaos parameters, so that the damaged topology can automatically restore the trusted communication tunnel.

2. The multi-node high-security IoT communication system according to claim 1, characterized in that: The chain-anchored identity module includes a fruit fly neighbor selection unit and a hash chain anchor unit; The fruit fly neighbor selection unit is used to dynamically optimize the multi-dimensional trust index of neighbor nodes using the fruit fly algorithm, quickly filter out trustworthy temporary notary nodes, and block hijackers from infiltrating the identity authentication path. The hash chain anchor unit is used to anchor the initial public key with the continuous, unidirectional, and irreversible characteristics of the hash chain, forcing hijacking nodes to be unable to forge the complete chain value.

3. The multi-node high-security IoT communication system according to claim 2, characterized in that: The fruit fly neighbor selection unit specifically includes: In an Internet of Things (IoT) communication system, a node to be connected broadcasts a neighbor discovery request with a dynamic random number seed and collects multi-dimensional trust indicators from neighboring nodes. These multi-dimensional trust indicators include historical response entropy, online duration jitter variance, and signal phase stability coefficient. The multidimensional trust index of each neighbor node is mapped to the odor concentration search space location of the fruit fly individual. The asymmetric odor concentration judgment function is used for iterative optimization, and a random drift suppression factor is introduced to prevent premature convergence. The candidate notary node set with the highest comprehensive trust is selected. A node is randomly selected from the candidate notary node set based on local sniffing distance weighting as a temporary notary. A one-time session identifier is dynamically generated to participate in the hash chain anchoring of the public key for the first handshake, thus blocking hijackers from infiltrating the authentication path through time replay or identity forgery.

4. The multi-node high-security Internet of Things communication system according to claim 2, characterized in that: The hash chain anchor unit specifically includes: The node to be connected generates the first communication public key and uses it as the tail value of the hash chain. After introducing the salt value bound to the identity of the temporary notary, it performs continuous one-way hash iteration to generate the anchor value of the chain head. The chain head, chain tail and salt value are submitted to the temporary notary. After the temporary notary binds the chain head value with his own digital signature, he broadcasts it to the entire network. When subsequent nodes verify, they are required to disclose the chain value in reverse order and attach timestamp proof. This exposes the tampering behavior of the hijacking node because it lacks salt value and cannot reverse the forgery of the previous chain value. After all nodes in the network perform a joint consistency verification of the chain value and signature and pass the verification, the initial public key combined with the temporary notary identity is solidified as the non-repudiation identity anchor of that node.

5. A multi-node high-security Internet of Things communication system according to claim 2, characterized in that: The chaos anti-analysis module includes a cloud-based chaos excitation unit and a terminal perturbation iteration unit; The cloud-based chaotic excitation unit generates an initial vector of high-dimensional chaotic mapping, i.e., a cloud-based chaotic vector, from the cloud management center. This disrupts the temporal logic of key generation, making it impossible for attackers to extract repeating sequences from historical traffic or predict the next-hop key state. The terminal perturbation iteration unit is used to perform nonlinear iteration on the cloud-based chaotic vector using the pre-fixed local public key as a perturbation factor on the terminal, generating a non-periodic session key that is not repeated in each session, thereby blocking key restoration attacks based on pattern prediction.

6. The multi-node high-security Internet of Things communication system according to claim 5, characterized in that: The cloud-based chaos stimulation unit specifically includes: The cloud management center generates an initial state vector based on a five-dimensional hyperchaotic system. The five state components of the five-dimensional hyperchaotic system drive each other through nonlinear cross-coupling terms. The initial state vector is dynamically confused and modulated with the real-time collected global entropy value of the network to generate an irreversible cloud-based chaotic vector, which is then broadcast to all online terminals across the network through a quantum-resistant encryption channel. The cloud updates the chaotic vector parameters at irregular session intervals, inserting a random jump step size before each update, so that there is no state transition matrix to follow between two consecutive excitation sources, making it impossible for attackers to extract any repeating patterns or reconstruct phase space trajectories from historical traffic.

7. A multi-node high-security Internet of Things communication system according to claim 5, characterized in that: The terminal perturbation iteration unit specifically includes: The terminal extracts the locally stored public key byte string as a perturbation seed, performs bidirectional cross-bit diffusion with the cloud-based chaotic vector, and generates a perturbation initial iteration value with an avalanche effect. The perturbated initial iteration value is used to drive the cascaded chaotic mapping function. In each session, different iteration start and end intervals are dynamically selected, and the state value at the end of the interval is used as the aperiodic key for this session. The terminal retains only the one-way hash pointer generated during the iteration process, pointing to the state slice required for the next round, and immediately erases all intermediate iteration variables. This prevents attackers from deriving any historical or future keys forward or backward, even if they obtain the key in this iteration, thus completely blocking key decryption attacks based on time-series correlation.

8. A multi-node high-security Internet of Things communication system according to claim 5, characterized in that: The container truncation module specifically includes: The IoT communication system uses the fruit fly algorithm to select a notary node and dynamically instantiates a micro-container instance for each pair of adjacent communication relationships. This instance is only injected with the decryption key and policy fragment directly related to the communication pair, thus achieving minimum permission isolation between the key and the context. Microcontainers forcibly block inter-process memory sharing and network stack raw socket sniffing through eBPF-based system call interception hooks, so that physically captured nodes can only decrypt ciphertext data whose destination address exactly matches their own and whose session identifier is consistent. The micro-container has a built-in real-time integrity measurement module that periodically verifies the hash value of the internal policy file. Once unauthorized memory access or key extraction is detected, the container self-destructs and communication channel is immediately interrupted to prevent upstream and downstream encrypted messages from being parsed across nodes or global policies from being reversed.

9. A multi-node high-security Internet of Things communication system according to claim 8, characterized in that: The strategy linkage module specifically includes: Based on the fixed node identity and non-periodic session key, the cloud management center generates a dynamic encryption strategy for each pair of adjacent nodes by combining the current network topology hash snapshot. The dynamic encryption strategy includes the encryption algorithm family rotation sequence number, key derivation depth and chaotic iteration round offset. When any node is detected to be abnormal or physically captured through side channel behavior fingerprint analysis, the cloud management center immediately broadcasts a time-stamped policy switching instruction to the upstream and downstream neighbors of that node. The policy switching instruction includes a one-time update seed and the absolute time boundary for the switch to take effect. Upon receiving the instruction, upstream and downstream nodes synchronously enter the policy conversion window. During the window period, the key materials corresponding to the old policy are completely discarded, and any instructions or data encapsulated using the old policy are refused to be processed. This causes the captured node to permanently lose the ability to decrypt communication with neighboring nodes due to the lack of a new policy seed.

10. A multi-node high-security Internet of Things communication system according to claim 9, characterized in that: The loop self-healing module specifically includes: The system triggers consistency verification between identity anchors and non-periodic keys according to an adaptive cycle based on network entropy change detection, and uses a lightweight zero-knowledge challenge-response protocol to compare the current parameters of the node with the hash chain root digest and chaotic state snapshot backed up in the cloud. When a verification failure or an isolation signal from the receiving policy linkage module is detected, a hierarchical reset process is automatically triggered: first, the communication tunnel status of the node and its upstream and downstream neighbors is temporarily stored, and all local session key caches are erased; The reset process is carried out in parallel, re-invoking the fruit fly algorithm to elect a new notary node, and synchronizing the latest high-dimensional chaotic initial vector and solidified identity parameters in the cloud. A version number mechanism is used to prevent the rollback of old parameters, so that the damaged topology can restore the trusted communication tunnel and reconnect to the network without reusing any contaminated keys.

Citation Information

Patent Citations

  • System for improving security of Internet of Things and communication method thereof

    CN116418594A