An edge image-oriented zero-trust lightweight protection method for industrial internet of things

CN122845733APending Publication Date: 2026-09-29LIAONING TECHNICAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610989216.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-03
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]然而,现有的图像保护方法中,直接采用静态密钥加密或分离式认证加密,并没有将设备身份、会话上下文与图像内容特征统一纳入保护链路,由此可能会导致终端物理暴露后静态密钥泄露、历史合法图像被重放或替换,或者逐帧公钥运算在高帧率场景下形成显著时延瓶颈,从而影响工业控制闭环的实时性与安全性,难以满足零信任网络“每次交互均需显式验证”的核心要求

Benefits of technology

[0017]本发明实施例的一种面向工业物联网边缘图像的零信任轻量级保护方法及装置,可以降低静态密钥泄露风险,实现零信任可信接入,提高抗单点失陷能力,增强抗重放和内容替换能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845733A_ABST
    Figure CN122845733A_ABST
Patent Text Reader

Abstract

The application discloses a zero-trust lightweight protection method for an industrial Internet of Things edge image. The application generates public and private device identity parameters by using physical unclonable features of a visual terminal, constructs a zero-knowledge proof upload gateway relying on the private identity to complete authentication, negotiates a session seed and threshold hosting after verification, collects industrial site images and extracts content fingerprints, binds the session seed, image fingerprints and frame data to generate a combined seed, derives encryption materials to perform pre-diffusion, global scrambling and parallel sponge encryption on the original image, and outputs a ciphertext image and an authentication tag. The gateway reconstructs the encryption material calculation tag according to the trusted identity and session information, and only when the verification is consistent, the downstream business can be transferred; if the verification fails, the access is blocked, an alarm is triggered and the session is refreshed. The application combines hardware trusted identity and frame-level image encryption to ensure that the edge device access is trusted, and to improve the tamper-proofing and integrity security of industrial image transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of image processing technology, and in particular to a zero-trust lightweight protection method for edge images in the Industrial Internet of Things (IIoT). Background Technology

[0002] As a crucial infrastructure for smart manufacturing, the Industrial Internet of Things (IIoT) has seen its visual edge terminals widely applied in industrial scenarios such as automated optical inspection, process monitoring, robot collaboration, and digital twins. Among related technologies, a preliminary security protection system has been constructed through the collaborative operation of image encryption, device authentication, and access control. Specifically, this system covers the entire chain from image acquisition and transmission to downstream business applications, including key steps such as pixel scrambling, public key signing, and session key negotiation, aiming to ensure the confidentiality and source trustworthiness of image data.

[0003] However, existing image protection methods directly employ static key encryption or separate authentication encryption, without integrating device identity, session context, and image content features into the protection chain. This may lead to static key leakage after the terminal is physically exposed, replay or replacement of historical legitimate images, or significant latency bottlenecks in frame-by-frame public key computation in high frame rate scenarios, thereby affecting the real-time performance and security of industrial control closed loops and failing to meet the core requirement of zero-trust networks that "every interaction must be explicitly verified". Summary of the Invention

[0004] The present invention aims to at least partially solve one of the technical problems in the related art.

[0005] Therefore, the first objective of this invention is to propose a zero-trust lightweight protection method for edge images in the Industrial Internet of Things.

[0006] Another objective of this invention is to provide a zero-trust lightweight protection device for edge images in the Industrial Internet of Things (IIoT).

[0007] The third objective of this invention is to provide a computer device.

[0008] The fourth objective of this invention is to provide a non-transitory computer-readable storage medium.

[0009] To achieve the above objectives, a first aspect of the present invention proposes a zero-trust lightweight protection method for edge images in the Industrial Internet of Things (IIoT), comprising: S1, recover device identity material based on the physical non-clonable features of the visual edge terminal, and generate device private identity value and public identity parameters based on the device identity material; S2, generate a non-interactive zero-knowledge proof based on the device's private identity value, and send the zero-knowledge proof to the edge security gateway for identity verification. After successful verification, negotiate a session seed and perform threshold management on the session seed. S3. Collect original images of the industrial site and extract image content fingerprints. Construct a combined seed by combining the session seed, the image content fingerprint, and the current frame binding data. Derive data surface protection material based on the combined seed. Use the data surface protection material to perform pre-diffusion, global scrambling, and parallel sponge protection processing on the original image in sequence to generate ciphertext image and authentication tag. S4, the edge security gateway receives the encrypted image and the authentication tag, reconstructs the data plane protection material according to the authenticated device identity and the current session state, and recalculates the authentication tag. If the recalculated authentication tag is consistent with the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is rejected and an alarm and session refresh are triggered.

[0010] In one embodiment of the present invention, S1 includes: Read the SRAM PUF response and generate stable identity materials through fuzzy extraction; The stable identity material, along with the device identifier and registration context, is input into a key derivation function to generate a device private identity value, and public identity parameters are calculated.

[0011] In one embodiment of the present invention, it further includes: During the registration phase, the original SRAM PUF response is read, and stable identity materials and publicly available auxiliary data are generated through the Gen function; During the runtime phase, the response is reread based on the challenge, and stable identity materials are restored through the Rep function in conjunction with publicly available auxiliary data.

[0012] In one embodiment of the present invention, S2 includes: A non-interactive zero-knowledge proof is generated based on the device's private identity value, and the zero-knowledge proof is sent to the edge security gateway for authentication. After successful verification, a session seed is negotiated, and the session seed is then managed with a threshold.

[0013] In one embodiment of the present invention, it further includes: The terminal randomly selects a one-time random number, calculates the commitment value, and generates a challenge value by combining the device identifier, timestamp, random number, session context, and policy identifier. It then calculates the response value to form a proof tuple. The edge security gateway reconstructs and verifies the commitment relationship based on the public identity parameters. The terminal and the edge security gateway negotiate and share a session secret, and derive a session seed; the shared session secret is threshold-managed using Shamir secret sharing, a polynomial is constructed, and the share is respectively managed by the edge security gateway, the edge control node, or the cloud control center.

[0014] In one embodiment of the present invention, S3 includes: Collect raw images of the industrial site and extract fingerprints from the image content; The session seed, the image content fingerprint, and the current frame binding data are constructed into a combined seed, and data surface protection material is derived based on the combined seed; The original image is pre-diffused using the data surface protection material; Globally scramble the pre-diffused image; The scrambled image is subjected to parallel sponge protection processing to generate a ciphertext image and authentication tag.

[0015] In one embodiment of the present invention, S4 includes: The edge security gateway receives the encrypted image and the authentication tag, reconstructs the data plane protection material and recalculates the authentication tag based on the authenticated device identity and the current session state; If the recalculated authentication tag matches the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is denied and an alarm and session refresh are triggered.

[0016] To achieve the above objectives, a second aspect of the present invention provides a zero-trust lightweight protection device for edge images in the Industrial Internet of Things (IIoT), comprising: The terminal identity self-generation module is used to recover device identity materials based on the physical unclonable features of the visual edge terminal, and generate device private identity values ​​and public identity parameters according to the device identity materials. The zero-knowledge identity authentication and seed hosting module is used to generate a non-interactive zero-knowledge proof based on the device's private identity value, send the zero-knowledge proof to the edge security gateway for identity verification, negotiate a session seed after successful verification, and perform threshold hosting on the session seed. The image ciphertext derivation encryption module is used to acquire original images from industrial sites and extract image content fingerprints. It constructs a combined seed by combining the session seed, the image content fingerprint, and the current frame binding data. Based on the combined seed, it derives a data surface protection material and uses the data surface protection material to sequentially perform pre-diffusion, global scrambling, and parallel sponge protection processing on the original image to generate a ciphertext image and an authentication tag. The gateway verification and authentication alarm module is used by the edge security gateway to receive the encrypted image and the authentication tag, reconstruct the data plane protection material according to the authenticated device identity and the current session state, and recalculate the authentication tag. If the recalculated authentication tag is consistent with the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is rejected and an alarm and session refresh are triggered.

[0017] This invention provides a zero-trust lightweight protection method and apparatus for edge images in the Industrial Internet of Things (IIoT), which can reduce the risk of static key leakage, achieve zero-trust trusted access, improve resistance to single point of failure, and enhance resistance to replay and content replacement.

[0018] To achieve the above objectives, a third aspect of this application provides a computer device, including a processor and a memory; wherein the processor runs a program corresponding to the executable program code by reading executable program code stored in the memory, for implementing the method described in the first aspect embodiment.

[0019] To achieve the above objectives, a fourth aspect of this application provides a non-transitory computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the method described in the first aspect.

[0020] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0021] Figure 1 This is a flowchart of a zero-trust lightweight protection method for edge images in the Industrial Internet of Things according to an embodiment of the present invention; Figure 2 This is an architecture diagram of an industrial IoT edge image zero-trust protection system according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the overall process according to an embodiment of the present invention; Figure 4 This is a functional block diagram of a visual edge terminal according to an embodiment of the present invention; Figure 5 This is a functional block diagram of an edge security gateway according to an embodiment of the present invention; Figure 6 This is a flowchart of FWHT pre-diffusion and CRT cycle-walking scrambling according to an embodiment of the present invention; Figure 7 This is a schematic diagram of the tree path key and parallel sponge protection core according to an embodiment of the present invention; Figure 8This is a flowchart of the rejection, alarm, and session refresh process after gateway-side verification failure according to an embodiment of the present invention; Figure 9 This is a structural diagram of a zero-trust lightweight protection device for edge images in the Industrial Internet of Things according to an embodiment of the present invention. Figure 10 It is a computer device according to an embodiment of the present invention. Detailed Implementation

[0022] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0023] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0024] The following description, with reference to the accompanying drawings, describes a zero-trust lightweight protection method and apparatus for edge images in the industrial Internet of Things (IoT) according to an embodiment of the present invention.

[0025] Figure 1 This is a flowchart of a zero-trust lightweight protection method for edge images in the Industrial Internet of Things (IIoT) according to an embodiment of the present invention, as shown below. Figure 1 As shown, it includes: S1, recover device identity material based on the physical non-clonable features of the visual edge terminal, and generate device private identity value and public identity parameters based on the device identity material; S2, generate a non-interactive zero-knowledge proof based on the device's private identity value, and send the zero-knowledge proof to the edge security gateway for identity verification. After successful verification, negotiate a session seed and perform threshold management on the session seed. S3. Collect original images of the industrial site and extract image content fingerprints. Construct a combined seed by combining the session seed, the image content fingerprint, and the current frame binding data. Derive data surface protection material based on the combined seed. Use the data surface protection material to perform pre-diffusion, global scrambling, and parallel sponge protection processing on the original image in sequence to generate ciphertext image and authentication tag. S4, the edge security gateway receives the encrypted image and the authentication tag, reconstructs the data plane protection material according to the authenticated device identity and the current session state, and recalculates the authentication tag. If the recalculated authentication tag is consistent with the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is rejected and an alarm and session refresh are triggered.

[0026] Furthermore, the implementation method is as follows: Figure 2 As shown, the system of this invention includes a visual edge terminal, an edge security gateway, a cloud control center, and downstream industrial application modules. The visual edge terminal is responsible for image acquisition, PUF identity recovery, zero-knowledge proof generation, image protection parameter derivation, and encrypted image generation; the edge security gateway is responsible for identity verification, session management, authentication tag recalculation, access control, denial alarms, and session refresh; the cloud control center is responsible for system parameter configuration, threshold share management, and audit management; and the downstream industrial application modules are responsible for business processing such as quality inspection, process monitoring, robot collaboration, and digital twins.

[0027] Furthermore, such as Figure 3 As shown, this invention employs a collaborative implementation approach combining a control plane and a data plane. The control plane handles device identity recovery, trusted access authentication, session seed generation, and session key material hosting; the data plane handles image content fingerprint extraction, protection material derivation, FWHT pre-diffusion, CRTcycle-walking global scrambling, tree path key generation, parallel sponge protection, and gateway-side authentication and access control. Through this design, this invention avoids repeatedly performing complex public-key operations in each image frame, while simultaneously binding the protected image to device identity, session context, and image content features.

[0028] Further, in step one, device registration, when a visual edge terminal first connects to the system, it submits its device identifier, device capability information, image acquisition parameters, supported security algorithms, and initial policy information to the cloud control center or edge security gateway. The cloud control center or edge security gateway records the terminal's public identity parameters, PUF challenge parameters, fuzzy extraction auxiliary data, session policy parameters, and image protection policy parameters.

[0029] In one implementation, the system parameters include at least group parameters, a hash function, a key derivation function, a threshold parameter, an image size, an authentication tag length, and a session refresh cycle. The group parameters include a large prime modulus. Group order parameters and generator The above parameters can be configured centrally by the cloud control center, or they can be distributed by the edge security gateway according to the industrial site policies.

[0030] Further, step two: PUF identity restoration. For example... Figure 4 As shown, the PUF reading module in the visual edge terminal reads the original SRAMPUF response during the registration phase and generates stable identity materials and publicly available auxiliary data through the fuzzy extraction module. During the operation phase, the terminal rereads the SRAMPUF response based on the challenge and combines it with the publicly available auxiliary data to recover the stable identity materials. This process can be summarized as follows:

[0031] in, This represents the raw SRAMPUF response read during the registration phase. This indicates a response that is reread during runtime. This indicates stable identity materials recovered from the PUF response. This indicates the public availability of auxiliary data. When the noise in the PUF response is within the error correction capability range, identity materials consistent with those in the registration phase can be recovered during the operational phase. In practice, the fuzzy extraction mechanism can employ methods such as majority voting with duplicate codes, BCH codes, Reed-Solomon codes, LDPC codes, or other error correction methods. Unlike traditional methods of long-term storage of static master keys, this invention utilizes the device's physically unclonable characteristics to recover identity materials during the operational phase, thereby reducing the risk of high-value keys being directly leaked after the visual edge terminal is physically captured.

[0032] Further, in step three, the device's private identity value and public identity parameters are generated. The visual edge terminal will then recover the obtained... Using the device identifier and registration context input key, a function is derived to generate the device's private identity value, and further, public identity parameters are generated:

[0033] in, Indicates equipment identification. Indicates the registration context. This represents the device's private identity value. This indicates that the identity parameters are public. Private identity values ​​can be stored at the edge security gateway or cloud control center during the registration phase. It will not be sent with the newspaper.

[0034] Further, step four involves zero-knowledge proof authentication. Before establishing a session, the visual edge terminal uses a private identity value... Generate a Schnorr-type non-interactive zero-knowledge proof. The terminal randomly selects a one-time random number. Calculate the commitment value Then, the challenge value is generated by combining the device identifier, timestamp, random number, session context, and policy identifier. And calculate the response value. This process can be represented as:

[0035] The terminal will prove the tuple Send to the edge security gateway. The edge security gateway then determines the identity parameters based on the publicly disclosed identity parameters. Reconstruct the commitment relationship and verify:

[0036] If the verification is successful, it indicates that the terminal possesses a private identity value corresponding to the public identity parameters, allowing entry into the session negotiation phase; if the verification fails, access is denied and an alarm is recorded. Figure 3 As shown, this step belongs to the zero-knowledge authentication phase in the overall process and is connected to the subsequent session seed negotiation phase.

[0037] Further, in step five, session seed negotiation and threshold management, after completing access authentication, the visual edge terminal and the edge security gateway negotiate and share a session secret, and further derive the current session seed:

[0038] in, Indicates sharing session secrets, This indicates a fixed-length session seed. This serves as the basis for deriving subsequent image protection parameters and changes with session refresh. To avoid storing critical session materials centrally on a single node, this invention employs the Shamir secret sharing mechanism. Threshold management is applied to its derivatives or similar materials. Let the threshold value be... The total number of shares is Construct a polynomial:

[0039] Different shares are hosted on edge security gateways, edge control nodes, or cloud control centers, respectively. When at least... When a legitimate share is involved, key materials for the session can be restored; less than [a certain percentage] The inability to recover the complete session secret when only one share is available reduces the risk of a single point of failure.

[0040] Further, step six involves image content fingerprint extraction and seed construction. The visual edge terminal acquires raw images from the industrial site. The image content fingerprint is then extracted. This content fingerprint can be obtained through image scaling, grayscale conversion, frequency domain transformation, low-frequency coefficient truncation, mean quantization, and binarization, and can be simply represented as follows:

[0041] in, Represents the frequency domain transform of an image. This indicates the extraction of low-frequency coefficients. This represents the mean of the low-frequency coefficients. This represents a binary quantization function. This represents the image content fingerprint. Subsequently, the terminal constructs a combined seed from the session seed, image content fingerprint, current frame random number, device binding information, and authentication context, and extends it to generate data plane protection material:

[0042] in, Represents the random number of the current frame. This represents bound data such as device identifier, zero-knowledge proof binding information, policy identifier, timestamp, or frame sequence number. The process involves segmentation to obtain the CRT scrambling seed, tree key material, sponge initialization parameters, and authentication tag generation parameters. Because... When participating in derivation, changes in image content will affect subsequent scrambling paths, tree path keys, sponge states, and authentication tags.

[0043] Further, in step seven, FWHT pre-diffusion, the visual edge terminal unfolds the input image into a one-dimensional sequence in row-major order. Then, perform a fast Walsh-Hadamard transform on it to obtain the pre-diffusion sequence:

[0044] like Figure 6 As shown, FWHT is implemented using a multi-level butterfly addition and subtraction network, mainly involving addition and subtraction operations, without requiring complex multiplication operations, making it suitable for deployment on resource-constrained edge terminals. This step can reduce the spatial correlation between pixels in plaintext images, providing a more uniform input distribution for subsequent global scrambling and sponge protection.

[0045] Further, step eight, CRT cycle-walking scrambling. The terminal generates a global scrambling index based on the derived CRT scrambling seed. In one implementation, for Image, target length can be set Choose coprime modulus and For the input index First, its remainder in the two modulus spaces is calculated, and then candidate indices are generated through two sub-scrambling rules and CRT reconstruction. This mapping can be summarized as follows:

[0046] in, and This represents the deterministic sub-scrambling rule generated from the scrambling seed. If a candidate index falls into an illegal region, the candidate value is re-entered into the mapping process for cycle-walking until a valid index is obtained. Finally, the scrambling mapping is used to rearrange the pre-diffused sequence.

[0047] like Figure 6 As shown, this step disrupts the image's positional structure while ensuring the reversibility of the scrambling. FWHT is responsible for pre-diffusion, and CRTcycle-walking is responsible for global positional perturbation. The two are connected in series to form a lightweight preprocessing procedure before the image enters the sponge's protective core.

[0048] Further, step nine, tree path key generation and nonlinear perturbation. The terminal constructs a complete binary tree key structure based on the tree key material. For the first... For each data block, determine its leaf node position, and aggregate along the path from the leaf node to the root node to obtain the path key:

[0049] in, Indicates the first Each data block corresponds to a set of paths from a leaf node to the root node. This represents the path node key. This path key enables location-dependent key differences between different data blocks. In practice, it can also be combined with the sponge state, the previous ciphertext block, and the block number to generate nonlinear perturbation parameters, thereby enhancing the dynamic diffusion capability during block-based parallel processing.

[0050] Further, step ten involves lightweight image preservation and tag generation using a parallel sponge structure. The terminal divides the scrambled sequence into several data blocks. For the first... Data blocks The ciphertext block is generated by combining the path key, nonlinear perturbation, feedback from the previous ciphertext, and sponge perturbation output:

[0051] in, Modulus addition, Indicates bitwise XOR, This represents the nonlinear perturbation parameter. Indicates the previous ciphertext block, This represents the perturbation output obtained by squeezing the current sponge state.

[0052] Furthermore, after all data blocks have been processed, a ciphertext sequence is obtained, and an authentication tag is generated from the final sponge state. For example... Figure 7As shown, this step generates ciphertext blocks and authentication tags by combining tree path keys, nonlinear perturbations, feedback from the previous ciphertext, and parallel sponge states. This allows image encryption and authentication tag generation to be completed in the same lightweight link, achieving joint protection of image confidentiality, integrity, source correlation, and content consistency.

[0053] Further, in step eleven, the protected image frame is encapsulated and transmitted. The visual edge terminal encapsulates the encrypted image, authentication tag, device identifier, session identifier, frame sequence number, current frame random number, and policy identifier into a protected image frame and transmits it to the edge security gateway. The protected image frame includes at least the device identifier, session identifier, frame sequence number, current frame random number, policy identifier, encrypted image data, and authentication tag. The device private identity value, PUF original response, PUF stable key, and session secret are not transmitted in plaintext with the image frame.

[0054] Further, step twelve involves verification and access decision-making at the edge security gateway. For example... Figure 5 As shown, after receiving a protected image frame, the edge security gateway does not directly forward it to the downstream industrial application module. Instead, the authentication module, session management module, derivation reconstruction module, and authentication tag recalculation module jointly complete the gateway-side verification. The edge security gateway reconstructs the data plane protection material based on the authenticated device identity, current session state, random number, frame sequence number, policy identifier, and content binding rules, and recalculates the authentication tag on the received ciphertext. Then, it compares the received tag with the recalculated tag.

[0055] If both conditions are met, the frame is considered to satisfy conditions such as a trustworthy device source, consistent session context, valid image content binding, and consistent data plane protection path. The edge security gateway then allows it to enter the deprotection process and downstream business domain. After successful verification, the gateway performs parallel sponge deprotection, CRT inverse scrambling, and inverse FWHT transformation to restore the image data and input it into industrial application modules such as quality inspection, process monitoring, robot collaboration, or digital twins.

[0056] If the two are inconsistent, it indicates that the frame may contain risks such as unauthorized terminal forgery, historical frame replay, encrypted text tampering, content replacement, session mismatch, or inconsistent policies. Figure 8 As shown, the edge security gateway marks the frame as an untrusted object, refuses to enter the business domain, and triggers an alarm, audit log recording, session refresh, or renegotiation process.

[0057] The embodiments of this invention also have the following technical effects: Reducing the risk of static key leakage at edge terminals. This invention utilizes SRAMPUF to recover device-related identity materials at runtime, eliminating the need for visual edge terminals to store high-value static master keys long-term, thus reducing the risk of direct key leakage after physical capture of the terminal. Achieving zero-trust trusted access. Through non-interactive zero-knowledge proofs, terminals can prove legitimacy to the edge security gateway without exposing private identity values, making the system conform to the zero-trust principle of "never defaulting to trust, always explicitly verifying." Improving the resistance to single-point-of-failure for key session materials. By using Shamir secret sharing to threshold-manage session seeds or key derived materials, key materials can be avoided from being centrally stored in a single gateway or a single terminal node, thereby improving authentication resilience in distributed industrial networks. Enhancing resistance to historical image replay and content replacement. This invention embeds the perceptual hash content fingerprint into the key derivation and state update process beforehand, allowing changes in image content to directly affect the scrambling seed, path key, and authentication tag, unlike methods that only detect content similarity after the fact at the receiving end. Balancing image confidentiality, integrity, and source correlation. This invention generates ciphertext and authentication tags within the same lightweight processing link through FWHT pre-diffusion, CRT global scrambling, tree path keys, and a parallel sponge protection core, tightly integrating image content protection and verification processes. It is suitable for high-frequency edge image streams. This invention limits the relatively heavy authentication and threshold management to the control plane or session stage, designing the data plane as a parallel, low-overhead, lightweight protection process, suitable for resource-constrained edge vision terminals and low-latency industrial applications. It enhances gateway-side access control capabilities. After receiving ciphertext frames, the edge security gateway first performs derivation reconstruction and tag verification. Only after successful verification is data allowed to enter the downstream service domain; if verification fails, it rejects, alarms, audits, and refreshes the session, preventing untrusted images from affecting the industrial control closed loop.

[0058] To achieve the above embodiments, such as Figure 9 As shown, this embodiment also provides a zero-trust lightweight protection device 10 for edge images in the Industrial Internet of Things, including: The terminal identity self-generation module 100 is used to recover device identity materials based on the physical non-clonable features of the visual edge terminal, and generate device private identity values ​​and public identity parameters according to the device identity materials. The zero-knowledge identity authentication and seed hosting module 200 is used to generate a non-interactive zero-knowledge proof based on the device's private identity value, send the zero-knowledge proof to the edge security gateway for identity verification, negotiate a session seed after successful verification, and host the session seed with a threshold. The image ciphertext derivation encryption module 300 is used to acquire original images from industrial sites and extract image content fingerprints. It constructs a combined seed by combining the session seed, the image content fingerprint, and the current frame binding data. Based on the combined seed, it derives a data surface protection material and uses the data surface protection material to sequentially perform pre-diffusion, global scrambling, and parallel sponge protection processing on the original image to generate a ciphertext image and an authentication tag. The gateway verification and authentication alarm module 400 is used by the edge security gateway to receive the encrypted image and the authentication tag, reconstruct the data plane protection material according to the authenticated device identity and the current session state, and recalculate the authentication tag. If the recalculated authentication tag is consistent with the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is rejected and an alarm and session refresh are triggered.

[0059] This invention provides a zero-trust lightweight protection device for edge images in the Industrial Internet of Things (IIoT), which can reduce the risk of static key leakage, achieve zero-trust trusted access, improve resistance to single point of failure, and enhance resistance to replay and content replacement.

[0060] To implement the methods of the above embodiments, the present invention also provides a computer device, such as... Figure 10 As shown, the computer device 600 includes a memory 601 and a processor 602; wherein, the processor 602 reads executable program code stored in the memory 601 to run a program corresponding to the executable program code, so as to implement the various steps of the method described above.

[0061] To implement the above embodiments, this application also proposes a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the method described in the foregoing embodiments.

[0062] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0063] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

Claims

1. A zero-trust lightweight protection method for edge images in the Industrial Internet of Things, characterized in that, include: S1, recover device identity material based on the physical non-clonable features of the visual edge terminal, and generate device private identity value and public identity parameters based on the device identity material; S2, generate a non-interactive zero-knowledge proof based on the device's private identity value, and send the zero-knowledge proof to the edge security gateway for identity verification. After successful verification, negotiate a session seed and perform threshold management on the session seed. S3. Collect original images of the industrial site and extract image content fingerprints. Construct a combined seed by combining the session seed, the image content fingerprint, and the current frame binding data. Derive data surface protection material based on the combined seed. Use the data surface protection material to perform pre-diffusion, global scrambling, and parallel sponge protection processing on the original image in sequence to generate ciphertext image and authentication tag. S4, the edge security gateway receives the encrypted image and the authentication tag, reconstructs the data plane protection material according to the authenticated device identity and the current session state, and recalculates the authentication tag. If the recalculated authentication tag is consistent with the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is rejected and an alarm and session refresh are triggered.

2. The method as described in claim 1, characterized in that, S1 includes: Read the SRAM PUF response and generate stable identity materials through fuzzy extraction; The stable identity material, along with the device identifier and registration context, is input into a key derivation function to generate a device private identity value, and public identity parameters are calculated.

3. The method as described in claim 2, characterized in that, The method further includes: During the registration phase, the original SRAM PUF response is read, and stable identity materials and publicly available auxiliary data are generated through the Gen function; During the runtime phase, the response is reread based on the challenge, and stable identity materials are restored through the Rep function in conjunction with publicly available auxiliary data.

4. The method as described in claim 1, characterized in that, S2 includes: A non-interactive zero-knowledge proof is generated based on the device's private identity value, and the zero-knowledge proof is sent to the edge security gateway for authentication. After successful verification, a session seed is negotiated, and the session seed is then managed with a threshold.

5. The method as described in claim 4, characterized in that, The method further includes: The terminal randomly selects a one-time random number, calculates the commitment value, and generates a challenge value by combining the device identifier, timestamp, random number, session context, and policy identifier. It then calculates the response value to form a proof tuple. The edge security gateway reconstructs and verifies the commitment relationship based on the public identity parameters. The terminal and the edge security gateway negotiate and share a session secret, and derive a session seed; the shared session secret is threshold-managed using Shamir secret sharing, a polynomial is constructed, and the share is respectively managed by the edge security gateway, the edge control node, or the cloud control center.

6. The method as described in claim 1, characterized in that, The S3 includes: Collect raw images of the industrial site and extract fingerprints from the image content; The session seed, the image content fingerprint, and the current frame binding data are constructed into a combined seed, and data surface protection material is derived based on the combined seed; The original image is pre-diffused using the data surface protection material; Global scrambling is performed on the pre-diffused image; The scrambled image is subjected to parallel sponge protection processing to generate a ciphertext image and authentication tag.

7. The method as described in claim 1, characterized in that, The S4 includes: The edge security gateway receives the encrypted image and the authentication tag, reconstructs the data plane protection material and recalculates the authentication tag based on the authenticated device identity and the current session state; If the recalculated authentication tag matches the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is denied and an alarm and session refresh are triggered.

8. A zero-trust lightweight protection device for edge images in the Industrial Internet of Things, characterized in that, include: The terminal identity self-generation module is used to recover device identity materials based on the physical unclonable features of the visual edge terminal, and generate device private identity values ​​and public identity parameters according to the device identity materials. The zero-knowledge identity authentication and seed hosting module is used to generate a non-interactive zero-knowledge proof based on the device's private identity value, send the zero-knowledge proof to the edge security gateway for identity verification, negotiate a session seed after successful verification, and perform threshold hosting on the session seed. The image ciphertext derivation encryption module is used to acquire original images from industrial sites and extract image content fingerprints. It constructs a combined seed by combining the session seed, the image content fingerprint, and the current frame binding data. Based on the combined seed, it derives a data surface protection material and uses the data surface protection material to sequentially perform pre-diffusion, global scrambling, and parallel sponge protection processing on the original image to generate a ciphertext image and an authentication tag. The gateway verification and authentication alarm module is used by the edge security gateway to receive the encrypted image and the authentication tag, reconstruct the data plane protection material according to the authenticated device identity and the current session state, and recalculate the authentication tag. If the recalculated authentication tag is consistent with the received authentication tag, the encrypted image is allowed to enter the deprotection process and downstream service domain; otherwise, access is rejected and an alarm and session refresh are triggered.

9. A computer device, characterized in that, Including processor and memory; The processor reads executable program code stored in the memory to run a program corresponding to the executable program code, so as to implement the method as described in any one of claims 1-7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-7.