In this paper,we focus on providing data provenance auditing schemes for distributed denial of service(DDoS)defense in intelligent internet of things(IoT).To achieve effective DDoS defense,we introduce a two-layer col...In this paper,we focus on providing data provenance auditing schemes for distributed denial of service(DDoS)defense in intelligent internet of things(IoT).To achieve effective DDoS defense,we introduce a two-layer collaborative blockchain framework to support data auditing.Specifically,using data scattered among intelligent IoT devices,switch gateways self-assemble a layer of blockchain in the local autonomous system(AS),and the main chain with controller participation can be aggregated by its associated layer of blocks once a cycle,to obtain a global security model.To optimize the processing delay of the security model,we propose a process of data pre-validation with the goal of ensuring data consistency while satisfying overhead requirements.Since the flood of identity spoofing packets,it is difficult to solve the identity consistency of data with traditional detection methods,and accountability cannot be pursued afterwards.Thus,we proposed a Packet Traceback Telemetry(PTT)scheme,based on in-band telemetry,to solve the problem.Specifically,the PTT scheme is executed on the distributed switch side,the controller to schedule and select routing policies.Moreover,a tracing probabilistic optimization is embedded into the PTT scheme to accelerate path reconstruction and save device resources.Simulation results show that the PTT scheme can reconstruct address spoofing packet forward path,reduce the resource consumption compared with existing tracing scheme.Data tracing audit method has fine-grained detection and feasible performance.展开更多
Federated learning is an important distributed model training technique in Internet of Things(IoT),in which participant selection is a key component that plays a role in improving training efficiency and model accurac...Federated learning is an important distributed model training technique in Internet of Things(IoT),in which participant selection is a key component that plays a role in improving training efficiency and model accuracy.This module enables a central server to select a subset of participants to performmodel training based on data and device information.By doing so,selected participants are rewarded and actively perform model training,while participants that are detrimental to training efficiency and model accuracy are excluded.However,in practice,participants may suspect that the central server may have miscalculated and thus not made the selection honestly.This lack of trustworthiness problem,which can demotivate participants,has received little attention.Another problem that has received little attention is the leakage of participants’private information during the selection process.We will therefore propose a federated learning framework with auditable participant selection.It supports smart contracts in selecting a set of suitable participants based on their training loss without compromising the privacy.Considering the possibility of malicious campaigning and impersonation of participants,the framework employs commitment schemes and zero-knowledge proofs to counteract these malicious behaviors.Finally,we analyze the security of the framework and conduct a series of experiments to demonstrate that the framework can effectively improve the efficiency of federated learning.展开更多
The exponential growth of the Internet of Things(IoT)has revolutionized various domains such as healthcare,smart cities,and agriculture,generating vast volumes of data that require secure processing and storage in clo...The exponential growth of the Internet of Things(IoT)has revolutionized various domains such as healthcare,smart cities,and agriculture,generating vast volumes of data that require secure processing and storage in cloud environments.However,reliance on cloud infrastructure raises critical security challenges,particularly regarding data integrity.While existing cryptographic methods provide robust integrity verification,they impose significant computational and energy overheads on resource-constrained IoT devices,limiting their applicability in large-scale,real-time scenarios.To address these challenges,we propose the Cognitive-Based Integrity Verification Model(C-BIVM),which leverages Belief-Desire-Intention(BDI)cognitive intelligence and algebraic signatures to enable lightweight,efficient,and scalable data integrity verification.The model incorporates batch auditing,reducing resource consumption in large-scale IoT environments by approximately 35%,while achieving an accuracy of over 99.2%in detecting data corruption.C-BIVM dynamically adapts integrity checks based on real-time conditions,optimizing resource utilization by minimizing redundant operations by more than 30%.Furthermore,blind verification techniques safeguard sensitive IoT data,ensuring privacy compliance by preventing unauthorized access during integrity checks.Extensive experimental evaluations demonstrate that C-BIVM reduces computation time for integrity checks by up to 40%compared to traditional bilinear pairing-based methods,making it particularly suitable for IoT-driven applications in smart cities,healthcare,and beyond.These results underscore the effectiveness of C-BIVM in delivering a secure,scalable,and resource-efficient solution tailored to the evolving needs of IoT ecosystems.展开更多
针对配电网调度设备状态监测对实时性、可靠性、全覆盖性及经济性的要求,研究窄带物联网(NarrowBand Internet of Things,NB-IoT)、远距离无线电(Long Range Radio,LoRa)、5G网络切片3种物联网通信技术的应用方案,建立数据传输可靠性、...针对配电网调度设备状态监测对实时性、可靠性、全覆盖性及经济性的要求,研究窄带物联网(NarrowBand Internet of Things,NB-IoT)、远距离无线电(Long Range Radio,LoRa)、5G网络切片3种物联网通信技术的应用方案,建立数据传输可靠性、通信链路预算和端到端时延的数学模型。实验结果表明,NB-IoT方案可靠性高且功耗低,LoRa方案通信覆盖范围大,5G网络切片方案时延最低。基于各技术的场景适应性特征,提出差异化混合组网部署策略,为配电网智能化改造提供技术支撑。展开更多
窄带物联网(narrowband Internet of things, NB-IoT)是互联网中的一个重要分支.NB-IoT依托云计算强大的资源处理能力提供应用层的各项服务以及实现信息智能化.然而由于数据异地存储,云平台服务提供商并不完全可信,用户数据暴露在不完...窄带物联网(narrowband Internet of things, NB-IoT)是互联网中的一个重要分支.NB-IoT依托云计算强大的资源处理能力提供应用层的各项服务以及实现信息智能化.然而由于数据异地存储,云平台服务提供商并不完全可信,用户数据暴露在不完全安全的环境下,带来了诸多安全问题,比如被外部用户恶意攻击、云服务器共谋攻击等.针对NB-IoT终端节点极易受到攻击、资源不足、功耗受限等问题,提出一种基于属性的云存储快速访问控制方案.在多个属性授权机构的背景下,以高效可验证的轻量级加密方案为目标,借鉴在线/离线加密思想,并结合外包解密技术,构造了具备选择明文攻击(chosen-plaintext attack, CPA)安全的在线/离线加密和外包解密的多机构密文策略属性基加密方案(online/offline and outsourced multi-authority ciphertext-policy attribute-based encryptin scheme, OO-MA-CP-ABE),提高加解密算法效率的同时最小化用户的计算开销,很适合计算能力弱且资源受限的终端设备.并进一步通过验证算法确保外包计算的正确性.还给出了云计算环境下轻量级NB-IoT应用系统安全性分析,保证资源共享过程中,灵活可扩展的访问控制策略以及用户数据的机密性和隐私保护.最后,给出了OO-MA-CP-ABE方案的性能分析,从功能性、计算开销和通信开销3个方面同现有方案进行比较.展开更多
With the recent introduction of NarrowBand Internet of Things(NB-IoT)technology in the 4th and 5th generations of mobile radio networks,the mobile communications context opens up significantly to the world of sensors....With the recent introduction of NarrowBand Internet of Things(NB-IoT)technology in the 4th and 5th generations of mobile radio networks,the mobile communications context opens up significantly to the world of sensors.By means of NB-IoT,the mobile systems within 3GPP standardization introduce the peculiar functions of sensor networks,thus making it possible to satisfy very specific requirements with respect to those which characterize traditional mobile telecommunications.Among the functions of interest for sensor networks,the possibility of locating the positions of the sensors without an increase in costs and energy consumption of the sensor nodes is of utmost interest.The present work describes a procedure for locating the NB-IoT nodes based on the quality of radio signals received by the mobile terminals,which therefore does not require further hardware implementations on board the nodes.This procedure,based on the RF fingerprinting technique and on machine learning processing,has been tested experimentally and has achieved interesting performances.展开更多
窄带物联网(NarrowBand Internet of Things,NB-IoT)是实现万物互联重要的通信技术,其为了扩大通信覆盖范围和提高可靠性而牺牲了时延等性能指标,且难以动态适应移动物联网设备.对此,本文提出了一种适用于移动设备的NB-IoT无线电资源配...窄带物联网(NarrowBand Internet of Things,NB-IoT)是实现万物互联重要的通信技术,其为了扩大通信覆盖范围和提高可靠性而牺牲了时延等性能指标,且难以动态适应移动物联网设备.对此,本文提出了一种适用于移动设备的NB-IoT无线电资源配置方案.该方案通过卡尔曼滤波对物联网设备的移动位置进行预测,建立数学模型对通信可靠性进行估计,开展了块误码率、时延、能耗等性能指标的量化分析,并提出了无线电资源配置的优化模型和方法.本文基于真实数据集开展了仿真实验,对该方案的有效性进行了验证,实验结果显示该方案能保证移动物联网设备与基站连接的同时降低时延.展开更多
与传统土壤栽培相比,水培可以使作物更快生长并减少虫害。由于作物持续从营养液中吸收养分,需要对水培营养液的水质参数进行及时和准确地监测并根据需要补充养分。本文针对水培生菜生长过程,设计并试验一个基于窄带物联网(Narrowband In...与传统土壤栽培相比,水培可以使作物更快生长并减少虫害。由于作物持续从营养液中吸收养分,需要对水培营养液的水质参数进行及时和准确地监测并根据需要补充养分。本文针对水培生菜生长过程,设计并试验一个基于窄带物联网(Narrowband Internet of Things, NB-IoT)的水培智能监控系统,通过微信公众号的用户界面实时监测水培环境参数,结合模糊控制方法,根据操作经验及作物需求调节营养液水质参数。由试验结果可知,本系统数据通信平均丢包率为0.76%;对初始pH值为7.3,电导率为1.2 mS/cm的营养液进行调控时,pH值和电导率分别在第68 s和第63 s后保持稳定的预设值;智能监控系统可以在作物生长周期内将营养液水质参数稳定维持在有利于作物生长的范围内。展开更多
基金supported by the Fundamental Research Funds under Grant 2021JBZD204 and 2022RC006in part by the National Natural Science Foundation of China under Grant 62201029in part by the China Postdoctoral Science Foundation under Grant Grant BX20220029 and 2022M710007.
摘要In this paper,we focus on providing data provenance auditing schemes for distributed denial of service(DDoS)defense in intelligent internet of things(IoT).To achieve effective DDoS defense,we introduce a two-layer collaborative blockchain framework to support data auditing.Specifically,using data scattered among intelligent IoT devices,switch gateways self-assemble a layer of blockchain in the local autonomous system(AS),and the main chain with controller participation can be aggregated by its associated layer of blocks once a cycle,to obtain a global security model.To optimize the processing delay of the security model,we propose a process of data pre-validation with the goal of ensuring data consistency while satisfying overhead requirements.Since the flood of identity spoofing packets,it is difficult to solve the identity consistency of data with traditional detection methods,and accountability cannot be pursued afterwards.Thus,we proposed a Packet Traceback Telemetry(PTT)scheme,based on in-band telemetry,to solve the problem.Specifically,the PTT scheme is executed on the distributed switch side,the controller to schedule and select routing policies.Moreover,a tracing probabilistic optimization is embedded into the PTT scheme to accelerate path reconstruction and save device resources.Simulation results show that the PTT scheme can reconstruct address spoofing packet forward path,reduce the resource consumption compared with existing tracing scheme.Data tracing audit method has fine-grained detection and feasible performance.
基金supported by the Key-Area Research and Development Program of Guangdong Province under Grant No.2020B0101090004the National Natural Science Foundation of China under Grant No.62072215,the Guangzhou Basic Research Plan City-School Joint Funding Project under Grant No.2024A03J0405+1 种基金the Guangzhou Basic and Applied Basic Research Foundation under Grant No.2024A04J3458the State Archives Administration Science and Technology Program Plan of China under Grant 2023-X-028.
摘要Federated learning is an important distributed model training technique in Internet of Things(IoT),in which participant selection is a key component that plays a role in improving training efficiency and model accuracy.This module enables a central server to select a subset of participants to performmodel training based on data and device information.By doing so,selected participants are rewarded and actively perform model training,while participants that are detrimental to training efficiency and model accuracy are excluded.However,in practice,participants may suspect that the central server may have miscalculated and thus not made the selection honestly.This lack of trustworthiness problem,which can demotivate participants,has received little attention.Another problem that has received little attention is the leakage of participants’private information during the selection process.We will therefore propose a federated learning framework with auditable participant selection.It supports smart contracts in selecting a set of suitable participants based on their training loss without compromising the privacy.Considering the possibility of malicious campaigning and impersonation of participants,the framework employs commitment schemes and zero-knowledge proofs to counteract these malicious behaviors.Finally,we analyze the security of the framework and conduct a series of experiments to demonstrate that the framework can effectively improve the efficiency of federated learning.
基金supported by King Saud University,Riyadh,Saudi Arabia,through Researchers Supporting Project number RSP2025R498.
摘要The exponential growth of the Internet of Things(IoT)has revolutionized various domains such as healthcare,smart cities,and agriculture,generating vast volumes of data that require secure processing and storage in cloud environments.However,reliance on cloud infrastructure raises critical security challenges,particularly regarding data integrity.While existing cryptographic methods provide robust integrity verification,they impose significant computational and energy overheads on resource-constrained IoT devices,limiting their applicability in large-scale,real-time scenarios.To address these challenges,we propose the Cognitive-Based Integrity Verification Model(C-BIVM),which leverages Belief-Desire-Intention(BDI)cognitive intelligence and algebraic signatures to enable lightweight,efficient,and scalable data integrity verification.The model incorporates batch auditing,reducing resource consumption in large-scale IoT environments by approximately 35%,while achieving an accuracy of over 99.2%in detecting data corruption.C-BIVM dynamically adapts integrity checks based on real-time conditions,optimizing resource utilization by minimizing redundant operations by more than 30%.Furthermore,blind verification techniques safeguard sensitive IoT data,ensuring privacy compliance by preventing unauthorized access during integrity checks.Extensive experimental evaluations demonstrate that C-BIVM reduces computation time for integrity checks by up to 40%compared to traditional bilinear pairing-based methods,making it particularly suitable for IoT-driven applications in smart cities,healthcare,and beyond.These results underscore the effectiveness of C-BIVM in delivering a secure,scalable,and resource-efficient solution tailored to the evolving needs of IoT ecosystems.
摘要针对配电网调度设备状态监测对实时性、可靠性、全覆盖性及经济性的要求,研究窄带物联网(NarrowBand Internet of Things,NB-IoT)、远距离无线电(Long Range Radio,LoRa)、5G网络切片3种物联网通信技术的应用方案,建立数据传输可靠性、通信链路预算和端到端时延的数学模型。实验结果表明,NB-IoT方案可靠性高且功耗低,LoRa方案通信覆盖范围大,5G网络切片方案时延最低。基于各技术的场景适应性特征,提出差异化混合组网部署策略,为配电网智能化改造提供技术支撑。
摘要窄带物联网(narrowband Internet of things, NB-IoT)是互联网中的一个重要分支.NB-IoT依托云计算强大的资源处理能力提供应用层的各项服务以及实现信息智能化.然而由于数据异地存储,云平台服务提供商并不完全可信,用户数据暴露在不完全安全的环境下,带来了诸多安全问题,比如被外部用户恶意攻击、云服务器共谋攻击等.针对NB-IoT终端节点极易受到攻击、资源不足、功耗受限等问题,提出一种基于属性的云存储快速访问控制方案.在多个属性授权机构的背景下,以高效可验证的轻量级加密方案为目标,借鉴在线/离线加密思想,并结合外包解密技术,构造了具备选择明文攻击(chosen-plaintext attack, CPA)安全的在线/离线加密和外包解密的多机构密文策略属性基加密方案(online/offline and outsourced multi-authority ciphertext-policy attribute-based encryptin scheme, OO-MA-CP-ABE),提高加解密算法效率的同时最小化用户的计算开销,很适合计算能力弱且资源受限的终端设备.并进一步通过验证算法确保外包计算的正确性.还给出了云计算环境下轻量级NB-IoT应用系统安全性分析,保证资源共享过程中,灵活可扩展的访问控制策略以及用户数据的机密性和隐私保护.最后,给出了OO-MA-CP-ABE方案的性能分析,从功能性、计算开销和通信开销3个方面同现有方案进行比较.
摘要With the recent introduction of NarrowBand Internet of Things(NB-IoT)technology in the 4th and 5th generations of mobile radio networks,the mobile communications context opens up significantly to the world of sensors.By means of NB-IoT,the mobile systems within 3GPP standardization introduce the peculiar functions of sensor networks,thus making it possible to satisfy very specific requirements with respect to those which characterize traditional mobile telecommunications.Among the functions of interest for sensor networks,the possibility of locating the positions of the sensors without an increase in costs and energy consumption of the sensor nodes is of utmost interest.The present work describes a procedure for locating the NB-IoT nodes based on the quality of radio signals received by the mobile terminals,which therefore does not require further hardware implementations on board the nodes.This procedure,based on the RF fingerprinting technique and on machine learning processing,has been tested experimentally and has achieved interesting performances.
摘要窄带物联网(NarrowBand Internet of Things,NB-IoT)是实现万物互联重要的通信技术,其为了扩大通信覆盖范围和提高可靠性而牺牲了时延等性能指标,且难以动态适应移动物联网设备.对此,本文提出了一种适用于移动设备的NB-IoT无线电资源配置方案.该方案通过卡尔曼滤波对物联网设备的移动位置进行预测,建立数学模型对通信可靠性进行估计,开展了块误码率、时延、能耗等性能指标的量化分析,并提出了无线电资源配置的优化模型和方法.本文基于真实数据集开展了仿真实验,对该方案的有效性进行了验证,实验结果显示该方案能保证移动物联网设备与基站连接的同时降低时延.
摘要与传统土壤栽培相比,水培可以使作物更快生长并减少虫害。由于作物持续从营养液中吸收养分,需要对水培营养液的水质参数进行及时和准确地监测并根据需要补充养分。本文针对水培生菜生长过程,设计并试验一个基于窄带物联网(Narrowband Internet of Things, NB-IoT)的水培智能监控系统,通过微信公众号的用户界面实时监测水培环境参数,结合模糊控制方法,根据操作经验及作物需求调节营养液水质参数。由试验结果可知,本系统数据通信平均丢包率为0.76%;对初始pH值为7.3,电导率为1.2 mS/cm的营养液进行调控时,pH值和电导率分别在第68 s和第63 s后保持稳定的预设值;智能监控系统可以在作物生长周期内将营养液水质参数稳定维持在有利于作物生长的范围内。