To address the problem of insufficient security of public data caused by its characteristics of wide sources, large information volume, and high sensitivity, as well as the vulnerability of one-way authentication networks to various attacks, an optimized public data security algorithm applying a lightweight mutual authentication protocol was proposed. A lightweight mutual authentication protocol was obtained by combining Physical Unclonable Functions (PUF) with synchronized random numbers in this algorithm, which reduces the computational and communication overheads during the optimization process. The credibility of user readers during protocol access was authenticated through trusted network connections. Synchronized random numbers were deployed at both ends of user readers and public data electronic tags, and PUF was integrated into the public data electronic tags to enhance the resistance of keys in massive public data electronic tags against various attacks. Thus, mutual identity authentication between user readers and public data electronic tags was completed, and secure optimized protection of sensitive data was achieved. The research results show that the algorithm can effectively resist 10 types of attacks, including de synchronization attacks, cloning attacks, and man in the middle attacks, during the storage and transmission of public data, and has low latency, which can ensure the security of public data.
目前,已有部分国内外学者针对该领域展开相关研究。例如,吴万青等[7]提出的数据安全存储和发布方法,以数据时空特征为依据,建立数据轨迹等价类别,结合Hilbert曲线划分建立的数据轨迹点,通过聚类所得轨迹中心点得到全新数据轨迹,实现数据空间简化。随后,创建数据前缀树并输入全新数据轨迹,采用等差隐私预算分配法将噪声数据点添加至前缀树中,以提升数据安全性。该方法通过合理的噪声添加和数据扰动处理,在保护隐私的同时,保持了数据的可用性和准确性。但采用等差隐私预算分配法时需要向数据中添加噪声,而噪声的大小和分布计算涉及复杂的数学运算和统计分析,这导致计算复杂度较高、数据处理时间较长,不利于数据安全防护的时效性。赵骏等[8]提出的物联网数据存储和共享方法,通过创建区块链与IOTA双账本,并结合委托权益证明(Delegated proof of stake,DPoS)算法,有效应对物联网数据存储和传输过程中的恶意节点攻击问题,保证数据的安全性。该方法的双账本结构使不同主体间的数据共享变得更加便捷。但双账本结构和区块链技术的引入,使整个方法的运算复杂度显著增加,尤其在针对海量数据的安全防护时,整体效率不佳。Li等[9]提出了金融数据安全存储和访问控制方法,通过创建基于属性的访问控制模型,并结合区块链智能合约,实现金融数据的细粒度访问控制。该方法借助区块链技术的分布式账本和加密算法,确保数据的不可篡改性和完整性,但存在隐私泄露的风险,特别是在公共区块链上,交易信息对所有参与者可见,会降低数据整体的安全性。万征等[10]提出的大健康数据存储和共享模型,以区块联盟链为依据创建双链网络模型,实现大健康数据密文与跨域访问记录的安全存储;同时结合代理重加密算法,重加密数据的跨域记录,保障数据共享的安全性。该模型的区块链共识机制可确保网络节点对数据的正确性达成一致,避免数据冗余和误差,提高数据的一致性和可信度。虽然区块链技术可以提供一定的数据隐私保护,但在数据脱敏不彻底或智能合约设计存在漏洞时,仍可能导致隐私数据泄露。
LiuHai-ou, ZhouYing-yu, WangHai-ying. Research on open sharing model of government data of public health emergencies based on blockchain[J].Modern Information, 2022, 42(10): 79-89.
ZhangLi-hua, CaoYu, ZhangGan-zhe, et al. Microgrid data security storage and deletion verification scheme based on blockchain[J].Computer Engineering and Design, 2023, 44(4): 967-976.
KongQing-yang, HeLe-sheng, JinHao-nan, et al. Design and implementation of security transmission mechanism of Internet of Things data for physical measurement equipment[J].Computer Application, 2022, 42(Sup.2): 180-185.
SuYan-xia, WangQing-sheng, ChenYong-le. Secure sharing of data in cloud storage based on data segmentation[J].Computer Engineering and Design, 2021, 42(10): 2742-2747.
ChengShun-da. Cloud data storage and access algorithm based on security verification[J].Journal of Shenyang University of Technology, 2023, 45(5): 565-570.
KangHai-yan, DengJie. Enhanced hybrid encryption for secure storage of medical data[J].Journal of Beijing Institute of Technology, 2021, 41(10): 1058-1068.
WuWan-qing, ZhaoYong-xin, WangQiao, et al. A method for safe storage and publication of trajectory data that satisfies differential privacy[J].Computer Research and Development, 2021, 58(11): 2430-2443.
ZhaoJun, DaiHuan, TangYi, et al. Internet of things data storage and sharing method based on double ledger[J]. Computer Engineering and Design, 2023, 44(11): 3276-3282.
[17]
LiD, HanD Z, CrespiN, et al. A blockchain-based secure storage and access control scheme for supply chain finance[J]. Journal of Supercomputing,2023, 79(1): 109-138.
ChenFei-hong, ZhangFeng, ChenJun-ning, et al. Lightweight RFID authentication protocol based on RRAM PUF[J].Computer Engineering and Applications, 2021, 57(1): 141-149.
GuoYi-min, ZhangZhen-feng, XiongPing, et al. Lightweight fog assisted iot authentication protocol based on PUF[J]. Journal of Computer Science, 2022, 45(7): 1412-1430.