近年来,物联网发展迅猛并得到广泛应用,在商品物流中的应用尤为突出。但其在传输的安全性及隐私的保护性方面存在不足,一定程度上限制了物联网的发展。文章基于ECC中的双线性函数和可信计算提出了一种可控可信匿名的物联网ONS查询机制(CTA-ONS),并且设计了ONS查询服务的安全协议。CTA—ONS在传统物联网ONS查询中加入可信以及匿名认证的过程,实现了只对授权可信的L—ONS提供查询服务,避免了证书查询机制中L—ONS证书有效期内受到攻击或被恶意节点控制而遭受网络地址的重放、篡改和窃听,加入对R—ONS的可信验证保证了R—ONS的安全可信,从而为查询提供合法可信的网络地址。分析表明该模型具有匿名性、安全性、可控性和可信性等特点。
In recent years, Internet of Things is developing rapidly and widely used, especially in the commodity logistics. But the development of Interact of Things was restricted due to the insufficiency of privacy protection and security transmission. So proposed an enquiry mechanism of IOT, Controllable Trusted Anonymous Object Naming Service (CTA-ONS) with trusted computing technology and bilin- ear function in ECC. It designed a security architecture and security protocols in the ONS query mechanism and added reliable and anonymous authentication process. CTA-ONS, only provided enquiry services to authorized L-ONS, avoided L-ONS controlled by malicious node which made network address subject to replay, tampering and eavesdropping within the validity period of certificate in the L-ONS query mechanism. In addition,it prevented R-ONS from taking attack and providing illegal network address by adding reliable authentication. The analysis shows that this model is safe, anonymous, trusted and controllable.