Internet equipment access authentication method for network security

By combining device type, historical access data and traffic data, establishing a baseline of equipment behavior and evaluating risk levels, and quickly screening low-risk equipment, the problem of too long verification time during temporary equipment access is solved, and the balance between safety and efficiency is achieved.

CN120200840AActive Publication Date: 2025-06-24JIANGSU YUEDA NETWORK TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510571468.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-06-24
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

In the prior art, when temporary equipment is connected to enterprise networks, the access authentication method with high security leads to too long verification time, especially during the peak period of enterprise business, resulting in inefficient access efficiency and service delays.

Method used

By obtaining the type of equipment, historical access data and traffic data, establishing a baseline of equipment behavior, calculating the access location deviation value, access time deviation value and traffic deviation value, comprehensively assessing the risk level of the equipment, quickly screening out low-risk equipment, reducing strict verification of high-risk equipment, and determining the best access authentication method.

Benefits of technology

It significantly shortens the overall access authentication time, improves the efficiency of device access, reduces service delays caused by long-term verification, improves overall service processing efficiency, and ensures network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200840A_ABST
    Figure CN120200840A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of equipment access authentication, and particularly discloses an internet equipment access authentication method for network security, which comprises the following steps of: S1, acquiring the type of equipment to be accessed, associating historical access data of the equipment to be accessed with historical flow data of equipment of the same type, and establishing an equipment behavior baseline; s2, comparing the difference between the current access place and time of the equipment and the historical distribution map in combination with the geographic position of the enterprise, and calculating an access place deviation value and an access time deviation value; based on the historical flow fluctuation rule of the similar equipment, evaluating the deviation between the current flow and the expectation, and generating a flow deviation value; s3, calculating a comprehensive risk value by integrating the three deviation values, and matching an authentication strategy according to a risk level; balance between safety and efficiency is achieved by quantifying behavior abnormity, and the method is suitable for mass equipment scenes such as the Internet of Things.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of device access authentication, and particularly to an Internet device access authentication method for network security. Background Art

[0002] In the current era of rapid digital development, the business operations of enterprises highly rely on various information technologies and network systems. In the complex process of daily business execution in enterprises, the link of temporary device login is often inevitably involved. Here, the temporary devices cover various types, such as mobile office devices used by employees due to temporary work needs, devices temporarily accessed by partners to the enterprise internal system for specific projects, and other external devices that need to be urgently used in some special business scenarios, etc.

[0003] However, the access of these temporary devices often has relatively large security risks. Due to the wide and uncertain sources of temporary devices, the network environments they are in may also be relatively complex and may lack the basic security protection measures required by the enterprise internal system. For example, some temporary devices may not install the latest security patches, or their operating systems have known security vulnerabilities, which provides opportunities for lawbreakers. They may use these security weaknesses to invade the enterprise network, steal sensitive information, tamper with data, or launch malicious attacks, thus posing a serious threat to the business operations and information security of the enterprise.

[0004] In view of this, in order to ensure the security of enterprise networks and data, relatively high-security access authentication methods usually need to be implemented for temporary devices. These relatively high-security access authentication methods often adopt multiple verification mechanisms, such as identity authentication combined with cryptography technology, multi-factor authentication (such as SMS verification codes, hardware tokens, etc.), and trust evaluation of the device itself, etc. Through these strict authentication means, the identity and legitimacy of temporary devices can be effectively identified and verified, preventing unauthorized devices from accessing the enterprise network, thereby reducing security risks to a certain extent.

[0005] However, this relatively high-security access authentication method also brings some new problems in practical applications, and the most prominent one is the relatively long verification time. This is because these complex authentication processes need to process and verify a large amount of information to ensure the security of the device. For example, in multi-factor authentication, users may need to input the username, password in sequence, then receive and input the SMS verification code, and may also need to insert the hardware token for secondary verification, etc. This series of operations will undoubtedly increase the time required for authentication.

[0006] During the peak period of enterprise business, the impact of this situation is particularly significant. With the booming development of business and the increasing market demand, enterprises may face a huge number of business requests within a specific period, and correspondingly, a large number of devices need to be connected to the enterprise system to support the business operation. In this case, if each temporary device needs to undergo a long-term security access authentication, the accumulated time cost will be very substantial. This will not only lead to low efficiency of device access, causing delays in business processes, but also may affect the customer experience, and even may result in the loss of some business opportunities with extremely high timeliness requirements. Therefore, how to improve the efficiency of access authentication while ensuring the security of temporary device access has become an important issue that enterprises urgently need to solve in the process of digital transformation. Summary of the Invention

[0007] The purpose of the present invention is to provide an Internet device access authentication method for network security to solve the above technical problems.

[0008] The purpose of the present invention can be achieved through the following technical solutions:

[0009] An Internet device access authentication method for network security includes the following steps:

[0010] Step S1: Obtain the current device type of the current device, and obtain the historical device access data and historical access traffic data of the current device type.

[0011] Step S2: Obtain the enterprise location, and obtain the access location and access time of the current device; according to the historical device access data and the enterprise location, obtain the access location distribution map and access time distribution curve of all historical devices, and according to the access location and access time, obtain the access location deviation value and access time deviation value of the current device; and according to the historical access traffic data, obtain the traffic deviation value of the current device type.

[0012] Step S3: Obtain the risk value of the current device according to the access location deviation value, access location deviation value, and access location deviation value of the current device; according to the risk value, determine the best access authentication method for the current device, and perform access authentication on the current device through the best access authentication method.

[0013] As a further solution of the present invention: Obtain the device type of the current device, denoted as the current device type, where the device type includes desktop computers, laptop computers, mobile phones, and routers; the historical device access data includes the historical access locations and historical access times of all historical devices, the access location is the position coordinates when the device applies for access, the historical access time is the access time of the historical device, and the access time is the time when the device applies for access; the historical access traffic data is the traffic data of historical devices of all device types within a preset monitoring time period.

[0014] As a further solution of the present invention: The process of setting the monitoring time period includes:

[0015] Obtain the access time t of the device, and obtain the disconnection time t' of the device, where the disconnection time is the time when the device disconnects from access; set a duration threshold T, and based on the access time and the duration threshold, select the monitoring start time t - T, then obtain the monitoring time period [t - T, t'].

[0016] As a further solution of the present invention: The process of obtaining the traffic data includes:

[0017] Select a number of time nodes at equal intervals within the monitoring time period, obtain the traffic transmission rate of the server at each time node, and record the traffic transmission rate at each time node as the traffic data.

[0018] As a further solution of the present invention: The process of obtaining the access location distribution map includes:

[0019] Obtain the distance between each historical access location and the enterprise location, select the maximum value of the distances, and use the maximum value of the distances as the radius and the enterprise location as the center to obtain a circular distribution range; record each historical access location as a point within the distribution range to obtain the access location distribution map.

[0020] As a further solution of the present invention: The process of obtaining the access location deviation value of the current device includes:

[0021] Perform rectangular grid division on the access location distribution map to obtain a number of rectangular grids, obtain the total number of points within each rectangular grid, and obtain the 8 rectangular grids adjacent to the rectangular grid, all denoted as adjacent grids, and obtain the total number of points within each adjacent grid; obtain the density value of the rectangular grid where N0 represents the total number of points within the rectangular grid, and N i represents the total number of points within the i-th adjacent grid;

[0022] Obtain the density values of each rectangular grid, select the rectangular grid with the highest density value, denote it as the central rectangular grid, obtain the center point of the central rectangular grid, and denote it as the distribution center of the access location distribution map; obtain the distance between the access location of the current device and the distribution center, and denote it as the access location deviation value.

[0023] As a further solution of the present invention: the obtaining process of the access time distribution curve includes:

[0024] Divide the 24 hours of a day into several time periods, number each time period, and obtain the total number of access times within each time period; use the number of the time period as the abscissa and the number of access times as the ordinate to establish a coordinate system; convert each numbered time period and the total number of access times within the time period into coordinate points at corresponding positions in the coordinate system, and connect the coordinate points with a smooth curve to obtain the access time distribution curve.

[0025] As a further solution of the present invention: the obtaining process of the access time deviation value of the current device includes:

[0026] Obtain all the maximum value points on the access time distribution curve, and obtain the ordinate values corresponding to each maximum value point, and denote them as maximum values; sort the maximum values from small to large, and sequentially set peak coefficients, set the peak coefficient of the first maximum value after sorting to 1, set the peak coefficient of the first maximum value after sorting to 2, and so on;

[0027] Convert the access time into a point on the coordinate system, and denote it as the current point; obtain the maximum value point closest to the current point, and denote it as the nearest point, and obtain the access time deviation value Dt = Pf|P - P′| according to the peak coefficient of the nearest point, where Pf represents the peak coefficient of the nearest point, and |P - P′| represents the distance between the nearest point P′ and the current point P.

[0028] Advantages of the present invention:

[0029] 1. The present invention combines device type, historical access data, and traffic data to establish a device behavior baseline, and calculates the access location deviation value, access time deviation value, and traffic deviation value, so as to comprehensively evaluate the risk level of the device. This method can quickly screen out low-risk devices, reduce the strict verification of high-risk devices, and significantly shorten the overall access authentication time. During the peak period of enterprise business, a large number of temporary devices need to quickly access the network to support business operations. Through the method of the present invention, it is possible to effectively reduce the business delay caused by long-term verification and improve the overall business processing efficiency.

[0030] 2. When the device is accessed, by comparing the differences between the current access location and time of the device and the historical distribution map, and evaluating the deviation of the current traffic based on the historical traffic fluctuation law of similar devices, multiple deviation values are generated. These deviation values together constitute the comprehensive risk value of the device, providing a basis for subsequent access authentication strategies. Through multiple verification mechanisms (such as identity authentication, multi-factor authentication, device trust evaluation, etc.), the identity and legitimacy of temporary devices can be effectively identified and verified, preventing unauthorized devices from accessing the enterprise network, thereby reducing security risks to a certain extent.

[0031] 3. The present invention is not only applicable to the access authentication of temporary devices, but also can be applied to various types of Internet devices, including desktop computers, laptops, mobile phones, routers, etc. By flexibly adjusting the monitoring time period and the way of obtaining traffic data, it can adapt to the needs of different devices and different application scenarios. Due to the adoption of the method of quantifying behavioral anomalies, this method is particularly suitable for scenarios with a large number of devices such as the Internet of Things, and can efficiently manage and authenticate the access of a large number of devices.

[0032] In summary, the beneficial effects of the present invention lie in achieving a balance between security and efficiency through quantifying behavioral anomalies, and being applicable to scenarios with a large number of devices such as the Internet of Things. Specifically, this Internet device access authentication method improves the efficiency of device access while ensuring network security, and solves the problem of excessive verification time brought by traditional high-security access authentication methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The present invention will be further described below with reference to the accompanying drawings.

[0034] Figure 1 It is a flowchart showing a method for authenticating access to Internet devices for network security according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0036] Please refer to Figure 1 As shown, the present invention is a method for authenticating access to Internet devices for network security, including the following steps:

[0037] Step S1: Obtain the device type of the current device, denoted as the current device type, and obtain the historical device access data of the current device type. The historical device access data includes the historical access locations and historical access times of all historical devices; and obtain the historical access traffic data, where the historical access traffic data is the traffic data of the historical devices of all device types within a preset monitoring time period;

[0038] In a preferred embodiment of the present invention, the device types include desktop computers, laptop computers, mobile phones, and routers. The historical access location is the access location of the historical device, the access location is the position coordinates when the device applies for access, and the historical access time is the access time of the historical device, and the access time is the time when the device applies for access;

[0039] In a preferred embodiment of the present invention, the process of setting the monitoring time period includes:

[0040] Obtain the access time t of the device, and obtain the disconnection time t' of the device. The disconnection time is the time when the device disconnects from access; set a duration threshold T, and select the monitoring start time t - T according to the access time and the duration threshold, then obtain the monitoring time period [t - T, t'];

[0041] In a preferred embodiment of the present invention, the process of obtaining the traffic data includes:

[0042] Select a number of time nodes at equal intervals within the monitoring time period, obtain the traffic transmission rate of the server at each time node, and record the traffic transmission rate at each time node as the traffic data;

[0043] It should be noted that the access time does not include the date, but only the moment within 24 hours of a day;

[0044] It should be noted that based on historical behavior modeling, a benchmark model for device access is established by collecting two types of key data; through the historical access locations and times of the same type of devices, a normal behavior model of the devices of this device type is constructed (for example, a certain model of sensor usually accesses from a fixed location between 8:00 and 18:00); through the historical traffic data of all devices (such as the number of requests per second, bandwidth occupancy), the traffic changes generated after the access of devices of different device types are statistically analyzed for detecting abnormal behaviors;

[0045] Step S2: Obtain the position coordinates of the enterprise, denoted as the enterprise location, and obtain the access location and access time of the current device; according to the historical device access data and the enterprise location, obtain the access location distribution map of all historical devices; according to the access location distribution map and the access location, obtain the access location deviation value of the current device;

[0046] According to the historical device access data, obtain the access time distribution curve of all historical devices, and obtain the access time deviation value of the current device according to the access time distribution curve and the access time; according to the historical access traffic data, obtain the traffic deviation value of the current device type;

[0047] In a preferred embodiment of the present invention, the process of obtaining the access location distribution map includes:

[0048] Obtain the distances between each historical access location and the enterprise location, select the maximum value of the distances, and use the maximum value of the distances as the radius and the enterprise location as the center to obtain a circular distribution range; record each historical access location as a point within the distribution range to obtain the access location distribution map;

[0049] In a preferred embodiment of the present invention, the process of obtaining the access location deviation value of the current device includes:

[0050] Perform rectangular grid division on the access location distribution map to obtain a number of rectangular grids, obtain the total number of points within each rectangular grid, and obtain the 8 rectangular grids adjacent to the rectangular grid, all of which are recorded as adjacent grids, and obtain the total number of points within each adjacent grid; obtain the density value of the rectangular grid where N0 represents the total number of points within the rectangular grid, and N i represents the total number of points within the i-th adjacent grid;

[0051] Obtain the density values of each rectangular grid, select the rectangular grid with the highest density value, record it as the central rectangular grid, obtain the center point of the central rectangular grid, and record it as the distribution center of the access location distribution map; obtain the distance between the access location of the current device and the distribution center, and record it as the access location deviation value;

[0052] It can be understood that the access locations of all historical devices are statistically analyzed (such as GPS coordinates, IP geolocation database) to form a heat map or a clustering model (such as DBSCAN), and the difference between the access location of the current device and the historical distribution is calculated (such as Euclidean distance, whether it is outside the historical aggregation area);

[0053] In a preferred embodiment of the present invention, the process of obtaining the access time distribution curve includes:

[0054] Divide the 24 hours of a day into several time periods, number each time period, and obtain the total number of access times within each time period; use the number of the time period as the abscissa and the number of access times as the ordinate to establish a coordinate system; convert each numbered time period and the total number of access times within the time period into coordinate points at corresponding positions within the coordinate system, and connect the coordinate points with a smooth curve to obtain the access time distribution curve;

[0055] In a preferred embodiment of the present invention, the process of obtaining the access time deviation value of the current device includes:

[0056] Obtain all the maximum value points on the access time distribution curve, and obtain the ordinate values corresponding to each maximum value point, denoted as maximum values; sort the maximum values from smallest to largest, and sequentially set peak coefficients, set the peak coefficient of the first maximum value after sorting to 1, set the peak coefficient of the first maximum value after sorting to 2, and so on;

[0057] Convert the access time into a point on the coordinate system, denoted as the current point; obtain the maximum value point closest to the current point, denoted as the nearest point, and obtain the access time deviation value Dt = Pf|P - P′| according to the peak coefficient of the nearest point, where Pf represents the peak coefficient of the nearest point, and |P - P′| represents the distance between the nearest point P′ and the current point P;

[0058] It can be understood that by statistically analyzing the access time patterns of historical devices (such as concentrated logins from 9:00 to 18:00), establishing a time probability model (such as Gaussian distribution), and determining whether the current access time is outside the common interval (such as logging in at 3 am);

[0059] In a preferred embodiment of the present invention, the process of obtaining the traffic deviation value of the current device type includes:

[0060] Obtain the standard deviation s of all traffic transmission rates in the traffic data of historical devices of each device type, and obtain the average value Ave of all traffic transmission rates, to obtain the coefficient of variation Cv = s / Ave of the traffic data of historical devices of each device type; obtain the average value of all coefficients of variation, denoted as the average coefficient of variation, and the coefficient of variation of the current device type, denoted as the current coefficient of variation, and obtain the difference between the current coefficient of variation and the average coefficient of variation, denoted as the traffic deviation value;

[0061] It can be understood that by comparing the real-time traffic (such as request frequency) of the current device type with the historical baseline (the traffic mean ± standard deviation of the same type of devices);

[0062] It should be noted that through multi-dimensional deviation detection, evaluate whether the behavior of the current device deviates from the historical normal mode, abstract the device behavior into numerical indicators (such as location deviation value = 3.2, time deviation value = 1.5), and provide input for subsequent comprehensive risk assessment; for example: a low deviation value (such as normal location / time / traffic) represents fast authentication (resource saving), and a high deviation value (such as different location + late at night + traffic surge) represents enhanced verification or blocking (attack prevention);

[0063] Step S3: Obtain the risk value of the current device based on the access location deviation value, access location deviation value, and access location deviation value of the current device; set several risk thresholds, set several access authentication methods according to the risk thresholds, and determine the optimal access authentication method for the current device according to the risk value of the current device, and perform access authentication on the current device through the optimal access authentication method;

[0064] In a preferred embodiment of the present invention, the risk value Rv of the current device = w1Dp + w2Dt + w3DI, where w1, w2, and w3 are all weight coefficients;

[0065] It should be noted that the weight coefficients are adjusted according to business requirements (for example, when an enterprise pays more attention to geographical security, w1 is higher), and at the same time, historical attack data (such as SIEM logs) is used to train the model to optimize each weight coefficient;

[0066] In a preferred embodiment of the present invention, a risk range is obtained from two adjacent risk thresholds, access authentication methods with different security strengths are obtained, and each risk range corresponds to an access authentication method;

[0067] It can be understood that preset risk thresholds (such as low risk: 0 - 30, medium risk: 30 - 70, high risk: 70 - 100) are used to discretize the continuous risk value and match different authentication strengths;

[0068] In a preferred embodiment of the present invention, the determination process of the optimal access authentication method includes:

[0069] Obtain the risk range where the risk value of the current device is located, obtain the access authentication method corresponding to the risk range, and record it as the optimal access authentication method.

[0070] The above has described an embodiment of the present invention in detail, but the content is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.

Claims

1. An Internet device access authentication method for network security, characterized in that: The following steps are involved: Step S1: obtaining the current device type of the current device, and obtaining the historical device access data and historical access traffic data of the current device type; Step S2: Obtain the enterprise location, and obtain the access location and access time of the current device; obtain the access location distribution map and access time distribution curve of all historical devices according to the historical device access data and the enterprise location, and obtain the access location deviation value and access time deviation value of the current device according to the access location and access time; and obtaining a flow deviation value of the current device type according to the historical access flow data; Step S3: obtaining a risk value of the current device according to the access location deviation value, the access location deviation value and the access location deviation value of the current device; An optimal access authentication method for the current device is determined according to the risk value, and access authentication is performed on the current device using the optimal access authentication method.

2. The Internet device access authentication method for network security according to claim 1, characterized in that: In step S1, the device type of the current device is obtained, recorded as the current device type, and the device types include desktop computers, laptop computers, mobile phones and routers; the historical device access data includes the historical access locations and historical access times of all historical devices, the access location is the location coordinates when the device applies for access, the historical access time is the access time of the historical device, and the access time is the time when the device applies for access; the historical access traffic data is the traffic data of historical devices of all device types within a preset monitoring time period.

3. The Internet device access authentication method for network security according to claim 2, characterized in that: In step S1, the process of setting the monitoring time period includes: Get the access time t of the device and the disconnection time t' of the device, where the disconnection time is the time when the device is disconnected; set a duration threshold T, and select the monitoring start time tT according to the access time and duration threshold, and then obtain the monitoring time period [tT, t'].

4. The Internet device access authentication method for network security according to claim 2, characterized in that: In step S1, the process of acquiring the flow data includes: A number of time nodes are selected at equal intervals within the monitoring time period, the flow transmission rate of the server at each time node is obtained, and the flow transmission rate at each time node is recorded as flow data.

5. The Internet device access authentication method for network security according to claim 2, characterized in that: In step S2, the process of obtaining the access location distribution map includes: Obtain the distance between each historical access location and the enterprise location, select the maximum value of the distance, and use the maximum value of the distance as the radius and the enterprise location as the center to obtain a circular distribution range; record each historical access location as a point within the distribution range to obtain an access location distribution map.

6. The Internet device access authentication method for network security according to claim 5, characterized in that: In step S2, the process of obtaining the access location deviation value of the current device includes: Divide the access location distribution map into rectangular grids to obtain a number of rectangular grids, obtain the total number of points in each rectangular grid, and obtain 8 rectangular grids adjacent to the rectangular grid, all of which are recorded as adjacent grids, and obtain the total number of points in each adjacent grid; obtain the density value of the rectangular grid Where N0 represents the total number of points in the rectangular grid, N i Represents the total number of points in the i-th adjacent grid; Obtain the density value of each rectangular grid, select the rectangular grid with the highest density value, record it as the central rectangular grid, obtain the center point of the central rectangular grid, record it as the distribution center of the access location distribution map; obtain the distance between the access location of the current device and the distribution center, record it as the access location deviation value.

7. The Internet device access authentication method for network security according to claim 2, characterized in that: In step S2, the process of obtaining the access time distribution curve includes: The 24 hours of a day are divided into several time periods, each time period is numbered, and the total number of access times in each time period is obtained; a coordinate system is established with the number of the time period as the horizontal coordinate and the number of access times as the vertical coordinate; each numbered time period and the total number of access times in the time period are converted into coordinate points of corresponding positions in the coordinate system, and each coordinate point is connected with a smooth curve to obtain an access time distribution curve.

8. The Internet device access authentication method for network security according to claim 7, characterized in that: In step S2, the process of obtaining the access time deviation value of the current device includes: Obtain all the maximum points on the access time distribution curve, and obtain the ordinate value corresponding to each maximum point, which is recorded as the maximum value; sort the maximum values ​​from small to large, and set the peak coefficients in sequence, setting the peak coefficient of the first maximum value after sorting to 1, setting the peak coefficient of the first maximum value after sorting to 2, and so on; The access time is converted into a point on the coordinate system, recorded as the current point; the maximum point closest to the current point is obtained, recorded as the nearest point, and the access time deviation value Dt=Pf|PP′| is obtained according to the peak coefficient of the nearest point, where Pf represents the peak coefficient of the nearest point, and |PP′| represents the distance between the nearest point P′ and the current point P.

Citation Information

Patent Citations

  • Internet of Things anomaly positioning method and device and electronic equipment

    CN112350836A

  • Operation sequence identification device, operation sequence identification system, operation sequence identification method, and program

    CN112368725A

  • Power network security protection method based on zero trust

    CN115189927A

  • Account-free user unification method and system of construction and management system based on multimode authentication

    CN119357939A

  • Local information retrieval server and local information retrieval method

    JP2011141682A