Bidirectional channel authentication communication device and method based on dynamic network fingerprint

Through dynamic network fingerprint generation and two-way authentication combined with blockchain technology, the problems of insufficient channel security and rigid authentication in IoT communication are solved, and efficient dynamic network adaptation and transparent audit are achieved to ensure trusted interaction between IoT devices and platforms.

CN120301575APending Publication Date: 2025-07-11SUZHOU CROSS-HEAD DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510410823.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing IoT secure communication technology has problems such as insufficient channel security, single authentication dimensions, rigid configurations and blind audits in dynamic network environments, which are difficult to adapt to complex security needs.

Method used

The two-way channel authentication communication device and method based on dynamic network fingerprint is adopted, and physical network features and logical identity credentials are collected through the network fingerprint generation module, and two-way authentication and adaptive verification are realized in combination with blockchain technology, port sequences are generated dynamically and encryption algorithms are adjusted to ensure the legitimacy of both parties in the communication and the security of the paths.

Benefits of technology

Enhance communication security, improve the system's adaptability in dynamic network environments, and realize the transparency of the authentication process and an untampered audit record.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301575A_ABST
    Figure CN120301575A_ABST
Patent Text Reader

Abstract

The invention provides a two-way channel authentication communication device based on dynamic network fingerprints, which comprises a network fingerprint generation module for generating equipment network fingerprints and platform network fingerprints; the bidirectional authentication protocol module is used for verifying the equipment network fingerprint and the platform network fingerprint; and the self-adaptive verification gateway module is used for generating and updating a dynamic port sequence based on the block chain intelligent contract, and selecting an encryption algorithm and verification strength of transmission data in real time. The invention also provides a two-way channel authentication communication method based on the dynamic network fingerprint. The method comprises the following steps: generating a device network fingerprint and a platform network fingerprint; the platform and the equipment respectively verify whether the fingerprints are matched; network environment parameters are collected in real time, a dynamic port sequence is generated and updated based on a block chain smart contract, and an encryption algorithm and verification strength of transmission data are selected according to real-time network information. According to the method, the three problems of bypass attack defense, bidirectional identity path verification and dynamic network adaptability are solved, and the security of communication authentication is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and more particularly, to a two-way channel authentication communication device and method based on dynamic network fingerprints. Background Art

[0002] Currently, in the field of Internet of Things (IoT) secure communication, technologies such as VPN tunnel technology, one-way TLS authentication, static network whitelists, and network traffic encryption are mainly adopted. However, these technologies have significant defects in practical applications. First, the VPN tunnel technology relies on fixed endpoint configurations, making it difficult to adapt to dynamic network environments and vulnerable to man-in-the-middle attacks and lagging key management. Second, one-way TLS authentication only verifies the identity of the server and cannot prevent attackers from forging the server or disguising as legitimate devices to launch attacks. The static network whitelist strategy is rigid, unable to adapt to dynamic IP allocation environments and easily bypassed by MAC address forgery. Finally, although network traffic encryption technology can protect data privacy, it lacks the ability to audit the legality of communication paths and is vulnerable to routing hijacking and side-channel penetration attacks. Generally speaking, the existing technologies fail to fully address the dynamic and highly complex security requirements of the IoT, suffering from problems such as insufficient channel security, single authentication dimension, rigid configuration, and auditing blind spots, and there is an urgent need for more flexible and comprehensive security solutions. Summary of the Invention

[0003] The present invention provides a two-way channel authentication communication device and method based on dynamic network fingerprints, aiming to solve the problems of insufficient channel security, single authentication dimension, rigid configuration, and auditing blind spots in the existing technologies and improve the security of communication authentication.

[0004] To achieve the above object, the present invention provides a two-way channel authentication communication device and method based on dynamic network fingerprints, including:

[0005] A network fingerprint generation module, which collects physical network characteristics and logical identity credential information of the current communication state, and generates a device network fingerprint and a platform network fingerprint. The device sends an authentication request data packet including the device network fingerprint and the device certificate to the two-way authentication protocol module, and the platform sends a response data packet including the platform network fingerprint and the platform certificate to the two-way authentication protocol module;

[0006] A two-way authentication protocol module, which includes a northbound authentication unit and a southbound authentication unit. The northbound authentication unit receives and authenticates the authentication request data packet sent by the device, and the southbound authentication unit receives and authenticates the response data packet sent by the platform;

[0007] Adaptive verification gateway module, the adaptive verification gateway module includes an input unit, a port hopping generation unit, and a policy adjustment unit. The input unit receives the authentication result from the two-way authentication protocol module and collects network environment parameters in real time. The port hopping generation unit generates and updates a dynamic port sequence based on a blockchain smart contract. The policy adjustment unit collects real-time network information and selects an encryption algorithm and verification strength for transmitting data according to the real-time network information.

[0008] In one embodiment, the physical network characteristics include physical characteristic information and spatio-temporal information of the network path of the current communication, and the logical identity credentials include device certificates and platform certificates;

[0009] The physical characteristic information includes IP address, port sequence, and routing hop count;

[0010] The spatio-temporal information includes timestamp and coordinates.

[0011] In one embodiment, the network fingerprint generation module combines the physical network characteristics of the device and platform communication with the logical identity credentials through a custom encryption algorithm to generate a device network fingerprint and a platform network fingerprint containing a timestamp.

[0012] In one embodiment, the authentication request data packet includes a device PKI certificate, a dynamic fingerprint containing a timestamp, and coordinate encapsulation.

[0013] In one embodiment, the response data packet includes a platform PKI certificate, a network fingerprint containing a timestamp, spatial coordinates, and time coordinates.

[0014] In one embodiment, the two-way channel authentication communication device based on dynamic network fingerprint further includes a blockchain audit network module, and the blockchain audit network module stores the generated device network fingerprint and platform network fingerprint and the authentication result of the two-way authentication protocol module.

[0015] A two-way channel authentication communication method based on dynamic network fingerprint, implemented by a two-way channel authentication communication device based on dynamic network fingerprint, includes:

[0016] Step S101, collect the physical network characteristics and logical identity credentials of the current communication, and generate a device network fingerprint and a platform network fingerprint;

[0017] Step S102, the device sends an authentication request data packet containing the device network fingerprint and the device certificate to the northbound authentication unit, and the platform verifies the authentication request data packet through the northbound authentication unit to verify whether the device certificate is valid and whether the device network fingerprint matches. If the certificate is valid and the fingerprint matches, enter step S103;

[0018] Step S103, the platform sends a response data packet containing the platform network fingerprint and the platform certificate to the southward authentication unit, and the device verifies the response data packet through the southward authentication unit to verify whether the platform certificate is valid and whether the platform network fingerprint matches. If the certificate is valid or the fingerprint matches, the two-way authentication passes.

[0019] Step S104, when the two-way authentication passes, data transmission is entered, and the network environment parameters are collected in real time. A dynamic port sequence is generated and updated based on the blockchain smart contract, and the encryption algorithm and verification strength for transmitting data are selected according to the real-time network information.

[0020] In one embodiment, in step S101, generating the device network fingerprint and the platform device network fingerprint specifically includes:

[0021] Step S1011, collect the physical network characteristics and logical identity credential information of the current communication;

[0022] Step S1012, bind the physical network characteristics and the logical identity credentials through the hash encryption algorithm to generate the device network fingerprint containing the time stamp and the platform network fingerprint containing the time stamp of the current communication.

[0023] In one embodiment, in step S102, the platform verifies the authentication request data packet through the northward authentication unit specifically includes:

[0024] Step S1021, certificate legality verification: the platform uses the preset CA root certificate to verify whether the device certificate is correct;

[0025] Step S1022, dynamic fingerprint comparison: the platform generates a device comparison fingerprint according to the current network path characteristics, and performs a consistency comparison with the device network fingerprint submitted by the device. If the fingerprints match, it is confirmed that the device accesses through the authorized path;

[0026] Among them, when performing dynamic fingerprint comparison, the platform verifies the timeliness of the device network fingerprint time stamp. If the fingerprints match within the specified time limit, the dynamic fingerprint comparison is successful.

[0027] In one embodiment, in step S103, the device verifies the response data packet through the southward authentication unit specifically includes:

[0028] Step S1031, platform certificate verification: the device uses the preset CA root certificate to verify whether the platform certificate is correct;

[0029] Step S1032, path fingerprint verification: the device generates a platform comparison fingerprint according to the network path characteristics in the response data packet, and compares it with the platform network fingerprint submitted by the platform. If the fingerprints match, it is confirmed that the platform identity and the communication path have not been tampered with;

[0030] Step S1033: The device parses the new port sequence sent by the platform and communicates on the new ports.

[0031] The present invention has the following beneficial effects:

[0032] 1. Enhanced security: Through the two-way authentication mechanism and dynamic network fingerprint technology, the two-way authentication of the present invention requires the device and the platform to mutually verify the PKI certificates and network fingerprints, ensuring the legitimacy of the identities and paths of both communication parties. The dynamic network fingerprint binds the physical network characteristics with the logical identity credentials through the spatio-temporal hashing algorithm to generate a unique and non-forgeable path identifier, preventing attackers from accessing the platform through unauthorized paths.

[0033] 2. Dynamic adaptability: Through the adaptive verification gateway and the policy engine driven by smart contracts, the present invention significantly improves the adaptability of the system in a dynamic network environment.

[0034] 3. Audit transparency: Through blockchain technology, the present invention realizes the distributed storage of authentication logs and network fingerprint change records, ensuring the immutability and traceability of audit data. Description of the Drawings

[0035] Figure 1 It is a schematic structural diagram of a two-way channel authentication communication device based on dynamic network fingerprint according to an embodiment of the present invention;

[0036] Figure 2 It is a schematic flow diagram of a two-way channel authentication communication device based on dynamic network fingerprint according to an embodiment of the present invention;

[0037] Figure 3 It is a schematic diagram of specific modules of a two-way channel authentication communication device based on dynamic network fingerprint according to an embodiment of the present invention;

[0038] Figure 4 It is a schematic diagram of an adaptive verification gateway module of a two-way channel authentication communication device based on dynamic network fingerprint according to an embodiment of the present invention;

[0039] Figure 5 It is a schematic flow diagram of the specific process of generating device network fingerprints and platform device network fingerprints according to an embodiment of the present invention.

[0040] Among them, 100 is the network fingerprint generation module; 200 is the two-way authentication protocol module; 210 is the northward authentication unit; 220 is the southward authentication unit; 300 is the adaptive verification gateway module; 310 is the input unit; 320 is the port hopping generation unit; 330 is the policy adjustment unit; 400 is the blockchain audit network module. Detailed Embodiments

[0041] To make the purpose, technical solution, and advantages of the implementation of this application clearer, the following will describe the technical solutions in the embodiments of this application in more detail with reference to the accompanying drawings in the embodiments of this application. In the drawings, the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions. The described embodiments are part of the embodiments of this application, not all of the embodiments. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain this application and should not be construed as a limitation of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts fall within the scope of protection of this application.

[0042] Figure 1 Schematic diagram of the structure of a two-way channel authentication communication device based on dynamic network fingerprints according to an embodiment of the present invention. The two-way channel authentication communication device based on dynamic network fingerprints includes:

[0043] A network fingerprint generation module 100, which collects physical network characteristics and logical identity credential information of the current communication state, and generates a device network fingerprint and a platform network fingerprint. The device sends an authentication request data packet including the device network fingerprint and the device certificate to the two-way authentication protocol module 200, and the platform sends a response data packet including the platform network fingerprint and the platform certificate to the two-way authentication protocol module 200;

[0044] A two-way authentication protocol module 200, which includes a northbound authentication unit 210 and a southbound authentication unit 220. The northbound authentication unit 210 receives and authenticates the authentication request data packet sent by the device, and the southbound authentication unit 220 receives and authenticates the response data packet sent by the platform;

[0045] An adaptive verification gateway module 300, which includes an input unit 310, a port hopping generation unit 320, and a policy adjustment unit 330. The input unit 310 receives the authentication result from the two-way authentication protocol module 200 and collects network environment parameters in real time. The port hopping generation unit 320 generates and updates a dynamic port sequence based on a blockchain smart contract, and the policy adjustment unit 330 collects real-time network information and selects an encryption algorithm and verification strength for transmitting data according to the real-time network information.

[0046] In one embodiment, as Figure 3 shown, the two-way channel authentication communication device based on dynamic network fingerprints further includes a blockchain audit network module 400, which stores the generated device network fingerprint and platform network fingerprint and the authentication result of the two-way authentication protocol module.

[0047] Specifically, the blockchain audit network module 400 is responsible for writing the port hopping sequence, policy adjustment records, and authentication logs into the blockchain. Its main workflow is as follows:

[0048] Data storage: Package the port sequence, policy adjustment reasons (such as "bandwidth fluctuation triggers encryption algorithm switch"), and authentication results (such as device ID, timestamp, coordinates) as blockchain data, and broadcast the data to the nodes on the chain to form an immutable audit record.

[0049] Support for multi-party auditing: The blockchain audit network module 400 is equipped with a blockchain browser. Device manufacturers, platform operators, and regulatory authorities can query the complete logs through the blockchain browser to verify the compliance and real-time nature of policy adjustments.

[0050] The complete process of two-way authentication is written into the blockchain through smart contracts, such as device ID, platform ID, timestamp, fingerprint hash value, port sequence, etc. Each block of the blockchain audit network module 400 contains the hash value of the previous block, forming an immutable audit chain. If an authentication failure is detected, such as certificate verification error or fingerprint mismatch, the smart contract automatically triggers an alarm event and synchronously records the exception log to the blockchain. Device manufacturers, platform operators, and regulatory authorities can all query the complete authentication history through the blockchain browser to verify whether the communication process complies with security policies, such as port hopping rules and certificate validity periods.

[0051] Specifically, the current block contains the hash value of the previous block, enabling the blocks to be linked in sequence to form a blockchain. This design ensures the immutability of data because modifying the content of any block will change its hash value, thereby affecting all subsequent blocks.

[0052] As Figure 4 shown, the input unit 310 receives the verification results and network status data from the two-way authentication protocol module 200, such as bandwidth, latency, and number of routing hops. Specifically included are:

[0053] Verification result parsing: Parse the two-way authentication results, such as device ID, platform ID, authentication timestamp, and dynamic fingerprint hash value, and determine whether to trigger port hopping or policy adjustment based on the authentication results.

[0054] Network status monitoring: Real-time collect network environment parameters, such as bandwidth fluctuation, routing change, and number of device accesses, to provide data support for policy adjustment.

[0055] Anomaly detection: If an authentication failure is detected, such as fingerprint mismatch or certificate expiration, immediately trigger an alarm and record it to the blockchain.

[0056] The port jump generation unit 320 realizes the generation and update of a dynamic port sequence based on a blockchain smart contract, specifically including smart contract triggering, dynamic port generation, blockchain consensus, and port synchronization.

[0057] Smart contract triggering: When the input unit 310 detects a network topology change, such as an SDN path (software-defined network path) switch or reaching a preset time interval, the smart contract is triggered to generate a new port sequence.

[0058] Dynamic port generation: The smart contract generates an unpredictable port sequence according to preset rules and the current network state. For example, the smart contract generates a port sequence such as 5001 → 5003 → 5005 according to the preset port range, jump frequency, current device quantity, and bandwidth utilization rate. The "smart contract" mentioned here does not specifically refer to a certain accurate smart contract program. In actual applications, custom development is carried out according to the actual scenario.

[0059] Blockchain consensus: The new port sequence is broadcast to the nodes on the chain through the blockchain consensus mechanism to ensure the immutability and consistency of the sequence.

[0060] Port synchronization: The device and the platform obtain the new port sequence through the blockchain and update the communication configuration to prevent attackers from initiating sniffing attacks through fixed ports.

[0061] Policy adjustment unit 330: After the device and the platform establish two-way authentication, both parties enter the data transmission stage. At this time, the adaptive authentication gateway dynamically selects an encryption algorithm and authentication strength according to the real-time network environment (such as bandwidth, latency, routing status) to ensure the confidentiality, integrity, and availability of the data during transmission, and dynamically optimizes the encryption algorithm and authentication strength according to the network environment. For example, when the network bandwidth is sufficient, a high-strength encryption algorithm is selected. For example, when the network latency is high, the authentication strength is reduced to reduce communication overhead and avoid data transmission interruption caused by authentication latency. The encryption algorithm and authentication strength mentioned by the policy adjustment unit 330 here do not specifically refer to a certain accurate encryption algorithm or authentication algorithm. In actual applications, custom development is carried out according to the actual scenario.

[0062] The main functions of the policy adjustment unit 330 include:

[0063] Bandwidth fluctuation response: When it is detected that the bandwidth drops by more than a threshold (such as 20%), it automatically switches to a lightweight encryption algorithm (such as the ChaCha20 encryption algorithm) to ensure communication efficiency.

[0064] Routing change adaptation: If the network topology changes (such as 5G network slice reconstruction), at this time, the authentication strength is increased (such as increasing the number of hash rounds or enabling dual certificate verification) to prevent path tampering attacks.

[0065] Device Load Balancing: Dynamically adjust the authentication policy according to the number of access devices (e.g., enable batch authentication under high load and enable per-packet verification under low load) to optimize system performance.

[0066] Policy Recording: All policy adjustments (such as encryption algorithm switching, verification strength change) are recorded to the blockchain through smart contracts to ensure audit transparency.

[0067] In one embodiment, the physical network features include physical feature information and spatio-temporal information of the current communication network path, and the logical identity credentials include device certificates and platform certificates;

[0068] The physical feature information includes IP (Internet Protocol) address, port sequence, and routing hop count;

[0069] The spatio-temporal information includes timestamp and coordinates.

[0070] In one embodiment, the network fingerprint generation module 100 combines the physical network features of device and platform communication with the logical identity credentials through a custom encryption algorithm to generate a device network fingerprint and a platform network fingerprint containing a timestamp.

[0071] Specifically, the combination method is a custom encryption algorithm, not referring to a specific accurate algorithm. The logical identity credentials include PKI (Public Key Infrastructure) certificates. The custom encryption algorithm includes, but is not limited to, spatio-temporal hashing algorithm.

[0072] Preferably, the encryption algorithm can be selected as the spatio-temporal hashing algorithm, which refers to an encryption algorithm that takes timestamp and coordinates as input parameters of the hash function, such as the SHA-256 algorithm (Secure Hash Algorithm - 256), etc. The result generated is a hash value. In actual applications, the encryption method can be selected according to the actual scenario.

[0073] Preferably, the authentication request data packet includes a device PKI certificate, a dynamic fingerprint containing a timestamp, and coordinate encapsulation. The response data packet includes a platform PKI certificate, a network fingerprint containing a timestamp, spatial coordinates, and time coordinates.

[0074] Figure 2 A two-way channel authentication communication method based on dynamic network fingerprint according to an embodiment of the present invention is implemented by a two-way channel authentication communication device based on dynamic network fingerprint, including:

[0075] Step S101, collect the physical network features and logical identity credentials of the current communication to generate a device network fingerprint and a platform network fingerprint;

[0076] Step S102, the device sends an authentication request data packet containing the device network fingerprint and the device certificate to the northbound authentication unit 210. The platform verifies the authentication request data packet through the northbound authentication unit 210 to verify whether the device certificate is valid and whether the device network fingerprint matches. If the certificate is valid and the fingerprint matches, it proceeds to step S103;

[0077] Step S103, the platform sends a response data packet containing the platform network fingerprint and the platform certificate to the southbound authentication unit 220. The device verifies the response data packet through the southbound authentication unit 220 to verify whether the platform certificate is valid and whether the platform network fingerprint matches. If the certificate is valid or the fingerprint matches, the two-way authentication passes;

[0078] Step S104, when the two-way authentication passes, data transmission is entered, and network environment parameters are collected in real time. A dynamic port sequence is generated and updated based on the blockchain smart contract, and the encryption algorithm and verification strength for transmitting data are selected according to the real-time network information.

[0079] Specifically, during two-way authentication, the northbound authentication is performed first. When the northbound authentication passes, the platform knows the legal identity of the device, and at this time, the southbound authentication work will be carried out. During the southbound authentication, the platform will send the result of the port jump update (this result is the port sequence result generated by the port jump module based on the smart contract after the previous two-way authentication is successful) to the device, and the device establishes a new network channel according to this result and marks the completion of the two-way authentication.

[0080] After the two-way authentication is completed, data starts to be transmitted. At this time, the blockchain smart contract updates the port sequence, that is, the new channel for the next connection of this device. At the same time, the platform will collect network environment parameters in real time and adjust the encryption algorithm and verification strength of the real-time data transmission according to the real-time network information.

[0081] In one embodiment, in step S101, generating the device network fingerprint and the platform device network fingerprint specifically includes:

[0082] As Figure 5 shown, step S1011, collect the physical network characteristics and logical identity credential information of the current communication;

[0083] Step S1012, bind the physical network characteristics and the logical identity credentials through the hash encryption algorithm to generate the device network fingerprint and the platform network fingerprint of the current communication.

[0084] After generating the device network fingerprint and the platform network fingerprint, dynamic update is required, and the updated content will be saved and recorded through the blockchain. When communicating next time, if the current network topology has not changed, directly maintain the fingerprint saved and recorded by the current blockchain for communication.

[0085] If a network topology change is detected, the device network fingerprint and the platform network fingerprint are regenerated, records are saved through the blockchain, and subsequent authentication is performed.

[0086] When the network topology changes, the device network fingerprint is regenerated, and the result is saved through the blockchain. Both the device and the platform interact with the blockchain. When the new device network fingerprint and the platform network fingerprint are saved to the blockchain, the nodes of the blockchains on both sides will passively complete data synchronization, knowing that the device network fingerprint has changed and recording it. At this time, the platform will disconnect from the device, causing the platform and the device to re-enter the two-way authentication process.

[0087] In one embodiment, in step S102, the platform verifies the authentication request data packet through the northbound authentication unit 210, which specifically includes:

[0088] Step S1021, certificate legality verification: The platform uses the preset CA root certificate to verify whether the device certificate is correct;

[0089] Step S1022, dynamic fingerprint comparison: The platform generates a device comparison fingerprint based on the current network path characteristics, and performs a consistency comparison with the device network fingerprint submitted by the device. If the fingerprints match, it is confirmed that the device accesses through the authorized path;

[0090] Among them, when performing dynamic fingerprint comparison, the platform verifies the timeliness of the device network fingerprint timestamp. If the fingerprints match within the specified time limit, the dynamic fingerprint comparison is successful.

[0091] Specifically, the timestamp of the network fingerprint is to prevent attackers from intercepting old authentication request data packets and launching replay attacks.

[0092] If the current device network fingerprint does not match the device comparison fingerprint, it is determined as a bypass attack and the connection is terminated.

[0093] In one embodiment, in step S103, the device verifies the response data packet through the southbound authentication unit 220, which specifically includes:

[0094] Step S1031, platform certificate verification: The device uses the preset CA (Certificate Authority) root certificate to verify whether the platform certificate is correct;

[0095] Step S1032, path fingerprint verification: The device generates a platform comparison fingerprint based on the network path characteristics in the response data packet, and compares it with the platform network fingerprint submitted by the platform. If the fingerprints match, it is confirmed that the platform identity and the communication path have not been tampered with;

[0096] Step S1033, the device parses the new port sequence sent by the platform and communicates on the new port.

[0097] Among them, for path fingerprint verification, the device verification platform checks the timeliness of the network fingerprint timestamp of the device. If the fingerprint matches within the specified time limit, the path fingerprint verification is successful.

[0098] Specifically, when the southbound authentication unit 220 performs southbound authentication, the platform also sends a dynamic port sequence to the device. The device establishes a network channel based on this dynamic port sequence, marking the completion of two-way authentication.

[0099] The dynamic port sequence is generated by the blockchain smart contract based on the consensus algorithm to ensure unpredictability.

[0100] After the port jumps, the communication will establish an encrypted channel using the new port.

[0101] During path fingerprint verification, if the fingerprint does not match or the timestamp is not within the specified time limit, it is determined as a malicious node and the session is terminated. The relevant process logs are synchronously recorded on the blockchain.

[0102] In one embodiment, when the smart meter in the smart grid communicates with the energy management platform in a trusted manner, there are 100,000 smart meters deployed in the city, and they need to report electricity consumption data to the energy management platform in real time. The smart meters access the platform through the 5G network slice, and the network topology is dynamically adjusted according to the load of the base station.

[0103] Meter startup and feature collection:

[0104] Hardware initialization: After the smart meter is powered on, it generates a unique device key pair, such as the public key PK_device and the private key SK_device, and issues a PKI certificate. This PKI certificate contains information such as the device ID, public key, and CA signature, and this PKI certificate is signed / encrypted by the public key PK_device.

[0105] Among them, PK_device is the public key name of the key pair, and SK_device is the private key name of the key pair.

[0106] Network path feature collection: The smart meter connects to the network and obtains the current network path features. Taking a 5G base station as an example, it obtains a series of physical network features such as the base station IP 192.168.5.100, the port sequence 5001 → 5003 → 5005, and the routing hop count 3, as well as a series of logical identity features such as the device PKI certificate and the SSL session key (example name is SessionKey_123).

[0107] Dynamic network fingerprint generation:

[0108] The electricity meter binds the above physical network characteristics, logical identity characteristics, timestamp 2025-02-15T08:00:00Z, and coordinates 116.629923, 39.937289, and generates a dynamic network fingerprint through the hash algorithm: a1b2c3d4e5f6...

[0109] For northbound authentication, the electricity meter sends an authentication request data packet:

[0110] Authentication request sending: The electricity meter encapsulates the PKI certificate, dynamic fingerprint a1b2c3..., timestamp, and coordinates into an authentication request data packet. The SSL session key is used to encrypt the authentication request data packet and send it to the platform for authentication.

[0111] Platform verifies the device certificate: The platform (IP 10.0.0.1) uses the CA root certificate to verify the legality of the CA signature in the electricity meter's PKI certificate. In one embodiment, if the validity period of the electricity meter's CA signature is until 2030, it indicates that the signature is valid. The private key SK_device is used to decrypt the PKI certificate.

[0112] Platform compares fingerprints: The platform generates a device comparison fingerprint based on information such as the network source (IP192.168.5.100) of the received request, port sequence 5001→5003→5005, routing hop count 3, device PKI certificate, SSL session key SessionKey_123, timestamp, and coordinates. When it is consistent with the device network fingerprint submitted by the electricity meter, the path is confirmed to be legal.

[0113] Timestamp verification: The set timestamp has an error of 10 seconds from the current time. When the platform detects that the error between the timestamp and the current time is 5 seconds, the current timestamp is within the allowable range.

[0114] For southbound authentication, the platform sends a response data packet:

[0115] Platform response generation: The platform sends a response data packet containing its own PKI certificate (including CA signature), dynamic fingerprint (Hash(platform IP + port sequence 6001→6003→6005 generated by the port hopping generation module)), port sequence, timestamp, coordinates, etc. to the electricity meter.

[0116] Electricity meter verifies the certificate: The electricity meter checks whether the platform certificate is issued by a trusted CA and confirms whether it is a legal energy management platform.

[0117] Path fingerprint verification: The electricity meter generates a platform comparison fingerprint based on the platform IP 10.0.0.1 and port sequence 6001→6003→6005. When it is consistent with the platform network fingerprint submitted by the platform, it is confirmed that the path has not been tampered with.

[0118] Timestamp verification: The set timestamp has an error of 10 seconds from the current time. When the device detects that the error between the timestamp and the current time is 5 seconds, the current timestamp is within the allowable range.

[0119] Port synchronization: The electricity meter parses the new port sequence 6001 → 6003 → 6005 and is ready to switch to communication on the new port.

[0120] Port jump trigger:

[0121] Network status monitoring: The adaptive gateway detects an increase in the load of the 5G network slice (bandwidth utilization reaches 80%), triggering a policy adjustment.

[0122] Smart contract execution: The gateway invokes the blockchain smart contract with input parameters: the current bandwidth is 80 Mbps (megabits per second), the number of devices is 1000, and the routing hop count is 3. The smart contract generates a new port sequence 7001 → 7003 → 7005 according to the preset rule (enable lightweight encryption when the bandwidth > 70%) and switches the encryption algorithm to the ChaCha20 encryption algorithm. The new port sequence is broadcast to all nodes in the blockchain for recording.

[0123] Policy synchronization and communication establishment:

[0124] Device - platform synchronization: The electricity meter and the platform obtain the new port 7001 and the ChaCha20 encryption algorithm through the blockchain and update the communication configuration.

[0125] Encrypted data transmission: The electricity meter encrypts the electricity consumption data using ChaCha20 and sends it to the platform through port 7001. For example, for a device numbered Meter_001 with an electricity consumption of 250 kWh, the encrypted electricity consumption data can be represented as {Meter_001:250kWh}.

[0126] Authentication log on - chain:

[0127] Data encapsulation record: The complete record of two - way authentication is encapsulated as a blockchain. For example, when the device ID in the two - way authentication is Meter_001, the platform ID is Platform_Energy, and the port sequence is 5001 → 6001 → 7001, the device ID, platform ID, port sequence, and timestamp can be stored in the Block#7890 block data in the blockchain and recorded. Here, Block#7890 represents the 7890th block in the blockchain.

[0128] Multi - party auditing and traceability:

[0129] Regulatory Inspection: Relevant departments query block Block#7890 through a blockchain browser to verify the communication record of meter Meter_001 using port 7001 at time 2025-02-15T08:05:00Z and coordinates 116.629923, 39.937289, and confirm data integrity.

[0130] The present invention aims to construct an end-to-end trusted communication method for the Internet of Things. Through dynamic network fingerprint binding, two-factor cross-verification, and adaptive security policies, it systematically solves three core problems: defense against side-channel attacks, two-way identity path verification, and dynamic network adaptability. Aiming at the defects of rigid channels, one-way authentication, and one-sided auditing in the prior art, the present invention innovatively dynamically associates physical network characteristics with logical identity credentials, relies on the blockchain to enhance auditing and policy flexibility, and realizes two-way trusted interaction between devices and platforms. The ultimate goal is to provide an efficient and secure solution for Internet of Things communication that can resist complex attacks (such as man-in-the-middle hijacking and side-channel penetration) and adapt to dynamic network environments, promoting the evolution of the Internet of Things from "passive defense" to "active trust".

[0131] In the description of the present application, it should be noted that the terms used here are only for describing specific embodiments and are not intended to limit the exemplary embodiments of the present application. For the convenience of description, the sizes of the various parts shown in the drawings are not drawn in actual proportional relationships. Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, such technologies, methods, and devices should be regarded as part of the authorization specification. In all the examples shown and discussed here, any specific value should be construed as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values. It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.

[0132] It should be noted that in the present application, the term "comprising", "including" or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. It should also be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0133] The above embodiments are provided for those skilled in the art to implement or use the present application. Those skilled in the art can make various modifications or changes to the above embodiments without departing from the application idea of the present application. Therefore, the protection scope of the present application is not limited by the above embodiments, but should be the maximum scope that conforms to the innovative features mentioned in the claims.

Claims

1. A two-way channel authentication communication device based on dynamic network fingerprints, characterized in that, The two-way channel authentication communication device based on dynamic network fingerprints includes: A network fingerprint generation module, which collects the physical network characteristics and logical identity credential information of the current communication status, and generates a device network fingerprint and a platform network fingerprint. The device sends an authentication request data packet including the device network fingerprint and the device certificate to the two-way authentication protocol module, and the platform sends a response data packet including the platform network fingerprint and the platform certificate to the two-way authentication protocol module; A two-way authentication protocol module, which includes a northbound authentication unit and a southbound authentication unit. The northbound authentication unit receives and authenticates the authentication request data packet sent by the device, and the southbound authentication unit receives and authenticates the response data packet sent by the platform; An adaptive verification gateway module, which includes an input unit, a port hopping generation unit, and a policy adjustment unit. The input unit receives the authentication result from the two-way authentication protocol module and collects network environment parameters in real time. The port hopping generation unit generates and updates a dynamic port sequence based on the blockchain smart contract. The policy adjustment unit collects real-time network information and selects an encryption algorithm and a verification strength for transmitting data according to the real-time network information.

2. The two-way channel authentication communication device based on dynamic network fingerprint according to claim 1, wherein The physical network characteristics include the physical characteristic information and spatio-temporal information of the network path of the current communication, and the logical identity credentials include a device certificate and a platform certificate; The physical characteristic information includes an IP address, a port sequence, and a routing hop count; The spatio-temporal information includes a time stamp and coordinates.

3. The two-way channel authentication communication device based on dynamic network fingerprint according to claim 1, characterized in that, The network fingerprint generation module combines the physical network characteristics and logical identity credentials of the device and platform communication through a custom encryption algorithm to generate a device network fingerprint and a platform network fingerprint containing a time stamp.

4. The two-way channel authentication communication device based on dynamic network fingerprints according to claim 3, characterized in that The authentication request data packet includes a device PKI certificate, a dynamic fingerprint containing a time stamp, and coordinate encapsulation.

5. The bi-directional channel authentication communication device based on dynamic network fingerprints according to claim 3, characterized in that, The response data packet includes a platform PKI certificate, a network fingerprint containing a time stamp, a spatial coordinate, and a time coordinate.

6. The two-way channel authentication communication device based on dynamic network fingerprints according to claim 1, wherein The two-way channel authentication communication device based on dynamic network fingerprints further includes a blockchain audit network module, which stores the generated device network fingerprint and platform network fingerprint and the authentication result of the two-way authentication protocol module.

7. A two-way channel authentication communication method based on dynamic network fingerprints, which is implemented by the two-way channel authentication communication device according to any one of claims 1-6. The method includes: Step S101, collecting the physical network characteristics and logical identity credentials of the current communication, and generating a device network fingerprint and a platform network fingerprint; Step S102, the device sends an authentication request data packet including the device network fingerprint and the device certificate to the northbound authentication unit. The platform verifies the authentication request data packet through the northbound authentication unit to verify whether the device certificate is valid and whether the device network fingerprint matches. If it matches, go to step S103; Step S103: The platform sends a response data packet containing the platform network fingerprint and the platform certificate to the southward authentication unit. The device verifies the response data packet through the southward authentication unit to check whether the platform certificate is valid and whether the platform network fingerprint matches. If they match, the two-way authentication passes. Step S104: When the two-way authentication passes, data transmission is entered, and network environment parameters are collected in real time. A dynamic port sequence is generated and updated based on the blockchain smart contract, and the encryption algorithm and verification strength for transmitting data are selected according to the real-time network information.

8. The two-way channel authentication communication method based on dynamic network fingerprint according to claim 7, wherein In step S101, generating the device network fingerprint and the platform device network fingerprint specifically includes: Step S1011: Collect the physical network characteristics and logical identity credential information of the current communication. Step S1012: Bind the physical network characteristics and the logical identity credentials through the hash encryption algorithm to generate the device network fingerprint containing a timestamp and the platform network fingerprint containing a timestamp for the current communication.

9. The two-way channel authentication communication method based on dynamic network fingerprint according to claim 8, characterized in that In step S102, the platform verifies the authentication request data packet through the northward authentication unit, which specifically includes: Step S1021: Certificate legality verification: The platform uses the pre-set CA root certificate to verify whether the device certificate is correct. Step S1022: Dynamic fingerprint comparison: The platform generates a device comparison fingerprint based on the current network path characteristics and compares it with the device network fingerprint submitted by the device. If the fingerprints match, it is confirmed that the device accesses through the authorized path. Among them, during the dynamic fingerprint comparison, the platform verifies the timeliness of the device network fingerprint timestamp. If the fingerprints match within the specified time limit, the dynamic fingerprint comparison is successful.

10. The two-way channel authentication communication method based on dynamic network fingerprints according to claim 8, wherein, In step S103, the device verifies the response data packet through the southward authentication unit, which specifically includes: Step S1031: Platform certificate verification: The device uses the pre-set CA root certificate to verify whether the platform certificate is correct. Step S1032: Path fingerprint verification: The device generates a platform comparison fingerprint based on the network path characteristics in the response data packet and compares it with the platform network fingerprint submitted by the platform. If the fingerprints match, it is confirmed that the platform identity and the communication path have not been tampered with. Step S1033: The device parses the new port sequence sent by the platform and communicates on the new port.

Citation Information

Cited By

  • Multi-protocol adaptive access method of intelligent fusion terminal and related equipment thereof

    CN121644232A