Internet of Things equipment access authentication method for seat attenuation test bench
By constructing a decision tree model and random forest classifier on a seat attenuation test bench, combined with a dynamic verification algorithm and an adaptive authorization mechanism, the dynamic adaptability and security issues of traditional IoT device access authentication methods are solved, and efficient, secure and accurate permission management of device access is achieved.
Patent Information
- Application Number
- CN202510794699.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-14
- Publication Date
- 2025-09-05
AI Technical Summary
Traditional IoT device access authentication methods on seat attenuation test benches suffer from insufficient dynamic adaptability, low security, unrefined authority management, and easy tampering of encrypted access tokens, making it difficult to meet the authentication requirements of devices in different test phases and environmental conditions.
By building a decision tree model based on device behavior data and environmental parameters, combining it with a random forest classifier to intelligently select authentication strategies, using a dynamic verification algorithm to verify initial authentication instructions, generating encrypted access tokens, and dynamically allocating permissions based on the device's historical operation sequence and test bench status parameters, adaptive authentication and high-intensity security are achieved.
It significantly improves the security and operational efficiency of device access, ensures the scientific nature and adaptability of policy selection, and the dynamic verification and adaptive authorization mechanism reduces manual intervention, achieves accurate matching of permissions and device requirements, prevents illegal access, and improves the reliability and operability of the system.
Smart Images

Figure CN120602166A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things device access authentication, and in particular to an Internet of Things device access authentication method for a seat attenuation test bench. Background Art
[0002] With the rapid development of Internet of Things (IoT) technology, the seat attenuation test bench, as an important test equipment, faces many challenges in the access authentication of IoT devices. Traditional IoT device access authentication methods have obvious shortcomings when facing specific scenarios such as seat attenuation test benches. On the one hand, traditional authentication methods often adopt fixed authentication strategies and cannot be dynamically adjusted according to the device's behavioral data and environmental parameters. For example, when the device is connected in different test phases or under different environmental conditions, the fixed strategy is difficult to adapt to actual needs, resulting in low authentication efficiency or insufficient security. On the other hand, traditional methods do not conduct in-depth analysis of device behavior and lack effective use of behavioral data and environmental parameters in the device's historical access logs. It is difficult to accurately judge the legitimacy and credibility of the device, and it is easy to have misauthentication or missed authentication.
[0003] When it comes to verifying and optimizing authentication instructions, traditional technologies lack a dynamic verification mechanism, making it impossible to automatically correct and optimize abnormal parameters in initial authentication instructions. This can lead to security vulnerabilities or parameter conflicts in authentication instructions, impacting the stability and security of device access. In terms of permission management, traditional methods typically use static permission allocation, which cannot dynamically adjust based on multi-dimensional characteristics such as the device's historical operation sequence and test bench status parameters. This makes it difficult to strike a balance between security and operational efficiency, and it cannot meet the differentiated permission requirements of different types of devices.
[0004] Traditional methods for generating encrypted access tokens are relatively simple and lack dynamic processing that incorporates the device's unique identifier, access time range, and environmental parameters. This makes them vulnerable to attacks, leading to token tampering or forgery, which in turn threatens the security of device access. During the triggering and verification phase of the device access process, traditional methods lack sufficient data collection and analysis of real-time data such as device current fluctuation characteristics and communication protocol fingerprints, making it difficult to accurately verify the legitimacy of the device. This can lead to unauthorized device access, compromising the normal operation and data security of the testbed.
[0005] The existing technology has obvious defects in the dynamic adaptability, security, and refined authority management of the access authentication of IoT devices in the seat attenuation test bench. There is an urgent need for an access authentication method that can combine device behavior data and environmental parameters to achieve dynamic authentication strategy selection, intelligent parameter verification, precise authority allocation and high-intensity security protection. Summary of the Invention
[0006] The purpose of the present invention is to provide an Internet of Things device access authentication method for a seat attenuation test bench to solve the problems raised in the above background technology.
[0007] To achieve the above-mentioned object, the present invention provides the following technical solution: a method for authenticating access to an IoT device in a seat attenuation test bench, the method comprising: Obtain the device identifier and authentication request of the IoT device to be connected, where the device identifier includes the device serial number and device type, and the authentication request includes the device function permissions and access time range; extract the registration information corresponding to the device serial number from the device basic information database, and also extract the device behavior data and environmental parameters from the historical access log; Based on device behavior data and environmental parameters, the optimal authentication policy is intelligently selected from the authentication policy library, and the device identifier, registration information, and device behavior data are filled into the corresponding fields of the optimal authentication policy to generate an initial authentication instruction; the initial authentication instruction is verified using a dynamic verification algorithm, and abnormal parameters in the initial authentication instruction are automatically corrected and optimized based on the verification results; Based on the optimized initial authentication instruction, the corresponding device operation permission information is obtained from the dynamic authorization database and filled into the authorization field to generate a complete authentication instruction; the complete authentication instruction is transmitted to the device access gateway to generate an encrypted access token, and the legitimacy of the access token is automatically verified through the device-side parsing module. The device is bound to the test bench operation interface, triggering the device access process and generating a real-time audit log.
[0008] Preferably, the optimal authentication strategy is intelligently selected from the authentication strategy library based on device behavior data and environmental parameters, including: The authentication strategy selection problem is modeled as a behavior-based decision tree model, which includes state nodes, branch actions, and an evaluation function. The state nodes contain device behavior characteristics, and the branch actions are candidate authentication strategy sets. Construct a random forest classifier whose input is the behavior feature vector and output is the confidence score of each authentication strategy; construct a behavior feature dataset, where each record contains the current behavior feature, the selected strategy, the environment feedback, and the next state; A sample set is extracted from the behavioral feature dataset. The policy priority is calculated based on the information gain algorithm. A decision path is constructed based on the priority and confidence score. The decision tree structure is optimized through a pruning algorithm to obtain a trained random forest classifier. A behavioral feature vector is generated based on device behavior data and environmental parameters, and is input into the trained random forest classifier to calculate the confidence score of each candidate authentication strategy. The candidate strategy with the highest score is selected as the optimal authentication strategy.
[0009] Preferably, generating a behavior feature vector based on device behavior data and environmental parameters, inputting the vector into a trained random forest classifier, calculating the confidence score of each candidate authentication strategy, and selecting the candidate strategy with the highest score as the optimal authentication strategy includes: Generate a strategy constraint vector based on the current environment parameters, wherein the constraint vector identifies the feasibility of each candidate strategy; multiply the constraint vector by the confidence score vector output by the classifier element by element to generate a modified score vector; Modeling multi-strategy combinations as branch actions in a decision tree, limiting strategy complexity by setting combination levels, and designing evaluation functions based on combination execution results to enable the classifier to learn the long-term stability of strategy combinations. Based on the stability evaluation of the revised score vector and the policy combination, the policy combination with the highest score is selected as the final decision. When the policy combination takes effect, the policies in the combination are executed in sequence to generate a complete authentication process. Real-time monitoring of device feedback during policy execution. If actual behavior deviates from expectations, the access process is interrupted and the random forest classifier is re-invoked to generate a new decision. A manual intervention mechanism is set up to push alerts and system recommendations to administrators when the confidence level of a new decision is lower than the preset threshold. The policy combination confirmed by the administrator is used as an artificial sample, and the new decision generated by the system is used as an exploration sample. Incremental training sets are added to update classifier parameters to form an adaptive authentication policy selection mechanism.
[0010] Preferably, the method of verifying the initial authentication instruction using a dynamic verification algorithm and automatically correcting and optimizing abnormal parameters in the initial authentication instruction according to the verification result includes: Convert device security specifications into a logical rule base, perform redundancy checks on the rules to obtain a conflict-free rule set; design a rule engine that uses a pattern matching algorithm based on the conflict-free rule set to verify the compliance of initial authentication instructions; Text analysis technology is introduced to perform semantic verification on key fields in instructions, and combined with the device terminology library, spelling errors are corrected and ambiguity is eliminated; Construct a dependency graph of instruction parameters, abstract the logical associations between fields into directed edges, deduce parameter consistency through a graph traversal algorithm, and mine implicit dependencies based on association rules. Integrate the rule engine results, text analysis results, and dependency derivation results to generate a multi-dimensional verification report, locate abnormal parameters, and provide automatic correction solutions.
[0011] Preferably, the generation of a multi-dimensional verification report, locating abnormal parameters and providing an automatic correction solution includes: Construct anomaly annotation dataset based on historical authentication logs; A bidirectional gated recurrent unit is used as a feature extractor, and an attention mechanism and conditional random field layer are integrated to build an end-to-end anomaly localization model. Divide the training set, validation set, and test set, train the model using the gradient descent algorithm, and automatically adjust the parameters in combination with Bayesian optimization; Integrate the trained anomaly location model into the verification process, input multi-dimensional verification results, output the location and type of abnormal parameters, and display them through a visual interface.
[0012] Preferably, the obtaining of corresponding device operation permission information from the dynamic authorization database includes: Extract multi-dimensional behavior pattern features based on the historical operation sequence of the equipment, and construct a spatiotemporal feature matrix based on the test bench state parameters; The spatiotemporal feature matrix is input into the time series prediction model, and the features of different time steps are integrated through the attention mechanism to generate a prediction sequence of future operation permissions; Divide permission levels based on device types, explore key influencing factors at different levels, and build a differentiated authorization rule base; The device identifier is input into the personalized authorization model to predict the probability of device adaptation to permissions, and the optimal permission allocation strategy is generated by combining the differentiated authorization rule base.
[0013] Preferably, generating the optimal authority allocation strategy includes: Taking security and operational efficiency as multi-objective functions, define permission allocation variables and resource constraints; Construct a multi-objective optimization model and use particle swarm optimization algorithm to iteratively solve the Pareto optimal solution set; The optimal permission allocation scheme is filtered through the elite retention strategy and output to the authorization field.
[0014] Preferably, generating an encrypted access token includes: An initial token seed is generated based on the device's unique identifier and access time range. The seed is obfuscated using a lightweight encryption algorithm, and a dynamic salt value is generated based on environmental parameters. The obfuscated seed and dynamic salt value are input into the hash chain iterator, and multiple rounds of irreversible hash operations are performed to generate the token core value. The core value is bound to the device's functional permissions, and a digital signature is generated using an asymmetric encryption algorithm. Finally, an unalterable encrypted access token is output.
[0015] Preferably, the triggering device access process includes: After the legitimacy of the token is verified by the device-side parsing module, the physical switch of the test bench operation interface is activated; the device current fluctuation characteristics and communication protocol fingerprints are collected in real time, and pattern matching is performed with the pre-stored security baseline; if the match is successful, the data transmission channel between the device and the test bench is unlocked, and a two-way encrypted link is established; if the match is abnormal, the fuse mechanism is triggered to isolate the device and generate a security alarm log.
[0016] Preferably, the construction of the dependency graph includes: The instruction parameters are abstracted as nodes, and the logical constraints between parameters are abstracted as directed edges; circular dependencies are detected through a topological sorting algorithm, and subgraph segmentation is performed on conflicting nodes; the implicit association weights between nodes are learned based on a graph neural network, and the parameter consistency probability is derived in combination with a confidence propagation algorithm; conflicting parameters are automatically corrected according to the probability threshold to generate an acyclic dependency graph.
[0017] Compared with the prior art, the present invention has the following beneficial effects: This invention provides an IoT device access authentication method for a seat attenuation test bench. Through intelligent strategy selection, dynamic verification, and adaptive authorization mechanisms, it significantly improves device access security and operational efficiency. This method utilizes device behavior data and environmental parameters to construct a decision tree model, combining it with a random forest classifier to intelligently select the optimal authentication strategy, ensuring the scientific and adaptable nature of the strategy selection. A dynamic verification algorithm verifies initial authentication instructions across multiple dimensions using a logical rule base, text analysis, and dependency graphs. It automatically corrects abnormal parameters, reduces manual intervention, and improves authentication accuracy.
[0018] Based on a spatiotemporal feature matrix constructed from historical operation sequences and testbed state parameters, combined with a time series prediction model and a differentiated authorization rule base, an optimal permission allocation strategy is generated, precisely matching permissions with device requirements. The encrypted access token utilizes a lightweight encryption algorithm and dynamic salt value technology to ensure token immutability and uniqueness, effectively preventing unauthorized access. During the device access process, current fluctuation characteristics and communication protocol fingerprints are collected in real time and matched against the security baseline to quickly identify abnormal behavior and trigger the circuit breaker mechanism, further ensuring system security.
[0019] This method uses an adaptive authentication strategy selection mechanism and incremental training sets to update classifier parameters, continuously optimizing strategic decision-making capabilities and adapting to complex and changing industrial environments. The application of a multi-objective optimization model and particle swarm optimization algorithm balances safety and operational efficiency, improving overall system performance. Furthermore, a visual anomaly location interface and manual intervention mechanism enhance the system's operability and reliability. This invention is not only applicable to seat attenuation test benches but can also be expanded to other industrial IoT scenarios, possessing broad application prospects and promotional value. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 This is a working principle diagram of the IoT device access authentication method for the seat attenuation test bench of the present invention; Figure 2 Design diagram for the optimal authentication strategy selection mechanism; Figure 3 Flowchart for dynamic verification algorithm verification; Figure 4 Flowchart for dynamic authorization database operations; Figure 5 A design diagram for the mechanism for generating encrypted access tokens. DETAILED DESCRIPTION
[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0022] See also Figure 1-Figure 5 As shown, the method for authenticating access to an IoT device of a seat attenuation test bench according to the present invention is specifically implemented in the following steps: The system first obtains the device identifier and authentication request of the IoT device to be connected. Among them, the device identifier includes the device serial number (such as a unique code burned through the device nameplate or chip) and the device type (such as "seat attenuation test bench sensor", "control terminal", etc.); the authentication request includes the device functional permissions (such as data collection, parameter adjustment, etc. permission levels) and access time range (such as access permission within a specified time period). Subsequently, the registration information corresponding to the device serial number (including device manufacturer, firmware version, security certificate, etc.) is extracted from the device basic information database, and the device's behavioral data (such as historical access frequency, operation duration, data transmission volume, etc.) and environmental parameters (such as the network IP address, geographic location, system time, etc. at the time of access) are extracted from the historical access log.
[0023] Authentication strategy selection and instruction generation: Based on acquired device behavior data and environmental parameters, the optimal authentication strategy is intelligently selected from the authentication strategy library. The device identifier, registration information, and device behavior data are entered into the corresponding fields of the optimal authentication strategy to generate initial authentication instructions. For example, if the device is being connected for the first time, a high-security multi-factor authentication strategy may be triggered; if the device is a standard device with normal behavior data, a lightweight authentication process is used.
[0024] A dynamic verification algorithm is used to verify the initial authentication command, for example, verifying the validity of the device security certificate and the compatibility of functional permissions with the device type. Based on the verification results, abnormal parameters in the initial authentication command (such as permissions exceeding the permitted range for the device type, incorrect access time format, etc.) are automatically corrected and optimized to ensure that the command complies with preset security specifications.
[0025] Based on the optimized initial authentication instructions, the corresponding device operation permission information (such as the functional permission breakdown within different time periods) is retrieved from the dynamic authorization database and filled into the authorization field to generate a complete authentication instruction. For example, based on the device's historical operation habits and the test bench's current operating status, its parameter modification permissions within a specific time period can be dynamically adjusted.
[0026] The complete authentication instruction is transmitted to the device access gateway, generating an encrypted access token. The device-side parsing module automatically verifies the legitimacy of the access token (e.g., verifying the token's integrity through a digital signature). Once verified, the device is bound to the testbed's operation interface, triggering the device access process and generating a real-time audit log (recording access time, device status, and operation history).
[0027] Example 1: This example implements the intelligent selection of authentication strategies based on the overall implementation plan. The authentication strategy selection problem is modeled as a behavior-based decision tree model, which includes state nodes, branch actions, and evaluation functions. Among them, the state nodes are used to characterize the behavioral characteristics of the device, specifically covering the historical access frequency of the device, operation duration, data transmission volume, historical access success rate, data transmission stability and other information reflecting the past access and operation status of the device. The branch action is a pre-set set of candidate authentication strategies, for example, including single-factor authentication (such as password authentication only), two-factor authentication (such as password combined with dynamic token authentication), biometric authentication (such as fingerprint or face recognition authentication), and other authentication methods of different complexity and security levels. The evaluation function is used to quantitatively evaluate the execution effect of different authentication strategies to assist the decision tree in selecting the optimal strategy.
[0028] Constructing a random forest classifier is one of the key steps in this embodiment. The input to the classifier is a behavioral feature vector, which is composed of multidimensional features extracted from device behavioral data and environmental parameters. Specifically, behavioral data features may include timestamps (recording the specific time of access operations), access times (access frequency within a specific time period), IP address change frequency (reflecting the stability of the access network environment), and peak data transmission periods (the distribution of time periods with high device data transmission volume). Environmental parameter features may include the network IP address at the time of access, geographic location, system time, network security level (such as low, medium, and high security level network environments), and testbed operation mode (such as normal operation mode and maintenance mode). By combining these multidimensional features, a behavioral feature vector is formed that comprehensively describes the current state of the device. The output of the classifier is the confidence score of each authentication policy, which reflects the classifier's confidence that each candidate authentication policy is applicable to the current device state.
[0029] To train a random forest classifier, a behavioral feature dataset is required. Each record in the dataset contains the current behavioral feature, the selected strategy, environmental feedback, and the next state. The current behavioral feature is a combination of the multidimensional features described above; the selected strategy is the authentication strategy used in practice for that behavioral feature; environmental feedback includes information reflecting the effectiveness of the authentication process, such as authentication time and success; and the next state is the subsequent state of the device after executing the authentication strategy, such as successful access and subsequent operational behavior. By collecting a large number of such records, we generate rich training data, providing a foundation for classifier learning.
[0030] After extracting a sample set from the behavioral feature dataset, policy priorities are calculated based on an information gain algorithm. This algorithm calculates the information gain of different features in policy selection to determine which features have a greater impact on policy selection, thus providing a basis for calculating policy priorities. For example, for high-risk device behaviors (such as frequent changes in access IP addresses or low historical access success rates), the information gain algorithm may prioritize authentication policy complexity, favoring stricter authentication policies to ensure security. Based on the calculated priorities and the confidence scores output by the classifier, a decision path is constructed, describing the logical process from the device's current state features to the final authentication policy selection. To prevent overfitting of the decision tree and improve the model's generalization, a pruning algorithm is used to optimize the decision tree structure, removing redundant branches and ultimately producing a trained random forest classifier.
[0031] When selecting an authentication strategy for a device waiting to connect, the system first generates a behavioral feature vector based on the device's behavioral data and environmental parameters. Specifically, the system collects data such as the device's historical access history and the current network environment in real time, extracting multidimensional features consistent with those used during the training phase and combining them into a behavioral feature vector according to the same rules. This feature vector is then input into a trained random forest classifier, which processes the feature vector using multiple internal decision trees to calculate confidence scores for each candidate authentication strategy. Each decision tree analyzes the feature vector based on its own training experience and assigns a confidence score. The random forest classifier then combines the results of multiple decision trees to obtain the final confidence scores for each candidate strategy. Finally, the system selects the candidate strategy with the highest score as the optimal authentication strategy. For example, if a device's behavioral feature vector has the highest confidence score for two-factor authentication after entering the classifier, the system will select two-factor authentication as the authentication strategy for that device's current access.
[0032] Throughout the intelligent selection of authentication strategies, each step is closely interconnected and coordinated. By modeling the association between device behavior characteristics and authentication strategies, leveraging the powerful classification capabilities of the random forest classifier, and combining optimization methods such as information gain and pruning algorithms, the system can dynamically and intelligently select the most appropriate authentication strategy based on the device's actual state and environmental conditions. This ensures access security while maximizing authentication efficiency, achieving a balance between the two. This data-driven and machine learning-based authentication strategy selection method can adapt to the diverse device types and complex and changing environments in IoT device access scenarios, providing a more flexible, efficient, and secure authentication mechanism for IoT device access to seat attenuation test benches.
[0033] Example 2: This example further optimizes the authentication policy selection process based on Example 1. The specific implementation method is as follows: the system generates a policy constraint vector based on the current environmental parameters. The vector is used to identify the feasibility of each candidate authentication policy. Environmental parameters cover network security levels (such as low, medium, and high security levels), test bed operation modes (such as normal operation, debugging, and maintenance modes), access time periods (such as working hours and non-working hours), etc. For example, when the network security level is "high", the policy constraint vector will mark the single-factor authentication policy that only supports simple encryption as infeasible; if the test bed is in "maintenance mode", the use of remote control authentication policies may be restricted. The policy constraint vector is represented in binary or numerical form, and each element corresponds to a candidate policy. A value of "0" indicates infeasible, "1" indicates feasible, or the degree of restriction is reflected by the size of the value.
[0034] After generating the policy constraint vector, the system multiplies it element-by-element by the confidence score vector output by the random forest classifier to obtain a revised score vector. This operation aims to filter out policies that are infeasible under the constraints and retain only the confidence scores of feasible policies. For example, if a candidate policy's corresponding element in the constraint vector is "0," its score in the confidence score vector will be set to "0," and it will be excluded from subsequent decision-making. This ensures that the ultimately selected authentication policy not only conforms to the device's behavioral characteristics but also meets the security and business rules requirements of the current environment.
[0035] In order to cope with complex authentication requirements, multi-strategy combinations are modeled as branch actions of a decision tree. Multi-strategy combination refers to combining two or more authentication methods in sequence or in parallel, for example, the combination process of "password authentication + dynamic token authentication + device fingerprint authentication". The system limits the complexity of policies by setting the combination level. For example, it stipulates that a maximum of 2 policy combinations are allowed or the combined authentication steps are no more than 3 steps, to avoid low authentication efficiency or reduced user experience due to overly complex policy combinations. At the same time, an evaluation function is designed based on the execution results of the combination. This function evaluates the long-term stability of the policy combination from the dimensions of authentication time, resource usage, and security. For example, the evaluation function will record the average authentication time, success rate, and load impact on the system server of the "password + dynamic token" combination authentication, and through statistical analysis of multiple execution results, it will determine whether the combination is suitable as a long-term authentication strategy.
[0036] Based on the revised score vector and the stability assessment of the strategy combination, the system selects the strategy combination with the highest score as the final decision. The specific process involves traversing all feasible single-strategy and multi-strategy combinations, calculating the revised score (confidence score after considering constraints) for each strategy or combination, and then comprehensively ranking them based on the stability indicators derived from the evaluation function (such as average authentication time less than 5 seconds and success rate greater than 99%). For example, if a single strategy has a revised score of 0.8 and the corresponding stability indicator shows an authentication success rate of 95%, while a two-strategy combination has a revised score of 0.75, but the stability indicator shows a success rate of 99% and a time increase of only 2 seconds, the system may prioritize this two-strategy combination to achieve a balance between score and stability.
[0037] When a policy combination takes effect, the system executes the policies in the combination in sequence to generate a complete authentication process. For example, for the combination of "device fingerprint authentication → dynamic token authentication", the legitimacy of the device is first confirmed through device fingerprint authentication (such as verifying the MAC address, operating system version and other hardware and software features of the access device). If the authentication is successful, the dynamic token sending process is triggered (such as sending a one-time password to the terminal bound to the device). The user completes the secondary authentication after entering the correct token. During the execution process, the system monitors the execution feedback of each step of the policy in real time, including authentication response time, number of user input errors, abnormal device behavior (such as reconnecting after a sudden disconnection), etc. If the actual behavior deviates from expectations, for example, the number of dynamic token input errors exceeds 3 times, or the hardware characteristics are detected to be inconsistent with the registration information during device fingerprint authentication, the system will immediately interrupt the access process and re-call the random forest classifier to generate a new decision to deal with possible security risks or abnormal user operations.
[0038] To enhance the system's adaptability and robustness, a manual intervention mechanism has been implemented. When the confidence level of a newly generated decision (whether a single policy or a combination of policies) falls below a preset threshold (e.g., 70%), the system will notify the administrator with an alert and system recommendations based on historical data and algorithmic analysis. For example, if the classifier's confidence level for the combination of "biometric authentication + USB key authentication" is only 65%, the system will alert the administrator of an anomaly in the device's current behavior and recommend manual review. It will also provide options such as allowing downgrade to two-factor authentication or requiring the user to provide additional identity information. Administrators can then confirm the policy combination based on their actual situation. This confirmation will serve as a manual sample and be added to the incremental training set along with the new decisions (exploratory samples) automatically generated by the system to update the parameters of the random forest classifier. In this way, the system can continuously learn from new scenarios and special cases in real-world applications, gradually optimizing the authentication policy selection model and forming an adaptive authentication policy selection mechanism that will continuously improve authentication accuracy and security over the long term.
[0039] The process of this embodiment closely revolves around "constraint filtering → combined modeling → dynamic monitoring → manual feedback → model iteration." By organically combining environmental constraints, policy combination, real-time monitoring, and manual intervention, this ensures the security and feasibility of the authentication strategy while enabling continuous optimization of the policy selection model through a data-driven approach. This multi-layered optimization mechanism effectively addresses the challenges of dynamic environmental changes and diverse device behaviors in IoT device access scenarios, ensuring that the IoT device access authentication process for the seat attenuation test bench remains efficient, reliable, and secure even under complex conditions.
[0040] Example 3: This example dynamically verifies and optimizes initial authentication instructions. The specific implementation is as follows: The system converts device security specifications (such as industry standards, internal enterprise security protocols, etc.) into a logical rule base, where each rule in the rule base corresponds to a security constraint. For example, "the device serial number must exist in the device basic information base," "the device function permissions must not exceed the permissions corresponding to its device type," and "the access time range must be within the device's validity period." To ensure the consistency and effectiveness of the rule base, the rules must be checked for redundancy, and duplicate or conflicting rules must be removed to obtain a conflict-free rule set. For example, if there are two rules, "Access time must be between 9:00 AM and 5:00 PM on weekdays" and "Access time must be within 1 hour before or after the system time," it is necessary to check whether there is a time interval conflict between the two. If so, manual review and correction are performed to ensure that there are no logical contradictions in the rules within the rule set.
[0041] A rule engine is designed to perform compliance verification on the initial authentication instructions based on a conflict-free rule set. The rule engine uses a pattern matching algorithm, such as forward matching (verifying whether the instruction parameters comply with the rules one by one) or reverse matching (first assuming that there is an exception in the instruction, and then verifying whether the exception is established through the rules). Taking "the device serial number must exist in the device basic information library" as an example, the rule engine will extract the device serial number from the initial authentication instruction and query the device basic information library. If there is matching registration information, the verification passes, otherwise it is judged as an exception. In this way, the rule engine can quickly identify parameters in the instruction that violate security specifications, such as invalid device serial numbers, unauthorized functional permissions, etc.
[0042] To further improve the accuracy of verification, the system introduces text analysis technology to perform semantic verification on key fields in the instructions. Key fields include functional permission descriptions (such as "data collection" and "remote control"), access time format (such as "YYYY-MM-DDHH:MM:SS"), device status descriptions (such as "normal" and "fault"), etc. Text analysis technology is combined with the device terminology library to perform semantic analysis on the fields, correct spelling errors and eliminate ambiguity. For example, if the functional permission field in the instruction is filled in as "data collection", the terminology library can recognize that "collection" is a variant of "collection" and automatically correct it to the standard term; if the "authority level" field contains ambiguous descriptions such as "high level" and "low level", the system can convert it into the corresponding numerical level according to the "authority levels are divided into level 1 (lowest) to level 5 (highest)" defined in the terminology library to ensure the accuracy and consistency of the instruction semantics.
[0043] Constructing a dependency graph for instruction parameters is one of the core steps. First, the parameters in the instruction (such as "device type," "functional permissions," "access time," and "firmware version in registration information") are abstracted as nodes in the graph, and the logical associations between the parameters are abstracted as directed edges. For example, there is a logical constraint between "the device type is a sensor" and "the functional permissions only allow data collection," which can be represented as a directed edge from the "device type" node to the "functional permissions" node, with the constraint "If the device type is a sensor, then the functional permissions must not include parameter adjustments." A topological sorting algorithm is used to detect circular dependencies in the graph, that is, whether there are mutual constraints between parameters (such as node A constraining node B, and node B constraining node A). If a circular dependency is found, subgraph splitting is performed on the conflicting nodes, dividing them into independent subgraphs for processing to avoid logical deadlocks during the verification process.
[0044] In order to mine the implicit associations between parameters, the system learns the implicit association weights between nodes based on graph neural networks. The graph neural network analyzes the feature vectors of the nodes (such as the type of parameters, value range, historical verification results, etc.) and the constraint information of the edges through multi-layer convolution or attention mechanisms, and generates an association weight for each directed edge. The larger the weight value, the stronger the dependency between the parameters. For example, the association weight between the "firmware version" node and the "security certificate validity" node may be high, because low-version firmware may have known vulnerabilities, resulting in an increased risk of security certificate invalidation. Combined with the confidence propagation algorithm, the system uses the association weight to derive the parameter consistency probability, that is, given the value of a parameter, calculate the probability that the value of another parameter meets the constraint conditions. Let the parameter consistency probability calculation formula be:
[0045] in, Indicates that the parameter When the value is known, the parameter The probability that the value meets the constraints; For parameters and The association weight between them; For parameters and An indicator function that indicates whether the value of satisfies the explicit constraint (1 if it does, 0 if it does not); For the parameters The total number of associated parameters. This formula quantifies the dependencies between parameters by combining association weights and explicit constraints, providing data support for consistency checking.
[0046] The system generates a multi-dimensional verification report based on the rule engine verification results, text analysis results, and dependency derivation results. The verification report includes the following: (1) Rule engine verification part: lists the violated security rules, corresponding parameters, and error types (such as "device serial number does not exist" and "authority exceeded"); (2) Text analysis part: marks the fields with spelling errors or semantic ambiguity, the corrected results, and the description of the ambiguity; (3) Dependency verification part: displays the dependency graph segments between parameters, and the parameter pairs with consistency probability lower than the threshold (for example, if the threshold is set to 80%, is marked as an exception) and the exception type (such as "potential permission conflict" or "time format does not match device time zone").
[0047] Based on the multi-dimensional verification report, the system locates abnormal parameters and provides automatic correction solutions. The generation of automatic correction solutions is based on an anomaly annotation dataset constructed from historical authentication logs. This dataset contains the characteristics of various abnormal parameters, common correction methods, and historical correction records. For example, for the anomaly of "device serial number does not exist", if the device has been removed from the registration information due to accidental deletion in the historical records, the system can automatically trigger the re-registration process; for "access time format error", the system can automatically convert the input value according to the preset time format template. To achieve accurate positioning, the system uses a bidirectional gated recurrent unit (Bi-GRU) as a feature extractor, and integrates the attention mechanism and the conditional random field (CRF) layer to build an end-to-end anomaly localization model. The Bi-GRU can capture the contextual dependencies in the parameter sequence, the attention mechanism can focus on key abnormal features, and the CRF layer is used to optimize the prediction results of the label sequence to ensure the accuracy of the abnormal parameter position and type.
[0048] During model training, the anomaly annotated dataset is first divided into training, validation, and test sets. Gradient descent is used to optimize model parameters, and Bayesian optimization is used to automatically adjust hyperparameters (such as the learning rate and hidden layer dimensions) to enhance the model's generalization capabilities. The trained anomaly localization model is integrated into the verification process, which inputs multi-dimensional verification results and outputs the specific location (such as the third field "Function Permission" in the instruction) and type (such as "Semantic Ambiguity" and "Rule Conflict"). This is displayed through a visual interface for intuitive review by the system backend or administrator. For anomalies that cannot be automatically corrected (such as those involving sensitive permission adjustments or unknown device types), the system generates a manual processing ticket, prompting the administrator to intervene and review to ensure the security and reliability of the verification process.
[0049] This embodiment utilizes a multi-dimensional synergy of logical rule verification, text semantic analysis, and parameter dependency modeling, combined with the anomaly location and automatic correction capabilities of machine learning models, to construct a comprehensive and accurate initial certification instruction verification system. This system not only rapidly identifies explicit errors (such as spelling errors and rule conflicts) within instructions, but also uncovers hidden parameter dependency anomalies, effectively improving the compliance and consistency of certification instructions. This provides reliable foundational data for subsequent permission allocation and device access, ensuring that the IoT device access authentication process for the seat attenuation test bench meets security requirements from the instruction generation stage.
[0050] Example 4: This example specifically implements the permission allocation mechanism of the dynamic authorization database. Taking two typical devices of a seat attenuation test bench, namely, a sensor (device A) and a control terminal (device B), as an example, the entire permission allocation process is described in detail: The system extracts multi-dimensional behavioral pattern features based on the device's historical operation sequence. For example, for device A (a certain model of pressure sensor), its historical operation sequence records hourly data collection operations from 8:00 AM to 6:00 PM daily for the past 30 days. Data transmission is concentrated between 10:00 AM and 11:00 AM and 2:00 PM to 3:00 PM, and the IP address used for each access is a fixed address on the testbed's local area network. The system extracts behavioral pattern features, including operation time distribution (e.g., daily operation periods are concentrated during work hours), data transmission peak periods (one peak each in the morning and afternoon), and access IP stability (no fluctuation). Furthermore, the system constructs a spatiotemporal feature matrix based on testbed status parameters (e.g., "normal test" operation phase, "medium load" load status). The rows of the matrix correspond to time points (e.g., divided by hours), and the columns correspond to feature dimensions (e.g., operation frequency, data volume, IP address, test bench load, etc.). Each row records the feature value of the device at that time point. For example, a row may represent "8:00-9:00 period, operation frequency 1 time, data volume 50KB, IP address 192.168.1.10, test bench load 30%."
[0051] For device B (a certain brand of control terminal), its historical operation sequence shows parameter adjustments performed between 9:00 AM and 10:00 AM every Monday, Wednesday, and Friday. Data downloads were also performed before and after these adjustments, and the access IP address alternated between the office network and the testbed's local network. The extracted behavioral features included operation periodicity (fixed weekday mornings), data interaction type (parameter adjustment + data download), and IP address change frequency (twice per week). Combined with testbed status parameters (e.g., "debugging" operation phase and "high load status"), a corresponding spatiotemporal feature matrix was constructed, reflecting the device's operating mode under different spatiotemporal conditions.
[0052] The system inputs the spatiotemporal feature matrix into the time series prediction model. Taking the Long Short-Term Memory (LSTM) network as an example, this model uses multiple layers of neurons to capture long-term dependencies in time series. For device A's spatiotemporal feature matrix, the model learns the regularity of its operation times and data transmissions and generates a sequence of predictions for future operation permissions. For example, it predicts that device A will require high data collection permissions from 10:00 AM to 11:00 AM the next day, but will not require parameter adjustment permissions. For device B, based on its periodic operation pattern, the model predicts that "parameter adjustment" and "data download" permissions will be required from 9:00 AM to 10:00 AM next Monday, and may also require additional network access permissions due to its access to the office network.
[0053] When categorizing permissions based on device type, the system divides devices into three categories: sensors, control terminals, and management terminals, corresponding to permission levels 1, 2, and 3, respectively. Level 1 (sensors) only allows data collection and status query permissions; Level 2 (control terminals) allows intermediate permissions such as parameter adjustment and device startup and shutdown; and Level 3 (management terminals) grants advanced permissions such as system configuration and user management. For example, device A (sensor) has permission level 1. Key influencing factors include the manufacturer's reputation (assessed through historical collaboration records) and the security of the firmware version (whether known vulnerabilities have been patched). Device B (control terminal) has permission level 2. Key influencing factors include not only the manufacturer and firmware version but also the operator's qualifications (which must be associated with a system-authenticated operator account). By analyzing the correlation between these factors and permissions, the system constructs a differentiated authorization rule base. For example, "Functional permissions for Level 1 devices must not include 'parameter modification'" and "Level 2 devices are allowed to temporarily increase the data download bandwidth limit during the test bench debugging phase."
[0054] When device identifiers are input into the personalized authorization model, using a neural network model as an example, the model learns through training the mapping between device characteristics and permissions. For example, if device A's identifier corresponds to the manufacturer "XYZ Company" and firmware version V2.3.1, the model predicts, based on historical data, that it has a 95% probability of being granted the "Data Collection" permission and a 5% probability of being granted the "Remote Control" permission. Device B's identifier corresponds to the manufacturer "ABC Technology," firmware version V3.0.2, and an associated operator account level of "Intermediate," the model predicts an 80% probability of being granted the "Parameter Adjustment" permission and a 30% probability of being granted the "System Restart" permission. Combining this with a differentiated authorization rule base, the system generates a permission allocation policy for device A that only includes the "Data Collection" and "Status Query" permissions. For device B, the system generates a policy that includes the "Parameter Adjustment" and "Data Download" permissions, and additionally grants the "Temporary Advanced Diagnostics" permission for a specific period based on the test bench's current state (e.g., during debugging).
[0055] During the multi-objective optimization process for generating the optimal permission allocation strategy, the system prioritizes security and operational efficiency. Security metrics include the probability of permission overreach (e.g., assigning device A the "parameter modification" permission significantly increases the risk probability) and the risk of data leakage (e.g., the risk of a high-privilege device accessing an untrusted network). Operational efficiency metrics include the time required to obtain permissions (e.g., the impact of multi-level approval processes on efficiency) and task completion rate (e.g., the number of operational interruptions due to insufficient permissions). For example, if device B is assigned the "parameter adjustment" and "data download" permissions, the security risk score is 70 (out of 100, with higher scores indicating lower risk) and the operational efficiency score is 85. However, if the "temporary advanced diagnostics" permission is added, the security risk score drops to 65, while the operational efficiency score increases to 90. The system uses a particle swarm algorithm to iteratively identify a Pareto-optimal solution: one that maximizes operational efficiency without compromising security, or one that improves security with an acceptable loss of efficiency. Ultimately, based on the testbed's current needs (e.g., the urgent need to complete debugging tasks), an elite retention strategy is used to select the solution that allows temporary advanced diagnostic permissions, but restricts them to the local network environment, and outputs it to the authorization field.
[0056] After permissions are assigned, the system monitors device operations in real time to ensure they comply with permission policies. For example, if device A attempts to send a parameter modification command at 3:00 PM on a given day, the system detects that its permissions do not include this function, immediately intercepts the request, and generates an alarm log. Similarly, if device B uses "temporary advanced diagnostics" permissions in a local network environment during the debugging phase, the system verifies that its IP address is within the testbed's local network, allows the operation, and logs it. If device behavior exceeds the scope of permissions or violates temporal and spatial constraints (for example, if device B uses advanced permissions outside of the debugging phase), the system triggers a permission recovery mechanism, suspends the offending permissions, and notifies the administrator for review.
[0057] This embodiment achieves refined management of dynamic authorization through a comprehensive chain of "feature extraction - time series prediction - hierarchical classification - personality modeling - multi-objective optimization." Taking a specific device as an example, the system conducts historical behavior analysis, predicts future permissions, and generates differentiated policies based on device type and environment, demonstrating intelligent and scenario-adaptive authorization allocation. This mechanism not only ensures that devices only receive the minimum permissions required to complete their tasks, reducing security risks, but also dynamically adjusts permissions based on the test bench's operating status, balancing security and business needs. This provides flexible and reliable authorization for IoT device access to the seat attenuation test bench.
[0058] Example 5: This example specifically implements the generation of an encrypted access token and the device access process. Taking the sensor device (device number: ST-20250603-01) and the control terminal (device number: CT-20250603-02) connected to a seat attenuation test bench as an example, the operation logic and interaction details of each link are explained in detail.
[0059] When generating an encrypted access token, the system generates an initial token seed based on the device's unique identifier and the access time range. For example, for device ST-20250603-01, its unique identifier is a combination of the device serial number (ST-20250603-01) and MAC address (00:1A:2B:3C:4D:5E), and the access time range is June 3, 2025, 9:00 AM to 5:00 PM. The system concatenates this information into the string "ST-20250603-01|00:1A:2B:3C:4D:5E|202506030900-1700," which serves as the initial seed. The seed is then obfuscated using a lightweight encryption algorithm, such as AES-128, and encrypted with a preset system key (a 128-bit random string). This produces the obfuscated seed data. At the same time, a dynamic salt value is generated based on environmental parameters. The environmental parameters include the current timestamp (2025-06-03 09:05:12) and a randomly generated 8-bit salt factor (such as "X7zQ4pN2"). The two are combined to form "20250603090512X7zQ4pN2" as the dynamic salt value.
[0060] The obfuscated seed and dynamic salt are input into the hash chain iterator, which performs multiple rounds of irreversible hashing. Using the SHA-256 algorithm as an example, the obfuscated seed and dynamic salt are first concatenated to generate the input string. Three iterative hashing operations are then performed: the first operation produces a 32-byte hash value, H1; the second, using H1 as input, produces H2; and the third, using H2 as input, produces H3. Finally, H3 serves as the token's core value. For example, suppose H3 after one operation is "a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6." The system then binds the core value to the device's functional permissions. For device ST-20250603-01, the functional permission is "Data Collection." The permission identifier "DATA_COLLECT" is concatenated with the core value, and a digital signature is generated using an asymmetric encryption algorithm (such as RSA). The specific process is: use the private key to encrypt the concatenated string to obtain the digital signature "sig_12345". The final output encrypted access token is "H3|DATA_COLLECT|sig_12345", which contains the core value, permission information and signature and is tamper-proof.
[0061] When device ST-20250603-01 initiates an access request, the system transmits the complete authentication instructions to the device access gateway, generates the aforementioned encrypted token, and sends it to the device. Upon receiving the token, the device parsing module first verifies its legitimacy: it decrypts the digital signature using the public key to obtain the original concatenated string. It then compares the core value within the string with the one generated locally using the same algorithm. It also checks whether the access timestamp is within the preset time range (9:00-17:00). If verification passes, the physical switch on the test bench's operating interface is activated, for example, by controlling a relay to connect a sensor to the test bench's data interface.
[0062] Real-time acquisition of device current fluctuation characteristics and communication protocol fingerprints is a key verification step in the access process. Taking the ST-20250603-01 device as an example, its current fluctuation range during normal operation is 4-20mA. The communication protocol uses the MQTT protocol, and the packet header features a fixed "0x100x020x000x05" format. The system uses a current sensor to monitor the device current in real time. If the current is stable at around 10mA (normal acquisition status) and the communication data is parsed and the packet header conforms to the MQTT protocol specification, the system determines that the match is successful. At this point, the system unlocks the data transmission channel between the device and the test bench, establishing a two-way encrypted link. For example, the transmitted data is encrypted using the TLS1.3 protocol to ensure that the pressure data collected by the sensor cannot be eavesdropped or tampered with during transmission.
[0063] If a mismatch occurs, for example, for device CT-20250603-02, whose communication protocol fingerprint displays HTTP (instead of the default Modbus protocol) upon connection, the system immediately triggers a fuse mechanism: the device's network connection to the testbed is severed, the power to the physical interface is turned off, and a security alert log is generated, recording the anomaly type (protocol anomaly), device ID (CT-20250603-02), and time (2025-06-03 10:15:30). Administrators can use the log query function to trace the anomaly and determine whether it represents a device failure or a malicious attack, allowing them to take appropriate action.
[0064] After a device is successfully connected, the system continuously monitors its operating status. For example, if device CT-20250603-02 sends a parameter adjustment command after connection, the system verifies that the command complies with its permissions (the control terminal allows parameter adjustment) and rechecks that the communication protocol fingerprint continues to match. If a device is suddenly disconnected and reconnected during the connection process, the system re-executes the token verification, current signature collection, and protocol fingerprint matching processes to ensure the legitimacy and security of each connection.
[0065] The process of this embodiment uses the access process of a specific device as a clue, and shows in detail the entire chain of operations from the various encryption steps of token generation to the legitimacy verification, physical interface activation, real-time feature matching and exception handling on the device side. By combining the unique identification of the device, dynamic environmental parameters and multi-layer encryption algorithms, the security and uniqueness of the access token are ensured; through the dual verification of current characteristics and protocol fingerprints, dual confirmation of the device entity and communication behavior is achieved, effectively preventing illegal devices from counterfeiting or malicious access. This mechanism not only meets the security requirements of the seat attenuation test bench for device access, but also improves access efficiency through automated processes, ensuring the stable operation of the test bench in various device access scenarios.
[0066] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0067] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A method for authenticating access to an IoT device in a seat attenuation test bench, characterized in that: include: Obtain the device identifier and authentication request of the IoT device to be connected, where the device identifier includes the device serial number and device type, and the authentication request includes the device function permissions and access time range; extract the registration information corresponding to the device serial number from the device basic information database, and also extract the device behavior data and environmental parameters from the historical access log; Based on device behavior data and environmental parameters, the optimal authentication policy is intelligently selected from the authentication policy library, and the device identifier, registration information, and device behavior data are filled into the corresponding fields of the optimal authentication policy to generate an initial authentication instruction; the initial authentication instruction is verified using a dynamic verification algorithm, and abnormal parameters in the initial authentication instruction are automatically corrected and optimized based on the verification results; Based on the optimized initial authentication instruction, the corresponding device operation permission information is obtained from the dynamic authorization database and filled into the authorization field to generate a complete authentication instruction; the complete authentication instruction is transmitted to the device access gateway to generate an encrypted access token, and the legitimacy of the access token is automatically verified through the device-side parsing module. The device is bound to the test bench operation interface, triggering the device access process and generating a real-time audit log.
2. The Internet of Things device access authentication method for a seat attenuation test bench according to claim 1 is characterized in that: Intelligently select the optimal authentication policy from the authentication policy library based on device behavior data and environmental parameters, including: The authentication strategy selection problem is modeled as a behavior-based decision tree model, which includes state nodes, branch actions, and an evaluation function. The state nodes contain device behavior characteristics, and the branch actions are candidate authentication strategy sets. Construct a random forest classifier whose input is the behavior feature vector and output is the confidence score of each authentication strategy; construct a behavior feature dataset, where each record contains the current behavior feature, the selected strategy, the environment feedback, and the next state; A sample set is extracted from the behavioral feature dataset. The policy priority is calculated based on the information gain algorithm. A decision path is constructed based on the priority and confidence score. The decision tree structure is optimized through a pruning algorithm to obtain a trained random forest classifier. A behavioral feature vector is generated based on device behavior data and environmental parameters, and is input into the trained random forest classifier to calculate the confidence score of each candidate authentication strategy. The candidate strategy with the highest score is selected as the optimal authentication strategy.
3. The Internet of Things device access authentication method for a seat attenuation test bench according to claim 2 is characterized in that: The process of generating a behavior feature vector based on device behavior data and environmental parameters, inputting the vector into a trained random forest classifier, calculating the confidence score of each candidate authentication strategy, and selecting the candidate strategy with the highest score as the optimal authentication strategy includes: Generate a strategy constraint vector based on the current environment parameters, wherein the constraint vector identifies the feasibility of each candidate strategy; multiply the constraint vector by the confidence score vector output by the classifier element by element to generate a modified score vector; Modeling multi-strategy combinations as branch actions in a decision tree, limiting strategy complexity by setting combination levels, and designing evaluation functions based on combination execution results to enable the classifier to learn the long-term stability of strategy combinations. Based on the stability evaluation of the revised score vector and the policy combination, the policy combination with the highest score is selected as the final decision. When the policy combination takes effect, the policies in the combination are executed in sequence to generate a complete authentication process. Real-time monitoring of device feedback during policy execution. If actual behavior deviates from expectations, the access process is interrupted and the random forest classifier is re-invoked to generate a new decision. A manual intervention mechanism is set up to push alerts and system recommendations to administrators when the confidence level of a new decision is lower than the preset threshold. The policy combination confirmed by the administrator is used as an artificial sample, and the new decision generated by the system is used as an exploration sample. Incremental training sets are added to update classifier parameters to form an adaptive authentication policy selection mechanism.
4. The method for authenticating access to an IoT device for a seat attenuation test bench according to claim 1, wherein: The method of verifying the initial authentication instruction by using a dynamic verification algorithm and automatically correcting and optimizing abnormal parameters in the initial authentication instruction according to the verification result includes: Convert device security specifications into a logical rule base, perform redundancy checks on the rules to obtain a conflict-free rule set; design a rule engine that uses a pattern matching algorithm based on the conflict-free rule set to verify the compliance of initial authentication instructions; Text analysis technology is introduced to perform semantic verification on key fields in instructions, and combined with the device terminology library, spelling errors are corrected and ambiguity is eliminated; Construct a dependency graph of instruction parameters, abstract the logical associations between fields into directed edges, deduce parameter consistency through a graph traversal algorithm, and mine implicit dependencies based on association rules. Integrate the rule engine results, text analysis results, and dependency derivation results to generate a multi-dimensional verification report, locate abnormal parameters, and provide automatic correction solutions.
5. The method for authenticating access to an IoT device for a seat attenuation test bench according to claim 4 is characterized in that: The multi-dimensional verification report is generated to locate abnormal parameters and provide automatic correction solutions, including: Construct anomaly annotation dataset based on historical authentication logs; A bidirectional gated recurrent unit is used as a feature extractor, and an attention mechanism and conditional random field layer are integrated to build an end-to-end anomaly localization model. Divide the training set, validation set, and test set, train the model using the gradient descent algorithm, and automatically adjust the parameters in combination with Bayesian optimization; Integrate the trained anomaly location model into the verification process, input multi-dimensional verification results, output the location and type of abnormal parameters, and display them through a visual interface.
6. The Internet of Things device access authentication method for a seat attenuation test bench according to claim 1 is characterized in that: The obtaining of corresponding device operation permission information from the dynamic authorization database includes: Extract multi-dimensional behavior pattern features based on the historical operation sequence of the equipment, and construct a spatiotemporal feature matrix based on the test bench state parameters; The spatiotemporal feature matrix is input into the time series prediction model, and the features of different time steps are integrated through the attention mechanism to generate a prediction sequence of future operation permissions; Divide permission levels based on device types, explore key influencing factors at different levels, and build a differentiated authorization rule base; The device identifier is input into the personalized authorization model to predict the probability of device adaptation to permissions, and the optimal permission allocation strategy is generated by combining the differentiated authorization rule base.
7. The method for authenticating access to an IoT device for a seat attenuation test bench according to claim 6, wherein: Generating the optimal authority allocation strategy includes: Taking security and operational efficiency as multi-objective functions, define permission allocation variables and resource constraints; Construct a multi-objective optimization model and use particle swarm optimization algorithm to iteratively solve the Pareto optimal solution set; The optimal permission allocation scheme is filtered through the elite retention strategy and output to the authorization field.
8. The Internet of Things device access authentication method for a seat attenuation test bench according to claim 1 is characterized in that: Generating an encrypted access token includes: An initial token seed is generated based on the device's unique identifier and access time range. The seed is obfuscated using a lightweight encryption algorithm, and a dynamic salt value is generated based on environmental parameters. The obfuscated seed and dynamic salt value are input into the hash chain iterator, and multiple rounds of irreversible hash operations are performed to generate the token core value. The core value is bound to the device's functional permissions, and a digital signature is generated using an asymmetric encryption algorithm. Finally, an unalterable encrypted access token is output.
9. The Internet of Things device access authentication method for a seat attenuation test bench according to claim 1 is characterized in that: The trigger device access process includes: After the legitimacy of the token is verified by the device-side parsing module, the physical switch of the test bench operation interface is activated; the device current fluctuation characteristics and communication protocol fingerprints are collected in real time, and pattern matching is performed with the pre-stored security baseline; if the match is successful, the data transmission channel between the device and the test bench is unlocked, and a two-way encrypted link is established; if the match is abnormal, the fuse mechanism is triggered to isolate the device and generate a security alarm log.
10. The Internet of Things device access authentication method for a seat attenuation test bench according to claim 4, characterized in that: The construction of the dependency graph includes: The instruction parameters are abstracted as nodes, and the logical constraints between parameters are abstracted as directed edges; circular dependencies are detected through a topological sorting algorithm, and subgraph segmentation is performed on conflicting nodes; the implicit association weights between nodes are learned based on a graph neural network, and the parameter consistency probability is derived in combination with a confidence propagation algorithm; conflicting parameters are automatically corrected according to the probability threshold to generate an acyclic dependency graph.
Citation Information
Patent Citations
Safe access method, device and equipment for Internet of Things equipment and medium
CN114268508A
Self-service terminal login state monitoring and active safety protection method
CN117992941A
Supply chain supervision rule conflict detection method based on topological sorting and constraint solution
CN118586496A
Jewelry inventory management authentication method and system based on multi-modal data identification
CN118587780A
Internet of Things authentication method and system
CN119652603A
Cited By
Intelligent unmanned equipment-oriented instruction security reinforcement system and verification method
CN122160201A