Multi-level password authentication method and system for industrial internet
By collecting device hardware characteristics, network access identifiers, and biometric features to generate dynamic initial keys, and disassembling subkeys according to hierarchical security weights, and performing cross-verification in conjunction with operational scenario information, the system solves the problems of insufficient security and timeliness of traditional multi-level cryptographic authentication in the industrial internet, and achieves enhanced uniqueness and security of identity binding.
Patent Information
- Application Number
- CN202511608439.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-05
- Publication Date
- 2025-12-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional industrial internet multi-level cryptographic authentication has a single dimension and lacks feature integrity verification, making it prone to identity forgery and data tampering risks. Key management is disordered and static, resulting in insufficient security and timeliness.
The system collects the device hardware characteristics, network access identifiers, and biometric characteristics of the entity to be authenticated in the industrial internet, generates a dynamic initial key, decomposes it into sub-keys according to hierarchical security weights, performs cross-validation in conjunction with operational scenario information, records authentication behavior logs, and dynamically adjusts access permissions.
It enhances the uniqueness and security of identity binding, adapts to the needs of multi-level architectures, accurately identifies authentication risks, and ensures the security, adaptability, and traceability of industrial internet authentication.
Smart Images

Figure CN121125340A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial internet, in particular to a multi-level password authentication method and system for industrial internet. BACKGROUND
[0002] Multi-level password authentication technology is a security protection means developed on the basis of traditional single password authentication, which improves the security of identity verification by integrating multi-dimensional and independent verification links. It usually includes knowledge layer, possession layer, biological layer and other layers, and users need to pass through multiple layers of verification in sequence or combination to complete identity confirmation. This technology can effectively resist the risk of single authentication link being cracked and reduce the probability of account theft.
[0003] Invention patent application No. 201110000415.5 discloses a multi-level directory-based password authentication method, which aims to solve the problem of "if the multi-level directory structure is intercepted by illegal users, the user password can be easily known according to the user's selected path, and there is a certain security risk".
[0004] However, the traditional multi-level password authentication of industrial internet has single dimension, relies only on single identification and has no feature integrity check, which is easy to cause identity forgery and data tampering risk. In addition, the key management under the multi-level architecture is easy to be disordered, and the keys are mostly static, the synchronization mechanism of each level is missing after updating, which leads to insufficient security and timeliness.
[0005] Therefore, we propose a multi-level password authentication method and system for industrial internet. SUMMARY
[0006] In view of the above shortcomings of the prior art, the present application provides a multi-level password authentication method and system for industrial internet, which can effectively solve the problems of the prior art.
[0007] To achieve the above purpose, the present application is realized by the following technical scheme;
[0008] The present application discloses a multi-level password authentication system for industrial internet, which comprises:
[0009] The collection module is used for collecting device hardware features, network access identification and operation subject biological feature information of a subject to be authenticated in the industrial internet, to form a three-dimensional identity basic data set of the subject to be authenticated; the generation module is used for receiving the three-dimensional identity basic data set, and applying the data set to generate a dynamic initial key bound with the identity of the subject to be authenticated; the distribution module is used for disassembling the dynamic initial key into sub-keys corresponding to the hierarchical architecture of the industrial internet according to the hierarchical architecture of the industrial internet, and distributing the sub-keys to authentication nodes of each level; the authentication module is used for receiving a sub-key verification request fed back by each level authentication node, cross-verifying each level sub-key in combination with current operation scene information of the subject to be authenticated, and judging authentication consistency; the tracing module is used for recording identity data set, key generation parameter, verification result and operation node information in each authentication process, and establishing an authentication behavior log; and the adaptation module is used for receiving a result of cross-verification, synchronously sending an authority adaptation instruction to resource nodes of each level of the industrial internet, and adjusting an access range and operation authority of the subject to be authenticated to corresponding level resources.
[0010] The collection module is connected with the generation module through wireless network interaction, the generation module is connected with the distribution module and the authentication module through wireless network interaction, the authentication module is connected with the tracing module through wireless network interaction, and the tracing module is connected with the adaptation module through wireless network interaction.
[0011] Further, the collection module runs the three-dimensional identity basic data set of the subject to be authenticated collected and includes:
[0012] Device hardware features: chip unique identification of an industrial device, device sensor firmware version number and device hardware interface configuration parameter, wherein the industrial device chip unique identification selects any one of a CPU serial number and a FPGA chip ID;
[0013] Network access identification: a binding combination of a physical address and a network protocol address of an industrial internet terminal, and additional device identification of a network access gateway;
[0014] Operation subject biological feature information: a fingerprint feature template or an iris feature code of an operation subject.
[0015] Further, the generation module runs a process of generating a dynamic initial key, and the process includes the following steps.
[0016] Hash operation is performed on the device hardware features, network access identification and operation subject biological feature information in the three-dimensional identity basic data set respectively, to obtain a device feature hash value, a network identification hash value and a biological feature hash value;
[0017] A timestamp of a millisecond-level current collection operation completion time is acquired, and a dynamic initial key is obtained:
[0018] ;
[0019] In the formula: It is a collision-resistant hash function; These include device feature hash values, network identifier hash values, and biometric hash values. The timestamp of the moment the current data collection operation was completed; The root key pre-configured for the system; Preset to large prime numbers; Represents the modular multiplication operator; This represents the modulo operator;
[0020] The collision-resistant hash function is:
[0021] ;
[0022] In the formula: For the input data string, i.e. The splicing result; Pre-set an initial vector for the system; It is the XOR operator; This is a fixed-length data block after M is padded; It is a nonlinear permutation function; This represents the number of iteration rounds. Let i be the round function for the i-th round; The hash value length is set to 256 bits by default.
[0023] in, ;
[0024] In the formula: Preset block length; for The An 8-bit sub-segment; To The result of truncating the first 16 bits of the i-th block of data after performing SHA-3-256 operation; In the original byte sub-block sequence, the sequence number is An 8-bit byte sub-block, m=8, then Represented as x= in 8-bit bytes Perform a reverse flip. The 7th bit value, either 0 or 1. Similarly, that is: = .
[0025] Furthermore, when the distribution module decomposes the dynamic initial key into corresponding level sub-keys and distributes the sub-keys to each level of authentication nodes, it follows the following rules:
[0026] Configure hierarchical security weights for the device layer, edge layer, and platform layer of the Industrial Internet. Let j=1 correspond to the device layer, j=2 to the edge layer, and j=3 to the platform layer, and > > Furthermore, the weight values are preset based on the security protection requirements of each level;
[0027] Each level generates an independent and one-to-one random number, which is generated by the random number generator built into the distribution module;
[0028] Calculate subkeys at each level ;
[0029] In the formula: This is the subkey for the j-th level; A dynamic initial key; A random number configured for the j-th level;
[0030] The distribution process is a hierarchical progression from the platform layer to the edge layer and from the edge layer to the device layer. The distribution module first sends the corresponding level subkey to the platform layer authentication node. Then, the platform layer authentication node verifies the validity of its own subkey and distributes the edge layer subkey to the edge layer authentication node. Finally, the edge layer authentication node distributes the device layer subkey to the device layer authentication node. Each level of distribution requires the receiving node to provide feedback confirmation information.
[0031] Furthermore, the authentication module, in conjunction with the current operation scenario information of the entity to be authenticated, performs cross-validation on the sub-keys at each level and determines the authentication consistency through the following steps:
[0032] Step 1: Collect information on the current operation scenario of the entity to be authenticated, including the operation type (such as data reading, parameter configuration, firmware upgrade), operation object, and scenario risk level;
[0033] Step 2: Configure a scenario risk coefficient for each level. The scenario risk coefficient configured for each level follows the rule that the higher the current scenario risk level and the greater the impact of the scenario on the level, the larger the coefficient.
[0034] Step 3: Receive the subkey verification results from each level of authentication nodes, and quantify the verification results into subkey verification scores: if the subkey is completely matched and has not been tampered with, the score is 1; if the subkey is partially matched, the score is between 0 and 1, and is determined based on the ratio of the matched subkey to the total number of subkeys; if the subkey is not matched, the score is 0.
[0035] Step 4: Quantify the total score , These are the subkey verification score and scenario risk coefficient for the q-th level, respectively.
[0036] Step 5: If If the value is not less than the preset authentication threshold, then the cross-validation of sub-keys at each level is determined to be consistent; if... If the value is less than the preset authentication threshold, the verification is deemed inconsistent, and an anomaly warning is triggered.
[0037] Furthermore, when establishing the authentication behavior log, the traceability module follows the following rules:
[0038] The authentication behavior log includes: hash digest of the 3D identity base dataset, dynamic initial key generation parameters, subkey verification results at each level, total cross-validation score, operation node ID identifier, and log generation timestamp;
[0039] In daily management, the authentication behavior logs are queried using the built-in log query mechanism of the traceability module.
[0040] It supports initiating queries by subject or level to be authenticated, and only authorized authentication nodes can initiate query operations; each query operation is recorded as an independent log entry in the authentication behavior log, including the query node identifier, query conditions and query time.
[0041] Furthermore, the adaptation module sends permission adaptation instructions to resource nodes at all levels of the industrial internet to adjust the access scope and operation permission stage of the subject to be authenticated, and establishes a permission adjustment mapping relationship based on the total cross-validation score and the risk level of the current operation scenario.
[0042] If V is not less than the preset high permission threshold, the entity to be authenticated is allowed to access all resources at the corresponding level. If V is between the preset medium permission threshold and the preset high permission threshold, including the preset medium permission threshold, the entity to be authenticated is only allowed to access the core business resources at the corresponding level, including key sensor data at the device layer, specified computing task resources at the edge layer, and read-only databases at the platform layer. If V is less than the preset medium permission threshold, the access scope of the entity to be authenticated is restricted, and it is only allowed to access basic status resources, including device online status at the device layer, node health status at the edge layer, and public data at the platform layer.
[0043] The time limit for operation permissions is set synchronously based on V. The higher the V, the longer the time limit for permissions.
[0044] On the other hand, multi-level cryptographic authentication methods for the Industrial Internet include:
[0045] The system collects the device hardware characteristics, network access identifiers, and biometric features of the entity to be authenticated in the Industrial Internet to form a three-dimensional identity base dataset. Collision-resistant hashing is performed on each feature of the three-dimensional identity base dataset. Combined with the millisecond-level timestamp at the time of data collection completion, the system's pre-configured root key, and a preset large prime number, a dynamic initial key bound to the identity of the entity to be authenticated is generated. Hierarchical security weights and independent random numbers are configured for the Industrial Internet device layer, edge layer, and platform layer. Sub-keys for each layer are calculated and distributed sequentially, with real-time confirmation feedback from receiving nodes during the distribution process. The system collects the current operating scenario information of the entity to be authenticated and configures the scenario risk coefficients for each layer. Sub-key verification results are received and quantified to further calculate the total score. If the score is not less than a preset authentication threshold, the verification is considered successful; otherwise, a preset abnormality warning is triggered. The system records the hash digest of the three-dimensional identity base dataset, key generation parameters, verification results, and operating node information for each authentication, establishing an authentication behavior log. Based on the total cross-validation score and scenario risk level, permission adaptation instructions are sent to adjust the access scope and operating permissions of the entity to be authenticated.
[0046] Compared with the known prior art, the technical solution provided by this invention has the following beneficial effects:
[0047] This invention provides a multi-level cryptographic authentication method and system for the Industrial Internet. During execution, this method and system collect three-dimensional identity data of the entity to be authenticated, including device hardware characteristics, network access identifiers, and biometric features of the operator. This data is then combined with a timestamp and a root key to generate a dynamic initial key, which is updated in real-time as the identity data changes, enhancing the uniqueness and security of identity binding. Furthermore, the key is decomposed according to security weights configured at the device, edge, and platform layers and distributed in a hierarchical manner to adapt to the security requirements of a multi-level architecture. Simultaneously, the sub-keys at each level are cross-validated using operational scenario information. Consistency is judged through quantitative scoring, accurately identifying authentication risks. Key information during the authentication process is recorded to establish a queryable authentication behavior log, and query operation records are retained for traceability. Finally, the resource access scope and operation permissions of the entity to be authenticated are adjusted based on the verification score and scenario risk level, with synchronized setting of permission expiration times for dynamic adaptation. The key update trigger conditions and hierarchical synchronization mechanism are clearly defined to ensure the continuous validity of the key, comprehensively guaranteeing the security, adaptability, and traceability of Industrial Internet authentication. Attached Figure Description
[0048] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0049] Figure 1 A schematic diagram of the structure of a multi-level cryptographic authentication system for the Industrial Internet;
[0050] Figure 2 This is a flowchart illustrating a multi-level cryptographic authentication method for the Industrial Internet. Detailed Implementation
[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0052] The present invention will be further described below with reference to embodiments.
[0053] Example 1:
[0054] This embodiment presents a multi-level cryptographic authentication system for the Industrial Internet, such as... Figure 1 As shown, it includes:
[0055] The data acquisition module is used to collect the device hardware characteristics, network access identifiers, and biometric information of the entities to be authenticated in the Industrial Internet, forming a three-dimensional identity basic dataset of the entities to be authenticated.
[0056] The dataset of 3D identities of the subjects to be authenticated, collected by the acquisition module, includes:
[0057] Equipment hardware features: unique chip identifier of industrial equipment, firmware version number of equipment sensors and configuration parameters of equipment hardware interfaces. The unique chip identifier of industrial equipment can be either CPU serial number or FPGA chip ID.
[0058] Network access identifier: It adopts the combination of the physical address and network protocol address of the industrial Internet terminal, and adds the device identifier of the network access gateway;
[0059] Biometric information of the operator: fingerprint feature template or iris feature code of the operator;
[0060] During the acquisition process, the acquisition module simultaneously performs integrity verification on each type of feature information. After the verification is passed, the three-dimensional identity basic dataset is formed. The integrity verification method is to compare the hash value of the feature information with the preset baseline hash value. If the comparison is consistent, the verification is deemed to have passed.
[0061] The generation module is used to receive the three-dimensional identity basic dataset and use the dataset to generate a dynamic initial key that is bound to the identity of the subject to be authenticated.
[0062] During the generation module's runtime phase, the process for generating a dynamic initial key is as follows:
[0063] Hash operations are performed on the device hardware features, network access identifiers, and biometric information of the operating subject in the three-dimensional identity basic dataset to obtain device feature hash values, network identifier hash values, and biometric hash values. The hash operation adopts a collision-resistant hash algorithm.
[0064] Obtain the timestamp of the current data acquisition operation completion time in milliseconds, and calculate the dynamic initial key:
[0065] ;
[0066] In the formula: It is a collision-resistant hash function; These include device feature hash values, network identifier hash values, and biometric hash values. The timestamp of the moment the current data collection operation was completed; The root key pre-configured for the system; Preset to large prime numbers; Represents the modular multiplication operator; This represents the modulo operator;
[0067] The above formula performs anti-collision hashing operations on the device hardware features, network access identifiers, and biometric information of the operating subject in the three-dimensional identity basic dataset to obtain three types of hash values. Then, it introduces millisecond-level timestamps, system pre-configured root keys, and preset large prime numbers, and uses modular multiplication and modulo operations to generate dynamic initial keys. This design deeply integrates core identity information, real-time time factors, and fixed security parameters of the system, which can ensure that the key is strongly bound to the identity of the subject to be authenticated and is updated in real time as the identity dataset changes and time progresses. It effectively resists replay attacks and identity forgery. At the same time, the application of anti-collision hashing algorithm avoids the risk of different identity information generating the same hash value, thereby improving the uniqueness and security of the key.
[0068] The collision-resistant hash function is:
[0069] ;
[0070] In the formula: For the input data string, i.e. The splicing result; Pre-set an initial vector for the system; It is the XOR operator; For a fixed-length data block after padding M, the padding logic is to append a length flag bit to the end of M so that the total length is an integer multiple of the preset block length; It is a nonlinear permutation function; This represents the number of iteration rounds. Let i be the round function for the i-th round; The hash value length is set to 256 bits by default.
[0071] The above formula uses the concatenated hash values of the three-dimensional identity basic data as the input data string. Combined with the system's preset initial vector, the input data string is first padded to make its total length an integer multiple of the preset block length. Then, through nonlinear permutation functions and multiple rounds of iterative round functions, the hash value length is finally limited to 256 bits to generate the hash result. This formula ensures the uniformity of the input data format through data padding, meets the requirements of iterative operation, and enhances the anti-cracking ability of the hash result through nonlinear permutation functions and multiple rounds of iteration. The 256-bit hash value length ensures security while taking into account the system's computational efficiency. It is also consistent with the anti-collision hash algorithm used in the dynamic initial key calculation, ensuring the continuity and security of the entire key generation process.
[0072] in, ;
[0073] In the formula: Preset block length; for The An 8-bit sub-segment; To The result of truncating the first 16 bits of the i-th block of data after performing SHA-3-256 operation; In the original byte sub-block sequence, the sequence number is An 8-bit byte sub-block, m=8, then Represented as x= in 8-bit bytes Perform a reverse flip. The 7th bit value, either 0 or 1. Similarly, that is: = ;
[0074] Among them, the collision-resistant hashing algorithm used to determine the device feature hash value, network identifier hash value, and biometric feature hash value is the same as the collision-resistant hashing algorithm used in the dynamic initial key acquisition stage;
[0075] The distribution module is used to break down the dynamic initial key into subkeys of the corresponding level according to the hierarchical architecture of the Industrial Internet, and distribute the subkeys to the authentication nodes at each level.
[0076] When the distribution module decomposes the dynamic initial key into corresponding level subkeys and distributes the subkeys to each level of authentication nodes, it follows the following rules:
[0077] Configure hierarchical security weights for the device layer, edge layer, and platform layer of the Industrial Internet. Let j=1 correspond to the device layer, j=2 to the edge layer, and j=3 to the platform layer, and > > Furthermore, the weight values are preset based on the security protection requirements of each level;
[0078] Generate independent and one-to-one random numbers for each level. The random numbers are generated by the random number generator built into the distribution module.
[0079] Calculate subkeys at each level ;
[0080] In the formula: This is the subkey for the j-th level; A dynamic initial key; A random number configured for the j-th level;
[0081] The above formula obtains subkeys for each level by operating on a dynamic initial key, corresponding level random numbers, and level security weights, so that the subkeys are precisely matched with the security requirements of the corresponding level. The platform layer, edge layer, and device layer form subkeys with different security levels due to weight differences. At the same time, the introduction of independent random numbers further enhances the uniqueness and security of the subkeys.
[0082] The distribution process is a hierarchical progression from the platform layer to the edge layer and from the edge layer to the device layer. The distribution module first sends the corresponding level subkey to the platform layer authentication node. Then, the platform layer authentication node verifies the validity of its own subkey and distributes the edge layer subkey to the edge layer authentication node. Finally, the edge layer authentication node distributes the device layer subkey to the device layer authentication node. Each level of distribution requires the receiving node to provide feedback confirmation information.
[0083] The authentication module is used to receive subkey verification requests from authentication nodes at each level, combine the current operation scenario information of the subject to be authenticated, cross-verify the subkeys at each level, and determine the authentication consistency.
[0084] The authentication module, in conjunction with the current operational scenario information of the entity to be authenticated, performs cross-validation of sub-keys at each level and determines the consistency of authentication. The steps are as follows:
[0085] Step 1: Collect the current operation scenario information of the entity to be certified, including operation type (such as data reading, parameter configuration, firmware upgrade), operation object (such as specific industrial equipment, edge gateway, platform database) and scenario risk level S (S is a preset level quantification value, and the quantification value of high-risk scenarios is higher than that of low-risk scenarios).
[0086] Step 2: Configure a scenario risk coefficient for each level. The scenario risk coefficient configured for each level follows the rule that the higher the current scenario risk level and the greater the impact of the scenario on the level, the larger the coefficient.
[0087] Step 3: Receive the subkey verification results from each level of authentication nodes, and quantify the verification results into subkey verification scores: if the subkey is completely matched and has not been tampered with, the score is 1; if the subkey is partially matched, the score is between 0 and 1, and is determined based on the ratio of the matched subkey to the total number of subkeys; if the subkey is not matched, the score is 0.
[0088] Step 4: Quantify the total score , These are the subkey verification score and scenario risk coefficient for the q-th level, respectively.
[0089] Step 5: If If the value is not less than the preset authentication threshold, then the cross-validation of sub-keys at each level is determined to be consistent; if... If the value is less than the preset authentication threshold, the verification is deemed inconsistent, and an anomaly warning is triggered.
[0090] The traceability module is used to record the identity dataset, key generation parameters, verification results, and operation node information for each authentication process, and to establish an authentication behavior log.
[0091] When the traceability module establishes the authentication behavior log, it follows the following rules:
[0092] The authentication behavior log includes: hash digest of the 3D identity base dataset, dynamic initial key generation parameters, subkey verification results at each level, total cross-validation score, operation node ID identifier, and log generation timestamp;
[0093] In daily management, the authentication behavior logs utilize a built-in log query mechanism within the application traceability module.
[0094] It supports initiating queries by subject or level to be authenticated, and only authorized authentication nodes can initiate query operations; each query operation is recorded as an independent log entry in the authentication behavior log, including the query node identifier, query conditions and query time;
[0095] The adaptation module is used to receive the results of cross-validation and synchronously send permission adaptation instructions to resource nodes at all levels of the industrial internet to adjust the access scope and operation permissions of the subject to be certified to the corresponding level of resources.
[0096] The adaptation module sends permission adaptation instructions to resource nodes at all levels of the industrial internet to adjust the access scope and operation permission stage of the subject to be authenticated. Based on the total cross-validation score and the risk level of the current operation scenario, a permission adjustment mapping relationship is established.
[0097] If V is not less than the preset high permission threshold, the entity to be authenticated is allowed to access all resources at the corresponding level. If V is between the preset medium permission threshold and the preset high permission threshold, including the preset medium permission threshold, the entity to be authenticated is only allowed to access the core business resources at the corresponding level, including key sensor data at the device layer, specified computing task resources at the edge layer, and read-only databases at the platform layer. If V is less than the preset medium permission threshold, the access scope of the entity to be authenticated is restricted, and it is only allowed to access basic status resources, including device online status at the device layer, node health status at the edge layer, and public data at the platform layer.
[0098] Synchronously set the validity period of operation permissions according to V; the higher the V, the longer the permission validity period.
[0099] Among them, the dynamic initial key bound to the identity of the subject to be authenticated is updated in real time as the identity dataset changes; the industrial internet hierarchical architecture includes the device layer, edge layer and platform layer; and the authentication behavior log supports querying by subject or level.
[0100] The specific triggering conditions for the dynamic initial key bound to the identity of the subject to be authenticated to be updated in real time as the identity dataset changes, and the updated key synchronization mechanism are as follows:
[0101] A dynamic initial key update is triggered if any of the following conditions are met:
[0102] When any feature in the 3D identity base dataset changes, including changes in device hardware features, switching of network access identifiers, or updates to the biometric features of the operating entity, the acquisition module detects the change and sends an update trigger signal; when the validity period of the dynamic initial key reaches the preset period, the generation module triggers an update by using a built-in timer; when the number of authentication failures of the entity to be authenticated exceeds the preset failure threshold consecutively, the authentication module sends an update trigger signal.
[0103] Key synchronization mechanism: After the generation module generates a new dynamic initial key, it synchronizes it to each layer in the order of platform layer to edge layer, and edge layer to device layer.
[0104] First, a new dynamic initial key and an updated timestamp are sent to the platform layer authentication node. After the platform layer node verifies the validity of the new dynamic initial key (by reverse-checking the parameter consistency through the generation formula), it sends back a synchronization confirmation.
[0105] After platform-level synchronization confirmation, the generation module forwards the new dynamic initial key to the edge-layer authentication node through the platform-layer node, and the edge-layer node verifies and sends back confirmation.
[0106] After edge layer synchronization confirmation, the generation module forwards the new dynamic initial key to the device layer authentication node through the edge layer node, and the device layer node verifies and sends back confirmation.
[0107] After all nodes at all levels have provided synchronization confirmation, the generation module marks the old dynamic initial key as invalid and records the invalidation time to the authentication behavior log.
[0108] The data acquisition module interacts with the generation module via a wireless network. The generation module interacts with the distribution module and the authentication module via a wireless network. The authentication module interacts with the traceability module via a wireless network. The traceability module interacts with the adaptation module via a wireless network.
[0109] In this embodiment, the acquisition module collects the device hardware characteristics, network access identifiers, and biometric information of the entity to be authenticated in the Industrial Internet, forming a three-dimensional identity base dataset for the entity to be authenticated. The generation module receives the three-dimensional identity base dataset and uses the dataset to generate a dynamic initial key bound to the identity of the entity to be authenticated. Then, the distribution module decomposes the dynamic initial key into sub-keys of corresponding levels according to the hierarchical architecture of the Industrial Internet and distributes the sub-keys to the authentication nodes at each level. The authentication module further receives the sub-key verification requests from the authentication nodes at each level, combines the current operation scenario information of the entity to be authenticated, and performs cross-verification on the sub-keys at each level to determine the authentication consistency. The traceability module records the identity dataset, key generation parameters, verification results, and operation node information in each authentication process to establish an authentication behavior log. Finally, the adaptation module receives the cross-verification results and synchronously sends permission adaptation instructions to the resource nodes at each level of the Industrial Internet to adjust the access scope and operation permissions of the entity to be authenticated for the corresponding level of resources.
[0110] In the above embodiments, when the system is applied to industrial internet scenarios, it can generate dynamic keys based on multi-dimensional identity information, decompose and verify them at different levels and cross-verify them in combination with operation scenarios, accurately adjust the access scope and permission validity period, and record authentication behavior for traceability. The key is updated as the identity changes or the validity period is triggered, thereby strengthening the security protection of devices, edge, and platform at all levels, reducing the risk of unauthorized access, ensuring controllable resource access, and improving the overall security operation level of the industrial internet.
[0111] Example 2:
[0112] At the implementation level, based on Example 1, this example refers to... Figure 2 The multi-level cryptographic authentication system for the Industrial Internet described in Example 1 will be further explained in detail below:
[0113] Multi-level cryptographic authentication methods for the Industrial Internet include:
[0114] Collect the device hardware characteristics, network access identifiers, and biometric characteristics of the operating entity of the industrial Internet entity to be authenticated, and form a three-dimensional identity basic dataset.
[0115] Collision-resistant hashing is performed on each feature of the three-dimensional identity basic dataset. Combined with the millisecond-level timestamp at the time of data collection completion, the system pre-configured root key, and a preset large prime number, a dynamic initial key bound to the identity of the subject to be authenticated is generated.
[0116] Configure hierarchical security weights and independent random numbers for the industrial internet device layer, edge layer, and platform layer, calculate sub-keys for each layer, and distribute the sub-keys in sequence. The distribution process receives real-time feedback confirmation from nodes.
[0117] Collect the current operation scenario information of the subject to be authenticated and configure the scenario risk coefficients at each level. Receive the subkey verification results and quantify the score to further calculate the total score. If it is not less than the preset authentication threshold, the verification is determined to be consistent; otherwise, an abnormal warning is triggered in a preset manner.
[0118] Record the hash digest of the three-dimensional identity base dataset, key generation parameters, verification results, and operation node information for each authentication, and establish an authentication behavior log;
[0119] Based on the total cross-validation score and the scenario risk level, permission adaptation instructions are sent to adjust the access scope and operation permissions of the subject to be authenticated; if a dynamic initial key update is triggered, the new key is synchronized hierarchically, and the old key is marked as invalid after synchronization is completed.
[0120] In summary, the system and method in the above embodiments, during execution, collect three-dimensional identity foundation data composed of the device hardware characteristics, network access identifier, and biometric characteristics of the entity to be authenticated in the Industrial Internet. This data is then combined with a timestamp and root key to generate a dynamic initial key, which is updated in real time as the identity data changes, enhancing the uniqueness and security of identity binding. Furthermore, the key is decomposed according to security weights configured at the device, edge, and platform layers and distributed in a hierarchical manner to adapt to the security requirements of a multi-layered architecture. Simultaneously, cross-validation of sub-keys at each layer is performed using operational scenario information, and consistency is judged through quantitative scoring to accurately identify authentication risks. Key information in the authentication process is recorded to establish a queryable authentication behavior log, and query operation records are retained for traceability. Finally, the resource access scope and operation permissions of the entity to be authenticated are adjusted based on the verification score and scenario risk level, with synchronized setting of permission expiration times to achieve dynamic adaptation. The key update trigger conditions and hierarchical synchronization mechanism are clearly defined to ensure the key remains valid, comprehensively guaranteeing the security, adaptability, and traceability of Industrial Internet authentication.
[0121] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A multi-level cryptographic authentication system for the Industrial Internet, characterized in that, include: The data acquisition module is used to collect the device hardware characteristics, network access identifiers, and biometric information of the entities to be authenticated in the Industrial Internet, forming a three-dimensional identity basic dataset of the entities to be authenticated. The generation module is used to receive the three-dimensional identity basic dataset and use the dataset to generate a dynamic initial key that is bound to the identity of the subject to be authenticated. The distribution module is used to break down the dynamic initial key into subkeys of the corresponding level according to the hierarchical architecture of the Industrial Internet, and distribute the subkeys to the authentication nodes at each level. The authentication module is used to receive subkey verification requests from authentication nodes at each level, combine the current operation scenario information of the subject to be authenticated, cross-verify the subkeys at each level, and determine the authentication consistency. The traceability module is used to record the identity dataset, key generation parameters, verification results, and operation node information for each authentication process, and to establish an authentication behavior log. The adaptation module is used to receive the results of cross-validation and synchronously send permission adaptation instructions to resource nodes at all levels of the industrial internet to adjust the access scope and operation permissions of the subject to be certified to the corresponding level of resources.
2. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, The dataset of the three-dimensional identity of the subject to be authenticated, collected by the acquisition module, includes: Equipment hardware features: unique chip identifier of industrial equipment, firmware version number of equipment sensors and configuration parameters of equipment hardware interfaces. The unique chip identifier of industrial equipment can be either CPU serial number or FPGA chip ID. Network access identifier: It adopts the combination of the physical address and network protocol address of the industrial Internet terminal, and adds the device identifier of the network access gateway; Biometric information of the operator: fingerprint feature template or iris feature code of the operator.
3. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, During the operation of the generation module, the process for generating a dynamic initial key is as follows: Hash operations are performed on the device hardware features, network access identifiers, and biometric information of the operating subject in the three-dimensional identity basic dataset to obtain device feature hash values, network identifier hash values, and biometric hash values. Obtain the timestamp of the current data acquisition operation completion time in milliseconds, and calculate the dynamic initial key: ; In the formula: It is a collision-resistant hash function; These include device feature hash values, network identifier hash values, and biometric hash values. The timestamp of the moment the current data collection operation was completed; The root key pre-configured for the system; Preset to large prime numbers; Represents the modular multiplication operator; This represents the modulo operator; The collision-resistant hash function is: ; In the formula: For the input data string, i.e. The splicing result; Pre-set an initial vector for the system; It is the XOR operator; This is a fixed-length data block after M is padded; It is a nonlinear permutation function; This represents the number of iteration rounds. Let i be the round function for the i-th round; The hash value length is set to 256 bits by default. in, ; In the formula: Preset block length; for The An 8-bit sub-segment; To The result of truncating the first 16 bits of the i-th block of data after performing SHA-3-256 operation; In the original byte sub-block sequence, the sequence number is An 8-bit byte sub-block, m=8, then Represented as x= in 8-bit bytes Perform a reverse flip. The 7th bit value, either 0 or 1. Similarly, that is: = .
4. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, When the distribution module decomposes the dynamic initial key into corresponding level subkeys and distributes the subkeys to each level of authentication nodes, it follows the following rules: Configure hierarchical security weights for the device layer, edge layer, and platform layer of the Industrial Internet. Let j=1 correspond to the device layer, j=2 to the edge layer, and j=3 to the platform layer, and > > Furthermore, the weight values are preset based on the security protection requirements of each level; Each level generates an independent and one-to-one random number, which is generated by the random number generator built into the distribution module; Calculate subkeys at each level ; In the formula: This is the subkey for the j-th level; A dynamic initial key; A random number configured for the j-th level; The distribution process is a hierarchical progression from the platform layer to the edge layer and from the edge layer to the device layer. The distribution module first sends the corresponding level subkey to the platform layer authentication node. Then, the platform layer authentication node verifies the validity of its own subkey and distributes the edge layer subkey to the edge layer authentication node. Finally, the edge layer authentication node distributes the device layer subkey to the device layer authentication node. Each level of distribution requires the receiving node to provide feedback confirmation information.
5. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, The authentication module, in conjunction with the current operational scenario information of the entity to be authenticated, performs cross-validation of sub-keys at each level and determines the consistency of authentication through the following steps: Step 1: Collect information on the current operation scenario of the entity to be authenticated, including the operation type (such as data reading, parameter configuration, firmware upgrade), operation object, and scenario risk level; Step 2: Configure a scenario risk coefficient for each level. The scenario risk coefficient configured for each level follows the rule that the higher the current scenario risk level and the greater the impact of the scenario on the level, the larger the coefficient. Step 3: Receive the subkey verification results from each level of authentication nodes, and quantify the verification results into subkey verification scores: if the subkey is completely matched and has not been tampered with, the score is 1; if the subkey is partially matched, the score is between 0 and 1, and is determined based on the ratio of the matched subkey to the total number of subkeys; if the subkey is not matched, the score is 0. Step 4: Quantify the total score , These are the subkey verification score and scenario risk coefficient for the q-th level, respectively. Step 5: If If the value is not less than the preset authentication threshold, then the cross-validation of sub-keys at each level is determined to be consistent; if... If the value is less than the preset authentication threshold, the verification is deemed inconsistent, and an anomaly warning is triggered.
6. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, When the traceability module establishes the authentication behavior log, it follows the following: The authentication behavior log includes: hash digest of the three-dimensional identity base dataset, dynamic initial key generation parameters, subkey verification results at each level, total cross-validation score, operation node ID identifier, and log generation timestamp; In daily management, the authentication behavior logs are queried using the built-in log query mechanism of the traceability module. It supports initiating queries by subject or level to be authenticated, and only authorized authentication nodes can initiate query operations; each query operation is recorded as an independent log entry in the authentication behavior log, including the query node identifier, query conditions and query time.
7. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, The adaptation module sends permission adaptation instructions to resource nodes at all levels of the industrial internet to adjust the access scope and operation permission stages of the subject to be authenticated. Based on the total cross-validation score and the risk level of the current operation scenario, a permission adjustment mapping relationship is established. If V is not less than the preset high-privilege threshold, the subject to be authenticated is allowed to access all resources at the corresponding level. If V is between the preset middle permission threshold and the preset high permission threshold, including the preset middle permission threshold, then the entity to be authenticated is only allowed to access the core business resources of the corresponding level, including the device layer only accessing key sensor data, the edge layer only accessing specified computing task resources, and the platform layer only accessing read-only databases; if V is less than the preset middle permission threshold, then the access scope of the entity to be authenticated is restricted, and it is only allowed to access basic status resources, including the device layer only accessing device online status, the edge layer only accessing node health status, and the platform layer only accessing public data. The time limit for operation permissions is set synchronously based on V. The higher the V, the longer the time limit for permissions.
8. The multi-level cryptographic authentication system for the Industrial Internet according to claim 1, characterized in that, The acquisition module is interactively connected to the generation module via a wireless network. The generation module is interactively connected to the distribution module and the authentication module via a wireless network. The authentication module is interactively connected to the traceability module via a wireless network. The traceability module is interactively connected to the adaptation module via a wireless network.
9. A multi-level cryptographic authentication method for the Industrial Internet, wherein the method is an implementation method of the multi-level cryptographic authentication system for the Industrial Internet as described in any one of claims 1-8, characterized in that, include: Collect the device hardware characteristics, network access identifiers, and biometric characteristics of the operating entity of the industrial Internet entity to be authenticated, and form a three-dimensional identity basic dataset. Collision-resistant hashing is performed on each feature of the three-dimensional identity basic dataset. Combined with the millisecond-level timestamp at the time of data collection completion, the system pre-configured root key, and a preset large prime number, a dynamic initial key bound to the identity of the subject to be authenticated is generated. Configure hierarchical security weights and independent random numbers for the industrial internet device layer, edge layer, and platform layer, calculate sub-keys for each layer, and distribute the sub-keys in sequence. The distribution process receives real-time feedback confirmation from nodes. Collect the current operation scenario information of the subject to be authenticated and configure the scenario risk coefficients at each level. Receive the subkey verification results and quantify the score to further calculate the total score. If it is not less than the preset authentication threshold, the verification is determined to be consistent; otherwise, an abnormal warning in the preset mode is triggered. Record the hash digest of the three-dimensional identity base dataset, key generation parameters, verification results, and operation node information for each authentication, and establish an authentication behavior log; Based on the total cross-validation score and the scenario risk level, an access adaptation instruction is sent to adjust the access scope and operation permissions of the subject to be authenticated.
Citation Information
Patent Citations
Password authentication method and device based on multilevel catalogue
CN102571734A