A terminal access identity authentication method and system based on trusted computing
By performing step-by-step extended measurement and timing dependency analysis on the hardware root of trust, and combining the behavioral pattern signals of protocol handshake messages with endogenous timing perturbation factors, the problem of the inability to identify dynamic timing anomalies in existing technologies is solved, and high-precision identification and dynamic trust assessment of complex attacks are achieved.
Patent Information
- Application Number
- CN202610322119.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-17
- Publication Date
- 2026-06-09
AI Technical Summary
Existing terminal access authentication methods based on trusted computing cannot effectively identify dynamic timing anomalies and abnormal synchronization relationships of network protocol behavior during system operation, and are difficult to detect complex attacks such as control flow hijacking and replay attacks.
By extending and measuring the hardware root of trust step by step, an initial trust chain is constructed and time-series dependency analysis is performed. Behavioral pattern signals in protocol handshake messages are collected, and overlap is checked in combination with endogenous time-series perturbation factors to determine the dynamic trust risk level and make authentication decisions.
It significantly improves the ability to perceive the dynamic behavior of the system during runtime, accurately identifies complex attacks, and achieves a technological upgrade from static identity authentication to dynamic trust assessment.
Smart Images

Figure CN122179188A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of trusted computing technology, and in particular to a terminal access authentication method and system based on trusted computing. Background Technology
[0002] In existing technologies, terminal access authentication methods based on trusted computing typically rely on static measurements of terminal platform configuration register values. The trustworthiness of the terminal is determined by comparing the current measurement value with a pre-stored baseline value. These methods only focus on a static snapshot at system startup, lacking the ability to dynamically perceive the system's runtime behavior sequence. They struggle to detect control flow hijacking attacks or timing obfuscation attacks that disrupt the normal execution order without altering the final measurement value. Because they cannot identify broken dependencies and reversed sequences in the system event sequence, the authentication mechanism has a blind spot when facing runtime attacks that exploit system timing anomalies, failing to effectively capture the timing disturbances caused by the attack within the system.
[0003] In existing technologies, trusted computing-based terminal access authentication methods typically separate terminal platform state from network access behavior, verifying only terminal integrity or user identity. This makes it difficult to detect replay attacks or man-in-the-middle attacks launched by attackers during the protocol handshake phase by forging a trusted platform state. The lack of correlation analysis between the micro-temporal characteristics of protocol handshake messages and internal system timing anomalies leads to insufficient accuracy and attack resistance in authentication results, failing to identify abnormal synchronization relationships between external network behavior and internal system state. Therefore, there is an urgent need to develop a terminal access authentication method that integrates system runtime timing behavior and network protocol behavior characteristics to address the problems of existing technologies' inability to detect dynamic timing anomalies and their inability to correlate internal and external behavioral characteristics for collaborative analysis, thereby improving the ability to identify complex attacks and the accuracy of authentication decisions. Summary of the Invention
[0004] This invention provides a terminal access authentication method and system based on trusted computing to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides a terminal access authentication method based on trusted computing, comprising: The hardware root of trust is extended step by step to obtain the initial trust chain construction result of the hardware root of trust. A timing dependency analysis is performed on the initial trusted chain construction results to obtain the runtime timing benchmark of the hardware trusted root; Collect protocol handshake messages during the identity authentication process, and use the time interval between the client key exchange parameters and the digital certificate micro timestamp in the protocol handshake messages as the behavior pattern signal during the identity authentication process; Based on the runtime timing benchmark, the system event sequence in the identity authentication process is evaluated by perturbation factorization to obtain the endogenous temporal perturbation factor of the system event sequence; The overlap of the behavioral pattern signal and the endogenous temporal perturbation factor is checked to obtain the identity status linkage indicator in the identity authentication process. Based on the time series change trend of the identity status linkage indicator, the dynamic trust risk level of the identity authentication process is determined, and the authentication process is adjudicated based on the dynamic trust risk level to obtain the final result of the identity authentication process.
[0006] In a preferred embodiment, the step of extending the hardware root of trust step by step to obtain the initial trust chain construction result of the hardware root of trust includes: Based on the trusted measurement engine, the initial measurement value of the hardware root of trust is read; Starting from the hardware root of trust, the components in the identity authentication process are measured step by step to obtain the step-by-step measurement values in the identity authentication process. Based on the startup order of the components, the initial metric value and the successive metric values are linked to form the initial trusted chain construction result of the hardware trusted root.
[0007] In a preferred embodiment, the step of performing time-dependency analysis on the initial trusted chain construction result to obtain the runtime timing baseline of the hardware trusted root includes: The dependencies between the components are determined based on the startup order, and the expected time intervals between the components are analyzed based on the dependencies. The startup order, dependencies, and expected time intervals are integrated into a runtime timing benchmark for the hardware root of trust.
[0008] In a preferred embodiment, the step of collecting protocol handshake messages during the identity authentication process and using the time interval between the client key exchange parameters and the digital certificate micro-timestamp in the protocol handshake messages as a behavioral pattern signal during the identity authentication process includes: Collect protocol handshake messages during the identity authentication process, including ClientKeyExchange messages and Certificate messages; Extract the client key exchange parameters from the ClientKeyExchange message and extract the digital certificate micro-timestamp from the Certificate message; The time interval between the client key exchange parameters and the digital certificate micro-timestamp is used as a behavioral pattern signal in the identity authentication process.
[0009] In a preferred embodiment, the step of performing a perturbation factorization evaluation on the system event sequence in the identity authentication process based on the runtime timing benchmark to obtain the endogenous temporal perturbation factor of the system event sequence includes: Based on the runtime sequence benchmark, the system event sequence in the identity authentication process is traversed by dependency to obtain the violation events in the identity authentication process; The violations include missing violation events, out-of-order violation events, time offset exceeding the limit violation events, and dependency breakage violation events; Based on the expected time interval in the runtime timing benchmark, the time offset of the violation event is analyzed to obtain the time offset of the violation event; The time offset is compared with a preset offset threshold to obtain the duration of the time offset of the violation event; The time offset, the duration of the time offset, and the expected time interval are weighted and fused to obtain the endogenous temporal perturbation factor of the system event sequence.
[0010] In a preferred embodiment, the formula for calculating the endogenous temporal perturbation factor is:
[0011] in, The term refers to the endogenous temporal perturbation factor. This is the system load adjustment factor in the identity authentication process. The total number of the aforementioned violations. Let be the sequence number of the aforementioned violation event. For the first The basic weighting coefficient for each violation event. For the first The type of penalty factor for each violation event; For the first The chain propagation coefficient of an individual violation incident. For the first The time offset of each violation event. For the first The expected time interval between each violation event. For the first Duration of time deviation for each violation event It is an exponential function with the natural constant as its base.
[0012] In a preferred embodiment, the step of performing an overlap test on the behavioral pattern signal and the endogenous temporal perturbation factor to obtain the identity status linkage indicator in the identity authentication process includes: Time-domain analysis was performed on the endogenous temporal disturbance factors to determine the high-activity periods of the endogenous temporal disturbance factors; The overlap between the acquisition time points of the behavioral pattern signals and the high-activity periods is checked to obtain the overlap of the behavioral pattern signals; An identity status linkage indicator for the identity authentication process is constructed based on the overlap.
[0013] In a preferred embodiment, determining the dynamic trust risk level of the identity authentication process based on the time-series change trend of the identity status linkage indicator, and making an authentication decision on the identity authentication process based on the dynamic trust risk level to obtain the final result of the identity authentication process, includes: The identity status linkage indicator is continuously recorded during the identity authentication process to form a time sequence of the identity authentication process; If the trend of the time series continues to rise and the identity status linkage indicator is the first status value, then the dynamic trust risk level is determined to be a high risk level. If the trend of the time series shows slight fluctuations, the dynamic trust risk level is determined to be a medium risk level. If the trend of the time series shows a continuous decline and the identity status linkage indicator is the second status value, it is determined to be a low-risk level. Based on the dynamic trust risk level, the identity authentication process is adjudicated to obtain the final result of the identity authentication process.
[0014] In a preferred embodiment, the authentication decision includes: Execute the authentication strategy during the identity authentication process; When the dynamic trust risk level is at the high risk level, access authentication will be denied. When the dynamic trust risk level is at the medium risk level, the identity authentication process is performed using multi-factor authentication. When the dynamic trust risk level is at the low risk level, the identity authentication is successful.
[0015] To address the above problems, the present invention also provides a terminal access authentication system based on trusted computing, the system comprising: The trust measurement module is used to perform step-by-step extension measurement on the hardware trust root to obtain the initial trust chain construction result of the hardware trust root; The timing analysis module is used to perform timing dependency analysis on the initial trusted chain construction results to obtain the runtime timing benchmark of the hardware trusted root; The behavior acquisition module is used to acquire protocol handshake messages during the identity authentication process, and to use the time interval between the client key exchange parameters and the digital certificate micro timestamp in the protocol handshake messages as the behavior pattern signal during the identity authentication process. The perturbation assessment module is used to perform perturbation factorization assessment on the system event sequence in the identity authentication process based on the runtime timing benchmark, so as to obtain the endogenous temporal perturbation factor of the system event sequence. The linkage verification module is used to perform overlap verification on the behavioral pattern signal and the endogenous temporal perturbation factor to obtain the identity status linkage indicator in the identity authentication process. The risk adjudication module is used to determine the dynamic trust risk level of the identity authentication process based on the time series change trend of the identity status linkage indicator, and to make an authentication adjudication on the identity authentication process based on the dynamic trust risk level, so as to obtain the final result of the identity authentication process.
[0016] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention significantly improves the ability to perceive the dynamic behavior of a system during runtime by constructing a runtime timing benchmark and evaluating the perturbation factor of the system event sequence. Existing technologies rely solely on static metric comparisons, failing to capture changes in the execution order and dependencies of events after system startup. This invention, however, performs temporal dependency analysis on the initial trusted chain construction results, establishing a runtime timing benchmark that includes component startup order, dependencies, and expected time intervals. It then traverses and verifies the system event sequence triggered by authentication, identifying various violations such as missing events, disordered sequences, excessive time offsets, and broken dependencies. Furthermore, it integrates the type attributes, time offset, offset duration, and causal propagation relationships of these violations to generate an endogenous temporal perturbation factor. This process transforms discrete abnormal events into continuously quantified perturbation indicators, enabling the effective identification of runtime attacks such as control flow hijacking and timing obfuscation that disrupt the normal execution order without changing the final metric, thus overcoming the shortcomings of existing technologies in perceiving dynamic behavioral anomalies.
[0017] 2. This invention achieves collaborative analysis of terminal system status and network access behavior by verifying the overlap between the micro-temporal characteristics of the protocol handshake messages and endogenous temporal perturbation factors. Existing technologies separate platform integrity verification from network identity authentication, making it difficult to detect behaviors such as forging a trusted state while implementing replay or man-in-the-middle attacks at the protocol level. By collecting ClientKeyExchange and Certificate messages during the protocol handshake process, the time interval between the client key exchange parameters and the micro-timestamp of the digital certificate is extracted as a behavioral pattern signal. This signal is then compared with the high-activity periods of endogenous temporal perturbation factors to generate an identity status linkage indicator. Furthermore, the risk level is dynamically determined based on the time-series change trend of this indicator, and differentiated authentication strategies are implemented. This internal and external linkage analysis mechanism accurately captures the highly synchronized characteristics of internal system temporal anomalies and external network behavioral anomalies, significantly improving the accuracy of identifying complex collaborative attacks and the reliability of authentication decisions, achieving a technological upgrade from static identity authentication to dynamic trust assessment. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating a terminal access authentication method based on trusted computing, provided in an embodiment of the present invention. Figure 2 A functional block diagram of a terminal access identity authentication system based on trusted computing provided in an embodiment of the present invention; The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0019] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0020] This application provides a terminal access authentication method based on trusted computing. The executing entity of this trusted computing-based terminal access authentication method includes, but is not limited to, at least one of the following: a server, a terminal, or any electronic device configured to execute the method provided in this application. In other words, the trusted computing-based terminal access authentication method can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0021] Reference Figure 1 The diagram shown is a flowchart illustrating a terminal access authentication method based on trusted computing according to an embodiment of the present invention. In this embodiment, the terminal access authentication method based on trusted computing includes: The hardware root of trust is extended step by step to obtain the initial trust chain construction result of the hardware root of trust. In this embodiment of the invention, the step of performing a step-by-step extension measurement on the hardware trusted root to obtain the initial trusted chain construction result of the hardware trusted root includes: Based on the trusted measurement engine, the initial measurement value of the hardware root of trust is read; Starting from the hardware root of trust, the components in the identity authentication process are measured step by step to obtain the step-by-step measurement values in the identity authentication process. Based on the startup order of the components, the initial metric value and the successive metric values are linked to form the initial trusted chain construction result of the hardware trusted root.
[0022] First, based on the Trusted Measurement Engine, the initial measurement value of the hardware root of trust is read. The Trusted Measurement Engine is an independent hardware execution environment in the terminal device, connected to the hardware root of trust via a dedicated internal bus. In the initial stage of system startup, the Trusted Measurement Engine sends a read command to the hardware root of trust. Upon receiving this command, the hardware root of trust returns its internally fixed, unchangeable identity and status information as the initial measurement value to the Trusted Measurement Engine. This initial measurement value represents the lowest starting point of the entire trust chain; its content is written once during hardware manufacturing, and no software-level attack can modify this value.
[0023] Starting with the hardware root of trust, the components in the authentication process are measured level by level to obtain the level-by-level measurement values. After completing the measurement of the hardware root of trust itself, the trusted measurement engine transfers control to the next level component and simultaneously measures that component. This process is progressive; the trusted measurement engine sequentially measures the bootloader, operating system kernel, critical device drivers, and security service components upon which authentication depends during system startup. For each component being measured, before gaining execution control, the trusted measurement engine loads the component's code and key data into a dedicated memory area, runs a hash algorithm engine to generate the component's measurement value, and records this measurement value as the corresponding level-by-level measurement value. This process ensures that the integrity of each component from the hardware layer to the authentication software layer is recorded.
[0024] Based on the startup order of the components, the initial metric value and the successive metric values are linked to form the initial trusted chain construction result of the hardware root of trust. The trusted metric engine concatenates the initial metric value with each subsequent successive metric value in the order in which the components are actually measured. This linking is not a simple numerical superposition, but rather employs a cryptographic expansion method; that is, the metric value of a later component is merged with the combined result of all previous metric values to form an interlocking metric chain. The final generated initial trusted chain construction result contains a complete record of all metric information from the hardware root of trust to the identity authentication component. Any tampering with any intermediate component will cause the final chain result to change.
[0025] The beneficial effect is that by establishing a complete metric chain from the hardware root of trust to the identity authentication components, the root of trust is extended from a single hardware chip to the entire system software stack. This step-by-step extension of the metric not only verifies the integrity of each component itself, but more importantly, it preserves the startup order and dependencies between components through chain links. This allows the subsequent authentication process to be upgraded from static value comparison to dynamic behavior analysis, significantly improving the ability to detect unknown attacks and runtime tampering.
[0026] A timing dependency analysis is performed on the initial trusted chain construction results to obtain the runtime timing benchmark of the hardware trusted root; In this embodiment of the invention, the step of performing time-series dependency analysis on the initial trusted chain construction result to obtain the runtime timing benchmark of the hardware trusted root includes: The dependencies between the components are determined based on the startup order, and the expected time intervals between the components are analyzed based on the dependencies. The startup order, dependencies, and expected time intervals are integrated into a runtime timing benchmark for the hardware root of trust.
[0027] After obtaining the initial trusted chain construction result, the terminal reads the result from the protected storage area. This result records the metrics and corresponding time points of each component from the hardware root of trust to the authentication component, in the order of startup. The terminal parses these metric time points and rearranges the components in chronological order to form a clear startup order list.
[0028] The dependencies between components are determined based on the boot order. The terminal, according to the parsed boot order and the predefined component function call relationships defined during system design, identifies which previously started components each component functionally depends on. For example, the terminal determines that loading a device driver depends on the completion of operating system kernel initialization, which in turn depends on loading the bootloader. By tracing back level by level, the terminal constructs a dependency graph between components, which clearly identifies which preceding components' successful startup is a prerequisite for the normal operation of each component.
[0029] Based on the dependencies, the expected time interval between the components is analyzed. For each pair of dependent adjacent components, the terminal repeatedly records the time difference between the startup completion time of the latter component and the startup completion time of the former component when the system is in a known trusted state. The terminal collects the distribution range of these time differences, and uses the lower and upper limits of this distribution range as the expected time interval corresponding to the dependency. This expected time interval reflects the reasonable time interval that the two components should take to start normally under hardware performance and software design constraints.
[0030] The startup order, dependencies, and expected time intervals are integrated into a runtime timing benchmark for the hardware root of trust. The terminal collects the startup order list, the dependency graph between components, and the expected time interval range corresponding to each pair of dependencies obtained in the above analysis process. This information is organized into a structured data format and written into the terminal's secure storage area, forming a complete standard reference model describing the normal operating timing behavior of the system, i.e., the runtime timing benchmark.
[0031] The beneficial effect is that by extracting and transforming the timing information contained in the initial trusted chain construction results into a runtime timing benchmark with logical constraints, the system is upgraded from only being able to verify the integrity of component identities to being able to monitor the timing compliance between components. The establishment of the runtime timing benchmark provides a clear reference standard for subsequent identification of runtime attacks such as control flow hijacking and timing obfuscation. Any behavior that deviates from the preset order or exceeds the expected time interval will be captured by the system, thereby significantly enhancing the ability to detect dynamic attack behavior.
[0032] Collect protocol handshake messages during the identity authentication process, and use the time interval between the client key exchange parameters and the digital certificate micro timestamp in the protocol handshake messages as the behavior pattern signal during the identity authentication process; In this embodiment of the invention, the step of collecting protocol handshake messages during the identity authentication process and using the time interval between the client key exchange parameters and the digital certificate micro-timestamp in the protocol handshake messages as a behavioral pattern signal during the identity authentication process includes: Collect protocol handshake messages during the identity authentication process, including ClientKeyExchange messages and Certificate messages; Extract the client key exchange parameters from the ClientKeyExchange message and extract the digital certificate micro-timestamp from the Certificate message; The time interval between the client key exchange parameters and the digital certificate micro-timestamp is used as a behavioral pattern signal in the identity authentication process.
[0033] During the identity authentication protocol handshake between the terminal and the authentication server, the protocol monitoring component on the terminal captures the network data packets exchanged between the two parties in real time. This capture process occurs at the data link layer of the network protocol stack. Based on preset filtering rules, the protocol monitoring component retains only the handshake messages related to identity authentication, filtering out other irrelevant network traffic. When the terminal initiates a connection request or responds to the server's authentication challenge, the protocol monitoring component begins recording the complete message content of each handshake interaction.
[0034] The protocol handshake messages during the identity authentication process are collected, including ClientKeyExchange messages and Certificate messages. The protocol monitoring component identifies the captured handshake messages based on the message type field, filtering out ClientKeyExchange messages sent by the client and Certificate messages sent by the server. The ClientKeyExchange message is a crucial message used by the client to transmit key negotiation parameters to the server after receiving the server's certificate. This message contains a random number generated by the client for session key calculation and key exchange materials. The Certificate message is a digital certificate message sent by the server to the client at the beginning of the handshake. This certificate is signed by a certificate authority and contains the server's public key and identity information, as well as time attributes such as the certificate's issuance and expiration dates.
[0035] The client key exchange parameters are extracted from the ClientKeyExchange message, and the digital certificate micro-timestamp is extracted from the Certificate message. The protocol monitoring component parses the payload of the ClientKeyExchange message and extracts the client key exchange parameter field according to the format defined by the TLS protocol. This field may include a client random number, a pre-master key, or the public key value in elliptic curve key exchange. Simultaneously, the protocol monitoring component parses the Certificate message and extracts the certificate issuance time or start validity time from the extended fields or validity period field of the digital certificate. This time value is then accurate to the microsecond level and used as the digital certificate micro-timestamp. This micro-timestamp reflects the time characteristics of the server certificate at the protocol level. Certificate issuance times differ between different servers, and even connections established on the same server at different times will have different certificate timestamps.
[0036] The time interval between the client key exchange parameters and the digital certificate's micro-timestamp is used as a behavioral pattern signal in the authentication process. The terminal records the time when it extracts the client key exchange parameters and the time when it extracts the digital certificate's micro-timestamp, calculating the time difference between these two events. This time difference incorporates the combined effects of network transmission latency, server processing latency, and protocol stack processing latency, reflecting the micro-characteristics of the handshake interaction under the current network environment and server load. The terminal uses this time interval as a feature value for a sampling point and records the corresponding sampling time point, forming a signal sequence that varies over time. This behavioral pattern signal is independent of the terminal system's internal state and is an access behavior fingerprint extracted from the network protocol layer.
[0037] The beneficial effect is that by extracting the time interval between the client key exchange parameters and the micro-timestamp of the digital certificate from the protocol handshake message, a network behavior characteristic signal independent of the internal state of the terminal system is constructed. This signal can reflect the real-time state of the current network environment and server response, providing an external perspective for subsequent collaborative analysis with internal system timing disturbance factors. By capturing the micro-time characteristics at the protocol level, even if attackers can forge the terminal system state, they cannot simultaneously and accurately simulate the dynamic time characteristics of the real network environment, thus effectively enhancing the ability to identify replay attacks and man-in-the-middle attacks.
[0038] Based on the runtime timing benchmark, the system event sequence in the identity authentication process is evaluated by perturbation factorization to obtain the endogenous temporal perturbation factor of the system event sequence; In this embodiment of the invention, the step of performing a perturbation factorization evaluation on the system event sequence in the identity authentication process based on the runtime timing benchmark to obtain the endogenous temporal perturbation factor of the system event sequence includes: Based on the runtime sequence benchmark, the system event sequence in the identity authentication process is traversed by dependency to obtain the violation events in the identity authentication process; The violations include missing violation events, out-of-order violation events, time offset exceeding the limit violation events, and dependency breakage violation events; Based on the expected time interval in the runtime timing benchmark, the time offset of the violation event is analyzed to obtain the time offset of the violation event; The time offset is compared with a preset offset threshold to obtain the duration of the time offset of the violation event; The time offset, the duration of the time offset, and the expected time interval are weighted and fused to obtain the endogenous temporal perturbation factor of the system event sequence.
[0039] The formula for calculating the endogenous temporal perturbation factor is as follows:
[0040] in, The term refers to the endogenous temporal perturbation factor. This is the system load adjustment factor in the identity authentication process. The total number of the aforementioned violations. Let be the sequence number of the aforementioned violation event. For the first The basic weighting coefficient for each violation event. For the first The type of penalty factor for each violation event; For the first The chain propagation coefficient of an individual violation incident. For the first The time offset of each violation event. For the first The expected time interval between each violation event. For the first Duration of time deviation for each violation event It is an exponential function with the natural constant as its base.
[0041] Upon triggering an authentication request, the terminal begins collecting various event records generated during system operation, including process creation events, system call events, file access events, and driver loading events. These events are arranged chronologically to form a system event sequence. Each event record includes an event identifier, a timestamp, and an event type attribute. The terminal reads a pre-established runtime timing baseline from the secure storage area. This baseline contains the component startup order, dependencies, and expected time intervals. The terminal compares the real-time collected system event sequence with the runtime timing baseline and begins the perturbation factorization evaluation process.
[0042] Based on the runtime timing benchmark, the system event sequence in the authentication process is traversed according to dependencies to obtain the violation events in the authentication process. The terminal traverses each event in the system event sequence one by one according to the startup order and dependencies defined in the runtime timing benchmark. For each event, the terminal checks whether the event has a corresponding item in the benchmark and whether the order of the event's appearance is consistent with the order defined in the benchmark. If an event specified in the benchmark is missing from the sequence, the terminal marks the event as a missing violation event. If the order of two events is reversed from the order defined in the benchmark, the terminal marks these two events as disordered sequence violations. If other events that should not appear are inserted into the sequence between two dependent events, the terminal marks these events as dependency break violations. Through this traversal and comparison, the terminal identifies all events that do not meet the benchmark requirements and records these events as violations.
[0043] The violations include missing events, out-of-order violations, time offset violations, and dependency break violations. A missing event is when a component event, which is required by the runtime timing baseline, is completely absent from the real-time acquired system event sequence. A out-of-order violation is when two component events with strict sequential requirements appear in the sequence in the opposite order to the baseline. A time offset violation is when the events occur in the correct order, but the difference between the event's occurrence time and the expected time recorded in the baseline exceeds the normal fluctuation range. A dependency break violation is when an additional event, which should not have occurred, appears between two dependent component events, breaking the dependency chain. The terminal records the specific type of each marked violation event as a basis for subsequent analysis.
[0044] Based on the expected time intervals in the runtime timing baseline, time offset analysis is performed on the violation events to obtain their time offsets. For each identified violation event, the terminal reads the corresponding expected time point or expected time interval from the runtime timing baseline. The terminal calculates the difference between the actual occurrence timestamp of the violation event and the expected time point recorded in the baseline, and uses the absolute value of this difference as the time offset of the violation event. For adjacent event pairs with dependencies, the terminal calculates the actual time interval between the two events and compares this actual time interval with the expected time interval recorded in the baseline, using the absolute value of the difference between the actual time interval and the expected time interval as the time offset of the event pair. This time offset reflects the degree to which real-time behavior deviates from the normal timing scale.
[0045] The time offset is compared with a preset offset threshold to obtain the duration of the time offset for the violation event. The terminal presets an offset threshold, which represents the upper limit of time fluctuation allowed by the system. For each violation event, the terminal continuously monitors the change of its time offset over time. If the time offset of a violation event first exceeds the preset offset threshold, the terminal records this moment as the offset start time. The terminal continues to monitor the performance of the violation event in subsequent time windows until its time offset falls below the offset threshold, recording this moment as the offset end time. The terminal calculates the difference between the offset end time and the offset start time, using this difference as the duration of the time offset for the violation event. This duration reflects the duration of the abnormal state, thus distinguishing between brief fluctuations and persistent anomalies.
[0046] The time offset, duration of the time offset, and expected time interval are weighted and fused to obtain the endogenous temporal perturbation factor of the system event sequence. The terminal summarizes all violations identified within the current time window. For each violation, its time offset, duration of the time offset, and the corresponding expected time interval are comprehensively processed. The terminal assigns different levels of influence to violations based on their type: higher influence for missing events and events with broken dependencies; medium influence for events with disordered sequences; and different levels of influence for events with excessive time offsets, based on the magnitude of the offset. The terminal also considers the causal relationships between violations, assigning higher influence weights to a group of violations with a propagation relationship as a whole. Simultaneously, the terminal collects the current system's CPU utilization and memory utilization, using these resource usages as environmental adjustment factors. The terminal aggregates all the above influencing factors to generate a quantitative value that reflects the overall state of system temporal anomalies within the current time window. This quantitative value is used as the endogenous temporal perturbation factor, and the start and end times of the corresponding window are recorded.
[0047] The The endogenous timing disturbance factor is a quantitative value calculated by the terminal based on all violation events within the current time window. It is used to characterize the overall severity of the system's timing behavior deviating from the normal baseline. The larger the value, the more severe the internal timing anomaly of the system.
[0048] The The system load adjustment factor in the identity authentication process is an adjustment coefficient generated by the terminal based on the CPU utilization and memory utilization within the current time window. It is used to reflect the impact of the current resource stress on the timing behavior. When the system load is high, the value of this factor is larger, and when the system load is low, the value of this factor is smaller.
[0049] The The total number of violation events is the sum of all violation events identified by the terminal through dependency traversal within the current time window, including missing violation events, out-of-order violation events, time offset exceeding the limit violation events, and dependency breakage violation events.
[0050] The The sequence number of the violation event is a sequential number assigned to each violation event identified within the current time window, starting from 1 and increasing sequentially to 1. This is used to distinguish each individual violation event in a summation operation.
[0051] For the first The basic weight coefficient of each violation event is a weight value pre-assigned by the terminal according to the basic category to which the violation event belongs. Missing violation events are assigned higher weights, disordered sequence violation events are assigned medium weights, time offset violation events are assigned different weights according to the degree of offset, and dependency break violation events are assigned higher weights.
[0052] For the first The type penalty factor for each violation event is a coefficient that the terminal adjusts according to the specific severity of the violation event within the same basic category. Higher penalty factors are assigned to violations involving critical system components, while lower penalty factors are assigned to similar events involving non-critical components.
[0053] For the first The chain propagation coefficient of a violation event is a coefficient assigned by the terminal based on whether the violation event belongs to a chain of violation events with causal relationship. If the event belongs to a chain of violation events, the coefficient is greater than 1, which is used to amplify the disturbance contribution of the event in the chain. If the event exists in isolation, the coefficient is equal to 1.
[0054] For the first The time offset of an exception event is the absolute value of the difference calculated by the terminal after comparing the actual occurrence time of the exception event with the expected time point recorded in the runtime timing baseline. It reflects the degree to which the event deviates from the normal time point.
[0055] For the first The expected time interval for each violation event is the standard time difference corresponding to the violation event obtained by the terminal from the runtime timing baseline. It is derived from the time interval records between adjacent components that have a dependency relationship during normal system operation.
[0056] The duration of the time offset for the i-th violation event is the duration obtained by the terminal continuously monitoring the time offset of the violation event and comparing the offset with a preset offset threshold. It is recorded from the moment the offset first exceeds the threshold until the offset falls back below the threshold, reflecting the duration of the abnormal state of the event.
[0057] The beneficial effect is that by performing dependency traversal and timing constraint verification on the real-time collected system event sequences and pre-established runtime timing benchmarks, discrete and isolated abnormal events are transformed into continuously quantified endogenous timing perturbation factors. These perturbation factors not only include the type information of the violation event but also incorporate the magnitude of the time offset, the duration of the anomaly, and the causal propagation relationship between events. This upgrades the description of system runtime anomalies from a simple presence or absence of anomalies to a quantitative assessment of the severity of the anomalies. Simultaneously, the introduction of system resource usage as a regulating factor allows the perturbation factor to perceive the current operating load of the terminal, avoiding misjudging normal time fluctuations under high load as attack behavior, thereby significantly improving the identification accuracy of runtime attacks such as control flow hijacking and timing obfuscation.
[0058] The overlap of the behavioral pattern signal and the endogenous temporal perturbation factor is checked to obtain the identity status linkage indicator in the identity authentication process. In this embodiment of the invention, the step of performing an overlap test on the behavioral pattern signal and the endogenous temporal perturbation factor to obtain the identity status linkage indicator in the identity authentication process includes: Time-domain analysis was performed on the endogenous temporal disturbance factors to determine the high-activity periods of the endogenous temporal disturbance factors; The overlap between the acquisition time points of the behavioral pattern signals and the high-activity periods is checked to obtain the overlap of the behavioral pattern signals; An identity status linkage indicator for the identity authentication process is constructed based on the overlap.
[0059] After obtaining the behavioral pattern signal and the endogenous temporal perturbation factor, the terminal begins to perform collaborative analysis on these two signals, which originate from the network protocol layer and the system internal layer, respectively. The behavioral pattern signal is a signal sequence with time points on the horizontal axis and time intervals on the vertical axis, while the endogenous temporal perturbation factor is a quantized numerical sequence generated in units of time windows. The terminal aligns these two signals on the time axis in preparation for overlap verification.
[0060] A time-domain analysis is performed on the endogenous temporal disturbance factor to determine its high-activity periods. The terminal reads the values of the endogenous temporal disturbance factor within each consecutive time window and compares these values with a pre-set activity threshold. When the value of the endogenous temporal disturbance factor within a certain time window continuously exceeds the activity threshold, the terminal records the start and end times of that time window. If the disturbance factor values in multiple adjacent time windows continuously exceed the activity threshold, the terminal merges these consecutive time windows into a single continuous time period, which is the high-activity period of the endogenous temporal disturbance factor. The high-activity period reflects the time interval where internal system temporal anomalies are more active and system behavior deviates significantly from the normal baseline.
[0061] The overlap between the acquisition time points of the behavioral pattern signals and the high-activity periods is checked to obtain the overlap of the behavioral pattern signals. The terminal compares each acquisition time point of the behavioral pattern signals with the aforementioned determined high-activity periods to determine whether each acquisition time point falls within the time interval of any high-activity period. The terminal counts the number of acquisition points of all behavioral pattern signals that fall within high-activity periods within a preset observation period, and also counts the total number of behavioral pattern signal acquisition points within the observation period. The terminal divides the number of acquisition points that fall within high-activity periods by the total number of acquisition points to obtain a ratio value between zero and one; this ratio value is the overlap of the behavioral pattern signals. The overlap reflects the degree of temporal overlap between the micro-temporal characteristics of external network behavior and the high-incidence periods of internal system timing anomalies.
[0062] Based on the overlap, an identity status linkage indicator for the authentication process is constructed. The terminal compares the calculated overlap value with a pre-set linkage threshold. If the overlap value exceeds the linkage threshold, it indicates that the external network behavior and the internal system timing anomaly are highly synchronized in time. The terminal generates an identity status linkage indicator with a first state value, which represents the synchronization anomaly between the internal and external behaviors. If the overlap value does not exceed the linkage threshold, it indicates that there is no significant synchronization relationship between the external network behavior and the internal system timing anomaly. The terminal generates an identity status linkage indicator with a second state value, which represents the absence of significant synchronization anomalies between the internal and external behaviors. The terminal records this indicator and the corresponding authentication initiation time as the output result of the internal and external collaborative analysis during this identity authentication process.
[0063] Based on the time series change trend of the identity status linkage indicator, the dynamic trust risk level of the identity authentication process is determined, and the authentication process is adjudicated based on the dynamic trust risk level to obtain the final result of the identity authentication process.
[0064] The terminal continuously records the identity status linkage indicators during the identity authentication process, forming a time sequence for the authentication process. During each authentication process, the terminal saves the generated identity status linkage indicator along with the initiation time of that authentication. As authentication requests are continuously initiated, the terminal arranges these indicators in chronological order of authentication occurrence, forming a time sequence with authentication time on the horizontal axis and indicator values on the vertical axis. This time sequence records the historical trajectory of the evolution of internal and external behavioral synchronization states over time.
[0065] If the trend of the time series continues to rise and the identity status linkage indicator is at the first state value, then the dynamic trust risk level is determined to be high risk. The terminal observes the direction of change of the indicator values in adjacent authentication periods within the time series. If the indicator values increase successively over multiple consecutive periods, showing a continuous upward trend, and the indicator value in the current authentication period is the first state value (i.e., an abnormal state of internal and external behavior synchronization), the terminal determines that the dynamic trust risk level corresponding to this identity authentication is high risk.
[0066] If the time series shows a slight fluctuation, the dynamic trust risk level is determined to be medium risk. The terminal continues to observe the time series. If the values of adjacent period indicators in the series sometimes increase and sometimes decrease without a clear unilateral trend, and the fluctuation range remains within a small range, the terminal determines that the dynamic trust risk level corresponding to this identity authentication is medium risk.
[0067] If the time series shows a continuous downward trend and the identity status linkage indicator is at the second state value, it is determined to be a low-risk level. The terminal observes the time series; if the indicator value decreases successively over multiple consecutive periods, showing a continuous downward trend, and the indicator value in the current authentication period is the second state value (i.e., no abnormal synchronization between internal and external behaviors), the terminal determines that the dynamic trust risk level corresponding to this identity authentication is a low-risk level.
[0068] Based on the dynamic trust risk level, the authentication process is adjudicated to obtain the final result of the authentication process. The terminal selects the corresponding processing method from the internally stored authentication policies according to the determined dynamic trust risk level, executes the processing method, generates a clear result of authentication success or failure, and returns this result as the final result of this authentication process to the entity that initiated the authentication request.
[0069] The authentication strategy in the identity authentication process is executed. The terminal has a pre-configured set of authentication strategies corresponding to different risk levels. These strategies specify the specific operational procedures to be performed under different risk conditions. The terminal invokes the corresponding strategy based on the currently determined risk level to begin execution.
[0070] When the dynamic trust risk level is at the high-risk level, access authentication is denied. When the terminal determines that the current risk level is high-risk, it immediately terminates the ongoing authentication process, does not perform subsequent authentication information verification, directly returns an authentication failure response to the initiator, and records the event of access denial due to high risk in the system log.
[0071] When the dynamic trust risk level is at the medium risk level, multi-factor authentication is performed on the identity authentication process. When the terminal determines that the current risk level is medium risk, an additional authentication step is added on the basis of the original identity authentication. A request for a second authentication factor is sent to the user terminal, and the user's dynamic verification code or biometric information is received. This additional information is independently verified. The identity authentication process continues only after the additional information is verified successfully; otherwise, an authentication failure response is returned.
[0072] When the dynamic trust risk level is at the low risk level, the identity authentication is successful. When the terminal determines that the current risk level is low risk, it completes the identity authentication according to the normal process, allows the entity that initiated the authentication request to access the network, returns a successful authentication response to the entity, and grants the corresponding network access permissions.
[0073] The beneficial effects include enabling collaborative analysis of external network behavior characteristics and internal system temporal anomalies by verifying the overlap between behavioral pattern signals and endogenous temporal perturbation factors. This allows the system to identify complex attack patterns where attackers simultaneously manipulate network protocols and system behavior. Furthermore, by analyzing the time-series changes of identity status linkage indicators, the static judgment of single authentication is upgraded to a dynamic risk assessment based on historical behavior, making risk level determination more accurate and reliable. Finally, differentiated authentication strategies are matched according to the risk level: direct blocking to ensure security in high-risk situations, increased authentication strength to balance security and usability in medium-risk situations, and rapid passage to improve user experience in low-risk situations, achieving dynamic adaptation of security protection strength to the current risk situation.
[0074] Based on the time series change trend of the identity status linkage indicator, the dynamic trust risk level of the identity authentication process is determined, and the authentication process is adjudicated based on the dynamic trust risk level to obtain the final result of the identity authentication process.
[0075] In this embodiment of the invention, determining the dynamic trust risk level of the identity authentication process based on the time-series change trend of the identity status linkage indicator, and making an authentication decision on the identity authentication process based on the dynamic trust risk level to obtain the final result of the identity authentication process, includes: The identity status linkage indicator is continuously recorded during the identity authentication process to form a time sequence of the identity authentication process; If the trend of the time series continues to rise and the identity status linkage indicator is the first status value, then the dynamic trust risk level is determined to be a high risk level. If the trend of the time series shows slight fluctuations, the dynamic trust risk level is determined to be a medium risk level. If the trend of the time series shows a continuous decline and the identity status linkage indicator is the second status value, it is determined to be a low-risk level. Based on the dynamic trust risk level, the identity authentication process is adjudicated to obtain the final result of the identity authentication process.
[0076] The authentication decision includes: Execute the authentication strategy during the identity authentication process; When the dynamic trust risk level is at the high risk level, access authentication will be denied. When the dynamic trust risk level is at the medium risk level, the identity authentication process is performed using multi-factor authentication. When the dynamic trust risk level is at the low risk level, the identity authentication is successful.
[0077] The identity status linkage indicators are continuously recorded during the identity authentication process to form a time sequence of the authentication process. During each authentication process, the terminal saves the identity status linkage indicator generated in the step, recording the authentication initiation time and the specific value of the indicator. These indicators are arranged in chronological order of authentication occurrence, with the time interval between two adjacent authentications automatically determined by the terminal based on the arrival time of the actual authentication request. This ultimately forms a sequence of indicator values arranged in chronological order, which is the time sequence of the identity status linkage indicators.
[0078] If the time series trend continues to rise and the identity status linkage indicator is at the first state value, then the dynamic trust risk level is determined to be high risk. The terminal analyzes the formed time series and observes the direction of change of the indicator values in adjacent periods. If the indicator values increase successively in multiple consecutive authentication periods, showing a clear and continuous upward trend, and the indicator value in the current authentication period is the first state value, which indicates an abnormal state value of internal and external behavior synchronization, the terminal determines the dynamic trust risk level corresponding to this identity authentication to be high risk.
[0079] If the time series shows a slight fluctuation in its trend, the dynamic trust risk level is determined to be medium risk. The terminal continues to analyze the time series. If the values of the indicators in adjacent periods in the series sometimes increase and sometimes decrease, without a clear unilateral trend, and the fluctuation range remains within a preset stable range, and the indicator values alternate between the first state value and the second state value or always take the second state value, the terminal determines the dynamic trust risk level corresponding to this identity authentication to be medium risk.
[0080] If the time series shows a continuous downward trend and the identity status linkage indicator is at the second state value, it is determined to be a low-risk level. The terminal analyzes the time series. If the indicator value decreases successively over multiple consecutive authentication cycles, showing a clear and continuous downward trend, and the indicator value in the current authentication cycle is the second state value, indicating no abnormal synchronization between internal and external behaviors, the terminal determines the dynamic trust risk level corresponding to this identity authentication to be a low-risk level.
[0081] Based on the dynamic trust risk level, the identity authentication process is adjudicated to obtain the final result of the identity authentication process. The terminal selects the authentication processing method corresponding to the determined dynamic trust risk level from a pre-configured authentication policy library, executes the authentication processing method, and generates a clear authentication result, which is the final result of this identity authentication process.
[0082] The authentication strategy is executed during the identity authentication process. The terminal pre-stores authentication strategies corresponding to different dynamic trust risk levels. These strategies specify the specific operation procedures that the terminal should perform after receiving an identity authentication request. The terminal calls the corresponding strategy to start execution based on the currently determined risk level.
[0083] When the dynamic trust risk level is at the high-risk level, access authentication is denied. When the terminal determines that the current risk level is high-risk, it directly terminates the authentication process, returns an authentication failure response to the entity that initiated the authentication request, and records the event log of this access denial, which includes the authentication time, terminal identifier, and risk level information that triggered the denial.
[0084] When the dynamic trust risk level is at the medium risk level, multi-factor authentication is performed on the identity authentication process. When the terminal determines that the current risk level is medium risk, it initiates an additional authentication request on the basis of the original identity authentication, sends a request to the user terminal to provide a second authentication factor, receives the dynamic verification code or biometric information returned by the user, verifies this additional information, and only continues to complete the identity authentication process after the additional information is verified; otherwise, an authentication failure response is returned.
[0085] When the dynamic trust risk level is at the low risk level, the identity authentication is successful. When the terminal determines that the current risk level is low risk, it directly completes the identity authentication process, allows the entity that initiated the authentication request to access, returns a successful authentication response to the entity, and grants the corresponding network access permissions.
[0086] The beneficial effect is that by linking the time-series change trend of identity status indicators with dynamic trust risk levels, an upgrade from static threshold judgment to dynamic trend assessment is achieved. Terminals no longer make binary decisions based solely on the indicator value of a single authentication, but instead conduct a comprehensive analysis combining the changing trends of historical authentication cycles, making risk assessment more accurate and reliable. Simultaneously, differentiated authentication strategies are matched according to different risk levels: high-risk situations result in direct blocking to ensure security; medium-risk situations increase authentication strength to balance security and usability; and low-risk situations allow rapid access to improve user experience, achieving dynamic adaptation of security protection strength to the current risk situation.
[0087] like Figure 2 The diagram shown is a functional block diagram of a terminal access identity authentication system based on trusted computing provided in an embodiment of the present invention.
[0088] The trusted computing-based terminal access authentication system 100 described in this invention can be installed in an electronic device. Depending on the functions implemented, the trusted computing-based terminal access authentication system 100 may include a trusted measurement module 101, a timing analysis module 102, a behavior acquisition module 103, a disturbance assessment module 104, a linkage verification module 105, and a risk adjudication module 106. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.
[0089] In this embodiment, the functions of each module / unit are as follows: The trust measurement module 101 is used to perform step-by-step extension measurement on the hardware trust root to obtain the initial trust chain construction result of the hardware trust root; The timing analysis module 102 is used to perform timing dependency analysis on the initial trusted chain construction results to obtain the runtime timing benchmark of the hardware trusted root. The behavior acquisition module 103 is used to acquire protocol handshake messages during the identity authentication process, and to use the time interval between the client key exchange parameters and the digital certificate micro timestamp in the protocol handshake messages as the behavior pattern signal during the identity authentication process. The disturbance assessment module 104 is used to perform disturbance factorization assessment on the system event sequence in the identity authentication process based on the runtime timing benchmark, so as to obtain the endogenous temporal disturbance factor of the system event sequence. The linkage verification module 105 is used to perform overlap verification on the behavior pattern signal and the endogenous temporal perturbation factor to obtain the identity status linkage indicator in the identity authentication process. The risk adjudication module 106 is used to determine the dynamic trust risk level of the identity authentication process based on the time series change trend of the identity status linkage indicator, and to make an authentication adjudication on the identity authentication process based on the dynamic trust risk level, so as to obtain the final result of the identity authentication process.
[0090] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.
[0091] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0092] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.
[0093] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0094] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0095] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A terminal access authentication method based on trusted computing, characterized in that, The method includes: The hardware root of trust is extended step by step to obtain the initial trust chain construction result of the hardware root of trust. A timing dependency analysis is performed on the initial trusted chain construction results to obtain the runtime timing benchmark of the hardware trusted root; Collect protocol handshake messages during the identity authentication process, and use the time interval between the client key exchange parameters and the digital certificate micro timestamp in the protocol handshake messages as the behavior pattern signal during the identity authentication process; Based on the runtime timing benchmark, the system event sequence in the identity authentication process is evaluated by perturbation factorization to obtain the endogenous temporal perturbation factor of the system event sequence; The overlap of the behavioral pattern signal and the endogenous temporal perturbation factor is checked to obtain the identity status linkage indicator in the identity authentication process. Based on the time series change trend of the identity status linkage indicator, the dynamic trust risk level of the identity authentication process is determined, and the authentication process is adjudicated based on the dynamic trust risk level to obtain the final result of the identity authentication process.
2. The terminal access authentication method based on trusted computing as described in claim 1, characterized in that, The step-by-step extension measurement of the hardware trust root to obtain the initial trust chain construction result of the hardware trust root includes: Based on the trusted measurement engine, the initial measurement value of the hardware root of trust is read; Starting from the hardware root of trust, the components in the identity authentication process are measured step by step to obtain the step-by-step measurement values in the identity authentication process. Based on the startup order of the components, the initial metric value and the successive metric values are linked to form the initial trusted chain construction result of the hardware trusted root.
3. The terminal access authentication method based on trusted computing as described in claim 2, characterized in that, The step of performing time-series dependency analysis on the initial trusted chain construction results to obtain the runtime timing baseline of the hardware trusted root includes: The dependencies between the components are determined based on the startup order, and the expected time intervals between the components are analyzed based on the dependencies. The startup order, dependencies, and expected time intervals are integrated into a runtime timing benchmark for the hardware root of trust.
4. The terminal access authentication method based on trusted computing as described in claim 3, characterized in that, The process of collecting protocol handshake messages during identity authentication, and using the time interval between the client key exchange parameters and the digital certificate micro-timestamp in the protocol handshake messages as behavioral pattern signals in the identity authentication process, includes: Collect protocol handshake messages during the identity authentication process, including ClientKeyExchange messages and Certificate messages; Extract the client key exchange parameters from the ClientKeyExchange message and extract the digital certificate micro-timestamp from the Certificate message; The time interval between the client key exchange parameters and the digital certificate micro-timestamp is used as a behavioral pattern signal in the identity authentication process.
5. The terminal access authentication method based on trusted computing as described in claim 4, characterized in that, Based on the runtime timing benchmark, the perturbation factorization evaluation of the system event sequence in the identity authentication process is performed to obtain the endogenous temporal perturbation factor of the system event sequence, including: Based on the runtime sequence benchmark, the system event sequence in the identity authentication process is traversed by dependency to obtain the violation events in the identity authentication process; The violations include missing violation events, out-of-order violation events, time offset exceeding the limit violation events, and dependency breakage violation events; Based on the expected time interval in the runtime timing benchmark, the time offset of the violation event is analyzed to obtain the time offset of the violation event; The time offset is compared with a preset offset threshold to obtain the duration of the time offset of the violation event; The time offset, the duration of the time offset, and the expected time interval are weighted and fused to obtain the endogenous temporal perturbation factor of the system event sequence.
6. The terminal access authentication method based on trusted computing as described in claim 5, characterized in that, The formula for calculating the endogenous temporal perturbation factor is as follows: in, The term refers to the endogenous temporal perturbation factor. This is the system load adjustment factor in the identity authentication process. The total number of the aforementioned violations. Let be the sequence number of the aforementioned violation event. For the first The basic weighting coefficient for each violation event. For the first The type of penalty factor for each violation event; For the first The chain propagation coefficient of an individual violation incident. For the first The time offset of each violation event. For the first The expected time interval between each violation event. For the first Duration of time deviation of each violation event It is an exponential function with the natural constant as its base.
7. The terminal access authentication method based on trusted computing as described in claim 1, characterized in that, The process of performing an overlap test on the behavioral pattern signal and the endogenous temporal perturbation factor to obtain the identity status linkage indicator in the identity authentication process includes: Time-domain analysis was performed on the endogenous temporal disturbance factors to determine the high-activity periods of the endogenous temporal disturbance factors; The overlap between the acquisition time points of the behavioral pattern signals and the high-activity periods is checked to obtain the overlap of the behavioral pattern signals; An identity status linkage indicator for the identity authentication process is constructed based on the overlap.
8. The terminal access authentication method based on trusted computing as described in claim 1, characterized in that, The method of determining the dynamic trust risk level of the identity authentication process based on the time series change trend of the identity status linkage indicator, and making an authentication decision on the identity authentication process based on the dynamic trust risk level to obtain the final result of the identity authentication process includes: The identity status linkage indicator is continuously recorded during the identity authentication process to form a time sequence of the identity authentication process; If the trend of the time series continues to rise and the identity status linkage indicator is the first status value, then the dynamic trust risk level is determined to be a high risk level. If the trend of the time series shows slight fluctuations, the dynamic trust risk level is determined to be a medium risk level. If the trend of the time series shows a continuous decline and the identity status linkage indicator is the second status value, it is determined to be a low-risk level. Based on the dynamic trust risk level, the identity authentication process is adjudicated to obtain the final result of the identity authentication process.
9. The terminal access authentication method based on trusted computing as described in claim 8, characterized in that, The authentication decision includes: Execute the authentication strategy during the identity authentication process; When the dynamic trust risk level is at the high risk level, access authentication will be denied. When the dynamic trust risk level is at the medium risk level, the identity authentication process is performed using multi-factor authentication. When the dynamic trust risk level is at the low risk level, the identity authentication is successful.
10. A terminal access authentication system based on trusted computing, characterized in that, The system is used to implement the terminal access authentication method based on trusted computing as described in claim 1, the system comprising: The trust measurement module is used to perform step-by-step extension measurement on the hardware trust root to obtain the initial trust chain construction result of the hardware trust root; The timing analysis module is used to perform timing dependency analysis on the initial trusted chain construction results to obtain the runtime timing benchmark of the hardware trusted root; The behavior acquisition module is used to acquire protocol handshake messages during the identity authentication process, and to use the time interval between the client key exchange parameters and the digital certificate micro timestamp in the protocol handshake messages as the behavior pattern signal during the identity authentication process. The perturbation assessment module is used to perform perturbation factorization assessment on the system event sequence in the identity authentication process based on the runtime timing benchmark, so as to obtain the endogenous temporal perturbation factor of the system event sequence. The linkage verification module is used to perform overlap verification on the behavioral pattern signal and the endogenous temporal perturbation factor to obtain the identity status linkage indicator in the identity authentication process. The risk adjudication module is used to determine the dynamic trust risk level of the identity authentication process based on the time series change trend of the identity status linkage indicator, and to make an authentication adjudication on the identity authentication process based on the dynamic trust risk level, so as to obtain the final result of the identity authentication process.