A working method for client security authentication for remote authorization

By using character set constraint character function and information matching degree function in the security authentication process of remote terminal and client, the problem of inaccurate matching of authentication information in remote device data interaction is solved, and the accuracy and security of secure authentication and information interaction are achieved.

CN114003894BActive Publication Date: 2025-06-10CHONGQING MOSES ROBOTS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111312942.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-08
Publication Date
2025-06-10
Estimated Expiration
2041-11-08

AI Technical Summary

Technical Problem

During the data interaction of remote devices, the security authentication operation of remote terminals and clients requires a complete data matching process. Inaccurate matching of massive authentication information may lead to serious security problems.

Method used

By collecting massive authentication information in the remote terminal, using character set constraint character function for weighting calculation, the client sends authentication information to the remote terminal, and the remote terminal performs information matching authentication operation of the information matching degree function. If the matching result reaches the set threshold, the client's working permission is enabled.

Benefits of technology

It realizes secure authentication for remote terminals and clients, prevents information loss caused by overfitting during information extraction, and ensures accurate matching of authentication information and secure information interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114003894B_ABST
    Figure CN114003894B_ABST
Patent Text Reader

Abstract

The present invention provides a client security authentication working method for remote authorization, which includes the following steps: S1, perform feature partitioning on the authentication information of the remote terminal. Since the authentication information is a combination with multiple character patterns, the combination is feature-partitioned into character set A, character set B, character set C, and character set D; S2, obtain serial number information from character set A, obtain geographical location coordinate information from character set B, obtain device model information from character set C, and obtain date and time information from character set D; Integrate the authentication information classification results of each group of obtained information, construct a fuzzy search function, and perform authentication extraction operations based on the corresponding information obtained in each group and the authentication constraint conditions through the fuzzy search function; S3, for the obtained corresponding information and authentication constraint conditions, calculate the feature extraction evaluation value for each type of information describing the classification attributes in the character set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and particularly to a client security authentication working method for remote authorization. Background Art

[0002] In the prior art, identity authentication is required during the data interaction process with remote devices. Due to the fact that the installation site of project devices is in remote areas, real-time and security considerations are needed for the control of the client. However, in the information interaction process, the security authentication operations between the remote terminal and the client require a complete data matching process, and the massive authentication information stored in the remote terminal needs to be matched with the client's authentication information. This requires relying on an accurate comparison method. If the matching information cannot completely correspond or is inaccurately corresponding, serious security problems will occur, which urgently requires those skilled in the art to solve the corresponding technical problems. Summary of the Invention

[0003] The present invention aims to at least solve the technical problems existing in the prior art, and particularly innovatively proposes a client security authentication working method for remote authorization.

[0004] To achieve the above object of the present invention, the present invention provides a client security authentication working method for remote authorization, including the following steps:

[0005] S1. The remote terminal collects massive authentication information. After the client is started and ready to send authentication information, weighted calculation is performed through a character set constraint character function, and the client sends the authentication information to the remote terminal.

[0006] S2. After the remote terminal obtains the authentication information sent by the client, the remote terminal performs information matching authentication operations through an information matching degree function and sends the matching authentication result to the client.

[0007] S3. If the similarity of the matching authentication result reaches the authentication passing set threshold function, the working permission of the corresponding client is enabled.

[0008] Preferably, the S1 includes:

[0009] S1-1. Feature partitioning is performed on the authentication information of the remote terminal. Since the authentication information is a combination with multiple character patterns, the combination is feature partitioned into character set A, character set B, character set C, and character set D.

[0010] S1-2. Obtain the serial number information from Character Set A, the geographical location coordinate information from Character Set B, the device model information from Character Set C, and the date and time information from Character Set D; integrate the obtained information in each group with the classification result of the authentication information, construct a fuzzy search function, and perform an authentication extraction operation based on the corresponding information obtained in each group and the authentication constraint conditions through the fuzzy search function.

[0011] Preferably, it further includes:

[0012] S1-3. For the corresponding information and authentication constraint conditions obtained, perform a constraint attribute judgment. Use a to represent successful feature extraction for the constraint attribute; use b to represent unsuccessful feature extraction, and calculate the feature extraction evaluation value for each type of information describing the classification attribute in the character set.

[0013] S1-4. Construct a single feature vector according to the weighting of the constraint character function, traverse the vector, and remove invalid characters through the constraint character function to form a character set for weighted constraint calculation.

[0014] Preferably, it further includes:

[0015] S1-5. Calculate the characters after weighted constraint for the feature extraction evaluation value. Each evaluation value will be integrated as pattern information into the character set calculated by the constraint character function. After data compression by the remote terminal, it is matched with the authentication information sent by the client.

[0016] Preferably, the S2 includes: S2-1. After the operation of the constraint character function, the successfully extracted feature elements are included in the authentication information of the remote terminal. After the remote terminal obtains the request authentication information sent by the client, calculate the mean value of the authentication attribute value J in the authentication dataset, and calculate the Mahalanobis distance from J to to Eliminate the deviation between the pre-stored authentication feature elements of the remote terminal and the client authentication feature elements, and obtain the correlation of the authentication information.

[0017] Preferably, the S2 further includes:

[0018] S2-2. Effectively obtain the accurate matching of the authentication information by establishing an information matching degree function for the discovery of the authentication information and the screening and elimination of non-matching information.

[0019] S2-3. If the authentication information of the remote terminal and the object matched by the client's feature elements are within the set matching range, perform a recommended operation for the matching object to the remote terminal; evaluate the similarity of the authentication information with the maximum matching probability obtained in the matching authentication according to the target consistency.

[0020] Preferably, the S3 includes:

[0021] S3-1, set the accuracy rate judgment threshold function for the matching authentication result;

[0022] S3-2, calculate the accuracy rate according to the accuracy rate judgment threshold function, and enable different client working permissions according to different conditions of the accuracy rate;

[0023] S3-3, after information matching between the remote terminal and the client in the network, perform security information interaction so as to effectively control the information of the PLC.

[0024] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are as follows:

[0025] By collecting and extracting the character set of the remote terminal, obtaining the constraint set of effective feature elements, and performing weighted calculation on the character set, and preventing the influence of information loss caused by overfitting during the information extraction process, a suitable convergence result is formed for the successfully extracted feature elements, which is convenient for matching operations with the client information.

[0026] Through the information authentication matching calculation of the remote terminal, the client enables the corresponding working interaction operation permissions according to the set accuracy rate judgment threshold, and if the authentication information interaction is invalid, the security information interaction process is terminated.

[0027] The additional aspects and advantages of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The above and / or additional aspects and advantages of the present invention will become obvious and easy to understand from the description of the embodiments in conjunction with the following drawings, wherein:

[0029] Figure 1 is the overall schematic diagram of the present invention;

[0030] Figure 2 is the character extraction schematic diagram of the present invention;

[0031] Figure 3 is the working schematic diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions from beginning to end. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.

[0033] As Figure 3As shown in the figure, the present invention discloses a client security authentication working method for remote authorization, including the following steps:

[0034] S1. The remote terminal collects a large amount of authentication information. After the client is started and prepares to send the authentication information, weighted calculation is performed through a character set constraint character function, and the client sends the authentication information to the remote terminal;

[0035] S2. After the remote terminal obtains the authentication information sent by the client, the remote terminal performs information matching authentication operations through an information matching degree function and sends the matching authentication result to the client;

[0036] S3. If the similarity of the matching authentication result reaches the set threshold function for authentication passing, the working permission of the corresponding client is enabled.

[0037] S1-1. Feature partitioning is performed on the authentication information of the remote terminal. Since the authentication information is a combination with multiple character patterns, the combination is feature partitioned into character sets A, B, C, and D;

[0038] S1-2. Serial number information is obtained from character set A, geographical location coordinate information is obtained from character set B, device model information is obtained from character set C, and date and time information is obtained from character set D; The information obtained in each group is integrated into the authentication information classification result, and a fuzzy search function is constructed. Based on the corresponding information obtained in each group and the authentication constraint conditions, authentication extraction operations are performed through the fuzzy search function;

[0039] S1-3. For the obtained corresponding information and authentication constraint conditions, constraint attribute judgment is performed. Use a to represent successful feature extraction for the constraint attribute; Use b to represent unsuccessful feature extraction, and calculate the feature extraction evaluation value for each type of information describing the classification attribute in the character set;

[0040] S1-4. According to the weighting of the constraint character function, a single feature vector is constructed. Traverse this vector, and through the constraint character function, remove invalid characters to form a character set for weighted constraint calculation. For example: the unit of geographical coordinates, the first few digits of the serial number are 0, and the first digit of the date is 0;

[0041] S1-5. The character after weighted constraint is calculated for the feature extraction evaluation value. Each evaluation value will be integrated into the character set calculated by the constraint character function as pattern information. After the remote terminal performs data compression, it is matched with the authentication information sent by the client; As Figure 2 shown

[0042] The said fuzzy search function is: Feature mapping is performed on the character object, and the formed character object vector is U→[sk 1 ,sk 2 ,...,skn , where \(s_k\) is the characteristic element, the subscript \(n\) is the number of elements. By collecting the same characteristic elements, the output of the character object vector is completed, and different characteristic elements are output for different character sets;

[0043]

[0044] Set an offset correction parameter \(\sigma\) and the weight \(\omega\) of the characteristic element to correct the character object vector. \(m\) is the weighting coefficient \(A\) i The parameter assignment of \(A\), \(c\) is the coincidence degree of the characteristic element, and \(g(c)\) is the coincidence degree calculation function;

[0045] After extracting the characteristic elements from the character set, determine whether the feature extraction is successful; if the extraction is successful, construct a weighted model of the characteristic elements:

[0046] Let \(a\) be the record symbol for successful feature extraction and \(b\) be the record symbol for unsuccessful feature extraction. After successful feature extraction, form a single feature vector for all characteristic elements according to the constraint character function, traverse the same characteristic elements included in the vector, and set a threshold to locate the client position where the characteristic element is located.

[0047] For the characteristic elements in the feature vector \(\{\langle y\) i ,z i \rangle|y i \in E a ,z i \in E b , 0\leq index(y i ,z i ) \lt destination\}, where \(y\) i is the characteristic element when the feature extraction is successful, classified into the successful sample set \(E\) a and \(z\) i is the characteristic element when the feature extraction is unsuccessful, classified into the unsuccessful sample set \(E\) b . The formed target index \(0\leq index(y i ,z i ) \lt destination\) always remains within the standard target threshold \(destination\). The threshold range is at the target mean configured for the two sample sets, and the target mean is the average of the two sample sets divided by the standard deviation; \(y_i + z_i = H\) is the sum of all characteristic elements of the client;

[0048] The formed constraint character function \(G=\alpha(1 - \alpha)X+\beta(H-\beta F)Y\), where the constraint parameter \(0\lt\alpha\lt1\), and the balance factor \(\beta\) converges the weight \(F\) of the matching result of the successfully extracted characteristic elements. \(X\) is the regularization threshold of the successfully extracted characteristic elements, and \(Y\) is the result parameter of the successfully extracted characteristic elements;

[0049] A is a character set of serial numbers, and each A i is:

[0050] A 1 : c_cL-UzGGlFSUVGpSECgCyVOVi70eBQcvJ5sbIZdbPNShDZs4fXSsxXogSi9A;

[0051] A 2 : BQlb85JdSCmxyT_VLHS-AFNXY0eBQcvJ5lFSUVPNShDZSShD70eB:

[0052] A3: VhAEJj6ysyFiVEbk9uE9RsotnDAJtrSylykC9wltr1YqkSCfNzmjBO2j02fond72g;

[0053] …

[0054] An: DZs4fXS85JdSsxXogSmo8Ni9S-AFA0 Qlb8eFiStgSUVBShDCgCyXosgVZ:

[0055] B is a character set of geographical location coordinates, and each B i is:

[0056] B 1 : 48°51'29.54"N, 2°17'40.19"E

[0057] B 2 : 40°41'21.48"N, 74°2'40.38"W

[0058] B 3 : 29°58'33.22"N, 31°7'49.29"E

[0059] …

[0060] B n : 27°10'30"N, 78°02'32"E

[0061] C is a character set of device models, and each Ci is: (because different products will generate different device model character codes)

[0062] C 1 : AB-Inbev(China)EquipmentNameplate ZBS-TS / Maintenance;

[0063] C 2: TTZA001 TTZB001 TTZC001 TTZD001 TTZD002 TTZE001 TTZE002 TTZE003TTZE004 TTZE005 TTZE006 TTZF001

[0064] …

[0065] C n : PLSY-GC-ZD-01-2012;

[0066] D is to obtain the date and time character set, and each Di is:

[0067] D 1 : yyyy-MM-dd; 2021-05-10; 10:26:30AM;

[0068] D 2 : yyyy-MM-dd; 2021-06-23; 06:59:06PM;

[0069] D 3 : yyyy-MM-dd; 2021-08-18; 05:50:17PM;

[0070] …

[0071] D n : yyyy-MM-dd; 2021-10-23; 11:08:59PM;

[0072] Regarding the working coordination mechanism between the remote terminal and the client PLC, the PLC needs to be securely authenticated before the remote terminal can complete the work instructions for the client. During the information extraction process, in order to prevent the loss of valid information due to overfitting, the extreme value strategy cannot be adopted in the parameter configuration, which may cause the loss of extracted feature elements.

[0073] Preferably, the S2 includes:

[0074] S2-1. After the operation of the constraint character function, the successfully extracted feature elements are included in the authentication information of the remote terminal. After the remote terminal obtains the request authentication information sent by the client, it calculates the mean value of the authentication attribute value J in the authentication dataset and calculates the Mahalanobis distance from J to to eliminate the deviation between the authentication feature elements pre-stored in the remote terminal and the client authentication feature elements and obtain the correlation of the authentication information;

[0075] S2-2. By establishing an information matching degree function, the discovery of authentication information and the screening and elimination of non-matching information are effectively used to obtain the accurate matching of authentication information.

[0076] Among them, the similarity between the remote terminal feature elements and the feature elements successfully extracted by the client is calculated through the information matching degree function Z(e).

[0077]

[0078] Among them, e is the number of authentication matching sample features of the remote terminal and the client, s is the total number of sample features, t e is the e-th feature of the sample t to be matched, λ is the feature weight value of the sample t to be matched, H is all the feature elements of the client, ε is the extraction threshold of the client feature elements, I is the feature elements to be matched by the remote terminal, μ is the extraction threshold of the remote terminal feature elements, h is the feature element of the client, M e (h) is the prior probability of the client feature element, M e (t e |h) is the conditional probability of t e in the client feature element h;

[0079] By setting the information matching classifier for t e as the matching category, N h is the matching correct rate of the client feature element h, where Q = (letter, num, time, position, direction, null, zero);

[0080] S2-3, if the authentication information of the remote terminal and the object matched by the client feature element are within the set matching range, a recommendation operation for the matching object is performed on the remote terminal; the authentication information with the maximum matching probability obtained in the matching authentication according to the target consistency is evaluated for similarity;

[0081] S2-4, the target consistency is calculated according to the logarithmic likelihood function

[0082] The CK combination is the matching authentication reference function, k is the number of authentications, is the covariance calculation formula of the authentication information, R is the authentication information estimate value, and η is the authentication adjustment threshold;

[0083] Preferably, the S3 includes:

[0084] S3-1, setting the matching authentication result accuracy judgment threshold function,

[0085]

[0086] Among them, O iFor matching the authentication fitting constraint condition, V j For matching the authentication smoothing constraint condition, For the category of the authentication samples, p j For the total number of the authentication samples,

[0087] S3-2. Calculate the accuracy rate according to the accuracy rate judgment threshold function, and enable different client working permissions according to different conditions of the accuracy rate;

[0088] The accuracy rate is calculated as:

[0089] where S(u) is the accuracy rate judgment threshold function value of the characteristic elements of all the accumulated authentication information, is the total number of samples of the remote terminal characteristic elements, is the total number of samples of the client characteristic elements,

[0090] S3-3. After information matching between the remote terminal and the client in the network, perform security information interaction so as to effectively control the information of the PLC,

[0091] The client enables the corresponding working interaction operation permission according to the set accuracy rate judgment threshold. If the authentication information interaction is invalid, the security information interaction process is terminated.

[0092] As Figure 1 shown, the program deployment of the remote terminal penetrates the internal network, and the client can access the remote terminal. The client is started by the remote terminal and connected to the network. When the client is started, it sends the serial number of the local machine to the remote terminal. The remote terminal listens to each client in real time. After receiving the serial number sent by the client, it queries the local database and sends the permission set by the administrator to the client as an authorization code. If the client serial number is 001, the permission set by the administrator is MosesA, the client location coordinates are X° and Y°, and the current time is 2021-10-11, then the authorization code is 001MosesA20211011. After receiving the authorization code, the client will respectively judge whether the serial number and the date are correct. If correct, it will then judge the granted permission level and enable the corresponding permission.

[0093] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and purposes of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A client security authentication working method for remote authorization, characterized in that, it includes the following steps: S1. The remote terminal collects a large amount of authentication information. After the client is started and ready to send the authentication information, weighted calculation is performed through the character set constraint character function, and the client sends the authentication information to the remote terminal; The character set constraint character function , constraint parameter , balance factor β Converge the weight F of the matching result of the successfully extracted feature elements. X is the regularization threshold of the successfully extracted feature elements, and Y is the result parameter of the successfully extracted feature elements; S2. After the remote terminal obtains the authentication information sent by the client, the remote terminal performs information matching authentication operations through the information matching degree function and sends the matching authentication result to the client; S3. If the similarity of the matching authentication result reaches the authentication passing set threshold function, the working permission of the corresponding client is enabled; The said S1 includes: S1-1. Feature division is performed on the authentication information of the remote terminal. Since the authentication information is a combination with multiple character patterns, the combination is feature-divided into character set A, character set B, character set C, and character set D; S1-2. Serial number information is obtained from character set A, geographical location coordinate information is obtained from character set B, device model information is obtained from character set C, and date and time information is obtained from character set D; The information obtained in each group is integrated with the authentication information classification result, a fuzzy search function is constructed, and authentication extraction operations are performed based on the corresponding information and authentication constraint conditions obtained in each group through the fuzzy search function; S1-3. For the corresponding information and authentication constraint conditions obtained, constraint attribute judgment is performed. Use a to represent successful feature extraction for the constraint attribute; use b to represent unsuccessful feature extraction, and calculate the feature extraction evaluation value for each type of information describing the classification attribute in the character set; S1-4. According to the weighting of the character set constraint character function, a single feature vector is constructed, traverse the vector, and remove invalid characters through the character set constraint character function to form a character set for weighted constraint calculation; S1-5. The characters after weighted constraint are calculated for the feature extraction evaluation value, and each evaluation value will be integrated into the character set calculated by the character set constraint character function as pattern information. After the remote terminal performs data compression, it is matched with the authentication information sent by the client.

2. The client security authentication working method for remote authorization according to claim 1, characterized in that, The S2 includes: S2-1. After the operation of the character function with character set constraints, the successfully extracted feature elements are included in the authentication information of the remote terminal. After the remote terminal obtains the request authentication information sent by the client, it calculates the mean value of the authentication attribute values in the authentication dataset, and calculates the Mahalanobis distance from J to J to to eliminate the deviation between the pre-stored authentication feature elements of the remote terminal and the client authentication feature elements, and obtain the correlation of the authentication information. ​ 3. The client security authentication working method for remote authorization according to claim 2, characterized in that, The said S2 also includes: S2-2. Through the establishment of an information matching degree function, the discovery of authentication information, as well as the screening and elimination of non-matching information, are used to effectively obtain the accurate matching of authentication information; S2-3. If the authentication information of the remote terminal and the object matched by the characteristic elements of the client are within the set matching range, a recommendation operation for the matching object is performed on the remote terminal; The authentication information with the maximum matching probability obtained in the matching authentication according to the target consistency is evaluated for similarity.

4. The client security authentication working method for remote authorization according to claim 1, characterized in that, The said S3 includes: S3-1. Set the accuracy judgment threshold function for the matching authentication result; S3-2. Calculate the accuracy according to the accuracy judgment threshold function, and enable different client working permissions according to different accuracy conditions; S3-3. After information matching between remote terminals and clients in the network, security information is exchanged to enable effective information control over the PLC.

Citation Information

Patent Citations

  • Access authentication method and related device of remote control terminal service and communication system

    CN101867475A

  • Authentication method, authentication device, authentication system and treatment equipment

    CN105871857A