A remote authorization authentication information matching working method
By performing feature division and weighting calculation of the authentication information of the remote terminal, a fuzzy search function and a constraint character function are constructed, which solves the problem of inaccurate matching of authentication information in the interaction between remote devices and client data, and improves the accuracy and effectiveness of security authentication.
Patent Information
- Application Number
- CN202111312951.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-08
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-11-08
AI Technical Summary
When remote devices interact with clients in data, there are problems such as incomplete or inaccurate information during the matching process of massive authentication information, resulting in impairment of security.
A remote authorization authentication information matching working method is adopted. By performing feature division and weighting calculation of the authentication information of the remote terminal, a fuzzy search function and a constraint character function are constructed, and feature extraction and matching operations are performed to ensure the accuracy of the authentication information.
Through effective feature extraction and weighted calculation, we ensure accurate matching of authentication information, prevent information loss caused by overfitting during information extraction, and improve the secure authentication process between remote devices and clients.
Smart Images

Figure CN114003895B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a remote authorization authentication information matching working method. Background Art
[0002] In the prior art, identity authentication is required during data interaction with remote devices. Since the project equipment installation site is in a remote area, the control of the client requires real-time and security considerations. However, during the information interaction process, the security authentication operation of the remote terminal and the client requires a complete data matching process, and the massive authentication information stored in the remote terminal needs to be matched with the authentication information of the client, which requires an accurate comparison method. If the matching information cannot completely correspond or the correspondence is inaccurate, it will cause serious security problems. This urgently requires technical personnel in this field to solve the corresponding technical problems. Summary of the invention
[0003] The present invention aims to at least solve the technical problems existing in the prior art, and in particular innovatively proposes a remote authorization authentication information matching working method.
[0004] In order to achieve the above-mentioned purpose of the present invention, the present invention provides a remote authorization authentication information matching working method, including the following steps: the remote terminal collects a large amount of authentication information, the client is started and prepares to send the authentication information, a weighted calculation is performed through a character set constraint character function, and the client sends the authentication information to the remote terminal.
[0005] Preferably, it also includes:
[0006] S1-1, feature division of the authentication information of the remote terminal. Since the authentication information is a combination of multiple character patterns, the combination is feature divided into A character set, B character set, C character set and D character set;
[0007] S1-2, obtain serial number information in character set A, obtain geographic location coordinate information in character set B, obtain device model information in character set C, and obtain date and time information in character set D; integrate the authentication information classification results for each group of information obtained, construct a fuzzy search function, and use the fuzzy search function to perform authentication extraction operations based on the corresponding information and authentication constraints obtained for each group.
[0008] Preferably, it also includes:
[0009] S1-3, for the corresponding information and authentication constraint conditions obtained, the constraint attribute is judged, and a is used to indicate successful feature extraction for the constraint attribute; b is used to indicate unsuccessful feature extraction, and the feature extraction evaluation value is calculated for each information describing the classification attribute in the character set;
[0010] S1-4, construct a unified feature vector according to the weight of the constrained character function, traverse the vector, remove invalid characters through the constrained character function, and form a character set for weighted constraint calculation.
[0011] Preferably, it also includes:
[0012] S1-5, feature extraction evaluation value calculation weighted constrained characters, each evaluation value will be integrated into the character set calculated by the constrained character function as pattern information, and the remote terminal will match the authentication information sent by the client after data compression.
[0013] Preferably, the fuzzy search function is: feature mapping is performed on the character object, and the character object vector formed is U→[sk 1 ,sk 2 ,...,sk n ], sk is the characteristic element, subscript n is the number of elements, and the output of the character object vector is completed by collecting the same characteristic elements, and different characteristic elements are output for different character sets;
[0014]
[0015] Set an offset correction parameter σ and a feature element weight ω to correct the character object vector, and m is the weight coefficient A i , c is the coincidence degree of characteristic elements, and g(c) is the coincidence calculation function.
[0016] Preferably, it also includes:
[0017] After extracting the feature elements of the character set, determine whether the feature extraction is successful; if it is successful, build a feature element weighted model:
[0018] a is used as the record symbol of successful feature extraction, and b is used as the record symbol of unsuccessful feature extraction. After the feature extraction is successful, a unified feature vector is formed for all feature elements according to the constraint character function, and the same feature elements contained in the vector are traversed, and the threshold is set to locate the remote terminal information list position where the feature element is located.
[0019] For the feature vector { <y i ,z i >|y i ∈E a ,z i ∈E b ,0≤index(y i ,z i )<destination}, where y i The feature elements when feature extraction is successful are classified into the successful sample set E aIn, z i The feature elements when feature extraction fails are classified into the unsuccessful sample set E b The target index 0≤index(y i ,z i )<destination always remains within the standard target threshold destination, yi+zi=H is the sum of all feature elements of the client;
[0020] The formed constraint character function G=α(1-α)X+β(H-βF)Y, the constraint parameter 0<α<1, the balance factor β converges the weight F of the successfully extracted feature element matching result, X is the regularization threshold of the successfully extracted feature element, and Y is the result parameter of the successfully extracted feature element.
[0021] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:
[0022] By collecting and extracting the character set of the remote terminal, the constraint set of effective feature elements is obtained, and the character set is weighted. In addition, the influence of information missing caused by overfitting in the information extraction process is prevented, and a suitable convergence result is formed for the successfully extracted feature elements, which is convenient for matching operations with client information.
[0023] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0025] Figure 1 It is an overall schematic diagram of the present invention.
[0026] Figure 2 It is a schematic diagram of character extraction of the present invention. DETAILED DESCRIPTION
[0027] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.
[0028] like Figure 1 As shown, the present invention discloses a remote authorization authentication information matching working method, comprising the following steps:
[0029] S1, the remote terminal collects a large amount of authentication information, and the client starts to send authentication information. It performs weighted calculation through the character set constraint character function, and the client sends the authentication information to the remote terminal;
[0030] S2, after the remote terminal obtains the authentication information sent by the client, the remote terminal performs information matching authentication operation through the information matching function and sends the matching authentication result to the client;
[0031] S3, if the similarity of the matching authentication result reaches the authentication pass set threshold function, the corresponding client's work permission is enabled.
[0032] S1-1, feature division of the authentication information of the remote terminal. Since the authentication information is a combination of multiple character patterns, the combination is feature divided into A character set, B character set, C character set and D character set;
[0033] S1-2, obtain serial number information in character set A, obtain geographic location coordinate information in character set B, obtain device model information in character set C, and obtain date and time information in character set D; integrate the authentication information classification results for each group of information obtained, construct a fuzzy search function, and use the fuzzy search function to perform authentication extraction operations based on the corresponding information and authentication constraints of each group;
[0034] S1-3, based on the corresponding information obtained and the authentication constraint conditions, the constraint attribute is judged, and a is used to indicate successful feature extraction for the constraint attribute; b is used to indicate unsuccessful feature extraction, and the feature extraction evaluation value is calculated for each information describing the classification attribute in the character set;
[0035] S1-4, construct a unified feature vector according to the weight of the constraint character function, traverse the vector, remove invalid characters through the constraint character function, and form a character set for weighted constraint calculation, for example: the unit of geographic coordinates, the first few digits in the serial number are 0, and the first digit in the date is 0;
[0036] S1-5, feature extraction evaluation value calculation weighted constrained characters, each evaluation value will be integrated into the character set calculated by the constrained character function as pattern information, and the remote terminal will match the authentication information sent by the client after data compression; Figure 2 As shown,
[0037] The fuzzy search function is: feature mapping is performed on the character object, and the character object vector formed is U→[sk 1 ,sk 2 ,...,sk n], sk is the characteristic element, subscript n is the number of elements, and the output of the character object vector is completed by collecting the same characteristic elements, and different characteristic elements are output for different character sets;
[0038]
[0039] Set an offset correction parameter σ and a feature element weight ω to correct the character object vector, and m is the weight coefficient A i , c is the coincidence degree of characteristic elements, g(c) is the coincidence degree calculation function;
[0040] After extracting the feature elements of the character set, determine whether the feature extraction is successful; if it is successful, build a feature element weighted model:
[0041] a is used as the record symbol of successful feature extraction, and b is used as the record symbol of unsuccessful feature extraction. After the feature extraction is successful, a unified feature vector is formed for all feature elements according to the constraint character function, and the same feature elements contained in the vector are traversed, and the threshold is set to locate the client position where the feature element is located.
[0042] For the feature vector { <y i ,z i >|y i ∈E a ,z i ∈E b ,0≤index(y i ,z i )<destination}, where y i The feature elements when feature extraction is successful are classified into the successful sample set E a In, z i The feature elements when feature extraction fails are classified into the unsuccessful sample set E b The target index 0≤index(y i ,z i )<destination always remains within the standard target threshold destination, the threshold range is the target mean configured for the two sample sets, and the target mean is the average of the two sample sets divided by the standard deviation; yi+zi=H is the sum of all feature elements of the client;
[0043] The constrained character function G=α(1-α)X+β(H-βF)Y is formed, the constraint parameter is 0<α<1, the balance factor β converges the weight F of the successfully extracted feature element matching result, X is the regularization threshold of the successfully extracted feature element, and Y is the result parameter of the successfully extracted feature element;
[0044] A is a serial number character set, each Ai for:
[0045] A 1 :c_cL-UzGGlFSUVGpSECgCyVOVi70eBQcvJ5sbIZdbPNShDZs4fXSsxXogSi9A;
[0046] A 2 :BQlb85JdSCmxyT_VLHS-AFNXY0eBQcvJ5lFSUVPNShDZSShD70eB:
[0047] A3: VhAEJj6ysyFiVEbk9uE9RsotnDAJtrSylykC9wltr1YqkSCfNzmjBO2j02fond72g;
[0048] …
[0049] An:DZs4fXS85JdSsxXogSmo8Ni9S-AFA0 Qlb8eFiStgSUVBShDCgCyXosgVZ:
[0050] B is the geographic location coordinate character set, each B i for:
[0051] B 1 :48°51'29.54"N,2°17'40.19"E
[0052] B 2 :40°41'21.48"N,74°2'40.38"W
[0053] B 3 :29°58'33.22"N,31°7'49.29"E
[0054] …
[0055] B n :27°10'30"N,78°02'32"E
[0056] C is the device model character set, each Ci is: (Because different products will generate different device model character codes)
[0057] C 1 :AB-Inbev(China)EquipmentNameplate ZBS-TS / Maintenance;
[0058] C 2:TTZA001 TTZB001 TTZC001 TTZD001 TTZD002 TTZE001 TTZE002 TTZE003TTZE004 TTZE005 TTZE006 TTZF001
[0059] …
[0060] C n :PLSY-GC-ZD-01-2012;
[0061] D is the character set for obtaining the date and time, each Di is:
[0062] D 1 :yyyy-MM-dd;2021-05-10;10:26:30AM;
[0063] D 2 :yyyy-MM-dd;2021-06-23;06:59:06PM;
[0064] D 3 :yyyy-MM-dd;2021-08-18;05:50:17PM;
[0065] …
[0066] D n :yyyy-MM-dd;2021-10-23;11:08:59PM;
[0067] For the coordination mechanism between the remote terminal and the client PLC, the PLC needs to be authenticated before the remote terminal can complete the work instructions to the client. In order to prevent the loss of extracted information due to overfitting, the extreme value strategy cannot be used in the parameter configuration, which will cause the loss of extracted feature elements.
[0068] Preferably, S2 includes:
[0069] S2-1, after the operation of the constrained character function, the successfully extracted feature elements are included in the authentication information of the remote terminal. After the remote terminal obtains the request authentication information sent by the client, it averages the authentication attribute values J in the authentication data set and calculates the Mahalanobis distance from J to J Eliminate the deviation between the authentication feature elements pre-stored in the remote terminal and the authentication feature elements of the client, and obtain the relevance of the authentication information;
[0070] S2-2, by establishing an information matching function to discover authentication information, and filter and eliminate non-matching information to effectively obtain accurate matching of authentication information,
[0071] The remote terminal feature elements and the feature elements successfully extracted by the client are similarly calculated through the information matching function Z(e).
[0072]
[0073] Among them, e is the number of sample features matching the remote terminal and the client authentication, s is the total number of sample features, t e is the e-th feature of the sample t to be matched, λ is the feature weight of the sample t to be matched, H is all the feature elements of the client, ε is the extraction threshold of the client feature elements, I is the feature element to be matched by the remote terminal, μ is the extraction threshold of the remote terminal feature element, h is the feature element of the client, M e (h) is the prior probability of the client feature element, M e (t e |h) is t e The conditional probability in the feature element h of the client;
[0074] Matching classifiers by setting information t e The matching category, N h is the matching accuracy of the client's feature element h, where
[0075] S2-3, if the object matched by the authentication information of the remote terminal and the characteristic element of the client is within the set matching range, a matching object recommendation operation is performed to the remote terminal; the authentication information with the maximum matching probability obtained in the matching authentication according to the target consistency is evaluated for similarity;
[0076] S2-4, the target consistency is calculated according to the log-likelihood function
[0077] CK combination is the matching authentication reference function, k is the number of authentication times, is the authentication information covariance calculation formula, R is the authentication information estimation value, and η is the authentication adjustment threshold;
[0078] Preferably, S3 includes:
[0079] S3-1, set the matching authentication result accuracy judgment threshold function,
[0080]
[0081] Among them, O i To match the certification fitting constraints, V j To match the authentication smoothness constraint, To match the category of the authentication sample, p j is the total number of matching authentication samples,
[0082] S3-2, calculate the accuracy rate according to the accuracy rate judgment threshold function, and enable different client work permissions according to different accuracy rate conditions;
[0083] The accuracy is calculated as:
[0084] Where S(u) is the accuracy judgment threshold function value of the characteristic elements of all authentication information calculated cumulatively, is the total number of samples of the remote terminal feature elements, is the total number of samples of client feature elements,
[0085] S3-3, after matching the information between the remote terminal and the client in the network, the security information is exchanged so that the PLC can be effectively controlled.
[0086] The client opens the corresponding work interaction operation permissions according to the set accuracy judgment threshold, and terminates the security information interaction process if the authentication information interaction is invalid.
[0087] like Figure 1 As shown, the program deployment of the remote terminal penetrates the intranet, and the client can access the remote terminal. Start the client through the remote terminal and connect to the Internet. When the client starts, it sends the serial number of the local machine to the remote terminal. The remote terminal monitors each client in real time. After receiving the serial number sent by the client, it converts the permissions set by the administrator into an authorization code and sends it to the client by querying the local database. For example, if the client serial number is 001, the permissions set by the administrator are MosesA, the client location coordinates are X° and Y°, and the current time is 2021-10-11, then the authorization code is 001MosesA20211011. After receiving the authorization code, the client will determine whether the serial number and date are correct. If correct, it will determine the level of permission granted and enable the corresponding permission.
[0088] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.
Claims
1. A remote authorization authentication information matching working method, It is characterized in that The method comprises the following steps: a remote terminal collects a large amount of authentication information, a client is started and is ready to send the authentication information, a weighted calculation is performed through a character set constraint character function, and the client sends the authentication information to the remote terminal; S1-1, feature division of the authentication information of the remote terminal. Since the authentication information is a combination of multiple character patterns, the combination is feature divided into A character set, B character set, C character set and D character set; S1-2, obtain serial number information in character set A, obtain geographic location coordinate information in character set B, obtain device model information in character set C, and obtain date and time information in character set D; integrate the authentication information classification results for each group of information obtained, construct a fuzzy search function, and use the fuzzy search function to perform authentication extraction operations based on the corresponding information and authentication constraints of each group; The character set constraint character function G=α(1-α)X+β(H-βF)Y, the constraint parameter 0<α<1, the balance factor β converges the weight F of the successfully extracted feature element matching result, X is the regularization threshold of the successfully extracted feature element, and Y is the result parameter of the successfully extracted feature element.
2. The remote authorization authentication information matching working method according to claim 1, It is characterized in that Also includes: S1-3, judging the constraint attribute according to the corresponding information and authentication constraint conditions, and using a to indicate successful feature extraction for the constraint attribute; b is used to indicate that feature extraction is unsuccessful, and the feature extraction evaluation value is calculated for each type of information describing the classification attribute in the character set; S1-4, construct a unified feature vector according to the weight of the character set constraint character function, traverse the vector, remove invalid characters through the constraint character function, and form a character set for weighted constraint calculation.
3. The remote authorization authentication information matching working method according to claim 2, It is characterized in that Also includes: S1-5, feature extraction evaluation value calculation weighted constrained characters, each evaluation value will be integrated into the character set calculated by the constrained character function as pattern information, and the remote terminal will match the authentication information sent by the client after data compression.
4. The remote authorization authentication information matching working method according to claim 1, It is characterized in that The fuzzy search function is: feature mapping is performed on the character object, and the character object vector formed is U→[sk 1 ,sk 2 ,...,sk n ], sk is the characteristic element, subscript n is the number of elements, and the output of the character object vector is completed by collecting the same characteristic elements, and different characteristic elements are output for different character sets; Set an offset correction parameter σ and a feature element weight ω to correct the character object vector, and m is the weight coefficient A i , c is the coincidence degree of characteristic elements, and g(c) is the coincidence calculation function.
5. The remote authorization authentication information matching working method according to claim 1, It is characterized in that Also includes: After extracting the feature elements of the character set, determine whether the feature extraction is successful; if it is successful, build a feature element weighted model: a is used as the record symbol of successful feature extraction, and b is used as the record symbol of unsuccessful feature extraction. After the feature extraction is successful, a unified feature vector is formed for all feature elements according to the constraint character function, and the same feature elements contained in the vector are traversed, and the threshold is set to locate the remote terminal information list position where the feature element is located. For the feature vector { <y i ,z i >|y i ∈E a ,z i ∈E b ,0≤index(y i ,z i )<destination}, where y i The feature elements when feature extraction is successful are classified into the successful sample set E a In, z i The feature elements when feature extraction fails are classified into the unsuccessful sample set E b The target index 0≤index(y i ,z i )<destination always remains within the standard target threshold destination, and yi+zi=H is the sum of all feature elements of the client.
Citation Information
Patent Citations
Authentication method, authentication device, authentication system and treatment equipment
CN105871857A
Trusted data authorization method, certificate authorization method and service access method
CN112306978A